Repository navigation
test: drop the bounded polls, elapsed bounds and positive-path timeouts - #29
Closed
MarcoDotIO wants to merge 13 commits into
Closed
MarcoDotIO wants to merge 13 commits into
MarcoDotIO wants to merge 13 commits into
Conversation
anotherAgentsRunBeforeTheAckNeverHijacksTheIntent and preAckEventsOfTheAckedRunAreReplayed failed on main (CI run 36644330107, xcode-27 runner) with "Caught error: CancellationError()" after ~8 s; the same tree passed on PR #20. waitForSend polled the requester every 5 ms and threw once a 5 s ContinuousClock deadline passed. With ~3,150 Swift Testing tests saturating the cooperative pool, the host.send task (and the poller itself) did not run for more than 5 s, so the deadline expired although nothing in GatewayOpenClawIntentHost.send is slow. Blocking every cooperative thread for 6 s reproduces the failure locally. - OpenClawAppIntentsRunMatchingTests: HeldChatSendRequester yields each chat.send's params to an AsyncStream the moment the request arrives, and waitForSend awaits that stream. Assertions are unchanged. - GatewayNetworkConnectionTransportTests: the loopback NWListener start waits on stateUpdateHandler (ready/failed/cancelled) instead of polling listener.state against the same 5 s deadline, which also had no final re-check after a late wake-up. - WatchNodeClientTests: eventually() drops its 5 s deadline. Its conditions read production client state that has no change hook, so it still polls, but slowness no longer fails it. Each suite gains .timeLimit(.minutes(1)) for hang protection. Every wait ends on cancellation, so a time-limit overrun reports "Time limit was exceeded" instead of hanging. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
keepalivePingIsBoundedWhenNoPongArrives and handshakeTimeoutOptionBoundsTheWholeHandshake failed on PR #22's macOS job (Xcode 27) with `ContinuousClock.now - start < .seconds(5)` at ~5.7 s. A trivial test in the same window took 5.3 s, so the runner stalled; the timeouts under test were 50 ms and 100 ms. - keepalive ping: the socket never pongs, so the thrown URLError already proves the ping deadline ended the wait; a time limit catches a hang. - handshake option: the fallback budget is raised to an hour through _test_setConnectTimeoutSeconds, so a channel that ignored the 100 ms option would trip the time limit instead of finishing at the 30 s default. Checked with a scratch test that drops the option: it fails with "Time limit was exceeded" and does not hang. Both tests take .timeLimit(.minutes(1)) and pass while every cooperative thread is blocked for several seconds. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ot elapsed time issuedTokenPersistenceNeverBlocksTheChannelActor asserted the actor answered within 3 s while a token write waited on another connection's SQLite lock. A saturated test pool can stall the run for longer than that, and a time limit alone would miss the regression it guards (a write on the actor holds it for SQLite's 30 s busy timeout, less than the one-minute limit). The test now relies on ordering. It releases the lock only after the actor answers, so the token can reach disk only if the actor answered while the write was pending. A write on the actor fails with SQLITE_BUSY first, the token never lands, and the final wait trips the new suite time limit. The 200 ms sleep that let hello-ok reach the write is replaced by a DEBUG hook, _test_setDeviceTokenPersistenceStartedHandler, that fires on the actor just before the persistence hop. Once the hop starts, shutdown cannot stop it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… limit The three tests asserted wall-clock bounds (2 s, 5 s, 1 s) that a saturated test pool can overrun. Each now has a one-minute time limit instead, and each makes sure a regression ends on the limit's cancellation instead of hanging the run: - file fetch refuses a FIFO: a blocking open(2) never returns. The cancellation handler opens the FIFO's write end once to release it. - operationThatIgnoresCancellationStillTimesOut: the parked operation is a gate the test opens on cancellation (and afterwards), not a never-resumed continuation that a loser-joining race would wait on forever. - total deadline can fire before the session starts: URLSession's own timeouts move past the limit, so only the fetcher's zero-second deadline can end the fetch. The fetch is awaited through a no-deadline AsyncTimeout race, because a deadline lost before start would leave it unresumed even on cancellation. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…aits gatewayCoreWaitUntil gave up after 10 s (15 s at two call sites) and the ChatViewModelSessionActionTests helpers after 15 s. A pool stall adds to those waits, so they could time out even though the condition was about to hold. Both now wait until the condition holds or the test is cancelled. Every suite that uses them has a one-minute time limit. gatewayCoreWaitUntil records its GatewayCoreWaitTimeout as an issue before throwing, because Swift Testing drops errors thrown after a time-limit cancellation and the label says which wait hung. waitForForkStart awaits the gate's stream directly instead of racing it against a sleep. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
waitUntil gave up after 15 s (7, 10 or 30 s at five call sites). The macOS CI job runs about 3,150 tests in parallel and the cooperative pool stalls for 5 to 8 s at a time, so a wait could time out even though the condition was about to hold. waitUntil now polls until the condition holds or the test is cancelled, and the timeoutSeconds and now: parameters are gone (nothing injected a clock, and with no deadline there is nothing to measure). Every suite whose tests reach waitUntil, directly or through a file-local helper, has a one-minute time limit; ChatViewModelSessionActionTests already had one. On cancellation the helper records AsyncWaitTimeoutError as an issue before throwing it, because Swift Testing drops errors thrown after a time-limit cancellation and the label says which wait hung. No call site relied on the timeout: nothing expects AsyncWaitTimeoutError, no wait runs in a child task that the test cancels, and the one try? wait is cleanup in a catch block that rethrows. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…nnect tests ChannelAdaptersE2ETests.waitFor gave up after 15 s and only recorded an unlabelled expectation failure. reconnectFailureSchedulesAnotherAttempt polled against a 10 s deadline. A pool stall can outlast either one. waitFor now takes a label, polls until the condition holds or the test is cancelled, and records a WaitTimeout issue before throwing it. The reconnect loop polls until cancelled. The suite and the reconnect test each have a one-minute time limit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
OpenClawChatUITests had its own waitUntil that gave up after 1 s and returned false. On the macOS CI job for this PR, a pool stall of about 10 s ran past it: both view-model tests failed after about 12 s, and the bootstrap expectations that followed failed with them. The tests now call the shared deadline-free waitUntil with a label for each wait, and the suite has a one-minute time limit. The private helper is removed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…ay tests - ProviderStreamingCancellationTests polls with the shared deadline-free waitUntil under a one-minute suite time limit. Both request timeouts are now an hour, so a cancellation that never reaches the request fails as a hang instead of passing once the 60 s request timeout fires. - ModelRouterStreamingFallbackTests waits for the stream termination (and the two stream/generate starts) with waitUntil, under a suite time limit. - RealtimeTalkRelaySession._test_waitForStartupCancelled() drops its timeoutSeconds parameter. A closed session answers before any timer is armed; a zero timeout makes one that is not closed fail at once rather than after a 1 s wall-clock wait. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- A shared TestAsyncHelpers.swift replaces AgentLoopHardeningTests' waitUntil (500 x 10 ms, recorded an unlabelled issue and returned). It polls until the test is cancelled, then records and throws AsyncWaitTimeoutError(label:). - GatewayServerTestHarness.collect (5 s) and Recorder.waitFor (5 s) take a label and wait until the time limit. The one deliberate negative wait now uses frames(_:arrivingWithinMs:), which returns what arrived; the old helper returned [] whenever its timer won, so that assertion could never fail. - ChannelAdaptersLinuxSmokeTests.poll (15 s), the SIWC loopback-page wait (10 s), the automation run waits (10 s) and the MCP list_changed waits (3 s + 2 s) use waitUntil. - addingAJobWakesTheSleepingLoop pushes the scheduler's idle cap to an hour through the new DEBUG hook CronScheduler._test_setMaximumSleepSeconds, so a missed wake hangs instead of racing the 60 s cap against the time limit. - The MCP list_changed test uses an hour request timeout and drops its "< 1.5 s" elapsed assertion: a stall behind another request now hangs. - .timeLimit(.minutes(1)) is on the nine suites that reach these waits and had no limit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
#26 left three kinds of wall-clock bounds in the test waits. A stalled cooperative pool (5-8 s on the macOS CI job) could fail any of them. - Iteration-count sleep polls now use waitUntil, under a one-minute time limit. The Task.yield loops before negative checks, the sampler repetitions and the media teardown grace are kept. - Elapsed "< N s" asserts are replaced by what they stood for: error payloads that name the short deadline, kill checks, and a stalled server or run that outlives the time limit. Lower bounds and the synchronous cron search are kept. The throttle drop and delay checks use an hour-long window, so a stall between the two requests cannot let the window pass. - Positive-path product timeouts move past the time limit where the wait ends on cancellation (SIWC signIn, runtime.run). Waits that park on a continuation cancellation never resumes (runtime.wait, agent.wait, the brokers, A2ATaskStore, imsg) go through the new awaitCancellable(_:) with no timeout. - The stale-timer test retries until its first run beats its 200 ms timer. The run-id collision test holds its run on a gate instead of a 3 s sleep. The coalescing reporter test uses a frozen clock. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
6 tasks done
…d-elapsed-asserts
2 of 3 tasks
MarcoDotIO
added a commit
that referenced
this pull request
Oct 1, 2026
* test: wait for events instead of a 5 s wall-clock deadline anotherAgentsRunBeforeTheAckNeverHijacksTheIntent and preAckEventsOfTheAckedRunAreReplayed failed on main (CI run 36644330107, xcode-27 runner) with "Caught error: CancellationError()" after ~8 s; the same tree passed on PR #20. waitForSend polled the requester every 5 ms and threw once a 5 s ContinuousClock deadline passed. With ~3,150 Swift Testing tests saturating the cooperative pool, the host.send task (and the poller itself) did not run for more than 5 s, so the deadline expired although nothing in GatewayOpenClawIntentHost.send is slow. Blocking every cooperative thread for 6 s reproduces the failure locally. - OpenClawAppIntentsRunMatchingTests: HeldChatSendRequester yields each chat.send's params to an AsyncStream the moment the request arrives, and waitForSend awaits that stream. Assertions are unchanged. - GatewayNetworkConnectionTransportTests: the loopback NWListener start waits on stateUpdateHandler (ready/failed/cancelled) instead of polling listener.state against the same 5 s deadline, which also had no final re-check after a late wake-up. - WatchNodeClientTests: eventually() drops its 5 s deadline. Its conditions read production client state that has no change hook, so it still polls, but slowness no longer fails it. Each suite gains .timeLimit(.minutes(1)) for hang protection. Every wait ends on cancellation, so a time-limit overrun reports "Time limit was exceeded" instead of hanging. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test: bound lifecycle timeouts with a time limit, not a 5 s wall clock keepalivePingIsBoundedWhenNoPongArrives and handshakeTimeoutOptionBoundsTheWholeHandshake failed on PR #22's macOS job (Xcode 27) with `ContinuousClock.now - start < .seconds(5)` at ~5.7 s. A trivial test in the same window took 5.3 s, so the runner stalled; the timeouts under test were 50 ms and 100 ms. - keepalive ping: the socket never pongs, so the thrown URLError already proves the ping deadline ended the wait; a time limit catches a hang. - handshake option: the fallback budget is raised to an hour through _test_setConnectTimeoutSeconds, so a channel that ignored the 100 ms option would trip the time limit instead of finishing at the 30 s default. Checked with a scratch test that drops the option: it fails with "Time limit was exceeded" and does not hang. Both tests take .timeLimit(.minutes(1)) and pass while every cooperative thread is blocked for several seconds. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test: show the device-auth write leaves the actor free by ordering, not elapsed time issuedTokenPersistenceNeverBlocksTheChannelActor asserted the actor answered within 3 s while a token write waited on another connection's SQLite lock. A saturated test pool can stall the run for longer than that, and a time limit alone would miss the regression it guards (a write on the actor holds it for SQLite's 30 s busy timeout, less than the one-minute limit). The test now relies on ordering. It releases the lock only after the actor answers, so the token can reach disk only if the actor answered while the write was pending. A write on the actor fails with SQLITE_BUSY first, the token never lands, and the final wait trips the new suite time limit. The 200 ms sleep that let hello-ok reach the write is replaced by a DEBUG hook, _test_setDeviceTokenPersistenceStartedHandler, that fires on the actor just before the persistence hop. Once the hop starts, shutdown cannot stop it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test: bound the FIFO, AsyncTimeout and link-preview tests with a time limit The three tests asserted wall-clock bounds (2 s, 5 s, 1 s) that a saturated test pool can overrun. Each now has a one-minute time limit instead, and each makes sure a regression ends on the limit's cancellation instead of hanging the run: - file fetch refuses a FIFO: a blocking open(2) never returns. The cancellation handler opens the FIFO's write end once to release it. - operationThatIgnoresCancellationStillTimesOut: the parked operation is a gate the test opens on cancellation (and afterwards), not a never-resumed continuation that a loser-joining race would wait on forever. - total deadline can fire before the session starts: URLSession's own timeouts move past the limit, so only the fetcher's zero-second deadline can end the fetch. The fetch is awaited through a no-deadline AsyncTimeout race, because a deadline lost before start would leave it unresumed even on cancellation. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test: drop wall-clock deadlines from the gateway and session-action waits gatewayCoreWaitUntil gave up after 10 s (15 s at two call sites) and the ChatViewModelSessionActionTests helpers after 15 s. A pool stall adds to those waits, so they could time out even though the condition was about to hold. Both now wait until the condition holds or the test is cancelled. Every suite that uses them has a one-minute time limit. gatewayCoreWaitUntil records its GatewayCoreWaitTimeout as an issue before throwing, because Swift Testing drops errors thrown after a time-limit cancellation and the label says which wait hung. waitForForkStart awaits the gate's stream directly instead of racing it against a sleep. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test: drop the wall-clock deadline from waitUntil waitUntil gave up after 15 s (7, 10 or 30 s at five call sites). The macOS CI job runs about 3,150 tests in parallel and the cooperative pool stalls for 5 to 8 s at a time, so a wait could time out even though the condition was about to hold. waitUntil now polls until the condition holds or the test is cancelled, and the timeoutSeconds and now: parameters are gone (nothing injected a clock, and with no deadline there is nothing to measure). Every suite whose tests reach waitUntil, directly or through a file-local helper, has a one-minute time limit; ChatViewModelSessionActionTests already had one. On cancellation the helper records AsyncWaitTimeoutError as an issue before throwing it, because Swift Testing drops errors thrown after a time-limit cancellation and the label says which wait hung. No call site relied on the timeout: nothing expects AsyncWaitTimeoutError, no wait runs in a child task that the test cancels, and the one try? wait is cleanup in a catch block that rethrows. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test(e2e): wait without a wall-clock deadline in the channel and reconnect tests ChannelAdaptersE2ETests.waitFor gave up after 15 s and only recorded an unlabelled expectation failure. reconnectFailureSchedulesAnotherAttempt polled against a 10 s deadline. A pool stall can outlast either one. waitFor now takes a label, polls until the condition holds or the test is cancelled, and records a WaitTimeout issue before throwing it. The reconnect loop polls until cancelled. The suite and the reconnect test each have a one-minute time limit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test: drop the 1 s deadline from the chat UI view-model waits OpenClawChatUITests had its own waitUntil that gave up after 1 s and returned false. On the macOS CI job for this PR, a pool stall of about 10 s ran past it: both view-model tests failed after about 12 s, and the bootstrap expectations that followed failed with them. The tests now call the shared deadline-free waitUntil with a label for each wait, and the suite has a one-minute time limit. The private helper is removed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test: drop the wall-clock waits left in the provider and realtime relay tests - ProviderStreamingCancellationTests polls with the shared deadline-free waitUntil under a one-minute suite time limit. Both request timeouts are now an hour, so a cancellation that never reaches the request fails as a hang instead of passing once the 60 s request timeout fires. - ModelRouterStreamingFallbackTests waits for the stream termination (and the two stream/generate starts) with waitUntil, under a suite time limit. - RealtimeTalkRelaySession._test_waitForStartupCancelled() drops its timeoutSeconds parameter. A closed session answers before any timer is armed; a zero timeout makes one that is not closed fail at once rather than after a 1 s wall-clock wait. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test(linux): wait without a wall-clock deadline in the runtime tests - A shared TestAsyncHelpers.swift replaces AgentLoopHardeningTests' waitUntil (500 x 10 ms, recorded an unlabelled issue and returned). It polls until the test is cancelled, then records and throws AsyncWaitTimeoutError(label:). - GatewayServerTestHarness.collect (5 s) and Recorder.waitFor (5 s) take a label and wait until the time limit. The one deliberate negative wait now uses frames(_:arrivingWithinMs:), which returns what arrived; the old helper returned [] whenever its timer won, so that assertion could never fail. - ChannelAdaptersLinuxSmokeTests.poll (15 s), the SIWC loopback-page wait (10 s), the automation run waits (10 s) and the MCP list_changed waits (3 s + 2 s) use waitUntil. - addingAJobWakesTheSleepingLoop pushes the scheduler's idle cap to an hour through the new DEBUG hook CronScheduler._test_setMaximumSleepSeconds, so a missed wake hangs instead of racing the 60 s cap against the time limit. - The MCP list_changed test uses an hour request timeout and drops its "< 1.5 s" elapsed assertion: a stall behind another request now hangs. - .timeLimit(.minutes(1)) is on the nine suites that reach these waits and had no limit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test: drop the bounded polls, elapsed bounds and positive-path timeouts #26 left three kinds of wall-clock bounds in the test waits. A stalled cooperative pool (5-8 s on the macOS CI job) could fail any of them. - Iteration-count sleep polls now use waitUntil, under a one-minute time limit. The Task.yield loops before negative checks, the sampler repetitions and the media teardown grace are kept. - Elapsed "< N s" asserts are replaced by what they stood for: error payloads that name the short deadline, kill checks, and a stalled server or run that outlives the time limit. Lower bounds and the synchronous cron search are kept. The throttle drop and delay checks use an hour-long window, so a stall between the two requests cannot let the window pass. - Positive-path product timeouts move past the time limit where the wait ends on cancellation (SIWC signIn, runtime.run). Waits that park on a continuation cancellation never resumes (runtime.wait, agent.wait, the brokers, A2ATaskStore, imsg) go through the new awaitCancellable(_:) with no timeout. - The stale-timer test retries until its first run beats its 200 ms timer. The run-id collision test holds its run on a gate instead of a 3 s sleep. The coalescing reporter test uses a frozen clock. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * test: wait for agent runs without a positive-path timeout #29 left runtime.wait and agent.wait calls with 2-5 s timeouts in the agent gateway, session branch, loop, event stream and wire shape tests, and in the OpenClawKitTests stack, gateway server and registry tests. A stalled cooperative pool (5-8 s on the macOS CI job) can let that timer beat the run and turn a passing wait into a "timeout". Both waits park on a continuation that cancellation never resumes, so they now go through awaitCancellable(_:) with no timeout, under a one-minute time limit. OpenClawKitTests gets its own copy of the helper. The client-side request timeout on the SDK gateway test's agent.wait moves past the limit too. The intended short timeouts (timeoutMs 1 and 10) are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * docs(changelog): 2026.3.2 Date the release 2026-10-01 and move the ConfigBoxed and config-decode stack entries under it. Add a Tests section for the test-wait hardening (#22, #25, #26, #29, #30), the per-test synthesizer (#23), the reply clock (#27) and the stack-depth tests (#28), with the release test counts and CI gates. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Owner
Author
|
Landed on main in dca4976 via #31. #31's branch was main plus #30's head, and its squash-merge went in before this PR, so dca4976 carries this PR's changes and lists its commits. Merging this PR now would only add an empty commit, so I'm closing it as landed. Checked: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
#26 left three kinds of wall-clock bounds in the test waits:
for _ in 0..<Nsleep polls, elapsed-time asserts, and product timeouts used as positive-path bounds. This PR audits each listed site and converts the ones a stalled cooperative pool (5–8 s on the macOS CI job) could fail, using the pattern from #25/#26.Several product waits park on a continuation that only their own timer or the awaited event resumes, so cancellation never ends them:
EmbeddedAgentRuntime.wait(runID:), the gateway'sagent.wait,ApprovalBroker.waitDecision,QuestionBroker.waitAnswer,A2ATaskStore.wait,IMsgRPCClient.requestandSpotlightTimeoutRace. If a test drops the timeout on one of these waits, a regression can't show up as a hang, because the time limit can't end the wait. A newawaitCancellable(_ label:)in the LinuxTestAsyncHelpers.swiftruns the wait in its own task and awaits it through anAsyncStream. When the time limit cancels the test, the stream ends and the helper records and throws a labelledAsyncWaitTimeoutError. Tests call these waits through it with no timeout.1. Iteration-count polls
ApprovalQuestionBrokerTests:80, :138, :212waitUntil; suite time limitAgentRuntimeExtensionsTests:96, :111, :161, :171waitUntil; suite time limit, replacing two per-test limitsExecApprovalHardeningTests.firstPending(:11)waitUntil; suite time limitGatewayRunLifecycleTests:74waitUntil; suite time limitRuntimeIntegrationWiringTests:436waitUntil; suite time limitToolsGatewayMethodsTests:168waitUntil; suite time limitGatewayServerChatUICompatTests.FrameRecorder.wait(:47)waitUntil; suite time limit. It used to return the frames it had after 500 polls.CoreAIModelRuntimeTests:307waitUntil; per-test time limit. If the loop gave up early, the cancel could land before the first generation had started.VoiceNoteRecorderTests:362waitUntil(the suite already had a time limit)SystemStateReportingTests:201waitUntil; per-test time limit. The reporter now uses a frozenTestClock. With the real clock, a pause of 50 ms between the two synchronous reports would forward the second one at once, and the "held" assertion would fail.MediaPipelineTests.waitForHTTPServer(:424)Kept, on purpose:
GatewayNodeSessionRouteTests:239, :624:Task.yieldloops before negative checks ("no result is sent"). A slow runner can only make them weaker, never fail them.CoreAIModelRuntimeTests:209, :213: sampler repetitions, not waits.MediaPipelineTests:407: teardown grace period (SIGTERM, then SIGKILL after about 1 s, thenwaitUntilExit). It cannot fail a test.2. Elapsed-time asserts
MCPHardeningTests:377 (< 2, legacy SSE)MCPStdioTransportTests:94 (< 5, close escalates to KILL)kill(pid, 0) != 0afterclose()already proves the KILL.MCPStdioTransportTests:127 (< 3, close must not wait for a blocked write)sleep 3600instead ofsleep 5. A close that waited for the write would hang. A cancellation handler SIGKILLs the server, so the time limit ends that hang.SpotlightMemoryTests:96 (< 3, bounded writes)SpotlightTimeoutError(operation:seconds: 0.2), so the 0.2 s deadline is the one that fired.FakeSpotlightStorenow keeps the calls it stalls, andstopHanging()answers them on cancellation, so a write with no deadline fails at the time limit instead of hanging the run. Per-test time limit.SpotlightMemoryTests:242 (< 2, race doesn't join a stalled op)StallFlagends it, either at test end or on cancellation. Before, it spun on cancelledTask.sleepcalls for the rest of the process. The fast-path check uses a 1 h deadline throughawaitCancellable. Per-test time limit.GatewayRunLifecycleTests:46 (< 5, timedagent.wait)awaitCancellableturns that into a failure.AutomationHardeningTests:156 (< 1, cron search)ChannelAutoReplyTests:233 (>= 0.07)ModelRoutingTests:379 (>= 0.06)model.throttle.delaycheck next to it could fail, though: a stall of more than 70 ms between the two requests lets the window pass, so no delay happens. That check now uses a second router with a 1 h window. The held request emits the event (withdelayMsnear the window) and is then cancelled.The drop test in
ModelRoutingTests(:326) had the same exposure: a 1 s window, and the second request had to land inside it. The window is now 1 h. A drop never waits, so a longer window costs no test time.3. Product timeouts on positive paths
SignInWithChatGPTSessionTestssignIn(timeout: 20)×4Task.sleep, and the test browsers return once the listener stops.timeout: 3_600.timeout: 1in the timed-out case is the behaviour under test and is kept.ChannelAdaptersLinuxSmokeTestsA2AreplyTimeoutMs: 5_000A2ATaskStore.wait)A2AChannelConfig.replyTimeoutRangeMs.upperBound(10 min, the clamp) +awaitCancellableSubagentRuntimeHardeningTestsruntime.wait(timeoutMs: 10_000)×5awaitCancellable { runtime.wait(runID:) }.runtime.run(timeoutMs: 10_000)ends on cancellation, so it moves to 1 h.In the same files:
ApprovalQuestionBrokerTests:waitDecision/waitAnswer(timeoutMs: 2_000)andruntime.wait(timeoutMs: 2_000).AgentRuntimeExtensionsTests:run(timeoutMs: 10_000),wait(timeoutMs: 2_000 / 5_000).GatewayRunLifecycleTests: threeagent.wait(timeoutMs: 5_000).ChannelAdaptersLinuxSmokeTests: the imsgrequest(timeoutMs: 10_000).All of these go through
awaitCancellablewith no timeout. The 20 ms negativewaitAnsweris kept.Two tests had a wall-clock window that was not a wait:
aStaleTimerNeverCancelsANewRunWithTheSameID: the first run has to finish inside its own 200 ms timer. A stall let the timer win, the run reportedtimeout, and the test failed. The test now starts over with a fresh runtime until the first run finishes first; the time limit bounds a regression that never lets it.reusedIdempotencyKeysDoNotStartASecondRunUnderTheSameID: the run stayed in flight for a 3 s sleep while the duplicate sends were checked. It now waits on anAsyncGatethat the test opens after those checks.Not in this PR
The same positive-path pattern (
agent.wait/runtime.waitwith a 2–5 s timeout) remains in files outside the list:AgentGatewayMethodsTests,SessionBranchGatewayMethodsTests,AgentLoopToolCallingTests,GatewayEventStreamTests,GatewayWireShapeTests, and in OpenClawKitTestsEmbeddedAgentStackTests,GatewayServerTestsandGatewayServerRegistryTests. WithawaitCancellable, converting them is a mechanical follow-up. OpenClawKitTests would need its own copy of the helper.Stacked on #26 (→ #25 → #24). Merge those first; until then this diff also includes their commits. Only the last commit (ba41908) is new.
Test plan
swift build --build-testsScripts/lint-swift.sh: 0 violationsswift test --filterover the 18 affected suites: everything passes except the knownreplyCoordinatorRoutesRepliesToOneInvocationAtATimeflake, which failed 1 of 6 isolated Spotlight runs.swift test: OpenClawKitTests 3,150 tests, OpenClawLinuxRuntimeTests 582 and OpenClawKitE2ETests 20, all passing.activeProcessorCount * 2Task.detached(priority: Task.currentPriority) { usleep(6_000_000) }blockers, which stalls the pool for about 12 s.The hooks fired at each converted wait: at the start of
waitUntil, insideawaitCancellableafter the operation starts, and inline beforeconnect()/close()/ the Spotlight writes / the race, between the two throttled requests, and between the two coalesced reports. Each process ran one test and at most 3 stalls.All 36 converted tests pass, after 12–36 s, so every one of them was stalled.
Control, with the same stalls on the old code: all 8 fail.
elapsed < 2elapsed < 5elapsed < 3second.providerID == "secondary": the 1 s window had passedmodel.throttle.delayeventruntime.wait(timeoutMs: 10_000)returnedtimeoutagent.waittimeoutThe stale-timer retry was checked with a scratch 1 ms timer on the first attempt only: the first run reports
timeout, the loop starts over, and the test passes.Time limit was exceeded, plusTimeout waiting for: <label>where a helper is involved, and the run then ends:approval expiredagent.waitwith no timeout on a 1 h run:timed-out agent.wait returnedimsg ping answeredA2A task completed.drop:model.throttle.delay emittedlocal HTTP server answeringconnectionTimeoutMs: 3_600_000: the connect ends withCancellationError.writeTimeoutSeconds: .infinity:stopHanging()answers the calls, and the test reports "an error was expected but none was thrown".StallFlagends the operation, and the test reportsvalue == nil.CancellationError.🤖 Generated with Claude Code