ci: retry the keyserver import in the coverage step - #2498
Merged
Merged
Conversation
The coverage step imports the codecov uploader signing key from keyserver.ubuntu.com, and that connection has been failing intermittently with connect timeouts, which fails the whole upload on otherwise green legs. Retry the import five times with a short pause, and keep failing the step when every attempt is unsuccessful so the signature verification chain is never skipped.
Contributor
Author
|
@ni4 One more small CI change for your queue when time allows: the coverage step now retries the keyserver.ubuntu.com key import instead of failing the leg on the intermittent connect timeouts seen today on #2491, #2492 and #2493. The gpgv and SHA256SUM verification of the uploader is untouched. Thank you. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2498 +/- ##
=======================================
Coverage 85.45% 85.45%
=======================================
Files 125 125
Lines 23042 23042
=======================================
Hits 19691 19691
Misses 3351 3351 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request makes the coverage step tolerate the intermittent keyserver outages that have been failing otherwise green jobs.
The coverage step imports the codecov uploader signing key from keyserver.ubuntu.com before verifying and running the uploader. Today the connection to the keyserver timed out on four coverage legs across pull requests #2491, #2492 and #2493, and each timeout failed the whole upload even though the build and the full test suite had already passed. The failure looks like
curl: (7) Failed to connect to keyserver.ubuntu.com port 443: Connection timed out, and gpg then exits with an error on the empty input.The change retries the import up to five times with a pause of ten seconds between attempts, and the step still fails when every attempt is unsuccessful, so the signature verification chain is never skipped. The verification of the uploader itself through gpgv and the SHA256SUM check is unchanged.
This is a CI and process change, so @ni4 a review from you is kindly requested whenever your time allows. Thank you.