Some checks failed
ci/crow/manual/build-all-versions-install-deps/1 Pipeline was successful
ci/crow/manual/build-all-versions-install-deps/2 Pipeline was successful
ci/crow/cron/process-updates/3 Pipeline was successful
ci/crow/cron/process-updates/13 Pipeline was successful
ci/crow/manual/build-all-versions/7 Pipeline was canceled
ci/crow/manual/build-all-versions/6 Pipeline was canceled
ci/crow/manual/build-all-versions/8 Pipeline was canceled
ci/crow/manual/build-all-versions/1 Pipeline was canceled
ci/crow/manual/build-all-versions/5 Pipeline was canceled
ci/crow/manual/build-all-versions/3 Pipeline was canceled
ci/crow/manual/build-all-versions/2 Pipeline was canceled
ci/crow/manual/build-all-versions/4 Pipeline was canceled
ci/crow/cron/process-updates/14 Pipeline was successful
ci/crow/cron/process-updates/10 Pipeline was successful
ci/crow/cron/process-updates/4 Pipeline was successful
## Why #191 gave the existence cache a per-minor view of the slot, but the paths it filters never carried a minor prefix, so the fix could not take effect. `s3fs::s3_dir_ls()` returns keys with the `s3://` scheme attached: ``` s3://devxy-rpkgs-binaries/amd64/resolute/latest/src/contrib/4.4/oeli_0.7.6.tar.gz ``` The contrib prefix was stripped as a *fixed substring*, so it was removed from the middle of the key and the scheme survived: ``` s3://4.4/oeli_0.7.6.tar.gz ``` That leading `s3://` defeats both `^<minor>/` and `^[0-9]+\.[0-9]+/`, so all 21212 per-minor objects on amd64/resolute were classified as flat-slot objects. Pipeline 12011 shows it exactly: ``` sensitive pass: 0 files (0 of 119053 objects apply to this pass) primary pass: 119053 files (119053 of 119053 objects apply to this pass) ``` Each sensitive pass therefore ran with an empty cache and recompiled all 10248 sensitive packages it already had. ## What changed - `local/packages-to-build.R`: anchor the contrib prefix and swallow an optional `s3://` with it. - `local/packages-to-build.R`: abort when the strip leaves fewer per-minor paths than the listing held. The failure mode is silent and only surfaces as a multi-hour rebuild, and both counts derive from the same listing so they must agree exactly. - `local/packages-to-build.R` / `local/build-all.R`: mark the cache with a `slot_relative` attribute and read that, instead of sniffing for a `/`. A slot-relative cache for a slot with no per-minor or Archive object holds bare names too, and would have been misread as legacy and used unfiltered, which makes a per-minor pass believe the flat slot's binaries are its own and build nothing. - `scripts/purge_cdn_zone.sh`: indent the jq continuation lines by a multiple of two. This is unrelated, but it fails editorconfig-checker on `main` and blocks `prek run -a` for everyone. jq ignores the whitespace, and both response shapes still resolve. ## Verification Replaying the real key shapes through the old and new code: ``` sensitive(4.6) primary OLD paths: 0 8 <- reproduces production NEW paths: 3 3 Invariant NEW: listing=4 stripped=4 -> PASS Invariant OLD: listing=4 stripped=0 -> ABORT (would have caught this) ``` Per-minor `Archive/` objects are attributed to their minor, and the flat bucket keeps its own `Archive/`. `prek run -a` passes. Pipelines 12011-12015 were stopped rather than left to spend hours recompiling what they already had. Their uploads are not lost, so a fresh run inherits them. Reviewed-on: #192
112 lines
3.5 KiB
Shell
Executable file
112 lines
3.5 KiB
Shell
Executable file
#!/usr/bin/env bash
|
|
#
|
|
# Purge the entire BunnyCDN pull zone.
|
|
#
|
|
# `purge_cdn_cache.sh` purges the five index files by URL, which is right after
|
|
# a normal update: new packages arrive at new URLs, so only the index is stale.
|
|
#
|
|
# A rebuild is different. It replaces an object *in place*: a package whose
|
|
# build failed was published as its CRAN source, and the rebuilt binary takes
|
|
# exactly the same URL. The zone caches tarballs for ~370 days
|
|
# (`cache_expiration_time` in cdn.tf), so without a purge every client keeps
|
|
# receiving the source tarball for up to a year, and nothing about it looks
|
|
# wrong from the outside.
|
|
#
|
|
# Purging per URL would mean one API call per replaced package -- ~13.5k per
|
|
# arch against a rate-limited endpoint, where a single missed call leaves a
|
|
# silently stale package. One zone purge is a single call regardless of how many
|
|
# objects were replaced. The cost is a cold cache for everything else, which is
|
|
# why this is not used by the daily update path.
|
|
#
|
|
# The public hostnames currently use separate pull zones, so callers must pass
|
|
# every zone that serves the repository. A zone can be identified by its
|
|
# numeric ID or by one of its hostnames; hostname lookup avoids persisting IDs
|
|
# that change when a zone is recreated.
|
|
#
|
|
# Usage:
|
|
# purge_cdn_zone.sh <BUNNYNET_API_KEY> <pull_zone> [<pull_zone>...]
|
|
#
|
|
set -euo pipefail
|
|
|
|
if (($# < 2)); then
|
|
echo "usage: $0 <api_key> <pull_zone> [<pull_zone>...]" >&2
|
|
exit 2
|
|
fi
|
|
|
|
api_key="$1"
|
|
shift
|
|
|
|
resolve_zone_id() {
|
|
local zone="$1"
|
|
local response_file
|
|
local zone_id
|
|
|
|
if [[ "${zone}" =~ ^[0-9]+$ ]]; then
|
|
echo "${zone}"
|
|
return
|
|
fi
|
|
|
|
response_file=$(mktemp)
|
|
local status
|
|
status=$(
|
|
curl -sS -o "${response_file}" -w '%{http_code}' \
|
|
-H "AccessKey: ${api_key}" \
|
|
"https://api.bunny.net/pullzone?perPage=1000"
|
|
)
|
|
|
|
if [[ "${status}" != "200" ]]; then
|
|
echo "Listing BunnyCDN pull zones failed with HTTP ${status}:" >&2
|
|
head -c 500 "${response_file}" >&2
|
|
echo >&2
|
|
rm -f "${response_file}"
|
|
exit 1
|
|
fi
|
|
|
|
# The endpoint answers with a bare array on some accounts and a paginated
|
|
# object on others. `.Items // .` looks like it covers both but does not:
|
|
# indexing an array with a string is an *error*, and `//` only substitutes
|
|
# for null, so the array case aborted with
|
|
# "Cannot index array with string" and the zone was never purged.
|
|
zone_id=$(
|
|
jq -r --arg hostname "${zone}" \
|
|
'(if type == "object" then (.Items // []) else . end)[]
|
|
| select(any(.Hostnames[]?; .Value == $hostname))
|
|
| .Id' \
|
|
"${response_file}"
|
|
)
|
|
rm -f "${response_file}"
|
|
|
|
if [[ -z "${zone_id}" ]]; then
|
|
echo "Could not find BunnyCDN pull zone for hostname ${zone}" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Two zones sharing a hostname would purge only whichever jq emitted first.
|
|
if [[ $(wc -l <<<"${zone_id}") -gt 1 ]]; then
|
|
echo "Hostname ${zone} matched multiple pull zones: ${zone_id//$'\n'/ }" >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "${zone_id}"
|
|
}
|
|
|
|
for zone in "$@"; do
|
|
zone_id=$(resolve_zone_id "${zone}")
|
|
echo "Purging BunnyCDN pull zone ${zone_id}"
|
|
|
|
response_file="/tmp/purge_zone_response_${zone_id}.txt"
|
|
status=$(
|
|
curl -sS -o "${response_file}" -w '%{http_code}' -X POST \
|
|
-H "AccessKey: ${api_key}" \
|
|
-H "Content-Length: 0" \
|
|
"https://api.bunny.net/pullzone/${zone_id}/purgeCache"
|
|
)
|
|
|
|
if [[ "${status}" != "200" && "${status}" != "204" ]]; then
|
|
echo "Purge of pull zone ${zone_id} failed with HTTP ${status}:" >&2
|
|
cat "${response_file}" >&2
|
|
exit 1
|
|
fi
|
|
|
|
echo "Purged pull zone ${zone_id} (HTTP ${status})"
|
|
done
|