Skip to content

feat(firewall): download from a random origin with cross-origin fallback - #18

Open
Julian Gruber (juliangruber) wants to merge 2 commits into
mainfrom
julian/sfw-mirror-origin
Open

Julian Gruber (juliangruber) wants to merge 2 commits into
mainfrom
julian/sfw-mirror-origin

Conversation

@juliangruber

@juliangruber Julian Gruber (juliangruber) commented Sep 23, 2026 •

Copy link
Copy Markdown
Member

The free-edition binary is now downloadable from two origins: GitHub release assets, and the Socket-owned mirror at install.socket.dev/firewall/dl/<version>/<binary> (served by SocketDev/depscan#26562). Each job picks one origin at random, so roughly half the fleet's downloads keep the mirror's edge cache warm — which is what lets it keep serving pinned binaries during a GitHub release-asset incident.

downloadToolWithRetry now takes the origin list and alternates across the existing 30s/60s retry schedule. An error a retry cannot change (a 404) still gets one immediate try of the other origin, because a missing asset on one host says nothing about the other — which also makes this safe to merge before the mirror endpoint is deployed: until then the mirror 404s and every download falls through to GitHub at the cost of one request.

The checksum table in this action's source validates every download regardless of origin, so the second host cannot alter what gets installed. Enterprise stays GitHub-only: firewall-release is private and not mirrored.

dist/ is rebuilt.


Note

Medium Risk
Changes how production firewall binaries are fetched and verified; incorrect failover or URL logic could break installs, though checksum pinning limits supply-chain impact from the mirror.

Overview
Free-edition sfw installs can now pull from GitHub release assets or a Socket mirror at install.socket.dev/firewall/dl; each job shuffles which origin is tried first so traffic keeps the mirror warm during GitHub CDN blips. Enterprise stays GitHub-only.

downloadToolWithRetry accepts multiple equivalent URLs, rotates origins across the existing 30s/60s backoff for retryable failures, and fails over immediately on errors like 404 without waiting—so a dead mirror still falls through to GitHub after one extra request. Pinned SHA256 validation is unchanged for every download.

A new CI regression workflow blocks either GitHub or the mirror via the hosts file on Windows and Ubuntu, runs this action with cache disabled, and asserts sfw --version still works. Unit tests cover URL construction, shuffle order, and cross-origin retry behavior; dist/ is rebuilt.

Reviewed by Cursor Bugbot for commit 3af8a1e. Configure here.

@juliangruber
Julian Gruber (juliangruber) changed the base branch from ruxandrafediuc/bump-sfw-1.15.2-and-download-retry to main September 29, 2026 12:00
Comment thread src/tools/firewall.js Outdated
Comment thread src/tools/firewall.js Outdated
Julian Gruber (juliangruber) added a commit that referenced this pull request Sep 29, 2026
Review on #18: firewallDownloadUrls now returns the equivalent origins in
a fixed order, GitHub first. The per-job coin flip lives in
orderDownloadOrigins, which downloadFirewall applies to that list. The
mirror constant is named for the edition it serves.
@juliangruber

This comment was marked as outdated.

Comment thread src/tools/firewall.js Outdated
The free-edition binary is now downloadable from two origins: GitHub
release assets, and the Socket-owned mirror at
install.socket.dev/firewall/dl/<version>/<binary> (served by
firewall-download-server in depscan). firewallDownloadUrls returns the
equivalent origins in a fixed order; downloadFirewall tries them in a
Fisher-Yates permutation from shuffledIndexes, so roughly half the
fleet's downloads keep the mirror's edge cache warm, which is what lets
it keep serving pinned binaries during a GitHub release-asset incident.
Adding a third origin needs no change to the selection.

downloadToolWithRetry takes the origin list and alternates across the
existing 30s/60s retry schedule. An error a retry cannot change (a 404)
still gets one immediate try of the other origin, because a missing
asset on one host says nothing about the other.

The checksum table in this action's source validates every download
regardless of origin, so the second host cannot alter what gets
installed. Enterprise stays GitHub-only: firewall-release is private
and not mirrored.

test-sfw-mirror.yml runs on every pull request and forces the failure
this guards against: GitHub or the mirror pointed at 127.0.0.1 in the
hosts file, with the install expected to succeed from the other origin
on windows-2025 and ubuntu-26.04.
Comment thread .github/workflows/test-sfw-mirror.yml Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant