diff --git a/src/proxy/tcp_proxy_client.c b/src/proxy/tcp_proxy_client.c index 9d1225ee..4c3752fe 100644 --- a/src/proxy/tcp_proxy_client.c +++ b/src/proxy/tcp_proxy_client.c @@ -250,7 +250,7 @@ static err_t tcp_proxy_client_accept_cb(void *arg, struct tcp_pcb *newpcb, err_t static void tcp_proxy_client_tx_waiter_cb(struct ll_queue* q, void* arg) { (void)q; struct tcp_proxy_client_conn* pc = (struct tcp_proxy_client_conn*)arg; - if (!pc || !pc->tx_buf) return; + if (!pc || !pc->proxy || pc->rem_closed || !pc->tx_buf) return; int ret = tcp_proxy_client_send_data(pc, pc->tx_buf, pc->tx_len); if (ret == 0) { if (pc->pcb) tcp_recved(pc->pcb, pc->tx_len); @@ -266,7 +266,7 @@ static void tcp_proxy_client_tx_waiter_cb(struct ll_queue* q, void* arg) { static err_t tcp_proxy_client_recv_cb(void *arg, struct tcp_pcb *pcb, struct pbuf *p, err_t err) { struct tcp_proxy_client_conn *pc = (struct tcp_proxy_client_conn *)arg; - if (!pc) { if (p) pbuf_free(p); return LERR_OK; } + if (!pc || !pc->proxy || pc->rem_closed) { if (p) pbuf_free(p); return LERR_OK; } if (p == NULL || err != LERR_OK) { pc->fin_local = 1; @@ -316,35 +316,36 @@ static err_t tcp_proxy_client_recv_cb(void *arg, struct tcp_pcb *pcb, struct pbu static err_t tcp_proxy_client_sent_cb(void *arg, struct tcp_pcb *pcb, uint16_t len) { (void)len; struct tcp_proxy_client_conn *pc = (struct tcp_proxy_client_conn *)arg; - if (!pc) return LERR_OK; + if (!pc || !pc->proxy || pc->rem_closed) return LERR_OK; tcp_proxy_client_feed_from_transport(pc); return LERR_OK; } static void tcp_proxy_client_err_cb(void *arg, err_t err) { struct tcp_proxy_client_conn *pc = (struct tcp_proxy_client_conn *)arg; - if (!pc) { DEBUG_ERROR(DEBUG_CATEGORY_SOCKET, "PROXY tcp_proxy_client_err_cb: pc=NULL err=%d", err); return; } + if (!pc || !pc->proxy || pc->rem_closed) { DEBUG_ERROR(DEBUG_CATEGORY_SOCKET, "PROXY tcp_proxy_client_err_cb: pc=%p proxy=%p rem_closed=%d err=%d", (void*)pc, pc ? (void*)pc->proxy : NULL, pc ? pc->rem_closed : 0, err); return; } DEBUG_ERROR(DEBUG_CATEGORY_SOCKET, "TCP proxy client: error %d sid=%08x pcb_state=%u fin_local=%d rem_closed=%d", err, pc->stream_id, pc->pcb ? pc->pcb->state : 0, pc->fin_local, pc->rem_closed); + pc->pcb = NULL;// pcb уже уничтожен стеком lwip pc->error = 1; if (tcp_proxy_client_send_error(pc) < 0) DEBUG_ERROR(DEBUG_CATEGORY_SOCKET, "PROXY send_error failed sid=%08x", pc->stream_id); } static err_t tcp_proxy_client_poll_cb(void *arg, struct tcp_pcb *pcb) { struct tcp_proxy_client_conn *pc = (struct tcp_proxy_client_conn *)arg; - if (!pc) return LERR_OK; + if (!pc || !pc->proxy || pc->rem_closed) return LERR_OK; if (pc->error) { DEBUG_ERROR(DEBUG_CATEGORY_SOCKET, "PROXY CLEANUP error sid=%08x", pc->stream_id); - if (pc->pcb) { - tcp_arg(pc->pcb, NULL); - tcp_recv(pc->pcb, NULL); - tcp_sent(pc->pcb, NULL); - tcp_err(pc->pcb, NULL); - tcp_poll(pc->pcb, NULL, 0); - tcp_abort(pc->pcb); - pc->pcb = NULL; - } + if (pc->pcb) { + tcp_arg(pc->pcb, NULL); + tcp_recv(pc->pcb, NULL); + tcp_sent(pc->pcb, NULL); + tcp_err(pc->pcb, NULL); + tcp_poll(pc->pcb, NULL, 0); + tcp_abort(pc->pcb); + pc->pcb = NULL; + } tcp_proxy_client_conn_free(pc); return LERR_OK; } @@ -478,7 +479,15 @@ static void tcp_proxy_client_handle_error(struct tcp_proxy_client* p, uint32_t s struct tcp_proxy_client_conn* pc = tcp_proxy_client_find_conn(p, stream_id); if (!pc) { DEBUG_INFO(DEBUG_CATEGORY_SOCKET, "PROXY ERROR sid=%08x — no conn, dropping", stream_id); return; } DEBUG_ERROR(DEBUG_CATEGORY_SOCKET, "PROXY ERROR from exit sid=%08x fin_local=%d", stream_id, pc->fin_local); - pc->pcb = NULL;// уже освобождён. больше им нельзя пользоваться + if (pc->pcb) { + tcp_arg(pc->pcb, NULL); + tcp_recv(pc->pcb, NULL); + tcp_sent(pc->pcb, NULL); + tcp_err(pc->pcb, NULL); + tcp_poll(pc->pcb, NULL, 0); + tcp_close(pc->pcb); + pc->pcb = NULL; + } pc->rem_closed = 1; if (pc->tx_buf) { u_free(pc->tx_buf); pc->tx_buf = NULL; pc->tx_len = 0; } etcp_router_waiter_cancel(pc->proxy->inst, pc->proxy->via_node_id, &pc->tx_waiter); @@ -490,8 +499,11 @@ static void tcp_proxy_client_handle_fin(struct tcp_proxy_client* p, uint32_t str if (!pc || !pc->pcb) return; DEBUG_INFO(DEBUG_CATEGORY_SOCKET, "PROXY FIN FROM exit sid=%08x pcb_state=%u — shutdown write (send FIN to local)", stream_id, pc->pcb->state); pc->fin_remote = 1; - if (pc->pcb->state != TIME_WAIT && pc->pcb->state != CLOSED) + if (pc->pcb->state != TIME_WAIT && pc->pcb->state != CLOSED) { tcp_shutdown(pc->pcb, 0, 1); + tcp_sent(pc->pcb, NULL); + tcp_poll(pc->pcb, NULL, 0); + } if (pc->fin_local && !pc->close_sent && !pc->close_pending) tcp_proxy_client_send_close(pc); }