{"record":{"id":"25707aea3cf4b50b","repo":"vectordotdev/vector","slug":"can-t-set-keepalive-on-connection-that-has-not-been-accepted","errorCode":null,"errorMessage":"Can't set keepalive on connection that has not been accepted yet.","messagePattern":"Can't set keepalive on connection that has not been accepted yet\\.","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"lib/vector-core/src/tls/incoming.rs","lineNumber":314,"sourceCode":"            ),\n            None => StreamState::Accepted(MaybeTlsStream::Raw(stream)),\n        };\n        Self { state, peer_addr }\n    }\n\n    // Explicit handshake method\n    pub async fn handshake(&mut self) -> crate::tls::Result<()> {\n        if let StreamState::Accepting(fut) = &mut self.state {\n            let stream = fut.await?;\n            self.state = StreamState::Accepted(MaybeTlsStream::Tls(stream));\n        }\n\n        Ok(())\n    }\n\n    pub fn set_keepalive(&mut self, keepalive: TcpKeepaliveConfig) -> io::Result<()> {\n        let stream = self.get_ref().ok_or_else(|| {\n            io::Error::new(\n                io::ErrorKind::NotConnected,\n                \"Can't set keepalive on connection that has not been accepted yet.\",\n            )\n        })?;\n\n        if let Some(time_secs) = keepalive.time_secs {\n            let config =\n                socket2::TcpKeepalive::new().with_time(std::time::Duration::from_secs(time_secs));\n\n            tcp::set_keepalive(stream, &config)?;\n        }\n\n        Ok(())\n    }\n\n    pub fn set_receive_buffer_bytes(&mut self, bytes: usize) -> std::io::Result<()> {\n        let stream = self.get_ref().ok_or_else(|| {\n            io::Error::new(","sourceCodeStart":296,"sourceCodeEnd":332,"githubUrl":"https://github.com/vectordotdev/vector/blob/bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013/lib/vector-core/src/tls/incoming.rs#L296-L332","documentation":"`IncomingTlsListener::set_keepalive` needs a reference to the accepted TCP stream. The wrapper holds `Option<T>` and returns `Err(NotConnected)` when called before a connection has been accepted and stored, since there is no socket on which to apply the keepalive options.","triggerScenarios":"Calling `set_keepalive` on the listener's connection wrapper before the accept future completes / before `handle_stream` has stored the accepted stream.","commonSituations":"Configuring TCP keepalive from a different task than the one that awaits the accept, or racing accept and socket tuning; usually surfaces as NotConnected on a TLS listener wrapper.","solutions":["Apply keepalive only after the connection has been accepted (call it inside handle_stream / after awaiting accept).","Check that the wrapper was created from an accepted stream, not a fresh listener.","Set keepalive via TcpKeepaliveConfig so it is applied post-accept automatically."],"exampleFix":"// before\nlet mut conn = listener.accept().await?; // not yet polled to completion\nconn.set_keepalive(cfg)?;\n\n// after\nlet mut conn = listener.accept().await?.into_stream();\nconn.set_keepalive(cfg).await?; // after connection exists","handlingStrategy":"try-catch","validationCode":"if conn.get_ref().is_none() {\n    return Err(std::io::Error::new(std::io::ErrorKind::NotConnected, \"connection not accepted yet\"));\n}","typeGuard":"// Rust: match on the Option inside the wrapper\nfn is_accepted(conn: &IncomingConnection) -> bool { conn.get_ref().is_some() }","tryCatchPattern":"match conn.set_keepalive(cfg) {\n    Err(e) if e.kind() == std::io::ErrorKind::NotConnected => {\n        // defer or skip; connection not yet accepted\n    }\n    other => other?,\n}","preventionTips":["Always await accept before tuning socket options.","Apply keepalive/buffer settings inside the same task that accepts the connection."],"tags":["network","tcp","tls","keepalive"],"backgroundTag":"invalid-state-transition","analyzedSha":"bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013","analyzedAt":"2026-09-16T02:53:35.741Z","contentChangedAt":"2026-09-16T02:53:35.741Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}