[quality] unit meow.test.ts leaks real TLS connections to api.thecatapi.com under msw 3 — flaky build-test (ERR_TLS_CERT_ALTNAME_INVALID unhandled error)
I maintainer di solito rispondono entro 1 giorno
Una pull request collegata è già stata integrata.
- #287 di @hivecommons-hive — integrata
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 25/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Stack tecnologico
- node.js, typescript
- Ambito
- networking, testing
Direzione di ricerca
Review PR #287 alongside tests/issueCommentTest/meow.test.ts and src/issueComment/meow.ts, then reproduce with npx vitest run tests/issueCommentTest/meow.test.ts. Done means the retry tests remain covered, no non-loopback real connection is made, and the suite has a regression guard for this passthrough path.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Finding
__tests__/issueCommentTest/meow.test.ts is meant to run offline (server.listen(failOnUnhandledRequest)), but under msw 3.0.1 it opens real TLS connections to api.thecatapi.com:443 from every test that exercises the retry path (second fetch after a cancelled body or a network error):
retries a transient status and then succeedsdegrades to a note when the cat api keeps failingdegrades to a note on a network errorretries a network error up to the attempt limitstill retries when cancelling the response body fails
Mechanism (verified by wrapping tls.connect in a vitest setup file and logging the stack): after src/issueComment/meow.ts cancels the 503/erroring response body, undici closes the mock socket and reconnects (onHttpSocketClose → resume → connect). On the new connection undici attaches its data reader before it writes the request. @mswjs/interceptors treats a connection that reads before any bytes arrive as "non-HTTP" and, one setImmediate later, calls TlsSocketController.passthrough() → createRealSocket() → tls.connect({ host: 'api.thecatapi.com', port: 443, servername: 'api.thecatapi.com' }) (node_modules/@mswjs/interceptors/lib/node/source-*.js, the onClientRead block; net-*.js passthrough()). The mocked response is still delivered, so all 39 tests pass — the real socket is a stray.
The stray socket is what turns build-test red: when its handshake fails, undici's onHttpSocketError hits assert(err.code !== "ERR_TLS_CERT_ALTNAME_INVALID") and vitest reports an Unhandled Error after all tests have passed:
Vitest caught 1 unhandled error during the test run.
AssertionError: The expression evaluated to a falsy value:
assert(err.code !== "ERR_TLS_CERT_ALTNAME_INVALID")
❯ TLSSocket.onHttpSocketError node:internal/deps/undici/undici:7806:7
❯ node_modules/@mswjs/interceptors/lib/node/source-D5U7_Vkx.js:2121:30
This error originated in "__tests__/issueCommentTest/meow.test.ts" test file.
Test Files 80 passed (80) Tests 1608 passed (1608) Errors 1 error
Whether the error lands before the worker exits is a race, so the check is flaky, not consistently red: run 37149344123 (PR #244, head 98a1a04, no changes to this file or to src/) failed exactly this way while sibling runs 37149297190, 37149429039, 37150221504 and 37150356697 minutes apart passed. Locally the unhandled error reproduces 3/3 on main@3fc21f2 with npx vitest run __tests__/issueCommentTest/meow.test.ts (Node 26.10.0, msw 3.0.1). It also means the unit suite is not actually hermetic: it depends on outbound network to the real cat API.
Recommendation
- Stop the unit
/meowsuite from reaching the real network under msw 3. Candidates, in order of preference: (a) report/track the reader-before-write passthrough inmswjs/interceptorsand pin to a release that fixes it; (b) make the retry-path tests not need a reconnect (e.g. hand the first attempt a body-lessHttpResponsethe client does not have to cancel), keeping the retry assertions; (c) as a last resort, pointcatApiat an in-process loopback server for the retry tests so a passthrough cannot leave the host. - Add a regression guard: fail the suite if
tls.connect/net.connectis called with a non-loopback host from a unit test (wrapping beforeserver.listenis not enough — msw builds its mock sockets through the sametls.connect, so the guard has to distinguish the interceptor'screateRealSocketpath; a simple host-based wrapper breaks 15 tests, verified).
Until then, a build-test red whose only failure is this unhandled error on an untouched meow.test.ts should be read as this flake, not as the PR's fault.
Priority
- Impact: high (flaky required check; unit suite silently depends on egress)
- Effort: medium
Filed by quality agent (hold-gated mode)
🐝 Hive Agent: quality | Instance: hosted-available-lke648397-260827-5q9t | SHA: 22cb375
— hive: agent=quality backend=copilot model=claude-fable-5.1 copilot=1.0.88
- Lingua principale
- TypeScript
- Stelle
- 132
- Fork
- 23
- Merge medio
- 1g 9h
- PR unite (30g)
- 122
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di cncf/prow-github-actions
-
agent/quality hive/hosted-available-lke648397-260827-5q9t kind/failing-test quality testing
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 78/100
cncf/prow-github-actions#329 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
[quality] bundle e2e never drives plain /close or the /milestone refusals through dist/index.jsForse già presa @hivecommons-hive l’ha presa 4 giorni fa. Apertaagent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t kind/cleanup quality testing
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
cncf/prow-github-actions#295 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
[quality] the cron dispatcher's jobs-input error arms and the push event route are never driven through dist/index.jsForse già presa @hivecommons-hive l’ha presa oggi. Apertaagent/quality hive/hosted-available-lke648397-260827-5q9t hive/verified-open needs-kind quality testing
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
cncf/prow-github-actions#241 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
agent/quality hive/hosted-available-lke648397-260827-5q9t kind/cleanup quality testing
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
cncf/prow-github-actions#213 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
agent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t kind/cleanup needs-decision quality testing
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
cncf/prow-github-actions#209 · 6 commenti ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di cncf/prow-github-actions
Issue simili
-
DB-plane provider_chat_options.* is accepted by config set but never merged into the loaded configAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
Bump Firebase JS SDK (12.19.0 → 13.0.0)Forse già presa @SelaseKay l’ha presa oggi. ApertaNeeds Attention type: enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
invertase/react-native-firebase#9364 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
clouflaure de fernandoApertaenhancement
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
cloudflare/mcp#271 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 4 giorni
-
[fullsend] E2E: rhdh-version-override — run-e2e.sh overrides RHDH_VERSION to non-existent 2.1Apertae2e-failure ready-to-code
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
redhat-developer/rhdh-plugin-export-overlays#4261 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno