From 4ff7610c868fac585de151a9032736dcdab67e07 Mon Sep 17 00:00:00 2001 From: Andrey Vasnetsov Date: Thu, 25 Jun 2026 13:07:01 +0200 Subject: [PATCH] ci: fix GCS multipart upload (disable default AWS CLI checksums) (#9568) Recent AWS CLI versions add default CRC32 integrity checksums on uploads, which GCS's S3-compatible UploadPart rejects with SignatureDoesNotMatch. This only affected the larger debug binaries that go through multipart upload. Opt out via AWS_REQUEST_CHECKSUM_CALCULATION / AWS_RESPONSE_CHECKSUM_VALIDATION=when_required. Co-authored-by: Claude Opus 4.8 (1M context) --- .github/workflows/debug-tools.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/debug-tools.yml b/.github/workflows/debug-tools.yml index a7fcda4291..fc7772c9c8 100644 --- a/.github/workflows/debug-tools.yml +++ b/.github/workflows/debug-tools.yml @@ -73,6 +73,11 @@ jobs: AWS_ACCESS_KEY_ID: ${{ secrets.GCS_ACCESS_KEY_ID }} AWS_SECRET_ACCESS_KEY: ${{ secrets.GCS_SECRET_ACCESS_KEY }} BRANCH: ${{ inputs.branch || github.ref_name }} + # Recent AWS CLI adds default CRC32 integrity checksums that GCS's + # S3-compatible UploadPart rejects (SignatureDoesNotMatch). Opt out so + # multipart uploads of the larger binaries work. + AWS_REQUEST_CHECKSUM_CALCULATION: when_required + AWS_RESPONSE_CHECKSUM_VALIDATION: when_required run: | branch="${BRANCH//\//-}" # replace all / with - sha="$(git rev-parse HEAD)" # actual commit built from the chosen branch