From 1d55c69dc7873d0ec6fce21e618124cf63cf1822 Mon Sep 17 00:00:00 2001 From: DanConwayDev Date: Mon, 17 Aug 2026 07:24:49 +0000 Subject: [PATCH] test(sync): isolate NEG proxy source traffic The NEG concurrency proxy records counters across all client connections. Once live self-subscription became reliable, the permissive archive source discovered the proxy URL in its own announcement and ran negentropy through the same measurement point, making the test evidence include scenery traffic. Reuse the production-outbound-policy archive source fixture already used by REQ. Its loopback event-directed targets are rejected while the syncing relay bootstrap remains operator-configured and allowed, preserving end-to-end coverage and attributing proxy counts only to the relay under test. Correctness assumes this integration topology remains loopback-only. Deliberately excluded: production sync behavior and the REQ scenario are unchanged. Validation: nix develop -c cargo fmt --check; cargo test --test sync sync::neg_concurrency::startup_historic_sync_stays_within_relay_neg_concurrency_limit; cargo test --test sync sync::req_concurrency::startup_historic_sync_stays_within_relay_req_concurrency_limit. --- tests/common/relay.rs | 11 +++++------ tests/sync/neg_concurrency.rs | 5 ++++- 2 files changed, 9 insertions(+), 7 deletions(-) diff --git a/tests/common/relay.rs b/tests/common/relay.rs index 6d97e81..540e97d 100644 --- a/tests/common/relay.rs +++ b/tests/common/relay.rs @@ -401,12 +401,11 @@ impl TestRelay { /// URL in the announcement so the relay under test targets the proxied /// connection. Under the permissive test policy the source itself also /// treats that URL as an event-directed sync target — it is a distinct - /// host:port that happens to front the source — and opens its own REQ - /// traffic through the proxy, contending with the relay under test for a - /// budget the scenario means to measure alone. The production policy - /// rejects non-global event-directed targets, so the source stays - /// scenery. Its own hosting, admission, and serving behavior is - /// unchanged. + /// host:port that happens to front the source — and opens its own sync + /// traffic through the proxy, contaminating measurements the scenario + /// means to attribute to the relay under test alone. The production + /// policy rejects non-global event-directed targets, so the source stays + /// scenery. Its own hosting, admission, and serving behavior is unchanged. pub async fn start_archive_source_behind_proxy() -> Self { Self::start_internal( port::reserve_port(), diff --git a/tests/sync/neg_concurrency.rs b/tests/sync/neg_concurrency.rs index c91ab15..e565dc5 100644 --- a/tests/sync/neg_concurrency.rs +++ b/tests/sync/neg_concurrency.rs @@ -97,7 +97,10 @@ async fn startup_historic_sync_stays_within_relay_neg_concurrency_limit() { // announcement's relays tag lists the proxy (so the syncing relay // targets the proxied connection), not the source itself, so the // source runs in archive-all mode to accept it. - let source = TestRelay::start_with_archive_config(true, false).await; + // The source applies the production outbound target policy so it does + // not itself sync through the proxy: the proxy's NEG measurements belong + // to the syncing relay under test. + let source = TestRelay::start_archive_source_behind_proxy().await; let proxy = NegLimitingProxy::start(source.url(), PROXY_NEG_LIMIT).await; // 3. One hosted repository: announcement + state event + git data. The