From 6acb991891f2ecc2c970188cb4220d0a2d1d4654 Mon Sep 17 00:00:00 2001 From: Teakowa <27560638+Teakowa@users.noreply.github.com> Date: Mon, 28 Sep 2026 15:24:11 +0800 Subject: [PATCH] fix(release): verify R2 objects over HTTP/2 --- docs/release.md | 2 +- scripts/publish-r2.sh | 6 +++--- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/release.md b/docs/release.md index 4fa04d1..4422564 100644 --- a/docs/release.md +++ b/docs/release.md @@ -148,7 +148,7 @@ https://install.wrightkit.dev/wright/install.ps1 The publisher takes both files from the exact release commit, uploads them after verifying the immutable archive/checksum set, and fetches them back over -HTTP/1.1 to compare their bytes and check their response headers. Each script +HTTP/2 to compare their bytes and check their response headers. Each script uses `Cache-Control: no-store, max-age=0` and `Content-Type: text/plain; charset=utf-8`. The scripts are verified before the stable `latest/version` pointer advances. Nightly publication does not change diff --git a/scripts/publish-r2.sh b/scripts/publish-r2.sh index a10a2ca..22e1505 100755 --- a/scripts/publish-r2.sh +++ b/scripts/publish-r2.sh @@ -69,11 +69,11 @@ verify_public() { local base_url="$1" key="$2" source="$3" cache_pattern="$4" content_type_pattern="$5" local downloaded downloaded="$GITHUB_WORKSPACE/downloaded-$(basename "$key")" - curl --http1.1 --fail --silent --show-error --location --output "$downloaded" "$base_url/$key" + curl --http2 --fail --silent --show-error --location --output "$downloaded" "$base_url/$key" cmp --silent "$source" "$downloaded" - curl --http1.1 --fail --silent --show-error --head "$base_url/$key" | \ + curl --http2 --fail --silent --show-error --head "$base_url/$key" | \ grep --ignore-case --extended-regexp "^cache-control:.*$cache_pattern" >/dev/null - curl --http1.1 --fail --silent --show-error --head "$base_url/$key" | \ + curl --http2 --fail --silent --show-error --head "$base_url/$key" | \ grep --ignore-case --extended-regexp "^content-type:.*$content_type_pattern" >/dev/null rm -f "$downloaded" }