Skip to content

chore(deps): slack-sdk 3.44.1 stops Socket Mode retry loop; tornado 6.5.8 DoS fixes (salvage #106817, #107122) - #109151

Merged
teknium1 merged 4 commits into
mainfrom
chore/deps-slack-sdk-tornado-salvage
Sep 12, 2026
Merged

teknium1 merged 4 commits into
mainfrom
chore/deps-slack-sdk-tornado-salvage

Conversation

@teknium1

Copy link
Copy Markdown
Collaborator

Slack Socket Mode no longer spins forever on Session is closed after a reconnect, and the webhook stack picks up tornado's multipart/form-body DoS fixes.

Salvages #106817 from @bill3wits
Salvages #107122 from @arlai-mk

Changes

Improvements during salvage

  • tools/lazy_deps.py: mirrored the slack-sdk pin to 3.44.1 in LAZY_DEPS["platform.slack"]. The original bump left it at 3.43.0, so the lazy installer would still have pulled the old SDK, and the existing pin-mirror contract tests fail without it.
  • Re-authored fix(deps): bump slack-sdk to 3.44.1 — aiohttp Socket Mode connect() retries forever against a closed session #107122's commit from the bare arlai-mk@users.noreply.github.com to 118589706+arlai-mk@users.noreply.github.com (id from gh api users/arlai-mk; misconfigured local git, not malice). Added the contributors/emails/ mapping for @bill3wits.

Validation

Check Result
tests/test_project_metadata.py (pin-mirror contracts) 7 passed
Red-on-base for the lazy_deps mirror (swap origin/main:tools/lazy_deps.py in) test_pyproject_pins_match_lazy_deps_pins + test_every_lazy_deps_exact_pin_matches_uv_lock FAIL; pass after restore
tests/tools/test_lazy_deps*.py 88 passed, 2 skipped
tests/test_packaging_metadata.py, tests/gateway/test_slack_socket_reconnect_heal.py passed (19 total across the metadata + slack files)
uv lock --check, tomllib.load(pyproject.toml) OK
ruff / windows-footguns / compat-pointers / git diff --check / attribution audit clean

Infographic

deps-slack-tornado

bill3wits and others added 4 commits September 12, 2026 07:03
…parts DoS)

tornado 6.5.7 is affected by GHSA-5w76-955r-9v8r (CVSS 8.7): parse_multipart_form_data
splits the body unbounded before the max_parts check, so a request with a very large
number of parts can exhaust memory. 6.5.8 caps the split at max_parts+1 so the flooding
part is never materialized.

uv lock --upgrade-package tornado on current main; only the tornado block changes
(13 insertions / 13 deletions in uv.lock), no other package or marker moves.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QghbdVnZSkJbRRDxCSs2zr
…ct() retrying forever

slack-sdk 3.44.1 contains the upstream fix for the aiohttp SocketModeClient
zombie retry loop (slackapi/python-slack-sdk#1956, closing #1913): connect()
used 'while True:' and never checked self.closed, so once close() closed the
shared aiohttp ClientSession, any connect/reconnect task in flight spun
forever logging 'Failed to connect (error: Session is closed); Retrying...'
every ping_interval.

Observed in production on this repo's own Slack adapter: the gateway's
socket watchdog (plugins/platforms/slack/adapter.py) heals wedged sockets by
rebuilding the AsyncSocketModeHandler, but the orphaned connect() task from
the pre-heal client kept retrying against the dead session indefinitely —
22k+ error lines per process per day while Slack itself remained connected.
The adapter's teardown docstring already references slackapi#1913.

3.44.1 adds the self.closed exit; slack-bolt 1.30.0 declares
slack_sdk>=3.38.0,<4, so the bump is compatible.
pyproject extras and the lazy installer must agree on the slack-sdk pin;
the salvaged bump only touched pyproject.toml + uv.lock, so the
`platform.slack` lazy-install spec would still have pulled 3.43.0.
@teknium1
teknium1 requested a review from a team September 12, 2026 14:07
@github-actions

github-actions Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

૮ >ﻌ< ა ci review

ran on c582b4f — chore(deps): mirror slack-sdk 3.44.1 pin in tools/lazy_deps.

⚠️ Warnings

OSV vulnerability scan · View job

76 known vulnerabilities found in pinned dependencies.

How to fix:

Review the findings in the Security tab. Update the affected dependencies if a patched version is available.


debug info

CI timings

CI timings · View report · View job

Wall time 4m27s vs 4m33s (-2.2%). 8 job(s) slower, 4 faster, 3 unchanged.

  • Python tests / Run tests: -36.0s
  • Check no committed infographics / check-no-committed-infographics: +34.0s
  • OS-specific tests / Windows-only tests: -8.0s
  • Python lints / Windows footguns (blocking): +5.0s
  • Python tests / e2e: +4.0s

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants