Repository navigation
fix(clamav): raise WRITE_TIMEOUT_SECONDS past the scan timeout - #13800
Merged
Merged
Conversation
clamav-rest's http.Server defaults WRITE_TIMEOUT_SECONDS to 300s, which we never override. That timeout is reset when the request's headers are read and bounds the whole handler-to-response-write duration, so for a scan slower than 300s the server severs the connection well before SCAN_TIMEOUT_MINUTES elapses - the scan keeps running, but its result is written to a connection nobody is listening on anymore, and the client sees a bare read timeout instead of the scan result. Set WRITE_TIMEOUT_SECONDS above SCAN_TIMEOUT_MINUTES*60 everywhere clamav.env is defined, so the configured scan timeout is the one that actually governs. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
1 task
netomi
added a commit
that referenced
this pull request
Oct 5, 2026
clamav-rest's http.Server defaults WRITE_TIMEOUT_SECONDS to 300s, which we never override. That timeout is reset when the request's headers are read and bounds the whole handler-to-response-write duration, so for a scan slower than 300s the server severs the connection well before SCAN_TIMEOUT_MINUTES elapses - the scan keeps running, but its result is written to a connection nobody is listening on anymore, and the client sees a bare read timeout instead of the scan result. Set WRITE_TIMEOUT_SECONDS above SCAN_TIMEOUT_MINUTES*60 everywhere clamav.env is defined on this branch (base values.yaml and values-aws-staging.yaml); values-staging.yaml/values-test.yaml don't override env, so they inherit the base fix. Same issue fixed on aws-production in #13800. Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
skettkepalli
approved these changes
Oct 5, 2026
Contributor
Author
|
please merge at your convenience so that the clamav service takes the correct timeout into account |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related to #13794.
Summary
clamav-rest(EclipseFdn/clamav-rest-new) defaultsWRITE_TIMEOUT_SECONDSto 300s and we never override it in any values file. Go'shttp.Server.WriteTimeoutis reset when the request's headers are read and bounds the entire handler-to-response-write duration, so for any scan slower than 300s the server severs the connection well beforeSCAN_TIMEOUT_MINUTESelapses.Read timed outinstead of the scan verdict, andExtensionScanCompletionServicemarks the scan groupERROREDeven though clamav-rest's own logs show a clean, completed scan.Oracle.oracle-java, whose VSIX (2398 files) scans in ~394s — comfortably past the undocumented 300s cutoff but still under the configured 10-minuteSCAN_TIMEOUT_MINUTES.WRITE_TIMEOUT_SECONDSaboveSCAN_TIMEOUT_MINUTES * 60everywhereclamav.envis defined (basevalues.yaml,values-aws.yaml,values-aws-staging.yaml), so the configured scan timeout is the one that actually governs.values-aws-dr.yamlhas clamav disabled andvalues-staging.yaml/values-test.yamldon't overrideenv, so they inherit the base fix.Test plan
SCAN_TIMEOUT_MINUTES); confirm the scan result now lands rather than erroring out.Oracle.oracle-java27.0.0 (or a comparably large version) in production and confirm the scan completes without the group being markedERRORED.🤖 Generated with Claude Code