A review of the group-E fixes found 13 further defects; ten were introduced by
those fixes, two pre-existed and were merely relocated, one is deferred.
Services / transport
E-10 retireWorker synthesized no bg/exit frame, so sharedspice's s_bgRunning
mirror stayed latched true after a mid-run worker death: Run stayed
disabled and the promised fresh-worker restart was unreachable for the
whole session. Retirement now dispatches a synthetic controlled-exit
straight to the installed handler (never through dispatchEvt — a
fabricated frame must not touch the credit ledger). Driving the repro
exposed two further defects, both fixed here: a replacement worker
trapped on pre-init engine reads, and the rerun's cm_input_path/circ hit
that uninitialized engine before KiCad's validate() re-init (the native
flow assumes a crashed engine survives in-process — true for the dll,
false for a dead worker). Reads now answer their empty shapes pre-init,
writes lazy-init, and init is idempotent per worker engine.
E-19 dispatchEvt acked only AFTER handler(evt) returned, and the sharedspice
client deliberately rethrows non-trap errors — so each throw leaked one
unit of the 64-frame credit window until the stream died with a
misattributed "transport exceeded". The ack moves to a finally in both
service copies; the throw still propagates (the trap machinery needs it).
E-20 the oversize-line path promises to transfer the accepted prefix, but
with the window full that flush only DEFERS, and stopEventStream wiped
the deferred queue — losing the diagnostics that explain the failure.
The terminal notice now carries them as pendingEvents; both hosts
deliver them in order, unacked (the fatal frame is outside the credit
protocol).
E-21 the 30s prefetch deadline discarded every model already collected and
reported nothing. A caller-owned progress sink ships the partials and
the omission reaches the export report. (Awaiting the aborted collection
was rejected: an in-flight source fetch is not abortable — E-4's
original disease.) Plus a serving-candidate memo, so a .wrl ref served
by its .step fallback stops re-probing the miss on every export.
Scheduler
E-14 _terminalizeNativeTrap classified by message substring, so any plain JS
error QUOTING 'Aborted(' or 'out of bounds' permanently bricked a
healthy instance. Now structural only: instanceof RuntimeError plus a
duck-typed name check (verified in this build's glue that abort() throws
a genuine RuntimeError both pre- and post-runtime-init). Module.onAbort
now latches the gate — the authoritative notification, previously
ignored.
E-15 the shim half: _pumpResume gates on terminal (catching wakes already
queued at latch time) and resolveWait refuses on terminal WITHOUT
consuming the entry, so a frame stays visibly parked rather than
resuming inside a trapped module.
E-16 the E-5 handler read the realm-global scheduler at dispatch instead of
its installing module's; also frees the per-line buffer on the non-trap
rethrow path.
E-11 get_vec trusted the worker's res.length over the transferred arrays.
Observed death shape: a 4 GiB std::vector threw an unhandled
std::length_error that exited the editor's main loop. Now clamped, with
the buffers freed on every failure path.
Guardrails (replacing two deferred refactors: e2e→production-code injection and
collapsing the four copies of the worker-lifecycle machinery)
E-18 the source contract asserted comment-string counts — rewording failed
CI while moving a guard outside its #ifdef passed. It now parses the
#ifdef regions and asserts on code.
service-stub-parity.ts pins what the four lifecycle copies must share:
credit-window equality parsed from source, the finally-ack, boot
deadlines, terminal-notice consumption. The transport numbers are now
single-sourced from the worker.
CI actually runs the gates: the web/standalone vitest suites (which had
NEVER run in CI), the reducer, the source contract and the parity tool —
with a NON_PLAYWRIGHT_GATES check so deleting a step re-fails the lint.
E-22 the e2e occ stub's 60s boot watchdog, deleted in a66e109, is restored in
the ngspice-stub shape with a wedgeNextBoot() repro hook.
Every behavioral fix has red-then-green evidence (the reds were captured first).
E-17 (a stale RUNNING cross-stamping the next run's generation under E-6's
transport deferral) is DEFERRED with its analysis recorded — a real fix needs
run identity on the bg frames.
Test hygiene: the dwell lint now requires the mandated ": <why>" and all 47 bare
markers carry their reason; three export-report dwells became modal-lease polls;
exact-ledger assertions became relative deltas; the dead data-wx-dom-id branch,
an unused fault hook and unused receipt plumbing are gone; abort scans, wx
dialog drivers, the sim harness and the vitest FakeWorker are each one copy now.
Bumps kicad and wxwidgets to their findings-group-e tips.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
82 lines
3.7 KiB
TypeScript
82 lines
3.7 KiB
TypeScript
import * as fs from 'fs';
|
|
import * as path from 'path';
|
|
import { test, expect } from './fixtures';
|
|
|
|
/**
|
|
* occ_service boot watchdog (findings E-22): a wedged worker boot — an
|
|
* importScripts hang, pthread spawn wedge, or OOM-kill leaves a worker that
|
|
* never posts `ready` OR `bootError` — must settle the request with a loud
|
|
* boot-timeout report instead of hanging to the spec timeout with zero
|
|
* evidence, and the NEXT request must recover on a fresh generation against
|
|
* the real occ_service.
|
|
*
|
|
* The wedge is a real silent Worker (a data: module that runs nothing), armed
|
|
* one-shot through the harness hook; the recovery half exercises the real
|
|
* occ_service wasm end to end.
|
|
*/
|
|
|
|
test.describe('occ_service boot watchdog', () => {
|
|
test.setTimeout(240000);
|
|
|
|
test('a wedged boot settles with a timeout report and the next request recovers', async ({ page }) => {
|
|
await page.goto('/kicad/pcbnew.html', { waitUntil: 'domcontentloaded' });
|
|
|
|
const probeBoard = fs.readFileSync(
|
|
path.resolve(__dirname, '..', 'fixtures', 'demo', 'demo.kicad_pcb'),
|
|
'utf8',
|
|
);
|
|
|
|
await page.evaluate((boardText: string) => {
|
|
const runtime = globalThis as any;
|
|
runtime.__occServiceTestHooks.wedgeNextBoot(5000);
|
|
runtime.__occWedgeResult = null;
|
|
void runtime.occService.request({
|
|
kind: 'export',
|
|
board: new TextEncoder().encode(boardText),
|
|
jobJson: JSON.stringify({ format: 'step', export_components: false }),
|
|
fileName: 'wedged.step',
|
|
}).then((res: unknown) => { runtime.__occWedgeResult = res; });
|
|
}, probeBoard);
|
|
|
|
await expect.poll(
|
|
() => page.evaluate(() => (globalThis as any).__occWedgeResult),
|
|
{
|
|
message: 'the wedged boot must settle via the boot watchdog, not hang',
|
|
timeout: 30000,
|
|
},
|
|
).toMatchObject({
|
|
ok: false,
|
|
report: expect.stringContaining('boot timed out after 5000 ms'),
|
|
});
|
|
|
|
const wedgedState = await page.evaluate(
|
|
() => (globalThis as any).__occServiceTestHooks.snapshot());
|
|
expect(wedgedState.retiredGenerations, 'the wedged generation was retired')
|
|
.toEqual([1]);
|
|
expect(wedgedState.activeGeneration, 'no active generation remains').toBeNull();
|
|
expect(wedgedState.pending, 'nothing left pending').toBe(0);
|
|
|
|
// Recovery: the wedge was one-shot — this boots the REAL occ_service
|
|
// and completes a real export through it.
|
|
const recovered = await page.evaluate(async (boardText: string) => {
|
|
const runtime = globalThis as any;
|
|
return await runtime.occService.request({
|
|
kind: 'export',
|
|
board: new TextEncoder().encode(boardText),
|
|
jobJson: JSON.stringify({ format: 'step', export_components: false }),
|
|
fileName: 'recovered.step',
|
|
});
|
|
}, probeBoard);
|
|
expect(recovered.ok, 'the fresh generation must serve the retry').toBe(true);
|
|
|
|
const recoveredState = await page.evaluate(
|
|
() => (globalThis as any).__occServiceTestHooks.snapshot());
|
|
expect(recoveredState.workerGenerationsStarted, 'a replacement generation booted')
|
|
.toEqual([1, 2]);
|
|
expect(recoveredState.pending, 'the replacement generation quiesced').toBe(0);
|
|
|
|
const exports = await page.evaluate(() => (window as any).__occExports);
|
|
expect(exports, 'the recovery produced a real STEP capture').toHaveLength(1);
|
|
expect(exports[0].magic.startsWith('ISO-10303-21'), 'real STEP bytes').toBe(true);
|
|
});
|
|
});
|