fix: restore diff/ tarball layout so existing installs can update - #1077
Merged
Merged
Conversation
helm plugin update runs the already-installed copy of install-binary.sh, which extracts the freshly downloaded release tarball and copies $HELM_TMP/diff/bin/diff into the plugin dir. The 3.15.14 layout change (wrapping content in a directory named after the archive, helm-diff-<os>- <arch>/) therefore broke helm plugin update on every pre-3.15.14 install with: cp: cannot stat '/tmp/helm-diff-*/diff/bin/diff': No such file or directory Fixes #1076. - .goreleaser.yml/Makefile: wrap archives in "diff/" again (the layout every released install/update hook expects) and, to keep the helm 4 local-tarball flow from #1071 working, publish each platform a second time under a versioned name, diff-<version>-<os>-<arch>.tgz. Helm 4 derives the directory it expects inside a locally installed tarball from its file name (it strips a -<version> component), so the versioned name resolves to diff/ while the historical name cannot. Both assets are byte-identical and each gets its own .prov signature (helm's verification matches file names against the checksums). - install-binary.sh/.ps1: no behavior change needed (they already support both layouts); comments updated to document the layout history. - release.yaml: smoke tests assert the diff/ layout and the two asset names; the helm 4 offline test installs the versioned archive; new regression test runs the exact v3.15.13 and v3.15.14 install hooks in update mode against the built archives (issue #1076). - README.md: offline/helm 4 install docs updated for the versioned asset. Verified locally: reproduced the #1076 failure with the real 3.15.14 asset, then confirmed both the v3.15.13 and v3.15.14 hooks update successfully from the new archives, and helm 4 installs + provenance- verifies the versioned tarball (Plugin Hash Verified). Signed-off-by: yxxhero <aiopsclub@163.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Fixes #1076 (without regressing #1071).
Root cause
helm plugin updateruns the already installed copy ofinstall-binary.sh(platformHooks.update→${HELM_PLUGIN_DIR}/install-binary.sh -u). Every hook released so far (checked v3.5.0 → v3.15.13) extracts the downloaded release tarball and copies"$HELM_TMP/diff/bin/diff"into the plugin dir. v3.15.14 (#1072) wrapped the release archives in a directory named after the archive (helm-diff-<os>-<arch>/) instead ofdiff/, so every pre-3.15.14 install now fails to update:Why not simply revert, or simply keep the new layout
diff/alone regresses Offline install not working in helm 4 unless you --verify=false #1071: helm 4'sLocalInstallerderives the directory it expects inside a locally installed tarball from the tarball file name (stripPluginNamestrips a trailing-<version>component, then it requires<name>/plugin.yaml).helm-diff-<os>-<arch>.tgzcan never satisfy that flow: the name carries no version component to strip, so helm 4 looks forhelm-diff-<os>-<arch>/plugin.yaml.diff/sibling) is not expressible in goreleaser (filescannot escape the wrap directory) and would double every archive's size.Fix
Wrap all archives in
diff/again — the layout every released hook expects — and publish each platform a second time under a versioned name,diff-<version>-<os>-<arch>.tgz:This satisfies, simultaneously:
helm plugin update diff(#1076)diff/bin/diffdiff/fallbackHELM_DIFF_BIN_TGZoffline flowdiff/derived from file namedetectPluginRoot)Each asset gets its own
.prov(goreleaser signs all archives; helm verification matches file names against the checksums in the.prov).Changes
.goreleaser.yml:wrap_in_directory: diff; newversionedarchive withdiff-{{ .Version }}-…name templateMakefile:dist-packagewraps indiff/and emits both asset names (byte-identical copies)install-binary.sh/install-binary.ps1: no behavior change (they already support both layouts — basename dir first, thendiff/fallback); comments updated to document the layout history.github/workflows/release.yaml:diff/layout for alldist/*.tgzand equal counts of legacy/versioned archivesdiff/--keyring)v3.15.13andv3.15.14install-binary.shin update mode against the built archives (direct regression test for v3.15.14 tarball layout change (diff/ → helm-diff-<os>-<arch>/) breakshelm plugin update difffor existing installs #1076)README.md: offline/helm 4 install docs updated to the versioned asset nameVerification (all local, on top of this branch)
helm plugin update difffor existing installs #1076 failure with the real v3.15.14helm-diff-macos-arm64.tgzand the v3.15.13 hookgoreleaser release --snapshot --clean --skip=sign(v1.26.2): 12 legacy + 12 versioned archives, alldiff/-wrapped (.exeon windows), byte-identical per platform-uupdates from the new archives;bin/diff versionrunsPlugin Hash Verified,helm diff versionworksmake distmacro (single platform) emits both names with thediff/layoutshellcheckclean, YAML validNote: takes effect with the next release; users already broken on 3.15.14 can either wait for it (
helm plugin updatewill start working again) or reinstall once.