From 342debaefa86a3b8e88024c70e272f38ace6582a Mon Sep 17 00:00:00 2001 From: Jared Knowles Date: Tue, 4 Aug 2026 11:57:49 -0400 Subject: [PATCH] ci: fetch apt indexes over HTTPS so the install step stops hanging The "Install system libraries" step was stalling indefinitely. It was not deadlocked on a config prompt and not slow-but-progressing: measured inside the live runner container, /var/cache/apt/archives stayed at 0 .deb files after 3+ minutes, with apt's http workers parked in S state waiting on the network. Root cause is the http:// mirror path being pathologically slow from this runner, not broken. Measured 2026-08-04 from inside the CI container, same index file, back to back: http://archive.ubuntu.com/ubuntu/dists/noble/Release 20.1s https://archive.ubuntu.com/ubuntu/dists/noble/Release 3.1s apt fetches many indexes serially, so ~20s apiece compounds into what looks like a hang. Rewriting the deb822 sources to https makes the step complete. Verified before committing, in the running CI container (rocker/r-ver:4.4): - ca-certificates present and apt 2.8.3 ships the https method built in, so nothing has to be installed over http first to bootstrap TLS - the sed rewrites both URIs (archive + security); the only remaining http:// is an inert comment line - '#' is used as the sed delimiter deliberately: '|' collides with the alternation and fails with "unknown option to `s'" - the regex survives YAML block-scalar parsing with backslashes intact `|| true` guards each sed because the step runs under `sh -e`, so a missing-sources-file on some other base image must not kill the job. --- .gitea/workflows/ci.yml | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 7b36f99..4b02e93 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -11,6 +11,21 @@ jobs: steps: - name: Install system libraries and Node.js (required by actions/checkout) run: | + # Switch apt to HTTPS mirrors. Measured from this runner on + # 2026-08-04: the SAME index file takes 20.1s over http:// and 3.1s + # over https://. apt fetches many indexes serially, so http:// does + # not read as "slow" -- it reads as a hang (zero bytes in + # /var/cache/apt/archives after 3+ minutes, apt's http workers parked + # in S state). rocker/r-ver:4.4 already ships ca-certificates and + # apt 2.8.3 has the https method built in, so nothing needs to be + # installed over http first to bootstrap this. + # `|| true` because the step runs under `sh -e`: on an image whose + # sources live in the other location, the missing-file sed must not + # kill the job. + sed -i -E 's#http://(archive|security)\.ubuntu\.com#https://\1.ubuntu.com#g' \ + /etc/apt/sources.list.d/ubuntu.sources 2>/dev/null || true + sed -i -E 's#http://(archive|security)\.ubuntu\.com#https://\1.ubuntu.com#g' \ + /etc/apt/sources.list 2>/dev/null || true apt-get update -qq apt-get install -y --no-install-recommends \ nodejs git \