feat(edge): send unsupported R minors to CRAN instead of serving them

Falling back to the flat index for an excluded minor is the silent case:
risky packages there are built under another minor and fail at load time,
far from the cause. Send those clients to CRAN for sources instead, which
is what the router already does for an unidentifiable distro.

The whole interaction has to move, not just the index. R resolves tarball
URLs against the repo it was configured with, so serving the index from
CRAN and tarballs from here would hand R a binary where it expects a
source tarball.

A client reporting no R minor at all is not excluded: mirror scripts and
image builds keep getting the flat slot.

- Declare the supported window once in cdn.tf as local.rpkgs_supported_minors
  and set KNOWN_MINORS from it on both zones, so the router cannot drift
  from build-env-images' LATEST/PREV1/PREV2 unnoticed.
- Split the verification script into supported and excluded minors: the
  former must have published indexes, the latter must have none and must
  redirect to CRAN under --live.
This commit is contained in:
Patrick Schratz 2026-08-30 15:44:14 +00:00
commit 771d3a7768
No known key found for this signature in database
GPG key ID: 62050D5BC68AB6DC
2 changed files with 115 additions and 23 deletions

View file

@ -98,17 +98,29 @@ Deno.test('rpkgs-router', async (t) => {
assertEquals(res.location, `https://cran.rpkgs.com${SLOT}/4.6/PACKAGES.gz`);
});
// No per-minor index is published for 4.3, and contribPath() cannot probe
// the origin. Routing it would send the client to a 404 and it would see no
// packages at all, so an unpublished minor must fall through to flat.
await t.step('falls back to flat for an R minor that is not published', async () => {
// We publish binaries only for the supported window. An excluded minor has
// no slot we can serve safely, so it goes to CRAN for sources rather than
// to a 404 or to binaries built under another minor.
await t.step('sends an excluded R minor to CRAN for the index', async () => {
const res = await probe(`${SLOT}/PACKAGES.gz`, UA_R43_MUSL);
assertEquals(res.location, null);
assertEquals(res.status, 200);
assertEquals(res.location, 'https://cran.r-project.org/src/contrib/PACKAGES.gz');
});
await t.step('falls back to flat for a future R minor', async () => {
await t.step('sends a future R minor to CRAN too', async () => {
const res = await probe(`${SLOT}/PACKAGES.gz`, UA_R47_MUSL);
assertEquals(res.location, 'https://cran.r-project.org/src/contrib/PACKAGES.gz');
});
// The index and the tarballs R resolves against it have to come from the
// same place. Serving one from CRAN and the other from here would hand R a
// binary where it expects a source tarball.
await t.step('sends an excluded minor to CRAN for tarballs as well', async () => {
const res = await probe(`${SLOT}/foo_1.0.tar.gz`, UA_R43_MUSL);
assertEquals(res.location, 'https://cran.r-project.org/src/contrib/foo_1.0.tar.gz');
});
await t.step('leaves an excluded minor alone on a slot outside UNION_SLOTS', async () => {
const res = await probe(`${OTHER_SLOT}/PACKAGES.gz`, UA_R43_MUSL);
assertEquals(res.location, null);
assertEquals(res.status, 200);
});

View file

@ -121,6 +121,18 @@ function publicCdnOrigin(url: URL): string {
return PUBLIC_CDN_HOSTS.has(url.hostname) ? url.origin : PUBLIC_CDN_ORIGIN;
}
/**
* True when the client reports an R minor that we deliberately do not serve.
*
* A client that reports no minor at all is not "unsupported": non-R fetchers
* (mirror scripts, image builds) must keep getting the flat slot. Only a
* known-and-excluded minor falls through to CRAN.
*/
function isExcludedMinor(userAgent: string): boolean {
const rMinor = extractRMinor(userAgent);
return rMinor !== null && !KNOWN_MINORS.has(rMinor);
}
function extractRMinor(userAgent: string): string | null {
for (const regex of R_MINOR_REGEXES) {
const match = userAgent.match(regex);
@ -249,6 +261,16 @@ BunnySDK.net.http
return Promise.resolve(ctx.request);
}
// An R minor outside the supported window has no binaries we can safely
// serve, so the whole interaction goes to CRAN: the index and the
// tarballs R will resolve against it. Serving the index from CRAN but
// tarballs from here would hand R a binary where it expects a source
// tarball, which fails in a far more confusing way than not being
// served at all.
if (UNION_SLOTS.has(slot) && isExcludedMinor(userAgent)) {
return Promise.resolve(redirectTo(`${CRAN_ORIGIN}/src/contrib/${rest}`));
}
const target = contribPath(slot, rest, userAgent);
if (target === path) {
return Promise.resolve(ctx.request);
@ -263,6 +285,10 @@ BunnySDK.net.http
return Promise.resolve(redirectTo(`${CRAN_ORIGIN}${path}`));
}
if (UNION_SLOTS.has(slot) && isExcludedMinor(userAgent)) {
return Promise.resolve(redirectTo(`${CRAN_ORIGIN}${path}`));
}
const rest = srcContrib ? srcContrib[1] : '';
return Promise.resolve(redirectTo(`${publicOrigin}${contribPath(slot, rest, userAgent)}`));
}