refactor: Replace portscanner in server with a native port scan - #1630
Conversation
Replace the unmaintained portscanner dependency (last published 2018, pulls in async + is-number-like) with a small connect-probe helper built on node:net, removing the dependency entirely. isPortInUse() mirrors portscanner's semantics exactly: a successful TCP connection means the port is in use, a refused connection or timeout means it is free, and any other socket error rejects as a scan failure. findAPortNotInUse() scans the inclusive range for the first free port. Because the probe semantics are unchanged, the existing behavior is fully preserved (including detection of occupiers bound to the dualstack :: address) and no test occupiers needed adapting. Only the former portscanner-stub test was rewritten to inject a generic socket error via esmock.
Options consideredget-port — third-party library (sindresorhus, zero deps, ESM). Uses a bind-probe: tries to bind a throwaway server on each candidate port. direct-listen — no library. Binds the real server directly, retries on native — no library. Uses a connect-probe: opens a TCP socket to each candidate port. Mirrors portscanner's exact behavior. Why nativeBoth get-port and direct-listen use bind semantics. On macOS/BSD, A connect-probe has no such blind spot: Native is a drop-in replacement for portscanner with identical semantics — no behavior change, no new dependency, CVE-flagged |
Replace the outer new Promise wrapper in listen() with linear async/await. The only remaining explicit Promise is isolated in a listenOnce() helper that bridges server.listen's separate 'listening' and 'error' event channels, detaching the losing listener once one fires (the old code leaked the error listener on every successful bind).
Release event all handlers once an event has been executed.
040fd7f to
6c604b1
Compare
JIRA: CPOUI5FOUNDATION-1359
Replace the unmaintained
portscannerdependency with a small connect-probe helper built on node:net, removing the dependency entirely.isPortInUse() mirrors portscanner's semantics exactly: a successful TCP connection means the port is in use, a refused connection or timeout means it is free, and any other socket error rejects as a scan failure. findAPortNotInUse() scans the inclusive range for the first free port.
Because the probe semantics are unchanged, the existing behavior is fully preserved (including detection of occupiers bound to the dualstack :: address) and no test occupiers needed adapting. Only the former portscanner-stub test was rewritten to inject a generic socket error via esmock.