如何在Privoxy中对持续连接强制设置套接字超时?
Great question! The built-in socket-timeout option in Privoxy only kicks in when there's no data activity on the connection—it won't terminate a connection that's actively transferring data, even if it's been running for hours. To achieve your goal of disconnecting connections after a fixed duration regardless of traffic, you have two solid approaches:
Option 1: System-Level TCP Timeout (Simplest Solution)
If you don't need per-site granularity, using your OS's firewall to enforce a hard timeout on Privoxy's connections is the easiest way. This works at the network level, so it'll automatically kill any TCP connection through Privoxy that exceeds your specified duration, even if data is flowing.
For iptables (Linux):
Run this command (replace 8118 with your Privoxy port, and 300 with your desired timeout in seconds):
iptables -I OUTPUT -p tcp --sport 8118 --state ESTABLISHED -m tcp --timeout 300 -j ACCEPT
To make this persistent across reboots, save your iptables rules (e.g., iptables-save > /etc/iptables/rules.v4 on Debian/Ubuntu).
For nftables (Modern Linux):
Add this rule to your nftables config (or run it directly):
nft add rule ip filter output tcp sport 8118 tcp flags established timeout 300s accept
Option 2: Privoxy Custom Action with External Script (Granular Control)
If you need to apply this timeout only to specific sites or have more control over the error response, you can use Privoxy's pipe-action feature to route connections through a custom script that tracks connection durations.
Step 1: Create the Timeout Check Script
Make a script like /usr/local/bin/privoxy-timeout.sh (make it executable with chmod +x):
#!/bin/bash # Track connection start times in a temporary file TIMEOUT_FILE="/tmp/privoxy_connections.tmp" MAX_DURATION=300 # 5 minutes in seconds # Get source IP and port to identify the connection SOURCE=$(echo "$PRIVOXY_CLIENT_IP:$PRIVOXY_CLIENT_PORT") # Check if this connection exists in our tracking file START_TIME=$(grep -w "$SOURCE" "$TIMEOUT_FILE" | cut -d' ' -f2) if [ -z "$START_TIME" ]; then # First request for this connection: record the start time echo "$SOURCE $(date +%s)" >> "$TIMEOUT_FILE" # Forward the request normally cat else # Calculate elapsed time ELAPSED=$(( $(date +%s) - START_TIME )) if [ $ELAPSED -gt $MAX_DURATION ]; then # Connection exceeded timeout: return HTTP 408 error echo -e "HTTP/1.1 408 Request Timeout\r\nConnection: close\r\n\r\n" # Remove the connection from tracking sed -i "/$SOURCE/d" "$TIMEOUT_FILE" else # Forward the request normally cat fi fi
Step 2: Configure Privoxy to Use the Script
- Open your Privoxy config file (usually
/etc/privoxy/config). - Add a line to include a custom actions file:
actionsfile custom-timeout.action - Create the
custom-timeout.actionfile (in the same directory as your config) with:# Apply timeout to all connections { +pipe-action /usr/local/bin/privoxy-timeout.sh } / # Or apply only to specific sites: # { +pipe-action /usr/local/bin/privoxy-timeout.sh } # example.com # *.example.net - Restart Privoxy to apply changes:
systemctl restart privoxy
Notes
- The system-level approach is ideal for global timeout rules, while the script method gives you per-site control and custom error responses.
- Test with a short timeout (e.g., 10 seconds) first to verify it works as expected.
- For the script, you may want to add cleanup logic to remove stale entries from the tracking file (e.g., a cron job that deletes entries older than your max duration).
内容的提问来源于stack exchange,提问作者Harish Ved

