Skip to content

fix(audit): detect explicit-seconds form sleep 30s in sleep-polling-loop - #845

Open
lakshya-dhariwal wants to merge 1 commit into
FailproofAI:mainfrom
lakshya-dhariwal:fix/sleep-polling-loop-seconds
Open

lakshya-dhariwal wants to merge 1 commit into
FailproofAI:mainfrom
lakshya-dhariwal:fix/sleep-polling-loop-seconds

Conversation

@lakshya-dhariwal

@lakshya-dhariwal lakshya-dhariwal commented Sep 27, 2026 •

Copy link
Copy Markdown

Description

Fixes #522. The sleep-polling-loop detector's unit alternation (m|h|d)? omitted s, and the trailing \b then failed on sleep 30s (both 0 and s are word characters), so the whole match silently dropped - exactly the most common form. Added s to the unit group and a comment explaining why. The detector's own docstring example (sleep 0.5m = 30s) now actually behaves the same as sleep 30s.

Tests: sleep 30s and sleep 45s now match, sleep 1s still does not, existing cases unchanged.

Type of Change

  • Bug fix
  • New feature
  • Refactor
  • Documentation

Checklist

  • npm run lint passes (eslint on the touched files - clean)
  • npx tsc --noEmit passes
  • npm run test:run passes - ran the touched suite instead: npx vitest run __tests__/audit/detectors.test.ts (33/33). Full test:run + build need bun, which I don't have here - flagging rather than ticking a box I didn't run.
  • npm run build succeeds - same bun constraint.

Summary by CodeRabbit

  • Bug Fixes
    • Long sleep intervals specified in seconds (such as sleep 30s) are now detected. Short intervals like sleep 1s remain undetected.

@github-actions

Copy link
Copy Markdown
Contributor

Thanks @lakshya-dhariwal for your contribution to Failproof AI! 🙌

We'd love to discuss your PR and welcome you to our community.

Discord: https://discord.befailproof.ai/
Reddit: https://www.reddit.com/r/failproofai/

@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 3170ea4d-4190-4171-ab38-54ff8e09c746

📥 Commits

Reviewing files that changed from the base of the PR and between e40de6c and 303bccc.

📒 Files selected for processing (2)
  • __tests__/audit/detectors.test.ts
  • src/audit/detectors/sleep-polling-loop.ts

Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 6 remain after this review.


📝 Walkthrough

Walkthrough

The sleep polling loop detector now accepts an explicit s suffix. Tests check detection for 30- and 45-second sleeps and no detection for a 1-second sleep.

Changes

Sleep Seconds Detection

Layer / File(s) Summary
Accept explicit seconds in sleep patterns
src/audit/detectors/sleep-polling-loop.ts, __tests__/audit/detectors.test.ts
The standalone sleep pattern accepts an s suffix. Tests cover 30- and 45-second sleeps and confirm that a 1-second sleep is not detected.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~5 minutes

Change: Bug fix · Severity of issue fixed: Low

Merge Risk: ⚪ Minimal · up to 303bc

The detector now recognizes qualifying explicit-second sleeps while retaining the short-sleep distinction. No concrete merge-blocking regression is evident.

Architecture Summary

Architecture risk: 🔵 Low · up to 303bc

The change affects 2 systems.

Changed systems: src, __tests__

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — src (service) was modified; 1 changed file maps to changed impact.
  • observed — tests (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in tests/audit/detectors.test.ts: Added tests that expect detection for explicit-second sleeps of 30 and 45 seconds, and no detection for a 1-second sleep.
  • observed — Modified behavior in src/audit/detectors/sleep-polling-loop.ts: The standalone sleep regex now accepts an optional s unit suffix, in addition to m, h, and d.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely identifies the primary change: detecting explicit-seconds durations such as sleep 30s in the sleep-polling-loop detector.
Description check ✅ Passed The description includes all required sections, explains the bug and fix, identifies the change as a bug fix, and reports test results. It accurately leaves the full test suite and build unchecked bec…
Linked Issues check ✅ Passed Issue #522 requires detection of explicit-seconds sleeps at or above 30 seconds and a regression test. The detector regex now includes s in the unit group. The existing conversion and threshold logi…
Out of Scope Changes check ✅ Passed The changes are limited to the sleep-polling-loop detector and its tests. The added comment and boundary-focused regression cases support issue #522. No unrelated changes are shown.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 2…

Warning

Some tools did not complete. Review the errors below.

🔧 ESLint

If the error stems from missing dependencies, add them to the package.json file. For unrecoverable errors (e.g., due to private dependencies), disable the tool in the CodeRabbit configuration.

__tests__/audit/detectors.test.ts

ESLint skipped: missing config or dependency (missing-dependency). The ESLint configuration references a package that is not available in the sandbox.

src/audit/detectors/sleep-polling-loop.ts

ESLint skipped: the matched ESLint configuration already failed (missing-dependency).


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the sleep command,
Thirty seconds now are scanned.
Forty-five joins the line,
One short second stays benign.
The burrow hops along just fine.

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Audit sleep-polling-loop detector misses the most common form, sleep 30s

1 participant