test(todo): qualify hard-lease claim races across providers - #3986
Conversation
Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Exact head:7e01840a51744debffd5fd3ee873c48e39bb7499。没有发现阻塞问题;批准,未执行合并。
动机
既有 canonical claim 在 hard-lease 模式下必须持有有效租约,但单次成功测试不能证明“检查后、提交前被另一 Agent 换租约”的竞争行为,也不能证明持久提交后丢响应的恢复行为。本 PR 给已有跨 provider conformance 增加这两个确定性反例,防止旧 claim 越过 CAS 或把重试变成新授权。
改动思路
复用 registerAuthorityStoreConformance、现有 factory 和生产 executeCoordinationTodoClaim,通过包裹 commit 边界插入故障,运行于 native/v0 两种 Todo 形状。不是复制 claim 实现:断言来自独立不变量——旧租约不得授权新提交、已提交请求应从 durable receipt 恢复、历史 replay 不续租。
正向路径:seed → 提供 alpha 有效 lease → claim 持久提交但返回 ambiguous → receipt readback → recovered,Todo 归 alpha 且 lease 不变。到过期时间,同 id 得到历史 replay,新 id 则拒绝;同 id 改 actor/owner 拒绝。
负向路径:无 lease 时拒绝且不消费 operation id;加入 lease 后,在 claim commit 前让 contender 将 lease 换成 beta/epoch 2 → 原 claim conflict、无 receipt、Todo 未被认领、beta lease 保留。重试仍由生产事务检查并拒绝,测试未把 conflict 当作成功。
具体改动
仅 tests/control_plane_ts/authority_store_conformance.ts,+82/-0。两个 fault × native/v0,复用原测试注册与 provider factory,不新增运行时、公共 schema、CLI、默认配置、权限或自动 promotion。
检查了相邻既有 claim/compatibility race 测试与 local_authority_runtime.test.ts 的 hard-lease 用例:已有覆盖偏单路径或普通 claim;本次新增的是明确的 lease 替换提交竞争与丢响应恢复在共享 provider conformance 中的组合,不是重复展示已知输出。它能直接保护 file、NoKV envelope、NoKV JSON-lines 和 PostgreSQL 的同一事务边界。同期作者 PR #3987 暴露 CLI 重试 id,覆盖层不同;不需要把本测试改成另一套 CLI 框架,也没有发现同形低价值测试批量堆积。
对主干的风险
产品运行时零变更;主要成本是测试时间和 fixture 维护。故障注入发生在确定的 commit 边界,不依赖 sleep 概率撞竞态;最后比较完整 authority readback,确保拒绝和历史 replay 不偷偷改状态。
独立 exact-head 验证:file/NoKV envelope/NoKV JSON-lines 三套共 70 passed;另启动隔离的本地真实 PostgreSQL,以合成 fixture 运行集成套件,24 passed;合计 94 passed,零失败、零跳过。测试服务器已停止,未触碰活跃 Goal 或生产数据库。TypeScript typecheck 和 diff whitespace 检查通过。远端该 head 的 Python、Windows、DCO、dependency、Sonar checks 也成功。本次没有重跑作者所述完整 635 项套件或全量 canary;不把作者声明算作本次独立执行。
范围边界:这些测试证明现有 provider transaction,不代表完整 CLI migration 或 claim+lease 联合获取完成;NoKV 套件使用仓库提供的 envelope/JSON-lines 测试 transport,不是生产服务资格认证。默认隔离/activation/安装 guidance 在本次纯测试 diff 中不适用;没有新增 actor authority 或 scheduler obligation。
我的整体评价
这是有持久价值、比例合适的测试补强:82 行集中覆盖同一安全边界,复用现成 conformance 而没有扩展生产机制。未来重构检查未发现需要同步引入的 helper/framework;保留当前局部 fault wrapper 更容易理解和维护。
建议作为低风险测试 PR 合并候选;它提高发布后的回归防护,但不是个人工作区前端发布的必需功能,也不应扩大成迁移工程。没有阻塞发现,合并仍遵循当前 head 和仓库 gate。
English verdict: APPROVE at 7e01840. No blocking findings. This focused test-only change reuses shared conformance to protect lease-replacement CAS rejection and durable-receipt recovery without granting fresh lease authority. Independently passed 70 file/NoKV tests and 24 isolated real PostgreSQL tests, with zero failures/skips, plus typecheck and diff checks. Full-suite/canary claims were not independently rerun. No merge performed.
Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
Exact head: 532db5f8ff808f019e56c2ba59a101747396653e; validated against main ee47b613825b2d3456cc1806e705a63407d97fc0.
1. Findings / 发现
没有阻塞发现。已通过普通 merge 解决同一插入位置的测试冲突,完整保留主干 Todo update 测试与本 PR hard-lease claim 测试。相对主干仍为单个测试文件 +82/-0,没有生产代码改动。
2. Assumptions / 边界
本次是 owner 明确授权的冲突修复与自合并。新 head 的 CI 独立于旧 head;不把旧 CI 成功当作本版本成功。无运行时、权限、默认行为或安装变更,无人工 hold。
3. Product and architecture / 产品与架构
复用既有 provider conformance、factory 与生产 claim 事务,覆盖租约被替换时 CAS 拒绝,以及提交成功但丢响应后的 durable receipt 恢复。历史 replay 不授予新租约。局部故障注入保护同一事务契约,不需要另建测试框架;冲突解决也没有删掉主干的新增覆盖。
4. Validation / 验证
- Full control-plane suite: 647 passed, 0 failed, 0 skipped, including isolated real PostgreSQL with synthetic fixtures; test server stopped afterward.
- TypeScript typecheck and committed/staged/unstaged diff hygiene passed.
- Premerge: all 3 selected catalog canaries passed; no failures or manual holds; self-merge gate allowed.
- Exact-scope change-quality receipt
cqr_53e3c3b470e1c20fa3c6verified valid; existing reuse retained, no unnecessary abstraction or safe-fix needed. - Public-boundary review: synthetic tests only; no credentials, private state or logs in the diff.
5. Merge decision / 合并判断
APPROVED for owner-authorized self-merge at the exact head above. 本次全量受影响测试与风险门禁均通过,足以验证这份仅测试的冲突解决;远端新 CI 尚需单独观察,不声称其已完成。
Summary
Validation
cqr_d4f3d9f64d16f0b62ca8valid for head7e01840a51744debffd5fd3ee873c48e39bb7499; one file, no blockers, no safe-fix pass. Requalified after commit because the source identity changed.Boundaries
Test-only: no runtime behavior, CLI schema, default configuration, provider promotion, or production state changes. A disposable local PostgreSQL server with synthetic tenants was used and stopped afterward. Local databases, logs, receipts and dependency links are excluded from Git.
This qualifies the existing provider transaction boundary; it does not implement a combined claim-and-lease acquisition operation or prove the complete CLI migration path. Those remain follow-up work. The conformance factory is reused without a new framework or runtime refactor. No merge requested by this PR automation.