From a41ed1b435f7475d765c1bffb457d0af646d49c3 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 19 Jun 2026 13:22:27 +0000 Subject: [PATCH 1/3] build(deps): bump actions/checkout from 4 to 7 Bumps [actions/checkout](https://github.com/actions/checkout) from 4 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v4...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] --- .github/workflows/backend-tests.yml | 4 ++-- .github/workflows/codeql.yml | 2 +- .github/workflows/cpu-profile.yml | 4 ++-- .github/workflows/npmpublish.yml | 4 ++-- .github/workflows/scaling-dive.yml | 4 ++-- 5 files changed, 9 insertions(+), 9 deletions(-) diff --git a/.github/workflows/backend-tests.yml b/.github/workflows/backend-tests.yml index 08415f2..f843d7d 100644 --- a/.github/workflows/backend-tests.yml +++ b/.github/workflows/backend-tests.yml @@ -16,12 +16,12 @@ jobs: steps: - name: Check out etherpad-load-test - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: path: ./loadtest - name: Check out Etherpad core - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: repository: ether/etherpad-lite path: ./etherpad diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index b59e78c..808edac 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -24,7 +24,7 @@ jobs: steps: - name: Checkout - uses: actions/checkout@v4 + uses: actions/checkout@v7 - name: Initialize CodeQL uses: github/codeql-action/init@v3 diff --git a/.github/workflows/cpu-profile.yml b/.github/workflows/cpu-profile.yml index d20a7c5..4e6161c 100644 --- a/.github/workflows/cpu-profile.yml +++ b/.github/workflows/cpu-profile.yml @@ -36,12 +36,12 @@ jobs: steps: - name: Checkout etherpad-load-test - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: path: ./loadtest - name: Checkout etherpad core (${{ inputs.core_ref }}) - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: repository: ether/etherpad ref: ${{ inputs.core_ref }} diff --git a/.github/workflows/npmpublish.yml b/.github/workflows/npmpublish.yml index e5dd1b7..f882589 100644 --- a/.github/workflows/npmpublish.yml +++ b/.github/workflows/npmpublish.yml @@ -17,7 +17,7 @@ jobs: test: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - uses: actions/setup-node@v4 with: @@ -56,7 +56,7 @@ jobs: needs: test runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: fetch-depth: 0 diff --git a/.github/workflows/scaling-dive.yml b/.github/workflows/scaling-dive.yml index 317174a..d4f6236 100644 --- a/.github/workflows/scaling-dive.yml +++ b/.github/workflows/scaling-dive.yml @@ -41,12 +41,12 @@ jobs: steps: - name: Checkout etherpad-load-test - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: path: ./loadtest - name: Checkout etherpad core (${{ inputs.core_ref }}) - uses: actions/checkout@v4 + uses: actions/checkout@v7 with: repository: ether/etherpad ref: ${{ inputs.core_ref }} From be6d1f9ea061cb33c859984c347c1ae2a7bb5113 Mon Sep 17 00:00:00 2001 From: John McLear Date: Sun, 21 Jun 2026 13:06:05 +0100 Subject: [PATCH 2/3] fix(ci): restore sweep integration test against hardened core MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The sweep integration test (and thus all Backend-tests CI) has been red on every PR since ~2026-05-19; the last green run was #111 (2026-05-16). The break is not in this repo — ether/etherpad#7773 ("harden: reject USER_CHANGES inserts without an author attribute", merged 2026-05-16 17:23, just after the last green run) tightened server-side changeset validation and bumped its own etherpad-cli-client dependency to 4.0.3 to comply. This repo was still pinned to etherpad-cli-client 4.0.2, whose append() splices at text.length (stranding the trailing '\n') with an empty apool and no author attribute — exactly the two shapes #7773 now rejects as badChangeset. Result: zero ACCEPT_COMMITs, so every step's latency sample count is 0 and the test asserts `count > 0`. Two-part fix, both verified against a local core build at develop HEAD: - Bump etherpad-cli-client 4.0.2 -> 4.0.3 (sends author-attributed inserts and preserves the trailing newline). - Raise commitRateLimiting on the SUT in the sweep step. The sweep drives 2..4 authors from a single IP; core's default 10 changes/s/IP rate-limits the 4-author step (~20/s), and a rate-limited USER_CHANGES never gets an ACCEPT_COMMIT, stalling the cli-client's in-flight slot. Mirrors the importExportRateLimiting bump runnerLoadTest.sh already applies. Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/backend-tests.yml | 8 ++++++++ package.json | 2 +- pnpm-lock.yaml | 10 +++++----- 3 files changed, 14 insertions(+), 6 deletions(-) diff --git a/.github/workflows/backend-tests.yml b/.github/workflows/backend-tests.yml index f843d7d..61c6a1c 100644 --- a/.github/workflows/backend-tests.yml +++ b/.github/workflows/backend-tests.yml @@ -78,6 +78,14 @@ jobs: # The previous step (runnerLoadTest.sh) tore Etherpad down, so # bring a minimal one back up just for the sweep integration test. cd ./etherpad + # The sweep drives 2..4 authors from a single IP (127.0.0.1). Core's + # default commitRateLimiting is 10 changes/s/IP, so the 4-author step + # (~20 changes/s) trips the limiter; a rate-limited USER_CHANGES never + # gets an ACCEPT_COMMIT, which stalls the cli-client's in-flight slot + # and zeroes out that step's latency samples. Raise the cap for the + # SUT so we measure throughput, not the rate limiter (mirrors the + # importExportRateLimiting bump runnerLoadTest.sh already applies). + sed -e '/^ *"commitRateLimiting":/,/^ *\}/ s/"points":.*/"points": 1000000/' -i settings.json (cd src && pnpm run prod &) for i in $(seq 1 60); do curl -sf http://127.0.0.1:9001/ >/dev/null && break diff --git a/package.json b/package.json index 63b9f24..73c9d46 100644 --- a/package.json +++ b/package.json @@ -10,7 +10,7 @@ }, "contributors": [], "dependencies": { - "etherpad-cli-client": "^4.0.2", + "etherpad-cli-client": "^4.0.3", "hdr-histogram-js": "^3.0.1" }, "devDependencies": { diff --git a/pnpm-lock.yaml b/pnpm-lock.yaml index a335e79..067405e 100644 --- a/pnpm-lock.yaml +++ b/pnpm-lock.yaml @@ -9,8 +9,8 @@ importers: .: dependencies: etherpad-cli-client: - specifier: ^4.0.2 - version: 4.0.2 + specifier: ^4.0.3 + version: 4.0.3 hdr-histogram-js: specifier: ^3.0.1 version: 3.0.1 @@ -619,8 +619,8 @@ packages: resolution: {integrity: sha512-kVscqXk4OCp68SZ0dkgEKVi6/8ij300KBWTJq32P/dYeWTSwK41WyTxalN1eRmA5Z9UU/LX9D7FWSmV9SAYx6g==} engines: {node: '>=0.10.0'} - etherpad-cli-client@4.0.2: - resolution: {integrity: sha512-oAyJxJj4UH0AAEmMPpMiTHKd2IT14OWnKaPzWTqLh3BJ8nyEv/IAMA5scAGjet0xKNERm+k7VSnfeJQvN4adKQ==} + etherpad-cli-client@4.0.3: + resolution: {integrity: sha512-nQt5FxpmfQHwJ546TJXKMT4fMIS1crvU+NvHAypfboHTsbFQMIPOu4ZANSirRzE1lYnH4APUBDwMQqlKeQt9rw==} engines: {node: '>=18.0.0'} hasBin: true @@ -1562,7 +1562,7 @@ snapshots: esutils@2.0.3: {} - etherpad-cli-client@4.0.2: + etherpad-cli-client@4.0.3: dependencies: socket.io-client: 4.8.3 superagent: 10.3.0 From 7e4208f0c0f655c18596c2aa2408afe6d3ae72be Mon Sep 17 00:00:00 2001 From: John McLear Date: Sun, 21 Jun 2026 13:10:54 +0100 Subject: [PATCH 3/3] ci: comma-preserving sed for commitRateLimiting + fail-fast assert Action Qodo review: use the comma-preserving "points":[^,]* substitution (matching scaling-dive.yml / cpu-profile.yml) so the edit can't strip a trailing comma or JSONC comment and produce invalid settings.json. Add a grep assertion so a non-matching template fails the step loudly instead of silently booting core with the default 10/s limiter. Co-Authored-By: Claude Opus 4.8 (1M context) --- .github/workflows/backend-tests.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/backend-tests.yml b/.github/workflows/backend-tests.yml index 61c6a1c..fc73816 100644 --- a/.github/workflows/backend-tests.yml +++ b/.github/workflows/backend-tests.yml @@ -85,7 +85,8 @@ jobs: # and zeroes out that step's latency samples. Raise the cap for the # SUT so we measure throughput, not the rate limiter (mirrors the # importExportRateLimiting bump runnerLoadTest.sh already applies). - sed -e '/^ *"commitRateLimiting":/,/^ *\}/ s/"points":.*/"points": 1000000/' -i settings.json + sed -e '/^ *"commitRateLimiting":/,/^ *\}/ s!"points":[^,]*!"points": 1000000!' -i settings.json + grep -q '"points": 1000000' settings.json # fail fast if the limiter wasn't raised (cd src && pnpm run prod &) for i in $(seq 1 60); do curl -sf http://127.0.0.1:9001/ >/dev/null && break