Close F3: give the two load-sensitive conformance tests explicit budgets - #329
Merged
Merged
Conversation
Every F3 recurrence was `Test timed out in 5000ms`, never an assertion, in the checkout-state test or in the 2,600-line "authenticates downloaded GitHub records" test, which is the only test over 0.7 s in either file. Both finish well inside five seconds alone and exceed it only under full-suite CPU contention. Give exactly those two tests the 30-second budget F2 used; no assertion or guard changes. Record F3 as fixed and R1 as fixed on main by #328 in the review record. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The security review record retains contradictory superseded F3 dispositions and follow-up instructions.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Adds explicit 30-second budgets to two load-sensitive conformance tests and records F3 as fixed.
Changes:
- Extends the two targeted test timeouts.
- Updates the security review record and revision history.
| File | Description |
|---|---|
tests/conformance-gaps.spec.ts |
Adds a 30-second test budget. |
tests/conformance-checkouts-publication.spec.ts |
Adds a 30-second test budget. |
docs/workflows/first-release-security-review.md |
Records F3 resolution and evidence. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

This resolves the F3 follow-up in the #40 review record, which was due 2026-10-17.
Evidence
Every captured recurrence was the same failure,
Error: Test timed out in 5000ms, never an assertion. It came from two tests:conformance-checkouts-publication.spec.ts › rejects staged, unstaged, hidden-index, and wrong-remote states, the original F3. It takes 532 ms alone and 7,168 ms in a loaded full run.conformance-gaps.spec.ts › authenticates downloaded GitHub records instead of committed aggregate claims. At load average 11 it is the only test over 0.7 s in either file, at 1,797 ms. It is one 2,600-line fixture-heavy test, lines 2751–5373. This cycle it timed out twice locally at load averages around 40, and it passed alone and in hosted CI.Both finish well inside five seconds on an idle machine and exceed it only under full-suite CPU contention. That is the question F3's follow-up asked to settle.
Change
mainby Route managed familiar contract and analytics through the authority resolver #328.cd10a3fSHIP recommendation is unchanged: this is test infrastructure and not in any packed artifact.Validation: both files pass, 116 passed and 1 skipped.
🤖 Generated with Claude Code