grpc-js: Parsing logic of no_grpc_proxy/no_proxy variable(s) is flawed
メンテナーはふだん 2 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 55/100
- issue の種類
- バグ
- 明瞭さ
- おおむね明確
- 活発さ
- 静か
- 技術スタック
- node.js, typescript
- 領域
- networking
調査の方向性
まず内部のエントリーポイント hostMatchesNoProxyList を見つけ、reproduce-bug.js で再現されている動作と比較します。docker compose up --build を実行し、完全一致するホストと有効なサブドメインがプロキシをバイパスする一方で、notlocal.com や snapple.com のような無関係なサフィックスはバイパスしないことを確認します。
索引モデルが issue の本文から書いたものです。
説明
Problem description
The logic for checking whether a host matches the no proxy list in hostMatchesNoProxyList is flawed due to the naive endsWith(host) logic.
Reproduction steps
Note these reproduction steps copy the function logic and have no dependency on the package as the relevant internal functions aren't publicly exposed. Parts unrelated to the bug with external dependencies are commented out and a version with a proposed fix is given (i.e. hostMatchesNoProxyListV2). This is done for ease of reproducibility.
Dockerfile:
FROM node:24-slim
WORKDIR /reproduce
RUN npm init -y
COPY reproduce-bug.js .
RUN node reproduce-bug.js
Docker compose:
services:
bug-reproduce:
build:
context: .
dockerfile: Dockerfile
container_name: bug_reproduce
command: node reproduce-bug.js
reproduce-bug.js:
// Mocking the environment
process.env.https_proxy = 'http://proxy.local:3128';
process.env.no_proxy = 'local.com,apple.com';
// Existing grpc-js function
function getNoProxyHostList() {
/* Prefer using 'no_grpc_proxy'. Fallback on 'no_proxy' if it is not set. */
let noProxyStr = process.env.no_grpc_proxy;
let envVar = 'no_grpc_proxy';
if (!noProxyStr) {
noProxyStr = process.env.no_proxy;
envVar = 'no_proxy';
}
if (noProxyStr) {
// trace('No proxy server list set by environment variable ' + envVar);
return noProxyStr.split(',');
} else {
return [];
}
}
// Exsting grpc-js function with bug, modified for ease of reproducibility
function hostMatchesNoProxyList(serverHost) {
for (const host of getNoProxyHostList()) {
// const parsedCIDR = parseCIDR(host);
// host is a CIDR and serverHost is an IP address
// if (isIPv4(serverHost) && parsedCIDR && isIpInCIDR(parsedCIDR, serverHost)) {
// return true;
// } else if (serverHost.endsWith(host)) {
// // host is a single IP or a domain name suffix
// return true;
// }
if (serverHost.endsWith(host)) {
console.log(`[checking against (${host})]: ${serverHost} MATCHES the no proxy host`)
return true
}
}
console.log(`${serverHost} DOES NOT MATCH any of the no proxy hosts`)
return false;
}
// Modified function with proposed fix
function hostMatchesNoProxyListV2(serverHost) {
for (const host of getNoProxyHostList()) {
// const parsedCIDR = parseCIDR(host);
// host is a CIDR and serverHost is an IP address
// if (isIPv4(serverHost) && parsedCIDR && isIpInCIDR(parsedCIDR, serverHost)) {
// return true;
// } else if (serverHost.endsWith(host)) {
// // host is a single IP or a domain name suffix
// return true;
// }
// Proposed fix
if (serverHost === host) return true;
if (serverHost.endsWith('.' + host)) return true;
if (host.startsWith('.') && serverHost.endsWith(host)) return true;
}
console.log(`${serverHost} DOES NOT MATCH any of the no proxy hosts`)
return false;
}
const testHosts = [
'local.com', // Correctly matches
'www.local.com', // Correctly matches
'notlocal.com', // BUG: Should NOT match
'www.notlocal.com', // BUG: Should NOT match
'www.apple.com', // Correctly matches
'www.snapple.com' // BUG: Should NOT match
];
console.log(`NO_PROXY is set to: ${process.env.no_proxy}\n`);
testHosts.forEach(host => {
hostMatchesNoProxyList(host);
});
// test proposed fix
// testHosts.forEach(host => {
// hostMatchesNoProxyListV2(host);
// });
Run docker compose up --build
Output :
[checking against (local.com)]: local.com MATCHES the no proxy host
[checking against (local.com)]: www.local.com MATCHES the no proxy host
[checking against (local.com)]: notlocal.com MATCHES the no proxy host <-- BUG
[checking against (local.com)]: www.notlocal.com MATCHES the no proxy host <-- BUG
[checking against (apple.com)]: www.apple.com MATCHES the no proxy host
[checking against (apple.com)]: www.snapple.com MATCHES the no proxy host <--- BUG
Environment
N/A - containerized example given
Additional context
The man pages for curl lay out the logic that is most commonly expected:
Comma-separated list of hosts for which not to use a proxy, if one is specified. The only wildcard is a single "*" character, which matches all hosts, and effectively disables the proxy. Each name in this list is matched as either a domain which contains the hostname, or the hostname itself. For example, "local.com" would match "local.com", "local.com:80", and "www.local.com", but not "www.notlocal.com".
This option overrides the environment variables that disable the proxy ("no_proxy" and "NO_PROXY"). If there is an environment variable disabling a proxy, you can set the no proxy list to "" to override it.
IP addresses specified to this option can be provided using CIDR notation (added in 7.86.0): an appended slash and number specifies the number of network bits out of the address to use in the comparison. For example "192.168.0.0/16" would match all addresses starting with "192.168".
- 主要言語
- TypeScript
- スター
- 4.8k
- フォーク
- 717
- 平均マージ
- 1日 18時間
- マージ済み PR(30日)
- 17
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
grpc/grpc-node のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
メンテナーはふだん 2 日以内に返信
-
package: @grpc/grpc-js
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
grpc/grpc-node#2993 · コメント 3 件 · リアクション 4 件 ·
メンテナーはふだん 2 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 65/100
grpc/grpc-node#3091 · リアクション 1 件 ·
メンテナーはふだん 2 日以内に返信
-
feature request
難易度 3/5 1〜2日 初心者へのやさしさ 68/100
grpc/grpc-node#3077 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 76/100
grpc/grpc-node#3068 · コメント 2 件 · リアクション 1 件 ·
メンテナーはふだん 2 日以内に返信
似ている issue
-
Mend: dependency security vulnerability untriaged
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
opensearch-project/security-dashboards-plugin#2545 ·
メンテナーはふだん 1 日以内に返信
-
Add: Dream TR SDオープンcheck:passed streams:add
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
メンテナーはふだん 1 日以内に返信
-
doctor integrity sample scans soft-deleted pages on Postgres (batch path has no deleted_at filter)オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信
-
難易度 1/5 1時間未満 初心者へのやさしさ 72/100
SocialGouv/egapro#4672 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
area:agents area:tui bug
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
anthropics/claude-code#98358 ·
メンテナーはふだん 1 日以内に返信