Skip to content

Commit 7cf4a47

Browse files
BYKGPT-6 Sol
andauthored
Install CLI nightlies from Toolkit GHCR (#1403)
## Summary - Point the shell installer at the publicly readable Toolkit GHCR nightly manifest and blobs. - Fail clearly on token and manifest transport errors; never fall back to legacy GHCR for those failures. - Cover direct and redirected blob downloads plus both failure paths in the installer tests. ## Verification - Live isolated stable-to-nightly upgrade: `0.46.0` → `0.47.0-dev.1791182867` from Toolkit GHCR. - Root `pnpm run tsc`, root and CLI lint, generated-file checks, and CLI tests (10,257 passed, 16 skipped) passed on current `main`. - Focused installer/upgrade tests: 362 passed; Cloudflare tests: 431 passed separately. - Aggregate `pnpm run test` timed out after 15 minutes while Cloudflare tests ran; other package summaries passed. Exact-head CI will verify the aggregate gate. Co-authored-by: GPT-6 Sol <agent@openai.com>
1 parent cb83fe1 commit 7cf4a47

2 files changed

Lines changed: 55 additions & 6 deletions

File tree

‎packages/cli/install‎

Lines changed: 10 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -202,18 +202,22 @@ if [[ "$requested_version" == "nightly" ]]; then
202202
echo -e "${MUTED}Fetching nightly build from GHCR...${NC}"
203203

204204
# Step 1: Get anonymous pull token
205-
GHCR_TOKEN=$(curl -sf \
206-
"https://ghcr.io/token?scope=repository:getsentry/cli:pull" \
207-
| awk -F'"' '{for(i=1;i<=NF;i++) if($i=="token"){print $(i+2);exit}}')
205+
if ! GHCR_TOKEN=$(curl -sf \
206+
"https://ghcr.io/token?scope=repository:getsentry/toolkit:pull" \
207+
| awk -F'"' '{for(i=1;i<=NF;i++) if($i=="token"){print $(i+2);exit}}'); then
208+
die "Failed to get GHCR token" "ghcr-token"
209+
fi
208210
if [[ -z "$GHCR_TOKEN" ]]; then
209211
die "Failed to get GHCR token" "ghcr-token"
210212
fi
211213

212214
# Step 2: Fetch the OCI manifest for the :nightly tag
213-
MANIFEST=$(curl -sf \
215+
if ! MANIFEST=$(curl -sf \
214216
-H "Authorization: Bearer $GHCR_TOKEN" \
215217
-H "Accept: application/vnd.oci.image.manifest.v1+json" \
216-
"https://ghcr.io/v2/getsentry/cli/manifests/nightly")
218+
"https://ghcr.io/v2/getsentry/toolkit/manifests/nightly"); then
219+
die "Failed to fetch nightly manifest from GHCR" "ghcr-manifest"
220+
fi
217221
if [[ -z "$MANIFEST" ]]; then
218222
die "Failed to fetch nightly manifest from GHCR" "ghcr-manifest"
219223
fi
@@ -248,7 +252,7 @@ if [[ "$requested_version" == "nightly" ]]; then
248252
# the redirect target.
249253
if ! blob_status=$(curl -sS -D "$blob_headers" -o "$blob_file" -w '%{http_code}' \
250254
-H "Authorization: Bearer $GHCR_TOKEN" \
251-
"https://ghcr.io/v2/getsentry/cli/blobs/${digest}"); then
255+
"https://ghcr.io/v2/getsentry/toolkit/blobs/${digest}"); then
252256
die "Failed to fetch nightly blob from GHCR" "ghcr-blob"
253257
fi
254258

‎packages/cli/test/lib/install-script.test.ts‎

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -287,11 +287,18 @@ esac
287287
`#!/usr/bin/env bash
288288
set -euo pipefail
289289
url="\${!#}"
290+
printf '%s\\n' "$url" >> "$SENTRY_TEST_DIR/curl-urls"
290291
case "$url" in
291292
*"/token?"*)
293+
if [[ "\${SENTRY_TEST_NIGHTLY_TOKEN_FAIL:-0}" != "0" ]]; then
294+
exit 22
295+
fi
292296
printf '{"token":"test-token"}'
293297
;;
294298
*"/manifests/nightly")
299+
if [[ "\${SENTRY_TEST_NIGHTLY_MANIFEST_FAIL:-0}" != "0" ]]; then
300+
exit 22
301+
fi
295302
cat <<'JSON'
296303
${manifest}
297304
JSON
@@ -450,6 +457,44 @@ process.exitCode = result.status ?? 1;
450457
]);
451458
expect(existsSync(join(installDir, "sentry"))).toBe(true);
452459
expect(installerTempFiles()).toEqual([]);
460+
expect(recorded("curl-urls").slice(0, 3)).toEqual([
461+
"https://ghcr.io/token?scope=repository:getsentry/toolkit:pull",
462+
"https://ghcr.io/v2/getsentry/toolkit/manifests/nightly",
463+
"https://ghcr.io/v2/getsentry/toolkit/blobs/sha256:test",
464+
]);
465+
});
466+
467+
test.each([
468+
{ failure: "token", flag: "SENTRY_TEST_NIGHTLY_TOKEN_FAIL" },
469+
{ failure: "manifest", flag: "SENTRY_TEST_NIGHTLY_MANIFEST_FAIL" },
470+
])("does not fall back to legacy GHCR when Toolkit $failure fails", ({
471+
flag,
472+
}) => {
473+
configureNightlyDownload(false);
474+
env[flag] = "1";
475+
const result = spawnSync("bash", [installScript, "--version", "nightly"], {
476+
env,
477+
encoding: "utf8",
478+
timeout: 10_000,
479+
});
480+
481+
expect(result.status).not.toBe(0);
482+
expect(result.stderr).toContain(
483+
flag === "SENTRY_TEST_NIGHTLY_TOKEN_FAIL"
484+
? "Failed to get GHCR token"
485+
: "Failed to fetch nightly manifest from GHCR"
486+
);
487+
expect(result.stderr).not.toContain("Unexpected failure at line");
488+
expect(recorded("curl-urls")).toEqual(
489+
flag === "SENTRY_TEST_NIGHTLY_TOKEN_FAIL"
490+
? ["https://ghcr.io/token?scope=repository:getsentry/toolkit:pull"]
491+
: [
492+
"https://ghcr.io/token?scope=repository:getsentry/toolkit:pull",
493+
"https://ghcr.io/v2/getsentry/toolkit/manifests/nightly",
494+
]
495+
);
496+
expect(recorded("setup-args")).toEqual([]);
497+
expect(existsSync(join(installDir, "sentry"))).toBe(false);
453498
});
454499

455500
test("uses the legacy release only after a Toolkit tag returns HTTP 404", () => {

0 commit comments

Comments
 (0)