Some checks failed
Tests / test (push) Has been cancelled
不是翻译 —— 多数文档描述的行为已经不存在了。 先修一个更基本的问题:我们不拥有 u-claw.org 域名,那是上游的。所以之前写在 README、诊断包提示、联系方式里的 help@u-claw.org 全都会把用户的问题发给 上游 —— 一个没有理由回复的人。改为指向我们自己的 issue tracker,并加断言 禁止再出现指向该域名的支持入口。 重写(内容过时,不是语言问题): - install/README.md —— 还写着 10 个中国技能、DeepSeek 优先、国内镜像。 现在按实际流程写:技能读 manifest、模型菜单 Gemini 优先、bundle 有 SHA256 校验。并如实写明 curl|bash 在受管企业电脑上会被 EDR 拦。 - CLAUDE.md 的模型配置整节 —— 还在描述虾盘云首选卡片和 12 个 provider, 那个界面已经换成单框 Key 输入了。 - SECURITY.md —— 安全报告原本指向上游维护者个人邮箱。fork 之后那条路由 是错的:漏洞会发给写不了这份代码、也修不了的人。 - CONTRIBUTING.md —— 补上 fork 关系、pre-push 钩子怎么装、以及 `node --test tests/` 为什么不能用。 翻译并保留: - bootable/README.md、TROUBLESHOOTING.md —— 面向用户,顺带把 「国内镜像」「小米/华为 BIOS 按键」等换成目标市场的实际情况 HANDOFF.md 重写为一份事故复盘:原文一半是过时的一次性交接笔记(引用的 website/guide.html 已不在本仓库),另一半是 persistence.dat 未格式化导致 启动失败的排查记录 —— 后者有长期价值,尤其是「读 offset 1080 的两字节 验证 ext4」这个判断方法,已同时写进 bootable/README.md。 bootable/IMPROVEMENTS_SUMMARY.md 保留中文,加了说明:它是上游 fork 前的 历史改进记录,没人引用,描述的是已完成的工作而非当前行为。翻译它反而会 让人误以为是现行文档。 新增 skills/en/uclaw-help —— 把「怎么用、东西在哪、出问题怎么办」做成 内置知识,每个角色都装。方案 C10.8:能问的产品才是不需要学的产品。
144 lines
6.8 KiB
JavaScript
144 lines
6.8 KiB
JavaScript
import { readFileSync, readdirSync, statSync } from 'node:fs';
|
|
import { fileURLToPath } from 'node:url';
|
|
import { join, relative, extname } from 'node:path';
|
|
import test from 'node:test';
|
|
import assert from 'node:assert/strict';
|
|
|
|
const repoRoot = fileURLToPath(new URL('..', import.meta.url));
|
|
const origin = JSON.parse(readFileSync(join(repoRoot, 'origin.json'), 'utf8'));
|
|
|
|
const SKIPPED_DIRS = new Set(['.git', 'node_modules', 'dist', '.download-cache', 'tests']);
|
|
// Lockfiles are full of third-party funding and repository links. They say
|
|
// nothing about where *this* build fetches from.
|
|
const SKIPPED_FILES = new Set(['package-lock.json']);
|
|
const SCANNED = new Set(['.sh', '.ps1', '.bat', '.command', '.mjs', '.js', '.yml', '.yaml', '.json', '.html', '.md']);
|
|
|
|
function* walk(dir) {
|
|
for (const entry of readdirSync(dir)) {
|
|
if (SKIPPED_DIRS.has(entry)) continue;
|
|
const full = join(dir, entry);
|
|
if (statSync(full).isDirectory()) yield* walk(full);
|
|
else yield full;
|
|
}
|
|
}
|
|
|
|
test('origin.json describes a coherent origin', () => {
|
|
assert.match(origin.repo.owner, /^[\w.-]+$/);
|
|
assert.match(origin.repo.name, /^[\w.-]+$/);
|
|
// A template, not a base: Gitea and GitHub lay raw paths out differently.
|
|
assert.match(origin.urls.rawTemplate, /\{ref\}.*\{path\}/, 'rawTemplate needs both placeholders');
|
|
for (const key of ['web', 'rawTemplate', 'releases', 'issues', 'website']) {
|
|
assert.match(origin.urls[key], /^https:\/\//, `${key} should be an https URL`);
|
|
}
|
|
assert.match(origin.urls.ssh, /^ssh:\/\//, 'ssh should be an ssh URL');
|
|
});
|
|
|
|
// This is a fork. Every URL the build fetches at runtime points at somebody
|
|
// else's host until we move it. The move is only safe if nothing is hiding in a
|
|
// file we forgot about, which is what this test is for.
|
|
test('no file points at an owner other than the one origin.json declares', () => {
|
|
const declaredOwner = origin.repo.owner;
|
|
const OWNER_PATTERN = new RegExp(
|
|
`${origin.repo.host.replace(/\./g, '\\.')}\\/([\\w.-]+)\\/|github\\.com\\/([\\w.-]+)\\/`, 'g');
|
|
const KNOWN_THIRD_PARTY = new Set([
|
|
'openclaw', // upstream runtime, a real dependency
|
|
'electron', // electron mirrors
|
|
'ventoy', // bootable USB
|
|
'dongsheng123132', // the project we forked — referenced, never fetched from
|
|
]);
|
|
|
|
const offenders = [];
|
|
for (const file of walk(repoRoot)) {
|
|
if (!SCANNED.has(extname(file))) continue;
|
|
const rel = relative(repoRoot, file);
|
|
if (rel === 'origin.json' || SKIPPED_FILES.has(rel.split('/').pop())) continue;
|
|
const content = readFileSync(file, 'utf8');
|
|
content.split(/\r?\n/).forEach((line, i) => {
|
|
for (const match of line.matchAll(OWNER_PATTERN)) {
|
|
const owner = match[1] ?? match[2];
|
|
if (owner === declaredOwner || KNOWN_THIRD_PARTY.has(owner)) continue;
|
|
offenders.push(`${rel}:${i + 1} points at ${owner}`);
|
|
}
|
|
});
|
|
}
|
|
assert.deepEqual(offenders, [], `unexpected owners:\n${offenders.join('\n')}`);
|
|
});
|
|
|
|
// The one-line installers run through curl|bash with no checkout, so they cannot
|
|
// read origin.json and carry the same URLs as literals. Without this check a
|
|
// migration would update origin.json, look done, and leave curl|bash users
|
|
// fetching from the old host.
|
|
test('the standalone installers carry URLs that match origin.json', () => {
|
|
const expected = {
|
|
releases: origin.urls.releases,
|
|
website: origin.urls.website,
|
|
};
|
|
|
|
for (const script of ['install/install.sh', 'install/install.ps1']) {
|
|
const content = readFileSync(join(repoRoot, script), 'utf8');
|
|
|
|
const rawPrefix = origin.urls.rawTemplate.split('{ref}')[0];
|
|
assert.ok(
|
|
!/raw\.githubusercontent\.com/.test(content) || content.includes(rawPrefix),
|
|
`${script} still fetches raw content from GitHub`,
|
|
);
|
|
if (content.includes('install-skills.mjs')) {
|
|
assert.ok(content.includes(rawPrefix), `${script} should fetch the installer from ${rawPrefix}`);
|
|
}
|
|
|
|
const releaseUrls = [...content.matchAll(new RegExp(`https://[\\w.-]+/[\\w.-]+/[\\w.-]+/releases`, 'g'))].map((m) => m[0]);
|
|
for (const url of releaseUrls) {
|
|
assert.equal(url, expected.releases, `${script} downloads from ${url}, origin.json says ${expected.releases}`);
|
|
}
|
|
|
|
const siteUrls = [...content.matchAll(/https:\/\/u-claw\.org|https:\/\/[\w.-]*u-claw[\w.-]*\.\w+/g)].map((m) => m[0]);
|
|
for (const url of siteUrls) {
|
|
assert.equal(url, expected.website, `${script} points at ${url}, origin.json says ${expected.website}`);
|
|
}
|
|
}
|
|
});
|
|
|
|
test('install-skills.mjs reads origin.json rather than hardcoding the host', () => {
|
|
const content = readFileSync(join(repoRoot, 'lib', 'install-skills.mjs'), 'utf8');
|
|
assert.match(content, /origin\.json/, 'it should read origin.json');
|
|
// A literal fallback is fine and necessary — the remote installers download
|
|
// this file on its own, with no repo around it — but it must agree.
|
|
// A literal fallback is necessary — the remote installers download this file on
|
|
// its own, with no repo around it — but it must agree with origin.json.
|
|
const fallback = content.match(/\?\?\s*'(https:\/\/[^']+)'/)?.[1];
|
|
assert.ok(fallback, 'there should be a hardcoded fallback template');
|
|
assert.equal(fallback, origin.urls.rawTemplate, 'the fallback template disagrees with origin.json');
|
|
});
|
|
|
|
test('we do not tell users to email a domain we do not own', () => {
|
|
// u-claw.org is the upstream project's domain. Any address on it reaches them,
|
|
// not us — so a support line pointing there sends our users' problems to
|
|
// someone with no reason to answer.
|
|
const OURS = new Set(Object.values(origin.upstream?.addresses ?? {}).filter((v) => /@/.test(v)));
|
|
const offenders = [];
|
|
for (const file of walk(repoRoot)) {
|
|
if (!SCANNED.has(extname(file))) continue;
|
|
const rel = relative(repoRoot, file);
|
|
if (rel === 'origin.json' || SKIPPED_FILES.has(rel.split('/').pop())) continue;
|
|
readFileSync(file, 'utf8').split(/\r?\n/).forEach((line, i) => {
|
|
for (const [found] of line.matchAll(/[\w.+-]+@u-claw\.org/g)) {
|
|
// Upstream's own addresses may appear where the text is about upstream.
|
|
if (OURS.has(found)) continue;
|
|
offenders.push(`${rel}:${i + 1} offers ${found}, a domain we do not control`);
|
|
}
|
|
});
|
|
}
|
|
assert.deepEqual(offenders, [], offenders.join('\n'));
|
|
});
|
|
|
|
test('support routes somewhere we actually control', () => {
|
|
assert.match(origin.support.issues, /^https:\/\//, 'there has to be a working support route');
|
|
assert.ok(
|
|
origin.support.issues.includes(origin.repo.host),
|
|
'support should point at our own host, not the upstream project',
|
|
);
|
|
// Until we have an address of our own, saying so beats leaving a stale one.
|
|
assert.ok('email' in origin.support, 'origin.json should record whether we have an address yet');
|
|
assert.match(origin.support.note, /do not own u-claw\.org/i);
|
|
});
|