From 2bce7ef8b915e3cbafd3e9d4b5619b929f76ae7a Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Sat, 19 Sep 2026 08:47:30 +0000 Subject: [PATCH] =?UTF-8?q?fix(ci):=20correct=20the=20rebar3=20guidance=20?= =?UTF-8?q?=E2=80=94=20a=20pin=20cannot=20bypass=20the=20builds.hex.pm=20c?= =?UTF-8?q?ert=20error?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The previous change in this area (and the state it replaced) both assumed the `rebar3-version` input could steer setup-beam away from `mix local.rebar`, and that the builds.hex.pm cert error it was added for had gone away. Neither holds, and the assumption cost bofig three months of red CI. Measured facts, 2026-09-19, same host, same action pin, same day: * setup-beam runs `mix local.rebar --force` whenever `install-rebar` is true (the default), BEFORE it considers `rebar3-version`. So the pin cannot bypass that call — it is gated only by `install-rebar`, an input this reusable does not expose. * the cert error is live, not historical. builds.hex.pm serves a Let's Encrypt chain (`YR1` intermediate) that older Erlang/OTP builds reject with `key_usage_mismatch` / `unsupported_certificate`. * it is OTP-build-specific: OTP 27.3.4.17 (erts-15.2.7.13) fetches from that host successfully; OTP 27.2.1 (erts-15.2.1) fails. chimichanga passes on the former while bofig failed on the latter, in the same hour. * bofig's failures began 2026-06-22, two days BEFORE its rebar3 pin existed, with the identical error — so the pin neither caused nor fixed them. - correct the `rebar3-version` description: it installs rebar3 from GitHub releases and does not replace `mix local.rebar`; pass `github-token` when set - replace the catalog note with the measured account and the actual remedy (bump `otp-version` to a current patch; or `install-rebar: false` to skip the call), including the ordering detail that makes the pin useless as a workaround --- .github/workflows/elixir-ci-reusable.yml | 16 ++++++------- CICD-WORKFLOW-CATALOG.md | 29 ++++++++++++++++-------- 2 files changed, 27 insertions(+), 18 deletions(-) diff --git a/.github/workflows/elixir-ci-reusable.yml b/.github/workflows/elixir-ci-reusable.yml index 71191d7ed..de04c11ce 100644 --- a/.github/workflows/elixir-ci-reusable.yml +++ b/.github/workflows/elixir-ci-reusable.yml @@ -76,15 +76,13 @@ on: default: "1.17" rebar3-version: description: >- - rebar3 version for erlef/setup-beam. ONLY set this when a dependency - is rebar-based; `mix` installs the rebar3 it needs on demand, so most - Elixir repos should leave this empty. Setting it makes setup-beam - resolve the version against api.github.com and download the binary - from GitHub releases instead of using `mix local.rebar` — so it - REQUIRES `github-token`, because those API calls are unauthenticated - otherwise and are rate-limited on the shared GitHub-hosted runner - ranges (observed: the setup step fails within ~5s, before any - dependency work). Empty = do not install rebar3 explicitly. + rebar3 version for erlef/setup-beam. ONLY set this when a dependency is + rebar-based; `mix` installs the rebar it needs on demand, so most Elixir + repos should leave this empty. Setting it installs rebar3 from GitHub + releases, resolved through api.github.com — pass `github-token` as well + so those lookups are authenticated. NOTE: this does NOT replace the + `mix local.rebar` call setup-beam makes when `install-rebar` is true + (the default); that runs first and is gated only by that input. type: string required: false default: "" diff --git a/CICD-WORKFLOW-CATALOG.md b/CICD-WORKFLOW-CATALOG.md index 7fd3b34b7..46ab558a1 100644 --- a/CICD-WORKFLOW-CATALOG.md +++ b/CICD-WORKFLOW-CATALOG.md @@ -122,15 +122,26 @@ These workflows only run when manually triggered. | `elixir-ci-reusable.yml` | Reusable Elixir CI | standards | Yes | | `echidna-verify.yml` | ECHIDNA trust-pipeline proof verification (Agda/Idris2). NOT the smart-contract fuzzer. Corpora are evicted to their own repos; surviving jobs (`agda-lol`, `idris2-avow`) open with a presence Guard and pass green-but-honest ("Nothing to type-check") until a corpus returns (#748/#828). The `idris2-a2ml` job is EVICTED as of 2026-09-17: the a2ml project is officially retired (owner ruling), so dormancy was moot — no ruleset pinned its check context (verified live: org ruleset Optimus-Branch #23359343). | standards | Yes | -**Elixir note — `rebar3-version` is a trap unless you need it.** Leave it empty: `mix` -installs the rebar3 it needs on demand, and only a rebar-based dependency justifies pinning it. -Setting it makes `erlef/setup-beam` resolve the version through **unauthenticated** `api.github.com` -calls, which are rate-limited on the shared GitHub-hosted runner ranges — the setup step then fails -within seconds, before any dependency work (bofig's Elixir CI sat red from 2026-06-24 to 2026-09 for -exactly this). If you genuinely need the pin, pass `github-token` too (the caller's -`secrets.GITHUB_TOKEN`); the reusable now warns when you set one without the other. The original -motivation for this input — a builds.hex.pm TLS `key_usage_mismatch` — **no longer applies**: that -host's chain was verified clean on 2026-09-18. +**Elixir note — `mix local.rebar` fails against builds.hex.pm on older OTP builds.** Erlang/OTP +rejects that host's current Let's Encrypt chain (`key_usage_mismatch` on the `YR1` intermediate), so +`erlef/setup-beam` dies in the setup step within seconds: + + ** (Mix) httpc request failed with: {:failed_connect, [{:to_address, {~c"builds.hex.pm", 443}}, + {:inet, [:inet], {:tls_alert, {:unsupported_certificate, ... {key_usage_mismatch, ...}}}}}]} + Could not install Rebar because Mix could not download metadata at + https://builds.hex.pm/installs/rebar3-1.x.csv. + +It is **version-specific and fixed upstream**: on the same day, against the same host and the same +action pin, OTP 27.3.4.17 (erts-15.2.7.13) succeeds where 27.2.1 (erts-15.2.1) fails — measured +2026-09-19 (chimichanga passing, bofig failing). **Bump `otp-version` to a current patch release**; +the pinned OTP build is the cause, not the environment. + +Passing `rebar3-version` does **not** avoid this: setup-beam runs `mix local.rebar` *before* it +considers that input, gated only by `install-rebar` (default true) — so a rebar3 pin cannot bypass the +cert error, and bofig spent three months red because it assumed otherwise. To skip the call itself, +set `install-rebar: false` (and `install-hex: false` if Hex is not needed from hex.pm). If you do set +`rebar3-version`, pass `github-token` too — the version lookup otherwise hits api.github.com +unauthenticated. ### Julia | Workflow | Description | Source | Reusable? |