Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
4f9629b089 | ||
|
|
36c2ed1361 | ||
|
|
755b82d2e5 | ||
|
|
0bdc812935 | ||
|
|
2de08f1358 | ||
|
|
91621df6c4 | ||
|
|
0690fe298c | ||
|
|
6a0d9e34dd | ||
|
|
77598ecc81 | ||
|
|
69a4b482ec | ||
|
|
ee89e04aae | ||
|
|
b431fe167e |
@@ -30,6 +30,7 @@ jobs:
|
|||||||
pnpm install --frozen-lockfile
|
pnpm install --frozen-lockfile
|
||||||
pnpm check
|
pnpm check
|
||||||
pnpm test
|
pnpm test
|
||||||
|
pnpm test:installer
|
||||||
- name: Build Linux release
|
- name: Build Linux release
|
||||||
run: pnpm release:build "${GITHUB_REF_NAME#v}" ./release
|
run: pnpm release:build "${GITHUB_REF_NAME#v}" ./release
|
||||||
- name: Create and publish Gitea Release
|
- name: Create and publish Gitea Release
|
||||||
|
|||||||
@@ -140,7 +140,7 @@ curl --proto '=https' --tlsv1.2 -fsSL https://git.awaioi.com/awaioi/TallyNote/ra
|
|||||||
|
|
||||||
卸载器会逐项输出停止、禁用和删除进度;每次 systemd/dbus 调用默认最多等待 30 秒,避免终端无限无响应。可通过 `TALLYNOTE_UNINSTALL_SYSTEMCTL_TIMEOUT_SECONDS` 调整超时时间。
|
卸载器会逐项输出停止、禁用和删除进度;每次 systemd/dbus 调用默认最多等待 30 秒,避免终端无限无响应。可通过 `TALLYNOTE_UNINSTALL_SYSTEMCTL_TIMEOUT_SECONDS` 调整超时时间。
|
||||||
|
|
||||||
公网反代必须使用 HTTPS,并在环境文件中设置真实的 `TALLYNOTE_PUBLIC_ORIGIN=https://...`、`TALLYNOTE_COOKIE_SECURE=true` 和明确的 `TALLYNOTE_TRUST_PROXY` 跳数(不要使用生产值 `true`)。
|
公网反代推荐使用 HTTPS,并在环境文件中设置真实的 `TALLYNOTE_PUBLIC_ORIGIN=https://...`、`TALLYNOTE_COOKIE_SECURE=true` 和明确的 `TALLYNOTE_TRUST_PROXY` 跳数(不要使用生产值 `true`)。反代只需把域名转发到 TallyNote 端口并保留 `Host`、`X-Forwarded-Proto`;应用不会因为代理缺少或改写浏览器 `Origin` 而拦截登录。已认证写请求仍使用会话 Cookie 与 CSRF 令牌保护。
|
||||||
|
|
||||||
### 构建发布包
|
### 构建发布包
|
||||||
|
|
||||||
|
|||||||
+6
-3
@@ -1012,7 +1012,10 @@ validate_listen_port() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
validate_public_origin() {
|
validate_public_origin() {
|
||||||
local value=$1 authority host path_part origin_port suffix
|
# Keep the optional origin port defined under `set -u`. Origins without an
|
||||||
|
# explicit port (for example https://example.test) are valid and should
|
||||||
|
# proceed to the default-port handling below.
|
||||||
|
local value=$1 authority host path_part origin_port='' suffix
|
||||||
case "$value" in
|
case "$value" in
|
||||||
http://*|https://*) ;;
|
http://*|https://*) ;;
|
||||||
*) die '公开访问地址必须是 http:// 或 https:// 地址' ;;
|
*) die '公开访问地址必须是 http:// 或 https:// 地址' ;;
|
||||||
@@ -1074,7 +1077,7 @@ validate_existing_env() {
|
|||||||
mode_bits=$(stat_mode_bits "$file")
|
mode_bits=$(stat_mode_bits "$file")
|
||||||
(( (mode_bits & 18) == 0 )) || die '环境文件不能被组或其他用户写入'
|
(( (mode_bits & 18) == 0 )) || die '环境文件不能被组或其他用户写入'
|
||||||
local key key_count
|
local key key_count
|
||||||
for key in TALLYNOTE_INSTALL_PREFIX TALLYNOTE_DATA_DIR TALLYNOTE_HOST TALLYNOTE_PORT TALLYNOTE_PUBLIC_ORIGIN TALLYNOTE_ALLOW_INSECURE_HTTP TALLYNOTE_COOKIE_SECURE TALLYNOTE_UPDATE_REQUIRE_SIGNATURE TALLYNOTE_UPDATE_METADATA_URL TALLYNOTE_UPDATE_ALLOWED_HOSTS TALLYNOTE_UPDATE_PUBLIC_KEY_FILE; do
|
for key in TALLYNOTE_INSTALL_PREFIX TALLYNOTE_DATA_DIR TALLYNOTE_HOST TALLYNOTE_PORT TALLYNOTE_PUBLIC_ORIGIN TALLYNOTE_ALLOWED_ORIGINS TALLYNOTE_ALLOW_INSECURE_HTTP TALLYNOTE_COOKIE_SECURE TALLYNOTE_UPDATE_REQUIRE_SIGNATURE TALLYNOTE_UPDATE_METADATA_URL TALLYNOTE_UPDATE_ALLOWED_HOSTS TALLYNOTE_UPDATE_PUBLIC_KEY_FILE; do
|
||||||
key_count=$(env_key_count "$file" "$key")
|
key_count=$(env_key_count "$file" "$key")
|
||||||
[[ "$key_count" =~ ^[0-9]+$ && "$key_count" -le 1 ]] || die "环境文件包含重复配置:$key"
|
[[ "$key_count" =~ ^[0-9]+$ && "$key_count" -le 1 ]] || die "环境文件包含重复配置:$key"
|
||||||
done
|
done
|
||||||
@@ -1395,7 +1398,7 @@ main() {
|
|||||||
unit_tmp=$(mktemp -d)
|
unit_tmp=$(mktemp -d)
|
||||||
sed "s#/opt/tallynote#$PREFIX#g; s#/var/lib/tallynote#$DATA_DIR#g" "$release_dir/systemd/tallynote.service" > "$unit_tmp/tallynote.service"
|
sed "s#/opt/tallynote#$PREFIX#g; s#/var/lib/tallynote#$DATA_DIR#g" "$release_dir/systemd/tallynote.service" > "$unit_tmp/tallynote.service"
|
||||||
sed "s#/opt/tallynote#$PREFIX#g; s#/var/lib/tallynote#$DATA_DIR#g; s#/var/lib/tallynote-backups#$(dirname -- "$DATA_DIR")/tallynote-backups#g" "$release_dir/systemd/tallynote-update.service" > "$unit_tmp/tallynote-update.service"
|
sed "s#/opt/tallynote#$PREFIX#g; s#/var/lib/tallynote#$DATA_DIR#g; s#/var/lib/tallynote-backups#$(dirname -- "$DATA_DIR")/tallynote-backups#g" "$release_dir/systemd/tallynote-update.service" > "$unit_tmp/tallynote-update.service"
|
||||||
sed "s#/var/lib/tallynote#$DATA_DIR#g" "$release_dir/systemd/tallynote-update.path" > "$unit_tmp/tallynote-update.path"
|
sed "s#/opt/tallynote#$PREFIX#g; s#/var/lib/tallynote#$DATA_DIR#g" "$release_dir/systemd/tallynote-update.path" > "$unit_tmp/tallynote-update.path"
|
||||||
sed "s#/opt/tallynote#$PREFIX#g; s#/etc/tallynote#$CONFIG_DIR#g" "$release_dir/bin/tallynote-admin-init" > "$unit_tmp/tallynote-admin-init"
|
sed "s#/opt/tallynote#$PREFIX#g; s#/etc/tallynote#$CONFIG_DIR#g" "$release_dir/bin/tallynote-admin-init" > "$unit_tmp/tallynote-admin-init"
|
||||||
install -o root -g root -m 644 "$unit_tmp/tallynote.service" /etc/systemd/system/tallynote.service
|
install -o root -g root -m 644 "$unit_tmp/tallynote.service" /etc/systemd/system/tallynote.service
|
||||||
install -o root -g root -m 644 "$unit_tmp/tallynote-update.service" /etc/systemd/system/tallynote-update.service
|
install -o root -g root -m 644 "$unit_tmp/tallynote-update.service" /etc/systemd/system/tallynote-update.service
|
||||||
|
|||||||
@@ -0,0 +1,3 @@
|
|||||||
|
ALTER TABLE update_jobs ADD COLUMN downloaded_bytes INTEGER;
|
||||||
|
ALTER TABLE update_jobs ADD COLUMN download_started_at INTEGER;
|
||||||
|
ALTER TABLE update_jobs ADD COLUMN download_speed_bps INTEGER;
|
||||||
+1
-1
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "tallynote",
|
"name": "tallynote",
|
||||||
"version": "1.1.12",
|
"version": "1.1.22",
|
||||||
"private": true,
|
"private": true,
|
||||||
"type": "module",
|
"type": "module",
|
||||||
"packageManager": "pnpm@9.0.6",
|
"packageManager": "pnpm@9.0.6",
|
||||||
|
|||||||
@@ -32,16 +32,120 @@ if [[ -f "$REQUEST_FILE" && ! -L "$REQUEST_FILE" ]]; then
|
|||||||
[[ "$request_operation" == download || "$request_operation" == apply ]] || request_operation='apply'
|
[[ "$request_operation" == download || "$request_operation" == apply ]] || request_operation='apply'
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# Capture the request id before any privileged preflight can fail. The
|
||||||
|
# request file is an application-owned one-shot marker; removing it on an
|
||||||
|
# early runner failure lets the server-side lease reaper release the DB row.
|
||||||
|
job_id=''
|
||||||
|
if [[ -f "$REQUEST_FILE" && ! -L "$REQUEST_FILE" ]]; then
|
||||||
|
job_id=$(sed -n 's/.*"jobId"[[:space:]]*:[[:space:]]*"\([0-9a-f-]*\)".*/\1/p' "$REQUEST_FILE" | head -n 1)
|
||||||
|
fi
|
||||||
|
STATE_CREATED=0
|
||||||
|
heartbeat_pid=''
|
||||||
|
heartbeat_owner=$$
|
||||||
|
|
||||||
|
write_recovery_state() {
|
||||||
|
local phase=$1 temporary
|
||||||
|
temporary="$PREFIX/.update-state-$$-${RANDOM}.tmp"
|
||||||
|
[[ ! -e "$temporary" && ! -L "$temporary" ]] || return 1
|
||||||
|
printf 'job_id=%s\nold_target=%s\nphase=%s\n' "$job_id" "$old_target" "$phase" > "$temporary"
|
||||||
|
chmod 600 "$temporary"
|
||||||
|
mv -Tf -- "$temporary" "$STATE_FILE"
|
||||||
|
STATE_CREATED=1
|
||||||
|
}
|
||||||
|
|
||||||
|
clear_recovery_state() {
|
||||||
|
[[ ! -L "$STATE_FILE" ]] || return 1
|
||||||
|
rm -f -- "$STATE_FILE"
|
||||||
|
STATE_CREATED=0
|
||||||
|
}
|
||||||
|
|
||||||
|
stop_heartbeat() {
|
||||||
|
if [[ -n "$heartbeat_pid" ]]; then
|
||||||
|
kill "$heartbeat_pid" 2>/dev/null || true
|
||||||
|
wait "$heartbeat_pid" 2>/dev/null || true
|
||||||
|
heartbeat_pid=''
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
heartbeat() {
|
||||||
|
# Keep the lease fresh during long downloads/backups, but stop on a hard
|
||||||
|
# runner kill so an orphaned child cannot keep the recovery marker alive.
|
||||||
|
while kill -0 "$heartbeat_owner" 2>/dev/null; do
|
||||||
|
sleep 10 || exit 0
|
||||||
|
[[ -f "$STATE_FILE" && ! -L "$STATE_FILE" ]] || exit 0
|
||||||
|
touch "$STATE_FILE" 2>/dev/null || exit 0
|
||||||
|
done
|
||||||
|
}
|
||||||
|
|
||||||
|
start_heartbeat() {
|
||||||
|
stop_heartbeat
|
||||||
|
heartbeat &
|
||||||
|
heartbeat_pid=$!
|
||||||
|
}
|
||||||
|
|
||||||
|
# This trap covers failures before the normal apply cleanup trap is installed,
|
||||||
|
# including a missing runtime, an invalid current link, and a failed service
|
||||||
|
# stop. It deliberately does not remove a pre-existing recovery marker.
|
||||||
|
preflight_cleanup() {
|
||||||
|
local result=$?
|
||||||
|
stop_heartbeat
|
||||||
|
if (( result != 0 )); then
|
||||||
|
rm -f -- "$REQUEST_FILE" 2>/dev/null || true
|
||||||
|
if (( STATE_CREATED == 1 )); then clear_recovery_state || true; fi
|
||||||
|
fi
|
||||||
|
return "$result"
|
||||||
|
}
|
||||||
|
trap preflight_cleanup EXIT
|
||||||
|
|
||||||
# Downloading is intentionally handled while the main service remains up.
|
# Downloading is intentionally handled while the main service remains up.
|
||||||
# The CLI persists the validated payload under the root-owned workspace and
|
# The CLI persists the validated payload under the root-owned workspace and
|
||||||
# leaves the job staged for a later apply request.
|
# leaves the job staged for a later apply request.
|
||||||
if [[ "$request_operation" == download ]]; then
|
if [[ "$request_operation" == download ]]; then
|
||||||
|
# A previous download runner may have been interrupted after creating its
|
||||||
|
# marker. Clear only that download marker and retry the idempotent request.
|
||||||
|
if [[ -f "$STATE_FILE" && ! -L "$STATE_FILE" ]] && grep -q '^phase=download$' "$STATE_FILE"; then
|
||||||
|
clear_recovery_state || die '无法清理上一次下载状态'
|
||||||
|
fi
|
||||||
|
write_recovery_state download || die '无法写入更新恢复状态'
|
||||||
|
cleanup_download() {
|
||||||
|
local result=$?
|
||||||
|
stop_heartbeat
|
||||||
|
if (( result != 0 )); then
|
||||||
|
# The CLI normally records failed itself. If it died before opening the
|
||||||
|
# database, the expired marker/request will be reconciled by the app.
|
||||||
|
rm -f -- "$REQUEST_FILE" 2>/dev/null || true
|
||||||
|
fi
|
||||||
|
clear_recovery_state || true
|
||||||
|
return "$result"
|
||||||
|
}
|
||||||
|
trap cleanup_download EXIT
|
||||||
|
trap 'exit 143' TERM
|
||||||
|
trap 'exit 130' INT
|
||||||
|
start_heartbeat
|
||||||
node_bin="$CURRENT_LINK/runtime/bin/node"
|
node_bin="$CURRENT_LINK/runtime/bin/node"
|
||||||
[[ -x "$node_bin" ]] || node_bin=$(command -v node || true)
|
[[ -x "$node_bin" ]] || node_bin=$(command -v node || true)
|
||||||
[[ -n "$node_bin" ]] || die 'node runtime not found'
|
[[ -n "$node_bin" ]] || die 'node runtime not found'
|
||||||
cli="$CURRENT_LINK/dist/server/cli/update.js"
|
cli="$CURRENT_LINK/dist/server/cli/update.js"
|
||||||
[[ -f "$cli" ]] || die 'update CLI not found in current release'
|
[[ -f "$cli" ]] || die 'update CLI not found in current release'
|
||||||
"$node_bin" "$cli" --request-file "$REQUEST_FILE" || exit $?
|
set +e
|
||||||
|
"$node_bin" "$cli" --request-file "$REQUEST_FILE"
|
||||||
|
download_result=$?
|
||||||
|
set -e
|
||||||
|
if (( download_result != 0 )); then
|
||||||
|
# The CLI normally records failed itself. Retry the explicit finalization
|
||||||
|
# for failures that happen before its catch handler can persist the row,
|
||||||
|
# then remove the one-shot request so a failed download cannot keep the
|
||||||
|
# path unit in a permanently triggered state.
|
||||||
|
download_job_id=$(sed -n 's/.*"jobId"[[:space:]]*:[[:space:]]*"\([0-9a-f-]*\)".*/\1/p' "$REQUEST_FILE" | head -n 1)
|
||||||
|
if [[ "$download_job_id" =~ ^[0-9a-f-]{36}$ ]]; then
|
||||||
|
for _ in 1 2 3; do
|
||||||
|
if "$node_bin" "$cli" --finalize-job "$download_job_id" --finalize-status failed --message '更新下载失败' >/dev/null 2>&1; then break; fi
|
||||||
|
sleep 1
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
rm -f -- "$REQUEST_FILE"
|
||||||
|
exit "$download_result"
|
||||||
|
fi
|
||||||
rm -f -- "$REQUEST_FILE"
|
rm -f -- "$REQUEST_FILE"
|
||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
@@ -51,34 +155,21 @@ if systemctl is-active --quiet "$SERVICE_NAME"; then was_active=1; fi
|
|||||||
# shellcheck disable=SC2329 # invoked indirectly by the EXIT trap below
|
# shellcheck disable=SC2329 # invoked indirectly by the EXIT trap below
|
||||||
restore_initial_service() {
|
restore_initial_service() {
|
||||||
local result=$?
|
local result=$?
|
||||||
|
stop_heartbeat
|
||||||
|
if (( result != 0 )); then
|
||||||
|
rm -f -- "$REQUEST_FILE" 2>/dev/null || true
|
||||||
|
if (( STATE_CREATED == 1 )); then clear_recovery_state || true; fi
|
||||||
|
fi
|
||||||
if (( was_active )); then systemctl start "$SERVICE_NAME" || true; fi
|
if (( was_active )); then systemctl start "$SERVICE_NAME" || true; fi
|
||||||
return "$result"
|
return "$result"
|
||||||
}
|
}
|
||||||
trap restore_initial_service EXIT
|
trap restore_initial_service EXIT
|
||||||
systemctl stop "$SERVICE_NAME"
|
|
||||||
|
|
||||||
job_id=''
|
|
||||||
if [[ -f "$REQUEST_FILE" && ! -L "$REQUEST_FILE" ]]; then
|
|
||||||
job_id=$(sed -n 's/.*"jobId"[[:space:]]*:[[:space:]]*"\([0-9a-f-]*\)".*/\1/p' "$REQUEST_FILE" | head -n 1)
|
|
||||||
fi
|
|
||||||
old_node="$CURRENT_LINK/runtime/bin/node"
|
old_node="$CURRENT_LINK/runtime/bin/node"
|
||||||
[[ -x "$old_node" ]] || old_node=$(command -v node || true)
|
[[ -x "$old_node" ]] || old_node=$(command -v node || true)
|
||||||
switched=0
|
|
||||||
handled=0
|
handled=0
|
||||||
|
|
||||||
write_update_state() {
|
write_update_state() { write_recovery_state "$1"; }
|
||||||
local phase=$1 temporary
|
clear_update_state() { clear_recovery_state; }
|
||||||
temporary="$PREFIX/.update-state-$$-${RANDOM}.tmp"
|
|
||||||
[[ ! -e "$temporary" && ! -L "$temporary" ]] || return 1
|
|
||||||
printf 'job_id=%s\nold_target=%s\nphase=%s\n' "$job_id" "$old_target" "$phase" > "$temporary"
|
|
||||||
chmod 600 "$temporary"
|
|
||||||
mv -Tf -- "$temporary" "$STATE_FILE"
|
|
||||||
}
|
|
||||||
|
|
||||||
clear_update_state() {
|
|
||||||
[[ ! -L "$STATE_FILE" ]] || return 1
|
|
||||||
rm -f -- "$STATE_FILE"
|
|
||||||
}
|
|
||||||
|
|
||||||
finalize_state_job() {
|
finalize_state_job() {
|
||||||
local node=$1 status=$2 state_job=$3
|
local node=$1 status=$2 state_job=$3
|
||||||
@@ -99,6 +190,15 @@ recover_stale_state() {
|
|||||||
[[ "$state_job" =~ ^[0-9a-f-]{36}$ ]] || die 'update state job id is invalid'
|
[[ "$state_job" =~ ^[0-9a-f-]{36}$ ]] || die 'update state job id is invalid'
|
||||||
[[ "$state_old" == "$PREFIX/releases/"* && -d "$state_old" && ! -L "$state_old" ]] || die 'update state target is invalid'
|
[[ "$state_old" == "$PREFIX/releases/"* && -d "$state_old" && ! -L "$state_old" ]] || die 'update state target is invalid'
|
||||||
current_target=$(readlink -f -- "$CURRENT_LINK" 2>/dev/null || true)
|
current_target=$(readlink -f -- "$CURRENT_LINK" 2>/dev/null || true)
|
||||||
|
if [[ "$state_phase" == download && "$current_target" == "$state_old" ]]; then
|
||||||
|
# Downloading never changes the active release. If the runner was killed
|
||||||
|
# after the CLI staged its payload but before it removed the recovery
|
||||||
|
# marker, keep the request available for an idempotent retry. Treating
|
||||||
|
# every stale download marker as a failed apply would discard a usable
|
||||||
|
# staged payload and leave the browser showing a misleading failure.
|
||||||
|
clear_update_state || true
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
if [[ "$state_phase" == finalizing && "$current_target" != "$state_old" ]]; then
|
if [[ "$state_phase" == finalizing && "$current_target" != "$state_old" ]]; then
|
||||||
recovery_node="$CURRENT_LINK/runtime/bin/node"
|
recovery_node="$CURRENT_LINK/runtime/bin/node"
|
||||||
[[ -x "$recovery_node" ]] || recovery_node=$(command -v node || true)
|
[[ -x "$recovery_node" ]] || recovery_node=$(command -v node || true)
|
||||||
@@ -112,6 +212,27 @@ recover_stale_state() {
|
|||||||
done
|
done
|
||||||
return 1
|
return 1
|
||||||
fi
|
fi
|
||||||
|
if [[ "$current_target" == "$state_old" ]]; then
|
||||||
|
# The process may have restored the old release before it was killed. In
|
||||||
|
# that case the old link is already safe to serve, but the database row
|
||||||
|
# can still be `applying`; finish it as failed before clearing recovery
|
||||||
|
# markers so the UI does not poll forever.
|
||||||
|
recovery_node="$CURRENT_LINK/runtime/bin/node"
|
||||||
|
[[ -x "$recovery_node" ]] || recovery_node=$(command -v node || true)
|
||||||
|
if finalize_state_job "$recovery_node" failed "$state_job"; then
|
||||||
|
rm -f -- "$REQUEST_FILE" 2>/dev/null || true
|
||||||
|
clear_update_state || true
|
||||||
|
return 11
|
||||||
|
fi
|
||||||
|
# A crash before the CLI created its job row is safe to retry. Preserve
|
||||||
|
# the request while dropping only the stale state marker.
|
||||||
|
if [[ -f "$REQUEST_FILE" && ! -L "$REQUEST_FILE" ]]; then
|
||||||
|
clear_update_state || true
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
clear_update_state || true
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
if [[ "$current_target" != "$state_old" ]]; then
|
if [[ "$current_target" != "$state_old" ]]; then
|
||||||
rollback_link="$PREFIX/.current-recovery-$$-${RANDOM}.tmp"
|
rollback_link="$PREFIX/.current-recovery-$$-${RANDOM}.tmp"
|
||||||
[[ ! -e "$rollback_link" && ! -L "$rollback_link" ]] || return 1
|
[[ ! -e "$rollback_link" && ! -L "$rollback_link" ]] || return 1
|
||||||
@@ -156,10 +277,26 @@ fi
|
|||||||
|
|
||||||
[[ -f "$REQUEST_FILE" && ! -L "$REQUEST_FILE" ]] || exit 0
|
[[ -f "$REQUEST_FILE" && ! -L "$REQUEST_FILE" ]] || exit 0
|
||||||
|
|
||||||
|
# Only create the marker for this invocation after any marker from a previous
|
||||||
|
# interrupted run has been reconciled. Otherwise the freshly-created `running`
|
||||||
|
# marker is indistinguishable from stale recovery state and the runner can
|
||||||
|
# finalize its own queued job as failed before the update CLI starts.
|
||||||
|
if [[ ! -e "$STATE_FILE" ]]; then
|
||||||
|
write_recovery_state running || die '无法写入更新恢复状态'
|
||||||
|
fi
|
||||||
|
start_heartbeat
|
||||||
|
if ! systemctl stop "$SERVICE_NAME"; then
|
||||||
|
die '无法停止 TallyNote 服务'
|
||||||
|
fi
|
||||||
|
|
||||||
rollback_current() {
|
rollback_current() {
|
||||||
local current_target rollback_link
|
local current_target rollback_link
|
||||||
current_target=$(readlink -f -- "$CURRENT_LINK" 2>/dev/null || true)
|
current_target=$(readlink -f -- "$CURRENT_LINK" 2>/dev/null || true)
|
||||||
[[ "$current_target" == "$old_target" ]] && return 0
|
if [[ "$current_target" == "$old_target" ]]; then
|
||||||
|
# An earlier failure branch may already have restored the link. Keep the
|
||||||
|
# marker truthful so the EXIT trap can still finalize the job.
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
rollback_link="$PREFIX/.current-rollback-$$-${RANDOM}.tmp"
|
rollback_link="$PREFIX/.current-rollback-$$-${RANDOM}.tmp"
|
||||||
[[ ! -e "$rollback_link" && ! -L "$rollback_link" ]] || return 1
|
[[ ! -e "$rollback_link" && ! -L "$rollback_link" ]] || return 1
|
||||||
ln -s -- "$old_target" "$rollback_link" || return 1
|
ln -s -- "$old_target" "$rollback_link" || return 1
|
||||||
@@ -167,13 +304,20 @@ rollback_current() {
|
|||||||
rm -f -- "$rollback_link" 2>/dev/null || true
|
rm -f -- "$rollback_link" 2>/dev/null || true
|
||||||
return 1
|
return 1
|
||||||
fi
|
fi
|
||||||
switched=0
|
|
||||||
}
|
}
|
||||||
|
|
||||||
finalize_failed_job() {
|
finalize_failed_job() {
|
||||||
[[ "$job_id" =~ ^[0-9a-f-]{36}$ ]] || return 0
|
[[ "$job_id" =~ ^[0-9a-f-]{36}$ ]] || return 0
|
||||||
[[ -n "$old_node" && -f "$CURRENT_LINK/dist/server/cli/update.js" ]] || return 0
|
[[ -n "$old_node" && -f "$CURRENT_LINK/dist/server/cli/update.js" ]] || return 1
|
||||||
"$old_node" "$CURRENT_LINK/dist/server/cli/update.js" --finalize-job "$job_id" --finalize-status failed --message '新版本健康检查失败,已恢复上一版本' >/dev/null 2>&1
|
# Give SQLite a moment to release a transient lock before declaring the
|
||||||
|
# recovery itself failed.
|
||||||
|
for _ in 1 2 3; do
|
||||||
|
if "$old_node" "$CURRENT_LINK/dist/server/cli/update.js" --finalize-job "$job_id" --finalize-status failed --message '新版本健康检查失败,已恢复上一版本' >/dev/null 2>&1; then
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
sleep 1
|
||||||
|
done
|
||||||
|
return 1
|
||||||
}
|
}
|
||||||
|
|
||||||
finalize_completed_job() {
|
finalize_completed_job() {
|
||||||
@@ -185,9 +329,13 @@ finalize_completed_job() {
|
|||||||
# shellcheck disable=SC2329 # invoked indirectly by the EXIT trap below
|
# shellcheck disable=SC2329 # invoked indirectly by the EXIT trap below
|
||||||
cleanup_after_update() {
|
cleanup_after_update() {
|
||||||
local result=$? rollback_ok=1
|
local result=$? rollback_ok=1
|
||||||
|
stop_heartbeat
|
||||||
if (( result != 0 && handled == 0 )); then
|
if (( result != 0 && handled == 0 )); then
|
||||||
if ! rollback_current; then rollback_ok=0; fi
|
if ! rollback_current; then rollback_ok=0; fi
|
||||||
if (( rollback_ok == 1 && switched == 0 )); then
|
# Once the old release is active again, always try to close the job. The
|
||||||
|
# previous marker could remain set when an earlier branch had already
|
||||||
|
# rolled back before entering this EXIT trap, leaving `applying` forever.
|
||||||
|
if (( rollback_ok == 1 )); then
|
||||||
if finalize_failed_job; then
|
if finalize_failed_job; then
|
||||||
rm -f -- "$REQUEST_FILE"
|
rm -f -- "$REQUEST_FILE"
|
||||||
clear_update_state || true
|
clear_update_state || true
|
||||||
@@ -203,7 +351,6 @@ cleanup_after_update() {
|
|||||||
}
|
}
|
||||||
trap cleanup_after_update EXIT
|
trap cleanup_after_update EXIT
|
||||||
|
|
||||||
write_update_state running || exit 1
|
|
||||||
node_bin="$CURRENT_LINK/runtime/bin/node"
|
node_bin="$CURRENT_LINK/runtime/bin/node"
|
||||||
[[ -x "$node_bin" ]] || node_bin=$(command -v node || true)
|
[[ -x "$node_bin" ]] || node_bin=$(command -v node || true)
|
||||||
[[ -n "$node_bin" ]] || die 'node runtime not found'
|
[[ -n "$node_bin" ]] || die 'node runtime not found'
|
||||||
@@ -218,9 +365,6 @@ if (( update_result != 0 )); then
|
|||||||
exit "$update_result"
|
exit "$update_result"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
if [[ "$(readlink -f -- "$CURRENT_LINK" 2>/dev/null || true)" != "$old_target" ]]; then
|
|
||||||
switched=1
|
|
||||||
fi
|
|
||||||
write_update_state health-check || exit 1
|
write_update_state health-check || exit 1
|
||||||
|
|
||||||
systemctl start "$SERVICE_NAME"
|
systemctl start "$SERVICE_NAME"
|
||||||
|
|||||||
@@ -4,6 +4,13 @@ root=$(cd "$(dirname "$0")/.." && pwd)
|
|||||||
bash -n "$root/install.sh" "$root/scripts/tallynote-update.sh"
|
bash -n "$root/install.sh" "$root/scripts/tallynote-update.sh"
|
||||||
grep -Eq '^RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK$' "$root/systemd/tallynote.service"
|
grep -Eq '^RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK$' "$root/systemd/tallynote.service"
|
||||||
grep -Eq '^RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK$' "$root/systemd/tallynote-update.service"
|
grep -Eq '^RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK$' "$root/systemd/tallynote-update.service"
|
||||||
|
grep -Eq '^PathExists=/opt/tallynote/\.update-state$' "$root/systemd/tallynote-update.path"
|
||||||
|
grep -Eq '^PathChanged=/opt/tallynote/\.update-state$' "$root/systemd/tallynote-update.path"
|
||||||
|
grep -Eq '^PathChanged=/opt/tallynote$' "$root/systemd/tallynote-update.path"
|
||||||
|
if grep -Eq '^ConditionPathExists=' "$root/systemd/tallynote-update.service"; then
|
||||||
|
echo 'update service must not require only the request file' >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
output=$(bash "$root/install.sh" --dry-run --release-base-url https://releases.example.test/releases)
|
output=$(bash "$root/install.sh" --dry-run --release-base-url https://releases.example.test/releases)
|
||||||
grep -q 'dry-run' <<<"$output"
|
grep -q 'dry-run' <<<"$output"
|
||||||
grep -q '\[阶段\] 检查运行环境' <<<"$output"
|
grep -q '\[阶段\] 检查运行环境' <<<"$output"
|
||||||
@@ -81,6 +88,12 @@ bash -c '
|
|||||||
chmod 700 "$mode_dir"
|
chmod 700 "$mode_dir"
|
||||||
[[ "$(stat_mode_bits "$mode_dir")" == 448 ]]
|
[[ "$(stat_mode_bits "$mode_dir")" == 448 ]]
|
||||||
mkdir -p "$owner_parent"
|
mkdir -p "$owner_parent"
|
||||||
|
# CI runs this shell suite as root. Make the parent genuinely non-root in
|
||||||
|
# that environment so the assertion exercises the ownership guard instead
|
||||||
|
# of accidentally passing because root-owned parents are allowed.
|
||||||
|
if [[ "${EUID:-$(id -u)}" == 0 ]]; then
|
||||||
|
chown 65534:65534 "$owner_parent"
|
||||||
|
fi
|
||||||
if (assert_path_chain "$owner_parent/child") >/dev/null 2>&1; then
|
if (assert_path_chain "$owner_parent/child") >/dev/null 2>&1; then
|
||||||
echo "expected non-root path parent to fail" >&2
|
echo "expected non-root path parent to fail" >&2
|
||||||
exit 1
|
exit 1
|
||||||
@@ -153,6 +166,69 @@ bash -c '
|
|||||||
wait_for_service_health 0.0.0.0 3011
|
wait_for_service_health 0.0.0.0 3011
|
||||||
' _ "$installer_lib"
|
' _ "$installer_lib"
|
||||||
|
|
||||||
|
# Exercise the privileged runner's normal apply hand-off with portable command
|
||||||
|
# shims. In particular, the freshly-created running marker must not be treated
|
||||||
|
# as stale state before the update CLI gets a chance to process the request.
|
||||||
|
runner_root="$tmp/runner"
|
||||||
|
runner_prefix="$runner_root/prefix"
|
||||||
|
runner_data="$runner_root/data"
|
||||||
|
runner_tools="$runner_root/tools"
|
||||||
|
mkdir -p "$runner_prefix/releases/1.0.0/runtime/bin" "$runner_prefix/releases/1.0.0/dist/server/cli" "$runner_data" "$runner_tools"
|
||||||
|
ln -s "$runner_prefix/releases/1.0.0" "$runner_prefix/current"
|
||||||
|
printf '%s\n' '{"jobId":"00000000-0000-4000-8000-000000000001","operation":"apply"}' > "$runner_data/update-request.json"
|
||||||
|
printf '%s\n' '#!/usr/bin/env bash' 'printf "%s\\n" "$*" >> "$TALLYNOTE_NODE_TRACE"' 'exit 0' > "$runner_prefix/releases/1.0.0/runtime/bin/node"
|
||||||
|
printf '%s\n' cli > "$runner_prefix/releases/1.0.0/dist/server/cli/update.js"
|
||||||
|
printf '%s\n' '#!/usr/bin/env bash' 'case "${1:-}" in is-active) exit 0;; *) exit 0;; esac' > "$runner_tools/systemctl"
|
||||||
|
printf '%s\n' '#!/usr/bin/env bash' 'if [[ "${1:-}" == "-f" ]]; then shift; [[ "${1:-}" == "--" ]] && shift; /bin/realpath "$1"; else /usr/bin/readlink "$@"; fi' > "$runner_tools/readlink"
|
||||||
|
printf '%s\n' '#!/usr/bin/env bash' 'if [[ "${1:-}" == "-Tf" ]]; then shift; /bin/mv -f "$@"; else /bin/mv "$@"; fi' > "$runner_tools/mv"
|
||||||
|
printf '%s\n' '#!/usr/bin/env bash' 'exit 0' > "$runner_tools/curl"
|
||||||
|
chmod 755 "$runner_prefix/releases/1.0.0/runtime/bin/node" "$runner_tools/systemctl" "$runner_tools/readlink" "$runner_tools/mv" "$runner_tools/curl"
|
||||||
|
runner_script="$runner_root/runner.sh"
|
||||||
|
runner_path="$runner_tools:/usr/sbin:/usr/bin:/sbin:/bin"
|
||||||
|
sed "s#PATH=/usr/sbin:/usr/bin:/sbin:/bin#PATH=$runner_path#" "$root/scripts/tallynote-update-runner.sh" > "$runner_script"
|
||||||
|
chmod 755 "$runner_script"
|
||||||
|
runner_prefix_physical=$(cd "$runner_prefix" && pwd -P)
|
||||||
|
runner_data_physical=$(cd "$runner_data" && pwd -P)
|
||||||
|
env EUID=0 TALLYNOTE_INSTALL_PREFIX="$runner_prefix_physical" TALLYNOTE_DATA_DIR="$runner_data_physical" TALLYNOTE_NODE_TRACE="$runner_root/node.log" bash "$runner_script"
|
||||||
|
grep -q -- '--request-file' "$runner_root/node.log"
|
||||||
|
grep -q -- '--finalize-job' "$runner_root/node.log"
|
||||||
|
[[ ! -e "$runner_data/update-request.json" ]]
|
||||||
|
[[ ! -e "$runner_prefix/.update-state" ]]
|
||||||
|
|
||||||
|
# A stale download marker must be recoverable without finalizing the staged
|
||||||
|
# download as a failed apply. The next runner invocation should retry the
|
||||||
|
# request and let the CLI preserve/refresh its staged workspace.
|
||||||
|
download_runner_root="$tmp/download-runner"
|
||||||
|
download_runner_prefix="$download_runner_root/prefix"
|
||||||
|
download_runner_data="$download_runner_root/data"
|
||||||
|
download_runner_tools="$download_runner_root/tools"
|
||||||
|
mkdir -p "$download_runner_prefix/releases/1.0.0/runtime/bin" "$download_runner_prefix/releases/1.0.0/dist/server/cli" "$download_runner_data" "$download_runner_tools"
|
||||||
|
ln -s "$download_runner_prefix/releases/1.0.0" "$download_runner_prefix/current"
|
||||||
|
# The request has already been consumed; only the stale download marker is
|
||||||
|
# left, which is the narrow recovery window covered by this fixture.
|
||||||
|
download_runner_prefix_physical=$(cd "$download_runner_prefix" && pwd -P)
|
||||||
|
download_runner_data_physical=$(cd "$download_runner_data" && pwd -P)
|
||||||
|
printf '%s\n' 'job_id=00000000-0000-4000-8000-000000000002' "old_target=$download_runner_prefix_physical/releases/1.0.0" 'phase=download' > "$download_runner_prefix/.update-state"
|
||||||
|
printf '%s\n' '#!/usr/bin/env bash' 'printf "%s\n" "$*" >> "$TALLYNOTE_DOWNLOAD_NODE_TRACE"' 'exit 0' > "$download_runner_prefix/releases/1.0.0/runtime/bin/node"
|
||||||
|
printf '%s\n' cli > "$download_runner_prefix/releases/1.0.0/dist/server/cli/update.js"
|
||||||
|
printf '%s\n' '#!/usr/bin/env bash' 'case "${1:-}" in is-active) exit 0;; *) exit 0;; esac' > "$download_runner_tools/systemctl"
|
||||||
|
printf '%s\n' '#!/usr/bin/env bash' 'if [[ "${1:-}" == "-f" ]]; then shift; [[ "${1:-}" == "--" ]] && shift; /bin/realpath "$1"; else /usr/bin/readlink "$@"; fi' > "$download_runner_tools/readlink"
|
||||||
|
cat >"$download_runner_tools/stat" <<'EOF'
|
||||||
|
#!/usr/bin/env bash
|
||||||
|
case "$*" in
|
||||||
|
*"-c %u"*|*"-f %u"*) printf '0\n' ;;
|
||||||
|
*"-c %a"*|*"-f %Lp"*) printf '600\n' ;;
|
||||||
|
*) /usr/bin/stat "$@" ;;
|
||||||
|
esac
|
||||||
|
EOF
|
||||||
|
chmod 755 "$download_runner_prefix/releases/1.0.0/runtime/bin/node" "$download_runner_tools/systemctl" "$download_runner_tools/readlink" "$download_runner_tools/stat"
|
||||||
|
download_runner_script="$download_runner_root/runner.sh"
|
||||||
|
sed "s#PATH=/usr/sbin:/usr/bin:/sbin:/bin#PATH=$download_runner_tools:/usr/sbin:/usr/bin:/sbin:/bin#" "$root/scripts/tallynote-update-runner.sh" > "$download_runner_script"
|
||||||
|
chmod 755 "$download_runner_script"
|
||||||
|
env EUID=0 TALLYNOTE_INSTALL_PREFIX="$download_runner_prefix_physical" TALLYNOTE_DATA_DIR="$download_runner_data_physical" TALLYNOTE_DOWNLOAD_NODE_TRACE="$download_runner_root/node.log" bash "$download_runner_script"
|
||||||
|
[[ ! -e "$download_runner_root/node.log" ]]
|
||||||
|
[[ ! -e "$download_runner_prefix/.update-state" ]]
|
||||||
|
|
||||||
# A RETURN trap installed by install_release must be cleared while its local
|
# A RETURN trap installed by install_release must be cleared while its local
|
||||||
# temporary variables still exist; otherwise set -u fails at the end of main.
|
# temporary variables still exist; otherwise set -u fails at the end of main.
|
||||||
release_fixture="$tmp/release-fixture"
|
release_fixture="$tmp/release-fixture"
|
||||||
@@ -192,6 +268,17 @@ bash -c '
|
|||||||
set_env_key test value
|
set_env_key test value
|
||||||
' _ "$installer_lib" "$release_archive" "$tmp/install-release"
|
' _ "$installer_lib" "$release_archive" "$tmp/install-release"
|
||||||
|
|
||||||
|
# The installed path unit must watch both the data-directory request and the
|
||||||
|
# release-prefix recovery marker after custom paths are substituted.
|
||||||
|
rendered_path="$tmp/rendered-update.path"
|
||||||
|
sed "s#/opt/tallynote#$tmp/custom-prefix#g; s#/var/lib/tallynote#$tmp/custom-data#g" \
|
||||||
|
"$root/systemd/tallynote-update.path" > "$rendered_path"
|
||||||
|
grep -Fxq "PathExists=$tmp/custom-data/update-request.json" "$rendered_path"
|
||||||
|
grep -Fxq "PathChanged=$tmp/custom-data/update-request.json" "$rendered_path"
|
||||||
|
grep -Fxq "PathExists=$tmp/custom-prefix/.update-state" "$rendered_path"
|
||||||
|
grep -Fxq "PathChanged=$tmp/custom-prefix/.update-state" "$rendered_path"
|
||||||
|
grep -Fxq "PathChanged=$tmp/custom-prefix" "$rendered_path"
|
||||||
|
|
||||||
# The production admin wrapper must load a release-relative runtime, change to
|
# The production admin wrapper must load a release-relative runtime, change to
|
||||||
# the release root, and forward CLI arguments without requiring pnpm.
|
# the release root, and forward CLI arguments without requiring pnpm.
|
||||||
wrapper_prefix="$tmp/wrapper-prefix"
|
wrapper_prefix="$tmp/wrapper-prefix"
|
||||||
@@ -200,7 +287,11 @@ ln -s "$wrapper_prefix/releases/1.0.0" "$wrapper_prefix/current"
|
|||||||
printf '%s\n' '#!/usr/bin/env bash' 'pwd -P > "$TALLYNOTE_WRAPPER_LOG"' 'printf "%s\n" "$@" >> "$TALLYNOTE_WRAPPER_LOG"' > "$wrapper_prefix/releases/1.0.0/runtime/bin/node"
|
printf '%s\n' '#!/usr/bin/env bash' 'pwd -P > "$TALLYNOTE_WRAPPER_LOG"' 'printf "%s\n" "$@" >> "$TALLYNOTE_WRAPPER_LOG"' > "$wrapper_prefix/releases/1.0.0/runtime/bin/node"
|
||||||
chmod 755 "$wrapper_prefix/releases/1.0.0/runtime/bin/node"
|
chmod 755 "$wrapper_prefix/releases/1.0.0/runtime/bin/node"
|
||||||
printf '%s\n' cli > "$wrapper_prefix/releases/1.0.0/dist/server/cli/admin-init.js"
|
printf '%s\n' cli > "$wrapper_prefix/releases/1.0.0/dist/server/cli/admin-init.js"
|
||||||
TALLYNOTE_INSTALL_PREFIX="$wrapper_prefix" TALLYNOTE_CONFIG_DIR="$tmp/no-config" TALLYNOTE_WRAPPER_LOG="$tmp/wrapper.log" \
|
# This fixture verifies release-relative execution and argument forwarding.
|
||||||
|
# Force the wrapper's non-root branch so the root CI runner does not need a
|
||||||
|
# real `tallynote` service account or a privileged runuser hand-off; that
|
||||||
|
# privilege boundary is validated by the production checks themselves.
|
||||||
|
env EUID=1000 TALLYNOTE_INSTALL_PREFIX="$wrapper_prefix" TALLYNOTE_CONFIG_DIR="$tmp/no-config" TALLYNOTE_WRAPPER_LOG="$tmp/wrapper.log" \
|
||||||
bash "$root/bin/tallynote-admin-init" --generate
|
bash "$root/bin/tallynote-admin-init" --generate
|
||||||
wrapper_expected_root=$(cd "$wrapper_prefix/releases/1.0.0" && pwd -P)
|
wrapper_expected_root=$(cd "$wrapper_prefix/releases/1.0.0" && pwd -P)
|
||||||
grep -Fxq "$wrapper_expected_root" "$tmp/wrapper.log"
|
grep -Fxq "$wrapper_expected_root" "$tmp/wrapper.log"
|
||||||
@@ -367,6 +458,9 @@ bash -c '
|
|||||||
stat_uid() { printf "0"; }
|
stat_uid() { printf "0"; }
|
||||||
stat_mode_bits() { printf "384"; }
|
stat_mode_bits() { printf "384"; }
|
||||||
validate_public_origin "http://[2001:db8::10]:3000"
|
validate_public_origin "http://[2001:db8::10]:3000"
|
||||||
|
# A standard HTTPS origin may omit its default port; this must remain valid
|
||||||
|
# under the installer strict unset-variable mode.
|
||||||
|
validate_public_origin "https://example.test"
|
||||||
' _ "$installer_lib"
|
' _ "$installer_lib"
|
||||||
printf '%s\n' \
|
printf '%s\n' \
|
||||||
'TALLYNOTE_HOST=0.0.0.0' \
|
'TALLYNOTE_HOST=0.0.0.0' \
|
||||||
|
|||||||
+20
-15
@@ -59,6 +59,7 @@ import {
|
|||||||
checkForUpdate,
|
checkForUpdate,
|
||||||
publicCheckFromCache,
|
publicCheckFromCache,
|
||||||
publicUpdateJob,
|
publicUpdateJob,
|
||||||
|
reconcileOrphanedUpdateJobs,
|
||||||
readCachedRelease,
|
readCachedRelease,
|
||||||
writeUpdateRequest,
|
writeUpdateRequest,
|
||||||
type UpdateRequest,
|
type UpdateRequest,
|
||||||
@@ -118,7 +119,7 @@ function enforceUpdateCooldown(
|
|||||||
adminId: string,
|
adminId: string,
|
||||||
operation: "check" | "download" | "apply",
|
operation: "check" | "download" | "apply",
|
||||||
reply: FastifyReply,
|
reply: FastifyReply,
|
||||||
): void {
|
): number {
|
||||||
const state = updateRateState(database, adminId);
|
const state = updateRateState(database, adminId);
|
||||||
const now = Date.now();
|
const now = Date.now();
|
||||||
const previous = operation === "check" ? state.checkedAt : operation === "download" ? state.downloadedAt : state.appliedAt;
|
const previous = operation === "check" ? state.checkedAt : operation === "download" ? state.downloadedAt : state.appliedAt;
|
||||||
@@ -133,6 +134,7 @@ function enforceUpdateCooldown(
|
|||||||
if (operation === "check") state.checkedAt = now;
|
if (operation === "check") state.checkedAt = now;
|
||||||
else if (operation === "download") state.downloadedAt = now;
|
else if (operation === "download") state.downloadedAt = now;
|
||||||
else state.appliedAt = now;
|
else state.appliedAt = now;
|
||||||
|
return now;
|
||||||
}
|
}
|
||||||
|
|
||||||
function adminSelect(alias = ""): string {
|
function adminSelect(alias = ""): string {
|
||||||
@@ -646,19 +648,6 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
|||||||
return payload;
|
return payload;
|
||||||
});
|
});
|
||||||
|
|
||||||
app.addHook("onRequest", async (request) => {
|
|
||||||
if (!unsafeMethods.has(request.method) || !request.url.startsWith("/api/")) return;
|
|
||||||
const origin = request.headers.origin;
|
|
||||||
const allowed = new Set([config.publicOrigin]);
|
|
||||||
if (!config.isProduction) {
|
|
||||||
allowed.add("http://127.0.0.1:5173");
|
|
||||||
allowed.add("http://localhost:5173");
|
|
||||||
}
|
|
||||||
if (typeof origin !== "string" || !allowed.has(origin)) {
|
|
||||||
throw new AppError(403, "ORIGIN_FORBIDDEN", "请求来源不受信任");
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
app.setErrorHandler((error, request, reply) => {
|
app.setErrorHandler((error, request, reply) => {
|
||||||
if (error instanceof AppError) return reply.code(error.statusCode).send(errorPayload(request, error));
|
if (error instanceof AppError) return reply.code(error.statusCode).send(errorPayload(request, error));
|
||||||
if (error instanceof ZodError) {
|
if (error instanceof ZodError) {
|
||||||
@@ -939,11 +928,14 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
|||||||
// Release metadata and task state should never be stored by an upstream
|
// Release metadata and task state should never be stored by an upstream
|
||||||
// proxy or a shared browser cache.
|
// proxy or a shared browser cache.
|
||||||
reply.header("Cache-Control", "no-store");
|
reply.header("Cache-Control", "no-store");
|
||||||
|
reconcileOrphanedUpdateJobs(database.sqlite, config);
|
||||||
const cached = publicCheckFromCache(database.sqlite, config);
|
const cached = publicCheckFromCache(database.sqlite, config);
|
||||||
const row = database.sqlite.prepare(`
|
const row = database.sqlite.prepare(`
|
||||||
SELECT id, operation, status, version, platform, asset_name AS assetName,
|
SELECT id, operation, status, version, platform, asset_name AS assetName,
|
||||||
size_bytes AS sizeBytes, error_message AS errorMessage,
|
size_bytes AS sizeBytes, error_message AS errorMessage,
|
||||||
created_at AS createdAt, updated_at AS updatedAt, completed_at AS completedAt,
|
created_at AS createdAt, updated_at AS updatedAt, completed_at AS completedAt,
|
||||||
|
downloaded_bytes AS downloadedBytes, download_started_at AS downloadStartedAt,
|
||||||
|
download_speed_bps AS downloadSpeedBps,
|
||||||
requested_at AS applyQueuedAt
|
requested_at AS applyQueuedAt
|
||||||
FROM update_jobs WHERE admin_id=? ORDER BY created_at DESC LIMIT 1
|
FROM update_jobs WHERE admin_id=? ORDER BY created_at DESC LIMIT 1
|
||||||
`).get(request.auth!.admin.id) as Record<string, unknown> | undefined;
|
`).get(request.auth!.admin.id) as Record<string, unknown> | undefined;
|
||||||
@@ -955,11 +947,15 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
|||||||
});
|
});
|
||||||
|
|
||||||
app.post("/api/update/check", { preHandler: guard(database, config), bodyLimit: 32 * 1024 }, async (request, reply) => {
|
app.post("/api/update/check", { preHandler: guard(database, config), bodyLimit: 32 * 1024 }, async (request, reply) => {
|
||||||
|
const rateState = updateRateState(database.sqlite, request.auth!.admin.id);
|
||||||
|
const previousCheckedAt = rateState.checkedAt;
|
||||||
|
let reservedCheckedAt: number | null = null;
|
||||||
try {
|
try {
|
||||||
|
reconcileOrphanedUpdateJobs(database.sqlite, config);
|
||||||
// Disabled/dev installs do not contact a release endpoint, so repeated
|
// Disabled/dev installs do not contact a release endpoint, so repeated
|
||||||
// checks are local status reads and should remain immediately usable.
|
// checks are local status reads and should remain immediately usable.
|
||||||
if (config.updateStrategy !== "disabled") {
|
if (config.updateStrategy !== "disabled") {
|
||||||
enforceUpdateCooldown(database.sqlite, config, request.auth!.admin.id, "check", reply);
|
reservedCheckedAt = enforceUpdateCooldown(database.sqlite, config, request.auth!.admin.id, "check", reply);
|
||||||
}
|
}
|
||||||
const result = await checkForUpdate(database.sqlite, config);
|
const result = await checkForUpdate(database.sqlite, config);
|
||||||
writeAudit(database.sqlite, {
|
writeAudit(database.sqlite, {
|
||||||
@@ -978,6 +974,10 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
|||||||
reply.header("Cache-Control", "no-store");
|
reply.header("Cache-Control", "no-store");
|
||||||
return { ...result, strategy: config.updateStrategy };
|
return { ...result, strategy: config.updateStrategy };
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
|
// A failed upstream request is not a successful check. Release the
|
||||||
|
// reservation only when this request still owns it, so a concurrent
|
||||||
|
// successful check cannot have its cooldown overwritten.
|
||||||
|
if (reservedCheckedAt !== null && rateState.checkedAt === reservedCheckedAt) rateState.checkedAt = previousCheckedAt;
|
||||||
writeAudit(database.sqlite, {
|
writeAudit(database.sqlite, {
|
||||||
requestId: request.id,
|
requestId: request.id,
|
||||||
actorAdminId: request.auth!.admin.id,
|
actorAdminId: request.auth!.admin.id,
|
||||||
@@ -995,6 +995,7 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
|||||||
let applyAuditRecorded = false;
|
let applyAuditRecorded = false;
|
||||||
let applyAuditTarget: string | undefined;
|
let applyAuditTarget: string | undefined;
|
||||||
try {
|
try {
|
||||||
|
reconcileOrphanedUpdateJobs(database.sqlite, config);
|
||||||
if (config.updateStrategy !== "systemd") {
|
if (config.updateStrategy !== "systemd") {
|
||||||
throw new AppError(503, "UPDATE_NOT_AVAILABLE", "当前安装方式未启用一键更新,请使用命令行更新");
|
throw new AppError(503, "UPDATE_NOT_AVAILABLE", "当前安装方式未启用一键更新,请使用命令行更新");
|
||||||
}
|
}
|
||||||
@@ -1145,6 +1146,7 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
|||||||
|
|
||||||
app.post("/api/update/download", { preHandler: guard(database, config), bodyLimit: 32 * 1024 }, async (request, reply) => {
|
app.post("/api/update/download", { preHandler: guard(database, config), bodyLimit: 32 * 1024 }, async (request, reply) => {
|
||||||
const input = updateDownloadSchema.parse(request.body);
|
const input = updateDownloadSchema.parse(request.body);
|
||||||
|
reconcileOrphanedUpdateJobs(database.sqlite, config);
|
||||||
if (config.updateStrategy !== "systemd") throw new AppError(503, "UPDATE_NOT_AVAILABLE", "当前安装方式未启用一键更新,请使用命令行更新");
|
if (config.updateStrategy !== "systemd") throw new AppError(503, "UPDATE_NOT_AVAILABLE", "当前安装方式未启用一键更新,请使用命令行更新");
|
||||||
const active = database.sqlite.prepare(`SELECT id FROM update_jobs WHERE status IN (${ACTIVE_UPDATE_STATUSES.map(() => "?").join(",")}) LIMIT 1`).get(...ACTIVE_UPDATE_STATUSES) as { id: string } | undefined;
|
const active = database.sqlite.prepare(`SELECT id FROM update_jobs WHERE status IN (${ACTIVE_UPDATE_STATUSES.map(() => "?").join(",")}) LIMIT 1`).get(...ACTIVE_UPDATE_STATUSES) as { id: string } | undefined;
|
||||||
if (active) throw new AppError(409, "UPDATE_IN_PROGRESS", "已有更新任务正在进行,请等待完成");
|
if (active) throw new AppError(409, "UPDATE_IN_PROGRESS", "已有更新任务正在进行,请等待完成");
|
||||||
@@ -1175,10 +1177,13 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
|||||||
|
|
||||||
app.get("/api/update/jobs/:id", { preHandler: guard(database, config) }, async (request, reply) => {
|
app.get("/api/update/jobs/:id", { preHandler: guard(database, config) }, async (request, reply) => {
|
||||||
const id = z.string().uuid().parse((request.params as { id: string }).id);
|
const id = z.string().uuid().parse((request.params as { id: string }).id);
|
||||||
|
reconcileOrphanedUpdateJobs(database.sqlite, config);
|
||||||
const row = database.sqlite.prepare(`
|
const row = database.sqlite.prepare(`
|
||||||
SELECT id, operation, status, version, platform, asset_name AS assetName,
|
SELECT id, operation, status, version, platform, asset_name AS assetName,
|
||||||
size_bytes AS sizeBytes, error_message AS errorMessage,
|
size_bytes AS sizeBytes, error_message AS errorMessage,
|
||||||
created_at AS createdAt, updated_at AS updatedAt, completed_at AS completedAt,
|
created_at AS createdAt, updated_at AS updatedAt, completed_at AS completedAt,
|
||||||
|
downloaded_bytes AS downloadedBytes, download_started_at AS downloadStartedAt,
|
||||||
|
download_speed_bps AS downloadSpeedBps,
|
||||||
requested_at AS applyQueuedAt
|
requested_at AS applyQueuedAt
|
||||||
FROM update_jobs WHERE id=? AND admin_id=?
|
FROM update_jobs WHERE id=? AND admin_id=?
|
||||||
`).get(id, request.auth!.admin.id) as Record<string, unknown> | undefined;
|
`).get(id, request.auth!.admin.id) as Record<string, unknown> | undefined;
|
||||||
|
|||||||
+32
-6
@@ -26,7 +26,7 @@ import {
|
|||||||
type ReleaseMetadata,
|
type ReleaseMetadata,
|
||||||
type UrlPolicy,
|
type UrlPolicy,
|
||||||
} from "../update.js";
|
} from "../update.js";
|
||||||
import { attachSidecarHash } from "../update-service.js";
|
import { ACTIVE_UPDATE_STATUSES, attachSidecarHash } from "../update-service.js";
|
||||||
import type { UpdateJobStatus } from "../../shared/contracts.js";
|
import type { UpdateJobStatus } from "../../shared/contracts.js";
|
||||||
|
|
||||||
const updateRequestFileSchema = z.object({
|
const updateRequestFileSchema = z.object({
|
||||||
@@ -153,7 +153,7 @@ function writeJob(sqlite: Database.Database | undefined, jobId: string, values:
|
|||||||
operation, status, version, platform, release_url, asset_name, asset_url,
|
operation, status, version, platform, release_url, asset_name, asset_url,
|
||||||
expected_sha256, actual_sha256, download_path, backup_path, size_bytes, error_message,
|
expected_sha256, actual_sha256, download_path, backup_path, size_bytes, error_message,
|
||||||
created_at, updated_at, completed_at)
|
created_at, updated_at, completed_at)
|
||||||
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
|
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
|
||||||
ON CONFLICT(id) DO UPDATE SET
|
ON CONFLICT(id) DO UPDATE SET
|
||||||
admin_id=COALESCE(excluded.admin_id, update_jobs.admin_id),
|
admin_id=COALESCE(excluded.admin_id, update_jobs.admin_id),
|
||||||
session_hash=COALESCE(excluded.session_hash, update_jobs.session_hash),
|
session_hash=COALESCE(excluded.session_hash, update_jobs.session_hash),
|
||||||
@@ -291,7 +291,24 @@ export async function runUpdate(options: UpdateRunOptions): Promise<UpdateRunRes
|
|||||||
const archivePath = path.join(workspace, resolved.asset.name.endsWith(".gz") || resolved.asset.name.endsWith(".zip") ? resolved.asset.name : `${resolved.asset.name}.tar.gz`);
|
const archivePath = path.join(workspace, resolved.asset.name.endsWith(".gz") || resolved.asset.name.endsWith(".zip") ? resolved.asset.name : `${resolved.asset.name}.tar.gz`);
|
||||||
try {
|
try {
|
||||||
updateJob(options.sqlite, jobId, { operation, status: "downloading", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, downloadPath: path.basename(archivePath), startedAt: Date.now() });
|
updateJob(options.sqlite, jobId, { operation, status: "downloading", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, downloadPath: path.basename(archivePath), startedAt: Date.now() });
|
||||||
const downloaded = await downloadReleaseAsset(resolved.asset.url, archivePath, options);
|
const progressStartedAt = Date.now();
|
||||||
|
let lastProgressWrite = 0;
|
||||||
|
const downloaded = await downloadReleaseAsset(resolved.asset.url, archivePath, {
|
||||||
|
...options,
|
||||||
|
onProgress: (downloadedBytes, totalBytes) => {
|
||||||
|
const now = Date.now();
|
||||||
|
if (!options.sqlite || now - lastProgressWrite < 250) return;
|
||||||
|
lastProgressWrite = now;
|
||||||
|
const elapsed = Math.max(1, now - progressStartedAt);
|
||||||
|
const speedBps = Math.round(downloadedBytes * 1000 / elapsed);
|
||||||
|
options.sqlite.prepare("UPDATE update_jobs SET downloaded_bytes=?, size_bytes=COALESCE(?, size_bytes), download_started_at=?, download_speed_bps=?, updated_at=? WHERE id=? AND status='downloading'").run(downloadedBytes, totalBytes, progressStartedAt, speedBps, now, jobId);
|
||||||
|
},
|
||||||
|
});
|
||||||
|
if (options.sqlite) {
|
||||||
|
const finishedAt = Date.now();
|
||||||
|
const elapsed = Math.max(1, finishedAt - progressStartedAt);
|
||||||
|
options.sqlite.prepare("UPDATE update_jobs SET downloaded_bytes=?, size_bytes=?, download_started_at=?, download_speed_bps=?, updated_at=? WHERE id=? AND status='downloading'").run(downloaded.size, downloaded.size, progressStartedAt, Math.round(downloaded.size * 1000 / elapsed), finishedAt, jobId);
|
||||||
|
}
|
||||||
if (expectedSha256 && downloaded.sha256 !== expectedSha256) throw new Error("更新文件 SHA-256 校验失败");
|
if (expectedSha256 && downloaded.sha256 !== expectedSha256) throw new Error("更新文件 SHA-256 校验失败");
|
||||||
updateJob(options.sqlite, jobId, { operation, status: "verifying", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, actualSha256: downloaded.sha256, sizeBytes: downloaded.size, downloadPath: path.basename(archivePath) });
|
updateJob(options.sqlite, jobId, { operation, status: "verifying", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, actualSha256: downloaded.sha256, sizeBytes: downloaded.size, downloadPath: path.basename(archivePath) });
|
||||||
if (!archivePath.endsWith(".tar.gz") && !archivePath.endsWith(".tgz") && !archivePath.endsWith(".tar") && !archivePath.endsWith(".zip")) throw new Error("更新文件格式仅支持 tar.gz、tar 或 zip");
|
if (!archivePath.endsWith(".tar.gz") && !archivePath.endsWith(".tgz") && !archivePath.endsWith(".tar") && !archivePath.endsWith(".zip")) throw new Error("更新文件格式仅支持 tar.gz、tar 或 zip");
|
||||||
@@ -355,7 +372,9 @@ export function finalizeUpdateJob(
|
|||||||
FROM update_jobs WHERE id=?
|
FROM update_jobs WHERE id=?
|
||||||
`).get(jobId) as { id: string; status: UpdateJobStatus; version: string; platform: string; adminId: string | null; requestId: string | null; sessionHash: string | null } | undefined;
|
`).get(jobId) as { id: string; status: UpdateJobStatus; version: string; platform: string; adminId: string | null; requestId: string | null; sessionHash: string | null } | undefined;
|
||||||
if (!row) throw new Error("更新任务不存在");
|
if (!row) throw new Error("更新任务不存在");
|
||||||
if (row.status !== "applying" && row.status !== "completed" && row.status !== "failed") throw new Error("更新任务状态不允许完成");
|
const canComplete = row.status === "applying" || row.status === "completed";
|
||||||
|
const canFail = ACTIVE_UPDATE_STATUSES.includes(row.status) || row.status === "completed" || row.status === "failed";
|
||||||
|
if (status === "completed" ? !canComplete : !canFail) throw new Error("更新任务状态不允许完成");
|
||||||
const now = Date.now();
|
const now = Date.now();
|
||||||
const safeFailureMessage = status === "failed" ? "新版本健康检查失败,已恢复上一版本" : null;
|
const safeFailureMessage = status === "failed" ? "新版本健康检查失败,已恢复上一版本" : null;
|
||||||
sqlite.transaction(() => {
|
sqlite.transaction(() => {
|
||||||
@@ -477,8 +496,9 @@ export async function main(config: AppConfig = loadConfig()): Promise<void> {
|
|||||||
const database = openDatabase(config);
|
const database = openDatabase(config);
|
||||||
try {
|
try {
|
||||||
if (request?.operation === "apply") {
|
if (request?.operation === "apply") {
|
||||||
const staged = database.sqlite.prepare("SELECT download_path AS downloadPath, version FROM update_jobs WHERE id=? AND status='staged' AND operation='apply'").get(request.jobId) as { downloadPath: string | null; version: string } | undefined;
|
const staged = database.sqlite.prepare("SELECT status, operation, download_path AS downloadPath, version FROM update_jobs WHERE id=?").get(request.jobId) as { status: UpdateJobStatus; operation: "download" | "apply"; downloadPath: string | null; version: string } | undefined;
|
||||||
if (!staged?.downloadPath || staged.version !== request.version) throw new Error("更新暂存任务无效");
|
if (staged?.status === "staged" && staged.operation === "apply") {
|
||||||
|
if (!staged.downloadPath || staged.version !== request.version) throw new Error("更新暂存任务无效");
|
||||||
const root = path.resolve(config.updateWorkspaceDir);
|
const root = path.resolve(config.updateWorkspaceDir);
|
||||||
const candidate = await validateStagedWorkspacePath(staged.downloadPath, root);
|
const candidate = await validateStagedWorkspacePath(staged.downloadPath, root);
|
||||||
await applyStagedUpdate({
|
await applyStagedUpdate({
|
||||||
@@ -499,6 +519,12 @@ export async function main(config: AppConfig = loadConfig()): Promise<void> {
|
|||||||
console.log(`更新已切换:${request.version}`);
|
console.log(`更新已切换:${request.version}`);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
if (staged && !(staged.status === "queued" && staged.operation === "apply")) throw new Error("更新任务状态无效");
|
||||||
|
// A direct one-click request starts in queued/apply. Older clients do
|
||||||
|
// not have a separate download step, so fall through to runUpdate,
|
||||||
|
// which downloads, verifies, backs up, and switches the release in one
|
||||||
|
// transaction. A staged request still takes the branch above.
|
||||||
|
}
|
||||||
const result = await runUpdate({
|
const result = await runUpdate({
|
||||||
...(effectiveMetadataUrl ? { metadataUrl: effectiveMetadataUrl } : {}),
|
...(effectiveMetadataUrl ? { metadataUrl: effectiveMetadataUrl } : {}),
|
||||||
...(effectiveAssetUrl ? { assetUrl: effectiveAssetUrl } : {}),
|
...(effectiveAssetUrl ? { assetUrl: effectiveAssetUrl } : {}),
|
||||||
|
|||||||
@@ -148,6 +148,9 @@ export const updateJobs = sqliteTable("update_jobs", {
|
|||||||
downloadPath: text("download_path"),
|
downloadPath: text("download_path"),
|
||||||
backupPath: text("backup_path"),
|
backupPath: text("backup_path"),
|
||||||
sizeBytes: integer("size_bytes"),
|
sizeBytes: integer("size_bytes"),
|
||||||
|
downloadedBytes: integer("downloaded_bytes"),
|
||||||
|
downloadStartedAt: integer("download_started_at"),
|
||||||
|
downloadSpeedBps: integer("download_speed_bps"),
|
||||||
errorMessage: text("error_message"),
|
errorMessage: text("error_message"),
|
||||||
createdAt: integer("created_at").notNull(),
|
createdAt: integer("created_at").notNull(),
|
||||||
requestedAt: integer("requested_at"),
|
requestedAt: integer("requested_at"),
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ import { loadConfig, prepareDataDirectories, acquireInstanceLock } from "./confi
|
|||||||
import { openDatabase } from "./db/index.js";
|
import { openDatabase } from "./db/index.js";
|
||||||
import { buildApp } from "./app.js";
|
import { buildApp } from "./app.js";
|
||||||
import { cleanupOrphanedExports, expireExports, resumeExports } from "./exporter.js";
|
import { cleanupOrphanedExports, expireExports, resumeExports } from "./exporter.js";
|
||||||
|
import { reconcileOrphanedUpdateJobs } from "./update-service.js";
|
||||||
|
|
||||||
const config = loadConfig();
|
const config = loadConfig();
|
||||||
prepareDataDirectories(config);
|
prepareDataDirectories(config);
|
||||||
@@ -18,6 +19,7 @@ async function start() {
|
|||||||
await expireExports(database.sqlite, config);
|
await expireExports(database.sqlite, config);
|
||||||
await cleanupOrphanedExports(database.sqlite, config);
|
await cleanupOrphanedExports(database.sqlite, config);
|
||||||
await resumeExports(database.sqlite, config);
|
await resumeExports(database.sqlite, config);
|
||||||
|
reconcileOrphanedUpdateJobs(database.sqlite, config);
|
||||||
const app = await buildApp(database, config);
|
const app = await buildApp(database, config);
|
||||||
const janitor = setInterval(() => {
|
const janitor = setInterval(() => {
|
||||||
void cleanupStaging(config);
|
void cleanupStaging(config);
|
||||||
@@ -27,6 +29,7 @@ async function start() {
|
|||||||
void processFileDeletions(database.sqlite, config);
|
void processFileDeletions(database.sqlite, config);
|
||||||
void expireExports(database.sqlite, config);
|
void expireExports(database.sqlite, config);
|
||||||
void cleanupOrphanedExports(database.sqlite, config);
|
void cleanupOrphanedExports(database.sqlite, config);
|
||||||
|
reconcileOrphanedUpdateJobs(database.sqlite, config);
|
||||||
}, 60_000);
|
}, 60_000);
|
||||||
const shutdown = async () => {
|
const shutdown = async () => {
|
||||||
clearInterval(janitor);
|
clearInterval(janitor);
|
||||||
|
|||||||
@@ -1,7 +1,9 @@
|
|||||||
|
import { lstatSync, realpathSync, readFileSync, unlinkSync } from "node:fs";
|
||||||
import { chmod, mkdir, rename, writeFile } from "node:fs/promises";
|
import { chmod, mkdir, rename, writeFile } from "node:fs/promises";
|
||||||
import path from "node:path";
|
import path from "node:path";
|
||||||
import { createPublicKey, randomUUID, verify as verifySignature } from "node:crypto";
|
import { createPublicKey, randomUUID, verify as verifySignature } from "node:crypto";
|
||||||
import type Database from "better-sqlite3";
|
import type Database from "better-sqlite3";
|
||||||
|
import { writeAudit } from "./audit.js";
|
||||||
import { AppError } from "./errors.js";
|
import { AppError } from "./errors.js";
|
||||||
import type { AppConfig } from "./config.js";
|
import type { AppConfig } from "./config.js";
|
||||||
import {
|
import {
|
||||||
@@ -30,6 +32,12 @@ export const ACTIVE_UPDATE_STATUSES: readonly UpdateJobStatus[] = [
|
|||||||
"applying",
|
"applying",
|
||||||
];
|
];
|
||||||
|
|
||||||
|
// A queued job normally starts within seconds and an applying job completes
|
||||||
|
// after the service health check. The runner refreshes its recovery marker as
|
||||||
|
// a lease while doing long downloads/backups; only an expired lease permits
|
||||||
|
// the server to reclaim an active row.
|
||||||
|
export const ORPHANED_UPDATE_TIMEOUT_MS = 5 * 60 * 1000;
|
||||||
|
|
||||||
export type CachedRelease = {
|
export type CachedRelease = {
|
||||||
checkedAt: number;
|
checkedAt: number;
|
||||||
metadataUrl: string;
|
metadataUrl: string;
|
||||||
@@ -343,6 +351,9 @@ export function publicUpdateJob(row: Record<string, unknown> | undefined): Recor
|
|||||||
platform: row.platform,
|
platform: row.platform,
|
||||||
assetName: row.assetName ?? null,
|
assetName: row.assetName ?? null,
|
||||||
sizeBytes: row.sizeBytes ?? null,
|
sizeBytes: row.sizeBytes ?? null,
|
||||||
|
downloadedBytes: row.downloadedBytes ?? null,
|
||||||
|
downloadStartedAt: row.downloadStartedAt ?? null,
|
||||||
|
downloadSpeedBps: row.downloadSpeedBps ?? null,
|
||||||
// Do not expose filesystem paths, command output, or upstream response
|
// Do not expose filesystem paths, command output, or upstream response
|
||||||
// text through the authenticated status endpoint. Detailed diagnostics
|
// text through the authenticated status endpoint. Detailed diagnostics
|
||||||
// remain in the server journal for operators.
|
// remain in the server journal for operators.
|
||||||
@@ -355,3 +366,157 @@ export function publicUpdateJob(row: Record<string, unknown> | undefined): Recor
|
|||||||
...(row.status === "applying" ? { restartWindowSeconds: 30 } : {}),
|
...(row.status === "applying" ? { restartWindowSeconds: 30 } : {}),
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function markerMtime(filePath: string): number | null {
|
||||||
|
try {
|
||||||
|
const info = lstatSync(filePath);
|
||||||
|
return info.isFile() ? info.mtimeMs : null;
|
||||||
|
} catch {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function removeExpiredRequest(filePath: string, now: number): void {
|
||||||
|
try {
|
||||||
|
const info = lstatSync(filePath);
|
||||||
|
if (!info.isFile() && !info.isSymbolicLink()) return;
|
||||||
|
if (now - info.mtimeMs < ORPHANED_UPDATE_TIMEOUT_MS) return;
|
||||||
|
unlinkSync(filePath);
|
||||||
|
} catch {
|
||||||
|
// The root runner may own the marker during a recovery race. The DB
|
||||||
|
// transition below is still enough to release the browser queue.
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function requestJobId(filePath: string): string | null {
|
||||||
|
try {
|
||||||
|
const info = lstatSync(filePath);
|
||||||
|
if (!info.isFile() || info.isSymbolicLink()) return null;
|
||||||
|
const value = JSON.parse(readFileSync(filePath, "utf8")) as { jobId?: unknown };
|
||||||
|
return typeof value.jobId === "string" && /^[0-9a-f-]{36}$/.test(value.jobId) ? value.jobId : null;
|
||||||
|
} catch {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
function currentReleaseVersion(config: AppConfig): string | null {
|
||||||
|
try {
|
||||||
|
const target = realpathSync(config.currentLink);
|
||||||
|
const releases = realpathSync(config.releasesDir);
|
||||||
|
if (!target.startsWith(`${releases}${path.sep}`)) return null;
|
||||||
|
return path.basename(target);
|
||||||
|
} catch {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Release an update row left behind after its privileged runner lease expired.
|
||||||
|
* This is deliberately conservative: staged downloads remain available for an
|
||||||
|
* explicit apply, and a fresh request/state marker means the runner still owns
|
||||||
|
* recovery.
|
||||||
|
*/
|
||||||
|
export function reconcileOrphanedUpdateJobs(database: Database.Database, config: AppConfig, now = Date.now()): number {
|
||||||
|
const placeholders = ACTIVE_UPDATE_STATUSES.map(() => "?").join(",");
|
||||||
|
const rows = database.prepare(`
|
||||||
|
SELECT id, status, operation, version, admin_id AS adminId, request_id AS requestId,
|
||||||
|
updated_at AS updatedAt
|
||||||
|
FROM update_jobs
|
||||||
|
WHERE status IN (${placeholders})
|
||||||
|
ORDER BY updated_at ASC
|
||||||
|
`).all(...ACTIVE_UPDATE_STATUSES) as Array<{ id: string; status: UpdateJobStatus; operation: "download" | "apply"; version: string; adminId: string | null; requestId: string | null; updatedAt: number | null }>;
|
||||||
|
if (rows.length === 0) return 0;
|
||||||
|
const statePath = path.join(config.installPrefix, ".update-state");
|
||||||
|
const requestMtime = markerMtime(config.updateRequestPath);
|
||||||
|
const stateMtime = markerMtime(statePath);
|
||||||
|
const requestPresent = requestMtime !== null;
|
||||||
|
const statePresent = stateMtime !== null;
|
||||||
|
const requestFresh = requestPresent && now - (requestMtime ?? 0) < ORPHANED_UPDATE_TIMEOUT_MS;
|
||||||
|
const stateFresh = statePresent && now - (stateMtime ?? 0) < ORPHANED_UPDATE_TIMEOUT_MS;
|
||||||
|
// A staged download is normally kept for an explicit apply. The one
|
||||||
|
// exception is the hand-off window where the API has already changed the
|
||||||
|
// operation to `apply` but crashed before writing the request file. That
|
||||||
|
// row is still safe to retry and must not block the queue forever.
|
||||||
|
const releaseVersion = currentReleaseVersion(config);
|
||||||
|
let reconciled = 0;
|
||||||
|
const reconciledIds = new Set<string>();
|
||||||
|
for (const row of rows) {
|
||||||
|
if (typeof row.updatedAt !== "number" || now - row.updatedAt < ORPHANED_UPDATE_TIMEOUT_MS) continue;
|
||||||
|
// The runner refreshes the state marker while a download is in flight.
|
||||||
|
// A stale request/state marker therefore no longer protects an orphaned
|
||||||
|
// row forever, while a fresh marker remains owned by the runner.
|
||||||
|
if (row.status === "staged") {
|
||||||
|
if (row.operation !== "apply" || requestFresh || stateFresh) continue;
|
||||||
|
const changed = database.transaction(() => {
|
||||||
|
const result = database.prepare(`
|
||||||
|
UPDATE update_jobs
|
||||||
|
SET operation='download', error_message=NULL, updated_at=?
|
||||||
|
WHERE id=? AND status='staged' AND operation='apply' AND updated_at=?
|
||||||
|
`).run(now, row.id, row.updatedAt);
|
||||||
|
if (result.changes !== 1) return false;
|
||||||
|
writeAudit(database, {
|
||||||
|
requestId: row.requestId || randomUUID(),
|
||||||
|
actorAdminId: row.adminId,
|
||||||
|
action: "update.reconciled",
|
||||||
|
targetType: "update",
|
||||||
|
targetId: row.id,
|
||||||
|
outcome: "success",
|
||||||
|
before: { status: row.status, operation: row.operation, version: row.version },
|
||||||
|
after: { status: "staged", operation: "download", version: row.version, reason: "apply_request_missing" },
|
||||||
|
});
|
||||||
|
return true;
|
||||||
|
})();
|
||||||
|
if (changed) {
|
||||||
|
reconciled += 1;
|
||||||
|
reconciledIds.add(row.id);
|
||||||
|
}
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
if (requestFresh || stateFresh) continue;
|
||||||
|
const status: "completed" | "failed" = row.status === "applying" && releaseVersion === row.version ? "completed" : "failed";
|
||||||
|
const errorMessage = status === "failed" ? "更新任务超时,已释放更新队列" : null;
|
||||||
|
const changed = database.transaction(() => {
|
||||||
|
const result = database.prepare(`
|
||||||
|
UPDATE update_jobs
|
||||||
|
SET status=?, error_message=?, completed_at=?, updated_at=?
|
||||||
|
WHERE id=? AND status=? AND updated_at=?
|
||||||
|
`).run(status, errorMessage, now, now, row.id, row.status, row.updatedAt);
|
||||||
|
if (result.changes !== 1) return false;
|
||||||
|
writeAudit(database, {
|
||||||
|
requestId: row.requestId || randomUUID(),
|
||||||
|
actorAdminId: row.adminId,
|
||||||
|
action: "update.reconciled",
|
||||||
|
targetType: "update",
|
||||||
|
targetId: row.id,
|
||||||
|
outcome: status === "completed" ? "success" : "failure",
|
||||||
|
before: { status: row.status, version: row.version },
|
||||||
|
after: { status, version: row.version, reason: "orphaned_timeout" },
|
||||||
|
});
|
||||||
|
return true;
|
||||||
|
})();
|
||||||
|
if (changed) {
|
||||||
|
reconciled += 1;
|
||||||
|
reconciledIds.add(row.id);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
// Prevent a stale request from being replayed after its DB row has been
|
||||||
|
// marked failed. The path is fixed by the server configuration and the
|
||||||
|
// operation is safe even when a root runner is racing with this call.
|
||||||
|
// A download runner refreshes the state marker while it is still using the
|
||||||
|
// request. Keep the request until that lease also expires; otherwise a
|
||||||
|
// long download can lose its job id and fail to finalize its row.
|
||||||
|
const queuedRequestId = requestPresent ? requestJobId(config.updateRequestPath) : null;
|
||||||
|
const queuedRequest = queuedRequestId ? rows.find((row) => row.id === queuedRequestId) : undefined;
|
||||||
|
const requestStillNeeded = Boolean(
|
||||||
|
queuedRequest
|
||||||
|
&& ACTIVE_UPDATE_STATUSES.includes(queuedRequest.status)
|
||||||
|
&& !reconciledIds.has(queuedRequest.id)
|
||||||
|
&& !(queuedRequest.status === "staged" && queuedRequest.operation === "download"),
|
||||||
|
);
|
||||||
|
if (!stateFresh
|
||||||
|
&& (!requestPresent || (requestMtime !== null && now - requestMtime >= ORPHANED_UPDATE_TIMEOUT_MS))
|
||||||
|
&& !requestStillNeeded) {
|
||||||
|
removeExpiredRequest(config.updateRequestPath, now);
|
||||||
|
}
|
||||||
|
return reconciled;
|
||||||
|
}
|
||||||
|
|||||||
+3
-1
@@ -423,7 +423,7 @@ export async function verifySha256(filePath: string, expected: string): Promise<
|
|||||||
export async function downloadReleaseAsset(
|
export async function downloadReleaseAsset(
|
||||||
url: string | URL,
|
url: string | URL,
|
||||||
destination: string,
|
destination: string,
|
||||||
options: UrlPolicy & { fetchImpl?: typeof fetch | undefined; maxBytes?: number | undefined } = {},
|
options: UrlPolicy & { fetchImpl?: typeof fetch | undefined; maxBytes?: number | undefined; onProgress?: ((downloadedBytes: number, totalBytes: number | null) => void) | undefined } = {},
|
||||||
): Promise<{ size: number; sha256: string }> {
|
): Promise<{ size: number; sha256: string }> {
|
||||||
const fetchImpl = options.fetchImpl ?? fetch;
|
const fetchImpl = options.fetchImpl ?? fetch;
|
||||||
let current = validateHttpsUrl(url, options);
|
let current = validateHttpsUrl(url, options);
|
||||||
@@ -446,6 +446,7 @@ export async function downloadReleaseAsset(
|
|||||||
}
|
}
|
||||||
if (response.status < 200 || response.status >= 300 || !response.body) throw new Error("更新文件下载失败");
|
if (response.status < 200 || response.status >= 300 || !response.body) throw new Error("更新文件下载失败");
|
||||||
const declared = Number(response.headers.get("content-length") ?? 0);
|
const declared = Number(response.headers.get("content-length") ?? 0);
|
||||||
|
const totalBytes = Number.isSafeInteger(declared) && declared > 0 ? declared : null;
|
||||||
const maxBytes = options.maxBytes ?? 512 * 1024 * 1024;
|
const maxBytes = options.maxBytes ?? 512 * 1024 * 1024;
|
||||||
if (declared > maxBytes) throw new Error("更新文件超过大小限制");
|
if (declared > maxBytes) throw new Error("更新文件超过大小限制");
|
||||||
await mkdir(path.dirname(destination), { recursive: true, mode: 0o700 });
|
await mkdir(path.dirname(destination), { recursive: true, mode: 0o700 });
|
||||||
@@ -454,6 +455,7 @@ export async function downloadReleaseAsset(
|
|||||||
const hash = createHash("sha256");
|
const hash = createHash("sha256");
|
||||||
const meter = new Transform({ transform(chunk: Buffer, _encoding, callback) {
|
const meter = new Transform({ transform(chunk: Buffer, _encoding, callback) {
|
||||||
size += chunk.length;
|
size += chunk.length;
|
||||||
|
options.onProgress?.(size, totalBytes);
|
||||||
if (size > maxBytes) return callback(new Error("更新文件超过大小限制"));
|
if (size > maxBytes) return callback(new Error("更新文件超过大小限制"));
|
||||||
hash.update(chunk);
|
hash.update(chunk);
|
||||||
callback(null, chunk);
|
callback(null, chunk);
|
||||||
|
|||||||
@@ -4,6 +4,15 @@ Description=Watch for TallyNote release update requests
|
|||||||
[Path]
|
[Path]
|
||||||
PathExists=/var/lib/tallynote/update-request.json
|
PathExists=/var/lib/tallynote/update-request.json
|
||||||
PathChanged=/var/lib/tallynote/update-request.json
|
PathChanged=/var/lib/tallynote/update-request.json
|
||||||
|
# The recovery marker lives beside the release link. Watching it as well
|
||||||
|
# allows systemd to resume reconciliation when the runner is interrupted
|
||||||
|
# after consuming the request but before clearing its state file.
|
||||||
|
PathExists=/opt/tallynote/.update-state
|
||||||
|
PathChanged=/opt/tallynote/.update-state
|
||||||
|
# Keep a directory-level fallback because some systemd/inotify versions skip
|
||||||
|
# dotfiles when watching an individual path. State writes are atomic renames,
|
||||||
|
# so the containing directory changes even when the marker itself is hidden.
|
||||||
|
PathChanged=/opt/tallynote
|
||||||
Unit=tallynote-update.service
|
Unit=tallynote-update.service
|
||||||
|
|
||||||
[Install]
|
[Install]
|
||||||
|
|||||||
@@ -2,7 +2,6 @@
|
|||||||
Description=TallyNote privileged release updater
|
Description=TallyNote privileged release updater
|
||||||
After=network-online.target
|
After=network-online.target
|
||||||
Wants=network-online.target
|
Wants=network-online.target
|
||||||
ConditionPathExists=/var/lib/tallynote/update-request.json
|
|
||||||
|
|
||||||
[Service]
|
[Service]
|
||||||
Type=oneshot
|
Type=oneshot
|
||||||
@@ -12,6 +11,10 @@ WorkingDirectory=/opt/tallynote/current
|
|||||||
EnvironmentFile=-/etc/tallynote/tallynote.env
|
EnvironmentFile=-/etc/tallynote/tallynote.env
|
||||||
ExecStart=/usr/local/libexec/tallynote-update-runner
|
ExecStart=/usr/local/libexec/tallynote-update-runner
|
||||||
Environment=PATH=/usr/sbin:/usr/bin:/sbin:/bin
|
Environment=PATH=/usr/sbin:/usr/bin:/sbin:/bin
|
||||||
|
# Downloads, archive validation and data backups can exceed systemd's 90s
|
||||||
|
# default start timeout on a slower server. Keep one update job alive long
|
||||||
|
# enough to finish or reach its own health-check/recovery path.
|
||||||
|
TimeoutStartSec=30min
|
||||||
NoNewPrivileges=true
|
NoNewPrivileges=true
|
||||||
CapabilityBoundingSet=
|
CapabilityBoundingSet=
|
||||||
AmbientCapabilities=
|
AmbientCapabilities=
|
||||||
|
|||||||
@@ -14,6 +14,8 @@ Environment=PATH=/opt/tallynote/current/runtime/bin:/usr/sbin:/usr/bin:/sbin:/bi
|
|||||||
ExecStart=/opt/tallynote/current/bin/tallynote
|
ExecStart=/opt/tallynote/current/bin/tallynote
|
||||||
Restart=on-failure
|
Restart=on-failure
|
||||||
RestartSec=5s
|
RestartSec=5s
|
||||||
|
# Do not let a wedged Node process hold an update stop forever.
|
||||||
|
TimeoutStopSec=30s
|
||||||
NoNewPrivileges=true
|
NoNewPrivileges=true
|
||||||
PrivateTmp=true
|
PrivateTmp=true
|
||||||
ProtectSystem=strict
|
ProtectSystem=strict
|
||||||
|
|||||||
+3
-3
@@ -129,10 +129,10 @@ describe("TallyNote API", () => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
it("拒绝没有 Origin 的写请求", async () => {
|
it("反向代理缺少 Origin 时仍允许登录请求进入认证流程", async () => {
|
||||||
const response = await app.inject({ method: "POST", url: "/api/auth/login", payload: { username: "x", password: "x" } });
|
const response = await app.inject({ method: "POST", url: "/api/auth/login", payload: { username: "x", password: "x" } });
|
||||||
expect(response.statusCode).toBe(403);
|
expect(response.statusCode).toBe(401);
|
||||||
expect(response.json().error.code).toBe("ORIGIN_FORBIDDEN");
|
expect(response.json().error.code).toBe("INVALID_CREDENTIALS");
|
||||||
});
|
});
|
||||||
|
|
||||||
it("将非法 JSON、伪造请求 ID 处理为结构化 400", async () => {
|
it("将非法 JSON、伪造请求 ID 处理为结构化 400", async () => {
|
||||||
|
|||||||
@@ -42,9 +42,10 @@ describe("数据库迁移", () => {
|
|||||||
{ name: "0002_update_jobs.sql" },
|
{ name: "0002_update_jobs.sql" },
|
||||||
{ name: "0003_update_job_ownership.sql" },
|
{ name: "0003_update_job_ownership.sql" },
|
||||||
{ name: "0004_update_download_apply.sql" },
|
{ name: "0004_update_download_apply.sql" },
|
||||||
|
{ name: "0005_update_progress.sql" },
|
||||||
]);
|
]);
|
||||||
const updateColumns = migrated.sqlite.prepare("PRAGMA table_info(update_jobs)").all() as Array<{ name: string }>;
|
const updateColumns = migrated.sqlite.prepare("PRAGMA table_info(update_jobs)").all() as Array<{ name: string }>;
|
||||||
expect(updateColumns.map((column) => column.name)).toEqual(expect.arrayContaining(["admin_id", "session_hash", "request_id", "requested_at", "started_at", "operation"]));
|
expect(updateColumns.map((column) => column.name)).toEqual(expect.arrayContaining(["admin_id", "session_hash", "request_id", "requested_at", "started_at", "operation", "downloaded_bytes", "download_started_at", "download_speed_bps"]));
|
||||||
expect(migrated.sqlite.prepare("SELECT note, invoice_missing_reason AS reason FROM expenses WHERE id='00000000-0000-4000-8000-000000000099'").get()).toEqual({ note: "旧账目", reason: null });
|
expect(migrated.sqlite.prepare("SELECT note, invoice_missing_reason AS reason FROM expenses WHERE id='00000000-0000-4000-8000-000000000099'").get()).toEqual({ note: "旧账目", reason: null });
|
||||||
migrated.sqlite.close();
|
migrated.sqlite.close();
|
||||||
migrated = openDatabase(config);
|
migrated = openDatabase(config);
|
||||||
|
|||||||
@@ -48,6 +48,7 @@ describe("部署安全配置", () => {
|
|||||||
expect(loadConfig().trustProxy).toBe(1);
|
expect(loadConfig().trustProxy).toBe(1);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|
||||||
it("systemd 更新必须绑定主机白名单,签名校验默认关闭", () => {
|
it("systemd 更新必须绑定主机白名单,签名校验默认关闭", () => {
|
||||||
process.env.TALLYNOTE_UPDATE_STRATEGY = "systemd";
|
process.env.TALLYNOTE_UPDATE_STRATEGY = "systemd";
|
||||||
process.env.TALLYNOTE_PUBLIC_ORIGIN = "https://example.test";
|
process.env.TALLYNOTE_PUBLIC_ORIGIN = "https://example.test";
|
||||||
|
|||||||
@@ -76,6 +76,12 @@ describe("更新 API", () => {
|
|||||||
expect(tooSoon.statusCode).toBe(429);
|
expect(tooSoon.statusCode).toBe(429);
|
||||||
expect(tooSoon.headers["retry-after"]).toBeDefined();
|
expect(tooSoon.headers["retry-after"]).toBeDefined();
|
||||||
|
|
||||||
|
// Cooldown is scoped to the authenticated administrator, not the whole
|
||||||
|
// database or release endpoint.
|
||||||
|
const otherSession = await login("update-admin-other");
|
||||||
|
const otherChecked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: otherSession.cookies, "x-csrf-token": otherSession.csrf }, payload: {} });
|
||||||
|
expect(otherChecked.statusCode).toBe(200);
|
||||||
|
|
||||||
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } });
|
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } });
|
||||||
expect(applied.statusCode).toBe(202);
|
expect(applied.statusCode).toBe(202);
|
||||||
const jobId = applied.json().job.id as string;
|
const jobId = applied.json().job.id as string;
|
||||||
@@ -157,6 +163,12 @@ describe("更新 API", () => {
|
|||||||
globalThis.fetch = (async () => new Response("upstream unavailable", { status: 503 })) as typeof fetch;
|
globalThis.fetch = (async () => new Response("upstream unavailable", { status: 503 })) as typeof fetch;
|
||||||
const response = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } });
|
const response = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } });
|
||||||
expect(response.statusCode).toBe(502);
|
expect(response.statusCode).toBe(502);
|
||||||
|
// A failed upstream check must not reserve the per-admin cooldown; an
|
||||||
|
// operator can retry immediately after fixing the release endpoint.
|
||||||
|
const check = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||||
|
expect(check.statusCode).toBe(502);
|
||||||
|
const retry = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||||
|
expect(retry.statusCode).toBe(502);
|
||||||
const audit = database.sqlite.prepare("SELECT outcome FROM audit_events WHERE action='update.apply_requested' ORDER BY id DESC LIMIT 1").get() as { outcome: string } | undefined;
|
const audit = database.sqlite.prepare("SELECT outcome FROM audit_events WHERE action='update.apply_requested' ORDER BY id DESC LIMIT 1").get() as { outcome: string } | undefined;
|
||||||
expect(audit?.outcome).toBe("failure");
|
expect(audit?.outcome).toBe("failure");
|
||||||
});
|
});
|
||||||
|
|||||||
+211
-5
@@ -1,9 +1,9 @@
|
|||||||
import { afterEach, describe, expect, it } from "vitest";
|
import { afterEach, describe, expect, it } from "vitest";
|
||||||
import { mkdir, readlink, symlink, writeFile, readFile, stat, readdir } from "node:fs/promises";
|
import { mkdir, readlink, symlink, writeFile, readFile, stat, readdir, utimes } from "node:fs/promises";
|
||||||
import { mkdtemp, rm } from "node:fs/promises";
|
import { mkdtemp, rm } from "node:fs/promises";
|
||||||
import { tmpdir } from "node:os";
|
import { tmpdir } from "node:os";
|
||||||
import path from "node:path";
|
import path from "node:path";
|
||||||
import { createHash, generateKeyPairSync, sign } from "node:crypto";
|
import { createHash, generateKeyPairSync, randomUUID, sign } from "node:crypto";
|
||||||
import {
|
import {
|
||||||
atomicSwitchRelease,
|
atomicSwitchRelease,
|
||||||
createSafeArchive,
|
createSafeArchive,
|
||||||
@@ -18,13 +18,13 @@ import {
|
|||||||
selectReleaseAsset,
|
selectReleaseAsset,
|
||||||
validateHttpsUrl,
|
validateHttpsUrl,
|
||||||
} from "../server/update.js";
|
} from "../server/update.js";
|
||||||
import { runUpdate } from "../server/cli/update.js";
|
import { finalizeUpdateJob, runUpdate } from "../server/cli/update.js";
|
||||||
import { validateUpdateRequest } from "../server/cli/update.js";
|
import { validateUpdateRequest } from "../server/cli/update.js";
|
||||||
import { checkForUpdate, verifyReleaseSignature } from "../server/update-service.js";
|
import { checkForUpdate, ORPHANED_UPDATE_TIMEOUT_MS, reconcileOrphanedUpdateJobs, verifyReleaseSignature } from "../server/update-service.js";
|
||||||
import { loadConfig, prepareDataDirectories } from "../server/config.js";
|
import { loadConfig, prepareDataDirectories } from "../server/config.js";
|
||||||
import { openDatabase } from "../server/db/index.js";
|
import { openDatabase } from "../server/db/index.js";
|
||||||
|
|
||||||
const envKeys = ["TALLYNOTE_DATA_DIR", "TALLYNOTE_PUBLIC_ORIGIN", "TALLYNOTE_COOKIE_SECURE", "TALLYNOTE_UPDATE_STRATEGY", "TALLYNOTE_UPDATE_METADATA_URL", "TALLYNOTE_UPDATE_ALLOWED_HOSTS", "TALLYNOTE_UPDATE_REQUIRE_SIGNATURE", "TALLYNOTE_UPDATE_PUBLIC_KEY"];
|
const envKeys = ["TALLYNOTE_DATA_DIR", "TALLYNOTE_INSTALL_PREFIX", "TALLYNOTE_PUBLIC_ORIGIN", "TALLYNOTE_COOKIE_SECURE", "TALLYNOTE_UPDATE_STRATEGY", "TALLYNOTE_UPDATE_METADATA_URL", "TALLYNOTE_UPDATE_ALLOWED_HOSTS", "TALLYNOTE_UPDATE_REQUIRE_SIGNATURE", "TALLYNOTE_UPDATE_PUBLIC_KEY"];
|
||||||
const originalFetch = globalThis.fetch;
|
const originalFetch = globalThis.fetch;
|
||||||
|
|
||||||
afterEach(() => {
|
afterEach(() => {
|
||||||
@@ -207,6 +207,212 @@ describe("更新安全工具", () => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it("更新器支持旧客户端创建的 queued/apply 直接更新请求", async () => {
|
||||||
|
const root = await mkdtemp(path.join(tmpdir(), "tallynote-update-direct-"));
|
||||||
|
const previousFetch = globalThis.fetch;
|
||||||
|
let database: ReturnType<typeof openDatabase> | undefined;
|
||||||
|
try {
|
||||||
|
const dataDir = path.join(root, "data");
|
||||||
|
const installPrefix = path.join(root, "install");
|
||||||
|
process.env.TALLYNOTE_DATA_DIR = dataDir;
|
||||||
|
process.env.TALLYNOTE_INSTALL_PREFIX = installPrefix;
|
||||||
|
process.env.TALLYNOTE_PUBLIC_ORIGIN = "http://127.0.0.1:3998";
|
||||||
|
process.env.TALLYNOTE_COOKIE_SECURE = "false";
|
||||||
|
process.env.TALLYNOTE_UPDATE_STRATEGY = "systemd";
|
||||||
|
process.env.TALLYNOTE_UPDATE_METADATA_URL = "https://updates.example/latest";
|
||||||
|
process.env.TALLYNOTE_UPDATE_ALLOWED_HOSTS = "updates.example";
|
||||||
|
process.env.TALLYNOTE_UPDATE_REQUIRE_SIGNATURE = "false";
|
||||||
|
const config = loadConfig();
|
||||||
|
prepareDataDirectories(config);
|
||||||
|
await mkdir(config.releasesDir, { recursive: true, mode: 0o755 });
|
||||||
|
const oldRelease = path.join(config.releasesDir, config.appVersion);
|
||||||
|
await mkdir(path.join(oldRelease, "dist"), { recursive: true, mode: 0o755 });
|
||||||
|
await writeFile(path.join(oldRelease, "dist", "marker"), "old");
|
||||||
|
await symlink(oldRelease, config.currentLink);
|
||||||
|
|
||||||
|
const source = path.join(root, "source");
|
||||||
|
await mkdir(path.join(source, "dist"), { recursive: true, mode: 0o755 });
|
||||||
|
await writeFile(path.join(source, "dist", "marker"), "new");
|
||||||
|
const archive = path.join(root, "release.tar.gz");
|
||||||
|
await createSafeArchive(source, archive);
|
||||||
|
const bytes = await readFile(archive);
|
||||||
|
const digest = createHash("sha256").update(bytes).digest("hex");
|
||||||
|
const jobId = randomUUID();
|
||||||
|
database = openDatabase(config);
|
||||||
|
const now = Date.now();
|
||||||
|
const assetName = `tallynote-1.2.0-${detectPlatform().target}.tar.gz`;
|
||||||
|
database.sqlite.prepare(`
|
||||||
|
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url,
|
||||||
|
expected_sha256, created_at, updated_at, requested_at)
|
||||||
|
VALUES (?, 'apply', 'queued', '1.2.0', ?, ?, ?, ?, ?, ?)
|
||||||
|
`).run(jobId, detectPlatform().target, "https://updates.example/" + assetName, digest, now, now, now);
|
||||||
|
globalThis.fetch = (async (input: string | URL) => {
|
||||||
|
const url = input.toString();
|
||||||
|
if (url.endsWith("/latest")) return new Response(JSON.stringify({ tag_name: "v1.2.0", assets: [{ name: assetName, browser_download_url: `https://updates.example/${assetName}` }, { name: "SHA256SUMS", browser_download_url: "https://updates.example/SHA256SUMS" }] }));
|
||||||
|
if (url.endsWith("SHA256SUMS")) return new Response(`${digest} ${assetName}\n`);
|
||||||
|
return new Response(bytes, { headers: { "content-length": String(bytes.length) } });
|
||||||
|
}) as typeof fetch;
|
||||||
|
|
||||||
|
await runUpdate({
|
||||||
|
metadataUrl: config.updateMetadataUrl,
|
||||||
|
version: "1.2.0",
|
||||||
|
currentVersion: config.appVersion,
|
||||||
|
currentDir: config.currentLink,
|
||||||
|
stagingDir: path.join(root, "staging"),
|
||||||
|
currentLink: config.currentLink,
|
||||||
|
releasesDir: config.releasesDir,
|
||||||
|
allowedHosts: config.updateAllowedHosts,
|
||||||
|
maxBytes: config.updateMaxBytes,
|
||||||
|
dataBackupMaxBytes: config.maxTotalBytes,
|
||||||
|
deferCompletion: true,
|
||||||
|
operation: "apply",
|
||||||
|
jobId,
|
||||||
|
sqlite: database.sqlite,
|
||||||
|
fetchImpl: globalThis.fetch,
|
||||||
|
});
|
||||||
|
expect(await readFile(path.join(config.currentLink, "dist", "marker"), "utf8")).toBe("new");
|
||||||
|
const row = database.sqlite.prepare("SELECT operation, status FROM update_jobs WHERE id=?").get(jobId);
|
||||||
|
expect(row).toEqual({ operation: "apply", status: "applying" });
|
||||||
|
finalizeUpdateJob(database.sqlite, jobId, "failed");
|
||||||
|
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "failed" });
|
||||||
|
} finally {
|
||||||
|
globalThis.fetch = previousFetch;
|
||||||
|
if (database) database.sqlite.close();
|
||||||
|
await rm(root, { recursive: true, force: true });
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
it("在请求和恢复标记丢失后收敛孤儿任务,但保留 staged 下载", async () => {
|
||||||
|
const root = await mkdtemp(path.join(tmpdir(), "tallynote-update-reconcile-"));
|
||||||
|
let database: ReturnType<typeof openDatabase> | undefined;
|
||||||
|
try {
|
||||||
|
const dataDir = path.join(root, "data");
|
||||||
|
const installPrefix = path.join(root, "install");
|
||||||
|
process.env.TALLYNOTE_DATA_DIR = dataDir;
|
||||||
|
process.env.TALLYNOTE_INSTALL_PREFIX = installPrefix;
|
||||||
|
process.env.TALLYNOTE_PUBLIC_ORIGIN = "http://127.0.0.1:3998";
|
||||||
|
process.env.TALLYNOTE_COOKIE_SECURE = "false";
|
||||||
|
process.env.TALLYNOTE_UPDATE_STRATEGY = "systemd";
|
||||||
|
process.env.TALLYNOTE_UPDATE_METADATA_URL = "https://updates.example/latest";
|
||||||
|
process.env.TALLYNOTE_UPDATE_ALLOWED_HOSTS = "updates.example";
|
||||||
|
process.env.TALLYNOTE_UPDATE_REQUIRE_SIGNATURE = "false";
|
||||||
|
const config = loadConfig();
|
||||||
|
prepareDataDirectories(config);
|
||||||
|
await mkdir(path.join(config.releasesDir, config.appVersion, "dist"), { recursive: true });
|
||||||
|
await symlink(path.join(config.releasesDir, config.appVersion), config.currentLink);
|
||||||
|
database = openDatabase(config);
|
||||||
|
const staleAt = Date.now() - ORPHANED_UPDATE_TIMEOUT_MS - 1;
|
||||||
|
const insert = database.sqlite.prepare(`
|
||||||
|
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
||||||
|
VALUES (?, ?, ?, ?, ?, ?, ?, ?)
|
||||||
|
`);
|
||||||
|
const queuedId = randomUUID();
|
||||||
|
const applyingId = randomUUID();
|
||||||
|
const stagedId = randomUUID();
|
||||||
|
const stagedApplyId = randomUUID();
|
||||||
|
insert.run(queuedId, "apply", "queued", "1.2.0", "linux-x64", "https://updates.example/queued.tar.gz", staleAt, staleAt);
|
||||||
|
insert.run(applyingId, "apply", "applying", config.appVersion, "linux-x64", "https://updates.example/applying.tar.gz", staleAt, staleAt);
|
||||||
|
insert.run(stagedId, "download", "staged", "1.2.0", "linux-x64", "https://updates.example/staged.tar.gz", staleAt, staleAt);
|
||||||
|
insert.run(stagedApplyId, "apply", "staged", "1.2.0", "linux-x64", "https://updates.example/staged-apply.tar.gz", staleAt, staleAt);
|
||||||
|
const now = Date.now();
|
||||||
|
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, now)).toBe(3);
|
||||||
|
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(queuedId)).toEqual({ status: "failed" });
|
||||||
|
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(applyingId)).toEqual({ status: "completed" });
|
||||||
|
expect(database.sqlite.prepare("SELECT status, operation FROM update_jobs WHERE id=?").get(stagedId)).toEqual({ status: "staged", operation: "download" });
|
||||||
|
expect(database.sqlite.prepare("SELECT status, operation FROM update_jobs WHERE id=?").get(stagedApplyId)).toEqual({ status: "staged", operation: "download" });
|
||||||
|
} finally {
|
||||||
|
if (database) database.sqlite.close();
|
||||||
|
await rm(root, { recursive: true, force: true });
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
it("下载心跳有效时不回收任务或删除仍在使用的请求文件", async () => {
|
||||||
|
const root = await mkdtemp(path.join(tmpdir(), "tallynote-update-heartbeat-"));
|
||||||
|
let database: ReturnType<typeof openDatabase> | undefined;
|
||||||
|
try {
|
||||||
|
const dataDir = path.join(root, "data");
|
||||||
|
const installPrefix = path.join(root, "install");
|
||||||
|
process.env.TALLYNOTE_DATA_DIR = dataDir;
|
||||||
|
process.env.TALLYNOTE_INSTALL_PREFIX = installPrefix;
|
||||||
|
process.env.TALLYNOTE_PUBLIC_ORIGIN = "http://127.0.0.1:3998";
|
||||||
|
process.env.TALLYNOTE_COOKIE_SECURE = "false";
|
||||||
|
process.env.TALLYNOTE_UPDATE_STRATEGY = "systemd";
|
||||||
|
process.env.TALLYNOTE_UPDATE_METADATA_URL = "https://updates.example/latest";
|
||||||
|
process.env.TALLYNOTE_UPDATE_ALLOWED_HOSTS = "updates.example";
|
||||||
|
process.env.TALLYNOTE_UPDATE_REQUIRE_SIGNATURE = "false";
|
||||||
|
const config = loadConfig();
|
||||||
|
prepareDataDirectories(config);
|
||||||
|
await mkdir(path.join(config.releasesDir, config.appVersion, "dist"), { recursive: true });
|
||||||
|
await symlink(path.join(config.releasesDir, config.appVersion), config.currentLink);
|
||||||
|
database = openDatabase(config);
|
||||||
|
const staleAt = Date.now() - ORPHANED_UPDATE_TIMEOUT_MS - 1;
|
||||||
|
const jobId = randomUUID();
|
||||||
|
database.sqlite.prepare(`
|
||||||
|
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
||||||
|
VALUES (?, 'download', 'downloading', '1.2.0', 'linux-x64', ?, ?, ?)
|
||||||
|
`).run(jobId, "https://updates.example/download.tar.gz", staleAt, staleAt);
|
||||||
|
await writeFile(config.updateRequestPath, JSON.stringify({ jobId, operation: "download" }));
|
||||||
|
const statePath = path.join(config.installPrefix, ".update-state");
|
||||||
|
await writeFile(statePath, `job_id=${jobId}\nold_target=${path.join(config.releasesDir, config.appVersion)}\nphase=download\n`);
|
||||||
|
const now = Date.now();
|
||||||
|
await utimes(config.updateRequestPath, new Date(staleAt), new Date(staleAt));
|
||||||
|
await utimes(statePath, new Date(now), new Date(now));
|
||||||
|
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, now)).toBe(0);
|
||||||
|
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "downloading" });
|
||||||
|
expect(await stat(config.updateRequestPath)).toBeTruthy();
|
||||||
|
|
||||||
|
const expiredNow = now + ORPHANED_UPDATE_TIMEOUT_MS + 1;
|
||||||
|
await utimes(statePath, new Date(staleAt), new Date(staleAt));
|
||||||
|
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, expiredNow)).toBe(1);
|
||||||
|
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "failed" });
|
||||||
|
await expect(stat(config.updateRequestPath)).rejects.toThrow();
|
||||||
|
} finally {
|
||||||
|
if (database) database.sqlite.close();
|
||||||
|
await rm(root, { recursive: true, force: true });
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
it("队列任务有新请求标记时可被重新检查,标记过期后才回收", async () => {
|
||||||
|
const root = await mkdtemp(path.join(tmpdir(), "tallynote-update-queued-marker-"));
|
||||||
|
let database: ReturnType<typeof openDatabase> | undefined;
|
||||||
|
try {
|
||||||
|
const dataDir = path.join(root, "data");
|
||||||
|
const installPrefix = path.join(root, "install");
|
||||||
|
process.env.TALLYNOTE_DATA_DIR = dataDir;
|
||||||
|
process.env.TALLYNOTE_INSTALL_PREFIX = installPrefix;
|
||||||
|
process.env.TALLYNOTE_PUBLIC_ORIGIN = "http://127.0.0.1:3998";
|
||||||
|
process.env.TALLYNOTE_COOKIE_SECURE = "false";
|
||||||
|
process.env.TALLYNOTE_UPDATE_STRATEGY = "systemd";
|
||||||
|
process.env.TALLYNOTE_UPDATE_METADATA_URL = "https://updates.example/latest";
|
||||||
|
process.env.TALLYNOTE_UPDATE_ALLOWED_HOSTS = "updates.example";
|
||||||
|
process.env.TALLYNOTE_UPDATE_REQUIRE_SIGNATURE = "false";
|
||||||
|
const config = loadConfig();
|
||||||
|
prepareDataDirectories(config);
|
||||||
|
database = openDatabase(config);
|
||||||
|
const staleAt = Date.now() - ORPHANED_UPDATE_TIMEOUT_MS - 1;
|
||||||
|
const jobId = randomUUID();
|
||||||
|
database.sqlite.prepare(`
|
||||||
|
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
||||||
|
VALUES (?, 'apply', 'queued', '1.2.0', 'linux-x64', ?, ?, ?)
|
||||||
|
`).run(jobId, "https://updates.example/queued.tar.gz", staleAt, staleAt);
|
||||||
|
await writeFile(config.updateRequestPath, JSON.stringify({ jobId, operation: "apply" }));
|
||||||
|
const now = Date.now();
|
||||||
|
await utimes(config.updateRequestPath, new Date(now), new Date(now));
|
||||||
|
|
||||||
|
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, now)).toBe(0);
|
||||||
|
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "queued" });
|
||||||
|
expect(await stat(config.updateRequestPath)).toBeTruthy();
|
||||||
|
|
||||||
|
const expiredNow = now + ORPHANED_UPDATE_TIMEOUT_MS + 1;
|
||||||
|
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, expiredNow)).toBe(1);
|
||||||
|
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "failed" });
|
||||||
|
await expect(stat(config.updateRequestPath)).rejects.toThrow();
|
||||||
|
} finally {
|
||||||
|
if (database) database.sqlite.close();
|
||||||
|
await rm(root, { recursive: true, force: true });
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
it("流式解包在展开大小上限前拒绝高压缩比归档,并修正发布树权限", async () => {
|
it("流式解包在展开大小上限前拒绝高压缩比归档,并修正发布树权限", async () => {
|
||||||
const root = await mkdtemp(path.join(tmpdir(), "tallynote-update-stream-"));
|
const root = await mkdtemp(path.join(tmpdir(), "tallynote-update-stream-"));
|
||||||
try {
|
try {
|
||||||
|
|||||||
@@ -7,7 +7,7 @@ import { ErrorBanner, Page, Surface } from "../common";
|
|||||||
import type { Notify } from "../expenses/types";
|
import type { Notify } from "../expenses/types";
|
||||||
|
|
||||||
type JobStatus = "queued" | "downloading" | "verifying" | "staged" | "backing_up" | "applying" | "completed" | "failed" | "cancelled";
|
type JobStatus = "queued" | "downloading" | "verifying" | "staged" | "backing_up" | "applying" | "completed" | "failed" | "cancelled";
|
||||||
type UpdateJob = { id: string; operation?: "download" | "apply"; status: JobStatus; version: string; platform: string; assetName?: string | null; sizeBytes?: number | null; errorMessage?: string | null; createdAt?: number; updatedAt?: number; completedAt?: number | null; applyQueuedAt?: number | string | null; restartWindowSeconds?: number | null; restartDeadline?: number | string | null; restartAt?: number | string | null; expectedRecoveryAt?: number | string | null };
|
type UpdateJob = { id: string; operation?: "download" | "apply"; status: JobStatus; version: string; platform: string; assetName?: string | null; sizeBytes?: number | null; downloadedBytes?: number | null; downloadStartedAt?: number | null; downloadSpeedBps?: number | null; errorMessage?: string | null; createdAt?: number; updatedAt?: number; completedAt?: number | null; applyQueuedAt?: number | string | null; restartWindowSeconds?: number | null; restartDeadline?: number | string | null; restartAt?: number | string | null; expectedRecoveryAt?: number | string | null };
|
||||||
type LatestRelease = { version: string; tagName?: string; releaseName?: string; publishedAt?: string; compatible: boolean; integrityReady: boolean; signatureReady: boolean; isNewer: boolean; assetName?: string; assetSize?: number; notes?: string | null; releaseNotes?: string | null; body?: string | null; htmlUrl?: string | null };
|
type LatestRelease = { version: string; tagName?: string; releaseName?: string; publishedAt?: string; compatible: boolean; integrityReady: boolean; signatureReady: boolean; isNewer: boolean; assetName?: string; assetSize?: number; notes?: string | null; releaseNotes?: string | null; body?: string | null; htmlUrl?: string | null };
|
||||||
type UpdateInfo = { configured: boolean; strategy: "disabled" | "systemd"; currentVersion: string; platform: { target: string; os: string; arch: string }; checkedAt: number; latest: LatestRelease | null; job: UpdateJob | null };
|
type UpdateInfo = { configured: boolean; strategy: "disabled" | "systemd"; currentVersion: string; platform: { target: string; os: string; arch: string }; checkedAt: number; latest: LatestRelease | null; job: UpdateJob | null };
|
||||||
const active = new Set<JobStatus>(["queued", "downloading", "verifying", "staged", "backing_up", "applying"]);
|
const active = new Set<JobStatus>(["queued", "downloading", "verifying", "staged", "backing_up", "applying"]);
|
||||||
@@ -24,6 +24,16 @@ function notesFor(latest: LatestRelease): string | null {
|
|||||||
const value = latest.notes ?? latest.releaseNotes ?? latest.body;
|
const value = latest.notes ?? latest.releaseNotes ?? latest.body;
|
||||||
return typeof value === "string" && value.trim() ? value.trim() : null;
|
return typeof value === "string" && value.trim() ? value.trim() : null;
|
||||||
}
|
}
|
||||||
|
function bytesText(value: number | null | undefined): string {
|
||||||
|
if (!Number.isFinite(value) || !value || value < 0) return "0 B";
|
||||||
|
if (value >= 1024 * 1024 * 1024) return `${(value / 1024 / 1024 / 1024).toFixed(1)} GB`;
|
||||||
|
if (value >= 1024 * 1024) return `${(value / 1024 / 1024).toFixed(1)} MB`;
|
||||||
|
if (value >= 1024) return `${(value / 1024).toFixed(1)} KB`;
|
||||||
|
return `${Math.round(value)} B`;
|
||||||
|
}
|
||||||
|
function speedText(value: number | null | undefined): string {
|
||||||
|
return value && value > 0 ? `${bytesText(value)}/s` : "计算中";
|
||||||
|
}
|
||||||
|
|
||||||
export default function UpdatePage({ timezone = "Asia/Shanghai", notify }: { timezone?: string; notify?: Notify }) {
|
export default function UpdatePage({ timezone = "Asia/Shanghai", notify }: { timezone?: string; notify?: Notify }) {
|
||||||
const [info, setInfo] = useState<UpdateInfo | null>(null);
|
const [info, setInfo] = useState<UpdateInfo | null>(null);
|
||||||
@@ -106,16 +116,20 @@ export default function UpdatePage({ timezone = "Asia/Shanghai", notify }: { tim
|
|||||||
const sameCompleted = Boolean(job?.status === "completed" && latest && job.version === latest.version);
|
const sameCompleted = Boolean(job?.status === "completed" && latest && job.version === latest.version);
|
||||||
const canDownload = Boolean(info?.strategy === "systemd" && latest?.isNewer && latest.compatible && latest.integrityReady && !hasActiveJob && !sameCompleted && (!job || job.version !== latest.version || job.status === "failed" || job.status === "cancelled"));
|
const canDownload = Boolean(info?.strategy === "systemd" && latest?.isNewer && latest.compatible && latest.integrityReady && !hasActiveJob && !sameCompleted && (!job || job.version !== latest.version || job.status === "failed" || job.status === "cancelled"));
|
||||||
const canApply = Boolean(info?.strategy === "systemd" && latest?.isNewer && latest.compatible && latest.integrityReady && job?.operation === "download" && job.status === "staged" && job.version === latest.version);
|
const canApply = Boolean(info?.strategy === "systemd" && latest?.isNewer && latest.compatible && latest.integrityReady && job?.operation === "download" && job.status === "staged" && job.version === latest.version);
|
||||||
const progress = job ? ({ queued: 8, downloading: 28, verifying: 48, staged: 65, backing_up: 80, applying: 92 } as Partial<Record<JobStatus, number>>)[job.status] ?? 100 : 0;
|
const progress = job?.status === "staged" && job.operation === "download"
|
||||||
|
? 100
|
||||||
|
: job?.status === "downloading" && job.sizeBytes && job.downloadedBytes !== null && job.downloadedBytes !== undefined
|
||||||
|
? Math.min(99, Math.max(8, Math.round(job.downloadedBytes / job.sizeBytes * 100)))
|
||||||
|
: job ? ({ queued: 8, downloading: 28, verifying: 48, staged: 65, backing_up: 80, applying: 92 } as Partial<Record<JobStatus, number>>)[job.status] ?? 100 : 0;
|
||||||
const notes = latest ? notesFor(latest) : null;
|
const notes = latest ? notesFor(latest) : null;
|
||||||
|
|
||||||
return <Page title="系统更新" subtitle="检查受信任的 Release;更新前会校验文件并保护现有数据。" actions={<Button variant="outline" onClick={() => void check()} disabled={checking || loading || hasActiveJob} icon={<RefreshCw size={15} />}>{checking ? "检查中…" : "检查更新"}</Button>}>
|
return <Page title="系统更新" subtitle="检查受信任的 Release;更新前会校验文件并保护现有数据。" actions={<Button variant="outline" onClick={() => void check()} disabled={checking || loading} icon={<RefreshCw size={15} />}>{checking ? "检查中…" : "检查更新"}</Button>}>
|
||||||
{error && <ErrorBanner message={error} onRetry={() => void load()} />}{pollError && <ErrorBanner message={pollError} />}
|
{error && <ErrorBanner message={error} onRetry={() => void load()} />}{pollError && <ErrorBanner message={pollError} />}
|
||||||
{loading ? <div className="tn-empty" role="status" aria-live="polite">正在读取版本信息…</div> : info && <>
|
{loading ? <div className="tn-empty" role="status" aria-live="polite">正在读取版本信息…</div> : info && <>
|
||||||
<div className="tn-update-grid"><Surface className="tn-update-block"><Server size={20} /><span className="tn-eyebrow">当前版本</span><strong className="tn-update-value">v{info.currentVersion}</strong><small>运行平台:{info.platform.target}</small></Surface><Surface className="tn-update-block"><ShieldCheck size={20} /><span className="tn-eyebrow">更新方式</span><strong>{info.strategy === "systemd" ? "后台一键更新" : "手动命令行更新"}</strong><small>{info.strategy === "systemd" ? (info.configured ? "由 systemd 更新服务执行" : "尚未配置发布源") : "当前安装未启用后台更新"}</small></Surface></div>
|
<div className="tn-update-grid"><Surface className="tn-update-block"><Server size={20} /><span className="tn-eyebrow">当前版本</span><strong className="tn-update-value">v{info.currentVersion}</strong><small>运行平台:{info.platform.target}</small></Surface><Surface className="tn-update-block"><ShieldCheck size={20} /><span className="tn-eyebrow">更新方式</span><strong>{info.strategy === "systemd" ? "后台一键更新" : "手动命令行更新"}</strong><small>{info.strategy === "systemd" ? (info.configured ? "由 systemd 更新服务执行" : "尚未配置发布源") : "当前安装未启用后台更新"}</small></Surface></div>
|
||||||
{latest ? <Surface className="tn-update-release"><div className="tn-update-release-head"><div><span className="tn-eyebrow">最新 Release</span><h2>{latest.releaseName || latest.tagName || `v${latest.version}`}</h2>{latest.publishedAt && <small>发布时间:{dateText(Date.parse(latest.publishedAt), timezone)}</small>}</div><Tag theme={latest.isNewer ? "primary" : "success"}>{latest.isNewer ? "有新版本" : "已是最新"}</Tag></div>{notes && <div className="tn-release-notes"><span className="tn-eyebrow">Release notes</span><div>{notes}</div></div>}<div className="tn-facts"><div><span>平台文件</span><strong>{latest.compatible ? latest.assetName : "无匹配文件"}</strong></div><div><span>完整性</span><strong className={latest.integrityReady ? "text-success" : "text-danger"}>{latest.integrityReady ? "SHA-256 + 签名可验证" : "不可验证"}</strong></div><div><span>文件大小</span><strong>{latest.assetSize ? `${(latest.assetSize / 1024 / 1024).toFixed(1)} MB` : "-"}</strong></div></div>{latest.isNewer && !latest.compatible && <div className="tn-inline-error"><AlertCircle size={16} />当前平台没有可安装的 Release 文件。</div>}{latest.isNewer && latest.compatible && !latest.integrityReady && <div className="tn-inline-error"><AlertCircle size={16} />发布文件缺少完整校验,已禁用更新。</div>}<div className="tn-page-actions">{canDownload && <Button theme="primary" onClick={() => { setConfirmAction("download"); setConfirmVersion(latest.version); }} disabled={actionBusy} loading={actionBusy && confirmAction === "download"} icon={<Download size={16} />}>下载更新包</Button>}{canApply && <Button theme="primary" onClick={() => { setConfirmAction("apply"); setConfirmVersion(latest.version); }} disabled={actionBusy} loading={actionBusy && confirmAction === "apply"} icon={<Zap size={16} />}>立即更新</Button>}{reloadReady && <Button theme="primary" onClick={() => window.location.reload()}>重新加载</Button>}</div></Surface> : <div className="tn-empty">点击“检查更新”获取最新 Release。</div>}
|
{latest ? <Surface className="tn-update-release"><div className="tn-update-release-head"><div><span className="tn-eyebrow">最新 Release</span><h2>{latest.releaseName || latest.tagName || `v${latest.version}`}</h2>{latest.publishedAt && <small>发布时间:{dateText(Date.parse(latest.publishedAt), timezone)}</small>}</div><Tag theme={latest.isNewer ? "primary" : "success"}>{latest.isNewer ? "有新版本" : "已是最新"}</Tag></div>{notes && <div className="tn-release-notes"><span className="tn-eyebrow">Release notes</span><div>{notes}</div></div>}<div className="tn-facts"><div><span>平台文件</span><strong>{latest.compatible ? latest.assetName : "无匹配文件"}</strong></div><div><span>完整性</span><strong className={latest.integrityReady ? "text-success" : "text-danger"}>{latest.integrityReady ? "SHA-256 + 签名可验证" : "不可验证"}</strong></div><div><span>文件大小</span><strong>{latest.assetSize ? `${(latest.assetSize / 1024 / 1024).toFixed(1)} MB` : "-"}</strong></div></div>{latest.isNewer && !latest.compatible && <div className="tn-inline-error"><AlertCircle size={16} />当前平台没有可安装的 Release 文件。</div>}{latest.isNewer && latest.compatible && !latest.integrityReady && <div className="tn-inline-error"><AlertCircle size={16} />发布文件缺少完整校验,已禁用更新。</div>}<div className="tn-page-actions">{canDownload && <Button theme="primary" onClick={() => { setConfirmAction("download"); setConfirmVersion(latest.version); }} disabled={actionBusy} loading={actionBusy && confirmAction === "download"} icon={<Download size={16} />}>下载更新包</Button>}{canApply && <Button theme="primary" onClick={() => { setConfirmAction("apply"); setConfirmVersion(latest.version); }} disabled={actionBusy} loading={actionBusy && confirmAction === "apply"} icon={<Zap size={16} />}>立即更新</Button>}{reloadReady && <Button theme="primary" onClick={() => window.location.reload()}>重新加载</Button>}</div></Surface> : <div className="tn-empty">点击“检查更新”获取最新 Release。</div>}
|
||||||
{!info.configured && <div className="tn-update-explainer"><Terminal size={17} /><div><strong>当前为手动更新模式</strong><p>源码安装默认不启用后台更新。需要更新时,在服务器拉取对应 Release 后重新构建并重启服务;安装器部署并配置 systemd 后,才会显示后台一键更新。</p></div></div>}
|
{!info.configured && <div className="tn-update-explainer"><Terminal size={17} /><div><strong>当前为手动更新模式</strong><p>源码安装默认不启用后台更新。需要更新时,在服务器拉取对应 Release 后重新构建并重启服务;安装器部署并配置 systemd 后,才会显示后台一键更新。</p></div></div>}
|
||||||
{job && <Surface className="tn-update-release"><span className="tn-sr-only" aria-live="polite">更新任务状态:{labels[job.status]}</span><div className="tn-update-release-head"><div><span className="tn-eyebrow">最近任务</span><h2>v{job.version}</h2></div><Tag theme={job.status === "completed" ? "success" : job.status === "failed" ? "danger" : "primary"}>{labels[job.status]}</Tag></div>{active.has(job.status) && <><div className="tn-progress" role="progressbar" aria-label="系统更新进度" aria-valuemin={0} aria-valuemax={100} aria-valuenow={progress}><span style={{ width: `${progress}%` }} /></div><small>{job.status === "staged" && job.operation === "download" ? "更新包已下载并校验,可以立即应用。" : job.status === "staged" && job.operation === "apply" ? "立即更新请求已提交,服务即将重启。" : "更新服务正在后台运行,页面会自动刷新状态。"}</small>{restartSeconds !== null && (job.status === "applying" || disconnected.current) && <div className="tn-restart-countdown" role="status">服务正在重启,预计 {restartSeconds} 秒后恢复</div>}</>}{job.status === "failed" && job.errorMessage && <div className="tn-inline-error" role="alert">{job.errorMessage}</div>}{job.status === "completed" && <div className="tn-inline-info"><CheckCircle2 size={16} />新版本已通过健康检查,数据和附件保持不变。</div>}</Surface>}
|
{job && <Surface className="tn-update-release"><span className="tn-sr-only" aria-live="polite">更新任务状态:{labels[job.status]}{job.status === "downloading" ? `,已下载 ${progress}%` : ""}</span><div className="tn-update-release-head"><div><span className="tn-eyebrow">最近任务</span><h2>v{job.version}</h2></div><Tag theme={job.status === "completed" ? "success" : job.status === "failed" ? "danger" : "primary"}>{labels[job.status]}</Tag></div>{active.has(job.status) && <><div className="tn-progress" role="progressbar" aria-label="系统更新进度" aria-valuemin={0} aria-valuemax={100} aria-valuenow={progress}><span style={{ width: `${progress}%` }} /></div>{job.status === "downloading" ? <small>已下载 {bytesText(job.downloadedBytes)} / {bytesText(job.sizeBytes)}({progress}%) · {speedText(job.downloadSpeedBps)}</small> : <small>{job.status === "staged" && job.operation === "download" ? "更新包已下载并校验,可以立即应用。" : job.status === "staged" && job.operation === "apply" ? "立即更新请求已提交,服务即将重启。" : "更新服务正在后台运行,页面会自动刷新状态。"}</small>}{restartSeconds !== null && (job.status === "applying" || disconnected.current) && <div className="tn-restart-countdown" role="status">服务正在重启,预计 {restartSeconds} 秒后恢复</div>}</>}{job.status === "failed" && job.errorMessage && <div className="tn-inline-error" role="alert">{job.errorMessage}</div>}{job.status === "completed" && <div className="tn-inline-info"><CheckCircle2 size={16} />新版本已通过健康检查,数据和附件保持不变。</div>}</Surface>}
|
||||||
</>}
|
</>}
|
||||||
<Dialog visible={Boolean(confirmVersion)} header={confirmAction === "download" ? "下载更新包" : "确认立即更新"} confirmBtn={{ content: confirmAction === "download" ? "开始下载" : "立即更新", theme: "primary", loading: actionBusy, disabled: actionBusy }} cancelBtn="取消" onClose={() => { if (!actionBusy) setConfirmVersion(null); }} onConfirm={() => void submitAction()} onCancel={() => { if (!actionBusy) setConfirmVersion(null); }}>{confirmAction === "download" ? `将下载并校验 v${confirmVersion},完成后可选择立即更新。` : `将应用已下载的 v${confirmVersion}。服务会短暂重启,更新前会备份数据目录。`}</Dialog>
|
<Dialog visible={Boolean(confirmVersion)} header={confirmAction === "download" ? "下载更新包" : "确认立即更新"} confirmBtn={{ content: confirmAction === "download" ? "开始下载" : "立即更新", theme: "primary", loading: actionBusy, disabled: actionBusy }} cancelBtn="取消" onClose={() => { if (!actionBusy) setConfirmVersion(null); }} onConfirm={() => void submitAction()} onCancel={() => { if (!actionBusy) setConfirmVersion(null); }}>{confirmAction === "download" ? `将下载并校验 v${confirmVersion},完成后可选择立即更新。` : `将应用已下载的 v${confirmVersion}。服务会短暂重启,更新前会备份数据目录。`}</Dialog>
|
||||||
</Page>;
|
</Page>;
|
||||||
|
|||||||
@@ -134,7 +134,18 @@ input:focus-visible, textarea:focus-visible, select:focus-visible {
|
|||||||
.tn-user-dropdown-identity { display: grid; gap: 3px; margin: 2px 4px 6px; padding: 8px 9px 10px; border-bottom: 1px solid var(--tn-border-subtle); }
|
.tn-user-dropdown-identity { display: grid; gap: 3px; margin: 2px 4px 6px; padding: 8px 9px 10px; border-bottom: 1px solid var(--tn-border-subtle); }
|
||||||
.tn-user-dropdown-identity strong { color: var(--tn-text); font-size: 13px; }
|
.tn-user-dropdown-identity strong { color: var(--tn-text); font-size: 13px; }
|
||||||
.tn-user-dropdown-identity span { overflow: hidden; color: var(--tn-text-secondary); font-size: 12px; text-overflow: ellipsis; white-space: nowrap; }
|
.tn-user-dropdown-identity span { overflow: hidden; color: var(--tn-text-secondary); font-size: 12px; text-overflow: ellipsis; white-space: nowrap; }
|
||||||
.tn-menu-logo { display: flex; width: 100%; height: 64px; align-items: center; justify-content: center; color: var(--tn-navy-900); }
|
.tn-menu-logo {
|
||||||
|
/* TDesign adds a left margin to every direct logo child. The logo owns
|
||||||
|
its full-width centering, so that default inset makes the wordmark look
|
||||||
|
visibly shifted to the right in both expanded and collapsed menus. */
|
||||||
|
display: flex;
|
||||||
|
width: 100%;
|
||||||
|
height: 64px;
|
||||||
|
margin-left: 0 !important;
|
||||||
|
align-items: center;
|
||||||
|
justify-content: center;
|
||||||
|
color: var(--tn-navy-900);
|
||||||
|
}
|
||||||
.tn-logo-full { font-size: 18px; font-weight: 750; letter-spacing: .01em; }
|
.tn-logo-full { font-size: 18px; font-weight: 750; letter-spacing: .01em; }
|
||||||
.tn-logo-short { color: var(--tn-blue-700); font-size: 16px; font-weight: 800; letter-spacing: .04em; }
|
.tn-logo-short { color: var(--tn-blue-700); font-size: 16px; font-weight: 800; letter-spacing: .04em; }
|
||||||
.tn-menu-icon { flex: 0 0 20px; width: 20px; height: 20px; margin-right: 10px; }
|
.tn-menu-icon { flex: 0 0 20px; width: 20px; height: 20px; margin-right: 10px; }
|
||||||
|
|||||||
+1
-1
@@ -771,7 +771,7 @@ function Update({ notify }: { notify: (message: string, kind?: Notice["kind"]) =
|
|||||||
const canApply = Boolean(info?.strategy === "systemd" && latest?.isNewer && latest.compatible && latest.integrityReady && !hasActiveJob && (!job || job.status === "failed" || job.version !== latest.version));
|
const canApply = Boolean(info?.strategy === "systemd" && latest?.isNewer && latest.compatible && latest.integrityReady && !hasActiveJob && (!job || job.status === "failed" || job.version !== latest.version));
|
||||||
|
|
||||||
return <div className="page update-page">
|
return <div className="page update-page">
|
||||||
<div className="page-head"><div><div className="eyebrow">系统</div><h1>系统更新</h1></div><div className="head-actions"><Button onClick={() => void load()} disabled={loading || checking}><RotateCcw size={15} />刷新</Button><Button kind="primary" onClick={() => void check()} disabled={loading || checking || hasActiveJob}><RefreshCw size={15} className={checking ? "spin" : undefined} />检查更新</Button></div></div>
|
<div className="page-head"><div><div className="eyebrow">系统</div><h1>系统更新</h1></div><div className="head-actions"><Button onClick={() => void load()} disabled={loading || checking}><RotateCcw size={15} />刷新</Button><Button kind="primary" onClick={() => void check()} disabled={loading || checking}><RefreshCw size={15} className={checking ? "spin" : undefined} />检查更新</Button></div></div>
|
||||||
{error && <div className="error banner" role="alert"><AlertCircle size={16} />{error}<button className="text-button" onClick={() => void load()}>重试</button></div>}
|
{error && <div className="error banner" role="alert"><AlertCircle size={16} />{error}<button className="text-button" onClick={() => void load()}>重试</button></div>}
|
||||||
{loading ? <div className="update-loading"><Loader2 className="spin" size={22} />正在读取版本信息</div> : info && <>
|
{loading ? <div className="update-loading"><Loader2 className="spin" size={22} />正在读取版本信息</div> : info && <>
|
||||||
<div className="update-overview">
|
<div className="update-overview">
|
||||||
|
|||||||
Reference in New Issue
Block a user