This is an automated email from the ASF dual-hosted git repository.

hubcio pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/iggy.git


The following commit(s) were added to refs/heads/master by this push:
     new fab50a861 ci: fix edge-gate over-publish and retry license check 
(#3468)
fab50a861 is described below

commit fab50a861a8ea773dc08024dcdb08a0c638994ed
Author: Hubert Gruszecki <[email protected]>
AuthorDate: Mon Jun 15 11:33:16 2026 +0200

    ci: fix edge-gate over-publish and retry license check (#3468)
---
 scripts/ci/edge-affected-images.sh | 47 +++++++++++++++++++++++++-------------
 scripts/ci/third-party-licenses.sh | 31 +++++++++++++++++++------
 2 files changed, 55 insertions(+), 23 deletions(-)

diff --git a/scripts/ci/edge-affected-images.sh 
b/scripts/ci/edge-affected-images.sh
index 8559aed4b..b69ba9907 100755
--- a/scripts/ci/edge-affected-images.sh
+++ b/scripts/ci/edge-affected-images.sh
@@ -79,23 +79,38 @@ if ! PLAN="$(cargo rail plan --since "$BASE" -f json 
2>"$RAIL_ERR")"; then
 fi
 
 # Parse defensively: malformed output must fall OPEN, never abort under set -e
-# (that fails closed and skips the publish). jq prints nothing on a parse 
error,
-# leaving MODE empty. A valid {mode:crates, crates:[]} is the normal
-# docs/SDK/config-only push and must publish nothing, so only an unparsable
-# MODE or a non-"crates" mode escalates to emit_all.
-MODE="$(jq -r '.scope.mode // "full"' <<<"$PLAN" 2>/dev/null || true)"
-if [[ -z "$MODE" ]]; then
-  echo "::warning::edge-gate: unparsable cargo-rail output, refreshing all 
images" >&2
-  emit_all
-  exit 0
-fi
-if [[ "$MODE" != "crates" ]]; then
-  echo "::notice::edge-gate: cargo-rail reports full workspace, refreshing all 
images" >&2
-  emit_all
-  exit 0
-fi
+# (that fails closed and skips the publish). cargo-rail's ExecutionScopeMode is
+# one of three snake_case values:
+#   crates    -> a specific affected subset; gate each image on it below.
+#   empty     -> no build/test/bench surface was touched (docs / infra / 
non-Rust
+#                files only), so zero crates ship new code. Non-crate build 
inputs
+#                (the embedded web UI, Dockerfiles) are still gated per image 
via
+#                gate.paths, so fall through with an EMPTY crate set rather 
than
+#                refreshing everything. A node/docs/SDK-only push lands here.
+#   workspace -> a package-scoped surface pins to all crates (or none 
resolvable);
+#                rebuild every image.
+# An absent or unparsable mode falls open to emit_all.
+MODE="$(jq -r '.scope.mode // ""' <<<"$PLAN" 2>/dev/null || true)"
+AFFECTED=()
+case "$MODE" in
+  crates)
+    mapfile -t AFFECTED < <(jq -r '.scope.crates // [] | .[]' <<<"$PLAN")
+    ;;
+  empty)
+    echo "::notice::edge-gate: no crate impact, gating images on paths only" 
>&2
+    ;;
+  workspace)
+    echo "::notice::edge-gate: cargo-rail reports full workspace, refreshing 
all images" >&2
+    emit_all
+    exit 0
+    ;;
+  *)
+    echo "::warning::edge-gate: unparsable or unexpected cargo-rail mode 
'${MODE:-<empty>}', refreshing all images" >&2
+    emit_all
+    exit 0
+    ;;
+esac
 
-mapfile -t AFFECTED < <(jq -r '.scope.crates // [] | .[]' <<<"$PLAN")
 declare -A AFFECTED_SET=()
 for crate in ${AFFECTED[@]+"${AFFECTED[@]}"}; do
   AFFECTED_SET["$crate"]=1
diff --git a/scripts/ci/third-party-licenses.sh 
b/scripts/ci/third-party-licenses.sh
index 5c54ca376..8c86b253a 100755
--- a/scripts/ci/third-party-licenses.sh
+++ b/scripts/ci/third-party-licenses.sh
@@ -44,6 +44,13 @@ set -euo pipefail
 SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
 REPO_ROOT="$(cd "$SCRIPT_DIR/../.." && pwd)"
 
+# cargo-about shells out to `cargo metadata`, which refreshes the crates.io
+# index and downloads dep manifests. Both can fail transiently on a network
+# blip ("Connection reset by peer") even past cargo's own net retries. Retry
+# the whole invocation a few times so a flake never reddens a release gate.
+CARGO_ABOUT_ATTEMPTS=3
+CARGO_ABOUT_RETRY_DELAY_SECONDS=5
+
 ACTION=""
 MANIFESTS=()
 OUTPUT=""
@@ -172,13 +179,23 @@ run_cargo_about() {
   local out="$2"
   require_cmd cargo-about
 
-  ( cd "$REPO_ROOT" && \
-    cargo about generate \
-      --config about.toml \
-      --manifest-path "$target_manifest" \
-      --fail \
-      -o "$out" \
-      about.hbs )
+  local attempt
+  for ((attempt = 1; attempt <= CARGO_ABOUT_ATTEMPTS; attempt++)); do
+    if ( cd "$REPO_ROOT" && \
+      cargo about generate \
+        --config about.toml \
+        --manifest-path "$target_manifest" \
+        --fail \
+        -o "$out" \
+        about.hbs ); then
+      return 0
+    fi
+    if ((attempt < CARGO_ABOUT_ATTEMPTS)); then
+      echo "warning: cargo-about failed (attempt 
${attempt}/${CARGO_ABOUT_ATTEMPTS}), retrying in 
${CARGO_ABOUT_RETRY_DELAY_SECONDS}s" >&2
+      sleep "$CARGO_ABOUT_RETRY_DELAY_SECONDS"
+    fi
+  done
+  return 1
 }
 
 # Run license-checker-rseidelsohn against an npm package directory and

Reply via email to