diff --git a/internal/proxy/bans_test.go b/internal/proxy/bans_test.go index fc27408..d6379d9 100644 --- a/internal/proxy/bans_test.go +++ b/internal/proxy/bans_test.go @@ -205,6 +205,7 @@ func TestBannedClientIsRefusedBeforeItsCountryIsLookedUp(t *testing.T) { geojsURL, asked := startGeoJS(t) s, _, _ := startWithClock(t, geojsURL, map[string]string{ + lookupTimeout: "1h", rateLimitPerMinute: "1", banScopeV4Prefix: "24", deniedCountries: "kp", @@ -243,6 +244,7 @@ func TestBanResponseAnswersEveryRefusalButTheSizeLimits(t *testing.T) { geojsURL, _ := startGeoJS(t) env := map[string]string{ + lookupTimeout: "1h", rateLimitPerMinute: "1", denyNets: denied, deniedCountries: "kp", @@ -268,6 +270,7 @@ func TestBanNotes(t *testing.T) { geojsURL, _ := startGeoJS(t) s, clk, server := startWithClock(t, geojsURL, map[string]string{ + lookupTimeout: "1h", rateLimitPerMinute: "1", deniedCountries: "kp", }) diff --git a/internal/proxy/countries_test.go b/internal/proxy/countries_test.go index e6d498a..5182e81 100644 --- a/internal/proxy/countries_test.go +++ b/internal/proxy/countries_test.go @@ -52,7 +52,7 @@ func TestCountryLists(t *testing.T) { calls.Add(1) }) geojsURL, _ := startGeoJS(t) - env := map[string]string{trustedProxies: trustLocalhost} + env := map[string]string{trustedProxies: trustLocalhost, lookupTimeout: "1h"} maps.Copy(env, tc.env) addr, out := startProxyWithGeoJS(t, app.URL, geojsURL, env) @@ -101,6 +101,7 @@ func TestCountryRefusalComesBeforeTheBody(t *testing.T) { geojsURL, _ := startGeoJS(t) addr, out := startProxyWithGeoJS(t, app.URL, geojsURL, map[string]string{ trustedProxies: trustLocalhost, + lookupTimeout: "1h", deniedCountries: "kp", }) @@ -280,7 +281,11 @@ func TestExclusiveListRefusesAPrivateAddressUnlessAllowed(t *testing.T) { // startGeoJS starts a stand-in for GeoJS, which places fromDE and fromKP, // each in an AS of its own, and no other address. It returns its URL, and -// what returns the addresses it has been asked about. +// what returns the addresses it has been asked about. A test in which a +// request waits for the stand-in's answer, as it does while a country +// list, a biased threshold or SWWAF_ADD_LOOKUP_HEADERS is set, sets +// SWWAF_LOOKUP_TIMEOUT to an hour: on the default second, a hold-up of +// the test process can leave the client unknown. func startGeoJS(t *testing.T) (string, func() []string) { t.Helper() diff --git a/internal/proxy/errorburst_test.go b/internal/proxy/errorburst_test.go index 5e777d5..6afde47 100644 --- a/internal/proxy/errorburst_test.go +++ b/internal/proxy/errorburst_test.go @@ -194,6 +194,7 @@ func TestErrorBurstIsNotLoweredForAClientWithLowerLimits(t *testing.T) { geojsURL, _ := startGeoJS(t) s, _, server := startWithClock(t, geojsURL, map[string]string{ + lookupTimeout: "1h", errorBurstThreshold: "2", rulesDir: writeRules(t, testRules), countryLimitPercent: countryDEHalf, diff --git a/internal/proxy/history_test.go b/internal/proxy/history_test.go index 7514c59..ffaa9de 100644 --- a/internal/proxy/history_test.go +++ b/internal/proxy/history_test.go @@ -18,6 +18,7 @@ func TestHistoryKeepsEachRequestOfTheClient(t *testing.T) { geojsURL, _ := startGeoJS(t) s, clk, server := startWithClock(t, geojsURL, map[string]string{ + lookupTimeout: "1h", rateLimitPerMinute: "2", deniedCountries: "kp", }) diff --git a/internal/proxy/lookup_test.go b/internal/proxy/lookup_test.go index f0192aa..5ba1094 100644 --- a/internal/proxy/lookup_test.go +++ b/internal/proxy/lookup_test.go @@ -249,6 +249,7 @@ func TestLookupHeadersArePassedToTheAppAndTheClientsOwnRemoved(t *testing.T) { geojsURL, _ := startGeoJS(t) addr, out, _ := startProxyWithClock(t, app.URL, geojsURL, time.Now, map[string]string{ trustedProxies: trustLocalhost, + lookupTimeout: "1h", addLookupHeaders: "true", }) s := &sender{t: t, addr: addr, out: out} diff --git a/internal/proxy/observe_test.go b/internal/proxy/observe_test.go index 8667af9..36a42bd 100644 --- a/internal/proxy/observe_test.go +++ b/internal/proxy/observe_test.go @@ -39,6 +39,7 @@ func TestObserveModeForwardsWhatEnforceModeRefuses(t *testing.T) { geojsURL, _ := startGeoJS(t) env := map[string]string{ + lookupTimeout: "1h", rateLimitPerMinute: "1", denyNets: denied, deniedCountries: "kp", diff --git a/internal/proxy/staticlists_test.go b/internal/proxy/staticlists_test.go index d757f19..ea7c67f 100644 --- a/internal/proxy/staticlists_test.go +++ b/internal/proxy/staticlists_test.go @@ -144,6 +144,7 @@ func TestRateLimitExemptNetsAreNeitherCountedNorRefused(t *testing.T) { geojsURL, _ := startGeoJS(t) addr, out := startProxyWithGeoJS(t, app.URL, geojsURL, map[string]string{ trustedProxies: trustLocalhost, + lookupTimeout: "1h", rateLimitExemptNets: listedAddr + "," + fromKP, deniedCountries: "kp", rateLimitPerMinute: "1",