Android: ProxyDetectorImpl crashes when DefaultProxySelector contains an invalid proxy port
メンテナーはふだん 2 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 78/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
調査の方向性
core/src/main/java/io/grpc/internal/ProxyDetectorImpl.java の detectProxy 周辺と、ソース検査で特定された行から開始し、次に DnsNameResolver がそれを呼び出す方法を追跡します。範囲外の https.proxyPort を指定したケースを再現し、名前解決を実行します。ProxySelector.select() からの IllegalArgumentException によって resolver がクラッシュせず、不正なプロキシ状態が直接接続にフォールバックすれば完了です。
索引モデルが issue の本文から書いたものです。
説明
What version of gRPC-Java are you using?
1.66.0
Source inspection indicates that latest 1.84.0 is also affected.
What is your environment?
Android production application.
Most events are from Android 13 devices (89%), predominantly Xiaomi (85%).
What did you expect to see?
A malformed system proxy configuration should not cause an uncaught exception on the gRPC resolver executor.
Because the configured proxy cannot be used, gRPC should preferably treat it as no usable proxy and continue with a direct connection. At minimum, it should convert the exception into an ordinary name-resolution failure instead of terminating the process.
What did you see instead?
Android’s DefaultProxySelector throws IllegalArgumentException while constructing a proxy address with an out-of-range port. The exception escapes through ProxyDetectorImpl and becomes a fatal process crash.
Fatal Exception: java.lang.IllegalArgumentException: port out of range:899858473
at java.net.InetSocketAddress.checkPort(InetSocketAddress.java:154)
at java.net.InetSocketAddress.createUnresolved(InetSocketAddress.java:279)
at sun.net.spi.DefaultProxySelector$1.run(DefaultProxySelector.java:315)
at sun.net.spi.DefaultProxySelector$1.run(DefaultProxySelector.java:219)
at java.security.AccessController.doPrivileged(AccessController.java:46)
at sun.net.spi.DefaultProxySelector.select(DefaultProxySelector.java:218)
at io.grpc.internal.ProxyDetectorImpl.detectProxy(ProxyDetectorImpl.java:230)
at io.grpc.internal.ProxyDetectorImpl.proxyFor(ProxyDetectorImpl.java:200)
at io.grpc.internal.DnsNameResolver.detectProxy(DnsNameResolver.java:269)
at io.grpc.internal.DnsNameResolver.access$600(DnsNameResolver.java:66)
at io.grpc.internal.DnsNameResolver$Resolve.run(DnsNameResolver.java:310)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1100)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
at java.lang.Thread.run(Thread.java:1572)
We observed multiple affected devices with different invalid ports. Each invalid value remains stable for its affected device. This suggests malformed device/system proxy state rather than corruption inside gRPC.
Analysis
On Android 13, DefaultProxySelector.select() reads the process proxy properties and passes the configured port directly to InetSocketAddress.createUnresolved().
InetSocketAddress rejects ports outside 0..65535.
The invalid value is the system proxy port, not the gRPC destination port. Although gRPC does not produce the malformed configuration, ProxyDetectorImpl currently allows the platform exception to escape from the resolver task.
The existing handling for a ProxySelector returning null or an empty list does not cover this case because the exception is thrown inside ProxySelector.select().
Comparable OkHttp behavior
OkHttp’s current implementation handles this exact case by catching IllegalArgumentException from ProxySelector.select() and treating it as no usable proxy, falling back to Proxy.NO_PROXY.
Its source explicitly explains the reason:
// A misconfigured system proxy (such as one with no port set) can make
// ProxySelector.select() itself throw IllegalArgumentException; treat that
// as "no usable proxy" rather than letting it crash.
Applying equivalent handling in gRPC would provide consistent behavior between regular OkHttp traffic and the gRPC OkHttp transport.
Reproduction
We have not reproduced the original malformed Android proxy state locally.
A synthetic reproduction should be possible by configuring:
https.proxyHost=<non-empty host>
https.proxyPort=<integer greater than 65535>
and then triggering name resolution through a gRPC channel using the default proxy detector.
Suggested change
Catch IllegalArgumentException around ProxySelector.select() and treat the result as no proxy:
final List<Proxy> proxies;
try {
proxies = proxySelector.select(uri);
} catch (IllegalArgumentException e) {
log.log(
Level.WARNING,
"ProxySelector failed while selecting a proxy; proceeding without proxy",
e);
return null;
}
Returning null from ProxyDetectorImpl.detectProxy() preserves connectivity through a direct connection and matches OkHttp’s behavior for malformed system proxy configuration.
If silently falling back to direct connectivity is considered inappropriate, converting the exception to IOException would still prevent a fatal process crash, although the channel would remain unavailable while the malformed proxy configuration persists.
- 主要言語
- Java
- スター
- 12.1k
- フォーク
- 4k
- 平均マージ
- 2日 3時間
- マージ済み PR(30日)
- 30
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
grpc/grpc-java のほかの issue
-
enhancement
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
メンテナーはふだん 2 日以内に返信
-
docs enhancement
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
grpc/grpc-java#10824 · コメント 8 件 ·
メンテナーはふだん 2 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 70/100
メンテナーはふだん 2 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 65/100
メンテナーはふだん 2 日以内に返信
-
enhancement
難易度 4/5 3〜5日 初心者へのやさしさ 30/100
メンテナーはふだん 2 日以内に返信
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
checkstyle/checkstyle#21755 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
メンテナーはふだん 1 日以内に返信
-
agentic-workflows
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
github/copilot-sdk#2782 ·
メンテナーはふだん 1 日以内に返信
-
documentation Good for newcomer quick win
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
CodeForPhilly/benefit-decision-toolkit#519 ·
メンテナーはふだん 1 日以内に返信
-
area-deployment triage:bot-seen triage:needs-human
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
microsoft/aspire#20533 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信