Skip to content

[SDK Sentinel] Stabilize timed-out workflow query test - #3119

Open
sdk-sentinel-bot wants to merge 1 commit into
temporalio:mainfrom
sdk-sentinel-forks:automation/sdk-sentinel/ci-flake/java/37080697620-1-af2f9f81f19a
Open

sdk-sentinel-bot wants to merge 1 commit into
temporalio:mainfrom
sdk-sentinel-forks:automation/sdk-sentinel/ci-flake/java/37080697620-1-af2f9f81f19a

Conversation

@sdk-sentinel-bot

Copy link
Copy Markdown
Contributor

Caution

This PR contains untrusted AI-generated code. Do not approve or run CI until a maintainer has reviewed the diff. SDK Sentinel verified that GitHub Actions remained approval-gated with zero executable jobs when this PR was opened.

Summary

Stabilize the timed-out workflow query test seen in the captured main-branch Java 11 CLI job and repeated same-SHA PR attempts. There are no breaking changes or coordinated server changes.

Root cause

Between the [preceding successful main workflow](https://github.com/temporalio/sdk-java/actions/runs/37029728465) and the [first bad main workflow](https://github.com/temporalio/sdk-java/actions/runs/37068414255), the one-second run timeout raced a five-second local activity. Because that activity held the first workflow task open, execution could close before the trace had replayable workflow-task state, causing the post-timeout query to be rejected.

Fix

Run the sleep activity as a regular activity. Scheduling it commits the workflow task and trace before timeout, while the workflow still times out waiting for activity completion. Existing assertions remain unchanged.

Validation

Five focused pre-change attempts did not reproduce the failure; five post-change Java 11 CLI attempts passed. The unchanged baseline passed. The canonical candidate validator was blocked by read-only submodule git metadata, while the equivalent check excluding only those maintenance tasks passed. Full CLI and Edge CI remain required.

Validation status: validation-incomplete

  • Flake confidence: high
  • Fix confidence: high
  • Value: high
  • Patch scope: standard — 1 changed file; 1.0 KiB
  • Local reproduction: not-reproduced — Five actual pre-change Java 11 CLI runs passed. Earlier harness setup attempts did not reach tests because Gradle cache or submodule metadata was read-only.
  • Regression coverage: pass-after-only — The existing regression test passed five post-change attempts, but it also passed five focused pre-change attempts; CI full-suite load remains the reproduction environment.
  • Unchanged baseline (Gradle formatting and test-source compilation) — passed
  • Independent candidate (Gradle formatting and test-source compilation) — did not pass (failure)

Investigator-run checks

  • GRADLE_USER_HOME="$PWD/.ci-flake-runtime/tmp/gradle-home" ./gradlew --offline --no-daemon :temporal-sdk:cleanTest :temporal-sdk:test -x :temporal-serviceclient:initSubmodules -x :temporal-serviceclient:updateSubmodules -x :temporal-sdk:compileJava17Java -PtestServer=dev-server -PtestJavaVersion=11 --tests "io.temporal.workflow.TerminatedWorkflowTest" — passed; 5 attempt(s). Five pre-change attempts passed; natural reproduction did not occur.
  • GRADLE_USER_HOME="$PWD/.ci-flake-runtime/tmp/gradle-home" ./gradlew --offline --no-daemon :temporal-sdk:cleanTest :temporal-sdk:test -x :temporal-serviceclient:initSubmodules -x :temporal-serviceclient:updateSubmodules -x :temporal-sdk:compileJava17Java -PtestServer=dev-server -PtestJavaVersion=11 --tests "io.temporal.workflow.TerminatedWorkflowTest" — passed; 5 attempt(s). Five post-change Java 11 CLI-backed attempts passed.
  • ./gradlew --offline :temporal-sdk:spotlessApply -x :temporal-serviceclient:initSubmodules -x :temporal-serviceclient:updateSubmodules — passed; 1 attempt(s). The affected module was formatted successfully.
  • .ci-flake-runtime/input/validate.sh — failed; 1 attempt(s). The fixed validator reached spotless checks but was blocked when Gradle tried to write read-only .git submodule configuration; the trusted unchanged baseline had succeeded.
  • ./gradlew --offline --no-daemon spotlessCheck testClasses -x test -x :temporal-serviceclient:initSubmodules -x :temporal-serviceclient:updateSubmodules — passed; 1 attempt(s). The equivalent repository check passed when only the sandbox-blocked submodule-maintenance tasks were excluded.

Required target CI

  • Fixed repository validator with writable submodule git metadata
  • Continuous Integration / Unit test with CLI (Java 11, dev-server)
  • Continuous Integration / Unit test with in-memory test service [Edge] (Java 23)

Residual risks

  • Full-suite concurrency was not reproduced locally.
  • The exact fixed validator remains pending in a writable trusted job.
  • A distinct direct-query replay-count flake can still fail the CLI job.

Automation provenance

If this finding should not be fixed, apply the sdk-sentinel:false-positive label and close the PR. Sentinel will suppress the finding until its affected source changes.

SDK Sentinel recurrence history

  • Unique failed CI run attempts: 1
  • First occurrence: 2026-10-02 21:53 UTC
  • Latest occurrence: 2026-10-02 21:53 UTC
  • Recent occurrences:

@sdk-sentinel-bot
sdk-sentinel-bot requested a review from a team as a code owner October 3, 2026 00:41

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant