Skip to content

tests: use an explicit 10 s run limit in the remaining default-limit … - #348

Merged
divarvel merged 1 commit into
eclipse-biscuit:mainfrom
aojea:tests-query-limits
Sep 29, 2026
Merged

divarvel merged 1 commit into
eclipse-biscuit:mainfrom
aojea:tests-query-limits

Conversation

@aojea

@aojea aojea commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

…tests

AuthorizerLimits::default() sets max_time to 1 ms. Most tests that run Datalog already override it with 10 s ("cheap worker on GitHub Actions"), but five call sites still relied on the default:

  • token::authorizer::tests::query_authorizer_from_token_tuple
  • token::authorizer::tests::query_authorizer_from_token_string
  • token::authorizer::tests::rule_validate_variables
  • token::tests::basic (3-block token)
  • token::tests::authorizer_queries (query on the cloned authorizer)

Under cargo-tarpaulin (ptrace, unoptimised build) rule_validate_variables fails deterministically with RunLimit(Timeout), and the others are one slow runner away from the same. This is what keeps the Coverage job red once the biscuit-quote timeout is out of the way.

Switch them to authorize_with_limits / query_with_limits with the same 10 s budget the neighbouring tests use. Verified with three consecutive cargo tarpaulin --workspace --exclude biscuit-quote runs (89/89 lib tests pass); the same command on main fails.

…tests

`AuthorizerLimits::default()` sets `max_time` to 1 ms. Most tests that
run Datalog already override it with 10 s ("cheap worker on GitHub
Actions"), but five call sites still relied on the default:

- token::authorizer::tests::query_authorizer_from_token_tuple
- token::authorizer::tests::query_authorizer_from_token_string
- token::authorizer::tests::rule_validate_variables
- token::tests::basic (3-block token)
- token::tests::authorizer_queries (query on the cloned authorizer)

Under cargo-tarpaulin (ptrace, unoptimised build) `rule_validate_variables`
fails deterministically with `RunLimit(Timeout)`, and the others are
one slow runner away from the same. This is what keeps the Coverage job
red once the biscuit-quote timeout is out of the way.

Switch them to `authorize_with_limits` / `query_with_limits` with the
same 10 s budget the neighbouring tests use. Verified with three
consecutive `cargo tarpaulin --workspace --exclude biscuit-quote` runs
(89/89 lib tests pass); the same command on main fails.
@divarvel
divarvel merged commit 2b321c5 into eclipse-biscuit:main Sep 29, 2026
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants