Skip to content

πŸ›‘οΈ Sentinel: [security improvement] Add timeout to subprocess.run to prevent unbounded hangs - #670

Merged
github-actions[bot] merged 1 commit into
mainfrom
sentinel/fix-git-timeout-check-adr-cross-ref-15812909212529746040
Sep 26, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
sentinel/fix-git-timeout-check-adr-cross-ref-15812909212529746040

Conversation

@wryenmeek

Copy link
Copy Markdown
Owner

🚨 Severity: MEDIUM
πŸ’‘ Vulnerability: External command execution via subprocess.run without a timeout leaves the script vulnerable to indefinite hanging, potentially causing DoS or unbounded pipeline waits.
🎯 Impact: An unresponsive git command could hang the pre-commit hook forever.
πŸ”§ Fix: Added a timeout=15 argument to subprocess.run and handled subprocess.TimeoutExpired securely.
βœ… Verification: Ran pytest tests/ locally to ensure no regressions. The change prevents unbounded hangs by gracefully exiting if the process exceeds the 15-second threshold.


PR created automatically by Jules for task 15812909212529746040 started by @wryenmeek

Adding a 15s timeout to the git subprocess in `check_adr_cross_ref.py`
to prevent potential indefinite hangs and resource exhaustion during hook execution.

Co-authored-by: wryenmeek <6856065+wryenmeek@users.noreply.github.com>
@google-labs-jules

Copy link
Copy Markdown
Contributor

πŸ‘‹ Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a πŸ‘€ emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
πŸ“ Code Review βœ… Completed 2026-09-26T22:31:39.719377Z e165a10 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with πŸ‘€ while any review is running, comments if it has suggestions, and reacts with πŸ‘ once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

πŸ’‘ Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e165a1054d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with πŸ‘.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +25 to +26
result = subprocess.run(
["git", *args], capture_output=True, text=True, timeout=15

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Declare the timeout in the write-surface matrix

This adds a timeout-triggered hard-failure path to an executable scripts/** surface, but the commit leaves the dedicated scripts/hooks/check_adr_cross_ref.py matrix row unchanged, so its declared failure contract still mentions only the ADR status-cascade violation. Update that row to document subprocess timeout handling as required for changes to executable surfaces.

AGENTS.md reference: AGENTS.md:L86-L86

Useful? React with πŸ‘Β / πŸ‘Ž.

@github-actions
github-actions Bot merged commit b36f804 into main Sep 26, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant