ci(bazel): vendor InfoZip unzip/zip tarballs to stop SourceForge 522s from breaking CI - #381
Conversation
… from breaking CI downloads.sourceforge.net had intermittent Cloudflare 522 outages on 2026-10-01 that broke multiple PR CI runs and shipped v0.89.0 with zero release assets (the safety-gate job exhausted its retries fetching unzip60.tar.gz/zip30.tar.gz). Both tarballs are now mirrored as GitHub release assets on this repo (sha256-verified byte-identical to the originals) and listed first in MODULE.bazel's http_archive urls, with MacPorts/OSUOSL as independent fallbacks and SourceForge demoted to last.
JVM Load Benchmark (Desktop)Synthetic in-memory benchmark measuring load performance for the desktop (JVM) app.
Flamegraphs (this PR)**Allocation** — object allocation pressure (JDBC/SQLite churn)Alloc flamegraph not available CPU — method-level hotspots by on-CPU time CPU flamegraph not available Top allocation hotspots (this PR)`38.4%` byte[]_[k] `7.2%` java.lang.String_[k] `6.7%` int[]_[k] `5.6%` java.util.LinkedHashMap$Entry_[k] `3.8%` java.lang.Object[]_[k]Top CPU hotspots (this PR)`96.5%` /usr/lib/x86_64-linux-gnu/libc.so.6 `1.4%` /tmp/sqlite-3.51.3.0-28eeef8a-6fb8-4ff5-91c6-b34a72cebbb9-libsqlitejdbc.so `0.4%` __libc_pwrite `0.3%` fsync `0.2%` SR_handler |
Android Load BenchmarkInstrumented benchmark on an API 30 x86_64 emulator — 500-page synthetic graph. Comparing Graph Load
Interactive Write Latency (during Phase 3)
SAF I/O Overhead (ContentProvider vs direct File read)Measures Binder IPC cost added by ContentResolver per readFile() call.
|
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
Release assets exist with matching SHA-256 digests, and Bazel retains integrity verification and multiple fallbacks.
Review effort: Balanced
Findings: None
What changed in this PR
Improves Bazel CI reliability by adding verified mirrors for InfoZip archives.
Changes:
- Prioritizes repository-hosted GitHub release assets.
- Adds independent mirrors while retaining SourceForge as fallback.
- Preserves existing SHA-256 integrity checks.
| File | Description |
|---|---|
MODULE.bazel |
Adds ordered fallback URLs for InfoZip sources. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Why
downloads.sourceforge.nethad intermittent Cloudflare 522 ("origin unreachable") outages on 2026-10-01 that:v0.89.0's release safety gate to exhaust its 3 retries, skipping every downstream build/publish job — the release shipped with zero assetsRoot cause:
MODULE.bazel'sunzip_src/zip_srchttp_archiverules had a single hardcoded SourceForge URL each, with no fallback.Fix
Both tarballs (InfoZip
unzip60.tar.gz/zip30.tar.gz) are now hosted as assets on a dedicated, non-app GitHub release in this repo — verifiedsha256-identical to the hashes already pinned inMODULE.bazel(confirmed against the original SourceForge files before the outage, and cross-checked against MacPorts/OSUOSL mirrors).MODULE.bazel'surlslists now try, in order: our own GitHub release → MacPorts/OSUOSL mirrors → SourceForge (demoted to last, kept only as a final fallback).http_archivetries each URL until one succeeds, so this requires no other code changes.Verification
bazel build --repository_cache=<empty> @unzip_src//:unzip @zip_src//:zipafter deleting the previously-extracted external repos — forces a true cold fetch, confirms the new URL list resolves and the sha256 check passes.bazel build //:stelekit_android_toolchain_impl— the consumer of these two targets — builds clean.