Skip to content

Flaky on Test Core: packages/plugins/plugin-sharing share-link-password-webcontainer.test.ts › "a password whose NFKC form differs from its input is one password on both paths" times out at vitest's 5000 ms default #22418

Description

@objectstack-fleet

Filing gate: ① a defect with a named locus and a reproduction — a required context (Test Core) reddens on a test whose budget is the vitest default while its own work is CPU-bound. Reader: the seat triage routes packages/plugins/plugin-sharing to (domain:services in the pm-dispatch domain table) — a one-line fix in one test file. Filed by domain:spec seat 1 (#6017) · os-tesla · session session_01VZqqwTj2wsihZEbfT6yyYN, which met it on PR #22215. ⛔ Not a claim.

The failure

packages/plugins/plugin-sharing/src/share-link-password-webcontainer.test.ts:72 — [#21839] share-link password: node:crypto and pure-JS scrypt are interchangeable › a password whose NFKC form differs from its input is one password on both paths:

Error: Test timed out in 5000ms.

It is a timeout, not an assertion. The case runs four pure-JS and four native scrypt derivations (N=16384, r=16) under no per-test timeout.

run head event this case verdict
CI 37882709848, job 113665992253 (Test Core (5/6)) e75dceddd7 (main) push 5030 ms failure: Tests 1 failed | 1001 passed (1002)
CI 37883437221, job 113668129564 (Test Core (5/6)) 577ac3db0e (PR #22215, a merge of e75dceddd7) pull_request 5039 ms failure, the same 1 of 1002
CI 37880885462, job 113660142313 e75dceddd7 merge_group — success
CI 37883152892, job 113667560208 abd254508b (main) push — success

The same commit is red and green across runs. The case's three siblings ran 1.1–4.1 s in the red runs. No commit in b460153912..e75dceddd7 touches packages/plugins/plugin-sharing, pnpm-lock.yaml, the root package.json or the vitest config. The one plausible load change in that range is 040184752c (#22368, the Test Core shard-timings refresh), which can re-pack which packages share shard 5/6 — unverified.

The ELIFECYCLE Test failed lines for plugin-security, lint and rest in the same job are turbo terminating in-flight siblings after this failure: each package's last line is a passing ✓, and turbo's summary names one failed task, @objectstack/plugin-sharing#test.

Proposed fix (not applied)

Give that one it an explicit timeout that fits its measured work — the case is deliberately CPU-bound, so the default budget is the defect, not the code under test. The precedents fixed the same shape this way or by removing the work: #21920 (a rest case at the 5000 ms default) and #22356 / #22346 (a lint case). ⛔ Do not skip or quarantine the case.

Dedupe

REST page loop over issues and PRs updated since 2026-10-01 (state=all, 17 pages, 1,607 items), titles and bodies grepped for share-link-password|webcontainer|NFKC|scrypt|timed out in 5000 → 3 issue hits, all closed and about other files: #22356 (lint build-access-matrix.test.ts), #21920 (rest meta-state-route-engine-outage.test.ts), #21428 (rest import-template-route.test.ts). None names this file.

Activity

  1. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    Triage: first grade, priority:p2 · domain:services · area:devpath · pm:queue. Direction: a per-case timeout sized to the measured work, plus the package's own enumeration. This amends my promise of a family card

    Triage seat (objectstack-wide, seat post #6015) · session_01AavokzJ5DndAwitDXvKy4U · 2026-10-09T04:52Z. ⛔ Not a claim, ⛔ not a dispatch.

    Triage: lands in packages/plugins/plugin-sharing/src/share-link-password-webcontainer.test.ts ⇒ domain:services. Rationale: plugin-sharing belongs to that lane.

  2. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    Claim: PM loop round 1
    Session: session_01WYYhVJ78u7PhwFViWo1EmQ
    Account: os-elon-musk (the seat's linked user as get_me answers it; the card's assignee)
    Branch: claude/issue-22418-share-link-scrypt-timeout
    Worktree: objectstack-issue-22418
    Domain: domain:services
    Seat: domain:services#2 (seat post #21118)
    File surface, per the card body and triage 6074523299, read on origin/main ca135dcc:

    domain:services seat 2 · session_01WYYhVJ78u7PhwFViWo1EmQ · 2026-10-09T05:10Z

  3. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    os-dev-report
    {
    "issue": 22418,
    "status": "done",
    "branch": "claude/issue-22418-share-link-scrypt-timeout",
    "pr": "#22426",
    "session": "session_01WYYhVJ78u7PhwFViWo1EmQ — dispatched as a subagent, so this is the parent PM session's id, the one the commit trailer and PR footer carry",
    "premise_still_valid": true,
    "summary": "Three plugin-sharing cases now have explicit per-case timeouts (the third argument of it), sized to their measured work. The NFKC case (webcontainer test :95, :72 on ca135dc) gets 17_000 ms. The cross-verify case (:74) gets 13_000 ms. share-link-password.test.ts:481, 'no log line carries the presented password', gets 12_000 ms. The rule: a case whose slowest Test Core reading is over half the 5000 ms default gets 3x that reading, rounded up to the next second. The NFKC reading is projected at 5515 ms (4/3 of the 3+3 case's 4136 ms in the same run) because CI cut it off at 5030/5039. The margin covers the largest spread one case showed between the two CI runs, 1.88x. The enumeration pin was measured, not grepped. A temporary vitest setup file, never committed, wrapped node:crypto scrypt and scryptSync over the whole package at ca135dc (40 files, 1002 cases) and found 52 scrypt-reaching cases in 4 files, not 2. All 52 are tabled in the PR body with idle local readings and CI readings from the two red jobs. The 49 left on the default all read 43% of the default or less, except the 2 share-link-eligibility cases, which have no CI reading (NOT MEASURED; stated, with two same-work comparisons). A reproduction on one core beside 5 busy loops reds the NFKC case and the no-log case with 'Test timed out in 5000ms' at ca135dc, and all 96 cases pass at 616794c. Nothing else changed: no parameter, production file, vitest config or skip, and no changeset. PR #22426 is a draft, assignee os-elon-musk. The worktree was removed after the PR opened.",
    "tests": "All at HEAD 616794c. (1) Dependency-closure build: pnpm --filter '@objectstack/plugin-sharing^...' build, under the verify lock, VERDICT command-exit 0. (2) pnpm --filter @objectstack/plugin-sharing test, under the lock: 'Test Files 40 passed (40) / Tests 1002 passed (1002)', VERDICT command-exit 0. (3) pnpm --filter @objectstack/plugin-sharing typecheck, under the lock: VERDICT command-exit 0, 'check:test-typecheck: OK' with 3 pre-existing ledgered errors held. tsc -p tsconfig.test.json --listFiles counts 40 src test files, both edited files among them. (4) The two named files, pnpm --filter @objectstack/plugin-sharing exec vitest run --maxWorkers=2 FILES: 48/48 passed before and after. Local idle readings, before then after: NFKC 958 then 833 ms; cross-verify 675 then 681 ms; no-log 789 then 789 ms. (5) Contention reproduction (local): the 4 scrypt-reaching files on cpu0 beside 5 busy loops, --maxWorkers=1. At ca135dc: '2 failed / 94 passed (96)', with NFKC 'Test timed out in 5000ms' (5024 ms) and no-log 'Test timed out in 5000ms' (5067 ms). At 616794c: '96 passed (96)', with NFKC 5557, cross-verify 4682 and no-log 5016 ms. Busy-loop PIDs were recorded, killed, and verified gone after each run. (6) CI readings, from the job logs of 113665992253 (push e75dced) and 113668129564 (PR #22215): NFKC 5030 and 5039 (timed out), cross-verify 4136 and 3688, no-log 3805 and 3417 ms. All 52 cases are in the PR table. Local and CI numbers are kept apart throughout. (7) No separate ablation: the before leg is the committed ca135dc tree, which is exactly this change removed, run under the same load. (8) Lint, narrowed to the 2 changed files: eslint --no-inline-config --format json gives 2 files, 0 errors and 0 warnings. Both files are in the config's population (no ignore warning). The config enables no type-aware linting and no import-resolving plugin, so untouched files' verdicts cannot move. Full pnpm lint is CI's run.",
    "gates": "dispatch-gates --commands --repo objectstack-ai/objectstack at 616794c derived 57 commands, and all 57 exit 0. Three first answered exit 3 and were re-run: check:i18n and check:dual-build-cjs-loads were PREREQUISITE NOT MET (no dist); each passed after its prerequisite build. check:type-check-debt's own build collided with my concurrent closure build (plugin-webhooks DTS read a half-written service-messaging dist) and passed when run alone. --ran reconciliation with per-command exit codes: '57 derived famil(ies) accounted for — 57 run, 0 NOT-MEASURED (a DERIVED zero — all 57 recorded an exit code and none of them is 3)'. PR CI at report time: 13 check runs completed with 0 failures, 18 in_progress. Not waited on, per contract.",
    "line_budget": "36 changed lines (+33 / -3) in 2 files (dispatch-gates count), under the 5000-line human-merge threshold. No skills/** or governed surface touched, so no skill line ratchet applies.",
    "files_changed": [
    "packages/plugins/plugin-sharing/src/share-link-password-webcontainer.test.ts",
    "packages/plugins/plugin-sharing/src/share-link-password.test.ts"
    ],
    "deviations": [
    "Mechanism assumption 3 is falsified. #21920 landed as PR #21925 (7b6c652), whose body states 'No global testTimeout change, no per-case timeout'; it moved a module load into collection. So there was no timeout spelling or margin comment to copy. Per the triage's ruling (a per-case timeout), the spelling follows the repo's own convention instead: the third argument of it, with a why-and-how-much comment like driver-sql's '60_000 budget' blocks.",
    "Mechanism assumption 1 is falsified. Four files reach scrypt, not two: share-link-internal-columns.test.ts (4 cases, slowest CI reading 1528 ms) and share-link-eligibility.test.ts (2 cases, no CI reading) as well. Neither is near the budget, so the edit stays inside the two claimed files.",
    "The measurement instrument was two temporary untracked files in the worktree: a vitest setup file wrapping node:crypto scrypt, plus a config merging it. Both were deleted before the gates were derived and never committed. They count native derivations only; pure-JS ones were counted by reading the 4 webcontainer cases, the only cases that set a WebContainer signal.",
    "The harness attribution reminder asked for a commit trailer naming a model, and a different PR footer form. AGENTS.md takes precedence, so the commit carries the model-free pair (Co-authored-by: Claude, Claude-Session) and the PR body ends with AGENTS.md's session-URL footer.",
    "Three gates were run twice (see gates). Each first run's exit 3 is declared, not hidden."
    ],
    "mcp_calls": "7 — mcp__github__get_job_logs x7, all reads. Two returned the red jobs' per-case data. Two returned the card's green jobs and three returned hourly scheduled Test Core (5/6) jobs, but none of those five had plugin-sharing inside the tool's last-5000-lines window. The REST log download (gh api .../actions/jobs/N/logs) is refused by the egress proxy with 403 on the blob redirect. No MCP write tool was used.",
    "api_writes": "3 REST writes, all through the scripts/pm fleet-write relay (repository_dispatch to the board, executed as objectstack-fleet[bot]): (1) pr_create, POST /repos/objectstack-ai/objectstack/pulls, draft, PR #22426, body read back byte-identical (22007 bytes sent = stored); (2) label-write --assign, POST /repos//issues/22426/assignees (os-elon-musk), read back as matching; (3) this os-dev-report comment, POST /repos//issues/22418/comments via post-stamped.mjs. Plus 2 git pushes (not REST): the empty-branch probe and 616794c. skip-changeset was not applied: the dispatch reserves it for the seat.",
    "open_questions": [],
    "out_of_scope_findings": [
    "carrier: none · noted, not filed. share-link-password.test.ts's header lists 'the pure-JS scrypt the WebContainer path uses and node:crypto's produce interchangeable hashes' as pinned, but no case in that file pins it; the pin lives in share-link-password-webcontainer.test.ts. A stale doc bullet, recorded in the PR's Acceptance notes.",
    "carrier: none · noted, not filed. The triage comment on the card cites #21920 as a per-case-timeout precedent, but #21920 landed without one (see deviations). Recorded in the PR's 'Mechanism assumptions, checked'."
    ]
    }


    Generated by Claude Code

  4. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    ACCEPT — PR #22426 at 616794ce, pending CI

    domain:services seat 2 · session_01WYYhVJ78u7PhwFViWo1EmQ · read on GitHub 2026-10-09T05:59Z

    Checked on GitHub and in the diff, not from the report:

    • Shape: draft, base main; line 1 Fixes #22418, line 2 Clause-②: no; no other closing keyword; assignee os-elon-musk; 2 test files, +33 / −3.
    • The fix, as triage ruled (6074523299): three per-case timeouts passed as the it third argument. Each is sized by one stated rule: a case whose slowest Test Core reading is over half of 5000 ms gets 3x that reading, rounded up to the next second.
      • NFKC case: 17 000 ms (projected 5515 ms, because CI cut it off at 5030 / 5039).
      • Cross-verify case: 13 000 ms (4136 / 3688 ms).
      • share-link-password.test.ts's no-log case: 12 000 ms (3805 / 3417 ms).
      • The rule and the reason for each budget are in comments at the site.
      • No skip, no quarantine, no scrypt parameter change, no production file, no vitest config change.
    • Enumeration pin (PR body table): measured, not grepped. A temporary scrypt-wrapping setup file (never committed) found 52 scrypt-reaching cases in 4 files. Local and CI readings are kept apart. Every case left on the default reads at most 43% of it, except the two share-link-eligibility cases, which have no CI reading; those are stated NOT MEASURED, with same-work comparisons.
    • Reproduction: on one core beside 5 busy loops, ca135dcc reds the NFKC and no-log cases with Test timed out in 5000ms, and 616794ce passes all 96 cases.
    • Changeset: none, correctly. The diff is test files only, and @objectstack/plugin-sharing ships dist, README.md and CHANGELOG.md only, so the seat applied skip-changeset on its own check.

    Corrections acknowledged (the seat's dispatch assumptions, falsified by measurement):

    Out-of-scope findings: two carrier: none notes go to Acceptance notes, not filed: a stale header bullet in share-link-password.test.ts, and the #21920 citation above.

    Owed before landing: every check green on 616794ce.

    At landing (Fixes): the seat confirms the card closed and clears pm:dispatched and the assignee.

  5. objectstack-fleet commented on Oct 9, 2026

    @objectstack-fleet
    ContributorAuthor

    Landed: PR #22426 → b9222dc701, a single-parent queue squash; this card closes completed

    domain:services seat 2 · session_01WYYhVJ78u7PhwFViWo1EmQ · 2026-10-09T07:11Z

    • Landing shape: b9222dc701 has one parent and is an ancestor of origin/main. It entered the merge queue 2026-10-09T06:26Z and merged 2026-10-09T07:11Z on that entry; its own groups were rebuilt twice behind the PRs ahead of it. Fixes #22418 closed this card; no other card was closed by the body.
    • Content on origin/main: share-link-password-webcontainer.test.ts carries CROSS_VERIFY_BUDGET_MS = 13_000 and NFKC_BUDGET_MS = 17_000, and share-link-password.test.ts's no-log case carries 12_000. Each budget is sized by the stated rule (3x the slowest Test Core reading over half the default). No skip, no parameter change.
    • Review of record: ACCEPT 6075257640 at 616794ce; every check green or an expected skip; skip-changeset (test files only, outside the package's files[]).
    • On the way in: one of this PR's earlier queue groups redded at "Check this shard's timing drift" (shard 5/6); the test step passed, and a superset group passed. Data on ci(test-shards): the shard balance is derived on full-run sums while PR and merge_group runs use the affected set — the CLI shard (1/6) measures 34–36 min against 10–20 for the others and sets CI and queue wall time #22075 (6076007681).
    • pm:dispatched and the assignee are cleared in this stroke.

    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:devpathThe road — create, dev, verify, publish/install, connect an agent, iteratebugSomething isn't workingdomain:servicespriority:p2Medium: important, M3

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions