Commit

Drill: hash bundles as a stream, and read production as you are logged in

syntaqxcommitted Parentbd8816dBrowse files
1 file+12−70/1 viewed
+12−7
3030 // The live repository is read as G1T_USER with G1T_TOKEN (an access token
3131 // with code:read) when they are set, which private repositories need. The
3232 // database and the bucket are read through Wrangler, as you are logged in
33−// (`npx wrangler login`), or with CLOUDFLARE_DEPLOY_TOKEN.
33+// (`npx wrangler login`), or with CLOUDFLARE_DEPLOY_TOKEN when that is set.
3434
3535 import { createHash } from "node:crypto";
36−import { mkdtempSync, readFileSync, rmSync, statSync } from "node:fs";
36+import { createReadStream, mkdtempSync, readFileSync, rmSync, statSync } from "node:fs";
3737 import { tmpdir } from "node:os";
3838 import { join } from "node:path";
3939
5353 return out.trim();
5454 }
5555
56+/** A file's SHA-256, read as a stream: a bundle can be a gigabyte. */
57+async function sha256Of(file) {
58+ const hash = createHash("sha256");
59+ for await (const chunk of createReadStream(file)) hash.update(chunk);
60+ return hash.digest("hex");
61+}
62+
5663 /** `<hash> <name>` lines (for-each-ref) or `<hash>\t<name>` (ls-remote), as a map. Peeled tags are left out. */
5764 export function parseRefs(listing) {
5865 const refs = {};
111118 const size = statSync(file).size;
112119 if (size !== entry.size) throw new Error(`${entry.key}: ${size} bytes, the manifest says ${entry.size}`);
113120 if (entry.sha256) {
114− const sha256 = createHash("sha256").update(readFileSync(file)).digest("hex");
121+ const sha256 = await sha256Of(file);
115122 if (sha256 !== entry.sha256) throw new Error(`${entry.key}: SHA-256 ${sha256}, the manifest says ${entry.sha256}`);
116123 }
117124 await git(["bundle", "verify", "--quiet", file], { cwd: dir });
135142 // ---------------------------------------------------------------------
136143
137144 async function d1(sql) {
138− const env = { ...wranglerEnv({ ...process.env, CI: "true" }) };
139− if (!process.env.CLOUDFLARE_DEPLOY_TOKEN) env.CLOUDFLARE_API_TOKEN = "";
145+ const env = wranglerEnv();
140146 const { code, out } = await exec(process.execPath, [WRANGLER, "d1", "execute", DATABASE, "--remote", "--json", "--command", sql], {
141147 cwd: join(ROOT, "services/repos"),
142148 env,
175181 function bucketReader(localCopy) {
176182 if (localCopy) return async (key) => join(localCopy, key);
177183 return async (key, file) => {
178− const env = { ...wranglerEnv({ ...process.env, CI: "true" }) };
179− if (!process.env.CLOUDFLARE_DEPLOY_TOKEN) env.CLOUDFLARE_API_TOKEN = "";
184+ const env = wranglerEnv();
180185 const { code, out } = await exec(process.execPath, [WRANGLER, "r2", "object", "get", `${BUCKET}/${key}`, "--remote", "--file", file], { env });
181186 if (code !== 0) throw new Error(`${key} could not be read: ${out.slice(-400)}`);
182187 return file;