Generate local metadata even when not publishing. (#116087)

* Generate local metadata even when not publishing.

For SLSA compliance we need to separate the fetch, compile and upload
steps of release artifacts. Translating this to the packaging workflows
the fetch step will checkout the prepare_package script at main ToT, the
compile step generate the bundle archives and the recipes will upload
the artifact bundles as part of the upload stage.

This change adds functionality to generate both the release bundle and
the updated metadata file in a way that both files can be uploaded as
part of the upload stage.

Bug: https://github.com/flutter/flutter/issues/115487

* Address comments.

* Update tests.
This commit is contained in:
godofredoc 2022-11-28 20:14:24 -08:00 committed by GitHub
parent a2fd688091
commit 61376de9b8
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
2 changed files with 32 additions and 13 deletions

View file

@ -637,6 +637,12 @@ class ArchivePublisher {
dest: destGsPath, dest: destGsPath,
); );
assert(tempDir.existsSync()); assert(tempDir.existsSync());
final String gcsPath = '$gsReleaseFolder/${getMetadataFilename(platform)}';
await _publishMetadata(gcsPath);
}
/// Downloads and updates the metadata file without publishing it.
Future<void> generateLocalMetadata() async {
await _updateMetadata('$gsReleaseFolder/${getMetadataFilename(platform)}'); await _updateMetadata('$gsReleaseFolder/${getMetadataFilename(platform)}');
} }
@ -705,6 +711,13 @@ class ArchivePublisher {
const JsonEncoder encoder = JsonEncoder.withIndent(' '); const JsonEncoder encoder = JsonEncoder.withIndent(' ');
metadataFile.writeAsStringSync(encoder.convert(jsonData)); metadataFile.writeAsStringSync(encoder.convert(jsonData));
}
/// Publishes the metadata file to GCS.
Future<void> _publishMetadata(String gsPath) async {
final File metadataFile = File(
path.join(tempDir.absolute.path, getMetadataFilename(platform)),
);
await _cloudCopy( await _cloudCopy(
src: metadataFile.absolute.path, src: metadataFile.absolute.path,
dest: gsPath, dest: gsPath,
@ -899,15 +912,16 @@ Future<void> main(List<String> rawArguments) async {
try { try {
final Map<String, String> version = await creator.initializeRepo(); final Map<String, String> version = await creator.initializeRepo();
final File outputFile = await creator.createArchive(); final File outputFile = await creator.createArchive();
final ArchivePublisher publisher = ArchivePublisher(
tempDir,
revision,
branch,
version,
outputFile,
dryRun,
);
await publisher.generateLocalMetadata();
if (parsedArguments['publish'] as bool) { if (parsedArguments['publish'] as bool) {
final ArchivePublisher publisher = ArchivePublisher(
tempDir,
revision,
branch,
version,
outputFile,
dryRun,
);
await publisher.publishArchive(parsedArguments['force'] as bool); await publisher.publishArchive(parsedArguments['force'] as bool);
} }
} on PreparePackageException catch (e) { } on PreparePackageException catch (e) {

View file

@ -434,10 +434,10 @@ void main() {
File(archivePath).writeAsStringSync('archive contents'); File(archivePath).writeAsStringSync('archive contents');
final Map<String, List<ProcessResult>?> calls = <String, List<ProcessResult>?>{ final Map<String, List<ProcessResult>?> calls = <String, List<ProcessResult>?>{
// This process fails because the file does NOT already exist // This process fails because the file does NOT already exist
'$gsutilCall -- cp $gsJsonPath $jsonPath': null,
'$gsutilCall -- stat $gsArchivePath': <ProcessResult>[ProcessResult(0, 1, '', '')], '$gsutilCall -- stat $gsArchivePath': <ProcessResult>[ProcessResult(0, 1, '', '')],
'$gsutilCall -- rm $gsArchivePath': null, '$gsutilCall -- rm $gsArchivePath': null,
'$gsutilCall -- -h Content-Type:$archiveMime cp $archivePath $gsArchivePath': null, '$gsutilCall -- -h Content-Type:$archiveMime cp $archivePath $gsArchivePath': null,
'$gsutilCall -- cp $gsJsonPath $jsonPath': null,
'$gsutilCall -- rm $gsJsonPath': null, '$gsutilCall -- rm $gsJsonPath': null,
'$gsutilCall -- -h Content-Type:application/json -h Cache-Control:max-age=60 cp $jsonPath $gsJsonPath': null, '$gsutilCall -- -h Content-Type:application/json -h Cache-Control:max-age=60 cp $jsonPath $gsJsonPath': null,
}; };
@ -461,6 +461,7 @@ void main() {
platform: platform, platform: platform,
); );
assert(tempDir.existsSync()); assert(tempDir.existsSync());
await publisher.generateLocalMetadata();
await publisher.publishArchive(); await publisher.publishArchive();
final File releaseFile = File(jsonPath); final File releaseFile = File(jsonPath);
@ -534,10 +535,10 @@ void main() {
File(archivePath).writeAsStringSync('archive contents'); File(archivePath).writeAsStringSync('archive contents');
final Map<String, List<ProcessResult>?> calls = <String, List<ProcessResult>?>{ final Map<String, List<ProcessResult>?> calls = <String, List<ProcessResult>?>{
// This process fails because the file does NOT already exist // This process fails because the file does NOT already exist
'$gsutilCall -- cp $gsJsonPath $jsonPath': null,
'$gsutilCall -- stat $gsArchivePath': <ProcessResult>[ProcessResult(0, 1, '', '')], '$gsutilCall -- stat $gsArchivePath': <ProcessResult>[ProcessResult(0, 1, '', '')],
'$gsutilCall -- rm $gsArchivePath': null, '$gsutilCall -- rm $gsArchivePath': null,
'$gsutilCall -- -h Content-Type:$archiveMime cp $archivePath $gsArchivePath': null, '$gsutilCall -- -h Content-Type:$archiveMime cp $archivePath $gsArchivePath': null,
'$gsutilCall -- cp $gsJsonPath $jsonPath': null,
'$gsutilCall -- rm $gsJsonPath': null, '$gsutilCall -- rm $gsJsonPath': null,
'$gsutilCall -- -h Content-Type:application/json -h Cache-Control:max-age=60 cp $jsonPath $gsJsonPath': null, '$gsutilCall -- -h Content-Type:application/json -h Cache-Control:max-age=60 cp $jsonPath $gsJsonPath': null,
}; };
@ -561,6 +562,7 @@ void main() {
platform: platform, platform: platform,
); );
assert(tempDir.existsSync()); assert(tempDir.existsSync());
await publisher.generateLocalMetadata();
await publisher.publishArchive(); await publisher.publishArchive();
final File releaseFile = File(jsonPath); final File releaseFile = File(jsonPath);
@ -598,10 +600,10 @@ void main() {
File(archivePath).writeAsStringSync('archive contents'); File(archivePath).writeAsStringSync('archive contents');
final Map<String, List<ProcessResult>?> calls = <String, List<ProcessResult>?>{ final Map<String, List<ProcessResult>?> calls = <String, List<ProcessResult>?>{
// This process fails because the file does NOT already exist // This process fails because the file does NOT already exist
'$gsutilCall -- cp $gsJsonPath $jsonPath': null,
'$gsutilCall -- stat $gsArchivePath': <ProcessResult>[ProcessResult(0, 1, '', '')], '$gsutilCall -- stat $gsArchivePath': <ProcessResult>[ProcessResult(0, 1, '', '')],
'$gsutilCall -- rm $gsArchivePath': null, '$gsutilCall -- rm $gsArchivePath': null,
'$gsutilCall -- -h Content-Type:$archiveMime cp $archivePath $gsArchivePath': null, '$gsutilCall -- -h Content-Type:$archiveMime cp $archivePath $gsArchivePath': null,
'$gsutilCall -- cp $gsJsonPath $jsonPath': null,
'$gsutilCall -- rm $gsJsonPath': null, '$gsutilCall -- rm $gsJsonPath': null,
'$gsutilCall -- -h Content-Type:application/json -h Cache-Control:max-age=60 cp $jsonPath $gsJsonPath': null, '$gsutilCall -- -h Content-Type:application/json -h Cache-Control:max-age=60 cp $jsonPath $gsJsonPath': null,
}; };
@ -625,6 +627,7 @@ void main() {
platform: platform, platform: platform,
); );
assert(tempDir.existsSync()); assert(tempDir.existsSync());
await publisher.generateLocalMetadata();
await publisher.publishArchive(); await publisher.publishArchive();
final File releaseFile = File(jsonPath); final File releaseFile = File(jsonPath);
@ -678,10 +681,10 @@ void main() {
File(archivePath).writeAsStringSync('archive contents'); File(archivePath).writeAsStringSync('archive contents');
final Map<String, List<ProcessResult>?> calls = <String, List<ProcessResult>?>{ final Map<String, List<ProcessResult>?> calls = <String, List<ProcessResult>?>{
// This process fails because the file does NOT already exist // This process fails because the file does NOT already exist
'$gsutilCall -- cp $gsJsonPath $jsonPath': null,
'$gsutilCall -- stat $gsArchivePath': <ProcessResult>[ProcessResult(0, 1, '', '')], '$gsutilCall -- stat $gsArchivePath': <ProcessResult>[ProcessResult(0, 1, '', '')],
'$gsutilCall -- rm $gsArchivePath': null, '$gsutilCall -- rm $gsArchivePath': null,
'$gsutilCall -- -h Content-Type:$archiveMime cp $archivePath $gsArchivePath': null, '$gsutilCall -- -h Content-Type:$archiveMime cp $archivePath $gsArchivePath': null,
'$gsutilCall -- cp $gsJsonPath $jsonPath': null,
'$gsutilCall -- rm $gsJsonPath': null, '$gsutilCall -- rm $gsJsonPath': null,
'$gsutilCall -- -h Content-Type:application/json -h Cache-Control:max-age=60 cp $jsonPath $gsJsonPath': null, '$gsutilCall -- -h Content-Type:application/json -h Cache-Control:max-age=60 cp $jsonPath $gsJsonPath': null,
}; };
@ -705,6 +708,7 @@ void main() {
platform: platform, platform: platform,
); );
assert(tempDir.existsSync()); assert(tempDir.existsSync());
await publisher.generateLocalMetadata();
await publisher.publishArchive(); await publisher.publishArchive();
final File releaseFile = File(jsonPath); final File releaseFile = File(jsonPath);
@ -799,14 +803,15 @@ void main() {
File(jsonPath).writeAsStringSync(releasesJson); File(jsonPath).writeAsStringSync(releasesJson);
File(archivePath).writeAsStringSync('archive contents'); File(archivePath).writeAsStringSync('archive contents');
final Map<String, List<ProcessResult>?> calls = <String, List<ProcessResult>?>{ final Map<String, List<ProcessResult>?> calls = <String, List<ProcessResult>?>{
'$gsutilCall -- cp $gsJsonPath $jsonPath': null,
'$gsutilCall -- rm $gsArchivePath': null, '$gsutilCall -- rm $gsArchivePath': null,
'$gsutilCall -- -h Content-Type:$archiveMime cp $archivePath $gsArchivePath': null, '$gsutilCall -- -h Content-Type:$archiveMime cp $archivePath $gsArchivePath': null,
'$gsutilCall -- cp $gsJsonPath $jsonPath': null,
'$gsutilCall -- rm $gsJsonPath': null, '$gsutilCall -- rm $gsJsonPath': null,
'$gsutilCall -- -h Content-Type:application/json -h Cache-Control:max-age=60 cp $jsonPath $gsJsonPath': null, '$gsutilCall -- -h Content-Type:application/json -h Cache-Control:max-age=60 cp $jsonPath $gsJsonPath': null,
}; };
processManager.addCommands(convertResults(calls)); processManager.addCommands(convertResults(calls));
assert(tempDir.existsSync()); assert(tempDir.existsSync());
await publisher.generateLocalMetadata();
await publisher.publishArchive(true); await publisher.publishArchive(true);
}); });
}); });