From b1b36dcd826f74d24ccc93206422fe577c119ccf Mon Sep 17 00:00:00 2001 From: Marketen Date: Thu, 8 Oct 2026 13:45:32 +0200 Subject: [PATCH] Make base ISO downloads survive mirror moves and dead mirror hosts Debian only moves a point release into cdimage/archive once it has been superseded, so the archive URL 404s for the current release. That broke every automated base ISO bump (e.g. #727, debian-13.7.0). Try debian-cd first and fall back to the archive. Download with curl instead of busybox wget. cdimage.debian.org resolves to two addresses and one of them is currently unreachable; wget gives up on it while curl moves on to the next one. Partial downloads are removed so a failed attempt is not reused by the next build. Co-Authored-By: Claude Opus 5.5 --- iso/scripts/common_iso_generation.sh | 26 +++++++++++++++++---- iso/scripts/generate_dappnode_iso_debian.sh | 7 ++++-- 2 files changed, 27 insertions(+), 6 deletions(-) diff --git a/iso/scripts/common_iso_generation.sh b/iso/scripts/common_iso_generation.sh index 1cd65a0c..37dd8f22 100644 --- a/iso/scripts/common_iso_generation.sh +++ b/iso/scripts/common_iso_generation.sh @@ -4,16 +4,34 @@ WORKDIR="/usr/src/app" ISO_BUILD_PATH="${WORKDIR}/dappnode-iso" DAPPNODE_ISO_PREFIX="Dappnode-" +# Usage: download_iso [fallback_url...] +# URLs are tried in order, which covers mirrors that move older releases elsewhere. download_iso() { local iso_path=$1 local iso_name=$2 - local iso_url=$3 + shift 2 echo "[INFO] Downloading base ISO image: ${iso_name}..." - if [ ! -f "${iso_path}" ]; then - wget "${iso_url}" -O "${iso_path}" + if [ -f "${iso_path}" ]; then + echo "[INFO] Download complete!" + return 0 fi - echo "[INFO] Download complete!" + + local iso_url + for iso_url in "$@"; do + # Unlike busybox wget, curl moves on to the next address when a mirror + # host resolves to several and one of them is down. + if curl -fsSL --retry 3 --retry-connrefused --connect-timeout 30 -o "${iso_path}" "${iso_url}"; then + echo "[INFO] Download complete!" + return 0 + fi + # A failed download leaves a partial file behind, which would be reused on the next run + rm -f "${iso_path}" + echo "[WARN] Could not download ${iso_url}" + done + + echo "[ERROR] Could not download ${iso_name} from any known location" + exit 1 } verify_download() { diff --git a/iso/scripts/generate_dappnode_iso_debian.sh b/iso/scripts/generate_dappnode_iso_debian.sh index 4ec4a93d..c86cbaf0 100755 --- a/iso/scripts/generate_dappnode_iso_debian.sh +++ b/iso/scripts/generate_dappnode_iso_debian.sh @@ -9,7 +9,10 @@ BASE_ISO_NAME="debian-13.5.0-amd64-netinst.iso" BASE_ISO_VERSION="${BASE_ISO_NAME#debian-}" BASE_ISO_VERSION="${BASE_ISO_VERSION%-amd64-netinst.iso}" BASE_ISO_PATH="/images/${BASE_ISO_NAME}" -BASE_ISO_URL="https://cdimage.debian.org/mirror/cdimage/archive/${BASE_ISO_VERSION}/amd64/iso-cd/${BASE_ISO_NAME}" +# Debian serves the newest point release from debian-cd/ and only moves it to the +# archive once it is superseded, so try both. +BASE_ISO_URL="https://cdimage.debian.org/debian-cd/${BASE_ISO_VERSION}/amd64/iso-cd/${BASE_ISO_NAME}" +BASE_ISO_ARCHIVE_URL="https://cdimage.debian.org/mirror/cdimage/archive/${BASE_ISO_VERSION}/amd64/iso-cd/${BASE_ISO_NAME}" BASE_ISO_SHASUM="95838884f5ea6c82421dfe6baaa5a639dbbe6756c1e380f9fe7a7cb0c1949d2a ${BASE_ISO_PATH}" DAPPNODE_ISO_NAME="${DAPPNODE_ISO_PREFIX}${BASE_ISO_NAME}" @@ -87,7 +90,7 @@ generate_debian_iso() { -isohybrid-gpt-basdat -o "${iso_output_path}" ${iso_build_path} } -download_iso "${BASE_ISO_PATH}" "${BASE_ISO_NAME}" "${BASE_ISO_URL}" +download_iso "${BASE_ISO_PATH}" "${BASE_ISO_NAME}" "${BASE_ISO_URL}" "${BASE_ISO_ARCHIVE_URL}" verify_download "${BASE_ISO_PATH}" "${BASE_ISO_SHASUM}" clean_old_files "${ISO_BUILD_PATH}" "${DAPPNODE_ISO_PREFIX}" extract_iso "${BASE_ISO_PATH}" "${ISO_BUILD_PATH}"