Skip to content

test: remove Rust duplication and timed settles (#194 Part 2) - #225

Draft
andersalm wants to merge 6 commits into
developfrom
fix/194-rust-test-cleanup
Draft

andersalm wants to merge 6 commits into
developfrom
fix/194-rust-test-cleanup

Conversation

@andersalm

@andersalm andersalm commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

The Rust suites spend time on repeated constructor, serialization and source-copy assertions, plus fixed waits in test fixtures. This change removes those duplicates, turns repeated behavior into table tests, and uses fixture readiness or virtual time for waits of one second or more. Every refused case remains covered. Production Rust behavior stays unchanged.

The draft starts from develop fe033fe. It shares the test-inventory commit with Part 1. The cleanup removes 122 listed test functions and consolidates duplicate groups, for a net reduction of 139 test attributes. Owner-controlled provider/bridge.rs and the canary workflows on fix/89-canary-inputs retain their existing contents.

Retained coverage:

  • Authority and refusal: Browser launch/unsafe exit/engine/URL cases share one labeled table; Shell denial covers all six action classes. Wallet managed recovery, intent binding, step-up and provider failure tests remain. The legacy Room route refusal remains executable. Successful Net HTTP dispatch to the internal Exit provider and actual reqwest IPFS gateway-path success remain, alongside their refusals. Operator expiry separately checks Tokio admission expiry and a manager-signed expired capability with live admission.
  • Wire and signatures: Runtime request/response compatibility, token signature verification, signed domain/provenance/tamper/wrong-CID tests and invalid DID decoding remain. Constructor and serializer echoes give way to these behavior checks.
  • Lifecycle: session registry, VM mapping, expiry, crash cleanup and pending request transitions remain. VZ locks and Browser/model child fixtures have bounded readiness and owned kill/reap/join cleanup, including assertion failure.
  • Product data: the complete cross-file provider runtime contract remains, including all 16 namespaces, Runtime-only scopes, install paths and public-gateway exclusion. One manifest icon inventory replaces three path pins and keeps the required service and Assistant/Elacity Player icons, app entrypoints, install and profile checks. Home command structure, aliases and PTY coverage remain; copy-only assertions are removed. Managed chat packaging and terminal exit inputs use tables with all previous cases.
  • Timing: expiry uses fixture timestamps or virtual time; real Carrier readiness precedes virtual deadline result checks, independent of pre-pause real latency. Both long regression cases get explicit CI timings with a 20-second failure bound, and the native VZ owner-death test runs on the hosted Mac after disposable hop cleanup.

Historical verification of the published candidate: 1e683d5, tree 74417fc6f6f68dc0d375039112079f5466d35e8c, has green CI37136248284, historical-head elastos-pr-review PASS and independent gpt-6.1-sol high development PASS. API and fetched PR heads match. Formatting, diff checks and the existing CI policy checks pass. All repair commits and prior review evidence stay in history. Release retains the local Mac heavy build slot. Rust diff SHA-256 27291570ddabf7ec5eb8449a58e6e7b2ea46ea3159f76aa636608c56409c544b. Hosted Apple Silicon CI executes all VZ package targets: 159 tests pass, with one existing ignored doc test. Exact-generation lock owner-death, child helper and symlink refusals execute successfully.

Hosted before/after proof uses cargo test -- --list in the same jobs. Job time includes checkout, tools and other checks; the test step includes compilation and execution. These observed runs vary with runner/cache state. Capsule jobs took longer than baseline, so this evidence establishes coverage and test inventory and keeps an overall speed claim open.

Candidate Workspace list Capsule list Total test-elastos job / test step test-capsules job / test step
Baseline 3,792 898 4,690 9m33s / 6m45s 9m59s / 9m39s
Part 1 3,792 898 4,690 12m19s / 9m13s 15m37s / 14m02s
Part 2 3,680 876 4,556 9m13s / 5m58s 15m24s / 13m47s

Source inventory has 139 fewer test attributes. Linux lists 134 fewer tests; the remaining five deletions are in the macOS-only VZ ffi module: balloon_device_constructs, dispatch_queue_constructs_without_panic, two_queues_are_independent, entropy_device_constructs and entitlement_hint_constant_points_at_day_4_script_and_docs. Actual presence and Carrier regression reruns each execute one case; wall times are 3.73s and 18.74s, test times 3.20s and 18.42s, with a separate 20s failure bound for each.

The independently inspected Mac receipt 11279616590 passes frozen install, plain Carrier check/apply/repeat, all 12 refusals, config/data/frozen-support preservation, four empty successful stderr streams, 17 clean holder outputs and empty owned cleanup. Install/check/apply/repeat take 1.978s/2.192s/2.007s/0.063s; 53 observer and 3 build processes stop, with zero M2 HTTP fallback. This disposable regression proof keeps #89 operator acceptance separate. Source df40dba/tree 415961c0736e34b40b1524a946c68f4aa7c75e8e matches the current PR merge against develop ad85c2e. Receipt JSON SHA-256 d82d63fe958c603041f2ce3c153e739638da8b08827fe750bbe1e0ce5ce7ce25; ZIP SHA-256 7bde3628262c1371995ea058bbbb1c8e5d7f07dc4e9ba965e590c236b7add804. Runtime N 0.7.1-dev SHA-256 a904580244fbb9b8baf85116beb4d3a44690857a5136777daa24804c4c7d4eb1; compiled N+1 0.7.2 SHA-256 2ae91a8c28880ab965037837ab4bf0899159d7231ee4e6b58998d80d17f5441d.

Historical acceptance gate: Anders's clarified #89 real-Mac acceptance: plain install.sh opens Home, the user creates an account and completes M2, with signed Carrier inputs after the initial binary. Current task merges require green checks, independent development and posted adversarial PASS with resolved findings; Irzhy follows up after merge. Part1 is merged, and the prepared normal integration preserves its data-checker replacement.

Remaining long child-command sleeps are cancellation, timeout or ownership subjects; tests kill and reap them instead of waiting for those sleeps to finish. Paused Tokio sleeps use virtual time. The last real 1.2s response delay now holds the first byte on a channel, proves the actual HTTP request arrived and preserves the 200ms backend-timeout refusal.

The gateway release path remains covered by test_release_binding_precedes_artifacts_check_and_same_version_on_both_transports: a real server serves only /release.json; request counters and matching check/same-version success detect any wrong client path.

The diff contains 122 listed deletion decisions, plus 22 old tests folded into tables. It removes 144 old named tests and adds five named tests: net 139 fewer test attributes.

Paths below use C/ for capsules/ and E/ for elastos/crates/. Echo, constructor, and copy rows had no independent behavior to replace; the coverage column identifies the retained meaningful checks where applicable.

File Removed listed functions Decision and retained coverage
C/browser-engine-adapter/src/tests.rs provider_bridge_default_config_initializes_empty Empty-constructor echo. Keep executable initialization, invalid configuration, dispatch, reconciliation, and cleanup cases.
C/decrypt-provider/src/main.rs status_advertises_blocked_raw_authority Static status JSON pin. Keep session refusal and receipt/input validation.
C/drm-provider/src/main.rs status_advertises_blocked_raw_authority, status_declares_canonical_open_sequence Static status JSON pins. Keep open_fails_closed_until_real_rights_key_and_decrypt_providers_exist, open_failure_declares_required_sequence, and request validation.
C/exit-provider/src/main.rs provider_bridge_default_config_initializes_empty Empty-constructor echo. Keep executable initialization, HTTP validation, and dispatch cases.
C/home-cli/src/tests.rs advanced_and_debug_help_keep_contract_commands_available, dashboard_commands_match_five_tabs_without_power_user_noise, first_run_help_matches_five_tabs_without_power_user_noise, home_cli_public_help_stays_plain_and_debug_keeps_authority_warning, home_screen_stays_compact, mywebsite_page_is_task_oriented_and_hides_space_roots, staged_site_summary_and_banner_stay_honest, system_tab_stays_short_and_actionable, tui_starts_at_tab_row_without_summary_header, tui_tabs_replace_redundant_banner Help, label, and layout-copy pins. Keep command parsing, actions, session transitions, and refusal tests.
C/ipfs-provider/src/main.rs test_cat_request_deserialization, test_init_request_deserialization, test_kubo_state_serialization, test_request_deserialization, test_response_serialization Derived-serde and constructor echoes. Keep test_request_accepts_runtime_invocation_metadata, test_request_still_rejects_unknown_fields, bounded read/range cases, and destination/source confinement refusals.
C/key-provider/src/main.rs status_advertises_blocked_raw_authority Static status JSON pin. Keep release refusal and evidence/input validation.
C/rights-provider/src/main.rs status_advertises_blocked_raw_authority Static status JSON pin. Keep access refusal and input validation.
E/elastos-guest/src/lib.rs test_capsule_info_default, test_version Incidental default and nonempty-version assertions. No independent behavior.
E/elastos-guest/src/runtime.rs test_envelope_serialization, test_request_serialization, test_response_serialization Own-serializer echoes. Keep runtime request/response behavior and Runtime control compatibility tests.
E/elastos-runtime/src/bootstrap/runtime_builder.rs test_runtime_accessors Calls getters without behavioral assertions.
E/elastos-runtime/src/bootstrap/shell.rs test_shell_config_default Incidental default. Keep bootstrap, duplicate bootstrap, stop, and CID refusal tests.
E/elastos-runtime/src/capability/policy.rs test_check_severity_serde, test_evidence_record_serialization, test_evidence_type_serde, test_grant_proposal_serialization, test_policy_decision_serialization, test_policy_outcome_display, test_proposed_constraints_default, test_turn_plan_serialization, test_verifier_check_blocking_vs_advisory Derive, display, and default echoes. Keep capability policy decisions, evidence validation, and the six-action Shell denial table.
E/elastos-runtime/src/capability/token.rs test_token_creation Constructor echo. Keep serialization/signature, tampering, resource matching, token identity, and hash-collision tests.
E/elastos-runtime/src/handler/protocol.rs test_envelope_roundtrip, test_error_response, test_request_serialization, test_response_serialization Derive and constructor echoes. Keep test_runtime_control_request_type_compatibility, test_runtime_control_response_type_compatibility, and test_capsule_kernel_abi_is_not_runtime_control_protocol.
E/elastos-runtime/src/primitives/audit.rs test_audit_event_serialization, test_audit_log_memory, test_policy_decision_made_event_serialization, test_policy_divergence_event_serialization, test_policy_event_type_names, test_policy_proposal_event_serialization Own-serializer/match-arm echoes and a no-assert memory-log constructor. Keep meaningful audit storage and policy behavior.
E/elastos-runtime/src/session/mod.rs test_session_creation Constructor echo. Keep session registry validation and lifecycle tests.
E/elastos-runtime/tests/http_api_integration.rs test_cleanup_dead_vm_sessions, test_create_capability_request, test_create_capsule_session_with_vm, test_create_shell_session, test_list_pending_requests, test_request_expiry_detection, test_shell_session_is_shell Duplicate registry/store paths. Retained equivalents: registry test_cleanup_dead_vm_sessions, test_vm_session_mapping, test_create_session, test_is_shell; pending test_create_request, test_list_pending, test_expired_request.
E/elastos-server/src/api/gateway_capsule_catalog/read_model.rs capsule_title_preserves_product_names Product-name copy pin.
E/elastos-server/src/api/gateway_home_system.rs request_notification_copy_names_the_requested_service Notification wording pin. Keep service request, approval, and authorization behavior.
E/elastos-server/src/api/gateway_tests/room.rs gateway_room_source_has_no_route_owned_resource_bridge Source-string guard. Retained replacements: configured_chat_rejects_every_legacy_control_and_guest_route_before_mutation checks 409 responses and unchanged store/attachment; test_chat_room_configured_send_uses_signed_home_authority_and_scoped_port checks scoped dispatch and changed-principal refusal; browser_room_cookie_capabilities_require_signed_home_admission checks admission.
E/elastos-server/src/api/gateway_tests/wallet/accounts.rs raw_wallet_account_dispatch_is_absent_from_production_routes Source-string guard. Account create/list/delete/rename/default cases call assert_v2_account_operations, which rejects retired raw operations and verifies Runtime invocation and authority. test_full_recovery_bundle_exports_and_restores_wallet_keys verifies typed Recovery Set export/import and authority; full_recovery_export_rejects_changed_intent_and_wrong_actor_before_effects preserves refusals.
E/elastos-server/src/api/gateway_tests/wallet/accounts.rs managed_recovery_key_routes_are_authority_bound_wallet_bus_v2_only Source-string guard. Retained test_wallet_recovery_key_requires_passkey_step_up, test_wallet_recovery_key_import_requires_passkey_step_up, test_managed_recovery_key_routes_reject_unverified_or_mismatched_intent_before_dispatch, and test_managed_recovery_key_routes_fail_closed_on_provider_errors. Wrong actor, substituted account/payload, stale token, and caller-supplied authority remain refused before dispatch.
E/elastos-server/src/api/gateway_tests/wallet/approvals_bus.rs approval_callers_use_wallet_bus_v2_while_deferred_paths_remain_explicit Source-string guard. Retained approval_routes_reject_caller_supplied_authority_before_wallet_dispatch and home_summary_queries_wallet_only_with_verified_home_authority; Inbox, managed-signing, and connector cases use assert_v2_approval_operations, rejecting every retired raw approval operation. Wallet send and Browser transaction tests preserve effect ownership, stale binding/hash substitution refusal, chain-evidence requirements, audit failure, and retry without rebroadcast.
E/elastos-server/src/carrier.rs test_gossip_message_serialization, test_gossip_message_with_signature, test_requested_gossip_nonce_prefers_explicit_value, test_requested_gossip_ts_prefers_explicit_value, test_topic_hash_deterministic Serializer, field-preference, and determinism echoes. Keep real gossip delivery, signed availability, wire bounds, replay/cursor/ack refusals, and test_topic_hash_matches_distributed_topic_tracker_topic_id.
E/elastos-server/src/chat_cmd.rs explicit_connect_uses_direct_join_mode, native_chat_exit_hint_is_explicit_for_home_launch, native_chat_exit_hint_is_explicit_for_terminal_launch, source_seed_uses_direct_join_mode Constant mode mappings and exit-hint wording. Keep direct connection behavior and the input behavior table below.
E/elastos-server/src/config_cmd.rs render_config_show_marks_empty_file, render_config_show_preserves_non_empty_contents Display/copy echoes. Keep configuration parsing and validation.
E/elastos-server/src/home_cmd.rs blocked_local_site_notice_explains_preview_prereq, blocked_local_site_notice_explains_stage_step Notice wording pins. Keep site stage/preview prerequisites and action behavior.
E/elastos-server/src/notifications.rs contact_request_notification_explains_the_people_consequence_only Notification wording pin.
E/elastos-server/src/operator_control.rs supported_actions_include_update_apply Static action-list pin. Keep operator action authorization and execution checks.
E/elastos-server/src/publish.rs test_discover_available_capsules_reads_workspace_layout Checkout-layout pin. Discovery implementation remains; remove its newly unused test-only wrapper.
E/elastos-server/src/runtime_control.rs managed_runtime_lane_conflict_mentions_gateway_when_gateway_owns_home, managed_runtime_lane_conflict_mentions_operator_lane_when_serve_owns_home Conflict-message wording pins. Keep ownership conflict and lifecycle behavior.
E/elastos-server/src/setup.rs assistant_capsule_is_packaged_with_a_capsule_owned_icon, elacity_player_capsule_is_packaged_with_a_capsule_owned_icon, service_provider_capsules_are_packaged_with_capsule_owned_icons Consolidate into declared_capsule_icons_exist_in_each_manifest_directory: require icons for the original 11 service providers and Assistant/Player, check declared assets, Assistant/Player entrypoints, install paths, and profile memberships.
E/elastos-server/src/setup.rs test_missing_manifest_message_mentions_source_checkout, test_missing_trusted_source_error_mentions_source_add, test_normalize_profile_name_preserves_home_profile Error wording and identity-mapping pins. Keep manifest/trusted-source validation and profile setup behavior.
E/elastos-server/src/shares.rs test_channel_head_domain_differs_from_provenance, test_empty_catalog_deserializes, test_encode_decode_did_key_roundtrip, test_full_catalog_roundtrips, test_share_entry_with_content_digest, test_sign_payload_deterministic, test_sign_payload_domain_separation, test_sign_payload_output_shape Serde, self-signing, and output-shape echoes. Keep test_provenance_domain_separator_prevents_reuse, channel-head signature/tamper/wrong-signer validation, and release-envelope valid/wrong-DID/tamper/wrong-domain cases.
E/elastos-server/src/supervisor.rs test_content_fetch_via_provider_uses_content_contract, test_supervisor_request_serialization, test_supervisor_response_error, test_supervisor_response_ok Mock echo and serializer/constructor echoes. Keep test_content_fetch_via_provider_surfaces_provider_error, artifact provenance checks, and stop/wait/reap retry-ownership tests.
E/elastos-server/src/update.rs test_fetch_release_manifest_via_gateway_uses_release_json_path Duplicate HTTP path coverage. Retained test_release_binding_precedes_artifacts_check_and_same_version_on_both_transports serves only /release.json, checks gateway/CID request counters, requires matching-release success, and refuses changed bytes/binding before artifact fetch.
E/elastos-storage/src/mutable/mod.rs test_dir_entry_serialization, test_entry_type_serialization Derived-serde echoes. Keep mutable storage operations and validation.
E/elastos-vz/src/config.rs from_manifest_default_boot_args_use_hvc0, from_manifest_remains_infallible_for_unvalidated_callers, vm_config_initramfs_path_defaults_to_none_from_manifest, vm_config_limits_default_matches_documented_constants, vm_config_with_initramfs_path_sets_the_field, vz_config_default_paths_under_local_share_elastos, vz_config_with_kernel_path_overrides, vz_config_with_prune_orphans_on_startup_round_trip Weak duplicate, incidental defaults, setter echoes, and a pin of absent validation. Keep from_manifest_emits_hvc0_console_for_microvm, session boot arguments, resource-limit refusal tests, and guest-kernel validation.
E/elastos-vz/src/ffi/balloon.rs balloon_device_constructs Constructor without behavioral assertion.
E/elastos-vz/src/ffi/dispatch.rs dispatch_queue_constructs_without_panic, two_queues_are_independent Bare no-panic constructors.
E/elastos-vz/src/ffi/entropy.rs entropy_device_constructs Constructor without behavioral assertion.
E/elastos-vz/src/ffi/lifecycle.rs entitlement_hint_constant_points_at_day_4_script_and_docs Literal documentation-path pin. Keep executable lifecycle/ownership checks.
E/elastos-vz/src/lib.rs carrier_guest_device_path_constant_is_hvc1, unavailable_message_is_single_source_of_truth Constant equality and message wording.
E/elastos-vz/tests/smoke.rs is_supported_reports_bool_without_panicking, network_config_new_is_deterministic_and_shape_compatible, vz_provider_constructable_with_defaults, vz_provider_supports_only_microvm Bare boolean construction, duplicate network shape, and duplicate provider construction/type checks. Keep provider unit tests including vz_provider_supports_microvm_only, typed non-microVM refusal, unloaded-handle lifecycle refusal, and network tests. The remaining is_supported import has the same platform gate as its assertion.
E/elastos-wallet-contract/src/lib.rs wire_contract_constants_are_exact Constants compared with identical literals. Keep executable Wallet wire encoding/decoding and validation.

The following 22 old functions become tables, separate from the 122 deletion decisions:

File Old functions Retained table
E/elastos-runtime/src/capability/policy.rs test_shell_denies_read_action, test_shell_denies_write_action, test_shell_denies_execute_action, test_shell_denies_message_action, test_shell_denies_delete_action, test_shell_denies_admin_action test_shell_denies_all_action_classes: all six refusal actions remain.
E/elastos-runtime/src/capability/token.rs test_token_base64 Existing test_token_serialization now covers bytes and base64, including preserved signature.
E/elastos-server/src/api/gateway_browser_route_tests.rs test_browser_open_requires_explicit_launch_contract, test_browser_open_rejects_mismatched_launch_contract, test_browser_open_rejects_non_http_urls, test_browser_open_rejects_unsafe_engine_adapter_id, test_browser_open_rejects_unsafe_remote_exit_id test_browser_open_refuses_invalid_launch_contracts: labeled payload/status/error rows preserve refusals.
E/elastos-server/src/chat_cmd.rs tty_loop_escape_returns_true, tty_loop_home_returns_true, tty_loop_quit_returns_false, tty_loop_ignores_leading_newlines_before_home, tty_loop_ignores_leading_newlines_before_quit tty_loop_handles_exit_inputs: all five input/result cases remain.
E/elastos-server/src/home_cmd.rs chat_action_launch_uses_managed_native_when_focus_chat_missing, chat_action_launch_uses_managed_native_when_fullscreen_chat_is_not_packaged, chat_action_stays_native_even_when_fullscreen_chat_prereqs_are_present, chat_action_stays_native_when_focus_chat_missing, chat_action_stays_native_when_fullscreen_chat_is_not_packaged chat_action_uses_managed_native_with_each_packaging_state: packaging-state and action cases remain.

Explicit retained exceptions:

  • provider_runtime_contract_covers_exact_active_provider_set remains intact: cross-file scopes, runtime_only, paths, helper exclusion, and public-gateway model exclusion.
  • test_browser_net_http_hands_validated_request_to_internal_exit_provider and test_fetch_cid_via_gateways_uses_ipfs_path remain as actual success-path checks.
  • Required icons, Assistant/Player entrypoints, and profile memberships remain covered by the generic inventory.
  • Every audit S2 case present at fe033fea remains. Three stale audit names were already absent from that base; all four existing grouped Shell-manager cases remain.
  • Long child-command sleeps remain cancellation/timeout/owner-death fixtures. Intentional real-time Rust test sleeps ≥1s are removed; virtual-time sleeps retain deadline coverage.

Prepared normal integration ancestor is 92a3b2e0eb2d2a71672efbd376ce570cd2c17a19 / tree 4543b18e4af2201f64d794d339b394b59ad33a92, a normal merge with parents7ccd1d5d and merged Part1/current develop3ce5f369. One modify/delete conflict retains Part1’s deletion of the obsolete Home text checker; Part2 had only removed stale source/test literal pins from that script. Incoming product code, unified Node behavior tests, product-data and actual-ref pre-push gate retain their integrated history. Workflow differences versus current develop are nine existing Part2 additions: bounded regression timings and native VZ unit coverage; Cargo caches stay. That ancestor was clean, origin0/58, while public PR225 remains1e683d5f. Diff and both Rust format gates pass. Independent high integration and bounded local Opus PASS the exact92 ancestor; all review processes ended. Current local Opus, actual-ref full pre-push gate, publication, posted adversarial review and hosted CI remain. Irzhy follows up after task merge under Anders's corrected rule; explicit operator acceptance remains. First merged-develop timing is GREEN39m31s, above38m by1m31s; #194 still requires three consecutive green develop runs at or below38m. Historical timings establish test inventory and scope.

Refs #194.

Current clean prepared head is 5db8143ff262ac26b5e06f50e0ba33b9b5b2c613, tree c68247048619e65dc5e1643c6815fb32f4e192ae, origin0/61. It appends only CI cache scope over reviewed92: the exact23 Mac receipt freshness lines from publishedPR227 and a command-scoped environment reset so native VZ unit tests use the existing general Cargo cache. The accepted Mac block runs after cache restoration and binds N/N+1 intermediate lineage to their receipt. All other source/job/cache bytes remain. The same independent high source round PASS;19CI policy cases and diff checks PASS, and both Rust format gates retain unchanged-source PASS. Bounded current local Opus PASS84.568s; output hash/source match and all owned review groups ended; actual-ref full pre-push verification, publication, current posted review and hosted binary/timing admission follow. This source evidence establishes composition; actual receipts establish compiled binary acceptance.

Current actual-ref gate correction

The current actual-ref gates refused publication at the manual adapter Default and three model argument-count style errors. Append-only corrections preserve RuntimeNetOnly and add three function-local lint allowances at existing transport/worker boundaries. Scoped all-target Clippy, format and existing tests pass: two adapter configuration cases and all35model adapter cases. Independent high and local Opus PASS cover both corrections; all repair/review processes ended. Prepared candidate5db8143f remains clean, origin0/61; publichead stays historical. The next full actual-ref gate refused publication at the15%disk reserve; all owned processes ended. Authorized headroom restoration precedes the next gate/push. Current posted review and hosted CI follow. Exact source/cause/hash/cleanup evidence stays in #194.

@andersalm

andersalm commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor Author

Independent gpt-6.1-sol high development round PASS on 1e683d5 / tree 74417fc6f6f68dc0d375039112079f5466d35e8c; origin divergence 0/0.
Rust diff SHA-256 27291570ddabf7ec5eb8449a58e6e7b2ea46ea3159f76aa636608c56409c544b preserves every refusal, provider authority, Net/IPFS success, required icons/entrypoints and actual /release.json transport coverage; net 139 fewer test attributes.
The same round repairs the final 1.2s first-byte fixture with owned request/release channels, bounds partial reads, removes an unused cfg(test) Home wrapper and checks the socket receipt after worker join. Formatting, source checks, CI policy 19 tests and diff checks pass.
Current CI37136248284 owns Rust/count/timing/Mac proof; renewed current-head Opus is running. The prior Rust workspace passed, listing 3,680 tests; explicit presence/Carrier tests took 2.26s/18.38s, with current reruns now enforcing 20s each.
Merge waits for #89 real-Mac M2 and required checks/reviews. Long child-command sleeps remain bounded cancellation/timeout subjects; intentional elapsed test waits use readiness or virtual time.

@andersalm

Copy link
Copy Markdown
Contributor Author

Independent adversarial review (Claude Opus via elastos-pr-review, 2026-10-03), head ad7209d.
VERDICT: FAIL

Blocking findings:

  • elastos/crates/elastos-server/src/setup.rs:4082: the PR deletes provider_runtime_contract_covers_exact_active_provider_set but files it under "one manifest icon inventory replaces three path pins". It is not an icon test. It is the only executed check of the provider authority scopes in components.json. It checks the exact set of providers and their provides values against each capsule's capsule.json, that runtime_only is set only for the custody, media and protected-content providers, the bin/<name> install paths, that helpers have no provider_runtime, and that public-gateway does not install model-provider. Nothing at this head replaces it. Production does not check that the two provides values match. source-home-provider-inventory-smoke.py covers 5 providers and no CI step runs it. The Part 1 lint is not in this tree. The new icon test also drops the checks that the Assistant and Elacity Player capsules are in each profile. Issue CI and tests: warm caches, fail fast, keep only what catches real bugs #194 Part 2 requires the PR to name the test that still covers each deleted behavior. Fix: point to the Part 1 lint check that covers these cases, or keep the cross-file checks as a data test.

Non-blocking notes:

  1. gateway_browser_route_tests.rs:~7494: the only success-path test of Browser Net HTTP to the internal Exit provider is deleted. Only refusal tests remain for /api/provider/net/http.
  2. carrier.rs:11619-11623: the 1 s deadline starts in real time before pause(). Real time spent on the Carrier round trip adds to the 950 ms virtual advance, so !fetch.is_finished() can flake on a slow CI runner. Assert the deadline result only.
  3. In the operator expiry case (gateway_browser_route_tests.rs:8892), virtual time expires only the tokio-based admission record. The capability token's wall-clock expiry is no longer exercised. The outcome is the same, but the coverage is narrower.

Not checked: I did not run any tests or CI, so the claimed timings, test counts and passes are unverified. I could not see the Part 1 lint or the gist of delete candidates, and I did not run the macOS VZ job.

@andersalm

Copy link
Copy Markdown
Contributor Author

Independent adversarial review (Claude Opus via elastos-pr-review, 2026-10-03), head 6e76726.
VERDICT: FAIL

Blocking findings:

  • elastos/crates/elastos-vz/tests/smoke.rs:24,77-80: The PR deletes is_supported_reports_bool_without_panicking, which was the only test that used is_supported on every platform. The one remaining use sits behind #[cfg(not(all(target_os = "macos", target_arch = "aarch64")))]. On Apple Silicon the import is therefore unused, and RUSTFLAGS="-D warnings" (ci.yml:34) and just lint / just verify (clippy --all-targets -- -D warnings, justfile:140,177) turn that warning into a build error. CI does not catch it: Linux clippy uses the import, and the new macOS step builds only --bin browser-vz-engine-supervisor. Fix: put the same cfg on the import, or remove the gate around the assertion.

Non-blocking notes:

  1. update.rs: The deleted test_fetch_cid_via_gateways_uses_ipfs_path was the only client test of the /ipfs/<cid> path, which is still used at release_cmd.rs:93. A wrong URL would still fail closed through the hash check, but nothing now detects that break. The /release.json gateway path is still covered by the binding test at update.rs:2352.
  2. setup.rs: The new icon inventory only checks icons that a manifest declares. The 11 service providers are no longer required to declare an icon, and the Assistant and Player entrypoint checks are gone.
  3. The new macOS debug test build, the rerun of two tests and the two listing steps add CI time, which works against CI and tests: warm caches, fail fast, keep only what catches real bugs #194's 38-minute goal.

The refused cases I traced still have behavior tests: Browser launch table, Shell's six action classes, operator capability-expiry fixture, configured-Room 409s, Wallet recovery step-up and intent, release envelope domain, tamper and wrong-DID, VM session crash cleanup.

Not checked: I did not compile or run anything; the PR says hosted CI is still pending. I also did not check the gist's per-test coverage list, whether iroh/quinn timers stay stable under the paused Tokio clock, or whether macOS clippy passes on develop today.

@andersalm

Copy link
Copy Markdown
Contributor Author

Independent adversarial review (Claude Opus via elastos-pr-review, 2026-10-03), head c100ac6.
VERDICT: PASS

Blocking findings: none.

Production behaviour is unchanged. The only addition is BrowserOperatorService::expired_capability_fixture (gateway_browser_operator.rs:32-63), and it is #[cfg(test)]. The refused cases are kept as labelled tables:

  • Browser launch contract, unsafe exit and adapter IDs, and non-HTTP URLs.
  • Shell denial for all six action classes.
  • Bounded-fetch deadline, now with virtual time; carrier.rs:7813 uses tokio::time::timeout, so these tests would still fail without the protection.
  • Operator admission expiry, plus a new case for an expired signed capability.

The removed tests that scanned source text are backed by behaviour tests:

  • Wallet: accounts.rs:587,751,846,995.
  • Signature domains: shares.rs:910,1282.
  • Provider role: manifest.rs:564-570 and setup.rs:4195.

No script, workflow or Markdown file names a deleted test.

Non-blocking notes:

  1. The test of the release.json path is deleted without a replacement. That path is the --gateway update override (update.rs:338, called at :944). The fetched bytes are still signature- and binding-checked, so this is a coverage gap, not a bypass.

  2. The ci.yml:241-245 "time bounded regression cases" step only prints times with /usr/bin/time -p. It does not fail when a test passes the CI and tests: warm caches, fail fast, keep only what catches real bugs #194 limit of 20 seconds.

  3. Several fixtures now wait forever instead of exiting on their own after 30 s, 60 s or 1 h:

    • test_support.rs:136,140 (threading.Event().wait())
    • the VZ lock child (thread::park loop)
    • supervisor.rs

    If the test process is killed abnormally, these children are orphaned with no bound. Also, tests.rs reads received before the worker thread is joined, which is a small source of flakiness.

Not checked: I could not compile or run any test, so I have no CI results for c100ac6, including the new macOS cargo test -p elastos-vz step. The list of 122 deleted tests with their covering tests (the #194 coverage gate) is not in pr.md. I did not check the #89 M2 merge gate or the before and after counts from cargo test -- --list.

@andersalm

Copy link
Copy Markdown
Contributor Author

Independent adversarial review (Claude Opus via elastos-pr-review, 2026-10-03), head 1e683d5.
VERDICT: PASS

Blocking findings: none.

The diff changes only test code, #[cfg(test)] helpers, CI steps and scripts/home-entropy-check.mjs, so production behavior stays the same. I checked that the refused cases the PR deletes or merges are still covered:

  • Browser open launch-contract, path and URL refusals are in one table: gateway_browser_route_tests.rs:1042.
  • All six Shell deny action classes are still tested.
  • The Room source scan is replaced by an executable test that sends legacy Room requests to a configured gateway: gateway_tests/room.rs:1119+.
  • Behavior tests for Wallet recovery-key export and import, step-up and mismatched intent remain: wallet/accounts.rs:587,751,846.
  • Release-envelope wrong-domain, wrong-DID and tamper tests remain, as do provenance domain-reuse and wrong-CID tests (shares.rs:854-1282).
  • test_cleanup_dead_vm_sessions is still in session/registry.rs:420.
  • /release.json is covered at update.rs:2300.

The admission-expiry check reads tokio::time::Instant (gateway_browser_operator.rs:19), so the virtual-time advance really expires it. No deleted test name is still referenced in scripts, docs or workflows.

Non-blocking notes:

  1. ci.yml:244-245: the filters are substring matches without --exact. If a test is renamed, 0 tests run and the step still passes. cargo test -p elastos-server may also recompile because features resolve differently than in the workspace run, which can break the 20 s bound.
  2. supervisor.rs:~2188: the success-path test for the content provider (test_content_fetch_via_provider_uses_content_contract) is deleted and only the error case remains. A wrong decode would still be refused by the SHA-256 check, but the success path is no longer tested.
  3. collaboration_presence.rs:1314: the capacity test now writes MAX-1 records straight to the stored state. Only the last record goes through project().

Not checked: I did not run any tests or read any CI or macOS VZ job results; I read source and the diff only. Also not checked: before/after cargo test -- --list totals, the full 122-test coverage list (the PR description is truncated), and the 20 s timings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant