Files
felhom.eu/hub/internal/api/chaosnight_events_test.go
T
admin 37ae31fd44
gates / gates (push) Successful in 21s
hub v0.117.0: the status follows the configured threshold; slow crash loop and interrupted restore events
R-549 (operator ruling A): controllerStatus hardcoded 30m/1h while both
staleness checkers and hostStatus read alerting.stale_threshold. Moving the
threshold to 45m would have painted a customer amber 15 minutes before the
alarm could fire - the second definition rollup.go's header forbids. It now
reads the same value, down at 2x. Both 'checker initialized' log lines print
the threshold, which no line did before.

R-539 (ruling 3 of 2026-09-16): controller_slow_crashloop (warning,
operator-only), minted when the agent's slow_crashloop_since moves, with the
fast sibling's first-sight rule.

R-550: restore_interrupted (warning, for the household) allowlisted with a
Hungarian customer message.

Red-proofs, each seen failing then passing: the status test with the old
hardcoded numbers; the checker test with the movement branch removed; the
operator-only test with the registration removed; the household-message test
with the Hungarian entry removed (asserted on the SUBJECT - the body
legitimately repeats the raw message, which my first version of the test
mistook for a fallback).

go build/vet/test ./... green, 18 packages.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-09-17 10:20:32 +02:00

50 lines
2.2 KiB
Go

package api
import (
"strings"
"testing"
"gitea.dooplex.hu/admin/felhom-hub/internal/notify"
)
// R-539 — controller_slow_crashloop joins its fast sibling: allowlisted AND operator-only.
// RED-PROOF: remove it from operatorOnlyEvents → "must be operator-only".
func TestControllerSlowCrashloopIsAllowlistedAndOperatorOnly(t *testing.T) {
et := "controller_slow_crashloop"
if !allowedEventTypes[et] {
t.Fatalf("%s must be in allowedEventTypes (R-77)", et)
}
if !notify.IsOperatorOnly(et) {
t.Fatalf("%s must be operator-only — host ids and vmids are not a household's business", et)
}
}
// R-550 — restore_interrupted is pushed by controller v0.246.0 and IS for the household: they started
// the restore and can run it again. So it must be allowlisted (or POST /event 400s — R-77), must NOT be
// operator-only, and must carry a Hungarian customer message (a missing entry falls back to the raw
// English message — the v0.78.0 defect).
// RED-PROOF: drop the customerMessages entry → the subject/body carry the raw message.
func TestRestoreInterruptedReachesTheHouseholdInHungarian(t *testing.T) {
et := "restore_interrupted"
if !allowedEventTypes[et] {
t.Fatalf("%s must be in allowedEventTypes — the controller's push would 400", et)
}
if notify.IsOperatorOnly(et) {
t.Fatalf("%s must reach the household, not only the operator", et)
}
const raw = "RAW-ENGLISH-SENTINEL restore interrupted"
// The SUBJECT is built from the Hungarian message alone; the body legitimately repeats the raw
// message as a detail line ("Üzenet: …"), so the body cannot be the witness — the subject is.
subject, body := notify.FormatCustomerEmail("c1", et, "warning", raw, "{}")
if strings.Contains(subject, "RAW-ENGLISH-SENTINEL") {
t.Fatalf("customer mail subject for %s is the raw message — customerMessages entry missing: %q", et, subject)
}
// ASCII fragment of the Hungarian text („megszakadt"), with a negative control.
if !strings.Contains(body, "megszakadt") {
t.Fatalf("customer mail for %s lacks the Hungarian sentence (fragment \"megszakadt\")", et)
}
if strings.Contains(body, "zzzz-not-present") {
t.Fatalf("negative control matched — the fragment search is broken")
}
}