fix(storage): clean up superseded S3 packages - #25
Open
Keruspe wants to merge 1 commit into
Open
Conversation
Collaborator
|
I specifically wanted initially to keep previous versions. In case of a supply chain attack, it seems better to not override old versions, and wait for a bump. I guess it should be a policy choice, or allow a one time override for specific cases |
Collaborator
Author
|
Sure, I'll make this optional |
With --s3.cleanup, replace existing metadata releases when a rebuilt package has the same firmware filename and component ID. Scoping replacement to the component prevents unrelated packages with a shared basename from disappearing. After metadata is committed, reconcile S3 CABs against its referenced locations. No-op refreshes retry transient deletion failures, while local repositories deliberately retain old CABs. Surface metadata-save and cleanup failures when cleanup is requested. Without the flag, preserve the previous append-only metadata behavior and retain all existing CAB objects. Log each superseded CAB that is left untouched so operators can see what cleanup would remove. Co-Authored-By: GPT-5 <noreply@openai.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replace existing metadata releases when a rebuilt package has the same firmware filename and component ID. Scoping replacement to the component prevents unrelated packages with a shared basename from disappearing.
After metadata is committed, reconcile S3 CABs against its referenced locations. Running reconciliation on no-op refreshes retries transient deletion failures, while local repositories deliberately retain old CABs. Propagate save failures so callers can observe incomplete cleanup.