Skip to content

chore: use testify's require in tests - #2792

Merged
Tofel merged 4 commits into
dx-5122-alerts-assertion-p12from
dx-5122-alerts-assertion-p13
Sep 9, 2026
Merged

chore: use testify's require in tests#2792
Tofel merged 4 commits into
dx-5122-alerts-assertion-p12from
dx-5122-alerts-assertion-p13

Conversation

@Tofel

@Tofel Tofel commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Migrates all test assertions from hand-rolled t.Fatal/Error to testify require, adds the testify dependency, and adds a recorder-mode fail-fast in check.go for from < StartedAt.

Review focus: the check.go fail-fast (the only non-test change); the rest is a mechanical assertion swap.

@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown

⚠️ API Diff Results - github.com/smartcontractkit/chainlink-testing-framework/grafana-alertcheck

⚠️ Breaking Changes (1)

package github (1)
  • com/smartcontractkit/chainlink-testing-framework/grafana-alertcheck/cmd/grafana-alertcheck — 🗑️ Removed

✅ Compatible Changes (1)

package github (1)
  • com/smartcontractkit/chainlink-testing-framework/grafana-alertcheck/cmd — ➕ Added

📄 View full apidiff report

@Tofel
Tofel force-pushed the dx-5122-alerts-assertion-p12 branch from 775befe to 6f766ca Compare September 4, 2026 15:03
@Tofel
Tofel force-pushed the dx-5122-alerts-assertion-p13 branch from c97e92d to 10c74ca Compare September 4, 2026 15:03
@Tofel
Tofel force-pushed the dx-5122-alerts-assertion-p12 branch from 6f766ca to 803f45f Compare September 4, 2026 15:15
@Tofel
Tofel force-pushed the dx-5122-alerts-assertion-p13 branch from 10c74ca to 33eea1f Compare September 4, 2026 15:15
@Tofel
Tofel force-pushed the dx-5122-alerts-assertion-p12 branch from 803f45f to 7a37ee3 Compare September 7, 2026 09:35
@Tofel
Tofel force-pushed the dx-5122-alerts-assertion-p13 branch from 33eea1f to a0a237e Compare September 7, 2026 09:35
@Tofel
Tofel marked this pull request as ready for review September 7, 2026 09:38
@Tofel
Tofel requested a review from a team as a code owner September 7, 2026 09:38
Copilot AI lite review requested due to automatic review settings September 7, 2026 09:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The new recorder-mode fail-fast can mask log-identity failures, and a couple of updated tests use require.Fail from goroutines via observeAll, which is unreliable.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

This PR standardizes the Grafana alertcheck test suite on testify/require for fail-fast assertions, adds the testify module dependency, and introduces a recorder-mode “fail fast” in internal/gate/check.go when from is before the recorded header’s StartedAt.

Changes:

  • Replace hand-rolled t.Fatal/t.Error patterns across tests with require.* assertions.
  • Add github.com/stretchr/testify (and indirect YAML dep) to go.mod/go.sum.
  • Add a recorder-mode early exit in check.go for the statically-detectable from < StartedAt bound violation.
File summaries
File Description
grafana-alertcheck/internal/gate/watch_test.go Mechanical migration of assertions to require.
grafana-alertcheck/internal/gate/watch_daemon_test.go Mechanical migration of assertions to require in integration-style daemon tests.
grafana-alertcheck/internal/gate/source_test.go Mechanical migration of assertions to require.
grafana-alertcheck/internal/gate/schedule_test.go Mechanical migration of assertions to require.
grafana-alertcheck/internal/gate/resolve_test.go Mechanical migration of assertions to require.
grafana-alertcheck/internal/gate/parse_state_test.go Mechanical migration of assertions to require.
grafana-alertcheck/internal/gate/parse_ruler_test.go Mechanical migration of assertions to require.
grafana-alertcheck/internal/gate/log_test.go Mechanical migration of assertions to require.
grafana-alertcheck/internal/gate/jsonreq_test.go Mechanical migration of assertions to require.
grafana-alertcheck/internal/gate/duration_test.go Mechanical migration of assertions to require.
grafana-alertcheck/internal/gate/coverage_test.go Mechanical migration of assertions to require.
grafana-alertcheck/internal/gate/classify_test.go Mechanical migration of assertions to require.
grafana-alertcheck/internal/gate/check.go Adds recorder-mode fail-fast when from precedes StartedAt.
grafana-alertcheck/internal/gate/check_test.go Updates tests to require and adds coverage for the new fail-fast path.
grafana-alertcheck/go.mod Adds testify dependency (and indirect YAML dep).
grafana-alertcheck/go.sum Adds checksums for newly introduced dependencies.
grafana-alertcheck/cmd/grafana-alertcheck/watch_test.go Mechanical migration of CLI tests to require.
grafana-alertcheck/cmd/grafana-alertcheck/table_test.go Mechanical migration of table rendering tests to require.
grafana-alertcheck/cmd/grafana-alertcheck/main_test.go Mechanical migration of CLI entrypoint tests to require.
grafana-alertcheck/cmd/grafana-alertcheck/list_test.go Mechanical migration of CLI list tests to require.
grafana-alertcheck/cmd/grafana-alertcheck/check_test.go Mechanical migration of CLI check tests to require.
Review details

Suppressed comments (1)

grafana-alertcheck/internal/gate/check_test.go:895

  • This responder can be invoked from goroutines via observeAll during the drain wait. require.Fail triggers FailNow from a worker goroutine, which doesn't reliably stop the test. Prefer returning an error (the caller path already makes the test fail by violating the require.NoError assertion).
		src := newCheckSource(func(title string, _ int) (Observation, error) {
			require.Fail(t, fmt.Sprintf("the drain wait polled skipped rule %q", title))
			return Observation{}, errors.New("unexpected poll")
		})
  • Files reviewed: 20/21 changed files
  • Comments generated: 2
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread grafana-alertcheck/internal/gate/check.go Outdated
Comment thread grafana-alertcheck/internal/gate/check_test.go
@Tofel
Tofel force-pushed the dx-5122-alerts-assertion-p12 branch from 7a37ee3 to f4df0d5 Compare September 7, 2026 09:46
@Tofel
Tofel force-pushed the dx-5122-alerts-assertion-p13 branch 2 times, most recently from 4855fcd to a87fc14 Compare September 7, 2026 15:02
@Tofel
Tofel force-pushed the dx-5122-alerts-assertion-p12 branch from f4df0d5 to 34040df Compare September 7, 2026 15:02
@Tofel
Tofel force-pushed the dx-5122-alerts-assertion-p13 branch from a87fc14 to ca3ccc6 Compare September 7, 2026 15:19
@Tofel
Tofel removed this pull request from stack #2791 September 9, 2026 09:52
* chore: fix logging and std out printing

* chore: truncate to seconds when comparing from time

* chore: add centralized docs (#2802)

* chore: add centralized docs

* chore: further update docs

* chore: address code review comments (#2807)

* chore: address code review comments

* chore: get rid of goreleaser
@Tofel
Tofel merged commit f9d48c5 into dx-5122-alerts-assertion-p12 Sep 9, 2026
46 of 52 checks passed
@Tofel
Tofel deleted the dx-5122-alerts-assertion-p13 branch September 9, 2026 09:57
Tofel added a commit that referenced this pull request Sep 9, 2026
* chore: more concise comments

* fix: merge conflict

* chore: shorten comments

* fix: resolve conflict

* chore: use testify's require in tests (#2792)

* chore: use testify's require in tests

* chore: move remaining assumptions to testify

* chore: address code review comments

* chore: fix logging and std out printing (#2798)

* chore: fix logging and std out printing

* chore: truncate to seconds when comparing from time

* chore: add centralized docs (#2802)

* chore: add centralized docs

* chore: further update docs

* chore: address code review comments (#2807)

* chore: address code review comments

* chore: get rid of goreleaser
Tofel added a commit that referenced this pull request Sep 9, 2026
* chore: implement phase 11

Add coverage.go's declared-KeepLast check (no_data_state/exec_err_state,
not just an observed reason) and close the remaining §22 gaps: newly_bad's
no-early-exit clock assertion, a recorder-mode gap right after the deploy,
a rule's own coverage gap overriding its own recovery, a genuinely
skew-discriminating staleness test, exit-2 consequences on two
Reason-only coverage tests, and end-to-end checks for log-name
collapse, a truncated log, and the real watch-written state histogram.

* chore: address code review comments

* chore: more concise comments (#2790)

* chore: more concise comments

* fix: merge conflict

* chore: shorten comments

* fix: resolve conflict

* chore: use testify's require in tests (#2792)

* chore: use testify's require in tests

* chore: move remaining assumptions to testify

* chore: address code review comments

* chore: fix logging and std out printing (#2798)

* chore: fix logging and std out printing

* chore: truncate to seconds when comparing from time

* chore: add centralized docs (#2802)

* chore: add centralized docs

* chore: further update docs

* chore: address code review comments (#2807)

* chore: address code review comments

* chore: get rid of goreleaser
Tofel added a commit that referenced this pull request Sep 9, 2026
* Wire watch/check subcommands to the gate library, with a table+JSON
renderer and H6/H7 exit-code mapping. Extend Result with per-rule/global
thresholds and a real skew bound; export SkewHardLimit; reject --states
normal.

* chore: fix goreleaser.yaml and add version command

* chore: implement phase 11 (#2789)

* chore: implement phase 11

Add coverage.go's declared-KeepLast check (no_data_state/exec_err_state,
not just an observed reason) and close the remaining §22 gaps: newly_bad's
no-early-exit clock assertion, a recorder-mode gap right after the deploy,
a rule's own coverage gap overriding its own recovery, a genuinely
skew-discriminating staleness test, exit-2 consequences on two
Reason-only coverage tests, and end-to-end checks for log-name
collapse, a truncated log, and the real watch-written state histogram.

* chore: address code review comments

* chore: more concise comments (#2790)

* chore: more concise comments

* fix: merge conflict

* chore: shorten comments

* fix: resolve conflict

* chore: use testify's require in tests (#2792)

* chore: use testify's require in tests

* chore: move remaining assumptions to testify

* chore: address code review comments

* chore: fix logging and std out printing (#2798)

* chore: fix logging and std out printing

* chore: truncate to seconds when comparing from time

* chore: add centralized docs (#2802)

* chore: add centralized docs

* chore: further update docs

* chore: address code review comments (#2807)

* chore: address code review comments

* chore: get rid of goreleaser
Tofel added a commit that referenced this pull request Sep 9, 2026
* chore: implement phase 9

Invariant defended: H5/H7. The one question: can check report a pass
over a window it did not prove?

Check() is the I/O shell around the pure decide(). Single-step
synthesizes the header and its own sentinel, so no mode flag reaches
the pure layer. Log mode stops the recorder before the one full read.

The header, not a definition re-resolved after the window closed, is
the authority for what was paused when the window opened — it decides
`skipped`, the drain set, and the transitionGrace max. The flock, not
the pidfile, is the authority for whether a writer still exists.

* chore: remove unix build tag

* chore: implement phase 10 (#2788)

* Wire watch/check subcommands to the gate library, with a table+JSON
renderer and H6/H7 exit-code mapping. Extend Result with per-rule/global
thresholds and a real skew bound; export SkewHardLimit; reject --states
normal.

* chore: fix goreleaser.yaml and add version command

* chore: implement phase 11 (#2789)

* chore: implement phase 11

Add coverage.go's declared-KeepLast check (no_data_state/exec_err_state,
not just an observed reason) and close the remaining §22 gaps: newly_bad's
no-early-exit clock assertion, a recorder-mode gap right after the deploy,
a rule's own coverage gap overriding its own recovery, a genuinely
skew-discriminating staleness test, exit-2 consequences on two
Reason-only coverage tests, and end-to-end checks for log-name
collapse, a truncated log, and the real watch-written state histogram.

* chore: address code review comments

* chore: more concise comments (#2790)

* chore: more concise comments

* fix: merge conflict

* chore: shorten comments

* fix: resolve conflict

* chore: use testify's require in tests (#2792)

* chore: use testify's require in tests

* chore: move remaining assumptions to testify

* chore: address code review comments

* chore: fix logging and std out printing (#2798)

* chore: fix logging and std out printing

* chore: truncate to seconds when comparing from time

* chore: add centralized docs (#2802)

* chore: add centralized docs

* chore: further update docs

* chore: address code review comments (#2807)

* chore: address code review comments

* chore: get rid of goreleaser
Tofel added a commit that referenced this pull request Sep 9, 2026
* chore: implement phase 8

Invariant defended: H6/H7. The one question: can a violation ever
outrank an unobservable rule, or can a pass happen without
Violations empty and err nil?

Adds classify.go: the pure per-instance classifier (outcome table,
preexisting policy, BadFor) and decide(), the seam combining
proveCoverage with those timelines under one Policy. Consolidates
rule-poll filtering and skew translation onto pollsForRule/runnerTime,
shared with coverage.go.

* chore: rename some vars + add unit tests

* chore: address code review comments

* chore: implement phase 9 (#2787)

* chore: implement phase 9

Invariant defended: H5/H7. The one question: can check report a pass
over a window it did not prove?

Check() is the I/O shell around the pure decide(). Single-step
synthesizes the header and its own sentinel, so no mode flag reaches
the pure layer. Log mode stops the recorder before the one full read.

The header, not a definition re-resolved after the window closed, is
the authority for what was paused when the window opened — it decides
`skipped`, the drain set, and the transitionGrace max. The flock, not
the pidfile, is the authority for whether a writer still exists.

* chore: remove unix build tag

* chore: implement phase 10 (#2788)

* Wire watch/check subcommands to the gate library, with a table+JSON
renderer and H6/H7 exit-code mapping. Extend Result with per-rule/global
thresholds and a real skew bound; export SkewHardLimit; reject --states
normal.

* chore: fix goreleaser.yaml and add version command

* chore: implement phase 11 (#2789)

* chore: implement phase 11

Add coverage.go's declared-KeepLast check (no_data_state/exec_err_state,
not just an observed reason) and close the remaining §22 gaps: newly_bad's
no-early-exit clock assertion, a recorder-mode gap right after the deploy,
a rule's own coverage gap overriding its own recovery, a genuinely
skew-discriminating staleness test, exit-2 consequences on two
Reason-only coverage tests, and end-to-end checks for log-name
collapse, a truncated log, and the real watch-written state histogram.

* chore: address code review comments

* chore: more concise comments (#2790)

* chore: more concise comments

* fix: merge conflict

* chore: shorten comments

* fix: resolve conflict

* chore: use testify's require in tests (#2792)

* chore: use testify's require in tests

* chore: move remaining assumptions to testify

* chore: address code review comments

* chore: fix logging and std out printing (#2798)

* chore: fix logging and std out printing

* chore: truncate to seconds when comparing from time

* chore: add centralized docs (#2802)

* chore: add centralized docs

* chore: further update docs

* chore: address code review comments (#2807)

* chore: address code review comments

* chore: get rid of goreleaser
Tofel added a commit that referenced this pull request Sep 9, 2026
* chore: implement phase 7

Invariant defended: H3. The one question: can a rule be called alive
because it looked alive one poll ago?

proveCoverage (grafana-alertcheck/internal/gate/coverage.go) is the pure
coverage function: nine checks over one rule's polls — sentinel,
from-bounds, heartbeat continuity, health error/nodata, liveness,
in-window pause, rule absence, KeepLast. Liveness is absolute, never a
delta. Cross-domain comparisons translate by each poll's own skew and
widen boundary segments by its skew bound, fail-closed.

* chore: enhance unit tests

* chore: address code review comments

* chore: implement phase 8 (#2786)

* chore: implement phase 8

Invariant defended: H6/H7. The one question: can a violation ever
outrank an unobservable rule, or can a pass happen without
Violations empty and err nil?

Adds classify.go: the pure per-instance classifier (outcome table,
preexisting policy, BadFor) and decide(), the seam combining
proveCoverage with those timelines under one Policy. Consolidates
rule-poll filtering and skew translation onto pollsForRule/runnerTime,
shared with coverage.go.

* chore: rename some vars + add unit tests

* chore: address code review comments

* chore: implement phase 9 (#2787)

* chore: implement phase 9

Invariant defended: H5/H7. The one question: can check report a pass
over a window it did not prove?

Check() is the I/O shell around the pure decide(). Single-step
synthesizes the header and its own sentinel, so no mode flag reaches
the pure layer. Log mode stops the recorder before the one full read.

The header, not a definition re-resolved after the window closed, is
the authority for what was paused when the window opened — it decides
`skipped`, the drain set, and the transitionGrace max. The flock, not
the pidfile, is the authority for whether a writer still exists.

* chore: remove unix build tag

* chore: implement phase 10 (#2788)

* Wire watch/check subcommands to the gate library, with a table+JSON
renderer and H6/H7 exit-code mapping. Extend Result with per-rule/global
thresholds and a real skew bound; export SkewHardLimit; reject --states
normal.

* chore: fix goreleaser.yaml and add version command

* chore: implement phase 11 (#2789)

* chore: implement phase 11

Add coverage.go's declared-KeepLast check (no_data_state/exec_err_state,
not just an observed reason) and close the remaining §22 gaps: newly_bad's
no-early-exit clock assertion, a recorder-mode gap right after the deploy,
a rule's own coverage gap overriding its own recovery, a genuinely
skew-discriminating staleness test, exit-2 consequences on two
Reason-only coverage tests, and end-to-end checks for log-name
collapse, a truncated log, and the real watch-written state histogram.

* chore: address code review comments

* chore: more concise comments (#2790)

* chore: more concise comments

* fix: merge conflict

* chore: shorten comments

* fix: resolve conflict

* chore: use testify's require in tests (#2792)

* chore: use testify's require in tests

* chore: move remaining assumptions to testify

* chore: address code review comments

* chore: fix logging and std out printing (#2798)

* chore: fix logging and std out printing

* chore: truncate to seconds when comparing from time

* chore: add centralized docs (#2802)

* chore: add centralized docs

* chore: further update docs

* chore: address code review comments (#2807)

* chore: address code review comments

* chore: get rid of goreleaser
Tofel added a commit that referenced this pull request Sep 9, 2026
* chore: implement phase 6

Invariant defended: H2. The one question: can watch return success over a
window that nothing is recording?

Watch() records the first observation of each non-skipped rule, then detaches
a child that polls at the cadence in the header. The parent returns only after
the child reports ready on an inherited pipe, and writes the pidfile after
that. A clean stop writes the sentinel; a hard error does not.

* chore: add a unit test, remove build tags

* chore: address code review comments

* chore: implement phase 7 (#2785)

* chore: implement phase 7

Invariant defended: H3. The one question: can a rule be called alive
because it looked alive one poll ago?

proveCoverage (grafana-alertcheck/internal/gate/coverage.go) is the pure
coverage function: nine checks over one rule's polls — sentinel,
from-bounds, heartbeat continuity, health error/nodata, liveness,
in-window pause, rule absence, KeepLast. Liveness is absolute, never a
delta. Cross-domain comparisons translate by each poll's own skew and
widen boundary segments by its skew bound, fail-closed.

* chore: enhance unit tests

* chore: address code review comments

* chore: implement phase 8 (#2786)

* chore: implement phase 8

Invariant defended: H6/H7. The one question: can a violation ever
outrank an unobservable rule, or can a pass happen without
Violations empty and err nil?

Adds classify.go: the pure per-instance classifier (outcome table,
preexisting policy, BadFor) and decide(), the seam combining
proveCoverage with those timelines under one Policy. Consolidates
rule-poll filtering and skew translation onto pollsForRule/runnerTime,
shared with coverage.go.

* chore: rename some vars + add unit tests

* chore: address code review comments

* chore: implement phase 9 (#2787)

* chore: implement phase 9

Invariant defended: H5/H7. The one question: can check report a pass
over a window it did not prove?

Check() is the I/O shell around the pure decide(). Single-step
synthesizes the header and its own sentinel, so no mode flag reaches
the pure layer. Log mode stops the recorder before the one full read.

The header, not a definition re-resolved after the window closed, is
the authority for what was paused when the window opened — it decides
`skipped`, the drain set, and the transitionGrace max. The flock, not
the pidfile, is the authority for whether a writer still exists.

* chore: remove unix build tag

* chore: implement phase 10 (#2788)

* Wire watch/check subcommands to the gate library, with a table+JSON
renderer and H6/H7 exit-code mapping. Extend Result with per-rule/global
thresholds and a real skew bound; export SkewHardLimit; reject --states
normal.

* chore: fix goreleaser.yaml and add version command

* chore: implement phase 11 (#2789)

* chore: implement phase 11

Add coverage.go's declared-KeepLast check (no_data_state/exec_err_state,
not just an observed reason) and close the remaining §22 gaps: newly_bad's
no-early-exit clock assertion, a recorder-mode gap right after the deploy,
a rule's own coverage gap overriding its own recovery, a genuinely
skew-discriminating staleness test, exit-2 consequences on two
Reason-only coverage tests, and end-to-end checks for log-name
collapse, a truncated log, and the real watch-written state histogram.

* chore: address code review comments

* chore: more concise comments (#2790)

* chore: more concise comments

* fix: merge conflict

* chore: shorten comments

* fix: resolve conflict

* chore: use testify's require in tests (#2792)

* chore: use testify's require in tests

* chore: move remaining assumptions to testify

* chore: address code review comments

* chore: fix logging and std out printing (#2798)

* chore: fix logging and std out printing

* chore: truncate to seconds when comparing from time

* chore: add centralized docs (#2802)

* chore: add centralized docs

* chore: further update docs

* chore: address code review comments (#2807)

* chore: address code review comments

* chore: get rid of goreleaser
Tofel added a commit that referenced this pull request Sep 9, 2026
* chore: implement phase 5

Add the JSONL evidence log (P5).

- log.go: Header/Poll records, reduction, H2 transition markers,
  §3.2 verification, append-only Writer with flock, ReadLog
- flock_unix.go: non-blocking exclusive lock, unix only
- schedule.go: DeriveTimingsFromLog — log-mode cadence comes from the
  header, never from the definitions

* chore: remove unix build tags

* chore: address code review comments

* chore: implement phase 6 (#2784)

* chore: implement phase 6

Invariant defended: H2. The one question: can watch return success over a
window that nothing is recording?

Watch() records the first observation of each non-skipped rule, then detaches
a child that polls at the cadence in the header. The parent returns only after
the child reports ready on an inherited pipe, and writes the pidfile after
that. A clean stop writes the sentinel; a hard error does not.

* chore: add a unit test, remove build tags

* chore: address code review comments

* chore: implement phase 7 (#2785)

* chore: implement phase 7

Invariant defended: H3. The one question: can a rule be called alive
because it looked alive one poll ago?

proveCoverage (grafana-alertcheck/internal/gate/coverage.go) is the pure
coverage function: nine checks over one rule's polls — sentinel,
from-bounds, heartbeat continuity, health error/nodata, liveness,
in-window pause, rule absence, KeepLast. Liveness is absolute, never a
delta. Cross-domain comparisons translate by each poll's own skew and
widen boundary segments by its skew bound, fail-closed.

* chore: enhance unit tests

* chore: address code review comments

* chore: implement phase 8 (#2786)

* chore: implement phase 8

Invariant defended: H6/H7. The one question: can a violation ever
outrank an unobservable rule, or can a pass happen without
Violations empty and err nil?

Adds classify.go: the pure per-instance classifier (outcome table,
preexisting policy, BadFor) and decide(), the seam combining
proveCoverage with those timelines under one Policy. Consolidates
rule-poll filtering and skew translation onto pollsForRule/runnerTime,
shared with coverage.go.

* chore: rename some vars + add unit tests

* chore: address code review comments

* chore: implement phase 9 (#2787)

* chore: implement phase 9

Invariant defended: H5/H7. The one question: can check report a pass
over a window it did not prove?

Check() is the I/O shell around the pure decide(). Single-step
synthesizes the header and its own sentinel, so no mode flag reaches
the pure layer. Log mode stops the recorder before the one full read.

The header, not a definition re-resolved after the window closed, is
the authority for what was paused when the window opened — it decides
`skipped`, the drain set, and the transitionGrace max. The flock, not
the pidfile, is the authority for whether a writer still exists.

* chore: remove unix build tag

* chore: implement phase 10 (#2788)

* Wire watch/check subcommands to the gate library, with a table+JSON
renderer and H6/H7 exit-code mapping. Extend Result with per-rule/global
thresholds and a real skew bound; export SkewHardLimit; reject --states
normal.

* chore: fix goreleaser.yaml and add version command

* chore: implement phase 11 (#2789)

* chore: implement phase 11

Add coverage.go's declared-KeepLast check (no_data_state/exec_err_state,
not just an observed reason) and close the remaining §22 gaps: newly_bad's
no-early-exit clock assertion, a recorder-mode gap right after the deploy,
a rule's own coverage gap overriding its own recovery, a genuinely
skew-discriminating staleness test, exit-2 consequences on two
Reason-only coverage tests, and end-to-end checks for log-name
collapse, a truncated log, and the real watch-written state histogram.

* chore: address code review comments

* chore: more concise comments (#2790)

* chore: more concise comments

* fix: merge conflict

* chore: shorten comments

* fix: resolve conflict

* chore: use testify's require in tests (#2792)

* chore: use testify's require in tests

* chore: move remaining assumptions to testify

* chore: address code review comments

* chore: fix logging and std out printing (#2798)

* chore: fix logging and std out printing

* chore: truncate to seconds when comparing from time

* chore: add centralized docs (#2802)

* chore: add centralized docs

* chore: further update docs

* chore: address code review comments (#2807)

* chore: address code review comments

* chore: get rid of goreleaser
Tofel added a commit that referenced this pull request Sep 9, 2026
* chore: implement phase 4

Add per-rule poll timings, scheduler, and budget check (P4).

- schedule.go: DeriveTimings, Scheduler, CheckBudget (§5)
- Address review: add Folder/Title resolve test, rename
  CheckBudget's minPollEvery to tightestUID

* chore: enhance unit tests

* chore: address code review comments

* chore: implement phase 5 (#2783)

* chore: implement phase 5

Add the JSONL evidence log (P5).

- log.go: Header/Poll records, reduction, H2 transition markers,
  §3.2 verification, append-only Writer with flock, ReadLog
- flock_unix.go: non-blocking exclusive lock, unix only
- schedule.go: DeriveTimingsFromLog — log-mode cadence comes from the
  header, never from the definitions

* chore: remove unix build tags

* chore: address code review comments

* chore: implement phase 6 (#2784)

* chore: implement phase 6

Invariant defended: H2. The one question: can watch return success over a
window that nothing is recording?

Watch() records the first observation of each non-skipped rule, then detaches
a child that polls at the cadence in the header. The parent returns only after
the child reports ready on an inherited pipe, and writes the pidfile after
that. A clean stop writes the sentinel; a hard error does not.

* chore: add a unit test, remove build tags

* chore: address code review comments

* chore: implement phase 7 (#2785)

* chore: implement phase 7

Invariant defended: H3. The one question: can a rule be called alive
because it looked alive one poll ago?

proveCoverage (grafana-alertcheck/internal/gate/coverage.go) is the pure
coverage function: nine checks over one rule's polls — sentinel,
from-bounds, heartbeat continuity, health error/nodata, liveness,
in-window pause, rule absence, KeepLast. Liveness is absolute, never a
delta. Cross-domain comparisons translate by each poll's own skew and
widen boundary segments by its skew bound, fail-closed.

* chore: enhance unit tests

* chore: address code review comments

* chore: implement phase 8 (#2786)

* chore: implement phase 8

Invariant defended: H6/H7. The one question: can a violation ever
outrank an unobservable rule, or can a pass happen without
Violations empty and err nil?

Adds classify.go: the pure per-instance classifier (outcome table,
preexisting policy, BadFor) and decide(), the seam combining
proveCoverage with those timelines under one Policy. Consolidates
rule-poll filtering and skew translation onto pollsForRule/runnerTime,
shared with coverage.go.

* chore: rename some vars + add unit tests

* chore: address code review comments

* chore: implement phase 9 (#2787)

* chore: implement phase 9

Invariant defended: H5/H7. The one question: can check report a pass
over a window it did not prove?

Check() is the I/O shell around the pure decide(). Single-step
synthesizes the header and its own sentinel, so no mode flag reaches
the pure layer. Log mode stops the recorder before the one full read.

The header, not a definition re-resolved after the window closed, is
the authority for what was paused when the window opened — it decides
`skipped`, the drain set, and the transitionGrace max. The flock, not
the pidfile, is the authority for whether a writer still exists.

* chore: remove unix build tag

* chore: implement phase 10 (#2788)

* Wire watch/check subcommands to the gate library, with a table+JSON
renderer and H6/H7 exit-code mapping. Extend Result with per-rule/global
thresholds and a real skew bound; export SkewHardLimit; reject --states
normal.

* chore: fix goreleaser.yaml and add version command

* chore: implement phase 11 (#2789)

* chore: implement phase 11

Add coverage.go's declared-KeepLast check (no_data_state/exec_err_state,
not just an observed reason) and close the remaining §22 gaps: newly_bad's
no-early-exit clock assertion, a recorder-mode gap right after the deploy,
a rule's own coverage gap overriding its own recovery, a genuinely
skew-discriminating staleness test, exit-2 consequences on two
Reason-only coverage tests, and end-to-end checks for log-name
collapse, a truncated log, and the real watch-written state histogram.

* chore: address code review comments

* chore: more concise comments (#2790)

* chore: more concise comments

* fix: merge conflict

* chore: shorten comments

* fix: resolve conflict

* chore: use testify's require in tests (#2792)

* chore: use testify's require in tests

* chore: move remaining assumptions to testify

* chore: address code review comments

* chore: fix logging and std out printing (#2798)

* chore: fix logging and std out printing

* chore: truncate to seconds when comparing from time

* chore: add centralized docs (#2802)

* chore: add centralized docs

* chore: further update docs

* chore: address code review comments (#2807)

* chore: address code review comments

* chore: get rid of goreleaser
Tofel added a commit that referenced this pull request Sep 9, 2026
* chore: implement phase 3

Add Resolve() for alert name resolution (uid:/Title/Folder/Title/
Folder/Group/Title forms, UID collapse, no-match suggestions) and the
grafana-alertcheck CLI's list subcommand, the first runnable piece of
the gate.

Incorporates review fixes: reject empty path segments in classifyForm,
guard uid: against an empty suffix, scope the no-match rule count and
suggestions to supported rule kinds only, and exit 0 on -h/--help.

* chore: enhance unit tests

* chore: implement phase 4 (#2782)

* chore: implement phase 4

Add per-rule poll timings, scheduler, and budget check (P4).

- schedule.go: DeriveTimings, Scheduler, CheckBudget (§5)
- Address review: add Folder/Title resolve test, rename
  CheckBudget's minPollEvery to tightestUID

* chore: enhance unit tests

* chore: address code review comments

* chore: implement phase 5 (#2783)

* chore: implement phase 5

Add the JSONL evidence log (P5).

- log.go: Header/Poll records, reduction, H2 transition markers,
  §3.2 verification, append-only Writer with flock, ReadLog
- flock_unix.go: non-blocking exclusive lock, unix only
- schedule.go: DeriveTimingsFromLog — log-mode cadence comes from the
  header, never from the definitions

* chore: remove unix build tags

* chore: address code review comments

* chore: implement phase 6 (#2784)

* chore: implement phase 6

Invariant defended: H2. The one question: can watch return success over a
window that nothing is recording?

Watch() records the first observation of each non-skipped rule, then detaches
a child that polls at the cadence in the header. The parent returns only after
the child reports ready on an inherited pipe, and writes the pidfile after
that. A clean stop writes the sentinel; a hard error does not.

* chore: add a unit test, remove build tags

* chore: address code review comments

* chore: implement phase 7 (#2785)

* chore: implement phase 7

Invariant defended: H3. The one question: can a rule be called alive
because it looked alive one poll ago?

proveCoverage (grafana-alertcheck/internal/gate/coverage.go) is the pure
coverage function: nine checks over one rule's polls — sentinel,
from-bounds, heartbeat continuity, health error/nodata, liveness,
in-window pause, rule absence, KeepLast. Liveness is absolute, never a
delta. Cross-domain comparisons translate by each poll's own skew and
widen boundary segments by its skew bound, fail-closed.

* chore: enhance unit tests

* chore: address code review comments

* chore: implement phase 8 (#2786)

* chore: implement phase 8

Invariant defended: H6/H7. The one question: can a violation ever
outrank an unobservable rule, or can a pass happen without
Violations empty and err nil?

Adds classify.go: the pure per-instance classifier (outcome table,
preexisting policy, BadFor) and decide(), the seam combining
proveCoverage with those timelines under one Policy. Consolidates
rule-poll filtering and skew translation onto pollsForRule/runnerTime,
shared with coverage.go.

* chore: rename some vars + add unit tests

* chore: address code review comments

* chore: implement phase 9 (#2787)

* chore: implement phase 9

Invariant defended: H5/H7. The one question: can check report a pass
over a window it did not prove?

Check() is the I/O shell around the pure decide(). Single-step
synthesizes the header and its own sentinel, so no mode flag reaches
the pure layer. Log mode stops the recorder before the one full read.

The header, not a definition re-resolved after the window closed, is
the authority for what was paused when the window opened — it decides
`skipped`, the drain set, and the transitionGrace max. The flock, not
the pidfile, is the authority for whether a writer still exists.

* chore: remove unix build tag

* chore: implement phase 10 (#2788)

* Wire watch/check subcommands to the gate library, with a table+JSON
renderer and H6/H7 exit-code mapping. Extend Result with per-rule/global
thresholds and a real skew bound; export SkewHardLimit; reject --states
normal.

* chore: fix goreleaser.yaml and add version command

* chore: implement phase 11 (#2789)

* chore: implement phase 11

Add coverage.go's declared-KeepLast check (no_data_state/exec_err_state,
not just an observed reason) and close the remaining §22 gaps: newly_bad's
no-early-exit clock assertion, a recorder-mode gap right after the deploy,
a rule's own coverage gap overriding its own recovery, a genuinely
skew-discriminating staleness test, exit-2 consequences on two
Reason-only coverage tests, and end-to-end checks for log-name
collapse, a truncated log, and the real watch-written state histogram.

* chore: address code review comments

* chore: more concise comments (#2790)

* chore: more concise comments

* fix: merge conflict

* chore: shorten comments

* fix: resolve conflict

* chore: use testify's require in tests (#2792)

* chore: use testify's require in tests

* chore: move remaining assumptions to testify

* chore: address code review comments

* chore: fix logging and std out printing (#2798)

* chore: fix logging and std out printing

* chore: truncate to seconds when comparing from time

* chore: add centralized docs (#2802)

* chore: add centralized docs

* chore: further update docs

* chore: address code review comments (#2807)

* chore: address code review comments

* chore: get rid of goreleaser
Tofel added a commit that referenced this pull request Sep 9, 2026
* chore: implement phase 2

Fix retry-error conflation, measure full poll latency, and harden Source test doubles for concurrency.

* chore: enhance unit tests

* chore: address code review comments

* chore: implement phase 3 (#2781)

* chore: implement phase 3

Add Resolve() for alert name resolution (uid:/Title/Folder/Title/
Folder/Group/Title forms, UID collapse, no-match suggestions) and the
grafana-alertcheck CLI's list subcommand, the first runnable piece of
the gate.

Incorporates review fixes: reject empty path segments in classifyForm,
guard uid: against an empty suffix, scope the no-match rule count and
suggestions to supported rule kinds only, and exit 0 on -h/--help.

* chore: enhance unit tests

* chore: implement phase 4 (#2782)

* chore: implement phase 4

Add per-rule poll timings, scheduler, and budget check (P4).

- schedule.go: DeriveTimings, Scheduler, CheckBudget (§5)
- Address review: add Folder/Title resolve test, rename
  CheckBudget's minPollEvery to tightestUID

* chore: enhance unit tests

* chore: address code review comments

* chore: implement phase 5 (#2783)

* chore: implement phase 5

Add the JSONL evidence log (P5).

- log.go: Header/Poll records, reduction, H2 transition markers,
  §3.2 verification, append-only Writer with flock, ReadLog
- flock_unix.go: non-blocking exclusive lock, unix only
- schedule.go: DeriveTimingsFromLog — log-mode cadence comes from the
  header, never from the definitions

* chore: remove unix build tags

* chore: address code review comments

* chore: implement phase 6 (#2784)

* chore: implement phase 6

Invariant defended: H2. The one question: can watch return success over a
window that nothing is recording?

Watch() records the first observation of each non-skipped rule, then detaches
a child that polls at the cadence in the header. The parent returns only after
the child reports ready on an inherited pipe, and writes the pidfile after
that. A clean stop writes the sentinel; a hard error does not.

* chore: add a unit test, remove build tags

* chore: address code review comments

* chore: implement phase 7 (#2785)

* chore: implement phase 7

Invariant defended: H3. The one question: can a rule be called alive
because it looked alive one poll ago?

proveCoverage (grafana-alertcheck/internal/gate/coverage.go) is the pure
coverage function: nine checks over one rule's polls — sentinel,
from-bounds, heartbeat continuity, health error/nodata, liveness,
in-window pause, rule absence, KeepLast. Liveness is absolute, never a
delta. Cross-domain comparisons translate by each poll's own skew and
widen boundary segments by its skew bound, fail-closed.

* chore: enhance unit tests

* chore: address code review comments

* chore: implement phase 8 (#2786)

* chore: implement phase 8

Invariant defended: H6/H7. The one question: can a violation ever
outrank an unobservable rule, or can a pass happen without
Violations empty and err nil?

Adds classify.go: the pure per-instance classifier (outcome table,
preexisting policy, BadFor) and decide(), the seam combining
proveCoverage with those timelines under one Policy. Consolidates
rule-poll filtering and skew translation onto pollsForRule/runnerTime,
shared with coverage.go.

* chore: rename some vars + add unit tests

* chore: address code review comments

* chore: implement phase 9 (#2787)

* chore: implement phase 9

Invariant defended: H5/H7. The one question: can check report a pass
over a window it did not prove?

Check() is the I/O shell around the pure decide(). Single-step
synthesizes the header and its own sentinel, so no mode flag reaches
the pure layer. Log mode stops the recorder before the one full read.

The header, not a definition re-resolved after the window closed, is
the authority for what was paused when the window opened — it decides
`skipped`, the drain set, and the transitionGrace max. The flock, not
the pidfile, is the authority for whether a writer still exists.

* chore: remove unix build tag

* chore: implement phase 10 (#2788)

* Wire watch/check subcommands to the gate library, with a table+JSON
renderer and H6/H7 exit-code mapping. Extend Result with per-rule/global
thresholds and a real skew bound; export SkewHardLimit; reject --states
normal.

* chore: fix goreleaser.yaml and add version command

* chore: implement phase 11 (#2789)

* chore: implement phase 11

Add coverage.go's declared-KeepLast check (no_data_state/exec_err_state,
not just an observed reason) and close the remaining §22 gaps: newly_bad's
no-early-exit clock assertion, a recorder-mode gap right after the deploy,
a rule's own coverage gap overriding its own recovery, a genuinely
skew-discriminating staleness test, exit-2 consequences on two
Reason-only coverage tests, and end-to-end checks for log-name
collapse, a truncated log, and the real watch-written state histogram.

* chore: address code review comments

* chore: more concise comments (#2790)

* chore: more concise comments

* fix: merge conflict

* chore: shorten comments

* fix: resolve conflict

* chore: use testify's require in tests (#2792)

* chore: use testify's require in tests

* chore: move remaining assumptions to testify

* chore: address code review comments

* chore: fix logging and std out printing (#2798)

* chore: fix logging and std out printing

* chore: truncate to seconds when comparing from time

* chore: add centralized docs (#2802)

* chore: add centralized docs

* chore: further update docs

* chore: address code review comments (#2807)

* chore: address code review comments

* chore: get rid of goreleaser
Tofel added a commit that referenced this pull request Sep 9, 2026
* chore: implement phase 1

Strict parsers for the state and ruler endpoints (H1), a Prometheus-style
duration parser, and fixtures sliced from real Grafana 13.1.0 payloads
covering every required/optional-field and must-error case, including the
"Normal (NoData)"/"Normal (Error)" composite reason states found live in the
current fleet capture (not in the original plan's vocabulary).

* chore: apply code review comments

* chore: implement phase 2 (#2780)

* chore: implement phase 2

Fix retry-error conflation, measure full poll latency, and harden Source test doubles for concurrency.

* chore: enhance unit tests

* chore: address code review comments

* chore: implement phase 3 (#2781)

* chore: implement phase 3

Add Resolve() for alert name resolution (uid:/Title/Folder/Title/
Folder/Group/Title forms, UID collapse, no-match suggestions) and the
grafana-alertcheck CLI's list subcommand, the first runnable piece of
the gate.

Incorporates review fixes: reject empty path segments in classifyForm,
guard uid: against an empty suffix, scope the no-match rule count and
suggestions to supported rule kinds only, and exit 0 on -h/--help.

* chore: enhance unit tests

* chore: implement phase 4 (#2782)

* chore: implement phase 4

Add per-rule poll timings, scheduler, and budget check (P4).

- schedule.go: DeriveTimings, Scheduler, CheckBudget (§5)
- Address review: add Folder/Title resolve test, rename
  CheckBudget's minPollEvery to tightestUID

* chore: enhance unit tests

* chore: address code review comments

* chore: implement phase 5 (#2783)

* chore: implement phase 5

Add the JSONL evidence log (P5).

- log.go: Header/Poll records, reduction, H2 transition markers,
  §3.2 verification, append-only Writer with flock, ReadLog
- flock_unix.go: non-blocking exclusive lock, unix only
- schedule.go: DeriveTimingsFromLog — log-mode cadence comes from the
  header, never from the definitions

* chore: remove unix build tags

* chore: address code review comments

* chore: implement phase 6 (#2784)

* chore: implement phase 6

Invariant defended: H2. The one question: can watch return success over a
window that nothing is recording?

Watch() records the first observation of each non-skipped rule, then detaches
a child that polls at the cadence in the header. The parent returns only after
the child reports ready on an inherited pipe, and writes the pidfile after
that. A clean stop writes the sentinel; a hard error does not.

* chore: add a unit test, remove build tags

* chore: address code review comments

* chore: implement phase 7 (#2785)

* chore: implement phase 7

Invariant defended: H3. The one question: can a rule be called alive
because it looked alive one poll ago?

proveCoverage (grafana-alertcheck/internal/gate/coverage.go) is the pure
coverage function: nine checks over one rule's polls — sentinel,
from-bounds, heartbeat continuity, health error/nodata, liveness,
in-window pause, rule absence, KeepLast. Liveness is absolute, never a
delta. Cross-domain comparisons translate by each poll's own skew and
widen boundary segments by its skew bound, fail-closed.

* chore: enhance unit tests

* chore: address code review comments

* chore: implement phase 8 (#2786)

* chore: implement phase 8

Invariant defended: H6/H7. The one question: can a violation ever
outrank an unobservable rule, or can a pass happen without
Violations empty and err nil?

Adds classify.go: the pure per-instance classifier (outcome table,
preexisting policy, BadFor) and decide(), the seam combining
proveCoverage with those timelines under one Policy. Consolidates
rule-poll filtering and skew translation onto pollsForRule/runnerTime,
shared with coverage.go.

* chore: rename some vars + add unit tests

* chore: address code review comments

* chore: implement phase 9 (#2787)

* chore: implement phase 9

Invariant defended: H5/H7. The one question: can check report a pass
over a window it did not prove?

Check() is the I/O shell around the pure decide(). Single-step
synthesizes the header and its own sentinel, so no mode flag reaches
the pure layer. Log mode stops the recorder before the one full read.

The header, not a definition re-resolved after the window closed, is
the authority for what was paused when the window opened — it decides
`skipped`, the drain set, and the transitionGrace max. The flock, not
the pidfile, is the authority for whether a writer still exists.

* chore: remove unix build tag

* chore: implement phase 10 (#2788)

* Wire watch/check subcommands to the gate library, with a table+JSON
renderer and H6/H7 exit-code mapping. Extend Result with per-rule/global
thresholds and a real skew bound; export SkewHardLimit; reject --states
normal.

* chore: fix goreleaser.yaml and add version command

* chore: implement phase 11 (#2789)

* chore: implement phase 11

Add coverage.go's declared-KeepLast check (no_data_state/exec_err_state,
not just an observed reason) and close the remaining §22 gaps: newly_bad's
no-early-exit clock assertion, a recorder-mode gap right after the deploy,
a rule's own coverage gap overriding its own recovery, a genuinely
skew-discriminating staleness test, exit-2 consequences on two
Reason-only coverage tests, and end-to-end checks for log-name
collapse, a truncated log, and the real watch-written state histogram.

* chore: address code review comments

* chore: more concise comments (#2790)

* chore: more concise comments

* fix: merge conflict

* chore: shorten comments

* fix: resolve conflict

* chore: use testify's require in tests (#2792)

* chore: use testify's require in tests

* chore: move remaining assumptions to testify

* chore: address code review comments

* chore: fix logging and std out printing (#2798)

* chore: fix logging and std out printing

* chore: truncate to seconds when comparing from time

* chore: add centralized docs (#2802)

* chore: add centralized docs

* chore: further update docs

* chore: address code review comments (#2807)

* chore: address code review comments

* chore: get rid of goreleaser
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants