Dependent pair with recipe PR recipe-maintainers/gitea#10 (upgrade 1.27.3-rootless → 28.0.0-rootless): !testme on that pair goes green only once THIS test PR is merged.
Diagnosis — stale test, not an upgrade regression (gitea PR #10, run #31): install/upgrade/backup/restore · lint all passed, and every other custom test passed; only test_lfs_roundtrip failed — inside the test's own post-restart wait loop, at test_lfs_roundtrip.py:192: TimeoutError: The read operation timed out in _api(live_app, "/version", ...).
The app itself was healthy (gitea's own /api/healthz + authed /api/v1/version served on a separate 28.0.0 deploy; see gitea-upgrade-2026-10-02.md §2b). Two compounding test bugs:
_api() let the timeout escape: it caught only HTTPError, so a urlopen(timeout=20) socket timeout raised out of the poll loop instead of being retried — the first slow request killed the restart poll itself. (The harness's own lifecycle.http_fetch is explicitly "never raising" for this reason.)
Hard-coded wait contradicting the recipe's declared readiness (tests/STYLE.md §5): fixed deadline = +120s poll of a fixed 20s request, while recipe_meta.py declares HTTP_TIMEOUT = 600; 28.0.0's first boot runs a longer migration window than 1.27.3.
Fix (wait/fixture only — assertions untouched, §3):
_api() is now never-raising, mirroring lifecycle.http_fetch: transient URLError/socket-timeout/OSError → (0, {})
so the bounded poll simply retries; request timeout stays 20s (per-request bound), the poll deadline is what bounds the wait.
Poll deadline derives from recipe_meta.HTTP_TIMEOUT (600) instead of a hard-coded 120;
probes the same /api/v1/version path that recipe_meta.READY_PROBE already declares.
Round-trip OID checks, the JWT-comparison assertions, and the final poisoned-token check are all unchanged.
Evidence:
Run #31 (PR #10): red ONLY in this poll; line 192 = the _api call, attribution above.
Latest upstream run at f675941+f675941 (bridge state, "NeighborDone original") — same state the pairs run against; the LFS test is green on base (2026-08-31) and run #31's failure is the poll, not the assertions.
Verification runs with the recipe PR head + this test change on the cc-ci host will be linked as a follow-up comment.
Dependency pair with recipe-maintainers/gitea#10: merge this first (or together), then re-run !testme on the recipe PR — it uses the deployed cc-ci tests, so it sees this change only after merge.
NOT merged — for operator review.
Dependent pair with recipe PR https://git.autonomic.zone/recipe-maintainers/gitea/pulls/10 (upgrade 1.27.3-rootless → 28.0.0-rootless): `!testme` on that pair goes green only once THIS test PR is merged.
**Diagnosis — stale test, not an upgrade regression** (gitea PR #10, run #31):
`install/upgrade/backup/restore · lint` all passed, and every other custom test passed; only `test_lfs_roundtrip` failed — inside the test's own *post-restart wait loop*, at `test_lfs_roundtrip.py:192`:
`TimeoutError: The read operation timed out` in `_api(live_app, "/version", ...)`.
The app itself was healthy (gitea's own `/api/healthz` + authed `/api/v1/version` served on a separate 28.0.0 deploy; see `gitea-upgrade-2026-10-02.md` §2b). Two compounding test bugs:
1. **`_api()` let the timeout escape**: it caught only `HTTPError`, so a `urlopen(timeout=20)` socket timeout *raised out of the poll loop* instead of being retried — the first slow request killed the restart poll itself. (The harness's own `lifecycle.http_fetch` is explicitly "never raising" for this reason.)
2. **Hard-coded wait contradicting the recipe's declared readiness** (tests/STYLE.md §5): fixed `deadline = +120s` poll of a fixed 20s request, while `recipe_meta.py` declares `HTTP_TIMEOUT = 600`; 28.0.0's first boot runs a longer migration window than 1.27.3.
**Fix (wait/fixture only — assertions untouched, §3):**
- `_api()` is now never-raising, mirroring `lifecycle.http_fetch`: transient `URLError`/socket-timeout/`OSError` → `(0, {})`
so the bounded poll simply retries; request timeout stays 20s (per-request bound), the poll deadline is what bounds the wait.
- Poll deadline derives from `recipe_meta.HTTP_TIMEOUT` (600) instead of a hard-coded 120;
probes the same `/api/v1/version` path that `recipe_meta.READY_PROBE` already declares.
- Round-trip OID checks, the JWT-comparison assertions, and the final poisoned-token check are all unchanged.
**Evidence:**
- Run #31 (PR #10): red ONLY in this poll; line 192 = the `_api` call, attribution above.
- Latest upstream run at f675941+f675941 (bridge state, "NeighborDone original") — same state the pairs run against; the LFS test is green on base (2026-08-31) and run #31's failure is the poll, not the assertions.
- Verification runs with the recipe PR head + this test change on the cc-ci host will be linked as a follow-up comment.
**Dependency pair** with https://git.autonomic.zone/recipe-maintainers/gitea/pulls/10: merge this first (or together), then re-run `!testme` on the recipe PR — it uses the *deployed* cc-ci tests, so it sees this change only after merge.
NOT merged — for operator review.
test_lfs_roundtrip's post-restart poll timed out on gitea 28.0.0 (PR #10 run #31):
_api() caught only HTTPError, so a single urlopen(timeout=20) socket timeout inside
the poll raised and aborted the poll itself instead of being retried; the poll also
hard-coded a 120s deadline + a 20s request timeout, contradicting the recipe's
declared HTTP_TIMEOUT=600 (tests/STYLE.md §5-sized for the warm custom tier; the
28.0.0 boot runs a longer migration window than 1.27.3).
Fix, assertion untouched (§3):
- _api() is never-raising like lifecycle.http_fetch: transient URLError/socket
timeout/OSError -> (0, {}) so the bounded poll simply retries (each request still
bounded at 20s; the poll's deadline is what bounds the wait).
- poll deadline derives from recipe_meta.HTTP_TIMEOUT (600) instead of a hard-coded
120, probing the same /api/v1/version path recipe_meta.READY_PROBE declares.
Evidence: gitea 28.0.0 dev deploy converged + served /api/healthz and /version
(gitea-upgrade-2026-10-02.md 2b); the RED run #31 failed only in this poll while
install/upgrade/backup/restore and every other custom test passed.
autonomic-bot
requested review from trav 2026-10-05 16:46:01 +00:00
autonomic-bot
requested review from notplants 2026-10-05 16:46:01 +00:00
Push build #33 (this branch) failed at the lint gate on failures inherited from
main, which block this PR from merging:
- runner/harness/warm.py: ruff format (long regex line — no code change)
- nix/modules/acme-dns.nix: statix W201 'avoid repeated keys' — fold the three
service definitions (acme-dns, cc-ci-acme-storage-seed,
cc-ci-acme-traefik-handoff) into one services = { ... } attrset. Pure
restructure: systemd.services eval of all three units is byte-identical to
main (nix eval --json diff, all three IDENTICAL).
scripts/lint.sh now: PASS.
Verification complete — GREEN. Full cold harness run on cc-ci (host, worktree cc-ci-verify-lfs @ e83cd46, this branch checked out) against the gitea PR head 91e42c8 (upgrade-28.0.0-rootless):
The previously-failing tests/gitea/custom/test_lfs_roundtrip.py::test_lfs_roundtripPASSED (20.96s) — including the forced restart + post-restart wait that timed out on run #31.
Regression sample: pytest tests/unit → 315 passed, 4 failed — the same 4 (test_dep_domain_distinct_per_dep, both test_meta key-count/doc-sync, test_no_head_version_skips_tag_lookup_uses_main) fail identically on deployed main (f675941), i.e. pre-existing and unrelated to this branch.
Also folded in: the two pre-existing lint failures that made the push self-test (build #33) RED on main were fixed on this branch so the gate is mergeable — ruff format on runner/harness/warm.py (no code change) and the statix W201 restructure of nix/modules/acme-dns.nix (all three affected systemd services eval byte-identical to main; push build #34success, scripts/lint.sh PASS).
Pair: recipe PR recipe-maintainers/gitea#10 — merge this first (or together), then re-!testme the recipe PR; it only sees this test change once merged into main.
NOT merged — for operator review.
**Verification complete — GREEN.** Full cold harness run on cc-ci (host, worktree `cc-ci-verify-lfs` @ e83cd46, this branch checked out) against the gitea PR head `91e42c8` (`upgrade-28.0.0-rootless`):
```
===== RUN SUMMARY =====
deploy-count = 1 (expect 1)
install : pass
upgrade : pass
backup : pass
restore : pass
custom : pass
results.json written: /var/lib/cc-ci-runs/manual/results.json (level=5 of 5)
```
The previously-failing `tests/gitea/custom/test_lfs_roundtrip.py::test_lfs_roundtrip` **PASSED** (20.96s) — including the forced restart + post-restart wait that timed out on run #31.
Regression sample: `pytest tests/unit` → **315 passed, 4 failed** — the same 4 (`test_dep_domain_distinct_per_dep`, both `test_meta` key-count/doc-sync, `test_no_head_version_skips_tag_lookup_uses_main`) fail identically on deployed `main` (f675941), i.e. pre-existing and unrelated to this branch.
Also folded in: the two pre-existing lint failures that made the push self-test (build #33) RED on `main` were fixed on this branch so the gate is mergeable — `ruff format` on `runner/harness/warm.py` (no code change) and the statix W201 restructure of `nix/modules/acme-dns.nix` (all three affected systemd services eval byte-identical to main; push build #34 `success`, `scripts/lint.sh` PASS).
**Pair:** recipe PR https://git.autonomic.zone/recipe-maintainers/gitea/pulls/10 — merge this first (or together), then re-`!testme` the recipe PR; it only sees this test change once merged into main.
NOT merged — for operator review.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Dependent pair with recipe PR recipe-maintainers/gitea#10 (upgrade 1.27.3-rootless → 28.0.0-rootless):
!testmeon that pair goes green only once THIS test PR is merged.Diagnosis — stale test, not an upgrade regression (gitea PR #10, run #31):
install/upgrade/backup/restore · lintall passed, and every other custom test passed; onlytest_lfs_roundtripfailed — inside the test's own post-restart wait loop, attest_lfs_roundtrip.py:192:TimeoutError: The read operation timed outin_api(live_app, "/version", ...).The app itself was healthy (gitea's own
/api/healthz+ authed/api/v1/versionserved on a separate 28.0.0 deploy; seegitea-upgrade-2026-10-02.md§2b). Two compounding test bugs:_api()let the timeout escape: it caught onlyHTTPError, so aurlopen(timeout=20)socket timeout raised out of the poll loop instead of being retried — the first slow request killed the restart poll itself. (The harness's ownlifecycle.http_fetchis explicitly "never raising" for this reason.)deadline = +120spoll of a fixed 20s request, whilerecipe_meta.pydeclaresHTTP_TIMEOUT = 600; 28.0.0's first boot runs a longer migration window than 1.27.3.Fix (wait/fixture only — assertions untouched, §3):
_api()is now never-raising, mirroringlifecycle.http_fetch: transientURLError/socket-timeout/OSError→(0, {})so the bounded poll simply retries; request timeout stays 20s (per-request bound), the poll deadline is what bounds the wait.
recipe_meta.HTTP_TIMEOUT(600) instead of a hard-coded 120;probes the same
/api/v1/versionpath thatrecipe_meta.READY_PROBEalready declares.Evidence:
_apicall, attribution above.Dependency pair with recipe-maintainers/gitea#10: merge this first (or together), then re-run
!testmeon the recipe PR — it uses the deployed cc-ci tests, so it sees this change only after merge.NOT merged — for operator review.
Verification complete — GREEN. Full cold harness run on cc-ci (host, worktree
cc-ci-verify-lfs@e83cd46, this branch checked out) against the gitea PR head91e42c8(upgrade-28.0.0-rootless):The previously-failing
tests/gitea/custom/test_lfs_roundtrip.py::test_lfs_roundtripPASSED (20.96s) — including the forced restart + post-restart wait that timed out on run #31.Regression sample:
pytest tests/unit→ 315 passed, 4 failed — the same 4 (test_dep_domain_distinct_per_dep, bothtest_metakey-count/doc-sync,test_no_head_version_skips_tag_lookup_uses_main) fail identically on deployedmain(f675941), i.e. pre-existing and unrelated to this branch.Also folded in: the two pre-existing lint failures that made the push self-test (build #33) RED on
mainwere fixed on this branch so the gate is mergeable —ruff formatonrunner/harness/warm.py(no code change) and the statix W201 restructure ofnix/modules/acme-dns.nix(all three affected systemd services eval byte-identical to main; push build #34success,scripts/lint.shPASS).Pair: recipe PR recipe-maintainers/gitea#10 — merge this first (or together), then re-
!testmethe recipe PR; it only sees this test change once merged into main.NOT merged — for operator review.