A rebuild replaces an object in place: a package whose build failed was
published as its CRAN source, and the rebuilt binary takes exactly the same
URL. Two things then hide the result from clients.
The slot's index still advertises the old MD5 and, for anything served from
source, no Built stamp, because weekly-rebuild-missing never re-indexed. And
the pull zone caches tarballs for ~370 days, while purge_cdn_cache.sh only
purges the five index files, so the edge keeps serving the source tarball for
up to a year with nothing about it looking wrong.
Observed after rebuilding AATtools 0.0.3: the pipeline reported a successful
upload while the edge still served the CRAN source, etag ea8127... and no Meta/.
- re-index the slot at the end of a rebuild, flat and per-minor, detecting the
codename from the image rather than adding OS_ID to 18 matrix rows
- add scripts/purge_cdn_zone.sh and call it afterwards. One zone purge covers
every replaced object and all three hostnames, which share pull zone 3857050;
purging per URL would be ~13.5k rate-limited calls per arch where one missed
call leaves a silently stale package
- purge on failure too, since a rebuild that died part-way still replaced
objects and those are exactly the ones a stale edge keeps hiding