T09 · Insecure Skill Coding Practices
- Location
scripts/pipeline.py:203- Finding
Timed-Out Nodes Continue Executing in Background Threads
- Content
View full analysis
Any: """Run a function with a timeout using a thread.""" result_container: List = [None] exception_container: List[Optional[Exception]] = [None] def target(): try: result_container[0] = fn(context, data) except Exception as e: exception_container[0] = e thread = threading.Thread(target=target, daemon=True) thread.start() thread.join(timeout) if thread.is_alive(): raise TimeoutError(f"Node execution timed out after {timeout}s") if exception_container[0] is not None: raise exception_container[0] # type: ignore return result_container[0] ``` ### Technical Analysis The timeout implementation waits for the worker thread only for the configured duration. When that duration expires, it raises `TimeoutError`, but Python threads cannot be forcibly terminated and the worker remains alive as a daemon thread. Consequently, the timeout limits how long the caller waits but does not limit how long the node executes. The timed-out callable retains access to the shared `context`, mutable input objects, process permissions, files, network resources, and any other resources available to the host process. The surrounding retry mechanism can make this behavior more dangerous. A timeout is treated as a failed attempt, so a node configured with retries may start another execution while the previous timed-out invocation is still running. Multiple copies can therefore operate concurrently on the same state or external resources. ### Attack Path 1. An attacker supplies, influences, or triggers a pipeline node callable that performs long-running or delayed operations. 2. The node is configured with a ...[truncated 1446 chars]- Remediation
View remediation
