fix: fence reconciliation admission race

This commit is contained in:
2026-09-11 07:36:11 +00:00
parent d753e8b698
commit e79f882993
10 changed files with 193 additions and 16 deletions
+27
View File
@@ -179,6 +179,32 @@ assert_stdin_close() {
fail "stdin command did not reach terminal success"
}
assert_signal_term() {
issued=$(rvc run --background --shell cmd "$client_id" 'ping -t 127.0.0.1 >NUL' 2>&1) || fail "signal command admission failed: $issued"
issue=$(printf '%s\n' "$issued" | awk 'NR == 1 { print $1 }')
case $issue in ????????-????-7???-????-????????????) ;; *) fail "signal command returned invalid issue UUID: $issued" ;; esac
attempt=0
while [ "$attempt" -lt 30 ]; do
result=$(rvc stat "$client_id" "$issue" 2>/dev/null || true)
if printf '%s\n' "$result" | grep -q 'lifecycle=COMMAND_RUNNING'; then break; fi
attempt=$((attempt + 1)); sleep 1
done
[ "$attempt" -lt 30 ] || fail "signal command did not reach running state"
rvc kill TERM "$client_id" "$issue" >/dev/null || fail "TERM request failed"
attempt=0
while [ "$attempt" -lt 45 ]; do
result=$(rvc stat "$client_id" "$issue" 2>/dev/null || true)
if printf '%s\n' "$result" | grep -q 'lifecycle=COMMAND_TERMINATED'; then
printf '%s\n' "$result" >"$fixture_dir/signal-term.stat"
printf 'passed signal-term issue=%s\n' "$issue"
return 0
fi
case $result in *'lifecycle=COMMAND_FAILED'*|*'lifecycle=COMMAND_REJECTED'*|*'lifecycle=COMMAND_SUCCEEDED'*) fail "TERM command reached wrong terminal state: $result" ;; esac
attempt=$((attempt + 1)); sleep 1
done
fail "TERM command did not reach terminal state"
}
collect() {
if [ "$vm_prepared" = yes ]; then
"$repo_root/scripts/windows/test-host" collect --run-id "$run_id" || true
@@ -224,6 +250,7 @@ case $action in
"$repo_root/scripts/windows/test-host" run --run-id "$run_id" --endpoint "$endpoint_host:$port"
wait_client
assert_stdin_close
assert_signal_term
assert_context active-user no active-user
assert_context active-user-elevated yes active-user-elevated
"$repo_root/scripts/windows/test-host" run --run-id "$run_id" --fail-contexts ACTIVE_USER_ELEVATED
+20 -3
View File
@@ -540,7 +540,22 @@ case "$action" in
attempt=$((attempt + 1))
sleep 1
done
[ "$(state)" = poweroff ] || fail "guest did not power off before reset"
# This is the exact named disposable fixture, with the matching
# run lease. Reset is its isolation boundary, not a graceful-stop
# diagnostic command: after a bounded ACPI attempt, discard only
# this guest's state so snapshot restore cannot strand the lane.
if [ "$(state)" != poweroff ]; then
printf 'reset: ACPI shutdown timed out; forcing disposable VM poweroff\n' >&2
VBoxManage controlvm "$vm" poweroff >/dev/null
attempt=0
while [ "$attempt" -lt 30 ]; do
[ "$(state)" = poweroff ] && break
attempt=$((attempt + 1))
sleep 1
done
[ "$(state)" = poweroff ] || fail "guest did not power off after forced reset"
printf 'reset-force-poweroff vm=%s\n' "$vm"
fi
fi
VBoxManage snapshot "$vm" restore "$snapshot" >/dev/null
assert_identity
@@ -580,7 +595,9 @@ accelerated_stage() {
printf 'stage: accelerated publish directory unavailable\n' >&2
return 1
}
stage_http_dir=$(mktemp -d "${TMPDIR:-/tmp}/rvbox-http-stage.XXXXXX")
# Keep all disposable test bytes inside the owning run directory; never
# consume global /tmp, which may belong to a different test or user.
stage_http_dir=$(mktemp -d "$run_root/.accelerated-stage.XXXXXX")
stage_http_xz=$stage_http_dir/rvbox.exe.xz
xz -T0 -3 -c "$bundle/rvbox.exe" >"$stage_http_xz"
stage_http_hash=$(sha256sum "$stage_http_xz" | awk '{print $1}')
@@ -615,7 +632,7 @@ copy_stage_file() {
target_name=$2
copy_attempt=1
while [ "$copy_attempt" -le 4 ]; do
if scp -q "$source_file" "$RVBOX_TEST_VBOX_HOST:$host_stage/$target_name"; then
if scp -q -o BatchMode=yes -o ConnectTimeout=10 -o ServerAliveInterval=10 -o ServerAliveCountMax=2 "$source_file" "$RVBOX_TEST_VBOX_HOST:$host_stage/$target_name"; then
return 0
fi
copy_attempt=$((copy_attempt + 1))