门禁加固与 Windows 可跑性

- 新增 scripts/check-generated-bindings.mjs 并接入 lint 与 ai-game-creator-shell:check:rust:crates:重跑 export_bindings 前后逐字节比对共享契约绑定。
- check:native-shells 的 AGC 边界改为负向门禁:渲染源码不得出现 fetch(/XHR/EventSource/sendBeacon/WebSocket/plugin-http,客户端 capability 不得授予 http:default。
- check-pingora-gateway-smoke 在 Windows 上找 pingora-gateway.exe,并修掉「API 并发保护」先关客户端连接再读响应的竞态。
- mobile-shell 三个 smoke 改成固定命令串启动 npm(绕开 npm.cmd EINVAL 与 DEP0190),desktop-shell 的 stage-release-binary 改用 fileURLToPath 修掉 F:\F:\… 路径拼接。
- vitest.config.ts 白名单补回现役根用例;三份 nginx 模板的 SPA allowlist 补回 /components 与 /design-system。
This commit is contained in:
kdletters
2026-09-28 14:15:50 +08:00
parent e7309ad71b
commit 01394ed238
12 changed files with 169 additions and 56 deletions
@@ -42,14 +42,13 @@ if (packageConfig.devDependencies?.['eas-cli'] !== '^20.3.0') {
);
}
const easVersionResult = spawnSync(
npmCommand,
['exec', 'eas', '--', '--version'],
{
cwd: shellRoot,
encoding: 'utf8',
},
);
// 同 check-expo-config.mjs:Windows 上启动 npm.cmd 必须有 shell,这里改用固定命令串,
// 既避开 EINVAL,也避开 Node 对「shell + args 数组」的 DEP0190 警告。
const easVersionResult = spawnSync(`${npmCommand} exec eas -- --version`, {
cwd: shellRoot,
encoding: 'utf8',
shell: true,
});
if (easVersionResult.error) {
throw new Error(
@@ -31,12 +31,15 @@ const expoPrivacyInfoPluginSource = fs.readFileSync(
const sharedContractSource = fs.readFileSync(sharedContractPath, 'utf8');
const npmCommand = process.platform === 'win32' ? 'npm.cmd' : 'npm';
// Node 18.20+/20+/24 在 Windows 上不允许不带 shell 直接执行 .cmd(npm.cmd → EINVAL),
// 因此这里用一条固定命令串交给 shell;参数都是字面量、不含空格或中文,不存在重新解析歧义。
// 不用「shell: true + args 数组」是为了避开 Node 的 DEP0190(args 在 shell 模式下不会被转义)。
const result = spawnSync(
npmCommand,
['exec', 'expo', 'config', '--', '--type', 'public', '--json'],
`${npmCommand} exec expo config -- --type public --json`,
{
cwd: shellRoot,
encoding: 'utf8',
shell: true,
},
);
@@ -50,22 +50,16 @@ const requiredNativeHostContextTokens = [
function runExpoExport(platform) {
const outputDir = `.expo-export-smoke/${platform}`;
// 同 check-expo-config.mjs:Windows 上启动 npm.cmd 必须有 shell,这里用固定命令串,
// 既避开 EINVAL 也避开 Node 对「shell + args 数组」的 DEP0190;串里的平台名来自固定
// 列表、输出目录是相对路径,都不含空格或中文。
const result = spawnSync(
npmCommand,
[
'exec',
'expo',
'export',
'--',
'--platform',
platform,
'--output-dir',
outputDir,
],
`${npmCommand} exec expo export -- --platform ${platform} --output-dir ${outputDir}`,
{
cwd: shellRoot,
encoding: 'utf8',
stdio: 'pipe',
shell: true,
},
);