Repository navigation
Fix composer e2e flake on packagist connect timeouts - #1037
Merged
Mikola Lysenko (mikolalysenko) merged 1 commit intoOct 7, 2026
Merged
Conversation
The composer capstones' fixture setup runs a real `composer update` against repo.packagist.org once. With SOCKET_PATCH_COMPOSER_E2E_REQUIRED set (every CI and composer-compatibility leg), a single 10 s curl connect timeout to packagist fails the leg through skip()'s assert, on PRs that never touch composer code (e.g. the rustls bump, job 112776608105: "curl error 28 while downloading https://repo.packagist.org/packages.json"). Re-run a failed composer command, up to 3 attempts with 5 s/10 s backoff, only when its output shows a connect-level curl failure (codes 6, 7, 28, 35, 52, 56) against a non-loopback host. HTTP status errors, checksum refusals and anything against the loopback wiremock patch server still fail at once, so the tampered-archive and no-source fallback assertions are unchanged, and a sustained outage still fails the required leg. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011j1YKsT7s3GopU6brHft2B
Collaborator
Author
|
bugbot run Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 8c23705. Configure here.
Mikola Lysenko (mikolalysenko)
enabled auto-merge (squash)
October 7, 2026 15:26
Tanmay Singla (Tanmay182003)
approved these changes
Oct 7, 2026
Mikola Lysenko (mikolalysenko)
deleted the
ci-janitor/composer-packagist-retry
branch
October 7, 2026 16:07
This was referenced Oct 7, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The composer capstones (
e2e_vendor_composer_build,e2e_redirect_composer_build) set up their fixture by running a realcomposer updateagainst repo.packagist.org, once. Every CI andcomposer-compatibility.ymlleg setsSOCKET_PATCH_COMPOSER_E2E_REQUIRED=1, so a single 10 s curl connect timeout to packagist turnsskip()'s assert into a hard failure. This happens on PRs that never touch composer code:dependabot/cargo/rustls-0.23.45),composer 2.2.30 / php 8.3 / windows-latest, testcomposer_vendor_redownloads_modified_copy:agent/fix-yarn-berry-catalog-resolutions) failed on the same leg with the same signature.Root cause
The fixture setup is the only step in these suites that reaches the public internet (packagist, plus the GitHub zipball).
composer_e2e_common::composerran it once with no handling for transient transport errors. Composer 2.2 does not retry a curl connect timeout onpackages.json. The hosted Windows runners intermittently fail to connect to packagist within composer's 10 s connect timeout.Fix
composer_e2e_common::composernow re-runs a failed composer command only when its output has acurl error <code> while downloading <url>line where:It makes up to 3 attempts, with 5 s and 10 s backoff. Nothing else changes:
127.0.0.1/localhost(the wiremock patch server) still fail on the first attempt. Socomposer_redirect_tampered_archive_fails_checksum_verificationand the no-source-fallback assertions are untouched.Two self-tests pin the classifier: the exact CI line and its wrapped
[TransportException]box form are transient; loopback, curl 60, HTTP 404, checksum and resolver errors are not.Proof
All local runs use real composer 2 and real packagist.
HTTPS_PROXY=http://10.255.255.1:3128for the firstcomposer updateonly, through aSOCKET_PATCH_PHP_BINwrapper).composer_vendor_redownloads_modified_copyfails with the CI signature:panicked at .../composer_e2e_common/mod.rs:91:5,curl error 28 while downloading https://repo.packagist.org/packages.json.composer update: transport failure (curl error 28 ...); retrying (1/3)and then passes (21.9 s).--ignoredandSOCKET_PATCH_COMPOSER_E2E_REQUIRED=1: 5 hosted, including the tampered-archive checksum test, and 6 vendored. The non-ignored tests in both binaries also pass, 17 and 11, including the 2 new self-tests.rustfmt --checkis clean on the touched file.prebuilt_common/mod.rs, which this PR doesn't touch; CI's clippy job doesn't lint test targets.Where tests run
No test was removed, moved or weakened, and no workflow changed. The composer capstones keep running in
ci.yml(e2ematrix, composer 1/2/2.2) and incomposer-compatibility.yml, as before.🤖 Generated with Claude Code
https://claude.ai/code/session_011j1YKsT7s3GopU6brHft2B
Generated by Claude Code
Note
Low Risk
Test-only helper changes with bounded retries; production code and security-sensitive assertions (loopback/checksum) are unchanged.
Overview
Reduces flaky CI failures when Composer e2e fixture setup hits transient network errors talking to Packagist/GitHub.
composer()now retries up to 3 times (5s/10s backoff) only when stderr/stdout contains a connect-levelcurl error(codes 6, 7, 28, 35, 52, 56) for a non-loopback URL. Loopback wiremock failures, HTTP status errors, checksum failures, and resolver errors still fail immediately on the first run.Adds
remote_transport_failureto classify output, splits the old single-shot runner intocomposer_once, documents the behavior forSOCKET_PATCH_COMPOSER_E2E_REQUIRED, and adds two self-tests that lock in transient vs non-transient cases (including the Windows packagist curl-28 signature).Reviewed by Cursor Bugbot for commit 8c23705. Configure here.
Generated by Claude Code