Skip to content

Close CI gaps and wait on events instead of fixed sleeps in flaky tests - #1600

Merged
jeremi merged 9 commits into
mainfrom
claude/quirky-cerf-0dmg89
Sep 26, 2026
Merged

jeremi merged 9 commits into
mainfrom
claude/quirky-cerf-0dmg89

Conversation

@jeremi

@jeremi jeremi commented Sep 26, 2026 •

Copy link
Copy Markdown
Member

Pull Request

Summary

Fixes CI gates that could pass without checking anything, and tests that failed on slow runners because they waited a fixed time instead of for an event.

CI (.github/, release/scripts/)

  • ci: check every standalone Cargo lockfile with --locked (refs Refresh the stale platform fuzz Cargo.lock and add --locked checks for fuzz and SDK workspaces #1528). The fuzz, wasm-handler SDK and Zed extension workspaces keep their own Cargo.lock, and most build root crates by path, so a root change could leave one stale unnoticed. rust-policy now runs cargo update --workspace --locked on each tracked non-root lock, which fails on a stale lock and fetches only the registry index. The gate inventory records the step.
  • ci: run the retained example recovery test by exact name (closes CI: BReg tutorial job's retained-example recovery step runs zero tests #1405). The BReg tutorial step filtered on a test that no longer exists, and a filter that matches nothing exits 0. It now names the successor with --exact and fails unless exactly one test passes. Two casework tutorial steps get the same guard. test_ci_changes.py checks the name, the guard, and that the test exists.

Tests (crates/)

Only test and CI code changes.

Evidence

  • Lockfile step: ran in this PR's rust-policy job. All four standalone locks resolved with --locked and Locking 0 packages. check-gates-inventory.py passes. actionlint output is the same as on main.
  • Exact-name guard: test_ci_changes.py passes (119 tests). The BReg and casework tutorial jobs pass in CI with the guard, so each named test ran and reported one pass.
  • BReg recovery test: on main it failed with Error("expected value", line: 1, column: 1), then on the unbound review authority. With this change it passes locally (50.8 s) and in the tutorial job.
  • Casework waits: I pinned the two tests that flake to a core shared with two nice −10 busy loops (test at nice 10) and ran 20 times per binary. The main binary failed 9 of 20: interrupted_native_prerequisite_is_killed_and_reaped exceeded its 1 s window, and killed_guard_leaves_the_supervisor_to_clean_its_exact_service_group hit "guarded service did not start". This branch failed 0 of 20.
  • LSP waits: under extreme starvation, run once per binary, the new evidence_cards_protocol passed all 12 tests in 771 s. The main binary was still stuck at the 900 s cap. Indicative, not statistical.
  • Crate gates: cargo fmt --check and cargo clippy -D warnings pass on the four touched crates. The touched suites pass, except two tests that fail on main too when run as root (as this container does). Both pass as an unprivileged user:
    • registry-caseworkctl config_change_keeps_the_owner_after_created_container_cannot_be_saved
    • registry-evidencectl --test access revoke_leaves_the_record_untouched_when_the_private_directory_cannot_be_removed
  • Not run locally: the full workspace suite and the PostgreSQL suites. CI covers them.

Notes

DCO

  • Every commit includes a Signed-off-by trailer.
  • I reviewed the submitted changes and am responsible for the contribution.

🤖 Generated with Claude Code

https://claude.ai/code/session_011gBjYHCSpw2Hs7LXPgE4da

The fuzz, wasm-handler SDK and Zed extension workspaces keep their own
Cargo.lock, and three of them build root crates by path, so a root
version bump or dependency change can leave one stale without any job
noticing. The rust-policy job now resolves each tracked non-root lock
with `cargo update --workspace --locked`, which fails on a stale lock
and fetches only the registry index. The gate inventory records the
step.

Refs #1528

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
…rter

The public-organizations starter is now commented YAML and its change
requests name the `casework` review authority, so the ignored
native_create_recovers_after_process_exit_without_duplicate_records test
failed before its first write: the fixture parsed registry.yaml as JSON,
and a local start refused to activate an unbound review authority.

Parse the starter as YAML and bind `casework` in the test's copied
dev-clients.yaml to a declared producer client and an unused loopback
endpoint. No scenario in the test submits a change request, so the
binding is never contacted.

Refs #1405

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
The breg tutorial step filtered on a test that no longer exists, and a
cargo test filter that selects nothing exits 0, so the step passed
without running anything. Point it at the successor,
native_create_recovers_after_process_exit_without_duplicate_records,
with --exact, and fail unless the run reports exactly one pass.

The two casework tutorial steps that select one ignored test by name
had the same hole and get the same guard. The CI classifier test now
checks the exact name, the guard, and that the named test exists.

Closes #1405

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-26T19:17:58.009053Z 857e6ae New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3988e3f507

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread release/scripts/check-gates-inventory.py
…ge gap

The language-server protocol tests gave each message a fixed 10 second
receive timeout, so a slow runner failed while the server was still
answering. receive_response now waits for the named response under one
120 second deadline for the whole wait, and reports what arrived
instead when the deadline passes or the server closes stdout.

The evidencectl termination test's 10 second readiness and exit
deadlines become the same 120 second bound. Its polling loop is
unchanged.

Refs #1361

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
…sses

The dev supervisor tests polled with short fixed windows, and one read
its prerequisite's PID marker as soon as the file existed, before the
child had written it, so a loaded runner failed them. Every wait now
polls its condition under one generous bound, and PID markers are read
only once they hold bytes.

Negative cases keep their meaning: a child that should be interrupted
sleeps far past the bound, and each elapsed-time check compares against
the production deadline it proves, not a test-chosen margin. Only the
test module changes.

Refs #1359

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
@jeremi
jeremi force-pushed the claude/quirky-cerf-0dmg89 branch from 3988e3f to 31a2ad1 Compare September 26, 2026 16:59

jeremi commented Sep 26, 2026

Copy link
Copy Markdown
Member Author

Rust tests (casework) failed on 31a2ad1 in dev::public_jwks::tests::serves_only_public_keys_and_releases_its_listener ("the explicit public JWKS port is occupied", public_jwks.rs:159). This PR doesn't touch that file or test. The test picks a port by binding :0, releases it, and later asserts it can rebind that port. Server::drop joins its thread first, so the listener is closed by then. Another parallel test's loopback connection can still take the same ephemeral port in that gap, and nothing in this PR adds loopback connections. The same job passed on the previous head. No fix exists yet. I'll re-run the failed job once when the workflow finishes, and if it fails again I'll treat it as real.


Generated by Claude Code

@jeremi
jeremi force-pushed the claude/quirky-cerf-0dmg89 branch from 31a2ad1 to 8b5f8c4 Compare September 26, 2026 18:31
The two task-approval single-test steps filtered by bare function name,
which matches any test sharing that name anywhere in the crate. Filter
by the full module path with --exact instead, and cover both steps in
the classifier test that already proved the BReg guard's exact name.

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
A bare grep -q exit gave no indication which test was missing or
duplicated, just a failed step. Report the test name through
::error:: so a broken guard is actionable from the job log alone.

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
…, not hangs

child.wait() after sending exit blocked forever if the server answered
shutdown but never acted on exit, hanging the whole CI job instead of
failing one test. Poll try_wait under RESPONSE_DEADLINE, then kill the
process and panic with a message that names what happened.

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
Casework's dev tests waited on a hung child for at most 60 seconds
while the language-server and evidencectl process tests allow 120.
No test here depends on the shorter bound; a wider one only gives a
starved runner more room before a real hang is reported.

Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
@jeremi
jeremi added this pull request to the merge queue Sep 26, 2026
@jeremi
jeremi removed this pull request from the merge queue due to a manual request Sep 26, 2026
@jeremi
jeremi enabled auto-merge September 26, 2026 19:14
@jeremi
jeremi added this pull request to the merge queue Sep 26, 2026
Merged via the queue into main with commit 0df549e Sep 26, 2026
55 checks passed
@jeremi
jeremi deleted the claude/quirky-cerf-0dmg89 branch September 26, 2026 20:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI: BReg tutorial job's retained-example recovery step runs zero tests

1 participant