fix(update): retry bootstrap downloads with safe diagnostics - #3991
Conversation
Signed-off-by: huangruiteng <huangrt01@163.com>
|
Self-review of b1839b8: no blocking findings. The changed surfaces are archive bootstrap execution, its plan/diagnostic rendering, focused regression coverage and operator documentation. Risk-based premerge validation: 46 update/download/activation/install-freshness/release tests passed, update smoke passed, new files passed Ruff, touched files passed syntax lint, and the public-boundary scan passed. The single skipped test is Windows-only on macOS; Windows CI remains part of the PR checks. Existing whole-file lint findings outside this change were not broadened into cleanup. A real GitHub Pages bootstrap download returned HTTP 200 and a complete shell script; execution was intercepted, so that probe performed no installation. No manual holds; merge remains contingent on inspection of CI results. Scope limit: retries apply only to the initial bootstrap download, not the bootstrap script's subsequent archive/API requests. This is sufficient for the reproduced failure without introducing a new generic network client or retrying partially applied installations. |
Archive updates stopped on a transient installer-download error with only a curl message. They now retry selected HTTP/network failures up to three times, download into a private temporary file, and execute only a complete successful response. JSON and text reports expose the attempt HTTP status and curl return code without recording response bodies, headers, URLs or raw curl errors.
The download has a 60-second budget capped by the command timeout; installer execution shares the remaining command budget and is never retried. Plan previews use the managed apply command. This affects archive bootstrap downloads only; pip/pipx, read-only checks and later archive transfers retain their existing behavior.
Validation: 46 focused update/download/activation/install-freshness/release tests passed; one Windows-only test skipped on macOS. The update smoke, new-module Ruff checks, changed-file syntax lint and public-boundary scan passed. Coverage includes transient 403 recovery, permanent HTTP failures, partial-body rejection, timeout budgets, redaction and no installer replay. No credentials or private runtime evidence are included.