Skip to content

fix(manifest): fail closed on scan timeout - #1615

Merged
mldangelo-oai merged 4 commits into
mainfrom
mdangelo/codex/fix-manifest-timeout-outcome
Jun 10, 2026
Merged

mldangelo-oai merged 4 commits into
mainfrom
mdangelo/codex/fix-manifest-timeout-outcome

Conversation

@mldangelo-oai

Copy link
Copy Markdown
Contributor

Summary

  • mark manifest timeouts as operational errors with incomplete coverage
  • return success=False instead of reporting a successful scan
  • retain findings emitted before the timeout

Reproduction

ManifestScanner.scan() caught TimeoutError, emitted a failed Manifest Scan Timeout check, then explicitly called finish(success=True). Existing timeout tests asserted the contradictory successful outcome.

Validation

  • pytest -q tests/scanners/test_manifest_scanner.py -k timeout (6 passed)
  • Ruff format and lint pass on changed Python files
  • mypy passes on changed Python files

@github-actions

github-actions Bot commented Jun 10, 2026 •

Copy link
Copy Markdown
Contributor

Workflow run and artifacts

Performance Benchmarks

Compared 12 shared benchmarks with a regression threshold of 15%.
Status: 0 regressions, 0 improved, 12 stable, 0 new, 0 missing.
Aggregate shared-benchmark median: 1.383s -> 1.391s (+0.6%).

Workload Benchmark Target Size Files Baseline Current Change Status
padded-multi-stream-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_padded_multi_stream_upload multi_stream_padded 4.1 KiB 1 640.2us 597.9us -6.6% stable
warm-cache-rescan tests/benchmarks/test_scan_benchmarks.py::test_scan_warm_cached_repository_rescan release-candidate 547.3 KiB 32 100.19ms 106.32ms +6.1% stable
chunked-upload-stream tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_chunked_upload_stream chunked_stream 278.2 KiB 1 111.91ms 110.72ms -1.1% stable
mixed-model-repository tests/benchmarks/test_scan_benchmarks.py::test_scan_release_candidate_repository release-candidate 547.3 KiB 32 471.22ms 475.84ms +1.0% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_raw] nested_raw 78 B 1 539.2us 544.0us +0.9% stable
clean-training-checkpoint tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_clean_training_checkpoint safe_large 278.2 KiB 1 108.19ms 107.38ms -0.7% stable
direct-malicious-upload tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_direct_malicious_upload malicious_reduce 52 B 1 505.2us 507.9us +0.5% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_hex] nested_hex 130 B 1 567.6us 564.8us -0.5% stable
suspicious-pickle-intake tests/benchmarks/test_scan_benchmarks.py::test_scan_suspicious_pickle_intake suspicious-intake 183.8 KiB 4 141.34ms 140.90ms -0.3% stable
nested-payload-review tests/benchmarks/test_picklescan_benchmarks.py::test_picklescan_nested_payload_review[nested_base64] nested_base64 98 B 1 540.9us 539.8us -0.2% stable
single-checkpoint-preflight tests/benchmarks/test_scan_benchmarks.py::test_scan_single_checkpoint_before_load single_checkpoint.pkl 183.0 KiB 1 68.59ms 68.67ms +0.1% stable
duplicate-heavy-registry tests/benchmarks/test_scan_benchmarks.py::test_scan_duplicate_registry_snapshot registry-snapshot 915.2 KiB 13 379.18ms 378.88ms -0.1% stable

@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Please review exact head SHA 6a23bcf.

@mldangelo-oai

Copy link
Copy Markdown
Contributor Author

@codex review

Please review exact head SHA 5a66e63.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Hooray!

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mldangelo-oai
mldangelo-oai enabled auto-merge (squash) June 10, 2026 14:45
@mldangelo-oai
mldangelo-oai merged commit c769097 into main Jun 10, 2026
29 checks passed
@mldangelo-oai
mldangelo-oai deleted the mdangelo/codex/fix-manifest-timeout-outcome branch June 10, 2026 14:59
@github-actions github-actions Bot mentioned this pull request Jun 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant