Skip to content

fix(update): retry bootstrap downloads with safe diagnostics - #3991

Merged
huangruiteng merged 1 commit into
mainfrom
codex/update-download-retry
Sep 6, 2026
Merged

huangruiteng merged 1 commit into
mainfrom
codex/update-download-retry

Conversation

@huangruiteng

Copy link
Copy Markdown
Collaborator

Archive updates stopped on a transient installer-download error with only a curl message. They now retry selected HTTP/network failures up to three times, download into a private temporary file, and execute only a complete successful response. JSON and text reports expose the attempt HTTP status and curl return code without recording response bodies, headers, URLs or raw curl errors.

The download has a 60-second budget capped by the command timeout; installer execution shares the remaining command budget and is never retried. Plan previews use the managed apply command. This affects archive bootstrap downloads only; pip/pipx, read-only checks and later archive transfers retain their existing behavior.

Validation: 46 focused update/download/activation/install-freshness/release tests passed; one Windows-only test skipped on macOS. The update smoke, new-module Ruff checks, changed-file syntax lint and public-boundary scan passed. Coverage includes transient 403 recovery, permanent HTTP failures, partial-body rejection, timeout budgets, redaction and no installer replay. No credentials or private runtime evidence are included.

Signed-off-by: huangruiteng <huangrt01@163.com>
@huangruiteng

Copy link
Copy Markdown
Collaborator Author

Self-review of b1839b8: no blocking findings.

The changed surfaces are archive bootstrap execution, its plan/diagnostic rendering, focused regression coverage and operator documentation. run_archive_installer truncates the private temporary file between attempts, admits execution only after a successful nonempty 2xx transfer, shares the command budget, and never retries the installer. Failure diagnostics contain only stage, attempt, HTTP status and curl exit code. _command_for_source reuses the existing action-command builder so previewed commands take the same path. Package-manager and read-only paths retain their existing call contracts.

Risk-based premerge validation: 46 update/download/activation/install-freshness/release tests passed, update smoke passed, new files passed Ruff, touched files passed syntax lint, and the public-boundary scan passed. The single skipped test is Windows-only on macOS; Windows CI remains part of the PR checks. Existing whole-file lint findings outside this change were not broadened into cleanup. A real GitHub Pages bootstrap download returned HTTP 200 and a complete shell script; execution was intercepted, so that probe performed no installation. No manual holds; merge remains contingent on inspection of CI results.

Scope limit: retries apply only to the initial bootstrap download, not the bootstrap script's subsequent archive/API requests. This is sufficient for the reproduced failure without introducing a new generic network client or retrying partially applied installations.

@huangruiteng
huangruiteng merged commit 8fe34c5 into main Sep 6, 2026
11 checks passed
@huangruiteng
huangruiteng deleted the codex/update-download-retry branch September 6, 2026 06:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant