Skip to content

Retry transient pinned inklecate downloads without weakening verification #160

Description

@chaoz23

Problem

A macOS CI job on PR #159 failed four compile-dependent tests because the first-use download of the pinned official inklecate archive raised TypeError: fetch failed. The duplicate workflow run passed unchanged. A transient network failure currently aborts CLI bootstrap and can make cross-platform CI flaky even though SHA-256 verification is correct.

Product contract

First-use compiler bootstrap may retry transient transport/server failures a small bounded number of times. It must never retry or accept a SHA-256 mismatch, never fall back to an unpinned version, and never leave a partial archive or executable that a later invocation trusts.

Acceptance criteria

  • Retry only transient fetch failures and retryable HTTP statuses with a documented small attempt cap and bounded backoff.
  • Fail immediately on SHA-256 mismatch and non-retryable client responses.
  • Download to a unique temporary file and atomically publish only the verified extracted compiler.
  • Concurrent first runs cannot consume each other's partial archive or executable.
  • Clean temporary files after success and terminal failure.
  • Deterministic tests cover transient recovery, exhausted attempts, checksum mismatch, and concurrent/bootstrap cleanup without live network access.
  • CI can prewarm/cache the verified compiler without bypassing the same verification contract.

Evidence

PR #159 run 29435672342, macOS job 87421594865: downloadInklecate failed at fetch; the duplicate macOS job passed all 214 tests unchanged.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions