Repository navigation
release: v1.21.18 (self-update token fix, terraphim-ai#3428) - #52
Conversation
…aphim-ai#3428) `terraphim-agent update` failed with a GitHub 403 even with GITHUB_TOKEN set, while `check-update` in the same shell succeeded: the verified install path (`update_with_verification` -> `get_latest_release_info`) built its own self_update builder and never applied the token. The auto-check (`check_for_updates_auto`, used by the REPL, terraphim-cli, startup and scheduler checks) still hard-coded the old `terraphim-ai` repository. - Add a private `GitHubSource` that builds every self_update GitHub builder (repo, hyphenated asset name, version, token, API URL, install path), so call sites can no longer drift. - Default repo comes from new `DEFAULT_REPO_OWNER`/`DEFAULT_REPO_NAME` constants (terraphim/terraphim-clients); the auto-check uses them. - `github_token_from_env()`: GITHUB_TOKEN, then GH_TOKEN; blank = unset. - 403 wording: only suggest setting a token when none was sent. - `UpdaterConfig::with_github_api_url` for GitHub Enterprise mirrors and local test servers. - Tests run against a real local HTTP server (no mocks) and assert the endpoint and Authorization header for check, update, verified update and auto-check paths. - Fix the feature-gated agent test that still expected `terraphim-ai`. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit ab57d348b378457d012e23ad283ec0b8bc778b05)
…fs terraphim/terraphim-ai#3428) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit 9e72917d0e82213fdf4b87cf6b8fa0007efa2e0b)
…loads (Refs terraphim/terraphim-ai#3428) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit 596e34091c777a56ce3f2624f343deb4512534ac)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Pre-merge review: PR
|
test_release_uses_checked_in_version_and_never_mutates_source pins the checked-in workspace version; move it with the 1.21.18 bump. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Pre-merge re-review: PR #52 at
|
| File | Change / status | Review result |
|---|---|---|
tests/test_release_binaries_workflow_contract.py |
Assertion updated from 1.21.17 to 1.21.18 at line 179 |
Correct and necessary for the checked-in workspace version |
tests/test_pkgbuild_release_contract.py |
No change in this PR; still enforces PKGBUILD pkgver == workspace version at line 151 |
Contract is valid; current failure is known pre-existing release sequencing debt |
pkgbuilds/terraphim-clients-bin/PKGBUILD |
No change in this PR; pkgver=1.21.16 at line 21 |
Acceptable as follow-up after v1.21.18 assets and digests exist |
Cargo.toml, Cargo.lock, crates/terraphim_update/src/lib.rs, crates/terraphim_update/tests/update_functionality_tests.rs |
Part of github/main...HEAD; previously reviewed at 4db4f42 with no issues |
No new concerns from the incremental diff |
Conclusion
No new P0/P1/P2 findings. The 1.21.18 assertion update is correct. The PKGBUILD mismatch should be fixed in a follow-up immediately after the v1.21.18 assets are published and their sha256sums are available; it is not release-blocking for this PR.
Author verification: agreed. The PKGBUILD contract failure is pre-existing on main (CI red on every commit since before v1.21.17), and it gets a follow-up PR bumping pkgver and sha256sums from the published v1.21.18 assets. Merging by rebase: branch protection requires linear history.
Release prep for v1.21.18: ships the self-update token fix (terraphim/terraphim-ai#3428, Gitea).
What
-x) the three commits of Gitea PR terraphim/terraphim-clients#353 (merged on Gitea asc7ae82033) onto the canonical GitHub line:52ba0aefix(update): send GitHub token on every API call8ee184etest(update): guard auto-check repo default and check 403 wordingc518198docs(update): github_api_url only affects API lookups, not asset downloads4db4f42chore: bump workspace version to 1.21.18. Same shape as chore: bump workspace version to 1.21.17 #40:Cargo.tomlplus 14Cargo.locklines.The fix:
terraphim-agent updatereturned a GitHub 403 even withGITHUB_TOKENset, because the verified-update release lookup never applied the token. The auto-check also still targeted the oldterraphim-airepo. All GitHub API calls now go through one builder that applies the repo, the token (GITHUB_TOKEN, thenGH_TOKEN) and the API URL. 12 new tests run against a real local HTTP server.Verification
crates/terraphim_update/src/lib.rs,crates/terraphim_agent/tests/update_functionality_tests.rs) are byte-identical to Giteamain.cargo test -p terraphim_update --lib: 151 passed.cargo clippy -p terraphim_update --all-targets -- -D warnings: clean.cargo build --release -p terraphim_agent -p terraphim_grep -p terraphim-cli: all three report1.21.18.TERRAPHIM_UPDATE_BACKEND=github):GITHUB_TOKEN:[OK] Already running latest version: 1.21.18;GitHub API rate limit exceeded. Set GITHUB_TOKEN (or GH_TOKEN) …, the new wording.After merge
Follow
docs/release-operator-checklist.md: tagv1.21.18at the merge commit, dispatchrelease-binaries.yml, inspect the sealed stage, obtain separate publication authorisation, then runscripts/promote-release.sh.Note: GitHub Actions currently has an open major-outage incident, so CI on this PR and the producer run may be delayed.
🤖 Generated with Claude Code