Skip to content

fix(clamav): raise WRITE_TIMEOUT_SECONDS past the scan timeout - #13801

Merged
netomi merged 1 commit into
aws-mainfrom
fix/clamav-write-timeout-staging
Oct 5, 2026
Merged

netomi merged 1 commit into
aws-mainfrom
fix/clamav-write-timeout-staging

Conversation

@netomi

@netomi netomi commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Summary

Staging counterpart of #13800 (aws-production).

  • clamav-rest (EclipseFdn/clamav-rest-new) defaults WRITE_TIMEOUT_SECONDS to 300s and we never override it in any values file on this branch. Go's http.Server.WriteTimeout is reset when the request's headers are read and bounds the entire handler-to-response-write duration, so for any scan slower than 300s the server severs the connection well before SCAN_TIMEOUT_MINUTES elapses.
  • The scan keeps running after the connection is cut, but its result is written to a connection nobody is listening on anymore — the calling openvsx server sees a bare Read timed out instead of the scan verdict, and ExtensionScanCompletionService marks the scan group ERRORED even though clamav-rest's own logs show a clean, completed scan.
  • Fix: set WRITE_TIMEOUT_SECONDS above SCAN_TIMEOUT_MINUTES * 60 everywhere clamav.env is defined on this branch — base values.yaml and values-aws-staging.yaml (both currently SCAN_TIMEOUT_MINUTES: 5). values-staging.yaml/values-test.yaml don't override env, so they inherit the base fix.

Test plan

  • Deploy to staging and publish an extension whose scan runs past 5 minutes; confirm the scan result now lands rather than erroring out.

🤖 Generated with Claude Code

clamav-rest's http.Server defaults WRITE_TIMEOUT_SECONDS to 300s, which
we never override. That timeout is reset when the request's headers are
read and bounds the whole handler-to-response-write duration, so for a
scan slower than 300s the server severs the connection well before
SCAN_TIMEOUT_MINUTES elapses - the scan keeps running, but its result
is written to a connection nobody is listening on anymore, and the
client sees a bare read timeout instead of the scan result.

Set WRITE_TIMEOUT_SECONDS above SCAN_TIMEOUT_MINUTES*60 everywhere
clamav.env is defined on this branch (base values.yaml and
values-aws-staging.yaml); values-staging.yaml/values-test.yaml don't
override env, so they inherit the base fix. Same issue fixed on
aws-production in #13800.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@netomi
netomi merged commit 637cbc1 into aws-main Oct 5, 2026
5 of 7 checks passed
@netomi
netomi deleted the fix/clamav-write-timeout-staging branch October 6, 2026 15:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant