Skip to content
Open
Show file tree
Hide file tree
Changes from 20 commits
Commits
Show all changes
42 commits
Select commit Hold shift + click to select a range
ac1c120
JAVA-6035: Add backpressure flag to connection handshake (#1906)
nhachicha Mar 5, 2026
b33dca9
Add `MongoException.SYSTEM_OVERLOADED_ERROR_LABEL`/`RETRYABLE_ERROR_L…
stIncMale Mar 24, 2026
fa82369
JAVA-6055 Implement prose backpressure retryable writes tests (#1929)
stIncMale Apr 10, 2026
ffe5242
Add `maxAdaptiveRetries` API (#1944)
stIncMale Apr 20, 2026
44541fc
Add support for server selection's deprioritized servers (#1860)
vbabanin Apr 21, 2026
c380b2e
Implement prose backpressure tests (#1946)
stIncMale Apr 22, 2026
d083e1b
Add `enableOverloadRetargeting` API (#1943)
vbabanin Apr 23, 2026
bd888c9
Add handshake prose Test 9: backpressure: true in handshake documents…
nhachicha Apr 28, 2026
394f7b1
JAVA-5950 Update Transactions Convenient API with exponential backoff…
nhachicha May 1, 2026
0eb04a0
JAVA-6194 Add MongoSocksProxyException for CMAP backpressure labeling
nhachicha May 8, 2026
f2bcce5
Merge remote-tracking branch 'origin/backpressure' into nh/backpressu…
nhachicha May 16, 2026
28a074d
update submodule
nhachicha May 16, 2026
c2ca4fd
Address review nits in MongoSocksProxyException
nhachicha May 16, 2026
801127f
Close proxy socket on MongoSocksProxyException in SocksSocket.connect
nhachicha May 16, 2026
61a1c5e
Use getHostString in SocksSocket exception reporting path
nhachicha May 16, 2026
49e58f0
Fix socket leak in SOCKS5 initializer methods and DRY open()
nhachicha May 16, 2026
db26d92
Replace Thread.sleep(300) with input drain in SocksSocketTest
nhachicha May 16, 2026
fd39744
Use ephemeral closed port instead of port 1 in SocksSocketTest
nhachicha May 16, 2026
7416dd3
Use Java 8-compatible drain in SocksSocketTest mini-server
nhachicha May 18, 2026
4e3249b
Add Scala type alias for MongoSocksProxyException
nhachicha May 18, 2026
98483bb
Phase-aware MongoSocksProxyException handling in BackpressureErrorLab…
nhachicha May 18, 2026
78d6b01
Tag handshake-phase IOExceptions with the correct HandshakePhase
nhachicha May 18, 2026
dee79f0
Validate non-null HandshakePhase in MongoSocksProxyException
nhachicha May 18, 2026
b3da503
Align MongoSocksProxyException class-level Javadoc with phase-aware b…
nhachicha May 19, 2026
2c5be54
Broaden HandshakePhase enum Javadoc to cover I/O-failure path
nhachicha May 19, 2026
effa09a
Rename misleading eofDuring* tests to ioFailureDuring*
nhachicha May 19, 2026
095f524
Narrow tcpConnectFailure test to IOException, not Throwable
nhachicha May 19, 2026
582169c
Drive real EOF in ioFailureDuring* tests via half-close
nhachicha May 19, 2026
d7a9b15
Align constructor Javadoc with phase/replyCode semantics post round 2
nhachicha May 19, 2026
43e478c
Potential fix for pull request finding
nhachicha May 19, 2026
7971f9a
Widen outer catch in SocksSocket.connect to IOException
nhachicha May 19, 2026
27417eb
Drop redundant MongoSocksProxyException re-throw branches
nhachicha May 19, 2026
b2bb401
Drop redundant null-phase guard in BackpressureErrorLabeler
nhachicha May 19, 2026
2517b69
Backpressure-label SOCKS5 failures by mongod-attribution
nhachicha May 20, 2026
df8430c
Include proxy host:port in PROXY_TCP_CONNECT exception message
nhachicha May 20, 2026
0aafd71
Add SOCKS5/code context to CONNECT non-success reply message
nhachicha May 20, 2026
11a5866
Realign comments on the two outer catches in SocksSocket.connect
nhachicha May 20, 2026
4023a0b
Cleanups
nhachicha May 20, 2026
4cac195
Stop swallowing unexpected exceptions in connectWithMiniServer
nhachicha May 20, 2026
4a44d38
Document constructor parameter ordering convention
nhachicha May 20, 2026
4306d2e
Review feedback
nhachicha May 20, 2026
c5abbce
Fixing SOCKS5 failing prose tests
nhachicha May 20, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
165 changes: 165 additions & 0 deletions driver-core/src/main/com/mongodb/MongoSocksProxyException.java
Original file line number Diff line number Diff line change
@@ -0,0 +1,165 @@
/*
* Copyright 2008-present MongoDB, Inc.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

package com.mongodb;

import com.mongodb.lang.Nullable;

/**
* Thrown when an error occurs while establishing a connection to a SOCKS5 proxy.
*
* <p>Per the CMAP specification, errors of this type are excluded from backpressure
* error labels ({@link MongoException#SYSTEM_OVERLOADED_ERROR_LABEL},
Comment thread
nhachicha marked this conversation as resolved.
Outdated
* {@link MongoException#RETRYABLE_ERROR_LABEL}).
*
* <p>The {@link #getHandshakePhase()} identifies which phase of the SOCKS5 handshake failed.
* For {@link HandshakePhase#CONNECT_RELAY} failures, {@link #getProxyReplyCode()} returns
* the RFC 1928 reply code sent by the proxy; for all other phases it returns {@code null}.
Comment thread
nhachicha marked this conversation as resolved.
Outdated
*
* <p>RFC 1928 reply codes: 1=general failure, 2=connection not allowed by ruleset,
* 3=network unreachable, 4=host unreachable, 5=connection refused, 6=TTL expired,
* 7=command not supported, 8=address type not supported.
*
* @since 5.8
*/
public class MongoSocksProxyException extends MongoSocketOpenException {
Comment thread
nhachicha marked this conversation as resolved.
private static final long serialVersionUID = 1L;

/**
* The phase of the SOCKS5 handshake at which the failure occurred.
*
* @since 5.8
*/
public enum HandshakePhase {
/**
* TCP connection to the proxy host itself failed before any SOCKS5 exchange.
* The proxy may be temporarily unreachable.
*/
PROXY_TCP_CONNECT,

/**
* SOCKS5 method-selection exchange failed: the proxy version is incompatible,
* no common authentication method was found, or the proxy returned an
* unrecognised method. This is always a configuration error.
Comment thread
nhachicha marked this conversation as resolved.
Outdated
*/
NEGOTIATION,

/**
* Credential verification with the proxy failed. This is always a
* configuration error (wrong username or password).
Comment thread
nhachicha marked this conversation as resolved.
Outdated
*/
AUTHENTICATION,

/**
* The proxy processed the CONNECT command for the target host and returned
* a non-success reply code. See {@link MongoSocksProxyException#getProxyReplyCode()}
* for the specific RFC 1928 reply code.
Comment thread
nhachicha marked this conversation as resolved.
Outdated
*/
CONNECT_RELAY
}

private final HandshakePhase handshakePhase;

@Nullable
private final Integer proxyReplyCode;

/**
* Construct an instance for failures that have no RFC 1928 reply code and no cause
* ({@link HandshakePhase#PROXY_TCP_CONNECT}, {@link HandshakePhase#NEGOTIATION},
* {@link HandshakePhase#AUTHENTICATION}).
*
* @param message the message
* @param serverAddress the server address
* @param handshakePhase the phase at which the failure occurred
*/
public MongoSocksProxyException(final String message, final ServerAddress serverAddress, final HandshakePhase handshakePhase) {
this(message, serverAddress, handshakePhase, null);
}

/**
* Construct an instance for failures that have no RFC 1928 reply code
* ({@link HandshakePhase#PROXY_TCP_CONNECT}, {@link HandshakePhase#NEGOTIATION},
* {@link HandshakePhase#AUTHENTICATION}).
*
* @param message the message
* @param address the server address
* @param cause the cause
* @param handshakePhase the phase at which the failure occurred
*/
public MongoSocksProxyException(final String message, final ServerAddress address,
final Throwable cause, final HandshakePhase handshakePhase) {
this(message, address, cause, handshakePhase, null);
}

/**
* Construct an instance with an optional RFC 1928 reply code.
* Use {@code null} for phases that do not carry a reply code
* ({@link HandshakePhase#PROXY_TCP_CONNECT}, {@link HandshakePhase#NEGOTIATION},
* {@link HandshakePhase#AUTHENTICATION}).
*
* @param message the message
* @param address the server address
* @param handshakePhase the phase at which the failure occurred
* @param proxyReplyCode the RFC 1928 reply code, or {@code null}
*/
public MongoSocksProxyException(final String message, final ServerAddress address, final HandshakePhase handshakePhase,
@Nullable final Integer proxyReplyCode) {
super(message, address);
this.handshakePhase = handshakePhase;
this.proxyReplyCode = proxyReplyCode;
Comment thread
nhachicha marked this conversation as resolved.
}

/**
* Construct an instance with an optional RFC 1928 reply code.
* Use {@code null} for phases that do not carry a reply code
* ({@link HandshakePhase#PROXY_TCP_CONNECT}, {@link HandshakePhase#NEGOTIATION},
* {@link HandshakePhase#AUTHENTICATION}).
*
* @param message the message
* @param address the server address
* @param cause the cause
* @param handshakePhase the phase at which the failure occurred
* @param proxyReplyCode the RFC 1928 reply code, or {@code null}
*/
public MongoSocksProxyException(final String message, final ServerAddress address,
final Throwable cause, final HandshakePhase handshakePhase,
@Nullable final Integer proxyReplyCode) {
super(message, address, cause);
this.handshakePhase = handshakePhase;
this.proxyReplyCode = proxyReplyCode;
Comment thread
nhachicha marked this conversation as resolved.
}
Comment thread
nhachicha marked this conversation as resolved.

/**
* Returns the phase of the SOCKS5 handshake at which the failure occurred.
*
* @return the handshake phase, never {@code null}
*/
public HandshakePhase getHandshakePhase() {
return handshakePhase;
}

/**
* Returns the RFC 1928 reply code sent by the SOCKS5 proxy in response to a CONNECT request,
* or {@code null} if the failure occurred before the proxy sent a CONNECT response
* (i.e. phase is not {@link HandshakePhase#CONNECT_RELAY}).
Comment thread
nhachicha marked this conversation as resolved.
Outdated
*
* @return the RFC 1928 proxy reply code, or {@code null}
*/
@Nullable
public Integer getProxyReplyCode() {
return proxyReplyCode;
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -16,9 +16,11 @@

package com.mongodb.internal.connection;

import com.mongodb.MongoInterruptedException;
import com.mongodb.MongoSocketException;
import com.mongodb.MongoSocketOpenException;
import com.mongodb.MongoSocketReadException;
import com.mongodb.MongoSocksProxyException;
import com.mongodb.ServerAddress;
import com.mongodb.connection.AsyncCompletionHandler;
import com.mongodb.connection.ProxySettings;
Expand All @@ -38,6 +40,7 @@
import java.net.SocketTimeoutException;
import java.util.Iterator;
import java.util.List;
import java.util.Optional;

import static com.mongodb.assertions.Assertions.assertTrue;
import static com.mongodb.assertions.Assertions.notNull;
Expand Down Expand Up @@ -79,10 +82,21 @@ public void open(final OperationContext operationContext) {
socket = initializeSocket(operationContext);
outputStream = socket.getOutputStream();
inputStream = socket.getInputStream();
} catch (MongoSocksProxyException e) {
close();
throw e;
} catch (IOException e) {
close();
throw translateInterruptedException(e, "Interrupted while connecting")
.orElseThrow(() -> new MongoSocketOpenException("Exception opening socket", getAddress(), e));
Optional<MongoInterruptedException> interrupted = translateInterruptedException(e, "Interrupted while connecting");
if (interrupted.isPresent()) {
throw interrupted.get();
}
if (settings.getProxySettings().isProxyEnabled()) {
throw new MongoSocksProxyException(
"Exception connecting to SOCKS5 proxy", getAddress(), e,
MongoSocksProxyException.HandshakePhase.PROXY_TCP_CONNECT);
}
Comment thread
nhachicha marked this conversation as resolved.
Comment thread
nhachicha marked this conversation as resolved.
Outdated
Comment thread
nhachicha marked this conversation as resolved.
Outdated
throw new MongoSocketOpenException("Exception opening socket", getAddress(), e);
}
}

Comment thread
nhachicha marked this conversation as resolved.
Outdated
Expand Down Expand Up @@ -119,15 +133,28 @@ private SSLSocket initializeSslSocketOverSocksProxy(final OperationContext opera
final int serverPort = address.getPort();

SocksSocket socksProxy = new SocksSocket(settings.getProxySettings());
configureSocket(socksProxy, operationContext, settings);
InetSocketAddress inetSocketAddress = toSocketAddress(serverHost, serverPort);
socksProxy.connect(inetSocketAddress, operationContext.getTimeoutContext().getConnectTimeoutMs());

SSLSocket sslSocket = (SSLSocket) sslSocketFactory.createSocket(socksProxy, serverHost, serverPort, true);
//Even though Socks proxy connection is already established, TLS handshake has not been performed yet.
//So it is possible to set SSL parameters before handshake is done.
configureSslSocket(sslSocket, sslSettings, inetSocketAddress);
return sslSocket;
// Track the outermost socket layer to close on failure. Initially this is socksProxy;
// once we wrap it into an SSLSocket, that becomes the outermost layer and closing it
// tears down the underlying socksProxy as well.
Socket toClose = socksProxy;
try {
configureSocket(socksProxy, operationContext, settings);
InetSocketAddress inetSocketAddress = toSocketAddress(serverHost, serverPort);
socksProxy.connect(inetSocketAddress, operationContext.getTimeoutContext().getConnectTimeoutMs());
SSLSocket sslSocket = (SSLSocket) sslSocketFactory.createSocket(socksProxy, serverHost, serverPort, true);
toClose = sslSocket;
//Even though Socks proxy connection is already established, TLS handshake has not been performed yet.
//So it is possible to set SSL parameters before handshake is done.
configureSslSocket(sslSocket, sslSettings, inetSocketAddress);
return sslSocket;
} catch (IOException | RuntimeException e) {
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

try {
toClose.close();
} catch (IOException closeException) {
e.addSuppressed(closeException);
}
throw e;
}
}


Expand All @@ -141,17 +168,30 @@ private static InetSocketAddress toSocketAddress(final String serverHost, final

private Socket initializeSocketOverSocksProxy(final OperationContext operationContext) throws IOException {
Socket createdSocket = socketFactory.createSocket();
configureSocket(createdSocket, operationContext, settings);
/*
Wrap the configured socket with SocksSocket to add extra functionality.
Reason for separate steps: We can't directly extend Java 11 methods within 'SocksSocket'
to configure itself.
*/
SocksSocket socksProxy = new SocksSocket(createdSocket, settings.getProxySettings());

socksProxy.connect(toSocketAddress(address.getHost(), address.getPort()),
operationContext.getTimeoutContext().getConnectTimeoutMs());
return socksProxy;
try {
configureSocket(createdSocket, operationContext, settings);
/*
Wrap the configured socket with SocksSocket to add extra functionality.
Reason for separate steps: We can't directly extend Java 11 methods within 'SocksSocket'
to configure itself.
*/
SocksSocket socksProxy = new SocksSocket(createdSocket, settings.getProxySettings());
socksProxy.connect(toSocketAddress(address.getHost(), address.getPort()),
operationContext.getTimeoutContext().getConnectTimeoutMs());
return socksProxy;
} catch (IOException | RuntimeException e) {
// SocksSocket.connect() now closes itself on failure, but createdSocket may not yet
// be owned by a SocksSocket (e.g. configureSocket threw). Close defensively; on success
// path SocksSocket holds the reference and this catch is not entered.
// Note: when SocksSocket.connect() has already closed the inner socket, this is a
// no-op (java.net.Socket.close() is idempotent per the JDK contract).
try {
createdSocket.close();
} catch (IOException closeException) {
e.addSuppressed(closeException);
}
throw e;
Comment on lines +194 to +201
Copy link
Copy Markdown
Member

@vbabanin vbabanin May 21, 2026

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think configureSocket only sets socket options; it does not open a connection. If it throws, there should not be a connected socket to close.

Could we remove this try/catch?

}
}

@Override
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,9 @@
*/
package com.mongodb.internal.connection;

import com.mongodb.MongoSocksProxyException;
import com.mongodb.MongoSocksProxyException.HandshakePhase;
import com.mongodb.ServerAddress;
import com.mongodb.connection.ProxySettings;
import com.mongodb.internal.time.Timeout;
import com.mongodb.lang.Nullable;
Expand Down Expand Up @@ -100,6 +103,16 @@ public void connect(final SocketAddress endpoint, final int connectTimeoutMs) th
SocksAuthenticationMethod authenticationMethod = performNegotiation(timeout);
authenticate(authenticationMethod, timeout);
sendConnect(timeout);
} catch (MongoSocksProxyException e) {
// The underlying proxy TCP socket is already connected at this point.
// MongoSocksProxyException is a RuntimeException and is not caught below,
// so close the socket here to avoid leaking the FD on every SOCKS5 protocol failure.
try {
close();
} catch (Exception closeException) {
e.addSuppressed(closeException);
}
throw e;
} catch (SocketException socketException) {
/*
* The 'close()' call here has two purposes:
Expand All @@ -125,6 +138,8 @@ private void socketConnect(final InetSocketAddress proxyAddress, final int rem)
}

private void sendConnect(final Timeout timeout) throws IOException {
// remoteAddress is unresolved (asserted in connect()), so getHostName() returns the stored
// hostname string without triggering DNS. The SOCKS5 CONNECT request requires this string.
final String host = remoteAddress.getHostName();
final int port = remoteAddress.getPort();
Comment thread
nhachicha marked this conversation as resolved.
final byte[] bytesOfHost = host.getBytes(StandardCharsets.US_ASCII);
Expand Down Expand Up @@ -223,7 +238,7 @@ private void checkServerReply(final Timeout timeout) throws IOException {
}
return;
}
throw new ConnectException(reply.getMessage());
throw new MongoSocksProxyException(reply.message, targetServerAddress(), HandshakePhase.CONNECT_RELAY, reply.replyNumber);
Comment thread
nhachicha marked this conversation as resolved.
Outdated
Comment thread
nhachicha marked this conversation as resolved.
Outdated
Comment thread
nhachicha marked this conversation as resolved.
Outdated
}
Comment thread
nhachicha marked this conversation as resolved.
Comment thread
nhachicha marked this conversation as resolved.

private void authenticate(final SocksAuthenticationMethod authenticationMethod, final Timeout timeout) throws IOException {
Expand All @@ -249,7 +264,9 @@ private void authenticate(final SocksAuthenticationMethod authenticationMethod,
byte authStatus = authResult[1];

if (authStatus != AUTHENTICATION_SUCCEEDED_STATUS) {
throw new ConnectException("Authentication failed. Proxy server returned status: " + authStatus);
throw new MongoSocksProxyException(
"Authentication failed. Proxy server returned status: " + authStatus,
targetServerAddress(), HandshakePhase.AUTHENTICATION);
}
}
}
Expand All @@ -273,21 +290,32 @@ private SocksAuthenticationMethod performNegotiation(final Timeout timeout) thro
byte[] handshakeReply = readSocksReply(2, timeout);

if (handshakeReply[0] != SOCKS_VERSION) {
throw new ConnectException("Remote server doesn't support socks version 5"
+ " Received version: " + handshakeReply[0]);
throw new MongoSocksProxyException("Remote server doesn't support socks version 5"
+ " Received version: " + handshakeReply[0],
targetServerAddress(), HandshakePhase.NEGOTIATION);
}
byte authMethodNumber = handshakeReply[1];
if (authMethodNumber == (byte) 0xFF) {
throw new ConnectException("None of the authentication methods listed are acceptable. Attempted methods: "
+ Arrays.toString(authenticationMethods));
throw new MongoSocksProxyException(
"None of the authentication methods listed are acceptable. Attempted methods: "
+ Arrays.toString(authenticationMethods),
targetServerAddress(), HandshakePhase.NEGOTIATION);
}
if (authMethodNumber == SocksAuthenticationMethod.NO_AUTH.getMethodNumber()) {
return SocksAuthenticationMethod.NO_AUTH;
} else if (authMethodNumber == SocksAuthenticationMethod.USERNAME_PASSWORD.getMethodNumber()) {
return SocksAuthenticationMethod.USERNAME_PASSWORD;
}

throw new ConnectException("Proxy returned unsupported authentication method: " + authMethodNumber);
throw new MongoSocksProxyException("Proxy returned unsupported authentication method: " + authMethodNumber,
targetServerAddress(), HandshakePhase.NEGOTIATION);
}

private ServerAddress targetServerAddress() {
// remoteAddress is asserted unresolved in connect(), so getHostName() would also be safe today.
// Using getHostString() defensively guarantees no reverse DNS in this exception-reporting path
// even if that invariant is ever weakened.
return new ServerAddress(remoteAddress.getHostString(), remoteAddress.getPort());
}

private SocksAuthenticationMethod[] getSocksAuthenticationMethods() {
Expand Down
Loading