From c38a522cd8e3e87d91f91b31d98795531e513a92 Mon Sep 17 00:00:00 2001 From: Dave Jong Date: Tue, 1 Sep 2026 17:52:23 +0200 Subject: [PATCH] Keep a resolver out of the egress shape tests MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit These cases time out under a slow resolver, which is what a CI runner sometimes has. The guard screens a hostname by resolving it, and the destinations here are either literal IPs — which never reach a resolver — or names that do not exist, so a live lookup adds a network round trip to every case and decides none of them. With DNS screening off the guard builds no resolver at all, and the hostname and address rules these tests are about still apply. What the screen does with an address it resolves is `egress-dns.test.ts`, which builds the guard directly and injects the addresses it is asking about. Co-Authored-By: Claude Opus 5 (1M context) --- tests/protect/rule-shapes.test.ts | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/tests/protect/rule-shapes.test.ts b/tests/protect/rule-shapes.test.ts index 18a77724..6bdd5983 100644 --- a/tests/protect/rule-shapes.test.ts +++ b/tests/protect/rule-shapes.test.ts @@ -244,7 +244,21 @@ describe('when the destination is the only chokepoint', () => { const entry = { id: `shape:${ID}`, title: s.title, category: s.category, phase: s.phase, rule_v2: s.rule_v2 }; const original = globalThis.fetch; globalThis.fetch = (async () => new Response('stub')) as any; - const p: any = await createProtection({ rules: { firewall: [entry] }, mode: 'block', egress: true, ...opts }); + const p: any = await createProtection({ + rules: { firewall: [entry] }, + mode: 'block', + egress: true, + // No resolver, so nothing here waits on one. The guard screens a hostname by resolving it, and + // these destinations are either literal IPs — which never reach a resolver — or names that do not + // exist, so a live lookup adds a round trip to every case and decides none of them. With this off + // the guard builds no resolver at all, and the hostname and address rules these tests are about + // still apply. + // + // What the screen does with an address it resolves is `egress-dns.test.ts`, which builds the guard + // directly and injects the addresses it is asking about. + screenDns: false, + ...opts, + }); try { await fn(globalThis.fetch); } finally {