Skip to content

test: stop the GET rate-limit test flaking on a minute boundary - #289

Merged
snekxs merged 1 commit into
mainfrom
fix/ratelimit-test-minute-boundary
Sep 24, 2026
Merged

snekxs merged 1 commit into
mainfrom
fix/ratelimit-test-minute-boundary

Conversation

@snekxs

@snekxs snekxs commented Sep 24, 2026

Copy link
Copy Markdown
Member

What

The GET rate-limit test fired 241 requests in a tight loop and asserted the 241st returned 429. It depends on the wall clock.

functions/_middleware.js buckets requests as:

const key = `window:${ip}:${method}:${Math.floor(Date.now() / 60_000)}`;

If the clock ticks into the next minute partway through the loop, the counter moves to a fresh bucket, the cap is never crossed, and the loop finishes on 200 — the test then fails depending only on when it happened to run. That is why it passed on retry both times it was seen.

Fix

  • Pin Date.now to a fixed instant inside a single minute so the run cannot straddle the boundary. Behaviour is unchanged (cap is 240 GETs/min, the 241st crosses it); only the clock is frozen, and it is restored in a finally.
  • Add the GET rate limit resets on a new minute, which moves the clock deliberately and proves the reset — turning the race the old test tripped over into an asserted behaviour.

Verification

  • Reproduced the flake first: with a clock that advances ~100ms per call, the old loop ends on 200 instead of 429.
  • Fixed suite: 12/12 clean runs.
  • Full suite: 266 tests, 0 failures; tsc --noEmit clean.

Test-only change; no production code touched.

The limiter buckets requests as `window:<ip>:<method>:<floor(Date.now()/60000)`.
The test fired 241 GETs in a tight loop and asserted the 241st returned 429,
but if the wall clock ticked into the next minute partway through, the counter
moved to a fresh bucket and the cap was never crossed — the loop finished on
200 and the test failed depending only on when it happened to run.

Pin Date.now to a fixed instant inside one minute so the run cannot straddle
the boundary, and add a companion test that moves the clock deliberately to
prove the limit does reset on a new minute.
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying openmouse with  Cloudflare Pages  Cloudflare Pages

Latest commit: 9f60e82
Status: ✅  Deploy successful!
Preview URL: https://04c2a08d.openmouse.pages.dev
Branch Preview URL: https://fix-ratelimit-test-minute-bo.openmouse.pages.dev

View logs

@snekxs
snekxs merged commit 26675d2 into main Sep 24, 2026
6 checks passed
@snekxs
snekxs deleted the fix/ratelimit-test-minute-boundary branch September 24, 2026 07:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant