Summary
The "Verify proto syntax" step in the Go Build & Test job can hang for a long time. On 2026-09-30 a PR run (36728235996, attempt 1) sat about 45 minutes in this step after every Go test step had already passed; a rerun went through the step in seconds. The step and its job have no timeout of their own, so a hang holds the runner until the workflow-level limits kick in.
Where (master be35eefb)
.github/workflows/deploy.yml, around lines 251–260:
- name: Verify proto syntax
run: |
set -e
sudo apt-get update -qq
sudo apt-get install -y protobuf-compiler
...
apt-get update / install against the runner's mirrors is the likely place it stalled (network or mirror lock).
Proposed fix
Keep the check, make a stall fail fast instead of hanging:
- add
timeout-minutes: 5 to the step (and consider one on the job);
- give apt network timeouts and retries, e.g.
-o Acquire::Retries=3 -o Acquire::http::Timeout=30, or avoid apt entirely by downloading a pinned protoc release with a checksum (cacheable).
Do not change triggers, permissions, jobs or the fork guards (github.repository == 'Kpa-clawbot/CoreScope').
Acceptance criteria
- A stalled apt/download in this step fails within a few minutes with a clear message instead of hanging.
- The step still validates every
proto/*.proto.
- Fork-guard lines unchanged.
Summary
The "Verify proto syntax" step in the Go Build & Test job can hang for a long time. On 2026-09-30 a PR run (36728235996, attempt 1) sat about 45 minutes in this step after every Go test step had already passed; a rerun went through the step in seconds. The step and its job have no timeout of their own, so a hang holds the runner until the workflow-level limits kick in.
Where (master
be35eefb).github/workflows/deploy.yml, around lines 251–260:apt-get update/installagainst the runner's mirrors is the likely place it stalled (network or mirror lock).Proposed fix
Keep the check, make a stall fail fast instead of hanging:
timeout-minutes: 5to the step (and consider one on the job);-o Acquire::Retries=3 -o Acquire::http::Timeout=30, or avoid apt entirely by downloading a pinnedprotocrelease with a checksum (cacheable).Do not change triggers, permissions, jobs or the fork guards (
github.repository == 'Kpa-clawbot/CoreScope').Acceptance criteria
proto/*.proto.