Retry Composer/Maven/Gradle downloads on connect and TLS errors - #868
Merged
Mikola Lysenko (mikolalysenko) merged 1 commit intoOct 5, 2026
Merged
Conversation
The Composer phar, Maven and Gradle downloads used `curl --retry 3`, which only retries timeouts and HTTP 408/429/5xx. A refused connection (exit 7) or a TLS handshake failure (exit 35, e.g. Windows schannel CRYPT_E_REVOCATION_OFFLINE) fails the step on the first try. Both happened on 2026-10-05 in composer-compatibility legs on PRs that don't touch Composer. Use the repo's existing `--retry 5 --retry-all-errors` pattern (the vexctl downloads in ci.yml). Every one of these downloads is checked against a pinned or published digest right after, so retrying any error can't let a bad body through. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01M7YkVUqGY83YbfQPipKzk5
Collaborator
Author
|
bugbot run Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 5d351c7. Configure here.
Tanmay Singla (Tanmay182003)
approved these changes
Oct 5, 2026
Collaborator
Author
|
Burn-down agent: labeled Ready for review at
Generated by Claude Code |
Mikola Lysenko (mikolalysenko)
deleted the
ci-janitor/curl-retry-all-errors
branch
October 5, 2026 17:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Two
composer-compatibility.ymlruns on 2026-10-05 went red in the Download and verify composer step, before any test ran, on PRs that don't touch Composer:curl: (35) schannel: next InitializeSecurityContext failed: CRYPT_E_REVOCATION_OFFLINEcurl: (7) Failed to connect to getcomposer.org port 443 after 112 msThat's 2 of the 6 failed Composer runs in the last 300 (2026-10-03 to 10-05). Most of the other 4 were PR bugs that failed every leg. Each one needs a re-run of the 19-leg matrix. The CI Maven/Gradle install steps download the same way, so they're exposed to the same thing.
Root cause
All three steps use
curl -fsSL --retry 3. curl's--retryonly retries timeouts and HTTP 408/429/5xx. A refused connection (exit 7) and a TLS handshake failure (exit 35) fail on the first attempt, so the 3 retries never run. Both logs show a single attempt.Fix
Use
--retry 5 --retry-all-errorson the 6 downloads (Composer phar +.sha256sum, Maven tarball +.sha512, Gradle zip +.sha256). ci.yml already uses exactly this for the vexctl downloads. Each body is checked against a pinned or published digest right after the download, so retrying any error can't let a bad file through. A real outage still fails, after about 31 s of backoff (1+2+4+8+16 s).Proof
Local curl 8.5.0:
curl -fS --retry 3 https://127.0.0.1:9/→ one(7), exit 7, no retry. With--retry 5 --retry-all-errors→ 5 retries with backoff, then exit 7.https://to a plain-http server) → one(35)with--retry 3. With--retry-all-errorsit retries.actionlintfinds nothing new in either file (the 24 findings it reports are all from the existing YAML anchors, which actionlint 1.7.7 doesn't parse). Both files parse with PyYAML.Where tests run
No test, job or check is removed, renamed or moved. Only the retry policy of 6 download commands changes.
🤖 Generated with Claude Code
https://claude.ai/code/session_01M7YkVUqGY83YbfQPipKzk5
Generated by Claude Code