Fetch apk-tools from the GitHub mirror first, with a capped timeout

Retrying gitlab.alpinelinux.org was not enough: the dispatched run on
this branch had aarch64 fetch the pinned commit on the first try while
x86_64, in the same run, could not connect at all across four attempts
spanning ten minutes. The host fails per runner, not per run, so more
attempts against the one host do not converge.

Prefer alpinelinux's GitHub mirror and keep the canonical host as the
fallback, three rounds over the pair. The commit is pinned by SHA and the
mirror serves that exact object, checked by fetching it, so the mirror
cannot substitute different content. Each attempt is wrapped in a 60
second timeout, since curl's own connect timeout is 135 seconds and four
of those is most of a job.
This commit is contained in:
Johnathan Corgan
2026-08-25 15:13:08 +01:00
parent 931cb40395
commit e9b6bfd3ad
+22 -18
View File
@@ -718,34 +718,38 @@ jobs:
sudo apt-get install -y --no-install-recommends \
git ca-certificates build-essential meson ninja-build pkg-config \
zlib1g-dev libssl-dev libzstd-dev liblzma-dev lua5.4-dev scdoc
# The upstream host has failed this step twice in one run (early EOF,
# then a connect timeout), so fetch only the pinned commit and retry.
# The by-SHA fetch needs uploadpack.allowReachableSHA1InWant, which
# the server has today; the full clone stays as the fallback in case
# that policy changes.
APK_TOOLS_REPO=https://gitlab.alpinelinux.org/alpine/apk-tools.git
# gitlab.alpinelinux.org has taken this step down repeatedly, both as
# a truncated clone and as a 135-second connect timeout, and it fails
# per runner rather than per run: one architecture fetched while the
# other could not reach the host at all. So prefer alpinelinux's
# GitHub mirror and keep the canonical host as the fallback. The
# commit is pinned by SHA, so the mirror cannot supply different
# content under the same name.
#
# Each attempt fetches only that commit at depth 1, which needs
# uploadpack.allowReachableSHA1InWant; both hosts allow it today. The
# timeout caps a dead host at a minute instead of curl's own 135.
APK_TOOLS_MIRRORS="https://github.com/alpinelinux/apk-tools.git https://gitlab.alpinelinux.org/alpine/apk-tools.git"
fetch_pinned() {
rm -rf /tmp/apk-tools
git init --quiet /tmp/apk-tools \
&& git -C /tmp/apk-tools remote add origin "$APK_TOOLS_REPO" \
&& git -C /tmp/apk-tools fetch --quiet --depth 1 origin "${APK_TOOLS_COMMIT}" \
timeout 120 git init --quiet /tmp/apk-tools \
&& git -C /tmp/apk-tools remote add origin "$1" \
&& timeout 60 git -C /tmp/apk-tools fetch --quiet --depth 1 origin "${APK_TOOLS_COMMIT}" \
&& git -C /tmp/apk-tools checkout --quiet FETCH_HEAD
}
clone_full() {
rm -rf /tmp/apk-tools
git clone --quiet "$APK_TOOLS_REPO" /tmp/apk-tools \
&& git -C /tmp/apk-tools checkout --quiet "${APK_TOOLS_COMMIT}"
}
got_source=
for method in fetch_pinned fetch_pinned fetch_pinned clone_full; do
if "$method"; then got_source=$method; break; fi
echo "apk-tools $method failed; retrying after backoff" >&2
for round in 1 2 3; do
for repo in $APK_TOOLS_MIRRORS; do
if fetch_pinned "$repo"; then got_source=$repo; break 2; fi
echo "apk-tools: round $round failed against $repo" >&2
done
sleep 20
done
if [ -z "$got_source" ]; then
echo "::error::could not obtain apk-tools ${APK_TOOLS_COMMIT} from $APK_TOOLS_REPO"
echo "::error::could not obtain apk-tools ${APK_TOOLS_COMMIT} from any of: $APK_TOOLS_MIRRORS"
exit 1
fi
echo "apk-tools ${APK_TOOLS_COMMIT} fetched from $got_source"
cd /tmp/apk-tools
meson setup build
ninja -C build src/apk