A conformance verdict drops the bound a refusal named, so host.deadline_exceeded cannot be told from host.deadline_exceeded #254
Labels
No labels
code-review
correctness
dos
performance
security
severity/high
severity/low
severity/medium
tech-debt
Kind/Breaking
Kind/Bug
Kind/Documentation
Kind/Enhancement
Kind/Feature
Kind/Security
Kind/Testing
Priority
Critical
Priority
High
Priority
Low
Priority
Medium
Reviewed
Confirmed
Reviewed
Duplicate
Reviewed
Invalid
Reviewed
Won't Fix
Status
Abandoned
Status
Blocked
Status
Need More Info
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
h-dv/code-index#254
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The supervisor deliberately builds a refusal that says which of three enforcement points stopped a guest. The conformance verdict — the artifact CI and operators actually read — throws it away one call before writing it down, keeping only the reason code, which is identical for all three.
The tree promises this discrimination, twice
plugin_supervisor::limits, on the wall-clock backstop:supervise::deadline_refusal, which constructs it:Where it is lost
extract_with_grammarreturnsResult<ValidatedFacts, Refusal>— the fullRefusal, carryinglimit,limit_value,observed,witness. Then:and both worker-refusal sites in
conform::checkdoFixtureOutcome::ungraded(..., reason_of(&r)).FixtureOutcome::refusalis anOption<String>holding only the code. Everything that distinguishes a reproducible refusal from a timing one is discarded one call short of the record.What that cost, measured
CI job 34810 on
5131654failed with:host.deadline_exceededfrom fuel would be deterministic — a real defect in the fixture or the extractor. From epoch or process it is a loaded runner and means nothing about the product. The verdict could not say which, and the same binary passed locally, so the triage had to be done by re-running under artificial load instead of by reading the record.For the record, the contention was real and self-inflicted in an ironic way: the fix in
3aea49dun-brokeOSS corpus (tier 1), so that job went from failing at ~25 min to succeeding at ~54 min — andcargo test, sharing the runner pool, went 32 min → 68 min.cargo testbd1c4e25131654Fix
Three additive,
serde(default)fields onFixtureOutcome—refusal_limit,refusal_limit_value,refusal_witness— and aFixtureOutcome::refused(…, &Refusal)constructor used at the two sites that hold a realRefusal.Not folded into
ungraded. The other four sites refuse for reasons that are not bounds (a staging failure, a nondeterministic second extraction); giving them an emptylimitwould make "this refusal names no bound" and "nobody recorded the bound" the same fact, which is the conflation the fields exist to end. Absent stays a third state.Additive and back-compatible: old verdict files deserialize with
None, new ones add keys old readers ignore.xaml_large_file_budgets's probe now has an arm that fires on a deadline and prints the bound, its value and the witness, instead of the generic "the expectation was never COMPARED" — which is true but sends the reader after the byte ceiling rather than after the machine. The code it matches is bound tocode_index_abi::Reason::HostDeadlineExceeded.as_str()rather than spelled out, because a literal that drifted by one character would turn that arm into dead code whose failure mode is silence.Mutations, run
reason_ofinrefused— the exact shape that shipped. RED:left: (Some("host.deadline_exceeded"), None, None, None)against the full discriminator. md5 verified changed, then restored.Refusal::new(HostWorkerUnavailable)— not a bound — must recordNone, so a constructor stamping a placeholder fails.HostDeadlineExceededcontrol fixture now carries a non-empty discriminator and asserts it survives the verdict file, following this tree's ownnormalize_graph_replylesson that a wire test over an empty payload passes against a shim that drops everything.Not fixed here, deliberately
Whether the 30 s wall-clock backstop has enough headroom over legitimate worst-case input is a separate question and a supervision change, so it is not being decided as a side effect of this. I attempted to quantify the headroom and got it wrong: the whole test takes ~17 s idle, but under 2× CPU oversubscription it took 36 s and still passed, which proves the guest's share is well under the 17 s I first attributed to it. The honest statement today is that CI exceeded the bound and an idle machine does not, and the new witness field is what will settle the rest the next time it happens.
claim_domain_scalemoved ONE wall-clock ratio to#[ignore]and left its sibling live — the sibling is a FLOOR, which contention breaks in the direction a floor cannot survive #253read_codesays an empty body "PROVES the range does not exist" — but it proves it about the SERVER's tree, which is not the caller's when a worktree is in play #258