Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 10 additions & 6 deletions packages/cli/install
Original file line number Diff line number Diff line change
Expand Up @@ -202,18 +202,22 @@ if [[ "$requested_version" == "nightly" ]]; then
echo -e "${MUTED}Fetching nightly build from GHCR...${NC}"

# Step 1: Get anonymous pull token
GHCR_TOKEN=$(curl -sf \
"https://ghcr.io/token?scope=repository:getsentry/cli:pull" \
| awk -F'"' '{for(i=1;i<=NF;i++) if($i=="token"){print $(i+2);exit}}')
if ! GHCR_TOKEN=$(curl -sf \
"https://ghcr.io/token?scope=repository:getsentry/toolkit:pull" \
| awk -F'"' '{for(i=1;i<=NF;i++) if($i=="token"){print $(i+2);exit}}'); then
die "Failed to get GHCR token" "ghcr-token"
fi
if [[ -z "$GHCR_TOKEN" ]]; then
die "Failed to get GHCR token" "ghcr-token"
fi

# Step 2: Fetch the OCI manifest for the :nightly tag
MANIFEST=$(curl -sf \
if ! MANIFEST=$(curl -sf \
-H "Authorization: Bearer $GHCR_TOKEN" \
-H "Accept: application/vnd.oci.image.manifest.v1+json" \
"https://ghcr.io/v2/getsentry/cli/manifests/nightly")
"https://ghcr.io/v2/getsentry/toolkit/manifests/nightly"); then
die "Failed to fetch nightly manifest from GHCR" "ghcr-manifest"
fi
if [[ -z "$MANIFEST" ]]; then
die "Failed to fetch nightly manifest from GHCR" "ghcr-manifest"
fi
Expand Down Expand Up @@ -248,7 +252,7 @@ if [[ "$requested_version" == "nightly" ]]; then
# the redirect target.
if ! blob_status=$(curl -sS -D "$blob_headers" -o "$blob_file" -w '%{http_code}' \
-H "Authorization: Bearer $GHCR_TOKEN" \
"https://ghcr.io/v2/getsentry/cli/blobs/${digest}"); then
"https://ghcr.io/v2/getsentry/toolkit/blobs/${digest}"); then
die "Failed to fetch nightly blob from GHCR" "ghcr-blob"
fi

Expand Down
45 changes: 45 additions & 0 deletions packages/cli/test/lib/install-script.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -287,11 +287,18 @@ esac
`#!/usr/bin/env bash
set -euo pipefail
url="\${!#}"
printf '%s\\n' "$url" >> "$SENTRY_TEST_DIR/curl-urls"
case "$url" in
*"/token?"*)
if [[ "\${SENTRY_TEST_NIGHTLY_TOKEN_FAIL:-0}" != "0" ]]; then
exit 22
fi
printf '{"token":"test-token"}'
;;
*"/manifests/nightly")
if [[ "\${SENTRY_TEST_NIGHTLY_MANIFEST_FAIL:-0}" != "0" ]]; then
exit 22
fi
cat <<'JSON'
${manifest}
JSON
Expand Down Expand Up @@ -450,6 +457,44 @@ process.exitCode = result.status ?? 1;
]);
expect(existsSync(join(installDir, "sentry"))).toBe(true);
expect(installerTempFiles()).toEqual([]);
expect(recorded("curl-urls").slice(0, 3)).toEqual([
"https://ghcr.io/token?scope=repository:getsentry/toolkit:pull",
"https://ghcr.io/v2/getsentry/toolkit/manifests/nightly",
"https://ghcr.io/v2/getsentry/toolkit/blobs/sha256:test",
]);
});

test.each([
{ failure: "token", flag: "SENTRY_TEST_NIGHTLY_TOKEN_FAIL" },
{ failure: "manifest", flag: "SENTRY_TEST_NIGHTLY_MANIFEST_FAIL" },
])("does not fall back to legacy GHCR when Toolkit $failure fails", ({
flag,
}) => {
configureNightlyDownload(false);
env[flag] = "1";
const result = spawnSync("bash", [installScript, "--version", "nightly"], {
env,
encoding: "utf8",
timeout: 10_000,
});

expect(result.status).not.toBe(0);
expect(result.stderr).toContain(
flag === "SENTRY_TEST_NIGHTLY_TOKEN_FAIL"
? "Failed to get GHCR token"
: "Failed to fetch nightly manifest from GHCR"
);
expect(result.stderr).not.toContain("Unexpected failure at line");
expect(recorded("curl-urls")).toEqual(
flag === "SENTRY_TEST_NIGHTLY_TOKEN_FAIL"
? ["https://ghcr.io/token?scope=repository:getsentry/toolkit:pull"]
: [
"https://ghcr.io/token?scope=repository:getsentry/toolkit:pull",
"https://ghcr.io/v2/getsentry/toolkit/manifests/nightly",
]
);
expect(recorded("setup-args")).toEqual([]);
expect(existsSync(join(installDir, "sentry"))).toBe(false);
});

test("uses the legacy release only after a Toolkit tag returns HTTP 404", () => {
Expand Down
Loading