Bound registry downloads by ApiTimeouts instead of a 60 s total deadline (#872) - #876
Open
Mikola Lysenko (mikolalysenko) wants to merge 4 commits into
Open
Mikola Lysenko (mikolalysenko) wants to merge 4 commits into
Mikola Lysenko (mikolalysenko) wants to merge 4 commits into
Conversation
Assisted-by: Claude Code:claude-opus-5-5
6 tasks
Hosted upstream restore (rollback, vendor takeover) and vendored Maven built their registry clients with a 60 s whole-request deadline and no connect bound, so on a slow link an original tarball, module zip or jar that took over a minute to download failed with a transport error even while bytes were still arriving, and a black-holed host held the run for the full minute. Both now build through one registry_fetch::registry_client_builder that applies the shared ApiTimeouts policy: 10 s connect plus 60 s of silence, no total deadline. registry_fetch::download reads the body through utils::http::read_capped, deleting the last hand-rolled copy of the capped reader; the cap and its checks are unchanged, only the refusal wording now matches the other capped downloads. Assisted-by: Claude Code:claude-opus-5-5
#646 landed inline sha1/sha256 computations in patch/jvm_jar.rs, patch/sidecars/maven.rs and crawlers/gradle_cache.rs after the utils::digest ratchet, so production_digests_go_through_the_helpers fails on main. jvm_jar's private sha1_hex/sha256_hex copies and the Maven sidecar's inline sha1 now call the shared helpers; gradle_cache.rs, which an open PR also edits, joins the pending list for now. Hashes are byte-identical. Assisted-by: Claude Code:claude-opus-5-5
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 5, 2026 18:21
Collaborator
Author
|
BugBot review Generated by Claude Code |
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 5, 2026
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 28d4d52. Configure here.
Tanmay Singla (Tanmay182003)
approved these changes
Oct 5, 2026
Collaborator
Author
|
Burn-down agent: labeled Ready for review at
Generated by Claude Code |
Mikola Lysenko (mikolalysenko)
pushed a commit
that referenced
this pull request
Oct 5, 2026
#646 landed inline sha1/sha256 computations in patch/jvm_jar.rs, patch/sidecars/maven.rs and crawlers/gradle_cache.rs after the utils::digest ratchet, so production_digests_go_through_the_helpers fails on main. jvm_jar's private sha1_hex/sha256_hex copies and the Maven sidecar's inline sha1 now call the shared helpers; gradle_cache.rs, which an open PR also edits, joins the pending list for now. Hashes are byte-identical. Ported from #876 so this PR's CI is not red on the base-red ratchet. (cherry picked from commit 28d4d52) Assisted-by: Claude Code:claude-opus-5-5
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
LLM Description written by Claude Code:claude-opus-5-5
Fixes #872
Summary
Hosted upstream restore (
rollback, thevendortakeover) and vendored Maven built their registry clients with a 60 s whole-request deadline and no connect bound, so a slow but progressing download of an original tarball, Go module zip, NuGet document or jar was aborted at 60 s. Both now build through oneregistry_fetch::registry_client_builderunder the sharedApiTimeoutspolicy (10 s connect, 60 s of silence reset per chunk, no total deadline), andregistry_fetch::downloadreads throughutils::http::read_capped.Why
register/20-audit-core.md, living document §7 "Other HTTP stacks" (doc/07-infra-agent.md).read_cappedand Maven's second registryClient::builder), R = L. Score ≈ 5.1, first in the refactor queue.What changed
vendor/registry_fetch.rs: newregistry_client_builder(user_agent)appliesApiTimeouts;build_registry_clientuses it.downloadkeeps its http(s) and status checks, then callsread_capped(resp, MAX_DOWNLOAD_BYTES, "registry artifact"). A#[cfg(test)]thread-localtest_timeoutsoverride shortens the bounds in tests.vendor/maven_repo.rs:fetch_registry_bytesbuilds throughregistry_client_builder(MAVEN_USER_AGENT), so it keeps its Maven user agent.mainfailsutils::digest::tests::production_digests_go_through_the_helpersbecause Full Gradle support in agent, hosted and vendored modes #646 landed inline digests after the ratchet.patch/jvm_jar.rs's privatesha1_hex/sha256_hexand the Maven sidecar's inline sha1 now callutils::digest::{sha1_hex_of, sha256_hex_of}.crawlers/gradle_cache.rsjoinsPENDING_INLINE_DIGESTSrather than being edited, because open sbt, Mill and scala-cli support in agent, hosted and vendored modes #690 changes it. Hashes are byte-identical.Deviation from the issue: Maven still builds a client per fetch (now through the shared builder) rather than one per process. A process-global
reqwest::Clientkeeps pooled connections bound to the tokio runtime that opened them, which breaks across the many per-test runtimes. Each Maven vendor run makes only a handful of fetches.Deleted
registry_fetch::download.Client::builder().timeout(60 s)and theDurationimport.jvm_jar.rs's two private digest helpers.git diff --stat origin/main: 5 files, +165 / −55. Production ≈ +55 / −60; tests ≈ +91 / −1.Behavior
downloadnow useread_capped's wording (registry artifact too large: declared N bytes > CAP cap/… exceeded CAP-byte cap mid-stream), prefixed with the URL. The caps themselves are unchanged.Test evidence
registry_clients_have_no_total_deadline: with the idle bound shortened to 400 ms, a body that trickles for 1.6 s arrives whole through bothbuild_registry_client+downloadand Maven'sfetch_registry_bytes.registry_clients_fail_a_body_that_stalls_past_the_idle_bound: a body that goes silent for 5 s mid-stream fails at the idle bound through both clients. Red→green: with the builder reverted to the old.timeout(60 s)it FAILS (both fetches wait out the stall and succeed); on the branch it passes.error decoding response body). Branch: both return all 71 680 bytes in ≈70.1 s.cargo test -p socket-patch-core --lib: 5248 passed, 4 failed. The 4 are the known root-only sandbox failures (relax_loop_must_not_traverse_symlinked_root,an_unremovable_hidden_lock_keeps_every_store_entry,wire_write_failure_maps_error_and_leaves_lock_untouched,wire_failure_rolls_back_already_written_files), which also fail onmain.production_digests_go_through_the_helpersfails onmainand passes here.cargo test -p socket-patch-cli --all-features --test in_process_rollback_hosted --test maven_sidecar_cli: 23 + 8 passed.cargo clippy --workspace --all-features -- -D warnings: clean.28d4d52at 18:42Z: 412 checks passed, 0 failed (includingcoverage,clippyandtest (macos-latest)); 24 Gradle and Windows jobs still running. Bugbot found no issues on28d4d52.Risk
Low. The transport bounds follow the policy the patch-API clients have used since #581. The download cap and its checks are unchanged.
🤖 Generated with Claude Code
https://claude.ai/code/session_01DBN2DxcmTxCSNfaHk2oxu2
Generated by Claude Code