fix(firewall): pin sfw v1.15.2 and retry transient download failures - #17
Conversation
The pinned release was v1.15.0, and the checksum table only covers the pinned release, so `firewall-version` could not reach any other build: an explicit `1.15.2` downloaded that binary and then failed validation against the v1.15.0 hash. The Windows command-resolution fix released in v1.15.2 was therefore unreachable through this action. Downloads also had no retry beyond the three attempts `downloadTool` makes on its own, roughly 40 seconds against a single origin. A GitHub release-asset 504 outlives that and fails the whole job, which is what drove repeated CI re-runs. Attempts are now layered on top, skipping the 4xx codes that will not change on a retry.
Rename downloadWithRetry to downloadToolWithRetry, drop DOWNLOAD_MAX_ATTEMPTS in favor of DOWNLOAD_RETRY_DELAYS_SECONDS.length so the delay table alone sizes the retry budget, keep the timers/promises setTimeout under its own name, and spell out why 408 and 429 are the retryable 4xx codes.
CI hydrates the fleet payload before installing, and the current fleet pack ships hook workspace members the committed lockfile predates, so every job died on frozen-lockfile before running any code. Regenerated against the current pack.
The current fleet pack ships the optimizer at scripts/fleet/gen/svg/optimize.mts; the old svg-optimize.mts path is gone, so the repo-owned glyph test failed to import it on every CI run.
|
I'm working on the bucket mirror as a follow up |
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
The retry tests should assert the promised 30s/60s backoff delays.
Review effort: Lite
Findings: None
What changed in this PR
Updates Socket Firewall installation to pin v1.15.2 and retry transient asset-download failures.
Changes:
- Refreshes twelve v1.15.2 checksums.
- Adds layered retry handling.
- Rebuilds distributions, regenerates the lockfile, and updates the glyph optimizer import.
| File | Description |
|---|---|
test/unit/tools/firewall.test.mts |
Tests retry classification and behavior. Moderate (1 vote): does not assert the 30s/60s backoff delays. |
test/repo/unit/glyph.test.mts |
Updates the SVG optimizer module path. |
src/tools/firewall.js |
Pins the firewall release, refreshes checksums, and adds download retries. |
pnpm-lock.yaml |
Regenerates workspace dependency metadata. |
dist/post.js |
Rebuilt post-action bundle. |
dist/main.js |
Rebuilt action bundle. |
Files not reviewed (1)
- pnpm-lock.yaml: Generated file
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Record each stubbed sleep and pin the delays to 30s then 60s, so a change to the schedule fails a test instead of only changing a log line.
|
Andre Coetzee (Andre153)
left a comment
There was a problem hiding this comment.
Approving. Verified the six sfw-free v1.15.2 checksums against the digests GitHub publishes for the release; all match. The rebuilt dist carries the new pin, hashes, and retry path. Could not verify the six enterprise hashes from my side (private repo), so someone with firewall-release access should spot-check one.
Two problems with how the action installs the firewall binary.
The pin was
v1.15.0and the checksum table only covers the pinned release, so no other version was installable:firewall-version: 1.15.2downloaded that binary and then failed validation against the v1.15.0 hash, whilelatestquietly resolved to the pin rather than the newest release. This bumps the pin tov1.15.2and recomputes all twelve checksums from the published assets.Downloads also had no retry beyond the three attempts
downloadToolmakes internally, roughly 40 seconds against a single origin. A 504 from GitHub release assets outlives that and fails the whole job.downloadToolWithRetrynow layers attempts on top, one more than the delay table has entries (30s then 60s), skipping the 4xx codes that will not change on a retry (408 and 429 stay retryable).dist/is rebuilt, which also clears the standingcheck: distfailure on main.The lockfile is regenerated against the current fleet pack: CI hydrates the fleet payload before installing, and the pack ships hook workspace members the committed lockfile predated, so every job died on frozen-lockfile before running any code.
The repo-owned glyph test also follows the fleet payload's svg optimizer module move.
ci: gates' Check job stays red on remaining cascade-managed drift (a fleet hook importing a symbol the committed.git-hooksbundle keeps private) that predates this branch and resolves with the next wheelhouse cascade.Note
Medium Risk
Changes how CI jobs fetch and verify the firewall binary (pinned hashes and download retry behavior); a wrong pin or retry bug could block installs or delay jobs, but checksum validation still gates execution.
Overview
Pins the Socket Firewall binary to
v1.15.2and refreshes all twelve enterprise/free SHA256 checksums so default installs and checksum validation match the published release (fixing mismatches when jobs requested newer versions against the oldv1.15.0table).Adds resilient release-asset downloads via
downloadToolWithRetry: extra attempts afterdownloadTool's built-in retries, with 30s/60s backoff usingnode:timers/promises,isRetryableDownloadError(5xx/408/429 and network-style errors; not 404/403), and unit tests with mockeddownloadTooland sleep.Rebuilds
dist/main.js/dist/post.js(including bundled@socketsecurity/libpath/platform/fs primordial refactors from the build). Regeneratespnpm-lock.yamlfor current fleet hook workspaces. Updates the glyph unit test to import the fleet SVG optimizer from its new module path.Reviewed by Cursor Bugbot for commit a3a51c3. Configure here.