Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Windows CI: flaky pcre2/zlib/openssl tarball download in test_new.yml's build-windows job

Aperta Adatta ai principianti
#388 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
74/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Tranquilla
Stack tecnologico
github-actions
Ambito
ci-cd

Direzione di ricerca

Inizia in .github/workflows/test_new.yml, nel passaggio “Set up third-party libraries” del job build-windows, ed esamina i log delle esecuzioni non riuscite a cui si fa riferimento. Conferma che i tre download dei tarball forniscano tentativi di ripetizione e diagnostica utile dei fallimenti, quindi verifica che il passaggio abbia esito positivo in modo affidabile nelle riesecuzioni senza nascondere quale URL ha avuto esito negativo.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Summary

The build-windows job in .github/workflows/test_new.yml's "Set up third-party libraries" step intermittently fails downloading pcre2/zlib/openssl for the nginx build itself:

gzip: stdin: unexpected end of file
tar: Child returned status 1
tar: Error is not recoverable: exiting now

from:

wget -q -O - https://github.com/PCRE2Project/pcre2/releases/download/pcre2-10.47/pcre2-10.47.tar.gz | tar -xzf -
wget -q -O - https://www.zlib.net/fossils/zlib-1.3.2.tar.gz | tar -xzf -
wget -q -O - https://www.openssl.org/source/openssl-3.6.2.tar.gz | tar -xzf -

The -q flag on wget also hides which of the three downloads actually failed, and piping straight into tar with no retry means a single truncated/interrupted download kills the whole job immediately with no diagnostic output about the download itself.

Impact

Intermittent, not deterministic (unlike the separate, unrelated yajl/CMake issue also affecting this same job — see owasp-modsecurity/ModSecurity#3604) — a re-run of the same job sometimes gets past this step and sometimes doesn't, consistent with a flaky network fetch rather than a real incompatibility.

Suggested fix

  • Add --retry-connrefused --tries=3 (or similar) to each wget call, or switch to curl --retry 3 --retry-delay 2 -fsSL.
  • Drop the -q/-s quiet flag, or at least fail loudly with the HTTP status/URL on error, so a future failure here is immediately distinguishable from a build-step failure.
  • Consider downloading once and caching the three tarballs (e.g. actions/cache) across matrix runs, since all three windows-nginx-* jobs in the matrix currently re-download the same fixed versions independently.

Where observed

build-windows job, e.g. https://github.com/owasp-modsecurity/ModSecurity-nginx/actions/runs/30317326448/job/90145603796 (triggered from PR #385, but unrelated to that PR's changes).

Lingua principale
Perl
Stelle
1.9k
Fork
312
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

  • Nessun Dockerfile né file Docker Compose
  • Ha un modello di pull request
  • Nessuna guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di owasp-modsecurity/ModSecurity-nginx

Tutte le issue di owasp-modsecurity/ModSecurity-nginx

Issue simili

Altre issue su Perl

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.