Commit 0728a77dae

0728a77dae961c651d8dac1463add1b6d33eced6

parent: 367c79588a

Verified · cmc ci/build: success ci/test: success ci/vuln: success

cmc <hello@cleberg.net> · 2026-09-29 02:54 UTC

control: import-issues API client keeps no idle connections

Ref #301

Layout: unified · split

internal/control/ghimport.go +3 −2
@@ -136,11 +136,12 @@ func (g *ghClient) get(path string, out any) error {
136 136
137// pinnedClient reaches api's host only at its checked addresses, never 137// pinnedClient reaches api's host only at its checked addresses, never
138// through a proxy from the environment, and follows no redirect, as 138// through a proxy from the environment, and follows no redirect, as
139// webhook delivery and repo import do. 139// webhook delivery and repo import do. Each import builds its own
140// client, so connections are not kept for reuse.
140func pinnedClient(api gitpin.Remote) *http.Client { 141func pinnedClient(api gitpin.Remote) *http.Client {
141 return &http.Client{ 142 return &http.Client{
142 Timeout: 30 * time.Second, 143 Timeout: 30 * time.Second,
143 Transport: &http.Transport{Proxy: nil, DialContext: api.DialContext, TLSHandshakeTimeout: 10 * time.Second}, 144 Transport: &http.Transport{Proxy: nil, DialContext: api.DialContext, TLSHandshakeTimeout: 10 * time.Second, DisableKeepAlives: true},
144 CheckRedirect: func(req *http.Request, _ []*http.Request) error { 145 CheckRedirect: func(req *http.Request, _ []*http.Request) error {
145 return fmt.Errorf("refusing redirect to %s://%s; a renamed repository is imported under its new name", req.URL.Scheme, req.URL.Host) 146 return fmt.Errorf("refusing redirect to %s://%s; a renamed repository is imported under its new name", req.URL.Scheme, req.URL.Host)
146 }, 147 },