Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
44 changes: 44 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -887,11 +887,31 @@ jobs:
fi

- name: Checkout
id: checkout
continue-on-error: true
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
submodules: recursive
persist-credentials: false

# WarpBuild can lose GitHub DNS on an otherwise healthy runner. Retry the
# checkout once only after that action fails; healthy jobs still perform
# one checkout, and a second failure remains a hard failure with evidence.
- name: Retry checkout after transient network failure
id: checkout-retry
if: steps.checkout.outcome == 'failure'
continue-on-error: true
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
submodules: recursive
persist-credentials: false

- name: Diagnose checkout network failure
if: steps.checkout.outcome == 'failure' && steps.checkout-retry.outcome == 'failure'
run: |
scripts/ci/capture-network-diagnostics.sh

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Diagnostics Depend on Checkout

On a fresh runner, a failure while fetching the main repository can leave GITHUB_WORKSPACE without scripts/ci/capture-network-diagnostics.sh. The double-checkout failure step then reports that the script is missing instead of capturing the DNS evidence it was added to collect. The same issue applies to the diagnostic call in macos-compile-admission at line 2496. Make these diagnostics available independently of a successful repository checkout, such as by inlining them in the workflow.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in upstream replacement #13204, commit 6842bd9. Both checkout-failure steps now inline the diagnostic commands and have a one-minute step limit. Regression eb3190a executes both real workflow bodies from empty workspaces: it fails before the fix and passes afterward, including probe errors while retaining the final exit 1. This PR is being superseded because its source repository cannot be changed from teamleaderleo/cmux to manaflow-ai/cmux; the replacement links this review history.

Comment thread
coderabbitai[bot] marked this conversation as resolved.
exit 1

- name: Select Xcode
run: |
set -euo pipefail
Expand Down Expand Up @@ -996,6 +1016,10 @@ jobs:
echo "Resolve succeeded but binary artifacts are missing (stale cache); clearing and retrying" >&2
rm -rf "$SOURCE_PACKAGES_DIR" # whole dir — resolve will not re-materialize artifacts into a partial tree
fi
# Keep the existing three-attempt policy, but record resolver
# state when a package attempt fails so provider incidents are
# distinguishable from SwiftPM or cache defects.
scripts/ci/capture-network-diagnostics.sh || true
if [ "$attempt" -eq 3 ]; then
echo "Failed to resolve Swift packages after 3 attempts" >&2
exit 1
Expand Down Expand Up @@ -2447,11 +2471,31 @@ jobs:
fi

- name: Checkout
id: checkout
continue-on-error: true
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
submodules: recursive
persist-credentials: false

# WarpBuild can lose GitHub DNS on an otherwise healthy runner. Retry the
# checkout once only after that action fails; healthy jobs still perform
# one checkout, and a second failure remains a hard failure with evidence.
- name: Retry checkout after transient network failure
id: checkout-retry
if: steps.checkout.outcome == 'failure'
continue-on-error: true
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
with:
submodules: recursive
persist-credentials: false

- name: Diagnose checkout network failure
if: steps.checkout.outcome == 'failure' && steps.checkout-retry.outcome == 'failure'
run: |
scripts/ci/capture-network-diagnostics.sh
exit 1

- name: Prepare isolated admission DerivedData
run: |
set -euo pipefail
Expand Down
22 changes: 22 additions & 0 deletions scripts/ci/capture-network-diagnostics.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
#!/usr/bin/env bash
set -u

# Keep provider/network evidence in the job log without failing the original
# operation. These commands are intentionally read-only and emit no tokens.
echo "== network diagnostics (runner=${RUNNER_NAME:-unknown}) ==" >&2
if command -v scutil >/dev/null 2>&1; then
scutil --dns 2>&1 || true
fi
if command -v route >/dev/null 2>&1; then
route -n get default 2>&1 || true
fi
if command -v ifconfig >/dev/null 2>&1; then
ifconfig 2>&1 || true
fi
if command -v dscacheutil >/dev/null 2>&1; then
dscacheutil -q host -a name github.com 2>&1 || true
fi
if command -v curl >/dev/null 2>&1; then
curl --connect-timeout 5 --max-time 10 --silent --show-error --head https://github.com/ 2>&1 || true
fi
echo "== end network diagnostics ==" >&2
5 changes: 5 additions & 0 deletions scripts/ci/compile-app-host-test-product.sh
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,8 @@
# another layout cannot hit, so it should be a cache miss and not a download.
set -euo pipefail

SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"

usage() {
echo "usage: $0 fingerprint <derived-data>" >&2
echo " $0 resolve <derived-data> <source-packages>" >&2
Expand Down Expand Up @@ -51,6 +53,9 @@ resolve() {
fi
echo "Resolve succeeded but binary artifacts are missing" >&2
fi
# Preserve resolver evidence for transient WarpBuild failures. Diagnostics
# are advisory and never replace the bounded retry below.
"$SCRIPT_DIR/capture-network-diagnostics.sh" || true
[ "$attempt" -lt 3 ] || break
echo "Package resolution failed on attempt $attempt; clearing packages and retrying" >&2
rm -rf "$source_packages"
Expand Down
Loading