Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
112 commits
Select commit Hold shift + click to select a range
ed4a264
ci: guard workflow shell interpolation
z13321812367-sys Sep 4, 2026
4d31165
ci: enforce workflow shell boundary
z13321812367-sys Sep 4, 2026
33b74e5
ci: harden supplemental Linux release inputs
z13321812367-sys Sep 4, 2026
04b3e28
ci: make supplemental macOS release fail closed
z13321812367-sys Sep 4, 2026
3f16ba7
ci: harden release signing boundary
z13321812367-sys Sep 4, 2026
c00f7ff
fix(storage): restore app config dir migration
z13321812367-sys Sep 4, 2026
80ffd5f
fix(storage): preserve existing app dir override during migration
z13321812367-sys Sep 4, 2026
7cf4484
fix(storage): enable Windows atomic replace API
z13321812367-sys Sep 4, 2026
370c664
fix(storage): make config writes durable and atomic
z13321812367-sys Sep 4, 2026
4643b53
style: rustfmt storage migration
z13321812367-sys Sep 4, 2026
e9c2d73
style: rustfmt atomic storage hardening
z13321812367-sys Sep 4, 2026
203b906
chore: stage branch hardening patch
z13321812367-sys Sep 4, 2026
a209cee
chore: add one-shot hardening patch driver
z13321812367-sys Sep 4, 2026
24a8aec
chore: run one-shot hardening patch
z13321812367-sys Sep 4, 2026
8d449b3
fix: close persistence and sensitive-input failure boundaries
github-actions[bot] Sep 4, 2026
20d97b2
chore: remove one-shot hardening workflow
z13321812367-sys Sep 4, 2026
5288900
chore: remove one-shot hardening workflow v2
z13321812367-sys Sep 4, 2026
63957cb
chore: remove one-shot hardening patch driver
z13321812367-sys Sep 4, 2026
54cfa7c
ci: enforce Rust failure-boundary policy
z13321812367-sys Sep 4, 2026
3518ff8
refactor: centralize auto-sync signal semantics
z13321812367-sys Sep 4, 2026
c1b1fdd
refactor: register shared auto-sync core
z13321812367-sys Sep 4, 2026
76d0951
chore: stage deep-link and auto-sync unification
z13321812367-sys Sep 4, 2026
f23a295
chore: run one-shot deep-link and auto-sync unification
z13321812367-sys Sep 4, 2026
05bcc28
fix: unify deep-link and auto-sync failure boundaries
github-actions[bot] Sep 4, 2026
7c90a64
chore: remove one-shot deep-link auto-sync workflow
z13321812367-sys Sep 4, 2026
e13e9e1
chore: remove one-shot deep-link auto-sync patch driver
z13321812367-sys Sep 4, 2026
ec1dc47
refactor: model proxy timeout semantics explicitly
z13321812367-sys Sep 4, 2026
225668c
refactor: register proxy timeout policy
z13321812367-sys Sep 4, 2026
77509d0
chore: stage explicit proxy timeout policy integration
z13321812367-sys Sep 4, 2026
23b41ea
chore: run self-cleaning timeout policy integration
z13321812367-sys Sep 4, 2026
f745c38
fix: make proxy timeout semantics explicit
github-actions[bot] Sep 4, 2026
7e9bfd4
chore: create one-shot audit source snapshot
z13321812367-sys Sep 4, 2026
04a65f5
chore: remove one-shot audit snapshot workflow
z13321812367-sys Sep 4, 2026
493b00a
chore: stage final global hardening patch driver
z13321812367-sys Sep 4, 2026
b8f734e
chore: run verified self-cleaning final hardening patch
z13321812367-sys Sep 4, 2026
74f7e0c
chore: add one-shot forwarder timeout test migration
z13321812367-sys Sep 4, 2026
010d5ba
ci: add one-shot forwarder timeout test fixer
z13321812367-sys Sep 4, 2026
c39bb42
ci: install native deps for timeout test fixer
z13321812367-sys Sep 4, 2026
c427376
test: align forwarder timeout helper with policy
github-actions[bot] Sep 4, 2026
67392ba
chore: remove one-shot timeout test migration
z13321812367-sys Sep 4, 2026
9dceffd
ci: remove one-shot timeout test fixer
z13321812367-sys Sep 4, 2026
748c778
ci: remove obsolete snippet helper in final hardening pass
z13321812367-sys Sep 4, 2026
51a2d3d
ci: remove stale body snippet test import
z13321812367-sys Sep 4, 2026
117ccc9
ci: normalize all-target Clippy baselines
z13321812367-sys Sep 4, 2026
c7acc5d
chore: capture final hardening test failure
z13321812367-sys Sep 5, 2026
19f25bb
ci: persist final hardening test diagnostics reliably
z13321812367-sys Sep 5, 2026
dcc244c
chore: capture final hardening test failure
github-actions[bot] Sep 5, 2026
1db5ea1
ci: align hardening diagnostics test with redaction boundary
z13321812367-sys Sep 5, 2026
d7c66cc
ci: fix final hardening workflow block syntax
z13321812367-sys Sep 5, 2026
725208a
fix: close global diagnostics and rollback failure boundaries
github-actions[bot] Sep 5, 2026
1a28704
ci: guard home and model-discovery failure boundaries
z13321812367-sys Sep 5, 2026
498c2d1
ci: apply final home and model candidate hardening
z13321812367-sys Sep 5, 2026
4023ced
ci: make home model hardening patch structure-aware
z13321812367-sys Sep 5, 2026
09a475c
ci: preserve config test imports during hardening
z13321812367-sys Sep 5, 2026
5ce8002
fix: fail closed home override and retry model candidates
github-actions[bot] Sep 5, 2026
e05f6ca
ci: centralize home directory resolution
z13321812367-sys Sep 5, 2026
c40a5d1
ci: unify remaining home resolution boundaries
z13321812367-sys Sep 5, 2026
fd09e78
ci: rerun unified home boundary migration
z13321812367-sys Sep 5, 2026
b98f83a
fix: centralize home resolution across persistence paths
github-actions[bot] Sep 5, 2026
0ba9387
chore: remove temporary home hardening workflow
z13321812367-sys Sep 5, 2026
69cd015
ci: add design invariant hardening driver
z13321812367-sys Sep 5, 2026
94af26f
ci: run design invariant hardening once
z13321812367-sys Sep 5, 2026
fccb1ab
ci: make design guard patch structure-aware
z13321812367-sys Sep 5, 2026
062716d
ci: separate design patch from policy patch
z13321812367-sys Sep 5, 2026
dcf430a
ci: extend design invariant hardening across fallible callers
z13321812367-sys Sep 5, 2026
11f31de
ci: make design invariant follow-up structural
z13321812367-sys Sep 5, 2026
4f9f348
ci: run structural design invariant hardening
z13321812367-sys Sep 5, 2026
3cfef8b
ci: align structural follow-up with both skill HOME callers
z13321812367-sys Sep 5, 2026
3235bc5
ci: normalize Windows raw path in design hardening
z13321812367-sys Sep 5, 2026
e53c6fc
ci: make Skill invariant guard exact
z13321812367-sys Sep 5, 2026
4193589
ci: verify OpenCode scan failure propagation
z13321812367-sys Sep 5, 2026
88f46dc
ci: encode Hermes fallible path boundary
z13321812367-sys Sep 5, 2026
84b9c8f
ci: verify Hermes fallible failure boundary
z13321812367-sys Sep 5, 2026
128d8b7
ci: scope Hermes write-path transform to production
z13321812367-sys Sep 5, 2026
bdeea57
ci: scope Hermes failure guards to production APIs
z13321812367-sys Sep 5, 2026
a30d554
ci: migrate Hermes fallible path callers
z13321812367-sys Sep 5, 2026
5db72d6
ci: guard Hermes fallible caller boundary
z13321812367-sys Sep 5, 2026
8aae1c5
ci: verify Hermes callers through fallible boundary
z13321812367-sys Sep 5, 2026
23de258
ci: cover both Hermes MCP write paths
z13321812367-sys Sep 5, 2026
5600202
ci: persist bounded default-test diagnostics
z13321812367-sys Sep 5, 2026
ee58f3d
ci: encode root failure semantics before test alignment
z13321812367-sys Sep 7, 2026
7d15380
ci: apply failure-semantics redesign before verification
z13321812367-sys Sep 7, 2026
674be7f
ci: fix typed root implementation without weakening semantics
z13321812367-sys Sep 7, 2026
201b6b8
ci: encode session structural failure semantics
z13321812367-sys Sep 7, 2026
8d4fa4f
ci: encode session dirty-history parse semantics
z13321812367-sys Sep 7, 2026
d8bc929
chore: add final design convergence stage
z13321812367-sys Sep 7, 2026
49b8d3d
chore: chain final root and session convergence
z13321812367-sys Sep 7, 2026
e0ab03f
fix: make final convergence matcher robust
z13321812367-sys Sep 7, 2026
4b6e42b
chore: retrigger final convergence workflow
z13321812367-sys Sep 7, 2026
4bac7ae
fix: align OpenClaw session parser migration
z13321812367-sys Sep 7, 2026
1726da0
chore: rerun convergence after OpenClaw driver fix
z13321812367-sys Sep 7, 2026
b07d620
fix: insert OpenClaw test adapter before index helper
z13321812367-sys Sep 7, 2026
a4f413b
fix: correct finalizer string quoting
z13321812367-sys Sep 7, 2026
8187223
chore: rerun convergence with corrected OpenClaw boundary
z13321812367-sys Sep 7, 2026
ca0a949
fix: consume structural scanner closing braces exactly once
z13321812367-sys Sep 7, 2026
9f92d3e
chore: rerun convergence after structural brace fix
z13321812367-sys Sep 7, 2026
d927438
chore: validate generated session function boundaries
z13321812367-sys Sep 7, 2026
e2b5715
chore: rerun convergence with generated-boundary diagnostics
z13321812367-sys Sep 7, 2026
68bc059
fix: make structural region replacement consume old function close
z13321812367-sys Sep 7, 2026
22837f3
chore: rerun convergence with deterministic structural replacement
z13321812367-sys Sep 7, 2026
7938cf4
fix: remove obsolete session parser compatibility wrappers
z13321812367-sys Sep 7, 2026
7277e0b
chore: retrigger verified convergence after session wrapper cleanup
z13321812367-sys Sep 7, 2026
4adb119
fix: make one-shot cleanup converge after verified migration
z13321812367-sys Sep 8, 2026
e4ffb05
fix: avoid duplicate one-shot helper cleanup
z13321812367-sys Sep 8, 2026
c3de758
fix: enforce typed persistence failure semantics
github-actions[bot] Sep 8, 2026
110e5fc
ci: verify cleaned hardening head
z13321812367-sys Sep 8, 2026
628fd27
ci: validate final durability boundaries once
z13321812367-sys Sep 9, 2026
c4e0865
ci: retrigger registered durability hardening
z13321812367-sys Sep 9, 2026
0668416
ci: make durability transform boundary-based
z13321812367-sys Sep 9, 2026
3f3b98f
ci: format generated durability changes before verification
z13321812367-sys Sep 9, 2026
84ad33e
ci: separate durability promotion from one-shot cleanup
z13321812367-sys Sep 9, 2026
6706b63
ci: export verified durability candidate
z13321812367-sys Sep 10, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 14 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,19 @@ concurrency:
cancel-in-progress: true

jobs:
workflow-policy:
name: Workflow Policy
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v6

- name: Reject unsafe shell interpolation
run: python scripts/check_workflow_shell_interpolation.py

- name: Check Rust failure boundaries
run: python scripts/check_rust_failure_boundaries.py

frontend:
name: Frontend Checks
runs-on: ubuntu-latest
Expand Down Expand Up @@ -96,4 +109,4 @@ jobs:
run: cargo clippy --manifest-path src-tauri/Cargo.toml -- -D warnings

- name: Run tests
run: cargo test --manifest-path src-tauri/Cargo.toml
run: cargo test --manifest-path src-tauri/Cargo.toml
162 changes: 162 additions & 0 deletions .github/workflows/final-durability-hardening-once.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,162 @@
name: Final Durability Hardening Once

on:
push:
branches: [fix/global-hardening-20260904]
paths:
- ".github/workflows/final-durability-hardening-once.yml"

permissions:
contents: read

jobs:
harden:
runs-on: ubuntu-22.04
steps:
- name: Checkout hardening branch
uses: actions/checkout@v6
with:
ref: fix/global-hardening-20260904
fetch-depth: 0

- name: Apply durability and cross-platform CI invariants
shell: bash
run: |
set -euo pipefail
python - <<'PY'
from pathlib import Path
import re

config_path = Path("src-tauri/src/config.rs")
config = config_path.read_text(encoding="utf-8")

old_contract = "/// - 任何写入/替换错误都会清理临时文件,旧目标保持不变(文件系统自身故障除外)。"
new_contract = """/// - 替换前的写入/替换失败会清理临时文件并保留旧目标;
/// - Unix 替换后必须同步父目录;目录同步失败返回错误,因为新内容可能已可见但持久化尚未确认。"""
if config.count(old_contract) != 1:
raise SystemExit(f"expected one atomic-write contract marker, found {config.count(old_contract)}")
config = config.replace(old_contract, new_contract)

start_marker = " #[cfg(unix)]\n if let Ok(directory) = fs::File::open(parent) {"
end_marker = "\n\n Ok(())\n}"
start = config.find(start_marker)
if start < 0:
raise SystemExit("atomic-write parent-sync start marker not found")
end = config.find(end_marker, start)
if end < 0:
raise SystemExit("atomic-write parent-sync end marker not found")
new_sync = ''' #[cfg(unix)]
{
let directory = fs::File::open(parent).map_err(|err| AppError::IoContext {
context: format!(
"无法打开父目录以确认原子写入持久化: {}",
parent.display()
),
source: err,
})?;
directory.sync_all().map_err(|err| AppError::IoContext {
context: format!(
"父目录同步失败,无法确认原子写入持久化(新内容可能已可见): {}",
parent.display()
),
source: err,
})?;
}'''
config = config[:start] + new_sync + config[end:]
config_path.write_text(config, encoding="utf-8")

policy_path = Path("scripts/check_rust_failure_boundaries.py")
policy = policy_path.read_text(encoding="utf-8")
marker = '''if 'let legacy_dir = PathBuf::from(trimmed).join(".cc-switch")' in config_text:
failures.append("src-tauri/src/config.rs: Windows legacy HOME must be validated before DB fallback")
'''
guard = '''if 'let legacy_dir = PathBuf::from(trimmed).join(".cc-switch")' in config_text:
failures.append("src-tauri/src/config.rs: Windows legacy HOME must be validated before DB fallback")

# A successful rename is not a durable commit on Unix until the parent directory entry is
# synced. Returning success after a directory-sync failure would recreate the same
# acknowledged-but-not-durable persistence failure class this hardening pass removes.
if not re.search(r"directory\\.sync_all\\(\\)\\.map_err", config_text):
failures.append(
"src-tauri/src/config.rs: atomic writes must propagate parent-directory durability sync failures"
)
'''
if policy.count(marker) != 1:
raise SystemExit(f"expected one policy insertion marker, found {policy.count(marker)}")
policy = policy.replace(marker, guard)
policy_path.write_text(policy, encoding="utf-8")

ci_path = Path(".github/workflows/ci.yml")
ci = ci_path.read_text(encoding="utf-8")
if "backend-windows:" in ci:
raise SystemExit("Windows backend gate already exists unexpectedly")
windows_job = '''

backend-windows:
name: Backend Windows Durability
runs-on: windows-latest
steps:
- name: Checkout
uses: actions/checkout@v6

- name: Setup Rust
uses: dtolnay/rust-toolchain@stable

- name: Create frontend dist placeholder
shell: pwsh
run: New-Item -ItemType Directory -Force dist | Out-Null

- name: Compile and link all Windows targets and features
run: cargo test --manifest-path src-tauri/Cargo.toml --all-targets --all-features --no-run

- name: Exercise Windows atomic replacement
run: cargo test --manifest-path src-tauri/Cargo.toml --all-features atomic_write_replaces_complete_file
'''
ci = ci.rstrip() + windows_job + "\n"
ci_path.write_text(ci, encoding="utf-8")
PY

- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
with:
components: rustfmt, clippy

- name: Install Linux system deps
run: |
sudo apt-get update
sudo apt-get install -y --no-install-recommends \
build-essential pkg-config libssl-dev \
libgtk-3-dev librsvg2-dev libayatana-appindicator3-dev
sudo apt-get install -y --no-install-recommends libwebkit2gtk-4.1-dev \
|| sudo apt-get install -y --no-install-recommends libwebkit2gtk-4.0-dev
sudo apt-get install -y --no-install-recommends libsoup-3.0-dev \
|| sudo apt-get install -y --no-install-recommends libsoup2.4-dev

- name: Create frontend dist placeholder
run: mkdir -p dist

- name: Check permanent failure boundaries
run: python scripts/check_rust_failure_boundaries.py

- name: Format generated Rust
run: cargo fmt --manifest-path src-tauri/Cargo.toml

- name: Check Rust formatting
run: cargo fmt --check --manifest-path src-tauri/Cargo.toml

- name: Strict Clippy
run: cargo clippy --manifest-path src-tauri/Cargo.toml --all-targets --all-features -- -D warnings

- name: Run all-feature Rust tests
run: cargo test --manifest-path src-tauri/Cargo.toml --all-features

- name: Export verified durability candidate
uses: actions/upload-artifact@v4
with:
name: verified-durability-candidate
path: |
src-tauri/src/config.rs
scripts/check_rust_failure_boundaries.py
.github/workflows/ci.yml
if-no-files-found: error
retention-days: 3
Loading
Loading