修复 AGC 文件列举被无关临时锁删除打断(#552) (#580)
Project CI / AI game creator shell Rust smoke (push) Successful in 2m6s
Project CI / AI game creator shell Rust crates (push) Successful in 1m10s
Project CI / Backend tests (push) Successful in 4m15s
Project CI / Native shell tests (push) Successful in 6m43s
Project CI / Frontend tests (push) Successful in 2m54s
Project CI / AI game creator shell Rust lane 1/2 (push) Successful in 11m2s
Project CI / AI game creator shell Rust lane 2/2 (push) Successful in 10m12s
Project CI / AI game creator shell web tests (push) Successful in 2m23s
Project CI / Repository checks (push) Successful in 3m14s
Project CI / AI game creator shell Rust smoke (push) Successful in 2m6s
Project CI / AI game creator shell Rust crates (push) Successful in 1m10s
Project CI / Backend tests (push) Successful in 4m15s
Project CI / Native shell tests (push) Successful in 6m43s
Project CI / Frontend tests (push) Successful in 2m54s
Project CI / AI game creator shell Rust lane 1/2 (push) Successful in 11m2s
Project CI / AI game creator shell Rust lane 2/2 (push) Successful in 10m12s
Project CI / AI game creator shell web tests (push) Successful in 2m23s
Project CI / Repository checks (push) Successful in 3m14s
列举 `assets` 时,原实现先递归扫描整个项目,再过滤范围;`.agent/project.lock` 在枚举与读取元数据之间正常删除会使整次查询失败。 现在在读取条目元数据前裁剪目标范围与受保护路径,只遍历目标子树及必要祖先。枚举后消失的文件/目录仅跳过 `NotFound`,其余权限与 IO 错误仍返回;进入排队目录前复核符号链接与 Windows 重解析点。通用文件树保留原有可见范围,Agent 结果继续过滤、排序后分页。 通过通道协调真实项目写锁释放,确定性覆盖全量扫描的 TOCTOU 及定向 `assets` 扫描;另覆盖目录消失/类型变化、权限错误、私有路径、链接、引擎目录和分页。同步更新 AGC 契约与共享排障记录。 验证: - 15 条定向 Rust 测试通过:`cargo test --locked --manifest-path apps/ai-game-creator-shell/src-tauri/Cargo.toml --bin genarrative-ai-game-creator-shell -- --test-threads=1 project_file_listing generic_file_tools local_project_file_commands external_listing` - 生产 Rust 检查通过:`cargo check --locked --manifest-path apps/ai-game-creator-shell/src-tauri/Cargo.toml --bin genarrative-ai-game-creator-shell` - `npm run check:encoding`、`npm run check:doc-index`、`git diff --check` 通过。 - 本地验证在 Linux 执行,未运行 Windows 专属运行时验证;分页仍是实时观察,不承诺跨请求快照一致性。 Fixes #552 Reviewed-on: #580
This commit was merged in pull request #580.
This commit is contained in:
@@ -47,6 +47,12 @@
|
||||
- **判据/取证**:`cargo test --manifest-path apps/ai-game-creator-shell/src-tauri/Cargo.toml --bin genarrative-ai-game-creator-shell direct_thread_delta`——新增 `direct_thread_delta_sanitization_preserves_line_breaks` 钉住「逐段脱敏 == 整段脱敏」,去掉 `split_inclusive` 即红;真实文本的回归用渲染侧夹具复核(修复前 table/li/h2 全 0,修复后与整段脱敏一致:1 个 table / 3 个 th / 4 个 h2)。
|
||||
- **关联**:`apps/ai-game-creator-shell/src-tauri/src/agent/codex_app_server/mod.rs`、`.../agent/generation/prompt_context.rs`、`.../agent/thread_manager/wire.rs`、`apps/ai-game-creator-shell/src/view/project-development/chat/conversation/directThreadChat.ts`、`#384`。
|
||||
|
||||
## 2026-10-01 文件列举被无关临时锁删除打断
|
||||
|
||||
- `read_dir` 返回名字后,文件可能在 `symlink_metadata` 前正常消失;`.agent/project.lock` 的正常释放就能触发这类竞态。不要先全项目扫描再按 Agent 的 `path` 和可见性过滤。
|
||||
- 项目内列举在元数据读取前裁剪范围和受保护路径,只进入目标子树及必要祖先;共享文件树保留自己的可见性策略。枚举后消失的文件/目录仅跳过 `NotFound`,其它 IO 错误仍可诊断,进入排队目录前复核链接/重解析点。
|
||||
- 并发回归用通道协调真实写锁的释放与元数据读取,不靠高频循环碰撞;分页按本次观察到的可见文件排序,不保证跨请求快照。完整合同见 AGC 实施计划“项目文件列举的范围与并发边界”。
|
||||
|
||||
## 2026-09-29 Game Agent 读工具被项目相对路径规则拦住
|
||||
|
||||
- 项目外读取不能只依赖末段 `O_NOFOLLOW`:父目录符号链接可隐藏 `.ssh` 等受保护名字。文件读取和目录列表在访问前逐段检查原始路径,拒绝符号链接与 Windows 重解析点;目录扫描对子目录再次检查。系统临时目录若含平台别名(例如 macOS `/var`),普通读取测试使用临时目录的 canonical 路径,不能通过 canonicalize 待读路径来抹掉待检测链接。
|
||||
|
||||
Reference in New Issue
Block a user