合并 master 到 AGC 交付效率分支
Project CI / AI game creator shell Rust shard 1/4 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust shard 2/4 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust shard 3/4 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust shard 4/4 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust smoke (pull_request) Has been cancelled
Project CI / AI game creator shell Rust crates (pull_request) Has been cancelled
Project CI / Backend tests (pull_request) Has been cancelled
Project CI / Native shell tests (pull_request) Has been cancelled
Project CI / Frontend tests (pull_request) Has been cancelled
Project CI / Repository checks (pull_request) Has been cancelled
Project CI / AI game creator shell web tests (pull_request) Has been cancelled
Project CI / AI game creator shell Rust shard 1/4 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust shard 2/4 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust shard 3/4 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust shard 4/4 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust smoke (pull_request) Has been cancelled
Project CI / AI game creator shell Rust crates (pull_request) Has been cancelled
Project CI / Backend tests (pull_request) Has been cancelled
Project CI / Native shell tests (pull_request) Has been cancelled
Project CI / Frontend tests (pull_request) Has been cancelled
Project CI / Repository checks (pull_request) Has been cancelled
Project CI / AI game creator shell web tests (pull_request) Has been cancelled
- 合并 master 的模型使用记录、Godot 编辑器接入与 macOS universal 发布管线 - 保留本次的请求/工具分段计时与 master 的模型用量观测:同一响应流同时统计耗时并观测型号,归属在读取请求体前冻结 - 保留本次的宿主执行许可分类与并行调度,补上 master 新增的 agc_godot_execute 执行许可与分派 - Skill 包文件表合并双方新增项到 23 项,保留双方的 Skill 校验测试 - macOS 侧车校验同时采用 master 的产品名推导与本次的锁定版本来源,避免版本字面量漂移 - 目录真实用例的拉取次数断言改为有界区间:SDK 自带瞬时重试不再造成负载相关偶发失败,来源真伪仍由字段断言证明 - 合并后重跑编译、定向测试、九项生产夹具与发行载荷 smoke
This commit is contained in:
@@ -302,6 +302,23 @@ jobs:
|
||||
sleep $((attempt * 2))
|
||||
done
|
||||
|
||||
- name: Prepare Godot plugin Rust dependencies
|
||||
shell: bash
|
||||
run: |
|
||||
set -euo pipefail
|
||||
for attempt in $(seq 1 5); do
|
||||
if cargo fetch --locked \
|
||||
--target x86_64-unknown-linux-gnu \
|
||||
--manifest-path plugins/agc-godot-editor/native/godot-editor-bridge/Cargo.toml; then
|
||||
break
|
||||
fi
|
||||
if [[ "${attempt}" -eq 5 ]]; then
|
||||
echo 'Godot plugin Cargo dependency fetch failed after 5 attempts.' >&2
|
||||
exit 1
|
||||
fi
|
||||
sleep $((attempt * 2))
|
||||
done
|
||||
|
||||
- name: Run AI game creator shell shared crate gates
|
||||
run: npm run check:native-shells:agc-rust-crates
|
||||
|
||||
|
||||
@@ -47,6 +47,8 @@ temp*build*/
|
||||
/apps/ai-game-creator-shell/src-tauri/resources/codex/mac-native/codex-package.json
|
||||
/apps/ai-game-creator-shell/src-tauri/resources/codex/mac-native/manifest.json
|
||||
/apps/ai-game-creator-shell/src-tauri/resources/codex/mac-native/NOTICE.md
|
||||
/apps/ai-game-creator-shell/src-tauri/resources/codex/mac-native/darwin-arm64/
|
||||
/apps/ai-game-creator-shell/src-tauri/resources/codex/mac-native/darwin-x64/
|
||||
/plugins/agc-cocos-editor/native/payload/
|
||||
/plugins/agc-unity-editor/dotnet/**/bin/
|
||||
/plugins/agc-unity-editor/dotnet/**/obj/
|
||||
|
||||
@@ -0,0 +1,330 @@
|
||||
/**
|
||||
* AGC 总版本号(发号源)。
|
||||
*
|
||||
* 唯一事实源是 OSS 对象 `agc/global-version.json`;渠道清单只写各自本次拿到的号。
|
||||
* 仓库里的 5 个版本文件仍由构建改写,但只作构建输入参考,不作为事实源。
|
||||
*
|
||||
* 发号顺序固定为「先写总号 → 再构建 → 再发渠道清单」:任何一步失败都不回滚,
|
||||
* 只烧号。这样渠道之间不会复用同一个号,代价是可能出现空洞。
|
||||
*/
|
||||
import { spawnSync } from 'node:child_process';
|
||||
import fs from 'node:fs';
|
||||
import os from 'node:os';
|
||||
import path from 'node:path';
|
||||
|
||||
export const AGC_GLOBAL_VERSION_OBJECT_KEY = 'agc/global-version.json';
|
||||
const defaultOssBaseUrl =
|
||||
'https://agc-dev.oss-rg-china-mainland.aliyuncs.com/agc';
|
||||
const versionPattern = /^\d+\.\d+\.\d+$/u;
|
||||
|
||||
function trimTrailingSlashes(value) {
|
||||
return value.replace(/\/+$/u, '');
|
||||
}
|
||||
|
||||
export function ossBaseUrl(env = process.env) {
|
||||
return trimTrailingSlashes(
|
||||
env.AGC_UPDATE_OSS_BASE_URL?.trim() || defaultOssBaseUrl,
|
||||
);
|
||||
}
|
||||
|
||||
export function globalVersionUrl(env = process.env) {
|
||||
return `${ossBaseUrl(env)}/global-version.json`;
|
||||
}
|
||||
|
||||
export function parseVersion(value, label) {
|
||||
if (typeof value !== 'string' || !versionPattern.test(value.trim())) {
|
||||
throw new Error(`${label} 不是有效的三段版本号:${String(value)}`);
|
||||
}
|
||||
return value.trim();
|
||||
}
|
||||
|
||||
export function compareVersions(left, right) {
|
||||
const leftParts = parseVersion(left, '左版本').split('.').map(Number);
|
||||
const rightParts = parseVersion(right, '右版本').split('.').map(Number);
|
||||
for (let index = 0; index < 3; index += 1) {
|
||||
if (leftParts[index] !== rightParts[index]) {
|
||||
return leftParts[index] > rightParts[index] ? 1 : -1;
|
||||
}
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
|
||||
/** 取较大版本;任一为空时返回另一个。 */
|
||||
export function maxVersion(...versions) {
|
||||
return versions
|
||||
.filter((value) => typeof value === 'string' && value.trim())
|
||||
.map((value) => parseVersion(value, '候选版本'))
|
||||
.reduce(
|
||||
(best, current) =>
|
||||
best == null || compareVersions(current, best) > 0 ? current : best,
|
||||
null,
|
||||
);
|
||||
}
|
||||
|
||||
export function nextVersion(current) {
|
||||
const [major, minor, patch] = parseVersion(current, '总版本')
|
||||
.split('.')
|
||||
.map(Number);
|
||||
if (patch === Number.MAX_SAFE_INTEGER) {
|
||||
throw new Error(`版本号 patch 已达到上限:${current}`);
|
||||
}
|
||||
return `${major}.${minor}.${patch + 1}`;
|
||||
}
|
||||
|
||||
export function readReleaseDryRun(env = process.env) {
|
||||
const value = env.AGC_RELEASE_DRY_RUN?.trim().toLowerCase();
|
||||
return value === '1' || value === 'true';
|
||||
}
|
||||
|
||||
async function fetchJson(url, label, { fetchImpl = fetch } = {}) {
|
||||
let response;
|
||||
try {
|
||||
response = await fetchImpl(url, {
|
||||
headers: { Accept: 'application/json' },
|
||||
});
|
||||
} catch (error) {
|
||||
throw new Error(`读取 ${label} 失败:${error.message}`);
|
||||
}
|
||||
if (response.status === 404) return null;
|
||||
if (!response.ok) {
|
||||
throw new Error(`读取 ${label} 失败:HTTP ${response.status}`);
|
||||
}
|
||||
try {
|
||||
return await response.json();
|
||||
} catch (error) {
|
||||
throw new Error(`${label} 不是有效 JSON:${error.message}`);
|
||||
}
|
||||
}
|
||||
|
||||
/** 渠道清单版本;缺失或 404 时返回 null(首次启用渠道)。 */
|
||||
export async function readChannelVersion(channel, options = {}) {
|
||||
const payload = await fetchJson(
|
||||
`${ossBaseUrl(options.env)}/${channel}/latest.json`,
|
||||
`${channel} 渠道清单`,
|
||||
options,
|
||||
);
|
||||
if (payload == null) return null;
|
||||
const version = typeof payload.version === 'string' ? payload.version : '';
|
||||
if (!version) {
|
||||
throw new Error(`${channel} 渠道清单缺少 version 字段`);
|
||||
}
|
||||
return parseVersion(version, `${channel} 渠道清单 version`);
|
||||
}
|
||||
|
||||
/** 旧协议迁移指针 `agc/latest.json`;只在迁移窗口内存在,仅参与播种。 */
|
||||
export async function readLegacyPointerVersion(options = {}) {
|
||||
const payload = await fetchJson(
|
||||
`${ossBaseUrl(options.env)}/latest.json`,
|
||||
'OSS 迁移指针',
|
||||
options,
|
||||
);
|
||||
if (payload == null) return null;
|
||||
const version = typeof payload.version === 'string' ? payload.version : '';
|
||||
return version ? parseVersion(version, 'OSS 迁移指针 version') : null;
|
||||
}
|
||||
|
||||
export async function readGlobalVersion(options = {}) {
|
||||
const payload = await fetchJson(
|
||||
globalVersionUrl(options.env),
|
||||
'AGC 总版本号',
|
||||
options,
|
||||
);
|
||||
if (payload == null) return null;
|
||||
const version = typeof payload.version === 'string' ? payload.version : '';
|
||||
if (!version) {
|
||||
throw new Error('AGC 总版本号对象缺少 version 字段');
|
||||
}
|
||||
return {
|
||||
...payload,
|
||||
version: parseVersion(version, 'AGC 总版本号 version'),
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* 一次性播种基线:仓库当前版本、渠道清单与旧迁移指针里的最大值。
|
||||
* 基线本身不发给客户端,首个发放号是 baseline + 1。
|
||||
*/
|
||||
export async function resolveSeedBaseline({
|
||||
channels = ['dev-win', 'dev-mac'],
|
||||
repoVersion = null,
|
||||
env = process.env,
|
||||
fetchImpl = fetch,
|
||||
} = {}) {
|
||||
const candidates = [];
|
||||
if (repoVersion) candidates.push(parseVersion(repoVersion, '仓库当前版本'));
|
||||
for (const channel of channels) {
|
||||
const version = await readChannelVersion(channel, { env, fetchImpl });
|
||||
if (version) candidates.push(version);
|
||||
}
|
||||
const legacy = await readLegacyPointerVersion({ env, fetchImpl });
|
||||
if (legacy) candidates.push(legacy);
|
||||
const baseline = maxVersion(...candidates);
|
||||
if (!baseline) {
|
||||
throw new Error('无法确定总版本号播种基线:仓库版本与渠道清单都不可用');
|
||||
}
|
||||
return baseline;
|
||||
}
|
||||
|
||||
/**
|
||||
* 组装 ossutil 参数。
|
||||
*
|
||||
* 该桶与凭据按 v1 签名使用(ossutil v2 默认 v4,缺 region 会直接失败),
|
||||
* 因此默认显式传 `--sign-version v1`;需要 v4 时用 `AGC_OSS_SIGN_VERSION=v4`
|
||||
* 并同时给 `AGC_OSS_REGION`。
|
||||
*/
|
||||
export function buildOssutilArgs({
|
||||
args,
|
||||
endpoint,
|
||||
accessKeyId,
|
||||
accessKeySecret,
|
||||
env = process.env,
|
||||
}) {
|
||||
const finalArgs = [...args, '--endpoint', endpoint];
|
||||
const region = env.AGC_OSS_REGION?.trim();
|
||||
if (region) finalArgs.push('--region', region);
|
||||
finalArgs.push('--sign-version', env.AGC_OSS_SIGN_VERSION?.trim() || 'v1');
|
||||
if (accessKeyId) {
|
||||
finalArgs.push(
|
||||
'--access-key-id',
|
||||
accessKeyId,
|
||||
'--access-key-secret',
|
||||
accessKeySecret,
|
||||
);
|
||||
}
|
||||
return finalArgs;
|
||||
}
|
||||
|
||||
function runOssutil(args, { env = process.env } = {}) {
|
||||
const binary = env.OSSUTIL_BIN?.trim() || 'ossutil';
|
||||
const endpoint =
|
||||
env.AGC_OSS_ENDPOINT?.trim() || 'oss-rg-china-mainland.aliyuncs.com';
|
||||
const accessKeyId = env.AGC_OSS_ACCESS_KEY_ID?.trim();
|
||||
const accessKeySecret = env.AGC_OSS_ACCESS_KEY_SECRET;
|
||||
if (Boolean(accessKeyId) !== Boolean(accessKeySecret)) {
|
||||
throw new Error('OSS AccessKey ID 和 Secret 必须同时提供');
|
||||
}
|
||||
const result = spawnSync(
|
||||
binary,
|
||||
buildOssutilArgs({
|
||||
args,
|
||||
endpoint,
|
||||
accessKeyId,
|
||||
accessKeySecret,
|
||||
env,
|
||||
}),
|
||||
{ stdio: 'inherit', shell: false, env },
|
||||
);
|
||||
if (result.error) {
|
||||
throw new Error(`无法执行 ${binary},请先安装并配置 ossutil`);
|
||||
}
|
||||
if (result.status !== 0) {
|
||||
throw new Error(`${binary} 执行失败,退出码 ${result.status}`);
|
||||
}
|
||||
}
|
||||
|
||||
/** 写入总版本号对象;dry-run 下只打印将要执行的上传。 */
|
||||
export function writeGlobalVersion(payload, options = {}) {
|
||||
const { env = process.env, dryRun = readReleaseDryRun(env) } = options;
|
||||
const bucket = env.AGC_OSS_BUCKET?.trim() || 'agc-dev';
|
||||
const body = Buffer.from(`${JSON.stringify(payload, null, 2)}\n`, 'utf8');
|
||||
const tempDirectory = fs.mkdtempSync(
|
||||
path.join(os.tmpdir(), 'agc-global-version-'),
|
||||
);
|
||||
const tempPath = path.join(tempDirectory, 'global-version.json');
|
||||
try {
|
||||
fs.writeFileSync(tempPath, body);
|
||||
const ossUrl = `oss://${bucket}/${AGC_GLOBAL_VERSION_OBJECT_KEY}`;
|
||||
if (dryRun) {
|
||||
console.log(
|
||||
`[dry-run] 不写总版本号:${ossUrl} <- ${JSON.stringify(payload)}`,
|
||||
);
|
||||
return { written: false, objectUrl: ossUrl, payload };
|
||||
}
|
||||
runOssutil(['cp', '--force', tempPath, ossUrl], { env });
|
||||
return { written: true, objectUrl: ossUrl, payload };
|
||||
} finally {
|
||||
fs.rmSync(tempDirectory, { force: true, recursive: true });
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* 发一次号并写回总版本号对象。
|
||||
*
|
||||
* 写后回读校验:若远端值与自己写下的不一致,说明有并发发号,按失败关闭处理
|
||||
* (号已烧,不重试、不回滚),由人工确认后再发。
|
||||
*/
|
||||
export async function issueGlobalVersion({
|
||||
channel,
|
||||
commit = null,
|
||||
buildId = null,
|
||||
repoVersion = null,
|
||||
env = process.env,
|
||||
fetchImpl = fetch,
|
||||
now = () => new Date().toISOString(),
|
||||
writeImpl = writeGlobalVersion,
|
||||
} = {}) {
|
||||
if (!channel) throw new Error('发号必须显式指定 channel');
|
||||
const dryRun = readReleaseDryRun(env);
|
||||
const current = await readGlobalVersion({ env, fetchImpl });
|
||||
let baseline = current?.version ?? null;
|
||||
let seeded = false;
|
||||
if (!baseline) {
|
||||
baseline = await resolveSeedBaseline({ repoVersion, env, fetchImpl });
|
||||
seeded = true;
|
||||
}
|
||||
const issued = nextVersion(baseline);
|
||||
const payload = {
|
||||
version: issued,
|
||||
updatedAt: now(),
|
||||
channel,
|
||||
commit,
|
||||
buildId,
|
||||
};
|
||||
console.log(
|
||||
`[agc-global-version] ${
|
||||
seeded ? `按播种基线 ${baseline} 首发` : `总号 ${baseline}`
|
||||
} -> ${issued}(channel=${channel} dry-run=${dryRun})`,
|
||||
);
|
||||
writeImpl(payload, { env, dryRun });
|
||||
if (!dryRun) {
|
||||
const stored = await readGlobalVersion({ env, fetchImpl });
|
||||
if (!stored || stored.version !== issued) {
|
||||
throw new Error(
|
||||
`总版本号写后回读不一致:期望 ${issued},远端 ${
|
||||
stored?.version ?? '不存在'
|
||||
};可能存在并发发号,本次构建失败关闭`,
|
||||
);
|
||||
}
|
||||
}
|
||||
return issued;
|
||||
}
|
||||
|
||||
/** 渠道高水位断言:请求号低于本渠道清单版本即失败关闭。 */
|
||||
export function assertRequestedVersionNotBelowChannel({
|
||||
requested,
|
||||
channelVersion,
|
||||
channel,
|
||||
}) {
|
||||
const requestedVersion = parseVersion(requested, '请求版本');
|
||||
if (channelVersion == null) return requestedVersion;
|
||||
const current = parseVersion(channelVersion, `${channel} 渠道版本`);
|
||||
if (compareVersions(requestedVersion, current) < 0) {
|
||||
throw new Error(
|
||||
`请求版本 ${requestedVersion} 低于 ${channel} 渠道当前清单版本 ${current};拒绝回退发布`,
|
||||
);
|
||||
}
|
||||
return requestedVersion;
|
||||
}
|
||||
|
||||
/** 只读预览:不写回、不烧号。 */
|
||||
export async function previewNextGlobalVersion(options = {}) {
|
||||
const current = await readGlobalVersion(options);
|
||||
const baseline =
|
||||
current?.version ??
|
||||
(await resolveSeedBaseline({
|
||||
repoVersion: options.repoVersion,
|
||||
env: options.env,
|
||||
fetchImpl: options.fetchImpl,
|
||||
}));
|
||||
return nextVersion(baseline);
|
||||
}
|
||||
@@ -0,0 +1,206 @@
|
||||
import assert from 'node:assert/strict';
|
||||
import { test } from 'node:test';
|
||||
|
||||
import {
|
||||
assertRequestedVersionNotBelowChannel,
|
||||
buildOssutilArgs,
|
||||
issueGlobalVersion,
|
||||
maxVersion,
|
||||
nextVersion,
|
||||
previewNextGlobalVersion,
|
||||
resolveSeedBaseline,
|
||||
} from './agc-global-version.mjs';
|
||||
|
||||
function jsonResponse(payload, status = 200) {
|
||||
return {
|
||||
ok: status >= 200 && status < 300,
|
||||
status,
|
||||
json: async () => payload,
|
||||
};
|
||||
}
|
||||
|
||||
/** 以 URL 为键的假 OSS:只读 fetch + 记录写入。 */
|
||||
function createFakeOss({ objects = {} } = {}) {
|
||||
const state = { ...objects };
|
||||
const writes = [];
|
||||
return {
|
||||
state,
|
||||
writes,
|
||||
fetchImpl: async (url) => {
|
||||
const key = String(url).replace(/^https?:\/\/[^/]+\//u, '');
|
||||
if (!(key in state)) return jsonResponse(null, 404);
|
||||
return jsonResponse(state[key]);
|
||||
},
|
||||
writeImpl: (payload, options = {}) => {
|
||||
writes.push({ payload, dryRun: Boolean(options.dryRun) });
|
||||
if (!options.dryRun) state['agc/global-version.json'] = payload;
|
||||
return { written: !options.dryRun, payload };
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
test('播种基线取仓库版本、各渠道清单与旧迁移指针的最大值', async () => {
|
||||
const oss = createFakeOss({
|
||||
objects: {
|
||||
'agc/dev-win/latest.json': { version: '0.1.57' },
|
||||
'agc/dev-mac/latest.json': { version: '0.1.12' },
|
||||
'agc/latest.json': { version: '0.1.60' },
|
||||
},
|
||||
});
|
||||
assert.equal(
|
||||
await resolveSeedBaseline({
|
||||
repoVersion: '0.1.48',
|
||||
env: {},
|
||||
fetchImpl: oss.fetchImpl,
|
||||
}),
|
||||
'0.1.60',
|
||||
);
|
||||
assert.equal(maxVersion('0.1.9', '0.1.10', null), '0.1.10');
|
||||
});
|
||||
|
||||
test('无总号时按播种基线发首号,并把总号写回唯一事实源', async () => {
|
||||
const oss = createFakeOss({
|
||||
objects: {
|
||||
'agc/dev-win/latest.json': { version: '0.1.57' },
|
||||
'agc/dev-mac/latest.json': { version: '0.1.12' },
|
||||
},
|
||||
});
|
||||
const issued = await issueGlobalVersion({
|
||||
channel: 'dev-win',
|
||||
commit: 'a'.repeat(40),
|
||||
buildId: '319',
|
||||
repoVersion: '0.1.48',
|
||||
env: {},
|
||||
fetchImpl: oss.fetchImpl,
|
||||
writeImpl: oss.writeImpl,
|
||||
now: () => '2026-09-20T00:00:00.000Z',
|
||||
});
|
||||
assert.equal(issued, '0.1.58');
|
||||
assert.deepEqual(
|
||||
oss.writes.map((entry) => entry.payload.version),
|
||||
['0.1.58'],
|
||||
);
|
||||
assert.equal(oss.state['agc/global-version.json'].version, '0.1.58');
|
||||
assert.equal(oss.state['agc/global-version.json'].channel, 'dev-win');
|
||||
assert.equal(oss.state['agc/global-version.json'].buildId, '319');
|
||||
});
|
||||
|
||||
test('已有总号时只递增,不再回看渠道清单', async () => {
|
||||
const oss = createFakeOss({
|
||||
objects: {
|
||||
'agc/global-version.json': { version: '0.2.7' },
|
||||
// 渠道清单被手工改小也不能把总号拉回去。
|
||||
'agc/dev-win/latest.json': { version: '0.1.10' },
|
||||
},
|
||||
});
|
||||
const issued = await issueGlobalVersion({
|
||||
channel: 'dev-mac',
|
||||
env: {},
|
||||
fetchImpl: oss.fetchImpl,
|
||||
writeImpl: oss.writeImpl,
|
||||
});
|
||||
assert.equal(issued, '0.2.8');
|
||||
assert.equal(oss.state['agc/global-version.json'].version, '0.2.8');
|
||||
});
|
||||
|
||||
test('dry-run 只预览下一位,不写回、不烧号', async () => {
|
||||
const oss = createFakeOss({
|
||||
objects: { 'agc/global-version.json': { version: '0.3.4' } },
|
||||
});
|
||||
const preview = await previewNextGlobalVersion({
|
||||
env: {},
|
||||
fetchImpl: oss.fetchImpl,
|
||||
});
|
||||
assert.equal(preview, '0.3.5');
|
||||
assert.equal(oss.writes.length, 0);
|
||||
|
||||
const issued = await issueGlobalVersion({
|
||||
channel: 'dev-win',
|
||||
env: { AGC_RELEASE_DRY_RUN: '1' },
|
||||
fetchImpl: oss.fetchImpl,
|
||||
writeImpl: oss.writeImpl,
|
||||
});
|
||||
assert.equal(issued, '0.3.5');
|
||||
assert.deepEqual(
|
||||
oss.writes.map((entry) => entry.dryRun),
|
||||
[true],
|
||||
);
|
||||
assert.equal(oss.state['agc/global-version.json'].version, '0.3.4');
|
||||
});
|
||||
|
||||
test('传入低于本渠道清单的号时失败关闭', () => {
|
||||
assert.equal(
|
||||
assertRequestedVersionNotBelowChannel({
|
||||
requested: '0.1.60',
|
||||
channelVersion: '0.1.60',
|
||||
channel: 'dev-win',
|
||||
}),
|
||||
'0.1.60',
|
||||
);
|
||||
assert.throws(
|
||||
() =>
|
||||
assertRequestedVersionNotBelowChannel({
|
||||
requested: '0.1.59',
|
||||
channelVersion: '0.1.60',
|
||||
channel: 'dev-win',
|
||||
}),
|
||||
/低于 dev-win 渠道当前清单版本/u,
|
||||
);
|
||||
assert.equal(
|
||||
assertRequestedVersionNotBelowChannel({
|
||||
requested: '0.1.1',
|
||||
channelVersion: null,
|
||||
channel: 'dev-mac',
|
||||
}),
|
||||
'0.1.1',
|
||||
);
|
||||
});
|
||||
|
||||
test('写后回读不一致(并发发号)时失败关闭', async () => {
|
||||
const oss = createFakeOss({
|
||||
objects: { 'agc/global-version.json': { version: '0.5.1' } },
|
||||
});
|
||||
await assert.rejects(
|
||||
issueGlobalVersion({
|
||||
channel: 'dev-win',
|
||||
env: {},
|
||||
// 模拟另一个发号进程在写入后覆盖了总号。
|
||||
writeImpl: (payload, options) => {
|
||||
const result = oss.writeImpl(payload, options);
|
||||
// 另一个发号进程紧随其后覆盖总号。
|
||||
oss.state['agc/global-version.json'] = { version: '0.5.9' };
|
||||
return result;
|
||||
},
|
||||
fetchImpl: oss.fetchImpl,
|
||||
}),
|
||||
/写后回读不一致/u,
|
||||
);
|
||||
});
|
||||
|
||||
test('nextVersion 只在 patch 位递增', () => {
|
||||
assert.equal(nextVersion('0.1.9'), '0.1.10');
|
||||
assert.equal(nextVersion('1.0.0'), '1.0.1');
|
||||
assert.throws(() => nextVersion('0.1'), /不是有效的三段版本号/u);
|
||||
});
|
||||
|
||||
test('ossutil 参数默认使用 v1 签名,并可按需带 region 与 v4', () => {
|
||||
const base = {
|
||||
args: ['cp', '--force', '/tmp/a.json', 'oss://agc-dev/agc/global-version.json'],
|
||||
endpoint: 'oss-rg-china-mainland.aliyuncs.com',
|
||||
accessKeyId: 'id',
|
||||
accessKeySecret: 'secret',
|
||||
env: {},
|
||||
};
|
||||
const v1 = buildOssutilArgs(base);
|
||||
assert.equal(v1[v1.indexOf('--sign-version') + 1], 'v1');
|
||||
assert.ok(!v1.includes('--region'));
|
||||
assert.equal(v1[v1.indexOf('--access-key-id') + 1], 'id');
|
||||
assert.equal(v1[v1.indexOf('--access-key-secret') + 1], 'secret');
|
||||
|
||||
const v4 = buildOssutilArgs({
|
||||
...base,
|
||||
env: { AGC_OSS_SIGN_VERSION: 'v4', AGC_OSS_REGION: 'cn-beijing' },
|
||||
});
|
||||
assert.equal(v4[v4.indexOf('--region') + 1], 'cn-beijing');
|
||||
assert.equal(v4[v4.indexOf('--sign-version') + 1], 'v4');
|
||||
});
|
||||
@@ -0,0 +1,280 @@
|
||||
import assert from 'node:assert/strict';
|
||||
import { execFileSync, spawnSync } from 'node:child_process';
|
||||
import { createHash } from 'node:crypto';
|
||||
import fs from 'node:fs';
|
||||
import os from 'node:os';
|
||||
import path from 'node:path';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
|
||||
import {
|
||||
generateUpdateManifest,
|
||||
prepareReleaseVersion,
|
||||
resolveReleaseContext,
|
||||
resolveReleasePartition,
|
||||
runTauriBuild,
|
||||
} from './build-release.mjs';
|
||||
import { readReleaseDryRun, uploadReleaseArtifacts } from './release-oss.mjs';
|
||||
import {
|
||||
readUpdaterPubkey,
|
||||
verifyUpdaterSignature,
|
||||
} from './verify-updater-signature.mjs';
|
||||
|
||||
/**
|
||||
* AGC macOS 分区(`<channel>-mac`)发布入口:构建 universal 包 → 双架构 smoke → 生成 universal DMG
|
||||
* → 生成分区清单 latest.json → 用产物内烘焙的公钥验签 → 按 dry-run 决定是否上传 OSS。
|
||||
*
|
||||
* 边界:
|
||||
* - Apple 签名与公证暂缺:本入口剥离 `APPLE_*` 凭据让 Tauri 跳过 Apple 签名,但**不能传
|
||||
* `--no-sign`** —— 该标志同时会跳过 updater 的 minisign 签名,产物就没有 `.sig`;
|
||||
* 未签名 + 未公证必须显式记录而非静默通过;
|
||||
* - 更新包签名(TAURI_SIGNING_PRIVATE_KEY,minisign)是硬需求:缺了客户端一律拒绝安装,
|
||||
* 因此构建前要求凭据存在,构建后用内置公钥复核 `.sig` 才允许继续上传;
|
||||
* - 未通过验签绝不写 OSS:上传顺序为更新包、签名、首装包,全部成功后才覆盖渠道清单指针。
|
||||
*/
|
||||
const appRoot = fileURLToPath(new URL('..', import.meta.url));
|
||||
const repoRoot = path.resolve(appRoot, '../..');
|
||||
|
||||
/**
|
||||
* 产品名只从 Tauri 配置读取:它同时决定 `*.app` 目录名、updater 归档名与 DMG 卷名。
|
||||
* 写死会在改名后让入口静默找错对象(清理、打包、归档三处一起失效)。
|
||||
*/
|
||||
function readProductName() {
|
||||
const read = (file) =>
|
||||
JSON.parse(fs.readFileSync(path.join(appRoot, 'src-tauri', file), 'utf8'));
|
||||
const base = read('tauri.conf.json');
|
||||
const macosPath = path.join(appRoot, 'src-tauri', 'tauri.macos.conf.json');
|
||||
const productName = fs.existsSync(macosPath)
|
||||
? (read('tauri.macos.conf.json').productName ?? base.productName)
|
||||
: base.productName;
|
||||
assert.ok(
|
||||
typeof productName === 'string' && productName.trim().length > 0,
|
||||
'Tauri 配置缺少 productName',
|
||||
);
|
||||
return productName;
|
||||
}
|
||||
|
||||
const productName = readProductName();
|
||||
const appBundleName = `${productName}.app`;
|
||||
const updaterArtifactName = `${productName}.app.tar.gz`;
|
||||
assert.equal(process.platform, 'darwin', '只能在 macOS Agent 执行');
|
||||
assert.equal(
|
||||
process.env.JENKINS_URL?.length > 0,
|
||||
true,
|
||||
'此入口仅用于 Jenkins 独立工作区',
|
||||
);
|
||||
assert.equal(
|
||||
fs.realpathSync(process.env.WORKSPACE || '.'),
|
||||
fs.realpathSync(repoRoot),
|
||||
'必须在 Jenkins workspace 根目录执行',
|
||||
);
|
||||
const space = fs.statfsSync(repoRoot);
|
||||
assert.ok(
|
||||
space.bavail * space.bsize >= 8 * 1024 ** 3,
|
||||
'构建前至少需要 8 GiB 可用空间;禁止自动清理开发缓存',
|
||||
);
|
||||
|
||||
// 仅剥离 Apple 签名/公证变量:本节点没有证书,误用只会让构建失败;
|
||||
// 更新包签名与 OSS 凭据必须保留,它们是本入口发布能力的组成部分。
|
||||
for (const key of Object.keys(process.env)) {
|
||||
if (/^APPLE_/u.test(key)) delete process.env[key];
|
||||
}
|
||||
assert.ok(
|
||||
process.env.TAURI_SIGNING_PRIVATE_KEY?.length > 0 ||
|
||||
process.env.TAURI_SIGNING_PRIVATE_KEY_PATH?.length > 0,
|
||||
'缺少更新包签名私钥(TAURI_SIGNING_PRIVATE_KEY / _PATH):无签名的更新包会被客户端拒绝,禁止继续',
|
||||
);
|
||||
|
||||
const bucket = process.env.AGC_OSS_BUCKET?.trim() || 'agc-dev';
|
||||
const endpoint =
|
||||
process.env.AGC_OSS_ENDPOINT?.trim() || 'oss-rg-china-mainland.aliyuncs.com';
|
||||
if (!/^[a-z0-9][a-z0-9.-]{1,62}$/u.test(bucket) || /[\r\n\0]/u.test(endpoint)) {
|
||||
throw new Error('OSS bucket 或 endpoint 配置无效');
|
||||
}
|
||||
process.env.AGC_UPDATE_OSS_BASE_URL ||= `https://${bucket}.${endpoint}/agc`;
|
||||
const dryRun = readReleaseDryRun();
|
||||
|
||||
process.env.CARGO_TARGET_DIR = path.join(appRoot, 'src-tauri/target');
|
||||
const context = resolveReleaseContext(['--target=universal-apple-darwin']);
|
||||
const partition = resolveReleasePartition(context.channel, context.target);
|
||||
const version = await prepareReleaseVersion(context);
|
||||
// 首装包名必须保持 `<产品名>_<版本>_universal.dmg`:清单侧按该后缀唯一匹配本次产物。
|
||||
const firstInstallName = `${productName}_${version}_universal.dmg`;
|
||||
|
||||
// 幂等边界:workspace 会保留上一轮产物。先删掉本次将要写出的对象,否则
|
||||
// 1) hdiutil 会因同名 DMG 已存在直接失败(首次实跑即命中);
|
||||
// 2) 上一轮遗留的 `.sig` 会让验签门禁把「本轮其实没签」判成通过。
|
||||
// 只删本次要写出的确切路径,不动其它版本产物与编译缓存。
|
||||
const macosBundle = path.join(context.bundleRoot, 'macos');
|
||||
for (const stale of [
|
||||
path.join(macosBundle, updaterArtifactName),
|
||||
path.join(macosBundle, `${updaterArtifactName}.sig`),
|
||||
path.join(macosBundle, `${firstInstallName}`),
|
||||
path.join(macosBundle, `${firstInstallName}.sha256`),
|
||||
path.join(context.bundleRoot, 'latest.json'),
|
||||
path.join(context.bundleRoot, 'release-notes.txt'),
|
||||
]) {
|
||||
fs.rmSync(stale, { force: true });
|
||||
}
|
||||
|
||||
const args = [
|
||||
'--target=universal-apple-darwin',
|
||||
'--bundles',
|
||||
'app',
|
||||
'--ci',
|
||||
// 刻意不传 `--no-sign`:它会连带跳过 updater 签名,而客户端强制校验更新包签名。
|
||||
// Apple 侧改为剥离 APPLE_* 凭据,未配置身份时 Tauri 不签名也不失败。
|
||||
// 基础配置已开启;这里显式声明,避免被其它配置来源关掉后静默失去更新能力。
|
||||
'--config',
|
||||
'{"bundle":{"createUpdaterArtifacts":true}}',
|
||||
];
|
||||
const command = (binary, argv, options = {}) =>
|
||||
execFileSync(binary, argv, { cwd: repoRoot, stdio: 'inherit', ...options });
|
||||
runTauriBuild(args, context);
|
||||
|
||||
const app = path.join(context.bundleRoot, 'macos', appBundleName);
|
||||
for (const architecture of ['arm64', 'x86_64']) {
|
||||
command(process.execPath, [
|
||||
path.join(appRoot, 'scripts/check-macos-bundle.mjs'),
|
||||
app,
|
||||
architecture,
|
||||
'--universal',
|
||||
]);
|
||||
}
|
||||
|
||||
// DMG 放在 bundle 根目录下:渠道清单的首装包选择会扫描该目录,命名必须匹配 `_<version>_universal.dmg`。
|
||||
const dmgDirectory = path.join(context.bundleRoot, 'macos');
|
||||
fs.mkdirSync(dmgDirectory, { recursive: true });
|
||||
const dmg = path.join(dmgDirectory, firstInstallName);
|
||||
const stage = fs.mkdtempSync(path.join(os.tmpdir(), 'agc-ci-dmg-'));
|
||||
try {
|
||||
command('ditto', [app, path.join(stage, appBundleName)]);
|
||||
fs.symlinkSync('/Applications', path.join(stage, 'Applications'));
|
||||
command('hdiutil', [
|
||||
'create',
|
||||
// 前面已删除同名对象;这里再要求显式覆盖,避免残留文件让构建以「文件已存在」失败。
|
||||
'-ov',
|
||||
'-volname',
|
||||
productName,
|
||||
'-srcfolder',
|
||||
stage,
|
||||
'-format',
|
||||
'UDZO',
|
||||
dmg,
|
||||
]);
|
||||
command('hdiutil', ['verify', dmg]);
|
||||
} finally {
|
||||
fs.rmSync(stage, { recursive: true, force: true });
|
||||
}
|
||||
|
||||
const release = await generateUpdateManifest(context);
|
||||
assert.equal(
|
||||
path.resolve(release.downloadArtifact),
|
||||
path.resolve(dmg),
|
||||
'首装包必须锁定本次生成的 universal DMG',
|
||||
);
|
||||
|
||||
// 上传前门禁:用产物里烘焙的公钥复核更新包签名。验不过就停在这里,绝不写 OSS。
|
||||
const signature = verifyUpdaterSignature({
|
||||
artifactPath: release.artifact,
|
||||
signaturePath: `${release.artifact}.sig`,
|
||||
pubkey: readUpdaterPubkey(),
|
||||
});
|
||||
console.log(
|
||||
`[agc-macos] 更新包签名校验通过:alg=${signature.algorithm},keyId=${signature.keyId}`,
|
||||
);
|
||||
|
||||
const artifacts = path.join(repoRoot, 'artifacts');
|
||||
// 只清理本 Job 的归档输出,不能把上次 DMG 当成本次成功产物。
|
||||
fs.rmSync(artifacts, { recursive: true, force: true });
|
||||
fs.mkdirSync(artifacts, { recursive: true });
|
||||
const sha256 = (file) => {
|
||||
const hash = createHash('sha256');
|
||||
hash.update(fs.readFileSync(file));
|
||||
return hash.digest('hex');
|
||||
};
|
||||
const dmgHash = sha256(dmg);
|
||||
fs.writeFileSync(`${dmg}.sha256`, `${dmgHash} ${path.basename(dmg)}\n`);
|
||||
|
||||
const uploadPlan = uploadReleaseArtifacts(release, {
|
||||
bucket,
|
||||
endpoint,
|
||||
binary: process.env.OSSUTIL_BIN?.trim() || 'ossutil',
|
||||
accessKeyId: process.env.AGC_OSS_ACCESS_KEY_ID?.trim(),
|
||||
accessKeySecret: process.env.AGC_OSS_ACCESS_KEY_SECRET,
|
||||
dryRun,
|
||||
});
|
||||
|
||||
const archived = [
|
||||
dmg,
|
||||
`${dmg}.sha256`,
|
||||
release.manifestPath,
|
||||
release.notesPath,
|
||||
`${release.artifact}.sig`,
|
||||
];
|
||||
for (const file of archived) {
|
||||
fs.copyFileSync(file, path.join(artifacts, path.basename(file)));
|
||||
}
|
||||
|
||||
const commit = execFileSync('git', ['rev-parse', 'HEAD'], {
|
||||
cwd: repoRoot,
|
||||
encoding: 'utf8',
|
||||
}).trim();
|
||||
// Apple 签名状态必须实测:剥离 APPLE_* 后 Tauri 通常跳过签名,但节点若装了 Developer ID
|
||||
// 证书仍可能签上,硬编码 appleSigned=false 会把「其实签了」写成假事实。
|
||||
const signatureProbe = spawnSync('codesign', ['-dv', '--verbose=2', app], {
|
||||
encoding: 'utf8',
|
||||
});
|
||||
const signatureText = `${signatureProbe.stdout ?? ''}${signatureProbe.stderr ?? ''}`;
|
||||
const appleSigned = /Authority=Developer ID Application/u.test(signatureText);
|
||||
const appleSignatureKind = appleSigned
|
||||
? 'developer-id'
|
||||
: /Signature=adhoc/u.test(signatureText)
|
||||
? 'adhoc'
|
||||
: 'unsigned';
|
||||
fs.writeFileSync(
|
||||
path.join(artifacts, 'build-manifest.json'),
|
||||
`${JSON.stringify(
|
||||
{
|
||||
version,
|
||||
commit,
|
||||
target: context.target,
|
||||
channel: context.channel,
|
||||
// Apple 签名与公证暂缺:显式记录为未验证项,不静默通过。
|
||||
appleSigned,
|
||||
appleSignatureKind,
|
||||
notarized: false,
|
||||
dryRun,
|
||||
uploaded: !dryRun,
|
||||
updaterSignature: {
|
||||
algorithm: signature.algorithm,
|
||||
keyId: signature.keyId,
|
||||
verified: true,
|
||||
},
|
||||
oss: {
|
||||
bucket,
|
||||
endpoint,
|
||||
partition,
|
||||
latest: `oss://${bucket}/agc/${partition}/latest.json`,
|
||||
objects: uploadPlan.map(({ destination }) => destination),
|
||||
},
|
||||
artifacts: {
|
||||
updater: path.basename(release.artifact),
|
||||
updaterSha256: sha256(release.artifact),
|
||||
updaterBytes: fs.statSync(release.artifact).size,
|
||||
updaterSignature: path.basename(`${release.artifact}.sig`),
|
||||
firstInstall: path.basename(dmg),
|
||||
firstInstallSha256: dmgHash,
|
||||
manifest: 'latest.json',
|
||||
},
|
||||
smokes: ['arm64', 'x86_64'],
|
||||
intelSmoke: process.arch === 'arm64' ? 'Rosetta' : 'native',
|
||||
},
|
||||
null,
|
||||
2,
|
||||
)}\n`,
|
||||
);
|
||||
console.log(
|
||||
dryRun
|
||||
? `[agc-macos] dry-run 完成:${partition} 分区产物与清单已生成,未写入 OSS`
|
||||
: `[agc-macos] ${partition} 分区更新包、签名、首装包与清单已上传 OSS`,
|
||||
);
|
||||
@@ -5,6 +5,10 @@ import os from 'node:os';
|
||||
import path from 'node:path';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
|
||||
import {
|
||||
assertRequestedVersionNotBelowChannel,
|
||||
issueGlobalVersion as issueAgcGlobalVersion,
|
||||
} from './agc-global-version.mjs';
|
||||
import {
|
||||
defaultEditorFeatures,
|
||||
withDefaultCargoFeatures,
|
||||
@@ -43,16 +47,12 @@ function explicitBuildTarget(args) {
|
||||
}
|
||||
|
||||
function validateReleaseTarget(target) {
|
||||
if (target === 'universal-apple-darwin') {
|
||||
throw new Error(
|
||||
'内置 Codex 资源仅支持 macOS 单架构构建,请使用 aarch64-apple-darwin 或 x86_64-apple-darwin',
|
||||
);
|
||||
}
|
||||
if (
|
||||
![
|
||||
'x86_64-pc-windows-msvc',
|
||||
'aarch64-apple-darwin',
|
||||
'x86_64-apple-darwin',
|
||||
'universal-apple-darwin',
|
||||
].includes(target)
|
||||
) {
|
||||
throw new Error(`不支持的发布目标:${target}`);
|
||||
@@ -107,6 +107,7 @@ export const agcReleasePathPatterns = [
|
||||
'server-rs/crates/',
|
||||
'plugins/agc-cocos-editor/',
|
||||
'plugins/agc-unity-editor/',
|
||||
'plugins/agc-godot-editor/',
|
||||
'apps/desktop-shell/src-tauri/icons/',
|
||||
'package.json',
|
||||
'package-lock.json',
|
||||
@@ -196,10 +197,12 @@ export function updateManifestUrl(
|
||||
}
|
||||
|
||||
/**
|
||||
* 单架构产物只登记实际目标,不能把同一原生资源映射为另一架构。
|
||||
* universal 主程序与双目录原生资源共用一个更新包;单架构只登记实际目标。
|
||||
*/
|
||||
export function resolveManifestPlatformKeys(target = defaultTarget()) {
|
||||
validateReleaseTarget(target);
|
||||
if (target === 'universal-apple-darwin')
|
||||
return ['darwin-aarch64', 'darwin-x86_64'];
|
||||
if (target === 'aarch64-apple-darwin') return ['darwin-aarch64'];
|
||||
if (target === 'x86_64-apple-darwin') return ['darwin-x86_64'];
|
||||
if (target.includes('windows')) {
|
||||
@@ -312,14 +315,35 @@ function replaceVersionLine(source, version, pattern, label) {
|
||||
return source.replace(pattern, `$1${version}$3`);
|
||||
}
|
||||
|
||||
/**
|
||||
* 版本来源固定为 OSS 总版本号(`agc/global-version.json`):
|
||||
* - CI 统一构建由发号 Job 先发号,再通过 AGC_RELEASE_VERSION 透传给各渠道;
|
||||
* - 未传入时(本地手工兜底)由本函数现场发号并写回总号;
|
||||
* - 渠道高水位只做断言:传入号低于本渠道清单版本即失败关闭。
|
||||
*/
|
||||
export async function prepareReleaseVersion(context = resolveReleaseContext()) {
|
||||
const { channel, target } = context;
|
||||
const localVersion = parseVersion(readPackageJson().version, '本地版本');
|
||||
const remoteVersion = await resolveRemoteHighWaterVersion(channel, target);
|
||||
const requestedVersion = process.env.AGC_RELEASE_VERSION?.trim();
|
||||
const nextVersion = requestedVersion
|
||||
? parseVersion(requestedVersion, '指定版本')
|
||||
: nextPatchVersion(localVersion, remoteVersion);
|
||||
? assertRequestedVersionNotBelowChannel({
|
||||
requested: requestedVersion,
|
||||
channelVersion: remoteVersion,
|
||||
channel,
|
||||
})
|
||||
: await issueAgcGlobalVersion({
|
||||
channel,
|
||||
commit:
|
||||
process.env.COMMIT_HASH?.trim() ||
|
||||
process.env.GIT_COMMIT?.trim() ||
|
||||
null,
|
||||
buildId:
|
||||
process.env.BUILD_NUMBER?.trim() ||
|
||||
process.env.AGC_BUILD_ID?.trim() ||
|
||||
null,
|
||||
repoVersion: localVersion,
|
||||
});
|
||||
|
||||
const packageSource = fs.readFileSync(packageJsonPath, 'utf8');
|
||||
fs.writeFileSync(
|
||||
@@ -378,8 +402,8 @@ export async function prepareReleaseVersion(context = resolveReleaseContext()) {
|
||||
|
||||
console.log(
|
||||
requestedVersion
|
||||
? `[ai-game-creator-shell] 渠道 ${channel} 使用指定版本 ${nextVersion}(本地 ${localVersion} / OSS ${remoteVersion ?? '不存在'})`
|
||||
: `[ai-game-creator-shell] 渠道 ${channel} 版本 ${localVersion} / OSS ${remoteVersion ?? '不存在'} -> ${nextVersion}`,
|
||||
? `[ai-game-creator-shell] 渠道 ${channel} 使用发号 Job 下发的总号 ${nextVersion}(本渠道清单 ${remoteVersion ?? '不存在'} / 仓库 ${localVersion})`
|
||||
: `[ai-game-creator-shell] 渠道 ${channel} 本地兜底发号 ${nextVersion}(本渠道清单 ${remoteVersion ?? '不存在'} / 仓库 ${localVersion})`,
|
||||
);
|
||||
return nextVersion;
|
||||
}
|
||||
@@ -526,6 +550,18 @@ export function selectFirstInstallArtifact(
|
||||
if (!selected?.endsWith('.exe')) {
|
||||
throw new Error('Windows 首装包必须复用本次 NSIS .exe 更新包');
|
||||
}
|
||||
} else if (target === 'universal-apple-darwin') {
|
||||
// universal 主程序只产出一个 DMG,aarch64 与 x86_64 首装共用它(命名见 build-macos-ci.mjs)。
|
||||
const suffix = `_${version}_universal.dmg`;
|
||||
const candidates = files.filter((file) =>
|
||||
path.basename(file).endsWith(suffix),
|
||||
);
|
||||
if (candidates.length !== 1) {
|
||||
throw new Error(
|
||||
`首装 DMG 必须唯一匹配本次版本 ${version} 的 universal 产物,找到 ${candidates.length} 个`,
|
||||
);
|
||||
}
|
||||
selected = candidates[0];
|
||||
} else {
|
||||
// Tauri DMG 文件名使用 aarch64 / x64,而 updater 的 Intel 平台键是 x86_64。
|
||||
const architecture = target.startsWith('aarch64') ? 'aarch64' : 'x64';
|
||||
|
||||
@@ -45,19 +45,22 @@ const packageVersion = JSON.parse(
|
||||
).version;
|
||||
|
||||
function createDmgFixture(root, target, version = packageVersion) {
|
||||
const architecture = target.startsWith('aarch64') ? 'aarch64' : 'x64';
|
||||
const architecture = target.startsWith('aarch64')
|
||||
? 'aarch64'
|
||||
: target === universalTarget
|
||||
? 'universal'
|
||||
: 'x64';
|
||||
const dmg = path.join(root, `陶泥儿_${version}_${architecture}.dmg`);
|
||||
writeFileSync(dmg, 'first installation disk image');
|
||||
return dmg;
|
||||
}
|
||||
|
||||
test('native sidecar builds reject universal targets and accept each macOS architecture', () => {
|
||||
assert.throws(() => buildTauriBuildArguments([], universalTarget), /单架构/);
|
||||
assert.throws(
|
||||
() => buildTauriBuildArguments(['--target=universal-apple-darwin']),
|
||||
/单架构/,
|
||||
);
|
||||
for (const target of ['aarch64-apple-darwin', 'x86_64-apple-darwin']) {
|
||||
test('native sidecar builds accept universal and each macOS architecture', () => {
|
||||
for (const target of [
|
||||
universalTarget,
|
||||
'aarch64-apple-darwin',
|
||||
'x86_64-apple-darwin',
|
||||
]) {
|
||||
assert.deepEqual(buildTauriBuildArguments([], target), [
|
||||
'build',
|
||||
'--target',
|
||||
@@ -201,8 +204,11 @@ test('channel manifest URL and build-time endpoint follow the channel', () => {
|
||||
});
|
||||
});
|
||||
|
||||
test('macOS manifests only advertise the architecture actually built', () => {
|
||||
assert.throws(() => resolveManifestPlatformKeys(universalTarget), /单架构/);
|
||||
test('macOS manifests advertise exactly the architectures actually built', () => {
|
||||
assert.deepEqual(resolveManifestPlatformKeys(universalTarget), [
|
||||
'darwin-aarch64',
|
||||
'darwin-x86_64',
|
||||
]);
|
||||
assert.deepEqual(resolveManifestPlatformKeys('aarch64-apple-darwin'), [
|
||||
'darwin-aarch64',
|
||||
]);
|
||||
@@ -246,7 +252,6 @@ test('release context resolves explicit targets before environment/default and f
|
||||
['--target='],
|
||||
['--target', '--no-bundle'],
|
||||
['--target', windowsTarget, '--target=aarch64-apple-darwin'],
|
||||
['--target', universalTarget],
|
||||
['--target', 'unknown'],
|
||||
])
|
||||
assert.throws(() => resolveReleaseContext(args, {}));
|
||||
@@ -462,8 +467,8 @@ test('invalid target or platform used as channel fails before any release side e
|
||||
},
|
||||
};
|
||||
await assert.rejects(
|
||||
() => buildRelease(['--target', universalTarget], sideEffects),
|
||||
/单架构/,
|
||||
() => buildRelease(['--target', 'unknown'], sideEffects),
|
||||
/不支持的发布目标/,
|
||||
);
|
||||
await withEnv({ AGC_UPDATE_CHANNEL: 'dev-win' }, () =>
|
||||
assert.rejects(
|
||||
@@ -474,6 +479,43 @@ test('invalid target or platform used as channel fails before any release side e
|
||||
assert.equal(touched, false);
|
||||
});
|
||||
|
||||
test('universal uses the Mac channel and the same signed artifact for both architectures', () => {
|
||||
const context = resolveReleaseContext(['--target', universalTarget], {
|
||||
AGC_BUILD_TARGET: windowsTarget,
|
||||
});
|
||||
// 渠道本身不含系统:分区由渠道 + 目标推导,二者不能混为一谈。
|
||||
assert.equal(context.channel, 'dev');
|
||||
assert.equal(
|
||||
resolveReleasePartition(context.channel, context.target),
|
||||
'dev-mac',
|
||||
);
|
||||
assert.ok(context.bundleRoot.includes(universalTarget));
|
||||
withSignedArtifact('陶泥儿.app.tar.gz', (artifact) => {
|
||||
const manifest = createUpdateManifest(artifact, {
|
||||
...context,
|
||||
downloadArtifact: createDmgFixture(
|
||||
path.dirname(artifact),
|
||||
universalTarget,
|
||||
),
|
||||
});
|
||||
assert.deepEqual(Object.keys(manifest.platforms), [
|
||||
'darwin-aarch64',
|
||||
'darwin-x86_64',
|
||||
]);
|
||||
assert.deepEqual(
|
||||
manifest.platforms['darwin-aarch64'],
|
||||
manifest.platforms['darwin-x86_64'],
|
||||
);
|
||||
assert.match(manifest.platforms['darwin-aarch64'].url, /\/dev-mac\//);
|
||||
// 两个平台键共用同一个 universal 首装包,不能要求出两份架构 DMG。
|
||||
assert.deepEqual(
|
||||
manifest.downloads['darwin-aarch64'].url,
|
||||
manifest.downloads['darwin-x86_64'].url,
|
||||
);
|
||||
assert.match(manifest.downloads['darwin-aarch64'].url, /_universal\.dmg$/u);
|
||||
});
|
||||
});
|
||||
|
||||
test('Windows remains the default and explicit Windows overrides macOS environment', () => {
|
||||
const files = ['/tmp/mac.app.tar.gz', '/tmp/windows.exe', '/tmp/mac.dmg'];
|
||||
for (const context of [
|
||||
@@ -495,7 +537,7 @@ test('Windows remains the default and explicit Windows overrides macOS environme
|
||||
spawn: (_binary, command) => {
|
||||
assert.ok(
|
||||
command.includes(
|
||||
'--features=cocos-editor-execute,unity-editor-execute',
|
||||
'--features=cocos-editor-execute,unity-editor-execute,godot-editor-execute',
|
||||
),
|
||||
);
|
||||
assert.ok(command.includes('user-config.json'));
|
||||
|
||||
@@ -19,6 +19,6 @@ export function withDefaultCargoFeatures(argv, features) {
|
||||
|
||||
export function defaultEditorFeatures(target) {
|
||||
return target === 'win32' || target.includes('windows')
|
||||
? ['cocos-editor-execute', 'unity-editor-execute']
|
||||
? ['cocos-editor-execute', 'unity-editor-execute', 'godot-editor-execute']
|
||||
: [];
|
||||
}
|
||||
|
||||
@@ -9,7 +9,7 @@ test('Windows release includes the same editor feature as development', () => {
|
||||
buildTauriBuildArguments([], 'x86_64-pc-windows-msvc', 'win32'),
|
||||
[
|
||||
'build',
|
||||
'--features=cocos-editor-execute,unity-editor-execute',
|
||||
'--features=cocos-editor-execute,unity-editor-execute,godot-editor-execute',
|
||||
'--target',
|
||||
'x86_64-pc-windows-msvc',
|
||||
],
|
||||
|
||||
@@ -1393,18 +1393,20 @@ if (windowsTauriConfig.bundle?.useLocalToolsDir !== true) {
|
||||
assert.deepEqual(
|
||||
macosTauriConfig.bundle?.resources,
|
||||
Object.fromEntries([
|
||||
...[
|
||||
'bin/codex',
|
||||
'bin/codex-code-mode-host',
|
||||
'codex-path/rg',
|
||||
'codex-resources/zsh/bin/zsh',
|
||||
'codex-package.json',
|
||||
'NOTICE.md',
|
||||
'manifest.json',
|
||||
].map((file) => [
|
||||
`resources/codex/mac-native/${file}`,
|
||||
`coding-agent/mac-native/${file}`,
|
||||
]),
|
||||
...['darwin-arm64', 'darwin-x64'].flatMap((arch) =>
|
||||
[
|
||||
'bin/codex',
|
||||
'bin/codex-code-mode-host',
|
||||
'codex-path/rg',
|
||||
'codex-resources/zsh/bin/zsh',
|
||||
'codex-package.json',
|
||||
'NOTICE.md',
|
||||
'manifest.json',
|
||||
].map((file) => [
|
||||
`resources/codex/mac-native/${arch}/${file}`,
|
||||
`coding-agent/mac-native/${arch}/${file}`,
|
||||
]),
|
||||
),
|
||||
['resources/plugins', 'plugins'],
|
||||
]),
|
||||
'macOS must bundle the complete native Codex layout and plugin workspace',
|
||||
|
||||
@@ -8,6 +8,13 @@ import path from 'node:path';
|
||||
// 只操作临时复制品;不启动 GUI、不读取开发机凭据、不访问 Provider。
|
||||
assert.equal(process.platform, 'darwin', '此验证必须在 macOS 执行');
|
||||
const source = path.resolve(process.argv[2] || '');
|
||||
const architecture =
|
||||
process.argv[3] || (process.arch === 'arm64' ? 'arm64' : 'x86_64');
|
||||
assert.ok(
|
||||
['arm64', 'x86_64'].includes(architecture),
|
||||
'架构只接受 arm64 / x86_64',
|
||||
);
|
||||
const requireUniversal = process.argv.includes('--universal');
|
||||
assert.ok(
|
||||
source.endsWith('.app') && fs.statSync(source).isDirectory(),
|
||||
'请传入 .app 绝对路径',
|
||||
@@ -15,6 +22,9 @@ assert.ok(
|
||||
const root = fs.realpathSync(
|
||||
fs.mkdtempSync(path.join(os.tmpdir(), 'agc-macos-bundle-')),
|
||||
);
|
||||
// 产品名从传入的 .app 推导,不在校验脚本里写死;改名后校验对象仍指向同一个包。
|
||||
const appBundleName = path.basename(source);
|
||||
const app = path.join(root, `隔离-${appBundleName}`);
|
||||
// 侧车清单版本必须等于锁定的 @openai/codex 版本,避免两处固定版本漂移。
|
||||
const appPackage = JSON.parse(
|
||||
fs.readFileSync(
|
||||
@@ -34,7 +44,6 @@ assert.match(
|
||||
/^\d+\.\d+\.\d+$/u,
|
||||
'package.json 必须锁定精确的 @openai/codex 版本',
|
||||
);
|
||||
const app = path.join(root, '陶泥儿 隔离测试.app');
|
||||
const home = path.join(root, 'home');
|
||||
const config = path.join(root, 'config');
|
||||
const tmp = path.join(root, 'tmp');
|
||||
@@ -50,17 +59,58 @@ const env = {
|
||||
};
|
||||
|
||||
function run(command, args) {
|
||||
const result = spawnSync(command, args, {
|
||||
cwd: root,
|
||||
env,
|
||||
encoding: 'utf8',
|
||||
timeout: 30_000,
|
||||
maxBuffer: 1024 * 1024,
|
||||
});
|
||||
// 只强制被测应用切片;本机 Xcode 检查工具可能仅提供宿主架构。
|
||||
const useSlice = command.startsWith(`${app}${path.sep}`);
|
||||
const result = spawnSync(
|
||||
useSlice ? '/usr/bin/arch' : command,
|
||||
useSlice ? [`-${architecture}`, command, ...args] : args,
|
||||
{
|
||||
cwd: root,
|
||||
env,
|
||||
encoding: 'utf8',
|
||||
timeout: 120_000,
|
||||
maxBuffer: 1024 * 1024,
|
||||
},
|
||||
);
|
||||
assert.ifError(result.error);
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* APFS 上优先用 `ditto --clone`:整包按区块克隆,秒级完成且几乎不占额外空间。
|
||||
* 跨卷或非 APFS 时回退到真实复制;两种路径都必须产出可独立改动的副本,
|
||||
* 因为「缺组件拒绝」用例会在副本里改名文件。
|
||||
*/
|
||||
function copyBundle(from, to) {
|
||||
const cloned = spawnSync('/usr/bin/ditto', ['--clone', from, to], {
|
||||
encoding: 'utf8',
|
||||
});
|
||||
if (
|
||||
cloned.status === 0 &&
|
||||
fs.existsSync(path.join(to, 'Contents/Info.plist'))
|
||||
) {
|
||||
return 'clone';
|
||||
}
|
||||
fs.cpSync(from, to, { recursive: true });
|
||||
return 'copy';
|
||||
}
|
||||
|
||||
/** 可执行名以包内 Info.plist 为准:它是稳定契约,但没必要在校验脚本里重复硬编码。 */
|
||||
function readBundleExecutable(appPath) {
|
||||
const plist = path.join(appPath, 'Contents/Info.plist');
|
||||
const result = spawnSync(
|
||||
'/usr/libexec/PlistBuddy',
|
||||
['-c', 'Print :CFBundleExecutable', plist],
|
||||
{ encoding: 'utf8' },
|
||||
);
|
||||
const name = (result.stdout ?? '').trim();
|
||||
assert.ok(
|
||||
name.length > 0,
|
||||
`无法从 Info.plist 读取 CFBundleExecutable:${plist}`,
|
||||
);
|
||||
return name;
|
||||
}
|
||||
|
||||
async function hashFile(file) {
|
||||
const hash = createHash('sha256');
|
||||
for await (const chunk of fs.createReadStream(file)) hash.update(chunk);
|
||||
@@ -79,7 +129,7 @@ async function handshake(executable) {
|
||||
await new Promise((resolve, reject) => {
|
||||
const timer = setTimeout(
|
||||
() => reject(new Error('app-server 初始化超时')),
|
||||
15_000,
|
||||
120_000,
|
||||
);
|
||||
const finish = (error) => {
|
||||
clearTimeout(timer);
|
||||
@@ -146,22 +196,38 @@ async function handshake(executable) {
|
||||
}
|
||||
|
||||
try {
|
||||
fs.cpSync(source, app, { recursive: true });
|
||||
const copiedWith = copyBundle(source, app);
|
||||
const resources = path.join(app, 'Contents/Resources');
|
||||
const bundle = path.join(resources, 'coding-agent/mac-native');
|
||||
const platform = architecture === 'arm64' ? 'darwin-arm64' : 'darwin-x64';
|
||||
const bundle = path.join(resources, 'coding-agent/mac-native', platform);
|
||||
const executable = path.join(bundle, 'bin/codex');
|
||||
const main = path.join(
|
||||
app,
|
||||
'Contents/MacOS/genarrative-ai-game-creator-shell',
|
||||
);
|
||||
const main = path.join(app, 'Contents/MacOS', readBundleExecutable(app));
|
||||
const mainArchitectures = run('/usr/bin/lipo', ['-archs', main]);
|
||||
assert.equal(mainArchitectures.status, 0);
|
||||
assert.ok(mainArchitectures.stdout.split(/\s+/).includes(architecture));
|
||||
if (requireUniversal) {
|
||||
assert.deepEqual(mainArchitectures.stdout.trim().split(/\s+/).sort(), [
|
||||
'arm64',
|
||||
'x86_64',
|
||||
]);
|
||||
for (const platform of ['darwin-arm64', 'darwin-x64']) {
|
||||
assert.ok(
|
||||
fs.existsSync(
|
||||
path.join(
|
||||
resources,
|
||||
'coding-agent/mac-native',
|
||||
platform,
|
||||
'manifest.json',
|
||||
),
|
||||
),
|
||||
);
|
||||
}
|
||||
}
|
||||
const manifest = JSON.parse(
|
||||
fs.readFileSync(path.join(bundle, 'manifest.json'), 'utf8'),
|
||||
);
|
||||
assert.equal(manifest.schemaVersion, 'genarrative-codex-sidecar.v2');
|
||||
assert.equal(
|
||||
manifest.platform,
|
||||
process.arch === 'arm64' ? 'darwin-arm64' : 'darwin-x64',
|
||||
);
|
||||
assert.equal(manifest.platform, platform);
|
||||
assert.equal(manifest.version, `codex-cli ${pinnedCodexVersion}`);
|
||||
const components = [
|
||||
'bin/codex',
|
||||
@@ -178,11 +244,7 @@ try {
|
||||
fs.accessSync(file, fs.constants.X_OK);
|
||||
const arch = run('/usr/bin/lipo', ['-archs', file]);
|
||||
assert.equal(arch.status, 0, component);
|
||||
assert.equal(
|
||||
arch.stdout.trim(),
|
||||
process.arch === 'arm64' ? 'arm64' : 'x86_64',
|
||||
component,
|
||||
);
|
||||
assert.equal(arch.stdout.trim(), architecture, component);
|
||||
}
|
||||
}
|
||||
assert.ok(fs.existsSync(path.join(bundle, 'NOTICE.md')));
|
||||
@@ -265,7 +327,7 @@ try {
|
||||
assert.notEqual(broken.status, 0);
|
||||
assert.match(`${broken.stdout}\n${broken.stderr}`, /Codex CLI 未安装/);
|
||||
console.log(
|
||||
'PASS: 隔离安装包资源、架构、摘要、权限、正式 Codex 查找、app-server 握手及缺组件拒绝',
|
||||
`PASS (${architecture}, 副本=${copiedWith}): 隔离安装包资源、架构、摘要、权限、正式 Codex 查找、app-server 握手及缺组件拒绝`,
|
||||
);
|
||||
console.log(
|
||||
'未验证:GUI、真实登录/Provider 对话、Cocos macOS 原生桥接;插件 Node 仍为外部前提',
|
||||
|
||||
@@ -0,0 +1,121 @@
|
||||
/**
|
||||
* AGC 总版本号发号入口(CI 发号 Job 与本地手工兜底共用)。
|
||||
*
|
||||
* 用法:
|
||||
* node scripts/issue-global-version.mjs --channel dev-win [--commit <sha>] [--build-id <id>] [--out <file>]
|
||||
* node scripts/issue-global-version.mjs --seed-only
|
||||
* node scripts/issue-global-version.mjs --dry-run --channel dev-win # 只预览,不写回、不烧号
|
||||
*
|
||||
* 输出固定为一行 `AGC_GLOBAL_VERSION=<version>`,便于 Jenkins 直接读取。
|
||||
*/
|
||||
import fs from 'node:fs';
|
||||
|
||||
import {
|
||||
issueGlobalVersion,
|
||||
previewNextGlobalVersion,
|
||||
readGlobalVersion,
|
||||
readReleaseDryRun,
|
||||
resolveSeedBaseline,
|
||||
writeGlobalVersion,
|
||||
} from './agc-global-version.mjs';
|
||||
|
||||
function parseArgs(argv) {
|
||||
const options = {
|
||||
channel: '',
|
||||
commit: '',
|
||||
buildId: '',
|
||||
repoVersion: '',
|
||||
out: '',
|
||||
seedOnly: false,
|
||||
dryRun: readReleaseDryRun(),
|
||||
};
|
||||
for (let index = 0; index < argv.length; index += 1) {
|
||||
const arg = argv[index];
|
||||
const readValue = (label) => {
|
||||
const value = argv[index + 1];
|
||||
if (value == null || value.startsWith('--')) {
|
||||
throw new Error(`${label} 缺少取值`);
|
||||
}
|
||||
index += 1;
|
||||
return value;
|
||||
};
|
||||
switch (arg) {
|
||||
case '--channel':
|
||||
options.channel = readValue('--channel');
|
||||
break;
|
||||
case '--commit':
|
||||
options.commit = readValue('--commit');
|
||||
break;
|
||||
case '--build-id':
|
||||
options.buildId = readValue('--build-id');
|
||||
break;
|
||||
case '--repo-version':
|
||||
options.repoVersion = readValue('--repo-version');
|
||||
break;
|
||||
case '--out':
|
||||
options.out = readValue('--out');
|
||||
break;
|
||||
case '--seed-only':
|
||||
options.seedOnly = true;
|
||||
break;
|
||||
case '--dry-run':
|
||||
options.dryRun = true;
|
||||
break;
|
||||
default:
|
||||
throw new Error(`未知参数:${arg}`);
|
||||
}
|
||||
}
|
||||
return options;
|
||||
}
|
||||
|
||||
function emit(version, options) {
|
||||
console.log(`AGC_GLOBAL_VERSION=${version}`);
|
||||
if (options.out) {
|
||||
fs.writeFileSync(options.out, `${version}\n`, 'utf8');
|
||||
}
|
||||
}
|
||||
|
||||
const options = parseArgs(process.argv.slice(2));
|
||||
process.env.AGC_RELEASE_DRY_RUN = options.dryRun ? '1' : '0';
|
||||
|
||||
if (options.seedOnly) {
|
||||
const current = await readGlobalVersion();
|
||||
if (current) {
|
||||
console.log(
|
||||
`[agc-global-version] 总号已存在(${current.version}),播种跳过;需要重新播种请先人工确认`,
|
||||
);
|
||||
emit(current.version, options);
|
||||
} else {
|
||||
const baseline = await resolveSeedBaseline({
|
||||
repoVersion: options.repoVersion || null,
|
||||
});
|
||||
const payload = {
|
||||
version: baseline,
|
||||
updatedAt: new Date().toISOString(),
|
||||
channel: options.channel || 'seed',
|
||||
commit: options.commit || null,
|
||||
buildId: options.buildId || null,
|
||||
};
|
||||
writeGlobalVersion(payload, { dryRun: options.dryRun });
|
||||
console.log(
|
||||
`[agc-global-version] 播种基线 ${baseline}(尚未发号,首发为下一位)`,
|
||||
);
|
||||
emit(baseline, options);
|
||||
}
|
||||
} else if (options.dryRun) {
|
||||
const preview = await previewNextGlobalVersion({
|
||||
repoVersion: options.repoVersion || null,
|
||||
});
|
||||
console.log(
|
||||
`[agc-global-version] 预览下一个总号 ${preview}(dry-run 不写回、不烧号)`,
|
||||
);
|
||||
emit(preview, options);
|
||||
} else {
|
||||
const issued = await issueGlobalVersion({
|
||||
channel: options.channel || 'manual',
|
||||
commit: options.commit || null,
|
||||
buildId: options.buildId || null,
|
||||
repoVersion: options.repoVersion || null,
|
||||
});
|
||||
emit(issued, options);
|
||||
}
|
||||
@@ -0,0 +1,134 @@
|
||||
import assert from 'node:assert/strict';
|
||||
import { execFileSync } from 'node:child_process';
|
||||
import { createHash } from 'node:crypto';
|
||||
import fs from 'node:fs';
|
||||
import path from 'node:path';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
|
||||
const appRoot = fileURLToPath(new URL('..', import.meta.url));
|
||||
const repoRoot = path.resolve(appRoot, '../..');
|
||||
const platforms = {
|
||||
arm64: 'aarch64-apple-darwin',
|
||||
x64: 'x86_64-apple-darwin',
|
||||
};
|
||||
|
||||
export function lockedMacPackage(lock, arch, version) {
|
||||
assert.ok(Object.hasOwn(platforms, arch), '未知 macOS 架构');
|
||||
const alias = `@openai/codex-darwin-${arch}`;
|
||||
const entry = lock.packages?.[`node_modules/${alias}`];
|
||||
assert.equal(
|
||||
entry?.version,
|
||||
`${version}-darwin-${arch}`,
|
||||
'原生依赖必须与应用锁定版本一致',
|
||||
);
|
||||
assert.deepEqual(entry.os, ['darwin']);
|
||||
assert.deepEqual(entry.cpu, [arch]);
|
||||
const url = new URL(entry.resolved);
|
||||
assert.equal(url.protocol, 'https:');
|
||||
assert.equal(
|
||||
url.hostname,
|
||||
'registry.npmjs.org',
|
||||
'只下载锁定的官方 npm 原生包',
|
||||
);
|
||||
assert.equal(url.username + url.password + url.search + url.hash, '');
|
||||
assert.match(entry.integrity, /^sha512-[A-Za-z0-9+/]+={0,2}$/);
|
||||
return { alias, target: platforms[arch], ...entry };
|
||||
}
|
||||
|
||||
export function verifyPackageIntegrity(bytes, expected) {
|
||||
const actual = `sha512-${createHash('sha512').update(bytes).digest('base64')}`;
|
||||
assert.equal(actual, expected, 'Codex 下载包 lockfile integrity 不匹配');
|
||||
}
|
||||
|
||||
export function validateArchiveListing(listing) {
|
||||
const files = listing.trim().split(/\r?\n/u);
|
||||
assert.ok(files.length > 0);
|
||||
for (const file of files) {
|
||||
assert.ok(file.startsWith('package/'), '原生包必须只有 package 根目录');
|
||||
assert.ok(
|
||||
!file.split('/').includes('..') && !file.includes('\\'),
|
||||
'压缩包路径不安全',
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
export async function prepareMacosCodex() {
|
||||
assert.equal(process.platform, 'darwin', '该入口仅用于 macOS 构建机');
|
||||
const lock = JSON.parse(
|
||||
fs.readFileSync(path.join(repoRoot, 'package-lock.json'), 'utf8'),
|
||||
);
|
||||
const app = JSON.parse(
|
||||
fs.readFileSync(path.join(appRoot, 'package.json'), 'utf8'),
|
||||
);
|
||||
const version = app.devDependencies['@openai/codex'];
|
||||
assert.match(version, /^\d+\.\d+\.\d+$/u, 'Codex 必须锁定精确版本');
|
||||
const cache = path.join(appRoot, 'src-tauri/target/.macos-native-cache');
|
||||
fs.mkdirSync(cache, { recursive: true });
|
||||
for (const arch of Object.keys(platforms)) {
|
||||
const entry = lockedMacPackage(lock, arch, version);
|
||||
const archive = path.join(cache, `codex-${entry.version}.tgz`);
|
||||
if (!fs.existsSync(archive)) {
|
||||
const response = await fetch(entry.resolved, {
|
||||
signal: AbortSignal.timeout(300_000),
|
||||
});
|
||||
assert.ok(response.ok, `原生包下载失败 HTTP ${response.status}`);
|
||||
const bytes = Buffer.from(await response.arrayBuffer());
|
||||
verifyPackageIntegrity(bytes, entry.integrity);
|
||||
const partial = `${archive}.${process.pid}.tmp`;
|
||||
fs.writeFileSync(partial, bytes);
|
||||
fs.renameSync(partial, archive);
|
||||
}
|
||||
verifyPackageIntegrity(fs.readFileSync(archive), entry.integrity);
|
||||
validateArchiveListing(
|
||||
execFileSync('tar', ['-tzf', archive], { encoding: 'utf8' }),
|
||||
);
|
||||
// 拒绝链接、设备及其它特殊条目,不能让 tar 在包目录之外写入。
|
||||
const entries = execFileSync('tar', ['-tvzf', archive], {
|
||||
encoding: 'utf8',
|
||||
});
|
||||
assert.ok(
|
||||
entries
|
||||
.trim()
|
||||
.split(/\r?\n/u)
|
||||
.every((line) => /^[-d]/u.test(line)),
|
||||
'原生包禁止链接或特殊文件',
|
||||
);
|
||||
const parent = path.join(repoRoot, 'node_modules/@openai');
|
||||
fs.mkdirSync(parent, { recursive: true });
|
||||
const stage = fs.mkdtempSync(path.join(parent, '.mac-native-'));
|
||||
try {
|
||||
execFileSync(
|
||||
'tar',
|
||||
['-xzf', archive, '-C', stage, '--strip-components=1'],
|
||||
{ stdio: 'pipe' },
|
||||
);
|
||||
const metadata = JSON.parse(
|
||||
fs.readFileSync(
|
||||
path.join(stage, 'vendor', entry.target, 'codex-package.json'),
|
||||
'utf8',
|
||||
),
|
||||
);
|
||||
assert.equal(metadata.version, version);
|
||||
assert.equal(metadata.target, entry.target);
|
||||
assert.equal(metadata.entrypoint, 'bin/codex');
|
||||
const destination = path.join(repoRoot, 'node_modules', entry.alias);
|
||||
assert.ok(
|
||||
!fs.existsSync(destination) ||
|
||||
!fs.lstatSync(destination).isSymbolicLink(),
|
||||
'拒绝覆盖链接依赖',
|
||||
);
|
||||
fs.rmSync(destination, { recursive: true, force: true });
|
||||
fs.renameSync(stage, destination);
|
||||
} finally {
|
||||
fs.rmSync(stage, { recursive: true, force: true });
|
||||
}
|
||||
console.log(`[macOS Codex] ${entry.version}: lockfile integrity 已验证`);
|
||||
}
|
||||
}
|
||||
|
||||
if (
|
||||
process.argv[1] &&
|
||||
path.resolve(process.argv[1]) === fileURLToPath(import.meta.url)
|
||||
) {
|
||||
await prepareMacosCodex();
|
||||
}
|
||||
@@ -0,0 +1,197 @@
|
||||
import assert from 'node:assert/strict';
|
||||
import { createHash } from 'node:crypto';
|
||||
import fs from 'node:fs';
|
||||
import { test } from 'node:test';
|
||||
|
||||
import {
|
||||
lockedMacPackage,
|
||||
validateArchiveListing,
|
||||
verifyPackageIntegrity,
|
||||
} from './prepare-macos-codex.mjs';
|
||||
|
||||
const lock = JSON.parse(
|
||||
fs.readFileSync(new URL('../../../package-lock.json', import.meta.url)),
|
||||
);
|
||||
const version = JSON.parse(
|
||||
fs.readFileSync(new URL('../package.json', import.meta.url)),
|
||||
).devDependencies['@openai/codex'];
|
||||
|
||||
test('both macOS dependencies resolve from the lockfile without floating versions', () => {
|
||||
assert.equal(
|
||||
lockedMacPackage(lock, 'arm64', version).target,
|
||||
'aarch64-apple-darwin',
|
||||
);
|
||||
assert.equal(
|
||||
lockedMacPackage(lock, 'x64', version).target,
|
||||
'x86_64-apple-darwin',
|
||||
);
|
||||
assert.throws(() => lockedMacPackage(lock, 'other', version));
|
||||
assert.throws(() => lockedMacPackage(lock, 'x64', '0.0.0'));
|
||||
});
|
||||
|
||||
test('native package integrity rejects tampering', () => {
|
||||
const bytes = Buffer.from('pinned package');
|
||||
const integrity = `sha512-${createHash('sha512').update(bytes).digest('base64')}`;
|
||||
verifyPackageIntegrity(bytes, integrity);
|
||||
assert.throws(() =>
|
||||
verifyPackageIntegrity(Buffer.from('modified'), integrity),
|
||||
);
|
||||
});
|
||||
|
||||
test('archive traversal and non-package entries fail closed', () => {
|
||||
validateArchiveListing(
|
||||
'package/package.json\npackage/vendor/target/bin/codex\n',
|
||||
);
|
||||
for (const listing of [
|
||||
'',
|
||||
'/tmp/payload',
|
||||
'package/../private',
|
||||
'other/file',
|
||||
'package/..\\file',
|
||||
]) {
|
||||
assert.throws(() => validateArchiveListing(listing));
|
||||
}
|
||||
});
|
||||
|
||||
test('CI pipeline is manual, publishes the macOS partition and never reuses a developer workspace', () => {
|
||||
const pipeline = fs.readFileSync(
|
||||
new URL(
|
||||
'../../../jenkins/Jenkinsfile.ai-game-creator-shell-macos-build',
|
||||
import.meta.url,
|
||||
),
|
||||
'utf8',
|
||||
);
|
||||
for (const required of [
|
||||
'genarrative-agc-macos',
|
||||
'disableConcurrentBuilds()',
|
||||
'$AGC_AGENT_ROOT',
|
||||
'StrictHostKeyChecking=yes',
|
||||
'git merge-base --is-ancestor',
|
||||
'allowEmptyArchive: false',
|
||||
"string(name: 'AGC_UPDATE_CHANNEL', defaultValue: 'dev'",
|
||||
'AGC_UPDATE_CHANNEL=${params.AGC_UPDATE_CHANNEL}',
|
||||
"string(credentialsId: 'AgcUpdaterSigningKey'",
|
||||
"string(credentialsId: 'AgcUpdaterSigningKeyPassword'",
|
||||
"string(credentialsId: 'AliyunAccessKeyId'",
|
||||
"string(credentialsId: 'AliyunaccessKeySecret'",
|
||||
'AGC_RELEASE_VERSION',
|
||||
'OSSUTIL_BIN',
|
||||
// 并行度必须可调:节点是共用机器,写死容易把整机压满或反过来浪费一半核心。
|
||||
"string(name: 'CARGO_BUILD_JOBS', defaultValue: '8'",
|
||||
'CARGO_BUILD_JOBS=${params.CARGO_BUILD_JOBS}',
|
||||
// Agent 工作区按约定匹配,不写死节点名:节点改名(-local → -01)后守卫仍成立。
|
||||
'"$HOME"/Library/Jenkins/agents/*/workspace/*',
|
||||
// 上一次发布的 commit 落在 master 上,取到它更新摘要才不会退化成「最近提交」。
|
||||
'refs/heads/master:refs/remotes/origin/master',
|
||||
]) {
|
||||
assert.ok(pipeline.includes(required), required);
|
||||
}
|
||||
assert.ok(
|
||||
!pipeline.includes('genarrative-agc-macos-local'),
|
||||
'Jenkinsfile 不得写死具体节点名',
|
||||
);
|
||||
// 这条管线是正式发布入口(与 Windows 对称):默认真发布,演练需显式勾选。
|
||||
assert.match(
|
||||
pipeline,
|
||||
/booleanParam\(name: 'AGC_RELEASE_DRY_RUN', defaultValue: false/u,
|
||||
'Channel 发布默认必须是真发布,演练只能显式勾选',
|
||||
);
|
||||
// 节点是办公机:离线期间排队的旧构建必须自行让位,且跳过要覆盖后续全部阶段。
|
||||
assert.match(
|
||||
pipeline,
|
||||
/booleanParam\(name: 'SKIP_IF_SUPERSEDED', defaultValue: false/u,
|
||||
);
|
||||
// 仓库文件不得出现节点用户名/个人 Home 路径:换机或改名后必须仍然可用。
|
||||
assert.ok(
|
||||
!pipeline.includes('/Users/'),
|
||||
'Jenkinsfile 不得写死个人 Home 路径,工具链位置应按 $HOME 展开',
|
||||
);
|
||||
assert.ok(
|
||||
pipeline.includes('export PATH="$HOME/'),
|
||||
'PATH 必须在 shell 步骤里按 $HOME 展开',
|
||||
);
|
||||
// 超时必须高于实测最慢(78 分钟冷构建 + 共用机器),否则会被中断在链接阶段。
|
||||
assert.ok(
|
||||
pipeline.includes('timeout(time: 150'),
|
||||
'构建超时上限必须留出冷构建余量',
|
||||
);
|
||||
for (const diagnostic of ['macOS 发布失败', '被中断']) {
|
||||
assert.ok(pipeline.includes(diagnostic), diagnostic);
|
||||
}
|
||||
assert.ok(
|
||||
pipeline.includes('.jenkins-superseded-by'),
|
||||
'必须记录被推进的标记供后续阶段判定',
|
||||
);
|
||||
assert.equal(
|
||||
(pipeline.match(/env\.AGC_BUILD_SUPERSEDED != 'true'/gu) ?? []).length,
|
||||
3,
|
||||
'Toolchain / Package / Archive 三个阶段都必须按跳过标记收口',
|
||||
);
|
||||
for (const forbidden of [
|
||||
'triggers {',
|
||||
'cron(',
|
||||
'pollSCM(',
|
||||
'git clean -fdx',
|
||||
// release:upload 会重新触发一次完整构建,既翻倍耗时也绕过本 Job 的验签门禁。
|
||||
'release:upload',
|
||||
]) {
|
||||
assert.ok(!pipeline.includes(forbidden), forbidden);
|
||||
}
|
||||
});
|
||||
|
||||
test('macOS release entry verifies the updater signature before uploading', () => {
|
||||
const entry = fs.readFileSync(
|
||||
new URL('./build-macos-ci.mjs', import.meta.url),
|
||||
'utf8',
|
||||
);
|
||||
const verifyIndex = entry.indexOf('verifyUpdaterSignature({');
|
||||
const uploadIndex = entry.indexOf('uploadReleaseArtifacts(release');
|
||||
assert.ok(verifyIndex > 0, '必须调用更新包验签');
|
||||
assert.ok(uploadIndex > 0, '必须调用 OSS 上传');
|
||||
assert.ok(verifyIndex < uploadIndex, '必须先验签再上传,验不过不得写 OSS');
|
||||
// 无签名私钥时禁止构建:未签名的更新包会被客户端一律拒绝。
|
||||
assert.ok(entry.includes('TAURI_SIGNING_PRIVATE_KEY'));
|
||||
// `--no-sign` 会连带跳过 updater 的 minisign 签名,产物将没有 .sig,入口不得传它。
|
||||
assert.ok(
|
||||
!entry.includes("'--no-sign'"),
|
||||
'--no-sign 会同时跳过 updater 签名,产物缺少 .sig',
|
||||
);
|
||||
// workspace 会跨构建保留产物:必须先删本次要写的对象,否则会因同名 DMG 失败,
|
||||
// 或让上一轮遗留的 .sig 让验签门禁误通过。
|
||||
for (const required of [
|
||||
// 清理对象用派生的产品名算出来,而不是写死某个名字。
|
||||
'${updaterArtifactName}.sig',
|
||||
'${firstInstallName}.sha256',
|
||||
'fs.rmSync(stale, { force: true })',
|
||||
"'-ov'",
|
||||
]) {
|
||||
assert.ok(entry.includes(required), required);
|
||||
}
|
||||
});
|
||||
|
||||
test('macOS release entry and smoke script derive product names from config and the bundle', () => {
|
||||
const entry = fs.readFileSync(
|
||||
new URL('./build-macos-ci.mjs', import.meta.url),
|
||||
'utf8',
|
||||
);
|
||||
// 产品名决定 *.app、updater 归档与 DMG 卷名:写死会在改名后静默找错对象。
|
||||
assert.ok(entry.includes('readProductName'), '入口必须从 Tauri 配置读产品名');
|
||||
assert.ok(!entry.includes('陶泥儿'), 'macOS 发布入口不得写死产品名');
|
||||
assert.ok(
|
||||
entry.includes('_${version}_universal.dmg'),
|
||||
'首装包名必须保留清单侧唯一匹配所需的后缀',
|
||||
);
|
||||
|
||||
const smoke = fs.readFileSync(
|
||||
new URL('./check-macos-bundle.mjs', import.meta.url),
|
||||
'utf8',
|
||||
);
|
||||
assert.ok(!smoke.includes('陶泥儿'), '校验脚本不得写死产品名');
|
||||
for (const required of [
|
||||
'path.basename(source)',
|
||||
'Print :CFBundleExecutable',
|
||||
"'--clone'",
|
||||
]) {
|
||||
assert.ok(smoke.includes(required), required);
|
||||
}
|
||||
});
|
||||
@@ -312,34 +312,15 @@ function runShard(executable, shardIndex, shardCount, shardTestNames) {
|
||||
},
|
||||
);
|
||||
|
||||
const failureLines = [];
|
||||
let inFailureList = false;
|
||||
// Rust 的首个 failures: 后有空行,不能按空行结束采集,否则会丢掉 panic 详情。
|
||||
// 只保存有界尾部;成功时不输出,失败时优先输出完整失败段。
|
||||
let stdoutTail = '';
|
||||
let stderr = '';
|
||||
const consumeLine = (rawLine) => {
|
||||
const line = rawLine.replace(/\r$/, '');
|
||||
if (line.includes('failures:')) {
|
||||
inFailureList = true;
|
||||
return;
|
||||
}
|
||||
if (inFailureList) {
|
||||
if (line.trim().length === 0) {
|
||||
inFailureList = false;
|
||||
return;
|
||||
}
|
||||
failureLines.push(line.trim());
|
||||
}
|
||||
};
|
||||
|
||||
child.stdout.setEncoding('utf8');
|
||||
child.stderr.setEncoding('utf8');
|
||||
let stdoutBuffer = '';
|
||||
child.stdout.on('data', (chunk) => {
|
||||
stdoutBuffer += chunk;
|
||||
const lines = stdoutBuffer.split('\n');
|
||||
stdoutBuffer = lines.pop() ?? '';
|
||||
for (const line of lines) {
|
||||
consumeLine(line);
|
||||
}
|
||||
stdoutTail = (stdoutTail + chunk).slice(-64_000);
|
||||
});
|
||||
child.stderr.on('data', (chunk) => {
|
||||
stderr += chunk;
|
||||
@@ -356,12 +337,17 @@ function runShard(executable, shardIndex, shardCount, shardTestNames) {
|
||||
});
|
||||
});
|
||||
child.on('close', (code) => {
|
||||
const output = stdoutTail.replace(/\r\n/g, '\n');
|
||||
const failureStart = output.indexOf('failures:\n');
|
||||
resolve({
|
||||
label,
|
||||
ok: code === 0,
|
||||
durationMs: Date.now() - startedAt,
|
||||
testCount: shardTestNames.length,
|
||||
failures: failureLines,
|
||||
failures: output
|
||||
.slice(failureStart < 0 ? 0 : failureStart)
|
||||
.trim()
|
||||
.split('\n'),
|
||||
stderr,
|
||||
});
|
||||
});
|
||||
@@ -438,7 +424,7 @@ async function main() {
|
||||
}
|
||||
failed = true;
|
||||
console.error(
|
||||
`[rust-shards] ${result.label} FAILED: ${result.testCount} test(s) in ${formatDuration(result.durationMs)}`,
|
||||
`[rust-shards] ${result.label} FAILED (selected ${result.testCount} test(s)) in ${formatDuration(result.durationMs)}`,
|
||||
);
|
||||
for (const failure of result.failures) {
|
||||
console.error(`[rust-shards] ${failure}`);
|
||||
|
||||
@@ -0,0 +1,70 @@
|
||||
import assert from 'node:assert/strict';
|
||||
import { spawnSync } from 'node:child_process';
|
||||
import fs from 'node:fs';
|
||||
import os from 'node:os';
|
||||
import path from 'node:path';
|
||||
import test from 'node:test';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
|
||||
const runner = fileURLToPath(
|
||||
new URL('./run-rust-shell-test-shards.mjs', import.meta.url),
|
||||
);
|
||||
|
||||
function runFixture(t, source) {
|
||||
const root = fs.mkdtempSync(path.join(os.tmpdir(), 'agc-shard-output-'));
|
||||
t.after(() => fs.rmSync(root, { recursive: true, force: true }));
|
||||
fs.mkdirSync(path.join(root, 'src'));
|
||||
fs.writeFileSync(
|
||||
path.join(root, 'Cargo.toml'),
|
||||
'[package]\nname = "shard-output-fixture"\nversion = "0.1.0"\nedition = "2021"\n',
|
||||
);
|
||||
fs.writeFileSync(path.join(root, 'src/lib.rs'), source);
|
||||
const result = spawnSync(
|
||||
process.execPath,
|
||||
[
|
||||
runner,
|
||||
`--manifest=${path.join(root, 'Cargo.toml')}`,
|
||||
'--target-kind=lib',
|
||||
'--no-locked',
|
||||
'--shards=1',
|
||||
`--shard-tmp-root=${path.join(root, 'tmp')}`,
|
||||
],
|
||||
{
|
||||
encoding: 'utf8',
|
||||
timeout: 60_000,
|
||||
windowsHide: true,
|
||||
env: { ...process.env, CARGO_TARGET_DIR: path.join(root, 'target') },
|
||||
},
|
||||
);
|
||||
assert.ifError(result.error);
|
||||
return { status: result.status, output: result.stdout + result.stderr };
|
||||
}
|
||||
|
||||
test('failed shard retains panic details and separates selected count from failures', (t) => {
|
||||
const result = runFixture(
|
||||
t,
|
||||
`
|
||||
#[test]
|
||||
fn passing_case() {}
|
||||
#[test]
|
||||
fn failing_case() {
|
||||
assert_eq!(1, 2, "shard panic evidence");
|
||||
}
|
||||
`,
|
||||
);
|
||||
assert.equal(result.status, 1, result.output);
|
||||
assert.match(result.output, /FAILED \(selected 2 test\(s\)\)/);
|
||||
assert.match(result.output, /failing_case/);
|
||||
assert.match(result.output, /panicked at src[\\/]lib\.rs:/);
|
||||
assert.match(result.output, /shard panic evidence/);
|
||||
assert.match(result.output, /left: 1/);
|
||||
assert.match(result.output, /right: 2/);
|
||||
assert.match(result.output, /1 passed; 1 failed/);
|
||||
});
|
||||
|
||||
test('successful shard keeps its compact summary', (t) => {
|
||||
const result = runFixture(t, '#[test]\nfn passing_case() {}\n');
|
||||
assert.equal(result.status, 0, result.output);
|
||||
assert.match(result.output, /shard 1\/1 ok: 1 test\(s\)/);
|
||||
assert.doesNotMatch(result.output, /test passing_case \.\.\. ok/);
|
||||
});
|
||||
@@ -9,7 +9,9 @@ export const EXPECTED_SKILL_NAMES = Object.freeze([
|
||||
'agc-browser-playtest',
|
||||
'agc-client-projection',
|
||||
'agc-game-production-workflow',
|
||||
'agc-godot-editor',
|
||||
'agc-project-structure',
|
||||
'agc-unity-editor',
|
||||
'agc-web-game-development',
|
||||
'taonier-art-assets',
|
||||
]);
|
||||
|
||||
@@ -0,0 +1,177 @@
|
||||
import {
|
||||
createHash,
|
||||
createPublicKey,
|
||||
verify as cryptoVerify,
|
||||
} from 'node:crypto';
|
||||
import fs from 'node:fs';
|
||||
import path from 'node:path';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
|
||||
/**
|
||||
* 更新包签名门禁:用产物里烘焙的 updater 公钥校验 `.sig`,
|
||||
* 防止「发布出去的更新包没人装得上」——客户端校验失败会直接拒绝安装,
|
||||
* 而且公钥发布后不可更换,所以必须在构建期、上传前就失败关闭。
|
||||
*
|
||||
* 格式说明(与 Tauri 2 的实际产出对齐,均为实测):
|
||||
* - `tauri.conf.json` 的 `plugins.updater.pubkey` 是「minisign 公钥文本」的 base64;
|
||||
* - 产物旁的 `<artifact>.sig` 是「minisign 签名文本」的 base64;
|
||||
* - 公钥 blob 42 字节(alg `Ed` + 8 字节 keyId + 32 字节 Ed25519 公钥);
|
||||
* - 签名 blob 74 字节(alg `Ed` 或 `ED` + 8 字节 keyId + 64 字节签名);
|
||||
* - Tauri 产出的是 `ED`:先对文件做 BLAKE2b-512,再对摘要做 Ed25519 签名。
|
||||
*/
|
||||
const appRoot = fileURLToPath(new URL('..', import.meta.url));
|
||||
const defaultTauriConfigPath = path.join(appRoot, 'src-tauri/tauri.conf.json');
|
||||
const defaultMacosConfigPath = path.join(
|
||||
appRoot,
|
||||
'src-tauri/tauri.macos.conf.json',
|
||||
);
|
||||
|
||||
const PUBLIC_KEY_ALGORITHM = 'Ed';
|
||||
const RAW_ALGORITHM = 'Ed';
|
||||
const PREHASHED_ALGORITHM = 'ED';
|
||||
|
||||
function unwrapMinisignText(value, label) {
|
||||
if (typeof value !== 'string' || value.trim().length === 0) {
|
||||
throw new Error(`${label} 为空`);
|
||||
}
|
||||
const trimmed = value.trim();
|
||||
if (trimmed.startsWith('untrusted comment:')) return trimmed;
|
||||
const decoded = Buffer.from(trimmed, 'base64').toString('utf8');
|
||||
if (!decoded.startsWith('untrusted comment:')) {
|
||||
throw new Error(`${label} 不是 minisign 内容(缺少 untrusted comment 头)`);
|
||||
}
|
||||
return decoded;
|
||||
}
|
||||
|
||||
function contentLines(text) {
|
||||
return text
|
||||
.split('\n')
|
||||
.map((line) => line.trim())
|
||||
.filter((line) => line.length > 0);
|
||||
}
|
||||
|
||||
/** 解析 updater 公钥(`tauri.conf.json` 里的 base64 值或 minisign 文本)。 */
|
||||
export function decodeUpdaterPublicKey(value, label = 'updater 公钥') {
|
||||
const lines = contentLines(unwrapMinisignText(value, label));
|
||||
if (lines.length < 2) throw new Error(`${label} 缺少密钥内容行`);
|
||||
const blob = Buffer.from(lines[1], 'base64');
|
||||
if (blob.length !== 42) {
|
||||
throw new Error(
|
||||
`${label} 长度异常:期望 42 字节,实际 ${blob.length} 字节`,
|
||||
);
|
||||
}
|
||||
const algorithm = blob.subarray(0, 2).toString('latin1');
|
||||
if (algorithm !== PUBLIC_KEY_ALGORITHM) {
|
||||
throw new Error(`${label} 算法不受支持:${algorithm}`);
|
||||
}
|
||||
return { algorithm, keyId: blob.subarray(2, 10), key: blob.subarray(10) };
|
||||
}
|
||||
|
||||
/** 解析 `.sig`(base64 值或 minisign 文本)。 */
|
||||
export function decodeUpdaterSignature(value, label = '更新包签名') {
|
||||
const lines = contentLines(unwrapMinisignText(value, label));
|
||||
if (lines.length < 2) throw new Error(`${label} 缺少签名内容行`);
|
||||
const blob = Buffer.from(lines[1], 'base64');
|
||||
if (blob.length !== 74) {
|
||||
throw new Error(
|
||||
`${label} 长度异常:期望 74 字节,实际 ${blob.length} 字节`,
|
||||
);
|
||||
}
|
||||
const algorithm = blob.subarray(0, 2).toString('latin1');
|
||||
if (algorithm !== RAW_ALGORITHM && algorithm !== PREHASHED_ALGORITHM) {
|
||||
throw new Error(`${label} 算法不受支持:${algorithm}`);
|
||||
}
|
||||
return {
|
||||
algorithm,
|
||||
keyId: blob.subarray(2, 10),
|
||||
signature: blob.subarray(10),
|
||||
trustedComment: lines[2] ?? '',
|
||||
};
|
||||
}
|
||||
|
||||
function publicKeyObject(rawKey) {
|
||||
return createPublicKey({
|
||||
key: { kty: 'OKP', crv: 'Ed25519', x: rawKey.toString('base64url') },
|
||||
format: 'jwk',
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* 校验更新包签名;任何不一致都抛错(调用方据此失败关闭)。
|
||||
*/
|
||||
export function verifyUpdaterSignature({
|
||||
artifactPath,
|
||||
signaturePath,
|
||||
pubkey,
|
||||
}) {
|
||||
const publicKey = decodeUpdaterPublicKey(pubkey);
|
||||
const signature = decodeUpdaterSignature(
|
||||
fs.readFileSync(signaturePath, 'utf8'),
|
||||
);
|
||||
if (!publicKey.keyId.equals(signature.keyId)) {
|
||||
throw new Error(
|
||||
`更新包签名与内置公钥的 keyId 不一致:公钥 ${publicKey.keyId.toString('hex')},签名 ${signature.keyId.toString('hex')};` +
|
||||
'签名私钥与产物内烘焙的公钥不是同一对,发布后客户端会拒绝安装',
|
||||
);
|
||||
}
|
||||
const payload = fs.readFileSync(artifactPath);
|
||||
const message =
|
||||
signature.algorithm === PREHASHED_ALGORITHM
|
||||
? createHash('blake2b512').update(payload).digest()
|
||||
: payload;
|
||||
if (
|
||||
!cryptoVerify(
|
||||
null,
|
||||
message,
|
||||
publicKeyObject(publicKey.key),
|
||||
signature.signature,
|
||||
)
|
||||
) {
|
||||
throw new Error(
|
||||
`更新包签名校验失败:${path.basename(artifactPath)};该产物无法被客户端接受`,
|
||||
);
|
||||
}
|
||||
return {
|
||||
algorithm: signature.algorithm,
|
||||
keyId: publicKey.keyId.toString('hex'),
|
||||
trustedComment: signature.trustedComment,
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* 读取该平台生效的 updater 公钥:macOS 配置可覆盖基础配置,与构建期行为一致。
|
||||
*/
|
||||
export function readUpdaterPubkey({
|
||||
configPath = defaultTauriConfigPath,
|
||||
platformConfigPath = defaultMacosConfigPath,
|
||||
} = {}) {
|
||||
const readPubkey = (file) => {
|
||||
if (!fs.existsSync(file)) return null;
|
||||
const config = JSON.parse(fs.readFileSync(file, 'utf8'));
|
||||
return config?.plugins?.updater?.pubkey ?? null;
|
||||
};
|
||||
const pubkey = readPubkey(platformConfigPath) ?? readPubkey(configPath);
|
||||
if (!pubkey) throw new Error('未在 Tauri 配置中找到 plugins.updater.pubkey');
|
||||
return pubkey;
|
||||
}
|
||||
|
||||
if (
|
||||
process.argv[1] &&
|
||||
path.resolve(process.argv[1]) === fileURLToPath(import.meta.url)
|
||||
) {
|
||||
const [artifactPath, signaturePath = `${artifactPath}.sig`] =
|
||||
process.argv.slice(2);
|
||||
if (!artifactPath) {
|
||||
throw new Error(
|
||||
'用法:node verify-updater-signature.mjs <更新包> [<签名文件>]',
|
||||
);
|
||||
}
|
||||
const result = verifyUpdaterSignature({
|
||||
artifactPath,
|
||||
signaturePath,
|
||||
pubkey: readUpdaterPubkey(),
|
||||
});
|
||||
console.log(
|
||||
`[agc-macos] 更新包签名校验通过:${path.basename(artifactPath)}(alg=${result.algorithm},keyId=${result.keyId})`,
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,182 @@
|
||||
import assert from 'node:assert/strict';
|
||||
import {
|
||||
createHash,
|
||||
generateKeyPairSync,
|
||||
randomBytes,
|
||||
sign as cryptoSign,
|
||||
} from 'node:crypto';
|
||||
import fs from 'node:fs';
|
||||
import os from 'node:os';
|
||||
import path from 'node:path';
|
||||
import test from 'node:test';
|
||||
|
||||
import {
|
||||
decodeUpdaterPublicKey,
|
||||
decodeUpdaterSignature,
|
||||
readUpdaterPubkey,
|
||||
verifyUpdaterSignature,
|
||||
} from './verify-updater-signature.mjs';
|
||||
|
||||
/**
|
||||
* 用进程内生成的 Ed25519 密钥自造 minisign 结构,
|
||||
* 覆盖 Tauri 实际使用的 `ED`(BLAKE2b-512 预哈希)与 `Ed`(原文)两种模式。
|
||||
*/
|
||||
function createKeyMaterial() {
|
||||
const { publicKey, privateKey } = generateKeyPairSync('ed25519');
|
||||
const rawKey = Buffer.from(
|
||||
publicKey.export({ format: 'jwk' }).x,
|
||||
'base64url',
|
||||
);
|
||||
const keyId = randomBytes(8);
|
||||
const pubkey = Buffer.from(
|
||||
`untrusted comment: minisign public key: ${keyId.reverse().toString('hex').toUpperCase()}\n` +
|
||||
`${Buffer.concat([Buffer.from('Ed'), keyId, rawKey]).toString('base64')}\n`,
|
||||
).toString('base64');
|
||||
return { privateKey, keyId, rawKey, pubkey };
|
||||
}
|
||||
|
||||
function signFixture({ privateKey, keyId }, payload, algorithm) {
|
||||
const message =
|
||||
algorithm === 'ED'
|
||||
? createHash('blake2b512').update(payload).digest()
|
||||
: payload;
|
||||
const signature = cryptoSign(null, message, privateKey);
|
||||
const blob = Buffer.concat([Buffer.from(algorithm), keyId, signature]);
|
||||
const globalSignature = cryptoSign(null, blob, privateKey);
|
||||
return Buffer.from(
|
||||
'untrusted comment: signature from tauri secret key\n' +
|
||||
`${blob.toString('base64')}\n` +
|
||||
'trusted comment: timestamp:0\tfile:fixture\n' +
|
||||
`${globalSignature.toString('base64')}\n`,
|
||||
).toString('base64');
|
||||
}
|
||||
|
||||
function withFixture(run) {
|
||||
const directory = fs.mkdtempSync(path.join(os.tmpdir(), 'agc-sig-test-'));
|
||||
try {
|
||||
const artifactPath = path.join(directory, 'app.app.tar.gz');
|
||||
fs.writeFileSync(artifactPath, 'update payload');
|
||||
return run({ directory, artifactPath });
|
||||
} finally {
|
||||
fs.rmSync(directory, { recursive: true, force: true });
|
||||
}
|
||||
}
|
||||
|
||||
test('接受 Tauri 实际使用的 ED(BLAKE2b-512 预哈希)签名', () => {
|
||||
withFixture(({ directory, artifactPath }) => {
|
||||
const material = createKeyMaterial();
|
||||
const signaturePath = path.join(directory, 'app.app.tar.gz.sig');
|
||||
fs.writeFileSync(
|
||||
signaturePath,
|
||||
signFixture(material, fs.readFileSync(artifactPath), 'ED'),
|
||||
);
|
||||
const result = verifyUpdaterSignature({
|
||||
artifactPath,
|
||||
signaturePath,
|
||||
pubkey: material.pubkey,
|
||||
});
|
||||
assert.equal(result.algorithm, 'ED');
|
||||
assert.equal(result.keyId, material.keyId.toString('hex'));
|
||||
});
|
||||
});
|
||||
|
||||
test('接受原文 Ed 签名,两种算法互不通用', () => {
|
||||
withFixture(({ directory, artifactPath }) => {
|
||||
const material = createKeyMaterial();
|
||||
const payload = fs.readFileSync(artifactPath);
|
||||
const signaturePath = path.join(directory, 'app.app.tar.gz.sig');
|
||||
fs.writeFileSync(signaturePath, signFixture(material, payload, 'Ed'));
|
||||
assert.equal(
|
||||
verifyUpdaterSignature({
|
||||
artifactPath,
|
||||
signaturePath,
|
||||
pubkey: material.pubkey,
|
||||
}).algorithm,
|
||||
'Ed',
|
||||
);
|
||||
// 原文模式下签名的是别的载荷时必须失败:证明确实在校验内容而非只看结构。
|
||||
fs.writeFileSync(
|
||||
signaturePath,
|
||||
signFixture(material, Buffer.from('别的载荷'), 'Ed'),
|
||||
);
|
||||
assert.throws(
|
||||
() =>
|
||||
verifyUpdaterSignature({
|
||||
artifactPath,
|
||||
signaturePath,
|
||||
pubkey: material.pubkey,
|
||||
}),
|
||||
/签名校验失败/u,
|
||||
);
|
||||
});
|
||||
});
|
||||
|
||||
test('产物被篡改时失败关闭', () => {
|
||||
withFixture(({ directory, artifactPath }) => {
|
||||
const material = createKeyMaterial();
|
||||
const signaturePath = path.join(directory, 'app.app.tar.gz.sig');
|
||||
fs.writeFileSync(
|
||||
signaturePath,
|
||||
signFixture(material, fs.readFileSync(artifactPath), 'ED'),
|
||||
);
|
||||
fs.writeFileSync(artifactPath, 'tampered payload');
|
||||
assert.throws(
|
||||
() =>
|
||||
verifyUpdaterSignature({
|
||||
artifactPath,
|
||||
signaturePath,
|
||||
pubkey: material.pubkey,
|
||||
}),
|
||||
/签名校验失败/u,
|
||||
);
|
||||
});
|
||||
});
|
||||
|
||||
test('签名私钥与内置公钥不是同一对时给出明确错误', () => {
|
||||
withFixture(({ directory, artifactPath }) => {
|
||||
const signing = createKeyMaterial();
|
||||
const baked = createKeyMaterial();
|
||||
const signaturePath = path.join(directory, 'app.app.tar.gz.sig');
|
||||
fs.writeFileSync(
|
||||
signaturePath,
|
||||
signFixture(signing, fs.readFileSync(artifactPath), 'ED'),
|
||||
);
|
||||
assert.throws(
|
||||
() =>
|
||||
verifyUpdaterSignature({
|
||||
artifactPath,
|
||||
signaturePath,
|
||||
pubkey: baked.pubkey,
|
||||
}),
|
||||
/keyId 不一致/u,
|
||||
);
|
||||
});
|
||||
});
|
||||
|
||||
test('公钥或签名格式非法时拒绝解析', () => {
|
||||
assert.throws(() => decodeUpdaterPublicKey(''), /为空/u);
|
||||
assert.throws(
|
||||
() => decodeUpdaterPublicKey('bm90IGEgbWluaXNpZ24ga2V5'),
|
||||
/不是 minisign 内容/u,
|
||||
);
|
||||
assert.throws(
|
||||
() =>
|
||||
decodeUpdaterPublicKey(
|
||||
Buffer.from('untrusted comment: x\nAAAA\n').toString('base64'),
|
||||
),
|
||||
/长度异常/u,
|
||||
);
|
||||
assert.throws(
|
||||
() =>
|
||||
decodeUpdaterSignature(
|
||||
Buffer.from('untrusted comment: x\nAAAA\n').toString('base64'),
|
||||
),
|
||||
/长度异常/u,
|
||||
);
|
||||
});
|
||||
|
||||
test('仓库里配置的 updater 公钥可被解析(两平台共用)', () => {
|
||||
const decoded = decodeUpdaterPublicKey(readUpdaterPubkey());
|
||||
assert.equal(decoded.algorithm, 'Ed');
|
||||
assert.equal(decoded.key.length, 32);
|
||||
});
|
||||
+13
@@ -1804,6 +1804,7 @@ dependencies = [
|
||||
"editor-adapter-api",
|
||||
"futures",
|
||||
"getrandom 0.3.4",
|
||||
"godot-editor-bridge",
|
||||
"http",
|
||||
"image",
|
||||
"jsonschema",
|
||||
@@ -2030,6 +2031,18 @@ dependencies = [
|
||||
"system-deps",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "godot-editor-bridge"
|
||||
version = "0.1.0"
|
||||
dependencies = [
|
||||
"editor-adapter-api",
|
||||
"serde",
|
||||
"serde_json",
|
||||
"sha2",
|
||||
"tempfile",
|
||||
"windows-sys 0.61.2",
|
||||
]
|
||||
|
||||
[[package]]
|
||||
name = "gtk"
|
||||
version = "0.18.2"
|
||||
|
||||
@@ -17,6 +17,7 @@ cocos-editor = ["cocos-editor-bridge/process-discovery"]
|
||||
cocos-editor-execute = ["cocos-editor", "cocos-editor-bridge/windows-bootstrap"]
|
||||
cocos-editor-injection = ["cocos-editor-execute", "cocos-editor-bridge/windows-injection"]
|
||||
unity-editor-execute = []
|
||||
godot-editor-execute = []
|
||||
|
||||
[build-dependencies]
|
||||
serde = { version = "1", features = ["derive"] }
|
||||
@@ -35,6 +36,7 @@ agent-runtime-core = { path = "../../../server-rs/crates/agent-runtime-core" }
|
||||
cocos-editor-bridge = { path = "../../../plugins/agc-cocos-editor/native/cocos-editor-bridge", default-features = false }
|
||||
editor-adapter-api = { path = "../../../server-rs/crates/editor-adapter-api" }
|
||||
unity-editor-bridge = { path = "../../../plugins/agc-unity-editor/native/unity-editor-bridge" }
|
||||
godot-editor-bridge = { path = "../../../plugins/agc-godot-editor/native/godot-editor-bridge" }
|
||||
base64 = "0.22"
|
||||
axum = "0.8"
|
||||
chromiumoxide = "0.9.1"
|
||||
|
||||
@@ -2,6 +2,8 @@
|
||||
mod codex_bundle;
|
||||
#[path = "build_support/frontend_dist_guard.rs"]
|
||||
mod frontend_dist_guard;
|
||||
#[path = "build_support/godot_bundle.rs"]
|
||||
mod godot_bundle;
|
||||
#[path = "build_support/runtime_prompt_bundle.rs"]
|
||||
mod runtime_prompt_bundle;
|
||||
|
||||
@@ -31,7 +33,23 @@ fn sha256_file(path: &std::path::Path) -> Result<String, std::io::Error> {
|
||||
fn stage_bundled_codex_cli(manifest_dir: &std::path::Path) {
|
||||
let target = env::var("TARGET").expect("Cargo TARGET");
|
||||
println!("cargo:rustc-env=AGC_BUILD_TARGET={target}");
|
||||
let Some(layout) = codex_bundle::for_target(&target) else {
|
||||
if target.contains("apple-darwin") {
|
||||
// Tauri 的 universal 两次 Cargo 编译共用 resource staging,
|
||||
// 每次都生成完整双架构目录,最终 bundle 不取决于最后编译的切片。
|
||||
let staging = manifest_dir.join("resources/codex/mac-native");
|
||||
if staging.exists() {
|
||||
fs::remove_dir_all(&staging).expect("清理 macOS Codex staging 失败");
|
||||
}
|
||||
for target in ["aarch64-apple-darwin", "x86_64-apple-darwin"] {
|
||||
stage_codex_target(manifest_dir, target);
|
||||
}
|
||||
} else {
|
||||
stage_codex_target(manifest_dir, &target);
|
||||
}
|
||||
}
|
||||
|
||||
fn stage_codex_target(manifest_dir: &std::path::Path, target: &str) {
|
||||
let Some(layout) = codex_bundle::for_target(target) else {
|
||||
assert!(
|
||||
!target.contains("windows") && !target.contains("apple-darwin"),
|
||||
"不支持的 Codex 随包目标:{target}"
|
||||
@@ -81,7 +99,7 @@ fn stage_bundled_codex_cli(manifest_dir: &std::path::Path) {
|
||||
&fs::read(source.join("codex-package.json")).expect("读取 Codex 原生包元数据失败"),
|
||||
)
|
||||
.expect("Codex 原生包元数据无效");
|
||||
codex_bundle::validate_package_metadata(&metadata, &target, layout)
|
||||
codex_bundle::validate_package_metadata(&metadata, target, layout)
|
||||
.unwrap_or_else(|error| panic!("{error}"));
|
||||
let target_dir = manifest_dir.join("resources/codex").join(layout.directory);
|
||||
let notice = target_dir.join("NOTICE.md");
|
||||
@@ -197,6 +215,7 @@ fn main() {
|
||||
let manifest_path = manifest_dir.join("prompts/runtime/manifest.json");
|
||||
stage_bundled_codex_cli(&manifest_dir);
|
||||
prepare_unity_editor_helper(&manifest_dir);
|
||||
prepare_godot_editor_extension(&manifest_dir);
|
||||
stage_plugin_workspace(&manifest_dir);
|
||||
stage_cocos_editor_payload(&manifest_dir);
|
||||
let compiled = runtime_prompt_bundle::compile_manifest(&manifest_path)
|
||||
@@ -368,6 +387,39 @@ fn collect_unity_helper_sources(root: &std::path::Path, sources: &mut Vec<PathBu
|
||||
}
|
||||
}
|
||||
|
||||
fn prepare_godot_editor_extension(manifest_dir: &std::path::Path) {
|
||||
println!("cargo:rerun-if-env-changed=CARGO_FEATURE_GODOT_EDITOR_EXECUTE");
|
||||
if env::var_os("CARGO_FEATURE_GODOT_EDITOR_EXECUTE").is_none()
|
||||
|| env::var("TARGET").expect("Cargo TARGET") != "x86_64-pc-windows-msvc"
|
||||
{
|
||||
return;
|
||||
}
|
||||
let root = manifest_dir.join("../../../plugins/agc-godot-editor/native/gdextension");
|
||||
for source in godot_bundle::source_files(&root).unwrap_or_else(|error| panic!("{error}")) {
|
||||
println!("cargo:rerun-if-changed={}", source.display());
|
||||
}
|
||||
assert!(
|
||||
cfg!(windows),
|
||||
"构建 Godot 原生扩展需要 Windows x64 C 编译器"
|
||||
);
|
||||
let status = std::process::Command::new("powershell.exe")
|
||||
// Cargo 可能从 PowerShell 7 启动,Windows PowerShell 应使用自身模块目录。
|
||||
.env_remove("PSModulePath")
|
||||
.args([
|
||||
"-NoProfile",
|
||||
"-NonInteractive",
|
||||
"-ExecutionPolicy",
|
||||
"Bypass",
|
||||
"-File",
|
||||
])
|
||||
.arg(root.join("build.ps1"))
|
||||
.current_dir(&root)
|
||||
.status()
|
||||
.expect("无法启动 Godot 原生扩展构建脚本");
|
||||
assert!(status.success(), "Godot 原生扩展构建失败");
|
||||
godot_bundle::validate(&root).unwrap_or_else(|error| panic!("{error}"));
|
||||
}
|
||||
|
||||
/// 把 `plugins/` 工作区里的插件包随包映射到应用资源目录。
|
||||
///
|
||||
/// 只复制插件运行需要的清单、入口、面板和 native payload,不复制 native 源码、
|
||||
@@ -428,6 +480,15 @@ fn stage_plugin_workspace(manifest_dir: &std::path::Path) {
|
||||
}
|
||||
copy_plugin_tree(&plugin_root.join(&relative), &destination.join(&relative));
|
||||
}
|
||||
if name == "agc-godot-editor" {
|
||||
godot_bundle::stage(
|
||||
&plugin_root.join("native/gdextension"),
|
||||
&destination.join("native/gdextension"),
|
||||
&target,
|
||||
env::var_os("CARGO_FEATURE_GODOT_EDITOR_EXECUTE").is_some(),
|
||||
)
|
||||
.unwrap_or_else(|error| panic!("{error}"));
|
||||
}
|
||||
println!("cargo:rerun-if-changed={}", plugin_root.display());
|
||||
}
|
||||
}
|
||||
|
||||
@@ -49,7 +49,11 @@ pub fn for_target(target: &str) -> Option<Layout> {
|
||||
} else {
|
||||
"codex-darwin-x64"
|
||||
},
|
||||
directory: "mac-native",
|
||||
directory: if target.starts_with("aarch64") {
|
||||
"mac-native/darwin-arm64"
|
||||
} else {
|
||||
"mac-native/darwin-x64"
|
||||
},
|
||||
executable: "bin/codex",
|
||||
files: MAC_FILES,
|
||||
}),
|
||||
@@ -90,6 +94,9 @@ mod tests {
|
||||
let intel = for_target("x86_64-apple-darwin").unwrap();
|
||||
assert_eq!(intel.platform, "darwin-x64");
|
||||
assert_eq!(intel.npm_package, "codex-darwin-x64");
|
||||
assert_eq!(mac.directory, "mac-native/darwin-arm64");
|
||||
assert_eq!(intel.directory, "mac-native/darwin-x64");
|
||||
assert_ne!(mac.directory, intel.directory);
|
||||
let windows = for_target("x86_64-pc-windows-msvc").unwrap();
|
||||
assert_eq!(windows.directory, "win-x64");
|
||||
assert_eq!(windows.files.len(), 6);
|
||||
|
||||
@@ -0,0 +1,215 @@
|
||||
use sha2::{Digest, Sha256};
|
||||
use std::fs;
|
||||
use std::path::{Path, PathBuf};
|
||||
|
||||
pub const BUNDLE_FILES: [&str; 4] = [
|
||||
"bin/win-x64/agc_godot_editor.dll",
|
||||
"bin/win-x64/metadata.json",
|
||||
"vendor/LICENSE.txt",
|
||||
"vendor/provenance.json",
|
||||
];
|
||||
|
||||
fn plain_metadata(path: &Path) -> Result<fs::Metadata, String> {
|
||||
let metadata = fs::symlink_metadata(path)
|
||||
.map_err(|error| format!("Godot 资源不可读 {}:{error}", path.display()))?;
|
||||
#[cfg(windows)]
|
||||
let linked = {
|
||||
use std::os::windows::fs::MetadataExt;
|
||||
metadata.file_attributes() & 0x400 != 0
|
||||
};
|
||||
#[cfg(not(windows))]
|
||||
let linked = metadata.file_type().is_symlink();
|
||||
if linked {
|
||||
return Err(format!("Godot 资源不能经过链接:{}", path.display()));
|
||||
}
|
||||
Ok(metadata)
|
||||
}
|
||||
|
||||
fn read_bundle_file(root: &Path, relative: &str) -> Result<Vec<u8>, String> {
|
||||
plain_metadata(root)?;
|
||||
let mut path = root.to_path_buf();
|
||||
for component in Path::new(relative).components() {
|
||||
path.push(component);
|
||||
plain_metadata(&path)?;
|
||||
}
|
||||
let metadata = plain_metadata(&path)?;
|
||||
if !metadata.is_file() || metadata.len() == 0 {
|
||||
return Err(format!("Godot 随包资源缺失或为空:{}", path.display()));
|
||||
}
|
||||
if relative.ends_with("metadata.json") && metadata.len() > 64 * 1024 {
|
||||
return Err("Godot 构建元数据超过 64 KiB".to_string());
|
||||
}
|
||||
fs::read(&path).map_err(|error| format!("读取 Godot 资源失败:{error}"))
|
||||
}
|
||||
|
||||
pub fn validate(root: &Path) -> Result<Vec<(&'static str, Vec<u8>)>, String> {
|
||||
let files = BUNDLE_FILES
|
||||
.iter()
|
||||
.map(|relative| read_bundle_file(root, relative).map(|bytes| (*relative, bytes)))
|
||||
.collect::<Result<Vec<_>, _>>()?;
|
||||
let metadata: serde_json::Value = serde_json::from_slice(&files[1].1)
|
||||
.map_err(|error| format!("Godot 构建元数据无效:{error}"))?;
|
||||
for (field, expected) in [
|
||||
("protocol", "agc.godot.editor.v1"),
|
||||
("platform", "windows"),
|
||||
("arch", "x86_64"),
|
||||
("entrySymbol", "agc_godot_editor_init"),
|
||||
("minimumGodotVersion", "4.7"),
|
||||
] {
|
||||
if metadata[field].as_str() != Some(expected) {
|
||||
return Err(format!("Godot 构建元数据 {field} 不匹配"));
|
||||
}
|
||||
}
|
||||
if !metadata["buildId"].as_str().is_some_and(|value| {
|
||||
value.strip_prefix("sha256:").is_some_and(|digest| {
|
||||
digest.len() == 64 && digest.bytes().all(|byte| byte.is_ascii_hexdigit())
|
||||
})
|
||||
}) {
|
||||
return Err("Godot 构建身份无效".to_string());
|
||||
}
|
||||
let actual_sha256 = format!("{:x}", Sha256::digest(&files[0].1));
|
||||
if metadata["sha256"].as_str() != Some(actual_sha256.as_str()) {
|
||||
return Err("Godot DLL 与构建元数据 SHA256 不匹配".to_string());
|
||||
}
|
||||
Ok(files)
|
||||
}
|
||||
|
||||
pub fn stage(root: &Path, destination: &Path, target: &str, enabled: bool) -> Result<(), String> {
|
||||
if target != "x86_64-pc-windows-msvc" || !enabled {
|
||||
return Ok(());
|
||||
}
|
||||
for (relative, bytes) in validate(root)? {
|
||||
let path = destination.join(relative);
|
||||
fs::create_dir_all(path.parent().expect("Godot resource parent"))
|
||||
.map_err(|error| format!("创建 Godot 资源目录失败:{error}"))?;
|
||||
fs::write(&path, bytes).map_err(|error| format!("写入 Godot 资源失败:{error}"))?;
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
pub fn source_files(root: &Path) -> Result<Vec<PathBuf>, String> {
|
||||
plain_metadata(root)?;
|
||||
let mut sources = Vec::new();
|
||||
for entry in fs::read_dir(root).map_err(|error| format!("读取 Godot 源码失败:{error}"))?
|
||||
{
|
||||
let entry = entry.map_err(|error| format!("读取 Godot 源码目录项失败:{error}"))?;
|
||||
if matches!(entry.file_name().to_str(), Some("bin" | ".build")) {
|
||||
continue;
|
||||
}
|
||||
let metadata = plain_metadata(&entry.path())?;
|
||||
if metadata.is_dir() {
|
||||
sources.extend(source_files(&entry.path())?);
|
||||
} else if metadata.is_file() {
|
||||
sources.push(entry.path());
|
||||
}
|
||||
}
|
||||
sources.sort();
|
||||
Ok(sources)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
fn fixture(root: &Path) {
|
||||
for relative in BUNDLE_FILES {
|
||||
let path = root.join(relative);
|
||||
fs::create_dir_all(path.parent().unwrap()).unwrap();
|
||||
fs::write(path, b"fixture").unwrap();
|
||||
}
|
||||
fs::write(
|
||||
root.join(BUNDLE_FILES[1]),
|
||||
serde_json::to_vec(&serde_json::json!({
|
||||
"protocol": "agc.godot.editor.v1",
|
||||
"platform": "windows",
|
||||
"arch": "x86_64",
|
||||
"entrySymbol": "agc_godot_editor_init",
|
||||
"minimumGodotVersion": "4.7",
|
||||
"buildId": format!("sha256:{}", "a".repeat(64)),
|
||||
"sha256": format!("{:x}", Sha256::digest(b"fixture")),
|
||||
}))
|
||||
.unwrap(),
|
||||
)
|
||||
.unwrap();
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn stage_only_verified_windows_runtime_and_not_build_inputs() {
|
||||
let source = tempfile::tempdir().unwrap();
|
||||
let destination = tempfile::tempdir().unwrap();
|
||||
fixture(source.path());
|
||||
fs::write(source.path().join("bridge.gd"), "source").unwrap();
|
||||
fs::write(source.path().join("bin/win-x64/extra.dll"), "excluded").unwrap();
|
||||
stage(
|
||||
source.path(),
|
||||
destination.path(),
|
||||
"x86_64-pc-windows-msvc",
|
||||
true,
|
||||
)
|
||||
.unwrap();
|
||||
for relative in BUNDLE_FILES {
|
||||
assert_eq!(
|
||||
fs::read(source.path().join(relative)).unwrap(),
|
||||
fs::read(destination.path().join(relative)).unwrap()
|
||||
);
|
||||
}
|
||||
assert!(!destination.path().join("bridge.gd").exists());
|
||||
assert!(!destination.path().join("bin/win-x64/extra.dll").exists());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn unsupported_or_disabled_targets_need_no_native_artifacts() {
|
||||
let destination = tempfile::tempdir().unwrap();
|
||||
for (target, enabled) in [
|
||||
("aarch64-apple-darwin", true),
|
||||
("x86_64-apple-darwin", true),
|
||||
("x86_64-unknown-linux-gnu", true),
|
||||
("aarch64-pc-windows-msvc", true),
|
||||
("x86_64-pc-windows-msvc", false),
|
||||
] {
|
||||
stage(
|
||||
Path::new("missing-godot-native"),
|
||||
destination.path(),
|
||||
target,
|
||||
enabled,
|
||||
)
|
||||
.unwrap();
|
||||
assert_eq!(fs::read_dir(destination.path()).unwrap().count(), 0);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn incomplete_or_tampered_bundle_fails_before_copying() {
|
||||
let source = tempfile::tempdir().unwrap();
|
||||
let destination = tempfile::tempdir().unwrap();
|
||||
fixture(source.path());
|
||||
fs::write(source.path().join(BUNDLE_FILES[0]), b"tampered").unwrap();
|
||||
assert!(stage(
|
||||
source.path(),
|
||||
destination.path(),
|
||||
"x86_64-pc-windows-msvc",
|
||||
true
|
||||
)
|
||||
.unwrap_err()
|
||||
.contains("SHA256"));
|
||||
assert_eq!(fs::read_dir(destination.path()).unwrap().count(), 0);
|
||||
fixture(source.path());
|
||||
fs::remove_file(source.path().join("vendor/LICENSE.txt")).unwrap();
|
||||
assert!(validate(source.path()).is_err());
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn source_watch_list_excludes_build_outputs() {
|
||||
let source = tempfile::tempdir().unwrap();
|
||||
fixture(source.path());
|
||||
fs::create_dir(source.path().join(".build")).unwrap();
|
||||
fs::write(source.path().join(".build/bridge.obj"), "generated").unwrap();
|
||||
fs::write(source.path().join("bridge.gd"), "source").unwrap();
|
||||
let sources = source_files(source.path()).unwrap();
|
||||
assert_eq!(sources.len(), 3);
|
||||
assert!(sources.contains(&source.path().join("bridge.gd")));
|
||||
assert!(!sources.iter().any(|path| path
|
||||
.components()
|
||||
.any(|component| component.as_os_str() == "bin" || component.as_os_str() == ".build")));
|
||||
}
|
||||
}
|
||||
@@ -1,4 +1,3 @@
|
||||
顾问阶段遵照用户的具体指示行动。
|
||||
顾问阶段遵照用户的具体指示行动,不自主推进项目或主动安排下一步,不提交阶段审批。
|
||||
根据用户指示回答问题、读取相关文档、修改工作区文件,并说明改动可能影响的已有产物。
|
||||
涉及方向性变化或多个可行方案时,先向用户说明影响并等待用户决定。
|
||||
顾问阶段以完成用户当前请求并汇报结果为结束点。
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user