按 U-Claw-海外化改造方案.md 与 范围决策记录.md 实施。这是 fork,不回上游: 海外版删掉的正是上游的中国市场默认值。 阶段 0 地基 - 下载源全部改国际:脚本/CI 61 处 + lockfile 880 条 npmmirror URL 归零 (lockfile 那 880 条是 npm 的 resolved 字段,脚本层参数化根本绕不过它) - 移除 install.ps1 里三个第三方 GitHub 加速代理,bundle 改直连 + SHA256 校验 (原来只检查"文件大于 1MB"就解压运行) - 技能内容与分发分离:skills/manifest.json 单一来源,install.sh 1170→658 行、 install.ps1 721→546 行,两者技能内容归零 实测原来是三份不一致:skills-cn 完整、install.sh 约 40%、install.ps1 约 17%, 且 7 个通用技能只有 U 盘版有 —— 一键安装的用户一个能用的技能都没有 - Node 版本三种(v22.14/16/22.1)统一,新建 NODE_VERSION 单一来源 - Config 页三份合一。portable/Config.html 用根相对路径调 API 却只从 file:// 打开, 保存功能已静默失效两个月;现缩为 120 行重定向壳 - 测试接入 CI(此前 node --test 无人运行,所有断言形同虚设) 阶段 1 双语可用 - 浏览器侧 i18n:JSON 为源、生成经典 script(file:// 下 fetch 本地 JSON 被拦) 语言跟盘走不跟机器走:启动器写 data/.openclaw/locale.js - 8 处硬编码 lang="zh-CN" 归零,data-i18n 覆盖 213 处,词条 en/zh 各 279 条 - B3 单框 Key:12 张模型卡 → 一个输入框,前缀识别 provider, 服务端 /api/test-key 发 1-token 请求实测,错误映射成人话 Key 填错到得知:从"直到对话失败"降到 ≤1 秒 - 区域格式 SG:DD/MM/YYYY、12 小时、S$、Asia/Singapore (ICU 在 en-SG 下把 SGD 渲染成裸 $,与美元无法区分,故自行拼 S$) - README 内容分叉而非翻译,§1.3 证据清单逐条清零 阶段 2 降门槛 - 启动逻辑上移 lib/start.mjs:Windows-Start.bat 220→28 行、 Mac-Start.command 235→33 行 修掉 Mac 侧两个 bug:控制台端口硬编码 18788(回落时打开死页)、 微信插件从未在 Mac 上安装 - U 盘根目录 23 → 3 个可点文件,其余进 advanced/ - 首启向导:语言 → 用途(7 角色,manifest 驱动)→ 密钥,答过不再问 - 三档界面,Simple 档隐藏一切技术名词 - 自动自愈:启动失败先自查自修,修不好导出脱敏诊断包 (Doctor 从"用户要知道去点的工具"变成后台机制) 阶段 3 技能库 - 19 个英文技能,planned 归零。sg-weather / sg-transport 的端点均实测过 - SkillHub 从 56 张手写第三方卡片改为 manifest 生成:703→125 行,中文归零 其他 - origin.json 收拢所有运行时地址,tests/origin.test.mjs 保证迁移不会漏 - portable/ 下用户可见中文归零(由断言保证) - 82 项测试 未验证(本机无 Windows / 无 pwsh): - install.ps1、setup.ps1 约 210 行改动从未经 PowerShell 解析器 - 完整启动路径仅在假 node + 假 openclaw 上冒烟 - 8 个 .bat 的盘根推导仅静态断言 详见 U盘实测清单.md 受阻: - 隐藏黑窗口 —— 需代码签名证书(.vbs 已被 Windows 弃用,替代方案都要签名) - 场景卡 —— OpenClaw 上游 Dashboard 无预填 prompt 接口 - 官网 36 条 —— 上游 2026-04-14 拆到私有仓库,无权限
This commit is contained in:
144
tests/origin.test.mjs
Normal file
144
tests/origin.test.mjs
Normal file
@@ -0,0 +1,144 @@
|
||||
import { readFileSync, readdirSync, statSync } from 'node:fs';
|
||||
import { fileURLToPath } from 'node:url';
|
||||
import { join, relative, extname } from 'node:path';
|
||||
import test from 'node:test';
|
||||
import assert from 'node:assert/strict';
|
||||
|
||||
const repoRoot = fileURLToPath(new URL('..', import.meta.url));
|
||||
const origin = JSON.parse(readFileSync(join(repoRoot, 'origin.json'), 'utf8'));
|
||||
|
||||
const SKIPPED_DIRS = new Set(['.git', 'node_modules', 'dist', '.download-cache', 'tests']);
|
||||
// Lockfiles are full of third-party funding and repository links. They say
|
||||
// nothing about where *this* build fetches from.
|
||||
const SKIPPED_FILES = new Set(['package-lock.json']);
|
||||
const SCANNED = new Set(['.sh', '.ps1', '.bat', '.command', '.mjs', '.js', '.yml', '.yaml', '.json', '.html', '.md']);
|
||||
|
||||
function* walk(dir) {
|
||||
for (const entry of readdirSync(dir)) {
|
||||
if (SKIPPED_DIRS.has(entry)) continue;
|
||||
const full = join(dir, entry);
|
||||
if (statSync(full).isDirectory()) yield* walk(full);
|
||||
else yield full;
|
||||
}
|
||||
}
|
||||
|
||||
test('origin.json describes a coherent origin', () => {
|
||||
assert.match(origin.repo.owner, /^[\w.-]+$/);
|
||||
assert.match(origin.repo.name, /^[\w.-]+$/);
|
||||
// A template, not a base: Gitea and GitHub lay raw paths out differently.
|
||||
assert.match(origin.urls.rawTemplate, /\{ref\}.*\{path\}/, 'rawTemplate needs both placeholders');
|
||||
for (const key of ['web', 'rawTemplate', 'releases', 'issues', 'website']) {
|
||||
assert.match(origin.urls[key], /^https:\/\//, `${key} should be an https URL`);
|
||||
}
|
||||
assert.match(origin.urls.ssh, /^ssh:\/\//, 'ssh should be an ssh URL');
|
||||
});
|
||||
|
||||
// This is a fork. Every URL the build fetches at runtime points at somebody
|
||||
// else's host until we move it. The move is only safe if nothing is hiding in a
|
||||
// file we forgot about, which is what this test is for.
|
||||
test('no file points at an owner other than the one origin.json declares', () => {
|
||||
const declaredOwner = origin.repo.owner;
|
||||
const OWNER_PATTERN = new RegExp(
|
||||
`${origin.repo.host.replace(/\./g, '\\.')}\\/([\\w.-]+)\\/|github\\.com\\/([\\w.-]+)\\/`, 'g');
|
||||
const KNOWN_THIRD_PARTY = new Set([
|
||||
'openclaw', // upstream runtime, a real dependency
|
||||
'electron', // electron mirrors
|
||||
'ventoy', // bootable USB
|
||||
'dongsheng123132', // the project we forked — referenced, never fetched from
|
||||
]);
|
||||
|
||||
const offenders = [];
|
||||
for (const file of walk(repoRoot)) {
|
||||
if (!SCANNED.has(extname(file))) continue;
|
||||
const rel = relative(repoRoot, file);
|
||||
if (rel === 'origin.json' || SKIPPED_FILES.has(rel.split('/').pop())) continue;
|
||||
const content = readFileSync(file, 'utf8');
|
||||
content.split(/\r?\n/).forEach((line, i) => {
|
||||
for (const match of line.matchAll(OWNER_PATTERN)) {
|
||||
const owner = match[1] ?? match[2];
|
||||
if (owner === declaredOwner || KNOWN_THIRD_PARTY.has(owner)) continue;
|
||||
offenders.push(`${rel}:${i + 1} points at ${owner}`);
|
||||
}
|
||||
});
|
||||
}
|
||||
assert.deepEqual(offenders, [], `unexpected owners:\n${offenders.join('\n')}`);
|
||||
});
|
||||
|
||||
// The one-line installers run through curl|bash with no checkout, so they cannot
|
||||
// read origin.json and carry the same URLs as literals. Without this check a
|
||||
// migration would update origin.json, look done, and leave curl|bash users
|
||||
// fetching from the old host.
|
||||
test('the standalone installers carry URLs that match origin.json', () => {
|
||||
const expected = {
|
||||
releases: origin.urls.releases,
|
||||
website: origin.urls.website,
|
||||
};
|
||||
|
||||
for (const script of ['install/install.sh', 'install/install.ps1']) {
|
||||
const content = readFileSync(join(repoRoot, script), 'utf8');
|
||||
|
||||
const rawPrefix = origin.urls.rawTemplate.split('{ref}')[0];
|
||||
assert.ok(
|
||||
!/raw\.githubusercontent\.com/.test(content) || content.includes(rawPrefix),
|
||||
`${script} still fetches raw content from GitHub`,
|
||||
);
|
||||
if (content.includes('install-skills.mjs')) {
|
||||
assert.ok(content.includes(rawPrefix), `${script} should fetch the installer from ${rawPrefix}`);
|
||||
}
|
||||
|
||||
const releaseUrls = [...content.matchAll(new RegExp(`https://[\\w.-]+/[\\w.-]+/[\\w.-]+/releases`, 'g'))].map((m) => m[0]);
|
||||
for (const url of releaseUrls) {
|
||||
assert.equal(url, expected.releases, `${script} downloads from ${url}, origin.json says ${expected.releases}`);
|
||||
}
|
||||
|
||||
const siteUrls = [...content.matchAll(/https:\/\/u-claw\.org|https:\/\/[\w.-]*u-claw[\w.-]*\.\w+/g)].map((m) => m[0]);
|
||||
for (const url of siteUrls) {
|
||||
assert.equal(url, expected.website, `${script} points at ${url}, origin.json says ${expected.website}`);
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
test('install-skills.mjs reads origin.json rather than hardcoding the host', () => {
|
||||
const content = readFileSync(join(repoRoot, 'lib', 'install-skills.mjs'), 'utf8');
|
||||
assert.match(content, /origin\.json/, 'it should read origin.json');
|
||||
// A literal fallback is fine and necessary — the remote installers download
|
||||
// this file on its own, with no repo around it — but it must agree.
|
||||
// A literal fallback is necessary — the remote installers download this file on
|
||||
// its own, with no repo around it — but it must agree with origin.json.
|
||||
const fallback = content.match(/\?\?\s*'(https:\/\/[^']+)'/)?.[1];
|
||||
assert.ok(fallback, 'there should be a hardcoded fallback template');
|
||||
assert.equal(fallback, origin.urls.rawTemplate, 'the fallback template disagrees with origin.json');
|
||||
});
|
||||
|
||||
test('every u-claw.org address in the tree is one origin.json accounts for', () => {
|
||||
// Not "all the same" — they legitimately differ by role. The point is that no
|
||||
// address exists that nobody has thought about, because on a fork some of
|
||||
// these route to the upstream maintainer rather than to us.
|
||||
const known = new Set(Object.values(origin.support).filter((v) => /@/.test(v)));
|
||||
const offenders = [];
|
||||
for (const file of walk(repoRoot)) {
|
||||
if (!SCANNED.has(extname(file))) continue;
|
||||
const rel = relative(repoRoot, file);
|
||||
if (rel === 'origin.json' || SKIPPED_FILES.has(rel.split('/').pop())) continue;
|
||||
readFileSync(file, 'utf8').split(/\r?\n/).forEach((line, i) => {
|
||||
for (const [found] of line.matchAll(/[\w.+-]+@u-claw\.org/g)) {
|
||||
if (!known.has(found)) offenders.push(`${rel}:${i + 1} uses ${found}`);
|
||||
}
|
||||
});
|
||||
}
|
||||
assert.deepEqual(offenders, [], `addresses origin.json does not account for:\n${offenders.join('\n')}`);
|
||||
});
|
||||
|
||||
test('origin.json flags the addresses that still belong to upstream', () => {
|
||||
// This is the thing that is easy to ship without noticing: a fork whose
|
||||
// SECURITY.md sends vulnerability reports to someone who did not write the
|
||||
// code, and cannot fix it.
|
||||
assert.ok(origin.support.note, 'origin.json should say which addresses are not ours yet');
|
||||
assert.match(origin.support.note, /security/i);
|
||||
|
||||
const security = readFileSync(join(repoRoot, 'SECURITY.md'), 'utf8');
|
||||
assert.ok(
|
||||
security.includes(origin.support.security),
|
||||
'SECURITY.md and origin.json disagree about where to report a vulnerability',
|
||||
);
|
||||
});
|
||||
Reference in New Issue
Block a user