Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
32a73c5b50 | ||
|
|
45de0ef759 | ||
|
|
65b5d95937 | ||
|
|
89a8edad88 | ||
|
|
283c1d77b4 | ||
|
|
f060f917a0 | ||
|
|
704740182a | ||
|
|
a61860fcb3 | ||
|
|
340d9b5245 | ||
|
|
5d02fa5769 | ||
|
|
526b2df8ea | ||
|
|
4f9629b089 | ||
|
|
36c2ed1361 | ||
|
|
755b82d2e5 | ||
|
|
0bdc812935 | ||
|
|
2de08f1358 | ||
|
|
91621df6c4 | ||
|
|
0690fe298c | ||
|
|
6a0d9e34dd |
@@ -17,6 +17,10 @@ jobs:
|
||||
steps:
|
||||
- name: Checkout tag
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
# Release notes are derived from the previous version tag. A shallow
|
||||
# checkout would leave only the synthetic release commit available.
|
||||
fetch-depth: 0
|
||||
- name: Set up Node.js
|
||||
uses: actions/setup-node@v4
|
||||
with:
|
||||
@@ -29,7 +33,10 @@ jobs:
|
||||
test "$(node -p 'require("./package.json").version')" = "${GITHUB_REF_NAME#v}"
|
||||
pnpm install --frozen-lockfile
|
||||
pnpm check
|
||||
pnpm test
|
||||
# better-sqlite3 is a native addon; a single Vitest worker avoids a
|
||||
# Node cleanup race observed on the hosted runner while preserving
|
||||
# the complete test suite.
|
||||
pnpm test -- --pool=forks --poolOptions.forks.singleFork=true --maxWorkers=1 --minWorkers=1
|
||||
pnpm test:installer
|
||||
- name: Build Linux release
|
||||
run: pnpm release:build "${GITHUB_REF_NAME#v}" ./release
|
||||
|
||||
@@ -140,7 +140,7 @@ curl --proto '=https' --tlsv1.2 -fsSL https://git.awaioi.com/awaioi/TallyNote/ra
|
||||
|
||||
卸载器会逐项输出停止、禁用和删除进度;每次 systemd/dbus 调用默认最多等待 30 秒,避免终端无限无响应。可通过 `TALLYNOTE_UNINSTALL_SYSTEMCTL_TIMEOUT_SECONDS` 调整超时时间。
|
||||
|
||||
公网反代必须使用 HTTPS,并在环境文件中设置真实的 `TALLYNOTE_PUBLIC_ORIGIN=https://...`、`TALLYNOTE_COOKIE_SECURE=true` 和明确的 `TALLYNOTE_TRUST_PROXY` 跳数(不要使用生产值 `true`)。
|
||||
公网反代推荐使用 HTTPS,并在环境文件中设置真实的 `TALLYNOTE_PUBLIC_ORIGIN=https://...`、`TALLYNOTE_COOKIE_SECURE=true` 和明确的 `TALLYNOTE_TRUST_PROXY` 跳数(不要使用生产值 `true`)。反代只需把域名转发到 TallyNote 端口并保留 `Host`、`X-Forwarded-Proto`;应用不会因为代理缺少或改写浏览器 `Origin` 而拦截登录。已认证写请求仍使用会话 Cookie 与 CSRF 令牌保护。
|
||||
|
||||
### 构建发布包
|
||||
|
||||
|
||||
+4
-2
@@ -12,6 +12,8 @@ TallyNote 的发布包必须在目标 Linux 架构上构建。`better-sqlite3`
|
||||
2. 由 `scripts/publish-gitea-release.sh` 计算所有归档的 `SHA256SUMS`。
|
||||
3. 如果提供 Ed25519 私钥则生成 `SHA256SUMS.sig`,通过 Gitea Releases API 创建/复用对应 Release,并幂等上传归档、清单和可选签名。
|
||||
|
||||
发布脚本会根据当前 tag 与上一个版本 tag 之间的真实 Git 提交自动生成 Release 正文,按“新增功能、问题修复、优化与重构、文档与测试”分类,并以 Markdown 写入 Gitea。Gitea 页面会渲染这些标题和列表;更新中心读取同一份正文后再进行安全的 Markdown 子集渲染,不会显示 Markdown 源代码。旧版本曾使用单行占位正文 `TallyNote <版本>`,新版本发布时不会再使用该占位内容。
|
||||
|
||||
在仓库的 Actions secrets 配置:
|
||||
|
||||
- `GITEA_TOKEN`:仅授予当前仓库 Release 写权限的 token。
|
||||
@@ -28,7 +30,7 @@ GITEA_TOKEN=... \
|
||||
./scripts/publish-gitea-release.sh v1.1.2 ./release
|
||||
```
|
||||
|
||||
发布资产名称必须包含当前平台,例如 `tallynote-1.1.2-linux-x64-glibc.tar.gz`。同一个 Release 只保留一个 `SHA256SUMS`;有签名时再保留一个 `SHA256SUMS.sig`,签名覆盖清单完整原文。
|
||||
发布资产名称必须包含当前平台,例如 `tallynote-1.1.2-linux-x64-glibc.tar.gz`。构建脚本会同时生成完整安装包和轻量更新包:`tallynote-1.1.2-linux-x64-glibc.tar.gz` 用于首次安装,`tallynote-1.1.2-linux-x64-glibc.update-<锁文件 SHA256>.tar.gz` 仅用于复用现有运行时的后台更新。同一个 Release 只保留一个 `SHA256SUMS`;有签名时再保留一个 `SHA256SUMS.sig`,签名覆盖清单完整原文。
|
||||
|
||||
## curl 安装
|
||||
|
||||
@@ -104,7 +106,7 @@ sudo /usr/local/sbin/tallynote-uninstall
|
||||
|
||||
将环境文件中的 `TALLYNOTE_UPDATE_STRATEGY=systemd`、`TALLYNOTE_UPDATE_METADATA_URL` 和 `TALLYNOTE_UPDATE_ALLOWED_HOSTS` 配好后,后台“系统更新”会读取 Gitea 的 `/api/v1/repos/<owner>/<repo>/releases/latest`。检查结果只显示当前平台匹配且通过 SHA-256 校验的资产;如果配置了 `TALLYNOTE_UPDATE_PUBLIC_KEY_FILE` 并启用签名要求,再额外验证 Ed25519 签名。
|
||||
|
||||
后台更新分为两个明确阶段。管理员先在“系统更新”读取最新 Release 的版本号、发布时间和更新说明,点击“下载更新包”;root 更新器会在主服务继续运行时下载、校验 SHA-256、解包并暂存。页面显示“下载完成,等待应用”后,管理员再点击“立即更新”。应用阶段才会短暂停止服务、备份数据、切换 release、启动并执行健康检查;页面显示重启倒计时并自动重试连接。浏览器只提交版本号、任务 ID 和确认标志,不能提交 URL 或文件路径。
|
||||
后台更新分为两个明确阶段。管理员先在“系统更新”读取最新 Release 的版本号、发布时间和更新说明,点击“下载更新包”;当前安装如果存在匹配的锁文件指纹,更新器会自动选择轻量 `update-<锁文件 SHA256>` 资产,仅下载 `dist`、迁移和版本元数据,并复用当前版本的 Node 与生产依赖;如果运行时指纹不匹配或轻量包不可用,则自动选择完整安装包。root 更新器会在主服务继续运行时下载、校验 SHA-256、解包并暂存。页面显示“下载完成,等待应用”后,管理员再点击“立即更新”。应用阶段才会短暂停止服务、备份数据、切换 release、启动并执行健康检查;页面显示重启倒计时并自动重试连接。浏览器只提交版本号、任务 ID 和确认标志,不能提交 URL 或文件路径。
|
||||
|
||||
Web 进程把受保护的任务文件交给 root 的 `tallynote-update.path`/`tallynote-update.service`,root runner 会重新读取配置源并验证 metadata、清单和暂存目录,不信任队列文件中的 URL 或摘要。切换失败或健康检查失败会恢复旧版本;手动回滚:
|
||||
|
||||
|
||||
+5
-2
@@ -1012,7 +1012,10 @@ validate_listen_port() {
|
||||
}
|
||||
|
||||
validate_public_origin() {
|
||||
local value=$1 authority host path_part origin_port suffix
|
||||
# Keep the optional origin port defined under `set -u`. Origins without an
|
||||
# explicit port (for example https://example.test) are valid and should
|
||||
# proceed to the default-port handling below.
|
||||
local value=$1 authority host path_part origin_port='' suffix
|
||||
case "$value" in
|
||||
http://*|https://*) ;;
|
||||
*) die '公开访问地址必须是 http:// 或 https:// 地址' ;;
|
||||
@@ -1074,7 +1077,7 @@ validate_existing_env() {
|
||||
mode_bits=$(stat_mode_bits "$file")
|
||||
(( (mode_bits & 18) == 0 )) || die '环境文件不能被组或其他用户写入'
|
||||
local key key_count
|
||||
for key in TALLYNOTE_INSTALL_PREFIX TALLYNOTE_DATA_DIR TALLYNOTE_HOST TALLYNOTE_PORT TALLYNOTE_PUBLIC_ORIGIN TALLYNOTE_ALLOW_INSECURE_HTTP TALLYNOTE_COOKIE_SECURE TALLYNOTE_UPDATE_REQUIRE_SIGNATURE TALLYNOTE_UPDATE_METADATA_URL TALLYNOTE_UPDATE_ALLOWED_HOSTS TALLYNOTE_UPDATE_PUBLIC_KEY_FILE; do
|
||||
for key in TALLYNOTE_INSTALL_PREFIX TALLYNOTE_DATA_DIR TALLYNOTE_HOST TALLYNOTE_PORT TALLYNOTE_PUBLIC_ORIGIN TALLYNOTE_ALLOWED_ORIGINS TALLYNOTE_ALLOW_INSECURE_HTTP TALLYNOTE_COOKIE_SECURE TALLYNOTE_UPDATE_REQUIRE_SIGNATURE TALLYNOTE_UPDATE_METADATA_URL TALLYNOTE_UPDATE_ALLOWED_HOSTS TALLYNOTE_UPDATE_PUBLIC_KEY_FILE; do
|
||||
key_count=$(env_key_count "$file" "$key")
|
||||
[[ "$key_count" =~ ^[0-9]+$ && "$key_count" -le 1 ]] || die "环境文件包含重复配置:$key"
|
||||
done
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
ALTER TABLE update_jobs ADD COLUMN downloaded_bytes INTEGER;
|
||||
ALTER TABLE update_jobs ADD COLUMN download_started_at INTEGER;
|
||||
ALTER TABLE update_jobs ADD COLUMN download_speed_bps INTEGER;
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "tallynote",
|
||||
"version": "1.1.16",
|
||||
"version": "1.1.31",
|
||||
"private": true,
|
||||
"type": "module",
|
||||
"packageManager": "pnpm@9.0.6",
|
||||
|
||||
@@ -27,7 +27,11 @@ pnpm build
|
||||
stage=$(mktemp -d)
|
||||
trap 'rm -rf "$stage"' EXIT
|
||||
mkdir -p "$stage/dist" "$stage/migrations" "$stage/bin" "$stage/scripts" "$stage/systemd" "$stage/runtime/bin"
|
||||
cp -a dist/. "$stage/dist/"
|
||||
# Copy only the production build outputs. In particular, do not carry a
|
||||
# stale dist/web-next directory from a previous local preview build.
|
||||
cp -a dist/server "$stage/dist/"
|
||||
cp -a dist/shared "$stage/dist/"
|
||||
cp -a dist/web "$stage/dist/"
|
||||
cp -a migrations/. "$stage/migrations/"
|
||||
cp package.json pnpm-lock.yaml "$stage/"
|
||||
cp -a bin/. "$stage/bin/"
|
||||
@@ -46,6 +50,26 @@ find "$stage" -type l -delete
|
||||
mkdir -p "$OUT_DIR"
|
||||
archive="$OUT_DIR/tallynote-${VERSION}-linux-${ARCH}-${LIBC}.tar.gz"
|
||||
tar -C "$stage" -czf "$archive" --owner=0 --group=0 --numeric-owner .
|
||||
|
||||
# The application-only asset is used by the online updater. It deliberately
|
||||
# excludes the stable runtime (Node and production dependencies), systemd
|
||||
# helpers and installer files; the updater overlays it on the currently
|
||||
# installed, already-validated runtime before atomically switching releases.
|
||||
app_stage=$(mktemp -d)
|
||||
trap 'rm -rf "$stage" "$app_stage"' EXIT
|
||||
mkdir -p "$app_stage/dist" "$app_stage/migrations" "$app_stage/bin" "$app_stage/scripts" "$app_stage/systemd"
|
||||
cp -a "$stage/dist/server" "$app_stage/dist/"
|
||||
cp -a "$stage/dist/shared" "$app_stage/dist/"
|
||||
cp -a "$stage/dist/web" "$app_stage/dist/"
|
||||
cp -a "$stage/migrations/." "$app_stage/migrations/"
|
||||
cp -a "$stage/bin/." "$app_stage/bin/"
|
||||
cp -a "$stage/scripts/." "$app_stage/scripts/"
|
||||
cp -a "$stage/systemd/." "$app_stage/systemd/"
|
||||
cp "$stage/package.json" "$app_stage/package.json"
|
||||
cp "$stage/uninstall.sh" "$app_stage/uninstall.sh"
|
||||
runtime_hash=$(sha256sum pnpm-lock.yaml | awk '{print $1}')
|
||||
app_archive="$OUT_DIR/tallynote-${VERSION}-linux-${ARCH}-${LIBC}.update-${runtime_hash}.tar.gz"
|
||||
tar -C "$app_stage" -czf "$app_archive" --owner=0 --group=0 --numeric-owner .
|
||||
# Keep the sidecar useful when a caller builds more than one architecture into
|
||||
# the same directory. The publishing script recomputes this list immediately
|
||||
# before signing, so stale or hand-edited entries can never reach a Release.
|
||||
|
||||
@@ -24,6 +24,7 @@ DRY_RUN=0
|
||||
AUTH_CONFIG=''
|
||||
SUMS_TMP=''
|
||||
SIG_TMP=''
|
||||
RELEASE_NOTES_TMP=''
|
||||
SIGNATURE_GENERATED=0
|
||||
|
||||
usage() {
|
||||
@@ -43,6 +44,81 @@ EOF
|
||||
die() { printf 'release publisher: %s\n' "$*" >&2; exit 1; }
|
||||
log() { printf 'release publisher: %s\n' "$*"; }
|
||||
|
||||
generate_release_notes() {
|
||||
local current=${TAG#v} previous='' subject kind line count=0
|
||||
local -a commits
|
||||
commits=()
|
||||
|
||||
# A workflow checks out the tag with history. Prefer an explicitly supplied
|
||||
# notes file for mirrors, then derive notes from the immutable tag range.
|
||||
if [[ -n "${TALLYNOTE_RELEASE_NOTES_FILE:-}" && -f "$TALLYNOTE_RELEASE_NOTES_FILE" ]]; then
|
||||
# Read at most the API's bounded notes size without a pipe that can turn a
|
||||
# deliberately truncated input into a SIGPIPE failure under pipefail.
|
||||
LC_ALL=C awk 'BEGIN { remaining = 65536 } { if (remaining <= 0) exit; line=$0; gsub(/[[:cntrl:]]/, "", line); bytes=length(line)+1; if (bytes > remaining) { print substr(line, 1, remaining); exit } print line; remaining-=bytes }' "$TALLYNOTE_RELEASE_NOTES_FILE"
|
||||
return
|
||||
fi
|
||||
|
||||
if command -v git >/dev/null 2>&1 && git rev-parse --is-inside-work-tree >/dev/null 2>&1; then
|
||||
while IFS= read -r line; do
|
||||
[[ -n "$line" ]] || continue
|
||||
[[ "$line" == "v${current}" ]] && continue
|
||||
previous="$line"
|
||||
break
|
||||
done < <(git tag --sort=-version:refname --list 'v*')
|
||||
if [[ -n "$previous" && "$previous" != "v${current}" ]]; then
|
||||
while IFS= read -r line; do
|
||||
[[ -n "$line" ]] && commits+=("$line")
|
||||
done < <(git log --format='%s' "${previous}..${TAG}")
|
||||
else
|
||||
while IFS= read -r line; do
|
||||
[[ -n "$line" ]] && commits+=("$line")
|
||||
done < <(git log -n 30 --format='%s' "$TAG")
|
||||
fi
|
||||
fi
|
||||
|
||||
printf '# TallyNote %s\n\n' "$current"
|
||||
if [[ -n "$previous" ]]; then
|
||||
printf '> 从 `%s` 到 `%s` 的变更\n\n' "$previous" "v${current}"
|
||||
else
|
||||
printf '> 本版本变更\n\n'
|
||||
fi
|
||||
|
||||
local -a features fixes improvements docs other
|
||||
features=(); fixes=(); improvements=(); docs=(); other=()
|
||||
for subject in "${commits[@]-}"; do
|
||||
# Do not expose merge noise or the synthetic release commit in user notes.
|
||||
[[ "$subject" != Merge\ * && "$subject" != release:* ]] || continue
|
||||
kind=${subject%%:*}
|
||||
if [[ "$subject" == *:* ]]; then subject=${subject#*: }; fi
|
||||
subject=${subject# }
|
||||
[[ -n "$subject" ]] || continue
|
||||
case "$kind" in
|
||||
feat|feature) features+=("$subject") ;;
|
||||
fix|bugfix) fixes+=("$subject") ;;
|
||||
refactor|perf|style|improvement) improvements+=("$subject") ;;
|
||||
docs|doc|test|tests) docs+=("$subject") ;;
|
||||
*) other+=("$subject") ;;
|
||||
esac
|
||||
done
|
||||
|
||||
print_group() {
|
||||
local title=$1; shift
|
||||
local item
|
||||
(($# > 0)) || return 0
|
||||
printf '## %s\n\n' "$title"
|
||||
for item in "$@"; do printf -- '- %s\n' "$item"; done
|
||||
printf '\n'
|
||||
}
|
||||
((${#features[@]})) && print_group '新增功能' "${features[@]}"
|
||||
((${#fixes[@]})) && print_group '问题修复' "${fixes[@]}"
|
||||
((${#improvements[@]})) && print_group '优化与重构' "${improvements[@]}"
|
||||
((${#docs[@]})) && print_group '文档与测试' "${docs[@]}"
|
||||
((${#other[@]})) && print_group '其他变更' "${other[@]}"
|
||||
if (( ${#features[@]} + ${#fixes[@]} + ${#improvements[@]} + ${#docs[@]} + ${#other[@]} == 0 )); then
|
||||
printf '本版本包含内部维护更新。\n'
|
||||
fi
|
||||
}
|
||||
|
||||
validate_semver() {
|
||||
local value=$1 prerelease part
|
||||
[[ "$value" =~ ^v?(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)\.(0|[1-9][0-9]*)(-[0-9A-Za-z-]+(\.[0-9A-Za-z-]+)*)?(\+[0-9A-Za-z-]+(\.[0-9A-Za-z-]+)*)?$ ]] || return 1
|
||||
@@ -128,7 +204,8 @@ fi
|
||||
[[ "$CURL_BIN" != *[[:space:]]* && "$CURL_BIN" != *[[:cntrl:]]* ]] || die 'curl executable path is invalid'
|
||||
command -v "$CURL_BIN" >/dev/null 2>&1 || die 'curl is required'
|
||||
|
||||
assets=()
|
||||
full_assets=()
|
||||
update_assets=()
|
||||
for file in "$ASSET_DIR"/*.tar.gz; do
|
||||
[[ -f "$file" && ! -L "$file" ]] || continue
|
||||
name=$(basename -- "$file")
|
||||
@@ -136,9 +213,16 @@ for file in "$ASSET_DIR"/*.tar.gz; do
|
||||
asset_version=${name#tallynote-}
|
||||
asset_version=${asset_version%%-linux-*}
|
||||
[[ "$asset_version" == "${TAG#v}" ]] || die "release asset version does not match tag: $name"
|
||||
assets+=("$file")
|
||||
if [[ "$name" =~ \.update-[a-f0-9]{64}\.tar\.gz$ ]]; then
|
||||
update_assets+=("$file")
|
||||
else
|
||||
full_assets+=("$file")
|
||||
fi
|
||||
done
|
||||
assets=("${full_assets[@]}")
|
||||
if ((${#update_assets[@]})); then assets+=("${update_assets[@]}"); fi
|
||||
(( ${#assets[@]} > 0 )) || die 'no .tar.gz release asset found'
|
||||
(( ${#full_assets[@]} > 0 )) || die 'no full release asset found'
|
||||
|
||||
SUMS_FILE="$ASSET_DIR/SHA256SUMS"
|
||||
SIG_FILE="$ASSET_DIR/SHA256SUMS.sig"
|
||||
@@ -161,6 +245,7 @@ cleanup() {
|
||||
if [[ -n "$AUTH_CONFIG" ]]; then rm -f -- "$AUTH_CONFIG"; fi
|
||||
if [[ -n "$SUMS_TMP" ]]; then rm -f -- "$SUMS_TMP"; fi
|
||||
if [[ -n "$SIG_TMP" ]]; then rm -f -- "$SIG_TMP"; fi
|
||||
if [[ -n "$RELEASE_NOTES_TMP" ]]; then rm -f -- "$RELEASE_NOTES_TMP"; fi
|
||||
}
|
||||
trap cleanup EXIT
|
||||
if [[ -n "$SIGNING_KEY_FILE" ]]; then
|
||||
@@ -196,6 +281,13 @@ command -v jq >/dev/null 2>&1 || die 'jq is required for Gitea API publishing'
|
||||
write_auth_config
|
||||
unset TOKEN
|
||||
|
||||
# Keep the release body deterministic and human-readable. Gitea renders this
|
||||
# Markdown in the Release page; the update API later exposes the same body as
|
||||
# text for the safe client-side Markdown renderer.
|
||||
RELEASE_NOTES_TMP=$(mktemp)
|
||||
generate_release_notes > "$RELEASE_NOTES_TMP"
|
||||
release_notes=$(<"$RELEASE_NOTES_TMP")
|
||||
|
||||
api_curl() {
|
||||
"$CURL_BIN" --proto '=https' --tlsv1.2 --fail --silent --show-error --connect-timeout 15 --max-time 120 \
|
||||
--config "$AUTH_CONFIG" "$@"
|
||||
@@ -213,8 +305,17 @@ release_json=$(mktemp)
|
||||
status=$(api_curl_status --max-time 30 -o "$release_json" -w '%{http_code}' "$API_ROOT/repos/$repo_path/releases/tags/$TAG") || die '无法读取 Gitea Release'
|
||||
if [[ "$status" == 200 ]]; then
|
||||
release_id=$(jq -r '.id // empty' "$release_json")
|
||||
existing_body=$(jq -r '.body // ""' "$release_json")
|
||||
# Older releases used a one-line placeholder. Upgrade that placeholder when
|
||||
# a tag is republished, while leaving deliberately authored release notes
|
||||
# untouched.
|
||||
if [[ "$existing_body" == "TallyNote $TAG" || -z "$existing_body" ]]; then
|
||||
patch_body=$(jq -cn --arg body "$release_notes" '{body:$body}')
|
||||
patch_status=$(api_curl_status -X PATCH -H 'Content-Type: application/json' -d "$patch_body" -o /dev/null -w '%{http_code}' "$API_ROOT/repos/$repo_path/releases/$release_id") || die '无法更新 Gitea Release 日志'
|
||||
[[ "$patch_status" == 2* ]] || die "无法更新 Gitea Release 日志(HTTP $patch_status)"
|
||||
fi
|
||||
elif [[ "$status" == 404 ]]; then
|
||||
body=$(jq -cn --arg tag "$TAG" --arg name "$TAG" --arg body "TallyNote $TAG" '{tag_name:$tag,name:$name,body:$body,draft:false,prerelease:false}')
|
||||
body=$(jq -cn --arg tag "$TAG" --arg name "$TAG" --arg body "$release_notes" '{tag_name:$tag,name:$name,body:$body,draft:false,prerelease:false}')
|
||||
create_status=$(api_curl_status -H 'Content-Type: application/json' -d "$body" -o "$release_json" -w '%{http_code}' "$API_ROOT/repos/$repo_path/releases") || die '无法创建 Gitea Release'
|
||||
if [[ "$create_status" == 2* ]]; then
|
||||
release_id=$(jq -r '.id // empty' "$release_json")
|
||||
|
||||
@@ -190,6 +190,15 @@ recover_stale_state() {
|
||||
[[ "$state_job" =~ ^[0-9a-f-]{36}$ ]] || die 'update state job id is invalid'
|
||||
[[ "$state_old" == "$PREFIX/releases/"* && -d "$state_old" && ! -L "$state_old" ]] || die 'update state target is invalid'
|
||||
current_target=$(readlink -f -- "$CURRENT_LINK" 2>/dev/null || true)
|
||||
if [[ "$state_phase" == download && "$current_target" == "$state_old" ]]; then
|
||||
# Downloading never changes the active release. If the runner was killed
|
||||
# after the CLI staged its payload but before it removed the recovery
|
||||
# marker, keep the request available for an idempotent retry. Treating
|
||||
# every stale download marker as a failed apply would discard a usable
|
||||
# staged payload and leave the browser showing a misleading failure.
|
||||
clear_update_state || true
|
||||
return 0
|
||||
fi
|
||||
if [[ "$state_phase" == finalizing && "$current_target" != "$state_old" ]]; then
|
||||
recovery_node="$CURRENT_LINK/runtime/bin/node"
|
||||
[[ -x "$recovery_node" ]] || recovery_node=$(command -v node || true)
|
||||
|
||||
@@ -195,6 +195,40 @@ grep -q -- '--finalize-job' "$runner_root/node.log"
|
||||
[[ ! -e "$runner_data/update-request.json" ]]
|
||||
[[ ! -e "$runner_prefix/.update-state" ]]
|
||||
|
||||
# A stale download marker must be recoverable without finalizing the staged
|
||||
# download as a failed apply. The next runner invocation should retry the
|
||||
# request and let the CLI preserve/refresh its staged workspace.
|
||||
download_runner_root="$tmp/download-runner"
|
||||
download_runner_prefix="$download_runner_root/prefix"
|
||||
download_runner_data="$download_runner_root/data"
|
||||
download_runner_tools="$download_runner_root/tools"
|
||||
mkdir -p "$download_runner_prefix/releases/1.0.0/runtime/bin" "$download_runner_prefix/releases/1.0.0/dist/server/cli" "$download_runner_data" "$download_runner_tools"
|
||||
ln -s "$download_runner_prefix/releases/1.0.0" "$download_runner_prefix/current"
|
||||
# The request has already been consumed; only the stale download marker is
|
||||
# left, which is the narrow recovery window covered by this fixture.
|
||||
download_runner_prefix_physical=$(cd "$download_runner_prefix" && pwd -P)
|
||||
download_runner_data_physical=$(cd "$download_runner_data" && pwd -P)
|
||||
printf '%s\n' 'job_id=00000000-0000-4000-8000-000000000002' "old_target=$download_runner_prefix_physical/releases/1.0.0" 'phase=download' > "$download_runner_prefix/.update-state"
|
||||
printf '%s\n' '#!/usr/bin/env bash' 'printf "%s\n" "$*" >> "$TALLYNOTE_DOWNLOAD_NODE_TRACE"' 'exit 0' > "$download_runner_prefix/releases/1.0.0/runtime/bin/node"
|
||||
printf '%s\n' cli > "$download_runner_prefix/releases/1.0.0/dist/server/cli/update.js"
|
||||
printf '%s\n' '#!/usr/bin/env bash' 'case "${1:-}" in is-active) exit 0;; *) exit 0;; esac' > "$download_runner_tools/systemctl"
|
||||
printf '%s\n' '#!/usr/bin/env bash' 'if [[ "${1:-}" == "-f" ]]; then shift; [[ "${1:-}" == "--" ]] && shift; /bin/realpath "$1"; else /usr/bin/readlink "$@"; fi' > "$download_runner_tools/readlink"
|
||||
cat >"$download_runner_tools/stat" <<'EOF'
|
||||
#!/usr/bin/env bash
|
||||
case "$*" in
|
||||
*"-c %u"*|*"-f %u"*) printf '0\n' ;;
|
||||
*"-c %a"*|*"-f %Lp"*) printf '600\n' ;;
|
||||
*) /usr/bin/stat "$@" ;;
|
||||
esac
|
||||
EOF
|
||||
chmod 755 "$download_runner_prefix/releases/1.0.0/runtime/bin/node" "$download_runner_tools/systemctl" "$download_runner_tools/readlink" "$download_runner_tools/stat"
|
||||
download_runner_script="$download_runner_root/runner.sh"
|
||||
sed "s#PATH=/usr/sbin:/usr/bin:/sbin:/bin#PATH=$download_runner_tools:/usr/sbin:/usr/bin:/sbin:/bin#" "$root/scripts/tallynote-update-runner.sh" > "$download_runner_script"
|
||||
chmod 755 "$download_runner_script"
|
||||
env EUID=0 TALLYNOTE_INSTALL_PREFIX="$download_runner_prefix_physical" TALLYNOTE_DATA_DIR="$download_runner_data_physical" TALLYNOTE_DOWNLOAD_NODE_TRACE="$download_runner_root/node.log" bash "$download_runner_script"
|
||||
[[ ! -e "$download_runner_root/node.log" ]]
|
||||
[[ ! -e "$download_runner_prefix/.update-state" ]]
|
||||
|
||||
# A RETURN trap installed by install_release must be cleared while its local
|
||||
# temporary variables still exist; otherwise set -u fails at the end of main.
|
||||
release_fixture="$tmp/release-fixture"
|
||||
@@ -253,7 +287,11 @@ ln -s "$wrapper_prefix/releases/1.0.0" "$wrapper_prefix/current"
|
||||
printf '%s\n' '#!/usr/bin/env bash' 'pwd -P > "$TALLYNOTE_WRAPPER_LOG"' 'printf "%s\n" "$@" >> "$TALLYNOTE_WRAPPER_LOG"' > "$wrapper_prefix/releases/1.0.0/runtime/bin/node"
|
||||
chmod 755 "$wrapper_prefix/releases/1.0.0/runtime/bin/node"
|
||||
printf '%s\n' cli > "$wrapper_prefix/releases/1.0.0/dist/server/cli/admin-init.js"
|
||||
TALLYNOTE_INSTALL_PREFIX="$wrapper_prefix" TALLYNOTE_CONFIG_DIR="$tmp/no-config" TALLYNOTE_WRAPPER_LOG="$tmp/wrapper.log" \
|
||||
# This fixture verifies release-relative execution and argument forwarding.
|
||||
# Force the wrapper's non-root branch so the root CI runner does not need a
|
||||
# real `tallynote` service account or a privileged runuser hand-off; that
|
||||
# privilege boundary is validated by the production checks themselves.
|
||||
env EUID=1000 TALLYNOTE_INSTALL_PREFIX="$wrapper_prefix" TALLYNOTE_CONFIG_DIR="$tmp/no-config" TALLYNOTE_WRAPPER_LOG="$tmp/wrapper.log" \
|
||||
bash "$root/bin/tallynote-admin-init" --generate
|
||||
wrapper_expected_root=$(cd "$wrapper_prefix/releases/1.0.0" && pwd -P)
|
||||
grep -Fxq "$wrapper_expected_root" "$tmp/wrapper.log"
|
||||
@@ -420,6 +458,9 @@ bash -c '
|
||||
stat_uid() { printf "0"; }
|
||||
stat_mode_bits() { printf "384"; }
|
||||
validate_public_origin "http://[2001:db8::10]:3000"
|
||||
# A standard HTTPS origin may omit its default port; this must remain valid
|
||||
# under the installer strict unset-variable mode.
|
||||
validate_public_origin "https://example.test"
|
||||
' _ "$installer_lib"
|
||||
printf '%s\n' \
|
||||
'TALLYNOTE_HOST=0.0.0.0' \
|
||||
|
||||
+23
-17
@@ -119,7 +119,7 @@ function enforceUpdateCooldown(
|
||||
adminId: string,
|
||||
operation: "check" | "download" | "apply",
|
||||
reply: FastifyReply,
|
||||
): void {
|
||||
): number {
|
||||
const state = updateRateState(database, adminId);
|
||||
const now = Date.now();
|
||||
const previous = operation === "check" ? state.checkedAt : operation === "download" ? state.downloadedAt : state.appliedAt;
|
||||
@@ -134,6 +134,7 @@ function enforceUpdateCooldown(
|
||||
if (operation === "check") state.checkedAt = now;
|
||||
else if (operation === "download") state.downloadedAt = now;
|
||||
else state.appliedAt = now;
|
||||
return now;
|
||||
}
|
||||
|
||||
function adminSelect(alias = ""): string {
|
||||
@@ -647,19 +648,6 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
||||
return payload;
|
||||
});
|
||||
|
||||
app.addHook("onRequest", async (request) => {
|
||||
if (!unsafeMethods.has(request.method) || !request.url.startsWith("/api/")) return;
|
||||
const origin = request.headers.origin;
|
||||
const allowed = new Set([config.publicOrigin]);
|
||||
if (!config.isProduction) {
|
||||
allowed.add("http://127.0.0.1:5173");
|
||||
allowed.add("http://localhost:5173");
|
||||
}
|
||||
if (typeof origin !== "string" || !allowed.has(origin)) {
|
||||
throw new AppError(403, "ORIGIN_FORBIDDEN", "请求来源不受信任");
|
||||
}
|
||||
});
|
||||
|
||||
app.setErrorHandler((error, request, reply) => {
|
||||
if (error instanceof AppError) return reply.code(error.statusCode).send(errorPayload(request, error));
|
||||
if (error instanceof ZodError) {
|
||||
@@ -942,13 +930,22 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
||||
reply.header("Cache-Control", "no-store");
|
||||
reconcileOrphanedUpdateJobs(database.sqlite, config);
|
||||
const cached = publicCheckFromCache(database.sqlite, config);
|
||||
// Status is a live control surface, not an update history endpoint.
|
||||
// Terminal failures/cancellations from a previous attempt must not be
|
||||
// replayed as if the operator had just started an update. They remain in
|
||||
// the database/audit log, while this endpoint exposes only an actionable
|
||||
// task (or the latest successful completion for confirmation).
|
||||
const row = database.sqlite.prepare(`
|
||||
SELECT id, operation, status, version, platform, asset_name AS assetName,
|
||||
size_bytes AS sizeBytes, error_message AS errorMessage,
|
||||
created_at AS createdAt, updated_at AS updatedAt, completed_at AS completedAt,
|
||||
downloaded_bytes AS downloadedBytes, download_started_at AS downloadStartedAt,
|
||||
download_speed_bps AS downloadSpeedBps,
|
||||
requested_at AS applyQueuedAt
|
||||
FROM update_jobs WHERE admin_id=? ORDER BY created_at DESC LIMIT 1
|
||||
`).get(request.auth!.admin.id) as Record<string, unknown> | undefined;
|
||||
FROM update_jobs
|
||||
WHERE admin_id=? AND status IN (${[...ACTIVE_UPDATE_STATUSES, "completed"].map(() => "?").join(",")})
|
||||
ORDER BY created_at DESC LIMIT 1
|
||||
`).get(request.auth!.admin.id, ...ACTIVE_UPDATE_STATUSES, "completed") as Record<string, unknown> | undefined;
|
||||
return {
|
||||
...cached,
|
||||
strategy: config.updateStrategy,
|
||||
@@ -957,12 +954,15 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
||||
});
|
||||
|
||||
app.post("/api/update/check", { preHandler: guard(database, config), bodyLimit: 32 * 1024 }, async (request, reply) => {
|
||||
const rateState = updateRateState(database.sqlite, request.auth!.admin.id);
|
||||
const previousCheckedAt = rateState.checkedAt;
|
||||
let reservedCheckedAt: number | null = null;
|
||||
try {
|
||||
reconcileOrphanedUpdateJobs(database.sqlite, config);
|
||||
// Disabled/dev installs do not contact a release endpoint, so repeated
|
||||
// checks are local status reads and should remain immediately usable.
|
||||
if (config.updateStrategy !== "disabled") {
|
||||
enforceUpdateCooldown(database.sqlite, config, request.auth!.admin.id, "check", reply);
|
||||
reservedCheckedAt = enforceUpdateCooldown(database.sqlite, config, request.auth!.admin.id, "check", reply);
|
||||
}
|
||||
const result = await checkForUpdate(database.sqlite, config);
|
||||
writeAudit(database.sqlite, {
|
||||
@@ -981,6 +981,10 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
||||
reply.header("Cache-Control", "no-store");
|
||||
return { ...result, strategy: config.updateStrategy };
|
||||
} catch (error) {
|
||||
// A failed upstream request is not a successful check. Release the
|
||||
// reservation only when this request still owns it, so a concurrent
|
||||
// successful check cannot have its cooldown overwritten.
|
||||
if (reservedCheckedAt !== null && rateState.checkedAt === reservedCheckedAt) rateState.checkedAt = previousCheckedAt;
|
||||
writeAudit(database.sqlite, {
|
||||
requestId: request.id,
|
||||
actorAdminId: request.auth!.admin.id,
|
||||
@@ -1185,6 +1189,8 @@ export async function buildApp(database: DatabaseContext, config: AppConfig) {
|
||||
SELECT id, operation, status, version, platform, asset_name AS assetName,
|
||||
size_bytes AS sizeBytes, error_message AS errorMessage,
|
||||
created_at AS createdAt, updated_at AS updatedAt, completed_at AS completedAt,
|
||||
downloaded_bytes AS downloadedBytes, download_started_at AS downloadStartedAt,
|
||||
download_speed_bps AS downloadSpeedBps,
|
||||
requested_at AS applyQueuedAt
|
||||
FROM update_jobs WHERE id=? AND admin_id=?
|
||||
`).get(id, request.auth!.admin.id) as Record<string, unknown> | undefined;
|
||||
|
||||
+40
-3
@@ -1,5 +1,5 @@
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { lstat, mkdir, mkdtemp, readFile, realpath, rm } from "node:fs/promises";
|
||||
import { cp, lstat, mkdir, mkdtemp, readFile, realpath, rm } from "node:fs/promises";
|
||||
import path from "node:path";
|
||||
import { pathToFileURL } from "node:url";
|
||||
import type Database from "better-sqlite3";
|
||||
@@ -10,6 +10,7 @@ import { writeAudit } from "../audit.js";
|
||||
import {
|
||||
atomicSwitchDirectory,
|
||||
atomicSwitchRelease,
|
||||
applicationUpdateRuntimeHash,
|
||||
compareSemver,
|
||||
createSafeArchive,
|
||||
detectPlatform,
|
||||
@@ -19,6 +20,7 @@ import {
|
||||
isNewerVersion,
|
||||
normalizeReleasePermissions,
|
||||
parseSemver,
|
||||
runtimeHashFromLockfile,
|
||||
selectReleaseAsset,
|
||||
sanitizeAssetName,
|
||||
validateHttpsUrl,
|
||||
@@ -212,9 +214,16 @@ async function resolveRelease(options: UpdateRunOptions, platform: ReturnType<ty
|
||||
if (options.metadataUrl) {
|
||||
const metadataUrl = validateHttpsUrl(options.metadataUrl, options);
|
||||
const release = await fetchReleaseMetadata(metadataUrl, options);
|
||||
let runtimeHash: string | undefined;
|
||||
try {
|
||||
runtimeHash = runtimeHashFromLockfile(await readFile(path.join(options.currentDir, "pnpm-lock.yaml")));
|
||||
} catch {
|
||||
// Fall back to the full archive when the current installation predates
|
||||
// runtime fingerprints or is missing deployment provenance.
|
||||
}
|
||||
let asset = options.assetUrl && !options.requireSignature
|
||||
? { name: sanitizeAssetName(options.assetName ?? path.basename(new URL(options.assetUrl).pathname)), url: validateHttpsUrl(options.assetUrl, { ...options, baseUrl: metadataUrl }).toString(), ...(options.expectedSha256 ? { sha256: options.expectedSha256 } : {}) }
|
||||
: selectReleaseAsset(release, platform);
|
||||
: selectReleaseAsset(release, platform, runtimeHash);
|
||||
if (!asset) throw new Error("没有匹配当前平台的更新文件");
|
||||
const integrity = await attachSidecarHash(release, asset, {
|
||||
allowedHosts: options.allowedHosts ?? [],
|
||||
@@ -291,12 +300,40 @@ export async function runUpdate(options: UpdateRunOptions): Promise<UpdateRunRes
|
||||
const archivePath = path.join(workspace, resolved.asset.name.endsWith(".gz") || resolved.asset.name.endsWith(".zip") ? resolved.asset.name : `${resolved.asset.name}.tar.gz`);
|
||||
try {
|
||||
updateJob(options.sqlite, jobId, { operation, status: "downloading", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, downloadPath: path.basename(archivePath), startedAt: Date.now() });
|
||||
const downloaded = await downloadReleaseAsset(resolved.asset.url, archivePath, options);
|
||||
const progressStartedAt = Date.now();
|
||||
let lastProgressWrite = 0;
|
||||
const downloaded = await downloadReleaseAsset(resolved.asset.url, archivePath, {
|
||||
...options,
|
||||
onProgress: (downloadedBytes, totalBytes) => {
|
||||
const now = Date.now();
|
||||
if (!options.sqlite || now - lastProgressWrite < 250) return;
|
||||
lastProgressWrite = now;
|
||||
const elapsed = Math.max(1, now - progressStartedAt);
|
||||
const speedBps = Math.round(downloadedBytes * 1000 / elapsed);
|
||||
options.sqlite.prepare("UPDATE update_jobs SET downloaded_bytes=?, size_bytes=COALESCE(?, size_bytes), download_started_at=?, download_speed_bps=?, updated_at=? WHERE id=? AND status='downloading'").run(downloadedBytes, totalBytes, progressStartedAt, speedBps, now, jobId);
|
||||
},
|
||||
});
|
||||
if (options.sqlite) {
|
||||
const finishedAt = Date.now();
|
||||
const elapsed = Math.max(1, finishedAt - progressStartedAt);
|
||||
options.sqlite.prepare("UPDATE update_jobs SET downloaded_bytes=?, size_bytes=?, download_started_at=?, download_speed_bps=?, updated_at=? WHERE id=? AND status='downloading'").run(downloaded.size, downloaded.size, progressStartedAt, Math.round(downloaded.size * 1000 / elapsed), finishedAt, jobId);
|
||||
}
|
||||
if (expectedSha256 && downloaded.sha256 !== expectedSha256) throw new Error("更新文件 SHA-256 校验失败");
|
||||
updateJob(options.sqlite, jobId, { operation, status: "verifying", version: resolved.version, platform: platform.target, releaseUrl: resolved.releaseUrl, assetName: resolved.asset.name, assetUrl: resolved.asset.url, expectedSha256, actualSha256: downloaded.sha256, sizeBytes: downloaded.size, downloadPath: path.basename(archivePath) });
|
||||
if (!archivePath.endsWith(".tar.gz") && !archivePath.endsWith(".tgz") && !archivePath.endsWith(".tar") && !archivePath.endsWith(".zip")) throw new Error("更新文件格式仅支持 tar.gz、tar 或 zip");
|
||||
const stagedDir = path.join(workspace, "payload");
|
||||
await extractSafeArchive(archivePath, stagedDir, options.maxBytes === undefined ? {} : { maxBytes: options.maxBytes });
|
||||
if (applicationUpdateRuntimeHash(resolved.asset.name)) {
|
||||
const currentRelease = await realpath(options.currentDir).catch(() => { throw new Error("当前安装目录无效"); });
|
||||
const currentInfo = await lstat(currentRelease).catch(() => null);
|
||||
if (!currentInfo?.isDirectory() || currentInfo.isSymbolicLink()) throw new Error("当前安装目录无效");
|
||||
for (const entry of ["node_modules", "runtime", "pnpm-lock.yaml"] as const) {
|
||||
const source = path.join(currentRelease, entry);
|
||||
const sourceInfo = await lstat(source).catch(() => null);
|
||||
if (!sourceInfo || sourceInfo.isSymbolicLink()) throw new Error("当前运行时不完整,无法应用轻量更新");
|
||||
await cp(source, path.join(stagedDir, entry), { recursive: sourceInfo.isDirectory(), errorOnExist: true, force: false });
|
||||
}
|
||||
}
|
||||
await normalizeReleasePermissions(stagedDir);
|
||||
const payloadInfo = await lstat(path.join(stagedDir, "dist")).catch(() => null);
|
||||
if (!payloadInfo?.isDirectory() || payloadInfo.isSymbolicLink()) throw new Error("发布包缺少 dist 目录");
|
||||
|
||||
@@ -148,6 +148,9 @@ export const updateJobs = sqliteTable("update_jobs", {
|
||||
downloadPath: text("download_path"),
|
||||
backupPath: text("backup_path"),
|
||||
sizeBytes: integer("size_bytes"),
|
||||
downloadedBytes: integer("downloaded_bytes"),
|
||||
downloadStartedAt: integer("download_started_at"),
|
||||
downloadSpeedBps: integer("download_speed_bps"),
|
||||
errorMessage: text("error_message"),
|
||||
createdAt: integer("created_at").notNull(),
|
||||
requestedAt: integer("requested_at"),
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
import { lstatSync, realpathSync, unlinkSync } from "node:fs";
|
||||
import { lstatSync, realpathSync, readFileSync, unlinkSync } from "node:fs";
|
||||
import { chmod, mkdir, rename, writeFile } from "node:fs/promises";
|
||||
import path from "node:path";
|
||||
import { createPublicKey, randomUUID, verify as verifySignature } from "node:crypto";
|
||||
@@ -13,6 +13,7 @@ import {
|
||||
fetchReleaseText,
|
||||
isNewerVersion,
|
||||
parseSemver,
|
||||
runtimeHashFromLockfile,
|
||||
sanitizeAssetName,
|
||||
selectReleaseAsset,
|
||||
validateHttpsUrl,
|
||||
@@ -204,7 +205,14 @@ export async function checkForUpdate(database: Database.Database, config: AppCon
|
||||
} catch {
|
||||
throw new AppError(502, "UPDATE_CHECK_FAILED", "暂时无法获取最新版本,请稍后重试");
|
||||
}
|
||||
let asset = selectReleaseAsset(metadata, platform);
|
||||
let runtimeHash: string | undefined;
|
||||
try {
|
||||
runtimeHash = runtimeHashFromLockfile(readFileSync(path.join(config.projectRoot, "pnpm-lock.yaml")));
|
||||
} catch {
|
||||
// Legacy or source installations may not contain the lockfile. They stay
|
||||
// on the full release asset instead of risking an incompatible runtime.
|
||||
}
|
||||
let asset = selectReleaseAsset(metadata, platform, runtimeHash);
|
||||
let signatureVerified = false;
|
||||
if (asset) {
|
||||
const integrity = await attachSidecarHash(metadata, asset, {
|
||||
@@ -351,6 +359,9 @@ export function publicUpdateJob(row: Record<string, unknown> | undefined): Recor
|
||||
platform: row.platform,
|
||||
assetName: row.assetName ?? null,
|
||||
sizeBytes: row.sizeBytes ?? null,
|
||||
downloadedBytes: row.downloadedBytes ?? null,
|
||||
downloadStartedAt: row.downloadStartedAt ?? null,
|
||||
downloadSpeedBps: row.downloadSpeedBps ?? null,
|
||||
// Do not expose filesystem paths, command output, or upstream response
|
||||
// text through the authenticated status endpoint. Detailed diagnostics
|
||||
// remain in the server journal for operators.
|
||||
@@ -385,6 +396,17 @@ function removeExpiredRequest(filePath: string, now: number): void {
|
||||
}
|
||||
}
|
||||
|
||||
function requestJobId(filePath: string): string | null {
|
||||
try {
|
||||
const info = lstatSync(filePath);
|
||||
if (!info.isFile() || info.isSymbolicLink()) return null;
|
||||
const value = JSON.parse(readFileSync(filePath, "utf8")) as { jobId?: unknown };
|
||||
return typeof value.jobId === "string" && /^[0-9a-f-]{36}$/.test(value.jobId) ? value.jobId : null;
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
function currentReleaseVersion(config: AppConfig): string | null {
|
||||
try {
|
||||
const target = realpathSync(config.currentLink);
|
||||
@@ -425,6 +447,7 @@ export function reconcileOrphanedUpdateJobs(database: Database.Database, config:
|
||||
// row is still safe to retry and must not block the queue forever.
|
||||
const releaseVersion = currentReleaseVersion(config);
|
||||
let reconciled = 0;
|
||||
const reconciledIds = new Set<string>();
|
||||
for (const row of rows) {
|
||||
if (typeof row.updatedAt !== "number" || now - row.updatedAt < ORPHANED_UPDATE_TIMEOUT_MS) continue;
|
||||
// The runner refreshes the state marker while a download is in flight.
|
||||
@@ -451,7 +474,10 @@ export function reconcileOrphanedUpdateJobs(database: Database.Database, config:
|
||||
});
|
||||
return true;
|
||||
})();
|
||||
if (changed) reconciled += 1;
|
||||
if (changed) {
|
||||
reconciled += 1;
|
||||
reconciledIds.add(row.id);
|
||||
}
|
||||
continue;
|
||||
}
|
||||
if (requestFresh || stateFresh) continue;
|
||||
@@ -476,7 +502,10 @@ export function reconcileOrphanedUpdateJobs(database: Database.Database, config:
|
||||
});
|
||||
return true;
|
||||
})();
|
||||
if (changed) reconciled += 1;
|
||||
if (changed) {
|
||||
reconciled += 1;
|
||||
reconciledIds.add(row.id);
|
||||
}
|
||||
}
|
||||
// Prevent a stale request from being replayed after its DB row has been
|
||||
// marked failed. The path is fixed by the server configuration and the
|
||||
@@ -484,7 +513,17 @@ export function reconcileOrphanedUpdateJobs(database: Database.Database, config:
|
||||
// A download runner refreshes the state marker while it is still using the
|
||||
// request. Keep the request until that lease also expires; otherwise a
|
||||
// long download can lose its job id and fail to finalize its row.
|
||||
if (!stateFresh && (!requestPresent || (requestMtime !== null && now - requestMtime >= ORPHANED_UPDATE_TIMEOUT_MS))) {
|
||||
const queuedRequestId = requestPresent ? requestJobId(config.updateRequestPath) : null;
|
||||
const queuedRequest = queuedRequestId ? rows.find((row) => row.id === queuedRequestId) : undefined;
|
||||
const requestStillNeeded = Boolean(
|
||||
queuedRequest
|
||||
&& ACTIVE_UPDATE_STATUSES.includes(queuedRequest.status)
|
||||
&& !reconciledIds.has(queuedRequest.id)
|
||||
&& !(queuedRequest.status === "staged" && queuedRequest.operation === "download"),
|
||||
);
|
||||
if (!stateFresh
|
||||
&& (!requestPresent || (requestMtime !== null && now - requestMtime >= ORPHANED_UPDATE_TIMEOUT_MS))
|
||||
&& !requestStillNeeded) {
|
||||
removeExpiredRequest(config.updateRequestPath, now);
|
||||
}
|
||||
return reconciled;
|
||||
|
||||
+23
-3
@@ -43,6 +43,16 @@ export type ReleaseMetadata = {
|
||||
assets: ReleaseAsset[];
|
||||
};
|
||||
|
||||
const APPLICATION_UPDATE_ASSET = /\.update-([a-f0-9]{64})\.tar\.gz$/i;
|
||||
|
||||
export function applicationUpdateRuntimeHash(assetName: string): string | undefined {
|
||||
return APPLICATION_UPDATE_ASSET.exec(assetName)?.[1]?.toLowerCase();
|
||||
}
|
||||
|
||||
export function runtimeHashFromLockfile(lockfile: string | Buffer): string {
|
||||
return createHash("sha256").update(lockfile).digest("hex");
|
||||
}
|
||||
|
||||
export type UrlPolicy = {
|
||||
/** Host names or HTTPS URLs which are allowed for requests. */
|
||||
allowedHosts?: readonly string[] | undefined;
|
||||
@@ -379,7 +389,7 @@ export async function fetchReleaseBytes(
|
||||
}
|
||||
}
|
||||
|
||||
export function selectReleaseAsset(release: ReleaseMetadata, platform = detectPlatform()): ReleaseAsset | undefined {
|
||||
export function selectReleaseAsset(release: ReleaseMetadata, platform = detectPlatform(), runtimeHash?: string): ReleaseAsset | undefined {
|
||||
const platformCandidates = release.assets.filter((asset) => {
|
||||
const name = asset.name.toLowerCase();
|
||||
return platform.aliases.filter((alias) => alias.toLowerCase().includes(platform.arch.toLowerCase())).some((alias) => name.includes(alias.toLowerCase()));
|
||||
@@ -398,7 +408,15 @@ export function selectReleaseAsset(release: ReleaseMetadata, platform = detectPl
|
||||
const target = platform.target.toLowerCase();
|
||||
return Number(b.name.toLowerCase().includes(target)) - Number(a.name.toLowerCase().includes(target));
|
||||
});
|
||||
return candidates[0];
|
||||
const normalizedRuntimeHash = runtimeHash?.trim().toLowerCase();
|
||||
if (normalizedRuntimeHash && /^[a-f0-9]{64}$/.test(normalizedRuntimeHash)) {
|
||||
const applicationUpdate = candidates.find((asset) => applicationUpdateRuntimeHash(asset.name) === normalizedRuntimeHash);
|
||||
if (applicationUpdate) return applicationUpdate;
|
||||
}
|
||||
// Older clients choose the first matching asset. Releases therefore keep
|
||||
// the traditional full archive first, while current clients explicitly
|
||||
// opt into a compatible application-only asset.
|
||||
return candidates.find((asset) => !applicationUpdateRuntimeHash(asset.name));
|
||||
}
|
||||
|
||||
export function sanitizeAssetName(value: string): string {
|
||||
@@ -423,7 +441,7 @@ export async function verifySha256(filePath: string, expected: string): Promise<
|
||||
export async function downloadReleaseAsset(
|
||||
url: string | URL,
|
||||
destination: string,
|
||||
options: UrlPolicy & { fetchImpl?: typeof fetch | undefined; maxBytes?: number | undefined } = {},
|
||||
options: UrlPolicy & { fetchImpl?: typeof fetch | undefined; maxBytes?: number | undefined; onProgress?: ((downloadedBytes: number, totalBytes: number | null) => void) | undefined } = {},
|
||||
): Promise<{ size: number; sha256: string }> {
|
||||
const fetchImpl = options.fetchImpl ?? fetch;
|
||||
let current = validateHttpsUrl(url, options);
|
||||
@@ -446,6 +464,7 @@ export async function downloadReleaseAsset(
|
||||
}
|
||||
if (response.status < 200 || response.status >= 300 || !response.body) throw new Error("更新文件下载失败");
|
||||
const declared = Number(response.headers.get("content-length") ?? 0);
|
||||
const totalBytes = Number.isSafeInteger(declared) && declared > 0 ? declared : null;
|
||||
const maxBytes = options.maxBytes ?? 512 * 1024 * 1024;
|
||||
if (declared > maxBytes) throw new Error("更新文件超过大小限制");
|
||||
await mkdir(path.dirname(destination), { recursive: true, mode: 0o700 });
|
||||
@@ -454,6 +473,7 @@ export async function downloadReleaseAsset(
|
||||
const hash = createHash("sha256");
|
||||
const meter = new Transform({ transform(chunk: Buffer, _encoding, callback) {
|
||||
size += chunk.length;
|
||||
options.onProgress?.(size, totalBytes);
|
||||
if (size > maxBytes) return callback(new Error("更新文件超过大小限制"));
|
||||
hash.update(chunk);
|
||||
callback(null, chunk);
|
||||
|
||||
+3
-3
@@ -129,10 +129,10 @@ describe("TallyNote API", () => {
|
||||
}
|
||||
});
|
||||
|
||||
it("拒绝没有 Origin 的写请求", async () => {
|
||||
it("反向代理缺少 Origin 时仍允许登录请求进入认证流程", async () => {
|
||||
const response = await app.inject({ method: "POST", url: "/api/auth/login", payload: { username: "x", password: "x" } });
|
||||
expect(response.statusCode).toBe(403);
|
||||
expect(response.json().error.code).toBe("ORIGIN_FORBIDDEN");
|
||||
expect(response.statusCode).toBe(401);
|
||||
expect(response.json().error.code).toBe("INVALID_CREDENTIALS");
|
||||
});
|
||||
|
||||
it("将非法 JSON、伪造请求 ID 处理为结构化 400", async () => {
|
||||
|
||||
@@ -42,9 +42,10 @@ describe("数据库迁移", () => {
|
||||
{ name: "0002_update_jobs.sql" },
|
||||
{ name: "0003_update_job_ownership.sql" },
|
||||
{ name: "0004_update_download_apply.sql" },
|
||||
{ name: "0005_update_progress.sql" },
|
||||
]);
|
||||
const updateColumns = migrated.sqlite.prepare("PRAGMA table_info(update_jobs)").all() as Array<{ name: string }>;
|
||||
expect(updateColumns.map((column) => column.name)).toEqual(expect.arrayContaining(["admin_id", "session_hash", "request_id", "requested_at", "started_at", "operation"]));
|
||||
expect(updateColumns.map((column) => column.name)).toEqual(expect.arrayContaining(["admin_id", "session_hash", "request_id", "requested_at", "started_at", "operation", "downloaded_bytes", "download_started_at", "download_speed_bps"]));
|
||||
expect(migrated.sqlite.prepare("SELECT note, invoice_missing_reason AS reason FROM expenses WHERE id='00000000-0000-4000-8000-000000000099'").get()).toEqual({ note: "旧账目", reason: null });
|
||||
migrated.sqlite.close();
|
||||
migrated = openDatabase(config);
|
||||
|
||||
@@ -48,6 +48,7 @@ describe("部署安全配置", () => {
|
||||
expect(loadConfig().trustProxy).toBe(1);
|
||||
});
|
||||
|
||||
|
||||
it("systemd 更新必须绑定主机白名单,签名校验默认关闭", () => {
|
||||
process.env.TALLYNOTE_UPDATE_STRATEGY = "systemd";
|
||||
process.env.TALLYNOTE_PUBLIC_ORIGIN = "https://example.test";
|
||||
|
||||
@@ -76,6 +76,12 @@ describe("更新 API", () => {
|
||||
expect(tooSoon.statusCode).toBe(429);
|
||||
expect(tooSoon.headers["retry-after"]).toBeDefined();
|
||||
|
||||
// Cooldown is scoped to the authenticated administrator, not the whole
|
||||
// database or release endpoint.
|
||||
const otherSession = await login("update-admin-other");
|
||||
const otherChecked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: otherSession.cookies, "x-csrf-token": otherSession.csrf }, payload: {} });
|
||||
expect(otherChecked.statusCode).toBe(200);
|
||||
|
||||
const applied = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } });
|
||||
expect(applied.statusCode).toBe(202);
|
||||
const jobId = applied.json().job.id as string;
|
||||
@@ -131,6 +137,24 @@ describe("更新 API", () => {
|
||||
expect(disabledConfig.updateStrategy).toBe("disabled");
|
||||
});
|
||||
|
||||
it("首次进入状态页不会展示历史失败任务,也不会阻断新的检查", async () => {
|
||||
const session = await login("update-history");
|
||||
const admin = database.sqlite.prepare("SELECT id FROM admins WHERE username=?").get("update-history") as { id: string };
|
||||
const now = Date.now();
|
||||
database.sqlite.prepare(`
|
||||
INSERT INTO update_jobs(id, admin_id, operation, status, version, platform, asset_url, error_message, created_at, updated_at)
|
||||
VALUES (?, ?, 'download', 'failed', '1.1.0', ?, 'https://updates.example/old.tar.gz', 'old failure', ?, ?)
|
||||
`).run(randomUUID(), admin.id, detectPlatform().target, now - 60_000, now - 60_000);
|
||||
const initial = await app.inject({ method: "GET", url: "/api/update/status", headers: { cookie: session.cookies } });
|
||||
expect(initial.statusCode).toBe(200);
|
||||
expect(initial.json().job).toBeNull();
|
||||
|
||||
mockRelease();
|
||||
const checked = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||
expect(checked.statusCode).toBe(200);
|
||||
expect(checked.json().latest).toMatchObject({ version: "1.2.0", isNewer: true });
|
||||
});
|
||||
|
||||
it("更新任务只对发起管理员可见,并隐藏内部错误详情", async () => {
|
||||
const owner = await login("update-owner");
|
||||
const other = await login("update-other");
|
||||
@@ -157,6 +181,12 @@ describe("更新 API", () => {
|
||||
globalThis.fetch = (async () => new Response("upstream unavailable", { status: 503 })) as typeof fetch;
|
||||
const response = await app.inject({ method: "POST", url: "/api/update/apply", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: { version: "1.2.0", confirm: true } });
|
||||
expect(response.statusCode).toBe(502);
|
||||
// A failed upstream check must not reserve the per-admin cooldown; an
|
||||
// operator can retry immediately after fixing the release endpoint.
|
||||
const check = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||
expect(check.statusCode).toBe(502);
|
||||
const retry = await app.inject({ method: "POST", url: "/api/update/check", headers: { origin: config.publicOrigin, cookie: session.cookies, "x-csrf-token": session.csrf }, payload: {} });
|
||||
expect(retry.statusCode).toBe(502);
|
||||
const audit = database.sqlite.prepare("SELECT outcome FROM audit_events WHERE action='update.apply_requested' ORDER BY id DESC LIMIT 1").get() as { outcome: string } | undefined;
|
||||
expect(audit?.outcome).toBe("failure");
|
||||
});
|
||||
|
||||
@@ -6,6 +6,7 @@ import path from "node:path";
|
||||
import { createHash, generateKeyPairSync, randomUUID, sign } from "node:crypto";
|
||||
import {
|
||||
atomicSwitchRelease,
|
||||
applicationUpdateRuntimeHash,
|
||||
createSafeArchive,
|
||||
detectPlatform,
|
||||
downloadReleaseAsset,
|
||||
@@ -16,6 +17,7 @@ import {
|
||||
normalizeReleasePermissions,
|
||||
sanitizeAssetName,
|
||||
selectReleaseAsset,
|
||||
runtimeHashFromLockfile,
|
||||
validateHttpsUrl,
|
||||
} from "../server/update.js";
|
||||
import { finalizeUpdateJob, runUpdate } from "../server/cli/update.js";
|
||||
@@ -50,6 +52,17 @@ describe("更新安全工具", () => {
|
||||
expect(() => sanitizeAssetName("../release.tar.gz")).toThrow();
|
||||
});
|
||||
|
||||
it("优先选择运行时匹配的轻量更新包,并对旧客户端保留完整包回退", () => {
|
||||
const runtimeHash = runtimeHashFromLockfile("lockfile-v1\n");
|
||||
const full = { name: "tallynote-1.2.0-linux-x64-glibc.tar.gz", url: "https://updates.example/full" };
|
||||
const app = { name: `tallynote-1.2.0-linux-x64-glibc.update-${runtimeHash}.tar.gz`, url: "https://updates.example/app" };
|
||||
const release = { version: "1.2.0", assets: [full, app] };
|
||||
expect(applicationUpdateRuntimeHash(app.name)).toBe(runtimeHash);
|
||||
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"), runtimeHash)).toEqual(app);
|
||||
expect(selectReleaseAsset(release, detectPlatform("linux", "x86_64"))).toEqual(full);
|
||||
expect(applicationUpdateRuntimeHash(full.name)).toBeUndefined();
|
||||
});
|
||||
|
||||
it("验证 SHA256SUMS 的 Ed25519 detached signature", () => {
|
||||
const { publicKey, privateKey } = generateKeyPairSync("ed25519");
|
||||
const payload = "a".repeat(64) + " tallynote.tar.gz\n";
|
||||
@@ -372,6 +385,47 @@ describe("更新安全工具", () => {
|
||||
}
|
||||
});
|
||||
|
||||
it("队列任务有新请求标记时可被重新检查,标记过期后才回收", async () => {
|
||||
const root = await mkdtemp(path.join(tmpdir(), "tallynote-update-queued-marker-"));
|
||||
let database: ReturnType<typeof openDatabase> | undefined;
|
||||
try {
|
||||
const dataDir = path.join(root, "data");
|
||||
const installPrefix = path.join(root, "install");
|
||||
process.env.TALLYNOTE_DATA_DIR = dataDir;
|
||||
process.env.TALLYNOTE_INSTALL_PREFIX = installPrefix;
|
||||
process.env.TALLYNOTE_PUBLIC_ORIGIN = "http://127.0.0.1:3998";
|
||||
process.env.TALLYNOTE_COOKIE_SECURE = "false";
|
||||
process.env.TALLYNOTE_UPDATE_STRATEGY = "systemd";
|
||||
process.env.TALLYNOTE_UPDATE_METADATA_URL = "https://updates.example/latest";
|
||||
process.env.TALLYNOTE_UPDATE_ALLOWED_HOSTS = "updates.example";
|
||||
process.env.TALLYNOTE_UPDATE_REQUIRE_SIGNATURE = "false";
|
||||
const config = loadConfig();
|
||||
prepareDataDirectories(config);
|
||||
database = openDatabase(config);
|
||||
const staleAt = Date.now() - ORPHANED_UPDATE_TIMEOUT_MS - 1;
|
||||
const jobId = randomUUID();
|
||||
database.sqlite.prepare(`
|
||||
INSERT INTO update_jobs(id, operation, status, version, platform, asset_url, created_at, updated_at)
|
||||
VALUES (?, 'apply', 'queued', '1.2.0', 'linux-x64', ?, ?, ?)
|
||||
`).run(jobId, "https://updates.example/queued.tar.gz", staleAt, staleAt);
|
||||
await writeFile(config.updateRequestPath, JSON.stringify({ jobId, operation: "apply" }));
|
||||
const now = Date.now();
|
||||
await utimes(config.updateRequestPath, new Date(now), new Date(now));
|
||||
|
||||
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, now)).toBe(0);
|
||||
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "queued" });
|
||||
expect(await stat(config.updateRequestPath)).toBeTruthy();
|
||||
|
||||
const expiredNow = now + ORPHANED_UPDATE_TIMEOUT_MS + 1;
|
||||
expect(reconcileOrphanedUpdateJobs(database.sqlite, config, expiredNow)).toBe(1);
|
||||
expect(database.sqlite.prepare("SELECT status FROM update_jobs WHERE id=?").get(jobId)).toEqual({ status: "failed" });
|
||||
await expect(stat(config.updateRequestPath)).rejects.toThrow();
|
||||
} finally {
|
||||
if (database) database.sqlite.close();
|
||||
await rm(root, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
it("流式解包在展开大小上限前拒绝高压缩比归档,并修正发布树权限", async () => {
|
||||
const root = await mkdtemp(path.join(tmpdir(), "tallynote-update-stream-"));
|
||||
try {
|
||||
|
||||
@@ -66,7 +66,7 @@ export default function ExpenseDetail({ expense, timezone = "Asia/Shanghai", onC
|
||||
</Drawer>
|
||||
<Dialog visible={action === "status"} header={detail.status === "reimbursed" ? "改回未报销?" : "标记为已报销?"} confirmBtn={{ content: "确认变更", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setAction(null); }} onConfirm={() => void updateStatus()} onCancel={() => { if (!busy) setAction(null); }}>{detail.status === "reimbursed" ? "这笔账目会重新出现在未报销列表。" : "确认这笔账目已完成报销,并从未报销列表移出?"}</Dialog>
|
||||
<Dialog visible={action === "trash"} header="移入回收站?" confirmBtn={{ content: "移入回收站", theme: "danger", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setAction(null); }} onConfirm={() => void trash()} onCancel={() => { if (!busy) setAction(null); }}>账目会从普通列表和导出结果中隐藏,附件会保留,可在回收站恢复。</Dialog>
|
||||
<Dialog visible={Boolean(removeTarget)} header="删除附件?" confirmBtn={{ content: "删除附件", theme: "danger", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setRemoveTarget(null); }} onConfirm={() => void remove()} onCancel={() => { if (!busy) setRemoveTarget(null); }}>{removeTarget && <><p>{removeTarget.kind === "payment_proof" ? "账目至少需要保留一张付款凭证。" : detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() ? "这是最后一张发票。删除后必须填写无发票原因。" : "将删除这张发票。"}</p>{removeTarget.kind === "invoice" && detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() && <Textarea disabled={busy} aria-label="无发票原因" aria-invalid={Boolean(removeError)} aria-describedby={removeError ? "remove-attachment-error" : undefined} value={removeReason} onChange={value => { setRemoveReason(value); setRemoveError(""); }} placeholder="例如:商家无法开具发票" maxlength={500} />}{removeError && <div id="remove-attachment-error" className="expense-error" role="alert"><AlertCircle size={16} />{removeError}</div>}</>}</Dialog>
|
||||
<Dialog visible={Boolean(removeTarget)} header="删除附件?" confirmBtn={{ content: "删除附件", theme: "danger", loading: busy, disabled: busy }} cancelBtn="取消" onClose={() => { if (!busy) setRemoveTarget(null); }} onConfirm={() => void remove()} onCancel={() => { if (!busy) setRemoveTarget(null); }}>{removeTarget && <><p>{removeTarget.kind === "payment_proof" ? "账目至少需要保留一张付款凭证。" : detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() ? "这是最后一张发票。删除后必须填写无发票原因。" : "将删除这张发票。"}</p>{removeTarget.kind === "invoice" && detail.invoiceCount <= 1 && !detail.invoiceMissingReason?.trim() && <Textarea disabled={busy} aria-label="无发票原因" aria-invalid={Boolean(removeError)} aria-describedby={removeError ? "remove-attachment-error" : undefined} value={removeReason} onChange={value => { setRemoveReason(value); setRemoveError(""); }} placeholder="例如:商家无法开具发票" maxlength={500} />}{removeError && <div id="remove-attachment-error" className="expense-error" role="alert">{removeError}</div>}</>}</Dialog>
|
||||
<Dialog visible={Boolean(preview)} header={preview?.originalName} onClose={() => setPreview(null)} cancelBtn="关闭" footer={null}>{preview && <div className="tn-preview">{preview.mimeType.startsWith("image/") ? <img src={`/api/attachments/${preview.id}/content`} alt={preview.originalName} /> : <iframe src={`/api/attachments/${preview.id}/content`} title={preview.originalName} />}</div>}</Dialog>
|
||||
</>;
|
||||
}
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,283 @@
|
||||
export type MockScenario =
|
||||
| "latest" // 已是最新
|
||||
| "available" // 发现新版本(待下载)
|
||||
| "downloading_30" // 下载中 30%
|
||||
| "downloading_85" // 下载中 85% + 高速
|
||||
| "staged" // 下载完成已校验,待立即更新
|
||||
| "backing_up" // 正在备份数据
|
||||
| "applying" // 正在原子切换并重启中(倒计时)
|
||||
| "completed" // 更新完成
|
||||
| "failed_verify" // 完整性校验失败
|
||||
| "disabled"; // 手动模式未配置源
|
||||
|
||||
export interface MockUpdateState {
|
||||
info: any;
|
||||
title: string;
|
||||
description: string;
|
||||
}
|
||||
|
||||
export const MOCK_SCENARIOS: Record<MockScenario, MockUpdateState> = {
|
||||
latest: {
|
||||
title: "版本健康(已是最新)",
|
||||
description: "展示当前运行版本已是最新,各项指标正常,无待处理任务",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 600_000,
|
||||
latest: {
|
||||
version: "1.1.22",
|
||||
tagName: "v1.1.22",
|
||||
releaseName: "v1.1.22 稳定版",
|
||||
publishedAt: new Date(Date.now() - 3600_000 * 24).toISOString(),
|
||||
compatible: true,
|
||||
integrityReady: true,
|
||||
signatureReady: true,
|
||||
isNewer: false,
|
||||
assetName: "tallynote-1.1.22-linux-x64-glibc.tar.gz",
|
||||
assetSize: 120540160,
|
||||
notes: "### TallyNote 1.1.22\n\n- 优化反向代理下登录兼容性\n- 增强安全审计与防重放机制\n- 前端组件性能深度优化",
|
||||
},
|
||||
job: null,
|
||||
},
|
||||
},
|
||||
available: {
|
||||
title: "发现新版本(待下载)",
|
||||
description: "检查到官方发布了更高版本,显示更新日志与文件校验信息,可点击下载",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 60_000,
|
||||
latest: {
|
||||
version: "1.1.23",
|
||||
tagName: "v1.1.23",
|
||||
releaseName: "v1.1.23 重大更新",
|
||||
publishedAt: new Date(Date.now() - 1800_000).toISOString(),
|
||||
compatible: true,
|
||||
integrityReady: true,
|
||||
signatureReady: true,
|
||||
isNewer: true,
|
||||
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||
assetSize: 121000000,
|
||||
notes: "### TallyNote 1.1.23\n\n- 【新功能】系统更新中心全面重构,支持动态速率流光进度条与平滑重启倒计时\n- 【交互】优化抽屉展开动效与手机端自适应导航\n- 【安全】发布包支持双重 Ed25519 签名与 SHA-256 清单交叉校验",
|
||||
},
|
||||
job: null,
|
||||
},
|
||||
},
|
||||
downloading_30: {
|
||||
title: "下载更新中(进度 38%)",
|
||||
description: "展示真实下载速率、已下载字节数与动态流光进度条",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 120_000,
|
||||
latest: {
|
||||
version: "1.1.23",
|
||||
tagName: "v1.1.23",
|
||||
compatible: true,
|
||||
integrityReady: true,
|
||||
signatureReady: true,
|
||||
isNewer: true,
|
||||
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||
assetSize: 121000000,
|
||||
},
|
||||
job: {
|
||||
id: "mock-job-001",
|
||||
operation: "download",
|
||||
status: "downloading",
|
||||
version: "1.1.23",
|
||||
platform: "x64/glibc",
|
||||
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||
sizeBytes: 121000000,
|
||||
downloadedBytes: 46200000,
|
||||
downloadStartedAt: Date.now() - 10000,
|
||||
downloadSpeedBps: 8800000, // 8.4 MB/s
|
||||
createdAt: Date.now() - 10000,
|
||||
updatedAt: Date.now(),
|
||||
},
|
||||
},
|
||||
},
|
||||
downloading_85: {
|
||||
title: "下载冲刺中(进度 88%)",
|
||||
description: "高速冲刺状态,即将触发 SHA-256 校验",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 120_000,
|
||||
latest: {
|
||||
version: "1.1.23",
|
||||
tagName: "v1.1.23",
|
||||
compatible: true,
|
||||
integrityReady: true,
|
||||
signatureReady: true,
|
||||
isNewer: true,
|
||||
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||
assetSize: 121000000,
|
||||
},
|
||||
job: {
|
||||
id: "mock-job-002",
|
||||
operation: "download",
|
||||
status: "downloading",
|
||||
version: "1.1.23",
|
||||
platform: "x64/glibc",
|
||||
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||
sizeBytes: 121000000,
|
||||
downloadedBytes: 106480000,
|
||||
downloadStartedAt: Date.now() - 15000,
|
||||
downloadSpeedBps: 12500000, // 11.9 MB/s
|
||||
createdAt: Date.now() - 15000,
|
||||
updatedAt: Date.now(),
|
||||
},
|
||||
},
|
||||
},
|
||||
staged: {
|
||||
title: "下载完成(待立即应用)",
|
||||
description: "更新包与签名均已校验就绪,随时可以安全点击【立即更新】",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 120_000,
|
||||
latest: {
|
||||
version: "1.1.23",
|
||||
tagName: "v1.1.23",
|
||||
compatible: true,
|
||||
integrityReady: true,
|
||||
signatureReady: true,
|
||||
isNewer: true,
|
||||
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||
assetSize: 121000000,
|
||||
notes: "### TallyNote 1.1.23\n\n- 更新包已完整解压检验通过,具备升级条件。",
|
||||
},
|
||||
job: {
|
||||
id: "mock-job-003",
|
||||
operation: "download",
|
||||
status: "staged",
|
||||
version: "1.1.23",
|
||||
platform: "x64/glibc",
|
||||
assetName: "tallynote-1.1.23-linux-x64-glibc.tar.gz",
|
||||
sizeBytes: 121000000,
|
||||
downloadedBytes: 121000000,
|
||||
createdAt: Date.now() - 60000,
|
||||
updatedAt: Date.now() - 5000,
|
||||
},
|
||||
},
|
||||
},
|
||||
backing_up: {
|
||||
title: "数据备份中(更新保护)",
|
||||
description: "正在为 /var/lib/tallynote 生成自动还原快照",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 120_000,
|
||||
latest: { version: "1.1.23", tagName: "v1.1.23", compatible: true, integrityReady: true, signatureReady: true, isNewer: true },
|
||||
job: {
|
||||
id: "mock-job-004",
|
||||
operation: "apply",
|
||||
status: "backing_up",
|
||||
version: "1.1.23",
|
||||
platform: "x64/glibc",
|
||||
createdAt: Date.now() - 20000,
|
||||
updatedAt: Date.now() - 2000,
|
||||
},
|
||||
},
|
||||
},
|
||||
applying: {
|
||||
title: "服务平滑重启中(倒计时中)",
|
||||
description: "已原子切换版本,systemd 正在热重启,前端实时探活",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 120_000,
|
||||
latest: { version: "1.1.23", tagName: "v1.1.23", compatible: true, integrityReady: true, signatureReady: true, isNewer: true },
|
||||
job: {
|
||||
id: "mock-job-005",
|
||||
operation: "apply",
|
||||
status: "applying",
|
||||
version: "1.1.23",
|
||||
platform: "x64/glibc",
|
||||
applyQueuedAt: Date.now() - 12000,
|
||||
restartWindowSeconds: 30,
|
||||
restartDeadline: Date.now() + 18000,
|
||||
createdAt: Date.now() - 25000,
|
||||
updatedAt: Date.now() - 2000,
|
||||
},
|
||||
},
|
||||
},
|
||||
completed: {
|
||||
title: "更新成功完成",
|
||||
description: "新版本健康检查通过,已平滑无感升级至最新",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.23",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 30_000,
|
||||
latest: { version: "1.1.23", tagName: "v1.1.23", compatible: true, integrityReady: true, signatureReady: true, isNewer: false },
|
||||
job: {
|
||||
id: "mock-job-006",
|
||||
operation: "apply",
|
||||
status: "completed",
|
||||
version: "1.1.23",
|
||||
platform: "x64/glibc",
|
||||
completedAt: Date.now() - 10000,
|
||||
createdAt: Date.now() - 45000,
|
||||
updatedAt: Date.now() - 10000,
|
||||
},
|
||||
},
|
||||
},
|
||||
failed_verify: {
|
||||
title: "更新失败状态(安全拦截)",
|
||||
description: "模拟签名不匹配或发布包篡改时的安全拦截展示与错误提示",
|
||||
info: {
|
||||
configured: true,
|
||||
strategy: "systemd",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "x64/glibc", os: "linux", arch: "x64" },
|
||||
checkedAt: Date.now() - 120_000,
|
||||
latest: {
|
||||
version: "1.1.23",
|
||||
tagName: "v1.1.23",
|
||||
compatible: true,
|
||||
integrityReady: false,
|
||||
signatureReady: false,
|
||||
isNewer: true,
|
||||
},
|
||||
job: {
|
||||
id: "mock-job-007",
|
||||
operation: "download",
|
||||
status: "failed",
|
||||
version: "1.1.23",
|
||||
platform: "x64/glibc",
|
||||
errorMessage: "发布包 SHA-256 校验与清单不一致,系统已自动阻断并保护原有数据。",
|
||||
createdAt: Date.now() - 30000,
|
||||
updatedAt: Date.now() - 5000,
|
||||
},
|
||||
},
|
||||
},
|
||||
disabled: {
|
||||
title: "手动源码模式",
|
||||
description: "未接入 systemd 时的只读说明与命令引导展示",
|
||||
info: {
|
||||
configured: false,
|
||||
strategy: "disabled",
|
||||
currentVersion: "1.1.22",
|
||||
platform: { target: "macOS/darwin", os: "darwin", arch: "arm64" },
|
||||
checkedAt: Date.now() - 3600_000,
|
||||
latest: null,
|
||||
job: null,
|
||||
},
|
||||
},
|
||||
};
|
||||
@@ -410,6 +410,34 @@ input:focus-visible, textarea:focus-visible, select:focus-visible {
|
||||
@keyframes tn-app-enter { from { opacity: 0; } to { opacity: 1; } }
|
||||
@keyframes tn-auth-page-in { from { opacity: 0; transform: translateY(4px); } to { opacity: 1; transform: translateY(0); } }
|
||||
.t-dialog { border: 1px solid var(--tn-border); border-radius: 4px; box-shadow: 0 18px 42px rgba(8, 47, 118, .18); }
|
||||
/* TDesign Dialog global no-icon & pure baseline typography normalization */
|
||||
.t-dialog__header .t-icon:not(.t-icon-close),
|
||||
.t-dialog__body .t-icon,
|
||||
.t-dialog .t-icon.t-is-info,
|
||||
.t-dialog .t-icon.t-is-success,
|
||||
.t-dialog .t-icon.t-is-warning,
|
||||
.t-dialog .t-icon.t-is-error {
|
||||
display: none !important;
|
||||
}
|
||||
.t-dialog__header {
|
||||
font-size: 16px;
|
||||
font-weight: 600;
|
||||
color: var(--tn-navy-900);
|
||||
line-height: 1.4;
|
||||
margin-bottom: 8px;
|
||||
gap: 0 !important;
|
||||
}
|
||||
.t-dialog__header-content {
|
||||
display: block !important;
|
||||
width: 100%;
|
||||
}
|
||||
.t-dialog__body {
|
||||
font-size: 13.5px;
|
||||
line-height: 1.65;
|
||||
color: var(--tn-text);
|
||||
padding: 8px 0 20px 0;
|
||||
}
|
||||
|
||||
.t-dialog__mask { background: var(--td-mask-active) !important; }
|
||||
.t-dialog__footer .t-button { min-width: 76px; }
|
||||
@media (max-width: 900px) {
|
||||
@@ -537,3 +565,545 @@ input:focus-visible, textarea:focus-visible, select:focus-visible {
|
||||
@media (prefers-reduced-motion: reduce) {
|
||||
*, *::before, *::after { animation-duration: .01ms !important; animation-iteration-count: 1 !important; transition-duration: .01ms !important; scroll-behavior: auto !important; }
|
||||
}
|
||||
|
||||
/* ==========================================================================
|
||||
TallyNote Update Center (Redesigned UI & Interactive Styles)
|
||||
========================================================================== */
|
||||
|
||||
/* Mock Console Controller */
|
||||
.tn-mock-console {
|
||||
margin-bottom: 16px;
|
||||
padding: 14px 18px;
|
||||
background: #f8fbff;
|
||||
border: 1px dashed var(--td-brand-color-3);
|
||||
border-radius: 4px;
|
||||
}
|
||||
.tn-mock-console-header {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: space-between;
|
||||
flex-wrap: wrap;
|
||||
gap: 8px;
|
||||
margin-bottom: 12px;
|
||||
}
|
||||
.tn-mock-console-title {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
font-size: 13px;
|
||||
color: var(--tn-navy-900);
|
||||
}
|
||||
.tn-mock-console-tip {
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-secondary);
|
||||
}
|
||||
.tn-mock-scenario-chips {
|
||||
display: flex;
|
||||
flex-wrap: wrap;
|
||||
gap: 8px;
|
||||
}
|
||||
.tn-scenario-chip {
|
||||
padding: 5px 11px;
|
||||
font-size: 12px;
|
||||
border: 1px solid var(--tn-border);
|
||||
border-radius: 3px;
|
||||
background: #ffffff;
|
||||
color: var(--tn-text-secondary);
|
||||
cursor: pointer;
|
||||
transition: all 0.16s ease;
|
||||
}
|
||||
.tn-scenario-chip:hover {
|
||||
border-color: var(--td-brand-color-4);
|
||||
color: var(--td-brand-color);
|
||||
background: var(--td-brand-color-1);
|
||||
}
|
||||
.tn-scenario-chip.active {
|
||||
background: var(--td-brand-color);
|
||||
border-color: var(--td-brand-color);
|
||||
color: #ffffff;
|
||||
font-weight: 600;
|
||||
box-shadow: 0 2px 6px rgba(23, 92, 211, 0.2);
|
||||
}
|
||||
|
||||
/* Update Page Actions */
|
||||
.tn-update-page-actions {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 10px;
|
||||
}
|
||||
|
||||
/* 4 Metrics Grid */
|
||||
.tn-update-metrics-grid {
|
||||
display: grid;
|
||||
grid-template-columns: repeat(4, minmax(0, 1fr));
|
||||
gap: 14px;
|
||||
margin-bottom: 16px;
|
||||
}
|
||||
.tn-metric-card .t-card__body {
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
justify-content: space-between;
|
||||
padding: 16px 18px;
|
||||
min-height: 104px;
|
||||
}
|
||||
.tn-metric-content {
|
||||
width: 100%;
|
||||
}
|
||||
.tn-metric-label {
|
||||
display: block;
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-secondary);
|
||||
margin-bottom: 4px;
|
||||
}
|
||||
.tn-metric-value {
|
||||
font-size: 20px;
|
||||
font-weight: 700;
|
||||
color: var(--tn-navy-900);
|
||||
font-family: "Plus Jakarta Sans Variable", sans-serif;
|
||||
font-variant-numeric: tabular-nums;
|
||||
line-height: 1.2;
|
||||
}
|
||||
.tn-metric-foot {
|
||||
margin-top: 6px;
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-muted);
|
||||
}
|
||||
|
||||
/* Stepper Surface */
|
||||
.tn-stepper-surface {
|
||||
margin-bottom: 16px;
|
||||
padding: 20px;
|
||||
}
|
||||
.tn-stepper-head {
|
||||
display: flex;
|
||||
align-items: flex-start;
|
||||
justify-content: space-between;
|
||||
gap: 16px;
|
||||
margin-bottom: 20px;
|
||||
}
|
||||
.tn-section-heading {
|
||||
margin: 0 0 4px;
|
||||
font-size: 15px;
|
||||
font-weight: 700;
|
||||
color: var(--tn-text);
|
||||
}
|
||||
.tn-section-subheading {
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-secondary);
|
||||
}
|
||||
.tn-stepper-wrap {
|
||||
padding: 10px 0 20px;
|
||||
}
|
||||
.tn-stepper-wrap .t-steps {
|
||||
max-width: 860px;
|
||||
margin: 0 auto;
|
||||
}
|
||||
.tn-stepper-wrap {
|
||||
min-width: 0;
|
||||
overflow-x: auto;
|
||||
scrollbar-width: thin;
|
||||
scrollbar-color: var(--td-brand-color-3) transparent;
|
||||
}
|
||||
.tn-stepper-wrap .t-steps {
|
||||
min-width: 680px;
|
||||
}
|
||||
|
||||
/* Job Runtime Panel (Active download & progress) */
|
||||
.tn-job-runtime-panel {
|
||||
margin-top: 14px;
|
||||
padding: 16px;
|
||||
background: #f8fbff;
|
||||
border: 1px solid var(--td-brand-color-2);
|
||||
border-radius: 4px;
|
||||
}
|
||||
.tn-job-runtime-header {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: space-between;
|
||||
flex-wrap: wrap;
|
||||
gap: 10px;
|
||||
margin-bottom: 12px;
|
||||
}
|
||||
.tn-job-status-badge {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
font-size: 13px;
|
||||
color: var(--tn-navy-900);
|
||||
min-width: 0;
|
||||
overflow-wrap: anywhere;
|
||||
}
|
||||
.tn-pulse-dot {
|
||||
width: 8px;
|
||||
height: 8px;
|
||||
border-radius: 50%;
|
||||
background: var(--td-brand-color);
|
||||
box-shadow: 0 0 0 0 rgba(23, 92, 211, 0.7);
|
||||
animation: tn-pulse 1.8s infinite;
|
||||
}
|
||||
@keyframes tn-pulse {
|
||||
0% { transform: scale(0.95); box-shadow: 0 0 0 0 rgba(23, 92, 211, 0.7); }
|
||||
70% { transform: scale(1); box-shadow: 0 0 0 6px rgba(23, 92, 211, 0); }
|
||||
100% { transform: scale(0.95); box-shadow: 0 0 0 0 rgba(23, 92, 211, 0); }
|
||||
}
|
||||
.tn-job-subtext {
|
||||
color: var(--tn-text-secondary);
|
||||
font-size: 12px;
|
||||
font-family: "Plus Jakarta Sans Variable", sans-serif;
|
||||
font-variant-numeric: tabular-nums;
|
||||
}
|
||||
.tn-speed-indicator {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
min-width: 0;
|
||||
flex-wrap: wrap;
|
||||
}
|
||||
.tn-speed-badge {
|
||||
display: inline-flex;
|
||||
align-items: center;
|
||||
gap: 4px;
|
||||
padding: 2px 8px;
|
||||
border-radius: 3px;
|
||||
background: #ffffff;
|
||||
border: 1px solid var(--td-brand-color-3);
|
||||
color: var(--td-brand-color);
|
||||
font-size: 12px;
|
||||
font-weight: 600;
|
||||
font-family: "Plus Jakarta Sans Variable", sans-serif;
|
||||
font-variant-numeric: tabular-nums;
|
||||
}
|
||||
.tn-eta-badge {
|
||||
display: inline-block;
|
||||
padding: 2px 8px;
|
||||
border-radius: 3px;
|
||||
background: #f2f5f9;
|
||||
color: var(--tn-text-secondary);
|
||||
font-size: 12px;
|
||||
font-variant-numeric: tabular-nums;
|
||||
}
|
||||
|
||||
/* Progress Bar with modern stream light effect */
|
||||
.tn-progress-stream {
|
||||
position: relative;
|
||||
height: 8px;
|
||||
background: #e1e9f4;
|
||||
border-radius: 999px;
|
||||
overflow: hidden;
|
||||
margin-bottom: 12px;
|
||||
}
|
||||
.tn-progress-stream-bar {
|
||||
height: 100%;
|
||||
background: linear-gradient(90deg, #175cd3 0%, #3d7be5 100%);
|
||||
border-radius: inherit;
|
||||
transition: width 0.35s ease;
|
||||
position: relative;
|
||||
}
|
||||
.tn-progress-stream-bar::after {
|
||||
content: "";
|
||||
position: absolute;
|
||||
top: 0; left: 0; bottom: 0; right: 0;
|
||||
background-image: linear-gradient(
|
||||
-45deg,
|
||||
rgba(255, 255, 255, 0.25) 25%,
|
||||
transparent 25%,
|
||||
transparent 50%,
|
||||
rgba(255, 255, 255, 0.25) 50%,
|
||||
rgba(255, 255, 255, 0.25) 75%,
|
||||
transparent 75%,
|
||||
transparent
|
||||
);
|
||||
background-size: 30px 30px;
|
||||
animation: tn-stream-flow 1.5s linear infinite;
|
||||
}
|
||||
@keyframes tn-stream-flow {
|
||||
0% { background-position: 0 0; }
|
||||
100% { background-position: 30px 30px; }
|
||||
}
|
||||
|
||||
.tn-job-runtime-desc {
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-secondary);
|
||||
line-height: 1.6;
|
||||
}
|
||||
|
||||
/* Restarting State Banner */
|
||||
.tn-restarting-banner {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 12px;
|
||||
padding: 8px 12px;
|
||||
background: #fff8e6;
|
||||
border: 1px solid #ffd666;
|
||||
border-radius: 3px;
|
||||
color: #8c5b00;
|
||||
}
|
||||
.tn-restarting-spinner {
|
||||
color: #faad14;
|
||||
}
|
||||
|
||||
/* Release Surface */
|
||||
.tn-release-surface {
|
||||
margin-bottom: 16px;
|
||||
padding: 20px;
|
||||
}
|
||||
.tn-release-notes-surface {
|
||||
margin-bottom: 16px;
|
||||
padding: 20px;
|
||||
}
|
||||
.tn-release-notes-header {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: space-between;
|
||||
gap: 16px;
|
||||
margin-bottom: 12px;
|
||||
}
|
||||
.tn-release-header {
|
||||
display: flex;
|
||||
align-items: flex-start;
|
||||
justify-content: space-between;
|
||||
gap: 16px;
|
||||
}
|
||||
.tn-release-tag-row {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
margin-bottom: 6px;
|
||||
}
|
||||
.tn-release-title {
|
||||
margin: 0 0 6px;
|
||||
font-size: 22px;
|
||||
font-weight: 700;
|
||||
color: var(--tn-navy-900);
|
||||
}
|
||||
.tn-release-time {
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-secondary);
|
||||
}
|
||||
.tn-release-notes-box {
|
||||
margin: 0;
|
||||
padding: 12px 16px;
|
||||
background: #f8fafc;
|
||||
border: 1px solid var(--tn-border);
|
||||
border-left: 3px solid var(--td-brand-color);
|
||||
border-radius: 3px;
|
||||
}
|
||||
.tn-release-notes-heading {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 6px;
|
||||
font-size: 12px;
|
||||
font-weight: 600;
|
||||
color: var(--tn-navy-900);
|
||||
margin-bottom: 6px;
|
||||
}
|
||||
.tn-release-notes-content {
|
||||
font-size: 13px;
|
||||
color: var(--tn-text-secondary);
|
||||
line-height: 1.6;
|
||||
max-height: 140px;
|
||||
overflow-y: auto;
|
||||
}
|
||||
|
||||
.tn-markdown-notes {
|
||||
color: inherit;
|
||||
line-height: 1.7;
|
||||
overflow-wrap: anywhere;
|
||||
}
|
||||
.tn-markdown-notes p,
|
||||
.tn-markdown-notes h3,
|
||||
.tn-markdown-notes h4,
|
||||
.tn-markdown-notes h5 {
|
||||
margin: 0 0 8px;
|
||||
}
|
||||
.tn-markdown-notes p:last-child,
|
||||
.tn-markdown-notes ul:last-child,
|
||||
.tn-markdown-notes pre:last-child,
|
||||
.tn-markdown-notes h3:last-child,
|
||||
.tn-markdown-notes h4:last-child,
|
||||
.tn-markdown-notes h5:last-child {
|
||||
margin-bottom: 0;
|
||||
}
|
||||
.tn-markdown-notes h3,
|
||||
.tn-markdown-notes h4,
|
||||
.tn-markdown-notes h5 {
|
||||
color: var(--tn-navy-900);
|
||||
font-weight: 700;
|
||||
}
|
||||
.tn-markdown-notes h3 { font-size: 15px; }
|
||||
.tn-markdown-notes h4 { font-size: 14px; }
|
||||
.tn-markdown-notes h5 { font-size: 13px; }
|
||||
.tn-markdown-notes ul {
|
||||
margin: 0 0 8px;
|
||||
padding-left: 20px;
|
||||
}
|
||||
.tn-markdown-notes li { margin: 3px 0; }
|
||||
.tn-markdown-notes strong { color: var(--tn-navy-900); font-weight: 700; }
|
||||
.tn-markdown-notes code {
|
||||
padding: 1px 4px;
|
||||
border: 1px solid var(--tn-border-subtle);
|
||||
border-radius: 3px;
|
||||
background: #f2f5f9;
|
||||
color: var(--tn-navy-900);
|
||||
font-family: "Plus Jakarta Sans Variable", ui-monospace, monospace;
|
||||
font-size: .92em;
|
||||
}
|
||||
.tn-markdown-notes pre {
|
||||
margin: 0 0 8px;
|
||||
padding: 10px 12px;
|
||||
overflow-x: auto;
|
||||
border: 1px solid var(--tn-border-subtle);
|
||||
border-radius: 3px;
|
||||
background: #f8fafc;
|
||||
white-space: pre-wrap;
|
||||
}
|
||||
.tn-markdown-notes pre code { padding: 0; border: 0; background: transparent; }
|
||||
.tn-markdown-notes a { color: var(--td-brand-color); text-decoration: underline; text-underline-offset: 2px; }
|
||||
.tn-markdown-notes-compact { font-size: 13px; }
|
||||
|
||||
/* Facts Grid */
|
||||
.tn-facts-grid {
|
||||
display: grid;
|
||||
grid-template-columns: repeat(3, minmax(0, 1fr));
|
||||
gap: 14px;
|
||||
margin: 18px 0;
|
||||
padding: 14px 0;
|
||||
border-top: 1px solid var(--tn-border-subtle);
|
||||
border-bottom: 1px solid var(--tn-border-subtle);
|
||||
}
|
||||
.tn-fact-item {
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
gap: 4px;
|
||||
}
|
||||
.tn-fact-label {
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-secondary);
|
||||
}
|
||||
.tn-fact-value {
|
||||
font-size: 14px;
|
||||
color: var(--tn-text);
|
||||
font-weight: 600;
|
||||
overflow-wrap: anywhere;
|
||||
}
|
||||
.tn-fact-hint {
|
||||
font-size: 11px;
|
||||
color: var(--tn-text-muted);
|
||||
}
|
||||
|
||||
.tn-release-card-actions {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 12px;
|
||||
margin-top: 16px;
|
||||
}
|
||||
|
||||
/* Dialog content styles */
|
||||
.tn-confirm-dialog-content {
|
||||
font-size: 13px;
|
||||
line-height: 1.6;
|
||||
color: var(--tn-text);
|
||||
}
|
||||
.tn-update-safety-tips {
|
||||
margin-top: 10px;
|
||||
padding: 10px 14px;
|
||||
background: #f6f8fb;
|
||||
border-radius: 3px;
|
||||
border: 1px solid var(--tn-border-subtle);
|
||||
font-size: 12px;
|
||||
color: var(--tn-text-secondary);
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
gap: 4px;
|
||||
}
|
||||
|
||||
.tn-full-notes-modal {
|
||||
margin: 0;
|
||||
padding: 12px;
|
||||
background: #f8fafc;
|
||||
border-radius: 3px;
|
||||
font-size: 13px;
|
||||
line-height: 1.6;
|
||||
color: var(--tn-text);
|
||||
max-height: 50vh;
|
||||
overflow-y: auto;
|
||||
}
|
||||
|
||||
.tn-empty-surface {
|
||||
padding: 36px 20px;
|
||||
text-align: center;
|
||||
}
|
||||
.tn-empty-content {
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
color: var(--tn-text-secondary);
|
||||
font-size: 13px;
|
||||
}
|
||||
|
||||
.tn-inline-warning {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
padding: 10px 14px;
|
||||
margin-bottom: 14px;
|
||||
background: #fffbe6;
|
||||
border: 1px solid #ffe58f;
|
||||
border-radius: 3px;
|
||||
color: #d48806;
|
||||
font-size: 13px;
|
||||
}
|
||||
|
||||
/* Responsive adjustments */
|
||||
@media (max-width: 992px) {
|
||||
.tn-update-metrics-grid {
|
||||
grid-template-columns: repeat(2, minmax(0, 1fr));
|
||||
}
|
||||
.tn-facts-grid {
|
||||
grid-template-columns: 1fr;
|
||||
}
|
||||
}
|
||||
@media (max-width: 640px) {
|
||||
.tn-update-metrics-grid {
|
||||
grid-template-columns: 1fr;
|
||||
}
|
||||
.tn-mock-console-header {
|
||||
flex-direction: column;
|
||||
align-items: flex-start;
|
||||
}
|
||||
.tn-release-header {
|
||||
flex-direction: column;
|
||||
}
|
||||
.tn-release-notes-header {
|
||||
align-items: flex-start;
|
||||
flex-direction: column;
|
||||
}
|
||||
.tn-release-notes-header .t-button {
|
||||
width: 100%;
|
||||
}
|
||||
.tn-release-card-actions {
|
||||
flex-direction: column;
|
||||
width: 100%;
|
||||
}
|
||||
.tn-release-card-actions .t-button {
|
||||
width: 100%;
|
||||
}
|
||||
.tn-stepper-wrap {
|
||||
margin-inline: -4px;
|
||||
padding-inline: 4px;
|
||||
}
|
||||
.tn-stepper-wrap .t-steps {
|
||||
min-width: 620px;
|
||||
}
|
||||
.tn-job-runtime-header {
|
||||
align-items: stretch;
|
||||
}
|
||||
.tn-job-status-badge,
|
||||
.tn-speed-indicator {
|
||||
width: 100%;
|
||||
}
|
||||
.tn-speed-indicator {
|
||||
justify-content: flex-start;
|
||||
}
|
||||
}
|
||||
|
||||
+1
-1
@@ -771,7 +771,7 @@ function Update({ notify }: { notify: (message: string, kind?: Notice["kind"]) =
|
||||
const canApply = Boolean(info?.strategy === "systemd" && latest?.isNewer && latest.compatible && latest.integrityReady && !hasActiveJob && (!job || job.status === "failed" || job.version !== latest.version));
|
||||
|
||||
return <div className="page update-page">
|
||||
<div className="page-head"><div><div className="eyebrow">系统</div><h1>系统更新</h1></div><div className="head-actions"><Button onClick={() => void load()} disabled={loading || checking}><RotateCcw size={15} />刷新</Button><Button kind="primary" onClick={() => void check()} disabled={loading || checking || hasActiveJob}><RefreshCw size={15} className={checking ? "spin" : undefined} />检查更新</Button></div></div>
|
||||
<div className="page-head"><div><div className="eyebrow">系统</div><h1>系统更新</h1></div><div className="head-actions"><Button onClick={() => void load()} disabled={loading || checking}><RotateCcw size={15} />刷新</Button><Button kind="primary" onClick={() => void check()} disabled={loading || checking}><RefreshCw size={15} className={checking ? "spin" : undefined} />检查更新</Button></div></div>
|
||||
{error && <div className="error banner" role="alert"><AlertCircle size={16} />{error}<button className="text-button" onClick={() => void load()}>重试</button></div>}
|
||||
{loading ? <div className="update-loading"><Loader2 className="spin" size={22} />正在读取版本信息</div> : info && <>
|
||||
<div className="update-overview">
|
||||
|
||||
Reference in New Issue
Block a user