From 8845c39804f9c4a167658193d2d54af9d4619213 Mon Sep 17 00:00:00 2001 From: Kayshen-X Date: Sat, 8 Aug 2026 12:48:59 +0800 Subject: [PATCH] fix(desktop): unblock native CI on windows and de-flake the idle heartbeat test MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The locator HSM signer is a unix-socket daemon with no Windows target, but its unconditional std::os::unix imports failed cargo check on the windows runner — the socket server and secure-file layers are now cfg(unix) with a stub main. The transfer-idle heartbeat test pinned its handshake windows to the same 400ms as the deadline under test, so a loaded runner could flake the connect phase; the idle deadline (and the validation-capped handshake windows) now sit at 2s. --- crates/op-collab-relay-locator-hsm/src/lib.rs | 5 +++++ .../op-collab-relay-locator-hsm/src/main.rs | 19 ++++++++++++++++--- .../op-collab-transport/src/runtime_tests.rs | 10 +++++++--- 3 files changed, 28 insertions(+), 6 deletions(-) diff --git a/crates/op-collab-relay-locator-hsm/src/lib.rs b/crates/op-collab-relay-locator-hsm/src/lib.rs index 5170f5430..912f35579 100644 --- a/crates/op-collab-relay-locator-hsm/src/lib.rs +++ b/crates/op-collab-relay-locator-hsm/src/lib.rs @@ -2,7 +2,12 @@ pub mod config; pub mod error; pub mod pkcs11; pub mod protocol; +// The signer daemon speaks over a permission-checked Unix domain socket and +// enforces unix file modes on its secrets; there is no Windows deployment +// target, so the socket server and secure-file layers are unix-only. +#[cfg(unix)] pub mod secure_file; +#[cfg(unix)] pub mod server; pub use config::{KeyConfig, Region, SignerConfig}; diff --git a/crates/op-collab-relay-locator-hsm/src/main.rs b/crates/op-collab-relay-locator-hsm/src/main.rs index 234060771..6f479270b 100644 --- a/crates/op-collab-relay-locator-hsm/src/main.rs +++ b/crates/op-collab-relay-locator-hsm/src/main.rs @@ -1,8 +1,12 @@ +// The signer only deploys on unix (permission-checked unix socket); other +// hosts get a stub main so workspace-wide checks still build the target. +#![cfg_attr(not(unix), allow(dead_code))] + use std::{env, path::PathBuf, process::ExitCode}; -use op_collab_relay_locator_hsm::{ - secure_file, server, KeyStore, SignerConfig, SignerError, SignerResult, -}; +#[cfg(unix)] +use op_collab_relay_locator_hsm::{secure_file, server, KeyStore, SignerConfig}; +use op_collab_relay_locator_hsm::{SignerError, SignerResult}; use tracing_subscriber::EnvFilter; enum Command { @@ -18,6 +22,7 @@ struct Arguments { config: PathBuf, } +#[cfg(unix)] fn main() -> ExitCode { init_tracing(); match run() { @@ -29,6 +34,14 @@ fn main() -> ExitCode { } } +#[cfg(not(unix))] +fn main() -> ExitCode { + init_tracing(); + eprintln!("locator HSM signer requires a unix host"); + ExitCode::FAILURE +} + +#[cfg(unix)] fn run() -> SignerResult<()> { let arguments = parse_arguments()?; let config_bytes = secure_file::read_config(&arguments.config)?; diff --git a/crates/op-collab-transport/src/runtime_tests.rs b/crates/op-collab-transport/src/runtime_tests.rs index 96afe090a..49e78d214 100644 --- a/crates/op-collab-transport/src/runtime_tests.rs +++ b/crates/op-collab-transport/src/runtime_tests.rs @@ -79,9 +79,13 @@ mod heartbeat_idle { TransportConfig { timeouts: TimeoutConfig { heartbeat: Duration::from_millis(50), - idle: Duration::from_millis(400), - read_write: Duration::from_millis(400), - admission: Duration::from_millis(400), + // The transfer-idle deadline is what this module tests; 2s + // keeps the run short while leaving the handshake windows + // (capped at idle by config validation) wide enough that a + // loaded CI runner cannot flake the connect/admission phase. + idle: Duration::from_secs(2), + read_write: Duration::from_secs(2), + admission: Duration::from_secs(2), ..TimeoutConfig::default() }, ..TransportConfig::default()