Skip to content

fix: use GitHub HEAD when repository branch is unspecified - #10080

Open
iona-s wants to merge 2 commits into
AstrBotDevs:masterfrom
iona-s:master
Open

fix: use GitHub HEAD when repository branch is unspecified#10080
iona-s wants to merge 2 commits into
AstrBotDevs:masterfrom
iona-s:master

Conversation

@iona-s

@iona-s iona-s commented Sep 14, 2026

Copy link
Copy Markdown

Fixes #10068.

AstrBot currently queries the unauthenticated GitHub repository API to resolve the default branch of a plugin repository. If this request is rate-limited or otherwise fails, the updater falls back to main, which prevents repositories using another default branch, such as master, from being installed or updated.

GitHub's HEAD reference already resolves to the repository's default branch, so the API request and hard-coded fallback are unnecessary.

The download path also needs safer cleanup when a transfer fails or is cancelled. Previously, asyncio.CancelledError bypassed the existing exception handler, potentially leaving a partial archive behind. In addition, an OSError raised while deleting a partial file could mask the original download error.

This PR uses the same cleanup path for regular download failures and cancellation, logs cleanup failures, and always re-raises the original exception.

Modifications / 改动点

  • Use HEAD for GitHub archive and raw metadata URLs when no branch is explicitly specified.

  • Remove the GitHub repository API lookup and hard-coded main fallback.

  • Remove the obsolete asynchronous repository source resolver.

  • Preserve explicit /tree/<branch> and proxy behavior.

  • Apply the same default-reference behavior to CLI plugin downloads.

  • Remove partial archive files after download failures or cancellation.

  • Preserve the original download or cancellation exception if cleanup fails.

  • Add regression tests for default references, explicit branches, proxy handling, cancellation, and cleanup failures.

  • This is NOT a breaking change. / 这不是一个破坏性变更。

Screenshots or Test Results / 运行截图或测试结果

This is a backend-only change, so screenshots are not applicable.

Verification command:

python -m pytest -p no:cacheprovider tests/test_repository.py tests/test_updater_socks.py tests/unit/test_cli_plugin_utils.py -q

Result:

65 passed, 1 warning in 2.77s

The warning is an existing Python deprecation warning for audioop and is unrelated to this change.

The modified files were also verified with Ruff and git diff --check:

7 files already formatted
All checks passed
No whitespace errors

Checklist / 检查清单

  • 😊 If there are new features added in the PR, I have discussed it with the authors through issues/emails, etc.
    / 如果 PR 中有新加入的功能,已经通过 Issue / 邮件等方式和作者讨论过。

    No new features are introduced by this PR.

  • 👀 My changes have been well-tested, and "Verification Steps" and "Screenshots" have been provided above.
    / 我的更改经过了良好的测试,并已在上方提供了“验证步骤”和“运行截图”

  • 🤓 I have ensured that no new dependencies are introduced, OR if new dependencies are introduced, they have been added to the appropriate locations in requirements.txt and pyproject.toml.
    / 我确保没有引入新依赖库,或者引入了新依赖库的同时将其添加到 requirements.txtpyproject.toml 文件相应位置。

  • 😮 My changes do not introduce malicious code.
    / 我的更改没有引入恶意代码。

Related to #10073.

Summary by Sourcery

Use GitHub HEAD for unspecified repository branches and make failed-download cleanup safe for errors and cancellation.

Bug Fixes:

  • Use GitHub’s HEAD reference when no repository branch is specified, avoiding unreliable default-branch API lookups and hard-coded main fallbacks.
  • Ensure failed or cancelled downloads remove partial archives without masking the original error when cleanup fails.

Enhancements:

  • Apply consistent default-reference handling across updater and CLI plugin downloads while preserving explicit branch and proxy behavior.
  • Remove obsolete asynchronous repository branch resolution logic.

Tests:

  • Add regression coverage for HEAD-based archive and metadata URLs, explicit branches, proxy handling, cancellation cleanup, and cleanup-error preservation.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Needs a human reviewer. If the HEAD archive or raw-file reference resolves to the wrong repository content, the updater could install or inspect incorrect plugin code, and reverting this change would not remove an already-downloaded update. The impact is bounded and can be repaired by reinstalling or rerunning the update with the correct reference.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] 插件使用github源时更新因github api返回错误而导致的更新/安装失败

1 participant