From e9b6bfd3addc7b881e423fbd8da3e2b017aeac56 Mon Sep 17 00:00:00 2001 From: Johnathan Corgan Date: Tue, 25 Aug 2026 15:13:08 +0100 Subject: [PATCH] Fetch apk-tools from the GitHub mirror first, with a capped timeout Retrying gitlab.alpinelinux.org was not enough: the dispatched run on this branch had aarch64 fetch the pinned commit on the first try while x86_64, in the same run, could not connect at all across four attempts spanning ten minutes. The host fails per runner, not per run, so more attempts against the one host do not converge. Prefer alpinelinux's GitHub mirror and keep the canonical host as the fallback, three rounds over the pair. The commit is pinned by SHA and the mirror serves that exact object, checked by fetching it, so the mirror cannot substitute different content. Each attempt is wrapped in a 60 second timeout, since curl's own connect timeout is 135 seconds and four of those is most of a job. --- .github/workflows/package-openwrt.yml | 40 +++++++++++++++------------ 1 file changed, 22 insertions(+), 18 deletions(-) diff --git a/.github/workflows/package-openwrt.yml b/.github/workflows/package-openwrt.yml index 918a7abd..d8d79fe0 100644 --- a/.github/workflows/package-openwrt.yml +++ b/.github/workflows/package-openwrt.yml @@ -718,34 +718,38 @@ jobs: sudo apt-get install -y --no-install-recommends \ git ca-certificates build-essential meson ninja-build pkg-config \ zlib1g-dev libssl-dev libzstd-dev liblzma-dev lua5.4-dev scdoc - # The upstream host has failed this step twice in one run (early EOF, - # then a connect timeout), so fetch only the pinned commit and retry. - # The by-SHA fetch needs uploadpack.allowReachableSHA1InWant, which - # the server has today; the full clone stays as the fallback in case - # that policy changes. - APK_TOOLS_REPO=https://gitlab.alpinelinux.org/alpine/apk-tools.git + # gitlab.alpinelinux.org has taken this step down repeatedly, both as + # a truncated clone and as a 135-second connect timeout, and it fails + # per runner rather than per run: one architecture fetched while the + # other could not reach the host at all. So prefer alpinelinux's + # GitHub mirror and keep the canonical host as the fallback. The + # commit is pinned by SHA, so the mirror cannot supply different + # content under the same name. + # + # Each attempt fetches only that commit at depth 1, which needs + # uploadpack.allowReachableSHA1InWant; both hosts allow it today. The + # timeout caps a dead host at a minute instead of curl's own 135. + APK_TOOLS_MIRRORS="https://github.com/alpinelinux/apk-tools.git https://gitlab.alpinelinux.org/alpine/apk-tools.git" fetch_pinned() { rm -rf /tmp/apk-tools - git init --quiet /tmp/apk-tools \ - && git -C /tmp/apk-tools remote add origin "$APK_TOOLS_REPO" \ - && git -C /tmp/apk-tools fetch --quiet --depth 1 origin "${APK_TOOLS_COMMIT}" \ + timeout 120 git init --quiet /tmp/apk-tools \ + && git -C /tmp/apk-tools remote add origin "$1" \ + && timeout 60 git -C /tmp/apk-tools fetch --quiet --depth 1 origin "${APK_TOOLS_COMMIT}" \ && git -C /tmp/apk-tools checkout --quiet FETCH_HEAD } - clone_full() { - rm -rf /tmp/apk-tools - git clone --quiet "$APK_TOOLS_REPO" /tmp/apk-tools \ - && git -C /tmp/apk-tools checkout --quiet "${APK_TOOLS_COMMIT}" - } got_source= - for method in fetch_pinned fetch_pinned fetch_pinned clone_full; do - if "$method"; then got_source=$method; break; fi - echo "apk-tools $method failed; retrying after backoff" >&2 + for round in 1 2 3; do + for repo in $APK_TOOLS_MIRRORS; do + if fetch_pinned "$repo"; then got_source=$repo; break 2; fi + echo "apk-tools: round $round failed against $repo" >&2 + done sleep 20 done if [ -z "$got_source" ]; then - echo "::error::could not obtain apk-tools ${APK_TOOLS_COMMIT} from $APK_TOOLS_REPO" + echo "::error::could not obtain apk-tools ${APK_TOOLS_COMMIT} from any of: $APK_TOOLS_MIRRORS" exit 1 fi + echo "apk-tools ${APK_TOOLS_COMMIT} fetched from $got_source" cd /tmp/apk-tools meson setup build ninja -C build src/apk