{"record":{"id":"34ea7afe93746ac7","repo":"apache/seatunnel","slug":"collector-from-closed-connection-before-authent","errorCode":null,"errorMessage":"Collector from {} closed connection before authentication","messagePattern":"Collector from (.+?) closed connection before authentication","errorType":"console","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/protocol/IngressProtocolHandler.java","lineNumber":66,"sourceCode":"            log.warn(\n                    \"Unsupported auth type: {}, from {}\",\n                    config.getAuthType(),\n                    channel.remoteAddress());\n            return false;\n        }\n        String authLine;\n        try {\n            authLine = channel.readLine();\n        } catch (SocketTimeoutException timeoutException) {\n            channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());\n            log.warn(\n                    \"Collector authentication timeout from {}, connection rejected\",\n                    channel.remoteAddress());\n            return false;\n        }\n        if (authLine == null) {\n            channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());\n            log.warn(\n                    \"Collector from {} closed connection before authentication\",\n                    channel.remoteAddress());\n            return false;\n        }\n        String presentedToken = parseAuthToken(authLine);\n        if (!constantTimeEquals(config.getToken(), presentedToken)) {\n            channel.writeLine(EdgeSocketResponseCode.AUTH_FAILED.getCode());\n            log.warn(\"Collector authentication failed from {}\", channel.remoteAddress());\n            return false;\n        }\n        channel.writeLine(EdgeSocketResponseCode.ACK.getCode());\n        return true;\n    }\n\n    public void receiveLoop(IngressChannel channel, BooleanSupplier isActive) throws IOException {\n        while (isActive.getAsBoolean()) {\n            String record;\n            try {","sourceCodeStart":48,"sourceCodeEnd":84,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-connectors-v2/connector-edge-socket/src/main/java/org/apache/seatunnel/connectors/seatunnel/edgesocket/protocol/IngressProtocolHandler.java#L48-L84","documentation":"A WARN logged by IngressProtocolHandler.authenticate when the collector closes the TCP connection before sending any authentication line — readLine() returns null. The connection is rejected with the AUTH_FAILED response code (write will fail harmlessly on a closed socket).","triggerScenarios":"channel.readLine() returns null because the remote peer closed the socket during the authentication phase of the EdgeSocket ingress handshake.","commonSituations":"Port scanners or health probes connecting and immediately disconnecting; collector crash or restart mid-handshake; collector-side network drop; wrong client connecting to the EdgeSocket port.","solutions":["Verify only intended collector clients target the EdgeSocket ingress port.","Check collector-side logs/errors for why it disconnected before authenticating.","Filter out scanners/probes at the network layer if the port is exposed.","If collectors crash, fix the collector's connection/auth send logic first."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"String line = channel.readLine();\nif (line == null || line.isEmpty()) {\n    // peer closed or sent nothing; do not proceed to token comparison\n    return false;\n}","typeGuard":null,"tryCatchPattern":"if (authLine == null) {\n    // peer closed before auth; nothing to recover client-side\n    return false;\n}","preventionTips":["Restrict EdgeSocket port exposure with a firewall","Harden collectors against crashing mid-handshake","Monitor for scanners hitting the port and block at network layer"],"tags":["edge-socket","authentication","connection-closed","handshake"],"backgroundTag":"authentication-required","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}