Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
140 changes: 15 additions & 125 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,47 +24,21 @@ jobs:
node-version: "20"
cache: "pnpm"

# Installed from the runner's package index rather than a third-party
# action that downloads release assets from another repository. That
# action has broken this pipeline twice: first when the 8.1 asset was
# published corrupt, then again when the 7.1 pin added to work around
# it stopped resolving. Neither failure was caused by anything in this
# repository, and both blocked every open pull request. apt carries a
# version new enough for what the suites exercise, and it cannot be
# invalidated by an upstream release being moved or rebuilt.
- name: Install ffmpeg
timeout-minutes: 15
run: |
if command -v ffmpeg >/dev/null 2>&1; then
echo "ffmpeg already present: $(ffmpeg -version | head -1)"
exit 0
fi
export DEBIAN_FRONTEND=noninteractive
# Runners boot with unattended-upgrades holding the dpkg lock, and a
# plain apt-get waits on that lock forever. On 2026-08-18 this step
# sat in_progress for 90 minutes on two open PRs, leaving the quality
# gate permanently "pending" with nothing to re-run against. Bound
# every wait so a contended lock fails fast, and let the step
# deadline catch anything the bounds miss.
sudo systemctl stop unattended-upgrades.service >/dev/null 2>&1 || true
APT_OPTS="-o DPkg::Lock::Timeout=60 -o Acquire::Retries=3"
APT_OPTS="$APT_OPTS -o Acquire::http::Timeout=30 -o Acquire::https::Timeout=30"
for attempt in 1 2 3; do
sudo apt-get $APT_OPTS update && break
echo "apt-get update failed (attempt ${attempt}/3), retrying in 5s"
sleep 5
done
sudo apt-get $APT_OPTS install -y --no-install-recommends ffmpeg

- name: Verify ffmpeg installation
run: |
echo "🎬 Verifying ffmpeg installation..."
ffmpeg -version || {
echo "❌ ffmpeg installation failed!"
echo "apt-get install ffmpeg did not produce a working binary."
exit 1
}
echo "✅ ffmpeg installed successfully"
# ffmpeg is deliberately NOT installed in this workflow. Nothing these

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 MINOR: Remove unnecessary ffmpeg installation from CI - The ffmpeg dependency is bundled via ffmpeg-static/ffprobe-static as optional dependencies and is used at runtime only (frame extraction, video merging). All CI jobs either run static analysis (lint, format, typecheck), mock tests, or build verification - none require runtime media processing. This change addresses real CI failures where apt-get install ffmpeg caused 90+ minute lock waits and was blocked by corrupt upstream assets. Jobs that genuinely need ffmpeg (e.g., test:media suite) should be added separately with proper apt timeout guards.

# jobs run needs it: no package script invokes it, and src/ shells out to
# ffmpeg only at runtime (frame extraction, video merge, audio playback),
# never during install, lint, typecheck, build or pack. provider-safety-net
# has always built and run its suites without it.
#
# Removed after the apt install broke CI three ways in one day: a corrupt
# published asset, a version pin that stopped resolving, and an Ubuntu
# mirror returning Ign: for every index while apt sat for 14 minutes.
# Because build-check is a required check, each of those blocked every
# open pull request on a dependency none of these jobs use.
#
# If a job here ever runs a suite that genuinely exercises media, install
# ffmpeg in THAT job only, and bound every wait (DPkg::Lock::Timeout,
# Acquire::*::Timeout) plus a step timeout-minutes.

- name: Install dependencies
run: pnpm install
Expand Down Expand Up @@ -215,48 +189,6 @@ jobs:
node-version: "22"
cache: "pnpm"

# Installed from the runner's package index rather than a third-party
# action that downloads release assets from another repository. That
# action has broken this pipeline twice: first when the 8.1 asset was
# published corrupt, then again when the 7.1 pin added to work around
# it stopped resolving. Neither failure was caused by anything in this
# repository, and both blocked every open pull request. apt carries a
# version new enough for what the suites exercise, and it cannot be
# invalidated by an upstream release being moved or rebuilt.
- name: Install ffmpeg
timeout-minutes: 15
run: |
if command -v ffmpeg >/dev/null 2>&1; then
echo "ffmpeg already present: $(ffmpeg -version | head -1)"
exit 0
fi
export DEBIAN_FRONTEND=noninteractive
# Runners boot with unattended-upgrades holding the dpkg lock, and a
# plain apt-get waits on that lock forever. On 2026-08-18 this step
# sat in_progress for 90 minutes on two open PRs, leaving the quality
# gate permanently "pending" with nothing to re-run against. Bound
# every wait so a contended lock fails fast, and let the step
# deadline catch anything the bounds miss.
sudo systemctl stop unattended-upgrades.service >/dev/null 2>&1 || true
APT_OPTS="-o DPkg::Lock::Timeout=60 -o Acquire::Retries=3"
APT_OPTS="$APT_OPTS -o Acquire::http::Timeout=30 -o Acquire::https::Timeout=30"
for attempt in 1 2 3; do
sudo apt-get $APT_OPTS update && break
echo "apt-get update failed (attempt ${attempt}/3), retrying in 5s"
sleep 5
done
sudo apt-get $APT_OPTS install -y --no-install-recommends ffmpeg

- name: Verify ffmpeg installation
run: |
echo "🎬 Verifying ffmpeg installation..."
ffmpeg -version || {
echo "❌ ffmpeg installation failed!"
echo "apt-get install ffmpeg did not produce a working binary."
exit 1
}
echo "✅ ffmpeg installed successfully"

- name: Install dependencies
run: pnpm i

Expand Down Expand Up @@ -315,48 +247,6 @@ jobs:
node-version: "22"
cache: "pnpm"

# Installed from the runner's package index rather than a third-party
# action that downloads release assets from another repository. That
# action has broken this pipeline twice: first when the 8.1 asset was
# published corrupt, then again when the 7.1 pin added to work around
# it stopped resolving. Neither failure was caused by anything in this
# repository, and both blocked every open pull request. apt carries a
# version new enough for what the suites exercise, and it cannot be
# invalidated by an upstream release being moved or rebuilt.
- name: Install ffmpeg
timeout-minutes: 15
run: |
if command -v ffmpeg >/dev/null 2>&1; then
echo "ffmpeg already present: $(ffmpeg -version | head -1)"
exit 0
fi
export DEBIAN_FRONTEND=noninteractive
# Runners boot with unattended-upgrades holding the dpkg lock, and a
# plain apt-get waits on that lock forever. On 2026-08-18 this step
# sat in_progress for 90 minutes on two open PRs, leaving the quality
# gate permanently "pending" with nothing to re-run against. Bound
# every wait so a contended lock fails fast, and let the step
# deadline catch anything the bounds miss.
sudo systemctl stop unattended-upgrades.service >/dev/null 2>&1 || true
APT_OPTS="-o DPkg::Lock::Timeout=60 -o Acquire::Retries=3"
APT_OPTS="$APT_OPTS -o Acquire::http::Timeout=30 -o Acquire::https::Timeout=30"
for attempt in 1 2 3; do
sudo apt-get $APT_OPTS update && break
echo "apt-get update failed (attempt ${attempt}/3), retrying in 5s"
sleep 5
done
sudo apt-get $APT_OPTS install -y --no-install-recommends ffmpeg

- name: Verify ffmpeg installation
run: |
echo "🎬 Verifying ffmpeg installation..."
ffmpeg -version || {
echo "❌ ffmpeg installation failed!"
echo "apt-get install ffmpeg did not produce a working binary."
exit 1
}
echo "✅ ffmpeg installed successfully"

- name: Install dependencies
run: pnpm install

Expand Down
94 changes: 15 additions & 79 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -31,45 +31,21 @@ jobs:
cache: "pnpm"
registry-url: https://registry.npmjs.org/

# Installed from the runner's package index rather than a third-party
# action that downloads release assets from another repository. That
# action broke this workflow twice — first a corrupt 8.1 asset, then
# the 7.1 pin added to work around it — and because this is the
# publish workflow, each break silently stopped releases from going
# out while CI still looked healthy. ci.yml was moved off it already.
- name: Install ffmpeg
timeout-minutes: 15
run: |
if command -v ffmpeg >/dev/null 2>&1; then
echo "ffmpeg already present: $(ffmpeg -version | head -1)"
exit 0
fi
export DEBIAN_FRONTEND=noninteractive
# Runners boot with unattended-upgrades holding the dpkg lock, and a
# plain apt-get waits on that lock forever. On 2026-08-18 this step
# sat in_progress for 90 minutes on two open PRs, leaving the quality
# gate permanently "pending" with nothing to re-run against. Bound
# every wait so a contended lock fails fast, and let the step
# deadline catch anything the bounds miss.
sudo systemctl stop unattended-upgrades.service >/dev/null 2>&1 || true
APT_OPTS="-o DPkg::Lock::Timeout=60 -o Acquire::Retries=3"
APT_OPTS="$APT_OPTS -o Acquire::http::Timeout=30 -o Acquire::https::Timeout=30"
for attempt in 1 2 3; do
sudo apt-get $APT_OPTS update && break
echo "apt-get update failed (attempt ${attempt}/3), retrying in 5s"
sleep 5
done
sudo apt-get $APT_OPTS install -y --no-install-recommends ffmpeg

- name: Verify ffmpeg installation
run: |
echo "🎬 Verifying ffmpeg installation..."
ffmpeg -version || {
echo "❌ ffmpeg installation failed!"
echo "apt-get install ffmpeg did not produce a working binary."
exit 1
}
echo "✅ ffmpeg installed successfully"
# ffmpeg is deliberately NOT installed in this workflow. Nothing these

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 MINOR: Remove unnecessary ffmpeg installation from release workflow - Removing ffmpeg from release.yml prevents the same apt lock issues from affecting release pipelines. The release workflow builds and publishes packages - it does not run any media processing suites that would require ffmpeg at runtime. Consistent with ci.yml changes - release jobs don't need ffmpeg and were vulnerable to the same apt lock issues.

# jobs run needs it: no package script invokes it, and src/ shells out to
# ffmpeg only at runtime (frame extraction, video merge, audio playback),
# never during install, lint, typecheck, build or pack. provider-safety-net
# has always built and run its suites without it.
#
# Removed after the apt install broke CI three ways in one day: a corrupt
# published asset, a version pin that stopped resolving, and an Ubuntu
# mirror returning Ign: for every index while apt sat for 14 minutes.
# Because build-check is a required check, each of those blocked every
# open pull request on a dependency none of these jobs use.
Comment on lines +43 to +44

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in #1895: the release.yml comment no longer says build-check gates that workflow; it separates the pull-request blocking in ci.yml from a stall in a release run.

#
# If a job here ever runs a suite that genuinely exercises media, install
# ffmpeg in THAT job only, and bound every wait (DPkg::Lock::Timeout,
# Acquire::*::Timeout) plus a step timeout-minutes.

- name: Install dependencies
run: pnpm i
Expand Down Expand Up @@ -107,46 +83,6 @@ jobs:
registry-url: "https://registry.npmjs.org"
cache: "pnpm"

# Installed from the runner's package index rather than a third-party
# action that downloads release assets from another repository. That
# action broke this workflow twice — first a corrupt 8.1 asset, then
# the 7.1 pin added to work around it — and because this is the
# publish workflow, each break silently stopped releases from going
# out while CI still looked healthy. ci.yml was moved off it already.
- name: Install ffmpeg
timeout-minutes: 15
run: |
if command -v ffmpeg >/dev/null 2>&1; then
echo "ffmpeg already present: $(ffmpeg -version | head -1)"
exit 0
fi
export DEBIAN_FRONTEND=noninteractive
# Runners boot with unattended-upgrades holding the dpkg lock, and a
# plain apt-get waits on that lock forever. On 2026-08-18 this step
# sat in_progress for 90 minutes on two open PRs, leaving the quality
# gate permanently "pending" with nothing to re-run against. Bound
# every wait so a contended lock fails fast, and let the step
# deadline catch anything the bounds miss.
sudo systemctl stop unattended-upgrades.service >/dev/null 2>&1 || true
APT_OPTS="-o DPkg::Lock::Timeout=60 -o Acquire::Retries=3"
APT_OPTS="$APT_OPTS -o Acquire::http::Timeout=30 -o Acquire::https::Timeout=30"
for attempt in 1 2 3; do
sudo apt-get $APT_OPTS update && break
echo "apt-get update failed (attempt ${attempt}/3), retrying in 5s"
sleep 5
done
sudo apt-get $APT_OPTS install -y --no-install-recommends ffmpeg

- name: Verify ffmpeg installation
run: |
echo "🎬 Verifying ffmpeg installation..."
ffmpeg -version || {
echo "❌ ffmpeg installation failed!"
echo "apt-get install ffmpeg did not produce a working binary."
exit 1
}
echo "✅ ffmpeg installed successfully"

- name: Upgrade npm for native OIDC publish support
run: |
npx -y npm@11 install -g npm@11
Expand Down
Loading