Skip to content

Cache Conan 2 recipe and package archives - #431

Open
pinguinfuss wants to merge 3 commits into
git-pkgs:mainfrom
pinguinfuss:fix-conan-v2-routes
Open

pinguinfuss wants to merge 3 commits into
git-pkgs:mainfrom
pinguinfuss:fix-conan-v2-routes

Conversation

@pinguinfuss

Copy link
Copy Markdown
Contributor

Conan 2 fetches recipe and package files from /v2/conans/{ref}/revisions/{rrev}/files/{file} and .../packages/{id}/revisions/{prev}/files/{file}. The handler only cached /v1/files and /v2/files, which no client uses. So conan install never stored an archive: no offline copies, and scanning, max_size and retention never saw them.

This adds the real routes and drops the old ones. v1 hands out signed URLs on the upstream host, so those downloads never came through the proxy anyway. Manifests and conaninfo.txt stay in the metadata cache. The xz and zstd archives Conan 2.25 can upload (.txz, .tzst) are cached too.

Archives are now stored as pkg:conan/zlib@1.3.1, with the revisions and any user/channel in the filename, so a denylist entry like pkg:conan/zlib@1.3.1 actually blocks them. Before, every revision was its own version of a package called zlib/1.3.1@_/_.

With cache_metadata on, archives cached before this change are fetched again on first use. Their old _metadata/conan/ entries are no longer read and can be deleted.

Tests cover the real paths, caching, separate user/channel files and the denylist.

…ons/{rrev}/files/{file} and .../packages/{id}/revisions/{prev}/files/{file}, but the handler only cached the invalid /v1/files and /v2/files paths, so archives were never stored. This adds the real routes and drops the old ones; manifests and conaninfo.txt stay in the metadata cache.
…txz, conan_package.tzst and so on), so cache those too.
…b@1.3.1, with the revisions and any user/channel in the filename. The old name/version@user/channel with one version per revision never matched a denylist entry or what scanners look up.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant