Skip to content

compat-check: resolve avocado CLI version once per run, not per leg - #35

Merged
jetm merged 1 commit into
mainfrom
work-stick-2026-09-17/fix-rubikpi3
Sep 22, 2026
Merged

jetm merged 1 commit into
mainfrom
work-stick-2026-09-17/fix-rubikpi3

Conversation

@jetm

@jetm jetm commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

Closes #33

Description

CI job rubikpi3 · rubikpi3 @ 2024/edge fails at the "Install avocado CLI" step with curl: (22) The requested URL returned error: 403. This is not a rubikpi3-specific or content-specific failure - it's a GitHub API rate limit.

setup-avocado-cli@v1 resolves version: latest by curling https://api.github.com/repos/avocado-linux/avocado-cli/releases/latest unauthenticated (60 requests/hour, shared across every GitHub Actions customer on the runner's IP pool). compat-check.yml fans out to roughly 90 matrix legs, each independently making that same unauthenticated call in its own "Install avocado CLI" step. Any leg can lose that race; this run it was rubikpi3.

Acceptance criteria

  • The avocado CLI version is resolved once per workflow run, not once per matrix leg.
  • compat-check.yml's cell jobs no longer make an unauthenticated api.github.com call for version resolution.

Implementation notes

Fixes avocado-linux/references@main::rubikpi3 · rubikpi3 @ 2024/edge:: (CI break, tracked via devtool ci-watch).

Fix: added a "Resolve avocado CLI version" step to the plan job using an authenticated gh api call (the job's own GITHUB_TOKEN, 5000 requests/hour), and threaded the result to every cell job's "Install avocado CLI" step via a new avocado_cli_version job output - instead of each of the ~90 legs re-resolving latest unauthenticated. Still tracks the newest CLI release automatically; no version is hardcoded.

Root cause confirmed from the actual job log (gh api repos/avocado-linux/references/actions/jobs/106018692872/logs), not the CI-log excerpt the tracking issue was filed from - that excerpt only captured an unrelated post-job cache-cleanup warning and missed the real failure.

Not verified end-to-end in CI (no actionlint in this repo to dry-run the workflow). Validated the YAML parses (python3 -c "import yaml; yaml.safe_load(...)") and that yamllint reports no new warnings beyond pre-existing line-length style ones, plus a manual line-by-line diff review.

Sibling risk, not fixed here: build-check.yml:123's build job uses the identical unpinned setup-avocado-cli@v1 pattern in its own matrix. It hasn't broken yet, likely because it runs a smaller/less concurrent matrix on PRs, but it carries the same latent exposure to this rate limit.

The rubikpi3 @ 2024/edge cell of the compat-check matrix failed at
"Install avocado CLI" with `curl: (22) The requested URL returned
error: 403`. The composite action resolves `version: latest` by
querying `api.github.com/repos/avocado-linux/avocado-cli/releases/latest`
unauthenticated, and that endpoint shares a 60-request/hour budget
across every GitHub Actions customer on the runner's IP range. This
workflow fans out to roughly 90 matrix legs per run, each making that
same unauthenticated call independently, so one of them losing the
race was a matter of when, not if - confirmed by checking the endpoint
directly: 60/hour unauthenticated vs 5000/hour with a token.

Resolve the version once in the plan job instead, using an
authenticated `gh api` call (the job's own GITHUB_TOKEN raises the
budget to 5000/hour), and thread the result to every cell job's
"Install avocado CLI" step via a new `avocado_cli_version` output.
This keeps the "always test against the latest release" behavior the
workflow wants, rather than trading it for a hardcoded version that
would need manual bumps, while cutting the unauthenticated call count
from ~90 to zero.

Signed-off-by: Javier Tia <javier@peridio.com>
@jetm
jetm merged commit 9eabda6 into main Sep 22, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CI break: rubikpi3 · rubikpi3 @ 2024/edge - Install avocado CLI

2 participants