|
| 1 | +import { execFileSync } from 'node:child_process'; |
| 2 | +import { readFileSync } from 'node:fs'; |
| 3 | +import path from 'node:path'; |
| 4 | + |
| 5 | +const ROOT = path.resolve(import.meta.dirname, '..'); |
| 6 | +const SELF = 'scripts/check-identity-freeze.mjs'; |
| 7 | +const SELF_TEST = 'scripts/check-identity-freeze.test.mjs'; |
| 8 | + |
| 9 | +export const VSCODE_PUBLISHER = 'pymodel'; |
| 10 | +export const VSCODE_NAME = 'pythinker'; |
| 11 | +export const VSCODE_DISPLAY_NAME = 'Pythinker'; |
| 12 | +export const CLI_PACKAGE = '@pymodel/pythinker-code'; |
| 13 | +export const CAPABILITY_MARKER = 'pymodel.kosong.UNKNOWN_CAPABILITY'; |
| 14 | +export const FORBIDDEN_CAPABILITY_MARKER = 'moonshot-ai.kosong.UNKNOWN_CAPABILITY'; |
| 15 | + |
| 16 | +export const CAPABILITY_FILES = [ |
| 17 | + 'packages/kosong/src/capability.ts', |
| 18 | + 'packages/agent-core-v2/src/kosong/contract/capability.ts', |
| 19 | + 'packages/agent-core-v2/src/llm-adapter/contract/capability.ts', |
| 20 | + 'packages/agent-core-v2/src/human/llm/capability.ts', |
| 21 | +]; |
| 22 | + |
| 23 | +export const CHANGELOG_FILES = { |
| 24 | + cli: 'apps/pythinker-code/CHANGELOG.md', |
| 25 | + vscode: 'apps/vscode/CHANGELOG.md', |
| 26 | + desktop: 'apps/desktop/CHANGELOG.md', |
| 27 | +}; |
| 28 | + |
| 29 | +export const MOONSHOT_AI_ALLOW_FILES = new Set([ |
| 30 | + SELF, |
| 31 | + SELF_TEST, |
| 32 | + 'packages/oauth/src/open-platform.ts', |
| 33 | + 'packages/oauth/src/refreshProviderModels.ts', |
| 34 | + 'packages/oauth/test/open-platform.test.ts', |
| 35 | +]); |
| 36 | + |
| 37 | +const CORE = /^(\d+)\.(\d+)\.(\d+)/u; |
| 38 | +const HEADING = /^## (\d+\.\d+\.\d+)\b/mu; |
| 39 | +const PROVIDER_HOST = /api\.moonshot\.(?:ai|cn)/u; |
| 40 | + |
| 41 | +export function parseSemverCore(version) { |
| 42 | + if (typeof version !== 'string') return null; |
| 43 | + const match = CORE.exec(version); |
| 44 | + if (match === null) return null; |
| 45 | + return [Number(match[1]), Number(match[2]), Number(match[3])]; |
| 46 | +} |
| 47 | + |
| 48 | +export function compareSemverCore(left, right) { |
| 49 | + const a = parseSemverCore(left); |
| 50 | + const b = parseSemverCore(right); |
| 51 | + if (a === null || b === null) return null; |
| 52 | + for (let index = 0; index < 3; index += 1) { |
| 53 | + if (a[index] !== b[index]) return a[index] - b[index]; |
| 54 | + } |
| 55 | + return 0; |
| 56 | +} |
| 57 | + |
| 58 | +export function firstChangelogHeading(source) { |
| 59 | + if (typeof source !== 'string') return null; |
| 60 | + return HEADING.exec(source)?.[1] ?? null; |
| 61 | +} |
| 62 | + |
| 63 | +function asText(value) { |
| 64 | + return typeof value === 'string' ? value : '-'; |
| 65 | +} |
| 66 | + |
| 67 | +export function evaluate(input) { |
| 68 | + const failures = []; |
| 69 | + const vscode = input.vscode ?? {}; |
| 70 | + if (vscode.publisher !== VSCODE_PUBLISHER) { |
| 71 | + failures.push(`VS Code publisher must be ${VSCODE_PUBLISHER}, got ${asText(vscode.publisher)}`); |
| 72 | + } |
| 73 | + if (vscode.name !== VSCODE_NAME) { |
| 74 | + failures.push(`VS Code name must be ${VSCODE_NAME}, got ${asText(vscode.name)}`); |
| 75 | + } |
| 76 | + if (vscode.displayName !== VSCODE_DISPLAY_NAME) { |
| 77 | + failures.push(`VS Code displayName must be ${VSCODE_DISPLAY_NAME}, got ${asText(vscode.displayName)}`); |
| 78 | + } |
| 79 | + |
| 80 | + for (const [lane, heading] of Object.entries(input.changelogHeadings ?? {})) { |
| 81 | + const version = input.versions?.[lane]; |
| 82 | + if (typeof version !== 'string') { |
| 83 | + failures.push(`${lane} package.json version is missing`); |
| 84 | + continue; |
| 85 | + } |
| 86 | + if (heading !== version) { |
| 87 | + failures.push(`${lane} changelog heading ${asText(heading)} does not match version ${version}`); |
| 88 | + } |
| 89 | + } |
| 90 | + |
| 91 | + for (const [file, source] of Object.entries(input.capabilitySources ?? {})) { |
| 92 | + if (!source.includes(CAPABILITY_MARKER)) { |
| 93 | + failures.push(`${file}: missing ${CAPABILITY_MARKER}`); |
| 94 | + } |
| 95 | + if (source.includes(FORBIDDEN_CAPABILITY_MARKER)) { |
| 96 | + failures.push(`${file}: still uses ${FORBIDDEN_CAPABILITY_MARKER}`); |
| 97 | + } |
| 98 | + } |
| 99 | + |
| 100 | + for (const hit of input.moonshotHits ?? []) { |
| 101 | + failures.push(`${hit.file}:${hit.line}: moonshot-ai identity token`); |
| 102 | + } |
| 103 | + |
| 104 | + for (const [lane, base] of Object.entries(input.baseVersions ?? {})) { |
| 105 | + const head = input.versions?.[lane]; |
| 106 | + const order = compareSemverCore(asText(head), asText(base)); |
| 107 | + if (order !== null && order < 0) { |
| 108 | + failures.push(`${lane} version rewound ${asText(base)} -> ${asText(head)}`); |
| 109 | + } |
| 110 | + } |
| 111 | + |
| 112 | + if (typeof input.npmLatest === 'string') { |
| 113 | + const cliVersion = asText(input.versions?.cli); |
| 114 | + const order = compareSemverCore(cliVersion, input.npmLatest); |
| 115 | + if (order !== null && order < 0) { |
| 116 | + failures.push(`CLI version ${cliVersion} is below npm latest ${input.npmLatest}`); |
| 117 | + } |
| 118 | + } |
| 119 | + |
| 120 | + return { ok: failures.length === 0, failures }; |
| 121 | +} |
| 122 | + |
| 123 | +export function moonshotHitAllowed(file, line) { |
| 124 | + if (MOONSHOT_AI_ALLOW_FILES.has(file)) return true; |
| 125 | + return PROVIDER_HOST.test(line); |
| 126 | +} |
| 127 | + |
| 128 | +function readJson(relative) { |
| 129 | + return JSON.parse(readFileSync(path.join(ROOT, relative), 'utf8')); |
| 130 | +} |
| 131 | + |
| 132 | +function readText(relative) { |
| 133 | + return readFileSync(path.join(ROOT, relative), 'utf8'); |
| 134 | +} |
| 135 | + |
| 136 | +function trackedFiles() { |
| 137 | + return execFileSync('git', ['ls-files', '-z'], { cwd: ROOT }) |
| 138 | + .toString('utf8') |
| 139 | + .split('\0') |
| 140 | + .filter(Boolean); |
| 141 | +} |
| 142 | + |
| 143 | +function scanMoonshotHits() { |
| 144 | + const hits = []; |
| 145 | + for (const file of trackedFiles()) { |
| 146 | + if (file === 'pnpm-lock.yaml' || file.includes('/dist/') || file.includes('/dist-web/')) continue; |
| 147 | + let bytes; |
| 148 | + try { |
| 149 | + bytes = readFileSync(path.join(ROOT, file)); |
| 150 | + } catch { |
| 151 | + continue; |
| 152 | + } |
| 153 | + if (bytes.length > 2 * 1024 * 1024 || bytes.includes(0)) continue; |
| 154 | + let text; |
| 155 | + try { |
| 156 | + text = new TextDecoder('utf-8', { fatal: true }).decode(bytes); |
| 157 | + } catch { |
| 158 | + continue; |
| 159 | + } |
| 160 | + for (const [index, line] of text.split(/\r?\n/).entries()) { |
| 161 | + if (!line.includes('moonshot-ai')) continue; |
| 162 | + if (moonshotHitAllowed(file, line)) continue; |
| 163 | + hits.push({ file, line: index + 1, text: line.trim() }); |
| 164 | + } |
| 165 | + } |
| 166 | + return hits; |
| 167 | +} |
| 168 | + |
| 169 | +function readBaseVersion(baseSha, relative) { |
| 170 | + try { |
| 171 | + const source = execFileSync('git', ['show', `${baseSha}:${relative}`], { |
| 172 | + cwd: ROOT, |
| 173 | + encoding: 'utf8', |
| 174 | + stdio: ['ignore', 'pipe', 'pipe'], |
| 175 | + }); |
| 176 | + const version = JSON.parse(source).version; |
| 177 | + return typeof version === 'string' ? version : undefined; |
| 178 | + } catch { |
| 179 | + return undefined; |
| 180 | + } |
| 181 | +} |
| 182 | + |
| 183 | +function readNpmLatest() { |
| 184 | + const cleanEnv = { ...process.env }; |
| 185 | + delete cleanEnv.NODE_AUTH_TOKEN; |
| 186 | + delete cleanEnv.NPM_CONFIG_USERCONFIG; |
| 187 | + delete cleanEnv.npm_config_userconfig; |
| 188 | + return execFileSync( |
| 189 | + 'npm', |
| 190 | + ['view', CLI_PACKAGE, 'version', '--registry=https://registry.npmjs.org'], |
| 191 | + { cwd: ROOT, env: cleanEnv, encoding: 'utf8', timeout: 30_000 }, |
| 192 | + ).trim(); |
| 193 | +} |
| 194 | + |
| 195 | +function main() { |
| 196 | + const vscode = readJson('apps/vscode/package.json'); |
| 197 | + const cli = readJson('apps/pythinker-code/package.json'); |
| 198 | + const desktop = readJson('apps/desktop/package.json'); |
| 199 | + const versions = { cli: cli.version, vscode: vscode.version, desktop: desktop.version }; |
| 200 | + const changelogHeadings = Object.fromEntries( |
| 201 | + Object.entries(CHANGELOG_FILES).map(([lane, file]) => [lane, firstChangelogHeading(readText(file))]), |
| 202 | + ); |
| 203 | + const capabilitySources = Object.fromEntries( |
| 204 | + CAPABILITY_FILES.map((file) => [file, readText(file)]), |
| 205 | + ); |
| 206 | + |
| 207 | + const baseSha = process.env.BASE_SHA; |
| 208 | + const baseVersions = {}; |
| 209 | + if (typeof baseSha === 'string' && /^[0-9a-f]{7,40}$/u.test(baseSha)) { |
| 210 | + const cliBase = readBaseVersion(baseSha, 'apps/pythinker-code/package.json'); |
| 211 | + const vscodeBase = readBaseVersion(baseSha, 'apps/vscode/package.json'); |
| 212 | + const desktopBase = readBaseVersion(baseSha, 'apps/desktop/package.json'); |
| 213 | + if (cliBase !== undefined) baseVersions.cli = cliBase; |
| 214 | + if (vscodeBase !== undefined) baseVersions.vscode = vscodeBase; |
| 215 | + if (desktopBase !== undefined) baseVersions.desktop = desktopBase; |
| 216 | + } |
| 217 | + |
| 218 | + let npmLatest; |
| 219 | + if (process.argv.includes('--npm')) { |
| 220 | + try { |
| 221 | + npmLatest = readNpmLatest(); |
| 222 | + } catch (error) { |
| 223 | + process.stderr.write( |
| 224 | + `Identity freeze failed: cannot read npm latest for ${CLI_PACKAGE}: ${error instanceof Error ? error.message : String(error)}\n`, |
| 225 | + ); |
| 226 | + process.exit(1); |
| 227 | + } |
| 228 | + } |
| 229 | + |
| 230 | + const result = evaluate({ |
| 231 | + vscode: { |
| 232 | + publisher: vscode.publisher, |
| 233 | + name: vscode.name, |
| 234 | + displayName: vscode.displayName, |
| 235 | + }, |
| 236 | + versions, |
| 237 | + changelogHeadings, |
| 238 | + capabilitySources, |
| 239 | + moonshotHits: scanMoonshotHits(), |
| 240 | + baseVersions: Object.keys(baseVersions).length > 0 ? baseVersions : undefined, |
| 241 | + npmLatest, |
| 242 | + }); |
| 243 | + |
| 244 | + if (!result.ok) { |
| 245 | + process.stderr.write(`Identity freeze failed:\n${result.failures.map((line) => `- ${line}`).join('\n')}\n`); |
| 246 | + process.exit(1); |
| 247 | + } |
| 248 | + process.stdout.write('Identity freeze passed.\n'); |
| 249 | +} |
| 250 | + |
| 251 | +if (process.argv[1] === import.meta.filename) { |
| 252 | + try { |
| 253 | + main(); |
| 254 | + } catch (error) { |
| 255 | + process.stderr.write(`${error instanceof Error ? error.message : String(error)}\n`); |
| 256 | + process.exitCode = 1; |
| 257 | + } |
| 258 | +} |
0 commit comments