补齐游戏分发安全下架取证并记录发行包对象可匿名直取
Project CI / AI game creator shell Rust crates (push) Successful in 1m32s
Project CI / AI game creator shell Rust smoke (push) Successful in 2m6s
Project CI / Backend tests (push) Successful in 4m55s
Project CI / AI game creator shell Rust lane 2/2 (push) Successful in 8m34s
Project CI / Frontend tests (push) Successful in 2m19s
Project CI / Native shell tests (push) Successful in 7m14s
Project CI / AI game creator shell Rust lane 1/2 (push) Successful in 9m55s
Project CI / AI game creator shell web tests (push) Successful in 1m57s
Project CI / Repository checks (push) Successful in 2m28s
Project CI / AI game creator shell Rust crates (push) Successful in 1m32s
Project CI / AI game creator shell Rust smoke (push) Successful in 2m6s
Project CI / Backend tests (push) Successful in 4m55s
Project CI / AI game creator shell Rust lane 2/2 (push) Successful in 8m34s
Project CI / Frontend tests (push) Successful in 2m19s
Project CI / Native shell tests (push) Successful in 7m14s
Project CI / AI game creator shell Rust lane 1/2 (push) Successful in 9m55s
Project CI / AI game creator shell web tests (push) Successful in 1m57s
Project CI / Repository checks (push) Successful in 2m28s
- 媒体链路脚本新增管理员安全下架与恢复段:suspend 后目录/详情/发行读取全部关闭、过期 revision 的 suspend 被 CAS 拒绝、restore 后重新公开且可玩 - 新增匿名直取发行包对象探测:本地 dev bucket 返回 200(同 bucket 不存在 key 为 404),默认只打 WARN,E2E_REQUIRE_PRIVATE_BUCKET=1 时按失败处理 - 游戏分发里程碑阶段 B 第 7 条补上「不能绕过网关直取 OSS 在当前环境不成立」的实测、根因与剩余缺口 - pitfalls 记录 platform-oss 的 put_internal_object_bytes 从不发送 x-oss-object-acl 的问题与上线前处理
This commit is contained in:
@@ -6052,3 +6052,11 @@ Cocos Creator 根目录由 `package.json.creator.version` 与普通 `assets/`
|
||||
- **判据**:拿它当门禁会得到假红。要判断某次改动是否真的破坏了这些用例,必须做 A/B:在当前改动与改动前(或 `master`)上分别**单独**跑同一条用例。
|
||||
- **本轮实测(2026-09-28)**:`tests::collaboration::delegation::background_agent_runtime_delegate_respects_project_policy` 在机器被其它 cargo 任务压住时曾失败(`Timeout` 与状态竞争各一次),安静状态下合并前后都 3/3 通过;`background_agent_runtime_can_delegate_task_to_other_agent` 与 `runtime_state::foreground_agent_chat_releases_lane_then_drains_queued_background_task` 在合并前的 `74b83aa1a` 上同样失败。
|
||||
- **做法**:AGC Rust 验证只跑受影响模块的定向过滤(例如 `direct_thread_manager`、`platform_maintenance`、`external_generation_state`、`write_lock`、`gui_`),全量或 `background` 这类宽过滤留给 CI 分片;本地要排查该家族时一次只跑一条、且先确认没有其它 cargo/链接任务在跑。
|
||||
|
||||
## 2026-09-28 game-distribution 发行包对象在 dev bucket 可匿名直取(platform-oss 不发对象级 ACL)
|
||||
|
||||
- **现象**:匿名请求 `https://agc-dev.oss-rg-china-mainland.aliyuncs.com/agc/project-snapshots/v1/game-distribution/<gameId>/<versionId>.zip` 返回 **200**,可以绕过发行网关直接下载发行包;同一 bucket 里不存在的 key 返回 404,所以是 bucket 默认 ACL 允许匿名读,而不是 404 兜底。
|
||||
- **根因**:`server-rs/crates/platform-oss/src/lib.rs` 的 `put_internal_object_bytes` 收下 `OssObjectAccess` 却只把它交给 `oss_access_label` 写日志,PUT 请求从不带 `x-oss-object-acl`;对象 ACL 因此继承 bucket 默认值(dev 的 `agc-dev` 是允许匿名读的)。
|
||||
- **判据**:`npm run check:game-distribution-media-e2e` 默认把这条打印成 `WARN`(本地 dev bucket 允许匿名读是环境现状),设 `E2E_REQUIRE_PRIVATE_BUCKET=1` 时按失败处理;本轮两种模式都实测过(默认 63 PASS + WARN,强制模式该条 FAIL)。
|
||||
- **处理**:上线前必须 ① 确认生产 bucket 不是 public-read;② 给 `platform-oss` 的内部 PUT、分片追加与直传策略补对象级 ACL(或干脆在 bucket 策略层对 `agc/project-snapshots/**` 收紧)。
|
||||
- **影响面**:所有经 `platform-oss` 写入「private」对象的链路(游戏发行包、AGC 项目快照、后台导出)在公开 bucket 上都继承公开读。
|
||||
Reference in New Issue
Block a user