Conversation
Cortex.axoninfo is an empty dict until the Axon connects, so indexing axoninfo['synapse']['version'] raised a bare KeyError. The known path is $lib.inet.http.post() with sha256 fields, which never waits on axready. Add stormtypes.getAxonVersion(), which reads the version with get() and raises FeatureNotSupported if it is missing, and use it at every site that previously indexed into axoninfo.
Add Cortex.waitAxonReady(), which waits up to s_const.AXON_READY_TIMEOUT seconds for axready and raises TimeOut if the Axon is still not ready. getAxonVersion() and $lib.axon.unpack() now call it before reading axoninfo, so $lib.inet.http requests with sha256 fields no longer read axoninfo before the Axon connects. $lib.axon.wget() and wput() used to wait on getAxon() with no timeout; they now use waitAxonReady() and time out instead of blocking indefinitely. Update the changelog fragment to describe the timeout, and restore the double back-ticks the shell stripped from it in the previous commit.
- Use waitAxonReady() in every remaining LibAxon method, so the whole library times out consistently instead of blocking indefinitely. - Check the axon.get permission in $lib.axon.unpack() before waiting on the Axon, matching the other LibAxon methods. - Avoid building a throwaway dict default in getAxonVersion().
Add axon:ready and axon:version to the cell section of the Cortex getCellInfo() output. axon:version is the Synapse version most recently reported by the Axon, or None before the Cortex first connects to it.
Match the default timeout of the $lib.inet.http request APIs.
vEpiphyte
commented
Sep 28, 2026
Use waitAxonReady() in the deprecated LibBytes methods, matching LibAxon.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #5019 +/- ##
==========================================
- Coverage 97.93% 97.84% -0.09%
==========================================
Files 308 308
Lines 65763 65792 +29
==========================================
- Hits 64405 64377 -28
- Misses 1358 1415 +57 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Use waitAxonReady() in the IMAP server fetch() method.
Use waitAxonReady() in delnode --delbytes, after its permission check.
- Cortex.getAxon() now takes timeout=s_const.AXON_READY_TIMEOUT and raises TimeOut, with timeout=None waiting indefinitely. It returns the Axon iden from axoninfo, because self.axon.iden was a telepath Method object for a remote Axon. - Drop the unreleased waitAxonReady() and move its callers to getAxon(). - CoreApi.getAxonUpload() and getAxonBytes() use the bounded wait. - The Cortex Axon HTTP handlers return a 503 TimeOut error when the Axon is not ready, instead of hanging.
Move the Cortex Axon HTTP handlers' Axon wait from prepare() into an allowed() override, so an unauthenticated or unauthorized request is refused immediately instead of waiting on the Axon first. Return from AxonHttpUploadV1.prepare() after a denied request, which previously went on to start an upload in the Axon.
- Rename getAxonVersion() to getAxonSynapseVersion(). - Wait on the Axon in $lib.axon.metrics(), Cortex.exportStormToAxon() and Cortex.feedFromAxon() (after its permission check). - Avoid a throwaway dict default in the unpack() feature check. - Drop axon:version from getCellInfo(); telepath getCellInfo() is available to any authenticated user.
Wait with s_common.wait_for() and raise TimeOut from its TimeoutError, matching the other timeout handlers. CI coverage did not record the raise that followed a timed out event_wait().
vEpiphyte
commented
Sep 28, 2026
vEpiphyte
commented
Sep 28, 2026
vEpiphyte
commented
Sep 28, 2026
vEpiphyte
marked this pull request as ready for review
September 28, 2026 20:47
invisig0th
requested changes
Sep 29, 2026
invisig0th
approved these changes
Sep 29, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
SYN-11748: Avoid
KeyErrorwhen the Axon is not readyProblem
Cortex.axoninfois an empty dict until the Axon connects (the embedded Axon finishing its boot, or aremote Axon's
onlinkfiring). Several Storm code paths indexedaxoninfo['synapse']['version']directly.If one of them ran before the Axon was connected, Storm raised a bare
KeyError.Every
axoninforead undersynapse/:axreadyfirst?stormtypes.resolveAxonProxyArg()['synapse']['version']$lib.axon.wget()withssl_opts['synapse']['version']$lib.axon.wput()withssl_opts['synapse']['version']$lib.inet.httpwithsha256fields (proxy +ssl_opts)['synapse']['version']$lib.axon.unpack().get('features', {})FeatureNotSupportedbefore connectThere was also no way for an operator to see whether the Cortex's Axon was ready.
Changes
stormtypes.getAxonSynapseVersion(runt). It waits for the Axon, reads the version withget(), and raisesFeatureNotSupportedif the version is missing. Every site that indexedaxoninfo['synapse']['version']now uses it.
Cortex.getAxon()now takestimeout=s_const.AXON_READY_TIMEOUT(300 seconds, the same as the default$lib.inet.httprequest timeout) and raisess_exc.TimeOutif the Axon is not ready in time.timeout=Nonewaits indefinitely as before. It returns the Axon iden from the Axon's reported cellinfo, or
Noneif the Axon did not report one. Previously it returnedself.axon.iden, which was atelepath
Methodobject rather than an iden when the Axon was remote. If the Axon is already ready, itreturns immediately. This is a behavior change for Python callers, which previously waited indefinitely.
$lib.axonmethod (wget,wput,urlfile,put,has,size,read,unpack,readlines,jsonlines,csvrows,list,upload,hashset,metrics,delanddels) now raisesTimeOutafter 300 seconds instead of blocking indefinitely. Each one checks its permission before itwaits.
$lib.axon.unpack()now waits for the Axon before it checks the Axon'sunpackfeature, so it no longerreports
FeatureNotSupportedjust because the Axon has not connected yet.getCellInfo()output now includesaxon:readyin itscellsection. The Axon's version isdeliberately not included, because Telepath
getCellInfo()is open to any authenticated user.$lib.bytesAPIs (put,has,size,hashsetandupload), the IMAP serverfetch()method, the
delnode --delbytescommand, andCortex.feedFromAxon()(Telepath and$lib.feed.fromAxon())get the same bounded wait, after their permission checks.
Cortex.exportStormToAxon()(
$lib.export.toaxon()), which has no permission check of its own, waits before it starts the export.CoreApi.getAxonUpload()andCoreApi.getAxonBytes()used to wait indefinitely onaxready. They now raiseTimeOutafter 300 seconds./api/v1/axon/files/...) used to wait for the Axon indefinitely, beforechecking authentication or permissions. They now check permissions first, then wait up to 300 seconds and
return an HTTP 503 with a
TimeOuterror if the Axon is still not ready. An unauthenticated orunauthorized request is refused immediately, whatever the Axon's state.
/api/v1/axon/files/put) no longer starts an upload in the Axon after itdenies a request. This fix also applies to the Axon service itself.
Tests
core.axoninforaisesFeatureNotSupportedinstead ofKeyError: 'synapse'.is denied immediately.
getAxon(),axon:ready, and the denied-upload fix have direct tests.