ci: retry dropped release asset downloads - #2667
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: needs maintainer review before merge. Reviewed October 2, 2026, 6:22 AM ET / 10:22 UTC (Revision 2). ClawSweeper reviewWhat this changesThe PR makes public release-asset downloads retry all curl errors, uses curl-managed output files to reset partial downloads, and updates workflow tests and release notes. Merge readiness✅ Ready for maintainer review The change remains useful: current main lacks the broader download retry, and the patch preserves release validation and credential isolation. No actionable defect was found. Priority: P2 Review scores
Verification
How this fits togetherCrabbox’s release verification workflows download published binaries and metadata before checking their integrity and running native installation checks. These downloads feed release-asset validation and Homebrew verification. flowchart TD
A[Published release assets] --> B[Public download]
B --> C{Transfer succeeds?}
C -->|No| D[Retry with reset output file]
D --> B
C -->|Yes| E[Release identity and integrity checks]
E --> F[Native and Homebrew verification]
Before mergeNone. Agent review detailsSecurityNone. Review metricsNone. Technical reviewBest possible solution: Keep bounded retries with curl-managed output while preserving immutable-release identity, digest checks, and credential-free installation. Do we have a high-confidence way to reproduce the issue? Yes, from source: current-main asset downloads omit retry-all-errors, leaving dropped-connection failures outside the broader retry handling. The reported curl failure was not independently executed. Is this the best way to solve the issue? Yes. Broadening retries for these idempotent downloads and giving curl control of output files is a focused repair that retains existing validation. AGENTS.md: found and applied where relevant. Codex review notes: model internal, reasoning medium; reviewed against b83d53caf233. LabelsLabel changes: No label changes. Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (1 earlier review cycle)
|
fcdf5dd to
5e828e4
Compare
The hosted Homebrew verifier rerun for 0.70.0 (run 36992418395) failed its x86_64 job on a single transient
curl: (56) Recv failure: Operation timed outwhile downloading a public release asset. Plain--retry 3only retries timeouts and HTTP 408/429/5xx, so one dropped connection failed the whole verification.Changes:
verify-homebrew.yml: the public asset download adds--retry-all-errors.release-assets.ymlpublic download mode: adds--retry-all-errorsand writes with--outputinstead of a shell redirect, so curl can discard a partial file before retrying.Size and digest validation after each download is unchanged, so a bad retry still fails closed.
Proof: the release-workflow mock now requires
--retry-all-errorsand--outputfor public asset downloads. It fails against the previous workflow and passes with this change; all 77 release-workflow script tests pass. Autoreview is scoped-clean.