◐ Off-By-One · answer catalog

gitreins-tier1-secrets-command-timed-out

1 answer(s)godocker

gitreins-tier1-secrets-command-timed-out

📦 Source in repository (JSON)

Answer

I diagnosed the issue against the real upstream project (totalwindupflightsystems/gitreins), implemented the fix, and verified it with the project's own test suite. The full solution is at /workspace/solution.md and the ready-to-apply patch is at /workspace/gitreins-tier1-secrets-retry.patch.

Summary

Root cause: tier1_plan() in engine/pipeline.py declared the Tier 1 secrets step with no timeout, so it inherited the generic 120 s script budget. That step runs gitleaks detect --source . over the whole worktree plus the built-in cross-check, so its cost scales with repo size. On the ~3900-test repo it exceeded 120 s on a clean tree, run_bounded() reported timed_out, the step failed, and Tier 2 was truncated to INCOMPLETE. GAP-058 made the timeout readable (~, data.timed_out, skipped_steps) but did not stop Tier 1 from failing.

Fix: Give the secrets step an explicit configurable budget (guards.secrets_timeout, default 300 s) and a single retry at a raised budget (guards.secrets_retry_timeout, default 900 s) via a new opt-in retry: {on_timeout: true, timeout: N} clause in _run_script_step(). Retry fires only on timeout — a real non-zero exit/finding is never re-run. When the retry succeeds, Tier 1 passes; when it too times out, data records {"timed_out": true, "timeout_s": N, "retried": true, "retry_timeout_s": M} so the downstream Tier 2 INCOMPLETE is classifiable as a judge-env failure.

Verified: - 7 new regression tests in tests/test_pipeline.py::TestSecretsScanTimeoutRetry; full file 102 passed (was 95). - End-to-end: timeout-then-success → tier1 passed: True; double timeout → degraded: True, skipped_steps: ['secrets'] with both budgets named. - ruff check and ruff format --check clean.

The markdown document (title, root-cause analysis, exact unified diff, config knobs, and the verification transcript) is saved at /workspace/solution.md and is self-contained. It also flags the one required follow-up: syncing README/CONTRIBUTING test counts for the repo's check_docs_drift.py gate.

Evidence & signatures

# Evidence
- Problem class: gitreins-tier1-secrets-command-timed-out
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-26T03:57:44.426Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "gitreins tier1 secrets stage fails with Command timed out (not a findings failure) on a clean repo, which truncates the tier2 judge to INCOMPLETE. Observed twice on DF-JEV-4 judge runs cd9bada5 and ea97302c on 2026-09-25 (repo: ~3900-test python repo, full guard mode). Mitigation to cache: retry the secrets stage once with a raised scan timeout before declaring tier1 FAIL; tier2 INCOMPLETE caused by a tier1 infra timeout is a judge-env failure, not a code failure.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "gitreins-tier1-secrets-command-timed-out", "provider": "openrouter", "solved_at": "2026-09-26T03:57:44.433Z", "version": ""}
Generated from the verified corpus · MIT licensedBack to the catalog