Plain TCP and TLS clients independently implement address resolution, socket creation, timeout setup, address copying, retry iteration, and connection failure handling in src/shared/transport_tcp.c:176-226 and src/shared/transport_tls.c:150-199. Any future IPv6, cancellation, socket-option, timeout, or error-reporting change must be applied twice. This makes transport behavior drift likely and complicates testing.
Scope
Extract a shared TCP connect helper that returns a connected descriptor and selected address metadata; let TLS perform only context creation and handshake after the helper succeeds. Preserve the existing plain/TLS APIs and timeout semantics, and ensure failed descriptors are closed on every address attempt.
Acceptance criteria
Plain and TLS connection paths share address iteration, socket creation, timeout, and cleanup code.
The helper supports all getaddrinfo() results currently accepted (including IPv6) and reports the final failure consistently.
Unit tests cover first-address failure/fallback, timeout setup, and descriptor cleanup for both transports.
Existing TCP, TLS, SSH, and integration tests pass without changing user-visible connection behavior.
Severity
medium
Category
quality
Automated maintainability audit; no source changes were made.
## Summary
Plain TCP and TLS clients independently implement address resolution, socket creation, timeout setup, address copying, retry iteration, and connection failure handling in `src/shared/transport_tcp.c:176-226` and `src/shared/transport_tls.c:150-199`. Any future IPv6, cancellation, socket-option, timeout, or error-reporting change must be applied twice. This makes transport behavior drift likely and complicates testing.
## Scope
Extract a shared TCP connect helper that returns a connected descriptor and selected address metadata; let TLS perform only context creation and handshake after the helper succeeds. Preserve the existing plain/TLS APIs and timeout semantics, and ensure failed descriptors are closed on every address attempt.
## Acceptance criteria
- Plain and TLS connection paths share address iteration, socket creation, timeout, and cleanup code.
- The helper supports all `getaddrinfo()` results currently accepted (including IPv6) and reports the final failure consistently.
- Unit tests cover first-address failure/fallback, timeout setup, and descriptor cleanup for both transports.
- Existing TCP, TLS, SSH, and integration tests pass without changing user-visible connection behavior.
## Severity
medium
## Category
quality
---
_Automated maintainability audit; no source changes were made._
Fixed. Plain and TLS clients now share tcp_connect_socket_ex() (src/shared/transport_tcp.c) for address iteration/socket/timeout/cleanup; the server paths share accept_loop(). PR #308 added the missing acceptance tests: first-address fallback, fd-cleanup on failed attempts, and contimeout/IO-timeout setup (hardened against TOCTOU and gated under valgrind). Closing as completed.
Fixed. Plain and TLS clients now share `tcp_connect_socket_ex()` (`src/shared/transport_tcp.c`) for address iteration/socket/timeout/cleanup; the server paths share `accept_loop()`. PR #308 added the missing acceptance tests: first-address fallback, fd-cleanup on failed attempts, and contimeout/IO-timeout setup (hardened against TOCTOU and gated under valgrind). Closing as completed.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Plain TCP and TLS clients independently implement address resolution, socket creation, timeout setup, address copying, retry iteration, and connection failure handling in
src/shared/transport_tcp.c:176-226andsrc/shared/transport_tls.c:150-199. Any future IPv6, cancellation, socket-option, timeout, or error-reporting change must be applied twice. This makes transport behavior drift likely and complicates testing.Scope
Extract a shared TCP connect helper that returns a connected descriptor and selected address metadata; let TLS perform only context creation and handshake after the helper succeeds. Preserve the existing plain/TLS APIs and timeout semantics, and ensure failed descriptors are closed on every address attempt.
Acceptance criteria
getaddrinfo()results currently accepted (including IPv6) and reports the final failure consistently.Severity
medium
Category
quality
Automated maintainability audit; no source changes were made.
Fixed. Plain and TLS clients now share
tcp_connect_socket_ex()(src/shared/transport_tcp.c) for address iteration/socket/timeout/cleanup; the server paths shareaccept_loop(). PR #308 added the missing acceptance tests: first-address fallback, fd-cleanup on failed attempts, and contimeout/IO-timeout setup (hardened against TOCTOU and gated under valgrind). Closing as completed.