9167cf53af
gates / gates (push) Successful in 23s
The hub has written every customer e-mail in Hungarian whatever the box was set to. The box has published its language since controller v0.247.0; nothing read it. Now it does. Nothing an operator reads changes. The Hungarian mails are byte-identical, and that is a diff rather than a reading: 56 goldens per language captured from v0.117.0 BEFORE any string moved, and all 56 Hungarian ones pass unchanged after every sentence was routed through the new bundle. - internal/i18n: flat bundle, 79 keys, hu authoritative + hu fallback, ceiling 0. - customerMessages/severityLabels are DERIVED from the bundle, so a sentence is written in one place and all 40+ tests that read those maps still work. - Language order: last reported -> created-with -> hu. reports.language defaults to EMPTY, never hu: "never told us" is not "chose Hungarian". - message_customer on POST /api/v1/event, additive and optional forever, for the sentences the box composes and the hub cannot translate. - The bind page is per-language, and its `expired` state stays Hungarian: it is the state an unknown token lands in, so rendering a real English customer's token in English would make the LANGUAGE answer what the TEXT refuses to. Two defects found inside the release: - R-581: the newest report was picked by received_at, which has SECOND granularity, so same-second reports tied and the winner was arbitrary. Ordered by the autoincrement id now. GetCustomers() still has the shape - row open. - R-582: the English copy-guard stems, ported word for word from Hungarian, convicted 141 honest sentences. The English claim is a phrase with a modal. R-555 closed: the language allowlist entry is out of wire_contract_gate.py. hub_copy_gate.py follows the sentences into the bundle - without that it would have scanned four files that no longer hold any customer text and reported success. Three new decoys incl. an innocent control. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
72 lines
2.9 KiB
Go
72 lines
2.9 KiB
Go
package notify
|
|
|
|
import (
|
|
"io"
|
|
"log"
|
|
"sync"
|
|
"testing"
|
|
"time"
|
|
)
|
|
|
|
// Operator ruling 2026-09-15 (decision A) — "box is down" mail is not swallowed by the quiet hour.
|
|
// BIGNIGHT F9: a node_stale 39 minutes after F8's node_stale was suppressed by the 1-hour cooldown.
|
|
//
|
|
// RED-PROOF (run 2026-09-15, recorded in REPORT.md): with operatorCooldownFor returning the hour for
|
|
// every type (the pre-ruling behaviour), the 39-minute node_stale was suppressed and this failed at
|
|
// "node_stale 39 min after the previous one was suppressed".
|
|
func TestOperatorCooldown_NodeLivenessBypassesQuietHour(t *testing.T) {
|
|
st := newDispStore(t)
|
|
d := NewDispatcher(st, "test-key", "from@felhom.eu", "op@felhom.eu", true, log.New(io.Discard, "", 0))
|
|
var mu sync.Mutex
|
|
sent := 0
|
|
d.sendEmailFn = func(string, string, string, map[string]string) error {
|
|
mu.Lock()
|
|
defer mu.Unlock()
|
|
sent++
|
|
return nil
|
|
}
|
|
count := func() int { mu.Lock(); defer mu.Unlock(); return sent }
|
|
|
|
// The previous node_stale mail went 39 minutes ago.
|
|
d.mu.Lock()
|
|
d.opCooldowns["c1:host_stale"] = time.Now().Add(-39 * time.Minute)
|
|
d.opCooldowns["c1:node_stale"] = time.Now().Add(-39 * time.Minute)
|
|
d.opCooldowns["c1:app_start_failed"] = time.Now().Add(-39 * time.Minute)
|
|
d.mu.Unlock()
|
|
|
|
d.processOperator("c1", "node_stale", "warning", "box stale", "{}", "hub")
|
|
if count() != 1 {
|
|
t.Fatalf("node_stale 39 min after the previous one was suppressed (sent=%d) — the BIGNIGHT F9 silence", count())
|
|
}
|
|
// A flap 1 minute later is deduped.
|
|
d.processOperator("c1", "node_stale", "warning", "box stale again", "{}", "hub")
|
|
if count() != 1 {
|
|
t.Fatalf("node_stale 1 min after a sent one was mailed again (sent=%d) — the 5-minute dedupe is gone", count())
|
|
}
|
|
// Ruling 2: the same for a HOST-plane mail, 39 minutes after the last one.
|
|
d.processOperator("c1", "host_stale", "warning", "host stale", "{}", "hub")
|
|
if count() != 2 {
|
|
t.Fatalf("host_stale 39 min after the previous one was suppressed (sent=%d) — ruling 2 (R-529)", count())
|
|
}
|
|
// The design is unchanged for every other type: still the hour.
|
|
d.processOperator("c1", "app_start_failed", "warning", "app down", "{}", "hub")
|
|
if count() != 2 {
|
|
t.Fatalf("a non-liveness type lost its 1-hour cooldown (sent=%d)", count())
|
|
}
|
|
for _, et := range []string{"node_down", "node_recovered"} {
|
|
if operatorCooldownFor(et) != nodeLivenessDedupeWindow {
|
|
t.Fatalf("%s is not in the ruling's bypass", et)
|
|
}
|
|
}
|
|
// Ruling 2 (2026-09-16, R-529): the host-plane siblings joined the bypass.
|
|
for _, et := range []string{"host_stale", "host_down", "host_recovered"} {
|
|
if operatorCooldownFor(et) != nodeLivenessDedupeWindow {
|
|
t.Fatalf("%s must bypass the quiet hour too (operator ruling 2026-09-16)", et)
|
|
}
|
|
}
|
|
// A type in neither ruling keeps the hour — the design is narrowed, not removed.
|
|
if operatorCooldownFor("storage_disconnected") != operatorCooldown {
|
|
t.Fatal("an unrelated type lost its 1-hour cooldown")
|
|
}
|
|
}
|