Repository navigation
feat(prober): scan all 65535 ports (nmap -p-) - #85
Merged
Merged
Conversation
Full TCP port scan instead of top-100 — the point of exposed-services drift is to catch anything open. Safe because targets are owner-verified and scanning runs on the dedicated off-Railway droplet. - prober: nmap -sT -Pn -p- -T4 --host-timeout 1500s; execFile ceiling 30m. - prober-queue: RUNNING_TIMEOUT_MS 15m -> 40m for long scans. - SSE route: MAX_MS -> 45m + 15s heartbeat so idle proxies don't drop the connection while a long scan sits in 'running'. - PRD §12: document full-range scan + ownership/off-Railway justification. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Switches the exposed-services prober from top-100 to a full 65535-port TCP-connect scan (
nmap -sT -Pn -p- -T4 --host-timeout 1500s) — catching anything exposed is the whole point of drift detection. Safe because targets are owner-verified and the scan runs on the dedicated off-Railway droplet.Timeouts stretched to match a multi-minute scan: reconcile window 15m→40m, nmap ceiling 30m, SSE stream 5m→45m with a 15s heartbeat so long
runningscans don't drop the connection. PRD §12 updated.🤖 Generated with Claude Code