门禁加固与 Windows 可跑性

- 新增 scripts/check-generated-bindings.mjs 并接入 lint 与 ai-game-creator-shell:check:rust:crates:重跑 export_bindings 前后逐字节比对共享契约绑定。
- check:native-shells 的 AGC 边界改为负向门禁:渲染源码不得出现 fetch(/XHR/EventSource/sendBeacon/WebSocket/plugin-http,客户端 capability 不得授予 http:default。
- check-pingora-gateway-smoke 在 Windows 上找 pingora-gateway.exe,并修掉「API 并发保护」先关客户端连接再读响应的竞态。
- mobile-shell 三个 smoke 改成固定命令串启动 npm(绕开 npm.cmd EINVAL 与 DEP0190),desktop-shell 的 stage-release-binary 改用 fileURLToPath 修掉 F:\F:\… 路径拼接。
- vitest.config.ts 白名单补回现役根用例;三份 nginx 模板的 SPA allowlist 补回 /components 与 /design-system。
This commit is contained in:
kdletters
2026-09-28 14:15:50 +08:00
parent e7309ad71b
commit 01394ed238
12 changed files with 169 additions and 56 deletions
@@ -1,7 +1,12 @@
import fs from 'node:fs';
import path from 'node:path';
import { fileURLToPath } from 'node:url';
const repoRoot = path.resolve(new URL('../../../', import.meta.url).pathname);
// `new URL(...).pathname` 在 Windows 上会给出 `/F:/…` 这种带前导斜杠的形式,
// 交给 path.resolve 会拼成 `F:\F:\…`;必须用 fileURLToPath 做跨平台转换。
const repoRoot = path.resolve(
fileURLToPath(new URL('../../../', import.meta.url)),
);
const releaseDir = path.join(
repoRoot,
'apps',