test: stabilize watcher and brief test assertions - #3
Merged
Merged
Conversation
added 2 commits
July 19, 2026 07:26
The watcher-restart-vs-healthy-peer test in tests/fm-watcher-lock.test.sh
simulated a TERM-resistant live watcher peer with a bare
`node -e 'process.on("SIGTERM", ...)' &`, then immediately captured its
pid identity and exercised the restart path. Under load (e.g. right
after the suite's 40-process concurrency tests), node's own startup can
still be registering the signal handler when the restart logic signals
it, so the signal falls through to the default disposition and the
"TERM-resistant" peer dies. The arm script then correctly starts a
fresh watcher instead of reporting the peer healthy, and since a real
watcher blocks for a wake, the arm never exits within the test's
timeout. Confirmed via instrumented liveness-check tracing: the peer
pid transitioned from alive to gone mid-loop while the restart logic
was still polling it. Fixed by having the peer write a ready marker
(fs.writeFileSync, which JS guarantees runs after process.on() in the
same tick) and waiting for it before any signal is sent, removing the
race without weakening the assertion.
tests/fm-brief.test.sh's "secondmate charter must declare its role"
assertion still expected the pre-kunchenguid#685 wording "persistent domain
supervisor". Commit 1182883 (fix: accept secondmate house vocabulary,
kunchenguid#685) intentionally changed the charter text to "a persistent second
mate" as part of adopting nautical house vocabulary, and updated
tests/fm-captain-translation-contract.test.sh to match, but missed this
assertion in tests/fm-brief.test.sh. Not a code bug: the production
wording change was deliberate. Updated the stale assertion to match.
Verified: 20 consecutive green runs of each fixed test individually,
plus one full clean run of all 79 tests/*.test.sh files (0 failures).
shellcheck (bin/fm-lint.sh) clean.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Fix the two pre-existing flaky/failing tests that taxed every validation run on 2026-07-18: (1) tests/fm-watcher-lock.test.sh's test_watch_restart_reports_healthy_peer_without_attaching, which simulated a TERM-resistant live watcher peer via a bare backgrounded node process and immediately relied on it being SIGTERM-immune, racing node's own startup (its signal handler registration) against the restart logic's kill signal - under load this let the peer die via the default disposition, causing the arm to start a fresh watcher (which blocks indefinitely) instead of reporting the peer healthy, so the test timed out. Confirmed via instrumented liveness-check tracing that the peer's pid transitioned from alive to gone mid-poll. This was judged a test-side timing bug, not a production bug, and was fixed by having the peer write a readiness marker (JS guarantees process.on() runs before the following writeFileSync in the same tick) and waiting for that marker before any signal is sent, so the SIGTERM-immunity is real before it's relied on - this does not weaken what the test asserts. (2) tests/fm-brief.test.sh's 'secondmate charter must declare its role' assertion still expected the pre-existing wording 'persistent domain supervisor', but commit 1182883 ('fix: accept secondmate house vocabulary', kunchenguid#685) had intentionally changed bin/fm-brief.sh's charter text to 'a persistent second mate' as part of adopting nautical house vocabulary, and updated tests/fm-captain-translation-contract.test.sh to match, but missed this one assertion in tests/fm-brief.test.sh. This was judged a stale test assertion, not a code regression, since the production wording change was deliberate policy; updated the assertion text to match the current intentional wording. Verification performed: 20 consecutive green runs of each fixed test individually (confirming the fixes hold under repetition, not just once), plus one full clean run of all 79 tests/*.test.sh files in the repo with zero failures, plus bin/fm-lint.sh (shellcheck) clean. No production code was touched - both changes are confined to the two test files.
What Changed
persistent second matewording.Risk Assessment
✅ Low: Captain, the amended change is confined to the two intended tests, preserves their assertions, and reaps the peer on all explicit post-spawn failure paths.
Testing
The supplied all-tests baseline had already succeeded; I ran both affected suites, exercised the real restart flow repeatedly with persisted CLI evidence, and generated a secondmate charter from production code. The observed behavior satisfies the readiness, healthy-peer/no-attach, and intentional wording requirements; no linting was run per instruction.
Evidence: Restart CLI transcript: readiness-confirmed peer stays alive and is reported healthy without attachment
Evidence: Generated secondmate charter showing the intended role wording
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
🔧 **Review** - 1 issue found → auto-fixed ✅
tests/fm-watcher-lock.test.sh:459- If the readiness check fails, the test exits before killing the TERM-resistant Node peer. The suite cleanup only removes temp directories, so a peer that writes its marker just after the timeout can survive for five minutes and consume resources during later tests. Kill and reap$peerbeforefailon this path.🔧 Fix: Captain, reap TERM-resistant watcher peer
✅ Re-checked - no issues remain.
✅ **Test** - passed
✅ No issues found.
command -v tmux >/dev/null || { echo "tmux is required for e2e tests" >&2; exit 1; }; tmux -V; rc=0; for t in tests/*.test.sh; do echo "== $t =="; bash "$t" || rc=1; done; exit "$rc"Provided successful baseline:command -v tmux >/dev/null || { echo "tmux is required for e2e tests" >&2; exit 1; }; tmux -V; rc=0; for t in tests/*.test.sh; do echo "== $t =="; bash "$t" || rc=1; done; exit "$rc"git diff --check 6cfdb29b2dea411ef63c34be0eccb018ecd2e28b d90e018ec31fccb12624c03de8a79f3ca5138d96bash tests/fm-brief.test.shbash tests/fm-watcher-lock.test.shManual repeated end-to-endbin/fm-watch-arm.sh --restartexercise with a readiness-confirmed SIGTERM-resistant Node peer; verifiedhealthy, no attachment, and peer liveness in the saved transcript.FM_HOME=<evidence-home> FM_SECONDMATE_CHARTER='Supervise the alpha domain.' bin/fm-brief.sh evidence-secondmate --secondmate alphaEvidence assertions confirming every recorded restart outcome, generated charter wording, two-file diff scope, and clean worktree.✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.