Skip to content

Add Spec Update Watchdog for unmerged spec-update PRs - #602

Closed
cguldner wants to merge 1 commit into
mainfrom
add-spec-update-watchdog
Closed

cguldner wants to merge 1 commit into
mainfrom
add-spec-update-watchdog

Conversation

@cguldner

Copy link
Copy Markdown
Contributor

Problem

The Spec Update workflow opens a PR, arms auto-merge (gh pr merge --auto), and then finishes green regardless of the outcome. If the PR later stalls — failing CI, merge conflict, REVIEW_REQUIRED, auto-merge silently not armed — it just sits open and nothing signals it. That's how the 2026-09-29 spec updates went unmerged across several repos unnoticed.

Subscribing to CI-failure notifications doesn't cover this: it only sees check failures (not conflicts / review blocks), fires on ephemeral PR branches the default subscription filter can't match, and is noisy across all PRs.

What this does

A scheduled watchdog that asserts the end-state invariant: no automated-spec-update PR is still open past a grace window.

  • Runs daily at 02:00 UTC (a couple hours after nightly updates normally land), plus workflow_dispatch.
  • Lists open PRs with the automated-spec-update label using only the built-in GITHUB_TOKEN (pull-requests: read) — no new credential.
  • Ignores PRs younger than GRACE_MINUTES (60) so a run legitimately mid-CI doesn't trip it.
  • If any qualify, writes a summary (PR link, age, merge state, failing check names) to the job summary and exits non-zero so the run fails. Nothing open → silent success.

Notifications

Delivery rides the GitHub Slack app (no secret in the job). Subscribe once per repo in the target channel:

/github subscribe dropbox/dropbox-sdk-python workflows:{name:"Spec Update Watchdog" event:"schedule"}

(event:"schedule" matters — the default pull_request filter wouldn't match a cron run.)

Notes

  • This is the per-repo template. Once it looks good, the same file drops into the other SDK repos (label and structure are identical across them).
  • Validated the detection logic against live PR data (0 open → pass) and a synthetic stalled PR (correctly flagged with its failing check, fresh PR ignored).

The Spec Update workflow opens a PR, arms auto-merge, and finishes green
regardless of the outcome, so a PR that stalls (failing CI, merge conflict,
review required, auto-merge disabled) sits open silently. This scheduled
watchdog asserts 'no automated-spec-update PR is still open past a grace
window' and fails loudly when violated.

Uses only the built-in GITHUB_TOKEN (no new credential). Slack delivery is via
the GitHub Slack app by subscribing to this workflow's scheduled runs:
  /github subscribe <owner>/<repo> workflows:{name:"Spec Update Watchdog" event:"schedule"}
@codecov

codecov Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 65.34%. Comparing base (4e5d7d9) to head (65cf026).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #602   +/-   ##
=======================================
  Coverage   65.34%   65.34%           
=======================================
  Files          36       36           
  Lines       68053    68053           
  Branches     4909     4909           
=======================================
  Hits        44468    44468           
  Misses      23330    23330           
  Partials      255      255           
Flag Coverage Δ
integration 64.36% <ø> (ø)
unit 65.03% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@cguldner

Copy link
Copy Markdown
Contributor Author

Superseded by a centralized Spec Update Watchdog in dropbox/dropbox-api-spec, which checks all SDK repos from one place (reusing the existing sdk-updater app token via AWS OIDC).

@cguldner cguldner closed this Sep 30, 2026
@cguldner
cguldner deleted the add-spec-update-watchdog branch September 30, 2026 16:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant