Skip to content

CI: install apt packages from ghcr .deb bundles - #1293

Open
ejohnstown wants to merge 4 commits into
wolfSSL:masterfrom
ejohnstown:ci-apt-retry
Open

ejohnstown wants to merge 4 commits into
wolfSSL:masterfrom
ejohnstown:ci-apt-retry

Conversation

@ejohnstown

@ejohnstown ejohnstown commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Keep CI package installs off the Ubuntu mirror. A daily job on master publishes the workflows' apt packages as .deb bundles on ghcr, ported from wolfSSL's install-apt-deps; jobs install from them offline and fall back to the mirror.

  • apt-get retries dropped downloads, and install steps fit their job timeouts
  • new ci-deps-image workflow and install-apt-deps action; every install step uses the action

After merge and the first ci-deps-image run, an org admin must make the wolfssh-ci-debs package public once. Until then every job, including this PR's CI, takes the mirror fallback.

Copilot AI balanced review requested due to automatic review settings October 1, 2026 18:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Both FatFS install deadlines exceed the enclosing job timeout and therefore cannot provide the intended step-level failure reporting.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Improves CI resilience against flaky Ubuntu package mirrors and stalled installations.

Changes:

  • Adds three retries to apt-get operations.
  • Adds time limits to package-install steps.
  • Separates inline expect and valgrind installation from test execution.
File Description
.github/​workflows/​x509-interop.yml Hardens build and test dependency installation.
.github/​workflows/​windows-cert-store-test.yml Hardens MinGW toolchain installation.
.github/​workflows/​tpm-ssh.yml Hardens TPM dependency installation.
.github/​workflows/​test-fatfs.yml Hardens FatFS dependencies, but adds ineffective step timeouts.
.github/​workflows/​sshd-test.yml Separates and hardens Valgrind installation.
.github/​workflows/​sftp-test.yml Separates and hardens Expect installation.
.github/​workflows/​paramiko-sftp-test.yml Hardens Paramiko test dependencies.
.github/​workflows/​network-contention-test.yml Hardens Expect installation.
.github/​workflows/​multi-compiler.yml Hardens compiler installation.
.github/​workflows/​cppcheck.yml Updates package metadata and installs cppcheck noninteractively.
.github/​workflows/​code-coverage.yml Hardens Clang and LLVM installation.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/test-fatfs.yml Outdated
Every workflow that installs packages now passes Acquire::Retries=3
to apt-get, and each install step gets its own timeout, sized to fit
inside its job's limit, so a stalled mirror fails fast under a step
name that says what went wrong.

- cppcheck runs apt-get update before installing, and installs with -y
- sftp-test and sshd-test move their inline installs into their own
  steps
- test-fatfs job timeout goes from 4 to 10 minutes to hold its installs
Port wolfSSL's install-apt-deps action and ci-deps-image workflow. A
daily job on master downloads each package list's .debs and publishes
them as ghcr.io/wolfssl/wolfssh-ci-debs; the workflows install from
that bundle offline and fall back to the mirror with bounded retries.

- two bundles: ubuntu-24.04-tests and ubuntu-24.04-compilers
- every apt-get install step in the workflows now uses the action
- the package must be made public once after the first build; until
  then every job takes the mirror fallback
- sshd-test job timeout goes from 10 to 15 minutes to fit the install
@ejohnstown ejohnstown changed the title CI: retry apt-get and time-limit install steps CI: install apt packages from ghcr .deb bundles Oct 1, 2026
download-deb-closure.sh runs as root, so a debs directory it creates is
root-owned and the unprivileged index step cannot write Packages into
it. Create the directory as the runner user first; the script then
chowns the .debs to match.
The sshd-test valgrind install pulled 27 MB with gdb and libc6-dbg,
which a slow mirror could not deliver inside the 180s fallback budget.
Skip the recommends and give the fallback 300s, which still fits the
15-minute job.
@philljj philljj self-assigned this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants