From 5fb8cef38353f27d40b89b62a60b1c48e1a1dd5f Mon Sep 17 00:00:00 2001 From: "Danilo M." Date: Wed, 23 Sep 2026 09:41:49 +0200 Subject: image-builder: retry docker build once on failure The -current full build failed on 2026-09-23 after all ten steps had passed, at layer export, losing a race on the containerd snapshotter's content lock ("failed to open writer: ref ... locked for 74ms ... unavailable"). Disk was not the issue this time (73G free). The build cache pre-prune that works around this only runs under --force, so the normal gated nightly build had no guard. Add docker_build() to lib.sh: docker build, retried once. By the time the export fails every step is cached, so the retry is little more than a re-export. Used by build-full-image.sh and build-sbo-testbuild.sh, the two scripts that export ~20-33G images; bootstrap.sh's image is small and has never hit this. Self-check covers success, one failure, and two failures with a stub. Co-Authored-By: Claude Opus 5.5 --- image-builder/build-full-image.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'image-builder/build-full-image.sh') diff --git a/image-builder/build-full-image.sh b/image-builder/build-full-image.sh index 47e034b..9a2b83c 100755 --- a/image-builder/build-full-image.sh +++ b/image-builder/build-full-image.sh @@ -212,7 +212,7 @@ DOCKERFILE # docker build would otherwise fall through to push a nonexistent tag and # log "Done". Check each step and return non-zero on failure. _log " Building ${FULL_TAG}..." - if ! docker build "${BUILD_FLAGS[@]}" \ + if ! docker_build "${BUILD_FLAGS[@]}" \ -t "${FULL_TAG}" \ "${WORKDIR}"; then _warn " build failed for ${FULL_TAG}; not pushing." -- cgit v1.2.3