From a21db071ac2d2ab5a933936cbc1de53ca3190269 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Thu, 8 Oct 2026 05:25:49 +0000 Subject: [PATCH] Tests that need a lookup answer give it an hour (closes #119) Twelve tests in internal/proxy needed the GeoJS stand-in to be asked or to answer within the default SWWAF_LOOKUP_TIMEOUT of one second on the real clock. A hold-up of the test process past it abandoned the request to the stand-in, or left the client unknown. Each now sets SWWAF_LOOKUP_TIMEOUT to an hour, and the comment on startGeoJS asks the same of later tests. Judgement call: set in each test, not as a default in newProxy, where it would change two tests that rely on the default second. Model: opus-5-5 --- internal/proxy/bans_test.go | 3 +++ internal/proxy/countries_test.go | 12 +++++++++--- internal/proxy/errorburst_test.go | 1 + internal/proxy/history_test.go | 1 + internal/proxy/lookup_test.go | 1 + internal/proxy/observe_test.go | 1 + internal/proxy/staticlists_test.go | 1 + 7 files changed, 17 insertions(+), 3 deletions(-) diff --git a/internal/proxy/bans_test.go b/internal/proxy/bans_test.go index fc27408..d6379d9 100644 --- a/internal/proxy/bans_test.go +++ b/internal/proxy/bans_test.go @@ -205,6 +205,7 @@ func TestBannedClientIsRefusedBeforeItsCountryIsLookedUp(t *testing.T) { geojsURL, asked := startGeoJS(t) s, _, _ := startWithClock(t, geojsURL, map[string]string{ + lookupTimeout: "1h", rateLimitPerMinute: "1", banScopeV4Prefix: "24", deniedCountries: "kp", @@ -243,6 +244,7 @@ func TestBanResponseAnswersEveryRefusalButTheSizeLimits(t *testing.T) { geojsURL, _ := startGeoJS(t) env := map[string]string{ + lookupTimeout: "1h", rateLimitPerMinute: "1", denyNets: denied, deniedCountries: "kp", @@ -268,6 +270,7 @@ func TestBanNotes(t *testing.T) { geojsURL, _ := startGeoJS(t) s, clk, server := startWithClock(t, geojsURL, map[string]string{ + lookupTimeout: "1h", rateLimitPerMinute: "1", deniedCountries: "kp", }) diff --git a/internal/proxy/countries_test.go b/internal/proxy/countries_test.go index e6d498a..a5e558f 100644 --- a/internal/proxy/countries_test.go +++ b/internal/proxy/countries_test.go @@ -52,7 +52,7 @@ func TestCountryLists(t *testing.T) { calls.Add(1) }) geojsURL, _ := startGeoJS(t) - env := map[string]string{trustedProxies: trustLocalhost} + env := map[string]string{trustedProxies: trustLocalhost, lookupTimeout: "1h"} maps.Copy(env, tc.env) addr, out := startProxyWithGeoJS(t, app.URL, geojsURL, env) @@ -101,6 +101,7 @@ func TestCountryRefusalComesBeforeTheBody(t *testing.T) { geojsURL, _ := startGeoJS(t) addr, out := startProxyWithGeoJS(t, app.URL, geojsURL, map[string]string{ trustedProxies: trustLocalhost, + lookupTimeout: "1h", deniedCountries: "kp", }) @@ -147,6 +148,7 @@ func TestRequestRefusedByCountryIsNotCounted(t *testing.T) { app := startApp(t, func(http.ResponseWriter, *http.Request) {}) addr, _ := startProxyWithGeoJS(t, app.URL, geojs.URL, map[string]string{ trustedProxies: trustLocalhost, + lookupTimeout: "1h", allowedCountries: "de", rateLimitPerMinute: "1", }) @@ -194,7 +196,7 @@ func TestPrivateAddressIsNeverLookedUp(t *testing.T) { app := startApp(t, func(http.ResponseWriter, *http.Request) {}) geojsURL, asked := startGeoJS(t) - env := map[string]string{trustedProxies: trustLocalhost} + env := map[string]string{trustedProxies: trustLocalhost, lookupTimeout: "1h"} maps.Copy(env, tc.env) addr, out := startProxyWithGeoJS(t, app.URL, geojsURL, env) @@ -280,7 +282,11 @@ func TestExclusiveListRefusesAPrivateAddressUnlessAllowed(t *testing.T) { // startGeoJS starts a stand-in for GeoJS, which places fromDE and fromKP, // each in an AS of its own, and no other address. It returns its URL, and -// what returns the addresses it has been asked about. +// what returns the addresses it has been asked about. A test that needs +// the stand-in to be asked or to answer sets SWWAF_LOOKUP_TIMEOUT to an +// hour, whether or not a request waits for the answer: on the default +// second, a hold-up of the test process can abandon the request to the +// stand-in, and leave the client unknown. func startGeoJS(t *testing.T) (string, func() []string) { t.Helper() diff --git a/internal/proxy/errorburst_test.go b/internal/proxy/errorburst_test.go index 5e777d5..6afde47 100644 --- a/internal/proxy/errorburst_test.go +++ b/internal/proxy/errorburst_test.go @@ -194,6 +194,7 @@ func TestErrorBurstIsNotLoweredForAClientWithLowerLimits(t *testing.T) { geojsURL, _ := startGeoJS(t) s, _, server := startWithClock(t, geojsURL, map[string]string{ + lookupTimeout: "1h", errorBurstThreshold: "2", rulesDir: writeRules(t, testRules), countryLimitPercent: countryDEHalf, diff --git a/internal/proxy/history_test.go b/internal/proxy/history_test.go index 7514c59..ffaa9de 100644 --- a/internal/proxy/history_test.go +++ b/internal/proxy/history_test.go @@ -18,6 +18,7 @@ func TestHistoryKeepsEachRequestOfTheClient(t *testing.T) { geojsURL, _ := startGeoJS(t) s, clk, server := startWithClock(t, geojsURL, map[string]string{ + lookupTimeout: "1h", rateLimitPerMinute: "2", deniedCountries: "kp", }) diff --git a/internal/proxy/lookup_test.go b/internal/proxy/lookup_test.go index f0192aa..5ba1094 100644 --- a/internal/proxy/lookup_test.go +++ b/internal/proxy/lookup_test.go @@ -249,6 +249,7 @@ func TestLookupHeadersArePassedToTheAppAndTheClientsOwnRemoved(t *testing.T) { geojsURL, _ := startGeoJS(t) addr, out, _ := startProxyWithClock(t, app.URL, geojsURL, time.Now, map[string]string{ trustedProxies: trustLocalhost, + lookupTimeout: "1h", addLookupHeaders: "true", }) s := &sender{t: t, addr: addr, out: out} diff --git a/internal/proxy/observe_test.go b/internal/proxy/observe_test.go index 8667af9..36a42bd 100644 --- a/internal/proxy/observe_test.go +++ b/internal/proxy/observe_test.go @@ -39,6 +39,7 @@ func TestObserveModeForwardsWhatEnforceModeRefuses(t *testing.T) { geojsURL, _ := startGeoJS(t) env := map[string]string{ + lookupTimeout: "1h", rateLimitPerMinute: "1", denyNets: denied, deniedCountries: "kp", diff --git a/internal/proxy/staticlists_test.go b/internal/proxy/staticlists_test.go index d757f19..ea7c67f 100644 --- a/internal/proxy/staticlists_test.go +++ b/internal/proxy/staticlists_test.go @@ -144,6 +144,7 @@ func TestRateLimitExemptNetsAreNeitherCountedNorRefused(t *testing.T) { geojsURL, _ := startGeoJS(t) addr, out := startProxyWithGeoJS(t, app.URL, geojsURL, map[string]string{ trustedProxies: trustLocalhost, + lookupTimeout: "1h", rateLimitExemptNets: listedAddr + "," + fromKP, deniedCountries: "kp", rateLimitPerMinute: "1",