Skip to content

ci: retry the keyserver import in the coverage step - #2498

Merged
ronaldtse merged 1 commit into
mainfrom
ci-coverage-keyserver-retry
Sep 24, 2026
Merged

ronaldtse merged 1 commit into
mainfrom
ci-coverage-keyserver-retry

Conversation

@ronaldtse

Copy link
Copy Markdown
Contributor

This pull request makes the coverage step tolerate the intermittent keyserver outages that have been failing otherwise green jobs.

The coverage step imports the codecov uploader signing key from keyserver.ubuntu.com before verifying and running the uploader. Today the connection to the keyserver timed out on four coverage legs across pull requests #2491, #2492 and #2493, and each timeout failed the whole upload even though the build and the full test suite had already passed. The failure looks like curl: (7) Failed to connect to keyserver.ubuntu.com port 443: Connection timed out, and gpg then exits with an error on the empty input.

The change retries the import up to five times with a pause of ten seconds between attempts, and the step still fails when every attempt is unsuccessful, so the signature verification chain is never skipped. The verification of the uploader itself through gpgv and the SHA256SUM check is unchanged.

This is a CI and process change, so @ni4 a review from you is kindly requested whenever your time allows. Thank you.

The coverage step imports the codecov uploader signing key from
keyserver.ubuntu.com, and that connection has been failing
intermittently with connect timeouts, which fails the whole upload on
otherwise green legs. Retry the import five times with a short pause,
and keep failing the step when every attempt is unsuccessful so the
signature verification chain is never skipped.
@ronaldtse

Copy link
Copy Markdown
Contributor Author

@ni4 One more small CI change for your queue when time allows: the coverage step now retries the keyserver.ubuntu.com key import instead of failing the leg on the intermittent connect timeouts seen today on #2491, #2492 and #2493. The gpgv and SHA256SUM verification of the uploader is untouched. Thank you.

@codecov

codecov Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.45%. Comparing base (26482f6) to head (29a0013).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #2498   +/-   ##
=======================================
  Coverage   85.45%   85.45%           
=======================================
  Files         125      125           
  Lines       23042    23042           
=======================================
  Hits        19691    19691           
  Misses       3351     3351           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@ni4 ni4 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@ronaldtse
ronaldtse merged commit 9c2a40d into main Sep 24, 2026
132 of 133 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants