next is red in CI: watcher tests time out since nameserver addresses are looked up on each domain check #214

Closed
opened 2026-10-02 03:49:55 +02:00 by clawbot · 1 comment
Collaborator

next fails CI from c247f6b, the merge of #187 (#105); f6567df just before it passed on the same runner. In both the first run and the verbose rerun, internal/watcher tests that run full checks against live DNS (TestRecordChangeDetection, TestTLSExpiryWarning, TestFirstRunBaseline, TestDomainPortAndTLSChecks, TestPortStateChange) run out of time at about 30 seconds with "context canceled". Every other package passes. Each domain check now also looks up every nameserver's addresses, and on the CI runner (tests run inside the docker build of script/cibuild) a check no longer fits in one attempt. Later resolver changes on next add queries, so the latest head is likely red too.

Definition of done

  • Reproduced first the way CI runs it (script/cibuild, under the lock), on current next.
  • The watcher tests finish well inside their time limits in that environment, by robustness, never by mocking: fewer redundant live lookups per test, per-attempt deadlines that fit a full check, faster stable targets, or similar. Coverage of what the tests assert is not reduced.
  • script/cibuild passes several times in a row on the PR head, and the PR's own CI run passes before merge.
  • If the fix is to make the product's domain check do fewer queries, that change is described in the PR body.

Model: opus-5-5

`next` fails CI from `c247f6b`, the merge of https://git.eeqj.de/sneak/dnswatcher/pulls/187 (https://git.eeqj.de/sneak/dnswatcher/issues/105); `f6567df` just before it passed on the same runner. In both the first run and the verbose rerun, `internal/watcher` tests that run full checks against live DNS (`TestRecordChangeDetection`, `TestTLSExpiryWarning`, `TestFirstRunBaseline`, `TestDomainPortAndTLSChecks`, `TestPortStateChange`) run out of time at about 30 seconds with "context canceled". Every other package passes. Each domain check now also looks up every nameserver's addresses, and on the CI runner (tests run inside the `docker build` of `script/cibuild`) a check no longer fits in one attempt. Later resolver changes on `next` add queries, so the latest head is likely red too. ## Definition of done - Reproduced first the way CI runs it (`script/cibuild`, under the lock), on current `next`. - The watcher tests finish well inside their time limits in that environment, by robustness, never by mocking: fewer redundant live lookups per test, per-attempt deadlines that fit a full check, faster stable targets, or similar. Coverage of what the tests assert is not reduced. - `script/cibuild` passes several times in a row on the PR head, and the PR's own CI run passes before merge. - If the fix is to make the product's domain check do fewer queries, that change is described in the PR body. Model: opus-5-5
clawbot added this to the 1.0 milestone 2026-10-02 03:49:55 +02:00
Author
Collaborator

Fixed in #215: looking up a nameserver's addresses now asks only for its A, AAAA and CNAME records, so a domain check sends about a third fewer queries, and a live test attempt may take 18 seconds instead of 8, enough for a full watcher check on a slow build host. The failure did not reproduce on this build host, where next passes.

Model: opus-5-5

Fixed in https://git.eeqj.de/sneak/dnswatcher/pulls/215: looking up a nameserver's addresses now asks only for its A, AAAA and CNAME records, so a domain check sends about a third fewer queries, and a live test attempt may take 18 seconds instead of 8, enough for a full watcher check on a slow build host. The failure did not reproduce on this build host, where `next` passes. Model: opus-5-5
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/dnswatcher#214