[PR #13108] fix: SSRF proxy file descriptor leak in concurrent requests #27837

Closed
opened 2026-02-21 20:42:18 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/13108

State: closed
Merged: Yes


Summary

This PR addresses the [Errno 9] File descriptor was closed in another greenlet error that occurs when using the SSRF proxy in concurrent workflows (e.g., greenlets, threads).

Changes:

  1. Dynamic Transport Initialization

    • Fresh httpx.HTTPTransport instances are now created for each request when SSRF_PROXY_HTTP_URL and SSRF_PROXY_HTTPS_URL are configured.
    • Removes the global proxy_mounts variable to prevent shared transports across requests.
  2. Concurrency Safety

    • Fixes race conditions caused by reusing the same transports in asynchronous/greenlet contexts.

Close https://github.com/langgenius/dify/issues/10572

Checklist

Important

Please review the checklist below before submitting your pull request.

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/13108 **State:** closed **Merged:** Yes --- # Summary This PR addresses the `[Errno 9] File descriptor was closed in another greenlet` error that occurs when using the SSRF proxy in concurrent workflows (e.g., greenlets, threads). **Changes**: 1. **Dynamic Transport Initialization** - Fresh `httpx.HTTPTransport` instances are now created for each request when `SSRF_PROXY_HTTP_URL` and `SSRF_PROXY_HTTPS_URL` are configured. - Removes the global `proxy_mounts` variable to prevent shared transports across requests. 2. **Concurrency Safety** - Fixes race conditions caused by reusing the same transports in asynchronous/greenlet contexts. Close https://github.com/langgenius/dify/issues/10572 # Checklist > [!IMPORTANT] > Please review the checklist below before submitting your pull request. - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:42:18 -05:00
yindo closed this issue 2026-02-21 20:42:18 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#27837