Skip to content

Fix flaky autests for timeout, sigusr2, and thread_config - #13012

Merged
bryancall merged 5 commits into
apache:masterfrom
bryancall:fix/flaky-autests
Mar 25, 2026
Merged

Fix flaky autests for timeout, sigusr2, and thread_config#13012
bryancall merged 5 commits into
apache:masterfrom
bryancall:fix/flaky-autests

Conversation

@bryancall

@bryancall bryancall commented Mar 23, 2026

Copy link
Copy Markdown
Contributor

Problem

The tls_conn_timeout and thread_config autests fail intermittently under parallel ASAN runs. The ssl-delay-server helper dies when a client disconnects during the handshake delay (SIGPIPE) or when accept() is interrupted (EINTR), failing the StillRunningAfter check. The thread_config test can't find the correct traffic_server process under ASAN because the process CWD differs from the expected ts_path.

Changes

  • Handle SIGPIPE in ssl-delay-server -- ignore SIGPIPE to prevent the helper from dying when a client disconnects during the TLS handshake delay.
  • Retry accept() on EINTR -- under heavy parallel load, accept() can return EINTR; retry instead of treating it as a fatal error.
  • Fix accept() error check -- use < 0 instead of <= 0 since fd 0 is a valid descriptor when stdin is closed.
  • Add cmdline matching for ASAN in check_threads.py -- fall back to matching ts_path in process command line arguments when the CWD doesn't match, which happens under ASAN.

Testing

  • Run AuTests in ASAN configuration
  • No production code paths changed (test-only PR)
  • All 15 CI platforms green

The ssl-delay-server test helper could die unexpectedly when a
client disconnects during the handshake delay. SIGPIPE from the
broken connection kills the process, or accept() returns EINTR
under heavy parallel load. Add SIGPIPE ignore and EINTR retry to
keep the server alive for the StillRunningAfter check.
Test 1's Default process had Ready = When.FileExists(diags.log),
but by the time Default starts, rotate_diags_log has already moved
diags.log to diags.log_old. This creates a deadlock: Default waits
for diags.log to exist, but only SIGUSR2 (sent by Default) would
cause TS to recreate it. The StartBefore chain already guarantees
correct ordering (ts → rotate → Default), so the Ready condition
is unnecessary and harmful.
Under ASAN, the ATS process CWD may differ from the
expected ts_path. Fall back to matching ts_path in the
process command line arguments so the test can find the
correct traffic_server process.
@bryancall bryancall self-assigned this Mar 23, 2026
@bryancall bryancall added AuTest Tests ASan Address Sanitizer labels Mar 23, 2026
@bryancall bryancall added this to the 11.0.0 milestone Mar 23, 2026
@bryancall
bryancall requested a review from Copilot March 23, 2026 17:44

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Test-only PR to stabilize three flaky AuTests under parallel ASAN runs by hardening helper behavior and improving AuTest process sequencing / matching.

Changes:

  • Update ssl-delay-server helper to ignore SIGPIPE and retry accept() on EINTR.
  • Make thread_config’s thread-count helper identify the correct traffic_server process more reliably under ASAN by matching via CWD or command line.
  • Adjust sigusr2 test process ordering to remove a deadlocking Ready condition and clarify the intended startup chain.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 2 comments.

File Description
tests/gold_tests/timeout/ssl-delay-server.cc Improves helper robustness against SIGPIPE and EINTR during accept.
tests/gold_tests/thread_config/check_threads.py Improves ATS process identification under ASAN by broadening the matching criteria.
tests/gold_tests/logging/sigusr2.test.py Removes deadlocking Ready gating and documents intended process ordering for SIGUSR2 log rotation.

Comment thread tests/gold_tests/timeout/ssl-delay-server.cc Outdated
Comment thread tests/gold_tests/logging/sigusr2.test.py Outdated
@bryancall
bryancall requested a review from bneradt March 23, 2026 22:39
accept() returns -1 on error but fd 0 is a valid descriptor
(e.g. if stdin is closed). The <= 0 check would incorrectly
treat a valid connection as failure.
Comment thread tests/gold_tests/logging/sigusr2.test.py Outdated
@bryancall
bryancall requested a review from bneradt March 25, 2026 18:51
@bryancall
bryancall merged commit ff31470 into apache:master Mar 25, 2026
15 checks passed
cmcfarlen pushed a commit that referenced this pull request Jun 9, 2026
* Handle SIGPIPE in ssl-delay-server to prevent helper death
  when a client disconnects during TLS handshake delay.
* Retry accept() on EINTR under heavy parallel load instead
  of treating the interruption as a fatal error.
* Fix accept() error check to use < 0 instead of <= 0 since
  fd 0 is a valid descriptor when stdin is closed.
* Add cmdline matching fallback in check_threads.py for ASAN
  where the process CWD differs from expected ts_path.

(cherry picked from commit ff31470)
bneradt pushed a commit to bneradt/trafficserver that referenced this pull request Jun 10, 2026
* Handle SIGPIPE in ssl-delay-server to prevent helper death
  when a client disconnects during TLS handshake delay.
* Retry accept() on EINTR under heavy parallel load instead
  of treating the interruption as a fatal error.
* Fix accept() error check to use < 0 instead of <= 0 since
  fd 0 is a valid descriptor when stdin is closed.
* Add cmdline matching fallback in check_threads.py for ASAN
  where the process CWD differs from expected ts_path.

(cherry picked from commit ff31470)
cmcfarlen pushed a commit that referenced this pull request Jun 10, 2026
* curl 8.20 test update: curl PROXY destination changes (#13239)

curl 8.20 intentionally mirrors --haproxy-clientip into both PROXY
addresses to keep the header address family consistent. The
TSVConnPPInfo AuTest still expected the older destination address, so
jobs with newer curl failed even though ATS preserved the PROXY metadata
it received.

This relaxes the destination-address expectation to accept either curl
behavior while continuing to verify the source address and PROXY
metadata. This also wraps the long curl command strings while leaving
the test's request flow unchanged.

(cherry picked from commit ad0ce02)

* fedora:44: Trim remap ACL reload waits (#13237)

The remap ACL AuTests run hundreds of reload scenarios in a single case,
and the Fedora 44 shard is sensitive to extra reload-wait overhead,
causing the tests to hang. Their reload sentinel also counted only
explicit reloads, even though the log contains the startup load marker
too.

This replaces the long-lived sleep Ready helper with a short command
that exits once the expected reload marker count is present. This also
waits for the startup marker plus the explicit reload count, so each
scenario observes the reload it just requested.

(cherry picked from commit c52eeda)

* Align AuTests with latest proxy-verifier checks (#12986)

The latest proxy-verifier now fails a run when a verifier server or
client is given proxy-side checks for traffic that ATS never produces.
Most tests only needed stale proxy-request or proxy-response nodes
removed, but the shared replay cases below need server-specific files
so each verifier only owns traffic it can actually observe.

- disable_pristine_host_hdr_server_canary_false.replay.yaml keeps
  the canary server on uuid 1 when pristine_host_hdr stays enabled.
- disable_pristine_host_hdr_server_canary_true.replay.yaml keeps the
  canary server on uuid 1 when the Host header is rewritten.
- disable_pristine_host_hdr_server_stable.replay.yaml keeps the
  stable server on uuid 2, which the canary server never receives.
- escalate_original_server_default.replay.yaml keeps only the
  requests that the default-mode origin server really handles.
- escalate_failover_server_default.replay.yaml keeps only the GET
  requests that default-mode escalation sends to failover.
- escalate_original_server_non_get.replay.yaml keeps the origin-side
  subset when --escalate-non-get-methods is enabled.
- escalate_failover_server_non_get.replay.yaml keeps the failover
  subset, including the escalated HEAD request in that mode.
- ja4_fingerprint_basic_server.replay.yaml limits the non-preserve
  test to its one real request instead of preserve-only checks.
- traffic_dump_server.yaml keeps origin verification only for the
  sessions that really reach origin in the main traffic_dump test.
- traffic_dump_ip_filter_server.yaml keeps only the /one request
  used by the traffic_dump IP filter test.

These per-server replays preserve fallback server-response directives
and client-side coverage while dropping only the proxy-side checks
that latest proxy-verifier now correctly reports as unprocessed.

(cherry picked from commit ecf505c)

* Fix 10.1.x PV replay expectations

Adjust two replay expectations after backporting the proxy-verifier 3.1 cleanup. The 10.1.x branch has fewer escalate transactions, and duplicate header checks now observe the combined header value.

* [autest] thread_config: add startup polling and skip test on non-Linux (#12940)

* thread_config: add startup polling for thread checks and skip on non-Linux
check_threads.py now uses a short bounded poll/retry window so thread-count
validation does not fail on startup races; the test is also skipped on
non-Linux platforms because per-thread introspection used by this check is not
reliably available there.
* thread_config: stop retrying when Process.threads() access is denied

(cherry picked from commit 6dfaadd)

* Fix flaky autests for timeout, sigusr2, and thread_config (#13012)

* Handle SIGPIPE in ssl-delay-server to prevent helper death
  when a client disconnects during TLS handshake delay.
* Retry accept() on EINTR under heavy parallel load instead
  of treating the interruption as a fatal error.
* Fix accept() error check to use < 0 instead of <= 0 since
  fd 0 is a valid descriptor when stdin is closed.
* Add cmdline matching fallback in check_threads.py for ASAN
  where the process CWD differs from expected ts_path.

(cherry picked from commit ff31470)

* Fix 10.1.x JA4 AuTest setup

Initialize the branch-local JA4 test helper's preserve flag after backporting replay changes from master. Without it the test fails during Python load before the actual replay runs.

* Proxy Verifier: use concise stack protocol specification (#13003)

Proxy Verifier v3.0.0 has a more concise `stack` configurable for
`protocol` specification. This makes use of that over the more verbose
full `protocol` sequence.

* tests/gold_tests/headers tests: use ATSReplayTest (#13033)

Move the replay-friendly headers gold tests to ATSReplayTest
wrappers and describe their ATS, origin, and client setup in
replay YAML.

This keeps the cache, range, redirect, HSTS, and alternate
handling coverage while making the tests easier to read and
maintain, and removes the old gold files left orphaned by the
conversion.

(cherry picked from commit 49cb7c8)

* Adapt headers replay tests for 10.1.x

---------

Co-authored-by: bneradt <bneradt@yahooinc.com>
Co-authored-by: Mo Chen <mochen@apache.org>
Co-authored-by: Bryan Call <bcall@apache.org>
@cmcfarlen cmcfarlen modified the milestones: 11.0.0, 10.2.0 Jun 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ASan Address Sanitizer AuTest Tests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants