Skip to content

ci: bound the Verify proto syntax step so an apt stall fails fast - #168

Merged
dborup merged 1 commit into
masterfrom
codex/issue-156-proto-step-timeout
Oct 2, 2026
Merged

dborup merged 1 commit into
masterfrom
codex/issue-156-proto-step-timeout

Conversation

@dborup

@dborup dborup commented Oct 2, 2026

Copy link
Copy Markdown
Owner

Relates to #156.

Problem

The Verify proto syntax step in Go Build & Test ran apt-get update / install with no timeout. A stalled mirror could hold the runner until the workflow-level limits kicked in (one PR run sat about 45 minutes in this step on 2026-09-30).

Change

Only .github/workflows/deploy.yml, 8 insertions and 2 deletions:

  • timeout-minutes: 5 on the Verify proto syntax step.
  • apt runs with -o Acquire::Retries=3 -o Acquire::http::Timeout=30 on both update and install, plus DEBIAN_FRONTEND=noninteractive.
  • Explicit ::error:: and exit 1 if protoc is missing after the install.
  • timeout-minutes: 40 on the go-test job.

The loop that runs protoc over every proto/*.proto is unchanged. Triggers, permissions, other jobs, concurrency and fork guards are untouched.

Job timeout rationale

Go Build & Test took 15.8 to 21.9 minutes (median about 20.7) over the last 12 completed runs. 40 minutes is roughly 1.8x the slowest observed run, so ordinary variance will not trip it, and it is far below the 6 hour GitHub default. The 5 minute step timeout is what actually bounds the apt hang. The proto step itself took 9 to 19 seconds in those runs.

Alternative considered

Download a pinned protoc release and check its sha256. That removes apt entirely and is cacheable, but it adds a version and checksum to maintain and a new download dependency. Bounded apt with retries plus a step timeout meets the acceptance criteria with the smallest diff, so I chose that.

Verification

  • Workflow YAML parses (python3 yaml). actionlint is not installed locally.
  • Fork guard count github.repository == 'Kpa-clawbot/CoreScope' is 9 before and after, and the diff of the guard lines is empty.
  • The step's shell logic was run locally with the sudo apt-get lines removed: all proto/*.proto validate and exit is 0.
  • A copy of proto/ with an invalid .proto added makes the step exit 1 with the protoc error.
  • With protoc off PATH the step exits 1 with protoc not found after install.

Not verified

A real apt hang cannot be provoked in CI, so the fail-fast behaviour on a genuine stall is reasoned from the timeouts, not observed.

🤖 Generated with Claude Code

Relates to #156. The step ran apt-get update/install with no timeout, so a
stalled mirror held the runner (one PR run sat ~45 min on 2026-09-30).

- timeout-minutes: 5 on the step
- apt: Acquire::Retries=3 and Acquire::http::Timeout=30 on update and install,
  DEBIAN_FRONTEND=noninteractive
- explicit error if protoc is missing after install
- timeout-minutes: 40 on the "Go Build & Test" job (normal 16-22 min)
@dborup
dborup marked this pull request as ready for review October 2, 2026 15:44
@dborup
dborup merged commit 84c637e into master Oct 2, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant