Skip to content

fix: return scan-error status for partial URL timeouts - #60

Merged
tayfuryldz merged 1 commit into
tayfuryldz:mainfrom
Ymax27:ymax27/fix-partial-timeout-exit
Oct 2, 2026
Merged

tayfuryldz merged 1 commit into
tayfuryldz:mainfrom
Ymax27:ymax27/fix-partial-timeout-exit

Conversation

@Ymax27

@Ymax27 Ymax27 commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Summary

  • _result_exit_code() now treats partial_timeout > 0 as an incomplete scan and returns exit code 2.
  • Scan-error status keeps precedence over verified findings. Clean runs stay 0, finding runs stay 1, and error / partial_error behavior is unchanged.
  • docs/CI.md states that a per-URL budget expiry is exit code 2.

Scope

Fixes #35.

The change stays at the result/exit-code boundary. A partial timeout is not turned into a finding, and evidence gates are unchanged.

Validation

Commands run on this branch:

PYTHONPATH=src python3 -m pytest -q tests/test_output_formats.py tests/test_header_active_scan.py::test_partial_url_timeout_is_scan_error_exit

Observed result: 4 passed.

The integration case uses a localhost handler and a shortened UrlBudget so the public CLI path reports partial_timeout without waiting for the fixed 9 second budget. The slow handler can log a BrokenPipeError when the client times out; the test still asserts status partial_timeout and exit code 2.

ruff and mypy are not installed in this environment, so those gates were not run.

Checklist

  • CLI changes are safe by default and documented.
  • New detection behavior includes tests.
  • False-positive filtering remains conservative by default.
  • Observations/probes are preserved even when findings are filtered.
  • Evidence schema and proof-gate mutation tests pass.
  • No destructive payloads or denial-of-service behavior were added.
  • I reviewed the final diff and can explain the changes I am submitting.
  • Validation results in this PR are from commands actually run on this branch; no results or evidence were fabricated.
  • Any assumptions I could not verify are stated explicitly instead of being presented as facts.

Made with Cursor

@Ymax27
Ymax27 requested a review from tayfuryldz as a code owner October 2, 2026 10:51

@tayfuryldz tayfuryldz left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I checked this against current main and ran the full maintainer gates locally: pytest, Ruff, and mypy are clean. The diff stays within the issue scope and I did not find a blocking regression.

@tayfuryldz
tayfuryldz enabled auto-merge (squash) October 2, 2026 16:56
@tayfuryldz
tayfuryldz force-pushed the ymax27/fix-partial-timeout-exit branch 5 times, most recently from 5695a7a to c30f171 Compare October 2, 2026 17:10
A per-URL budget expiry is an incomplete scan, so it now exits 2 and keeps precedence over verified findings.

Co-authored-by: Cursor <cursoragent@cursor.com>
@tayfuryldz
tayfuryldz force-pushed the ymax27/fix-partial-timeout-exit branch from c30f171 to 6499c37 Compare October 2, 2026 17:11
@tayfuryldz
tayfuryldz merged commit 5eb8635 into tayfuryldz:main Oct 2, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Return scan-error exit status for partial URL timeouts

2 participants