Compare commits

..
Author SHA1 Message Date
suyx e9fd15e7b6 fix(POSTV1-runtime): 改善后台启动与状态窗口可见性
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 23:12:31 +08:00
suyx d9e39702e0 fix(POSTV1-06): 恢复贴纸与字体运行时资源链路
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 16:58:45 +08:00
suyx 7de633d4c9 fix(POSTV1-05): 修复生成请求与 Worker 重入
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 16:04:11 +08:00
suyx b995662388 fix(POSTV1-04): 修复生成服务运行时装配
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 15:36:47 +08:00
suyx 92434aec17 feat(POSTV1-03): 增加本机测试直达入口
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 14:53:20 +08:00
suyx f7cac5dabf fix(POSTV1-02): 修复便携网页静态资源类型
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 14:07:42 +08:00
suyx a7f62adad4 fix(POSTV1-02): 确保AI探测输出后退出
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 13:26:44 +08:00
suyx b1f143c238 feat(POSTV1-02): 增加AI真实生成探测
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 13:14:40 +08:00
suyx 99fd3b1802 fix(POSTV1-02): 修复便携版网页入口门禁
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 12:58:28 +08:00
suyx fd0003a804 fix(POSTV1-02): 补齐便携包Worker运行依赖
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 12:46:59 +08:00
suyx bfdfe44f87 test(POSTV1-02): 修正便携包AI适配器检查
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 12:34:46 +08:00
suyx cbb7f658a3 fix(POSTV1-02): 接通真实AI生成链路
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 12:29:14 +08:00
suyx 43d946bb5c fix(POSTV1-02): 修复便携包首次启动链路
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 12:00:23 +08:00
suyx 79b01ebc81 test(POSTV1-01): 增加最终便携包启动链路验收
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 11:38:32 +08:00
suyx 90f812fae5 fix(POSTV1-01): 让Worker使用便携包SQLite原生绑定
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 11:25:02 +08:00
suyx 1155a81c3b fix(POSTV1-01): 接入Worker生成任务消费链路
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 11:24:14 +08:00
suyx 3dca4ad77c fix(POSTV1-01): 在最终包中提供产品网页与同源API
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
2026-08-05 11:22:58 +08:00
suyx 99fe07a761 fix(POSTV1-01): 允许非关键外部服务降级启动 2026-08-05 11:22:42 +08:00
tuyixuan 443e8b94f0 Merge pull request 'feat(P0-A): 整合第一版并冻结最终发布' (#1) from codex/wp7-07 into codex/wp0-09
Dada P0-A isolated Windows CI / validate-and-package (push) Waiting to run
Reviewed-on: #1
2026-08-05 10:29:22 +08:00
suyx 693fa117b7 chore(WP7-07): 冻结第一版发布记录
Dada P0-A isolated Windows CI / validate-and-package (push) Successful in 17m46s
Dada P0-A isolated Windows CI / validate-and-package (pull_request) Successful in 17m49s
2026-08-04 23:32:51 +08:00
suyx 08f3cccae4 fix(WP7-07): 排除发布扫描器路径误报
Dada P0-A isolated Windows CI / validate-and-package (push) Canceled after 0s
2026-08-04 23:20:40 +08:00
suyx a22b1f19e9 fix(WP7-07): 修正最终包浏览器门禁探测
Dada P0-A isolated Windows CI / validate-and-package (push) Canceled after 0s
2026-08-04 23:15:36 +08:00
suyx 194b59d4a5 fix(WP7-07): 统一构建全部工作区依赖
Dada P0-A isolated Windows CI / validate-and-package (push) Canceled after 0s
2026-08-04 23:07:01 +08:00
suyx 0f03b12f64 fix(WP7-07): 补齐便携包前置构建顺序
Dada P0-A isolated Windows CI / validate-and-package (push) Canceled after 0s
2026-08-04 23:05:38 +08:00
suyx ad86b4ddcc feat(WP7-07): 增加最终发布冻结与泄漏扫描
Dada P0-A isolated Windows CI / validate-and-package (push) Canceled after 0s
2026-08-04 23:03:11 +08:00
suyx 08e9c39e49 feat(WP7-06): 增加最终AC预冻结门禁
Dada P0-A isolated Windows CI / validate-and-package (push) Canceled after 0s
2026-08-04 22:43:35 +08:00
suyx ffd1643848 chore(WP7-06): 合并候选环境验收基线
Dada P0-A isolated Windows CI / validate-and-package (push) Canceled after 0s
# Conflicts:
#	package.json
2026-08-04 22:39:26 +08:00
suyx 95ab0cb93b chore(WP7-06): 合并高德发布门禁基线
Dada P0-A isolated Windows CI / validate-and-package (push) Canceled after 0s
# Conflicts:
#	package.json
#	supervisor/Dada.Supervisor/OfflineCommandRouter.cs
2026-08-04 22:38:29 +08:00
suyx b2793a2392 chore(WP7-06): 合并Resend发布门禁基线
Dada P0-A isolated Windows CI / validate-and-package (push) Canceled after 0s
# Conflicts:
#	package.json
2026-08-04 22:37:15 +08:00
suyx a7140e99e1 chore(WP7-06): 合并WP4视觉验收与资源迁移修复
Dada P0-A isolated Windows CI / validate-and-package (push) Canceled after 0s
2026-08-04 22:36:08 +08:00
suyx f4fabb66e5 fix(WP4-07): 兼容迁移后的字体资源路径
Dada P0-A isolated Windows CI / validate-and-package (push) Canceled after 0s
2026-08-04 18:29:17 +08:00
suyx 4a0fb1bfae fix(WP4-07): 支持新的贴纸资源根目录
Dada P0-A isolated Windows CI / validate-and-package (push) Canceled after 0s
2026-08-04 18:22:28 +08:00
suyx f7bed92e61 test: cover Amap production security gates
Dada P0-A isolated Windows CI / validate-and-package (push) Failing after 2m43s
2026-08-04 17:31:25 +08:00
suyx d03b491d2f fix: harden controlled Amap probe
Dada P0-A isolated Windows CI / validate-and-package (push) Failing after 1m46s
2026-08-04 17:28:24 +08:00
suyx 8c349fb56c fix: wire production Amap adapter
Dada P0-A isolated Windows CI / validate-and-package (push) Failing after 1m47s
2026-08-04 17:09:04 +08:00
suyx 55646ba1b4 feat: build sanitized WP7-05 coverage evidence
Dada P0-A isolated Windows CI / validate-and-package (push) Failing after 1m49s
2026-08-04 17:08:44 +08:00
suyx 8abf1397a6 test: require WP7-05 state evidence
Dada P0-A isolated Windows CI / validate-and-package (push) Failing after 3m17s
2026-08-04 17:02:52 +08:00
suyx e0e101ef28 fix: align WP7-05 candidate record schema
Dada P0-A isolated Windows CI / validate-and-package (push) Failing after 2m30s
2026-08-04 16:59:31 +08:00
suyx 33f87f8db3 test: scaffold WP7-05 candidate UI gate
Dada P0-A isolated Windows CI / validate-and-package (push) Failing after 2m18s
2026-08-04 16:58:15 +08:00
suyx a7772a7e92 test: harden WP7-04 release gate evidence
Dada P0-A isolated Windows CI / validate-and-package (push) Failing after 3m1s
2026-08-04 15:49:25 +08:00
suyx 2bfb5f2953 test: prove Amap monthly egress hard stop
Dada P0-A isolated Windows CI / validate-and-package (push) Failing after 50s
2026-08-04 15:39:46 +08:00
suyx 4ec8327f5e feat: add controlled Amap credential probe
Dada P0-A isolated Windows CI / validate-and-package (push) Failing after 1m0s
2026-08-04 14:52:23 +08:00
suyx cca0a38ada feat: add Resend release gate evidence validation (TASK-WP7-03)
Dada P0-A isolated Windows CI / validate-and-package (push) Failing after 59s
2026-08-04 13:51:02 +08:00
suyx d474768a2b test: record WP7-04 Amap external blocker
Dada P0-A isolated Windows CI / validate-and-package (push) Failing after 57s
2026-08-04 13:35:10 +08:00
73 changed files with 15690 additions and 102 deletions
+29
View File
@@ -0,0 +1,29 @@
{
"appVersion": "0.0.0",
"browsers": [
{
"brand": "Google Chrome",
"fullVersion": "150.0.7871.187"
},
{
"brand": "Microsoft Edge",
"fullVersion": "151.0.4129.59"
}
],
"buildCommit": "08f3cccae4a1e75e2f2292eef14611313523916d",
"deferredExternalTasks": [
"TASK-WP7-03",
"TASK-WP7-04"
],
"finalRelease": true,
"fixedPort": 43121,
"frozenFromCommit": "08e9c39e49d68f8642d5acfe22b0fdb40a3a08fa",
"recordedAt": "2026-08-04T15:20:54.271Z",
"releaseStatus": "first_version_internal",
"schemaVersion": "1.0",
"windows": {
"arch": "x64",
"build": "26200.8875",
"displayVersion": "25H2"
}
}
+1 -1
View File
@@ -16,7 +16,7 @@ const forbiddenDiagnosticPatterns = [
/https?:\/\//i,
];
const safePauseReasons = new Set([
"asset_root_state_missing", "balance_insufficient", "configured_disabled", "contract_blocked",
"asset_manifest_invalid", "asset_root_missing", "asset_root_state_missing", "balance_insufficient", "configured_disabled", "contract_blocked",
"contract_unverified", "gateway_balance_insufficient", "gateway_paused", "health_check_failed",
"model_disabled", "provider_unavailable", "quota_exhausted", "service_state_missing", "unknown",
"worker_degraded", "worker_state_missing", "worker_stopped",
+150 -1
View File
@@ -1,5 +1,31 @@
import { request as httpsRequest } from "node:https";
const amapHostname = "restapi.amap.com" as const;
const amapMaxResponseBytes = 65_536;
const amapTimeoutMs = 15_000;
export interface AmapHttpRequest {
allowRedirects: false;
hostname: typeof amapHostname;
maxResponseBytes: number;
method: "GET";
path: string;
protocol: "https:";
rejectUnauthorized: true;
timeoutMs: number;
}
type AmapRequester = (request: AmapHttpRequest) => Promise<unknown>;
export class AmapAdapterError extends Error {
constructor(readonly code: "amap_adapter_disposed" | "amap_invalid_request" | "amap_invalid_response" | "amap_provider_rejected" | "amap_provider_unavailable" | "amap_redirect_rejected" | "amap_request_timeout" | "amap_response_too_large") {
super(code);
}
}
export interface AmapAdapter {
reverseGeocode(coordinates: { latitude: number; longitude: number }): Promise<{ formattedValue: string; serviceMode: "mock" }>;
dispose?(): void;
reverseGeocode(coordinates: { latitude: number; longitude: number }): Promise<{ formattedValue: string; serviceMode: "mock" | "real" }>;
}
export class MockAmapAdapter implements AmapAdapter {
@@ -13,3 +39,126 @@ export class MockAmapAdapter implements AmapAdapter {
};
}
}
function requestAmapJson(input: AmapHttpRequest) {
return new Promise<unknown>((resolve, reject) => {
if (input.protocol !== "https:" || input.hostname !== amapHostname || input.allowRedirects || !input.rejectUnauthorized) {
reject(new AmapAdapterError("amap_invalid_request"));
return;
}
let settled = false;
const finish = (callback: () => void) => {
if (settled) return;
settled = true;
callback();
};
const request = httpsRequest({
headers: { Accept: "application/json" },
hostname: input.hostname,
method: input.method,
path: input.path,
port: 443,
protocol: input.protocol,
rejectUnauthorized: input.rejectUnauthorized,
servername: input.hostname,
}, (response) => {
const statusCode = response.statusCode ?? 0;
if (statusCode >= 300 && statusCode < 400) {
response.resume();
finish(() => reject(new AmapAdapterError("amap_redirect_rejected")));
return;
}
if (statusCode !== 200) {
response.resume();
finish(() => reject(new AmapAdapterError("amap_provider_unavailable")));
return;
}
const declaredLength = Number(response.headers["content-length"] ?? 0);
if (Number.isFinite(declaredLength) && declaredLength > input.maxResponseBytes) {
response.destroy();
finish(() => reject(new AmapAdapterError("amap_response_too_large")));
return;
}
const chunks: Buffer[] = [];
let receivedBytes = 0;
response.on("data", (chunk: Buffer | string) => {
const bytes = Buffer.isBuffer(chunk) ? chunk : Buffer.from(chunk);
receivedBytes += bytes.length;
if (receivedBytes > input.maxResponseBytes) {
response.destroy();
finish(() => reject(new AmapAdapterError("amap_response_too_large")));
return;
}
chunks.push(bytes);
});
response.on("end", () => {
finish(() => {
try {
resolve(JSON.parse(Buffer.concat(chunks).toString("utf8")));
} catch {
reject(new AmapAdapterError("amap_invalid_response"));
} finally {
for (const chunk of chunks) chunk.fill(0);
chunks.length = 0;
}
});
});
});
request.setTimeout(input.timeoutMs, () => request.destroy(new AmapAdapterError("amap_request_timeout")));
request.on("error", (error) => finish(() => reject(error instanceof AmapAdapterError ? error : new AmapAdapterError("amap_provider_unavailable"))));
request.end();
});
}
function isRecord(value: unknown): value is Record<string, unknown> {
return Boolean(value) && typeof value === "object" && !Array.isArray(value);
}
export class RealAmapAdapter implements AmapAdapter {
private readonly credential: Buffer;
private readonly requester: AmapRequester;
private disposed = false;
constructor(value: string, options: { request?: AmapRequester } = {}) {
if (!value.trim()) throw new AmapAdapterError("amap_invalid_request");
this.credential = Buffer.from(value, "utf8");
this.requester = options.request ?? requestAmapJson;
}
async reverseGeocode(coordinates: { latitude: number; longitude: number }) {
if (this.disposed) throw new AmapAdapterError("amap_adapter_disposed");
if (!Number.isFinite(coordinates.latitude) || coordinates.latitude < -90 || coordinates.latitude > 90
|| !Number.isFinite(coordinates.longitude) || coordinates.longitude < -180 || coordinates.longitude > 180) {
throw new AmapAdapterError("amap_invalid_request");
}
const query = new URLSearchParams({
extensions: "base",
key: this.credential.toString("utf8"),
location: `${coordinates.longitude},${coordinates.latitude}`,
});
const response = await this.requester({
allowRedirects: false,
hostname: amapHostname,
maxResponseBytes: amapMaxResponseBytes,
method: "GET",
path: `/v3/geocode/regeo?${query.toString()}`,
protocol: "https:",
rejectUnauthorized: true,
timeoutMs: amapTimeoutMs,
});
if (!isRecord(response) || response.status !== "1" || !isRecord(response.regeocode)) {
throw new AmapAdapterError("amap_provider_rejected");
}
const formattedValue = typeof response.regeocode.formatted_address === "string"
? response.regeocode.formatted_address.trim()
: "";
if (!formattedValue || formattedValue.length > 200) throw new AmapAdapterError("amap_invalid_response");
return { formattedValue, serviceMode: "real" as const };
}
dispose() {
if (this.disposed) return;
this.disposed = true;
this.credential.fill(0);
}
}
+82 -4
View File
@@ -1,6 +1,6 @@
import { randomBytes, randomUUID } from "node:crypto";
import { createReadStream, readFileSync } from "node:fs";
import { resolve } from "node:path";
import { createReadStream, existsSync, readFileSync } from "node:fs";
import { extname, resolve } from "node:path";
import {
AccountDeletionCompleteRequestSchema,
@@ -218,6 +218,24 @@ import type { ManagedStorage } from "./managed-storage.js";
import { PrivateContentError, PrivateContentService } from "./private-content.js";
import { assertSafeAdminDiagnostics, assertSafeAdminServicesStorage } from "./admin-state.js";
const productAssetContentTypes: Readonly<Record<string, string>> = {
".css": "text/css; charset=utf-8",
".jpeg": "image/jpeg",
".jpg": "image/jpeg",
".js": "text/javascript; charset=utf-8",
".json": "application/json; charset=utf-8",
".mjs": "text/javascript; charset=utf-8",
".png": "image/png",
".svg": "image/svg+xml",
".webp": "image/webp",
".woff": "font/woff",
".woff2": "font/woff2",
};
function productAssetContentType(path: string) {
return productAssetContentTypes[extname(path).toLowerCase()] ?? "application/octet-stream";
}
const defaultBootstrap: BootstrapResponse = {
app_version: "0.0.0",
dependencies: [],
@@ -238,12 +256,14 @@ export interface CreateAppOptions {
assetReleases?: AssetReleaseReader;
bootstrap?: () => BootstrapResponse | Promise<BootstrapResponse>;
browserGate?: boolean;
productIndexHtml?: string;
browserSupportRelease?: BrowserSupportRelease;
browserSupportSecret?: Buffer;
credits?: CreditService;
eventHub?: EventHub;
generations?: GenerationSubmissionService;
latestExports?: LatestExportService;
localTestAuth?: boolean;
models?: ModelConfigurationService;
networkBoundary?: NetworkBoundaryOptions;
publicAssets?: PublicAssetResolver;
@@ -272,6 +292,10 @@ const supportGateDirectory = resolve(process.env.DADA_SUPPORT_GATE_ROOT ?? "apps
const supportGateHtml = readFileSync(resolve(supportGateDirectory, "index.html"), "utf8");
const supportGateCss = readFileSync(resolve(supportGateDirectory, "support-gate.css"), "utf8");
const supportGateJavaScript = readFileSync(resolve(supportGateDirectory, "support-gate.js"), "utf8");
const productWebRoot = resolve(process.env.DADA_WEB_ROOT ?? "apps/web/dist");
const packagedProductIndexHtml = existsSync(resolve(productWebRoot, "index.html"))
? readFileSync(resolve(productWebRoot, "index.html"), "utf8")
: undefined;
const clientHints = "Sec-CH-UA, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Platform";
const contentSecurityPolicy = [
"default-src 'self'",
@@ -710,6 +734,7 @@ export async function createApp(options: CreateAppOptions = {}) {
)
: undefined);
const browserGate = options.browserGate ?? true;
const productIndexHtml = options.productIndexHtml ?? packagedProductIndexHtml;
const browserSupportSecret = options.browserSupportSecret ?? randomBytes(32);
const browserSupportRelease = options.browserSupportRelease;
const app = Fastify({
@@ -901,11 +926,25 @@ export async function createApp(options: CreateAppOptions = {}) {
});
for (const route of ["/", "/app", "/app/*", "/admin", "/admin/*"]) {
app.get(route, { schema: { hide: true } }, async (_request, reply) => {
app.get(route, { schema: { hide: true } }, async (request, reply) => {
reply.type("text/html; charset=utf-8");
return supportGateHtml;
if (!browserGate) return productIndexHtml ?? supportGateHtml;
const verified = verifyBrowserSupportCookie({
cookieHeader: headerValue(request.headers.cookie),
release: browserSupportRelease,
secChUa: headerValue(request.headers["sec-ch-ua"]),
secret: browserSupportSecret,
});
return verified.supported && productIndexHtml ? productIndexHtml : supportGateHtml;
});
}
app.get("/assets/*", { schema: { hide: true } }, async (request, reply) => {
const relativePath = decodeURIComponent(request.url.split("?", 1)[0]!.slice("/assets/".length));
const assetPath = resolve(productWebRoot, "assets", relativePath);
if (!assetPath.startsWith(resolve(productWebRoot, "assets")) || !existsSync(assetPath)) return reply.code(404).send();
reply.type(productAssetContentType(assetPath));
return reply.send(readFileSync(assetPath));
});
app.get("/support-gate.css", { schema: { hide: true } }, async (_request, reply) => {
reply.type("text/css; charset=utf-8");
return supportGateCss;
@@ -2037,6 +2076,45 @@ export async function createApp(options: CreateAppOptions = {}) {
},
);
if (options.localTestAuth && options.registration) {
app.get(
"/api/v1/auth/local-test",
{ schema: { hide: true } },
async () => ({ available: true }),
);
app.post(
"/api/v1/auth/local-test",
{ schema: { hide: true } },
async (request, reply) => {
try {
const result = options.registration!.createLocalTestSession();
reply.header(
"Set-Cookie",
`${userSessionCookieName}=${result.sessionToken}; Max-Age=${30 * 24 * 60 * 60}; Path=/; HttpOnly; SameSite=Strict`,
);
return {
audience: result.audience,
credits: {
available_balance: result.credits.availableBalance,
reserved_balance: result.credits.reservedBalance,
},
session_expires_at: new Date(result.sessionExpiresAt).toISOString(),
status: result.status,
user: {
creator_name: result.user.creatorName,
role: result.user.role,
social_id: result.user.socialId,
status: result.user.status,
user_id: result.user.userId,
},
};
} catch (error) {
return registrationFailure(reply, request.id, error);
}
},
);
}
app.post(
"/api/v1/auth/login/complete",
{
+22 -9
View File
@@ -19,7 +19,7 @@ import { dirname, isAbsolute, join, parse, relative, resolve, sep } from "node:p
const require = createRequire(import.meta.url);
const Database = require("better-sqlite3") as typeof import("better-sqlite3");
const assetIdPattern = /^[0-9a-f]{8}-[0-9a-f]{4}-[1-8][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$/i;
const assetIdPattern = /^[a-z0-9][a-z0-9_-]{2,119}$/i;
const fixedDirectories = [
"db",
"content/references",
@@ -33,6 +33,12 @@ const fixedDirectories = [
"logs/supervisor",
] as const;
export function ensureLocalDataRuntimeDirectories(dataRoot: string) {
for (const directory of fixedDirectories) {
mkdirSync(join(resolve(dataRoot), directory), { recursive: true });
}
}
export const DATA_TRANSFER_POLICY = {
allowed_downloads: ["original_generation", "jpg", "png"],
application_backup: false,
@@ -76,13 +82,21 @@ export function readConfiguredLocalDataRoot(configFile = defaultInstanceConfigPa
return resolve(candidate);
}
export function readConfiguredAssetRoot(configFile = defaultInstanceConfigPath()) {
const configuration = JSON.parse(readFileSync(configFile, "utf8")) as Record<string, unknown>;
if (typeof configuration.asset_root !== "string" || !isAbsolute(configuration.asset_root)) {
throw new Error("asset_root_configuration_invalid");
}
return resolve(configuration.asset_root);
}
export interface ValidatedReadOnlyAssetRoot {
absolute_root: string;
ok: true;
root_ref: string;
}
interface PublicAssetEntry {
export interface PublicAssetEntry {
assetId: string;
mimeType: string;
relativePath: string;
@@ -219,9 +233,7 @@ export function initializeLocalDataRoot(input: {
const createdRoot = !existsSync(validation.normalized_path);
try {
for (const directory of fixedDirectories) {
mkdirSync(join(validation.normalized_path, directory), { recursive: true });
}
ensureLocalDataRuntimeDirectories(validation.normalized_path);
openInstanceDatabase(join(validation.normalized_path, "db", "dada.sqlite3"));
const configuration: InstanceConfiguration = {
data_root: validation.normalized_path,
@@ -313,18 +325,19 @@ export function createPublicAssetResolver(input: {
const roots = new Map(input.roots.map((root) => [root.root_ref, root.absolute_root]));
const entries = new Map<string, PublicAssetEntry>();
for (const entry of input.entries) {
if (!assetIdPattern.test(entry.assetId) || entries.has(entry.assetId)) throw new Error("asset_id_invalid");
const key = `${entry.resourceVersion}\u0000${entry.assetId}`;
if (!assetIdPattern.test(entry.assetId) || entries.has(key)) throw new Error("asset_id_invalid");
if (!roots.has(entry.rootRef)) throw new Error("asset_root_unvalidated");
if (!/^[a-z0-9][a-z0-9._-]{0,79}$/i.test(entry.resourceVersion)) throw new Error("resource_version_invalid");
if (!/^[a-z0-9][a-z0-9.+-]*\/[a-z0-9][a-z0-9.+-]*$/i.test(entry.mimeType)) throw new Error("mime_type_invalid");
entries.set(entry.assetId, { ...entry });
entries.set(key, { ...entry });
}
return {
read(resourceVersion, assetId) {
if (!assetIdPattern.test(assetId)) return undefined;
const entry = entries.get(assetId);
if (!entry || entry.resourceVersion !== resourceVersion) return undefined;
const entry = entries.get(`${resourceVersion}\u0000${assetId}`);
if (!entry) return undefined;
const root = roots.get(entry.rootRef);
if (!root) return undefined;
let path: string;
+41 -5
View File
@@ -5,7 +5,7 @@ import { registrationNotice } from "@dada/shared-contracts";
import { createApp } from "./app.js";
import { readBrowserSupportRelease } from "./browser-support.js";
import { defaultInstanceConfigPath, readConfiguredLocalDataRoot } from "./local-data-root.js";
import { defaultInstanceConfigPath, ensureLocalDataRuntimeDirectories, readConfiguredLocalDataRoot, type PublicAssetResolver } from "./local-data-root.js";
import { ManagedStorage } from "./managed-storage.js";
import { LatestExportService } from "./latest-exports.js";
import { CreditService } from "./credits.js";
@@ -16,10 +16,16 @@ import { MockResendAdapter } from "./resend-adapter.js";
import { readSecureConfigCandidate } from "./secure-config.js";
import { StructuredJsonlLogger } from "./structured-log.js";
import { attachApiSupervisorControl, initializeApiCredentialClients, receiveApiCredentials } from "./supervisor-channel.js";
import { ModelConfigurationService } from "./model-configuration.js";
import { MockAmapAdapter } from "./amap-adapter.js";
import { GenerationSubmissionService } from "./generation-submission.js";
import {
GenerationModelConfigurationCatalog,
ModelConfigurationService,
portableRuntimeModelCandidates,
} from "./model-configuration.js";
import { MockAmapAdapter, type AmapAdapter } from "./amap-adapter.js";
import { StickerReleaseService } from "./sticker-releases.js";
import { createAdminDiagnosticsProvider, createAdminServicesStorageProvider } from "./admin-state.js";
import { loadConfiguredRuntimeAssets, type RuntimeAssetState } from "./runtime-assets.js";
const credentialChannelEnabled = process.argv.includes("--dada-credential-stdin");
let registration: RegistrationService | undefined;
@@ -28,16 +34,31 @@ let credits: CreditService | undefined;
let storage: ManagedStorage | undefined;
let latestExports: LatestExportService | undefined;
let models: ModelConfigurationService | undefined;
let generations: GenerationSubmissionService | undefined;
let recentAssets: RecentAssetService | undefined;
let stickers: StickerReleaseService | undefined;
let publicAssets: PublicAssetResolver | undefined;
let assetRootState: RuntimeAssetState | undefined;
let amap: AmapAdapter = new MockAmapAdapter();
let localTestAuth = false;
const instanceConfigPath = process.env.DADA_INSTANCE_CONFIG_PATH ?? defaultInstanceConfigPath();
if (credentialChannelEnabled) {
const clients = initializeApiCredentialClients(await receiveApiCredentials());
try {
amap = clients.amap;
localTestAuth = !clients.resendConfigured;
const derivePepper = (purpose: string) => createHmac("sha256", clients.adminAllowlistPepper)
.update(`Dada/P0A/${purpose}/v1`, "utf8")
.digest();
const dataRoot = readConfiguredLocalDataRoot(instanceConfigPath);
ensureLocalDataRuntimeDirectories(dataRoot);
const runtimeAssets = loadConfiguredRuntimeAssets({
configFile: instanceConfigPath,
dataRoot,
trustedManifestPath: resolve("asset-metadata", "manifest.json"),
});
publicAssets = runtimeAssets.publicAssets;
assetRootState = runtimeAssets.state;
const databasePath = join(dataRoot, "db", "dada.sqlite3");
registration = new RegistrationService({
adminAllowlistPepper: Buffer.from(clients.adminAllowlistPepper),
@@ -53,14 +74,23 @@ if (credentialChannelEnabled) {
storage = new ManagedStorage({ dataRoot, databasePath });
stickers = new StickerReleaseService({ databasePath, storage });
latestExports = new LatestExportService({ databasePath, storage });
models = new ModelConfigurationService({ database: registration.database });
models = new ModelConfigurationService({ database: registration.database, seedCandidates: portableRuntimeModelCandidates });
generations = new GenerationSubmissionService({
credits,
models: new GenerationModelConfigurationCatalog(models),
storage,
});
recentAssets = new RecentAssetService({ database: registration.database });
registration.applySecureConfig(readSecureConfigCandidate(instanceConfigPath));
} catch (error) {
amap.dispose?.();
amap = new MockAmapAdapter();
stickers?.close();
stickers = undefined;
latestExports?.close();
latestExports = undefined;
generations?.close();
generations = undefined;
storage?.close();
storage = undefined;
credits?.close();
@@ -81,6 +111,7 @@ const adminServicesStorage = registration
database: registration.database,
...(models ? { models } : {}),
...(storage ? { storage } : {}),
...(assetRootState ? { assetRoot: assetRootState } : {}),
})
: undefined;
const adminDiagnostics = adminServicesStorage
@@ -92,12 +123,15 @@ const adminDiagnostics = adminServicesStorage
const app = await createApp({
...(adminServicesStorage ? { adminServicesStorage } : {}),
...(adminDiagnostics ? { adminDiagnostics } : {}),
amap: new MockAmapAdapter(),
amap,
...(browserSupportRelease ? { browserSupportRelease } : {}),
...(credits ? { credits } : {}),
...(generations ? { generations } : {}),
...(latestExports ? { latestExports } : {}),
...(registration && localTestAuth ? { localTestAuth: true } : {}),
...(models ? { models } : {}),
...(projects ? { projects } : {}),
...(publicAssets ? { publicAssets } : {}),
...(registration ? { registration } : {}),
...(recentAssets ? { recentAssets } : {}),
...(stickers ? { stickers } : {}),
@@ -115,7 +149,9 @@ if (controlPipeIndex >= 0) {
if (!controlPipe) throw new Error("Supervisor control pipe name is required.");
const control = attachApiSupervisorControl(controlPipe, async () => {
await app.close();
amap.dispose?.();
latestExports?.close();
generations?.close();
credits?.close();
projects?.close();
registration?.close();
+90 -6
View File
@@ -2,6 +2,8 @@ import { randomUUID, createHash } from "node:crypto";
import type BetterSqlite3 from "better-sqlite3";
import { serializeAuditSummary, auditRetentionMilliseconds } from "./audit-policy.js";
import type { GenerationModelCatalog, GenerationModelSnapshot } from "./generation-submission.js";
import { projectRatios } from "./projects.js";
export const modelIds = [
"gemini-3.1-flash-image-preview",
@@ -59,6 +61,45 @@ export interface ModelConfigurationView {
models: ModelConfigView[];
}
type ReadableModelConfiguration = Pick<ModelConfigurationService, "read">;
function generationRuntimeReason(reason: ModelRuntimeReason): GenerationModelSnapshot["runtimeAvailability"]["reason"] {
if (reason === "gateway_balance_insufficient") return reason;
if (reason === "contract_unverified" || reason === "contract_blocked") return "gateway_contract_invalid";
if (reason === "available") return null;
return "model_disabled";
}
export class GenerationModelConfigurationCatalog implements GenerationModelCatalog {
constructor(private readonly models: ReadableModelConfiguration) {}
readModel(modelId: string): GenerationModelSnapshot | undefined {
const configuration = this.models.read();
const model = configuration.models.find((entry) => entry.model_id === modelId);
if (!model) return undefined;
const supportedRatios = projectRatios.filter((ratio) => model.supported_ratios.includes(ratio));
return {
configSetVersion: configuration.config_set_version,
configVersion: model.config_version,
contractValidationStatus: model.contract_validation_status === "verified" ? "verified" : "unverified",
creditCost: model.credit_cost,
enabled: model.enabled,
modelId: model.model_id,
promptMaxLength: model.prompt_max_length,
referenceLimits: {
maxFileBytes: model.reference_limits.max_file_bytes,
maxFiles: model.reference_limits.max_files,
maxTotalBytes: model.reference_limits.max_total_bytes,
},
runtimeAvailability: {
availableForNewJobs: model.runtime_availability.available_for_new_jobs,
reason: generationRuntimeReason(model.runtime_availability.reason),
},
supportedRatios,
};
}
}
export class ModelConfigurationError extends Error {
constructor(
readonly code:
@@ -111,7 +152,7 @@ const defaultErrorMapping: Record<string, string> = {
upstream_timeout: "upstream_timeout",
};
const seedCandidates: ModelConfigCandidate[] = [
const defaultSeedCandidates: ModelConfigCandidate[] = [
{
model_id: modelIds[0], display_name: "Gemini 3.1 Flash Image Preview", enabled: true, is_default: true,
recommendation_priority: 1, route_profile: { endpoint: "https://mock.invalid/v1/images", mode: "sync" },
@@ -138,6 +179,42 @@ const seedCandidates: ModelConfigCandidate[] = [
},
];
export const portableRuntimeModelCandidates: ModelConfigCandidate[] = [
{
...defaultSeedCandidates[0]!,
display_name: "Gemini 3.1 Flash Image",
route_profile: {
endpoint: "https://oneapi.intelligrow.cn/v1/chat/completions",
mode: "sync",
protocol_version: "gemini-openai-chat-v1",
provider_model_id: "gemini-3.1-flash-image",
},
gateway_account_ref: "oneapi-intelligrow-test",
contract_validation_status: "verified",
contract_evidence_ref: "contract:wp7-02:gemini-3.1-flash-image:v7",
},
{
...defaultSeedCandidates[1]!,
enabled: false,
route_profile: { endpoint: "https://oneapi.intelligrow.cn/unsupported", mode: "disabled" },
gateway_account_ref: "oneapi-intelligrow-test",
contract_validation_status: "unverified",
contract_evidence_ref: null,
},
{
...defaultSeedCandidates[2]!,
route_profile: {
endpoint: "https://oneapi.intelligrow.cn/v1/images/generations",
mode: "sync",
protocol_version: "openai-images-v1",
reference_endpoint: "https://oneapi.intelligrow.cn/v1/images/edits",
},
gateway_account_ref: "oneapi-intelligrow-test",
contract_validation_status: "verified",
contract_evidence_ref: "contract:wp7-02:gpt-image-2:v2",
},
];
function stableJson(value: unknown): string {
if (Array.isArray(value)) return `[${value.map(stableJson).join(",")}]`;
if (value && typeof value === "object") {
@@ -207,17 +284,20 @@ export interface ModelConfigurationServiceOptions {
clock?: () => number;
database: BetterSqlite3.Database;
onChanged?: (configSetVersion: number) => void;
seedCandidates?: ModelConfigCandidate[];
}
export class ModelConfigurationService {
readonly database: BetterSqlite3.Database;
readonly #clock: () => number;
readonly #onChanged: ((configSetVersion: number) => void) | undefined;
readonly #seedCandidates: ModelConfigCandidate[];
constructor(options: ModelConfigurationServiceOptions) {
this.database = options.database;
this.#clock = options.clock ?? Date.now;
this.#onChanged = options.onChanged;
this.#seedCandidates = structuredClone(options.seedCandidates ?? defaultSeedCandidates);
this.ensureSchema();
}
@@ -503,7 +583,7 @@ export class ModelConfigurationService {
const current = this.database.prepare("SELECT config_set_id FROM model_config_current WHERE singleton = 1").get() as { config_set_id: string } | undefined;
if (current) return;
const seed = this.database.transaction(() => {
validateModelConfigurationCandidateSet(seedCandidates);
validateModelConfigurationCandidateSet(this.#seedCandidates);
const now = this.#clock();
const setId = randomUUID();
this.database.prepare("INSERT INTO model_config_sets (config_set_id, config_set_version, created_at, created_by) VALUES (?, 1, ?, 'system_seed')")
@@ -520,7 +600,9 @@ export class ModelConfigurationService {
INSERT INTO model_config_set_members (config_set_id, model_id, config_version, enabled, is_default, recommendation_priority)
VALUES (?, ?, 1, ?, ?, ?)
`);
for (const candidate of seedCandidates) {
for (const candidate of this.#seedCandidates) {
const contractStatus = candidate.contract_validation_status ?? "unverified";
const contractEvidenceRef = contractStatus === "unverified" ? null : candidate.contract_evidence_ref ?? null;
const routeProfileId = profileRef("route", candidate.route_profile);
const errorMappingProfileId = profileRef("error", candidate.error_mapping_profile);
this.database.prepare("INSERT OR IGNORE INTO gateway_route_profiles (route_profile_id, profile_json, created_at) VALUES (?, ?, ?)")
@@ -530,12 +612,14 @@ export class ModelConfigurationService {
insertVersion.run(candidate.model_id, candidate.display_name, candidate.enabled ? 1 : 0, candidate.is_default ? 1 : 0,
candidate.recommendation_priority, routeProfileId, stableJson(candidate.route_profile), candidate.gateway_account_ref,
errorMappingProfileId, stableJson(candidate.error_mapping_profile), candidate.credit_cost, stableJson(candidate.supported_ratios), stableJson(candidate.reference_limits),
candidate.prompt_max_length, candidate.safety_source, "unverified", null, fingerprint(candidate), now);
candidate.prompt_max_length, candidate.safety_source, contractStatus, contractEvidenceRef, fingerprint(candidate), now);
insertMember.run(setId, candidate.model_id, candidate.enabled ? 1 : 0, candidate.is_default ? 1 : 0, candidate.recommendation_priority);
const available = candidate.enabled && contractStatus === "verified";
const runtimeReason = !candidate.enabled ? "configured_disabled" : available ? "available" : "contract_unverified";
this.database.prepare(`
INSERT INTO model_runtime_availability (model_id, available_for_new_jobs, reason, checked_at, runtime_availability_version)
VALUES (?, 0, 'contract_unverified', ?, 0)
`).run(candidate.model_id, now);
VALUES (?, ?, ?, ?, 0)
`).run(candidate.model_id, available ? 1 : 0, runtimeReason, now);
}
this.database.prepare("INSERT INTO model_config_current (singleton, config_set_id) VALUES (1, ?)").run(setId);
});
+55
View File
@@ -38,6 +38,7 @@ export interface RegistrationTransactionEvent {
| "registration_send"
| "registration_complete"
| "registration_send_compensation"
| "local_test_session"
| "login_send"
| "login_complete"
| "admin_login_send"
@@ -654,6 +655,60 @@ export class RegistrationService {
return outcome;
}
createLocalTestSession(): LoginCompleteResult {
const now = this.options.clock();
return this.runImmediate("local_test_session", () => {
const registrationId = "local-test-user-v1";
const existing = this.database.prepare(`
SELECT user_id, role, status FROM users WHERE registration_id = ?
`).get(registrationId) as {
role: "user" | "super_admin";
status: "active" | "suspended" | "deleted";
user_id: string;
} | undefined;
if (existing) {
if (existing.role !== "user" || existing.status !== "active") {
throw new RegistrationError("AUTH_ENTRY_REJECTED", "account_suspended");
}
const session = this.insertSession(existing.user_id, "user", now);
return {
outcome: "committed",
value: this.loginResult(this.readCompletedRegistration(existing.user_id, session.sessionId)),
};
}
const userId = randomUUID();
this.database.prepare(`
INSERT INTO users (
user_id, normalized_email, role, status, counts_toward_stage_limit,
registration_id, created_at
) VALUES (?, 'local-test-user@dada.invalid', 'user', 'active', 0, ?, ?)
`).run(userId, registrationId, now);
this.database.prepare(`
INSERT INTO user_profiles (
user_id, creator_name, social_id, private_content_notice_version,
private_content_notice_acknowledged_at
) VALUES (?, '本机测试用户', '@dada_local_test', NULL, NULL)
`).run(userId);
this.database.prepare(`
INSERT INTO credit_accounts (user_id, available_balance, reserved_balance, updated_at)
VALUES (?, 10, 0, ?)
`).run(userId, now);
this.database.prepare(`
INSERT INTO credit_ledger (
ledger_id, user_id, operation_key, entry_type, amount,
available_before, available_after, reserved_before, reserved_after, created_at
) VALUES (?, ?, 'local-test-registration:v1', 'registration_grant', 10, 0, 10, 0, 0, ?)
`).run(randomUUID(), userId, now);
const session = this.insertSession(userId, "user", now);
return {
outcome: "committed",
value: this.loginResult(this.readCompletedRegistration(userId, session.sessionId)),
};
});
}
applySecureConfig(candidate: SecureConfigCandidate) {
const now = this.options.clock();
const fail = (reason: string): never => {
+93
View File
@@ -0,0 +1,93 @@
import { createHash } from "node:crypto";
import { existsSync, readFileSync } from "node:fs";
import {
createPublicAssetResolver,
readConfiguredAssetRoot,
validateReadOnlyAssetRoot,
type PublicAssetEntry,
type PublicAssetResolver,
} from "./local-data-root.js";
const rootRef = "p0a_runtime_assets";
const schemaVersion = "DadaRuntimeAssets/v1";
const assetIdPattern = /^[a-z0-9][a-z0-9_-]{2,119}$/i;
const releasePattern = /^[a-z0-9][a-z0-9._-]{0,79}$/i;
const shaPattern = /^[a-f0-9]{64}$/i;
export interface RuntimeAssetState {
checked_at: string;
configured: boolean;
pause_reason: "asset_manifest_invalid" | "asset_root_missing" | "asset_root_state_missing" | null;
status: "active" | "unavailable";
}
export interface LoadedRuntimeAssets {
publicAssets?: PublicAssetResolver;
state: RuntimeAssetState;
}
function parseRuntimeManifest(bytes: Buffer): PublicAssetEntry[] {
const value = JSON.parse(bytes.toString("utf8")) as Record<string, unknown>;
if (value.schema_version !== schemaVersion || value.source !== "external_read_only" || value.root_ref !== rootRef) {
throw new Error("runtime_asset_manifest_invalid");
}
if (!Array.isArray(value.entries) || value.entries.length === 0) throw new Error("runtime_asset_manifest_invalid");
return value.entries.map((candidate) => {
if (!candidate || typeof candidate !== "object" || Array.isArray(candidate)) throw new Error("runtime_asset_manifest_invalid");
const entry = candidate as Record<string, unknown>;
if (
typeof entry.assetId !== "string" || !assetIdPattern.test(entry.assetId)
|| typeof entry.mimeType !== "string" || !/^[a-z0-9][a-z0-9.+-]*\/[a-z0-9][a-z0-9.+-]*$/i.test(entry.mimeType)
|| typeof entry.relativePath !== "string" || entry.relativePath.includes("\\") || entry.relativePath.split("/").includes("..")
|| typeof entry.resourceVersion !== "string" || !releasePattern.test(entry.resourceVersion)
|| entry.rootRef !== rootRef
|| typeof entry.sha256 !== "string" || !shaPattern.test(entry.sha256)
) throw new Error("runtime_asset_manifest_invalid");
return entry as unknown as PublicAssetEntry;
});
}
function unavailable(
configured: boolean,
pauseReason: Exclude<RuntimeAssetState["pause_reason"], null>,
checkedAt: string,
): LoadedRuntimeAssets {
return { state: { checked_at: checkedAt, configured, pause_reason: pauseReason, status: "unavailable" } };
}
export function loadConfiguredRuntimeAssets(input: {
configFile: string;
dataRoot: string;
trustedManifestPath: string;
clock?: () => number;
}): LoadedRuntimeAssets {
const checkedAt = new Date((input.clock ?? Date.now)()).toISOString();
let assetRoot: string;
try {
assetRoot = readConfiguredAssetRoot(input.configFile);
} catch {
return unavailable(false, "asset_root_state_missing", checkedAt);
}
if (!existsSync(input.trustedManifestPath)) return unavailable(true, "asset_manifest_invalid", checkedAt);
try {
const trustedBytes = readFileSync(input.trustedManifestPath);
const entries = parseRuntimeManifest(trustedBytes);
const validatedRoot = validateReadOnlyAssetRoot({
dataRoot: input.dataRoot,
expectedSha256: createHash("sha256").update(trustedBytes).digest("hex"),
manifestRelativePath: "manifest.json",
root: assetRoot,
rootRef,
});
if (!validatedRoot.ok) {
return unavailable(true, validatedRoot.reason === "asset_root_missing" ? "asset_root_missing" : "asset_manifest_invalid", checkedAt);
}
return {
publicAssets: createPublicAssetResolver({ entries, roots: [validatedRoot] }),
state: { checked_at: checkedAt, configured: true, pause_reason: null, status: "active" },
};
} catch {
return unavailable(true, "asset_manifest_invalid", checkedAt);
}
}
+14 -6
View File
@@ -1,5 +1,7 @@
import { createConnection } from "node:net";
import { MockAmapAdapter, RealAmapAdapter } from "./amap-adapter.js";
const API_CREDENTIALS = ["Dada/P0A/api/resend", "Dada/P0A/api/amap", "Dada/P0A/admin/pepper"] as const;
export async function receiveApiCredentials(input: NodeJS.ReadableStream = process.stdin) {
@@ -13,7 +15,7 @@ export async function receiveApiCredentials(input: NodeJS.ReadableStream = proce
if (names.length !== expected.length || names.some((name, index) => name !== expected[index])) {
throw new Error("API credential channel contains an unexpected credential scope.");
}
if (expected.some((name) => typeof parsed[name] !== "string" || parsed[name] === "")) {
if (expected.some((name) => typeof parsed[name] !== "string")) {
throw new Error("API credential channel contains an invalid credential value.");
}
return parsed as Record<(typeof API_CREDENTIALS)[number], string>;
@@ -25,11 +27,17 @@ export async function receiveApiCredentials(input: NodeJS.ReadableStream = proce
}
export function initializeApiCredentialClients(credentials: Record<(typeof API_CREDENTIALS)[number], string>) {
const configured = API_CREDENTIALS.every((name) => credentials[name].length > 0);
const adminPepperValue = credentials["Dada/P0A/admin/pepper"];
for (const name of API_CREDENTIALS) credentials[name] = "";
if (!configured) throw new Error("API credential client initialization failed.");
return { adminAllowlistPepper: Buffer.from(adminPepperValue, "utf8") };
try {
const adminPepper = credentials["Dada/P0A/admin/pepper"];
if (!adminPepper) throw new Error("admin_pepper_not_configured");
return {
adminAllowlistPepper: Buffer.from(adminPepper, "utf8"),
amap: credentials["Dada/P0A/api/amap"] ? new RealAmapAdapter(credentials["Dada/P0A/api/amap"]) : new MockAmapAdapter(),
resendConfigured: Boolean(credentials["Dada/P0A/api/resend"]),
};
} finally {
for (const name of API_CREDENTIALS) credentials[name] = "";
}
}
export function attachApiSupervisorControl(pipeName: string, shutdown: () => Promise<void>) {
+1 -1
View File
@@ -922,7 +922,7 @@ export type ReverseGeocodeRequest = {
export type ReverseGeocodeResponse = {
"formatted_value": string;
"service_mode": "mock";
"service_mode": "mock" | "real";
"status": "resolved";
};
+19
View File
@@ -124,6 +124,25 @@ button {
margin-inline: auto;
}
.auth-test-entry {
margin-bottom: 18px;
border-bottom: 1px solid #b4b4af;
padding-bottom: 18px;
}
.auth-test-entry .auth-primary {
margin-top: 0;
border-color: #111111;
background: #111111;
color: #f2f500;
}
.auth-test-entry .auth-primary:disabled {
border-color: #777773;
background: #deded9;
color: #777773;
}
.auth-tabs {
display: grid;
grid-template-columns: 1fr 1fr;
+44
View File
@@ -77,6 +77,9 @@ export function UserAuthPage() {
const [sendState, setSendState] = useState<SendState>("idle");
const [countdown, setCountdown] = useState(0);
const [error, setError] = useState<string>();
const [localTestAvailable, setLocalTestAvailable] = useState(false);
const [localTestError, setLocalTestError] = useState<string>();
const [localTestSubmitting, setLocalTestSubmitting] = useState(false);
const [submitting, setSubmitting] = useState(false);
const emailValid = /^[^@\s]+@[^@\s]+$/.test(email);
const registrationReady = Boolean(
@@ -93,6 +96,18 @@ export function UserAuthPage() {
return () => window.clearInterval(timer);
}, [countdown]);
useEffect(() => {
const controller = new AbortController();
void fetch("/api/v1/auth/local-test", { credentials: "same-origin", signal: controller.signal })
.then(async (response) => {
if (!response.ok || !response.headers.get("content-type")?.includes("application/json")) return;
const body = await response.json() as { available?: boolean };
if (body.available === true) setLocalTestAvailable(true);
})
.catch(() => undefined);
return () => controller.abort();
}, []);
useEffect(() => {
if (!noticeOpen) return;
const previousOverflow = document.body.style.overflow;
@@ -255,6 +270,27 @@ export function UserAuthPage() {
}
}
async function enterLocalTest() {
if (localTestSubmitting) return;
setLocalTestSubmitting(true);
setLocalTestError(undefined);
try {
const response = await fetch("/api/v1/auth/local-test", {
credentials: "same-origin",
method: "POST",
});
if (!response.ok) {
setLocalTestError("本机测试会话未能建立,请重试。");
return;
}
window.location.assign("/app");
} catch {
setLocalTestError("本机测试会话未能建立,请重试。");
} finally {
setLocalTestSubmitting(false);
}
}
return (
<>
<main className="auth-page">
@@ -271,6 +307,14 @@ export function UserAuthPage() {
<section className="auth-content">
<a className="auth-admin-link" href="/admin/login"></a>
<div className="auth-panel">
{localTestAvailable ? (
<div className="auth-test-entry">
<button className="auth-primary" disabled={localTestSubmitting} onClick={enterLocalTest} type="button">
{localTestSubmitting ? "正在进入" : "直接进入本机测试"}
</button>
{localTestError ? <p className="auth-error" role="alert">{localTestError}</p> : null}
</div>
) : null}
<div className="auth-tabs" role="tablist" aria-label="认证方式">
<button
aria-selected={mode === "login"}
+1
View File
@@ -69,6 +69,7 @@ async function checkSupport() {
browserValue.textContent = `${result.browser.brand} ${result.browser.major}`;
supportedValue.textContent = supportedLabel(result.supported_browsers);
window.dispatchEvent(new CustomEvent("dada:support-ready"));
window.location.replace(window.location.pathname.startsWith("/admin") ? "/admin" : "/app");
return;
}
showBlocked(
+6
View File
@@ -7,6 +7,11 @@ export interface GenerationAdapterRequest {
prompt: string;
ratio: "3:4" | "1:1" | "4:3" | "9:16";
referenceAssetIds: readonly string[];
referenceImages?: readonly {
assetId: string;
bytes: Buffer;
mimeType: "image/jpeg" | "image/png" | "image/webp";
}[];
}
export interface NormalizedGenerationOutput {
@@ -27,6 +32,7 @@ export type GenerationAdapterResult =
};
export interface GenerationAdapter {
dispose?(): void;
start(request: GenerationAdapterRequest): Promise<GenerationAdapterResult>;
poll?(upstreamJobReference: string): Promise<GenerationAdapterResult>;
}
+47
View File
@@ -0,0 +1,47 @@
import type { GenerationAdapter } from "./ai-adapter-contract.js";
export type AiRuntimeProbeResult =
| {
code: "ai_probe_passed";
mime_type: "image/jpeg" | "image/png" | "image/webp";
pixel_height: number;
pixel_width: number;
real_calls: 1;
success: true;
}
| {
code: "ai_probe_failed";
error_category: string;
real_calls: 1;
success: false;
};
export async function runAiRuntimeProbe(adapter: GenerationAdapter): Promise<AiRuntimeProbeResult> {
const result = await adapter.start({
configSnapshot: { probe: true },
generationId: "00000000-0000-4000-8000-000000000002",
modelId: "gemini-3.1-flash-image-preview",
prompt: "生成一张简洁的红蓝几何色块测试图,不含文字。",
ratio: "1:1",
referenceAssetIds: [],
});
if (result.status === "failed") {
return { code: "ai_probe_failed", error_category: result.category, real_calls: 1, success: false };
}
if (result.status !== "completed" || result.outputs.length !== 1) {
return { code: "ai_probe_failed", error_category: "gateway_contract_invalid", real_calls: 1, success: false };
}
const output = result.outputs[0]!;
try {
return {
code: "ai_probe_passed",
mime_type: output.mimeType,
pixel_height: output.pixelHeight,
pixel_width: output.pixelWidth,
real_calls: 1,
success: true,
};
} finally {
output.bytes.fill(0);
}
}
@@ -0,0 +1,35 @@
export interface GenerationPollingProcessor {
processNext(): Promise<unknown>;
}
export class GenerationPollingLoop {
private closed = false;
private inFlight = false;
private readonly timer: ReturnType<typeof setInterval>;
constructor(
private readonly processor: GenerationPollingProcessor,
intervalMilliseconds = 250,
) {
if (!Number.isSafeInteger(intervalMilliseconds) || intervalMilliseconds <= 0) {
throw new Error("generation_polling_interval_invalid");
}
this.timer = setInterval(() => this.run(), intervalMilliseconds);
}
close() {
if (this.closed) return;
this.closed = true;
clearInterval(this.timer);
}
private run() {
if (this.closed || this.inFlight) return;
this.inFlight = true;
void this.processor.processNext()
.catch(() => undefined)
.finally(() => {
this.inFlight = false;
});
}
}
+38 -4
View File
@@ -1,11 +1,11 @@
import { createHash, randomUUID } from "node:crypto";
import { existsSync, mkdirSync, renameSync, rmSync, writeFileSync } from "node:fs";
import { dirname, join, resolve } from "node:path";
import { existsSync, mkdirSync, readFileSync, renameSync, rmSync, statSync, writeFileSync } from "node:fs";
import { dirname, isAbsolute, join, relative, resolve, sep } from "node:path";
import Database from "better-sqlite3";
import type BetterSqlite3 from "better-sqlite3";
import type { GenerationAdapter, GenerationAdapterResult, NormalizedGenerationOutput } from "./ai-adapter-contract.js";
import type { GenerationAdapter, GenerationAdapterRequest, GenerationAdapterResult, NormalizedGenerationOutput } from "./ai-adapter-contract.js";
import { GatewayBalanceRuntime } from "./gateway-balance-runtime.js";
import { generationErrorRegistry, type GenerationErrorCategory } from "./generation-error-registry.js";
import { configureWorkerDatabase } from "./sqlite-connection.js";
@@ -91,7 +91,8 @@ export class GenerationProcessor {
this.clock = input.clock ?? Date.now;
this.dataRoot = resolve(input.dataRoot);
this.workerId = input.workerId;
this.database = new Database(input.databasePath);
const nativeBinding = process.env.DADA_SQLITE_NATIVE_BINDING;
this.database = new Database(input.databasePath, nativeBinding ? { nativeBinding } : undefined);
configureWorkerDatabase(this.database);
this.migrate();
this.gatewayBalance = new GatewayBalanceRuntime({ clock: this.clock, database: this.database });
@@ -119,6 +120,7 @@ export class GenerationProcessor {
.run("worker_stopped", now, this.workerId);
});
this.gatewayBalance.close();
this.adapter.dispose?.();
this.database.close();
}
@@ -143,6 +145,12 @@ export class GenerationProcessor {
SELECT managed_file_id FROM generation_reference_snapshots WHERE generation_id = ? ORDER BY position
`).all(generationId) as Array<{ managed_file_id: string }>;
let adapterResult: GenerationAdapterResult;
let referenceImages: NonNullable<GenerationAdapterRequest["referenceImages"]>;
try {
referenceImages = this.loadReferenceImages(references.map((row) => row.managed_file_id));
} catch {
return this.completeFailure(job, "reference_invalid", "reference_load_failed");
}
try {
if (job.upstream_job_reference) {
if (!this.adapter.poll) return this.completeFailure(job, "unknown_retryable", "poll_unsupported", undefined, false, "pending_manual_review");
@@ -155,10 +163,13 @@ export class GenerationProcessor {
prompt: job.prompt,
ratio: job.ratio,
referenceAssetIds: references.map((row) => row.managed_file_id),
referenceImages,
}));
}
} catch {
return this.completeFailure(job, "unknown_retryable", "adapter_exception", undefined, false, "pending_manual_review");
} finally {
for (const reference of referenceImages) reference.bytes.fill(0);
}
if (adapterResult.status === "failed") return this.completeFailure(job, adapterResult.category, adapterResult.sourceCategory, adapterResult.balanceSignal);
@@ -174,6 +185,29 @@ export class GenerationProcessor {
}
}
private loadReferenceImages(referenceAssetIds: string[]): NonNullable<GenerationAdapterRequest["referenceImages"]> {
return referenceAssetIds.map((assetId) => {
const row = this.database.prepare(`
SELECT relative_path, mime_type FROM managed_files
WHERE file_id = ? AND file_kind = 'reference' AND status = 'committed'
`).get(assetId) as { mime_type: string; relative_path: string } | undefined;
if (!row || !["image/jpeg", "image/png", "image/webp"].includes(row.mime_type) || isAbsolute(row.relative_path)) {
throw new Error("reference_invalid");
}
const path = resolve(this.dataRoot, row.relative_path);
const child = relative(this.dataRoot, path);
if (!child || child === ".." || child.startsWith(`..${sep}`) || isAbsolute(child)
|| !existsSync(path) || !statSync(path).isFile()) {
throw new Error("reference_invalid");
}
return {
assetId,
bytes: readFileSync(path),
mimeType: row.mime_type as "image/jpeg" | "image/png" | "image/webp",
};
});
}
private claim(generationId: string) {
return this.immediate(() => {
const row = this.readJob(generationId);
@@ -0,0 +1,221 @@
import sharp from "sharp";
import type {
GenerationAdapter,
GenerationAdapterRequest,
GenerationAdapterResult,
NormalizedGenerationOutput,
} from "./ai-adapter-contract.js";
import { gptImageRequestSizeForRatio, normalizeImageOutputToRatio } from "./image-output-normalizer.mjs";
const geminiProductModelId = "gemini-3.1-flash-image-preview";
const geminiProviderModelId = "gemini-3.1-flash-image";
const gptImageModelId = "gpt-image-2";
const geminiEndpoint = "https://oneapi.intelligrow.cn/v1/chat/completions";
const gptImageEndpoint = "https://oneapi.intelligrow.cn/v1/images/generations";
const gptImageReferenceEndpoint = "https://oneapi.intelligrow.cn/v1/images/edits";
const maximumResponseBytes = 32 * 1024 * 1024;
const requestTimeoutMilliseconds = 180_000;
const geminiImageSystemInstruction = "Generate exactly one image from the user's description. Return the generated image and do not answer with text only.";
type FetchLike = typeof fetch;
class OneApiRuntimeError extends Error {
constructor(
readonly category: "gateway_balance_insufficient" | "gateway_contract_invalid" | "model_disabled" | "reference_invalid" | "upstream_failed" | "upstream_timeout" | "unknown_non_retryable",
readonly sourceCategory: string,
) {
super(sourceCategory);
}
}
function failure(error: unknown): GenerationAdapterResult {
if (error instanceof OneApiRuntimeError) {
return { category: error.category, sourceCategory: error.sourceCategory, status: "failed" };
}
if (error instanceof Error && error.name === "AbortError") {
return { category: "upstream_timeout", sourceCategory: "upstream_timeout", status: "failed" };
}
return { category: "upstream_failed", sourceCategory: "upstream_failed", status: "failed" };
}
function mapHttpFailure(status: number) {
if (status === 408 || status === 504) return new OneApiRuntimeError("upstream_timeout", `upstream_http_${status}`);
if (status === 429) return new OneApiRuntimeError("gateway_balance_insufficient", "upstream_http_429");
if (status >= 500) return new OneApiRuntimeError("upstream_failed", `upstream_http_${status}`);
if (status === 400 || status === 404 || status === 422) return new OneApiRuntimeError("gateway_contract_invalid", `upstream_http_${status}`);
return new OneApiRuntimeError("unknown_non_retryable", `upstream_http_${status}`);
}
async function readBoundedJson(response: Response) {
const declaredLength = Number(response.headers.get("content-length") ?? 0);
if (Number.isFinite(declaredLength) && declaredLength > maximumResponseBytes) {
throw new OneApiRuntimeError("gateway_contract_invalid", "upstream_response_too_large");
}
if (!response.body) throw new OneApiRuntimeError("gateway_contract_invalid", "upstream_response_empty");
const reader = response.body.getReader();
const chunks: Buffer[] = [];
let total = 0;
try {
while (true) {
const next = await reader.read();
if (next.done) break;
const chunk = Buffer.from(next.value);
total += chunk.length;
if (total > maximumResponseBytes) {
await reader.cancel();
throw new OneApiRuntimeError("gateway_contract_invalid", "upstream_response_too_large");
}
chunks.push(chunk);
}
try {
return JSON.parse(Buffer.concat(chunks).toString("utf8")) as unknown;
} catch {
throw new OneApiRuntimeError("gateway_contract_invalid", "upstream_response_invalid");
}
} finally {
for (const chunk of chunks) chunk.fill(0);
}
}
function extractGeminiImage(response: unknown) {
if (!response || typeof response !== "object" || !("choices" in response) || !Array.isArray(response.choices)) {
throw new OneApiRuntimeError("gateway_contract_invalid", "response_shape_invalid");
}
const choice = response.choices[0];
const content = choice && typeof choice === "object" && "message" in choice && choice.message && typeof choice.message === "object"
&& "content" in choice.message && typeof choice.message.content === "string" ? choice.message.content : "";
const matches = [...content.matchAll(/!\[[^\]]*\]\(\s*data:(image\/(?:jpeg|png|webp));base64,([A-Za-z0-9+/=\r\n]+)\s*\)/gi)];
if (matches.length !== 1) throw new OneApiRuntimeError("gateway_contract_invalid", "response_single_image_required");
return { bytes: Buffer.from(matches[0]![2]!, "base64"), declaredMimeType: matches[0]![1]!.toLowerCase() };
}
function extractGptImage(response: unknown) {
if (!response || typeof response !== "object" || !("data" in response) || !Array.isArray(response.data)
|| response.data.length !== 1 || !response.data[0] || typeof response.data[0] !== "object"
|| !("b64_json" in response.data[0]) || typeof response.data[0].b64_json !== "string") {
throw new OneApiRuntimeError("gateway_contract_invalid", "response_single_image_required");
}
return { bytes: Buffer.from(response.data[0].b64_json, "base64"), declaredMimeType: undefined };
}
async function normalizeOutput(bytes: Buffer, declaredMimeType: string | undefined, ratio: GenerationAdapterRequest["ratio"]): Promise<NormalizedGenerationOutput> {
try {
const metadata = await sharp(bytes, { failOn: "error", limitInputPixels: 40_000_000 }).metadata();
const mimeType = metadata.format === "png" ? "image/png" : metadata.format === "jpeg" ? "image/jpeg" : metadata.format === "webp" ? "image/webp" : undefined;
if (!mimeType || !metadata.width || !metadata.height || (declaredMimeType && declaredMimeType !== mimeType)) {
throw new OneApiRuntimeError("gateway_contract_invalid", "response_media_invalid");
}
const normalized = await normalizeImageOutputToRatio({ bytes, mimeType, pixelHeight: metadata.height, pixelWidth: metadata.width, ratio });
return { bytes: normalized.bytes, mimeType: normalized.mimeType, pixelHeight: normalized.pixelHeight, pixelWidth: normalized.pixelWidth };
} catch (error) {
if (error instanceof OneApiRuntimeError) throw error;
throw new OneApiRuntimeError("gateway_contract_invalid", "response_media_invalid");
}
}
function validateRequest(request: GenerationAdapterRequest) {
if (!request.prompt.trim() || request.prompt.length > 1_000) throw new OneApiRuntimeError("gateway_contract_invalid", "prompt_invalid");
const references = request.referenceImages ?? [];
if (references.length !== request.referenceAssetIds.length || references.length > 2) {
throw new OneApiRuntimeError("reference_invalid", "reference_count_invalid");
}
const totalBytes = references.reduce((total, reference) => total + reference.bytes.length, 0);
if (totalBytes > 20 * 1024 * 1024 || references.some((reference) => reference.bytes.length === 0 || reference.bytes.length > 10 * 1024 * 1024)) {
throw new OneApiRuntimeError("reference_invalid", "reference_size_invalid");
}
return references;
}
function buildRequest(request: GenerationAdapterRequest) {
const references = validateRequest(request);
if (request.modelId === geminiProductModelId) {
const content = references.length === 0
? request.prompt
: [
{ text: request.prompt, type: "text" },
...references.map((reference) => ({
image_url: { url: `data:${reference.mimeType};base64,${reference.bytes.toString("base64")}` },
type: "image_url",
})),
];
return {
body: JSON.stringify({
extra_body: { google: { image_config: { aspect_ratio: request.ratio, image_size: "1K" } } },
messages: [
{ content: geminiImageSystemInstruction, role: "system" },
{ content, role: "user" },
],
model: geminiProviderModelId,
stream: false,
}),
contentType: "application/json",
endpoint: geminiEndpoint,
parser: extractGeminiImage,
};
}
if (request.modelId !== gptImageModelId) throw new OneApiRuntimeError("model_disabled", "model_not_supported");
if (references.length > 0) {
const form = new FormData();
form.append("model", gptImageModelId);
form.append("prompt", request.prompt);
form.append("response_format", "b64_json");
form.append("size", gptImageRequestSizeForRatio(request.ratio));
references.forEach((reference, index) => form.append("image[]", new Blob([reference.bytes], { type: reference.mimeType }), `reference-${index + 1}.png`));
return { body: form, contentType: undefined, endpoint: gptImageReferenceEndpoint, parser: extractGptImage };
}
return {
body: JSON.stringify({ model: gptImageModelId, prompt: request.prompt, response_format: "b64_json", size: gptImageRequestSizeForRatio(request.ratio) }),
contentType: "application/json",
endpoint: gptImageEndpoint,
parser: extractGptImage,
};
}
export class OneApiGenerationAdapter implements GenerationAdapter {
private readonly credential: Buffer;
private readonly fetchImpl: FetchLike;
private disposed = false;
constructor(input: { credential: Buffer; fetch?: FetchLike }) {
if (input.credential.length < 8) throw new Error("ai_gateway_credential_invalid");
this.credential = Buffer.from(input.credential);
this.fetchImpl = input.fetch ?? fetch;
}
async start(request: GenerationAdapterRequest): Promise<GenerationAdapterResult> {
if (this.disposed) return { category: "upstream_failed", sourceCategory: "adapter_disposed", status: "failed" };
const controller = new AbortController();
const timeout = setTimeout(() => controller.abort(), requestTimeoutMilliseconds);
let sourceBytes: Buffer | undefined;
try {
const providerRequest = buildRequest(request);
const headers = new Headers({ authorization: `Bearer ${this.credential.toString("utf8")}` });
if (providerRequest.contentType) headers.set("content-type", providerRequest.contentType);
const response = await this.fetchImpl(providerRequest.endpoint, {
body: providerRequest.body,
headers,
method: "POST",
redirect: "error",
signal: controller.signal,
});
if (!response.ok) throw mapHttpFailure(response.status);
const parsed = await readBoundedJson(response);
const extracted = providerRequest.parser(parsed);
sourceBytes = extracted.bytes;
const output = await normalizeOutput(sourceBytes, extracted.declaredMimeType, request.ratio);
return { outputs: [output], status: "completed" };
} catch (error) {
return failure(error);
} finally {
clearTimeout(timeout);
sourceBytes?.fill(0);
}
}
dispose() {
if (this.disposed) return;
this.disposed = true;
this.credential.fill(0);
}
}
+8 -4
View File
@@ -13,7 +13,7 @@ export async function receiveWorkerCredentials(input: NodeJS.ReadableStream = pr
if (names.length !== expected.length || names.some((name, index) => name !== expected[index])) {
throw new Error("Worker credential channel contains an unexpected credential scope.");
}
if (expected.some((name) => typeof parsed[name] !== "string" || parsed[name] === "")) {
if (expected.some((name) => typeof parsed[name] !== "string")) {
throw new Error("Worker credential channel contains an invalid credential value.");
}
return parsed as Record<(typeof WORKER_CREDENTIALS)[number], string>;
@@ -25,9 +25,13 @@ export async function receiveWorkerCredentials(input: NodeJS.ReadableStream = pr
}
export function initializeWorkerCredentialClient(credentials: Record<(typeof WORKER_CREDENTIALS)[number], string>) {
const configured = WORKER_CREDENTIALS.every((name) => credentials[name].length > 0);
for (const name of WORKER_CREDENTIALS) credentials[name] = "";
if (!configured) throw new Error("Worker credential client initialization failed.");
const value = credentials["Dada/P0A/worker/ai-gateway"];
try {
if (!value) throw new Error("worker_ai_gateway_not_configured");
return { aiGatewayCredential: Buffer.from(value, "utf8") };
} finally {
for (const name of WORKER_CREDENTIALS) credentials[name] = "";
}
}
export function attachWorkerSupervisorControl(pipeName: string, shutdown: () => Promise<void> | void) {
+37 -2
View File
@@ -2,6 +2,10 @@ import { parentPort } from "node:worker_threads";
import { join } from "node:path";
import { WorkerAiCallGate } from "./ai-call-gate.js";
import { runAiRuntimeProbe } from "./ai-runtime-probe.js";
import { GenerationPollingLoop } from "./generation-polling-loop.js";
import { GenerationProcessor } from "./generation-processor.js";
import { OneApiGenerationAdapter } from "./oneapi-generation-adapter.js";
import { readConfiguredLocalDataRoot } from "./runtime-config.js";
import { RetentionCleanup } from "./retention-cleanup.js";
import { ProjectPurgeCleanup } from "./project-purge-cleanup.js";
@@ -21,8 +25,25 @@ if (workerPort) {
});
}
if (!workerPort && process.argv.includes("--dada-credential-stdin")) {
initializeWorkerCredentialClient(await receiveWorkerCredentials());
if (!workerPort && process.argv.includes("--dada-ai-probe")) {
const credentialClient = initializeWorkerCredentialClient(await receiveWorkerCredentials());
let adapter: OneApiGenerationAdapter | undefined;
let probeResult: Awaited<ReturnType<typeof runAiRuntimeProbe>> | { code: "ai_probe_failed"; error_category: "upstream_failed"; real_calls: 0; success: false };
try {
adapter = new OneApiGenerationAdapter({ credential: credentialClient.aiGatewayCredential });
probeResult = await runAiRuntimeProbe(adapter);
} catch {
probeResult = { code: "ai_probe_failed", error_category: "upstream_failed", real_calls: 0, success: false };
} finally {
credentialClient.aiGatewayCredential.fill(0);
adapter?.dispose();
}
await new Promise<void>((resolveWrite, rejectWrite) => {
process.stdout.write(JSON.stringify(probeResult), (error) => error ? rejectWrite(error) : resolveWrite());
});
process.exit(probeResult.success ? 0 : 2);
} else if (!workerPort && process.argv.includes("--dada-credential-stdin")) {
const credentialClient = initializeWorkerCredentialClient(await receiveWorkerCredentials());
const controlPipeIndex = process.argv.indexOf("--dada-control-pipe");
const controlPipe = process.argv[controlPipeIndex + 1];
if (controlPipeIndex < 0 || !controlPipe) throw new Error("Supervisor control pipe name is required.");
@@ -31,11 +52,15 @@ if (!workerPort && process.argv.includes("--dada-credential-stdin")) {
let retention: RetentionCleanup | undefined;
let projectCleanup: ProjectPurgeCleanup | undefined;
let retentionTimer: ReturnType<typeof setInterval> | undefined;
let processor: GenerationProcessor | undefined;
let generationLoop: GenerationPollingLoop | undefined;
const control = attachWorkerSupervisorControl(controlPipe, () => {
clearInterval(keepAlive);
if (retentionTimer) clearInterval(retentionTimer);
retention?.close();
projectCleanup?.close();
generationLoop?.close();
processor?.close();
storage?.close();
});
let storageStatus: "active" | "unavailable" = "active";
@@ -45,6 +70,13 @@ if (!workerPort && process.argv.includes("--dada-credential-stdin")) {
storage = new WorkerStorageStatus(databasePath);
retention = new RetentionCleanup({ databasePath });
projectCleanup = new ProjectPurgeCleanup({ dataRoot, databasePath });
let adapter: OneApiGenerationAdapter;
try {
adapter = new OneApiGenerationAdapter({ credential: credentialClient.aiGatewayCredential });
} finally {
credentialClient.aiGatewayCredential.fill(0);
}
processor = new GenerationProcessor({ adapter, dataRoot, databasePath, workerId: `portable-oneapi-worker-${process.pid}` });
const runRetentionCleanup = () => {
try {
retention?.purgeExpired();
@@ -71,8 +103,11 @@ if (!workerPort && process.argv.includes("--dada-credential-stdin")) {
});
logger.write({ error_category: "none", status_category: "ready" });
new WorkerAiCallGate({ getStorageStatus: () => storageStatus === "unavailable" ? storageStatus : (storage?.getStatus() ?? "unavailable"), logger });
generationLoop = new GenerationPollingLoop(processor);
} catch {
storageStatus = "unavailable";
control.reportStatus("storage_unavailable");
clearInterval(keepAlive);
setTimeout(() => process.exit(1), 50);
}
}
File diff suppressed because it is too large Load Diff
+14 -4
View File
@@ -5621,10 +5621,20 @@
"type": "string"
},
"service_mode": {
"enum": [
"mock"
],
"type": "string"
"anyOf": [
{
"enum": [
"mock"
],
"type": "string"
},
{
"enum": [
"real"
],
"type": "string"
}
]
},
"status": {
"enum": [
+12 -1
View File
@@ -21,6 +21,8 @@
"test:security": "node scripts/verify-frozen-dependencies.mjs && node scripts/redaction-scan.mjs",
"test:package": "pnpm build:workspace-packages && pnpm run typecheck && node --test tests/package/wp0-09-portable.test.mjs && node scripts/package-smoke.mjs && node scripts/loopback-boundary-smoke.mjs",
"package:portable": "node scripts/build-portable.mjs",
"assets:manifest": "pnpm build:workspace-packages && node scripts/generate-runtime-asset-manifest.mjs",
"assets:deploy": "pnpm build:workspace-packages && node scripts/deploy-runtime-assets.mjs",
"generate:openapi": "node scripts/generate-openapi.mjs",
"check:openapi": "node scripts/check-openapi.mjs",
"validate:tdd-trace": "node scripts/validate-tdd-trace.mjs",
@@ -109,7 +111,16 @@
"review:wp7-01": "node scripts/record-wp7-01-manual-review.mjs",
"test:wp7-02": "node scripts/run-wp7-02-validation.mjs",
"test:wp7-02:controlled": "node scripts/run-wp7-02-validation.mjs --controlled-real",
"review:wp7-02": "node scripts/record-wp7-02-manual-review.mjs"
"review:wp7-02": "node scripts/record-wp7-02-manual-review.mjs",
"test:wp7-03": "node scripts/run-wp7-03-validation.mjs --phase green",
"test:wp7-03:red": "node scripts/run-wp7-03-validation.mjs --phase red",
"test:wp7-04": "node scripts/run-wp7-04-validation.mjs",
"test:wp7-05": "node scripts/run-wp7-05-validation.mjs",
"test:wp7-05:unit": "node --test tests/package/wp7-05-ui-gate.test.mjs tests/package/wp7-05-coverage.test.mjs",
"test:wp7-06": "node scripts/run-wp7-06-validation.mjs",
"test:wp7-06:unit": "node --test tests/package/wp7-06-prefreeze.test.mjs",
"test:wp7-07": "node scripts/run-wp7-07-validation.mjs",
"test:wp7-07:unit": "node --test tests/package/wp7-07-final-release.test.mjs"
},
"devDependencies": {
"@playwright/test": "1.62.0",
+7 -1
View File
@@ -228,7 +228,13 @@ function readCsv(tracker: SourceTracker, path: string, label: string): CsvRow[]
function itemDirectoryFor(collection: CollectionConfig, catalogPath: string, row: CsvRow): { directory: string; metadataPath: string } {
if (collection.id === "font_panel") {
const resourceDir = requireString(row.resource_dir, "font resource_dir");
const configuredResourceDir = requireString(row.resource_dir, "font resource_dir");
const normalizedResourceDir = configuredResourceDir.replaceAll("\\", "/");
const relocationMarker = "/resources/font_packages/";
const markerIndex = normalizedResourceDir.lastIndexOf(relocationMarker);
const resourceDir = isAbsolute(configuredResourceDir) && !inside(configuredResourceDir, collection.root.path) && markerIndex >= 0
? relativeReference(normalizedResourceDir.slice(markerIndex + 1), "font resource_dir relocation")
: configuredResourceDir;
const directory = resolveSourcePath(resourceDir, collection.root.path, collection.root.path, "font resource_dir");
return { directory, metadataPath: resolveSourcePath("metadata.json", directory, collection.root.path, "font metadata") };
}
+1 -1
View File
@@ -7,7 +7,7 @@ export const ReverseGeocodeRequestSchema = Type.Object({
export const ReverseGeocodeResponseSchema = Type.Object({
formatted_value: Type.String({ maxLength: 200, minLength: 1 }),
service_mode: Type.Literal("mock"),
service_mode: Type.Union([Type.Literal("mock"), Type.Literal("real")]),
status: Type.Literal("resolved"),
}, { additionalProperties: false, $id: "ReverseGeocodeResponse" });
+21
View File
@@ -23,6 +23,27 @@ export const P0A_DYNAMIC_STICKER_IDS = [
"DYN008", "DYN011", "DYN012", "DYN015", "DYN016",
] as const;
export const P0A_DYNAMIC_RUNTIME_FONT_SOURCES = [
{ assetId: "15974853bc3294ef68e7e6d58fe74fd7", sourceReference: "fonts/15974853bc3294ef68e7e6d58fe74fd7", templateId: "DYN002" },
{ assetId: "46f8336813e4c48d06a1aef294fdccf6", sourceReference: "fonts/46f8336813e4c48d06a1aef294fdccf6", templateId: "DYN016" },
{ assetId: "53ca6b704728520da50c145eabb2e635", sourceReference: "fonts/53ca6b704728520da50c145eabb2e635", templateId: "DYN007" },
{ assetId: "cca5efc0e02fb1bf62349bd68ef30fc1", sourceReference: "fonts/cca5efc0e02fb1bf62349bd68ef30fc1", templateId: "DYN015" },
{ assetId: "dd25b35dcb7ba4476cbaa9a9592e39e2", sourceReference: "fonts/dd25b35dcb7ba4476cbaa9a9592e39e2", templateId: "DYN001" },
{ assetId: "e4210c9872f0c279b35273f230809821", sourceReference: "fonts/e4210c9872f0c279b35273f230809821", templateId: "DYN011" },
{ assetId: "f4bfd4132df2d6be97ceabadf3853505", sourceReference: "fonts/f4bfd4132df2d6be97ceabadf3853505", templateId: "DYN008" },
] as const;
export const P0A_DYNAMIC_RUNTIME_IMAGE_SOURCES = [
{ assetId: "DYN001-image28", sourceReference: "resource/image28.png", templateId: "DYN001" },
{ assetId: "DYN002-image29", sourceReference: "resource/image29.png", templateId: "DYN002" },
{ assetId: "DYN003-image30", sourceReference: "resource/image30.png", templateId: "DYN003" },
{ assetId: "DYN004-image32", sourceReference: "resource/image32.png", templateId: "DYN004" },
{ assetId: "DYN008-backendui0", sourceReference: "resource/backendui0.png", templateId: "DYN008" },
{ assetId: "DYN011-backendui0", sourceReference: "resource/backendui0.png", templateId: "DYN011" },
{ assetId: "DYN015-imager2", sourceReference: "resource/imager2_2.png", templateId: "DYN015" },
{ assetId: "DYN016-image21", sourceReference: "resource/image21.png", templateId: "DYN016" },
] as const;
export type RegisteredComplexFamily = "color_card" | "font_panel" | "interactive_sticker" | "text_template";
export interface RegisteredComplexAsset extends Record<string, unknown> {
+11 -1
View File
@@ -1,10 +1,20 @@
import { execFileSync } from "node:child_process";
import { readFileSync } from "node:fs";
import { resolve } from "node:path";
import { buildAndValidatePortablePackage } from "./lib/portable-package.mjs";
import { validateFinalReleaseRecord } from "./lib/wp7-07-final-release.mjs";
const outputIndex = process.argv.indexOf("--output");
const outputRoot = outputIndex >= 0 ? resolve(process.argv[outputIndex + 1]) : resolve(".build", "portable-release");
const result = await buildAndValidatePortablePackage({ outputRoot });
const previousRelease = JSON.parse(readFileSync(resolve("RELEASE.json"), "utf8"));
const releaseRecord = validateFinalReleaseRecord({
...previousRelease,
buildCommit: execFileSync("git", ["rev-parse", "HEAD"], { encoding: "utf8" }).trim(),
maintenanceFromCommit: previousRelease.buildCommit,
recordedAt: new Date().toISOString(),
});
const result = await buildAndValidatePortablePackage({ outputRoot, releaseRecord });
console.log(JSON.stringify({
package: result.packageManifest.package_name,
sha256: result.packageManifest.zip_sha256,
+25 -5
View File
@@ -1,7 +1,7 @@
import { createHash } from "node:crypto";
import { existsSync, mkdirSync, readFileSync, writeFileSync } from "node:fs";
import { copyFileSync, existsSync, mkdirSync, readFileSync, writeFileSync } from "node:fs";
import { homedir } from "node:os";
import { join, resolve } from "node:path";
import { dirname, join, resolve } from "node:path";
import { compileAssetArchive, compileStaticStickerCatalog } from "../packages/asset-compiler/dist/index.js";
import { createP0aColorCardRenderPlans } from "../packages/asset-renderer/dist/index.js";
@@ -18,18 +18,38 @@ import {
const runDirectory = resolve(process.env.DADA_WP5_03_RUN_DIRECTORY ?? "artifacts/tdd/wp5-03-local");
const whiteDirectory = resolve(process.env.DADA_WP5_03_WHITE_EVIDENCE_DIR ?? join(runDirectory, "cases", "TDD-WP5-WHITE-001-p0a-allowlist"));
const colorDirectory = resolve(process.env.DADA_WP5_03_COLOR_EVIDENCE_DIR ?? join(runDirectory, "cases", "TDD-WP5-COL-001-four-layouts"));
const handoffManifest = resolve(process.env.DADA_COMPLEX_ASSET_MANIFEST ?? join(homedir(), "Desktop", "sticker_web_handoff", "sticker_web_catalog_manifest.json"));
const stickerRoot = resolve(process.env.DADA_STATIC_STICKER_ROOT ?? join(homedir(), "Desktop", "贴纸素材"));
const replicationRoot = resolve(process.env.DADA_REPLICATION_ASSET_ROOT ?? join(homedir(), "Desktop", "sticker_web_replication_assets"));
const handoffManifest = resolve(process.env.DADA_COMPLEX_ASSET_MANIFEST ?? join(replicationRoot, "sticker_web_handoff", "sticker_web_catalog_manifest.json"));
const stickerRoot = resolve(process.env.DADA_STATIC_STICKER_ROOT ?? join(replicationRoot, "sticker_normal"));
if (!existsSync(handoffManifest)) throw new Error("normalized complex asset handoff is unavailable");
if (!existsSync(stickerRoot)) throw new Error("static sticker source is unavailable");
const complexDirectory = resolve(runDirectory, "inputs", "complex");
const staticDirectory = resolve(runDirectory, "inputs", "static");
const normalizedHandoffDirectory = resolve(runDirectory, "inputs", "normalized-handoff");
mkdirSync(whiteDirectory, { recursive: true });
mkdirSync(colorDirectory, { recursive: true });
const sourceHandoff = JSON.parse(readFileSync(handoffManifest, "utf8"));
const normalizedHandoff = {
...sourceHandoff,
web_handoff: "STICKER_WEB_REPLICATION_HANDOFF.md",
validation: "sticker_archive_validation_20260722.json",
collections: sourceHandoff.collections
.filter((collection) => collection.id !== "normal_stickers")
.map((collection) => ({
...collection,
root: resolve(dirname(handoffManifest), collection.root),
})),
};
const normalizedHandoffPath = resolve(normalizedHandoffDirectory, "sticker_web_catalog_manifest.normalized.json");
mkdirSync(normalizedHandoffDirectory, { recursive: true });
copyFileSync(resolve(dirname(handoffManifest), sourceHandoff.web_handoff), resolve(normalizedHandoffDirectory, normalizedHandoff.web_handoff));
copyFileSync(resolve(dirname(handoffManifest), sourceHandoff.validation), resolve(normalizedHandoffDirectory, normalizedHandoff.validation));
writeFileSync(normalizedHandoffPath, `${JSON.stringify(normalizedHandoff, null, 2)}\n`);
const complex = compileAssetArchive({
manifestPath: handoffManifest,
manifestPath: normalizedHandoffPath,
outputDirectory: complexDirectory,
releaseVersion: P0A_COMPLEX_RELEASE_VERSION,
});
+37
View File
@@ -0,0 +1,37 @@
import { readFileSync } from "node:fs";
import { isAbsolute, join, resolve } from "node:path";
import {
buildP0aRuntimeAssetPlan,
defaultReplicationRoot,
deployRuntimeAssetPlan,
readRuntimeAssetManifest,
serializeRuntimeAssetManifest,
} from "./lib/runtime-assets.mjs";
function option(name) {
const index = process.argv.indexOf(name);
return index >= 0 ? process.argv[index + 1] : undefined;
}
function defaultConfigPath() {
if (!process.env.LOCALAPPDATA || !isAbsolute(process.env.LOCALAPPDATA)) throw new Error("local_app_data_unavailable");
return join(process.env.LOCALAPPDATA, "Dada", "P0A", "config", "instance.json");
}
const configFile = resolve(option("--config") ?? process.env.DADA_INSTANCE_CONFIG_PATH ?? defaultConfigPath());
const configuration = JSON.parse(readFileSync(configFile, "utf8"));
const assetRootCandidate = option("--asset-root") ?? configuration.asset_root;
if (typeof assetRootCandidate !== "string" || !isAbsolute(assetRootCandidate)) {
throw new Error("asset_root_configuration_invalid");
}
const assetRoot = resolve(assetRootCandidate);
const trustedManifest = readRuntimeAssetManifest(resolve(option("--trusted-manifest") ?? "config/runtime-assets-manifest.json"));
const plan = await buildP0aRuntimeAssetPlan({
replicationRoot: resolve(option("--replication-root") ?? defaultReplicationRoot()),
});
if (serializeRuntimeAssetManifest(plan.manifest) !== serializeRuntimeAssetManifest(trustedManifest)) {
throw new Error("runtime_asset_source_does_not_match_trusted_manifest");
}
const result = deployRuntimeAssetPlan({ assetRoot, manifest: trustedManifest, resources: plan.resources });
process.stdout.write(`${JSON.stringify({ linked_files: result.linked_files, status: result.status })}\n`);
@@ -0,0 +1,23 @@
import { resolve } from "node:path";
import {
buildP0aRuntimeAssetPlan,
defaultReplicationRoot,
serializeRuntimeAssetManifest,
writeRuntimeAssetManifest,
} from "./lib/runtime-assets.mjs";
function option(name) {
const index = process.argv.indexOf(name);
return index >= 0 ? process.argv[index + 1] : undefined;
}
const replicationRoot = resolve(option("--replication-root") ?? defaultReplicationRoot());
const outputPath = resolve(option("--output") ?? "config/runtime-assets-manifest.json");
const plan = await buildP0aRuntimeAssetPlan({ replicationRoot });
writeRuntimeAssetManifest(outputPath, plan.manifest);
process.stdout.write(`${JSON.stringify({
counts: plan.manifest.counts,
manifest_bytes: Buffer.byteLength(serializeRuntimeAssetManifest(plan.manifest)),
status: "generated",
})}\n`);
+52 -16
View File
@@ -18,6 +18,7 @@ import { tmpdir } from "node:os";
import { basename, dirname, join, relative, resolve, sep } from "node:path";
import { frozenRuntime } from "../frozen-versions.mjs";
import { readRuntimeAssetManifest } from "./runtime-assets.mjs";
const repositoryRoot = resolve(import.meta.dirname, "..", "..");
const fixedPort = 43121;
@@ -165,7 +166,7 @@ function copyApplication(source, destination, runtimeDependencies) {
function buildArtifacts(stagingRoot) {
debug("build workspace artifacts");
run("pnpm", ["--filter", "@dada/shared-contracts", "build"]);
run("pnpm", ["build:workspace-packages"]);
run("pnpm", ["--filter", "@dada/web", "build"]);
run("pnpm", ["--filter", "@dada/api", "build"]);
run("pnpm", ["--filter", "@dada/worker", "build"]);
@@ -208,7 +209,7 @@ async function waitForHealth(child) {
throw new Error("Packaged API did not become healthy on fixed port 43121.", { cause: lastError });
}
async function verifyExtractedPackage(zipPath, packageName) {
export async function verifyExtractedPackage(zipPath, packageName, expectedSupport) {
const extractRoot = mkdtempSync(join(tmpdir(), "dada-wp0-09-"));
try {
const escapedZip = zipPath.replaceAll("'", "''");
@@ -235,21 +236,37 @@ async function verifyExtractedPackage(zipPath, packageName) {
});
try {
const health = await waitForHealth(api);
const brands = [
{ brand: "Not_A Brand", version: "99" },
{ brand: "Chromium", version: String(expectedSupport.major) },
{ brand: expectedSupport.brand, version: String(expectedSupport.major) },
];
const fullVersionList = [
{ brand: "Not_A Brand", version: "99.0.0.0" },
{ brand: "Chromium", version: expectedSupport.fullVersion },
{ brand: expectedSupport.brand, version: expectedSupport.fullVersion },
];
const serializeBrands = (values) => values.map(({ brand, version }) => `"${brand}";v="${version}"`).join(", ");
const releaseGate = await fetch(`http://127.0.0.1:${fixedPort}/api/v1/support/check`, {
body: JSON.stringify({
brands: [{ brand: "Google Chrome", version: "150" }],
full_version_list: [{ brand: "Google Chrome", version: "150.0.0.0" }],
brands,
full_version_list: fullVersionList,
platform: "Windows",
}),
headers: {
"content-type": "application/json",
"sec-ch-ua": '"Google Chrome";v="150"',
"sec-ch-ua-full-version-list": '"Google Chrome";v="150.0.0.0"',
host: `127.0.0.1:${fixedPort}`,
origin: `http://127.0.0.1:${fixedPort}`,
"sec-ch-ua": serializeBrands(brands),
"sec-ch-ua-full-version-list": serializeBrands(fullVersionList),
"sec-ch-ua-platform": '"Windows"',
},
method: "POST",
});
if (releaseGate.status !== 426) throw new Error(`Candidate RELEASE.json unexpectedly passed with ${releaseGate.status}.`);
if (releaseGate.status !== expectedSupport.statusCode) {
const responseBody = await releaseGate.text();
throw new Error(`Packaged RELEASE.json support gate returned ${releaseGate.status}; expected ${expectedSupport.statusCode}: ${responseBody}`);
}
return {
api: { executable: "runtime/node.exe", health, pid: api.pid, release_gate: { status_code: releaseGate.status }, status: "passed" },
native,
@@ -291,7 +308,7 @@ function scanPackage(packageDirectory) {
return { disallowed_matches: disallowedMatches, reparse_points: reparsePoints, scanned_files: files.length, status: disallowedMatches.length === 0 && reparsePoints.length === 0 ? "passed" : "failed" };
}
export async function buildAndValidatePortablePackage({ evidenceDirectory, outputRoot }) {
export async function buildAndValidatePortablePackage({ evidenceDirectory, outputRoot, releaseRecord }) {
if (process.platform !== frozenRuntime.os || process.arch !== frozenRuntime.arch || process.version.slice(1) !== frozenRuntime.node) {
throw new Error("Portable package build requires frozen Node 24.13.0 on win-x64.");
}
@@ -320,7 +337,7 @@ export async function buildAndValidatePortablePackage({ evidenceDirectory, outpu
debug("copy API application");
const apiDependencies = copyApplication(join(repositoryRoot, "apps", "api"), join(serverRoot, "api"), ["@fastify/multipart", "@fastify/swagger", "@sinclair/typebox", "better-sqlite3", "fastify", "sharp"]);
debug("copy Worker application");
const workerDependencies = copyApplication(join(repositoryRoot, "apps", "worker"), join(serverRoot, "worker"), ["better-sqlite3"]);
const workerDependencies = copyApplication(join(repositoryRoot, "apps", "worker"), join(serverRoot, "worker"), ["better-sqlite3", "sharp"]);
const sharedDestination = join(serverRoot, "api", "node_modules", "@dada", "shared-contracts");
mkdirSync(sharedDestination, { recursive: true });
copyTree(join(repositoryRoot, "packages", "shared-contracts", "dist"), join(sharedDestination, "dist"));
@@ -347,11 +364,15 @@ export async function buildAndValidatePortablePackage({ evidenceDirectory, outpu
copyTree(join(repositoryRoot, "apps", "web", "dist"), join(packageDirectory, "web"));
copyTree(join(repositoryRoot, "apps", "web", "support-gate"), join(packageDirectory, "web", "support-gate"));
writeJson(join(packageDirectory, "migrations", "manifest.json"), { migrations: [], schema_version: "0" });
writeJson(join(packageDirectory, "asset-metadata", "manifest.json"), { resources: [], schema_version: "1.0", source: "external_read_only" });
writeJson(
join(packageDirectory, "asset-metadata", "manifest.json"),
readRuntimeAssetManifest(join(repositoryRoot, "config", "runtime-assets-manifest.json")),
);
writeJson(join(packageDirectory, "LICENSES", "third-party.json"), { api: apiDependencies, runtime: { node: frozenRuntime.node }, schema_version: "1.0", worker: workerDependencies });
const commit = run("git", ["rev-parse", "HEAD"]);
writeJson(join(packageDirectory, "RELEASE.json"), {
const finalRelease = releaseRecord !== undefined;
writeJson(join(packageDirectory, "RELEASE.json"), releaseRecord ?? {
app_version: appVersion,
browsers: [],
build_commit: commit,
@@ -360,16 +381,20 @@ export async function buildAndValidatePortablePackage({ evidenceDirectory, outpu
windows_build: null,
});
writeFileSync(join(packageDirectory, "START-HERE.txt"), [
"Dada P0-A candidate package",
finalRelease ? "Dada P0-A first-version portable package" : "Dada P0-A candidate package",
"",
"This candidate is unsigned and is not a final P0-A release.",
finalRelease
? "This unsigned first-version package passed the local P0-A release gates recorded in RELEASE.json."
: "This candidate is unsigned and is not a final P0-A release.",
"Verify the adjacent SHA-256 file before first launch.",
"Windows SmartScreen may warn on first launch because the executable is unsigned.",
"For an antivirus alert, compare the package hash with the Gitea build record.",
"Do not disable antivirus protection, add broad exclusions, or skip hash verification.",
"To update, exit Dada from the tray and replace the complete program directory.",
"Dada uses 127.0.0.1:43121 and does not support LAN or remote access.",
"A final RELEASE.json is created only after WP-7 acceptance.",
finalRelease
? "Resend and Amap real-provider validation remain explicitly deferred and are not recorded as passed."
: "A final RELEASE.json is created only after WP-7 acceptance.",
"",
].join("\r\n"));
@@ -381,7 +406,18 @@ export async function buildAndValidatePortablePackage({ evidenceDirectory, outpu
const zipSha256 = fileSha256(zipPath);
const shaPath = `${zipPath}.sha256`;
writeFileSync(shaPath, `${zipSha256} ${basename(zipPath)}\n`);
const processTree = await verifyExtractedPackage(zipPath, packageName);
const supportBrowser = finalRelease ? releaseRecord.browsers[0] : undefined;
const processTree = await verifyExtractedPackage(zipPath, packageName, finalRelease ? {
brand: supportBrowser.brand,
fullVersion: supportBrowser.fullVersion,
major: Number.parseInt(supportBrowser.fullVersion.split(".")[0], 10),
statusCode: 200,
} : {
brand: "Google Chrome",
fullVersion: "150.0.0.0",
major: 150,
statusCode: 426,
});
const fileEntries = listFiles(packageDirectory).files.map((path) => ({
path: relative(packageDirectory, path).replaceAll("\\", "/"),
sha256: fileSha256(path),
@@ -392,7 +428,7 @@ export async function buildAndValidatePortablePackage({ evidenceDirectory, outpu
files: fileEntries,
fixed_port: fixedPort,
package_name: packageName,
release_status: "candidate_unvalidated",
release_status: finalRelease ? releaseRecord.releaseStatus : "candidate_unvalidated",
schema_version: "1.0",
zip_sha256: zipSha256,
};
+145
View File
@@ -0,0 +1,145 @@
import { createHash } from "node:crypto";
import { existsSync, readFileSync } from "node:fs";
import { validateReleaseCandidateRecord } from "./release-candidate.mjs";
export const RESEND_DAILY_LIMIT = 80;
export const RESEND_MONTHLY_LIMIT = 2_400;
export const DELIVERY_CATEGORIES = Object.freeze(["qq", "163", "enterprise"]);
export const DELIVERY_SAMPLE_SIZE = 20;
export const DELIVERY_MINIMUM_WITHIN_TWO_MINUTES = 19;
export const DELIVERY_WINDOW_SECONDS = 120;
export const EXPECTED_WP7_01_COMMIT = "623cad25b2a2a9a003502c9a92ebd318dad06248";
const emailPattern = /\b[A-Z0-9._%+-]+@[A-Z0-9.-]+\.[A-Z]{2,}\b/i;
const absolutePathPattern = /(?:[A-Z]:[\\/]|\\\\|\/Users\/|\/home\/)/i;
const sensitiveKeyPattern = /"(?:api[_ -]?key|secret|password|authorization|bearer|cookie|session[_ -]?token|verification[_ -]?code|private[_ -]?content|prompt|image)"\s*:/i;
function object(value) {
return value !== null && typeof value === "object" && !Array.isArray(value) ? value : undefined;
}
function errorList(...values) {
return [...new Set(values.flat().filter((value) => typeof value === "string" && value.length > 0))];
}
export function validateDomainCheck(value) {
const item = object(value);
const freeRules = object(item?.free_rules);
const spf = object(item?.spf);
const dkim = object(item?.dkim);
const errors = [];
if (item?.schema_version !== "1.0") errors.push("schema_version");
if (item?.service !== "resend") errors.push("service");
if (item?.source !== "human_controlled_real") errors.push("source");
if (item?.status !== "verified") errors.push("status");
if (item?.domain_controlled !== true) errors.push("domain_controlled");
if (spf?.status !== "pass") errors.push("spf");
if (dkim?.status !== "pass") errors.push("dkim");
if (freeRules?.status !== "verified") errors.push("free_rules.status");
if (freeRules?.daily_limit !== RESEND_DAILY_LIMIT) errors.push("free_rules.daily_limit");
if (freeRules?.monthly_limit !== RESEND_MONTHLY_LIMIT) errors.push("free_rules.monthly_limit");
if (freeRules?.paid_fallback_enabled !== false) errors.push("free_rules.paid_fallback_enabled");
return errorList(errors);
}
export function validateDeliverySummary(value) {
const item = object(value);
const errors = [];
if (item?.schema_version !== "1.0") errors.push("schema_version");
if (item?.service !== "resend") errors.push("service");
if (item?.source !== "human_controlled_real") errors.push("source");
if (item?.status !== "verified") errors.push("status");
if (!Array.isArray(item?.categories) || item.categories.length !== DELIVERY_CATEGORIES.length) {
errors.push("categories");
} else {
const categories = item.categories.map((entry) => entry?.category).sort();
if (categories.join("|") !== DELIVERY_CATEGORIES.slice().sort().join("|")) errors.push("categories.names");
for (const entry of item.categories) {
if (!Number.isInteger(entry?.sent_count) || entry.sent_count !== DELIVERY_SAMPLE_SIZE) errors.push(`${entry?.category ?? "unknown"}.sent_count`);
if (!Number.isInteger(entry?.delivered_within_120_seconds)
|| entry.delivered_within_120_seconds < DELIVERY_MINIMUM_WITHIN_TWO_MINUTES
|| entry.delivered_within_120_seconds > DELIVERY_SAMPLE_SIZE) {
errors.push(`${entry?.category ?? "unknown"}.delivered_within_120_seconds`);
}
if (!Number.isFinite(entry?.max_latency_seconds) || entry.max_latency_seconds > DELIVERY_WINDOW_SECONDS) errors.push(`${entry?.category ?? "unknown"}.max_latency_seconds`);
if (entry?.mock_used !== false) errors.push(`${entry?.category ?? "unknown"}.mock_used`);
if (entry?.preseeded_account_used !== false) errors.push(`${entry?.category ?? "unknown"}.preseeded_account_used`);
}
}
return errorList(errors);
}
export function validateAuthResult(value) {
const item = object(value);
const ordinary = object(item?.ordinary);
const admin = object(item?.admin);
const errors = [];
if (item?.schema_version !== "1.0") errors.push("schema_version");
if (item?.service !== "resend") errors.push("service");
if (item?.source !== "human_controlled_real") errors.push("source");
if (item?.status !== "verified") errors.push("status");
if (item?.mock_used !== false) errors.push("mock_used");
if (item?.preseeded_account_used !== false) errors.push("preseeded_account_used");
for (const [name, auth] of [["ordinary", ordinary], ["admin", admin]]) {
if (auth?.status !== "passed") errors.push(`${name}.status`);
if (auth?.chain !== "formal") errors.push(`${name}.chain`);
if (auth?.verification_code_source !== "real_delivery") errors.push(`${name}.verification_code_source`);
}
return errorList(errors);
}
export function validateRedaction(value, serializedEvidence = "") {
const item = object(value);
const errors = [];
if (item?.schema_version !== "1.0") errors.push("schema_version");
if (item?.status !== "passed") errors.push("status");
if (item?.forbidden_matches !== 0) errors.push("forbidden_matches");
if (item?.credentials_in_evidence !== false) errors.push("credentials_in_evidence");
if (item?.mailboxes_in_evidence !== false) errors.push("mailboxes_in_evidence");
if (item?.private_content_in_evidence !== false) errors.push("private_content_in_evidence");
if (item?.absolute_paths_in_evidence !== false) errors.push("absolute_paths_in_evidence");
if (emailPattern.test(serializedEvidence)) errors.push("email_value");
if (absolutePathPattern.test(serializedEvidence)) errors.push("absolute_path");
if (sensitiveKeyPattern.test(serializedEvidence)) errors.push("sensitive_value");
return errorList(errors);
}
export function validateCandidateReference(record) {
try {
validateReleaseCandidateRecord(record);
} catch (error) {
return [error instanceof Error ? "candidate_record_invalid" : "candidate_record_invalid"];
}
const errors = [];
if (record.build_commit !== EXPECTED_WP7_01_COMMIT) errors.push("candidate_build_commit");
const versions = new Map((record.browsers ?? []).map((browser) => [browser.brand, browser.full_version]));
if (versions.get("Google Chrome") !== "150.0.7871.187") errors.push("chrome_full_version");
if (versions.get("Microsoft Edge") !== "151.0.4129.59") errors.push("edge_full_version");
return errorList(errors);
}
export function readJson(path) {
if (!path || !existsSync(path)) return undefined;
try {
return JSON.parse(readFileSync(path, "utf8"));
} catch {
return undefined;
}
}
export function fileSha256(path) {
return createHash("sha256").update(readFileSync(path)).digest("hex").toUpperCase();
}
export function validateResendEvidence({ candidate, domainCheck, deliverySummary, authResult, redaction }) {
const serializedEvidence = JSON.stringify({ domainCheck, deliverySummary, authResult });
const errors = [
...validateCandidateReference(candidate),
...validateDomainCheck(domainCheck),
...validateDeliverySummary(deliverySummary),
...validateAuthResult(authResult),
...validateRedaction(redaction, serializedEvidence),
];
return errorList(errors);
}
+317
View File
@@ -0,0 +1,317 @@
import { createHash } from "node:crypto";
import {
existsSync,
linkSync,
lstatSync,
mkdirSync,
mkdtempSync,
readFileSync,
readdirSync,
realpathSync,
rmSync,
statSync,
writeFileSync,
} from "node:fs";
import { tmpdir } from "node:os";
import { basename, dirname, extname, isAbsolute, join, resolve, sep } from "node:path";
export const P0A_RUNTIME_ASSET_ROOT_REF = "p0a_runtime_assets";
export const RUNTIME_ASSET_MANIFEST_SCHEMA = "DadaRuntimeAssets/v1";
const assetIdPattern = /^[a-z0-9][a-z0-9_-]{2,119}$/i;
const mimePattern = /^[a-z0-9][a-z0-9.+-]*\/[a-z0-9][a-z0-9.+-]*$/i;
const releasePattern = /^[a-z0-9][a-z0-9._-]{0,79}$/i;
const shaPattern = /^[a-f0-9]{64}$/i;
const fontMimeTypes = new Map([
[".otf", "font/otf"],
[".ttf", "font/ttf"],
[".woff", "font/woff"],
[".woff2", "font/woff2"],
]);
function sha256(bytes) {
return createHash("sha256").update(bytes).digest("hex");
}
function fileSha256(path) {
return sha256(readFileSync(path));
}
function stableEntries(entries) {
return entries.map((entry) => {
if (!entry || typeof entry !== "object") throw new Error("runtime_asset_entry_invalid");
if (!assetIdPattern.test(entry.assetId)) throw new Error("runtime_asset_id_invalid");
if (!mimePattern.test(entry.mimeType)) throw new Error("runtime_asset_mime_invalid");
if (!releasePattern.test(entry.resourceVersion)) throw new Error("runtime_asset_version_invalid");
if (entry.rootRef !== P0A_RUNTIME_ASSET_ROOT_REF) throw new Error("runtime_asset_root_ref_invalid");
if (!shaPattern.test(entry.sha256)) throw new Error("runtime_asset_sha256_invalid");
if (
typeof entry.relativePath !== "string"
|| isAbsolute(entry.relativePath)
|| entry.relativePath.includes("\\")
|| entry.relativePath.split("/").some((part) => part === "" || part === "..")
) throw new Error("runtime_asset_relative_path_invalid");
return { ...entry, sha256: entry.sha256.toLowerCase() };
}).sort((left, right) => {
const byVersion = left.resourceVersion.localeCompare(right.resourceVersion);
return byVersion || left.assetId.localeCompare(right.assetId);
});
}
function derivedCounts(entries) {
return {
dynamic_fonts: entries.filter((entry) => entry.resourceVersion === "p0a-complex-v1" && /^[a-f0-9]{32}$/.test(entry.assetId)).length,
dynamic_images: entries.filter((entry) => entry.resourceVersion === "p0a-complex-v1" && /^DYN\d{3}-/.test(entry.assetId)).length,
font_panel_items: entries.filter((entry) => entry.resourceVersion === "p0a-complex-v1" && /^FONT\d{3}$/.test(entry.assetId)).length,
static_stickers: entries.filter((entry) => entry.resourceVersion === "p0a-static-v1" && /^STK\d{3,4}$/.test(entry.assetId)).length,
};
}
export function createRuntimeAssetManifest({ counts, entries, sourceManifestSha256 }) {
const normalizedEntries = stableEntries(entries);
const keys = new Set();
const paths = new Set();
for (const entry of normalizedEntries) {
const key = `${entry.resourceVersion}\u0000${entry.assetId}`;
if (keys.has(key)) throw new Error("runtime_asset_id_duplicate");
if (paths.has(entry.relativePath)) throw new Error("runtime_asset_path_duplicate");
keys.add(key);
paths.add(entry.relativePath);
}
const actualCounts = derivedCounts(normalizedEntries);
if (JSON.stringify(counts) !== JSON.stringify(actualCounts)) throw new Error("runtime_asset_counts_invalid");
if (sourceManifestSha256 !== undefined && !shaPattern.test(sourceManifestSha256)) {
throw new Error("runtime_asset_source_manifest_sha256_invalid");
}
return {
counts: actualCounts,
entries: normalizedEntries,
root_ref: P0A_RUNTIME_ASSET_ROOT_REF,
schema_version: RUNTIME_ASSET_MANIFEST_SCHEMA,
source: "external_read_only",
...(sourceManifestSha256 ? { source_manifest_sha256: sourceManifestSha256.toLowerCase() } : {}),
};
}
export function readRuntimeAssetManifest(path) {
const value = JSON.parse(readFileSync(path, "utf8"));
if (
value?.schema_version !== RUNTIME_ASSET_MANIFEST_SCHEMA
|| value?.source !== "external_read_only"
|| value?.root_ref !== P0A_RUNTIME_ASSET_ROOT_REF
|| !Array.isArray(value.entries)
) throw new Error("runtime_asset_manifest_invalid");
return createRuntimeAssetManifest({
counts: value.counts,
entries: value.entries,
...(value.source_manifest_sha256 ? { sourceManifestSha256: value.source_manifest_sha256 } : {}),
});
}
export function serializeRuntimeAssetManifest(manifest) {
return `${JSON.stringify(manifest, null, 2)}\n`;
}
export function writeRuntimeAssetManifest(path, manifest) {
mkdirSync(dirname(path), { recursive: true });
writeFileSync(path, serializeRuntimeAssetManifest(manifest));
}
function targetWithinRoot(root, relativePath) {
const absoluteRoot = resolve(root);
const target = resolve(absoluteRoot, ...relativePath.split("/"));
if (target === absoluteRoot || !target.startsWith(`${absoluteRoot}${sep}`)) throw new Error("asset_target_path_invalid");
return target;
}
function sameFile(left, right) {
const leftStat = statSync(left);
const rightStat = statSync(right);
return leftStat.dev === rightStat.dev && leftStat.ino === rightStat.ino;
}
export function deployRuntimeAssetPlan({ assetRoot, manifest, resources }) {
if (!isAbsolute(assetRoot)) throw new Error("asset_root_must_be_absolute");
const normalizedManifest = createRuntimeAssetManifest({
counts: manifest.counts,
entries: manifest.entries,
...(manifest.source_manifest_sha256 ? { sourceManifestSha256: manifest.source_manifest_sha256 } : {}),
});
const entries = new Map(normalizedManifest.entries.map((entry) => [`${entry.resourceVersion}\u0000${entry.assetId}`, entry]));
if (resources.length !== entries.size) throw new Error("asset_resource_plan_incomplete");
mkdirSync(assetRoot, { recursive: true });
for (const resource of resources) {
const key = `${resource.entry.resourceVersion}\u0000${resource.entry.assetId}`;
const entry = entries.get(key);
if (!entry || JSON.stringify(entry) !== JSON.stringify({ ...resource.entry, sha256: resource.entry.sha256.toLowerCase() })) {
throw new Error("asset_resource_plan_mismatch");
}
if (!existsSync(resource.sourcePath) || !statSync(resource.sourcePath).isFile() || lstatSync(resource.sourcePath).isSymbolicLink()) {
throw new Error("asset_source_invalid");
}
if (fileSha256(resource.sourcePath) !== entry.sha256) throw new Error("asset_source_hash_invalid");
const targetPath = targetWithinRoot(assetRoot, entry.relativePath);
mkdirSync(dirname(targetPath), { recursive: true });
if (existsSync(targetPath)) {
if (fileSha256(targetPath) !== entry.sha256) throw new Error("asset_target_conflict");
if (!sameFile(resource.sourcePath, targetPath)) throw new Error("asset_target_not_hardlink");
continue;
}
try {
linkSync(resource.sourcePath, targetPath);
} catch (error) {
if (error && typeof error === "object" && "code" in error && error.code === "EXDEV") {
throw new Error("asset_hardlink_volume_mismatch");
}
throw error;
}
if (!sameFile(resource.sourcePath, targetPath)) throw new Error("asset_hardlink_verification_failed");
}
writeRuntimeAssetManifest(join(assetRoot, "manifest.json"), normalizedManifest);
return { linked_files: resources.length, manifest: normalizedManifest, status: "ready" };
}
function oneDirectoryWithPrefix(root, prefix) {
const matches = readdirSync(root, { withFileTypes: true })
.filter((entry) => entry.isDirectory() && entry.name.startsWith(`${prefix}_`));
if (matches.length !== 1) throw new Error(`runtime_asset_source_directory_invalid:${prefix}`);
return join(root, matches[0].name);
}
function oneSupportedFont(root) {
const matches = readdirSync(root, { withFileTypes: true })
.filter((entry) => entry.isFile() && fontMimeTypes.has(extname(entry.name).toLowerCase()));
if (matches.length !== 1) throw new Error(`runtime_font_source_invalid:${basename(root)}`);
return join(root, matches[0].name);
}
function entryFor(sourcePath, assetId, resourceVersion, relativePath, mimeType) {
return {
assetId,
mimeType,
relativePath,
resourceVersion,
rootRef: P0A_RUNTIME_ASSET_ROOT_REF,
sha256: fileSha256(sourcePath),
};
}
function dynamicMetadata(templateRoot, descriptor, field) {
const templateDirectory = join(templateRoot, descriptor.templateId);
const metadata = JSON.parse(readFileSync(join(templateDirectory, "metadata.json"), "utf8"));
if (!Array.isArray(metadata?.files?.[field]) || !metadata.files[field].includes(descriptor.sourceReference)) {
throw new Error(`runtime_dynamic_reference_invalid:${descriptor.assetId}`);
}
return templateDirectory;
}
export async function buildP0aRuntimeAssetPlan({ replicationRoot }) {
const [{ compileStaticStickerCatalog }, registry] = await Promise.all([
import("../../packages/asset-compiler/dist/index.js"),
import("../../packages/template-registry/dist/index.js"),
]);
const compilerOutput = mkdtempSync(join(tmpdir(), "dada-runtime-asset-plan-"));
try {
const staticSourceRoot = join(replicationRoot, "sticker_normal");
const staticResult = compileStaticStickerCatalog({
outputDirectory: compilerOutput,
releaseVersion: registry.P0A_STATIC_STICKER_RELEASE_VERSION,
sourceRoot: staticSourceRoot,
});
const resources = staticResult.catalog.items.map((item) => {
const sourcePath = join(staticSourceRoot, ...item.relative_path.split("/"));
const entry = entryFor(
sourcePath,
item.stable_id,
registry.P0A_STATIC_STICKER_RELEASE_VERSION,
`${registry.P0A_STATIC_STICKER_RELEASE_VERSION}/${item.stable_id}.png`,
"image/png",
);
if (entry.sha256 !== item.sha256.toLowerCase()) throw new Error(`static_sticker_hash_invalid:${item.stable_id}`);
return { entry, sourcePath };
});
const fontPackagesRoot = join(
replicationRoot,
"sticker_text",
"字体",
"面板全量采集",
"font_panel_full_20260722",
"resources",
"font_packages",
);
for (const assetId of registry.P0A_REQUIRED_FONT_PANEL_IDS) {
const packageDirectory = oneDirectoryWithPrefix(fontPackagesRoot, assetId);
const sourcePath = oneSupportedFont(join(packageDirectory, "font_files"));
const extension = extname(sourcePath).toLowerCase();
resources.push({
entry: entryFor(
sourcePath,
assetId,
registry.P0A_COMPLEX_RELEASE_VERSION,
`${registry.P0A_COMPLEX_RELEASE_VERSION}/${assetId}${extension}`,
fontMimeTypes.get(extension),
),
sourcePath,
});
}
const templateRoot = join(replicationRoot, "sticker_interactive", "单模板归档", "templates");
for (const descriptor of registry.P0A_DYNAMIC_RUNTIME_FONT_SOURCES) {
const templateDirectory = dynamicMetadata(templateRoot, descriptor, "fonts");
const sourcePath = oneSupportedFont(join(templateDirectory, ...descriptor.sourceReference.split("/")));
const extension = extname(sourcePath).toLowerCase();
resources.push({
entry: entryFor(
sourcePath,
descriptor.assetId,
registry.P0A_COMPLEX_RELEASE_VERSION,
`${registry.P0A_COMPLEX_RELEASE_VERSION}/${descriptor.assetId}${extension}`,
fontMimeTypes.get(extension),
),
sourcePath,
});
}
for (const descriptor of registry.P0A_DYNAMIC_RUNTIME_IMAGE_SOURCES) {
const templateDirectory = dynamicMetadata(templateRoot, descriptor, "images");
const sourcePath = join(templateDirectory, ...descriptor.sourceReference.split("/"));
if (!existsSync(sourcePath) || extname(sourcePath).toLowerCase() !== ".png") {
throw new Error(`runtime_dynamic_image_invalid:${descriptor.assetId}`);
}
resources.push({
entry: entryFor(
sourcePath,
descriptor.assetId,
registry.P0A_COMPLEX_RELEASE_VERSION,
`${registry.P0A_COMPLEX_RELEASE_VERSION}/${descriptor.assetId}.png`,
"image/png",
),
sourcePath,
});
}
const manifestPath = join(replicationRoot, "sticker_web_handoff", "sticker_web_catalog_manifest.json");
const manifest = createRuntimeAssetManifest({
counts: {
dynamic_fonts: registry.P0A_DYNAMIC_RUNTIME_FONT_SOURCES.length,
dynamic_images: registry.P0A_DYNAMIC_RUNTIME_IMAGE_SOURCES.length,
font_panel_items: registry.P0A_REQUIRED_FONT_PANEL_IDS.length,
static_stickers: staticResult.catalog.count,
},
entries: resources.map((resource) => resource.entry),
sourceManifestSha256: fileSha256(manifestPath),
});
const resourcesByKey = new Map(resources.map((resource) => [`${resource.entry.resourceVersion}\u0000${resource.entry.assetId}`, resource]));
return {
manifest,
resources: manifest.entries.map((entry) => resourcesByKey.get(`${entry.resourceVersion}\u0000${entry.assetId}`)),
};
} finally {
rmSync(compilerOutput, { force: true, recursive: true });
}
}
export function defaultReplicationRoot(environment = process.env) {
if (!environment.USERPROFILE || !isAbsolute(environment.USERPROFILE)) throw new Error("user_profile_unavailable");
return join(environment.USERPROFILE, "Desktop", "sticker_web_replication_assets");
}
+45
View File
@@ -0,0 +1,45 @@
import path from 'node:path';
import { REQUIRED_COVERAGE_UNITS } from './wp7-05-ui-gate.mjs';
const ABSOLUTE_PATH = /^(?:[A-Za-z]:[\\/]|[\\/]{2}|\\\\)/;
function assertSafeRelative(value, field) {
if (typeof value !== 'string' || !value || ABSOLUTE_PATH.test(value) || path.isAbsolute(value)) {
throw new Error(`WP7_05_UNSAFE_${field}`);
}
const normalized = value.replaceAll('\\', '/');
if (normalized.split('/').includes('..')) throw new Error(`WP7_05_UNSAFE_${field}`);
return normalized;
}
export function buildCoverageEvidence({ runId, candidateSha256, coverageUnits, viewports }) {
if (!runId || !/^[A-Za-z0-9._-]+$/.test(runId)) throw new Error('WP7_05_INVALID_RUN_ID');
if (!/^[A-Fa-f0-9]{64}$/.test(candidateSha256 ?? '')) throw new Error('WP7_05_INVALID_CANDIDATE_HASH');
if (!Array.isArray(coverageUnits)) throw new Error('WP7_05_COVERAGE_UNITS_REQUIRED');
const byPage = new Map();
for (const unit of coverageUnits) {
if (!REQUIRED_COVERAGE_UNITS.includes(unit.page_id)) throw new Error('WP7_05_UNKNOWN_PAGE');
if (byPage.has(unit.page_id)) throw new Error('WP7_05_DUPLICATE_PAGE');
if (!Array.isArray(unit.states) || unit.states.length === 0) throw new Error('WP7_05_STATES_REQUIRED');
const states = unit.states.map((state) => ({
state: assertSafeRelative(state.state, 'STATE'),
screenshot_100pct: assertSafeRelative(state.screenshot_100pct, 'SCREENSHOT'),
screenshot_200pct: assertSafeRelative(state.screenshot_200pct, 'SCREENSHOT'),
trace: assertSafeRelative(state.trace, 'TRACE'),
}));
byPage.set(unit.page_id, { page_id: unit.page_id, states });
}
const missing = REQUIRED_COVERAGE_UNITS.filter((page) => !byPage.has(page));
if (missing.length) throw new Error(`WP7_05_MISSING_PAGES:${missing.join(',')}`);
if (!Array.isArray(viewports) || viewports.length !== 2) throw new Error('WP7_05_VIEWPORTS_REQUIRED');
return {
schema_version: '1.0',
task: 'TASK-WP7-05',
run_id: runId,
candidate_sha256: candidateSha256.toUpperCase(),
viewports,
coverage_units: REQUIRED_COVERAGE_UNITS.map((page) => byPage.get(page)),
};
}
+71
View File
@@ -0,0 +1,71 @@
import fs from 'node:fs';
export const REQUIRED_COVERAGE_UNITS = Object.freeze([
'support-gate', 'user-auth', 'workspace', 'current-task', 'projects',
'project-detail', 'editor', 'export', 'credits', 'settings',
'preview-user-variant', 'admin-auth', 'admin-overview', 'admin-users',
'admin-invites', 'admin-models', 'admin-assets', 'admin-preview',
'admin-generations', 'admin-services-storage', 'admin-audit', 'system-ui',
]);
const REQUIRED_VIEWPORTS = Object.freeze([
{ width: 1920, height: 1080, deviceScaleFactor: 1, zoom: 100 },
{ width: 1920, height: 1080, deviceScaleFactor: 1, zoom: 200 },
]);
function blocked(code, details = {}) {
return { status: 'externally_blocked', code, ...details };
}
export function loadCandidateRecord(path) {
if (!path || !fs.existsSync(path)) return blocked('candidate_record_missing');
try {
const record = JSON.parse(fs.readFileSync(path, 'utf8'));
if (!Array.isArray(record.browsers) || record.browsers.length !== 2) {
return blocked('candidate_browser_record_incomplete');
}
const brands = new Set(record.browsers.map((browser) => browser.brand));
if (brands.size !== 2 || !brands.has('Google Chrome') || !brands.has('Microsoft Edge')) {
return blocked('candidate_browser_pair_invalid');
}
if (record.windows?.build == null || !record.candidate_package?.sha256 || !record.candidate_package?.fixed_port) {
return blocked('candidate_identity_incomplete');
}
if (record.browsers.some((browser) => !browser.full_version || !browser.major)) {
return blocked('candidate_full_version_missing');
}
return { status: 'ready', record };
} catch {
return blocked('candidate_record_invalid');
}
}
export function validateCoverageEvidence(evidence) {
if (!evidence || !Array.isArray(evidence.coverage_units)) {
return blocked('coverage_evidence_missing');
}
const actual = new Set(evidence.coverage_units.map((unit) => unit.page_id));
const missing = REQUIRED_COVERAGE_UNITS.filter((unit) => !actual.has(unit));
if (missing.length) return blocked('coverage_units_incomplete', { missing });
const missingStates = evidence.coverage_units
.filter((unit) => REQUIRED_COVERAGE_UNITS.includes(unit.page_id))
.filter((unit) => !Array.isArray(unit.states) || unit.states.length === 0)
.map((unit) => unit.page_id);
if (missingStates.length) return blocked('coverage_states_incomplete', { missingStates });
const viewportKeys = new Set((evidence.viewports ?? []).map((viewport) => JSON.stringify(viewport)));
const missingViewports = REQUIRED_VIEWPORTS.filter((viewport) => !viewportKeys.has(JSON.stringify(viewport)));
if (missingViewports.length) return blocked('candidate_viewports_incomplete', { missingViewports });
return { status: 'ready' };
}
export function runWp705Gate({ candidatePath, evidence, dependencies = {} }) {
const candidate = loadCandidateRecord(candidatePath);
if (candidate.status !== 'ready') return candidate;
const coverage = validateCoverageEvidence(evidence);
if (coverage.status !== 'ready') return coverage;
const externalBlockers = Object.entries(dependencies)
.filter(([, status]) => status === 'externally_blocked')
.map(([task]) => task);
if (externalBlockers.length) return blocked('upstream_external_blocked', { externalBlockers });
return { status: 'ready_for_execution' };
}
+62
View File
@@ -0,0 +1,62 @@
const EXPECTED_TRACE_SUMMARY = Object.freeze({
acceptanceCriteria: 52,
errorCategories: 9,
featureModules: 13,
parentFamilies: 89,
penProductFrames: 18,
productContracts: 19,
requirements: 109,
tasks: 52,
testCases: 117,
uiPages: 22,
});
const REQUIRED_UPSTREAM = Object.freeze({
"TASK-WP7-01": "passed",
"TASK-WP7-02": "passed",
"TASK-WP7-03": "deferred_nonblocking_first_version",
"TASK-WP7-04": "deferred_nonblocking_first_version",
"TASK-WP7-05": "passed",
});
const shaPattern = /^[0-9a-f]{40}$/i;
export function buildWp706PrefreezeReport({ currentCommit, releaseExists, trace, upstream }) {
if (releaseExists) throw new Error("WP7_06_RELEASE_WRITTEN_PREMATURELY");
if (!shaPattern.test(currentCommit ?? "")) throw new Error("WP7_06_CURRENT_COMMIT_INVALID");
if (trace?.status !== "passed" || !Array.isArray(trace?.errors) || trace.errors.length > 0) {
throw new Error("WP7_06_TRACE_VALIDATION_FAILED");
}
for (const [key, expected] of Object.entries(EXPECTED_TRACE_SUMMARY)) {
if (trace.summary?.[key] !== expected) throw new Error(`WP7_06_TRACE_COUNT_MISMATCH:${key}`);
}
for (const [taskId, expectedStatus] of Object.entries(REQUIRED_UPSTREAM)) {
const item = upstream?.[taskId];
if (!item || !shaPattern.test(item.head ?? "")) throw new Error(`WP7_06_UPSTREAM_HEAD_INVALID:${taskId}`);
if (item.merged !== true) throw new Error(`WP7_06_UPSTREAM_NOT_MERGED:${taskId}`);
if (item.status !== expectedStatus) throw new Error(`WP7_06_UNSUPPORTED_STATUS:${taskId}`);
}
return {
schema_version: "1.0",
task_id: "TASK-WP7-06",
status: "passed",
current_commit: currentCommit.toLowerCase(),
release_json_written: false,
trace_summary: { ...EXPECTED_TRACE_SUMMARY },
upstream: Object.fromEntries(Object.entries(REQUIRED_UPSTREAM).map(([taskId]) => [taskId, {
branch: upstream[taskId].branch,
head: upstream[taskId].head.toLowerCase(),
merged: true,
status: upstream[taskId].status,
}])),
deferred_external_tasks: Object.entries(REQUIRED_UPSTREAM)
.filter(([, status]) => status === "deferred_nonblocking_first_version")
.map(([taskId]) => taskId),
final_release_allowed: false,
next_task: "TASK-WP7-07",
};
}
export { EXPECTED_TRACE_SUMMARY, REQUIRED_UPSTREAM };
+96
View File
@@ -0,0 +1,96 @@
import { createHash } from "node:crypto";
import { readFileSync, readdirSync, statSync } from "node:fs";
import { extname, join, relative } from "node:path";
const SHA40 = /^[a-f0-9]{40}$/i;
const SHA64 = /^[a-f0-9]{64}$/i;
const VERSION = /^[1-9][0-9]*\.[0-9]+\.[0-9]+\.[0-9]+$/;
const ABSOLUTE_PATH = /(?:[A-Za-z]:[\\/](?:Users|Documents)[\\/][^\\/"'\s]+[\\/]|\/Users\/[^/"'\s]+\/|\/home\/[^/"'\s]+\/)/;
const CREDENTIAL = /\b(?:sk|key)-[A-Za-z0-9_-]{16,}\b|-----BEGIN (?:RSA |EC |OPENSSH )?PRIVATE KEY-----/i;
const TEXT_EXTENSIONS = new Set([".cjs", ".cs", ".css", ".html", ".js", ".json", ".mjs", ".ts", ".tsx", ".txt", ".xml", ".yaml", ".yml"]);
export const DEFERRED_EXTERNAL_TASKS = Object.freeze(["TASK-WP7-03", "TASK-WP7-04"]);
export function buildFinalReleaseRecord({ appVersion, browsers, buildCommit, frozenFromCommit, recordedAt, windows }) {
const record = {
appVersion,
browsers: browsers.map(({ brand, fullVersion }) => ({ brand, fullVersion })),
buildCommit: buildCommit.toLowerCase(),
deferredExternalTasks: [...DEFERRED_EXTERNAL_TASKS],
finalRelease: true,
fixedPort: 43121,
frozenFromCommit: frozenFromCommit.toLowerCase(),
recordedAt,
releaseStatus: "first_version_internal",
schemaVersion: "1.0",
windows: { arch: windows.arch, build: windows.build, displayVersion: windows.displayVersion },
};
return validateFinalReleaseRecord(record);
}
export function validateFinalReleaseRecord(record) {
const errors = [];
if (record?.schemaVersion !== "1.0") errors.push("schemaVersion");
if (record?.releaseStatus !== "first_version_internal") errors.push("releaseStatus");
if (record?.finalRelease !== true) errors.push("finalRelease");
if (record?.fixedPort !== 43121) errors.push("fixedPort");
if (!SHA40.test(record?.buildCommit ?? "")) errors.push("buildCommit");
if (!SHA40.test(record?.frozenFromCommit ?? "")) errors.push("frozenFromCommit");
if (!Number.isFinite(Date.parse(record?.recordedAt ?? ""))) errors.push("recordedAt");
if (!Array.isArray(record?.deferredExternalTasks) || record.deferredExternalTasks.join("|") !== DEFERRED_EXTERNAL_TASKS.join("|")) errors.push("deferredExternalTasks");
if (record?.windows?.arch !== "x64" || !/^\d+\.\d+$/.test(record?.windows?.build ?? "")) errors.push("windows");
if (!Array.isArray(record?.browsers) || record.browsers.length !== 2) {
errors.push("browsers");
} else {
const brands = record.browsers.map(({ brand }) => brand).sort();
if (brands.join("|") !== "Google Chrome|Microsoft Edge") errors.push("browserBrands");
for (const browser of record.browsers) {
if (!VERSION.test(browser.fullVersion ?? "")) errors.push(`${browser.brand}.fullVersion`);
if ("path" in browser || "executablePath" in browser || "executableSha256" in browser) errors.push(`${browser.brand}.privateMetadata`);
}
}
const serialized = JSON.stringify(record);
if (ABSOLUTE_PATH.test(serialized) || CREDENTIAL.test(serialized)) errors.push("sensitiveValue");
if (errors.length > 0) throw new Error(`WP7_07_RELEASE_INVALID:${[...new Set(errors)].join(",")}`);
return record;
}
export function sha256File(path) {
return createHash("sha256").update(readFileSync(path)).digest("hex").toUpperCase();
}
export function scanReleaseFiles({ roots, allowedFixturePaths = [] }) {
const allowed = new Set(allowedFixturePaths.map((value) => value.replaceAll("\\", "/")));
const findings = [];
let scannedFiles = 0;
function visit(root, current = root) {
for (const entry of readdirSync(current, { withFileTypes: true })) {
if ([".git", ".pnpm-store", "node_modules", "bin", "obj"].includes(entry.name)) continue;
const path = join(current, entry.name);
if (entry.isDirectory()) {
visit(root, path);
continue;
}
if (!entry.isFile()) continue;
scannedFiles += 1;
if (!TEXT_EXTENSIONS.has(extname(entry.name).toLowerCase())) continue;
const logicalPath = relative(root, path).replaceAll("\\", "/");
const content = readFileSync(path, "utf8");
if (!allowed.has(logicalPath) && ABSOLUTE_PATH.test(content)) findings.push({ path: logicalPath, rule: "absolute_user_path" });
if (!allowed.has(logicalPath) && CREDENTIAL.test(content)) findings.push({ path: logicalPath, rule: "credential_shape" });
}
}
for (const root of roots) {
if (!statSync(root).isDirectory()) throw new Error(`WP7_07_SCAN_ROOT_INVALID:${root}`);
visit(root);
}
return { findings, scanned_files: scannedFiles, status: findings.length === 0 ? "passed" : "failed" };
}
export function validateFinalEvidence({ packageManifest, release, releaseSha256, scan }) {
validateFinalReleaseRecord(release);
if (!SHA64.test(releaseSha256 ?? "")) throw new Error("WP7_07_RELEASE_HASH_INVALID");
if (packageManifest?.release_status !== release.releaseStatus || !SHA64.test(packageManifest?.zip_sha256 ?? "")) throw new Error("WP7_07_PACKAGE_MANIFEST_INVALID");
if (scan?.status !== "passed" || scan.findings?.length !== 0) throw new Error("WP7_07_LEAK_SCAN_FAILED");
return { release_sha256: releaseSha256.toUpperCase(), status: "passed", zip_sha256: packageManifest.zip_sha256.toUpperCase() };
}
+175
View File
@@ -0,0 +1,175 @@
import { spawnSync } from "node:child_process";
import { createHash } from "node:crypto";
import { existsSync, mkdirSync, readFileSync, writeFileSync } from "node:fs";
import { join, resolve } from "node:path";
import {
fileSha256,
readJson,
validateCandidateReference,
validateResendEvidence,
} from "./lib/resend-release-gate.mjs";
const phaseIndex = process.argv.indexOf("--phase");
const phase = phaseIndex >= 0 ? process.argv[phaseIndex + 1] : "green";
if (!new Set(["red", "green"]).has(phase)) throw new Error(`Unsupported phase: ${phase}`);
const candidateRunId = process.env.DADA_WP7_01_RUN_ID ?? "wp7-01-candidate-20260804052447717";
const runId = process.env.DADA_TDD_RUN_ID ?? `wp7-03-${phase}-${new Date().toISOString().replace(/[^0-9]/g, "")}`;
const runDirectory = resolve("artifacts", "tdd", runId);
const caseId = "TDD-WP7-EXT-002-real-resend";
const caseDirectory = resolve(runDirectory, "cases", caseId);
if (existsSync(runDirectory)) throw new Error(`Evidence run already exists: ${runId}`);
mkdirSync(caseDirectory, { recursive: true });
function writeJson(path, value) {
writeFileSync(path, `${JSON.stringify(value, null, 2)}\n`);
}
function runCommand(name, command) {
const startedAt = new Date().toISOString();
const result = spawnSync(process.env.ComSpec ?? "cmd.exe", ["/d", "/s", "/c", command], {
encoding: "utf8",
env: process.env,
maxBuffer: 40 * 1024 * 1024,
stdio: "inherit",
});
return {
command,
exit_code: result.status ?? 1,
finished_at: new Date().toISOString(),
name,
started_at: startedAt,
};
}
const candidateEvidenceRoot = resolve(
process.env.DADA_WP7_01_EVIDENCE_DIR ?? join("artifacts", "tdd", candidateRunId),
);
const candidate = readJson(join(candidateEvidenceRoot, "release-candidate.json"));
const candidateErrors = candidate ? validateCandidateReference(candidate) : ["candidate_record_missing"];
writeJson(resolve(caseDirectory, "candidate-reference.json"), candidate ? {
browsers: candidate.browsers.map(({ brand, full_version: fullVersion, major }) => ({ brand, full_version: fullVersion, major })),
build_commit: candidate.build_commit,
candidate_status: candidate.status,
final_release: candidate.final_release,
fixed_port: candidate.fixed_port,
run_id: candidateRunId,
schema_version: "1.0",
} : {
candidate_status: "not_available",
reason: "candidate_record_missing",
run_id: candidateRunId,
schema_version: "1.0",
});
const commands = phase === "red" ? [] : [
["workspace-build", "pnpm build:workspace-packages"],
["integration", "pnpm test:integration"],
["api", "pnpm check:openapi && pnpm exec vitest run tests/api --maxWorkers=1"],
["security", "pnpm test:security"],
["tdd-trace", "pnpm validate:tdd-trace"],
].map(([name, command]) => runCommand(name, command));
const localGatePassed = phase === "red" || commands.length > 0 && commands.every(({ exit_code }) => exit_code === 0);
const redaction = {
absolute_paths_in_evidence: false,
credentials_in_evidence: false,
forbidden_matches: 0,
mailboxes_in_evidence: false,
private_content_in_evidence: false,
schema_version: "1.0",
status: "passed",
};
const externalRoot = process.env.DADA_RESEND_EVIDENCE_DIR ? resolve(process.env.DADA_RESEND_EVIDENCE_DIR) : undefined;
const realAuthorized = process.env.DADA_RESEND_REAL_AUTHORIZED === "1";
const externalFiles = ["domain-check.json", "delivery-summary.json", "auth-result.json", "redaction.json"];
const externalEvidence = externalRoot
? Object.fromEntries(externalFiles.map((file) => [file, readJson(join(externalRoot, file))]))
: {};
const externalEvidenceMissing = externalRoot ? externalFiles.filter((file) => !externalEvidence[file]) : externalFiles;
const externalErrors = externalRoot && externalEvidenceMissing.length === 0 && candidate
? validateResendEvidence({
authResult: externalEvidence["auth-result.json"],
candidate,
deliverySummary: externalEvidence["delivery-summary.json"],
domainCheck: externalEvidence["domain-check.json"],
redaction: externalEvidence["redaction.json"],
})
: [];
const externalBlockers = [];
if (candidateErrors.length > 0) externalBlockers.push("candidate_record_unavailable_or_drifted");
if (!realAuthorized) externalBlockers.push("controlled_domain_or_real_mailbox_authorization_absent");
if (!externalRoot) externalBlockers.push("real_resend_evidence_not_supplied");
if (externalRoot && externalEvidenceMissing.length > 0) externalBlockers.push("real_resend_evidence_incomplete");
if (externalErrors.length > 0) externalBlockers.push("real_resend_evidence_invalid");
if (phase === "red") {
writeJson(resolve(caseDirectory, "red-observation.json"), {
expected_failure: "Resend SPF/DKIM, free-rule, delivery, and formal authentication evidence is absent before TASK-WP7-03.",
observed_commands: ["pnpm test:wp7-03:red"],
red_reason: "TDD-WP7-EXT-002 requires controlled real domain/mailbox evidence; mock or pre-seeded accounts are not release evidence.",
status: "red_confirmed",
});
} else if (externalRoot && externalEvidenceMissing.length === 0 && candidateErrors.length === 0 && realAuthorized && externalErrors.length === 0) {
for (const file of externalFiles) writeJson(resolve(caseDirectory, file), externalEvidence[file]);
writeJson(resolve(caseDirectory, "source-hashes.json"), {
files: Object.fromEntries(externalFiles.map((file) => [file, fileSha256(join(externalRoot, file))])),
schema_version: "1.0",
});
} else {
writeJson(resolve(caseDirectory, "blocker.json"), {
blockers: externalErrors.length > 0 ? ["real_resend_evidence_invalid"] : externalBlockers,
mock_accepted_as_evidence: false,
paid_fallback_enabled: false,
preseeded_accounts_accepted_as_evidence: false,
real_calls_started: false,
schema_version: "1.0",
status: "externally_blocked",
});
writeJson(resolve(caseDirectory, "redaction.json"), redaction);
writeJson(resolve(caseDirectory, "source-hashes.json"), { files: {}, schema_version: "1.0" });
}
const expectedEvidence = phase === "red"
? ["candidate-reference.json", "red-observation.json"]
: externalRoot && externalEvidenceMissing.length === 0 && candidateErrors.length === 0 && realAuthorized && externalErrors.length === 0
? ["candidate-reference.json", "domain-check.json", "delivery-summary.json", "auth-result.json", "redaction.json", "source-hashes.json"]
: ["candidate-reference.json", "blocker.json", "redaction.json", "source-hashes.json"];
const missingEvidence = expectedEvidence.filter((file) => !existsSync(resolve(caseDirectory, file)));
const status = phase === "red"
? localGatePassed && missingEvidence.length === 0 ? "red_confirmed" : "failed"
: !localGatePassed || missingEvidence.length > 0 ? "failed"
: realAuthorized && (!externalRoot || externalEvidenceMissing.length > 0 || externalErrors.length > 0) ? "failed"
: externalRoot && externalEvidenceMissing.length === 0 && candidateErrors.length === 0 && realAuthorized && externalErrors.length === 0 ? "passed"
: "externally_blocked";
const manifest = {
path: "tasks.manifest.json",
sha256: createHash("sha256").update(readFileSync("tasks.manifest.json")).digest("hex").toUpperCase(),
};
const result = {
acceptance_criteria: ["AC-01", "AC-33", "AC-41", "AC-47", "AC-49"],
automation: ["controlled_real", "manual_review"],
candidate_run_id: candidateRunId,
commit: spawnSync("git", ["rev-parse", "HEAD"], { encoding: "utf8" }).stdout.trim(),
evidence_refs: expectedEvidence,
external_blockers: phase === "green" && status === "externally_blocked" ? externalBlockers : [],
finished_at: new Date().toISOString(),
layer: ["EXT-REAL", "MANUAL"],
manifest,
missing_evidence: missingEvidence,
phase,
requirements: ["AUTH-01", "AUTH-02", "AUTH-07"],
run_id: runId,
schema_version: "1.0",
status,
task_id: "TASK-WP7-03",
test_id: caseId,
work_package: "WP-7",
};
writeJson(resolve(caseDirectory, "commands.json"), { commands, phase, run_id: runId, schema_version: "1.0" });
writeJson(resolve(caseDirectory, "result.json"), result);
writeJson(resolve(runDirectory, "evidence.json"), { cases: [{ external_blockers: result.external_blockers, missing_evidence: missingEvidence, status, test_id: caseId }], phase, run_id: runId, status });
console.log(JSON.stringify({ external_blockers: result.external_blockers, phase, run_id: runId, status }, null, 2));
if (status === "failed") process.exit(1);
+261
View File
@@ -0,0 +1,261 @@
import { spawnSync } from "node:child_process";
import { createHash } from "node:crypto";
import { existsSync, mkdirSync, readFileSync, writeFileSync } from "node:fs";
import { resolve } from "node:path";
const runId = process.env.DADA_TDD_RUN_ID ?? `wp7-04-amap-${new Date().toISOString().replace(/[^0-9]/g, "")}`;
const runDirectory = resolve("artifacts", "tdd", runId);
const caseDirectory = resolve(runDirectory, "cases", "TDD-WP7-EXT-003-real-amap");
if (existsSync(runDirectory)) throw new Error(`Evidence run already exists: ${runId}`);
mkdirSync(caseDirectory, { recursive: true });
function run(command, args, evidenceCommand = [command, ...args].join(" ")) {
const startedAt = new Date().toISOString();
const executable = process.platform === "win32" ? (process.env.ComSpec ?? "cmd.exe") : command;
const actualArgs = process.platform === "win32" ? ["/d", "/s", "/c", [command, ...args].join(" ")] : args;
const result = spawnSync(executable, actualArgs, { encoding: "utf8" });
return {
command: evidenceCommand,
exit_code: result.status ?? 1,
finished_at: new Date().toISOString(),
stderr: result.stderr ?? "",
stdout: result.stdout ?? "",
started_at: startedAt,
};
}
function skipped(command) {
const timestamp = new Date().toISOString();
return { command, exit_code: 1, finished_at: timestamp, started_at: timestamp, stderr: "prerequisite_failed", stdout: "" };
}
function readConsoleReview() {
const raw = process.env.DADA_AMAP_CONSOLE_REVIEW_JSON;
const fallback = {
allowlist: "not_verified",
auto_scaling: "not_verified",
paid_fallback: "not_verified",
qps: "not_verified",
qps_limit_per_second: null,
reviewed_at: null,
security_restriction: "not_verified",
service_binding: "not_verified",
source: "not_supplied",
valid: true,
};
if (!raw) return fallback;
try {
const parsed = JSON.parse(raw);
const requiredKeys = ["allowlist", "auto_scaling", "paid_fallback", "qps", "qps_limit_per_second", "reviewed_at", "security_restriction", "service_binding", "source"];
if (!parsed || typeof parsed !== "object" || Array.isArray(parsed) || Object.keys(parsed).sort().join("|") !== requiredKeys.sort().join("|")) {
return { ...fallback, source: "invalid_input", valid: false };
}
const statusFields = ["allowlist", "qps", "security_restriction", "service_binding"];
const statusValid = statusFields.every((field) => ["failed", "not_verified", "passed"].includes(parsed[field]));
const disabledFieldsValid = ["auto_scaling", "paid_fallback"].every((field) => ["disabled", "not_verified"].includes(parsed[field]));
const qpsLimitValid = parsed.qps === "passed"
? Number.isSafeInteger(parsed.qps_limit_per_second) && parsed.qps_limit_per_second >= 1 && parsed.qps_limit_per_second <= 1_000
: parsed.qps_limit_per_second === null;
const reviewedAtValid = typeof parsed.reviewed_at === "string" && Number.isFinite(Date.parse(parsed.reviewed_at));
if (!statusValid || !disabledFieldsValid || !qpsLimitValid || !reviewedAtValid || parsed.source !== "amap_console_manual_review") {
return { ...fallback, source: "invalid_input", valid: false };
}
return { ...parsed, valid: true };
} catch {
return { ...fallback, source: "invalid_input", valid: false };
}
}
function writeJson(path, value) {
writeFileSync(path, `${JSON.stringify(value, null, 2)}\n`);
}
function probeCode(value) {
return typeof value === "string" && /^[a-z0-9_]{1,64}$/.test(value) ? value : "invalid_output";
}
function containsForbiddenEvidence(value) {
const serialized = JSON.stringify(value);
return [
/[A-Za-z]:[\\/](?:Users|Documents)[\\/]/i,
/"(?:api[_-]?key|credential|secret_value|latitude|longitude|coordinates|email_address|ip_address)"\s*:/i,
/-----BEGIN (?:RSA |EC |OPENSSH )?PRIVATE KEY-----/,
].some((pattern) => pattern.test(serialized));
}
const consoleReview = readConsoleReview();
const build = run("pnpm", ["build:workspace-packages"]);
const locationRegression = build.exit_code === 0
? run("pnpm", ["exec", "vitest", "run", "tests/api/wp4-04-location.test.ts"])
: skipped("pnpm exec vitest run tests/api/wp4-04-location.test.ts");
const serviceRegression = build.exit_code === 0
? run("pnpm", ["exec", "vitest", "run", "tests/api/wp6-03-services.test.ts"])
: skipped("pnpm exec vitest run tests/api/wp6-03-services.test.ts");
const localHardStop = build.exit_code === 0
? run("pnpm", ["exec", "vitest", "run", "tests/api/wp7-04-amap-release-gate.test.ts"])
: skipped("pnpm exec vitest run tests/api/wp7-04-amap-release-gate.test.ts");
const productionAdapter = build.exit_code === 0
? run("pnpm", ["exec", "vitest", "run", "tests/api/wp7-04-amap-production-adapter.test.ts"])
: skipped("pnpm exec vitest run tests/api/wp7-04-amap-production-adapter.test.ts");
const consentFlow = build.exit_code === 0
? run("pnpm", ["exec", "vitest", "run", "tests/unit/wp4-04-palette-dynamic.test.ts"])
: skipped("pnpm exec vitest run tests/unit/wp4-04-palette-dynamic.test.ts");
const supervisorBuild = run("dotnet", ["build", "supervisor/Dada.Supervisor/Dada.Supervisor.csproj", "--configuration", "Release"]);
const supervisorSecurity = supervisorBuild.exit_code === 0
? run("dotnet", ["run", "--project", "supervisor/Dada.Supervisor.Tests/Dada.Supervisor.Tests.csproj", "--configuration", "Release"])
: skipped("dotnet run --project supervisor/Dada.Supervisor.Tests/Dada.Supervisor.Tests.csproj --configuration Release");
const supervisorExe = resolve("supervisor", "Dada.Supervisor", "bin", "Release", "net8.0-windows", "Dada.Supervisor.exe");
const external = supervisorBuild.exit_code === 0 && existsSync(supervisorExe)
? run(supervisorExe, ["secrets", "probe", "api-amap"], "Dada.Supervisor.exe secrets probe api-amap")
: skipped("Dada.Supervisor.exe secrets probe api-amap");
const trace = run("pnpm", ["validate:tdd-trace"]);
const security = run("pnpm", ["test:security"]);
const commands = [build, locationRegression, serviceRegression, localHardStop, productionAdapter, consentFlow, supervisorBuild, supervisorSecurity, external, trace, security]
.map(({ command, exit_code, finished_at, started_at }) => ({ command, exit_code, finished_at, started_at }));
const parsedExternal = (() => {
try { return JSON.parse(external.stdout.trim().split(/\r?\n/).at(-1) ?? ""); } catch { return {}; }
})();
const safeProbeCode = probeCode(parsedExternal.code);
const realCalls = Number.isSafeInteger(parsedExternal.real_calls) && parsedExternal.real_calls >= 0 && parsedExternal.real_calls <= 2
? parsedExternal.real_calls
: 0;
const probePassed = external.exit_code === 0 && safeProbeCode === "amap_probe_passed" && realCalls === 2;
const hardStopPassed = localHardStop.exit_code === 0;
const productionAdapterPassed = productionAdapter.exit_code === 0;
const consentPassed = consentFlow.exit_code === 0;
const supervisorSecurityPassed = supervisorSecurity.exit_code === 0;
const regressionPassed = locationRegression.exit_code === 0 && serviceRegression.exit_code === 0;
const automatedPassed = build.exit_code === 0 && hardStopPassed && productionAdapterPassed && consentPassed && supervisorSecurityPassed && regressionPassed && trace.exit_code === 0 && security.exit_code === 0;
const manualReviewPassed = consoleReview.valid
&& consoleReview.service_binding === "passed"
&& consoleReview.qps === "passed"
&& consoleReview.allowlist === "passed"
&& consoleReview.security_restriction === "passed"
&& consoleReview.paid_fallback === "disabled"
&& consoleReview.auto_scaling === "disabled";
const requiredBeforeRelease = [];
if (!probePassed) requiredBeforeRelease.push("real_location_and_reverse_geocode");
if (consoleReview.service_binding !== "passed") requiredBeforeRelease.push("service_binding");
if (consoleReview.qps !== "passed") requiredBeforeRelease.push("qps_confirmation");
if (consoleReview.allowlist !== "passed") requiredBeforeRelease.push("allowlist_confirmation");
if (consoleReview.security_restriction !== "passed") requiredBeforeRelease.push("security_restriction");
if (consoleReview.paid_fallback !== "disabled") requiredBeforeRelease.push("paid_fallback_disabled");
if (consoleReview.auto_scaling !== "disabled") requiredBeforeRelease.push("auto_scaling_disabled");
if (!hardStopPassed) requiredBeforeRelease.push("monthly_1000_hard_stop");
if (!productionAdapterPassed) requiredBeforeRelease.push("production_amap_adapter");
if (!consentPassed) requiredBeforeRelease.push("dyn004_confirmation");
if (!supervisorSecurityPassed) requiredBeforeRelease.push("controlled_probe_security");
const blocker = !automatedPassed
? "automated_regression_failed"
: !probePassed
? safeProbeCode
: !consoleReview.valid
? "manual_review_invalid"
: consoleReview.allowlist === "failed"
? "amap_allowlist_unconfigured"
: consoleReview.security_restriction === "failed"
? "amap_security_restriction_unconfigured"
: !manualReviewPassed
? "manual_acceptance_required"
: null;
const status = !automatedPassed ? "failed" : probePassed && manualReviewPassed ? "passed" : "externally_blocked";
const contractEvidence = {
blocker,
checks: {
allowlist: consoleReview.allowlist === "passed" ? "manual_console_passed" : consoleReview.allowlist,
auto_scaling: consoleReview.auto_scaling,
client_security_controls: productionAdapterPassed && supervisorSecurityPassed ? "automated_passed" : "failed",
controlled_probe_security: supervisorSecurityPassed ? "automated_passed" : "failed",
dyn004_hard_stop: consentPassed ? "confirmation_contract_passed" : "failed",
location_and_reverse_geocode: probePassed ? "real_probe_passed" : "not_verified",
monthly_hard_limit_1000: hardStopPassed ? "local_pre_egress_passed" : "failed",
paid_fallback: consoleReview.paid_fallback,
production_adapter: productionAdapterPassed ? "credential_channel_real_adapter_passed" : "failed",
provider_qps: consoleReview.qps === "passed" ? "manual_console_passed" : consoleReview.qps,
provider_qps_limit_per_second: consoleReview.qps_limit_per_second,
security_binding: consoleReview.security_restriction === "passed" ? "manual_console_passed" : consoleReview.security_restriction,
service_binding: consoleReview.service_binding === "passed" ? "manual_console_passed" : consoleReview.service_binding,
},
mode: probePassed ? "controlled_real" : "blocked",
real_calls: realCalls,
status,
schema_version: "1.1",
};
const externalCallsEvidence = {
blocker,
mode: probePassed ? "controlled_real" : "blocked",
real_calls: realCalls,
request_scope: ["geocoding", "reverse_geocoding"],
service: "amap",
source_command_status: safeProbeCode,
status,
schema_version: "1.1",
};
const manualReviewEvidence = {
blocker,
checks: {
allowlist: consoleReview.allowlist,
auto_scaling: consoleReview.auto_scaling,
paid_fallback: consoleReview.paid_fallback,
qps: consoleReview.qps,
qps_limit_per_second: consoleReview.qps_limit_per_second,
security_restriction: consoleReview.security_restriction,
service_binding: consoleReview.service_binding,
},
required_before_release: requiredBeforeRelease,
reviewed_at: consoleReview.reviewed_at,
source: consoleReview.source,
status,
schema_version: "1.1",
};
const result = {
acceptance_criteria: ["AC-17", "AC-41", "AC-47"],
automation: ["controlled_real", "manual_review"],
blocker,
contract_regression: automatedPassed ? "passed" : "failed",
external_calls: realCalls,
finished_at: new Date().toISOString(),
manifest: { path: "tasks.manifest.json", sha256: createHash("sha256").update(readFileSync("tasks.manifest.json")).digest("hex").toUpperCase() },
missing_evidence: requiredBeforeRelease,
parent_family: "TDD-WP7-EXT-003",
phase: "green",
release_gate: ["release:P0-A"],
requirements: ["DYN-04", "PRIV-03"],
run_id: runId,
schema_version: "1.1",
status,
task_id: "TASK-WP7-04",
test_id: "TDD-WP7-EXT-003-real-amap",
work_package: "WP-7",
};
const commandsEvidence = { commands, run_id: runId, schema_version: "1.1" };
const evidenceIndex = { cases: [{ status: result.status, test_id: result.test_id }], run_id: runId, status: result.status, schema_version: "1.1" };
const redactionInputs = [contractEvidence, externalCallsEvidence, manualReviewEvidence, result, commandsEvidence, evidenceIndex];
const evidenceRedactionPassed = !redactionInputs.some(containsForbiddenEvidence);
const redactionEvidence = {
findings: evidenceRedactionPassed ? [] : ["forbidden_evidence_field"],
forbidden_fields_present: !evidenceRedactionPassed,
source_security_scan: security.exit_code === 0 ? "passed" : "failed",
status: evidenceRedactionPassed && security.exit_code === 0 ? "passed" : "failed",
stored_fields: ["service", "status", "logical_limit", "manual_review_status", "qps_limit_per_second"],
schema_version: "1.1",
};
if (redactionEvidence.status !== "passed") {
result.status = "failed";
result.blocker = "redaction_failed";
evidenceIndex.status = "failed";
evidenceIndex.cases[0].status = "failed";
}
writeJson(resolve(caseDirectory, "amap-contract.json"), contractEvidence);
writeJson(resolve(caseDirectory, "external-calls.json"), externalCallsEvidence);
writeJson(resolve(caseDirectory, "redaction.json"), redactionEvidence);
writeJson(resolve(caseDirectory, "manual-review.json"), manualReviewEvidence);
writeJson(resolve(caseDirectory, "commands.json"), commandsEvidence);
writeJson(resolve(caseDirectory, "result.json"), result);
writeJson(resolve(runDirectory, "evidence.json"), evidenceIndex);
console.log(JSON.stringify(result, null, 2));
if (result.status === "failed") process.exit(1);
+13
View File
@@ -0,0 +1,13 @@
import { runWp705Gate } from './lib/wp7-05-ui-gate.mjs';
const result = runWp705Gate({
candidatePath: process.env.WP7_01_CANDIDATE_RECORD,
evidence: null,
dependencies: {
'TASK-WP7-03': 'externally_blocked',
'TASK-WP7-04': 'externally_blocked',
},
});
console.log(JSON.stringify({ task: 'TASK-WP7-05', ...result }));
process.exitCode = result.status === 'ready_for_execution' ? 0 : 3;
+108
View File
@@ -0,0 +1,108 @@
import { spawnSync } from "node:child_process";
import { createHash } from "node:crypto";
import { existsSync, mkdirSync, readFileSync, writeFileSync } from "node:fs";
import { resolve } from "node:path";
import { validateTddTrace } from "./lib/tdd-trace.mjs";
import { buildWp706PrefreezeReport, REQUIRED_UPSTREAM } from "./lib/wp7-06-prefreeze.mjs";
const runId = process.env.DADA_TDD_RUN_ID ?? `wp7-06-prefreeze-${new Date().toISOString().replace(/[^0-9]/g, "")}`;
const runDirectory = resolve("artifacts", "tdd", runId);
const caseDirectory = resolve(runDirectory, "cases", "TDD-WP7-AC-001-trace-structure");
if (existsSync(runDirectory)) throw new Error(`Evidence run already exists: ${runId}`);
mkdirSync(caseDirectory, { recursive: true });
function writeJson(path, value) {
writeFileSync(path, `${JSON.stringify(value, null, 2)}\n`);
}
function git(args) {
const result = spawnSync("git", args, { encoding: "utf8", timeout: 60_000 });
if ((result.status ?? 1) !== 0) throw new Error(`WP7_06_GIT_COMMAND_FAILED:${args[0]}`);
return result.stdout.trim();
}
function runCommand(name, command) {
const startedAt = new Date().toISOString();
const result = spawnSync(process.env.ComSpec ?? "cmd.exe", ["/d", "/s", "/c", command], {
encoding: "utf8",
env: process.env,
maxBuffer: 64 * 1024 * 1024,
});
if (result.stdout) process.stdout.write(result.stdout);
if (result.stderr) process.stderr.write(result.stderr);
return {
command,
exit_code: result.status ?? 1,
finished_at: new Date().toISOString(),
name,
started_at: startedAt,
};
}
const commands = [
runCommand("prefreeze-unit", "node --test tests/package/wp7-06-prefreeze.test.mjs"),
runCommand("tdd-trace", "pnpm validate:tdd-trace"),
];
if (commands.some((command) => command.exit_code !== 0)) {
writeJson(resolve(caseDirectory, "commands.json"), { commands, run_id: runId, schema_version: "1.0" });
process.exit(1);
}
const trace = validateTddTrace();
const currentCommit = git(["rev-parse", "HEAD"]);
const remoteLines = git(["ls-remote", "--heads", "origin", "codex/wp7-01", "codex/wp7-02", "codex/wp7-03", "codex/wp7-04", "codex/wp7-05"])
.split(/\r?\n/)
.filter(Boolean);
const remoteHeads = Object.fromEntries(remoteLines.map((line) => {
const [head, reference] = line.split(/\s+/);
return [reference.replace("refs/heads/", ""), head];
}));
const upstream = Object.fromEntries(Object.entries(REQUIRED_UPSTREAM).map(([taskId, status]) => {
const branch = taskId.replace("TASK-", "codex/").toLowerCase();
const head = remoteHeads[branch];
const ancestry = spawnSync("git", ["merge-base", "--is-ancestor", head ?? "missing", "HEAD"], { encoding: "utf8", timeout: 30_000 });
return [taskId, { branch, head, merged: ancestry.status === 0, status }];
}));
const report = buildWp706PrefreezeReport({
currentCommit,
releaseExists: existsSync(resolve("RELEASE.json")),
trace,
upstream,
});
const result = {
acceptance_criteria: Array.from({ length: 56 }, (_, index) => index + 1)
.filter((number) => ![8, 26, 37, 54].includes(number))
.map((number) => `AC-${String(number).padStart(2, "0")}`),
automation: ["automated", "manual_review"],
commit: currentCommit,
evidence_refs: ["commands.json", "trace-summary.json", "upstream-lineage.json", "deferred-external.json"],
finished_at: new Date().toISOString(),
manifest: {
path: "tasks.manifest.json",
sha256: createHash("sha256").update(readFileSync("tasks.manifest.json")).digest("hex").toUpperCase(),
},
missing_evidence: [],
release_gate: ["release:P0-A"],
requirements: ["NFR-05"],
run_id: runId,
schema_version: "1.0",
status: report.status,
task_id: "TASK-WP7-06",
test_id: "TDD-WP7-AC-001-trace-structure",
work_package: "WP-7",
};
writeJson(resolve(caseDirectory, "commands.json"), { commands, run_id: runId, schema_version: "1.0" });
writeJson(resolve(caseDirectory, "trace-summary.json"), { status: trace.status, summary: trace.summary, schema_version: "1.0" });
writeJson(resolve(caseDirectory, "upstream-lineage.json"), { current_commit: currentCommit, tasks: report.upstream, schema_version: "1.0" });
writeJson(resolve(caseDirectory, "deferred-external.json"), {
policy: "product_owner_first_version_nonblocking",
tasks: report.deferred_external_tasks,
treated_as_real_provider_pass: false,
schema_version: "1.0",
});
writeJson(resolve(caseDirectory, "result.json"), result);
writeJson(resolve(runDirectory, "evidence.json"), { cases: [{ missing_evidence: [], status: result.status, test_id: result.test_id }], run_id: runId, status: result.status, schema_version: "1.0" });
console.log(JSON.stringify({ deferred_external_tasks: report.deferred_external_tasks, next_task: report.next_task, run_id: runId, status: report.status }, null, 2));
+157
View File
@@ -0,0 +1,157 @@
import { spawnSync } from "node:child_process";
import { copyFileSync, existsSync, mkdirSync, readFileSync, writeFileSync } from "node:fs";
import { basename, join, resolve } from "node:path";
import { buildAndValidatePortablePackage } from "./lib/portable-package.mjs";
import { readCandidateEnvironment } from "./lib/release-candidate.mjs";
import {
buildFinalReleaseRecord,
scanReleaseFiles,
sha256File,
validateFinalEvidence,
} from "./lib/wp7-07-final-release.mjs";
const runId = process.env.DADA_TDD_RUN_ID ?? `wp7-07-final-${new Date().toISOString().replace(/[^0-9]/g, "")}`;
const runDirectory = resolve("artifacts", "tdd", runId);
const releaseCase = resolve(runDirectory, "cases", "TDD-WP7-REL-001-final-release-record");
const securityCase = resolve(runDirectory, "cases", "TDD-WP7-SEC-001-artifact-leak-scan");
const outputRoot = resolve(".build", "wp7-07-final-release");
if (existsSync(runDirectory)) throw new Error(`Evidence run already exists: ${runId}`);
mkdirSync(releaseCase, { recursive: true });
mkdirSync(securityCase, { recursive: true });
function writeJson(path, value) {
writeFileSync(path, `${JSON.stringify(value, null, 2)}\n`);
}
function git(args) {
const result = spawnSync("git", args, { encoding: "utf8", maxBuffer: 64 * 1024 * 1024, timeout: 120_000 });
if ((result.status ?? 1) !== 0) throw new Error(`WP7_07_GIT_FAILED:${args.join(" ")}`);
return result.stdout.trim();
}
function gitGrep(args) {
const result = spawnSync("git", ["grep", ...args], { encoding: "utf8", maxBuffer: 64 * 1024 * 1024, timeout: 120_000 });
if (![0, 1].includes(result.status ?? 2)) throw new Error("WP7_07_GIT_GREP_FAILED");
return result.status === 0 ? result.stdout.trim() : "";
}
function run(name, command) {
const startedAt = new Date().toISOString();
const result = spawnSync(process.env.ComSpec ?? "cmd.exe", ["/d", "/s", "/c", command], {
encoding: "utf8",
env: process.env,
maxBuffer: 64 * 1024 * 1024,
});
if (result.stdout) process.stdout.write(result.stdout);
if (result.stderr) process.stderr.write(result.stderr);
return { command, exit_code: result.status ?? 1, finished_at: new Date().toISOString(), name, started_at: startedAt };
}
const currentCommit = git(["rev-parse", "HEAD"]);
const prefreezeCommit = git(["ls-remote", "origin", "refs/heads/codex/wp7-06"]).split(/\s+/)[0];
if (!prefreezeCommit || spawnSync("git", ["merge-base", "--is-ancestor", prefreezeCommit, "HEAD"]).status !== 0) {
throw new Error("WP7_07_PREFREEZE_LINEAGE_INVALID");
}
const commands = [
run("unit", "node --test tests/package/wp7-07-final-release.test.mjs"),
run("security", "pnpm test:security"),
run("trace", "pnpm validate:tdd-trace"),
];
if (commands.some(({ exit_code }) => exit_code !== 0)) {
writeJson(join(releaseCase, "commands.json"), { commands, run_id: runId, schema_version: "1.0" });
process.exit(1);
}
const environment = readCandidateEnvironment();
const packageJson = JSON.parse(readFileSync("package.json", "utf8"));
const release = buildFinalReleaseRecord({
appVersion: packageJson.version,
browsers: environment.browsers.map(({ brand, full_version }) => ({ brand, fullVersion: full_version })),
buildCommit: currentCommit,
frozenFromCommit: prefreezeCommit,
recordedAt: new Date().toISOString(),
windows: {
arch: environment.windows.arch,
build: environment.windows.build,
displayVersion: environment.windows.display_version,
},
});
writeJson(resolve("RELEASE.json"), release);
const packageResult = await buildAndValidatePortablePackage({ evidenceDirectory: releaseCase, outputRoot, releaseRecord: release });
const packageDirectory = join(outputRoot, packageResult.packageManifest.package_name);
const zipPath = join(outputRoot, `${packageResult.packageManifest.package_name}.zip`);
const releaseSha256 = sha256File(resolve("RELEASE.json"));
const packageReleaseSha256 = sha256File(join(packageDirectory, "RELEASE.json"));
if (releaseSha256 !== packageReleaseSha256) throw new Error("WP7_07_PACKAGE_RELEASE_DRIFT");
const finalScan = scanReleaseFiles({ roots: [packageDirectory, releaseCase] });
const trackedSensitive = gitGrep(["-I", "-n", "-E", "C:\\\\Users\\\\[^\\\\]+|sk-[A-Za-z0-9_-]{24,}", "HEAD", "--", ":!tests", ":!scripts/lib/wp7-07-final-release.mjs"]);
const scan = {
...finalScan,
git_current_findings: trackedSensitive ? trackedSensitive.split(/\r?\n/).filter(Boolean) : [],
status: finalScan.status === "passed" && !trackedSensitive ? "passed" : "failed",
};
writeJson(join(securityCase, "scan-report.json"), scan);
writeJson(join(securityCase, "allowlist.json"), {
entries: ["tests/**:synthetic security traps", "scripts/lib/wp7-07-final-release.mjs:scanner patterns"],
real_values_allowed: false,
schema_version: "1.0",
});
if (scan.status !== "passed") throw new Error("WP7_07_LEAK_SCAN_FAILED");
const finalEvidence = validateFinalEvidence({ packageManifest: packageResult.packageManifest, release, releaseSha256, scan });
copyFileSync(resolve("RELEASE.json"), join(releaseCase, "RELEASE.json"));
copyFileSync(join(packageDirectory, "START-HERE.txt"), join(releaseCase, "START-HERE.txt"));
writeJson(join(releaseCase, "environment.json"), {
browsers: release.browsers,
fixed_port: release.fixedPort,
windows: release.windows,
schema_version: "1.0",
});
writeJson(join(releaseCase, "final-package.json"), {
file_name: basename(zipPath),
release_sha256: finalEvidence.release_sha256,
release_status: release.releaseStatus,
zip_sha256: finalEvidence.zip_sha256,
schema_version: "1.0",
});
writeJson(join(releaseCase, "commands.json"), { commands, run_id: runId, schema_version: "1.0" });
writeJson(join(releaseCase, "result.json"), {
acceptance_criteria: ["AC-24", "AC-41", "AC-48", "AC-56"],
deferred_external_tasks: release.deferredExternalTasks,
evidence_refs: ["RELEASE.json", "START-HERE.txt", "environment.json", "package-manifest.json", "final-package.json"],
release_gate: ["release:P0-A"],
requirements: ["NFR-01", "NFR-09", "PRIV-01", "PRIV-02"],
status: "passed",
task_id: "TASK-WP7-07",
test_id: "TDD-WP7-REL-001-final-release-record",
});
writeJson(join(securityCase, "result.json"), {
evidence_refs: ["scan-report.json", "allowlist.json"],
status: "passed",
task_id: "TASK-WP7-07",
test_id: "TDD-WP7-SEC-001-artifact-leak-scan",
});
writeJson(join(runDirectory, "evidence.json"), {
cases: [
{ missing_evidence: [], status: "passed", test_id: "TDD-WP7-REL-001-final-release-record" },
{ missing_evidence: [], status: "passed", test_id: "TDD-WP7-SEC-001-artifact-leak-scan" },
],
deferred_external_tasks: release.deferredExternalTasks,
release_sha256: finalEvidence.release_sha256,
run_id: runId,
status: "passed",
zip_sha256: finalEvidence.zip_sha256,
schema_version: "1.0",
});
console.log(JSON.stringify({
deferred_external_tasks: release.deferredExternalTasks,
release_sha256: finalEvidence.release_sha256,
run_id: runId,
status: "passed",
zip_sha256: finalEvidence.zip_sha256,
}, null, 2));
@@ -38,7 +38,9 @@ internal static class Program
{
var security = await TestCredentialBoundaryAsync();
var supervisor = await TestSupervisorLifecycleAsync();
await TestAmapProbeSecurityAsync();
TestSecureConfigurationPersistence();
TestRuntimeDirectoryBootstrap();
TestStructuredLogging();
WriteEvidence(Environment.GetEnvironmentVariable("DADA_EVIDENCE_DIR_SEC"), security);
WriteEvidence(Environment.GetEnvironmentVariable("DADA_EVIDENCE_DIR_SUP"), supervisor);
@@ -52,6 +54,20 @@ internal static class Program
}
}
private static async Task TestAmapProbeSecurityAsync()
{
using var handler = AmapProbe.CreateHandler();
False(handler.AllowAutoRedirect, "Amap probe redirects disabled");
Equal(1, handler.MaxConnectionsPerServer, "Amap probe per-server connection cap");
True(AmapProbe.IsAllowedEndpoint(new Uri("https://restapi.amap.com/v3/geocode/regeo")), "Amap fixed HTTPS endpoint accepted");
False(AmapProbe.IsAllowedEndpoint(new Uri("http://restapi.amap.com/v3/geocode/regeo")), "Amap HTTP endpoint rejected");
False(AmapProbe.IsAllowedEndpoint(new Uri("https://example.invalid/v3/geocode/regeo")), "Amap alternate host rejected");
using var oversized = new ByteArrayContent(new byte[AmapProbe.MaximumResponseBytes + 1]);
await ThrowsAsync<InvalidDataException>(
() => AmapProbe.ReadBoundedJsonAsync(oversized),
"Amap oversized response must be rejected before parsing");
}
private static void TestStructuredLogging()
{
Equal(10 * 1024 * 1024L, StructuredJsonlLogger.SizeLimitBytes, "Supervisor log byte limit");
@@ -110,6 +126,29 @@ internal static class Program
}
}
private static void TestRuntimeDirectoryBootstrap()
{
var root = Path.Combine(Path.GetTempPath(), $"dada-runtime-root-{Guid.NewGuid():N}");
try
{
Directory.CreateDirectory(root);
SupervisorRuntime.EnsureRuntimeDirectories(root);
foreach (var relativePath in new[]
{
"db", "content/references", "content/generated", "content/exports",
"managed-assets", "derived-assets", "staging",
"logs/api", "logs/worker", "logs/supervisor",
})
{
True(Directory.Exists(Path.Combine(root, relativePath)), $"runtime directory missing: {relativePath}");
}
}
finally
{
if (Directory.Exists(root)) Directory.Delete(root, recursive: true);
}
}
private static async Task<object> TestCredentialBoundaryAsync()
{
var store = new TestCredentialStore();
@@ -131,6 +170,8 @@ internal static class Program
True(leakProbe.SensitiveOutputDetected, "credential echo must be detected");
Equal(string.Empty, leakProbe.StandardOutput, "credential echo output discarded");
Equal(string.Empty, leakProbe.StandardError, "credential echo error discarded");
True(AiGatewayProbe.TryValidateOutput("{\"code\":\"ai_probe_passed\",\"mime_type\":\"image/png\",\"pixel_height\":1080,\"pixel_width\":1080,\"real_calls\":1,\"success\":true}", out _), "AI probe success output accepted");
False(AiGatewayProbe.TryValidateOutput("{\"code\":\"ai_probe_passed\",\"raw_body\":\"private\",\"real_calls\":1,\"success\":true}", out _), "AI probe private output rejected");
var externalArguments = new[]
{
@@ -0,0 +1,74 @@
using System.Diagnostics;
using System.Text.Json;
namespace Dada.Supervisor;
internal static class AiGatewayProbe
{
internal static async Task<int> RunAsync(ICredentialStore credentials, CancellationToken cancellationToken = default)
{
var node = Path.Combine(AppContext.BaseDirectory, "runtime", "node.exe");
var worker = Path.Combine(AppContext.BaseDirectory, "server", "worker.mjs");
if (!File.Exists(node) || !File.Exists(worker)) return WriteFailure("ai_probe_runtime_missing", 0);
var startInfo = new ProcessStartInfo(node) { WorkingDirectory = AppContext.BaseDirectory };
startInfo.Environment["DADA_SQLITE_NATIVE_BINDING"] = Path.Combine(AppContext.BaseDirectory, "server", "native", "better_sqlite3.node");
startInfo.ArgumentList.Add(worker);
startInfo.ArgumentList.Add("--dada-ai-probe");
startInfo.ArgumentList.Add("--dada-credential-stdin");
var result = await CredentialProcessLauncher.RunToCompletionAsync(startInfo, ChildRole.Worker, credentials, cancellationToken);
if (result.SensitiveOutputDetected || result.StandardError.Length > 0 || !TryValidateOutput(result.StandardOutput, out var sanitized))
{
return WriteFailure("ai_probe_runtime_failed", 0);
}
Console.WriteLine(sanitized);
return result.ExitCode;
}
internal static bool TryValidateOutput(string output, out string sanitized)
{
sanitized = string.Empty;
try
{
using var document = JsonDocument.Parse(output);
var root = document.RootElement;
if (root.ValueKind != JsonValueKind.Object) return false;
var allowed = new HashSet<string>(StringComparer.Ordinal)
{
"code", "error_category", "mime_type", "pixel_height", "pixel_width", "real_calls", "success",
};
if (root.EnumerateObject().Any(property => !allowed.Contains(property.Name))) return false;
if (!root.TryGetProperty("success", out var success) || success.ValueKind is not (JsonValueKind.True or JsonValueKind.False)) return false;
if (!root.TryGetProperty("real_calls", out var realCalls) || realCalls.ValueKind != JsonValueKind.Number || !realCalls.TryGetInt32(out var count) || count is < 0 or > 1) return false;
var passed = success.GetBoolean();
var code = root.GetProperty("code").GetString();
if (passed)
{
if (code != "ai_probe_passed" || count != 1) return false;
var mime = root.GetProperty("mime_type").GetString();
if (mime is not ("image/jpeg" or "image/png" or "image/webp")) return false;
if (!PositiveDimension(root, "pixel_width") || !PositiveDimension(root, "pixel_height")) return false;
}
else
{
if (code != "ai_probe_failed" || !root.TryGetProperty("error_category", out var category)
|| category.ValueKind != JsonValueKind.String || (category.GetString()?.Length ?? 0) is < 1 or > 64) return false;
}
sanitized = JsonSerializer.Serialize(root);
return true;
}
catch (Exception exception) when (exception is JsonException or InvalidOperationException or KeyNotFoundException)
{
return false;
}
}
private static bool PositiveDimension(JsonElement root, string name) =>
root.TryGetProperty(name, out var value) && value.ValueKind == JsonValueKind.Number
&& value.TryGetInt32(out var dimension) && dimension is > 0 and <= 4096;
private static int WriteFailure(string code, int realCalls)
{
Console.WriteLine(JsonSerializer.Serialize(new { code, real_calls = realCalls, success = false }));
return 2;
}
}
+107
View File
@@ -0,0 +1,107 @@
using System.Buffers;
using System.Net;
using System.Text.Json;
namespace Dada.Supervisor;
internal static class AmapProbe
{
internal const int MaximumResponseBytes = 65_536;
private const string ProviderHostname = "restapi.amap.com";
private static readonly HttpClient Client = new(CreateHandler()) { Timeout = TimeSpan.FromSeconds(15) };
internal static SocketsHttpHandler CreateHandler() => new()
{
AllowAutoRedirect = false,
AutomaticDecompression = DecompressionMethods.None,
ConnectTimeout = TimeSpan.FromSeconds(10),
MaxConnectionsPerServer = 1,
};
internal static bool IsAllowedEndpoint(Uri endpoint) =>
endpoint.Scheme == Uri.UriSchemeHttps
&& endpoint.Host.Equals(ProviderHostname, StringComparison.OrdinalIgnoreCase)
&& (endpoint.IsDefaultPort || endpoint.Port == 443)
&& string.IsNullOrEmpty(endpoint.UserInfo)
&& endpoint.AbsolutePath is "/v3/geocode/regeo" or "/v3/geocode/geo";
internal static int Run(string? key)
{
if (string.IsNullOrWhiteSpace(key))
{
Write("amap_credentials_missing", false, 0, null, null);
return 3;
}
var realCalls = 0;
try
{
realCalls += 1;
var reverse = Call("https://restapi.amap.com/v3/geocode/regeo?location=120.6994,27.9943&extensions=base", key).GetAwaiter().GetResult();
realCalls += 1;
var geocode = Call($"https://restapi.amap.com/v3/geocode/geo?address={Uri.EscapeDataString("")}", key).GetAwaiter().GetResult();
var success = reverse.Status == "1" && geocode.Status == "1";
Write(success ? "amap_probe_passed" : "amap_provider_rejected", success, realCalls, reverse.Status, geocode.Status);
return success ? 0 : 3;
}
catch (TaskCanceledException)
{
Write("amap_probe_timeout", false, realCalls, null, null);
return 3;
}
catch (HttpRequestException exception)
{
Write($"amap_probe_network_{exception.StatusCode?.ToString() ?? "error"}", false, realCalls, null, null);
return 3;
}
catch (Exception exception) when (exception is JsonException or InvalidDataException)
{
Write("amap_probe_invalid_response", false, realCalls, null, null);
return 3;
}
}
private static async Task<ProbeResponse> Call(string endpoint, string key)
{
var requestUri = new Uri($"{endpoint}&key={Uri.EscapeDataString(key)}", UriKind.Absolute);
if (!IsAllowedEndpoint(requestUri)) throw new InvalidDataException("amap_endpoint_rejected");
using var request = new HttpRequestMessage(HttpMethod.Get, requestUri);
using var response = await Client.SendAsync(request, HttpCompletionOption.ResponseHeadersRead);
response.EnsureSuccessStatusCode();
using var document = await ReadBoundedJsonAsync(response.Content);
var root = document.RootElement;
return new ProbeResponse(root.GetProperty("status").GetString() ?? "", root.TryGetProperty("infocode", out var code) ? code.GetString() : null);
}
internal static async Task<JsonDocument> ReadBoundedJsonAsync(HttpContent content)
{
if (content.Headers.ContentLength is > MaximumResponseBytes) throw new InvalidDataException("amap_response_too_large");
await using var stream = await content.ReadAsStreamAsync();
using var buffered = new MemoryStream();
var buffer = ArrayPool<byte>.Shared.Rent(4_096);
try
{
var total = 0;
while (true)
{
var read = await stream.ReadAsync(buffer);
if (read == 0) break;
total += read;
if (total > MaximumResponseBytes) throw new InvalidDataException("amap_response_too_large");
await buffered.WriteAsync(buffer.AsMemory(0, read));
}
buffered.Position = 0;
return await JsonDocument.ParseAsync(buffered);
}
finally
{
Array.Clear(buffer);
ArrayPool<byte>.Shared.Return(buffer);
}
}
private static void Write(string code, bool success, int realCalls, string? reverseStatus, string? geocodeStatus) =>
Console.WriteLine(JsonSerializer.Serialize(new { code, success, real_calls = realCalls, reverse_status = reverseStatus, geocode_status = geocodeStatus }));
private sealed record ProbeResponse(string Status, string? InfoCode);
}
+6 -2
View File
@@ -50,7 +50,9 @@ internal static class CredentialProcessLauncher
var credentials = new Dictionary<string, string>(StringComparer.Ordinal);
foreach (var target in CredentialCatalog.RequiredFor(role))
{
credentials[target] = store.Read(target) ?? throw new MissingCredentialException(target);
var value = store.Read(target);
if (role == ChildRole.Worker && string.IsNullOrWhiteSpace(value)) throw new MissingCredentialException(target);
credentials[target] = value ?? string.Empty;
}
startInfo.UseShellExecute = false;
@@ -98,7 +100,9 @@ internal static class CredentialProcessLauncher
var credentials = new Dictionary<string, string>(StringComparer.Ordinal);
foreach (var target in CredentialCatalog.RequiredFor(role))
{
credentials[target] = store.Read(target) ?? throw new MissingCredentialException(target);
var value = store.Read(target);
if (role == ChildRole.Worker && string.IsNullOrWhiteSpace(value)) throw new MissingCredentialException(target);
credentials[target] = value ?? string.Empty;
}
startInfo.UseShellExecute = false;
@@ -26,7 +26,7 @@ internal static class OfflineCommandRouter
return args[0] switch
{
"configure" => RunConfigure(args.Skip(1).ToArray()),
"secrets" => RunSecrets(args.Skip(1).ToArray(), credentials),
"secrets" => await RunSecretsAsync(args.Skip(1).ToArray(), credentials),
"admin-allowlist" => RunAdminAllowlist(args.Skip(1).ToArray(), credentials),
"doctor" when args.Length == 1 => RunDoctor(credentials),
"validate-external" => await ControlledExternalValidationLauncher.RunAsync(args.Skip(1).ToArray(), credentials),
@@ -66,7 +66,7 @@ internal static class OfflineCommandRouter
return 0;
}
private static int RunSecrets(string[] args, ICredentialStore store)
private static async Task<int> RunSecretsAsync(string[] args, ICredentialStore store)
{
if (args.Length != 2 || !TryResolveCredential(args[1], out var target)) return Usage();
switch (args[0])
@@ -84,6 +84,10 @@ internal static class OfflineCommandRouter
store.Write(target, value);
WriteResult("credential_saved", true);
return 0;
case "probe" when target == CredentialCatalog.ApiAmap:
return AmapProbe.Run(store.Read(target));
case "probe" when target == CredentialCatalog.WorkerAiGateway:
return await AiGatewayProbe.RunAsync(store);
default:
return Usage();
}
@@ -199,7 +203,7 @@ internal static class OfflineCommandRouter
private static int Usage()
{
WriteResult("usage: configure init|data-root|asset-root; secrets set|status|clear; admin-allowlist add|remove|status; doctor; validate-external", false);
WriteResult("usage: configure init|data-root|asset-root; secrets set|status|clear|probe; admin-allowlist add|remove|status; doctor; validate-external", false);
return 2;
}
}
+4 -1
View File
@@ -30,7 +30,10 @@ internal static class Program
};
var state = await runtime.StartAsync();
if (!form.IsDisposed) form.SetState(state);
if (state == SupervisorState.Ready) SupervisorForm.OpenProductInSupportedBrowser();
if (state == SupervisorState.Ready && !SupervisorForm.OpenProductInSupportedBrowser())
{
form.SetBrowserLaunchFailure();
}
}
form.Shown += async (_, _) => await StartRuntimeAsync();
form.RestartRequested += async () => await StartRuntimeAsync();
+9 -4
View File
@@ -26,6 +26,7 @@ internal sealed class SupervisorForm : Form
Font = new Font("Segoe UI", 9F);
FormBorderStyle = FormBorderStyle.FixedDialog;
MaximizeBox = false;
ShowInTaskbar = true;
StartPosition = FormStartPosition.CenterScreen;
Text = "Dada";
@@ -90,10 +91,6 @@ internal sealed class SupervisorForm : Form
trayIcon.DoubleClick += (_, _) => RestoreWindow();
FormClosing += (_, _) => trayIcon.Visible = false;
Resize += (_, _) =>
{
if (WindowState == FormWindowState.Minimized) Hide();
};
SetState(initialState);
}
@@ -139,6 +136,14 @@ internal sealed class SupervisorForm : Form
Activate();
}
internal void SetBrowserLaunchFailure()
{
if (state == SupervisorState.Ready)
{
statusDetail.Text = "本机服务运行正常,但未能自动打开浏览器;请点击“打开 Dada”或选择浏览器。";
}
}
protected override void Dispose(bool disposing)
{
if (disposing) trayIcon.Dispose();
+65 -10
View File
@@ -1,9 +1,23 @@
using System.Diagnostics;
using System.Security.Cryptography;
namespace Dada.Supervisor;
internal sealed class SupervisorRuntime : IAsyncDisposable
{
private static readonly string[] RequiredDataDirectories =
[
"db",
Path.Combine("content", "references"),
Path.Combine("content", "generated"),
Path.Combine("content", "exports"),
"managed-assets",
"derived-assets",
"staging",
Path.Combine("logs", "api"),
Path.Combine("logs", "worker"),
Path.Combine("logs", "supervisor"),
];
private readonly ICredentialStore credentials;
private ManagedComponentSupervisor? api;
private ManagedComponentSupervisor? worker;
@@ -25,6 +39,7 @@ internal sealed class SupervisorRuntime : IAsyncDisposable
{
return SupervisorState.StartupFailed;
}
EnsureRuntimeDirectories(configuration.LocalDataRoot);
try
{
logger = new StructuredJsonlLogger(Path.Combine(configuration.LocalDataRoot, "logs", "supervisor"), "supervisor");
@@ -34,22 +49,45 @@ internal sealed class SupervisorRuntime : IAsyncDisposable
{
return SupervisorState.StorageUnavailable;
}
if (CredentialCatalog.RequiredFor(ChildRole.Api).Concat(CredentialCatalog.RequiredFor(ChildRole.Worker)).Any(target => !credentials.IsConfigured(target)))
{
return SupervisorState.StartupFailed;
}
EnsureAdminPepper();
var node = Path.Combine(AppContext.BaseDirectory, "runtime", "node.exe");
var apiEntry = Path.Combine(AppContext.BaseDirectory, "server", "api.mjs");
var workerEntry = Path.Combine(AppContext.BaseDirectory, "server", "worker.mjs");
if (!File.Exists(node) || !File.Exists(apiEntry) || !File.Exists(workerEntry)) return SupervisorState.StartupFailed;
api = CreateComponent(node, apiEntry, ChildRole.Api, SupervisorState.ApiDegraded);
await api.StartAsync(cancellationToken);
try
{
api = CreateComponent(node, apiEntry, ChildRole.Api, SupervisorState.ApiDegraded);
await api.StartAsync(cancellationToken);
worker = CreateComponent(node, workerEntry, ChildRole.Worker, SupervisorState.WorkerDegraded);
await worker.StartAsync(cancellationToken);
return TryLog(new StructuredLogEvent("ready", ErrorCategory: "none")) ? SupervisorState.Ready : SupervisorState.StorageUnavailable;
worker = CreateComponent(node, workerEntry, ChildRole.Worker, SupervisorState.WorkerDegraded);
await worker.StartAsync(cancellationToken);
return TryLog(new StructuredLogEvent("ready", ErrorCategory: "none")) ? SupervisorState.Ready : SupervisorState.StorageUnavailable;
}
catch
{
await StopComponentsAsync();
return TryLog(new StructuredLogEvent("failed", ErrorCategory: "service_unavailable"))
? SupervisorState.StartupFailed
: SupervisorState.StorageUnavailable;
}
}
internal static void EnsureRuntimeDirectories(string dataRoot)
{
foreach (var directory in RequiredDataDirectories)
{
Directory.CreateDirectory(Path.Combine(dataRoot, directory));
}
}
private void EnsureAdminPepper()
{
if (credentials.IsConfigured(CredentialCatalog.AdminPepper)) return;
var pepper = Convert.ToBase64String(RandomNumberGenerator.GetBytes(32));
credentials.Write(CredentialCatalog.AdminPepper, pepper);
Array.Clear(System.Text.Encoding.UTF8.GetBytes(pepper));
}
private ManagedComponentSupervisor CreateComponent(string node, string entry, ChildRole role, SupervisorState degradedState)
@@ -60,6 +98,7 @@ internal sealed class SupervisorRuntime : IAsyncDisposable
startInfo.WorkingDirectory = AppContext.BaseDirectory;
startInfo.Environment["DADA_SQLITE_NATIVE_BINDING"] = Path.Combine(AppContext.BaseDirectory, "server", "native", "better_sqlite3.node");
startInfo.Environment["DADA_SUPPORT_GATE_ROOT"] = Path.Combine(AppContext.BaseDirectory, "web", "support-gate");
startInfo.Environment["DADA_WEB_ROOT"] = Path.Combine(AppContext.BaseDirectory, "web");
startInfo.Environment["DADA_INSTANCE_CONFIG_PATH"] = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "Dada", "P0A", "config", "instance.json");
startInfo.ArgumentList.Add(entry);
var child = await ManagedChildProcess.StartAsync(startInfo, role, credentials, cancellationToken);
@@ -95,10 +134,26 @@ internal sealed class SupervisorRuntime : IAsyncDisposable
}
public async ValueTask DisposeAsync()
{
await StopComponentsAsync();
}
private async Task StopComponentsAsync()
{
var stops = new List<Task>();
if (worker is not null) stops.Add(worker.DisposeAsync().AsTask());
if (api is not null) stops.Add(api.DisposeAsync().AsTask());
await Task.WhenAll(stops);
try
{
await Task.WhenAll(stops);
}
catch
{
}
finally
{
worker = null;
api = null;
}
}
}
@@ -1,3 +1,4 @@
using System.ComponentModel;
using System.Diagnostics;
using Microsoft.Win32;
@@ -13,10 +14,20 @@ internal static class SupportedBrowserLauncher
{
var executable = FindExecutable(executableName);
if (executable is null) return false;
var startInfo = new ProcessStartInfo(executable) { UseShellExecute = false };
startInfo.ArgumentList.Add(uri.AbsoluteUri);
Process.Start(startInfo);
return true;
try
{
var startInfo = new ProcessStartInfo(executable) { UseShellExecute = false };
startInfo.ArgumentList.Add(uri.AbsoluteUri);
return Process.Start(startInfo) is not null;
}
catch (Win32Exception)
{
return false;
}
catch (InvalidOperationException)
{
return false;
}
}
private static string? FindExecutable(string executableName)
@@ -0,0 +1,100 @@
import { readFileSync } from "node:fs";
import { describe, expect, it } from "vitest";
import { GenerationModelConfigurationCatalog, type ModelConfigurationView } from "../../apps/api/src/model-configuration.js";
describe("POSTV1-04 generation runtime wiring", () => {
it("constructs, injects and closes the production generation submission service", () => {
const main = readFileSync("apps/api/src/main.ts", "utf8");
expect(main).toContain('import { GenerationSubmissionService } from "./generation-submission.js";');
expect(main).toContain("let generations: GenerationSubmissionService | undefined;");
expect(main).toContain("generations = new GenerationSubmissionService({");
expect(main).toContain("models: new GenerationModelConfigurationCatalog(models),");
expect(main).toContain("...(generations ? { generations } : {}),");
expect(main).toContain("generations?.close();");
});
it("maps the current model configuration into the generation submission contract", () => {
const configuration: ModelConfigurationView = {
config_set_version: 7,
configured_default_model_id: "gemini-3.1-flash-image-preview",
recommended_model_id: "gemini-3.1-flash-image-preview",
models: [{
config_version: 3,
contract_evidence_ref: "fixture-contract",
contract_validation_status: "verified",
credit_cost: 2,
display_name: "Fixture model",
enabled: true,
error_mapping_profile: {},
gateway_account_ref: "fixture-gateway",
is_default: true,
model_id: "gemini-3.1-flash-image-preview",
prompt_max_length: 1_000,
recommendation_priority: 1,
reference_limits: { max_file_bytes: 10, max_files: 2, max_total_bytes: 20 },
route_profile: {},
runtime_availability: { available_for_new_jobs: true, checked_at: "2026-08-05T00:00:00.000Z", reason: "available" },
safety_source: "provider",
supported_ratios: ["3:4", "invalid"],
}],
};
const catalog = new GenerationModelConfigurationCatalog({ read: () => configuration });
expect(catalog.readModel("gemini-3.1-flash-image-preview")).toEqual({
configSetVersion: 7,
configVersion: 3,
contractValidationStatus: "verified",
creditCost: 2,
enabled: true,
modelId: "gemini-3.1-flash-image-preview",
promptMaxLength: 1_000,
referenceLimits: { maxFileBytes: 10, maxFiles: 2, maxTotalBytes: 20 },
runtimeAvailability: { availableForNewJobs: true, reason: null },
supportedRatios: ["3:4"],
});
expect(catalog.readModel("missing")).toBeUndefined();
});
it("maps model and contract blocks into generation error categories", () => {
const configuration = {
config_set_version: 1,
configured_default_model_id: "gemini-3.1-flash-image-preview",
recommended_model_id: null,
models: [],
} satisfies ModelConfigurationView;
const catalog = new GenerationModelConfigurationCatalog({ read: () => configuration });
const base = {
config_version: 1,
contract_evidence_ref: null,
contract_validation_status: "verified" as const,
credit_cost: 1,
display_name: "Fixture model",
enabled: true,
error_mapping_profile: {},
gateway_account_ref: "fixture-gateway",
is_default: true,
model_id: "gemini-3.1-flash-image-preview" as const,
prompt_max_length: 1_000,
recommendation_priority: 1,
reference_limits: { max_file_bytes: 10, max_files: 2, max_total_bytes: 20 },
route_profile: {},
safety_source: "provider",
supported_ratios: ["3:4"],
};
configuration.models = [{
...base,
runtime_availability: { available_for_new_jobs: false, checked_at: "2026-08-05T00:00:00.000Z", reason: "contract_blocked" },
}];
expect(catalog.readModel(base.model_id)?.runtimeAvailability.reason).toBe("gateway_contract_invalid");
configuration.models = [{
...base,
runtime_availability: { available_for_new_jobs: false, checked_at: "2026-08-05T00:00:00.000Z", reason: "worker_degraded" },
}];
expect(catalog.readModel(base.model_id)?.runtimeAvailability.reason).toBe("model_disabled");
});
});
@@ -0,0 +1,95 @@
import { mkdtempSync, rmSync } from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { afterEach, describe, expect, it } from "vitest";
import { createApp } from "../../apps/api/src/app.js";
import { RegistrationService } from "../../apps/api/src/registration.js";
import { MockResendAdapter } from "../../apps/api/src/resend-adapter.js";
const fixedNow = Date.parse("2026-08-05T06:00:00.000Z");
const writeHeaders = { host: "127.0.0.1:43121", origin: "http://127.0.0.1:43121" };
const roots: string[] = [];
const services: RegistrationService[] = [];
function createRegistrationService() {
const root = mkdtempSync(join(tmpdir(), "dada-local-test-session-"));
roots.push(root);
const registration = new RegistrationService({
challengePepper: Buffer.alloc(32, 0x51),
clock: () => fixedNow,
currentPrivacyNoticeVersion: "p0a-notice-v1",
databasePath: join(root, "dada.sqlite3"),
invitePepper: Buffer.alloc(32, 0x52),
resend: new MockResendAdapter(),
sessionPepper: Buffer.alloc(32, 0x53),
});
services.push(registration);
return registration;
}
afterEach(() => {
for (const service of services.splice(0)) {
try { service.close(); } catch { /* already closed by the test */ }
}
for (const root of roots.splice(0)) rmSync(root, { force: true, recursive: true });
});
describe("POSTV1-03 local test session", () => {
it("does not expose the local test route unless explicitly enabled", async () => {
const registration = createRegistrationService();
const app = await createApp({ browserGate: false, networkBoundary: { allowTestPort: true }, registration });
const status = await app.inject({ headers: writeHeaders, method: "GET", url: "/api/v1/auth/local-test" });
const created = await app.inject({ headers: writeHeaders, method: "POST", url: "/api/v1/auth/local-test" });
expect(status.statusCode).toBe(404);
expect(created.statusCode).toBe(404);
await app.close();
});
it("creates one isolated fixture account and restores it without duplicate credits", async () => {
const registration = createRegistrationService();
const app = await createApp({
browserGate: false,
localTestAuth: true,
networkBoundary: { allowTestPort: true },
registration,
});
const status = await app.inject({ headers: writeHeaders, method: "GET", url: "/api/v1/auth/local-test" });
expect(status.statusCode).toBe(200);
expect(status.json()).toEqual({ available: true });
const first = await app.inject({ headers: writeHeaders, method: "POST", url: "/api/v1/auth/local-test" });
expect(first.statusCode).toBe(200);
expect(first.json()).toMatchObject({
audience: "user",
credits: { available_balance: 10, reserved_balance: 0 },
status: "authenticated",
user: { creator_name: "本机测试用户", role: "user", social_id: "@dada_local_test", status: "active" },
});
expect(first.headers["set-cookie"]).toContain("dada_session=");
const session = await app.inject({
headers: { cookie: first.headers["set-cookie"], host: "127.0.0.1:43121" },
method: "GET",
url: "/api/v1/auth/session",
});
expect(session.statusCode).toBe(200);
expect(session.json()).toMatchObject({ authenticated: true, credits: { available_balance: 10 } });
const second = await app.inject({ headers: writeHeaders, method: "POST", url: "/api/v1/auth/local-test" });
expect(second.statusCode).toBe(200);
expect(second.json().user.user_id).toBe(first.json().user.user_id);
expect(registration.database.prepare("SELECT COUNT(*) AS count FROM users").get()).toEqual({ count: 1 });
expect(registration.database.prepare("SELECT COUNT(*) AS count FROM credit_ledger").get()).toEqual({ count: 1 });
expect(registration.database.prepare("SELECT counts_toward_stage_limit FROM users").get()).toEqual({ counts_toward_stage_limit: 0 });
const openapi = JSON.stringify(app.swagger());
expect(openapi).not.toContain("/api/v1/auth/local-test");
expect(openapi).not.toContain("local-test-user");
await app.close();
});
});
+67
View File
@@ -0,0 +1,67 @@
import { createHash } from "node:crypto";
import { mkdirSync, mkdtempSync, rmSync, writeFileSync } from "node:fs";
import { tmpdir } from "node:os";
import { join, resolve } from "node:path";
import { afterEach, describe, expect, it } from "vitest";
import { loadConfiguredRuntimeAssets } from "../../apps/api/src/runtime-assets.js";
const temporaryDirectories: string[] = [];
afterEach(() => {
for (const directory of temporaryDirectories.splice(0)) {
if (resolve(directory).startsWith(resolve(tmpdir()))) rmSync(directory, { force: true, recursive: true });
}
});
function fixture() {
const base = mkdtempSync(join(tmpdir(), "dada-postv1-assets-"));
temporaryDirectories.push(base);
const assetRoot = join(base, "assets");
const dataRoot = join(base, "data");
const configFile = join(base, "instance.json");
const trustedManifestPath = join(base, "trusted-manifest.json");
const bytes = Buffer.from("synthetic sticker bytes");
const entry = {
assetId: "STK001",
mimeType: "image/png",
relativePath: "p0a-static-v1/STK001.png",
resourceVersion: "p0a-static-v1",
rootRef: "p0a_runtime_assets",
sha256: createHash("sha256").update(bytes).digest("hex"),
};
const manifest = {
counts: { dynamic_fonts: 0, dynamic_images: 0, font_panel_items: 0, static_stickers: 1 },
entries: [entry],
root_ref: "p0a_runtime_assets",
schema_version: "DadaRuntimeAssets/v1",
source: "external_read_only",
};
mkdirSync(join(assetRoot, "p0a-static-v1"), { recursive: true });
writeFileSync(join(assetRoot, entry.relativePath), bytes);
writeFileSync(join(assetRoot, "manifest.json"), `${JSON.stringify(manifest, null, 2)}\n`);
writeFileSync(trustedManifestPath, `${JSON.stringify(manifest, null, 2)}\n`);
writeFileSync(configFile, JSON.stringify({ asset_root: assetRoot }));
return { assetRoot, configFile, dataRoot, trustedManifestPath };
}
describe("POSTV1-06 portable runtime assets", () => {
it("activates a validated external asset root without exposing its path", () => {
const input = fixture();
const loaded = loadConfiguredRuntimeAssets(input);
expect(loaded.state).toMatchObject({ configured: true, pause_reason: null, status: "active" });
expect(loaded.publicAssets?.read("p0a-static-v1", "STK001")?.bytes.toString()).toBe("synthetic sticker bytes");
expect(JSON.stringify(loaded.state)).not.toContain(input.assetRoot);
});
it("rejects a changed external manifest and leaves unrelated API features available", () => {
const input = fixture();
writeFileSync(join(input.assetRoot, "manifest.json"), "{}\n");
const loaded = loadConfiguredRuntimeAssets(input);
expect(loaded.publicAssets).toBeUndefined();
expect(loaded.state).toMatchObject({ configured: true, pause_reason: "asset_manifest_invalid", status: "unavailable" });
});
});
+44
View File
@@ -0,0 +1,44 @@
import { createRequire } from "node:module";
import { describe, expect, it } from "vitest";
import {
ModelConfigurationService,
portableRuntimeModelCandidates,
} from "../../apps/api/src/model-configuration.js";
const requireFromApi = createRequire(new URL("../../apps/api/package.json", import.meta.url));
const Database = requireFromApi("better-sqlite3") as new (path: string) => {
close(): void;
};
describe("POSTV1-02 portable runtime model seed", () => {
it("enables only models backed by the real OneAPI contract", () => {
const database = new Database(":memory:");
try {
const models = new ModelConfigurationService({ database, seedCandidates: portableRuntimeModelCandidates }).read();
const flash = models.models.find((model) => model.model_id === "gemini-3.1-flash-image-preview");
const pro = models.models.find((model) => model.model_id === "gemini-3-pro-image-preview");
const gpt = models.models.find((model) => model.model_id === "gpt-image-2");
expect(models.configured_default_model_id).toBe("gemini-3.1-flash-image-preview");
expect(flash).toMatchObject({
contract_validation_status: "verified",
enabled: true,
runtime_availability: { available_for_new_jobs: true, reason: "available" },
});
expect(flash?.route_profile).toMatchObject({ endpoint: "https://oneapi.intelligrow.cn/v1/chat/completions" });
expect(pro).toMatchObject({
contract_validation_status: "unverified",
enabled: false,
runtime_availability: { available_for_new_jobs: false, reason: "configured_disabled" },
});
expect(gpt).toMatchObject({
contract_validation_status: "verified",
enabled: true,
runtime_availability: { available_for_new_jobs: true, reason: "available" },
});
} finally {
database.close();
}
});
});
+14 -1
View File
@@ -125,7 +125,12 @@ afterAll(async () => {
describe("TDD-WP0-BRW-001 supported browser contract", () => {
it("cross-checks UA-CH and issues only a short-lived signed support cookie", async () => {
const app = await createApp({ browserSupportRelease: testBrowserSupportRelease } as never);
const app = await createApp({
browserSupportRelease: testBrowserSupportRelease,
productIndexHtml: "<!doctype html><title>Dada product test</title><div id=\"root\"></div>",
} as never);
const gate = await app.inject({ headers: { host: "127.0.0.1:43121" }, method: "GET", url: "/" });
expect(gate.body).toContain("当前浏览器无法使用 Dada");
const checked = await app.inject({
headers: supportedEdge.headers,
method: "POST",
@@ -150,6 +155,14 @@ describe("TDD-WP0-BRW-001 supported browser contract", () => {
const cookie = supportCookie(checked);
expect(cookie).toBeDefined();
const productHtml = await app.inject({
headers: { cookie, host: "127.0.0.1:43121", "sec-ch-ua": supportedEdge.headers["sec-ch-ua"] },
method: "GET",
url: "/app",
});
expect(productHtml.statusCode).toBe(200);
expect(productHtml.body).toContain("Dada product test");
expect(productHtml.body).not.toContain("当前浏览器无法使用 Dada");
const product = await app.inject({
headers: {
cookie,
+1 -1
View File
@@ -26,7 +26,7 @@ describe("TDD-WP0-DATA-001-root-validation resource boundary", () => {
const assetRoot = join(base, "read-only-assets");
const relativePath = "images/source.png";
const bytes = Buffer.from("synthetic png fixture");
const assetId = randomUUID();
const assetId = "STK001";
mkdirSync(join(assetRoot, "images"), { recursive: true });
writeFileSync(join(assetRoot, relativePath), bytes);
const manifest = JSON.stringify({ assets: [{ asset_id: assetId, relative_path: relativePath }] });
@@ -0,0 +1,62 @@
import { describe, expect, it, vi } from "vitest";
import { RealAmapAdapter } from "../../apps/api/src/amap-adapter.js";
import { initializeApiCredentialClients } from "../../apps/api/src/supervisor-channel.js";
describe("TDD-WP7-EXT-003 production Amap adapter", () => {
it("uses the fixed HTTPS provider boundary and returns only the formatted location", async () => {
const request = vi.fn(async () => ({
regeocode: { formatted_address: "模拟省模拟市" },
status: "1",
}));
const adapter = new RealAmapAdapter("fixture-amap-value", { request });
await expect(adapter.reverseGeocode({ latitude: 12.3456, longitude: 65.4321 })).resolves.toEqual({
formattedValue: "模拟省模拟市",
serviceMode: "real",
});
expect(request).toHaveBeenCalledOnce();
expect(request.mock.calls[0]?.[0]).toMatchObject({
allowRedirects: false,
hostname: "restapi.amap.com",
maxResponseBytes: 65_536,
method: "GET",
protocol: "https:",
rejectUnauthorized: true,
timeoutMs: 15_000,
});
expect(request.mock.calls[0]?.[0].path).toContain("/v3/geocode/regeo?");
expect(request.mock.calls[0]?.[0].path).toContain("location=65.4321%2C12.3456");
adapter.dispose();
await expect(adapter.reverseGeocode({ latitude: 0, longitude: 0 })).rejects.toThrow("amap_adapter_disposed");
});
it("constructs the real client from the API credential channel and clears the source values", () => {
const credentials = {
"Dada/P0A/admin/pepper": "fixture-admin-value",
"Dada/P0A/api/amap": "fixture-amap-value",
"Dada/P0A/api/resend": "fixture-resend-value",
};
const clients = initializeApiCredentialClients(credentials);
expect(clients.amap).toBeInstanceOf(RealAmapAdapter);
expect(clients.resendConfigured).toBe(true);
expect(Object.values(credentials)).toEqual(["", "", ""]);
clients.amap.dispose?.();
clients.adminAllowlistPepper.fill(0);
});
it("reports an empty Resend credential without retaining its value", () => {
const credentials = {
"Dada/P0A/admin/pepper": "fixture-admin-value",
"Dada/P0A/api/amap": "",
"Dada/P0A/api/resend": "",
};
const clients = initializeApiCredentialClients(credentials);
expect(clients.resendConfigured).toBe(false);
expect(Object.values(credentials)).toEqual(["", "", ""]);
clients.amap.dispose?.();
clients.adminAllowlistPepper.fill(0);
});
});
@@ -0,0 +1,85 @@
import { randomUUID } from "node:crypto";
import { mkdtempSync, rmSync } from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { afterEach, describe, expect, it } from "vitest";
import { MockAmapAdapter } from "../../apps/api/src/amap-adapter.js";
import { createApp } from "../../apps/api/src/app.js";
import { RegistrationService } from "../../apps/api/src/registration.js";
import { MockResendAdapter } from "../../apps/api/src/resend-adapter.js";
const roots: string[] = [];
const registrations: RegistrationService[] = [];
afterEach(() => {
for (const registration of registrations.splice(0)) registration.close();
for (const root of roots.splice(0)) rmSync(root, { force: true, recursive: true });
});
function createRegistration() {
const now = Date.parse("2026-08-04T09:00:00.000Z");
const root = mkdtempSync(join(tmpdir(), "dada-wp7-04-amap-"));
roots.push(root);
const registration = new RegistrationService({
challengePepper: Buffer.alloc(32, 0xa1),
clock: () => now,
currentPrivacyNoticeVersion: "p0a-registration-notice-v1",
databasePath: join(root, "dada.sqlite3"),
invitePepper: Buffer.alloc(32, 0xa2),
resend: new MockResendAdapter(),
sessionPepper: Buffer.alloc(32, 0xa3),
});
registrations.push(registration);
const userId = randomUUID();
registration.database.prepare(`
INSERT INTO users (user_id, normalized_email, role, status, counts_toward_stage_limit, registration_id, created_at)
VALUES (?, ?, 'user', 'active', 1, ?, ?)
`).run(userId, `${userId}@example.invalid`, randomUUID(), now);
registration.database.prepare("INSERT INTO user_profiles (user_id, creator_name, social_id) VALUES (?, 'Release Gate User', '@release_gate')").run(userId);
registration.database.prepare("INSERT INTO credit_accounts (user_id, available_balance, reserved_balance, updated_at) VALUES (?, 10, 0, ?)").run(userId, now);
return { registration, session: registration.issueAuthenticatedSession(userId, "user") };
}
describe("TDD-WP7-EXT-003 Amap release hard stop", () => {
it("admits the simulated 1000th request and blocks the 1001st before provider egress", async () => {
const { registration, session } = createRegistration();
registration.database.prepare(`
UPDATE external_service_usage
SET used_count = 999, service_status = 'active', pause_reason = NULL
WHERE service_id = 'amap_web_service' AND period_type = 'monthly'
`).run();
const amap = new MockAmapAdapter();
const app = await createApp({ amap, browserGate: false, networkBoundary: { allowTestPort: true }, registration });
const headers = {
cookie: `dada_session=${session.sessionToken}`,
host: "127.0.0.1:43121",
origin: "http://127.0.0.1:43121",
"x-csrf-token": registration.issueUserCsrfToken(session.sessionToken),
};
const thousandth = await app.inject({
headers,
method: "POST",
payload: { latitude: 0, longitude: 0 },
url: "/api/v1/location/reverse-geocode",
});
const thousandAndFirst = await app.inject({
headers,
method: "POST",
payload: { latitude: 0, longitude: 0 },
url: "/api/v1/location/reverse-geocode",
});
expect(thousandth.statusCode).toBe(200);
expect(thousandAndFirst.statusCode).toBe(503);
expect(amap.calls).toHaveLength(1);
expect(registration.serviceUsage.read("amap_web_service")).toEqual([
expect.objectContaining({ hardLimit: 1_000, status: "paused_quota", usedCount: 1_000 }),
]);
await app.close();
});
});
+23
View File
@@ -23,6 +23,29 @@ test.beforeAll(async () => {
test.afterAll(async () => vite.close());
test("POSTV1-03 enters the workspace through the local test session", async ({ page }) => {
await page.route("**/api/v1/auth/local-test", (route) => {
if (route.request().method() === "GET") {
return route.fulfill({ contentType: "application/json", status: 200, body: JSON.stringify({ available: true }) });
}
expect(route.request().postData()).toBeNull();
return route.fulfill({ contentType: "application/json", status: 200, body: JSON.stringify({ status: "authenticated" }) });
});
await page.goto(webUrl);
const button = page.getByRole("button", { name: "直接进入本机测试" });
await expect(button).toBeVisible();
await button.click();
await expect(page).toHaveURL(`${webUrl}/app`);
});
test("POSTV1-03 hides the local test entry when the API does not enable it", async ({ page }) => {
await page.route("**/api/v1/auth/local-test", (route) => route.fulfill({ status: 404, body: "" }));
await page.goto(webUrl);
await expect(page.getByRole("button", { name: "直接进入本机测试" })).toHaveCount(0);
});
test("TDD-WP1-NOTICE-001 expands DVPM8 only after successful code delivery", async ({ page }) => {
await page.route("**/api/v1/auth/register/send", (route) => route.fulfill({
contentType: "application/json",
@@ -22,6 +22,7 @@ import {
defaultLocalDataRoot,
initializeLocalDataRoot,
inspectInitializedLocalDataRoot,
readConfiguredAssetRoot,
resolvePathWithinRoot,
validateLocalDataRoot,
validateReadOnlyAssetRoot,
@@ -66,6 +67,17 @@ afterEach(() => {
});
describe("TDD-WP0-DATA-001-root-validation", () => {
it("reads only an absolute configured read-only asset root", () => {
const base = temporaryDirectory();
const configFile = join(base, "instance.json");
const assetRoot = join(base, "runtime-assets");
writeFileSync(configFile, JSON.stringify({ asset_root: assetRoot }));
expect(readConfiguredAssetRoot(configFile)).toBe(resolve(assetRoot));
writeFileSync(configFile, JSON.stringify({ asset_root: "relative-assets" }));
expect(() => readConfiguredAssetRoot(configFile)).toThrow("asset_root_configuration_invalid");
});
it("derives default data and configuration paths from LOCALAPPDATA without a hardcoded user", () => {
const localAppData = join(temporaryDirectory(), "LocalAppData");
expect(defaultLocalDataRoot({ LOCALAPPDATA: localAppData })).toBe(join(localAppData, "Dada", "P0A", "data"));
@@ -0,0 +1,86 @@
import assert from "node:assert/strict";
import { createHash } from "node:crypto";
import { mkdir, mkdtemp, readFile, rm, stat, writeFile } from "node:fs/promises";
import { tmpdir } from "node:os";
import { join } from "node:path";
import test from "node:test";
import {
createRuntimeAssetManifest,
deployRuntimeAssetPlan,
readRuntimeAssetManifest,
serializeRuntimeAssetManifest,
} from "../../scripts/lib/runtime-assets.mjs";
test("committed P0-A runtime manifest covers the frozen first-version binary assets", () => {
const manifest = readRuntimeAssetManifest("config/runtime-assets-manifest.json");
assert.deepEqual(manifest.counts, {
dynamic_fonts: 7,
dynamic_images: 8,
font_panel_items: 11,
static_stickers: 1407,
});
assert.equal(manifest.entries.length, 1433);
assert.doesNotMatch(serializeRuntimeAssetManifest(manifest), /[A-Za-z]:[\\/]/);
});
test("runtime asset deployment creates verified hardlinks and a path-free manifest", async (t) => {
const root = await mkdtemp(join(tmpdir(), "dada-runtime-assets-"));
t.after(() => rm(root, { force: true, recursive: true }));
const sourceRoot = join(root, "source");
const assetRoot = join(root, "assets");
const sourcePath = join(sourceRoot, "sticker.png");
const bytes = Buffer.from("runtime asset fixture");
await mkdir(sourceRoot);
await writeFile(sourcePath, bytes);
const entry = {
assetId: "STK001",
mimeType: "image/png",
relativePath: "p0a-static-v1/STK001.png",
resourceVersion: "p0a-static-v1",
rootRef: "p0a_runtime_assets",
sha256: createHash("sha256").update(bytes).digest("hex"),
};
const manifest = createRuntimeAssetManifest({
counts: { dynamic_fonts: 0, dynamic_images: 0, font_panel_items: 0, static_stickers: 1 },
entries: [entry],
});
await deployRuntimeAssetPlan({ assetRoot, manifest, resources: [{ entry, sourcePath }] });
const targetPath = join(assetRoot, entry.relativePath);
const [sourceStat, targetStat] = await Promise.all([stat(sourcePath), stat(targetPath)]);
assert.equal(sourceStat.ino, targetStat.ino);
assert.deepEqual(await readFile(targetPath), bytes);
const writtenManifest = await readFile(join(assetRoot, "manifest.json"), "utf8");
assert.deepEqual(JSON.parse(writtenManifest), manifest);
assert.doesNotMatch(writtenManifest, /[A-Za-z]:[\\/]/);
});
test("runtime asset deployment refuses a mismatched existing target", async (t) => {
const root = await mkdtemp(join(tmpdir(), "dada-runtime-assets-conflict-"));
t.after(() => rm(root, { force: true, recursive: true }));
const sourcePath = join(root, "source.png");
const assetRoot = join(root, "assets");
const targetPath = join(assetRoot, "p0a-static-v1", "STK001.png");
await mkdir(join(assetRoot, "p0a-static-v1"), { recursive: true });
await writeFile(sourcePath, "expected");
await writeFile(targetPath, "unexpected");
const entry = {
assetId: "STK001",
mimeType: "image/png",
relativePath: "p0a-static-v1/STK001.png",
resourceVersion: "p0a-static-v1",
rootRef: "p0a_runtime_assets",
sha256: createHash("sha256").update("expected").digest("hex"),
};
const manifest = createRuntimeAssetManifest({
counts: { dynamic_fonts: 0, dynamic_images: 0, font_panel_items: 0, static_stickers: 1 },
entries: [entry],
});
assert.throws(
() => deployRuntimeAssetPlan({ assetRoot, manifest, resources: [{ entry, sourcePath }] }),
/asset_target_conflict/,
);
});
+175
View File
@@ -0,0 +1,175 @@
import test from "node:test";
import assert from "node:assert/strict";
import { mkdtemp, readFile, rm, writeFile } from "node:fs/promises";
import { existsSync } from "node:fs";
import { join, resolve } from "node:path";
import { tmpdir } from "node:os";
import { spawn } from "node:child_process";
import { createServer } from "node:net";
const packageRoot = resolve(process.env.DADA_POSTV1_PACKAGE_ROOT ?? ".build/portable-release/Dada-P0A-0.0.0-win-x64");
const port = 43121;
async function waitForHealth(child) {
const deadline = Date.now() + 15_000;
while (Date.now() < deadline) {
if (child.exitCode !== null) throw new Error(`packaged api exited: ${child.exitCode}: ${child.errorOutput ?? ""}`);
try {
const response = await fetch(`http://127.0.0.1:${port}/healthz`, { headers: { host: `127.0.0.1:${port}` } });
if (response.ok) return;
} catch {}
await new Promise((resolveDelay) => setTimeout(resolveDelay, 100));
}
throw new Error("packaged api health timeout");
}
function startApi(configPath, dataRoot) {
const child = spawn(join(packageRoot, "runtime", "node.exe"), [join(packageRoot, "server", "api.mjs"), "--dada-credential-stdin"], {
cwd: packageRoot,
env: { ...process.env, DADA_INSTANCE_CONFIG_PATH: configPath, DADA_SUPPORT_GATE_ROOT: join(packageRoot, "web", "support-gate"), DADA_WEB_ROOT: join(packageRoot, "web") },
stdio: ["pipe", "ignore", "pipe"],
windowsHide: true,
});
child.errorOutput = "";
child.stderr.setEncoding("utf8");
child.stderr.on("data", (chunk) => { child.errorOutput += chunk; });
child.stdin.end(JSON.stringify({ "Dada/P0A/api/amap": "", "Dada/P0A/api/resend": "", "Dada/P0A/admin/pepper": "portable-test-pepper-00000000000000000000000000000000" }));
return child;
}
async function stop(child) {
if (child.exitCode === null) {
child.kill();
await new Promise((resolveExit) => child.once("exit", resolveExit));
}
}
async function verifyWorkerStartup(configPath) {
const pipeName = `Dada.P0A.PostV1.${process.pid}.${Date.now()}`;
const pipePath = `\\\\.\\pipe\\${pipeName}`;
const server = createServer();
await new Promise((resolveListen, rejectListen) => {
server.once("error", rejectListen);
server.listen(pipePath, resolveListen);
});
const child = spawn(join(packageRoot, "runtime", "node.exe"), [
join(packageRoot, "server", "worker.mjs"),
"--dada-control-pipe", pipeName,
"--dada-credential-stdin",
], {
cwd: packageRoot,
env: {
...process.env,
DADA_INSTANCE_CONFIG_PATH: configPath,
DADA_SQLITE_NATIVE_BINDING: join(packageRoot, "server", "native", "better_sqlite3.node"),
},
stdio: ["pipe", "ignore", "ignore"],
windowsHide: true,
});
child.stdin.end(JSON.stringify({ "Dada/P0A/worker/ai-gateway": "synthetic-runtime-token" }));
try {
await new Promise((resolveReady, rejectReady) => {
let settled = false;
const finish = (error) => {
if (settled) return;
settled = true;
clearTimeout(deadline);
child.off("exit", onExit);
if (error) rejectReady(error); else resolveReady();
};
const deadline = setTimeout(() => finish(new Error("packaged worker ready timeout")), 15_000);
const onExit = (code) => finish(new Error(`packaged worker exited before ready: ${code}`));
child.once("exit", onExit);
server.once("connection", (connection) => {
connection.setEncoding("utf8");
let pending = "";
connection.on("data", (chunk) => {
pending += chunk;
while (pending.includes("\n")) {
const newline = pending.indexOf("\n");
const status = pending.slice(0, newline).trim();
pending = pending.slice(newline + 1);
if (status === "storage_unavailable") finish(new Error("packaged worker reported storage_unavailable"));
if (status === "ready") {
setTimeout(() => {
if (settled) return;
connection.write("shutdown\n");
finish();
}, 500);
}
}
});
});
});
const exitCode = await new Promise((resolveExit) => child.once("exit", resolveExit));
assert.equal(exitCode, 0);
} finally {
if (child.exitCode === null) child.kill();
await new Promise((resolveClose) => server.close(resolveClose));
}
}
test("portable package serves the product and keeps SQLite data across API restart", async () => {
assert.ok(existsSync(join(packageRoot, "Dada.exe")));
assert.ok(existsSync(join(packageRoot, "web", "index.html")));
const runtimeAssetManifest = JSON.parse(await readFile(join(packageRoot, "asset-metadata", "manifest.json"), "utf8"));
assert.deepEqual(runtimeAssetManifest.counts, {
dynamic_fonts: 7,
dynamic_images: 8,
font_panel_items: 11,
static_stickers: 1407,
});
assert.equal(runtimeAssetManifest.entries.length, 1433);
const packagedWorker = await readFile(join(packageRoot, "server", "worker", "dist", "worker.js"), "utf8");
const packagedOneApiAdapter = await readFile(join(packageRoot, "server", "worker", "dist", "oneapi-generation-adapter.js"), "utf8");
assert.match(packagedWorker, /GenerationProcessor/);
assert.match(packagedWorker, /OneApiGenerationAdapter/);
assert.match(packagedOneApiAdapter, /oneapi\.intelligrow\.cn/);
assert.doesNotMatch(packagedWorker, /portable-mock-worker/);
const root = await mkdtemp(join(tmpdir(), "dada-postv1-"));
const dataRoot = join(root, "data");
const configPath = join(root, "instance.json");
await writeFile(configPath, JSON.stringify({ data_root: dataRoot, initialized: true, instance_id: "portable-test", schema_version: 1, secure_config_revision: 1, admin_allowlist_hashes: [], admin_recovery_hashes: [] }));
let api = startApi(configPath, dataRoot);
try {
await waitForHealth(api);
const initialPage = await fetch(`http://127.0.0.1:${port}/`, { headers: { host: `127.0.0.1:${port}` } });
assert.equal(initialPage.status, 200);
assert.match(await initialPage.text(), /当前浏览器无法使用 Dada/);
const support = await fetch(`http://127.0.0.1:${port}/api/v1/support/check`, {
method: "POST",
headers: { host: `127.0.0.1:${port}`, origin: `http://127.0.0.1:${port}`, "content-type": "application/json", "sec-ch-ua": '"Google Chrome";v="150"', "sec-ch-ua-full-version-list": '"Google Chrome";v="150.0.0.0"', "sec-ch-ua-platform": '"Windows"' },
body: JSON.stringify({ brands: [{ brand: "Google Chrome", version: "150" }], full_version_list: [{ brand: "Google Chrome", version: "150.0.0.0" }], platform: "Windows" }),
});
assert.equal(support.status, 200);
const cookie = support.headers.get("set-cookie")?.split(";", 1)[0];
assert.ok(cookie);
const page = await fetch(`http://127.0.0.1:${port}/app`, { headers: { host: `127.0.0.1:${port}`, cookie, "sec-ch-ua": '"Google Chrome";v="150"' } });
assert.equal(page.status, 200);
const pageHtml = await page.text();
assert.match(pageHtml, /<div id="root"><\/div>/);
const scriptPath = pageHtml.match(/<script[^>]+src="([^"]+)"/)?.[1];
const stylesheetPath = pageHtml.match(/<link[^>]+href="([^"]+)"/)?.[1];
assert.ok(scriptPath);
assert.ok(stylesheetPath);
const assetHeaders = { host: `127.0.0.1:${port}`, cookie, "sec-ch-ua": '"Google Chrome";v="150"' };
const script = await fetch(`http://127.0.0.1:${port}${scriptPath}`, { headers: assetHeaders });
const stylesheet = await fetch(`http://127.0.0.1:${port}${stylesheetPath}`, { headers: assetHeaders });
assert.equal(script.status, 200);
assert.match(script.headers.get("content-type") ?? "", /^(?:application|text)\/javascript\b/);
assert.equal(stylesheet.status, 200);
assert.match(stylesheet.headers.get("content-type") ?? "", /^text\/css\b/);
assert.ok(existsSync(join(dataRoot, "db", "dada.sqlite3")));
await verifyWorkerStartup(configPath);
} finally {
await stop(api);
}
api = startApi(configPath, dataRoot);
try {
await waitForHealth(api);
assert.ok(existsSync(join(dataRoot, "db", "dada.sqlite3")));
} finally {
await stop(api);
await rm(root, { recursive: true, force: true });
}
});
+76
View File
@@ -0,0 +1,76 @@
import assert from "node:assert/strict";
import { test } from "node:test";
import {
validateAuthResult,
validateDeliverySummary,
validateDomainCheck,
validateRedaction,
} from "../../scripts/lib/resend-release-gate.mjs";
const realEvidence = {
source: "human_controlled_real",
service: "resend",
status: "verified",
schema_version: "1.0",
};
test("requires SPF, DKIM, exact free limits, and no paid fallback", () => {
assert.deepEqual(validateDomainCheck({
...realEvidence,
dkim: { status: "pass" },
domain_controlled: true,
free_rules: { daily_limit: 80, monthly_limit: 2400, paid_fallback_enabled: false, status: "verified" },
spf: { status: "pass" },
}), []);
assert.ok(validateDomainCheck({ ...realEvidence, domain_controlled: true, spf: { status: "pass" }, dkim: { status: "fail" }, free_rules: { status: "unknown" } }).includes("dkim"));
});
test("requires exactly three 20-message delivery cohorts with 19 within 120 seconds", () => {
const summary = {
...realEvidence,
categories: ["qq", "163", "enterprise"].map((category) => ({
category,
delivered_within_120_seconds: 19,
max_latency_seconds: 120,
mock_used: false,
preseeded_account_used: false,
sent_count: 20,
})),
};
assert.deepEqual(validateDeliverySummary(summary), []);
assert.ok(validateDeliverySummary({ ...summary, categories: summary.categories.map((item) => item.category === "163" ? { ...item, delivered_within_120_seconds: 18 } : item) }).some((error) => error.includes("163")));
assert.ok(validateDeliverySummary({ ...summary, categories: summary.categories.map((item) => item.category === "enterprise" ? { ...item, max_latency_seconds: undefined } : item) }).some((error) => error.includes("enterprise")));
});
test("requires formal ordinary and admin authentication chains", () => {
assert.deepEqual(validateAuthResult({
...realEvidence,
admin: { chain: "formal", status: "passed", verification_code_source: "real_delivery" },
mock_used: false,
ordinary: { chain: "formal", status: "passed", verification_code_source: "real_delivery" },
preseeded_account_used: false,
}), []);
assert.ok(validateAuthResult({ ...realEvidence, admin: { chain: "mock", status: "passed", verification_code_source: "fixture" }, ordinary: { status: "failed" } }).length > 0);
});
test("rejects credentials, mailboxes, private values, and paths from evidence", () => {
assert.deepEqual(validateRedaction({
absolute_paths_in_evidence: false,
credentials_in_evidence: false,
forbidden_matches: 0,
mailboxes_in_evidence: false,
private_content_in_evidence: false,
schema_version: "1.0",
status: "passed",
}, JSON.stringify({ category: "qq", delivered_within_120_seconds: 20 })), []);
assert.ok(validateRedaction({
absolute_paths_in_evidence: false,
credentials_in_evidence: false,
forbidden_matches: 0,
mailboxes_in_evidence: false,
private_content_in_evidence: false,
schema_version: "1.0",
status: "passed",
}, JSON.stringify({ mailbox: "recipient@example.invalid" })).includes("email_value"));
});
+41
View File
@@ -0,0 +1,41 @@
import test from 'node:test';
import assert from 'node:assert/strict';
import { buildCoverageEvidence } from '../../scripts/lib/wp7-05-coverage.mjs';
import { REQUIRED_COVERAGE_UNITS } from '../../scripts/lib/wp7-05-ui-gate.mjs';
const viewports = [
{ width: 1920, height: 1080, deviceScaleFactor: 1, zoom: 100 },
{ width: 1920, height: 1080, deviceScaleFactor: 1, zoom: 200 },
];
function completeUnits() {
return REQUIRED_COVERAGE_UNITS.map((page_id) => ({
page_id,
states: [{
state: 'normal',
screenshot_100pct: `ui/${page_id}/normal/100pct.png`,
screenshot_200pct: `ui/${page_id}/normal/200pct.png`,
trace: `ui/${page_id}/normal/trace.zip`,
}],
}));
}
test('builds ordered, sanitized evidence for all 22 coverage units', () => {
const evidence = buildCoverageEvidence({
runId: 'wp7-05-red-001',
candidateSha256: 'a'.repeat(64),
coverageUnits: completeUnits(),
viewports,
});
assert.equal(evidence.coverage_units.length, 22);
assert.equal(evidence.coverage_units[0].page_id, 'support-gate');
assert.equal(evidence.candidate_sha256, 'A'.repeat(64));
});
test('rejects absolute evidence paths and incomplete page state', () => {
const units = completeUnits();
units[0].states[0].trace = 'C:\\secret\\trace.zip';
assert.throws(() => buildCoverageEvidence({
runId: 'wp7-05-red-001', candidateSha256: 'a'.repeat(64), coverageUnits: units, viewports,
}), /WP7_05_UNSAFE_TRACE/);
});
+47
View File
@@ -0,0 +1,47 @@
import test from 'node:test';
import assert from 'node:assert/strict';
import fs from 'node:fs';
import os from 'node:os';
import path from 'node:path';
import { loadCandidateRecord, validateCoverageEvidence, runWp705Gate, REQUIRED_COVERAGE_UNITS } from '../../scripts/lib/wp7-05-ui-gate.mjs';
test('WP7-05 accepts the WP7-01 candidate record schema', () => {
const directory = fs.mkdtempSync(path.join(os.tmpdir(), 'wp7-05-'));
const file = path.join(directory, 'release-candidate.json');
fs.writeFileSync(file, JSON.stringify({
browsers: [
{ brand: 'Google Chrome', full_version: '150.0.0', major: 150 },
{ brand: 'Microsoft Edge', full_version: '151.0.0', major: 151 },
],
windows: { build: '26200.8875' },
candidate_package: { fixed_port: 43121, sha256: 'A'.repeat(64) },
}));
assert.equal(loadCandidateRecord(file).status, 'ready');
fs.rmSync(directory, { recursive: true, force: true });
});
test('WP7-05 requires all 22 coverage units and both exact candidate viewports', () => {
const result = validateCoverageEvidence({ coverage_units: [], viewports: [] });
assert.equal(result.status, 'externally_blocked');
assert.equal(result.code, 'coverage_units_incomplete');
assert.equal(result.missing.length, REQUIRED_COVERAGE_UNITS.length);
});
test('WP7-05 requires state evidence for every listed coverage unit', () => {
const result = validateCoverageEvidence({
coverage_units: REQUIRED_COVERAGE_UNITS.map((page_id) => ({ page_id, states: [] })),
viewports: [],
});
assert.equal(result.code, 'coverage_states_incomplete');
assert.equal(result.missingStates.length, REQUIRED_COVERAGE_UNITS.length);
});
test('WP7-05 preserves upstream external blockers instead of declaring Green', () => {
const result = runWp705Gate({
candidatePath: 'missing-release-candidate.json',
evidence: null,
dependencies: { 'TASK-WP7-03': 'externally_blocked' },
});
assert.equal(result.status, 'externally_blocked');
assert.equal(result.code, 'candidate_record_missing');
});
+75
View File
@@ -0,0 +1,75 @@
import assert from "node:assert/strict";
import test from "node:test";
import { buildWp706PrefreezeReport } from "../../scripts/lib/wp7-06-prefreeze.mjs";
const expectedTrace = {
errors: [],
status: "passed",
summary: {
acceptanceCriteria: 52,
errorCategories: 9,
featureModules: 13,
parentFamilies: 89,
penProductFrames: 18,
productContracts: 19,
requirements: 109,
tasks: 52,
testCases: 117,
uiPages: 22,
},
};
const upstream = {
"TASK-WP7-01": { branch: "codex/wp7-01", head: "1".repeat(40), merged: true, status: "passed" },
"TASK-WP7-02": { branch: "codex/wp7-02", head: "2".repeat(40), merged: true, status: "passed" },
"TASK-WP7-03": { branch: "codex/wp7-03", head: "3".repeat(40), merged: true, status: "deferred_nonblocking_first_version" },
"TASK-WP7-04": { branch: "codex/wp7-04", head: "4".repeat(40), merged: true, status: "deferred_nonblocking_first_version" },
"TASK-WP7-05": { branch: "codex/wp7-05", head: "5".repeat(40), merged: true, status: "passed" },
};
test("builds the exact WP7-06 pre-freeze closure without pretending deferred suppliers passed", () => {
const report = buildWp706PrefreezeReport({
currentCommit: "a".repeat(40),
releaseExists: false,
trace: expectedTrace,
upstream,
});
assert.equal(report.status, "passed");
assert.equal(report.release_json_written, false);
assert.deepEqual(report.trace_summary, expectedTrace.summary);
assert.deepEqual(report.deferred_external_tasks, ["TASK-WP7-03", "TASK-WP7-04"]);
});
test("rejects missing lineage and premature RELEASE.json", () => {
assert.throws(() => buildWp706PrefreezeReport({
currentCommit: "a".repeat(40),
releaseExists: false,
trace: expectedTrace,
upstream: { ...upstream, "TASK-WP7-05": { ...upstream["TASK-WP7-05"], merged: false } },
}), /WP7_06_UPSTREAM_NOT_MERGED:TASK-WP7-05/);
assert.throws(() => buildWp706PrefreezeReport({
currentCommit: "a".repeat(40),
releaseExists: true,
trace: expectedTrace,
upstream,
}), /WP7_06_RELEASE_WRITTEN_PREMATURELY/);
});
test("rejects trace drift and unsupported upstream statuses", () => {
assert.throws(() => buildWp706PrefreezeReport({
currentCommit: "a".repeat(40),
releaseExists: false,
trace: { ...expectedTrace, summary: { ...expectedTrace.summary, testCases: 116 } },
upstream,
}), /WP7_06_TRACE_COUNT_MISMATCH:testCases/);
assert.throws(() => buildWp706PrefreezeReport({
currentCommit: "a".repeat(40),
releaseExists: false,
trace: expectedTrace,
upstream: { ...upstream, "TASK-WP7-03": { ...upstream["TASK-WP7-03"], status: "passed" } },
}), /WP7_06_UNSUPPORTED_STATUS:TASK-WP7-03/);
});
@@ -0,0 +1,47 @@
import assert from "node:assert/strict";
import { mkdtempSync, mkdirSync, writeFileSync } from "node:fs";
import { tmpdir } from "node:os";
import { join } from "node:path";
import { test } from "node:test";
import { buildFinalReleaseRecord, scanReleaseFiles, validateFinalEvidence } from "../../scripts/lib/wp7-07-final-release.mjs";
function release() {
return buildFinalReleaseRecord({
appVersion: "0.0.0",
browsers: [
{ brand: "Google Chrome", fullVersion: "150.0.7871.187" },
{ brand: "Microsoft Edge", fullVersion: "151.0.4129.59" },
],
buildCommit: "a".repeat(40),
frozenFromCommit: "b".repeat(40),
recordedAt: "2026-08-04T06:00:00.000Z",
windows: { arch: "x64", build: "26200.8875", displayVersion: "25H2" },
});
}
test("TDD-WP7-REL-001 creates a browser-gate compatible first-version record", () => {
const record = release();
assert.equal(record.finalRelease, true);
assert.equal(record.fixedPort, 43121);
assert.deepEqual(record.deferredExternalTasks, ["TASK-WP7-03", "TASK-WP7-04"]);
assert.deepEqual(record.browsers.map(({ brand }) => brand).sort(), ["Google Chrome", "Microsoft Edge"]);
});
test("TDD-WP7-SEC-001 rejects credential shapes and absolute user paths", () => {
const root = mkdtempSync(join(tmpdir(), "dada-wp7-07-scan-"));
mkdirSync(join(root, "logs"));
writeFileSync(join(root, "logs", "diagnostic.txt"), "credential=key-abcdefghijklmnop C:\\Users\\person\\private.txt\n");
const scan = scanReleaseFiles({ roots: [root] });
assert.equal(scan.status, "failed");
assert.deepEqual(new Set(scan.findings.map(({ rule }) => rule)), new Set(["absolute_user_path", "credential_shape"]));
});
test("TDD-WP7-REL-001 binds release and package hashes only after a zero-finding scan", () => {
assert.deepEqual(validateFinalEvidence({
packageManifest: { release_status: "first_version_internal", zip_sha256: "C".repeat(64) },
release: release(),
releaseSha256: "D".repeat(64),
scan: { findings: [], status: "passed" },
}), { release_sha256: "D".repeat(64), status: "passed", zip_sha256: "C".repeat(64) });
});
+21
View File
@@ -190,6 +190,27 @@ describe("TDD-WP5-MAN-001 readonly asset compiler", () => {
expect(repeated.report.derived_files).toEqual({ created: 0, reused: 4, total: 4 });
});
it("safely relocates legacy absolute font package paths after an archive move", () => {
const fixture = createFixture();
const catalogPath = join(fixture.sourceRoot, "fonts", "reports", "font_panel_catalog.csv");
const metadata = JSON.parse(readFileSync(join(fixture.sourceRoot, "fonts", "resources", "font_packages", "FONT001_Test", "metadata.json"), "utf8")) as { local_sha256: string };
csv(catalogPath, [{
candidate_id: "FONT001",
display_name: "Test Font",
font_family: "Dada Test",
local_sha256: metadata.local_sha256,
panel_order: "1",
resource_dir: "C:/Users/legacy/Desktop/sticker_text/fonts/resources/font_packages/FONT001_Test",
resource_status: "verified_extracted",
}]);
expect(() => compileAssetArchive({
manifestPath: fixture.manifestPath,
outputDirectory: fixture.outputRoot,
releaseVersion: "fixture-v1",
})).not.toThrow();
});
it("rejects evidence collections, traversal and output inside a source root", () => {
const fixture = createFixture();
const manifest = JSON.parse(readFileSync(fixture.manifestPath, "utf8")) as { collections: unknown[] };
@@ -1,7 +1,7 @@
import { createHash } from "node:crypto";
import { existsSync, readFileSync, readdirSync, statSync } from "node:fs";
import { homedir } from "node:os";
import { basename, extname, isAbsolute, join, relative, resolve, sep } from "node:path";
import { basename, dirname, extname, isAbsolute, join, relative, resolve, sep } from "node:path";
import { WP4_07_REAL_RESOURCE_VERSIONS } from "./wp4-07-fixture.mjs";
@@ -74,15 +74,16 @@ function assetRecord(assetId, path, sourceReference, expectedSha256) {
export function loadWp407RealAssets() {
const manifestPath = resolve(process.env.DADA_WP4_07_FINAL_ASSET_MANIFEST ?? "");
if (!process.env.DADA_WP4_07_FINAL_ASSET_MANIFEST || !existsSync(manifestPath)) throw new Error("WP4_07_FINAL_ASSET_MANIFEST_REQUIRED");
const handoffPath = resolve(process.env.DADA_COMPLEX_ASSET_MANIFEST ?? join(homedir(), "Desktop", "sticker_web_handoff", "sticker_web_catalog_manifest.json"));
const staticRoot = resolve(process.env.DADA_STATIC_STICKER_ROOT ?? join(homedir(), "Desktop", "贴纸素材"));
const replicationRoot = resolve(process.env.DADA_REPLICATION_ASSET_ROOT ?? join(homedir(), "Desktop", "sticker_web_replication_assets"));
const handoffPath = resolve(process.env.DADA_COMPLEX_ASSET_MANIFEST ?? join(replicationRoot, "sticker_web_handoff", "sticker_web_catalog_manifest.json"));
const staticRoot = resolve(process.env.DADA_STATIC_STICKER_ROOT ?? join(replicationRoot, "sticker_normal"));
const backgroundPath = resolve(process.env.DADA_WP4_07_BACKGROUND_PATH ?? join(homedir(), "Documents", "贴纸脚本", "time_01_input_20260716.png"));
if (!existsSync(handoffPath) || !existsSync(staticRoot)) throw new Error("WP4_07_REAL_ARCHIVE_ROOT_REQUIRED");
const manifestRaw = readFileSync(manifestPath, "utf8");
const manifest = JSON.parse(manifestRaw);
const handoff = JSON.parse(readFileSync(handoffPath, "utf8"));
const collectionRoots = Object.fromEntries(handoff.collections.map((collection) => [collection.id, resolve(collection.root)]));
const collectionRoots = Object.fromEntries(handoff.collections.map((collection) => [collection.id, resolve(dirname(handoffPath), collection.root)]));
const fontRoot = collectionRoots.font_panel;
const dynamicRoot = collectionRoots.interactive_stickers;
if (!fontRoot || !dynamicRoot) throw new Error("WP4_07_REAL_ARCHIVE_COLLECTION_REQUIRED");
@@ -0,0 +1,28 @@
import { afterEach, describe, expect, it, vi } from "vitest";
import { GenerationPollingLoop } from "../../apps/worker/src/generation-polling-loop.js";
describe("POSTV1-05 generation polling loop", () => {
afterEach(() => {
vi.useRealTimers();
});
it("does not start another processor call while the current call is unresolved", async () => {
vi.useFakeTimers();
let finishCurrentCall: (() => void) | undefined;
const processNext = vi.fn(() => new Promise<void>((resolve) => {
finishCurrentCall = resolve;
}));
const loop = new GenerationPollingLoop({ processNext }, 250);
await vi.advanceTimersByTimeAsync(1_000);
expect(processNext).toHaveBeenCalledTimes(1);
finishCurrentCall?.();
await Promise.resolve();
await vi.advanceTimersByTimeAsync(250);
expect(processNext).toHaveBeenCalledTimes(2);
loop.close();
});
});
@@ -0,0 +1,93 @@
import { describe, expect, it, vi } from "vitest";
import type { GenerationAdapterRequest } from "../../apps/worker/src/ai-adapter-contract.js";
import { runAiRuntimeProbe } from "../../apps/worker/src/ai-runtime-probe.js";
import { OneApiGenerationAdapter } from "../../apps/worker/src/oneapi-generation-adapter.js";
function request(overrides: Partial<GenerationAdapterRequest> = {}): GenerationAdapterRequest {
return {
configSnapshot: {},
generationId: "00000000-0000-4000-8000-000000000001",
modelId: "gemini-3.1-flash-image-preview",
prompt: "一张用于本机验收的抽象色彩图",
ratio: "1:1",
referenceAssetIds: [],
...overrides,
};
}
describe("POSTV1-02 OneAPI runtime adapter", () => {
it("uses the fixed Gemini gateway and normalizes one real-shaped response", async () => {
const source = Buffer.from(
"iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mNk+A8AAQUBAScY42YAAAAASUVORK5CYII=",
"base64",
);
const gateway = vi.fn(async (_url: string | URL | Request, init?: RequestInit) => {
const headers = new Headers(init?.headers);
expect(headers.get("authorization")).toBe("Bearer synthetic-runtime-token");
expect(init?.redirect).toBe("error");
const payload = JSON.parse(String(init?.body)) as { messages: Array<{ content: unknown; role: string }> };
expect(payload.messages).toEqual([
{
content: "Generate exactly one image from the user's description. Return the generated image and do not answer with text only.",
role: "system",
},
{ content: "一张用于本机验收的抽象色彩图", role: "user" },
]);
return new Response(JSON.stringify({
choices: [{ message: { content: `![result](data:image/png;base64,${source.toString("base64")})` } }],
}), { headers: { "content-type": "application/json" }, status: 200 });
});
const credential = Buffer.from("synthetic-runtime-token");
const adapter = new OneApiGenerationAdapter({ credential, fetch: gateway as typeof fetch });
const result = await adapter.start(request());
expect(gateway).toHaveBeenCalledOnce();
expect(gateway.mock.calls[0]?.[0]).toBe("https://oneapi.intelligrow.cn/v1/chat/completions");
expect(result.status === "failed" ? result.sourceCategory : "completed").toBe("completed");
if (result.status === "completed") {
expect(result.outputs).toHaveLength(1);
expect(result.outputs[0]).toMatchObject({ mimeType: "image/png", pixelHeight: 1080, pixelWidth: 1080 });
expect(result.outputs[0]?.bytes.length).toBeGreaterThan(0);
}
expect(JSON.stringify(result)).not.toContain("synthetic-runtime-token");
adapter.dispose();
credential.fill(0);
});
it("fails closed instead of returning a mock image", async () => {
const adapter = new OneApiGenerationAdapter({
credential: Buffer.from("synthetic-runtime-token"),
fetch: vi.fn(async () => new Response(null, { status: 503 })) as typeof fetch,
});
await expect(adapter.start(request())).resolves.toEqual({
category: "upstream_failed",
sourceCategory: "upstream_http_503",
status: "failed",
});
adapter.dispose();
await expect(adapter.start(request())).resolves.toEqual({
category: "upstream_failed",
sourceCategory: "adapter_disposed",
status: "failed",
});
});
it("returns only a bounded probe summary and wipes generated bytes", async () => {
const bytes = Buffer.from("probe-output");
const result = await runAiRuntimeProbe({
async start() {
return { outputs: [{ bytes, mimeType: "image/png", pixelHeight: 1080, pixelWidth: 1080 }], status: "completed" };
},
});
expect(result).toEqual({
code: "ai_probe_passed",
mime_type: "image/png",
pixel_height: 1080,
pixel_width: 1080,
real_calls: 1,
success: true,
});
expect(bytes.every((value) => value === 0)).toBe(true);
});
});