Hi, Gabriel Wicki <[email protected]> writes: > pinoaffe <[email protected]> writes: >> This is very cool work! > Thank you! > >> I have a few questions: >> - how can the bot-PRs be recognized as such? >> - what account(s) will the bots use to open PRs? > It tells you so, both with the PR author's name as well as the content > (and the for-its-purpose adjusted PR message).
It is good that the automatic PRs are marked as such, but it would have been better if that had been described/documented (and communicated) beforehand. > See the Pull Requests if you need more insight > (and understandably don't care to skim the source), here: > https://codeberg.org/guix/guix/pulls?q=&type=all&sort=relevance&state=open&labels=&milestone=0&project=0&assignee=0&poster=1339987 >> - what rate-limiting is built in, to prevent guix from being flooded >> with PRs? > None. Why would guix be flooded with PRs? There could be many reasons, ranging from bugs in the program to odd/unexpected scenarios (e.g., accidentally starting this on a lot more packages than you realized, or the updater inadvertently doing some kind of no-op change for many packages, some weird interaction caused by a package with several versions, etcpp) > The way the bot is implemented is to run our internal tools as > intended, sequentially, and—when successful—also build the `-P 1` > dependents and only then push the PR. *Iff* all steps go well there > is 1 single PR for each package it's been started for. > It does not cycle or keep going after attempting to upgrade once. So, > worst (or best?) case would be 1 PR for every package (e.g. in a module, > like I let it run before my holidays). Based on your earlier phrasing it sounded like it might do periodic polling of packages, which would open up many more possibilities for accidental PR floods. >> - is there some sort of "human in the loop", so that its output is >> manually checked while GGABS is still wet behind the ears? > As Hugo pointed out correctly, we (the reviewers and committers) are the > humans in the loop. While this may ultimately be a good way to have the human in the loop, I don't think this is adequate while GGABS is still "young". I think this is an especially inadequate approach if you are going to be AFK for a while in this early phase. >> - are logs available somewhere? > Yes. Currently only on the machine that runs the job. Good that it logs, but this means they are not available. I think long-term it would be good if logs were to be available - both per-updater logs and per-package/per-update logs. The latter could even be linked in the PR, but I understand that this is not part of an "MVP". >> I think the answers to those questions should have been well-known >> *before* the bot was actually taken into use. > What makes you think the answers to these questions were **not** > well-known? As far as I can tell, you did not publicly state them anywhere, hence they were not well-known. > Did I miss the memo where I should have asked for permission > somewhere? Please let me know and excuse my misbehavior if that is > the case. I don't think there's a need to explicitly ask for permission. If I were to introduce something like GGABS, I would personally have first let it loose on an intentionally outdated fork of guix for a couple of weeks/months so that: - we can see what it behaves like in practice - we can hopefully catch any bugs, - we can see what it misses compared to manual updates that have landed on guix proper, - and so that others can see it and voice any concerns before it is let loose on guix proper. In other words, I would be very hesitant to unleash something like GGABS, so that we can first ensure that it will be helpful rather than a nuisance. I would have hoped that you too had been somewhat more hesitant. I wouldn't consider this misbehaviour per sé, as I like to assume you did so out of excitement and in good faith. >> Without good answers to those questions, I would consider the bot >> output spam. > AFAICT this has happened, even though the "bot output" is nothing more > that the output of our tooling (guix refresh, the committer script) plus > a (custom) PR message. How the PRs are generated is not relevant to the "spam-iness", the level of informed consent is, as is the volume. So far, the volume has been relatively small, but we could not realistically have known what to expect given the scarce information you gave beforehand. >> *Please* don't do this, this can go wrong in so many ways. The fact >> that you suggest this makes me strongly doubt your sincerity > Sorry, this might have been caused by my wording, but I was well aware > of what this "bot" does and am well aware of how much damage it could > do. That is reassuring, my issue was that you did not communicate your expectations as to the bots behaviour beforehand >> making me doubt your sincerity > My sincerity in what regard, exactly? You doing something with relatively high potential for harm in a rather flippant manner arose the suspicion that this was perhaps (in part) motivated by provocation, but I choose to instead assume good faith. > The auto-upgrade bot was coined to be *the most important part* to close > the gap towards Nix, hence my last sentence in the previous mail. Aight, that explains the final sentence > Have a nice week! > g You too, pinoaffe
