Skip to content

Retry Composer/Maven/Gradle downloads on connect and TLS errors - #868

Merged
Mikola Lysenko (mikolalysenko) merged 1 commit into
mainfrom
ci-janitor/curl-retry-all-errors
Oct 5, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 1 commit into
mainfrom
ci-janitor/curl-retry-all-errors

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

Two composer-compatibility.yml runs on 2026-10-05 went red in the Download and verify composer step, before any test ran, on PRs that don't touch Composer:

run leg error
37317887822 (#731) composer 2.2.30 / php 8.3 / windows-latest curl: (35) schannel: next InitializeSecurityContext failed: CRYPT_E_REVOCATION_OFFLINE
37306119898 composer 1.10.28 / php 8.1 / macos-latest curl: (7) Failed to connect to getcomposer.org port 443 after 112 ms

That's 2 of the 6 failed Composer runs in the last 300 (2026-10-03 to 10-05). Most of the other 4 were PR bugs that failed every leg. Each one needs a re-run of the 19-leg matrix. The CI Maven/Gradle install steps download the same way, so they're exposed to the same thing.

Root cause

All three steps use curl -fsSL --retry 3. curl's --retry only retries timeouts and HTTP 408/429/5xx. A refused connection (exit 7) and a TLS handshake failure (exit 35) fail on the first attempt, so the 3 retries never run. Both logs show a single attempt.

Fix

Use --retry 5 --retry-all-errors on the 6 downloads (Composer phar + .sha256sum, Maven tarball + .sha512, Gradle zip + .sha256). ci.yml already uses exactly this for the vexctl downloads. Each body is checked against a pinned or published digest right after the download, so retrying any error can't let a bad file through. A real outage still fails, after about 31 s of backoff (1+2+4+8+16 s).

Proof

Local curl 8.5.0:

  • curl -fS --retry 3 https://127.0.0.1:9/ → one (7), exit 7, no retry. With --retry 5 --retry-all-errors → 5 retries with backoff, then exit 7.
  • A TLS handshake failure (https:// to a plain-http server) → one (35) with --retry 3. With --retry-all-errors it retries.
  • actionlint finds nothing new in either file (the 24 findings it reports are all from the existing YAML anchors, which actionlint 1.7.7 doesn't parse). Both files parse with PyYAML.

Where tests run

No test, job or check is removed, renamed or moved. Only the retry policy of 6 download commands changes.

🤖 Generated with Claude Code

https://claude.ai/code/session_01M7YkVUqGY83YbfQPipKzk5


Generated by Claude Code

The Composer phar, Maven and Gradle downloads used `curl --retry 3`,
which only retries timeouts and HTTP 408/429/5xx. A refused
connection (exit 7) or a TLS handshake failure (exit 35, e.g.
Windows schannel CRYPT_E_REVOCATION_OFFLINE) fails the step on the
first try. Both happened on 2026-10-05 in composer-compatibility
legs on PRs that don't touch Composer.

Use the repo's existing `--retry 5 --retry-all-errors` pattern (the
vexctl downloads in ci.yml). Every one of these downloads is checked
against a pinned or published digest right after, so retrying any
error can't let a bad body through.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M7YkVUqGY83YbfQPipKzk5
@mikolalysenko Mikola Lysenko (mikolalysenko) added the ci-janitor Opened by the CI janitor routine (flakes, redundant tests, CI perf) label Oct 5, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

bugbot run


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit 5d351c7. Configure here.

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 5, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

Burn-down agent: labeled Ready for review at 5d351c7.

  • CI: 357 success + 6 skipped, 0 failing; mergeable clean against main.
  • Bugbot: Cursor Bugbot check passed on 5d351c7; 0 unresolved review threads.
  • Linked issue(s) still open and not fixed on main.

Generated by Claude Code

@mikolalysenko
Mikola Lysenko (mikolalysenko) merged commit abd3c45 into main Oct 5, 2026
363 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the ci-janitor/curl-retry-all-errors branch October 5, 2026 17:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci-janitor Opened by the CI janitor routine (flakes, redundant tests, CI perf) Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants