Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 10 additions & 1 deletion crates/socket-patch-cli/tests/docker_e2e_cargo.rs
Original file line number Diff line number Diff line change
Expand Up @@ -157,7 +157,16 @@ EOF
echo 'fn main() {{}}' > src/main.rs

# cargo fetch populates $CARGO_HOME/registry/src/<index>/cfg-if-1.0.0/.
cargo fetch > /tmp/fetch.log 2>&1 || {{ cat /tmp/fetch.log >&2; exit 1; }}
# cfg-if arrives over the real network (static.crates.io). Cargo's own
# spurious-network retries span only seconds, which a runner's
# connect timeouts outlast, so retry with backoff before declaring the
# fixture broken (as docker_e2e_composer does for packagist).
for attempt in 1 2 3; do
cargo fetch > /tmp/fetch.log 2>&1 && break
if [ "$attempt" = 3 ]; then cat /tmp/fetch.log >&2; exit 1; fi
echo "cargo fetch attempt $attempt failed; retrying" >&2
sleep $((attempt * 10))
done

LIB_RS=$(ls "$CARGO_HOME/registry/src/"*/cfg-if-1.0.0/src/lib.rs 2>/dev/null | head -1)
[ -f "$LIB_RS" ] || {{ echo "FAIL: cfg-if lib.rs not in registry/src" >&2; exit 1; }}
Expand Down
40 changes: 35 additions & 5 deletions crates/socket-patch-cli/tests/docker_e2e_maven.rs
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,9 @@ use wiremock::{Mock, MockServer, ResponseTemplate};
const ORG: &str = "test-org";
const PURL: &str = "pkg:maven/org.apache.commons/commons-lang3@3.12.0";
const UUID: &str = "16161616-1616-4161-8161-161616161616";
/// Google's official Maven Central mirror, the in-container download's
/// retry target (Central's CDN answers shared runner IPs with 429s).
const CENTRAL_FALLBACK: &str = "https://maven-central.storage-download.googleapis.com/maven2";
/// The vulnerability the staged manifest carries so the agent-mode VEX leg
/// has something to attest (plain agent provenance — no vendored/redirected
/// marker — is what the host oracle asserts).
Expand Down Expand Up @@ -164,11 +167,38 @@ cat > pom.xml <<'EOF'
</project>
EOF

# Download the real artifact into ~/.m2/repository.
mvn -q dependency:get \
-Dartifact=org.apache.commons:commons-lang3:3.12.0 \
-DremoteRepositories=https://repo.maven.apache.org/maven2 \
> /tmp/install.log 2>&1 || {{ cat /tmp/install.log >&2; exit 1; }}
# Download the real artifact into ~/.m2/repository. Central's CDN
# rate-limits shared runner IPs with 429s, which Maven reports as an
# absent artifact, so retries go through Google's official Central
# mirror (a separate CDN, as in maven_build_common's warm-up).
# The mirror keeps the id `central`, and -U drops the cached misses.
cat > /tmp/mirror-settings.xml <<'EOF'
<settings xmlns="http://maven.apache.org/SETTINGS/1.0.0">
<mirrors>
<mirror>
<id>central</id>
<mirrorOf>central</mirrorOf>
<url>{CENTRAL_FALLBACK}</url>
</mirror>
</mirrors>
</settings>
EOF
for attempt in 1 2 3; do
if [ "$attempt" = 1 ]; then
mvn -q dependency:get \
-Dartifact=org.apache.commons:commons-lang3:3.12.0 \
-DremoteRepositories=https://repo.maven.apache.org/maven2 \
> /tmp/install.log 2>&1 && break
else
mvn -q -U -s /tmp/mirror-settings.xml dependency:get \
-Dartifact=org.apache.commons:commons-lang3:3.12.0 \
-DremoteRepositories={CENTRAL_FALLBACK} \
> /tmp/install.log 2>&1 && break
fi
if [ "$attempt" = 3 ]; then cat /tmp/install.log >&2; exit 1; fi
echo "mvn dependency:get attempt $attempt failed; retrying via the Central mirror" >&2
sleep $((attempt * 5))
done

POM_FILE="$HOME/.m2/repository/org/apache/commons/commons-lang3/3.12.0/commons-lang3-3.12.0.pom"
[ -f "$POM_FILE" ] || {{ echo "FAIL: $POM_FILE missing" >&2; exit 1; }}
Expand Down
Loading