Skip to content

fix(storage): clean up superseded S3 packages - #25

Open
Keruspe wants to merge 1 commit into
premday:mainfrom
Keruspe:main
Open

fix(storage): clean up superseded S3 packages#25
Keruspe wants to merge 1 commit into
premday:mainfrom
Keruspe:main

Conversation

@Keruspe

@Keruspe Keruspe commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

Replace existing metadata releases when a rebuilt package has the same firmware filename and component ID. Scoping replacement to the component prevents unrelated packages with a shared basename from disappearing.

After metadata is committed, reconcile S3 CABs against its referenced locations. Running reconciliation on no-op refreshes retries transient deletion failures, while local repositories deliberately retain old CABs. Propagate save failures so callers can observe incomplete cleanup.

@Keruspe
Keruspe requested a review from Arno500 August 27, 2026 15:01
@Arno500

Arno500 commented Aug 27, 2026

Copy link
Copy Markdown
Collaborator

I specifically wanted initially to keep previous versions. In case of a supply chain attack, it seems better to not override old versions, and wait for a bump. I guess it should be a policy choice, or allow a one time override for specific cases

@Keruspe

Keruspe commented Aug 28, 2026

Copy link
Copy Markdown
Collaborator Author

Sure, I'll make this optional

With --s3.cleanup, replace existing metadata releases when a rebuilt package has the same firmware filename and component ID. Scoping replacement to the component prevents unrelated packages with a shared basename from disappearing.

After metadata is committed, reconcile S3 CABs against its referenced locations. No-op refreshes retry transient deletion failures, while local repositories deliberately retain old CABs. Surface metadata-save and cleanup failures when cleanup is requested.

Without the flag, preserve the previous append-only metadata behavior and retain all existing CAB objects. Log each superseded CAB that is left untouched so operators can see what cleanup would remove.

Co-Authored-By: GPT-5 <noreply@openai.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants