Skip to content

ci(estate-audit): bound the job at 10 minutes (Hypatia missing_timeout_minutes) - #120

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/estate-audit-timeout
Oct 6, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/estate-audit-timeout

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Hypatia's workflow audit opened a code-scanning thread on #119 (alert 168, missing_timeout_minutes): the estate-audit job in main-estate-audit.yml declares no timeout-minutes, so it inherits GitHub's 6-hour default. A stuck fetch or a runner hang could burn that much budget. This PR bounds the job at 10 minutes. The job runs two quick gates, so 10 minutes is ample.

The fix was made on #119's branch after #119 had already merged at a87fa8a, so it never reached main. This PR carries it onto main (10819d6) by itself.

Type of change

  • 🐛 Bug fix: no runtime code changed.
  • ✨ New feature: N/A
  • 💥 Breaking change: N/A
  • 🕳️ Soundness fix: N/A
  • 📖 Documentation: N/A
  • 🧹 Refactor / tech debt: N/A
  • ⚡ Performance: N/A
  • 🔧 Build / CI / tooling: one timeout-minutes line.

📌 New pins

Head SHA: a42c00647083691f902d7897b6ca90e9617f2460

None. No uses: ref, actions.lock entry, lockfile or container digest is added or changed.

How has this been verified?

  • git diff origin/main --stat: one file, one line added (timeout-minutes: 10 under estate-audit).
  • actionlint .github/workflows/main-estate-audit.yml: rc=0.
  • Not yet verified: a CI run at this head, and the code-scanning alert closing. Hypatia re-scans on push, so alert 168 should close once this lands on main.

Checklist

  • My commits are signed (git commit -S): a42c006 shows G.
  • I ran the project's own checks: actionlint, as above. No test covers this workflow.
  • New files: none. The workflow keeps its existing SPDX header.
  • Docs: no user-facing change.
  • I have not introduced a soundness hole. No gate is weakened: the job runs the same steps, only with an upper bound on its runtime.

Notes for reviewers

🤖 Generated with Claude Code

https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm

Hypatia workflow_audit (code-scanning alert 168, missing_timeout_minutes)
flagged that estate-audit inherits the 6-hour default, so a stuck fetch or
runner hang can burn budget. The job runs two quick gates; 10 minutes is ample.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 622f19d9-dd3b-4396-8957-0888606d7a57
📥 Commits

Reviewing files that changed from the base of the PR and between 10819d6 and a42c006.

📒 Files selected for processing (1)
  • .github/workflows/main-estate-audit.yml

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
⏰ Context from checks skipped due to timeout. (7)
  • GitHub Check: governance / Validate Hypatia Baseline
  • GitHub Check: rust-ci / Cargo check + clippy + fmt
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: cargo test --features git-integration
  • GitHub Check: CodeQL Analysis (actions, none)
  • GitHub Check: idris2 0.8.0 --build git-reticulator-proofs
  • GitHub Check: semgrep-cloud-platform/scan
🔇 Additional comments (1)
.github/workflows/main-estate-audit.yml (1)

18-18: 🩺 Stability & Availability

The 10-minute timeout is not shown to be too short. The workflow lists many sequential gates, but the supplied evidence gives no run duration or other basis to conclude that the job reaches the limit. The request to verify a run is a validation reminder, not an established defect.


📝 Summary

Summary by CodeRabbit

  • Chores
    • The estate audit job now has a 10-minute time limit.

Walkthrough

The estate-audit job in the main estate audit workflow now has a 10-minute timeout.

Changes

Estate audit workflow

Layer / File(s) Summary
Set job timeout
.github/workflows/main-estate-audit.yml
The estate-audit job now has a 10-minute timeout.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to a42c0

This bounds the estate-audit CI job at 10 minutes instead of GitHub's six-hour default. No concrete problem was found. If the audit normally takes longer than 10 minutes, the job will be cancelled, so confirm with a CI run.

Architecture Summary

Architecture risk: 🔵 Low · up to a42c0

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .github/workflows/main-estate-audit.yml: Sets the estate-audit job timeout to 10 minutes.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the estate-audit job timeout change and its 10-minute limit.
Description check ✅ Passed The description explains why the workflow job needs a timeout and how this change adds the 10-minute limit.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

I’m a rabbit, hopping by,
I spot ten minutes in the sky.
The audit job now has a bound,
No endless wait can keep it round.
I thump my feet and nibble hay,
Then bounce along my merry way.

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 19f5681 into main Oct 6, 2026
35 of 36 checks passed
@hyperpolymath
hyperpolymath deleted the fix/estate-audit-timeout branch October 6, 2026 22:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant