fix(healthcheck): guard negative or zero timeout in check_tcp and check_http - #5951
Open
vaibhavsrv wants to merge 1 commit into
Open
vaibhavsrv wants to merge 1 commit into
vaibhavsrv wants to merge 1 commit into
Conversation
This was referenced Sep 19, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why this matters
In
ods/scripts/healthcheck.py, while the CLI entry point validates--timeout > 0, the underlying check functionscheck_tcpandcheck_httpare reusable programmatic helpers called directly by test suites, background monitors, and custom scripts. When callers pass a non-positive timeout (e.g.0or negative values from improper arithmetic or unset configuration),socket.create_connectionorurllib.request.urlopenraises unhandledValueError(timeout must be non-negative) or system-level connection errors instead of returning a controlled boolean status failure.This change introduces explicit non-positive guards at the top of
check_tcpandcheck_httpreturning(False, "timeout must be positive"). Existing positive timeout behaviors, retry policies, and CLI contracts remain completely unaffected.Validation
check_tcp("127.0.0.1", 80, timeout=0)orcheck_http(...)with non-positive timeout raised unhandledValueError: timeout must be non-negative.(False, "timeout must be positive"), and CLI invocation with non-positive values cleanly exits with code 2.test_healthcheck_timeout_bounds.pypasses cleanly (exit code 0). Wired into Linux CI workflow.Overlap check
healthcheck.py. This change touches only timeout bounds validation withincheck_tcpandcheck_httpwithout touching address parsing.parse_target. This PR operates strictly on timeout validation.Risk / AI disclosure
AI-assisted investigation, implementation, and test regressions. This strengthens bounds checking on helper function timeout parameters. Independent human review and platform/runtime qualification remain gates. No running configuration, deployment or upstream merge changed.
Follow-up integration evidence
Composed with #5875 and #5950 at HEAD without conflicts. Production and test diffs passed together; healthcheck IPv6 and redirect policy suites remain intact.
Backlog composition was local-only (production/test diffs, excluding workflow/Makefile wiring); it is not an upstream merge or independent human approval. Declared live-review gates remain open.