929fc17127
Hardens both workflows after the R-on-ubuntu job repeatedly hit the 20-minute job cap and was cancelled (no R-package cache + no retry + a slow source build). Each item below maps to the requested checklist. ### CI (`ci.yml`) - **Timeouts 20 → 30 min** on every job (backstop only; real jobs finish well under). - **R dependencies cached**: replace the manual `install.packages(testthat/knitr)` with `r-lib/actions/setup-r-dependencies` — restores a cached R library and pulls **RSPM binaries** instead of compiling from source (the slow/flaky path that blew the cap). This is the actual root-cause fix. - **NuGet cache** for the C# job (`~/.nuget/packages`, keyed on the project files). - **Retry** the network installs that had none — `npm ci`, `dotnet test`, `mvn install` — via `nick-fields/retry` (2–3 attempts, backoff). On top of the existing env-level retries (`CARGO_NET_RETRY`, `npm_config_fetch_retries`, `PIP_RETRIES`) and the setup-* CDN-flake retries. - **Go stays `cache: false`** on purpose: the module has no `go.sum` / external deps, so there is nothing to cache (enabling it would only warn). ### Release (`release.yml`) - **Per-job timeouts** added (there were none — only GitHub's 6h default): **45 min**, higher than CI's 30 because the wheel/build jobs compile from source incl. **vendored OpenSSL** and must not be killed mid-build. - **wasm-publish** gets a `Swatinem/rust-cache` like the other Rust-build jobs. - **Retry** the no-retry network installs (`npm ci` ×2, `dotnet pack`). The actual publish/deploy steps are left alone — they are already idempotent (skip-existing / skip-duplicate), so re-running the job is the safe recovery. ### R binding download (`bindings/r/configure[.win]`) - A freshly cut release can 404 for 1–2 min while assets propagate, which broke the C ABI download (`cannot open URL … 404`). Add a `wickra_download` retry helper (6 × 20s ≈ 2 min backoff) for both the release-asset and wasm-source downloads. Note: the CI R job builds the C ABI **locally** (`WICKRA_*_DIR`), so it never downloads — this fix covers the real-world r-universe / end-user build. This PR's own CI exercises the CI changes (the reworked R job, caches, retries, timeouts) before merge; the release-only changes are validated on the next tag.