From 342debaefa86a3b8e88024c70e272f38ace6582a Mon Sep 17 00:00:00 2001 From: Jared Knowles Date: Tue, 4 Aug 2026 11:57:49 -0400 Subject: [PATCH 1/2] ci: fetch apt indexes over HTTPS so the install step stops hanging The "Install system libraries" step was stalling indefinitely. It was not deadlocked on a config prompt and not slow-but-progressing: measured inside the live runner container, /var/cache/apt/archives stayed at 0 .deb files after 3+ minutes, with apt's http workers parked in S state waiting on the network. Root cause is the http:// mirror path being pathologically slow from this runner, not broken. Measured 2026-08-04 from inside the CI container, same index file, back to back: http://archive.ubuntu.com/ubuntu/dists/noble/Release 20.1s https://archive.ubuntu.com/ubuntu/dists/noble/Release 3.1s apt fetches many indexes serially, so ~20s apiece compounds into what looks like a hang. Rewriting the deb822 sources to https makes the step complete. Verified before committing, in the running CI container (rocker/r-ver:4.4): - ca-certificates present and apt 2.8.3 ships the https method built in, so nothing has to be installed over http first to bootstrap TLS - the sed rewrites both URIs (archive + security); the only remaining http:// is an inert comment line - '#' is used as the sed delimiter deliberately: '|' collides with the alternation and fails with "unknown option to `s'" - the regex survives YAML block-scalar parsing with backslashes intact `|| true` guards each sed because the step runs under `sh -e`, so a missing-sources-file on some other base image must not kill the job. --- .gitea/workflows/ci.yml | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 7b36f99..4b02e93 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -11,6 +11,21 @@ jobs: steps: - name: Install system libraries and Node.js (required by actions/checkout) run: | + # Switch apt to HTTPS mirrors. Measured from this runner on + # 2026-08-04: the SAME index file takes 20.1s over http:// and 3.1s + # over https://. apt fetches many indexes serially, so http:// does + # not read as "slow" -- it reads as a hang (zero bytes in + # /var/cache/apt/archives after 3+ minutes, apt's http workers parked + # in S state). rocker/r-ver:4.4 already ships ca-certificates and + # apt 2.8.3 has the https method built in, so nothing needs to be + # installed over http first to bootstrap this. + # `|| true` because the step runs under `sh -e`: on an image whose + # sources live in the other location, the missing-file sed must not + # kill the job. + sed -i -E 's#http://(archive|security)\.ubuntu\.com#https://\1.ubuntu.com#g' \ + /etc/apt/sources.list.d/ubuntu.sources 2>/dev/null || true + sed -i -E 's#http://(archive|security)\.ubuntu\.com#https://\1.ubuntu.com#g' \ + /etc/apt/sources.list 2>/dev/null || true apt-get update -qq apt-get install -y --no-install-recommends \ nodejs git \ -- 2.54.0 From e067a5930ffb4eefbf5aaa1bafb5ef14e5e454f7 Mon Sep 17 00:00:00 2001 From: Jared Knowles Date: Tue, 4 Aug 2026 12:07:59 -0400 Subject: [PATCH 2/2] test: accept schema_version 7, and keep the upper bound enforced The merged schema-v7 fix (b59b79b) widened .validate_schema()'s allow-list but left this test asserting that 7 is REJECTED, so main went red. CI had been hanging on the apt step before ever reaching the suite, which is why the failure only surfaced once the HTTPS fix let the job get that far. Flips 7L from expect_error to expect_silent, and ADDS an 8L rejection case. That second part is the point: simply deleting the 7L expectation would have left the test unable to prove any upper bound is enforced at all, so a future v8 corpus with a genuinely breaking change would pass validation silently. The test should assert the boundary moved, not that it disappeared. Suite: 796 PASS, 0 FAIL, 0 WARN, 0 SKIP. --- tests/testthat/test-manifest.R | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/tests/testthat/test-manifest.R b/tests/testthat/test-manifest.R index 318f5a3..31c9462 100644 --- a/tests/testthat/test-manifest.R +++ b/tests/testthat/test-manifest.R @@ -111,7 +111,7 @@ test_that("cog_manifest returns the active session's parsed manifest", { }) }) -test_that(".validate_schema accepts schema_version 4, 5 and 6, rejects others", { +test_that(".validate_schema accepts schema_version 4 through 7, rejects others", { expect_silent(uscogdata:::.validate_schema(list(schema_version = 4L))) expect_silent(uscogdata:::.validate_schema(list(schema_version = 5L))) # v6 = FIPS geography harmonization (2026-07-22): _code -> _asof rename + @@ -119,12 +119,22 @@ test_that(".validate_schema accepts schema_version 4, 5 and 6, rejects others", # renamed columns and its geography comes from the xwalk, so v6 is accepted # without behavioural change -- see .validate_schema()'s note. expect_silent(uscogdata:::.validate_schema(list(schema_version = 6L))) + # v7 = `data_year` APPENDED as column 29 (cog_pipeline #80, 2026-08-03), the + # most recent fiscal year contributing to a collapsed key. Appended, never + # inserted: canonical_govid stays at position 26, so nothing this package + # reads shifts. Verified against the real v7 corpus before widening the + # allow-list -- cog_spending()/cog_balances() return correctly for FY2024 AND + # for FY2012, so the new column is inert here. + expect_silent(uscogdata:::.validate_schema(list(schema_version = 7L))) expect_error( uscogdata:::.validate_schema(list(schema_version = 3L)), "schema_version" ) + # The upper bound still has to be ENFORCED, not just moved. Without this the + # test would no longer prove that an unknown future schema is refused, and a + # v8 corpus with a genuinely breaking change would sail through. expect_error( - uscogdata:::.validate_schema(list(schema_version = 7L)), + uscogdata:::.validate_schema(list(schema_version = 8L)), "schema_version" ) }) -- 2.54.0