Skip to content

fix(mitm): prevent NaN keep-alive timeout on Node 24.6 - #489

Merged
MagicalTux merged 2 commits into
KarpelesLab:masterfrom
AshFrancis:fix/mitm-keepalive-timeout-buffer
Oct 3, 2026
Merged

MagicalTux merged 2 commits into
KarpelesLab:masterfrom
AshFrancis:fix/mitm-keepalive-timeout-buffer

Conversation

@AshFrancis

Copy link
Copy Markdown
Contributor

HTTP/1.1 requests through the MITM tunnel can crash TeamClaude on Node 24.6.0 with RangeError [ERR_OUT_OF_RANGE]: The value of "msecs" is out of range ... Received NaN in resOnFinish.

The terminating HTTP/2 server has a keepAliveTimeout of 120,000 ms, but this runtime leaves its keepAliveTimeoutBuffer undefined. Node's HTTP/1 response completion path adds those values and passes NaN to TLSSocket.setTimeout().

Initialize the missing buffer to Node's normal 1,000 ms default, preserving any value supplied by the runtime. Extend the existing MITM keep-alive integration test to make three requests through the same CONNECT/TLS connection and verify the response bodies, connection reuse, and advertised timeout.

Validation on Node 24.6.0:

  • Before the fix, the updated regression test fails with the reported uncaught ERR_OUT_OF_RANGE exception.
  • npm test: 2,582 tests passed, 0 failed, including HTTP/1.1 and HTTP/2 tunnel integration tests.
  • npm run lint and npm run typecheck: passed.
  • npm run typecheck:strict -- --base origin/master: passed; 1,703 diagnostics on both the base and branch.
  • git diff --check: passed.

Prior art: searched upstream PRs in all states for keepAliveTimeoutBuffer; no matches. Reused the existing keep-alive integration test.

@AshFrancis

AshFrancis commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor Author

Follow-up: this workaround is not necessary for users running the latest Node 24 LTS. Node fixed the undefined keepAliveTimeoutBuffer crash in 24.8.0 (release notes, nodejs/node#59784), so upgrading from the affected 24.6.0 runtime to current Node 24 LTS should resolve this specific crash without a TeamClaude change.

The remaining value of this PR is compatibility with older runtimes still permitted by TeamClaude's node >=20.0.0 engine requirement. The regression was reproduced on Node 24.6.0, and the patch was verified there; I have not rerun the reproduction on the latest LTS locally.

Happy for this PR to be closed as not required if recommending an up-to-date LTS runtime is the preferred resolution. Otherwise, the small fallback can remain as protection for users on affected older versions.

Edit: Either way this should hopefully help anyone who runs into this outlier issue!

@MagicalTux
MagicalTux merged commit b9a0c55 into KarpelesLab:master Oct 3, 2026
5 checks passed
@MagicalTux MagicalTux mentioned this pull request Oct 4, 2026
MagicalTux added a commit that referenced this pull request Oct 4, 2026
Fifteen commits since 1.1.22. Two change what an existing install does
without an opt-in (#514, #503); the rest is additive or display.

Behaviour changes
  #514 the TUI quota-bar percentage (`quotaBarPercent`) is off unless set:
       a bar carries its countdown, and its fill is the percentage. The
       switch (g → Bar percentage) is unchanged; a config without the key
       now reads as off
  #503 with Codex accounts in the pool, a request on the intercepted
       chatgpt.com that is not Codex inference (codex-cli 0.156's workspace
       discovery, plugin, MCP and settings calls) is passed through to
       chatgpt.com with the client's own login instead of reaching the
       Anthropic pool and a 404; the Codex Responses WebSocket is refused
       (501) so the CLI falls back to HTTPS, where the pool serves it (#492)
  #502 `login --api` adds a key at priority 100, a last resort behind the
       subscriptions, with `--priority <n>` to place it; existing entries
       are untouched (#497)

Fixes
  #498 artifacts (`/api/frame/*`) are relayed with the client's own
       credential, so publishing and reading them works behind a rotated pool
  #499 the Remote Control bridge (`/v1/environments/*`, `/v1/sessions/*`,
       `/v2/session_ingress/*`, `/v2/ccr-sessions/*`), which Claude Code
       2.1.287 sends through HTTPS_PROXY, is relayed with the client's own
       credential; registration no longer lands in a rotated account's org
  #488 keep-warm works on Windows: the warm-up client is spawned through a
       shell, so npm's `claude.cmd` shim is found
  #489 Node 24.6's undefined HTTP/2 keep-alive buffer no longer crashes the
       MITM tunnel with a NaN timeout
  #490 on a very wide terminal the two provider panes sit together and their
       bars grow to the list's cap instead of padding half the screen

Features
  #496 `accountSort` orders the TUI account list by the soonest reset of a
       window (session, weekly, S7, F7) inside each provider group; cycled
       from the settings screen, display only
  #494 a z.ai GLM Coding Plan backend account shows its 5-hour and weekly
       windows in `teamclaude status`
  #495 a NanoGPT backend account shows its daily and weekly windows and
       NanoGPT's own billing advice (`billing balance`, `balance not allowed`)
  #500 each dashboard account card lists the models the account served in
       the last 15 minutes

Docs
  #505 what a cross-organization switch costs a Sonnet 5.5 conversation:
       the API drops the earlier thinking blocks silently; same-org pools are
       unaffected (#491)

Tests
  #501 #504 two tests that raced the wall clock or a shared port now assert
       the mechanism, and the last private server-spawn harness is gone

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants