The PDF job takes ~9 minutes and is the whole workflow's wall clock,
because install.sh pulls texlive-full: 455 packages and 4.0 GB of every
language pack, ConTeXt and Metapost. The book needs 68 packages,
768 MB.
Measured by building the book both ways in ubuntu:24.04 and comparing:
packages download apt install make pdf
texlive-full 455 3995 MB 270s 188s
reduced set 68 768 MB 92s 141s
Output is equivalent, not merely similar: all 19 PDFs (main plus 18
chapters) have identical page counts (main.pdf is 390 pages either
way), identical page sizes, and byte-identical pdftotext output, with
no unresolved references in either.
Also:
- fail-fast: false, so a WIKI failure 90 seconds in stops cancelling
the 9 minute PDF job. That happened repeatedly while fixing CI: the
run then says nothing about whether the PDF is healthy.
- concurrency groups, asymmetric on purpose. PR builds have no side
effects so a superseded run is cancelled. Deploy is NOT cancelled
mid-run: it pushes the wiki, force-pushes epub_deploy and pdf_deploy
and nudges the website, and interrupting that can leave the three
targets on different commits.
- timeout-minutes: 30, so a hung link check cannot burn six hours.
- pip cache. Marginal - five small pure-python wheels - but free.
Note make -j4 was tried and rejected: it cuts the build to 80s but
produces a wrong book, numbering the appendix 13 instead of 17 and
degrading a cross-reference to ??.
The coursebook now publishes its wiki again, but nothing tells the
website to rebuild, so a change reaches the site only when someone
else pushes to it.
Restore that trigger with a deploy key (SITE_DEPLOY_KEY) rather than
the built-in token: GITHUB_TOKEN is scoped to this repo, and pushes
made with it deliberately do not trigger workflows. A deploy key also
has no expiry and is exempt from the org's SAML SSO, so it will not
silently lapse the way the old credentials did.
- point site_deploy.sh at cs341-illinois/cs341-illinois.github.io; it
still named illinois-cs241, two renames stale
- add IdentitiesOnly so ssh cannot offer some other key
- seed known_hosts with ssh-keyscan instead of relying on the runner
- skip the site deploy when the secret is absent, so forks still pass
Every deploy has been failing at the push with "git@github.com:
Permission denied (publickey)". The repo has no deploy keys registered
at all, so the keys inside site-deploy.enc and wiki-deploy.enc cannot
authenticate - most likely lost in the illinois-cs241 ->
cs341-illinois org rename. GPG decryption itself still works, so
GPG_PASSPHRASE is not the problem.
Comment out the gpg/ssh-agent machinery and push over https with the
built-in GITHUB_TOKEN, granting the job contents: write. Nothing to
rotate, and it survives future renames.
site_deploy.sh stays disabled: it pushes to a different repo to nudge
the website into rebuilding, which GITHUB_TOKEN cannot do, and it still
names the twice-stale illinois-cs241/illinois-cs241.github.io.
Python 3.9 has builds only for ubuntu-22.04 and 24.04, so the pin added
in #220 blocks a future move to 26.04 runners. 3.11 covers 22.04, 24.04
and 26.04.
3.9 was chosen because panflute 1.10.6 imports MutableSequence from
collections, removed in Python 3.10. That does not require a pandoc
upgrade: panflute 1.12.5 fixed the import and still targets pandoc
2.7's AST (pandoc-types 1.17.5.4), so install.sh, the Makefile and the
filters are all unchanged.
Verified by building both stacks and diffing the output: all 20 wiki
files are byte-identical, and the EPUB is identical apart from the
random urn:uuid and build timestamp. Also clean on 3.12 and 3.14.
All four sources removed the referenced content; no equivalent page
exists on the original site any more. Each replacement snapshot was
fetched and confirmed to return 200 with the expected content.
- malloc: IBM developerWorks 'Data alignment' article -- ibm.com now
redirects the whole /developerworks/library/ tree to the
developer.ibm.com home page. Snapshot 20190313121701.
- post_mortems: geek.com shut down; the origin now serves an S3
AccessDenied 403. Snapshot 20191216004115 (title confirmed:
'What caused Gandhi's insatiable bloodlust in Civilization').
- filesystems: goo.gl/LwFIy resolved to a Google Faculty Summit 2010
PDF that is now 404. Snapshot 20160910131226 returns the original
storage_architecture_and_challenges.pdf (application/pdf, 85 KB).
- background: the osxfuse project moved to macfuse and deleted the
SSHFS wiki page; GitHub now redirects it to the macfuse wiki home.
Snapshot 20240913220726 (title confirmed: 'SSHFS - osxfuse Wiki').
lxr.free-electrons.com still resolves in DNS but refuses connections
(free-electrons rebranded to Bootlin and retired the lxr host). The
WIKI build's pandoc_header_filter.py calls requests.head() on every
link, so a connection failure aborts CI.
Replaced with the same document served by kernel.org:
https://www.kernel.org/doc/Documentation/memory-barriers.txt (200 OK).
The WIKI build died on www.gnu.org with "[Errno 101] Network is
unreachable". gnu.org is not down: it has an AAAA record and GitHub
runners have no IPv6 route, so the connection fails before IPv4 is
tried. Reachability of the build machine is not a property of the book,
so warn and carry on instead of aborting.
Also add a 15s timeout - the failing host stalled the job for over two
minutes of retries - and report non-2xx as a warning. The previous
status test was `code < 200 and code > 299`, which no integer can
satisfy, so no status has ever been checked. It stays non-fatal
deliberately: www.gnu.org answers a bare requests HEAD with 403 (it
blocks the default user agent), so failing on non-2xx would break the
build on links that are perfectly fine in a browser.
cyber.dhs.gov no longer has an A record, so the link check in
pandoc_header_filter.py died with "No address associated with hostname"
and took the WIKI build down with it.
CISA moved Emergency Directive 19-01; point at its current home.
Every build and deploy job has been failing at the "Setup python" step
with "Version 3.7 with arch x64 not found". ubuntu-latest now resolves
to ubuntu-24.04, and actions/python-versions only ships 3.7 builds for
20.04 and 22.04.
Move to 3.9, which does have a 24.04 build. 3.9 is the newest release
that still works with the pinned panflute 1.10.6: it imports
MutableSequence from collections, which was removed in Python 3.10, so
3.10+ would fail on import instead.
Also bump checkout/setup-python to v4/v5, since the v2 actions run on a
deprecated Node version.
The URL pointed at a specific past semester's course
(us/courses/61021), which no longer applies. The surrounding text
already says to use the current semester's CS341 Edstem, so link
edstem.org itself and let that sentence do the work.