Git, Docker & testing
Version control, containers, repeatable tests and deployment diagnostics.
100 troubleshooting guides · Page 4 / 5
How do I ensure pytest fixture cleanup runs after an assertion fails?
Cleanup placed after the test body outside a managed fixture may never run when execution raises. Resource ownership should be encoded in fixture teardown.
Why does patching a function not change the code under test?
A module may already hold its own imported reference to the function. Patching the original definition does not necessarily replace the name the consumer actually looks up.
How do I test expiry logic without sleeping for real minutes?
Real sleeps make tests slow and sensitive to scheduler timing. Expiry is a clock-dependent decision that can be tested with a controlled clock.
Why can an async test pass before its assertions inside a task run?
The test may start asynchronous work without awaiting its completion. Assertions in detached tasks then run after the test has already been reported successful.
How do I choose useful parameterized test cases instead of many equivalent examples?
More input rows do not necessarily cover more behavior. Cases should represent different rules, boundaries and failure modes.
When is a property-based test more useful than another fixed example?
Some behavior is best described by an invariant across many generated inputs, such as decoding an encoded valid value without changing its meaning.
Does 100 percent line coverage mean a feature is fully tested?
Line coverage records execution, not whether the assertions would detect an incorrect result. A test can execute a branch and ignore its output.
Why can approving a large snapshot update hide a regression?
A snapshot captures output, but replacing it wholesale can bless unintended changes along with expected ones. Reviewability decreases as unrelated output grows.
Why can SQLite-backed tests miss a PostgreSQL production bug?
SQL engines differ in typing, constraints, locking, syntax and query behavior. A convenient substitute may not exercise the production contract.
How can parallel tests avoid fighting over the same database or port?
Parallel workers share host resources unless the test design gives each an isolated namespace. Fixed database names, filenames and ports become contention points.
What should a network stub simulate besides a successful JSON response?
Real integrations fail in ways a single happy-path fixture cannot show: timeouts, partial bodies, malformed content and uncertain write outcomes.
How can consumer contract tests detect an API change before deployment?
A provider can change a response that still looks reasonable but violates a consumer’s actual assumptions. A contract test makes those assumptions executable.
How do I make a performance test comparison fair?
Different input size, cache state or runtime settings can make a change look faster without improving the same workload. One unusually quick run is weak evidence.
How can I test a race condition without hoping the scheduler triggers it?
A race may disappear during ordinary runs because the dangerous interleaving is rare. Sleeping for guessed durations makes the test fragile.
Why should tests avoid real customer data even when it is convenient?
Production data can contain personal information and hidden assumptions that make tests nondeterministic. Copying it expands the number of systems that must protect it.
When should a bug fix include a regression test?
A regression test is valuable when it captures a meaningful behavior that could fail again and would otherwise be hard to notice. It should encode the bug’s contract, not mirror the new implementation.
What evidence should CI preserve when an intermittent test fails?
A rerun can erase the only useful failure context if logs and artifacts are overwritten. Preserve evidence before deciding whether to retry.
What should a post-deployment smoke test verify that unit tests cannot?
Deployment introduces routing, credentials, asset paths and infrastructure configuration that local unit tests do not exercise. A small live check should confirm the release can actually serve its core path.
Why is a fast hash such as SHA-256 unsuitable for storing passwords by itself?
Fast general-purpose hashes make large numbers of password guesses inexpensive. Password storage needs a purpose-built, salted, configurable work factor.
How can I test that application logs do not contain tokens or passwords?
Logging complete requests can copy secrets into a system with broader access and longer retention than the application database. Redaction should be verified, not merely configured.
Does a clean dependency vulnerability scan prove the application is secure?
A scanner reports known issues it can identify in the scanned dependency set. It does not prove absence of unknown vulnerabilities or flaws in your own integration.
How do I test decompression limits without generating a dangerous archive bomb?
Decompression defenses should be tested with small controlled fixtures whose declared and expanded sizes exercise the policy. A real destructive bomb is unnecessary.
What should a multi-tenant authorization test cover beyond the main read endpoint?
Cross-tenant leaks often appear in secondary paths such as downloads, search, exports, counts or background jobs. Testing one page is insufficient.
How can I test that cached responses never mix two users’ data?
A correct origin can still leak data if a cache key omits an identity-dependent dimension or private responses are stored in a shared cache.
Ask your own question · Sign in to post questions and answers.