ci: stabilize v5 compatibility tests and macOS patch host resolution - #295
Mikola Lysenko (mikolalysenko) merged 4 commits into
Conversation
The Bun, vlt and Poetry compatibility workflows drive real package managers
against the production patch service. On GitHub's hosted macOS runners the
system resolver intermittently answers patch.socket.dev with EAI_NONAME
("[Errno 8] nodename nor servname provided"; bun: FailedToOpenSocket; Bun
1.3.x workspace installs never exit) for minutes at a time, at job start or
mid-job, while the service is up: ubuntu and windows legs of the same run
pass, and the same macOS cells pass before and after the window. Over the
last 60 Bun runs (69 attempts) 29 macOS native jobs failed this way and no
other OS did; the CLI's own API calls in those cells succeeded.
A pre-flight wait cannot cover a mid-job window, and the failing processes
are bun / vlt / poetry / python rather than the CLI, so a product retry
cannot help. The runner's resolver is not under test, so take it out of the
path: .github/actions/pin-socket-hosts runs scripts/pin-socket-hosts.py on
macOS, which resolves patch.socket.dev and patches-api.socket.dev (system
resolver, then DNS-over-HTTPS by IP literal, with bounded backoff), keeps
only addresses whose TLS handshake verifies the hostname, and pins them in
/etc/hosts. Every cell still hits production over TLS verified for the
hostname, so the captures depscan imports stay production captures.
Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
|
#279 landed on release/v5-prerelease as f6bdad5; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
|
#282 landed on release/v5-prerelease as 14a9cb0; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
|
#291 landed on release/v5-prerelease as f9cb7e1; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
|
#292 landed on release/v5-prerelease as a7b0d00; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
|
#296 landed on release/v5-prerelease as 1e3ace6; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
|
#293 landed on release/v5-prerelease as b9e106d; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
|
#294 landed on release/v5-prerelease as 180f10f; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
…x/pr295-ci # Conflicts: # docs/testing/vlt-compatibility.md
909c08c
into
release/v5-prerelease
Problem
GitHub-hosted macOS runners intermittently fail to resolve
patch.socket.devfor minutes, including midway through the Bun, vlt, and Poetry compatibility jobs. Package-manager tarball downloads fail even when the production service and the CLI's API calls are healthy.The historical compatibility matrix also had deterministic fixture failures: Yarn before 1.10 does not write an
integritylock field, and early vlt releases record explicit npmjs URLs that v5's ledger-free upstream restore does not reproduce verbatim.Changes
/etc/hosts. The package managers continue exercising the production service over verified TLS.release/v5-prereleaseand reconcile the compatibility documentation.Validation
check-vlt-legs.py.