Skip to content

fix(scheduler): bound organization sweep pressure under Actions saturation - #1630

Merged
seonghobae merged 16 commits into
mainfrom
fix/actions-queue-saturation-scheduler-cadence-20260902
Sep 1, 2026
Merged

fix(scheduler): bound organization sweep pressure under Actions saturation#1630
seonghobae merged 16 commits into
mainfrom
fix/actions-queue-saturation-scheduler-cadence-20260902

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Root cause

Organization Actions queue health remains in a proven QUEUE_SATURATION_CHICKEN_EGG: protected-main merge evidence for central and leaf repairs is queued behind the control plane's own recurring workload. The protected scheduler currently runs both */30 and */15 schedules; the 15-minute path performs the organization-wide sweep. The just-landed #1619 removes one orphaned OpenCode dispatch bootstrap, but fresh central evidence still reports roughly 800 queued workflow runs, so the source-level scheduler pressure recorded in #1531 remains actionable.

RED first

Exact branch head 713a4a68d2fb4ae054d07ef565c399c0760674f0 adds a permanent regression requiring the expensive organization sweep to be hourly (0 * * * *) rather than quarter-hourly while preserving event-driven pull_request_target, pull_request_review, workflow_run, and repository_dispatch wakes. It is intentionally RED against protected main until the workflow and existing stale cadence contract are repaired.

Intended repair

Re-fetch current main and live queue evidence before every mutation. Change only the expensive organization-sweep cadence from */15 to hourly; retain the independent 30-minute repository queue scan and event-driven wakes. Update the existing tests/test_required_workflow_queue_contract.py hard-coded quarter-hour assertion and docs/org-required-workflow-rollout.md so they express the new executable contract instead of becoming stale policy tests. Preserve fail-closed queue hygiene, live-ref/stale-head safety, rate-limit handling, concurrency semantics, and all required security/review/coverage gates. Do not cancel the sole current-head authoritative evidence.

Acceptance requires focused scheduler/queue tests, workflow lint/diff hygiene, exact-head checks/reviews, and post-change queue observation. Refs #1531, #712, #1619.


Devin Review

Copy link
Copy Markdown
Contributor Author

@opencode-agent Implement the RED contract on this exact existing writer branch now. Re-fetch current PR head and protected main before mutation. Change only the expensive organization-wide sweep schedule in .github/workflows/pr-review-merge-scheduler.yml from quarter-hourly to hourly (0 * * * *), while retaining the separate 30-minute repository scan and all event-driven wakes/concurrency/live-head safeguards. Update the existing stale hard-coded */15 assertions in tests/test_required_workflow_queue_contract.py to the new hourly contract, preserve explicit negative coverage that quarter-hourly org sweep cannot reappear, and update docs/org-required-workflow-rollout.md plus queue-saturation traceability (docs/product-technical-gap-baseline.md/CHANGELOG if those current docs require it). Run the new regression, focused required-workflow queue/scheduler tests, actionlint/diff hygiene, and push normally. Do not weaken any review/security/coverage gate and do not cancel current-head authoritative evidence.

github-advanced-security[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

github-advanced-security[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

Copy link
Copy Markdown
Contributor Author

QUEUE_SATURATION_CHICKEN_EGG integration decision for exact head 141d5827ecfaf5bcaa0d750df430574651d01dc9.

Fresh live evidence: protected main is 4ae90e18b03a3a455e13e501628010cabc5c37a8; GitHub reports this PR mechanically mergeable/rebaseable with mergeable_state=blocked only by admission; the repository currently has 822 queued Actions runs and this exact head's OSV, Semgrep, Security Scan, Secret Scan, CodeQL, SBOM, and Python Security workflows are queued while exact-head Scorecard is success. The exact resulting tree was independently exercised before publication by the one-shot repair run: all three cadence regressions passed, git diff --check passed, stale 15-minute/900-second maintenance prose was repaired, and the temporary write-enabled helper is now absent from the five-file PR delta. All review threads, including helper lifecycle/credential findings, are resolved or obsolete after helper removal; there is no submitted CHANGES_REQUESTED review.

This PR directly reduces recurring control-plane load by moving the expensive organization sweep from every 15 minutes to hourly while preserving event-driven wakes and the independent 30-minute repository scan. The remaining exact-head required evidence is unable to start behind the saturated fleet that this change reduces. This satisfies the bounded queue-saturation chicken-and-egg exception; merge must be pinned to this exact head and must not transfer predecessor check evidence.

@seonghobae
seonghobae merged commit 476e8be into main Sep 1, 2026
22 of 34 checks passed
@seonghobae
seonghobae deleted the fix/actions-queue-saturation-scheduler-cadence-20260902 branch September 1, 2026 18:01
seonghobae added a commit that referenced this pull request Sep 1, 2026
…u-latest (#1632)

QUEUE_SATURATION_CHICKEN_EGG: exact head ab9f378 is mechanically mergeable with no review threads or submitted objections and independently verified full-suite/coverage/YAML evidence. The repository has 850 queued Actions runs. This exact change removes the observed starved floating ubuntu-latest image from Strix, OpenCode Review, and Noema Review, the three organization-wide required semantic review gates, and fixes the stale scheduler cadence tests left by #1630.
seonghobae added a commit that referenced this pull request Sep 1, 2026
Integrate protected main@476e8be3037800fb84e7ba780ed2068ffdfe3da5 without force-push. Preserve PR #1176's current-state governance guide where #1630's predecessor-based documentation hunk overlaps, while taking the scheduler cadence repair, its doctoring record, and both cadence/queue regressions. Exact-head review and checks must regenerate.
seonghobae added a commit that referenced this pull request Sep 2, 2026
…#1704)

org-queue-sweep explicitly excludes ContextualWisdomLab/.github from its
target list, so scan-pr-queue's own cron is the sole periodic fallback
for this repository's PR queue, and for any required check (Security
Scan, SAST Semgrep) with no workflow_run listener anywhere in this file.
Deleting it would leave this repository strictly worse off than every
sibling repo, which still gets the hourly org-sweep.

Apply the same lever #1630 already used for org-queue-sweep: lengthen
the cron from */30 (every 30 min) to hourly, offset to "30 * * * *" so
it doesn't collide with org-queue-sweep's "0 * * * *" tick. Document
why the entry exists and why it cannot simply be removed, the way the
adjoining org-queue-sweep cron already documents its own rationale.

Add a cadence-contract test asserting the new schedule, and refresh a
stale docstring in test_required_workflow_queue_contract.py that
referred to "the separate 30-minute scan".

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
seonghobae pushed a commit that referenced this pull request Sep 2, 2026
…1630

pr-review-merge-scheduler.yml's repository-local heartbeat was lengthened
from cron: "*/30 * * * *" to cron: "30 * * * *" by #1630 to reduce
Actions-capacity pressure during organization-wide queue saturation.
tests/test_actions_queue_saturation_scheduler_cadence.py was updated to
match at the time, but the parallel bash contract in
scripts/ci/test_strix_quick_gate.sh was not, and kept asserting the
literal old string -- a genuine, reproducible defect on protected main
itself (confirmed failing on a fresh unmodified main clone before this
change), not a symptom of any one PR being stale. Since exact-head-path-policy
runs this trusted base-branch script against every PR's own exact head,
this silently blocked an unbounded number of unrelated PRs across the
whole .github queue until fixed at the root.

Updates the one stale assertion to the current cron string and corrects
an adjacent stale "15-minute organization sweep / 30-minute scheduled
scan" description to the current hourly/hourly cadence.

Verified: bash scripts/ci/test_strix_quick_gate.sh -- FAIL before this
change on unmodified main, PASS after. Full suite: coverage run -m
pytest tests -q -- all passed; coverage report --fail-under=100 -- 100%
on scripts/ci/; interrogate -- 100%.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015Gs7KmNvH75nxz1sL8mKjw
seonghobae pushed a commit that referenced this pull request Sep 2, 2026
… main

exact-head-path-policy failed on this branch's own copy of
scripts/ci/test_strix_quick_gate.sh for two unrelated stale assertions,
neither touching this PR's actual Strix evidence-hardening diff:

1. The LLM_TIMEOUT assertion (line 302) still expected the round-6
   'export LLM_TIMEOUT=300' value this PR itself introduced on
   2026-09-01 to match #1601's contemporary state. Main later reverted
   strix.yml back to 'export LLM_TIMEOUT=0' via #1658 ("remove the 300s
   LLM_TIMEOUT cap") without ever having carried the 300 assertion on
   main's own copy of this file, so a same-line 3-way merge always kept
   this branch's now-stale text with no conflict to surface it. Restored
   the assertion to match main's (and strix.yml's) current, unchanged
   content.

2. The scheduler-heartbeat cron assertion (line 1562) still expected the
   pre-#1704 'cron: "*/30 * * * *"' quarter-hourly schedule. #1704
   ("lengthen scan-pr-queue's own heartbeat, don't drop it") lengthened
   pr-review-merge-scheduler.yml's repository-local scan to hourly
   ('cron: "30 * * * *"') for the same Actions-capacity reason as #1630,
   and added/updated the matching pytest contract
   (tests/test_actions_queue_saturation_scheduler_cadence.py,
   tests/test_required_workflow_queue_contract.py) but missed this
   repo's separate, duplicate shell-harness assertion of the same
   contract. Confirmed this exact failure reproduces identically on
   fresh main (same stale assertion, same actual hourly cron) -- it
   predates and is unrelated to this PR's diff. Updated the assertion to
   match #1704's now-current cron and added the mirroring
   assert_file_not_contains for the retired quarter-hourly string, same
   pattern #1704 already established in its own pytest contract.

Verified on the merged head (origin/main merged in via the preceding
merge commit, mergeable_state was "behind" only, no conflicts):
- bash scripts/ci/test_strix_quick_gate.sh (full harness): PASS, 0
  failures (previously 2: the LLM_TIMEOUT and cron assertions above).
- PYTHONPATH=. python3.12 -m coverage run -m pytest tests -q: 2644
  passed, 1 skipped, 21 subtests.
- coverage report --show-missing: 100% on scripts/ci.
- interrogate: 100% (RESULT: PASSED, minimum: 100.0%, actual: 100.0%).
- python -m compileall on the five exact-head-path-policy test files,
  bash -n scripts/ci/strix_quick_gate.sh, git diff --exit-code: all
  clean after this commit.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BV96rXhqoR3tYZ9AeAVur4
seonghobae added a commit that referenced this pull request Sep 3, 2026
… root cause (#1754)

QUEUE_SATURATION_CHICKEN_EGG bypass: required checks (osv-scan, dependency-review, noema-review, opencode-review, scorecard, etc.) are queued behind the same org-wide Actions plan concurrency ceiling this docs-only PR documents (confirmed live: 1862 queued vs 2 in_progress runs on .github alone at merge time). Docs-only, +114/-0, 1 file, no code paths. Precedent: #1630 used the identical QUEUE_SATURATION_CHICKEN_EGG label for the same class of backlog. Authorized by product-goal-directive §2 stacked/root-cause-fix provisions and this session's explicit /loop item 31 (chicken-and-egg permits bypass merge).
seonghobae pushed a commit that referenced this pull request Sep 3, 2026
test_strix_quick_gate.sh's assert_pr_review_merge_scheduler_uses_github_actions_bot_token
still asserted the pre-lengthening cron literal 'cron: "*/30 * * * *"' for
pr-review-merge-scheduler.yml's scan-pr-queue heartbeat. That cadence was
deliberately lengthened to hourly ('cron: "30 * * * *"') for Actions-capacity
reasons (docs/doctoring/actions-queue-saturation-hourly-sweep.md, #1630),
and tests/test_actions_queue_saturation_scheduler_cadence.py's
test_scan_pr_queue_heartbeat_is_hourly_and_offset_not_removed already
enforces exactly that hourly value and explicitly forbids the old */30
literal -- but this quick-gate assertion was never updated in the same
change, so it started failing this PR's exact-head-path-policy check
against the current (correct) workflow content. Reproduces identically
on unmodified main; not specific to this PR's own diff.

Verified: the exact grep -F literal this assertion checks was RED against
the old '*/30 * * * *' string and is GREEN against the current
'30 * * * *' string; full scripts/ci/test_strix_quick_gate.sh run passes;
tests/test_actions_queue_saturation_scheduler_cadence.py still passes.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KPmJErfkcHer4UVEgrQxUX
seonghobae added a commit that referenced this pull request Sep 3, 2026
…1630 (#1750)

pr-review-merge-scheduler.yml's repository-local heartbeat was lengthened
from cron: "*/30 * * * *" to cron: "30 * * * *" by #1630 to reduce
Actions-capacity pressure during organization-wide queue saturation.
tests/test_actions_queue_saturation_scheduler_cadence.py was updated to
match at the time, but the parallel bash contract in
scripts/ci/test_strix_quick_gate.sh was not, and kept asserting the
literal old string -- a genuine, reproducible defect on protected main
itself (confirmed failing on a fresh unmodified main clone before this
change), not a symptom of any one PR being stale. Since exact-head-path-policy
runs this trusted base-branch script against every PR's own exact head,
this silently blocked an unbounded number of unrelated PRs across the
whole .github queue until fixed at the root.

Updates the one stale assertion to the current cron string and corrects
an adjacent stale "15-minute organization sweep / 30-minute scheduled
scan" description to the current hourly/hourly cadence.

Verified: bash scripts/ci/test_strix_quick_gate.sh -- FAIL before this
change on unmodified main, PASS after. Full suite: coverage run -m
pytest tests -q -- all passed; coverage report --fail-under=100 -- 100%
on scripts/ci/; interrogate -- 100%.


Claude-Session: https://claude.ai/code/session_015Gs7KmNvH75nxz1sL8mKjw

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants