5d075f1374
Six adversarial-review findings in the central SQL/ingest layer. F1 (AuditLogRepository.InsertChunkAsync) — the set-based ingest declared each string parameter at its COLUMN width (Actor/Target 256, Action 64, Outcome 16, Category 32, SourceNode 64), so SqlClient truncated an over-long value at bind time and committed the mutilated row — silent, in an append-only store, with no PayloadTruncated flag — while the per-row and reconciliation paths sent the same value in full and let the server reject it with 2628. Bind at the value's own length instead; explicit SqlDbType is kept (it fixes the VALUES constructor's derived column types and datetime2 precision). Design: reject everywhere, truncate nowhere — matching today's per-row behaviour. F2 (SiteCallAuditRepository.UpsertAsync) — the single-statement upsert ran the monotonic UPDATE first and INSERTed only if nothing matched. Two writers racing the first packet of one TrackedOperationId (the cached dual-write and the reconciliation pull carry DIFFERENT lifecycle states) both matched nothing, and the loser then skipped its INSERT or swallowed a 2627 — dropping its Status/RetryCount/HttpStatus/TerminalAtUtc. Legs swapped to `IF NOT EXISTS … INSERT; UPDATE <monotonic>` — still one round trip, and the loser's UPDATE now lands on the winner's row. The duplicate-key catch re-runs the monotonic UPDATE for the same reason. Moved to raw SQL with explicitly-typed parameters so the intricate rank predicate exists in exactly one place (an untyped DateTime would bind as `datetime` and round the freshness tiebreaker). F3 (docs/plans/sql/*.sql) — filtered-index DDL failed with error 1934 under the documented `docker exec … sqlcmd` path, which defaults QUOTED_IDENTIFIER OFF; once IX_Notifications_Delivered exists, QI-OFF DML on Notifications fails too. All four scripts now open with `SET QUOTED_IDENTIFIER ON; SET ANSI_NULLS ON; GO` (own batch, so it is in force when the next batch parses), and the migration convention in Component-ConfigurationDatabase.md documents `sqlcmd -I`. Verified live: the pre-fix script fails 1934 without -I, the fixed one applies. F4 (SiteCallAuditActor) — the off-mailbox reconciliation/purge passes reuse the injected repository, so tests drove one DbContext from the pass and a mailbox handler concurrently. Serialized at the CALL via a private SerializedRepository wrapper applied only by the test constructors, rather than running the pass on-mailbox: production keeps its PipeTo shape untouched, and the existing "a blocked drain does not stall ingest/query/KPI" regression tests stay meaningful (they would have been invalidated by suspending the mailbox). F5 (AuditLogIngestActor) — when the batch failed because the 20 s IngestBudget expired, the per-row fallback reused the same expired token: N instant failures, N counter bumps, zero accepted. The fallback now gets a fresh 5 s budget (inside the 30 s outer Ask), and a blown budget bumps the failure counter ONCE for the batch instead of once per row. F6 (NotificationOutboxRepository.UpdateAsync) — ExecuteUpdate's row count was discarded, so an operator Retry/Discard of a notification the retention purge had already deleted reported success (the pre-ExecuteUpdate code threw DbUpdateConcurrencyException). UpdateAsync now returns whether a row matched; the operator one-shots answer "notification not found" and emit no audit row for the action that did not happen, while the dispatcher logs a warning (its delivery already happened; nothing to retry). GetByIdAsync switched to AsNoTracking since the write is out-of-band. Tests: 5 new SQL-backed regressions (over-long Target rejected on both paths + boundary round-trip; concurrent first-write and already-created-by-another-writer upserts; vanished-row UpdateAsync), a token-identity pin on the ingest fallback, a repository-concurrency detector for the SiteCallAudit passes, and vanished-row operator-path tests. The F1/F2/F4 regressions were each confirmed failing against the pre-fix code. Suites: ConfigurationDatabase 369, AuditLog 378, SiteCallAudit 66, NotificationOutbox 152 — all green, solution builds with 0 warnings.
109 lines
4.3 KiB
C#
109 lines
4.3 KiB
C#
using Akka.Actor;
|
|
using Akka.TestKit.Xunit2;
|
|
using Microsoft.Extensions.DependencyInjection;
|
|
using Microsoft.Extensions.Logging.Abstractions;
|
|
using NSubstitute;
|
|
using ZB.MOM.WW.ScadaBridge.Commons.Entities.Notifications;
|
|
using ZB.MOM.WW.ScadaBridge.Commons.Interfaces.Repositories;
|
|
using ZB.MOM.WW.ScadaBridge.Commons.Types.Enums;
|
|
using ZB.MOM.WW.ScadaBridge.NotificationOutbox.Delivery;
|
|
using ZB.MOM.WW.ScadaBridge.NotificationOutbox.Messages;
|
|
using ZB.MOM.WW.ScadaBridge.NotificationOutbox.Tests.TestSupport;
|
|
|
|
namespace ZB.MOM.WW.ScadaBridge.NotificationOutbox.Tests;
|
|
|
|
/// <summary>
|
|
/// Task 16: Tests for the <see cref="NotificationOutboxActor"/> daily purge job — the
|
|
/// periodic sweep that bulk-deletes terminal notification rows older than
|
|
/// <see cref="NotificationOutboxOptions.TerminalRetention"/> via
|
|
/// <see cref="INotificationOutboxRepository.DeleteTerminalOlderThanAsync"/>.
|
|
/// </summary>
|
|
public class NotificationOutboxActorPurgeTests : TestKit
|
|
{
|
|
private readonly INotificationOutboxRepository _outboxRepository =
|
|
OutboxRepositorySubstitute.Healthy();
|
|
|
|
private readonly INotificationRepository _notificationRepository =
|
|
Substitute.For<INotificationRepository>();
|
|
|
|
private IServiceProvider BuildServiceProvider()
|
|
{
|
|
var services = new ServiceCollection();
|
|
services.AddScoped(_ => _outboxRepository);
|
|
services.AddScoped(_ => _notificationRepository);
|
|
return services.BuildServiceProvider();
|
|
}
|
|
|
|
/// <summary>
|
|
/// Creates the actor with both the dispatch and purge timers set to a long interval so
|
|
/// neither periodic timer fires during a test — purge ticks are sent manually instead.
|
|
/// </summary>
|
|
private IActorRef CreateActor(NotificationOutboxOptions? options = null)
|
|
{
|
|
return Sys.ActorOf(Props.Create(() => new NotificationOutboxActor(
|
|
BuildServiceProvider(),
|
|
options ?? new NotificationOutboxOptions
|
|
{
|
|
DispatchInterval = TimeSpan.FromHours(1),
|
|
PurgeInterval = TimeSpan.FromHours(1),
|
|
},
|
|
new NoOpCentralAuditWriter(),
|
|
NullLogger<NotificationOutboxActor>.Instance)));
|
|
}
|
|
|
|
[Fact]
|
|
public void PurgeTick_DeletesTerminalRows_WithCutoffAtUtcNowMinusTerminalRetention()
|
|
{
|
|
var retention = TimeSpan.FromDays(30);
|
|
var options = new NotificationOutboxOptions
|
|
{
|
|
DispatchInterval = TimeSpan.FromHours(1),
|
|
PurgeInterval = TimeSpan.FromHours(1),
|
|
TerminalRetention = retention,
|
|
};
|
|
_outboxRepository
|
|
.DeleteTerminalOlderThanAsync(Arg.Any<DateTimeOffset>(), Arg.Any<CancellationToken>())
|
|
.Returns(3);
|
|
var actor = CreateActor(options);
|
|
|
|
var expectedCutoff = DateTimeOffset.UtcNow - retention;
|
|
actor.Tell(InternalMessages.PurgeTick.Instance);
|
|
|
|
AwaitAssert(() =>
|
|
_outboxRepository.Received(1).DeleteTerminalOlderThanAsync(
|
|
Arg.Is<DateTimeOffset>(cutoff =>
|
|
(cutoff - expectedCutoff).Duration() < TimeSpan.FromMinutes(1)),
|
|
Arg.Any<CancellationToken>()));
|
|
}
|
|
|
|
[Fact]
|
|
public void FaultedPurge_DoesNotCrashActor_AndSubsequentPurgeStillRuns()
|
|
{
|
|
var calls = 0;
|
|
_outboxRepository
|
|
.DeleteTerminalOlderThanAsync(Arg.Any<DateTimeOffset>(), Arg.Any<CancellationToken>())
|
|
.Returns(_ =>
|
|
{
|
|
calls++;
|
|
// First purge faults; the second returns normally to prove the actor lives on.
|
|
if (calls == 1)
|
|
{
|
|
throw new InvalidOperationException("db down");
|
|
}
|
|
|
|
return Task.FromResult(0);
|
|
});
|
|
var actor = CreateActor();
|
|
|
|
// First tick: the purge faults internally but must be handled and not kill the actor.
|
|
actor.Tell(InternalMessages.PurgeTick.Instance);
|
|
AwaitAssert(() => _outboxRepository.Received(1).DeleteTerminalOlderThanAsync(
|
|
Arg.Any<DateTimeOffset>(), Arg.Any<CancellationToken>()));
|
|
|
|
// Second tick: if the faulted purge had crashed the actor, this would never run.
|
|
actor.Tell(InternalMessages.PurgeTick.Instance);
|
|
AwaitAssert(() => _outboxRepository.Received(2).DeleteTerminalOlderThanAsync(
|
|
Arg.Any<DateTimeOffset>(), Arg.Any<CancellationToken>()));
|
|
}
|
|
}
|