Compare commits

..

3 Commits

Author SHA1 Message Date
suzmii 92c05428ec 另一架构切片不得借用宿主 npm
Project CI / AI game creator shell Rust smoke (pull_request) Successful in 3m55s
Project CI / Backend tests (pull_request) Failing after 16s
Project CI / AI game creator shell Rust crates (pull_request) Successful in 1m17s
Project CI / AI game creator shell Rust lane 2/2 (pull_request) Failing after 6m48s
Project CI / Repository checks (pull_request) Failing after 15s
Project CI / AI game creator shell Rust lane 1/2 (pull_request) Failing after 7m43s
Project CI / AI game creator shell web tests (pull_request) Successful in 5m28s
Project CI / Frontend tests (pull_request) Successful in 8m34s
Project CI / Native shell tests (pull_request) Successful in 12m47s
- runtimeSourceForTarget 对非宿主架构返回 npmCli: null,明令按该发行版自己的安装目录查找 npm
- 覆盖经 npm run 触发(npm_execpath 指向宿主 npm)时两份切片仍各带自己那份 npm 的用例
2026-09-21 12:06:39 +08:00
suzmii 91f1554ac7 macOS universal 管线接入双架构 Node 运行时前置
Project CI / Frontend tests (pull_request) Has been cancelled
Project CI / AI game creator shell Rust lane 1/2 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust lane 2/2 (pull_request) Has been cancelled
Project CI / AI game creator shell Rust smoke (pull_request) Has been cancelled
Project CI / AI game creator shell Rust crates (pull_request) Has been cancelled
Project CI / Backend tests (pull_request) Has been cancelled
Project CI / Native shell tests (pull_request) Has been cancelled
Project CI / Repository checks (pull_request) Has been cancelled
Project CI / AI game creator shell web tests (pull_request) Has been cancelled
- Jenkinsfile.ai-game-creator-shell-macos-build 增加 AGC_NODE_RUNTIME_DARWIN_X64_HOME,并在 Toolchain 阶段编译前核对 x86_64 发行版存在且与构建 Node 同版本
- Package 阶段导出 AGC_NODE_RUNTIME_DARWIN_X64_PATH / _LICENSE_PATH,供 universal staging 取另一架构来源
- 开发运维文档记录节点前置:官方 darwin-x64 发行版安装与校验命令、同版本要求、按架构并列的资源布局、Rust 侧按运行架构选择、约 260 MB 解包体积代价,以及本机跨架构诊断构建的取值方式
- 实施计划与更新检查方案文档同步 universal 携带两套架构运行时的契约
2026-09-21 11:58:22 +08:00
suzmii 6a0b75779b AGC 随包 Node 支持 universal 双架构运行时
- stage-node-runtime 新增 targetRuntimes:universal 展开为 aarch64/x86_64 两份单架构运行时
- 新增 runtimeSourceForTarget:宿主架构取当前构建 Node,其它架构必须由 AGC_NODE_RUNTIME_<PLATFORM>_<ARCH>_PATH 显式提供,缺失即失败关闭
- 把 stageNodeRuntime 拆成 inspectRuntimeSource(只读校验)+ writeRuntimeBundle(落盘),universal 在写出任何目录前完成全部来源校验与版本一致性核对
- stageNodeRuntimeForTarget 单架构仍写扁平 node-runtime/,universal 按架构写 node-runtime/<platform>-<arch>/
- build-release 默认按发布目标 stage,universal 构建不再只带宿主架构的运行时
- environment_check resolve_at 在扁平目录之后按当前运行架构查找 <platform>-<arch> 子目录,两份候选都要过清单校验,存在但损坏则失败关闭
- 覆盖双架构 staging、缺非宿主运行时、版本不一致、按运行架构解析等用例
2026-09-21 11:57:43 +08:00
227 changed files with 1315 additions and 28768 deletions
@@ -3,15 +3,12 @@ import { afterEach, expect, test, vi } from 'vitest';
import {
createAdminAccount,
executeAdminRechargeRefund,
getAdminAgcTemplates,
getAdminFeatureGateConfig,
getAdminUserDetail,
importAdminAgcTemplates,
listAdminRechargeOrders,
reconcileAdminUserConsumption,
resolveAdminRechargeRefundManualReview,
updateAdminAccount,
updateAdminAgcTemplate,
uploadAdminEditorShowcaseCampaignImage,
upsertAdminFeatureGateConfig,
upsertProfileWalletConfig,
@@ -21,95 +18,6 @@ afterEach(() => {
vi.unstubAllGlobals();
});
test('模板管理读取和更新复用认证封装,提交 revision 和封面但不提交 ZIP 或版本', async () => {
const library = { revision: 'revision-new', writable: true, templates: [] };
const fetchMock = vi.fn().mockImplementation(
async () =>
new Response(JSON.stringify({ ok: true, data: library }), {
status: 200,
}),
);
vi.stubGlobal('fetch', fetchMock);
const controller = new AbortController();
expect(await getAdminAgcTemplates('admin-token', controller.signal)).toEqual(
library,
);
const update = {
expectedRevision: 'revision-old',
title: '空白模板',
summary: '简介',
tags: ['2D'],
enabled: true,
cover: { contentType: 'image/png', dataBase64: 'aW1hZ2U=' },
};
expect(
await updateAdminAgcTemplate('admin-token', 'template/1', update),
).toEqual(library);
expect(fetchMock.mock.calls[0]).toEqual([
'/admin/api/agc-templates',
expect.objectContaining({
method: 'GET',
signal: controller.signal,
headers: expect.objectContaining({ Authorization: 'Bearer admin-token' }),
}),
]);
expect(fetchMock.mock.calls[1]).toEqual([
'/admin/api/agc-templates/template%2F1',
expect.objectContaining({
method: 'PUT',
headers: expect.objectContaining({
Authorization: 'Bearer admin-token',
'Content-Type': 'application/json',
}),
body: JSON.stringify(update),
}),
]);
});
test('模板批量导入走 multipart,不预设 JSON Content-Type', async () => {
const imported = {
revision: 'rev-2',
writable: true,
templates: [],
imported: [
{
id: 'alpha',
templateVersion: '0.1.0',
zipSizeBytes: 4,
zipSha256: 'a'.repeat(64),
reusedObjects: false,
},
],
};
const fetchMock = vi
.fn()
.mockImplementation(
async () =>
new Response(JSON.stringify({ ok: true, data: imported }), {
status: 200,
}),
);
vi.stubGlobal('fetch', fetchMock);
const form = new FormData();
form.append(
'manifest',
JSON.stringify({ expectedRevision: 'rev-1', templates: [] }),
);
form.append(
'zip_0',
new File([new Uint8Array([1])], 'alpha.zip', { type: 'application/zip' }),
);
expect(await importAdminAgcTemplates('admin-token', form)).toEqual(imported);
const [url, init] = fetchMock.mock.calls[0]!;
expect(url).toBe('/admin/api/agc-templates/import');
expect(init.method).toBe('POST');
expect(init.body).toBe(form);
expect(init.headers).not.toHaveProperty('Content-Type');
expect(init.headers.Authorization).toBe('Bearer admin-token');
});
test('后台账号创建和更新同时携带 Tab 与独立操作权限', async () => {
const fetchMock = vi.fn().mockImplementation(() =>
Promise.resolve(
-37
View File
@@ -1,6 +1,5 @@
import type {
AdminAccountListResponse,
AdminAgcTemplateLibraryResponse,
AdminConfirmEditorShowcaseCampaignImageUploadRequest,
AdminCreateAccountRequest,
AdminCreateAccountResponse,
@@ -30,7 +29,6 @@ import type {
AdminExternalApiKeyListQuery,
AdminExternalApiKeyListResponse,
AdminFeatureGateConfigResponse,
AdminImportAgcTemplatesResponse,
AdminLoginResponse,
AdminMeResponse,
AdminOverviewResponse,
@@ -49,7 +47,6 @@ import type {
AdminTrackingEventListResponse,
AdminUpdateAccountRequest,
AdminUpdateAccountResponse,
AdminUpdateAgcTemplateRequest,
AdminUploadedEditorShowcaseCampaignImage,
AdminUpsertEditorShowcaseCampaignRequest,
AdminUpsertFeatureGateConfigRequest,
@@ -88,8 +85,6 @@ interface AdminRequestOptions {
method?: string;
token?: string;
body?: unknown;
/** multipart 表单:交给浏览器自己带 boundary,不能预设 Content-Type。 */
formData?: FormData;
headers?: Record<string, string>;
signal?: AbortSignal;
}
@@ -177,8 +172,6 @@ export async function request<T>(
if (typeof options.body !== 'undefined') {
headers['Content-Type'] = 'application/json';
init.body = JSON.stringify(options.body);
} else if (options.formData) {
init.body = options.formData;
}
const response = await fetch(buildRequestUrl(path), init);
@@ -1183,33 +1176,3 @@ export function saveAgcModelCatalog(
{ token, method: 'PUT', body },
);
}
export function getAdminAgcTemplates(token: string, signal?: AbortSignal) {
return request<AdminAgcTemplateLibraryResponse>('/admin/api/agc-templates', {
token,
signal,
});
}
export function updateAdminAgcTemplate(
token: string,
id: string,
body: AdminUpdateAgcTemplateRequest,
) {
return request<AdminAgcTemplateLibraryResponse>(
`/admin/api/agc-templates/${encodeURIComponent(id)}`,
{ token, method: 'PUT', body },
);
}
/** 批量导入模板包:manifest 与 zip_N / cover_N 一起走 multipart,一批一次锁一次提交。 */
export function importAdminAgcTemplates(token: string, formData: FormData) {
return request<AdminImportAgcTemplatesResponse>(
'/admin/api/agc-templates/import',
{
token,
method: 'POST',
formData,
},
);
}
-64
View File
@@ -1033,67 +1033,3 @@ export interface AdminAgcModelCatalog {
defaultModelId: string;
models: AdminAgcModel[];
}
export interface AdminAgcTemplatePayload {
id: string;
title: string;
summary: string;
tags: string[];
runtime: string;
engine: string;
engineVersion: string;
templateVersion: string;
enabled: boolean;
coverUrl: string;
zipSizeBytes: number;
}
export interface AdminAgcTemplateLibraryResponse {
revision: string;
writable: boolean;
templates: AdminAgcTemplatePayload[];
}
export interface AdminUpdateAgcTemplateRequest {
expectedRevision: string;
title: string;
summary: string;
tags: string[];
enabled: boolean;
cover?: {
contentType: string;
dataBase64: string;
};
}
export interface AdminImportAgcTemplateItemPayload {
id: string;
title: string;
summary: string;
tags: string[];
runtime: string;
engine: string;
engineVersion: string;
templateVersion: string;
entry: string;
zipField: string;
coverField: string;
}
export interface AdminImportAgcTemplatesManifest {
expectedRevision: string;
templates: AdminImportAgcTemplateItemPayload[];
}
export interface AdminImportAgcTemplateResult {
id: string;
templateVersion: string;
zipSizeBytes: number;
zipSha256: string;
reusedObjects: boolean;
}
export interface AdminImportAgcTemplatesResponse
extends AdminAgcTemplateLibraryResponse {
imported: AdminImportAgcTemplateResult[];
}
-7
View File
@@ -19,7 +19,6 @@ import {
} from '../auth/adminAuthStore';
import { AdminAccountsPage } from '../pages/AdminAccountsPage';
import { AdminAgcModelsPage } from '../pages/AdminAgcModelsPage';
import { AdminAgcTemplatesPage } from '../pages/AdminAgcTemplatesPage';
import { AdminDashboardPage } from '../pages/AdminDashboardPage';
import { AdminDatabaseTablesPage } from '../pages/AdminDatabaseTablesPage';
import { AdminDebugHttpPage } from '../pages/AdminDebugHttpPage';
@@ -295,12 +294,6 @@ export function AdminApp() {
{activeRouteId === 'agc-models' ? (
<AdminAgcModelsPage token={token} onUnauthorized={handleUnauthorized} />
) : null}
{activeRouteId === 'agc-templates' ? (
<AdminAgcTemplatesPage
token={token}
onUnauthorized={handleUnauthorized}
/>
) : null}
{activeRouteId === 'editor-showcase' ? (
<AdminEditorShowcaseReviewPage
token={token}
-1
View File
@@ -53,7 +53,6 @@ const routeIcons = {
'project-snapshots': FolderArchive,
accounts: Users,
'agc-models': ListChecks,
'agc-templates': Images,
} satisfies Record<AdminRouteId, typeof LayoutDashboard>;
export function AdminShell({
@@ -147,30 +147,3 @@ test('项目工程入口对 owner 与已授权 member 开放且可分配权限',
}),
).not.toContainEqual(route);
});
test('模板管理只对 owner 或具有 agc-templates 权限的 member 可见', () => {
expect(adminRoutes).toContainEqual({
id: 'agc-templates',
label: '模板管理',
hash: '#agc-templates',
});
expect(resolveAdminRoute('#agc-templates')).toBe('agc-templates');
expect(routeHash('agc-templates')).toBe('#agc-templates');
expect(
getAccessibleAdminRoutes({ accountRole: 'owner', tabPermissions: [] }).some(
(route) => route.id === 'agc-templates',
),
).toBe(true);
expect(
getAccessibleAdminRoutes({
accountRole: 'member',
tabPermissions: ['agc-templates'],
}).map((route) => route.id),
).toEqual(['agc-templates']);
expect(
getAccessibleAdminRoutes({
accountRole: 'member',
tabPermissions: ['editor-assets'],
}).some((route) => route.id === 'agc-templates'),
).toBe(false);
});
-2
View File
@@ -18,7 +18,6 @@ export type AdminRouteId =
| 'editor-assets'
| 'project-snapshots'
| 'agc-models'
| 'agc-templates'
| 'accounts';
export type AdminTabPermission = Exclude<
@@ -54,7 +53,6 @@ export const adminRoutes: AdminRouteDefinition[] = [
hash: '#editor-generation-pricing',
},
{ id: 'agc-models', label: 'AGC 模型', hash: '#agc-models', ownerOnly: true },
{ id: 'agc-templates', label: '模板管理', hash: '#agc-templates' },
{ id: 'editor-showcase', label: '精选审核', hash: '#editor-showcase' },
{ id: 'editor-assets', label: '素材查询', hash: '#editor-assets' },
{ id: 'project-snapshots', label: '项目工程', hash: '#project-snapshots' },
-1
View File
@@ -1,4 +1,3 @@
import '@genarrative/shared/styles.css';
import './styles/admin.css';
import { StrictMode } from 'react';
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
@@ -1,155 +0,0 @@
// @vitest-environment jsdom
import { describe, expect, it } from 'vitest';
import {
attachCoverFiles,
buildTemplateImportFormData,
deriveTemplateUploadRow,
parseTemplateTags,
sanitizeTemplateId,
TEMPLATE_IMPORT_MAX_BATCH,
type TemplateUploadRow,
validateTemplateUploadRows,
} from './adminAgcTemplateUploadModel';
function zipFile(name: string) {
return new File([new Uint8Array([0x50, 0x4b, 0x03, 0x04])], name, {
type: 'application/zip',
});
}
function coverFile(name: string) {
return new File([new Uint8Array([0x89, 0x50, 0x4e, 0x47])], name, {
type: 'image/png',
});
}
function row(zipName: string, patch: Partial<TemplateUploadRow> = {}) {
return { ...deriveTemplateUploadRow(zipFile(zipName)), ...patch };
}
describe('sanitizeTemplateId', () => {
it('lowercases, keeps whitelisted characters and drops traversal', () => {
expect(sanitizeTemplateId('Cocos Empty 2D.zip')).toBe('cocos-empty-2d');
expect(sanitizeTemplateId('../../evil.zip')).toBe('evil');
expect(sanitizeTemplateId('a..b.zip')).toBe('a.b');
expect(sanitizeTemplateId('__hidden__')).toBe('hidden__');
expect(sanitizeTemplateId(`${'x'.repeat(90)}.zip`)).toHaveLength(64);
});
});
describe('deriveTemplateUploadRow', () => {
it('starts from safe defaults so a batch only needs covers attached', () => {
const derived = row('my-template.zip');
expect(derived.id).toBe('my-template');
expect(derived.title).toBe('my-template');
expect(derived.runtime).toBe('html');
expect(derived.templateVersion).toBe('0.1.0');
expect(derived.entry).toBe('index.html');
expect(derived.coverFile).toBeNull();
});
});
describe('attachCoverFiles', () => {
it('matches covers by template id and ignores non-image files', () => {
const rows = [row('alpha.zip'), row('beta.zip')];
const covers = [
coverFile('alpha.png'),
coverFile('beta.webp'),
coverFile('notes.txt'),
];
const next = attachCoverFiles(rows, covers);
expect(next[0]?.coverFile?.name).toBe('alpha.png');
expect(next[1]?.coverFile?.name).toBe('beta.webp');
});
it('keeps an already matched cover when the new selection has no partner', () => {
const rows = [row('alpha.zip', { coverFile: coverFile('alpha.png') })];
const next = attachCoverFiles(rows, [coverFile('other.png')]);
expect(next[0]?.coverFile?.name).toBe('alpha.png');
});
});
describe('validateTemplateUploadRows', () => {
it('accepts a complete batch', () => {
const rows = [
row('alpha.zip', { coverFile: coverFile('alpha.png') }),
row('beta.zip', { coverFile: coverFile('beta.png'), runtime: 'cocos' }),
];
expect(validateTemplateUploadRows(rows)).toEqual({});
});
it('reports missing cover, duplicate id and invalid fields per row', () => {
const rows = [
row('alpha.zip'),
row('alpha.zip', { coverFile: coverFile('alpha.png'), key: 'second' }),
row('gamma.zip', {
coverFile: coverFile('gamma.png'),
runtime: 'docker',
templateVersion: 'Bad Version',
entry: '../escape.js',
title: ' ',
}),
];
const errors = validateTemplateUploadRows(rows);
expect(errors['alpha.zip']).toContain('缺少封面');
expect(errors.second).toContain('ID 在本批次内重复');
expect(errors['gamma.zip']).toContain('名称必须是 1-80 个字符');
});
it('rejects a batch larger than the server limit', () => {
const rows = Array.from(
{ length: TEMPLATE_IMPORT_MAX_BATCH + 1 },
(_, index) =>
row(`template-${index}.zip`, {
coverFile: coverFile(`template-${index}.png`),
}),
);
const errors = validateTemplateUploadRows(rows);
expect(Object.keys(errors)).toHaveLength(TEMPLATE_IMPORT_MAX_BATCH + 1);
expect(errors['template-0.zip']).toContain('单批最多上传');
});
});
describe('buildTemplateImportFormData', () => {
it('writes manifest field names and attaches zip / cover per row', () => {
const rows = [
row('alpha.zip', {
coverFile: coverFile('alpha.png'),
tags: '起步, 起步 2d',
title: ' Alpha ',
}),
row('beta.zip', { coverFile: coverFile('beta.png') }),
];
const form = buildTemplateImportFormData('a'.repeat(64), rows);
const manifest = JSON.parse(String(form.get('manifest')));
expect(manifest.expectedRevision).toBe('a'.repeat(64));
expect(manifest.templates).toHaveLength(2);
expect(manifest.templates[0]).toMatchObject({
id: 'alpha',
title: 'Alpha',
tags: ['起步', '2d'],
zipField: 'zip_0',
coverField: 'cover_0',
});
expect(manifest.templates[1]).toMatchObject({
id: 'beta',
zipField: 'zip_1',
coverField: 'cover_1',
});
expect((form.get('zip_0') as File).name).toBe('alpha.zip');
expect((form.get('cover_1') as File).name).toBe('beta.png');
});
it('parses tags with dedupe and caps them at the server limit', () => {
expect(parseTemplateTags(' a, ab c ')).toEqual(['a', 'b', 'c']);
const many = Array.from({ length: 20 }, (_, index) => `t${index}`).join(
',',
);
expect(parseTemplateTags(many)).toHaveLength(16);
});
});
@@ -1,191 +0,0 @@
import type {
AdminImportAgcTemplateItemPayload,
AdminImportAgcTemplatesManifest,
} from '../api/adminApiTypes';
/** 与服务端 module-assets 的导入上限保持一致;超出请分批或改走 CLI。 */
export const TEMPLATE_IMPORT_MAX_BATCH = 20;
export const TEMPLATE_UPLOAD_RUNTIMES = [
'html',
'unity',
'godot',
'cocos',
] as const;
const TEMPLATE_ID_PATTERN = /^[a-z0-9][a-z0-9._-]{0,63}$/u;
const TEMPLATE_VERSION_PATTERN = /^[a-z0-9][a-z0-9._-]{0,31}$/u;
const ENTRY_PATTERN = /^(?![\\/:])(?!.*\.\.)[^\s\\:]+$/u;
const COVER_EXTENSION_PATTERN = /\.(png|jpe?g|webp)$/iu;
export interface TemplateUploadRow {
/** 稳定行标识:用 ZIP 文件名,重选文件后不会串行。 */
key: string;
zipFile: File;
coverFile: File | null;
id: string;
title: string;
summary: string;
tags: string;
runtime: string;
engine: string;
engineVersion: string;
templateVersion: string;
entry: string;
}
/** 文件名 → 模板 ID:小写、只留白名单字符,并去掉 `..` 与开头的非字母数字。 */
export function sanitizeTemplateId(value: string) {
return value
.replace(/\.zip$/iu, '')
.trim()
.toLowerCase()
.replace(/\.{2,}/gu, '.')
.replace(/[^a-z0-9._-]+/gu, '-')
.replace(/^[^a-z0-9]+/u, '')
.slice(0, 64);
}
export function deriveTemplateUploadRow(zipFile: File): TemplateUploadRow {
const id = sanitizeTemplateId(zipFile.name);
return {
key: zipFile.name,
zipFile,
coverFile: null,
id,
title: id,
summary: '',
tags: '',
runtime: 'html',
engine: '',
engineVersion: '',
templateVersion: '0.1.0',
entry: 'index.html',
};
}
/** 封面按「与模板 ID 同名的图片」匹配,一次多选即可覆盖整批。 */
export function attachCoverFiles(
rows: TemplateUploadRow[],
coverFiles: File[],
): TemplateUploadRow[] {
const covers = new Map<string, File>();
for (const file of coverFiles) {
if (!COVER_EXTENSION_PATTERN.test(file.name)) continue;
const stem = sanitizeTemplateId(
file.name.replace(COVER_EXTENSION_PATTERN, ''),
);
if (!covers.has(stem)) covers.set(stem, file);
}
return rows.map((row) => {
const matched = covers.get(row.id.trim().toLowerCase()) ?? null;
return matched ? { ...row, coverFile: matched } : row;
});
}
export function parseTemplateTags(value: string) {
const seen = new Set<string>();
const tags: string[] = [];
for (const raw of value.split(/[,\s]+/u)) {
const tag = raw.trim();
if (!tag || seen.has(tag)) continue;
seen.add(tag);
tags.push(tag);
}
return tags.slice(0, 16);
}
/** 逐行校验:返回 row.key → 错误文案;空对象表示整批可以提交。 */
export function validateTemplateUploadRows(
rows: TemplateUploadRow[],
): Record<string, string> {
const errors: Record<string, string> = {};
const seen = new Set<string>();
const fail = (row: TemplateUploadRow, message: string) => {
if (!errors[row.key]) errors[row.key] = message;
};
if (rows.length === 0) return errors;
if (rows.length > TEMPLATE_IMPORT_MAX_BATCH) {
for (const row of rows) {
fail(row, `单批最多上传 ${TEMPLATE_IMPORT_MAX_BATCH} 个模板`);
}
return errors;
}
for (const row of rows) {
const id = row.id.trim();
if (!TEMPLATE_ID_PATTERN.test(id)) {
fail(
row,
'ID 必须是 1-64 位小写字母、数字、点、下划线或连字符,且以字母数字开头',
);
} else if (seen.has(id)) {
fail(row, 'ID 在本批次内重复');
} else {
seen.add(id);
}
if (!row.title.trim() || row.title.trim().length > 80) {
fail(row, '名称必须是 1-80 个字符');
}
if (row.summary.trim().length > 1000) {
fail(row, '简介最多 1000 个字符');
}
if (!TEMPLATE_VERSION_PATTERN.test(row.templateVersion.trim())) {
fail(row, '版本号必须是 1-32 位小写字母、数字、点、下划线或连字符');
}
if (
!TEMPLATE_UPLOAD_RUNTIMES.includes(
row.runtime as (typeof TEMPLATE_UPLOAD_RUNTIMES)[number],
)
) {
fail(row, `运行时只能是 ${TEMPLATE_UPLOAD_RUNTIMES.join(' / ')}`);
}
if (!ENTRY_PATTERN.test(row.entry.trim())) {
fail(row, 'entry 必须是模板包内的相对路径');
}
if (!row.coverFile) {
fail(row, '缺少封面:请上传与模板 ID 同名的 PNG / JPEG / WebP');
}
}
return errors;
}
export function buildTemplateImportManifest(
expectedRevision: string,
rows: TemplateUploadRow[],
): AdminImportAgcTemplatesManifest {
return {
expectedRevision,
templates: rows.map((row, index) => {
const item: AdminImportAgcTemplateItemPayload = {
id: row.id.trim(),
title: row.title.trim(),
summary: row.summary.trim(),
tags: parseTemplateTags(row.tags),
runtime: row.runtime,
engine: row.engine.trim(),
engineVersion: row.engineVersion.trim(),
templateVersion: row.templateVersion.trim(),
entry: row.entry.trim(),
zipField: `zip_${index}`,
coverField: `cover_${index}`,
};
return item;
}),
};
}
export function buildTemplateImportFormData(
expectedRevision: string,
rows: TemplateUploadRow[],
): FormData {
const form = new FormData();
form.append(
'manifest',
JSON.stringify(buildTemplateImportManifest(expectedRevision, rows)),
);
rows.forEach((row, index) => {
form.append(`zip_${index}`, row.zipFile, row.zipFile.name);
if (row.coverFile) {
form.append(`cover_${index}`, row.coverFile, row.coverFile.name);
}
});
return form;
}
-131
View File
@@ -13,137 +13,6 @@
text-rendering: optimizeLegibility;
}
.admin-agc-templates {
min-width: 0;
}
.admin-agc-template-filters {
display: grid;
grid-template-columns: minmax(180px, 1fr) repeat(2, minmax(130px, 190px));
gap: 14px;
}
.admin-agc-template-table {
min-width: 850px;
}
.admin-agc-template-table td:nth-child(2) {
min-width: 230px;
max-width: 380px;
}
.admin-agc-template-cover {
display: block;
width: 88px;
height: 62px;
border-radius: 8px;
object-fit: cover;
background: #f8efe7;
}
.admin-agc-template-summary {
display: -webkit-box;
overflow: hidden;
margin: 8px 0;
color: #866954;
-webkit-line-clamp: 2;
-webkit-box-orient: vertical;
}
.admin-agc-template-tags,
.admin-agc-template-actions {
display: flex;
flex-wrap: wrap;
align-items: center;
gap: 8px;
}
.admin-agc-template-tags span {
padding: 3px 7px;
border-radius: 5px;
background: #f8efe7;
font-size: 12px;
}
.admin-agc-template-dialog {
border-radius: 10px;
}
.admin-agc-template-editor,
.admin-agc-template-conflict {
display: grid;
gap: 14px;
}
.admin-agc-template-cover-preview {
display: block;
width: min(100%, 300px);
max-height: 180px;
border-radius: 8px;
object-fit: contain;
background: #f8efe7;
}
.admin-agc-template-dialog .admin-confirm-backdrop {
z-index: 1100;
}
.admin-actions {
display: flex;
flex-wrap: wrap;
gap: 8px;
justify-content: flex-end;
}
.admin-agc-template-upload-dialog {
border-radius: 10px;
max-width: min(1180px, calc(100vw - 24px));
}
.admin-agc-template-upload-pickers {
display: grid;
gap: 10px;
grid-template-columns: repeat(auto-fit, minmax(240px, 1fr));
}
.admin-agc-template-upload-picker {
display: grid;
gap: 6px;
font-size: 13px;
}
.admin-agc-template-upload-picker input[type='file'] {
width: 100%;
font-size: 12px;
}
/* 上传行数多时表格自己滚动,窄屏不撑坏整页布局。 */
.admin-agc-template-upload-scroll {
max-height: min(52vh, 520px);
overflow: auto;
}
.admin-agc-template-upload-file {
font-size: 12px;
word-break: break-all;
}
.admin-agc-template-upload-row-error {
margin-top: 4px;
color: #b3261e;
font-size: 12px;
}
@media (max-width: 680px) {
.admin-agc-template-filters {
grid-template-columns: minmax(0, 1fr);
}
.admin-agc-template-upload-dialog {
max-width: calc(100vw - 12px);
}
}
* {
box-sizing: border-box;
}
-2
View File
@@ -9,7 +9,6 @@
"dev-stack": "node scripts/start-dev-stack.mjs",
"build": "node scripts/build-release.mjs",
"release:upload": "node scripts/release-upload.mjs",
"nsis:prepare": "node scripts/ensure-nsis-toolset.mjs",
"skill-pack:check": "node scripts/check-skill-pack.mjs",
"skill-pack:sync": "node scripts/check-skill-pack.mjs --write",
"skill-pack:test": "node --test scripts/check-skill-pack.test.mjs",
@@ -76,7 +75,6 @@
"@types/react-dom": "^19.2.3",
"@types/react-window": "^1.8.8",
"@types/three": "^0.184.1",
"jszip": "^3.10.1",
"tailwindcss": "^4.1.14",
"typescript": "~5.8.2",
"vitest": "^0.34.6"
@@ -9,7 +9,6 @@ import { fileURLToPath } from 'node:url';
import {
generateUpdateManifest,
prepareReleaseVersion,
resolveManifestPlatformKeys,
resolveReleaseContext,
resolveReleasePartition,
runTauriBuild,
@@ -21,13 +20,10 @@ import {
} from './verify-updater-signature.mjs';
/**
* AGC macOS 分区(`<channel>-mac`)发布入口:构建 arm64 单架构包 → arm64 隔离 smoke → 生成 arm64 DMG
* AGC macOS 分区(`<channel>-mac`)发布入口:构建 universal 包 → 双架构 smoke → 生成 universal DMG
* → 生成分区清单 latest.json → 用产物内烘焙的公钥验签 → 按 dry-run 决定是否上传 OSS。
*
* 边界:
* - 只出 Apple Siliconarm64)单架构:清单只登记 `darwin-aarch64`。Intel 侧要可用,前提是随包 Node
* 也能按架构各带一份(`stage-node-runtime.mjs` 对 universal 目标失败关闭);在实现之前**不得**
* 把 arm64 产物登记成 `darwin-x86_64`,否则 Intel 客户端会装到跑不起来的包。
* - Apple 签名与公证暂缺:本入口剥离 `APPLE_*` 凭据让 Tauri 跳过 Apple 签名,但**不能传
* `--no-sign`** —— 该标志同时会跳过 updater 的 minisign 签名,产物就没有 `.sig`
* 未签名 + 未公证必须显式记录而非静默通过;
@@ -98,14 +94,11 @@ process.env.AGC_UPDATE_OSS_BASE_URL ||= `https://${bucket}.${endpoint}/agc`;
const dryRun = readReleaseDryRun();
process.env.CARGO_TARGET_DIR = path.join(appRoot, 'src-tauri/target');
// 单架构目标:清单侧 `resolveManifestPlatformKeys` 只为它登记 darwin-aarch64。
const macTarget = 'aarch64-apple-darwin';
const context = resolveReleaseContext([`--target=${macTarget}`]);
const context = resolveReleaseContext(['--target=universal-apple-darwin']);
const partition = resolveReleasePartition(context.channel, context.target);
const version = await prepareReleaseVersion(context);
// 首装包名必须让清单侧的单架构分支唯一匹配:`<产品名>_<版本>_<架构>.dmg`
// 架构段用 Tauri 的 aarch64 口径(不是 updater 平台键的 arm64 / x86_64)。
const firstInstallName = `${productName}_${version}_aarch64.dmg`;
// 首装包名必须保持 `<产品名>_<版本>_universal.dmg`:清单侧按该后缀唯一匹配本次产物。
const firstInstallName = `${productName}_${version}_universal.dmg`;
// 幂等边界:workspace 会保留上一轮产物。先删掉本次将要写出的对象,否则
// 1) hdiutil 会因同名 DMG 已存在直接失败(首次实跑即命中);
@@ -124,7 +117,7 @@ for (const stale of [
}
const args = [
`--target=${macTarget}`,
'--target=universal-apple-darwin',
'--bundles',
'app',
'--ci',
@@ -139,13 +132,16 @@ const command = (binary, argv, options = {}) =>
runTauriBuild(args, context);
const app = path.join(context.bundleRoot, 'macos', appBundleName);
command(process.execPath, [
path.join(appRoot, 'scripts/check-macos-bundle.mjs'),
app,
'arm64',
]);
for (const architecture of ['arm64', 'x86_64']) {
command(process.execPath, [
path.join(appRoot, 'scripts/check-macos-bundle.mjs'),
app,
architecture,
'--universal',
]);
}
// DMG 放在 bundle 根目录下:渠道清单的首装包选择会扫描该目录,命名必须匹配 `_<version>_aarch64.dmg`。
// DMG 放在 bundle 根目录下:渠道清单的首装包选择会扫描该目录,命名必须匹配 `_<version>_universal.dmg`。
const dmgDirectory = path.join(context.bundleRoot, 'macos');
fs.mkdirSync(dmgDirectory, { recursive: true });
const dmg = path.join(dmgDirectory, firstInstallName);
@@ -174,7 +170,7 @@ const release = await generateUpdateManifest(context);
assert.equal(
path.resolve(release.downloadArtifact),
path.resolve(dmg),
'首装包必须锁定本次生成的 arm64 DMG',
'首装包必须锁定本次生成的 universal DMG',
);
// 上传前门禁:用产物里烘焙的公钥复核更新包签名。验不过就停在这里,绝不写 OSS。
@@ -270,9 +266,8 @@ fs.writeFileSync(
firstInstallSha256: dmgHash,
manifest: 'latest.json',
},
// 单架构发布:只跑 arm64 隔离 smokeIntel 未支持(清单里没有 darwin-x86_64 键)。
smokes: ['arm64'],
manifestPlatformKeys: resolveManifestPlatformKeys(context.target),
smokes: ['arm64', 'x86_64'],
intelSmoke: process.arch === 'arm64' ? 'Rosetta' : 'native',
},
null,
2,
@@ -13,8 +13,7 @@ import {
defaultEditorFeatures,
withDefaultCargoFeatures,
} from './cargo-features.mjs';
import { prepareNsisToolsetForRelease } from './nsis-toolset.mjs';
import { stageNodeRuntime } from './stage-node-runtime.mjs';
import { stageNodeRuntimeForTarget } from './stage-node-runtime.mjs';
const appRoot = fileURLToPath(new URL('..', import.meta.url));
// 提交摘要里的 pathspec 与 `git log` 都以仓库根为基准,不能在应用目录里执行。
@@ -460,7 +459,8 @@ function writeChannelConfigFile(channel, target, includeNodeRuntime = false) {
export function runTauriBuild(
args = [],
context = resolveReleaseContext(args),
{ spawn = spawnSync, stageRuntime = stageNodeRuntime } = {},
// 默认按发布目标 stage:universal 需要两份架构运行时,单架构目标行为不变。
{ spawn = spawnSync, stageRuntime = stageNodeRuntimeForTarget } = {},
) {
if (
explicitBuildTarget(args) &&
@@ -878,19 +878,14 @@ export async function buildRelease(
args = [],
{
prepareVersion = prepareReleaseVersion,
prepareToolset = prepareNsisToolsetForRelease,
build = runTauriBuild,
generateManifest = generateUpdateManifest,
} = {},
) {
const context = resolveReleaseContext(args);
const bundling = !args.includes('--no-bundle');
if (bundling) await prepareVersion(context);
// Tauri bundler 下载 NSIS 工具链时不重试,网络截断会直接毁掉整次打包;
// 因此打包前先在 Windows 目标上预置(详见 nsis-toolset.mjs)。
if (bundling) await prepareToolset(context, { bundling });
if (!args.includes('--no-bundle')) await prepareVersion(context);
build(args, context);
if (bundling) return generateManifest(context);
if (!args.includes('--no-bundle')) return generateManifest(context);
}
if (
@@ -590,71 +590,6 @@ test('no-bundle smoke skips version writes and manifest generation', async () =>
assert.deepEqual(steps, ['dev']);
});
test('Windows 打包在 Tauri 构建前预置 NSIS 工具链', async () => {
const events = [];
await buildRelease(['--target', windowsTarget], {
prepareVersion: () => {
events.push('version');
},
prepareToolset: (context, options) => {
events.push(`toolset:${context.target}:${options.bundling}`);
},
build: () => {
events.push('build');
},
generateManifest: () => {
events.push('manifest');
},
});
assert.deepEqual(events, [
'version',
`toolset:${windowsTarget}:true`,
'build',
'manifest',
]);
});
test('NSIS 工具链预置失败即失败关闭,不进入 Tauri 构建', async () => {
const events = [];
await assert.rejects(
buildRelease(['--target', windowsTarget], {
prepareVersion: () => {
events.push('version');
},
prepareToolset: () => {
throw new Error('NSIS 工具链预置失败:下载 nsis-3.11.zip 失败');
},
build: () => {
events.push('build');
},
generateManifest: () => {
events.push('manifest');
},
}),
/NSIS 工具链预置失败/u,
);
assert.deepEqual(events, ['version']);
});
test('--no-bundle 不预置 NSIS 工具链', async () => {
const steps = [];
await buildRelease(['--no-bundle', '--target', windowsTarget], {
prepareVersion: () => {
steps.push('version');
},
prepareToolset: () => {
steps.push('toolset');
},
build: () => {
steps.push('build');
},
generateManifest: () => {
steps.push('manifest');
},
});
assert.deepEqual(steps, ['build']);
});
test('release stages Node before Tauri and injects its resource mapping only for bundles', () => {
const context = resolveReleaseContext(['--target', windowsTarget]);
const events = [];
@@ -76,6 +76,33 @@ function run(command, args) {
return result;
}
/**
* 单独执行随包 Node 分片:分片架构与宿主一致时直接跑,不一致时用 `arch` 强制
* arm64 机器上的 x86_64 分片依赖 Rosetta,与 `.app` 双架构 smoke 的前提相同)。
*/
function runNodeSlice(directory, args) {
const native = process.arch === 'arm64' ? 'arm64' : 'x86_64';
const binary = path.join(directory, 'node');
const [command, argv] =
architecture === native
? [binary, args]
: ['/usr/bin/arch', [`-${architecture}`, binary, ...args]];
const result = spawnSync(command, argv, {
cwd: root,
env,
encoding: 'utf8',
timeout: 120_000,
maxBuffer: 1024 * 1024,
});
assert.ifError(result.error);
assert.equal(
result.status,
0,
`${directory} 随包 Node 执行失败:${result.stderr || result.stdout}`,
);
return result.stdout.trim();
}
/**
* APFS 上优先用 `ditto --clone`:整包按区块克隆,秒级完成且几乎不占额外空间。
* 跨卷或非 APFS 时回退到真实复制;两种路径都必须产出可独立改动的副本,
@@ -248,37 +275,84 @@ try {
}
}
assert.ok(fs.existsSync(path.join(bundle, 'NOTICE.md')));
// 随包 Node:单架构构建是扁平目录,universal 构建把两套架构运行时并列放进
// `game-runtime/node/<platform>-<arch>/`(与 Codex 侧车同形态,由 Rust 侧按运行架构选择)。
// 两套清单在本函数里都做完整性与架构校验;只执行与本次 smoke 架构一致的那一份,
// 另一份由另一次架构的 smoke 覆盖(build-macos-ci.mjs 会对 arm64 / x86_64 各跑一次)。
const nodeRoot = path.join(resources, 'game-runtime/node');
const nodeManifest = JSON.parse(
fs.readFileSync(path.join(nodeRoot, 'manifest.json'), 'utf8'),
);
assert.equal(nodeManifest.schemaVersion, 'agc-node-runtime.v1');
assert.equal(nodeManifest.platform, 'darwin');
assert.equal(nodeManifest.arch, process.arch);
const runtimeFiles = fs
.readdirSync(nodeRoot, { recursive: true })
.filter(
(file) =>
fs.statSync(path.join(nodeRoot, file)).isFile() &&
file !== 'manifest.json',
const nodeSlices = requireUniversal
? ['darwin-arm64', 'darwin-x64'].map((platform) => ({
platform,
directory: path.join(nodeRoot, platform),
}))
: [{ platform: null, directory: nodeRoot }];
for (const slice of nodeSlices) {
const { directory } = slice;
const nodeManifest = JSON.parse(
fs.readFileSync(path.join(directory, 'manifest.json'), 'utf8'),
);
assert.deepEqual(runtimeFiles.sort(), Object.keys(nodeManifest.files).sort());
for (const [file, digest] of Object.entries(nodeManifest.files)) {
assert.equal(await hashFile(path.join(nodeRoot, file)), digest, file);
assert.equal(nodeManifest.schemaVersion, 'agc-node-runtime.v1');
assert.equal(nodeManifest.platform, 'darwin');
if (slice.platform) {
// 目录名与清单架构必须一致:错位会让用户拿到跑不起来的运行时。
assert.equal(`darwin-${nodeManifest.arch}`, slice.platform);
assert.ok(
/^(arm64|x64)$/u.test(nodeManifest.arch),
`未知运行架构:${nodeManifest.arch}`,
);
} else {
assert.equal(nodeManifest.arch, process.arch);
}
const runtimeFiles = fs
.readdirSync(directory, { recursive: true })
.filter(
(file) =>
fs.statSync(path.join(directory, file)).isFile() &&
file !== 'manifest.json',
);
assert.deepEqual(
runtimeFiles.sort(),
Object.keys(nodeManifest.files).sort(),
slice.platform ?? 'flat',
);
for (const [file, digest] of Object.entries(nodeManifest.files)) {
assert.equal(await hashFile(path.join(directory, file)), digest, file);
}
assert.ok(nodeManifest.files['NODE-LICENSE']);
assert.ok(nodeManifest.files['node_modules/npm/LICENSE']);
fs.accessSync(path.join(directory, 'node'), fs.constants.X_OK);
// 二进制本身必须是本分片的单一架构:官方发行版不做 universal,lipo 能直接证明。
const sliceArchitecture = spawnSync(
'/usr/bin/lipo',
['-archs', path.join(directory, 'node')],
{ encoding: 'utf8' },
);
assert.equal(sliceArchitecture.status, 0, 'lipo -archs node');
assert.equal(
sliceArchitecture.stdout.trim(),
nodeManifest.arch === 'x64' ? 'x86_64' : 'arm64',
'随包 Node 的二进制架构必须等于清单架构',
);
// 只有与本次 smoke 架构一致的分片才执行;另一架构留给对应的那次 smoke。
if (
!requireUniversal ||
nodeManifest.arch === (architecture === 'arm64' ? 'arm64' : 'x64')
) {
assert.equal(
runNodeSlice(directory, ['--version']),
nodeManifest.nodeVersion,
`${slice.platform ?? 'flat'} node --version`,
);
assert.equal(
runNodeSlice(directory, [
path.join(directory, 'node_modules/npm/bin/npm-cli.js'),
'--version',
]),
nodeManifest.npmVersion,
`${slice.platform ?? 'flat'} npm --version`,
);
}
}
assert.ok(nodeManifest.files['NODE-LICENSE']);
assert.ok(nodeManifest.files['node_modules/npm/LICENSE']);
assert.equal(
run(path.join(nodeRoot, 'node'), ['--version']).stdout.trim(),
nodeManifest.nodeVersion,
);
assert.equal(
run(path.join(nodeRoot, 'node'), [
path.join(nodeRoot, 'node_modules/npm/bin/npm-cli.js'),
'--version',
]).stdout.trim(),
nodeManifest.npmVersion,
);
const plugin = path.join(resources, 'plugins/agc-cocos-editor');
for (const file of [
'plugin.json',
@@ -287,13 +361,6 @@ try {
]) {
assert.ok(fs.existsSync(path.join(plugin, file)), file);
}
// 随包 Node 的 npm 是包里唯一允许出现的 node_modules:除了 npm 目录自身与它的子项,
// 还要放行它的上级目录 `game-runtime/node/node_modules`recursive readdir 会列出目录项,
// 少了这一条会让整个门禁对合法包失败——#439 引入后一直没被跑到,直到 2026-09-21 才暴露)。
const allowedNodeModules = (file) =>
file === 'game-runtime/node/node_modules' ||
file === 'game-runtime/node/node_modules/npm' ||
file.startsWith('game-runtime/node/node_modules/npm/');
const packageFiles = fs.readdirSync(resources, { recursive: true });
assert.ok(
!packageFiles.some(
@@ -301,7 +368,13 @@ try {
/(^|\/)(\.env[^/]*|auth\.json|target|\.git)(\/|$)|\.(exe|dll)$/.test(
file,
) ||
(/(^|\/)node_modules(\/|$)/.test(file) && !allowedNodeModules(file)),
// 只有随包 Node 自带的 npm 允许出现 node_modules;两种布局都要放行:
// 单架构的 `game-runtime/node/node_modules/npm` 与 universal 的
// `game-runtime/node/<platform>-<arch>/node_modules/npm`。
(/(^|\/)node_modules(\/|$)/.test(file) &&
!/^game-runtime\/node\/((darwin-(arm64|x64))\/)?node_modules\/npm(\/|$)/u.test(
file,
)),
),
);
assert.equal(run(executable, ['--version']).stdout.trim(), manifest.version);
@@ -1,28 +0,0 @@
// Jenkins Windows 预检入口:在数分钟的 Rust 编译之前完成 NSIS 工具链预置。
//
// 预置失败必须在此之前失败关闭,避免 bundler 用 `io: unexpected end of file`
// 把网络问题伪装成打包问题。
import { ensureNsisToolset, LOG_PREFIX } from './nsis-toolset.mjs';
// Jenkins 阶段用 `$ErrorActionPreference = 'Stop'` 执行 Powershell:重试告警走
// stderr 时可能被 PowerShell 当成终止错误,因此重试与进度一律写 stdout,只有
// 最终失败才写 stderr 并以退出码 1 失败关闭。
const logger = {
log: (message) => console.log(message),
warn: (message) => console.log(`${message}(将重试)`),
};
try {
const result = await ensureNsisToolset({ logger });
console.log(`${LOG_PREFIX} NSIS 工具链目录:${result.nsisDir}`);
console.log(`${LOG_PREFIX} NSIS 原始归档缓存:${result.cacheDir}`);
console.log(
result.reused
? `${LOG_PREFIX} NSIS 工具链复用已有目录,未访问网络`
: `${LOG_PREFIX} NSIS 工具链本次预置:${result.downloaded.join('、')}`,
);
} catch (error) {
console.error(`${LOG_PREFIX} NSIS 工具链预置失败:${error.message}`);
process.exit(1);
}
@@ -1,342 +0,0 @@
// Tauri Windows bundler 的 NSIS 工具链预置。
//
// 背景:`tauri build` 打 Windows NSIS 包时会现场从 GitHub 下载 `nsis-3.11.zip`
// 与 `nsis_tauri_utils.dll`(见 tauri-bundler `bundle/windows/nsis/mod.rs`)。
// 构建机每个检出(`git clean -fdx`)都会丢掉 `target/.tauri` 缓存,于是每次
// 发布都要重新下载;响应一旦被截断,bundler 只会报 `io: unexpected end of file`
// 整条流水线在 Rust 编译数分钟之后才失败。
//
// 这里在打包前用固定哈希 + 重试预置同一份工具链目录:bundler 检查到必需文件齐全
// 且 `nsis_tauri_utils.dll` 哈希一致后就不会再自行下载。原始归档(两个文件)
// 额外缓存在工作区之外,构建机重复构建时不再依赖 GitHub 连通性。
import { createHash } from 'node:crypto';
import fs from 'node:fs';
import os from 'node:os';
import path from 'node:path';
import { fileURLToPath } from 'node:url';
import JSZip from 'jszip';
export const LOG_PREFIX = '[ai-game-creator-shell]';
/** bundler 把工具链解到 `<tools>/.tauri/NSIS``bundle.useLocalToolsDir: true`)。 */
export const NSIS_TOOLSET_DIR_NAME = 'NSIS';
export const NSIS_ARCHIVE_ASSET_NAME = 'nsis-3.11.zip';
export const NSIS_ARCHIVE_URL =
'https://github.com/tauri-apps/binary-releases/releases/download/nsis-3.11/nsis-3.11.zip';
export const NSIS_ARCHIVE_SHA1 = 'ef7ff767e5cbd9edd22add3a32c9b8f4500bb10d';
export const NSIS_ARCHIVE_TOP_LEVEL_DIR = 'nsis-3.11';
export const NSIS_TAURI_UTILS_ASSET_NAME = 'nsis_tauri_utils.dll';
export const NSIS_TAURI_UTILS_URL =
'https://github.com/tauri-apps/nsis-tauri-utils/releases/download/nsis_tauri_utils-v0.5.3/nsis_tauri_utils.dll';
export const NSIS_TAURI_UTILS_SHA1 = '75197fee3c6a814fe035788d1c34ead39349b860';
export const NSIS_TAURI_UTILS_REQUIRED_FILE =
'Plugins/x86-unicode/additional/nsis_tauri_utils.dll';
/**
* 与 tauri-bundler 2.9.x 的 `NSIS_REQUIRED_FILES` 逐条对齐:少一条 bundler 就会
* 删掉整个目录重新下载,等于预置失效。升级 `@tauri-apps/cli` 时要同步核对。
*/
export const NSIS_REQUIRED_FILES = [
'makensis.exe',
'Bin/makensis.exe',
'Stubs/lzma-x86-unicode',
'Stubs/lzma_solid-x86-unicode',
NSIS_TAURI_UTILS_REQUIRED_FILE,
'Include/MUI2.nsh',
'Include/FileFunc.nsh',
'Include/x64.nsh',
'Include/nsDialogs.nsh',
'Include/WinMessages.nsh',
'Include/Win/COM.nsh',
'Include/Win/Propkey.nsh',
'Include/Win/RestartManager.nsh',
];
/** 需要预置的原始归档;测试可注入同结构描述替换其中的地址与哈希。 */
export const NSIS_ASSETS = [
{
assetName: NSIS_ARCHIVE_ASSET_NAME,
url: NSIS_ARCHIVE_URL,
sha1: NSIS_ARCHIVE_SHA1,
},
{
assetName: NSIS_TAURI_UTILS_ASSET_NAME,
url: NSIS_TAURI_UTILS_URL,
sha1: NSIS_TAURI_UTILS_SHA1,
},
];
const DEFAULT_DOWNLOAD_ATTEMPTS = 4;
const DEFAULT_RETRY_DELAY_MS = 3000;
const DEFAULT_DOWNLOAD_TIMEOUT_MS = 180_000;
export function defaultAppRoot() {
return fileURLToPath(new URL('..', import.meta.url));
}
export function resolveTauriToolsDir(appRoot = defaultAppRoot()) {
// 必须与 `src-tauri/tauri.windows.conf.json` 的 `bundle.useLocalToolsDir: true`
// 保持一致,否则预置的文件不在 bundler 的查找路径上。
return path.join(appRoot, 'src-tauri', 'target', '.tauri');
}
export function resolveNsisCacheDir(
env = process.env,
platform = process.platform,
) {
const explicit = env.AGC_TAURI_NSIS_CACHE_DIR?.trim();
if (explicit) return path.resolve(explicit);
// Jenkins Windows 节点以 SYSTEM 运行,ProgramData 稳定可写且不受工作区清理影响;
// 缓存里只有待解压的原始归档,不会从该目录执行任何程序。
if (platform === 'win32') {
const programData = env.ProgramData?.trim() || 'C:\\ProgramData';
return path.join(programData, 'genarrative', 'tauri-nsis-cache');
}
return path.join(os.homedir(), '.cache', 'genarrative', 'tauri-nsis-cache');
}
/** 与 tauri-bundler 相同的镜像开关语义,便于构建机绕过不可达的 GitHub。 */
export function resolveDownloadUrl(url, env = process.env) {
if (!url.startsWith('https://github.com/')) return url;
const template = env.TAURI_BUNDLER_TOOLS_GITHUB_MIRROR_TEMPLATE?.trim();
const match =
/^https:\/\/github\.com\/([^/]+)\/([^/]+)\/releases\/download\/([^/]+)\/(.+)$/u.exec(
url,
);
if (template && match) {
return template
.replaceAll('<owner>', match[1])
.replaceAll('<repo>', match[2])
.replaceAll('<version>', match[3])
.replaceAll('<asset>', match[4]);
}
const base = env.TAURI_BUNDLER_TOOLS_GITHUB_MIRROR?.trim();
if (base) return `${base.replace(/\/+$/u, '')}/${url}`;
return url;
}
export function sha1Of(data) {
return createHash('sha1').update(data).digest('hex');
}
function sha1OfFile(filePath) {
try {
return sha1Of(fs.readFileSync(filePath));
} catch {
return null;
}
}
export function verifyNsisToolset(
nsisDir,
{ utilsSha1 = NSIS_TAURI_UTILS_SHA1 } = {},
) {
const missing = NSIS_REQUIRED_FILES.filter(
(relativePath) => !fs.existsSync(path.join(nsisDir, relativePath)),
);
const hashMismatch =
missing.length === 0 &&
sha1OfFile(path.join(nsisDir, NSIS_TAURI_UTILS_REQUIRED_FILE)) !==
utilsSha1;
return { ok: missing.length === 0 && !hashMismatch, missing, hashMismatch };
}
/** 解析 zip 条目落盘位置,并拒绝 `../` 这类越界路径。 */
export function resolveArchiveEntryTarget(rootDir, entryName) {
const root = path.resolve(rootDir);
const target = path.resolve(root, entryName);
if (target !== root && !target.startsWith(`${root}${path.sep}`)) {
throw new Error(`NSIS 归档包含越界路径:${entryName}`);
}
return target;
}
function sleep(ms) {
return new Promise((resolve) => {
setTimeout(resolve, ms);
});
}
async function downloadBuffer(url, { fetchImpl, timeoutMs }) {
const response = await fetchImpl(url, {
redirect: 'follow',
signal: AbortSignal.timeout(timeoutMs),
});
if (!response.ok) {
throw new Error(`HTTP ${response.status} ${response.statusText}`.trim());
}
const data = Buffer.from(await response.arrayBuffer());
if (data.length === 0) throw new Error('响应为空');
return data;
}
async function downloadVerifiedAsset({
assetName,
url,
sha1,
env,
fetchImpl,
attempts,
retryDelayMs,
timeoutMs,
logger,
}) {
const downloadUrl = resolveDownloadUrl(url, env);
let lastError;
for (let attempt = 1; attempt <= attempts; attempt += 1) {
try {
const data = await downloadBuffer(downloadUrl, { fetchImpl, timeoutMs });
const actual = sha1Of(data);
if (actual !== sha1) {
throw new Error(`SHA1 不匹配(期望 ${sha1},实际 ${actual}`);
}
logger.log(
`${LOG_PREFIX} NSIS 工具链:已下载 ${assetName}${data.length} 字节,第 ${attempt} 次尝试)`,
);
return data;
} catch (error) {
lastError = error;
logger.warn(
`${LOG_PREFIX} NSIS 工具链:下载 ${assetName} 失败(第 ${attempt}/${attempts} 次):${error.message}`,
);
if (attempt < attempts) await sleep(retryDelayMs * attempt);
}
}
throw new Error(
`下载 ${assetName} 失败(已重试 ${attempts} 次):${lastError?.message ?? '未知错误'}\n` +
`下载地址:${downloadUrl}\n` +
`可先把该文件放入缓存目录(AGC_TAURI_NSIS_CACHE_DIR)或配置 ` +
`TAURI_BUNDLER_TOOLS_GITHUB_MIRROR_TEMPLATE 后重试。`,
);
}
async function ensureCachedAsset(options) {
const { assetName, sha1, cacheDir, logger } = options;
const cachePath = path.join(cacheDir, assetName);
if (sha1OfFile(cachePath) === sha1) {
logger.log(`${LOG_PREFIX} NSIS 工具链:命中缓存 ${cachePath}`);
return cachePath;
}
if (fs.existsSync(cachePath)) {
logger.warn(
`${LOG_PREFIX} NSIS 工具链:缓存文件校验失败,重新下载 ${cachePath}`,
);
}
const data = await downloadVerifiedAsset(options);
fs.mkdirSync(cacheDir, { recursive: true });
const tempPath = `${cachePath}.tmp-${process.pid}`;
fs.writeFileSync(tempPath, data);
fs.rmSync(cachePath, { force: true });
fs.renameSync(tempPath, cachePath);
return cachePath;
}
export async function extractNsisArchive(archivePath, destinationDir) {
const archive = await JSZip.loadAsync(fs.readFileSync(archivePath));
for (const [entryName, entry] of Object.entries(archive.files)) {
if (entry.dir) continue;
const target = resolveArchiveEntryTarget(destinationDir, entryName);
fs.mkdirSync(path.dirname(target), { recursive: true });
fs.writeFileSync(target, await entry.async('nodebuffer'));
}
}
/**
* 预置 `target/.tauri/NSIS`:已就绪时零网络直接返回,否则用缓存或重试下载补齐。
* 返回结构用于测试与日志,不参与发布产物。
*/
export async function ensureNsisToolset({
appRoot = defaultAppRoot(),
toolsDir = resolveTauriToolsDir(appRoot),
cacheDir = resolveNsisCacheDir(process.env),
env = process.env,
fetchImpl = globalThis.fetch,
assets = NSIS_ASSETS,
attempts = DEFAULT_DOWNLOAD_ATTEMPTS,
retryDelayMs = DEFAULT_RETRY_DELAY_MS,
timeoutMs = DEFAULT_DOWNLOAD_TIMEOUT_MS,
logger = console,
} = {}) {
const nsisDir = path.join(toolsDir, NSIS_TOOLSET_DIR_NAME);
// 生产路径下这里恒等于 bundler 固定的 `nsis_tauri_utils.dll` SHA1;测试注入
// 自己的归档描述时,校验口径必须与被注入的资产一致。
const missingAsset = [
NSIS_ARCHIVE_ASSET_NAME,
NSIS_TAURI_UTILS_ASSET_NAME,
].find((assetName) => !assets.some((asset) => asset.assetName === assetName));
if (missingAsset) throw new Error(`NSIS 资产描述缺少 ${missingAsset}`);
const utilsSha1 =
assets.find((asset) => asset.assetName === NSIS_TAURI_UTILS_ASSET_NAME)
?.sha1 ?? NSIS_TAURI_UTILS_SHA1;
const existing = verifyNsisToolset(nsisDir, { utilsSha1 });
if (existing.ok) {
logger.log(`${LOG_PREFIX} NSIS 工具链已就绪:${nsisDir}`);
return { nsisDir, toolsDir, cacheDir, reused: true, downloaded: [] };
}
logger.log(
`${LOG_PREFIX} NSIS 工具链需要预置:${nsisDir}` +
(existing.missing.length > 0
? `(缺少 ${existing.missing.length} 个文件)`
: '(哈希不符)'),
);
const downloadOptions = {
env,
fetchImpl,
attempts,
retryDelayMs,
timeoutMs,
cacheDir,
logger,
};
const assetPaths = {};
for (const asset of assets) {
assetPaths[asset.assetName] = await ensureCachedAsset({
...asset,
...downloadOptions,
});
}
fs.rmSync(nsisDir, { recursive: true, force: true });
await extractNsisArchive(assetPaths[NSIS_ARCHIVE_ASSET_NAME], toolsDir);
const extractedDir = path.join(toolsDir, NSIS_ARCHIVE_TOP_LEVEL_DIR);
if (!fs.existsSync(extractedDir)) {
throw new Error(
`NSIS 归档结构不符合预期:${assetPaths[NSIS_ARCHIVE_ASSET_NAME]} 未解出 ${NSIS_ARCHIVE_TOP_LEVEL_DIR}`,
);
}
fs.renameSync(extractedDir, nsisDir);
const utilsTarget = path.join(nsisDir, NSIS_TAURI_UTILS_REQUIRED_FILE);
fs.mkdirSync(path.dirname(utilsTarget), { recursive: true });
fs.copyFileSync(assetPaths[NSIS_TAURI_UTILS_ASSET_NAME], utilsTarget);
const installed = verifyNsisToolset(nsisDir, { utilsSha1 });
if (!installed.ok) {
throw new Error(
`NSIS 工具链预置不完整:缺少 ${installed.missing.join(', ') || '无'}` +
`哈希不符=${installed.hashMismatch}`,
);
}
logger.log(`${LOG_PREFIX} NSIS 工具链预置完成:${nsisDir}`);
return {
nsisDir,
toolsDir,
cacheDir,
reused: false,
downloaded: assets.map((asset) => asset.assetName),
};
}
/** `buildRelease` 用:只在 Windows 目标且需要打包时预置 NSIS 工具链。 */
export async function prepareNsisToolsetForRelease(
context,
{ bundling = true, ...deps } = {},
) {
if (!bundling || !context.target.includes('windows')) return null;
return ensureNsisToolset(deps);
}
@@ -1,331 +0,0 @@
import assert from 'node:assert/strict';
import fs from 'node:fs';
import os from 'node:os';
import path from 'node:path';
import { test } from 'node:test';
import JSZip from 'jszip';
import {
ensureNsisToolset,
extractNsisArchive,
NSIS_ARCHIVE_ASSET_NAME,
NSIS_ARCHIVE_TOP_LEVEL_DIR,
NSIS_REQUIRED_FILES,
NSIS_TAURI_UTILS_ASSET_NAME,
NSIS_TOOLSET_DIR_NAME,
prepareNsisToolsetForRelease,
resolveArchiveEntryTarget,
resolveDownloadUrl,
resolveNsisCacheDir,
resolveTauriToolsDir,
sha1Of,
verifyNsisToolset,
} from './nsis-toolset.mjs';
const appRoot = path.resolve(
path.dirname(new URL(import.meta.url).pathname),
'..',
);
const silentLogger = { log() {}, warn() {} };
function createSandbox() {
return fs.mkdtempSync(path.join(os.tmpdir(), 'agc-nsis-toolset-'));
}
/** 与真实归档同构的最小 zip:只保留 bundler 必需文件。 */
async function createArchiveFixture(extraEntries = {}) {
const zip = new JSZip();
for (const relativePath of NSIS_REQUIRED_FILES) {
zip.file(
`${NSIS_ARCHIVE_TOP_LEVEL_DIR}/${relativePath}`,
`fixture:${relativePath}`,
);
}
for (const [name, contents] of Object.entries(extraEntries)) {
zip.file(name, contents);
}
return zip.generateAsync({ type: 'nodebuffer' });
}
function fixtureAssets({ archive, utils }) {
return [
{
assetName: NSIS_ARCHIVE_ASSET_NAME,
url: `https://github.com/tauri-apps/binary-releases/releases/download/nsis-3.11/${NSIS_ARCHIVE_ASSET_NAME}`,
sha1: sha1Of(archive),
},
{
assetName: NSIS_TAURI_UTILS_ASSET_NAME,
url: `https://github.com/tauri-apps/nsis-tauri-utils/releases/download/nsis_tauri_utils-v0.5.3/${NSIS_TAURI_UTILS_ASSET_NAME}`,
sha1: sha1Of(utils),
},
];
}
function fixtureFetch({ archive, utils, failures = 0 }) {
let remainingFailures = failures;
const calls = [];
const fetchImpl = async (url) => {
calls.push(url);
if (remainingFailures > 0) {
remainingFailures -= 1;
throw new Error('network truncated');
}
const body = url.includes(NSIS_TAURI_UTILS_ASSET_NAME) ? utils : archive;
return {
ok: true,
status: 200,
statusText: 'OK',
arrayBuffer: async () => body,
};
};
return { fetchImpl, calls };
}
test('NSIS 工具链目录与 Tauri useLocalToolsDir 配置保持一致', () => {
const config = JSON.parse(
fs.readFileSync(
path.join(appRoot, 'src-tauri', 'tauri.windows.conf.json'),
'utf8',
),
);
assert.equal(config.bundle.useLocalToolsDir, true);
assert.equal(
resolveTauriToolsDir(appRoot),
path.join(appRoot, 'src-tauri', 'target', '.tauri'),
);
});
test('缓存目录默认落在工作区之外并支持环境变量覆盖', () => {
assert.equal(
resolveNsisCacheDir(
{ AGC_TAURI_NSIS_CACHE_DIR: '/tmp/agc-cache' },
'linux',
),
'/tmp/agc-cache',
);
assert.equal(
resolveNsisCacheDir({ ProgramData: 'D:\\ProgramData' }, 'win32'),
path.join('D:\\ProgramData', 'genarrative', 'tauri-nsis-cache'),
);
assert.ok(
resolveNsisCacheDir({}, 'linux').endsWith(
path.join('.cache', 'genarrative', 'tauri-nsis-cache'),
),
);
});
test('下载地址支持 tauri bundler 的两套 GitHub 镜像开关', () => {
const url =
'https://github.com/tauri-apps/binary-releases/releases/download/nsis-3.11/nsis-3.11.zip';
assert.equal(resolveDownloadUrl(url, {}), url);
assert.equal(
resolveDownloadUrl(url, {
TAURI_BUNDLER_TOOLS_GITHUB_MIRROR_TEMPLATE:
'https://mirror.example.com/<owner>/<repo>/<version>/<asset>',
}),
'https://mirror.example.com/tauri-apps/binary-releases/nsis-3.11/nsis-3.11.zip',
);
assert.equal(
resolveDownloadUrl(url, {
TAURI_BUNDLER_TOOLS_GITHUB_MIRROR: 'https://mirror.example.com/',
}),
`https://mirror.example.com/${url}`,
);
});
test('工具链已就绪时零下载复用', async () => {
const sandbox = createSandbox();
const toolsDir = path.join(sandbox, '.tauri');
const cacheDir = path.join(sandbox, 'cache');
const archive = await createArchiveFixture();
const utils = Buffer.from('nsis-tauri-utils-dll');
const assets = fixtureAssets({ archive, utils });
await ensureNsisToolset({
toolsDir,
cacheDir,
assets,
fetchImpl: fixtureFetch({ archive, utils }).fetchImpl,
logger: silentLogger,
});
let fetchCalls = 0;
const reused = await ensureNsisToolset({
toolsDir,
cacheDir,
assets,
fetchImpl: async () => {
fetchCalls += 1;
throw new Error('工具链已就绪时不应访问网络');
},
logger: silentLogger,
});
assert.equal(reused.reused, true);
assert.deepEqual(reused.downloaded, []);
assert.equal(fetchCalls, 0);
assert.equal(reused.nsisDir, path.join(toolsDir, NSIS_TOOLSET_DIR_NAME));
});
test('冷启动时下载、校验、解压并落缓存,重跑走缓存', async () => {
const sandbox = createSandbox();
const toolsDir = path.join(sandbox, '.tauri');
const cacheDir = path.join(sandbox, 'cache');
const archive = await createArchiveFixture();
const utils = Buffer.from('nsis-tauri-utils-dll');
const assets = fixtureAssets({ archive, utils });
const { fetchImpl, calls } = fixtureFetch({ archive, utils });
const result = await ensureNsisToolset({
toolsDir,
cacheDir,
assets,
fetchImpl,
logger: silentLogger,
});
assert.deepEqual(calls.length, 2);
assert.deepEqual(result.downloaded, [
NSIS_ARCHIVE_ASSET_NAME,
NSIS_TAURI_UTILS_ASSET_NAME,
]);
assert.equal(
verifyNsisToolset(path.join(toolsDir, NSIS_TOOLSET_DIR_NAME), {
utilsSha1: sha1Of(utils),
}).ok,
true,
);
assert.equal(
fs.readFileSync(
path.join(
toolsDir,
NSIS_TOOLSET_DIR_NAME,
'Plugins/x86-unicode/additional/nsis_tauri_utils.dll',
),
'utf8',
),
'nsis-tauri-utils-dll',
);
// 第二次构建:清空工作区工具目录后仍应零下载恢复(模拟 Jenkins git clean -fdx)。
fs.rmSync(path.join(toolsDir, NSIS_TOOLSET_DIR_NAME), {
recursive: true,
force: true,
});
const offline = await ensureNsisToolset({
toolsDir,
cacheDir,
assets,
fetchImpl: async () => {
throw new Error('命中缓存时不应访问网络');
},
logger: silentLogger,
});
assert.equal(
verifyNsisToolset(offline.nsisDir, { utilsSha1: sha1Of(utils) }).ok,
true,
);
});
test('下载失败按次数重试,最终成功', async () => {
const sandbox = createSandbox();
const archive = await createArchiveFixture();
const utils = Buffer.from('dll');
const { fetchImpl, calls } = fixtureFetch({ archive, utils, failures: 2 });
const result = await ensureNsisToolset({
toolsDir: path.join(sandbox, '.tauri'),
cacheDir: path.join(sandbox, 'cache'),
assets: fixtureAssets({ archive, utils }),
fetchImpl,
attempts: 3,
retryDelayMs: 1,
logger: silentLogger,
});
assert.equal(result.downloaded.length, 2);
assert.equal(calls.length, 4);
});
test('哈希不匹配时报错并给出可操作提示', async () => {
const sandbox = createSandbox();
const { fetchImpl } = fixtureFetch({
archive: Buffer.from('corrupted'),
utils: Buffer.from('corrupted'),
});
await assert.rejects(
ensureNsisToolset({
toolsDir: path.join(sandbox, '.tauri'),
cacheDir: path.join(sandbox, 'cache'),
assets: [
{
assetName: NSIS_ARCHIVE_ASSET_NAME,
url: 'https://github.com/a/b/releases/download/1/n.zip',
sha1: 'deadbeef',
},
{
assetName: NSIS_TAURI_UTILS_ASSET_NAME,
url: 'https://github.com/a/b/releases/download/1/n.dll',
sha1: 'deadbeef',
},
],
fetchImpl,
attempts: 2,
retryDelayMs: 1,
logger: silentLogger,
}),
/SHA1 不匹配/u,
);
assert.equal(
fs.existsSync(path.join(sandbox, 'cache', NSIS_ARCHIVE_ASSET_NAME)),
false,
);
});
test('归档越界路径与缺失必需文件都会失败关闭', async () => {
const sandbox = createSandbox();
assert.throws(
() =>
resolveArchiveEntryTarget(path.join(sandbox, 'extract'), '../escape.txt'),
/越界路径/u,
);
assert.equal(
resolveArchiveEntryTarget(path.join(sandbox, 'extract'), 'nsis-3.11/a/b'),
path.resolve(sandbox, 'extract', 'nsis-3.11/a/b'),
);
const emptyArchive = new JSZip()
.file(`${NSIS_ARCHIVE_TOP_LEVEL_DIR}/makensis.exe`, 'only-one')
.generateAsync({ type: 'nodebuffer' });
const emptyPath = path.join(sandbox, 'incomplete.zip');
fs.writeFileSync(emptyPath, await emptyArchive);
const toolsDir = path.join(sandbox, 'incomplete-tools');
await extractNsisArchive(emptyPath, toolsDir);
const status = verifyNsisToolset(
path.join(toolsDir, NSIS_ARCHIVE_TOP_LEVEL_DIR),
);
assert.equal(status.ok, false);
assert.ok(status.missing.includes('Bin/makensis.exe'));
});
test('非 Windows 目标或 --no-bundle 不预置工具链', async () => {
let called = 0;
const deps = {
ensure: async () => {
called += 1;
},
};
assert.equal(
await prepareNsisToolsetForRelease(
{ target: 'x86_64-pc-windows-msvc' },
{ bundling: false, ...deps },
),
null,
);
assert.equal(
await prepareNsisToolsetForRelease(
{ target: 'aarch64-apple-darwin' },
deps,
),
null,
);
assert.equal(called, 0);
});
@@ -178,12 +178,8 @@ test('macOS release entry and smoke script derive product names from config and
assert.ok(entry.includes('readProductName'), '入口必须从 Tauri 配置读产品名');
assert.ok(!entry.includes('陶泥儿'), 'macOS 发布入口不得写死产品名');
assert.ok(
entry.includes("const macTarget = 'aarch64-apple-darwin'"),
'macOS 发布入口必须固定单架构目标',
);
assert.ok(
entry.includes('_${version}_aarch64.dmg'),
'首装包名必须保留清单侧单架构分支唯一匹配所需的后缀(Tauri 口径 aarch64',
entry.includes('_${version}_universal.dmg'),
'首装包名必须保留清单侧唯一匹配所需的后缀',
);
const smoke = fs.readFileSync(
@@ -6,6 +6,13 @@ import { fileURLToPath } from 'node:url';
const appRoot = fileURLToPath(new URL('..', import.meta.url));
export const nodeRuntimeSchema = 'agc-node-runtime.v1';
// 单架构目标写扁平目录;universal 在此目录下按架构分目录,见 stageNodeRuntimeForTarget。
const defaultRuntimeDestination = path.join(
appRoot,
'src-tauri',
'resources',
'node-runtime',
);
export function readInstalledNodeLicense(
version,
@@ -65,22 +72,119 @@ export function targetRuntime(target) {
'aarch64-apple-darwin': ['darwin', 'arm64'],
'x86_64-apple-darwin': ['darwin', 'x64'],
};
// 随包 Node 是**单架构**官方发行版:一份运行时只服务它自己的架构。
// macOS 发布当前固定为 aarch64-apple-darwin 单架构包(Intel 未支持),
// universal 目标没有正确的运行时来源,必须失败关闭——绝不能退化成
// 「按宿主架构暂存一份 arm64」:那样通用包自检(按 process.arch)能过,
// 但 Intel 机器上这份运行时不可执行,用户拿到的是坏包。
if (target === 'universal-apple-darwin')
throw new Error(
'Node 运行时不支持 universal-apple-darwin:随包 Node 只有单架构发行版,' +
'通用包需按架构各带一份(另行下载另一架构官方发行版)之后才能构建;' +
'当前 macOS 发布固定为 aarch64-apple-darwin 单架构',
);
const value = targets[target];
if (!value) throw new Error(`Node 运行时不支持发布目标:${target}`);
// universal 不是单份运行时能表达的目标:它必须按架构展开成两份,见 targetRuntimes。
if (!value)
throw new Error(
target === 'universal-apple-darwin'
? 'Node 运行时不能直接按 universal-apple-darwin 制作:双架构请用 stageNodeRuntimeForTarget 按架构展开'
: `Node 运行时不支持发布目标:${target}`,
);
return { platform: value[0], arch: value[1] };
}
/**
* 发布目标需要的随包运行时列表:universal 需要两份单架构运行时,
* 其余目标仍然是一份(保持既有扁平布局与行为)。
*/
export function targetRuntimes(target) {
if (target === 'universal-apple-darwin')
return ['aarch64-apple-darwin', 'x86_64-apple-darwin'];
return [target];
}
/**
* 按架构选择 staging 输入。
*
* 契约(见实施计划):发布包只从**本机已安装且与目标平台/架构一致**的工具链取材,
* 不得使用项目内或相对 PATH 的伪造运行时。宿主架构直接复用当前 Node;
* 其它架构必须由构建节点显式提供,缺失即失败关闭——不静默跳过、不回退系统 Node。
*/
export function runtimeSourceForTarget(
archTarget,
{
env = process.env,
nodePath,
npmCli,
licensePath,
hostNodePath = process.execPath,
hostNpmCli = process.env.npm_execpath,
hostLicensePath = env.AGC_NODE_LICENSE_PATH,
hostPlatform = process.platform,
hostArch = process.arch,
} = {},
) {
const native = targetRuntime(archTarget);
if (native.platform === hostPlatform && native.arch === hostArch) {
return {
nodePath: nodePath ?? hostNodePath,
npmCli: npmCli ?? hostNpmCli,
licensePath: licensePath ?? hostLicensePath,
};
}
const key = `${native.platform}_${native.arch}`.toUpperCase();
const configured = env[`AGC_NODE_RUNTIME_${key}_PATH`]?.trim();
if (!configured) {
throw new Error(
`缺少 ${native.platform}/${native.arch} 的 Node 运行时:该架构不是构建宿主,` +
`请先在本机安装同架构 Node,再用 AGC_NODE_RUNTIME_${key}_PATH 指向其 bin/node`,
);
}
return {
nodePath: configured,
// 明令不使用宿主 npm`npm_execpath`):另一架构的 npm 必须来自它自己那份发行版
// 安装目录,否则两份切片的 npm 来源不同源,架构与来源对不上。null 表示"按 node 目录查找"。
npmCli: null,
licensePath: env[`AGC_NODE_RUNTIME_${key}_LICENSE_PATH`]?.trim(),
};
}
/**
* 按发布目标 stage 运行时资源。
*
* 单架构目标沿用既有扁平目录(`node-runtime/`),universal 目标写进
* `node-runtime/<platform>-<arch>/`——与捆绑 Codex 的分架构目录同一形态,
* 由 Rust 侧按当前运行架构选择;构建期资源映射仍是整目录映射,无需按架构分叉。
*
* 先解析并校验**全部**来源,再逐个落盘:非宿主架构的运行时缺失、平台/架构不符、
* 两套版本不一致,都在写出任何运行时目录之前失败,不留下半套资源冒充发布内容。
*/
export function stageNodeRuntimeForTarget(
target,
{ destination = defaultRuntimeDestination, ...options } = {},
) {
const targets = targetRuntimes(target);
const plans = targets.map((archTarget) => {
const native = targetRuntime(archTarget);
return {
destination:
targets.length === 1
? destination
: path.join(destination, `${native.platform}-${native.arch}`),
inspected: inspectRuntimeSource(archTarget, {
...options,
...runtimeSourceForTarget(archTarget, options),
}),
};
});
// 两个切片必须是同一套 Node:版本不一致意味着其中一份被换过,
// 用户在不同架构上会拿到行为不同的工具链。
const identities = new Set(
plans.map(
({ inspected }) =>
`${inspected.info.version}|${inspected.npmPackage.version}`,
),
);
if (identities.size !== 1) {
throw new Error(
`多架构 Node 运行时版本不一致:${[...identities].join(' / ')}`,
);
}
return plans.map(({ inspected, destination }) =>
writeRuntimeBundle(inspected, { destination }),
);
}
function inside(root, file) {
const relative = path.relative(root, file);
return (
@@ -223,13 +327,19 @@ export function assertPortableMacNode(output) {
}
}
export function stageNodeRuntime(
/**
* 只读校验一份运行时来源,返回 staging 需要的全部事实。
*
* 与写盘分离的原因:多架构发布必须能在写出任何文件之前发现「另一份来源缺失或
* 与目标不符」。校验口径保持原样——平台/架构必须等于目标、macOS 二进制只能链接
* 系统动态库、npm 的身份与实际版本必须一致、许可必须来自发行版本体。
*/
export function inspectRuntimeSource(
target,
{
nodePath = process.execPath,
npmCli = process.env.npm_execpath,
licensePath = process.env.AGC_NODE_LICENSE_PATH,
destination = path.join(appRoot, 'src-tauri', 'resources', 'node-runtime'),
execute = execFileSync,
installedLicense = readInstalledNodeLicense,
} = {},
@@ -264,6 +374,7 @@ export function stageNodeRuntime(
);
}
const nodeDirectory = path.dirname(node);
// `npmCli: null` 表示显式拒绝沿用宿主 npm,只按这份 node 自己的安装目录查找。
const npmCandidates = [
npmCli,
path.join(nodeDirectory, 'node_modules/npm/bin/npm-cli.js'),
@@ -320,6 +431,14 @@ export function stageNodeRuntime(
throw new Error('Node LICENSE 不包含发行许可');
if (!fs.statSync(path.join(npmRoot, 'LICENSE')).isFile())
throw new Error('npm 缺少 LICENSE');
return { native, node, npmRoot, npmPackage, info, license, licenseName };
}
/** 把已校验的来源写成一份发布资源,返回清单。 */
function writeRuntimeBundle(
{ native, node, npmRoot, npmPackage, info, license, licenseName },
{ destination },
) {
// 临时同级目录完成后才替换资源;不污染 Node 安装或项目工作区。
const requestedDestination = path.resolve(destination);
if (requestedDestination === path.dirname(requestedDestination))
@@ -405,3 +524,26 @@ export function stageNodeRuntime(
cleanupStaging(staging, parent, stagingPrefix, stagingIdentity);
}
}
export function stageNodeRuntime(
target,
{
nodePath = process.execPath,
npmCli = process.env.npm_execpath,
licensePath = process.env.AGC_NODE_LICENSE_PATH,
destination = defaultRuntimeDestination,
execute = execFileSync,
installedLicense = readInstalledNodeLicense,
} = {},
) {
return writeRuntimeBundle(
inspectRuntimeSource(target, {
nodePath,
npmCli,
licensePath,
execute,
installedLicense,
}),
{ destination },
);
}
@@ -9,7 +9,9 @@ import {
assertPortableMacNode,
readInstalledNodeLicense,
stageNodeRuntime,
stageNodeRuntimeForTarget,
targetRuntime,
targetRuntimes,
} from './stage-node-runtime.mjs';
function fixture(run) {
@@ -281,10 +283,10 @@ test('native target and macOS dynamic dependency policy reject nonportable Node'
platform: 'darwin',
arch: 'arm64',
});
// universal 必须失败关闭:只带宿主架构那一份运行时,Intel 上不可执行
// universal 不是单份运行时目标:必须报出「按架构展开」而不是笼统的「不支持」
assert.throws(
() => targetRuntime('universal-apple-darwin'),
/universal-apple-darwin/u,
/stageNodeRuntimeForTarget/u,
);
assertPortableMacNode(
'/node:\n\t/usr/lib/libSystem.B.dylib (compatibility version 1)\n',
@@ -297,3 +299,164 @@ test('native target and macOS dynamic dependency policy reject nonportable Node'
/非系统动态库/u,
);
});
// 双架构夹具:每个架构一份来源目录,execute 按被查询的二进制回报对应架构。
function universalFixture(run) {
const root = fs.mkdtempSync(
path.join(os.tmpdir(), 'agc-node-universal-test-'),
);
const sourceFor = (arch, nodeVersion) => {
const dir = path.join(root, `source-${arch}`);
const npm = path.join(dir, 'node_modules/npm');
fs.mkdirSync(path.join(npm, 'bin'), { recursive: true });
fs.writeFileSync(path.join(dir, 'node'), `node-${arch}`);
fs.writeFileSync(
path.join(dir, 'LICENSE'),
'Node.js\nPermission is hereby granted',
);
fs.writeFileSync(path.join(npm, 'LICENSE'), 'npm distribution license');
fs.writeFileSync(
path.join(npm, 'package.json'),
JSON.stringify({ name: 'npm', version: '11.0.0' }),
);
for (const name of ['npm', 'npx'])
fs.writeFileSync(path.join(npm, `bin/${name}-cli.js`), `// ${arch}`);
return {
nodePath: path.join(dir, 'node'),
npmCli: path.join(npm, 'bin/npm-cli.js'),
licensePath: path.join(dir, 'LICENSE'),
nodeVersion,
};
};
try {
return run(root, {
arm64: sourceFor('arm64', 'v22.23.2'),
x64: sourceFor('x64', 'v22.23.2'),
});
} finally {
fs.rmSync(root, { recursive: true, force: true });
}
}
function optionsFor(root, sources, overrides = {}) {
const archOf = (file) => (file.includes('source-x64') ? 'x64' : 'arm64');
return {
destination: path.join(root, 'resources/node-runtime'),
hostPlatform: 'darwin',
hostArch: 'arm64',
hostNodePath: sources.arm64.nodePath,
hostNpmCli: sources.arm64.npmCli,
env: {
AGC_NODE_RUNTIME_DARWIN_X64_PATH: sources.x64.nodePath,
AGC_NODE_RUNTIME_DARWIN_X64_LICENSE_PATH: sources.x64.licensePath,
},
installedLicense() {
throw new Error('no installed fixture license');
},
execute(file, args) {
if (file === '/usr/bin/otool')
return `\t/usr/lib/libSystem.B.dylib\n\t/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation\n`;
if (args[0] === '-p') {
const arch = archOf(file);
return JSON.stringify({
platform: 'darwin',
arch,
version: sources[arch].nodeVersion,
});
}
return '11.0.0';
},
...overrides,
};
}
test('universal stages one runtime per architecture with architecture-correct manifests', () =>
universalFixture((root, sources) => {
assert.deepEqual(targetRuntimes('universal-apple-darwin'), [
'aarch64-apple-darwin',
'x86_64-apple-darwin',
]);
// 模拟经 `npm run` 触发的构建:npm 把宿主的 npm-cli.js 放进环境变量。
// 另一架构的切片必须无视它,只能使用自己发行版目录里的 npm。
const previousNpmExecPath = process.env.npm_execpath;
process.env.npm_execpath = sources.arm64.npmCli;
let manifests;
try {
manifests = stageNodeRuntimeForTarget(
'universal-apple-darwin',
optionsFor(root, sources),
);
} finally {
if (previousNpmExecPath === undefined) delete process.env.npm_execpath;
else process.env.npm_execpath = previousNpmExecPath;
}
assert.deepEqual(
manifests.map((manifest) => `${manifest.platform}-${manifest.arch}`),
['darwin-arm64', 'darwin-x64'],
);
for (const manifest of manifests) {
const directory = path.join(
root,
'resources/node-runtime',
`${manifest.platform}-${manifest.arch}`,
);
assert.equal(
JSON.parse(
fs.readFileSync(path.join(directory, 'manifest.json'), 'utf8'),
).arch,
manifest.arch,
);
assert.ok(fs.existsSync(path.join(directory, 'node')));
assert.ok(
fs.existsSync(path.join(directory, 'node_modules/npm/LICENSE')),
);
// 每份切片必须自带对应架构发行版的 npm,不能借用宿主那一份。
assert.equal(
fs.readFileSync(
path.join(directory, 'node_modules/npm/bin/npm-cli.js'),
'utf8',
),
`// ${manifest.arch}`,
);
}
// 单架构目标仍写扁平目录(与既有发布一致),不产生分架构子目录。
const flat = stageNodeRuntimeForTarget(
'aarch64-apple-darwin',
optionsFor(root, sources, { destination: path.join(root, 'flat') }),
);
assert.equal(flat.length, 1);
assert.ok(fs.existsSync(path.join(root, 'flat/manifest.json')));
assert.ok(!fs.existsSync(path.join(root, 'flat/darwin-arm64')));
}));
test('universal fails closed when the non-host architecture runtime is absent', () =>
universalFixture((root, sources) => {
const options = optionsFor(root, sources, { env: {} });
assert.throws(
() => stageNodeRuntimeForTarget('universal-apple-darwin', options),
/AGC_NODE_RUNTIME_DARWIN_X64_PATH/u,
);
// 缺失时不得留下半成品目录。
assert.ok(!fs.existsSync(path.join(root, 'resources')));
}));
test('universal rejects mismatched Node versions between the two architectures', () =>
universalFixture((root, sources) => {
const options = optionsFor(root, sources);
options.execute = (file, args) => {
if (file === '/usr/bin/otool') return '\t/usr/lib/libSystem.B.dylib\n';
if (args[0] === '-p')
return JSON.stringify({
platform: 'darwin',
arch: file.includes('source-x64') ? 'x64' : 'arm64',
version: file.includes('source-x64') ? 'v22.23.2' : 'v24.0.0',
});
return '11.0.0';
};
assert.throws(
() => stageNodeRuntimeForTarget('universal-apple-darwin', options),
/版本不一致/u,
);
// 版本核对在写出任何架构之前完成,失败时不留下半套运行时。
assert.ok(!fs.existsSync(path.join(root, 'resources')));
}));
@@ -1006,58 +1006,16 @@ pub(crate) async fn external_editor_json_request(
let response = crate::http_client::with_agc_main_site_marker(request)
.send()
.await
.map_err(|error| {
format!(
"{action}失败:{}",
describe_external_request_failure(&error)
)
})?;
.map_err(|error| format!("{action}失败:{error}"))?;
let status = response.status();
if !status.is_success() {
let body = response.text().await.unwrap_or_default();
return Err(format_external_http_error(action, status, &body));
}
response.json::<serde_json::Value>().await.map_err(|error| {
format!(
"解析{action}响应失败:{}",
describe_external_request_failure(&error)
)
})
}
/// 把 reqwest 失败翻译成可现场定责的文案。
///
/// `reqwest::Error` 的 `Display` 只输出 kind:客户端预算内没读完正文(总超时)、
/// 正文被提前截断和正文不是合法 JSON 都会显示成同一句 `error decoding response body`
/// 现场无法区分是平台慢、链接慢还是响应被截断。这里补上 kind 语义与底层因链;
/// 因链只取错误文本,不拼接 URL,避免把绝对地址写进日志。
fn describe_external_request_failure(error: &reqwest::Error) -> String {
let kind = if error.is_timeout() {
"请求超时(连接、响应头或响应正文未在客户端预算内完成)"
} else if error.is_decode() {
"响应正文未完整返回或不是合法 JSON"
} else if error.is_body() {
"响应正文读取失败"
} else if error.is_connect() {
"连接失败"
} else if error.is_request() {
"请求发送失败"
} else {
"请求失败"
};
let mut causes: Vec<String> = Vec::new();
let mut source = std::error::Error::source(error);
while let Some(current) = source {
let text = current.to_string();
if !text.is_empty() && !causes.contains(&text) {
causes.push(text);
}
source = current.source();
}
if causes.is_empty() {
return kind.to_string();
}
format!("{kind}{}", causes.join(""))
response
.json::<serde_json::Value>()
.await
.map_err(|error| format!("解析{action}响应失败:{error}"))
}
/// Keep provider validation details useful to the operator without copying an
@@ -1485,14 +1443,10 @@ pub(crate) async fn prepare_external_canvas_generation_context(
let project_id = if let Some(project_id) = partial.remote_project_id.clone() {
project_id
} else {
// 这一步只需要按 projectId 确认绑定项目是否仍然存在,固定用摘要视图:
// 缺省 full 会把账号下每个项目的画布与全量资源都带回来,项目增长后会耗尽本次请求的
// 客户端预算,现场表现为「解析读取外部画布项目响应失败:error decoding response body」。
// 站内 `/api/editor/projects` 与 `/api/external/v1/editor/projects` 都支持该视图。
let projects_payload = external_editor_json_request(
client
.get(format!(
"{}{}?view=summary",
"{}{}",
access.api_base_url(),
access.api_route("/api/external/v1/editor/projects")
))
@@ -8581,28 +8535,6 @@ mod canvas_generation_tests {
);
}
/// reqwest 的 `Display` 只给 kind,超时 / 正文截断 / 非法 JSON 全都是同一句
/// `error decoding response body`。这个用例钉住「至少把 kind 语义换成人话」,
/// 避免再退回无法定责的原始文案。
#[tokio::test]
async fn external_request_failure_replaces_the_opaque_reqwest_kind() {
let error = reqwest::Client::new()
.get("http://127.0.0.1:1/healthz")
.timeout(Duration::from_secs(2))
.send()
.await
.expect_err("closed port must fail");
let described = describe_external_request_failure(&error);
// 该端口在真实环境里可能被直接拒绝、也可能被中间层吞掉直到超时,两种都必须能定责。
assert!(
described.contains("连接失败") || described.contains("请求超时"),
"{described}"
);
assert!(described.contains(""), "必须补上底层因链:{described}");
assert!(!described.contains("error sending request"), "{described}");
assert!(!described.contains("http://127.0.0.1:1"), "{described}");
}
fn read_test_http_request(stream: &mut std::net::TcpStream) -> String {
stream
.set_nonblocking(false)
@@ -8911,8 +8843,7 @@ mod canvas_generation_tests {
}),
);
false
} else if request.starts_with("GET /api/external/v1/editor/projects?view=summary ")
{
} else if request.starts_with("GET /api/external/v1/editor/projects ") {
write_test_json_response(
&mut stream,
"200 OK",
@@ -9282,7 +9213,7 @@ mod canvas_generation_tests {
.expect("write concurrent generation png body");
return;
}
if request.starts_with("GET /api/external/v1/editor/projects?view=summary ") {
if request.starts_with("GET /api/external/v1/editor/projects ") {
// 项目绑定已由 `install_test_external_project_binding` 预置,远端只需回认同一组身份。
write_test_json_response(
stream,
@@ -9756,7 +9687,7 @@ mod canvas_generation_tests {
"Bearer token-b" => "b",
unexpected => panic!("unexpected authorization {unexpected}"),
};
let response = if request.starts_with("GET /api/editor/projects?view=summary ") {
let response = if request.starts_with("GET /api/editor/projects ") {
let projects = if project_created.get(account).copied().unwrap_or(false) {
vec![serde_json::json!({
"projectId": format!("remote-project-{account}"),
@@ -9922,7 +9853,7 @@ mod canvas_generation_tests {
request_sender
.send(request.clone())
.expect("capture concurrent binding request");
let response = if request.starts_with("GET /api/editor/projects?view=summary ") {
let response = if request.starts_with("GET /api/editor/projects ") {
let (state_lock, ready) = &*state;
let mut state = state_lock.lock().expect("lock project fixture state");
if !state.project_created {
@@ -10057,7 +9988,7 @@ mod canvas_generation_tests {
request_sender
.send(request.clone())
.expect("capture project partial request");
if request.starts_with("GET /api/external/v1/editor/projects?view=summary ") {
if request.starts_with("GET /api/external/v1/editor/projects ") {
write_test_json_response(
&mut stream,
"200 OK",
@@ -10191,7 +10122,7 @@ mod canvas_generation_tests {
request_sender
.send(request.clone())
.expect("capture frozen binding request");
if request.starts_with("GET /api/external/v1/editor/projects?view=summary ") {
if request.starts_with("GET /api/external/v1/editor/projects ") {
write_test_json_response(
&mut stream,
"200 OK",
@@ -10316,24 +10247,23 @@ mod canvas_generation_tests {
request_sender
.send(request.clone())
.expect("capture folder partial request");
let response =
if request.starts_with("GET /api/external/v1/editor/projects?view=summary ") {
serde_json::json!({"data": {"projects": []}})
} else if request.starts_with("POST /api/external/v1/editor/projects ") {
serde_json::json!({"data": {"project": {
"projectId": "folder-partial-project"
}}})
} else if request.starts_with("GET /api/external/v1/editor/assets/library ") {
serde_json::json!({"data": {"library": {"folders": []}}})
} else if request.starts_with("POST /api/external/v1/editor/assets/folders ") {
fs::create_dir_all(&blocked_binding_path)
.expect("block final binding write after folder creation");
serde_json::json!({"data": {"folder": {
"folderId": "folder-partial-folder"
}}})
} else {
panic!("unexpected folder partial request: {request}");
};
let response = if request.starts_with("GET /api/external/v1/editor/projects ") {
serde_json::json!({"data": {"projects": []}})
} else if request.starts_with("POST /api/external/v1/editor/projects ") {
serde_json::json!({"data": {"project": {
"projectId": "folder-partial-project"
}}})
} else if request.starts_with("GET /api/external/v1/editor/assets/library ") {
serde_json::json!({"data": {"library": {"folders": []}}})
} else if request.starts_with("POST /api/external/v1/editor/assets/folders ") {
fs::create_dir_all(&blocked_binding_path)
.expect("block final binding write after folder creation");
serde_json::json!({"data": {"folder": {
"folderId": "folder-partial-folder"
}}})
} else {
panic!("unexpected folder partial request: {request}");
};
write_test_json_response(&mut stream, "200 OK", &response);
}
});

Some files were not shown because too many files have changed in this diff Show More