CB-578 stage B: make BackendQuarantine.none() actually inert
Added at merge review. none() held a clock frozen at 0 with a 1ns cooldown, so a quarantine() call on it recorded a deadline that could never pass — the credential would be locked out for the life of the daemon. Two production CompositePeerLauncher constructors default to none(), so that failure would have been silent and permanent. The implementer documented the limitation honestly rather than hiding it, but a stand-in named none() should not need the caveat. quarantine() is now a no-op on that instance, with a test asserting it. An inert value must omit the fact, never invent one.
This commit is contained in:
@@ -90,16 +90,27 @@ class BackendQuarantineTest {
|
||||
|
||||
@Test
|
||||
void noneReportsNothingQuarantinedWhenNeverToldTo() {
|
||||
// .none() is the stand-in for a caller whose code path never calls #quarantine at all (e.g.
|
||||
// the 2/5/6-arg CompositePeerLauncher constructors) — not a guarantee that a call to
|
||||
// #quarantine on it is a no-op. Left alone, as those call sites leave it, nothing is ever
|
||||
// quarantined.
|
||||
BackendQuarantine q = BackendQuarantine.none();
|
||||
|
||||
assertFalse(q.isQuarantined("anything"));
|
||||
assertTrue(q.activeRemainingSeconds().isEmpty());
|
||||
}
|
||||
|
||||
@Test
|
||||
void noneIgnoresAQuarantineCallInsteadOfLockingTheCredentialForever() {
|
||||
// .none() holds a clock frozen at 0, so if #quarantine recorded a deadline the credential
|
||||
// would never expire — locked out for the life of the daemon. Two production
|
||||
// CompositePeerLauncher constructors default to none(), so that failure would be silent and
|
||||
// permanent. An inert stand-in must omit the fact, never invent one.
|
||||
BackendQuarantine q = BackendQuarantine.none();
|
||||
|
||||
q.quarantine("shared-openai");
|
||||
|
||||
assertFalse(q.isQuarantined("shared-openai"), "none() must not quarantine anything");
|
||||
assertTrue(q.remainingSeconds("shared-openai").isEmpty());
|
||||
assertTrue(q.activeRemainingSeconds().isEmpty());
|
||||
}
|
||||
|
||||
@Test
|
||||
void aNonPositiveCooldownIsRejected() {
|
||||
assertThrows(IllegalArgumentException.class, () -> new BackendQuarantine(() -> 0L, 0L));
|
||||
|
||||
Reference in New Issue
Block a user