Skip to content

Commit abd3c45

Browse files
Retry pinned tool downloads on connect/TLS errors (#868)
The Composer phar, Maven and Gradle downloads used `curl --retry 3`, which only retries timeouts and HTTP 408/429/5xx. A refused connection (exit 7) or a TLS handshake failure (exit 35, e.g. Windows schannel CRYPT_E_REVOCATION_OFFLINE) fails the step on the first try. Both happened on 2026-10-05 in composer-compatibility legs on PRs that don't touch Composer. Use the repo's existing `--retry 5 --retry-all-errors` pattern (the vexctl downloads in ci.yml). Every one of these downloads is checked against a pinned or published digest right after, so retrying any error can't let a bad body through. Claude-Session: https://claude.ai/code/session_01M7YkVUqGY83YbfQPipKzk5 Co-authored-by: Claude <noreply@anthropic.com>
1 parent 7fd88f5 commit abd3c45

2 files changed

Lines changed: 6 additions & 6 deletions

File tree

‎.github/workflows/ci.yml‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1405,8 +1405,8 @@ jobs:
14051405
run: |
14061406
major="${MAVEN_VERSION%%.*}"
14071407
url="https://archive.apache.org/dist/maven/maven-${major}/${MAVEN_VERSION}/binaries/apache-maven-${MAVEN_VERSION}-bin.tar.gz"
1408-
curl -fsSL --retry 3 "$url" -o "$RUNNER_TEMP/maven.tgz"
1409-
curl -fsSL --retry 3 "$url.sha512" -o "$RUNNER_TEMP/maven.sha512"
1408+
curl -fsSL --retry 5 --retry-all-errors "$url" -o "$RUNNER_TEMP/maven.tgz"
1409+
curl -fsSL --retry 5 --retry-all-errors "$url.sha512" -o "$RUNNER_TEMP/maven.sha512"
14101410
python -c 'import hashlib, pathlib, os; p=pathlib.Path(os.environ["RUNNER_TEMP"]); assert hashlib.sha512((p/"maven.tgz").read_bytes()).hexdigest() == (p/"maven.sha512").read_text().split()[0]'
14111411
# Python accepts native Windows paths for both archive and destination.
14121412
python -m tarfile -e "$RUNNER_TEMP/maven.tgz" "$RUNNER_TEMP"
@@ -1421,8 +1421,8 @@ jobs:
14211421
GRADLE_VERSION: ${{ matrix.gradle }}
14221422
run: |
14231423
url="https://services.gradle.org/distributions/gradle-${GRADLE_VERSION}-bin.zip"
1424-
curl -fsSL --retry 3 "$url" -o "$RUNNER_TEMP/gradle.zip"
1425-
curl -fsSL --retry 3 "$url.sha256" -o "$RUNNER_TEMP/gradle.sha256"
1424+
curl -fsSL --retry 5 --retry-all-errors "$url" -o "$RUNNER_TEMP/gradle.zip"
1425+
curl -fsSL --retry 5 --retry-all-errors "$url.sha256" -o "$RUNNER_TEMP/gradle.sha256"
14261426
python -c 'import hashlib, pathlib, os; p=pathlib.Path(os.environ["RUNNER_TEMP"]); assert hashlib.sha256((p/"gradle.zip").read_bytes()).hexdigest() == (p/"gradle.sha256").read_text().strip()'
14271427
unzip -q "$RUNNER_TEMP/gradle.zip" -d "$RUNNER_TEMP"
14281428
launcher="$RUNNER_TEMP/gradle-${GRADLE_VERSION}/bin/gradle"

‎.github/workflows/composer-compatibility.yml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -133,8 +133,8 @@ jobs:
133133
fi
134134
phar="$dir/composer-$COMPOSER_RELEASE.phar"
135135
base="https://getcomposer.org/download/$COMPOSER_RELEASE/composer.phar"
136-
curl -fsSL --retry 3 -o "$phar" "$base"
137-
published="$(curl -fsSL --retry 3 "$base.sha256sum" | cut -d' ' -f1)"
136+
curl -fsSL --retry 5 --retry-all-errors -o "$phar" "$base"
137+
published="$(curl -fsSL --retry 5 --retry-all-errors "$base.sha256sum" | cut -d' ' -f1)"
138138
# shellcheck disable=SC2016 # $argv is PHP, not shell
139139
actual="$(php -r 'echo hash_file("sha256", $argv[1]);' "$phar")"
140140
if [ "$actual" != "$COMPOSER_PHAR_SHA256" ] || [ "$actual" != "$published" ]; then

0 commit comments

Comments
 (0)