test(security): keep the no-output policy timeout test off the real deadline

The test fires its mocked 1 s no-output timer by hand once the forked
process tree has written its pid file, but the 10 s overall deadline
still ran on a real timer. On a loaded runner, starting the process tree
can take the whole deadline, so the overall timeout won (CI run
36401631363 failed at exactly 10 s with "policy command timed out").

Intercept the overall timer with a non-firing placeholder so only the
path under test can fire. A local probe with a forced 10.5 s startup
stall fails with the CI signature before and passes after.
This commit is contained in:
Peter Steinberger 2026-09-28 02:37:48 -07:00
parent 224b7d31ee
commit 80fda958ad

View file

@ -240,6 +240,10 @@ describe("runInstallPolicy", () => {
noOutputTimeout = () => callback(...args);
return nativeSetTimeout(() => undefined, 60_000);
}
// A slow runner can spend the whole overall deadline starting the process tree.
if (delay === 10_000) {
return nativeSetTimeout(() => undefined, 60_000);
}
return nativeSetTimeout(callback, delay, ...args);
});