fix(upgrade-test): gate proposal on each validator's local height; retry signer account NotFound - #586
Conversation
…try signer account NotFound The nightly chain-upgrade suite submitted its gov proposal once the aggregate RPC reported height >= 1. With 3 of 4 validators forming quorum, the aggregate can be several blocks ahead of a validator that joined consensus late, whose local seid then returns NotFound for its own genesis account. - test: run AwaitNodesAtHeight(1) on every validator before proposing. - sidecar: signAndBroadcast waits up to 60s while the account lookup returns gRPC NotFound before giving up (still non-Terminal). Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
PR SummaryMedium Risk Overview Sidecar sign-tx: Before signing, Nightly upgrade integration test: The pre-proposal gate no longer waits on aggregate height ≥ 1 via Tests / deps: Unit tests cover wait-until-found and timeout paths; Reviewed by Cursor Bugbot for commit 66a2564. Bugbot is set up for automated code reviews on this repo. Configure here. |
There was a problem hiding this comment.
The nightly upgrade test now waits for each validator to reach height 1 on its own node before proposing, and the sidecar signer now re-polls the account lookup for up to 60s while seid returns gRPC NotFound. I checked against sei-cosmos at the pinned commit that queryABCI returns NotFound unwrapped as status.Error(codes.NotFound, …), so the retry does fire in production, and I found nothing blocking; codex's reading found nothing, which matches mine but added no findings.
1 nit, not posted on the code
sidecar/tasks/sign_and_broadcast.go:174— The NotFound wait applies to every sign-tx kind, not only genesis accounts at startup. A signer key that was never funded now takes about 60s to fail on each task-level attempt instead of failing at once. That is acceptable, but the doc comment could say so, so an operator seeing a slow failure knows to check funding.
seidroid review · decision approve · session 45332683610b4636b4330b728756eeb7 · turn resp_claude_376a4daaeead8ae9526a577f08ca815c · item 7842e2d6d0c4595f838391adc2e98487
Findings: 0 blocking | 0 non-blocking | 0 posted inline
…ners Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
|
Re the seidroid nit on |
Summary
Hardens
TestNightlyChainUpgradeagainst the startup race that failed Harbor nightly runnightly-harness-suite-29847360(PagerDuty Q01DQFA79YE621).What happened: the test submitted the gov proposal as soon as the aggregate RPC showed height ≥1. Validators 1–3 make up a 3-of-4 quorum, so the aggregate was already at height 7 while validator-0, which joined consensus late, had no committed state yet. The
GovSoftwareUpgradetask signs against validator-0's own seid, and that node returnedaccount retrieve sei1…: rpc error: code = NotFound … key not foundfor its own genesis account.upgrade_test.go): replaces the aggregatepollHeightAtLeast(tmRPC, 1)withawaitAllValidatorsAtHeight(..., "genesis-await", 1, ...), which runs oneAwaitNodesAtHeighttask per validator so the gate checks each validator's own height. The helper takes a newstepargument so it can run twice per chain without task-name collisions. The post-upgrade gate keeps the"await"prefix, so its task names are unchanged.sign_and_broadcast.go): a new function,retrieveAccount, re-pollsAccountNumberSequencewhile it returns gRPCcodes.NotFound, everyaccountNotFoundPollInterval(1s) for up toaccountNotFoundTimeout(60s). Callers can still cancel it throughctx. Other errors return immediately. If the timeout runs out, the original NotFound error is returned, still non-Terminal, so the task-level retry still applies. Broadcast never happens without a resolved account.sidecar/go.mod:google.golang.org/grpcis now a direct dependency (it was indirect before; the version is unchanged).After this merges, a follow-up platform PR will bump the integration-harness image in
clusters/harbor/nightly/harness/cronjobs.yaml.Verified locally:
make test,make tidy-check,golangci-lint --new-from-merge-base=origin/main(sidecar/tasks, and test/integration with-tags integration), andgo vet -tags integration ./test/integration/. The nightly upgrade suite itself was not run.Link to Devin session: https://app.devin.ai/sessions/a3d234c649fe4c17900ce1807a32b433
Open in Devin Desktop: https://app.devin.ai/desktop/session/a3d234c649fe4c17900ce1807a32b433?variant=devin
Requested by: @bdchatham