Skip to content

ci(reborn): retry crates.io network failures in the closure (CARGO_NET_RETRY) - #5115

Merged
serrrfirat merged 1 commit into
mainfrom
firat/ci-cargo-net-retry
Jun 21, 2026
Merged

serrrfirat merged 1 commit into
mainfrom
firat/ci-cargo-net-retry

Conversation

@serrrfirat

Copy link
Copy Markdown
Collaborator

Problem

The 64-crate closure (#5110) runs ~64 jobs that each resolve+download the dependency tree from crates.io in parallel. A transient registry SSL/HTTP2 hiccup hits many jobs at once and reddens the whole run — seen twice already:

  • download of once_cell_polyfill failed (HTTP2 framing)
  • agent-client-protocol ... curl [55] OpenSSL SSL_ERROR_SYSCALL (61 jobs red in one run)

Neither is a code failure — they pass on re-run.

Fix

Add to reborn-tests.yml env:

  • CARGO_NET_RETRY: "10" — Cargo retries network failures (default 3) far more aggressively, so transient download errors self-heal within the job.
  • CARGO_NET_GIT_FETCH_WITH_CLI: "true" — use the git CLI for git deps (more robust than libgit2 under flaky networks).

2-line env change, applies to all reborn-tests jobs. Zero behavior change otherwise.

Follow-up (not this PR)

The real scaling fix is build-once cargo nextest archive → shard the run, which eliminates the 64× parallel dependency resolution entirely. Tracked for the bake phase.

Automated agent-authored.

…T_RETRY)

The 64-crate closure runs ~64 jobs that each resolve+download the
dependency tree from crates.io in parallel. A transient registry hiccup
(seen twice: 'download of once_cell_polyfill failed' HTTP2 framing, and
'agent-client-protocol ... curl [55] SSL_ERROR_SYSCALL') hits many jobs
at once and reddens the whole run even though nothing is wrong with the
code. Bump Cargo's network retry from the default 3 to 10 and fetch git
deps via the git CLI, so transient download failures self-heal instead
of failing the job. The heavier fix (build-once `nextest archive` +
shard the run, eliminating 64x dependency resolution) remains a separate
follow-up.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5115 June 21, 2026 20:54 Destroyed
@coderabbitai

coderabbitai Bot commented Jun 21, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 8d8e9896-321f-4c3f-89e0-4807515e4240

📥 Commits

Reviewing files that changed from the base of the PR and between 3b4e1a0 and 759d4e6.

📒 Files selected for processing (1)
  • .github/workflows/reborn-tests.yml

📝 Walkthrough

Summary by CodeRabbit

  • Chores
    • Enhanced test workflow resilience by improving dependency download reliability through increased network retry configuration and Git-based dependency fetching.

Walkthrough

Two environment variables — CARGO_NET_RETRY: "10" and CARGO_NET_GIT_FETCH_WITH_CLI: "true" — are added to the reborn-tests GitHub Actions workflow to reduce transient SSL/HTTP2 failures during Cargo dependency downloads.

Changes

Reborn CI Network Resilience

Layer / File(s) Summary
Cargo network retry env vars
.github/workflows/reborn-tests.yml
Adds CARGO_NET_RETRY: "10" and CARGO_NET_GIT_FETCH_WITH_CLI: "true" to the workflow env block, routing git-based dependency fetches through the system git CLI instead of libcurl.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

Poem

Two env vars, small but sure,
libcurl's woes we now endure less.
Ten retries knock on Cargo's door,
git CLI steps up — no more distress.
The pipeline breathes, the deps restore. 🦀

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning Description lacks required template sections: Change Type checkbox, Linked Issue, Validation checklist, Security Impact, Reborn Trust-Boundary Checklist, Database Impact, Blast Radius, Rollback Plan, Review Follow-Through, and Review track designation. Complete the PR description template: check Change Type (CI/Infrastructure), specify Linked Issue, document validation steps, confirm Security Impact (None), mark N/A for irrelevant security/database sections, describe Blast Radius, state Rollback Plan, and assign Review track (likely Track A).
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed Title follows Conventional Commits style (ci(reborn): ...) and directly describes the main change: enabling Cargo network retries.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@github-actions github-actions Bot added size: XS < 10 changed lines (excluding docs) risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs scope: ci CI/CD workflows labels Jun 21, 2026
@railway-app

railway-app Bot commented Jun 21, 2026

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5115 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jun 21, 2026 at 8:55 pm

@serrrfirat
serrrfirat merged commit b1924ab into main Jun 21, 2026
107 checks passed
@serrrfirat
serrrfirat deleted the firat/ci-cargo-net-retry branch June 21, 2026 21:23
serrrfirat added a commit that referenced this pull request Jun 21, 2026
…r-crate caches (#5118)

The closure's crate-tests matrix used a per-crate cache key
(`reborn-tests-<crate>`), producing ~60 caches that each bundle the
cargo registry + a target dir (~0.4-0.7 GB each), plus 4 per-partition
root caches (~1 GB each). That's ~30+ GB competing for GitHub's ~10 GB
per-repo cache LRU, so the caches evict each other almost as fast as
they're written: a live snapshot showed only 10 of 64 crates had a cache
present, summing to 18 GB and actively evicting. The result is "No cache
found" on most jobs -> the crates.io registry is re-downloaded from cold
every run, and 64 parallel cold downloads amplify transient registry
flakes (the SSL_ERROR_SYSCALL / HTTP2 reds we saw).

Switch both matrices to `shared-key`:
- crate-tests -> `shared-key: reborn-tests-crates` (one entry for all
  crate jobs; the registry + shared-dep build is downloaded/compiled
  once and resident, not ~60x).
- root partitions -> `shared-key: reborn-tests-root` (all 4 partitions
  compile the identical root build, so one cache is strictly better than
  4 copies).

This drops the reborn-tests cache footprint from ~30+ GB / 68 entries to
~2 entries that comfortably fit the LRU, so the registry stays resident
and stops being re-downloaded. Complements CARGO_NET_RETRY (#5115),
which remains the safety net for the now-rare cold download.

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5115 — 759d4e64 Deployed Jun 21, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows size: XS < 10 changed lines (excluding docs)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant