Skip to content

[WIP] Fix failing GitHub Actions job for PR #20290 - #20768

Closed
nicholasdille with Copilot wants to merge 1 commit into
mainfrom
copilot/fix-github-actions-job-20290-again
Closed

[WIP] Fix failing GitHub Actions job for PR #20290#20768
nicholasdille with Copilot wants to merge 1 commit into
mainfrom
copilot/fix-github-actions-job-20290-again

Conversation

Copilot AI commented Apr 14, 2026

Copy link
Copy Markdown
Contributor
  • Fix tools/nvidia-container-toolkit/Dockerfile.template apt install step to clear cache, add retries, and clean up after install
Original prompt

Create a PR in uniget-org/tools to fix the failing GitHub Actions job for PR #20290 (run 23890532674, job 69662895711).

Failure context:

  • Workflow: .github/workflows/check.yml
  • The job fails during make ${{ matrix.tool }}--push while building a Docker image.
  • Error in logs:
    • dpkg: error: cannot access archive '/var/cache/apt/archives/libpython3.12-minimal_3.12.3-1ubuntu0.12_amd64.deb': No such file or directory
    • E: Sub-process /usr/bin/dpkg returned an error code (2)
    • This occurs during a Docker build step that runs:
      • apt-get update
      • apt-get -y install --no-install-recommends dh-make fakeroot devscripts lsb-release

Goal:

  • Make the apt install step in the Docker build resilient to missing/corrupted archives when using BuildKit/buildx.

Required changes:

  1. Identify which tool image Dockerfile template/stage contains the failing apt-get install --no-install-recommends dh-make fakeroot devscripts lsb-release step (likely in a shared base or a specific tool’s tools/<name>/Dockerfile.template).
  2. Update that Dockerfile step to:
    • remove apt lists and apt archives before update/install
    • add retries to apt operations
    • clean up apt lists and archives after install

Suggested replacement snippet:

RUN set -eux; \
    rm -rf /var/lib/apt/lists/* /var/cache/apt/archives/* /var/cache/apt/archives/partial/*; \
    apt-get -o Acquire::Retries=5 update; \
    apt-get -o Acquire::Retries=5 install -y --no-install-recommends \
        dh-make \
        fakeroot \
        devscripts \
        lsb-release; \
    rm -rf /var/lib/apt/lists/* /var/cache/apt/archives/*

Acceptance criteria:

  • CI should pass the previously failing build job.
  • Keep behavior identical aside from adding robustness and cleanup.
  • Ensure any shell flags (set -eux) and line continuations are correct for the target Dockerfile.

References:

The following is the prior conversation context from the user's chat exploration (may be truncated):

User: Please find a solution for this failing job. Use the logs, job definition, and any referenced files where the failure occurred. Keep your response focused on the solution and include code suggestions when appropriate.

Assistant: The job is failing during the Docker image build step (triggered by make ${{ matrix.tool }}--push in .github/workflows/check.yml at bd7e96d5de97541657b2681d815e995630566f0a), specifically while running apt-get -y install in one of the Docker build stages.

What’s failing (root cause)

From the job log:

dpkg: error: cannot access archive '/var/cache/apt/archives/libpython3.12-minimal_3.12.3-1ubuntu0.12_amd64.deb': No such file or directory
E: Sub-process /usr/bin/dpkg returned an error code (2)
...
ERROR: process "bash -clo errexit apt-get update
apt-get -y install --no-install-recommends \
    dh-make \
    fakeroot \
    devscripts \
    lsb-release
" did not complete successfully: exit code: 100

This is a known class of failure with container builds using BuildKit/buildx where apt-get expects .deb files to be present in /var/cache/apt/archives/ but they are missing (often due to cache corruption/inconsistency, concurrent/partial downloads, or layered cache reuse). In other words: apt thinks it downloaded packages, but the archive file isn’t there when dpkg goes to install it.

The most effective fix: make the Dockerfile’s apt step resilient

In the Dockerfile stage where you install:

  • dh-make
  • fakeroot
  • devscripts
  • lsb-release

change the install sequence to:

  1. purge apt lists + archives,
  2. update with retries,
  3. install with retries,
  4. clean up.

Suggested Dockerfile snippet

Replace the current step:

RUN apt-get update \
 && apt-get -y install --no-install-recommends \
    dh-make \
    fakeroot \
    devscripts \
    lsb-release

with:

RUN set -eux; \
    rm -rf /var/lib/apt/lists/* /var/cache/apt/archives/* /var/cache/apt/archives/partial/*; \
    apt-get -o Acquire::Retries=5 update; \
    apt-get -o Acquire::Retries=5 install -y --no-install-recommends \
        dh-make \
        fakeroot \
        devscripts \
        lsb-release; \
    rm -rf /var/lib/apt/lists/* /var/cache/apt/archives/*

Why this works:

  • Clearing /var/cache/apt/archives avoids dpkg referencing stale or missing cached artifacts.
  • Acquire::Retries mitigates transient mirror/network hiccups.
  • Cleaning lists/archives at the end reduces layer size and avoids reusing a broken cache state later.

If you control the base image: also consider pinning stability

The log shows Ubuntu noble repositories. If the base image tracks :latest of something that recently shifted to a newer Noble snapshot, the build can become more prone to transient apt is...

This pull request was created from Copilot chat.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants