feat: add BingShuo system body validation reflex
This commit is contained in:
parent
cd1c9203c6
commit
893f8e6781
25 changed files with 488 additions and 34 deletions
|
|
@ -42,6 +42,67 @@ const DEFAULT_CACHE_CANDIDATES = [
|
|||
".next/cache",
|
||||
"node_modules/.cache",
|
||||
];
|
||||
const PUBLIC_SNAPSHOT_HEALTH = "https://guanghulab.com/api/ai/health";
|
||||
|
||||
export function validatePublicSnapshotBeforePublish(worktree, repository) {
|
||||
if (repository.slug !== "guanghu-ice-heart") return null;
|
||||
const validator = path.join(
|
||||
worktree,
|
||||
"server-tools/ai-discovery-gateway/validate-public-snapshot.js",
|
||||
);
|
||||
if (!fs.existsSync(validator)) throw new Error("PUBLIC_SNAPSHOT_VALIDATOR_MISSING");
|
||||
const output = run(process.execPath, [
|
||||
validator,
|
||||
"--git-dir",
|
||||
path.join(worktree, ".git"),
|
||||
"--ref",
|
||||
"HEAD",
|
||||
]);
|
||||
const result = JSON.parse(output);
|
||||
if (result.result !== "PASS_100") throw new Error("PUBLIC_SNAPSHOT_PREFLIGHT_FAILED");
|
||||
return result;
|
||||
}
|
||||
|
||||
export async function waitForPublicSnapshotAcceptance({
|
||||
expectedCommit,
|
||||
expectedAnchorVersion,
|
||||
endpoint = PUBLIC_SNAPSHOT_HEALTH,
|
||||
attempts = 15,
|
||||
delayMs = 2000,
|
||||
probe = async (url) => {
|
||||
const response = await fetch(url, {
|
||||
headers: { accept: "application/json" },
|
||||
signal: AbortSignal.timeout(5000),
|
||||
});
|
||||
let body = null;
|
||||
try { body = await response.json(); } catch { body = {}; }
|
||||
return { status: response.status, body };
|
||||
},
|
||||
}) {
|
||||
let last = null;
|
||||
for (let attempt = 1; attempt <= attempts; attempt += 1) {
|
||||
try { last = await probe(`${endpoint}?expected_commit=${expectedCommit}`); }
|
||||
catch (error) { last = { status: 0, body: { error: String(error.message || error) } }; }
|
||||
const source = last.body?.navigation_source || {};
|
||||
if (
|
||||
last.status === 200 &&
|
||||
source.source_degraded === false &&
|
||||
source.source_commit === expectedCommit &&
|
||||
source.anchor_version === expectedAnchorVersion
|
||||
) {
|
||||
return { result: "PASS_100", attempt, endpoint, navigation_source: source };
|
||||
}
|
||||
if (attempt < attempts) await new Promise((resolve) => setTimeout(resolve, delayMs));
|
||||
}
|
||||
const source = last?.body?.navigation_source || {};
|
||||
throw new Error(
|
||||
`PUBLIC_SNAPSHOT_NOT_ACCEPTED:` +
|
||||
`status=${last?.status || 0}:commit=${source.source_commit || "missing"}:` +
|
||||
`anchor=${source.anchor_version || "missing"}:` +
|
||||
`degraded=${String(source.source_degraded)}:` +
|
||||
`error=${source.source_error_code || last?.body?.error || "unknown"}`,
|
||||
);
|
||||
}
|
||||
|
||||
export function parseArgs(argv) {
|
||||
const args = { receipts: [], cleanupPaths: [] };
|
||||
|
|
@ -498,6 +559,7 @@ export async function finalize(options) {
|
|||
);
|
||||
const branch = normalizeBranch(options.target || verified.branch);
|
||||
if (branch !== verified.branch) throw new Error("CHECKED_OUT_BRANCH_MISMATCH");
|
||||
const publicSnapshot = validatePublicSnapshotBeforePublish(worktree, repository);
|
||||
|
||||
let publishRequestId = null;
|
||||
let publishStarted = false;
|
||||
|
|
@ -516,9 +578,17 @@ export async function finalize(options) {
|
|||
verified.head,
|
||||
verified.receiptEvidence,
|
||||
);
|
||||
const publicAcceptance = publicSnapshot
|
||||
? await waitForPublicSnapshotAcceptance({
|
||||
expectedCommit: remote.remoteHead,
|
||||
expectedAnchorVersion: publicSnapshot.anchor_version,
|
||||
endpoint: options.publicSnapshotHealth || PUBLIC_SNAPSHOT_HEALTH,
|
||||
probe: options.publicSnapshotProbe,
|
||||
})
|
||||
: null;
|
||||
const publishReceipt =
|
||||
`PASS_100 remote=${repository.identity}#${branch} ` +
|
||||
`head=${remote.remoteHead} receipts=${verified.receiptEvidence
|
||||
`head=${remote.remoteHead} public_acceptance=${publicAcceptance ? "PASS_100" : "NOT_APPLICABLE"} receipts=${verified.receiptEvidence
|
||||
.map((item) => `${item.path}:${item.sha256}`)
|
||||
.join(",")}`;
|
||||
finishPublish(
|
||||
|
|
@ -545,6 +615,7 @@ export async function finalize(options) {
|
|||
fresh_clone_readback: 100,
|
||||
git_fsck: 100,
|
||||
receipts: verified.receiptEvidence,
|
||||
public_snapshot_acceptance: publicAcceptance,
|
||||
},
|
||||
cleanup: {
|
||||
scope: "CURRENT_WORKTREE_IGNORED_ALLOWLISTED_CACHES_ONLY",
|
||||
|
|
|
|||
Loading…
Reference in a new issue