@samitouri / QOS-React-2 / commits / 6854a3cf6d

[difftrain] Fix broken workflow (#26421)

Seems like CircleCI now enforces passing a token when fetching artifacts. I provisioned a new read-only CircleCI token just for difftrain. test plan: see https://github.com/facebook/react/actions/runs/4450679268

lauren committed Mar 17, 2023 at 15:16 UTC 6854a3cf6d0e980f93a5e8ee1e546e3e31ac0869
1 file changed +13 -3
.github/workflows/commit_artifacts.yml
+13 -3
@@ -10,6 +10,8 @@ jobs:
10 steps:
11 - name: Download and unzip artifacts
12 uses: actions/github-script@v6
13 + env:
14 + CIRCLECI_TOKEN: ${{secrets.CIRCLECI_TOKEN_DIFFTRAIN}}
15 with:
16 script: |
17 const cp = require('child_process');
@@ -58,10 +60,10 @@ jobs:
60 const ciBuildId = /\/facebook\/react\/([0-9]+)/.exec(
61 status.target_url,
62 )[1];
61 - console.log(`CircleCI build id found: ${ciBuildId}`);
63 if (Number.parseInt(ciBuildId, 10) + '' === ciBuildId) {
64 artifactsUrl =
65 `https://circleci.com/api/v1.1/project/github/facebook/react/${ciBuildId}/artifacts`;
66 + console.log(`Found artifactsUrl: ${artifactsUrl}`);
67 break spinloop;
68 } else {
69 throw new Error(`${ciBuildId} isn't a number`);
@@ -80,13 +82,21 @@ jobs:
82 await sleep(60_000);
83 }
84 if (artifactsUrl != null) {
83 - const res = await fetch(artifactsUrl);
85 + const {CIRCLECI_TOKEN} = process.env;
86 + const res = await fetch(artifactsUrl, {
87 + headers: {
88 + 'Circle-Token': CIRCLECI_TOKEN
89 + }
90 + });
91 const data = await res.json();
92 + if (!Array.isArray(data) && data.message != null) {
93 + throw `CircleCI returned: ${data.message}`;
94 + }
95 for (const artifact of data) {
96 if (artifact.path === 'build.tgz') {
97 console.log(`Downloading and unzipping ${artifact.url}`);
98 await execHelper(
89 - `curl -L ${artifact.url} | tar -xvz`
99 + `curl -L ${artifact.url} -H "Circle-Token: ${CIRCLECI_TOKEN}" | tar -xvz`
100 );
101 }
102 }