open-webui/backend/open_webui/retrieval/web
Classic298 7ef0530b24
fix: handle urllib3-future 4-element socket options in SSRF-safe web loader (#26796)
_ssrf_safe_new_conn unpacks each entry of self.socket_options straight into socket.setsockopt(), which accepts exactly 3 positional arguments. urllib3-future, a drop-in fork that shadows the urllib3 package whenever it is installed (for example as a dependency of niquests pulled in through a tool or function's requirements), declares its default socket options with a per-protocol 4th element: [(socket.IPPROTO_TCP, socket.TCP_NODELAY, 1, "tcp")]. Its own _set_socket_options() strips that element before calling setsockopt(), but our override does not, so with urllib3-future present every synchronous web fetch (fetch_url, web search loading) fails on connect with "TypeError: setsockopt() takes exactly 3 arguments (4 given)" and returns empty content.

Mirror urllib3-future's handling in the override: for 4-element options whose last element is a protocol string, apply "tcp" options truncated to the first 3 elements and skip "udp" options (all sockets created here are SOCK_STREAM). Plain 3-element options, and any other shapes stock urllib3 would accept, are passed through unchanged, so behavior with stock urllib3 (which only ever uses 3-element tuples) is identical.

Verified locally: with urllib3-future installed the loader previously raised the TypeError on every URL and now fetches successfully; with stock urllib3 2.3.0 and 2.7.0 fetches behave the same before and after.

Note: #26015 reported this same crash but attributed it to stock urllib3 2.x, which only uses 3-element tuples; the 4-element form comes from urllib3-future shadowing urllib3.

Fixes #26791
2026-07-23 23:33:55 -04:00
..
azure.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
bing.py chore: format 2026-06-01 13:56:55 -07:00
bocha.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
brave.py refac 2026-05-21 16:44:36 +04:00
brave_llm_context.py feat: brave search llm context 2026-05-09 06:34:25 +09:00
duckduckgo.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
exa.py refac 2026-03-17 17:58:01 -05:00
external.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
firecrawl.py fix: handle list-shape data in Firecrawl /search response (#24712) 2026-06-01 12:07:31 -07:00
google_pse.py refac 2026-05-21 16:44:36 +04:00
jina_search.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
kagi.py Update Kagi API endpoint and request method (#25015) 2026-06-01 12:48:44 -07:00
linkup.py chore: format 2026-06-01 13:56:55 -07:00
main.py refac 2026-07-01 02:20:16 -05:00
microsoft_web_iq.py refac 2026-06-29 01:52:07 -05:00
mojeek.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
ollama.py refac 2026-03-17 17:58:01 -05:00
perplexity.py refac 2026-06-17 02:52:35 +02:00
perplexity_search.py refac 2026-06-17 02:52:35 +02:00
searchapi.py refac 2026-03-17 17:58:01 -05:00
searxng.py refac 2026-05-21 16:44:36 +04:00
serpapi.py refac 2026-03-17 17:58:01 -05:00
serper.py refac 2026-05-21 16:44:36 +04:00
serphouse.py refac 2026-06-28 23:20:54 -05:00
serply.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
serpstack.py refac 2026-05-21 16:44:36 +04:00
sougou.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
tavily.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
utils.py fix: handle urllib3-future 4-element socket options in SSRF-safe web loader (#26796) 2026-07-23 23:33:55 -04:00
yacy.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
yandex.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00
ydc.py refac: modernize type annotations (PEP 604 / PEP 585) 2026-05-12 17:10:15 +09:00