Skip to content

fix(cloudformation): report ChangeSetNotFound for an unknown change set - #5

Closed
Sorttech wants to merge 1 commit into
mainfrom
fix/cfn-describe-change-set-not-found
Closed

Sorttech wants to merge 1 commit into
mainfrom
fix/cfn-describe-change-set-not-found

Conversation

@Sorttech

@Sorttech Sorttech commented Sep 11, 2026 •

Copy link
Copy Markdown
Owner

cdk deploy and cdk bootstrap hung forever against a stack that
already exists.

Before creating its change set the CDK CLI deletes any leftover one with
the same name, then polls DescribeChangeSet until the call reports
DELETE_COMPLETE/DELETE_FAILED or raises ChangeSetNotFoundException
(waitForGone). On a lookup miss DescribeChangeSet fabricated
{"Status": "CREATE_COMPLETE", "ExecutionStatus": "AVAILABLE"}, so the
change set was never gone and the poll never terminated: one
DeleteChangeSet followed by DescribeChangeSet every five seconds,
with CreateChangeSet never reached.

ChangeSetNotFoundException is declared on DescribeChangeSet,
DescribeChangeSetHooks and ExecuteChangeSet, with awsQueryError code
ChangeSetNotFound and HTTP 404 (aws-models/cloudformation.json), so
returning it costs no conformance. DeleteChangeSet does not declare it
and still succeeds for a change set that was never created, matching AWS.

All three reads had the same fabricated success with the lookup
copy-pasted, ExecuteChangeSet explicitly so ("pass-through success
rather than hard-fail"). They now share one find_change_set and map a
miss to the error, which is also what CONTRIBUTING's no-stub-responses
rule asks for.

The unit coverage was asserting the stub: change_sets built a fresh
service per call, so DescribeChangeSet("cs") only passed because the
miss was faked. It now runs the lifecycle against one service.

Test plan

Regression test: describe_change_set_reports_unknown_change_set_as_not_found in crates/fakecloud-e2e/tests/cloudformation_execute_change_set.rs, plus the change_sets unit lifecycle in extras.rs which previously asserted the stub

Verification

On this exact head, rebased onto current main:

  • cargo fmt --all --check - clean.
  • cargo clippy --workspace --all-targets -- -D warnings - clean.
  • cargo test --workspace excluding fakecloud-e2e, fakecloud-conformance,
    fakecloud-tfacc and fakecloud-parity (the same set CI's test job runs),
    plus cargo test -p fakecloud-conformance --lib - 9929 passed, 0 failed.
  • cargo test -p fakecloud-e2e --test cloudformation_execute_change_set - the
    regression test above passes against a freshly built target/debug/fakecloud.

Found by deploying a CDK CloudFront + S3 SPA against fakecloud.

@Sorttech Sorttech closed this Sep 11, 2026
@Sorttech Sorttech reopened this Sep 11, 2026
`cdk deploy` and `cdk bootstrap` hung forever against a stack that
already exists.

Before creating its change set the CDK CLI deletes any leftover one with
the same name, then polls `DescribeChangeSet` until the call reports
`DELETE_COMPLETE`/`DELETE_FAILED` or raises `ChangeSetNotFoundException`
(`waitForGone`). On a lookup miss `DescribeChangeSet` fabricated
`{"Status": "CREATE_COMPLETE", "ExecutionStatus": "AVAILABLE"}`, so the
change set was never gone and the poll never terminated: one
`DeleteChangeSet` followed by `DescribeChangeSet` every five seconds,
with `CreateChangeSet` never reached.

`ChangeSetNotFoundException` is declared on `DescribeChangeSet`,
`DescribeChangeSetHooks` and `ExecuteChangeSet`, with awsQueryError code
`ChangeSetNotFound` and HTTP 404 (aws-models/cloudformation.json), so
returning it costs no conformance. `DeleteChangeSet` does not declare it
and still succeeds for a change set that was never created, matching AWS.

All three reads had the same fabricated success with the lookup
copy-pasted, `ExecuteChangeSet` explicitly so ("pass-through success
rather than hard-fail"). They now share one `find_change_set` and map a
miss to the error, which is also what CONTRIBUTING's no-stub-responses
rule asks for.

The unit coverage was asserting the stub: `change_sets` built a fresh
service per call, so `DescribeChangeSet("cs")` only passed because the
miss was faked. It now runs the lifecycle against one service.
@Sorttech
Sorttech force-pushed the fix/cfn-describe-change-set-not-found branch from bc0a3ff to 64d711b Compare September 24, 2026 16:14
@Sorttech

Copy link
Copy Markdown
Owner Author

Retargeted upstream as faiscadev#2563.

@Sorttech Sorttech closed this Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant