-
Notifications
You must be signed in to change notification settings - Fork 1
Raise the blocking-rules poll timeout to outlast reachability triage #158
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
Ibrahimrahhal
wants to merge
1
commit into
main
Choose a base branch
from
raise-blocking-rules-poll-timeout
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+23
−5
Open
Changes from all commits
Commits
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -1057,8 +1057,12 @@ pub fn wait_for_scan(config: &Config, scan_id: &str, budget: WaitBudget) { | |
| } | ||
| } | ||
|
|
||
| /// Match doghouse `LICENSE_DEPS_WAIT_TIMEOUT` (15 minutes). | ||
| const DEFAULT_BLOCKING_RULES_TIMEOUT: Duration = Duration::from_secs(15 * 60); | ||
| /// Must outlast the longest doghouse wait window, currently | ||
| /// `SCA_REACHABILITY_WAIT_TIMEOUT` (30 minutes), with margin for the poll | ||
| /// interval and request latency. Whichever side's clock expires first decides | ||
| /// the outcome, and this side fails closed: expiring early would hard-fail a | ||
| /// pipeline on data doghouse was about to resolve as non-blocking. | ||
| const DEFAULT_BLOCKING_RULES_TIMEOUT: Duration = Duration::from_secs(35 * 60); | ||
| const BLOCKING_RULES_POLL_INTERVAL: Duration = Duration::from_secs(2); | ||
|
|
||
| fn stop_blocking_rules_spinner(stop_signal: &Arc<Mutex<bool>>, spinner: thread::JoinHandle<()>) { | ||
|
|
@@ -1122,7 +1126,7 @@ fn decide_blocking_rules_poll( | |
| } | ||
|
|
||
| /// Poll until blocking-rules status is `complete`, or `BLOCKING_RULES_TIMEOUT_ENV` | ||
| /// (15m by default) runs out. | ||
| /// (35m by default) runs out. | ||
| /// Older backends omit status (serde defaults to complete: one-shot). | ||
| /// `block_on` is forwarded as the CI rule-slug filter (`--block-on`); `None` | ||
| /// keeps legacy `--fail` "all active rules" behavior. | ||
|
|
@@ -1732,12 +1736,26 @@ mod tests { | |
| // The docs promise these two numbers; drifting from them silently is | ||
| // the failure mode worth catching. | ||
| assert_eq!(DEFAULT_SCAN_TIMEOUT, Duration::from_secs(10 * 60 * 60)); | ||
| assert_eq!(DEFAULT_BLOCKING_RULES_TIMEOUT, Duration::from_secs(15 * 60)); | ||
| assert_eq!(DEFAULT_BLOCKING_RULES_TIMEOUT, Duration::from_secs(35 * 60)); | ||
| assert_eq!(format_timeout(DEFAULT_SCAN_TIMEOUT), "10h"); | ||
| assert_eq!(format_timeout(DEFAULT_BLOCKING_RULES_TIMEOUT), "15m"); | ||
| assert_eq!(format_timeout(DEFAULT_BLOCKING_RULES_TIMEOUT), "35m"); | ||
| assert_eq!(format_timeout(Duration::from_secs(90)), "90s"); | ||
| } | ||
|
|
||
| #[test] | ||
| fn blocking_rules_timeout_outlasts_the_doghouse_wait_windows() { | ||
| // This side fails closed on its own deadline, so it must never expire | ||
| // while doghouse is still answering `pending`. The longest doghouse | ||
| // window is SCA_REACHABILITY_WAIT_TIMEOUT at 30 minutes. | ||
| let longest_doghouse_window = Duration::from_secs(30 * 60); | ||
| assert!( | ||
| DEFAULT_BLOCKING_RULES_TIMEOUT > longest_doghouse_window, | ||
|
Comment on lines
+1750
to
+1752
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. the local 30-minute literal cannot detect Doghouse timeout changes; could we label this as a local regression guard unless a shared or versioned contract is available? |
||
| "poll deadline {DEFAULT_BLOCKING_RULES_TIMEOUT:?} must outlast the \ | ||
| doghouse wait window {longest_doghouse_window:?}, or a pipeline \ | ||
| hard-fails on a rule doghouse was about to resolve" | ||
| ); | ||
| } | ||
|
|
||
| #[test] | ||
| fn budget_reports_what_is_left_and_then_nothing() { | ||
| let spent = WaitBudget::with_timeout(Duration::ZERO); | ||
|
|
||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
README.md:43andskills/corgea/SKILL.md:116still promise that--fail/--block-onwaits at most 15 minutes, while this line makes the shipped default 35 minutes. The mismatch is user-visible:package.json:20includesREADME.mdin the npm package, and operators sizing a CI job from that documented limit can now have the runner terminate the CLI before its own deadline. Please update both in-repo guides to35 minutesin this PR so the released CLI and its bundled documentation agree.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I agree with this finding and think it should be addressed.
high: Update user-facing timeout documentation to 35 minutes
The default blocking-rules timeout changes from 15 to 35 minutes, but the existing review identifies README.md and skills/corgea/SKILL.md as still promising a 15-minute maximum. That contract is now false and can cause CI jobs configured around it to terminate the CLI prematurely. Update both guides with this behavioral change.
Proof or reproduction: