Pin Renovate Maven lookups to the registry hosting each package - #20
Merged
Merged
Conversation
Renovate's Maven manager appends Maven Central to every Maven dependency and the datasource queries every registry in settings.xml for every dep. When Central answers 429, the datasource raises an ExternalHostError and the whole run aborts before any lookup or update. This is what has been aborting runs in packtests since around Sep 6, and this repo has the same multi-registry settings.xml, Central included. - Restrict lookups per groupId: org.cyclops.* to our GitHub Packages registry, mekanism to modmaven, refinedstorage to creeperhost (the only registry here carrying its current versions), curse.maven to cursemaven. Central is no longer in the lookup path at all. - Add a hostRule for repo.maven.apache.org as a backstop. Its description records that it does not actually suppress the Central abort, since the Maven datasource throws unconditionally for that host. - Migrate matchPackagePrefixes to matchPackageNames in "Cyclops packages", which Renovate was reporting as a needed config migration. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01N6hkW22Va1tk2EqxDguWG4
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Companion to CyclopsMC/packtests#73, which fixes the same problem in the pack tests repo.
Why this repo is affected too
Renovate runs in
packtestshave been aborting withExternal host error causing abort - skippingsince around Sep 6. The cause is a429 Too Many Requestsfrom Maven Central, which Renovate turns into anExternalHostErrorthat takes down the whole run before any lookup or update happens.This repo is exposed the same way, and more directly than the other infobook repos: its
settings.xmllists Central explicitly alongside github, modmaven, cursemaven and creeperhost, and the Maven datasource usesregistryStrategy = "merge", so all five are queried for each of the 12 deps. On top of that,cleanResultinmodules/manager/maven/extract.jsappends Central to every Maven dep unconditionally, so removing it fromsettings.xmlalone would not help.(Line references are from
renovate@44.82.3, the current release.)What changed
registryUrlspackage rules, so each groupId is only looked up in the registry that actually serves it. This takes Central out of the lookup path entirely, which is what prevents the abort, and cuts 5 registry requests per dep down to 1.org.cyclops.*https://maven.pkg.github.com/CyclopsMC/packagesmekanismhttps://modmaven.dev/com.refinedmods.refinedstoragehttps://maven.creeperhost.net/curse.mavenhttps://www.cursemaven.com/There is no
curse.mavendep here today, but the cursemaven profile is active insettings.xml, so the rule is included to keep a future CurseForge dep off Central from day one.A
hostRuleforrepo.maven.apache.orgwithabortOnError: falseandabortIgnoreStatusCodes: [429], as a backstop. See the caveat below.The config migration Renovate was reporting:
matchPackagePrefixes: ["org.cyclops."]is nowmatchPackageNames: ["org.cyclops.{/,}**"].The
rubensworks/renovate-presets:jsextend,enabledManagers, both automerge rules (including theversioningregex on the Maven one), the existingrefinedstorage-neoforgeallowedVersionsrule, and thegithub-actionsmajor setting are all unchanged.Why refinedstorage goes to creeperhost
maven.creeperhost.netis not the obvious upstream choice, but it is the only registry in thissettings.xmlthat servesrefinedstorage-neoforgeat all. It is not on modmaven, andmaven.refinedmods.comdoes not resolve. Conversely creeperhost is stale formekanism(1.21-10.6.7.54there vs1.21.1-10.7.19.85on modmaven), so mekanism is mapped to modmaven instead. Picking one registry for both without checking would have quietly frozen one of them.Caveat: the hostRule is a backstop, not the fix
I checked this rather than assuming it, and it does not do what it looks like it does. In
util/http/http.jstheExternalHostErrorconversion is gated onabortOnErrorbeing truthy, andabortOnErroris already falsy by default, so setting it tofalseis a no-op, andabortIgnoreStatusCodesis only consulted whenabortOnErroris true. The abort we actually hit is thrown later and unconditionally by the Maven datasource's own Central special case inmodules/datasource/maven/util.js. NohostRulesuppresses it.So change 1 is the real fix. The hostRule is kept only as a harmless backstop for non-Central hosts, and carries an in-file
descriptionsaying so, so nobody later mistakes it for working protection.If you want a hard guarantee instead,
{"matchHost": "repo.maven.apache.org", "enabled": false}does work: a disabled host raises a plainhost-disablederror that the Maven datasource classifies as unknown and swallows, never reaching the Central special case. I left it out because its failure mode is silent, but say the word and I will add it.Validation
.pomfor every non-Cyclops coordinate inmodpack.pom.xmlfrom its mapped registry:mekanism:Mekanism:1.21.1-10.7.18.84from modmaven andrefinedstorage-neoforge:2.0.9from creeperhost both return HTTP 200. No mapping is guessed.matchRegexOrGlobList: all 12 deps match exactly one registry rule, so none is left on the multi-registry default and none matches two rules. The migrated "Cyclops packages" group rule still matches all 10 Cyclops deps.npx --yes --package renovate -- renovate-config-validator --strictpasses on the new config. The same command onmasterexits 1 withConfig migration necessary.🤖 Generated with Claude Code
https://claude.ai/code/session_01N6hkW22Va1tk2EqxDguWG4
Generated by Claude Code