fix(ci): bound system dependency downloads (#4514)
An Ubuntu package download in #4357's CI took 54 minutes for 262 MB,
compared with 7–39 seconds on the other runners. The existing retry loop
waits indefinitely for a command to return, so it cannot recover from a
download that continues extremely slowly.
This change shares dependency setup across the unit, extras, and ingest
jobs. It applies 30-second HTTP/HTTPS inactivity timeouts, APT retries,
and three bounded five-minute attempts for index updates and downloads.
Packages are downloaded first and installed with `--no-download`,
keeping dpkg installation outside the outer timeout. Setup appears as a
separate step, and the PPA's implicit index refresh is replaced with an
explicitly bounded refresh.
The package set, Tesseract version check, and test commands are
preserved. Persistently poor networking now produces a clear setup
failure instead of an hour-long download; the change does not guarantee
a faster mirror.
Validation: Bash syntax, ShellCheck, shfmt, workflow YAML parsing, and
whitespace checks passed. A mocked harness verified success, retry after
timeout, exhaustion, and installation sequencing. A disposable Ubuntu
24.04 container validated the APT flags with strict index update,
download-only fetching, and offline installation of libmagic-dev. The
full helper also completed successfully in a disposable Ubuntu 24.04
ARM64 container, including LibreOffice, the Tesseract PPA, Korean OCR
data, and diffstat; Tesseract reported 5.5.1. The repository
release-version check passed on Ubuntu. GitHub CI passed on aa97013,
including the unit, dependency-extras, ingest and Dockerfile jobs that
use the new helper; no end-to-end CI speedup has been established.