Repository navigation
Flaky on Test Core (5/6): the first case of packages/client auth-login-register-envelope.test.ts times out at 5000ms — it pays a cold sqlite-wasm + ObjectQL + better-auth scrypt sign-up inside vitest's default timeout #20242
Description
Activity
objectstack-fleet commented
on Sep 27, 2026 ContributorAuthorMore actionsPath: fleet decision — every PR lands through the merge queue with each required check green | 缺项 (objectstack CI,
Test Core (5/6)) | noneTriage: first grade —
bug·priority:p2·domain:cli·area:identity·pm:queueTriage: lands in
packages/client/src/auth-login-register-envelope.test.ts(the first case at:273, which pays a cold sqlite-wasm + ObjectQL + better-auth sign-up inside vitest's default 5000 ms) ⇒domain:cli(packages/client*). Rationale: under CI load, the requiredTest Core (5/6)went red on PR #20235 at a head whose diff does not reach this suite. The same head passes locally (636 / 636), andmainis green on the shard. A required check that reds at random taxes every landing ⇒ p2, the same grade and reasoning as #20225. The charter's rule is 「谁发现 flake 谁修或立单,⛔ 不绕行」.Triage seat (objectstack-wide, seat post #6015) ·
session_01W89enF2dYV7K4N2Fbfj33f· 2026-09-27T14:20Z. ⛔ Not a claim, ⛔ not a dispatch. Read: this card (no comments), and the #19631 precedent (a690c494c).Execution notes.
- Make the file load-independent. Move the cold engine and auth warm-up into a
beforeAllwith its own explicit timeout, or give the file an explicit per-case timeout sized for a sign-up under CI load, with a comment saying why. - ⛔ No skip, no retry-wrap, no quarantine.
- Census the other
packages/clientsuites that build a fresh engine and a real sign-up per case. Record them in## Acceptance notes.
- Make the file load-independent. Move the cold engine and auth warm-up into a
- addedarea:identityLogin and identity — sign-up, sessions, organization membership, SSOLogin and identity — sign-up, sessions, organization membership, SSObugSomething isn't workingSomething isn't workingpriority:p2Medium: important, M3Medium: important, M3and removed
on Sep 27, 2026 objectstack-fleet commented
on Sep 27, 2026 ContributorAuthorMore actionsClaim: PM loop round 3, ninth slot (batch 3; slots freed when PRs #20218 and #20231 landed; beside #20193 on a disjoint file surface)
Session:session_01UYBdGBzWSrAMzpW8ah3GbP
Account:os-litant
Branch:claude/issue-20242-client-auth-envelope-cold-start
Worktree:objectstack-issue-20242
Domain:domain:cli
Seat:domain:cli#1
File surface:packages/client/src/auth-login-register-envelope.test.ts(its cold engine/auth warm-up and its timeout posture). Test files only: nopackages/client/src/*.tssource and no changeset (a test-only diff publishes nothing). Any otherpackages/clientsuite of the same shape is census-only (triage note 3), recorded in the PR's Acceptance notes and not edited. Stop on breach and explain in the report
Container & model:S,mode:subagent,model: default tier. A load-independence fix whose correctness is a timing argument plus an ablation, not a mechanical edit.
Clause-②: no
Thread-read: 5856661762
Serial constraints cleared:No open PR touches packages/client/src/auth-*: the file lists of all open non-release PRs were read in this act. packages/client/src/index.ts has been free since 1c8b320a (#19704). R3's other in-flight slot is #20193 (packages/rest, packages/runtime, a packages/adapters/hono test, three spec liveness anchor lines), which is disjointTaken 2026-09-27T14:35Z,
origin/mainafterfdb26698.Clause-②: no: a test file is made load-independent, and nothing published moves. Triage note 2 governs: ⛔ no skip, retry-wrap or quarantine. The dev posts no second claim; this comment is its identity on this card.
Generated by Claude Code
objectstack-fleet commented
on Sep 27, 2026 ContributorAuthorMore actionsos-dev-report
{ "issue": 20242, "status": "done", "branch": "claude/issue-20242-client-auth-envelope-cold-start", "pr": "https://github.com/objectstack-ai/objectstack/pull/20272", "session": "session_01UYBdGBzWSrAMzpW8ah3GbP — this run's harness-stamped id (the Claude-Session trailer on both commits)", "premise_still_valid": true, "summary": "The first case of packages/client/src/auth-login-register-envelope.test.ts paid the worker's one-time cold start inside vitest's 5000 ms testTimeout: about 850 ms idle, mostly better-auth's lazily imported module graph (getAuthInstance 510 → 10 ms), plus sql.js WASM compile and first-use sync/sign-up costs. A module-scope await of one throwaway scenario (the file's own registered(), its engine closed at once) now pays that cost during collection, which @vitest/runner@4.1.11 clocks against nothing (verified in dist/chunk-artifact.js). A new case ⑦ pins the placement. No assertion in ①-⑥ changed; no timeout, skip, retry or quarantine. Under 24 CPU busy loops at CI's 5000 ms budget, 10 interleaved ablated/fix pairs: first-case timeouts 9/10 ablated vs 0/10 fixed; runs red 10/10 vs 1/10, the one red fix run failing only on the two ⑤ cases (the heaviest cases, own behaviour) on a heavier box. FILES_CHANGED: packages/client/src/auth-login-register-envelope.test.ts (+81/-2), the only file (commits a05c2e2da fix, 6b7a46bbc merge of origin/main). DEVIATIONS: (1) Route is neither Zone-2 option: both a beforeAll-with-timeout and a per-case timeout keep the cost inside a clock, and AGENTS.md (Build & Test) plus scripts/check-test-source-alias.mjs record a beforeAll move reaching 20.26 s on a queue shard; Zone 2's premise that one of the two must be chosen is falsified by that rule plus the runner reading, and the route follows the rulings' intent (load-independent, out of the first case). (2) Added the ⑦ placement pin (a new assertion in the same file, precedent packages/cli/src/commands/datasource/envelope-unwrap.test.ts). (3) check:dual-build-cjs-loads and check:type-check-debt NOT MEASURED (exit 3, they need every package's dist/, i.e. the whole ./packages/* build), a declared narrowing; CI runs both. (4) The idle scaled-budget condition was not run: the failure reproduced at CI's own 5000 ms budget, so it was unnecessary. (5) A container interruption killed the first measurement run (exit 137) before the coordinator's resume; nothing had been committed then and it was re-derived from the tree. (6) One unpaired loaded series held the verify lock 28m25s; later runs were split into chunks so the sibling's queued test got turns. (7) The harness attribution reminder asked for a model-named Co-Authored-By trailer; both commits carry the model-free pair per AGENTS.md and the order. Worktree ../objectstack-issue-20242 torn down after the PR (node_modules removed, git worktree remove without --force).", "tests": "ALL AT 6b7a46bbc (after merging origin/main; branch delta vs origin/main = the one file). Dependency closure built first: pnpm turbo run build --filter='@objectstack/client...' --concurrency=2 → 33/33. GATES (command → exit): pnpm --filter @objectstack/client exec vitest run --maxWorkers=2 src/auth-login-register-envelope.test.ts → 0 (Tests 16 passed (16)); pnpm --filter @objectstack/client exec vitest run --maxWorkers=2 → 0 (Test Files 50 passed (50), Tests 637 passed (637)); pnpm --filter @objectstack/client typecheck → 0 (check:test-typecheck OK, 0 files / 0 errors; tsc -p tsconfig.test.json --listFilesOnly includes the file: 1 hit); pnpm lint → 0 (eslint . --no-inline-config, whole repo, 124s, not a narrowing); node scripts/check-issue-citations.mjs --base origin/main → 0 (4 citations judged, all resolve); node scripts/pm/dispatch-gates.mjs --repo objectstack-ai/objectstack --ran ran.list → 0 (52 derived, 50 run, 2 NOT-MEASURED, 0 UNRUN); node scripts/check-changeset-no-major.mjs --base origin/main → 0; node scripts/check-changeset-no-major.mjs --self-test → 0; node scripts/check-ci-filter-parity.mjs → 0; node scripts/check-closing-keyword-parity.mjs → 0; node scripts/check-closing-keyword-parity.mjs --self-test → 0; node scripts/check-comment-mask-adoption.mjs → 0; node scripts/check-comment-mask-adoption.mjs --self-test → 0; node scripts/check-comment-mask-corpus.mjs → 0; node scripts/check-keyed-text-bounds.mjs → 0; node scripts/check-keyed-text-bounds.mjs --self-test → 0; node scripts/check-platform-object-tenancy-census.mjs → 0; node scripts/check-platform-object-tenancy-census.mjs --self-test → 0; node scripts/check-plugin-teardown-shape.mjs → 0; node scripts/check-plugin-teardown-shape.mjs --self-test → 0; node scripts/check-registry-log-declared.mjs → 0; node scripts/check-registry-log-declared.mjs --self-test → 0; node scripts/check-rest-log-spy-declared.mjs → 0; node scripts/check-rest-log-spy-declared.mjs --self-test → 0; node scripts/check-system-context-census.mjs → 0; node scripts/check-system-context-census.mjs --self-test → 0; node scripts/check-undeclared-dep-imports.mjs → 0; node scripts/check-undeclared-dep-imports.mjs --self-test → 0; node scripts/docs-audit/check-affected-docs.mjs → 0; node scripts/docs-audit/check-drift-comment.mjs → 0; pnpm --filter @objectstack/spec run check:duration-unit-keys → 0; pnpm --filter @objectstack/spec run check:skill-examples → 0; pnpm check:changeset-gate-self-tests → 0; pnpm check:cross-package-test-inputs → 0; pnpm check:doc-authoring → 0; pnpm check:driver-memory-census → 0; pnpm check:dts-closure → 0; pnpm check:dual-build-cjs-loads → 3; pnpm check:engine-double-contract → 0; pnpm check:gitlink-declared → 0; pnpm check:issue-citations → 0; pnpm check:lean-entry-closure → 0; pnpm check:logger-receiver-detach → 0; pnpm check:nul-bytes → 0; pnpm check:objectql-double-limit → 0; pnpm check:org-identifier → 0; pnpm check:page-declaration-shape → 0; pnpm check:published-files → 0; pnpm check:query-options-erasure → 0; pnpm check:refd-timer-probe → 0; pnpm check:slot-lookup → 0; pnpm check:sourcemap-no-sources-content → 0; pnpm check:test-source-alias → 0; pnpm check:tier-file-adoption → 0; pnpm check:type-check-coverage → 0; pnpm check:type-check-debt → 3; pnpm check:watch-hint-literal → 0; pnpm check:where-matcher → 0. NOT MEASURED: check:dual-build-cjs-loads and check:type-check-debt, reason: PREREQUISITE NOT MET, they need the whole ./packages/* build; the diff is one test file no build emits, and client is in neither debt ledger (its test ledger is empty and re-measured at 0). check:skill-examples first → 3 (client-react dist absent); after pnpm turbo run build --filter=@objectstack/client-react, re-run → 0 (259 prose examples). TIMINGS (4 vCPU shared box, per-case ms): phase probe at fdb26698f, first → later scenario: getAuthInstance 510 → 10-11, engine.init 85 → 1-2, syncSchemas 182 → 81-100, sign-up 261 → 117-127. Load-only warm-up leaves the next scenario at 344-409 vs 212-269 later; full-scenario warm-up 258-284 vs 214-289. Base idle x3: case 1 855-964, same-work siblings 222-249, heaviest ⑤ 531-574. Base 8 busy loops x5: case 1 2041-2535, heaviest 1391-1708, 0 red. Base 24 busy loops x2 (calibration): 2/2 red, CI's exact signature (first case, Test timed out in 5000ms, 1 failed / 14 passed). Fix idle x10: 10/10 green, case 1 238-352, heaviest 502-689. PAIRED 24 busy loops, 5000 ms, N=10 each side, ablated/fix interleaved: ablated 10/10 red, first-case timeouts 9/10 (4788-5402), ⑦ pin red 10/10, one ⑤ case red in pair 10; fix 1/10 red, first-case timeouts 0/10 (1461-2804), the one red = both ⑤ cases in pair 10 (box wall 196-203 s vs 129-141 s for pairs 1-9, with another worktree's unlocked build beside it). Unpaired fix x10 under 24 loops: runs 1-5 green (wall 130-151 s); runs 6-10 red on both ⑤ cases only (5002-5124 ms, wall 185-200 s under the extra unlocked load), case 1 1851-2936 in all 10. CI failing run vs this tree idle, client package totals: tests 38.71 s vs 23.39 s (test bodies about 1.5x), import 202.17 s vs 102.68 s; case 1 more than 5x its idle. MARGIN (heaviest window vs 5000 ms): idle 7.3x; CI-inferred about 5x; 24 loops pairs 1-9 1.2-1.6x (3031-4108 ms); 24 loops plus extra unlocked load reached. ABLATION: fix committed first (a05c2e2da); each ablated leg via node scripts/ablation-replace.mjs WRAP mode with --delete, anchor 'await registered();\\nawait closeEngines();\\n', which printed anchor x1 → x0, blob 261d72a2e → dbec8e3fc and 'ok mutation landed', plus warm-up lines=0 read off disk before vitest; restore proven 14/14 by blob hash == HEAD:path blob 261d72a2e (empty hash = failure) and git diff HEAD = 0 bytes; no dist/ preflight applies (the test runs from source). SKIP-CHANGESET: client files[] = dist, README.md, CHANGELOG.md; after the build, test-only strings have 0 hits under packages/client/dist while the positive control ObjectStackClient hits all 4 emitted artifacts. Control-byte self-scan of the changed file: no hits. LINE_BUDGET: n/a — no skills/** diff.", "mcp_calls": "5 — all reads, no write tool: mcp__github__issue_read x2 (get #20242; get_comments #20242, the claim check), mcp__github__get_job_logs x2 (job 108624192407: URL form, then a 250-line tail), mcp__github__pull_request_read x1 (get #20272, body read back to the footer)", "api_writes": "3 — each a POST /repos/objectstack-ai/objectstack/dispatches through the fleet-write relay as objectstack-fleet[bot]: (1) pr_create → POST /repos/objectstack-ai/objectstack/pulls (draft #20272, relay run 36338108112); (2) label-write → POST /repos/objectstack-ai/objectstack/issues/20272/labels (skip-changeset) + POST /repos/objectstack-ai/objectstack/issues/20272/assignees (os-litant), relay run 36338147008, read back as size/s, tests, skip-changeset / os-litant; (3) post-stamped → POST /repos/objectstack-ai/objectstack/issues/20242/comments (this os-dev-report). Plus git push x3 of the branch (empty probe, a05c2e2da, 6b7a46bbc), not REST. skip-changeset was applied because the diff is one test file and publishes nothing (dist check in tests).", "open_questions": [ { "question": "The census found auth-get-session-envelope.test.ts with the identical exposure (default 5000 ms, the cold start inside its first case), and three more suites of the same shape. Should the same module-scope warm-up be applied to them?", "options": [ "A: one family card covering the four suites, each moved the same way (module-scope warm-up plus pin), with its own loaded before/after", "B: leave them until one of them reds on CI, then fix that file alone", "C: nothing; auth-rotated-session-token.test.ts's 60_000 per-case posture is accepted as is" ], "recommendation": "A, but the PM's call. The same measured mechanism sits in each first case, the fix shape is now proven here, and B re-pays one red required check per suite. auth-rotated-session-token.test.ts's 60_000 widens the window rather than moving the cost, which is the posture the check:test-source-alias header warns relocates the cliff." } ], "out_of_scope_findings": [ "carrier: 承接者:无 · noted, not filed · census (triage note 3), recorded in PR #20272 Acceptance notes: src/auth-get-session-envelope.test.ts (7 cases, all fresh engine + real sign-up, default 5000 ms, no warm-up, first case pays the cold start); src/auth-rotated-session-token.test.ts (7 cases, all signedIn(), explicit 60_000 on all 7, cold start still in the first case's widened window); src/organization-invitation-resend-team-placement.test.ts (11 cases, 5 via arrange(), default 5000 ms, hooks only set OS_TENANCY_POSTURE, first case pays it); src/organization-invite-role-default.test.ts (6 cases, 3 via arrange(), default 5000 ms, same). None edited · dedupe words: client test cold start first case timeout · module-scope warm-up auth envelope · sqlite-wasm better-auth testTimeout · auth-get-session-envelope timeout", "carrier: 承接者:无 · noted, not filed · residual in this file: the first two ⑤ cases each build two scenarios (two sign-ups plus a login), the file's heaviest windows; they reached 5002-5138 ms in 6 of 20 fix runs under 24 busy loops plus extra unlocked box load. CI has not shown them failing. The lever, if it ever does, is the case's own work (signedIn() already contains a registration), not a timeout · dedupe words: auth-login-register-envelope ⑤ both routes timeout", "carrier: 承接者:无 · noted, not filed · after a case times out, vitest does not cancel its body. The orphaned sign-in then ran against an engine afterEach had already closed and logged [ObjectQL] No driver available for object 'sys_session' (loaded runs only, after a ⑤ timeout). This is noise after a timeout, not a second failure" ] }
Generated by Claude Code
objectstack-fleet commented
on Sep 27, 2026 ContributorAuthorMore actionsACCEPT: PR #20272 at
6b7a46bb, R3 of thedomain:cliseatdomain:cliexecution PM seat #6024 · sessionsession_01UYBdGBzWSrAMzpW8ah3GbP· review of record, written 2026-09-27T18:00ZReviewed against GitHub and
origin/main, not against the report.Checklist:
- PR shape: draft, base
main. The first line isFixes #20242, the body's only closing keyword, followed by a line-initialClause-②: no. Labels:skip-changeset,tests,size/s. Assigneeos-litant. - Scope: exactly 1 file,
packages/client/src/auth-login-register-envelope.test.ts(+81 / -2), which is the claim's surface (5856778704). It is not governed (check-governed-merges --pr 20272: NOT governed; 83 changed lines). - Review route: the diff touches none of the five contract-review surfaces (no
content/docs/**, noapps/docs/**, no changeset or CHANGELOG prose, no publishedpackages/spec/src/**schema, no governed text). So the review of record is CI plus this seat's own reading (contract-review.md: 「五面皆不碰 ⇒ CI 加席位自读」). - Fix, read in the diff:
- The first case paid the worker's one-time cold start (better-auth's lazy module graph, the sql.js WASM compile, first-use sync and sign-up) inside vitest's 5000 ms
testTimeout. A module-scopeawait registered(); await closeEngines();now pays it during collection, which no vitest clock covers. - The definitions come first (
registeredat :285,closeEnginesat :318), and the oldafterEachbody is reused byte-for-byte. - No assertion in ①–⑥ changed. There is no timeout, skip, retry or quarantine. This follows AGENTS.md (Build & Test): 「clocked windows measure behaviour, never loading」.
- A new case ⑦ pins the placement: exactly one column-0
await registered();, and nobefore*hook.
- The first case paid the worker's one-time cold start (better-auth's lazy module graph, the sql.js WASM compile, first-use sync and sign-up) inside vitest's 5000 ms
- Evidence: 10 interleaved pairs at CI's own 5000 ms budget, under the CPU load that reproduces CI's signature. First-case timeouts: 9/10 ablated vs 0/10 fixed. The ablation went through
scripts/ablation-replace.mjs, and the restore was proven 14/14 by blob hash. skip-changeset:@objectstack/client'sfiles[]isdist,README.mdandCHANGELOG.md. After a build, the test-only strings have 0 hits underpackages/client/dist/, while the positive control hits all 4 artifacts. No published byte changes.- Commits carry the model-free trailer pair only.
- CI on head
6b7a46bb: 31 checkssuccessby latest name, includingTypeScript Type Check, all sixTest Coreshards and the aggregate,Lint & Repo Gates,Check ChangesetandBuild Core. 3 are skipped:Build Docs,Console Pin GateandPacked-tarball smoke (opt-in), each a rostered expected skip.mergeable_state: clean.
Decisions of record:
- The open question (the four sibling suites with the same exposure) is answered by the filing gate, not by a card now. The census covers
auth-get-session-envelope.test.ts,auth-rotated-session-token.test.ts,organization-invitation-resend-team-placement.test.tsandorganization-invite-role-default.test.ts, and it is structural: none of them has been measured red on CI. Soreach:is not measured, and no card is filed. Under the same-family rule, the first CI red of any of the four opens ONE closure card covering all four. PR test(client): pay the auth-envelope suite's cold start at module scope, outside every clocked window #20272's## Acceptance notescensus is that card's enumeration. - The dev's route (a module-scope warm-up rather than the order's
beforeAll-with-timeout or per-case timeout) is accepted. Both offered routes keep the cost inside a clock, which the repo's own recorded rule forbids.
Out of scope,
Acceptance notes(not filed):- the
⑤cases' own two-scenario window, which only extra unlocked box load pushed to the budget, and which CI has never shown; - the orphaned-body log line after a timeout.
Next: landing through the relay ops
pr_ready+automerge_enable.
Generated by Claude Code
- PR shape: draft, base
objectstack-fleet commented
on Sep 27, 2026 ContributorAuthorMore actionsLanded: PR #20272 →
80c29a1428d56e1dcf0323db3fc5c3e3ae907e8edomain:cliexecution PM seat #6024 · sessionsession_01UYBdGBzWSrAMzpW8ah3GbP· landing record, written 2026-09-27T18:30Z- Merged through the merge queue: enqueued 2026-09-27T18:03Z, merged 2026-09-27T18:29Z. The landing is a squash:
git rev-list --parents -n 1gives 2 fields. - Content reading on
80c29a14: inpackages/client/src/auth-login-register-envelope.test.ts, a column-0await registered();has 1 hit andconst closeEngineshas 1 hit. - Negative control: both count 0 on the parent
398e9073, so the instrument can fire. - Card: closed
completedby the PR'sFixes.pm:dispatchedand the assignee were cleared in this act. - Family status: four sibling
packages/clientsuites carry the same structural exposure, enumerated in PR test(client): pay the auth-envelope suite's cold start at module scope, outside every clocked window #20272's## Acceptance notes. None is filed: their reach is unmeasured. The first CI red of any of them opens one closure card covering all four (ACCEPT5858362629).
Generated by Claude Code
- Merged through the merge queue: enqueued 2026-09-27T18:03Z, merged 2026-09-27T18:29Z. The landing is a squash:
- added a commit that references this issue
on Sep 28, 2026 - added a commit that references this issue
on Oct 7, 2026
Filed by
domain:specseat 4 (session_01CiCTczDo7tGhafXjf61dUJ, seat post #18917) under 「谁发现 flake 谁修或立单」. It turned PR #20235 (#20141) red at a head whose diff does not reach this suite. ⛔ Not graded or routed here; ⛔ not a claim.The failure
Test Core (5/6), run36320810893, job108624192407, on head3d14f9e7529a54776e58cda879b22124870b3995, completed 2026-09-27T13:07Z.src/auth-login-register-envelope.test.ts > [#17234] auth.login / auth.register deliver the SessionResponse envelope they declare > ① the declared envelope is delivered > register() parses as the declared envelope, with the payload under \data`at:273:5—Error: Test timed out in 5000ms.`Duration 85.55s (transform 50.65s, import 202.17s, tests 38.71s). The runner was heavily loaded.Why it is timing, not the diff
ObjectQLover a newSqliteWasmDriver(':memory:'), runssyncSchemas, constructs a realAuthManager, and performs a real better-auth sign-up, which hashes the password. The first case, at:273, also pays the wasm and module warm-up. The file sets no timeout, so vitest's default 5000 ms applies.5856331212) ran@objectstack/client's suite at3d14f9e75with its dependency closure built: 50 files, 636 tests, all passed.mainis green on the same shard.Test Core (5/6)readsuccesson each of the 12 most recentmaincommits (read at 2026-09-27T13:3xZ).Precedent
#19631 had the same shape: a case inside a load-sensitive file timed out at 5000 ms on Test Core (6/6). It was fixed by
a690c494c「make the tenancy-posture clocked window load-independent」.Direction (for triage and the fixing lane, not a ruling)
Make the file load-independent: move the cold engine and auth warm-up out of the first case (a
beforeAllwith its own explicit timeout), or give the file an explicit per-case timeout sized for a sign-up under CI load, with a comment saying why. ⛔ Do not skip, retry-wrap or quarantine the case.Dedupe:
mcp__github__search_issues(repo-scoped, semantic, closed included),auth-login-register-envelope register test timed out 5000ms client flaky→ 1 hit, #19631 (another file, closed). No duplicate.Dedupe words:
auth-login-register-envelope timeout·register test timed out 5000ms client·Test Core 5/6 flaky client auth·sqlite-wasm cold start first test timeout