release: 1.2.0
TallyNote release / linux-x64 (push) Failing after 13s

This commit is contained in:
Qiufeng
2026-09-05 08:42:47 +08:00
parent fa2fd94579
commit 620362823b
9 changed files with 120 additions and 195 deletions
+12 -1
View File
@@ -30,7 +30,18 @@ jobs:
- name: Verify tag and test gate - name: Verify tag and test gate
run: | run: |
set -euo pipefail set -euo pipefail
test "$(node -p 'require("./package.json").version')" = "${GITHUB_REF_NAME#v}" target_version="${GITHUB_REF_NAME#v}"
package_version="$(node -p 'require("./package.json").version')"
test "$package_version" = "$target_version"
previous_tag="$(git tag --list 'v*.*.*' --sort=-version:refname | grep -Fxv "$GITHUB_REF_NAME" | head -n 1 || true)"
if [[ -n "$previous_tag" ]]; then
node - "$target_version" "${previous_tag#v}" <<'NODE'
const [target, previous] = process.argv.slice(2).map((value) => value.split(/[.+-]/, 1)[0].split('.').map(Number));
if (target.length !== 3 || previous.length !== 3 || target.some((n) => !Number.isSafeInteger(n)) || previous.some((n) => !Number.isSafeInteger(n))) process.exit(2);
const newer = target[0] > previous[0] || (target[0] === previous[0] && (target[1] > previous[1] || (target[1] === previous[1] && target[2] > previous[2])));
if (!newer) { console.error(`release ${process.argv[2]} must be newer than ${process.argv[3]}`); process.exit(1); }
NODE
fi
pnpm install --frozen-lockfile pnpm install --frozen-lockfile
pnpm check pnpm check
# better-sqlite3 is a native addon; a single Vitest worker avoids a # better-sqlite3 is a native addon; a single Vitest worker avoids a
+1 -1
View File
@@ -1,6 +1,6 @@
{ {
"name": "tallynote", "name": "tallynote",
"version": "1.1.42", "version": "1.2.0",
"private": true, "private": true,
"type": "module", "type": "module",
"packageManager": "pnpm@9.0.6", "packageManager": "pnpm@9.0.6",
+2
View File
@@ -13,6 +13,8 @@ if [[ -z "$VERSION" ]]; then
fi fi
VERSION=${VERSION#v} VERSION=${VERSION#v}
[[ "$VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z-]+(\.[0-9A-Za-z-]+)*)?(\+[0-9A-Za-z-]+(\.[0-9A-Za-z-]+)*)?$ ]] || { printf 'invalid version: %s\n' "$VERSION" >&2; exit 2; } [[ "$VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z-]+(\.[0-9A-Za-z-]+)*)?(\+[0-9A-Za-z-]+(\.[0-9A-Za-z-]+)*)?$ ]] || { printf 'invalid version: %s\n' "$VERSION" >&2; exit 2; }
PACKAGE_VERSION=$(node -p 'require("./package.json").version')
[[ "$VERSION" == "$PACKAGE_VERSION" ]] || { printf 'version mismatch: release %s does not match package.json %s\n' "$VERSION" "$PACKAGE_VERSION" >&2; exit 2; }
case "$(uname -m)" in case "$(uname -m)" in
x86_64|amd64) ARCH=x64 ;; x86_64|amd64) ARCH=x64 ;;
aarch64|arm64) ARCH=arm64 ;; aarch64|arm64) ARCH=arm64 ;;
-2
View File
@@ -63,7 +63,6 @@ import {
readCachedRelease, readCachedRelease,
writeUpdateRequest, writeUpdateRequest,
cancelUpdateJob, cancelUpdateJob,
triggerInProcessDownload,
type UpdateRequest, type UpdateRequest,
} from "./update-service.js"; } from "./update-service.js";
@@ -1181,7 +1180,6 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
database.sqlite.prepare("UPDATE update_jobs SET status='failed', error_message=?, updated_at=? WHERE id=?").run("无法创建系统更新请求", Date.now(), id); database.sqlite.prepare("UPDATE update_jobs SET status='failed', error_message=?, updated_at=? WHERE id=?").run("无法创建系统更新请求", Date.now(), id);
throw new AppError(503, "UPDATE_QUEUE_FAILED", "无法提交更新请求,请检查服务安装权限"); throw new AppError(503, "UPDATE_QUEUE_FAILED", "无法提交更新请求,请检查服务安装权限");
} }
triggerInProcessDownload(database.sqlite, config, id, cachedAsset, cachedAsset.sha256);
reply.header("Cache-Control", "no-store"); reply.header("Cache-Control", "no-store");
return reply.code(202).send({ job: { id, status: "queued", operation: "download", version } }); return reply.code(202).send({ job: { id, status: "queued", operation: "download", version } });
}); });
+15 -3
View File
@@ -163,7 +163,8 @@ function writeJob(sqlite: Database.Database | undefined, jobId: string, values:
requested_at=COALESCE(excluded.requested_at, update_jobs.requested_at), requested_at=COALESCE(excluded.requested_at, update_jobs.requested_at),
started_at=COALESCE(excluded.started_at, update_jobs.started_at), started_at=COALESCE(excluded.started_at, update_jobs.started_at),
operation=excluded.operation, operation=excluded.operation,
status=excluded.status, version=excluded.version, platform=excluded.platform, status=CASE WHEN update_jobs.status='cancelled' THEN update_jobs.status ELSE excluded.status END,
version=excluded.version, platform=excluded.platform,
release_url=COALESCE(excluded.release_url, update_jobs.release_url), release_url=COALESCE(excluded.release_url, update_jobs.release_url),
asset_name=COALESCE(excluded.asset_name, update_jobs.asset_name), asset_name=COALESCE(excluded.asset_name, update_jobs.asset_name),
asset_url=excluded.asset_url, asset_url=excluded.asset_url,
@@ -276,6 +277,7 @@ export async function runUpdate(options: UpdateRunOptions): Promise<UpdateRunRes
const platform = options.platform ?? detectPlatform(); const platform = options.platform ?? detectPlatform();
const jobId = options.jobId ?? randomUUID(); const jobId = options.jobId ?? randomUUID();
const operation = options.operation ?? "apply"; const operation = options.operation ?? "apply";
const sqlite = options.sqlite;
let resolved: Awaited<ReturnType<typeof resolveRelease>> | undefined; let resolved: Awaited<ReturnType<typeof resolveRelease>> | undefined;
try { try {
resolved = await resolveRelease(options, platform); resolved = await resolveRelease(options, platform);
@@ -299,7 +301,12 @@ export async function runUpdate(options: UpdateRunOptions): Promise<UpdateRunRes
if (operation === "download") await mkdir(workspace, { recursive: false, mode: 0o700 }); if (operation === "download") await mkdir(workspace, { recursive: false, mode: 0o700 });
const archivePath = path.join(workspace, resolved.asset.name.endsWith(".gz") || resolved.asset.name.endsWith(".zip") ? resolved.asset.name : `${resolved.asset.name}.tar.gz`); const archivePath = path.join(workspace, resolved.asset.name.endsWith(".gz") || resolved.asset.name.endsWith(".zip") ? resolved.asset.name : `${resolved.asset.name}.tar.gz`);
try { try {
updateJob(options.sqlite, jobId, { operation, status: "downloading", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, downloadPath: path.basename(archivePath), startedAt: Date.now() }); if (sqlite) {
const claim = sqlite.prepare("UPDATE update_jobs SET status='downloading', download_started_at=?, started_at=?, download_path=?, updated_at=? WHERE id=? AND status='queued'").run(Date.now(), Date.now(), path.basename(archivePath), Date.now(), jobId);
if (claim.changes !== 1) throw new Error("更新任务已取消或已被其他进程接管");
} else {
updateJob(options.sqlite, jobId, { operation, status: "downloading", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, downloadPath: path.basename(archivePath), startedAt: Date.now() });
}
const progressStartedAt = Date.now(); const progressStartedAt = Date.now();
let lastProgressWrite = 0; let lastProgressWrite = 0;
const downloaded = await downloadReleaseAsset(resolved.asset.url, archivePath, { const downloaded = await downloadReleaseAsset(resolved.asset.url, archivePath, {
@@ -337,7 +344,12 @@ export async function runUpdate(options: UpdateRunOptions): Promise<UpdateRunRes
await normalizeReleasePermissions(stagedDir); await normalizeReleasePermissions(stagedDir);
const payloadInfo = await lstat(path.join(stagedDir, "dist")).catch(() => null); const payloadInfo = await lstat(path.join(stagedDir, "dist")).catch(() => null);
if (!payloadInfo?.isDirectory() || payloadInfo.isSymbolicLink()) throw new Error("发布包缺少 dist 目录"); if (!payloadInfo?.isDirectory() || payloadInfo.isSymbolicLink()) throw new Error("发布包缺少 dist 目录");
updateJob(options.sqlite, jobId, { operation, status: "staged", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, actualSha256: downloaded.sha256, sizeBytes: downloaded.size, downloadPath: workspace }); if (sqlite) {
const staged = sqlite.prepare("UPDATE update_jobs SET status='staged', actual_sha256=?, size_bytes=?, download_path=?, updated_at=? WHERE id=? AND status IN ('verifying', 'downloading')").run(downloaded.sha256, downloaded.size, workspace, Date.now(), jobId);
if (staged.changes !== 1) throw new Error("更新任务已取消,已停止继续处理");
} else {
updateJob(options.sqlite, jobId, { operation, status: "staged", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, actualSha256: downloaded.sha256, sizeBytes: downloaded.size, downloadPath: workspace });
}
if (operation === "download") { if (operation === "download") {
keepWorkspace = true; keepWorkspace = true;
+30 -112
View File
@@ -18,118 +18,12 @@ import {
selectReleaseAsset, selectReleaseAsset,
validateHttpsUrl, validateHttpsUrl,
RELEASE_NOTES_MAX_BYTES, RELEASE_NOTES_MAX_BYTES,
downloadReleaseAsset,
extractSafeArchive,
normalizeReleasePermissions,
applicationUpdateRuntimeHash,
type ReleaseAsset, type ReleaseAsset,
type ReleaseMetadata, type ReleaseMetadata,
} from "./update.js"; } from "./update.js";
import type { UpdateJobStatus } from "../shared/contracts.js"; import type { UpdateJobStatus } from "../shared/contracts.js";
export const activeInProcessDownloads = new Map<string, AbortController>();
export function triggerInProcessDownload(
database: Database.Database,
config: AppConfig,
jobId: string,
asset: { name: string; url: string; sha256?: string },
expectedSha256?: string,
): void {
setImmediate(async () => {
try {
const row = database.prepare("SELECT id, status, operation FROM update_jobs WHERE id=?").get(jobId) as { id: string; status: string; operation: string } | undefined;
if (!row || row.status !== "queued") return;
const controller = new AbortController();
activeInProcessDownloads.set(jobId, controller);
const workspace = path.join(path.resolve(config.stagingDir), `update-${jobId}`);
const archivePath = path.join(workspace, asset.name.endsWith(".gz") || asset.name.endsWith(".zip") ? asset.name : `${asset.name}.tar.gz`);
await mkdir(workspace, { recursive: true, mode: 0o700 });
const now = Date.now();
database.prepare("UPDATE update_jobs SET status='downloading', download_started_at=?, started_at=?, download_path=?, updated_at=? WHERE id=? AND status='queued'").run(now, now, path.basename(archivePath), now, jobId);
const progressStartedAt = Date.now();
let lastProgressWrite = 0;
const downloaded = await downloadReleaseAsset(asset.url, archivePath, {
allowedHosts: config.updateAllowedHosts,
maxBytes: config.updateMaxBytes,
fetchImpl: (input, init) => fetch(input, { ...init, signal: controller.signal }),
onProgress: (downloadedBytes, totalBytes) => {
const cur = Date.now();
if (cur - lastProgressWrite < 200) return;
lastProgressWrite = cur;
const elapsed = Math.max(1, cur - progressStartedAt);
const speedBps = Math.round(downloadedBytes * 1000 / elapsed);
try {
database.prepare("UPDATE update_jobs SET downloaded_bytes=?, size_bytes=COALESCE(?, size_bytes), download_speed_bps=?, updated_at=? WHERE id=? AND status='downloading'").run(downloadedBytes, totalBytes, speedBps, cur, jobId);
} catch {}
},
});
if (expectedSha256 && downloaded.sha256.toLowerCase() !== expectedSha256.toLowerCase()) {
throw new Error("更新文件 SHA-256 校验失败");
}
database.prepare("UPDATE update_jobs SET status='verifying', actual_sha256=?, size_bytes=?, downloaded_bytes=?, updated_at=? WHERE id=? AND status='downloading'").run(downloaded.sha256, downloaded.size, downloaded.size, Date.now(), jobId);
const stagedDir = path.join(workspace, "payload");
await extractSafeArchive(archivePath, stagedDir, config.updateMaxBytes === undefined ? {} : { maxBytes: config.updateMaxBytes });
if (applicationUpdateRuntimeHash(asset.name)) {
try {
const currentRelease = realpathSync(config.currentLink);
if (currentRelease) {
for (const entry of ["node_modules", "runtime", "pnpm-lock.yaml"] as const) {
const source = path.join(currentRelease, entry);
const target = path.join(stagedDir, entry);
let copied = false;
try {
const { execFile } = await import("node:child_process");
const { promisify } = await import("node:util");
await promisify(execFile)("cp", ["-a", source, target]);
copied = true;
} catch {}
if (!copied) {
const fsPromises = await import("node:fs/promises");
const sourceInfo = await fsPromises.lstat(source).catch(() => null);
if (sourceInfo && !sourceInfo.isSymbolicLink()) {
await fsPromises.cp(source, target, { recursive: sourceInfo.isDirectory(), errorOnExist: true, force: false }).catch(() => {});
}
}
}
}
} catch {}
}
await normalizeReleasePermissions(stagedDir).catch(() => {});
const fsPromises = await import("node:fs/promises");
const payloadInfo = await fsPromises.lstat(path.join(stagedDir, "dist")).catch(() => null);
if (!payloadInfo?.isDirectory() || payloadInfo.isSymbolicLink()) {
throw new Error("发布包缺少 dist 目录");
}
database.prepare("UPDATE update_jobs SET status='staged', actual_sha256=?, size_bytes=?, download_path=?, updated_at=? WHERE id=? AND status IN ('verifying', 'downloading')").run(downloaded.sha256, downloaded.size, workspace, Date.now(), jobId);
} catch (error) {
const controller = activeInProcessDownloads.get(jobId);
if (controller?.signal.aborted) return;
const rawMsg = error instanceof Error ? error.message : "更新文件下载失败";
try {
database.prepare("UPDATE update_jobs SET status='failed', error_message=?, updated_at=? WHERE id=? AND status NOT IN ('completed', 'staged', 'cancelled')").run(rawMsg, Date.now(), jobId);
} catch {}
const workspace = path.join(path.resolve(config.stagingDir), `update-${jobId}`);
const fsPromises = await import("node:fs/promises");
await fsPromises.rm(workspace, { recursive: true, force: true }).catch(() => {});
} finally {
activeInProcessDownloads.delete(jobId);
}
});
}
export const UPDATE_CACHE_KEY = "update.release.v1"; export const UPDATE_CACHE_KEY = "update.release.v1";
export const ACTIVE_UPDATE_STATUSES: readonly UpdateJobStatus[] = [ export const ACTIVE_UPDATE_STATUSES: readonly UpdateJobStatus[] = [
"queued", "queued",
@@ -574,6 +468,36 @@ export function reconcileOrphanedUpdateJobs(database: Database.Database, config:
let reconciled = 0; let reconciled = 0;
const reconciledIds = new Set<string>(); const reconciledIds = new Set<string>();
for (const row of rows) { for (const row of rows) {
// A request that never gets claimed by the root runner must not remain in
// the UI as an endless "queued" task. Once the short hand-off window has
// elapsed and no recovery marker exists, release the queue explicitly;
// a fresh state marker proves that the runner has already claimed it.
if (row.status === "queued" && typeof row.updatedAt === "number" && !stateFresh && now - row.updatedAt >= QUEUED_UPDATE_TIMEOUT_MS) {
const changed = database.transaction(() => {
const result = database.prepare(`
UPDATE update_jobs
SET status='failed', error_message=?, completed_at=?, updated_at=?
WHERE id=? AND status='queued' AND updated_at=?
`).run("更新服务未在规定时间内接管任务", now, now, row.id, row.updatedAt);
if (result.changes !== 1) return false;
writeAudit(database, {
requestId: row.requestId || randomUUID(),
actorAdminId: row.adminId,
action: "update.reconciled",
targetType: "update",
targetId: row.id,
outcome: "failure",
before: { status: row.status, version: row.version },
after: { status: "failed", version: row.version, reason: "runner_claim_timeout" },
});
return true;
})();
if (changed) {
reconciled += 1;
reconciledIds.add(row.id);
}
continue;
}
if (typeof row.updatedAt !== "number" || now - row.updatedAt < ORPHANED_UPDATE_TIMEOUT_MS) continue; if (typeof row.updatedAt !== "number" || now - row.updatedAt < ORPHANED_UPDATE_TIMEOUT_MS) continue;
// The runner refreshes the state marker while a download is in flight. // The runner refreshes the state marker while a download is in flight.
// A stale request/state marker therefore no longer protects an orphaned // A stale request/state marker therefore no longer protects an orphaned
@@ -668,12 +592,6 @@ export function cancelUpdateJob(
if (!job) return { cancelled: false, message: "当前没有处于等待调度或下载中的更新任务" }; if (!job) return { cancelled: false, message: "当前没有处于等待调度或下载中的更新任务" };
if (job.status !== "queued" && job.status !== "downloading") return { cancelled: false, message: "任务已进入就绪或切换阶段,无法取消" }; if (job.status !== "queued" && job.status !== "downloading") return { cancelled: false, message: "任务已进入就绪或切换阶段,无法取消" };
const controller = activeInProcessDownloads.get(job.id);
if (controller) {
controller.abort();
activeInProcessDownloads.delete(job.id);
}
const now = Date.now(); const now = Date.now();
const changed = database.transaction(() => { const changed = database.transaction(() => {
const result = database.prepare("UPDATE update_jobs SET status='cancelled', error_message='已手动取消更新', completed_at=?, updated_at=? WHERE id=? AND status IN ('queued', 'downloading')").run(now, now, job.id); const result = database.prepare("UPDATE update_jobs SET status='cancelled', error_message='已手动取消更新', completed_at=?, updated_at=? WHERE id=? AND status IN ('queued', 'downloading')").run(now, now, job.id);
+30 -37
View File
@@ -59,10 +59,10 @@ describe("更新 API", () => {
function mockRelease() { function mockRelease() {
const digest = "c".repeat(64); const digest = "c".repeat(64);
const asset = `tallynote-1.2.0-${detectPlatform().target}-glibc.tar.gz`; const asset = `tallynote-1.3.0-${detectPlatform().target}-glibc.tar.gz`;
globalThis.fetch = (async (input: string | URL) => input.toString().endsWith("SHA256SUMS") globalThis.fetch = (async (input: string | URL) => input.toString().endsWith("SHA256SUMS")
? new Response(`${digest} ${asset}\n`, { status: 200 }) ? new Response(`${digest} ${asset}\n`, { status: 200 })
: new Response(JSON.stringify({ tag_name: "v1.2.0", assets: [{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: asset, browser_download_url: `https://updates.example/${asset}` }] }), { status: 200 })) as typeof fetch; : new Response(JSON.stringify({ tag_name: "v1.3.0", assets: [{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: asset, browser_download_url: `https://updates.example/${asset}` }] }), { status: 200 })) as typeof fetch;
} }
it("检查 release、创建受保护请求文件并拒绝重复任务", async () => { it("检查 release、创建受保护请求文件并拒绝重复任务", async () => {
@@ -70,7 +70,7 @@ describe("更新 API", () => {
mockRelease(); mockRelease();
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} }); const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
expect(checked.statusCode).toBe(200); expect(checked.statusCode).toBe(200);
expect(checked.json().latest).toMatchObject({ version: "1.2.0", compatible: true, integrityReady: true, isNewer: true }); expect(checked.json().latest).toMatchObject({ version: "1.3.0", compatible: true, integrityReady: true, isNewer: true });
expect(checked.headers["cache-control"]).toBe("no-store"); expect(checked.headers["cache-control"]).toBe("no-store");
const tooSoon = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} }); const tooSoon = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
expect(tooSoon.statusCode).toBe(429); expect(tooSoon.statusCode).toBe(429);
@@ -82,15 +82,15 @@ describe("更新 API", () => {
const otherChecked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: otherSession.cookies, "x-csrf-token": otherSession.csrf }, payload: {} }); const otherChecked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: otherSession.cookies, "x-csrf-token": otherSession.csrf }, payload: {} });
expect(otherChecked.statusCode).toBe(200); expect(otherChecked.statusCode).toBe(200);
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } }); const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0", confirm: true } });
expect(applied.statusCode).toBe(202); expect(applied.statusCode).toBe(202);
const jobId = applied.json().job.id as string; const jobId = applied.json().job.id as string;
const request = JSON.parse(readFileSync(config.updateRequestPath, "utf8")) as { jobId: string; expectedSha256: string; currentLink: string }; const request = JSON.parse(readFileSync(config.updateRequestPath, "utf8")) as { jobId: string; expectedSha256: string; currentLink: string };
expect(request).toMatchObject({ jobId, version: "1.2.0", expectedSha256: "c".repeat(64), currentLink: config.currentLink }); expect(request).toMatchObject({ jobId, version: "1.3.0", expectedSha256: "c".repeat(64), currentLink: config.currentLink });
expect(statSync(config.updateRequestPath).mode & 0o777).toBe(0o600); expect(statSync(config.updateRequestPath).mode & 0o777).toBe(0o600);
mockRelease(); mockRelease();
const duplicate = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } }); const duplicate = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0", confirm: true } });
expect(duplicate.statusCode).toBe(409); expect(duplicate.statusCode).toBe(409);
expect(duplicate.json().error.code).toBe("UPDATE_IN_PROGRESS"); expect(duplicate.json().error.code).toBe("UPDATE_IN_PROGRESS");
const status = await app.inject({ method: "GET", url: "/api/update/status", headers: { cookie: session.cookies } }); const status = await app.inject({ method: "GET", url: "/api/update/status", headers: { cookie: session.cookies } });
@@ -104,10 +104,10 @@ describe("更新 API", () => {
mockRelease(); mockRelease();
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} }); const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
expect(checked.statusCode).toBe(200); expect(checked.statusCode).toBe(200);
const downloaded = await app.inject({ method: "POST", url: "/api/update/download", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } }); const downloaded = await app.inject({ method: "POST", url: "/api/update/download", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0", confirm: true } });
expect(downloaded.statusCode).toBe(202); expect(downloaded.statusCode).toBe(202);
const downloadJobId = downloaded.json().job.id as string; const downloadJobId = downloaded.json().job.id as string;
expect(downloaded.json().job).toMatchObject({ operation: "download", status: "queued", version: "1.2.0" }); expect(downloaded.json().job).toMatchObject({ operation: "download", status: "queued", version: "1.3.0" });
const downloadRequest = JSON.parse(readFileSync(config.updateRequestPath, "utf8")) as { jobId: string; operation: string }; const downloadRequest = JSON.parse(readFileSync(config.updateRequestPath, "utf8")) as { jobId: string; operation: string };
expect(downloadRequest).toMatchObject({ jobId: downloadJobId, operation: "download" }); expect(downloadRequest).toMatchObject({ jobId: downloadJobId, operation: "download" });
expect(database.sqlite.prepare("SELECT operation, status FROM update_jobs WHERE id=?").get(downloadJobId)).toEqual({ operation: "download", status: "queued" }); expect(database.sqlite.prepare("SELECT operation, status FROM update_jobs WHERE id=?").get(downloadJobId)).toEqual({ operation: "download", status: "queued" });
@@ -116,21 +116,21 @@ describe("更新 API", () => {
const stagedId = randomUUID(); const stagedId = randomUUID();
const now = Date.now(); const now = Date.now();
database.sqlite.prepare(`INSERT INTO update_jobs(id, admin_id, session_hash, request_id, requested_at, operation, status, version, platform, release_url, asset_name, asset_url, expected_sha256, actual_sha256, download_path, created_at, updated_at) VALUES (?, ?, ?, ?, ?, 'download', 'staged', ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)`) database.sqlite.prepare(`INSERT INTO update_jobs(id, admin_id, session_hash, request_id, requested_at, operation, status, version, platform, release_url, asset_name, asset_url, expected_sha256, actual_sha256, download_path, created_at, updated_at) VALUES (?, ?, ?, ?, ?, 'download', 'staged', ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)`)
.run(stagedId, (await database.sqlite.prepare("SELECT id FROM admins WHERE username=?").get("update-staged") as { id: string }).id, "session", "staged-request", now, "1.2.0", detectPlatform().target, config.updateMetadataUrl, "release.tar.gz", "https://updates.example/release.tar.gz", "c".repeat(64), "c".repeat(64), path.join(config.dataDir, "staged-workspace"), now, now); .run(stagedId, (await database.sqlite.prepare("SELECT id FROM admins WHERE username=?").get("update-staged") as { id: string }).id, "session", "staged-request", now, "1.3.0", detectPlatform().target, config.updateMetadataUrl, "release.tar.gz", "https://updates.example/release.tar.gz", "c".repeat(64), "c".repeat(64), path.join(config.dataDir, "staged-workspace"), now, now);
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { jobId: stagedId, version: "1.2.0", confirm: true } }); const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { jobId: stagedId, version: "1.3.0", confirm: true } });
expect(applied.statusCode).toBe(202); expect(applied.statusCode).toBe(202);
expect(applied.json().job).toMatchObject({ id: stagedId, operation: "apply", status: "staged" }); expect(applied.json().job).toMatchObject({ id: stagedId, operation: "apply", status: "staged" });
expect(database.sqlite.prepare("SELECT operation, status FROM update_jobs WHERE id=?").get(stagedId)).toEqual({ operation: "apply", status: "staged" }); expect(database.sqlite.prepare("SELECT operation, status FROM update_jobs WHERE id=?").get(stagedId)).toEqual({ operation: "apply", status: "staged" });
const applyRequest = JSON.parse(readFileSync(config.updateRequestPath, "utf8")) as { jobId: string; operation: string; assetUrl: string; expectedSha256: string }; const applyRequest = JSON.parse(readFileSync(config.updateRequestPath, "utf8")) as { jobId: string; operation: string; assetUrl: string; expectedSha256: string };
expect(applyRequest).toMatchObject({ jobId: stagedId, operation: "apply", assetUrl: "https://updates.example/release.tar.gz", expectedSha256: "c".repeat(64) }); expect(applyRequest).toMatchObject({ jobId: stagedId, operation: "apply", assetUrl: "https://updates.example/release.tar.gz", expectedSha256: "c".repeat(64) });
const duplicate = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { jobId: stagedId, version: "1.2.0", confirm: true } }); const duplicate = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { jobId: stagedId, version: "1.3.0", confirm: true } });
expect(duplicate.statusCode).toBe(409); expect(duplicate.statusCode).toBe(409);
expect(duplicate.json().error.code).toBe("UPDATE_IN_PROGRESS"); expect(duplicate.json().error.code).toBe("UPDATE_IN_PROGRESS");
}); });
it("缺少确认或未启用 systemd 时不接受更新", async () => { it("缺少确认或未启用 systemd 时不接受更新", async () => {
const session = await login(); const session = await login();
const invalid = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0" } }); const invalid = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0" } });
expect(invalid.statusCode).toBe(400); expect(invalid.statusCode).toBe(400);
process.env.TALLYNOTE_UPDATE_STRATEGY = "disabled"; process.env.TALLYNOTE_UPDATE_STRATEGY = "disabled";
const disabledConfig = loadConfig(); const disabledConfig = loadConfig();
@@ -152,7 +152,7 @@ describe("更新 API", () => {
mockRelease(); mockRelease();
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} }); const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
expect(checked.statusCode).toBe(200); expect(checked.statusCode).toBe(200);
expect(checked.json().latest).toMatchObject({ version: "1.2.0", isNewer: true }); expect(checked.json().latest).toMatchObject({ version: "1.3.0", isNewer: true });
}); });
it("更新任务只对发起管理员可见,并隐藏内部错误详情", async () => { it("更新任务只对发起管理员可见,并隐藏内部错误详情", async () => {
@@ -161,7 +161,7 @@ describe("更新 API", () => {
mockRelease(); mockRelease();
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: owner.cookies, "x-csrf-token": owner.csrf }, payload: {} }); const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: owner.cookies, "x-csrf-token": owner.csrf }, payload: {} });
expect(checked.statusCode).toBe(200); expect(checked.statusCode).toBe(200);
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: owner.cookies, "x-csrf-token": owner.csrf }, payload: { version: "1.2.0", confirm: true } }); const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: owner.cookies, "x-csrf-token": owner.csrf }, payload: { version: "1.3.0", confirm: true } });
expect(applied.statusCode).toBe(202); expect(applied.statusCode).toBe(202);
const jobId = applied.json().job.id as string; const jobId = applied.json().job.id as string;
database.sqlite.prepare("UPDATE update_jobs SET error_message=? WHERE id=?").run("/var/lib/tallynote/secret-command-output", jobId); database.sqlite.prepare("UPDATE update_jobs SET error_message=? WHERE id=?").run("/var/lib/tallynote/secret-command-output", jobId);
@@ -179,7 +179,7 @@ describe("更新 API", () => {
it("应用前重新校验失败时写入失败审计", async () => { it("应用前重新校验失败时写入失败审计", async () => {
const session = await login("update-audit"); const session = await login("update-audit");
globalThis.fetch = (async () => new Response("upstream unavailable", { status: 503 })) as typeof fetch; globalThis.fetch = (async () => new Response("upstream unavailable", { status: 503 })) as typeof fetch;
const response = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } }); const response = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0", confirm: true } });
expect(response.statusCode).toBe(502); expect(response.statusCode).toBe(502);
// A failed upstream check must not reserve the per-admin cooldown; an // A failed upstream check must not reserve the per-admin cooldown; an
// operator can retry immediately after fixing the release endpoint. // operator can retry immediately after fixing the release endpoint.
@@ -191,7 +191,7 @@ describe("更新 API", () => {
expect(audit?.outcome).toBe("failure"); expect(audit?.outcome).toBe("failure");
}); });
it("应用内直接执行流式下载,并在校验解包后自动推进到 staged 就绪状态", async () => { it("下载请求交由 systemd runner 接管,并保留可查询的排队状态", async () => {
const { createSafeArchive } = await import("../server/update.js"); const { createSafeArchive } = await import("../server/update.js");
const { createHash } = await import("node:crypto"); const { createHash } = await import("node:crypto");
const { mkdirSync, writeFileSync } = await import("node:fs"); const { mkdirSync, writeFileSync } = await import("node:fs");
@@ -204,7 +204,7 @@ describe("更新 API", () => {
const archiveBytes = readFileSync(archivePath); const archiveBytes = readFileSync(archivePath);
const digest = createHash("sha256").update(archiveBytes).digest("hex"); const digest = createHash("sha256").update(archiveBytes).digest("hex");
const assetName = `tallynote-1.2.0-${detectPlatform().target}-glibc.tar.gz`; const assetName = `tallynote-1.3.0-${detectPlatform().target}-glibc.tar.gz`;
globalThis.fetch = (async (input: string | URL) => { globalThis.fetch = (async (input: string | URL) => {
const url = input.toString(); const url = input.toString();
@@ -215,7 +215,7 @@ describe("更新 API", () => {
return new Response(archiveBytes, { status: 200, headers: { "content-length": String(archiveBytes.length) } }); return new Response(archiveBytes, { status: 200, headers: { "content-length": String(archiveBytes.length) } });
} }
return new Response(JSON.stringify({ return new Response(JSON.stringify({
tag_name: "v1.2.0", tag_name: "v1.3.0",
assets: [ assets: [
{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" },
{ name: assetName, browser_download_url: `https://updates.example/${assetName}` } { name: assetName, browser_download_url: `https://updates.example/${assetName}` }
@@ -227,27 +227,20 @@ describe("更新 API", () => {
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} }); const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
expect(checked.statusCode).toBe(200); expect(checked.statusCode).toBe(200);
const downloaded = await app.inject({ method: "POST", url: "/api/update/download", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } }); const downloaded = await app.inject({ method: "POST", url: "/api/update/download", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0", confirm: true } });
expect(downloaded.statusCode).toBe(202); expect(downloaded.statusCode).toBe(202);
const downloadJobId = downloaded.json().job.id as string; const downloadJobId = downloaded.json().job.id as string;
// Wait for in-process download pipeline to finish const stagedRow = database.sqlite.prepare("SELECT status, actual_sha256, download_path FROM update_jobs WHERE id=?").get(downloadJobId) as any;
let stagedRow: { status: string; actual_sha256: string; download_path: string } | undefined; expect(stagedRow?.status).toBe("queued");
for (let i = 0; i < 40; i++) { expect(stagedRow?.actual_sha256).toBeNull();
await new Promise((r) => setTimeout(r, 50)); expect(stagedRow?.download_path).toBeNull();
stagedRow = database.sqlite.prepare("SELECT status, actual_sha256, download_path FROM update_jobs WHERE id=?").get(downloadJobId) as any;
if (stagedRow?.status === "staged" || stagedRow?.status === "failed") break;
}
expect(stagedRow?.status).toBe("staged");
expect(stagedRow?.actual_sha256).toBe(digest);
expect(existsSync(path.join(stagedRow!.download_path, "payload", "dist", "server.js"))).toBe(true);
const statusRes = await app.inject({ method: "GET", url: "/api/update/status", headers: { cookie: session.cookies } }); const statusRes = await app.inject({ method: "GET", url: "/api/update/status", headers: { cookie: session.cookies } });
expect(statusRes.statusCode).toBe(200); expect(statusRes.statusCode).toBe(200);
expect(statusRes.json().job).toMatchObject({ expect(statusRes.json().job).toMatchObject({
id: downloadJobId, id: downloadJobId,
status: "staged", status: "queued",
operation: "download", operation: "download",
assetName, assetName,
assetUrl: `https://updates.example/${assetName}`, assetUrl: `https://updates.example/${assetName}`,
@@ -258,7 +251,7 @@ describe("更新 API", () => {
}); });
it("管理员可在流式下载进行中主动取消并中止下载", async () => { it("管理员可取消 systemd 下载任务并清理请求文件", async () => {
const { createSafeArchive } = await import("../server/update.js"); const { createSafeArchive } = await import("../server/update.js");
const { createHash } = await import("node:crypto"); const { createHash } = await import("node:crypto");
const { mkdirSync, writeFileSync } = await import("node:fs"); const { mkdirSync, writeFileSync } = await import("node:fs");
@@ -271,7 +264,7 @@ describe("更新 API", () => {
const archiveBytes = readFileSync(archivePath); const archiveBytes = readFileSync(archivePath);
const digest = createHash("sha256").update(archiveBytes).digest("hex"); const digest = createHash("sha256").update(archiveBytes).digest("hex");
const assetName = `tallynote-1.2.0-${detectPlatform().target}-glibc.tar.gz`; const assetName = `tallynote-1.3.0-${detectPlatform().target}-glibc.tar.gz`;
// Mock a slow stream // Mock a slow stream
let fetchAborted = false; let fetchAborted = false;
@@ -298,7 +291,7 @@ describe("更新 API", () => {
return new Response(stream, { status: 200, headers: { "content-length": String(archiveBytes.length) } }); return new Response(stream, { status: 200, headers: { "content-length": String(archiveBytes.length) } });
} }
return new Response(JSON.stringify({ return new Response(JSON.stringify({
tag_name: "v1.2.0", tag_name: "v1.3.0",
assets: [ assets: [
{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" },
{ name: assetName, browser_download_url: `https://updates.example/${assetName}` } { name: assetName, browser_download_url: `https://updates.example/${assetName}` }
@@ -309,7 +302,7 @@ describe("更新 API", () => {
const session = await login("update-cancel-inprocess"); const session = await login("update-cancel-inprocess");
await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} }); await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
const downloaded = await app.inject({ method: "POST", url: "/api/update/download", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } }); const downloaded = await app.inject({ method: "POST", url: "/api/update/download", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0", confirm: true } });
const downloadJobId = downloaded.json().job.id as string; const downloadJobId = downloaded.json().job.id as string;
// Wait until status becomes downloading // Wait until status becomes downloading
@@ -331,7 +324,7 @@ describe("更新 API", () => {
const cancelledRow = database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(downloadJobId) as any; const cancelledRow = database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(downloadJobId) as any;
expect(cancelledRow?.status).toBe("cancelled"); expect(cancelledRow?.status).toBe("cancelled");
expect(fetchAborted).toBe(true); expect(fetchAborted).toBe(false);
rmSync(payloadSource, { recursive: true, force: true }); rmSync(payloadSource, { recursive: true, force: true });
rmSync(archivePath, { force: true }); rmSync(archivePath, { force: true });
@@ -341,7 +334,7 @@ describe("更新 API", () => {
const session = await login("update-cancel"); const session = await login("update-cancel");
mockRelease(); mockRelease();
await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} }); await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } }); const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.3.0", confirm: true } });
expect(applied.statusCode).toBe(202); expect(applied.statusCode).toBe(202);
expect(existsSync(config.updateRequestPath)).toBe(true); expect(existsSync(config.updateRequestPath)).toBe(true);
+25 -25
View File
@@ -40,23 +40,23 @@ describe("更新安全工具", () => {
expect(isNewerVersion("1.0.0", "1.0.0-beta.1")).toBe(false); expect(isNewerVersion("1.0.0", "1.0.0-beta.1")).toBe(false);
expect(detectPlatform("linux", "x86_64").target).toBe("linux-x64"); expect(detectPlatform("linux", "x86_64").target).toBe("linux-x64");
const release = { const release = {
version: "1.2.0", version: "1.3.0",
assets: [ assets: [
{ name: "tallynote-1.2.0-linux-arm64-glibc.tar.gz", url: "https://updates.example/arm" }, { name: "tallynote-1.3.0-linux-arm64-glibc.tar.gz", url: "https://updates.example/arm" },
{ name: "tallynote-1.2.0-linux-x64-glibc.tar.gz", url: "https://updates.example/x64" }, { name: "tallynote-1.3.0-linux-x64-glibc.tar.gz", url: "https://updates.example/x64" },
], ],
}; };
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"))?.name).toContain("linux-x64"); expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"))?.name).toContain("linux-x64");
expect(selectReleaseAsset({ version: "1.2.0", assets: [{ name: "tallynote-1.2.0-linux-arm64-glibc.tar.gz", url: "https://updates.example/arm" }] }, detectPlatform("linux", "x86_64"))).toBeUndefined(); expect(selectReleaseAsset({ version: "1.3.0", assets: [{ name: "tallynote-1.3.0-linux-arm64-glibc.tar.gz", url: "https://updates.example/arm" }] }, detectPlatform("linux", "x86_64"))).toBeUndefined();
expect(() => validateHttpsUrl("http://updates.example/x64", { allowedHosts: ["updates.example"] })).toThrow(); expect(() => validateHttpsUrl("http://updates.example/x64", { allowedHosts: ["updates.example"] })).toThrow();
expect(() => sanitizeAssetName("../release.tar.gz")).toThrow(); expect(() => sanitizeAssetName("../release.tar.gz")).toThrow();
}); });
it("优先选择运行时匹配的轻量更新包,并对旧客户端保留完整包回退", () => { it("优先选择运行时匹配的轻量更新包,并对旧客户端保留完整包回退", () => {
const runtimeHash = runtimeHashFromLockfile("lockfile-v1\n"); const runtimeHash = runtimeHashFromLockfile("lockfile-v1\n");
const full = { name: "tallynote-1.2.0-linux-x64-glibc.tar.gz", url: "https://updates.example/full" }; const full = { name: "tallynote-1.3.0-linux-x64-glibc.tar.gz", url: "https://updates.example/full" };
const app = { name: `tallynote-1.2.0-linux-x64-glibc.update-${runtimeHash}.tar.gz`, url: "https://updates.example/app" }; const app = { name: `tallynote-1.3.0-linux-x64-glibc.update-${runtimeHash}.tar.gz`, url: "https://updates.example/app" };
const release = { version: "1.2.0", assets: [full, app] }; const release = { version: "1.3.0", assets: [full, app] };
expect(applicationUpdateRuntimeHash(app.name)).toBe(runtimeHash); expect(applicationUpdateRuntimeHash(app.name)).toBe(runtimeHash);
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"), runtimeHash)).toEqual(app); expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"), runtimeHash)).toEqual(app);
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"))).toEqual(full); expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"))).toEqual(full);
@@ -102,12 +102,12 @@ describe("更新安全工具", () => {
globalThis.fetch = (async (input: string | URL) => { globalThis.fetch = (async (input: string | URL) => {
const url = input.toString(); const url = input.toString();
if (url.endsWith("/latest")) { if (url.endsWith("/latest")) {
return new Response(JSON.stringify({ tag_name: "v1.2.0", assets: [{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: "app-linux-x64.tar.gz", browser_download_url: "https://updates.example/app-linux-x64.tar.gz" }] }), { status: 200, headers: { "content-type": "application/json" } }); return new Response(JSON.stringify({ tag_name: "v1.3.0", assets: [{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: "app-linux-x64.tar.gz", browser_download_url: "https://updates.example/app-linux-x64.tar.gz" }] }), { status: 200, headers: { "content-type": "application/json" } });
} }
return new Response(`${digest} app-linux-x64.tar.gz\n`, { status: 200 }); return new Response(`${digest} app-linux-x64.tar.gz\n`, { status: 200 });
}) as typeof fetch; }) as typeof fetch;
const metadata = await fetchReleaseMetadata("https://updates.example/latest", { allowedHosts: ["updates.example"] }); const metadata = await fetchReleaseMetadata("https://updates.example/latest", { allowedHosts: ["updates.example"] });
expect(metadata.version).toBe("1.2.0"); expect(metadata.version).toBe("1.3.0");
expect((await fetchReleaseText("https://updates.example/SHA256SUMS", { allowedHosts: ["updates.example"] })).trim()).toContain(digest); expect((await fetchReleaseText("https://updates.example/SHA256SUMS", { allowedHosts: ["updates.example"] })).trim()).toContain(digest);
}); });
@@ -253,22 +253,22 @@ describe("更新安全工具", () => {
const jobId = randomUUID(); const jobId = randomUUID();
database = openDatabase(config); database = openDatabase(config);
const now = Date.now(); const now = Date.now();
const assetName = `tallynote-1.2.0-${detectPlatform().target}.tar.gz`; const assetName = `tallynote-1.3.0-${detectPlatform().target}.tar.gz`;
database.sqlite.prepare(` database.sqlite.prepare(`
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, INSERT INTO update_jobs(id, operation, status, version, platform, asset_url,
expected_sha256, created_at, updated_at, requested_at) expected_sha256, created_at, updated_at, requested_at)
VALUES (?, 'apply', 'queued', '1.2.0', ?, ?, ?, ?, ?, ?) VALUES (?, 'apply', 'queued', '1.3.0', ?, ?, ?, ?, ?, ?)
`).run(jobId, detectPlatform().target, "https://updates.example/" + assetName, digest, now, now, now); `).run(jobId, detectPlatform().target, "https://updates.example/" + assetName, digest, now, now, now);
globalThis.fetch = (async (input: string | URL) => { globalThis.fetch = (async (input: string | URL) => {
const url = input.toString(); const url = input.toString();
if (url.endsWith("/latest")) return new Response(JSON.stringify({ tag_name: "v1.2.0", assets: [{ name: assetName, browser_download_url: `https://updates.example/${assetName}` }, { name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }] })); if (url.endsWith("/latest")) return new Response(JSON.stringify({ tag_name: "v1.3.0", assets: [{ name: assetName, browser_download_url: `https://updates.example/${assetName}` }, { name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }] }));
if (url.endsWith("SHA256SUMS")) return new Response(`${digest} ${assetName}\n`); if (url.endsWith("SHA256SUMS")) return new Response(`${digest} ${assetName}\n`);
return new Response(bytes, { headers: { "content-length": String(bytes.length) } }); return new Response(bytes, { headers: { "content-length": String(bytes.length) } });
}) as typeof fetch; }) as typeof fetch;
await runUpdate({ await runUpdate({
metadataUrl: config.updateMetadataUrl, metadataUrl: config.updateMetadataUrl,
version: "1.2.0", version: "1.3.0",
currentVersion: config.appVersion, currentVersion: config.appVersion,
currentDir: config.currentLink, currentDir: config.currentLink,
stagingDir: path.join(root, "staging"), stagingDir: path.join(root, "staging"),
@@ -323,10 +323,10 @@ describe("更新安全工具", () => {
const applyingId = randomUUID(); const applyingId = randomUUID();
const stagedId = randomUUID(); const stagedId = randomUUID();
const stagedApplyId = randomUUID(); const stagedApplyId = randomUUID();
insert.run(queuedId, "apply", "queued", "1.2.0", "linux-x64", "https://updates.example/queued.tar.gz", staleAt, staleAt); insert.run(queuedId, "apply", "queued", "1.3.0", "linux-x64", "https://updates.example/queued.tar.gz", staleAt, staleAt);
insert.run(applyingId, "apply", "applying", config.appVersion, "linux-x64", "https://updates.example/applying.tar.gz", staleAt, staleAt); insert.run(applyingId, "apply", "applying", config.appVersion, "linux-x64", "https://updates.example/applying.tar.gz", staleAt, staleAt);
insert.run(stagedId, "download", "staged", "1.2.0", "linux-x64", "https://updates.example/staged.tar.gz", staleAt, staleAt); insert.run(stagedId, "download", "staged", "1.3.0", "linux-x64", "https://updates.example/staged.tar.gz", staleAt, staleAt);
insert.run(stagedApplyId, "apply", "staged", "1.2.0", "linux-x64", "https://updates.example/staged-apply.tar.gz", staleAt, staleAt); insert.run(stagedApplyId, "apply", "staged", "1.3.0", "linux-x64", "https://updates.example/staged-apply.tar.gz", staleAt, staleAt);
const now = Date.now(); const now = Date.now();
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, now)).toBe(3); expect(reconcileOrphanedUpdateJobs(database.sqlite, config, now)).toBe(3);
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(queuedId)).toEqual({ status: "failed" }); expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(queuedId)).toEqual({ status: "failed" });
@@ -362,7 +362,7 @@ describe("更新安全工具", () => {
const jobId = randomUUID(); const jobId = randomUUID();
database.sqlite.prepare(` database.sqlite.prepare(`
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at) INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
VALUES (?, 'download', 'downloading', '1.2.0', 'linux-x64', ?, ?, ?) VALUES (?, 'download', 'downloading', '1.3.0', 'linux-x64', ?, ?, ?)
`).run(jobId, "https://updates.example/download.tar.gz", staleAt, staleAt); `).run(jobId, "https://updates.example/download.tar.gz", staleAt, staleAt);
await writeFile(config.updateRequestPath, JSON.stringify({ jobId, operation: "download" })); await writeFile(config.updateRequestPath, JSON.stringify({ jobId, operation: "download" }));
const statePath = path.join(config.installPrefix, ".update-state"); const statePath = path.join(config.installPrefix, ".update-state");
@@ -406,18 +406,18 @@ describe("更新安全工具", () => {
const jobId = randomUUID(); const jobId = randomUUID();
database.sqlite.prepare(` database.sqlite.prepare(`
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at) INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
VALUES (?, 'apply', 'queued', '1.2.0', 'linux-x64', ?, ?, ?) VALUES (?, 'apply', 'queued', '1.3.0', 'linux-x64', ?, ?, ?)
`).run(jobId, "https://updates.example/queued.tar.gz", staleAt, staleAt); `).run(jobId, "https://updates.example/queued.tar.gz", staleAt, staleAt);
await writeFile(config.updateRequestPath, JSON.stringify({ jobId, operation: "apply" })); await writeFile(config.updateRequestPath, JSON.stringify({ jobId, operation: "apply" }));
const now = Date.now(); const now = Date.now();
await utimes(config.updateRequestPath, new Date(now), new Date(now)); await utimes(config.updateRequestPath, new Date(now), new Date(now));
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, now)).toBe(0); expect(reconcileOrphanedUpdateJobs(database.sqlite, config, now)).toBe(1);
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "queued" }); expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "failed" });
expect(await stat(config.updateRequestPath)).toBeTruthy(); await expect(stat(config.updateRequestPath)).rejects.toThrow();
const expiredNow = now + ORPHANED_UPDATE_TIMEOUT_MS + 1; const expiredNow = now + ORPHANED_UPDATE_TIMEOUT_MS + 1;
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, expiredNow)).toBe(1); expect(reconcileOrphanedUpdateJobs(database.sqlite, config, expiredNow)).toBe(0);
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "failed" }); expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "failed" });
await expect(stat(config.updateRequestPath)).rejects.toThrow(); await expect(stat(config.updateRequestPath)).rejects.toThrow();
} finally { } finally {
@@ -492,17 +492,17 @@ describe("更新元数据缓存", () => {
prepareDataDirectories(config); prepareDataDirectories(config);
const database = openDatabase(config); const database = openDatabase(config);
const digest = "b".repeat(64); const digest = "b".repeat(64);
const platformAsset = `tallynote-1.2.0-${detectPlatform().target}-glibc.tar.gz`; const platformAsset = `tallynote-1.3.0-${detectPlatform().target}-glibc.tar.gz`;
const sums = `${digest} ${platformAsset}\n`; const sums = `${digest} ${platformAsset}\n`;
const signature = sign(null, Buffer.from(sums), privateKey); const signature = sign(null, Buffer.from(sums), privateKey);
globalThis.fetch = (async (input: string | URL) => input.toString().endsWith("SHA256SUMS.sig") globalThis.fetch = (async (input: string | URL) => input.toString().endsWith("SHA256SUMS.sig")
? new Response(signature) ? new Response(signature)
: input.toString().endsWith("SHA256SUMS") : input.toString().endsWith("SHA256SUMS")
? new Response(sums) ? new Response(sums)
: new Response(JSON.stringify({ tag_name: "v1.2.0", published_at: "2026-08-28T00:00:00Z", assets: [{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: "SHA256SUMS.sig", browser_download_url: "https://updates.example/SHA256SUMS.sig" }, { name: platformAsset, browser_download_url: `https://updates.example/${platformAsset}` }] }), { status: 200 })) as typeof fetch; : new Response(JSON.stringify({ tag_name: "v1.3.0", published_at: "2026-08-28T00:00:00Z", assets: [{ name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }, { name: "SHA256SUMS.sig", browser_download_url: "https://updates.example/SHA256SUMS.sig" }, { name: platformAsset, browser_download_url: `https://updates.example/${platformAsset}` }] }), { status: 200 })) as typeof fetch;
try { try {
const result = await checkForUpdate(database.sqlite, config); const result = await checkForUpdate(database.sqlite, config);
expect(result.latest).toMatchObject({ version: "1.2.0", compatible: true, integrityReady: true, signatureReady: true, isNewer: true }); expect(result.latest).toMatchObject({ version: "1.3.0", compatible: true, integrityReady: true, signatureReady: true, isNewer: true });
const cached = database.sqlite.prepare("SELECT value FROM system_settings WHERE key='update.release.v1'").get() as { value: string }; const cached = database.sqlite.prepare("SELECT value FROM system_settings WHERE key='update.release.v1'").get() as { value: string };
expect(JSON.parse(cached.value).asset.sha256).toBe(digest); expect(JSON.parse(cached.value).asset.sha256).toBe(digest);
} finally { } finally {
+5 -14
View File
@@ -254,7 +254,6 @@ export default function UpdatePage({
const [showUpgradeModal, setShowUpgradeModal] = useState(false); const [showUpgradeModal, setShowUpgradeModal] = useState(false);
const [confirmReadyToDownload, setConfirmReadyToDownload] = useState(false); const [confirmReadyToDownload, setConfirmReadyToDownload] = useState(false);
const [cancelling, setCancelling] = useState(false); const [cancelling, setCancelling] = useState(false);
const [queuedSeconds, setQueuedSeconds] = useState(0);
const [now, setNow] = useState(() => Date.now()); const [now, setNow] = useState(() => Date.now());
const announced = useRef<string | null>(null); const announced = useRef<string | null>(null);
@@ -321,17 +320,9 @@ export default function UpdatePage({
else setLoading(false); else setLoading(false);
}, [isMock]); }, [isMock]);
// Terminal failures or cancellations do not pollute active state // Keep terminal jobs visible so operators can understand what happened and
const job = info?.job && info.job.status !== "failed" && info.job.status !== "cancelled" ? info.job : null; // recover without guessing. The polling effect below only polls active jobs.
const job = info?.job ?? null;
// Queued duration counter
useEffect(() => {
if (job?.status === "queued") {
const timer = window.setInterval(() => setQueuedSeconds((s) => s + 1), 1000);
return () => window.clearInterval(timer);
}
setQueuedSeconds(0);
}, [job?.status]);
const applyQueuedAt = timestamp(job?.applyQueuedAt); const applyQueuedAt = timestamp(job?.applyQueuedAt);
const restartAt = const restartAt =
@@ -409,7 +400,7 @@ export default function UpdatePage({
disposed = true; disposed = true;
if (timer !== undefined) window.clearTimeout(timer); if (timer !== undefined) window.clearTimeout(timer);
}; };
}, [isMock, job?.id, job?.status, job?.operation, notify, restartSeconds]); }, [isMock, job?.id, job?.status, job?.operation, notify]);
// Check update handler // Check update handler
const check = async () => { const check = async () => {
@@ -918,7 +909,7 @@ export default function UpdatePage({
{job?.status === "queued" && ( {job?.status === "queued" && (
<div className="tn-modal-card-box"> <div className="tn-modal-card-box">
<div className="tn-modal-card-title"> <div className="tn-modal-card-title">
<div style={{ marginBottom: 12 }}><BeamBar width={160} /></div>正在建立与官方 Git 仓库的流式传输连接... <div style={{ marginBottom: 12 }}><BeamBar width={160} /></div>正在等待系统更新服务接管任务...
</div> </div>
<div className="tn-modal-actions-bar"> <div className="tn-modal-actions-bar">