Repository navigation
Re-download truncated e2e-bin archives once in CI - #1387
Conversation
download-artifact v4 can finish "successfully" with a truncated file. Run 38059192473 attempt 1 (PR #1345) logged "Starting download" and nothing more, then the unpack step failed with zstd "Read error (39) : premature end" and the hatch e2e_vex_build leg went red. A re-run on the same SHA passed. In the merge queue the same blip evicts the entry and costs a full rebuild, and every merge group downloads e2e-bin once per e2e and cargo-vex leg. Add a composite download-artifact wrapper, alongside the upload one, that runs a caller-supplied check on the downloaded files. When the download or the check fails it clears the path and downloads once more; a second failure fails the job. The two e2e-bin consumers check the archive with `zstd -t`. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KdaGJqi1VLtSWMnHY4hP6g
|
bugbot run Generated by Claude Code |
The second check now runs only after the second download succeeds, so a failed retry download reports its own error rather than a missing file. `verify` is required: a caller without a check would get no retry. The test pins every step's exact `if:` gate, which catches a broken gate that a substring match missed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KdaGJqi1VLtSWMnHY4hP6g
|
bugbot run Generated by Claude Code |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit cd71fbf. Configure here.
|
Ready for review at
Slack announcement pending (no Slack send tool in this run; the next run retries). Generated by Claude Code |
Final review briefWhat it does. Adds a composite action Risk: low. CI-only; mirrors the existing upload wrapper's Look here
Verified. Read the full diff and compared with Changes I made. None. Open questions. None. Other download-artifact consumers (docker-base, compat workflows) are deliberately left for a follow-up. Auto-merge is armed: approving sends it straight to the merge queue. Generated by Claude Code |
Problem
actions/download-artifactv4 (pinned v4.3.0) can finish successfully and leave a truncated file. In run 38059192473 attempt 1 (PR #1345), jobe2e (ubuntu-latest, e2e_vex_build, hatch:: --ignored, 1.18.1)loggedStarting download of artifactand nothing after it. The next step then failed:Attempt 2 on the same SHA passed. It's the only time this happened in the 3-day window I checked (step-level scan of 107 failed CI runs since 2026-10-08). The exposure is large, though: every merge group downloads the ~94 MB e2e-bin archive once per
e2e,e2e-fullandcargo-vex-matrixleg. In the merge queue a single hit evicts the entry and costs a full rebuild.Root cause
A transient short read in the artifact download. The action doesn't check that the file is complete, so the truncation only shows up later, when
zstd -druns in "Unpack the e2e binaries". The upload side already has a retry wrapper (.github/actions/upload-artifact). The download side had nothing.Fix
.github/actions/download-artifact, built like the upload wrapper. It downloads once (continue-on-error) and runs a caller-suppliedverifybash check. If the download or the check fails, it clearspath, waits 10 s, downloads again and checks again. Neither of those last two steps continues on error, so a second bad download fails the job.ci.yml(the&e2e-stepsand&cargo-vex-stepsanchors, which cover e2e, e2e-windows/macos/full and every cargo-vex-matrix job) now use the wrapper withverify: zstd -q -t target/e2e-archive/e2e-bin.tar.zst.pattern: e2e-bin-${{ matrix.os }}*contract thattest_ci_scheduling.pychecks is unchanged.No test is removed or moved. Required-check names and
ci-okare unchanged.Proof
scripts/tests/test_ci_e2e_archive.py:verifycommand passes a good archive and fails a half-truncated one and a missing one.python3 -B -m unittest discover -s scripts/tests: 327 tests OK, with zstd installed, so the archive tests actually run.zizmor --offline: the new action has no findings. Inci.ymlthe only new notes are help-levelself-repository, the same note the existing./.github/actions/upload-artifactuses already get.actionlint: no new findings. Its aliassyntax-checkerrors were already there on main.Review findings not fixed here
From `/code-review high`. Fixed in cd71fbf: the second check is gated on the second download succeeding, `verify` is required, and the test pins each step's exact `if:` gate (checked by mutating one gate).
🤖 Generated with Claude Code
https://claude.ai/code/session_01KdaGJqi1VLtSWMnHY4hP6g
Generated by Claude Code