Skip to content

fix(firewall): pin sfw v1.15.2 and retry transient download failures - #17

Merged
Julian Gruber (juliangruber) merged 5 commits into
mainfrom
ruxandrafediuc/bump-sfw-1.15.2-and-download-retry
Sep 23, 2026
Merged

Julian Gruber (juliangruber) merged 5 commits into
mainfrom
ruxandrafediuc/bump-sfw-1.15.2-and-download-retry

Conversation

@ruxandrafed

@ruxandrafed Ruxandra Fediuc (ruxandrafed) commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Two problems with how the action installs the firewall binary.

The pin was v1.15.0 and the checksum table only covers the pinned release, so no other version was installable: firewall-version: 1.15.2 downloaded that binary and then failed validation against the v1.15.0 hash, while latest quietly resolved to the pin rather than the newest release. This bumps the pin to v1.15.2 and recomputes all twelve checksums from the published assets.

Downloads also had no retry beyond the three attempts downloadTool makes internally, roughly 40 seconds against a single origin. A 504 from GitHub release assets outlives that and fails the whole job. downloadToolWithRetry now layers attempts on top, one more than the delay table has entries (30s then 60s), skipping the 4xx codes that will not change on a retry (408 and 429 stay retryable).

dist/ is rebuilt, which also clears the standing check: dist failure on main.

The lockfile is regenerated against the current fleet pack: CI hydrates the fleet payload before installing, and the pack ships hook workspace members the committed lockfile predated, so every job died on frozen-lockfile before running any code.

The repo-owned glyph test also follows the fleet payload's svg optimizer module move. ci: gates' Check job stays red on remaining cascade-managed drift (a fleet hook importing a symbol the committed .git-hooks bundle keeps private) that predates this branch and resolves with the next wheelhouse cascade.


Note

Medium Risk
Changes how CI jobs fetch and verify the firewall binary (pinned hashes and download retry behavior); a wrong pin or retry bug could block installs or delay jobs, but checksum validation still gates execution.

Overview
Pins the Socket Firewall binary to v1.15.2 and refreshes all twelve enterprise/free SHA256 checksums so default installs and checksum validation match the published release (fixing mismatches when jobs requested newer versions against the old v1.15.0 table).

Adds resilient release-asset downloads via downloadToolWithRetry: extra attempts after downloadTool's built-in retries, with 30s/60s backoff using node:timers/promises, isRetryableDownloadError (5xx/408/429 and network-style errors; not 404/403), and unit tests with mocked downloadTool and sleep.

Rebuilds dist/main.js / dist/post.js (including bundled @socketsecurity/lib path/platform/fs primordial refactors from the build). Regenerates pnpm-lock.yaml for current fleet hook workspaces. Updates the glyph unit test to import the fleet SVG optimizer from its new module path.

Reviewed by Cursor Bugbot for commit a3a51c3. Configure here.

The pinned release was v1.15.0, and the checksum table only covers the
pinned release, so `firewall-version` could not reach any other build:
an explicit `1.15.2` downloaded that binary and then failed validation
against the v1.15.0 hash. The Windows command-resolution fix released in
v1.15.2 was therefore unreachable through this action.

Downloads also had no retry beyond the three attempts `downloadTool`
makes on its own, roughly 40 seconds against a single origin. A GitHub
release-asset 504 outlives that and fails the whole job, which is what
drove repeated CI re-runs. Attempts are now layered on top, skipping the
4xx codes that will not change on a retry.
Rename downloadWithRetry to downloadToolWithRetry, drop
DOWNLOAD_MAX_ATTEMPTS in favor of DOWNLOAD_RETRY_DELAYS_SECONDS.length
so the delay table alone sizes the retry budget, keep the
timers/promises setTimeout under its own name, and spell out why 408
and 429 are the retryable 4xx codes.
CI hydrates the fleet payload before installing, and the current fleet
pack ships hook workspace members the committed lockfile predates, so
every job died on frozen-lockfile before running any code. Regenerated
against the current pack.
The current fleet pack ships the optimizer at
scripts/fleet/gen/svg/optimize.mts; the old svg-optimize.mts path is
gone, so the repo-owned glyph test failed to import it on every CI
run.
@juliangruber
Julian Gruber (juliangruber) marked this pull request as ready for review September 22, 2026 08:24
@juliangruber

Copy link
Copy Markdown
Member

I'm working on the bucket mirror as a follow up

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The retry tests should assert the promised 30s/60s backoff delays.

Review effort: Lite
Findings: None

What changed in this PR

Updates Socket Firewall installation to pin v1.15.2 and retry transient asset-download failures.

Changes:

  • Refreshes twelve v1.15.2 checksums.
  • Adds layered retry handling.
  • Rebuilds distributions, regenerates the lockfile, and updates the glyph optimizer import.
File Description
test/​unit/​tools/​firewall.test.mts Tests retry classification and behavior. Moderate (1 vote): does not assert the 30s/60s backoff delays.
test/​repo/​unit/​glyph.test.mts Updates the SVG optimizer module path.
src/​tools/​firewall.js Pins the firewall release, refreshes checksums, and adds download retries.
pnpm-lock.yaml Regenerates workspace dependency metadata.
dist/​post.js Rebuilt post-action bundle.
dist/​main.js Rebuilt action bundle.
Files not reviewed (1)
  • pnpm-lock.yaml: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Record each stubbed sleep and pin the delays to 30s then 60s, so a
change to the schedule fails a test instead of only changing a log
line.
@juliangruber

Copy link
Copy Markdown
Member

The retry tests should assert the promised 30s/60s backoff delays.

c817d31

@Andre153 Andre Coetzee (Andre153) left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approving. Verified the six sfw-free v1.15.2 checksums against the digests GitHub publishes for the release; all match. The rebuilt dist carries the new pin, hashes, and retry path. Could not verify the six enterprise hashes from my side (private repo), so someone with firewall-release access should spot-check one.

@juliangruber
Julian Gruber (juliangruber) merged commit 401464a into main Sep 23, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants