Files
Genarrative/apps/ai-game-creator-shell/src-tauri/vendor/codex-patch-parser/upstream-integrity.test.mjs
T
kdletters 485ed50b26
Project CI / AI game creator shell Rust smoke (push) Has been cancelled
Project CI / AI game creator shell Rust crates (push) Has been cancelled
Project CI / Backend tests (push) Has been cancelled
Project CI / Native shell tests (push) Has been cancelled
Project CI / Frontend tests (push) Has been cancelled
Project CI / Repository checks (push) Has been cancelled
Project CI / AI game creator shell web tests (push) Has been cancelled
Project CI / AI game creator shell Rust shard 2/4 (push) Has been cancelled
Project CI / AI game creator shell Rust shard 1/4 (push) Has been cancelled
Project CI / AI game creator shell Rust shard 3/4 (push) Has been cancelled
Project CI / AI game creator shell Rust shard 4/4 (push) Has been cancelled
AGC 七项交付效率优化并升级捆绑 Codex 到 0.155.1 (#439)
## 背景

净月潭案例(2026-09-19 21:53 → 09-20 01:26,3 小时 33 分)的问题不是模型慢,而是环境未就绪、验收靠模型自述、预算只约束单个工具入口、工具调用被 SDK 全局串行闸门卡住。本 PR 落地确认后的七项交付效率合同,并把捆绑 Codex 升到当前 npm latest。

## 结果

- 新建 Web 游戏在正式生成前由宿主自动预检:捆绑 Node/npm、真实 Vite 构建、受限浏览器桌面/移动截图;失败不启动生成或付费素材。
- 首个副作用前冻结交付合同,宿主保存权威证据与预算;证据齐全后先封口、排空并取得执行器完整退出证明,再产出交付报告,模型回复不再当作验收。
- 原生 shell、内置浏览器与托管命令、第三方 MCP 共用同一执行许可和累计执行时间;`validation.maxRuns` 改为执行/返修批次语义,另设 `maxTurnSeconds` 墙钟上限。
- 所有工具可并发:移除 SDK 全局串行的 `apply_patch`/`update_plan` 注册,改由宿主 `agc_apply_patch`(官方 parser + 当前回合写许可 + 受控进程树 + 短项目事务)和 `agc_update_plan` 提供等价能力;真实请求目录里已无串行注册,长 MCP 与补丁/计划实测在同一响应内重叠。
- 付费提交与本地写入绑定原回合原租约:容量与同动作锁等待可取消,封口、取消或预算耗尽后零新增提交;已越过提交边界的请求保留 operation ID 走 GET 对账,不自动重放。
- 新增请求与工具分段计时、有界并行批读和首轮上下文预取,未知耗时不补零。
- 捆绑 Codex 0.147.0 → 0.155.1:固定版本收敛到 `build_support/codex_bundle.rs` 单一声明,vendor 解析源码按 `rust-v0.155.1` 逐字节重取并更新 UPSTREAM 证据,适配 0.155 统一 exec(`exec_command`/`write_stdin`);macOS 侧车最小系统版本仍为 15.0。

## 验证

- 生产 CLI → 捆绑 Codex 0.155.1 → 本地 Responses/MCP 夹具 9/9:补丁、完成收尾、批次、只读/可写 MCP 并发、原生命令并发、原生资源并发、统一 exec 会话、期限终止(真实重叠 775 / 764 / 999 ms)。
- 真实模型目录 2/2;vendor 上游库 111 项;宿主定向与回归 106 项;真实 Windows 进程与取消 21 项;Node 侧门禁 52 项。
- 发行载荷:artifact-only 重建 NSIS,解包验证侧车清单 `codex-cli 0.155.1`、6 个组件哈希、打包后 `bin/codex.exe --version`、Node 运行时 2130 文件与双端 PNG、`--environment-check` ready。
- `check-config`、TypeScript、编码(4991 文件)、文档索引、`git diff --check`、`cargo fmt --check` 全部通过。

## 未覆盖

- 真实陶泥儿登录态 Provider 生成尚未执行(本机 `--llm-status` 返回 `authentication-required`)。
- macOS 侧车只在本机做静态 Mach-O 与清单解析,未在 macOS 上跑 `check-macos-bundle.mjs`。
- 全仓库聚合套件在本机仍因负载敏感的后台 mock-provider 用例而红,与本次改动无关:改动前的旧二进制同样失败,换单线程后相关用例 3/3 通过。

---------

Co-authored-by: kdletters <61648117+kdletters@users.noreply.github.com>
Reviewed-on: http://192.168.35.82/git/GenarrativeAI/Genarrative/pulls/439
2026-09-21 02:29:29 +08:00

74 lines
2.6 KiB
JavaScript

import assert from 'node:assert/strict';
import { createHash } from 'node:crypto';
import { readFileSync } from 'node:fs';
import path from 'node:path';
import test from 'node:test';
import { fileURLToPath } from 'node:url';
const parserRoot = path.dirname(fileURLToPath(import.meta.url));
const vendorRoot = path.dirname(parserRoot);
const packages = [
'codex-patch-parser',
'codex-utils-absolute-path',
'codex-utils-path-uri',
];
const commit = 'be2951ea34f0d295ed0becf97079f92fa5f6950e';
for (const packageName of packages) {
test(`${packageName} 保留固定版本的完整源码与许可`, () => {
const packageRoot = path.join(vendorRoot, packageName);
const provenance = JSON.parse(
readFileSync(path.join(packageRoot, 'UPSTREAM.json'), 'utf8'),
);
assert.equal(provenance.repository, 'https://github.com/openai/codex');
assert.equal(provenance.commit, commit);
assert.equal(provenance.tag, 'rust-v0.155.1');
assert.ok(provenance.files.length >= 4);
for (const entry of provenance.files) {
const absolute = path.resolve(packageRoot, entry.path);
const relative = path.relative(packageRoot, absolute);
assert.ok(
relative && relative !== '..' && !relative.startsWith(`..${path.sep}`),
);
assert.ok(!path.isAbsolute(relative));
const bytes = readFileSync(absolute);
assert.doesNotThrow(() =>
new TextDecoder('utf-8', { fatal: true }).decode(bytes),
);
const digest = createHash('sha256').update(bytes).digest('hex');
assert.equal(
digest,
entry.sha256,
`${packageName}/${entry.path} 与上游固定源码不同`,
);
}
for (const license of ['LICENSE', 'NOTICE']) {
assert.ok(
provenance.files.some(
(entry) => entry.path === license && entry.upstreamPath === license,
),
);
}
for (const extraction of provenance.extractions ?? []) {
const source = readFileSync(
path.join(packageRoot, extraction.path),
'utf8',
);
const start = source.indexOf(extraction.startMarker);
assert.notEqual(start, -1);
const end = source.indexOf(extraction.endMarker, start);
assert.notEqual(end, -1);
const snippet = source.slice(start, end + extraction.endMarker.length);
assert.equal(
createHash('sha256').update(snippet).digest('hex'),
extraction.sha256,
);
}
const manifest = readFileSync(path.join(packageRoot, 'Cargo.toml'), 'utf8');
assert.doesNotMatch(
manifest,
/codex-(?:core|exec-server|protocol|api)\s*=/,
);
});
}