Skip to content

gateway tests: timing assertions hold under heavy host load - #127

Merged
jaredLunde merged 2 commits into
mainfrom
load-proof-timing
Oct 4, 2026
Merged

jaredLunde merged 2 commits into
mainfrom
load-proof-timing

Conversation

@jaredLunde

Copy link
Copy Markdown
Contributor

Wall-clock assertions failed under heavy host load (load 60–230 during local mutation runs) without any code being slower — CI noise, and worse, false "caught" verdicts in mutation runs. Tests only; one dev-dependency feature (rustix/time, already in the graph) for a safe thread-CPU-time read under unsafe_code = "forbid".

D217 linear merge: now thread CPU time at N and 4N (min of 3 runs each), asserting ratio < 8. Unloaded ≈ 4.0; the old quadratic merge put back gives 15.7 and fails.

18 fragile timing checks converted (event/ordering waits, hand-stepped clocks, re-run when a stall makes a run prove nothing, bounds stretched from a round-trip measured in the same run — common::stretched, exactly the old 2 s on an idle host), including two rate-limit tests the load runs exposed (requests spread across window boundaries). New Step::Until in tests/common makes scripted providers write the next event only after the client holds the previous one, replacing timing gaps in the streaming claims. Safe checks (generous "didn't hang" bounds, lower bounds only, virtual or injected time) left as is.

Verification: 160 busy-loop processes (load 105–168) — 5 full loaded runs green over lib + claims_streaming, request_deadlines, reliability_lifecycle, claims_security, replicas, reliability_log_stall, large_bodies, reliability_early_response, reliability_breaker; full cargo test -p beyond-ai green unloaded (71 binaries). Every converted test re-checked against a hand-broken subject (quadratic merge, early/late cooldowns, deadline checks off, drain never exits, no keep-alives, buffered SSE, reject cap off, rate limit off, deny 3 s late): all fail.

Side finding (not changed): ai_session_pinned_total rises on essentially every catalog walk, so reliability_breaker::an_undecidable_first_kib…'s assertion on it is weak regardless of load.

🤖 Generated with Claude Code

https://claude.ai/code/session_01JimHGjsfk2Ktm5GxyZJKKk

Wall-clock assertions failed at load averages of 60-230 without any code
getting slower. Each fragile one now asserts something load cannot fake
or break:

- D217 merge test: thread CPU time (rustix clock_gettime, dev-dep; the
  crate forbids unsafe) and scaling, 4x the messages < 8x the CPU, in
  place of < 2 s wall. The reintroduced quadratic merge reads 15.7x.
- deadline, breaker window, cache TTL, key cooldown unit tests: measured
  elapsed time, a stepped clock, or re-running a run that a stall made
  inconclusive, in place of fixed sleeps with an implicit upper bound.
- streaming claims: the scripted provider writes the next event only once
  the client holds the last one (new Step::Until), so the ordering is
  the proof rather than inter-arrival gaps.
- request deadlines, header stall, dead h2 PING, early answer, large-body
  failover: the bound is pushed far below the alternative ending, which
  is pushed far out (a trickled body that lasts over a minute), and
  the cause is asserted from the answer, row, metric or drain log line.
- SEC-17 deny bound: 2 s on an idle host, stretched by 40 round trips
  measured in the same run when the host is loaded (common::stretched).
- rate-limit and log-cap floods: bursts re-sent until one provably landed
  inside the windows the assertion needs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JimHGjsfk2Ktm5GxyZJKKk
@jaredLunde
jaredLunde enabled auto-merge (squash) October 4, 2026 19:52
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JimHGjsfk2Ktm5GxyZJKKk
@jaredLunde
jaredLunde merged commit ec63ee8 into main Oct 4, 2026
16 of 19 checks passed
@jaredLunde
jaredLunde deleted the load-proof-timing branch October 4, 2026 20:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant