Files
felhom.eu/hub/internal/notify/node_liveness_cooldown_test.go
T

67 lines
2.9 KiB
Go

package notify
import (
"io"
"log"
"sync"
"testing"
"time"
)
// Operator ruling 2026-09-15 (decision A) — "box is down" mail is not swallowed by the quiet hour.
// BIGNIGHT F9: a node_stale 39 minutes after F8's node_stale was suppressed by the 1-hour cooldown.
//
// RED-PROOF (run 2026-09-15, recorded in REPORT.md): with operatorCooldownFor returning the hour for
// every type (the pre-ruling behaviour), the 39-minute node_stale was suppressed and this failed at
// "node_stale 39 min after the previous one was suppressed".
func TestOperatorCooldown_NodeLivenessBypassesQuietHour(t *testing.T) {
st := newDispStore(t)
d := NewDispatcher(st, "test-key", "from@felhom.eu", "op@felhom.eu", true, log.New(io.Discard, "", 0))
var mu sync.Mutex
sent := 0
d.sendEmailFn = func(string, string, string, map[string]string) error { mu.Lock(); defer mu.Unlock(); sent++; return nil }
count := func() int { mu.Lock(); defer mu.Unlock(); return sent }
// The previous node_stale mail went 39 minutes ago.
d.mu.Lock()
d.opCooldowns["c1:host_stale"] = time.Now().Add(-39 * time.Minute)
d.opCooldowns["c1:node_stale"] = time.Now().Add(-39 * time.Minute)
d.opCooldowns["c1:app_start_failed"] = time.Now().Add(-39 * time.Minute)
d.mu.Unlock()
d.processOperator("c1", "node_stale", "warning", "box stale", "{}", "hub")
if count() != 1 {
t.Fatalf("node_stale 39 min after the previous one was suppressed (sent=%d) — the BIGNIGHT F9 silence", count())
}
// A flap 1 minute later is deduped.
d.processOperator("c1", "node_stale", "warning", "box stale again", "{}", "hub")
if count() != 1 {
t.Fatalf("node_stale 1 min after a sent one was mailed again (sent=%d) — the 5-minute dedupe is gone", count())
}
// Ruling 2: the same for a HOST-plane mail, 39 minutes after the last one.
d.processOperator("c1", "host_stale", "warning", "host stale", "{}", "hub")
if count() != 2 {
t.Fatalf("host_stale 39 min after the previous one was suppressed (sent=%d) — ruling 2 (R-529)", count())
}
// The design is unchanged for every other type: still the hour.
d.processOperator("c1", "app_start_failed", "warning", "app down", "{}", "hub")
if count() != 2 {
t.Fatalf("a non-liveness type lost its 1-hour cooldown (sent=%d)", count())
}
for _, et := range []string{"node_down", "node_recovered"} {
if operatorCooldownFor(et) != nodeLivenessDedupeWindow {
t.Fatalf("%s is not in the ruling's bypass", et)
}
}
// Ruling 2 (2026-09-16, R-529): the host-plane siblings joined the bypass.
for _, et := range []string{"host_stale", "host_down", "host_recovered"} {
if operatorCooldownFor(et) != nodeLivenessDedupeWindow {
t.Fatalf("%s must bypass the quiet hour too (operator ruling 2026-09-16)", et)
}
}
// A type in neither ruling keeps the hour — the design is narrowed, not removed.
if operatorCooldownFor("storage_disconnected") != operatorCooldown {
t.Fatal("an unrelated type lost its 1-hour cooldown")
}
}