feat(gateway): one gateway.trust_env key controls aiohttp proxy-env honoring at every adapter site (#48820 bug 3)

Every gateway/plugin platform adapter hard-coded aiohttp.ClientSession(trust_env=True)
(~20 sites), so a gateway launched by a Windows Scheduled Task that inherits a stale
HTTP_PROXY (Clash/V2Ray on 127.0.0.1:7890) looped on 'Cannot connect to host' with no
way to opt out short of NO_PROXY hacks per vendor host.

- gateway/platforms/base.py: gateway_trust_env() reads gateway.trust_env (default true);
  resolve_proxy_url() skips generic HTTP(S)_PROXY/ALL_PROXY + macOS system-proxy
  auto-detect when false (explicit per-platform vars still win).
- All aiohttp ClientSession sites in weixin, qqbot, matrix, line, wecom, slack, sms,
  teams, google_chat now pass trust_env=gateway_trust_env(); mattermost + homeassistant
  bare sessions gain the same kwarg (intent of #70119 / #56229).
- DEFAULT_CONFIG + cli-config.yaml.example + messaging docs.
- tests/gateway/test_gateway_trust_env.py: config flip + no-bare-literal sweep.

Reported-by: @ranlingfeng (#48820), @frontnopipe-cloud (#76309)
Co-authored-by: rcarrata <rcarratalasanchez@gmail.com>
Co-authored-by: Backroads4Me <TEDLANHAM@GMAIL.COM>
This commit is contained in:
Teknium
2026-09-02 03:56:29 -07:00
parent bc71b8bc95
commit 45b0d8cab5
18 changed files with 153 additions and 26 deletions

View File

@@ -1205,6 +1205,13 @@ gateway:
# if an agent has not unwound. Keep it below the service-manager stop budget.
# signal_interrupt_grace_timeout: 1
# Let platform adapters honor HTTP_PROXY / HTTPS_PROXY / NO_PROXY (and
# SSL_CERT_FILE) from the process environment, plus macOS system-proxy
# auto-detection. Set to false when the gateway inherits a proxy it must not
# use (e.g. a Windows Scheduled Task picking up a local Clash/V2Ray proxy that
# isn't running). Explicit per-platform vars like DISCORD_PROXY still apply.
# trust_env: true
# =============================================================================
# Toolsets
# =============================================================================