From e165a1054d0916144086a739fd2ce68f0037e276 Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Sat, 26 Sep 2026 22:29:54 +0000 Subject: [PATCH] Add timeout to subprocess.run to prevent unbounded hangs Adding a 15s timeout to the git subprocess in `check_adr_cross_ref.py` to prevent potential indefinite hangs and resource exhaustion during hook execution. Co-authored-by: wryenmeek <6856065+wryenmeek@users.noreply.github.com> --- scripts/hooks/check_adr_cross_ref.py | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/scripts/hooks/check_adr_cross_ref.py b/scripts/hooks/check_adr_cross_ref.py index 38bcabb2..c97d6c09 100644 --- a/scripts/hooks/check_adr_cross_ref.py +++ b/scripts/hooks/check_adr_cross_ref.py @@ -21,8 +21,14 @@ def _run_git(*args: str) -> tuple[int, str]: - result = subprocess.run(["git", *args], capture_output=True, text=True) - return result.returncode, result.stdout + try: + result = subprocess.run( + ["git", *args], capture_output=True, text=True, timeout=15 + ) + return result.returncode, result.stdout + except subprocess.TimeoutExpired: + print("ERROR: git command timed out", file=sys.stderr) + sys.exit(1) def _get_staged_content(path: str) -> str | None: