google-gemini/gemini-cli · error · Error

Security validation timed out after 5000ms

Error message

Security validation timed out after 5000ms

What it means

The synchronous PowerShell child process used for Windows path security validation was killed after its 5000ms spawnSync timeout (ETIMEDOUT). The security check fails closed: a validation that cannot complete is treated as insecure and re-thrown as this sentinel error.

Solutions

  1. Reduce the number/size of paths checked per batch
  2. Check system load and PowerShell startup health (profile scripts, AV scanning)
  3. Retry the validation once transient slowness subsides
Defensive patterns

Strategy: retry

When it happens

Trigger: Thrown at packages/core/src/utils/security.ts:331 when the library encounters an invalid state.

Common situations: See trigger scenarios.

Understand the failure class


AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16). Data as JSON: /api/errors/5b1b084117526ece. Report an issue: GitHub.

Appendix: source

Thrown at packages/core/src/utils/security.ts:331

    const powershellPath = getWindowsPowerShellPath();

    const encodedScript = Buffer.from(script, 'utf16le').toString('base64');
    const res = spawnSync(
      powershellPath,
      [
        '-NoProfile',
        '-NonInteractive',
        '-ExecutionPolicy',
        'Bypass',
        '-EncodedCommand',
        encodedScript,
      ],
      { encoding: 'utf-8', timeout: 5000 },
    );

    if (res.error) {
      if ((res.error as NodeJS.ErrnoException).code === 'ETIMEDOUT') {
        throw new Error(`Security validation timed out after 5000ms`);
      }
      throw res.error;
    }

    if (res.status !== 0) {
      throw new Error(
        `PowerShell execution failed with status ${res.status}: ${res.stderr || res.stdout}`,
      );
    }

    const batchResults = parseWindowsBatchSecurityOutput(
      res.stdout ?? '',
      uncached,
    );

    for (const p of uncached) {
      const parsed = batchResults.get(p) ?? {};
      let isDir = false;

View on GitHub (pinned to 6a466a7e2f)