复核版本守卫在真实 dev-win 构建上的表现并记入里程碑
Project CI / AI game creator shell Rust crates (push) Successful in 1m32s
Project CI / AI game creator shell Rust smoke (push) Successful in 2m0s
Project CI / Backend tests (push) Successful in 5m4s
Project CI / Native shell tests (push) Successful in 6m20s
Project CI / AI game creator shell Rust lane 2/2 (push) Successful in 8m44s
Project CI / Frontend tests (push) Successful in 2m15s
Project CI / AI game creator shell Rust lane 1/2 (push) Successful in 10m3s
Project CI / AI game creator shell web tests (push) Successful in 1m37s
Project CI / Repository checks (push) Successful in 2m14s
Project CI / AI game creator shell Rust crates (push) Successful in 1m32s
Project CI / AI game creator shell Rust smoke (push) Successful in 2m0s
Project CI / Backend tests (push) Successful in 5m4s
Project CI / Native shell tests (push) Successful in 6m20s
Project CI / AI game creator shell Rust lane 2/2 (push) Successful in 8m44s
Project CI / Frontend tests (push) Successful in 2m15s
Project CI / AI game creator shell Rust lane 1/2 (push) Successful in 10m3s
Project CI / AI game creator shell web tests (push) Successful in 1m37s
Project CI / Repository checks (push) Successful in 2m14s
- 只读核对线上 dev-win 0.1.157(commit d39931a01a):清单地址、产物签名、PE 身份与版本、统一总号四层同时成立 - 该构建是 assertArtifactVersionMatches 补上后的首个真实 Windows 渠道构建,确认守卫在 CI 不误伤也不漏放 - 渠道化里程碑记录本条证据,并保留仍未取证的 Jenkins 日志边界
This commit is contained in:
@@ -76,3 +76,16 @@
|
||||
- **注意(未验证项)**:`0.1.155` 这次构建的源码是 `3702e0f8e`,早于本轮给共享产物选择器加的 `assertArtifactVersionMatches()`(`c6ea0f0e3`),所以那条守卫还没有经过一次真实 Windows 构建;下一次渠道构建才能验证它在 CI 里不误伤。
|
||||
- **顺带发现的真实缺陷(已在 macOS 里程碑与 decision-log 记录)**:线上 `dev-mac/0.1.142` 清单只登记 `darwin-aarch64` 是符合 2026-09-21 单架构决策的;但它指向的更新包解出来是 **0.1.139 的 release 身份包**(`world.genarrative.ai-game-creator.release` / 陶泥儿 Release)。这一条本条验收没覆盖(本条只看「地址存在 + 签名匹配」),本轮已把「包内版本与渠道身份」加进 `check:agc-update-channel-manifests`,并在 mac 构建入口补上构建期身份断言。
|
||||
- 条目 5(Jenkins 归档与日志不含私钥)仍是未勾选:静态可证部分已记录在验收行上(`withCredentials` 注入 + 归档 glob 不含私钥文件),真实 Jenkins 运行日志需要一次 CI 构建取证。
|
||||
|
||||
## 本轮核对(2026-09-29,版本守卫经过真实构建)
|
||||
|
||||
- 线上在 2026-09-28 16:26(UTC)发布了 `dev-win` **0.1.157**(`pub_date=2026-09-28T16:26:21Z`、`commit=d39931a01a`)。这正是给共享产物选择器补上 `assertArtifactVersionMatches()`(`c6ea0f0e3`)之后的第一个真实 Windows 渠道构建(`git merge-base --is-ancestor c6ea0f0e3 d39931a01a` 成立),同时也是把签名凭据卫生收进 `check:production-ops` 门禁的那次构建(`d39931a01`)。
|
||||
- 只读复核:`AGC_UPDATE_CHANNELS=dev-win AGC_UPDATE_VERIFY_DOWNLOAD=1 npm run check:agc-update-channel-manifests` → **全部通过(1 项跳过)**:
|
||||
- 清单版本与发布元数据齐备:`version=0.1.157`、`commit=d39931a01a`;`windows-x86_64` 地址指向 `agc/dev-win/0.1.157/陶泥儿开发版_0.1.157_x64-setup.exe`(166,017,132 字节,HEAD 200)。
|
||||
- `.sig` 对象 436 字节且与清单内签名文本一致;下载后字节数与 HEAD 一致;旧协议指针 `agc/latest.json` 的 `sha256=cc990633d62c…`/`size=166,017,132` 与该产物一致。
|
||||
- 用产物内烘焙的公钥验签通过(`alg=ED`、`keyId=cb883447e3e87c4e`)。
|
||||
- 产物身份与版本属于本渠道:PE `FileVersion=0.1.157.0`/`0.1.157` 与清单 0.1.157 一致,PE `ProductName=陶泥儿开发版`。
|
||||
- 统一总号 `0.1.157`(`updatedAt=2026-09-28T16:11:20Z`、`channel=dev-win`),渠道清单不高于总号。
|
||||
- 结论:「地址 → 签名 → 产物身份 → 版本」四层在线上对同一次发布同时成立,`assertArtifactVersionMatches()` 在真实 CI 里既不误伤也不漏放;上一轮记的「这条守卫还没经过真实 Windows 构建」未验证项关闭。
|
||||
- 本轮跳过 1 项「不同渠道的更新包互不相同(渠道隔离)」,因为只指定了单个渠道;该条由 `AGC_UPDATE_CHANNELS=dev-win,dev-mac,release-win,release-mac` 全量核对覆盖,仍受 `dev-mac` 未重发(0.1.142 指向 release 身份包)阻塞。
|
||||
- 条目 5(Jenkins 归档与日志不含私钥)仍未勾选:静态口径已进仓门禁,真实 Jenkins 运行日志仍需要一次 CI 构建取证。
|
||||
|
||||
Reference in New Issue
Block a user