Skip to content

test: ignore late identities while awaiting rotating-keys ping - #3001

Merged
He-Pin merged 1 commit into
apache:mainfrom
He-Pin:fix/rotating-keys-ignore-late-identify
May 29, 2026
Merged

test: ignore late identities while awaiting rotating-keys ping#3001
He-Pin merged 1 commit into
apache:mainfrom
He-Pin:fix/rotating-keys-ignore-late-identify

Conversation

@He-Pin

@He-Pin He-Pin commented May 28, 2026

Copy link
Copy Markdown
Member

Motivation

RotatingKeysSSLEngineProviderSpec can receive a delayed ActorIdentity from an earlier Identify attempt after the target actor ref has already been resolved. Nightly retry policy still fails builds when that stale identity arrives before the ping reply.

Modification

Wait for the expected ping with fishForMessage and ignore late ActorIdentity messages while keeping the same per-attempt timeout budget.

Result

The test accepts the intended ping reply without being failed by harmless delayed Identify responses.

Tests

  • JDK 21: remote / Test / testOnly org.apache.pekko.remote.artery.tcp.ssl.RotatingProviderWithChangingKeysSpec
  • JDK 25: remote / Test / testOnly org.apache.pekko.remote.artery.tcp.ssl.RotatingProviderWithChangingKeysSpec (fails on existing JDK 25 EKU certificate validation behavior)
  • scalafmt --mode diff-ref=origin/main --quiet
  • scalafmt --list --mode diff-ref=origin/main
  • git diff --check

References

Refs #2994

Motivation:
RotatingKeysSSLEngineProviderSpec can receive a delayed ActorIdentity from an earlier Identify attempt after the target actor ref has already been resolved. Nightly retry policy still fails builds when that stale identity arrives before the ping reply.

Modification:
Wait for the expected ping with fishForMessage and ignore late ActorIdentity messages while keeping the same per-attempt timeout budget.

Result:
The test accepts the intended ping reply without being failed by harmless delayed Identify responses.

Tests:
- JDK 21: remote / Test / testOnly org.apache.pekko.remote.artery.tcp.ssl.RotatingProviderWithChangingKeysSpec
- JDK 25: remote / Test / testOnly org.apache.pekko.remote.artery.tcp.ssl.RotatingProviderWithChangingKeysSpec (fails on existing JDK 25 EKU certificate validation behavior)
- scalafmt --mode diff-ref=origin/main --quiet
- scalafmt --list --mode diff-ref=origin/main
- git diff --check

References:
Refs apache#2994

@pjfanning pjfanning left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@He-Pin
He-Pin merged commit 900e1f6 into apache:main May 29, 2026
9 checks passed
@He-Pin
He-Pin deleted the fix/rotating-keys-ignore-late-identify branch May 29, 2026 06:03
132982jianan pushed a commit to 132982jianan/pekko that referenced this pull request Aug 2, 2026
动机:
在目标 actor 引用已经解析之后,RotatingKeysSSLEngineProviderSpec 可以从之前的识别尝试中接收延迟的 ActorIdentity。当过时的身份在 ping 回复之前到达时,夜间重试策略仍然会失败。

修改:
使用 FishForMessage 等待预期的 ping,并忽略迟到的 ActorIdentity 消息,同时保持相同的每次尝试超时预算。

结果:
该测试接受预期的 ping 回复,而不会因无害的延迟识别响应而失败。

测试:
- JDK 21:远程/测试/testOnly org.apache.pekko.remote.artery.tcp.ssl.RotatingProviderWithChangingKeysSpec
- JDK 25:remote / Test / testOnly org.apache.pekko.remote.artery.tcp.ssl.RotatingProviderWithChangingKeysSpec(现有 JDK 25 EKU 证书验证行为失败)
- scalafmt --mode diff-ref=origin/main --quiet
- scalafmt --list --mode diff-ref=origin/main
- git diff --检查

参考文献:
参考号apache#2994
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants