Repository navigation
fix(ci): stop installing ffmpeg in jobs that never use it #1360
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -31,45 +31,21 @@ jobs: | |
| cache: "pnpm" | ||
| registry-url: https://registry.npmjs.org/ | ||
|
|
||
| # Installed from the runner's package index rather than a third-party | ||
| # action that downloads release assets from another repository. That | ||
| # action broke this workflow twice — first a corrupt 8.1 asset, then | ||
| # the 7.1 pin added to work around it — and because this is the | ||
| # publish workflow, each break silently stopped releases from going | ||
| # out while CI still looked healthy. ci.yml was moved off it already. | ||
| - name: Install ffmpeg | ||
| timeout-minutes: 15 | ||
| run: | | ||
| if command -v ffmpeg >/dev/null 2>&1; then | ||
| echo "ffmpeg already present: $(ffmpeg -version | head -1)" | ||
| exit 0 | ||
| fi | ||
| export DEBIAN_FRONTEND=noninteractive | ||
| # Runners boot with unattended-upgrades holding the dpkg lock, and a | ||
| # plain apt-get waits on that lock forever. On 2026-08-18 this step | ||
| # sat in_progress for 90 minutes on two open PRs, leaving the quality | ||
| # gate permanently "pending" with nothing to re-run against. Bound | ||
| # every wait so a contended lock fails fast, and let the step | ||
| # deadline catch anything the bounds miss. | ||
| sudo systemctl stop unattended-upgrades.service >/dev/null 2>&1 || true | ||
| APT_OPTS="-o DPkg::Lock::Timeout=60 -o Acquire::Retries=3" | ||
| APT_OPTS="$APT_OPTS -o Acquire::http::Timeout=30 -o Acquire::https::Timeout=30" | ||
| for attempt in 1 2 3; do | ||
| sudo apt-get $APT_OPTS update && break | ||
| echo "apt-get update failed (attempt ${attempt}/3), retrying in 5s" | ||
| sleep 5 | ||
| done | ||
| sudo apt-get $APT_OPTS install -y --no-install-recommends ffmpeg | ||
|
|
||
| - name: Verify ffmpeg installation | ||
| run: | | ||
| echo "🎬 Verifying ffmpeg installation..." | ||
| ffmpeg -version || { | ||
| echo "❌ ffmpeg installation failed!" | ||
| echo "apt-get install ffmpeg did not produce a working binary." | ||
| exit 1 | ||
| } | ||
| echo "✅ ffmpeg installed successfully" | ||
| # ffmpeg is deliberately NOT installed in this workflow. Nothing these | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 💡 MINOR: Remove unnecessary ffmpeg installation from release workflow - Removing ffmpeg from release.yml prevents the same apt lock issues from affecting release pipelines. The release workflow builds and publishes packages - it does not run any media processing suites that would require ffmpeg at runtime. Consistent with ci.yml changes - release jobs don't need ffmpeg and were vulnerable to the same apt lock issues. |
||
| # jobs run needs it: no package script invokes it, and src/ shells out to | ||
| # ffmpeg only at runtime (frame extraction, video merge, audio playback), | ||
| # never during install, lint, typecheck, build or pack. provider-safety-net | ||
| # has always built and run its suites without it. | ||
| # | ||
| # Removed after the apt install broke CI three ways in one day: a corrupt | ||
| # published asset, a version pin that stopped resolving, and an Ubuntu | ||
| # mirror returning Ign: for every index while apt sat for 14 minutes. | ||
| # Because build-check is a required check, each of those blocked every | ||
| # open pull request on a dependency none of these jobs use. | ||
|
Comment on lines
+43
to
+44
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Fixed in #1895: the |
||
| # | ||
| # If a job here ever runs a suite that genuinely exercises media, install | ||
| # ffmpeg in THAT job only, and bound every wait (DPkg::Lock::Timeout, | ||
| # Acquire::*::Timeout) plus a step timeout-minutes. | ||
|
|
||
| - name: Install dependencies | ||
| run: pnpm i | ||
|
|
@@ -107,46 +83,6 @@ jobs: | |
| registry-url: "https://registry.npmjs.org" | ||
| cache: "pnpm" | ||
|
|
||
| # Installed from the runner's package index rather than a third-party | ||
| # action that downloads release assets from another repository. That | ||
| # action broke this workflow twice — first a corrupt 8.1 asset, then | ||
| # the 7.1 pin added to work around it — and because this is the | ||
| # publish workflow, each break silently stopped releases from going | ||
| # out while CI still looked healthy. ci.yml was moved off it already. | ||
| - name: Install ffmpeg | ||
| timeout-minutes: 15 | ||
| run: | | ||
| if command -v ffmpeg >/dev/null 2>&1; then | ||
| echo "ffmpeg already present: $(ffmpeg -version | head -1)" | ||
| exit 0 | ||
| fi | ||
| export DEBIAN_FRONTEND=noninteractive | ||
| # Runners boot with unattended-upgrades holding the dpkg lock, and a | ||
| # plain apt-get waits on that lock forever. On 2026-08-18 this step | ||
| # sat in_progress for 90 minutes on two open PRs, leaving the quality | ||
| # gate permanently "pending" with nothing to re-run against. Bound | ||
| # every wait so a contended lock fails fast, and let the step | ||
| # deadline catch anything the bounds miss. | ||
| sudo systemctl stop unattended-upgrades.service >/dev/null 2>&1 || true | ||
| APT_OPTS="-o DPkg::Lock::Timeout=60 -o Acquire::Retries=3" | ||
| APT_OPTS="$APT_OPTS -o Acquire::http::Timeout=30 -o Acquire::https::Timeout=30" | ||
| for attempt in 1 2 3; do | ||
| sudo apt-get $APT_OPTS update && break | ||
| echo "apt-get update failed (attempt ${attempt}/3), retrying in 5s" | ||
| sleep 5 | ||
| done | ||
| sudo apt-get $APT_OPTS install -y --no-install-recommends ffmpeg | ||
|
|
||
| - name: Verify ffmpeg installation | ||
| run: | | ||
| echo "🎬 Verifying ffmpeg installation..." | ||
| ffmpeg -version || { | ||
| echo "❌ ffmpeg installation failed!" | ||
| echo "apt-get install ffmpeg did not produce a working binary." | ||
| exit 1 | ||
| } | ||
| echo "✅ ffmpeg installed successfully" | ||
|
|
||
| - name: Upgrade npm for native OIDC publish support | ||
| run: | | ||
| npx -y npm@11 install -g npm@11 | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
💡 MINOR: Remove unnecessary ffmpeg installation from CI - The ffmpeg dependency is bundled via ffmpeg-static/ffprobe-static as optional dependencies and is used at runtime only (frame extraction, video merging). All CI jobs either run static analysis (lint, format, typecheck), mock tests, or build verification - none require runtime media processing. This change addresses real CI failures where apt-get install ffmpeg caused 90+ minute lock waits and was blocked by corrupt upstream assets. Jobs that genuinely need ffmpeg (e.g., test:media suite) should be added separately with proper apt timeout guards.