process_host() guards its loop with host_queue.qsize() and then performs a
blocking host_queue.get(). With --threads N, several workers can pass the
qsize() check while a single item remains: one wins the get(), the others
block in it forever.
Every queued item still gets its task_done(), so work_queue.join() returns
and main() runs to completion - the scan finishes and the results are
written. But the leaked workers are non-daemon threads, so
threading._shutdown() joins them forever at interpreter exit and the process
never terminates.
Use a non-blocking get(), which makes the existing "except queue.Empty:
break" reachable. The sibling loops in this file, remove_from_queue() and
process_output(), already read their queues with block=False.
Problem
process_host() guards its loop with host_queue.qsize() and then performs a blocking host_queue.get():
With --threads N, several workers can pass the qsize() check while only one item remains. One wins the get(); the others block in it forever.
Every queued item still gets its task_done(), so work_queue.join() in loop_hosts() returns, main() runs all the way through, and the results are written — the scan looks completely successful. But the leaked workers are non-daemon threads, so threading._shutdown() joins them forever at interpreter exit and the process never terminates.
This is easy to miss precisely because the output is complete. The log just ends normally and then hangs:
It is very visible under Docker, where analyze_hosts is PID 1: the container stays Up indefinitely, docker run --rm never returns and so never cleans up, and whatever invoked it waits on it. We accumulated six such containers over a month of nightly scans — one of them had ~150 zombie children — before tracking it down.
Reproduction
This is the loop_hosts/process_host shape reduced to just the queue handling:
Run it under timeout 120 python3 repro.py.
The fix
Read the queue with block=False, which makes the existing except queue.Empty: break reachable and lets a worker that loses the race exit cleanly.
The two sibling loops in this same file already do exactly that — remove_from_queue() uses finished_queue.get(block=False) and process_output() uses output_queue.get(block=False). process_host() looks like the one that was missed.
Breaking out is the correct behaviour here: a worker only sees queue.Empty when the queue is genuinely empty, and every target is enqueued before the workers start, so an empty queue means there is no more work.
Unrelated, and happy to open a separate issue rather than bundle it: the current gofwd/analyze_hosts image prints [-] Please install required modules ...: No module named 'pkg_resources' at start-up and silently disables --framework. python-Wappalyzer imports pkg_resources, which ships with setuptools — and since Python 3.12 venv no longer seeds setuptools, while setuptools ≥ 82 has removed pkg_resources outright, so adding setuptools back does not help. Just say the word if that would be useful.