Repository navigation
test(ci): CI 必需运行时清单显式化,bash/rm 显式标注为平台相关 - #109
Merged
Merged
Conversation
Fog 4:把「哪些二进制算 CI 必需」这条判据本身钉成清单,双向防止
- 真正 CI 必需的项被悄悄摘掉(退回静默 skip);
- 平台相关的项被误升级为 fail(本地 Windows 被红)。
判定结论(附代码依据):
- node → CI 必需(29 处 shutil.which("node") 守卫,.mjs 探针全靠它)
- bash → 平台相关,刻意不进清单。CI(ubuntu) 上必然存在(镜像自带且
Actions run 步骤默认即 bash),缺它不现实;test_server.py:2591
的用法是 _find_bash() 五套策略的兜底分支,skip 语义是「本机
找不到任何可用 bash」——Windows 无 Git-Bash/WSL 时跳过是正确
行为,非回归守卫静默失效。升级会违背 #106「不做零 skip 禁令」。
- rm → 调研前提经核实不成立:全仓 shutil.which("rm") 命中 0 次、
def test_cleanup 命中 0 次、database.py 内 which 命中 0 次。
真实实现在 tests/db_cleanup.py,用跨平台 os.remove。已加守卫
钉住「不依赖外部 rm」,防将来引入 subprocess rm 造新 Fog。
conftest.py 无需改动:现有 session 检查已正确,扩展它反而会误伤。
仅新增守卫 + 清单常量。
ROM4n2
added a commit
that referenced
this pull request
Oct 6, 2026
更正:上一条 log 记的'shutil.which("rm") 是第 8 处同类 skip 漏网'是错的
——全仓 0 次,tests/db_cleanup.py 用跨平台 os.remove。教训:不要把未核实的
记忆当事实写进文档。
Fog 4(#109):两条前提均被推翻(rm 不存在、bash 判为平台相关),交付
否定式守卫——rm 与 bash 均显式标注'非 CI 必需'并断言不在清单,扩进清单
0 项、未改 conftest.py。
Fog 3(#110):原论证'改用运行时 dependant 更可靠'被实测推翻(运行时只
找出 4 条,看不到函数体内调用的 16 条)。改为加固 AST 守卫:关掉三个实测
确认的漏检洞,allowlist 20 条逐字未动,delector/ 零残留。16 处形式统一
(C-F)待用户裁决。
ROM4n2
added a commit
that referenced
this pull request
Oct 6, 2026
版本面六处同步(test_writer_mobile.py 30 passed 钉死一致): - static/sw.js CACHE_NAME -> delector-static-v5.16.0 - static/index.html 顶栏指示灯 -> System · v5.16.0 Online - android/app/build.gradle fallback -> 5.16.0 / 51600 - README badge + 下载表四行 + 摘要区 - CHANGELOG 完整条目(并补上 v5.15.0 章节的版本前缀) - PROJECT_OVERVIEW 发布面 + 测试基线 本版内容:Fog 1~4 全部收口 - #108 修掉「每次 GET 文章都重跑完整 spaCy + UPDATE articles」:惰性迁移判据 写死 3.4.0 而写入端两条路径都写 3.5.0,判据恒真 => 惰性迁移退化成每次迁移。 修法=PROCESSED_JSON_VERSION 单一真相源,惰性迁移语义完整保留。 - #109 CI 必需运行时清单显式化 + 两条否定守卫(rm 全仓不存在、bash 属平台相关) - #110 localhost 守卫加固三个「将来会漏」的洞,allowlist 20 条逐字未动 - Fog 1 裁决「内网可信」;Fog 3 的 16 处形式统一裁决不做 门禁:1317 passed + 1 skipped(1053 + 264);tools/*.mjs 探针 28/28;ruff 零告警; mypy 两道(93 + 70 files)零错误;发版守护 30 passed;五条守卫全绿。 无 static/ 改动(除 sw.js/index.html 的版本字符串)=> 桌面端刷新即生效; Android APK 随 tag 重建(versionCode 51600,可覆盖安装)。
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
把「CI 必需运行时」清单显式化成守卫,并钉住一条否定式结论:
bash与rm都不是 CI 必需。调研推翻了两条前提(上一轮任务书写错了)
①
shutil.which("rm")全仓 0 次。 三重交叉验证:grep -rc 'shutil.which("rm")' tests/ delector/= 0、def test_cleanup全仓 0 次、delector/core/database.py内shutil0 次。tests/db_cleanup.py::remove_db_files用的是跨平台os.remove。⇒ 我上一轮 work.log 里记的"database.py:2086的test_cleanup用shutil.which("rm"),是第 8 处同类漏网"是错的,在此更正。②
bash判为「平台相关」,不进 CI 必需清单。 依据:ubuntu-latest,bash 由镜像自带,且 GitHub Actions 的run:步骤本身就以 bash 为默认 shell——ci.yml里那些shell: bash正是靠这个默认,不存在"缺 bash"的现实路径tests/test_server.py:2591的 skip 不是if not shutil.which("bash"),而是_find_bash()五套策略的最后一招(git-bash 路径 →where bash→ PATH 扫描 →shutil.which,见:2574)。其语义是"本机找不到任何可用 bash"——Windows 无 Git-Bash/WSL 时跳过是正确行为,不是"守卫静默失效"⇒ 本 PR 未改动
conftest.py,扩进清单的项为 0。session 检查现状已正确,硬塞bash只会制造一条错误的门禁。守卫内容(
tests/test_ci_hardening.py+165)conftest.py实际强制的运行时集合 == 守卫里的显式清单(防止"代码加了但清单没记"与反向脱节)rm显式列为"平台相关、非 CI 必需"并断言其不在清单里——防将来有人误升级为 failbash显式列为"平台相关",并有一条反向钉:断言它不在 CI 必需清单里local_env_still_skips:钉住 conftest 的CI判据仍是环境变量判定(改恒真会红)无 RED 是诚实结果,不是跳过 TDD
新守卫首跑直接绿(
21 passed)——因为核实结论就是"清单无需变更"。改用五条变异证明守卫非空转:("node",)→()1 failed, 19 passed, 1 skippedrm2 failed(assert 'rm' in {'node'})bash2 failedbash同时进两个清单3 failed,含not_promoted_to_fail[bash]CI判据改恒真2 failed,含local_env_still_skips每条均
cp还原 +diff确认RESTORED IDENTICAL(测试文件 4 次、conftest 1 次)。门禁(两道 mypy 都跑)
test_ci_hardening.pytest_probe_wiring_guard.pytest_server.py -k precommitmypy --follow-imports=skip testsmypy --strict delector toolsruff零
static//delector//tools/*.mjs改动 ⇒ 不触发发版。