From 077156e88f2fb7d359384fed7fdd268ba5bf1805 Mon Sep 17 00:00:00 2001 From: Jordan Harband Date: Thu, 8 Oct 2026 11:10:27 -0700 Subject: [PATCH] [actions] never let an apt install wait on a prompt Moving WSL package installs out of `setup-wsl`'s `additional-packages` lost its non-interactive setup: on Ubuntu 18.04, upgrading `libssl1.1` asks whether to restart services, and the job waited on that dialog until it was cancelled. Set `DEBIAN_FRONTEND=noninteractive`, keep existing config files without asking, and give apt no stdin. --- .github/scripts/apt-install.sh | 5 ++++- .github/workflows/windows-nvm.yml | 17 +++++++++++------ 2 files changed, 15 insertions(+), 7 deletions(-) diff --git a/.github/scripts/apt-install.sh b/.github/scripts/apt-install.sh index 40269809..f67c143b 100644 --- a/.github/scripts/apt-install.sh +++ b/.github/scripts/apt-install.sh @@ -20,11 +20,14 @@ if [ "$(id -u)" != '0' ]; then fi apt_get() { + # never prompt: an upgrade (e.g. libssl asking to restart services) would wait forever $SUDO env DEBIAN_FRONTEND=noninteractive apt-get \ -o Acquire::Retries=5 \ -o Acquire::http::Timeout=30 \ -o Acquire::https::Timeout=30 \ - "$@" + -o Dpkg::Options::=--force-confdef \ + -o Dpkg::Options::=--force-confold \ + "$@" < /dev/null } ATTEMPT=1 diff --git a/.github/workflows/windows-nvm.yml b/.github/workflows/windows-nvm.yml index ee9ece3e..5ce63f4d 100644 --- a/.github/workflows/windows-nvm.yml +++ b/.github/workflows/windows-nvm.yml @@ -157,11 +157,13 @@ jobs: name: 'Install packages with retries' shell: 'wsl-bash {0}' run: | + # never prompt: an upgrade (e.g. libssl asking to restart services) would wait forever + export DEBIAN_FRONTEND=noninteractive attempt=1 delay=15 while true; do - apt-get -o Acquire::Retries=5 update || true - if apt-get -o Acquire::Retries=5 install --yes bash git curl ca-certificates wget; then + apt-get -o Acquire::Retries=5 update < /dev/null || true + if apt-get -o Acquire::Retries=5 -o Dpkg::Options::=--force-confdef -o Dpkg::Options::=--force-confold install --yes bash git curl ca-certificates wget < /dev/null; then break fi if [ "${attempt}" -ge 8 ]; then @@ -227,14 +229,17 @@ jobs: } done } + # never prompt: an upgrade (e.g. libssl asking to restart services) would wait forever + export DEBIAN_FRONTEND=noninteractive packages=(bash git curl ca-certificates wget) - retry apt-get update || true - if ! retry apt-get install --yes "${packages[@]}"; then + install_options=(-o Dpkg::Options::=--force-confdef -o Dpkg::Options::=--force-confold install --yes) + retry apt-get update < /dev/null || true + if ! retry apt-get "${install_options[@]}" "${packages[@]}" < /dev/null; then # a security index can outlive the pool objects it advertises, which # no retry resolves; main is complete once a release is archived sed -i '/debian-security/d' /etc/apt/sources.list - retry apt-get update || true - retry apt-get install --yes "${packages[@]}" + retry apt-get update < /dev/null || true + retry apt-get "${install_options[@]}" "${packages[@]}" < /dev/null fi - name: Retrieve nvm on WSL