Skip to content

ci: add timeout-minutes to the cloud jobs and explain the branch input - #1298

Merged
plum117 merged 1 commit into
webdriverio:mainfrom
plum117:ci/cloud-timeouts
Oct 9, 2026
Merged

plum117 merged 1 commit into
webdriverio:mainfrom
plum117:ci/cloud-timeouts

Conversation

@plum117

@plum117 plum117 commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds timeout-minutes to every job of the cloud workflows (e2e.yml, scheduled-tests.yml), like #1277 did for checks.yml, and makes the branch input of scheduled-tests explain how to run a PR from a fork.

Timeouts

Without a limit, a hung cloud job runs until the GitHub default of 6 hours (and keeps cloud sessions busy). Limits from the job durations of the recent runs:

Jobs Green runs Failing runs with retries (this week) Limit
Desktop, OCR (LambdaTest) 2–3 min — 20 min
Android web, iOS web (LambdaTest), mobile app (Sauce Labs) 5–17 min up to 34 min (Android), 26 min (iOS) 45 min
Schedule gate seconds — 5 min

Branch input

Before: "Branch to run tests against". After: "Branch of this repository, or refs/pull//head for a PR from a fork (only after reviewing that commit: the run gets the cloud credentials)". A fork branch name like owner:branch does not work (the checkout failed with "invalid refspec" on 2026-10-08), and fork code must be reviewed before it gets the credentials.

Test

  • Both workflow files parse; every job has the limit above.
  • The real check is the next cloud run (no job should hit the limit when green).

🤖 Generated with Claude Code

Without a limit, a hung cloud job runs until the GitHub default of 6
hours. Green runs take 2-3 minutes (desktop, OCR) and 5-17 minutes
(Android, iOS, Sauce app); failing checks with retries took up to 34
minutes this week. Limits: 20 minutes for desktop and OCR, 45 for the
mobile jobs, 5 for the schedule gate.

The branch input of scheduled-tests now says how to run a PR from a fork
(refs/pull/<number>/head) and that the run gets the cloud credentials,
so the commit must be reviewed first.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@changeset-bot

changeset-bot Bot commented Oct 9, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: 1ba9dfd

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@plum117
plum117 marked this pull request as ready for review October 9, 2026 02:18
@plum117
plum117 merged commit caa81ba into webdriverio:main Oct 9, 2026
10 checks passed
@greptile-apps

greptile-apps Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 4/5

[Low impact] Adds job timeouts and clarifies workflow input documentation.

The PR appears safe to merge, with a non-blocking improvement to keep manual fork runs tied to the reviewed commit.

Findings

  1. P2 Security Reviewed code can change ▶

Summary

Adds job time limits to both cloud workflows:

  • Cloud workflow jobs now stop at workload-based time limits.
  • Manual runs explain how to select a fork pull request branch.

Also explains how to select a fork PR for a manual run. One non-blocking improvement: recommend the reviewed commit SHA so later pushes cannot change the code being tested.

Acknowledgment: plum117 explicitly states that manually selected fork code receives cloud credentials and must be reviewed first. That intended access is not reported as a defect.

Reviews (1) · Last reviewed commit: "ci: add timeout-minutes to the cloud job..." · Reviewed by Greptile

inputs:
branch:
description: "Branch to run tests against"
description: "Branch of this repository, or refs/pull/<number>/head for a PR from a fork (only after reviewing that commit: the run gets the cloud credentials)"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 security Reviewed code can change

The new instructions recommend refs/pull/<number>/head, but that ref can change after review. If the contributor pushes again before a job checks out the code, the job can run an unreviewed commit with cloud credentials. Recommend entering the reviewed commit SHA instead of the moving PR ref.

How this was verified: Each scheduled job checks out inputs.branch and then runs that checkout’s test commands with LambdaTest or Sauce credentials.

Suggested change
description: "Branch of this repository, or refs/pull/<number>/head for a PR from a fork (only after reviewing that commit: the run gets the cloud credentials)"
description: "Branch of this repository, or the full reviewed commit SHA for a PR from a fork (not refs/pull/<number>/head, which can change: the run gets the cloud credentials)"

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants