[difftrain] Fix broken workflow (#26421)
Seems like CircleCI now enforces passing a token when fetching artifacts. I provisioned a new read-only CircleCI token just for difftrain. test plan: see https://github.com/facebook/react/actions/runs/4450679268
lauren committed
Mar 17, 2023 at 15:16 UTC
6854a3cf6d0e980f93a5e8ee1e546e3e31ac0869
1 file changed
+13
-3
.github/workflows/commit_artifacts.yml
+13
-3
@@ -10,6 +10,8 @@ jobs:
10
steps:
11
- name: Download and unzip artifacts
12
uses: actions/github-script@v6
13
+ env:
14
+ CIRCLECI_TOKEN: ${{secrets.CIRCLECI_TOKEN_DIFFTRAIN}}
15
with:
16
script: |
17
const cp = require('child_process');
@@ -58,10 +60,10 @@ jobs:
60
const ciBuildId = /\/facebook\/react\/([0-9]+)/.exec(
61
status.target_url,
62
)[1];
61
- console.log(`CircleCI build id found: ${ciBuildId}`);
63
if (Number.parseInt(ciBuildId, 10) + '' === ciBuildId) {
64
artifactsUrl =
65
`https://circleci.com/api/v1.1/project/github/facebook/react/${ciBuildId}/artifacts`;
66
+ console.log(`Found artifactsUrl: ${artifactsUrl}`);
67
break spinloop;
68
} else {
69
throw new Error(`${ciBuildId} isn't a number`);
@@ -80,13 +82,21 @@ jobs:
82
await sleep(60_000);
83
}
84
if (artifactsUrl != null) {
83
- const res = await fetch(artifactsUrl);
85
+ const {CIRCLECI_TOKEN} = process.env;
86
+ const res = await fetch(artifactsUrl, {
87
+ headers: {
88
+ 'Circle-Token': CIRCLECI_TOKEN
89
+ }
90
+ });
91
const data = await res.json();
92
+ if (!Array.isArray(data) && data.message != null) {
93
+ throw `CircleCI returned: ${data.message}`;
94
+ }
95
for (const artifact of data) {
96
if (artifact.path === 'build.tgz') {
97
console.log(`Downloading and unzipping ${artifact.url}`);
98
await execHelper(
89
- `curl -L ${artifact.url} | tar -xvz`
99
+ `curl -L ${artifact.url} -H "Circle-Token: ${CIRCLECI_TOKEN}" | tar -xvz`
100
);
101
}
102
}