test(daemon): age the stuck-probe sample from the sampler's time - #11
Merged
Merged
Conversation
…-C03) The pull_request run of aff986c failed once on the hosted macOS 14 runner, in the native host evidence step; the push run of the same head passed. The stuck-probe test asserted that admission stayed open no more than 6000 ms after last_read, the time its scripted probe records just before a read returns. The controller ages a sample from sample.at instead, which the sampler takes after the read has returned so that an age is never understated. sample.at is therefore never earlier than last_read, and a 20 ms poll that fell between the two thresholds saw a correct controller still open and failed the assertion. Take the reference from the first sample's pressure receipt, which carries the same sample.at the controller stores. So that this sample is the last one completed, the scripted probe now blocks its third read by count (baseline, first sample, then the stuck read) instead of blocking whichever read follows a store, and the test waits for that read to begin rather than sleeping 2300 ms. Both bounds and the other checks are unchanged; the two bound assertions now print their values. With a 40 ms pause inserted between the probe's timestamp and the sampler's, the old test failed 3 of 3 at this assertion and the new test passed 3 of 3. With the freshness limit changed to 5900 or 6100 ms, the new test failed 3 of 3 each; that instrumentation is not committed. The test then passed 30 of 30 runs, devguard-daemon's 41 library tests and scripts/qualify.py dg1-probes once, with rustfmt and Clippy for the crate clean, on Rust 1.95.0 with one Cargo job and one test thread. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This was referenced Sep 27, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Test-only fix for a false failure of
server::tests::native::a_stuck_probe_does_not_hold_the_authority_and_its_delay_closes_admission(DG1-C03). No product code changes.Failure
aff986cc83623d0a1c0521771964da1346e6c094), jobcontracts (macos-14), step "Native host evidence functional checks", stageservice-sampling:assertion failed: last_open - last_read <= 6_000atcrates/daemon/src/server.rs:2854.Cause
last_read, which the scripted probe records insideread()before returning.sample.at, whichSampler::sampletakes after the read returns ("so its age is never understated"), and stores as its last sample (PressureController::observe). Admission closes whennow - sample.at > 6_000.sample.at >= last_read, and the upper-bound assertion assumed they were equal. Whenever they differed by a millisecond or more and a 20 ms poll fell betweenlast_read + 6_000andsample.at + 6_000, a correct controller was reported as late. The lower-bound assertion cannot fail this way.Change
sample.at, read from itspressurereceipt, which carries the same value the controller stores.<= 6_000open,> 6_000closed), the lock check, the "closed before the stuck read returned" check and the slow-read and recovery checks are unchanged. The two bound assertions now print their values.Verification
Rust 1.95.0, one Cargo job, one test thread (
CARGO_BUILD_JOBS=1,RUST_TEST_THREADS=1), macOS arm64.cargo test -p devguard-daemon --lib --locked: 41 passed.python3 scripts/qualify.py dg1-probes: passed (service-sampling 2/2).cargo fmt --all -- --check,cargo clippy -p devguard-daemon --all-targets --locked -- -D warnings,git diff --check: clean.Not run locally
scripts/validate.pyand workspace-wide Clippy (host memory was tight); both run in this PR's CI on macOS and Ubuntu.Rollback
Revert this commit; it touches one test module only.
Handoff (session of 2026-09-27)
docs/handoff/2026-09-27-session-close.md). CodeSpace tracker: Handoff: CS-RG managed-execution suspension (#75) and the DevGuard boundary revalidation (2026-09-27) CodeSpace#76; CodeSpace note: docs: record the CS-RG suspension handoff note CodeSpace#77.2bbe7c5ed88ad3170bc76985bdecb1fd7434d501, CLEAN, not merged. Merging needs the owner's approval of this exact head (merge track in Handoff: CS-RG hold, boundary revalidation and pending owner approvals (2026-09-27) #14).