Skip to content

test(uds): drive the O and Q expired-deadline tests on a virtual clock - #190

Merged
dborgards merged 1 commit into
mainfrom
claude/pensive-wozniak-ivbwba
Sep 28, 2026
Merged

dborgards merged 1 commit into
mainfrom
claude/pensive-wozniak-ivbwba

Conversation

@dborgards

Copy link
Copy Markdown
Owner

What does this change?

Part of #171. Two tests in UdsExpiredDeadlineTests asserted a lower bound on the wall-clock gap between two sends, with only a 5 ms margin:

  • O_A_Suppressed_Send_Cancelled_Before_Confirmation_Still_Opens_Its_Window
  • Q_A_Stray_Pending_From_Before_The_Handoff_Still_Moves_Its_Services_Window

Q is red on main itself. It failed 1 of 6 full-suite runs at c870139, missing the bound by 64 µs (294.936 ms against ≥ 295 ms). It is recorded on #171.

How:

A send can then only be stamped later than the instant its window closed, never earlier. The lower bound becomes a property of the client, not of the host, and needs no margin:

  • O: gap ≥ P2. It was P2 − 5 ms.
  • Q: gap ≥ P2* − 2 ms, where the 2 ms is by how much the stray 0x78 predates the second send. It was P2* − 5 ms.

Mutation checks:

  • A cancelled send restores its window like a refused one, so none is left: O is red, gap 30 ms.
  • A stray 0x78 is not routed: Q is red, gap 149 ms.

R_… keeps its wall clock. Since #187 its note follows the cancellation, so scheduling delay can only lengthen the gap it bounds. The other tests in the file have margins of 100 ms and more and stay as they are.

Type of change

  • feat — new behaviour (minor release)
  • fix / perf — bug or performance fix (patch release)
  • docs / test / refactor / chore / ci — no release
  • Breaking change (! in the title, plus a BREAKING CHANGE: footer explaining the migration)

Checklist

  • dotnet build CanKit.Pro.sln -c Release succeeds (with -p:CI=true; the net48 test leg also compiles)
  • dotnet test CanKit.Pro.sln -c Release passes (net10.0, locally, 1220/1220)
  • Public API changes are documented with XML comments (none)
  • New behaviour is covered by a test (no new behaviour)
  • The requirement or ADR this relates to is referenced (e.g. FR-RAW-031, ADR-7), if any (Replace wall-clock category-2 test sleeps (macOS flake risk) #171)

🤖 Generated with Claude Code

https://claude.ai/code/session_013WJ8h1ahw4Nj5dYuEWy34s


Generated by Claude Code

O_A_Suppressed_Send_Cancelled_Before_Confirmation_Still_Opens_Its_Window
and Q_A_Stray_Pending_From_Before_The_Handoff_Still_Moves_Its_Services_Window
each asserted a lower bound on the wall-clock gap between two sends,
with a 5 ms margin. Q missed it by 64 us in 1 of 6 full-suite runs on
main at c870139 (294.936 ms against >= 295 ms).

StubChannel can now take the client's actor as its clock. Its stamps
and its delays then run on that actor, and the client is opened on the
same actor through the internal UdsClient.Create(channel, clock, ...).

The tests step the clock one millisecond at a time. A send can then
only be stamped later than the instant its window closed, never
earlier. So the lower bound is a property of the client, not of the
host, and needs no margin:
- O: gap >= P2, where it was P2 - 5 ms.
- Q: gap >= P2* - 2 ms, the 2 ms by which the stray 0x78 predates the
  second send, where it was P2* - 5 ms.

Mutation checks:
- A cancelled send restores like a refused one, leaving no window: O
  red, gap 30 ms.
- The stray 0x78 is not routed: Q red, gap 149 ms.

R keeps its wall clock. Since #187 its note follows the cancellation,
so scheduling delay can only lengthen the gap it bounds.

Refs #171

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013WJ8h1ahw4Nj5dYuEWy34s
@cursor

cursor Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

PR Summary

Low Risk
Test-only changes to UdsExpiredDeadlineTests and its StubChannel double; no production UDS behavior.

Overview
Part of #171: two UDS expired-deadline tests (O and Q) that bound the gap between sends on the wall clock were flaky on CI (Q missed by ~64 µs). This PR makes those assertions deterministic.

StubChannel can share the client’s ProtocolActor as its clock: send stamps, delivery scheduling, and delays use that time source (via Schedule) instead of Stopwatch / Task.Delay.

O and Q now use VirtualClock, UdsClient.Create(channel, actor, …), and RunAsync (1 ms steps until the operation finishes). Cancellation and pacing are driven by advancing the virtual clock; gaps are checked with Gap against P2 or P2 − 2 ms* without the old 5 ms host-margin. R and the other tests in the file stay on the wall clock.

Reviewed by Cursor Bugbot for commit 3bc8e21. Bugbot is set up for automated code reviews on this repo. Configure here.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T05:27:16.017700Z 3bc8e21 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@codecov

codecov Bot commented Sep 28, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@dborgards
dborgards merged commit 259a7f4 into main Sep 28, 2026
12 checks passed
@dborgards
dborgards deleted the claude/pensive-wozniak-ivbwba branch September 28, 2026 09:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants