Compare commits

...
3 Commits
Author SHA1 Message Date
Qiufeng 0690fe298c fix: initialize optional origin port
TallyNote release / linux-x64 (push) Successful in 6m49s
2026-09-03 08:22:46 +08:00
Qiufeng 6a0d9e34dd fix: make admin wrapper fixture portable in CI
TallyNote release / linux-x64 (push) Failing after 3m6s
2026-09-03 08:10:52 +08:00
Qiufeng 77598ecc81 fix: make installer gate portable in root CI
TallyNote release / linux-x64 (push) Failing after 3m5s
2026-09-03 08:02:48 +08:00
3 changed files with 19 additions and 3 deletions
+4 -1
View File
@@ -1012,7 +1012,10 @@ validate_listen_port() {
}
validate_public_origin() {
local value=$1 authority host path_part origin_port suffix
# Keep the optional origin port defined under `set -u`. Origins without an
# explicit port (for example https://example.test) are valid and should
# proceed to the default-port handling below.
local value=$1 authority host path_part origin_port='' suffix
case "$value" in
http://*|https://*) ;;
*) die '公开访问地址必须是 http:// 或 https:// 地址' ;;
+1 -1
View File
@@ -1,6 +1,6 @@
{
"name": "tallynote",
"version": "1.1.15",
"version": "1.1.18",
"private": true,
"type": "module",
"packageManager": "pnpm@9.0.6",
+14 -1
View File
@@ -88,6 +88,12 @@ bash -c '
chmod 700 "$mode_dir"
[[ "$(stat_mode_bits "$mode_dir")" == 448 ]]
mkdir -p "$owner_parent"
# CI runs this shell suite as root. Make the parent genuinely non-root in
# that environment so the assertion exercises the ownership guard instead
# of accidentally passing because root-owned parents are allowed.
if [[ "${EUID:-$(id -u)}" == 0 ]]; then
chown 65534:65534 "$owner_parent"
fi
if (assert_path_chain "$owner_parent/child") >/dev/null 2>&1; then
echo "expected non-root path parent to fail" >&2
exit 1
@@ -247,7 +253,11 @@ ln -s "$wrapper_prefix/releases/1.0.0" "$wrapper_prefix/current"
printf '%s\n' '#!/usr/bin/env bash' 'pwd -P > "$TALLYNOTE_WRAPPER_LOG"' 'printf "%s\n" "$@" >> "$TALLYNOTE_WRAPPER_LOG"' > "$wrapper_prefix/releases/1.0.0/runtime/bin/node"
chmod 755 "$wrapper_prefix/releases/1.0.0/runtime/bin/node"
printf '%s\n' cli > "$wrapper_prefix/releases/1.0.0/dist/server/cli/admin-init.js"
TALLYNOTE_INSTALL_PREFIX="$wrapper_prefix" TALLYNOTE_CONFIG_DIR="$tmp/no-config" TALLYNOTE_WRAPPER_LOG="$tmp/wrapper.log" \
# This fixture verifies release-relative execution and argument forwarding.
# Force the wrapper's non-root branch so the root CI runner does not need a
# real `tallynote` service account or a privileged runuser hand-off; that
# privilege boundary is validated by the production checks themselves.
env EUID=1000 TALLYNOTE_INSTALL_PREFIX="$wrapper_prefix" TALLYNOTE_CONFIG_DIR="$tmp/no-config" TALLYNOTE_WRAPPER_LOG="$tmp/wrapper.log" \
bash "$root/bin/tallynote-admin-init" --generate
wrapper_expected_root=$(cd "$wrapper_prefix/releases/1.0.0" && pwd -P)
grep -Fxq "$wrapper_expected_root" "$tmp/wrapper.log"
@@ -414,6 +424,9 @@ bash -c '
stat_uid() { printf "0"; }
stat_mode_bits() { printf "384"; }
validate_public_origin "http://[2001:db8::10]:3000"
# A standard HTTPS origin may omit its default port; this must remain valid
# under the installer strict unset-variable mode.
validate_public_origin "https://example.test"
' _ "$installer_lib"
printf '%s\n' \
'TALLYNOTE_HOST=0.0.0.0' \