feat: import Chinese-localized Buzz source snapshot
Docker image / Build (linux/amd64) (push) Has been cancelled
Docker image / Build (linux/arm64) (push) Has been cancelled
Docker image / Merge release multi-arch manifest (push) Has been cancelled
Docker image / Merge debug multi-arch manifest (push) Has been cancelled
Docker image / Build public push gateway (linux/amd64) (push) Has been cancelled
Docker image / Build public push gateway (linux/arm64) (push) Has been cancelled
Docker image / Publish public push gateway image (push) Has been cancelled
Sprig image / Build (linux/amd64) (push) Has been cancelled
Sprig image / Build (linux/arm64) (push) Has been cancelled
Sprig image / Merge multi-arch manifest (push) Has been cancelled
Harbor Buzz Orchestra / Python tests and lint (push) Has been cancelled
CI / Detect Changed Paths (push) Has been cancelled
CI / Rust Lint (push) Has been cancelled
CI / Unit Tests (push) Has been cancelled
CI / Desktop Core (push) Has been cancelled
CI / Desktop Smoke E2E (1) (push) Has been cancelled
CI / Desktop Smoke E2E (2) (push) Has been cancelled
CI / Desktop Smoke E2E (3) (push) Has been cancelled
CI / Desktop Smoke E2E (4) (push) Has been cancelled
CI / Desktop (push) Has been cancelled
CI / Desktop E2E Relay (push) Has been cancelled
CI / Desktop E2E Integration (1/2) (push) Has been cancelled
CI / Desktop E2E Integration (2/2) (push) Has been cancelled
CI / Desktop E2E Integration (push) Has been cancelled
CI / Backend Integration (relay e2e) (push) Has been cancelled
CI / Relay E2E (push) Has been cancelled
CI / Web (push) Has been cancelled
CI / Mobile (push) Has been cancelled
CI / Security (push) Has been cancelled
CI / Dead Token Reference Guard (push) Has been cancelled
CI / Server Cross-Compile (aarch64-unknown-linux-musl) (push) Has been cancelled
CI / Server Cross-Compile (x86_64-unknown-linux-musl) (push) Has been cancelled
CI / Windows Rust (x86_64-pc-windows-msvc) (push) Has been cancelled
CI / Desktop Build (macOS) (push) Has been cancelled
helm chart / lint + unittest + render matrix (push) Has been cancelled
helm chart / install on kind (gated) (push) Has been cancelled
helm chart / publish chart to GHCR (push) Has been cancelled
Mesh Lifecycle / Relay-Driven Mesh Lifecycle Smoke (push) Has been cancelled
Sprig / Build (aarch64-unknown-linux-musl) (push) Has been cancelled
Sprig / Build (x86_64-unknown-linux-musl) (push) Has been cancelled
Sprig / Publish rolling release (push) Has been cancelled
Sprig / Publish tagged release (push) Has been cancelled

Signed-off-by: cls_宁波本机 <908705107@qq.com>
This commit is contained in:
2026-08-13 18:34:25 +08:00
parent 61c3fa1df9
commit 9dfa06ffee
3785 changed files with 1085458 additions and 2 deletions
+108
View File
@@ -0,0 +1,108 @@
import { promises as fs } from "node:fs";
import path from "node:path";
/**
* Shared "no hand-rolled pubkey truncation" guard.
*
* A truncated pubkey prefix is forgeable by vanity-grinding, so display
* truncation must be consistent and centralized: the canonical
* `truncatePubkey` in `shared/lib/pubkey.ts` (or the `<PubKey>` component,
* which also offers full-key reveal + copy). Ad-hoc `pubkey.slice(0, N)`
* display forms fragmented into five formats before this guard existed.
*
* It flags `.slice(` / `.substring(` / `.slice(0` template-truncations applied
* to identifiers that look like a pubkey/npub, outside the canonical module.
* Non-display uses (array windows, color derivation from a key, avatar
* initials) live in each app's `overrides` allowlist.
*/
const PUBKEY_SLICE_RE =
/\b[A-Za-z_$][\w$]*(?:[Pp]ubkey|[Pp]ub_key|[Nn]pub)[\w$]*\??\.(?:slice|substring)\(|\b(?:pubkey|npub)\??\.(?:slice|substring)\(/g;
async function walkFiles(directory) {
const entries = await fs.readdir(directory, { withFileTypes: true });
const files = await Promise.all(
entries.map(async (entry) => {
const fullPath = path.join(directory, entry.name);
if (entry.isDirectory()) {
return walkFiles(fullPath);
}
return [fullPath];
}),
);
return files.flat();
}
/**
* @param {object} options
* @param {string} options.projectRoot Absolute path the rule roots resolve against.
* @param {Array<{root: string, extensions: Set<string>}>} options.rules Where to scan.
* @param {string} options.label Human label for the failure header.
* @param {Set<string>} [options.overrides] Allowlisted "relativePath:lineNumber" entries.
* @param {Set<string>} [options.allowedFiles] Relative paths allowed to truncate (the canonical module).
* @param {string} options.scriptPath Path mentioned in the failure hint.
*/
export async function runPubkeyTruncationCheck({
projectRoot,
rules,
label,
overrides = new Set(),
allowedFiles = new Set(),
scriptPath,
}) {
const candidateFiles = (
await Promise.all(
rules.map((rule) => {
const dir = path.join(projectRoot, rule.root);
return fs
.access(dir)
.then(() => walkFiles(dir))
.catch(() => []);
}),
)
).flat();
const violations = [];
for (const filePath of candidateFiles) {
const relativePath = path.relative(projectRoot, filePath);
const rule = rules.find((r) =>
relativePath.startsWith(`${r.root}${path.sep}`),
);
if (!rule || !rule.extensions.has(path.extname(filePath))) {
continue;
}
if (allowedFiles.has(relativePath.split(path.sep).join("/"))) {
continue;
}
if (relativePath.includes(".test.")) {
continue;
}
const content = await fs.readFile(filePath, "utf8");
const lines = content.split("\n");
lines.forEach((line, index) => {
PUBKEY_SLICE_RE.lastIndex = 0;
if (!PUBKEY_SLICE_RE.test(line)) {
return;
}
const key = `${relativePath.split(path.sep).join("/")}:${index + 1}`;
if (overrides.has(key)) {
return;
}
violations.push({ key, line: line.trim() });
});
}
if (violations.length > 0) {
console.error(
`${label}: found ${violations.length} hand-rolled pubkey truncation(s).\n` +
`Use \`truncatePubkey\` from shared/lib/pubkey (or the <PubKey> component) instead.\n` +
`Genuine non-display uses can be allowlisted in ${scriptPath}.\n`,
);
for (const violation of violations) {
console.error(` ${violation.key}: ${violation.line}`);
}
process.exit(1);
}
}