fix(ci): detect existing R versions via public object HEAD probe

The existing-version check listed the bucket with an anonymous curl, but
Backblaze B2 requires authentication for the list-bucket API, so it returned
AccessDenied and r-versions-existing.txt was always empty -> every version
was rebuilt despite already existing in s3.

Signing the request is not workable here: the B2 credentials are scoped to
the plugin-s3 image in crow and are not injected into this plain alpine step
(curl saw --user ":").

Individual artifacts are public-read, so probe each expected object URL with
an anonymous HEAD instead of listing the bucket. The filename mirrors what
nfpm produces (version/release pinned to 1): r-<ver>_1_<arch>.{apk,deb} for
alpine/ubuntu and R-<ver>-1-1.<arch>.rpm for el*. Verified against the live
bucket for all three packager families.
This commit is contained in:
Patrick Schratz 2026-06-29 13:00:26 +02:00
commit b917759865
Signed by: pat-s
GPG key ID: 3C6318841EF78925

View file

@ -162,12 +162,23 @@ steps:
- ip link set dev eth0 mtu 1280 2>/dev/null || true
- for i in 1 2 3 4 5; do apk add -q --no-cache curl && break; sleep 5; done
- |
LISTING=$(curl -s "https://s3.eu-central-003.backblazeb2.com/devxy-r-builds?prefix=${PLATFORM_ID}/" | \
grep -oE '<Key>[^<]+</Key>' | sed 's/<[^>]*>//g')
# Backblaze B2's list-bucket API requires authentication, but the upload
# credentials are scoped to the plugin-s3 image and aren't available here.
# Individual objects are public-read, so probe each expected artifact URL
# with an anonymous HEAD instead of listing the bucket. The filename mirrors
# what nfpm produces in builder/package.${PLATFORM} (version/release pinned
# to 1): r-<ver>_1_<arch>.{apk,deb} for alpine/ubuntu, R-<ver>-1-1.<arch>.rpm
# for el*.
case "${PLATFORM}" in
alpine-*) FILE="r-VER_1_${ARCH_ID}.apk" ;;
ubuntu-*) FILE="r-VER_1_${ARCH_ID}.deb" ;;
*) FILE="R-VER-1-1.${ARCH_ID}.rpm" ;;
esac
BASE="https://s3.eu-central-003.backblazeb2.com/devxy-r-builds/${PLATFORM_ID}"
: > r-versions-existing.txt
for VERSION in $(cat r-versions-to-build.txt); do
if printf '%s\n' "$LISTING" | \
awk -v arch="${ARCH_ID}" -v ver="$VERSION" 'index($0, arch) && index($0, ver) { found=1 } END { exit !found }'; then
URL="${BASE}/$(echo "$FILE" | sed "s/VER/${VERSION}/")"
if [ "$(curl -s -o /dev/null -w '%{http_code}' -I "$URL")" = "200" ]; then
echo "$VERSION" >> r-versions-existing.txt
fi
done