fix(ci): retry Nix shell and app dependency preparation - #4066
Conversation
|
Auto-sync is disabled for draft pull requests in this repository. Workflows must be run manually. Contributors can view more details about this message here. |
|
🌿 Preview your docs: https://nvidia-preview-pr-4066.docs.buildwithfern.com/openshell |
|
/ok to test 6c4bb76 |
|
Label |
|
Label |
6c4bb76 to
d1d6d68
Compare
|
/ok to test d1d6d68 |
Signed-off-by: Evan Lezar <elezar@nvidia.com>
Signed-off-by: Evan Lezar <elezar@nvidia.com>
4813a1c to
b1eef1c
Compare
|
The workaround targets a Nix download-resumption edge case: a transfer can report an error after receiving the full payload, then resume at EOF and fail with HTTP 416. Evidence from our CIAll three jobs installed Nix 2.35.2. Each failed on a different
For example, the gettext log records Why Nix's built-in retries do not recoverIn Nix 2.35.2, request setup passes the bytes already streamed directly to A separate local investigation reproduced the edge case on Nix 2.34.6 using an HTTP/1.1 chunked response that sends all 90,112 payload bytes but omits the final chunk. Nix reports a partial transfer, sends The initial CI transport failure remains unconfirmed. Nearby requests fail in bursts with SSL_read/EOF errors, but we do not have evidence assigning the cause to the CDN, runner network, HTTP/2, or libcurl. NixOS/infra #1106 reports the same 416 symptom without an established EOF diagnosis. No upstream Nix issue or released fix specifically for this mechanism has been confirmed; a candidate fix is being investigated separately. Scope of these two commits
Any preparation failure is retried once, and persistent failures still fail CI. Cargo, checks, tests, and artifact-generation runtime failures are not retried. Downloads initiated inside an app remain outside this preparation workaround. |
|
/ok-to-test b1eef1c |
Summary
Recover from intermittent Nix cache download failures during CI dependency preparation. A transport error after all payload bytes arrive can cause Nix to resume at EOF, receive HTTP 416, and fail before a check runs. Preparation gets one fresh invocation; checks and apps execute once.
Related Issue
No separate OpenShell issue required: localized CI reliability fix. Related upstream symptom report: NixOS/infra#1106.
Changes
The change is split into two commits:
setup-nix, with opt-inprepare-shelland ashell-installableselector. Enable it for every shell-based workflow, including Cargo Deny, workflow security, Trivy, and VM-driver builds. Remove duplicate preparation fromsetup-rust.nix runsites: integration tests, three artifact-generation apps, and protobuf compatibility. Expose existing artifact and protobuf app derivations as matching package outputs so preparation usesnix build --no-linkbefore executing each app once.Both preparation attempts remain in the normal log. A second failure fails the step. Any preparation failure is retried once; runtime failures from Cargo, lint, tests, artifact generation, and compatibility checks are not retried. Downloads initiated inside an app are outside this preparation retry.
Update CI documentation and the workflow-monitoring skill to reflect this behavior.
Testing
mise run pre-commitpasses for both commits, including installed commit-hook checks.concurrency.queuekeys inpublish-docs-website.ymlandsync-docs.yml.Earlier log evidence motivating the workaround (these jobs tested the previous implementation):
setup-nix.Checklist