Skip to content

ci: retry dropped release asset downloads - #2667

Merged
steipete merged 1 commit into
mainfrom
codex/release-download-retry
Oct 2, 2026
Merged

steipete merged 1 commit into
mainfrom
codex/release-download-retry

Conversation

@steipete

@steipete steipete commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

The hosted Homebrew verifier rerun for 0.70.0 (run 36992418395) failed its x86_64 job on a single transient curl: (56) Recv failure: Operation timed out while downloading a public release asset. Plain --retry 3 only retries timeouts and HTTP 408/429/5xx, so one dropped connection failed the whole verification.

Changes:

  • verify-homebrew.yml: the public asset download adds --retry-all-errors.
  • release-assets.yml public download mode: adds --retry-all-errors and writes with --output instead of a shell redirect, so curl can discard a partial file before retrying.

Size and digest validation after each download is unchanged, so a bad retry still fails closed.

Proof: the release-workflow mock now requires --retry-all-errors and --output for public asset downloads. It fails against the previous workflow and passes with this change; all 77 release-workflow script tests pass. Autoreview is scoped-clean.

@clawsweeper

clawsweeper Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review complete

ClawSweeper finished reviewing this revision. The review result is being finalized.

View the workflow run.

@steipete
steipete requested a review from a team as a code owner October 2, 2026 10:05
@clawsweeper clawsweeper Bot added P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR. labels Oct 2, 2026
@clawsweeper

clawsweeper Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Codex review: needs maintainer review before merge. Reviewed October 2, 2026, 6:22 AM ET / 10:22 UTC (Revision 2).

ClawSweeper review

What this changes

The PR makes public release-asset downloads retry all curl errors, uses curl-managed output files to reset partial downloads, and updates workflow tests and release notes.

Merge readiness

✅ Ready for maintainer review

The change remains useful: current main lacks the broader download retry, and the patch preserves release validation and credential isolation. No actionable defect was found.

Priority: P2
Reviewed head: 5e828e444aa47f071659d819ee78723c699521ac

Review scores

Measure Result What it means
Overall readiness 🐚 platinum hermit (4/6) A focused, maintainable repair with matching supplemental coverage and no blocking finding.
Proof confidence 🌊 off-meta tidepool Not applicable: GitHub confirms repository-admin authorship, so ordinary contributor runtime proof is exempt. The supplied mock coverage checks workflow arguments rather than real dropped-transfer recovery; no authority or stored-data contract changes require additional proof.
Patch quality 🐚 platinum hermit (4/6) No actionable review findings were identified.

Verification

Check Result Evidence
Real behavior Not applicable Not applicable: GitHub confirms repository-admin authorship, so ordinary contributor runtime proof is exempt. The supplied mock coverage checks workflow arguments rather than real dropped-transfer recovery; no authority or stored-data contract changes require additional proof.
Evidence reviewed 8 items Pinned introduced change: The pinned base-to-head diff changes only two download commands, their mock contract, and an Unreleased changelog bullet; it adds no permissions, dependency sources, or execution steps.
Integrity and credential boundaries remain intact: Public asset downloads remain anonymous and use fixed canonical URLs. Release-assets verification checks each downloaded file’s size and SHA-256 immediately afterward; Homebrew verification still passes through immutable-release validation and credential-free execution.
Curl retry contract: The installed curl manual confirms that retry-all-errors broadens retry handling and that curl resets partial output files before retrying, whereas shell redirects are not reset. The switch to --output follows that documented contract.
Findings None None.
Security None None.

How this fits together

Crabbox’s release verification workflows download published binaries and metadata before checking their integrity and running native installation checks. These downloads feed release-asset validation and Homebrew verification.

flowchart TD
 A[Published release assets] --> B[Public download]
 B --> C{Transfer succeeds?}
 C -->|No| D[Retry with reset output file]
 D --> B
 C -->|Yes| E[Release identity and integrity checks]
 E --> F[Native and Homebrew verification]
Loading

Before merge

None.

Agent review details

Security

None.

Review metrics

None.

Technical review

Best possible solution:

Keep bounded retries with curl-managed output while preserving immutable-release identity, digest checks, and credential-free installation.

Do we have a high-confidence way to reproduce the issue?

Yes, from source: current-main asset downloads omit retry-all-errors, leaving dropped-connection failures outside the broader retry handling. The reported curl failure was not independently executed.

Is this the best way to solve the issue?

Yes. Broadening retries for these idempotent downloads and giving curl control of output files is a focused repair that retains existing validation.

AGENTS.md: found and applied where relevant.

Codex review notes: model internal, reasoning medium; reviewed against b83d53caf233.

Labels

Label changes:

No label changes.

Label justifications:

  • P2: This is a bounded reliability repair for release verification failures caused by dropped asset downloads.
  • rating: 🐚 platinum hermit: Overall readiness is 🐚 platinum hermit; proof is 🌊 off-meta tidepool and patch quality is 🐚 platinum hermit.
  • status: 👀 ready for maintainer look: ClawSweeper has no concrete contributor-facing blocker left for this PR. Not applicable: GitHub confirms repository-admin authorship, so ordinary contributor runtime proof is exempt. The supplied mock coverage checks workflow arguments rather than real dropped-transfer recovery; no authority or stored-data contract changes require additional proof.

Evidence

What I checked:

  • Pinned introduced change: The pinned base-to-head diff changes only two download commands, their mock contract, and an Unreleased changelog bullet; it adds no permissions, dependency sources, or execution steps. (.github/workflows/release-assets.yml:254, 5e828e444aa4)
  • Integrity and credential boundaries remain intact: Public asset downloads remain anonymous and use fixed canonical URLs. Release-assets verification checks each downloaded file’s size and SHA-256 immediately afterward; Homebrew verification still passes through immutable-release validation and credential-free execution. (.github/workflows/release-assets.yml:259, 5e828e444aa4)
  • Curl retry contract: The installed curl manual confirms that retry-all-errors broadens retry handling and that curl resets partial output files before retrying, whereas shell redirects are not reset. The switch to --output follows that documented contract.
  • Still absent from main and latest release: GitHub’s main ref remains the pinned base. Its public release-assets command uses only --retry 3 and shell redirection; v0.70.0’s Homebrew download likewise lacks --retry-all-errors. The PR is still unmerged. (.github/workflows/release-assets.yml:254, b83d53caf233)
  • Latest-release comparison: The v0.70.0 Homebrew workflow already uses curl-managed output but retries only the default transient-error set. (.github/workflows/verify-homebrew.yml, 54b35063af21)
  • Supplemental regression coverage: The changed mock requires retry-all-errors and an explicit output file for public assets. Existing cases reject unsafe release identities and incorrect digests. The supplied body reports 77 passing script tests; no tests or target code were executed during this read-only review. (scripts/release-workflow.test.js:282, 5e828e444aa4)

Likely related people:

  • steipete: Suggested for follow-up; no historical authorship or introduction is verified. (role: unverified routing candidate; confidence: low)

Rating scale

Score Internal tier Crab rank Meaning
6/6 S 🦀 challenger crab Exceptional readiness
5/6 A 🦞 diamond lobster Very strong readiness
4/6 B 🐚 platinum hermit Good normal PR; ordinary maintainer review
3/6 C 🦐 gold shrimp Useful, but confidence is limited
2/6 D 🦪 silver shellfish Proof or implementation needs work
1/6 F 🧂 unranked krab Not merge-ready
N/A NA 🌊 off-meta tidepool Rating does not apply

Overall follows the weaker of proof and patch quality.
Shiny media proof means a screenshot, video, or linked artifact directly shows the changed behavior. Runtime, network, CSP, and security claims still need visible diagnostics.

Workflow

  • ClawSweeper keeps one durable marker-backed review comment per issue or PR.
  • Re-runs edit this comment so the latest verdict, findings, and automation markers stay together instead of adding duplicate bot comments.
  • A fresh review can be triggered by eligible @clawsweeper re-review comments, exact-item GitHub events, scheduled/background review runs, or manual workflow dispatch.
  • PR/issue authors and users with repository write access can comment @clawsweeper re-review or @clawsweeper re-run on an open PR or issue to request a fresh review only.
  • Maintainers can also comment @clawsweeper review to request a fresh review only.
  • Fresh-review commands do not start repair, autofix, rebase, CI repair, or automerge.
  • Maintainer-only repair and merge flows require explicit commands such as @clawsweeper autofix, @clawsweeper automerge, @clawsweeper fix ci, or @clawsweeper address review.
  • Maintainers can comment @clawsweeper explain to ask for more context, or @clawsweeper stop to stop active automation.

History

Review history (1 earlier review cycle)
  • reviewed 2026-10-02T10:09:28.486Z sha fcdf5dd :: needs maintainer review before merge. :: none

@steipete
steipete force-pushed the codex/release-download-retry branch from fcdf5dd to 5e828e4 Compare October 2, 2026 10:18
@steipete
steipete merged commit 07a46f2 into main Oct 2, 2026
52 checks passed
@steipete
steipete deleted the codex/release-download-retry branch October 2, 2026 10:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P2 Normal priority bug or improvement with limited blast radius. rating: 🐚 platinum hermit Good normal PR readiness with ordinary maintainer review expected. status: 👀 ready for maintainer look ClawSweeper has no concrete contributor-facing blocker left for this PR.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant