build(site): [SITE-07] verify embedded inspector and tokenizer sources

This commit is contained in:
Harvey Zhao committed 2026-09-15 07:34:42 +08:00
1 parent 199021c8a9
commit d2a83f8a69
24 files changed
+822 -21

No files matched your search

+3
View File
@@ -31,6 +31,9 @@ test('mobile vConsole shows logs and upstream site notice texts are served uncha
expect(await index.text()).toContain('Included component: @vscode/codicons 0.0.26')
expect(await index.text()).toContain('Included component: console-feed 3.2.2')
expect(await index.text()).toContain('Included component: chromium-string-utils')
expect(await index.text()).toContain('Included component: @babel/runtime (react-inspector embedded) 7.13.10')
expect(await index.text()).toContain('Included component: regenerator-runtime 0.13.7')
expect(await index.text()).toContain('Included component: simple-html-tokenizer git-04799f4638ec5ed903a4e5aa6e832269fa59be6b')
expect(await index.text()).toContain('Embedded attribution review is still incomplete')
await page.evaluate(() => {
window.vConsole.destroy()
+36
View File
@@ -8,12 +8,48 @@ import test from 'node:test'
import ts from 'typescript'
import { generateConsole, moduleRanges, obsoleteMap, upstreamSha256 } from '../scripts/site-vendor/console/build.ts'
import { extractNotice } from '../scripts/site-vendor/console/embedded-notices.ts'
import { verifyMappedSources, verifyTransformedSources } from '../scripts/site-vendor/console/embedded-sources.ts'
import { hash, parcelModules, verifyArchive, verifyModules, verifyPackageEdges } from '../scripts/site-vendor/console/provenance.ts'
import { reconstructModule, verifyPrelude } from '../scripts/site-vendor/console/reconstruction.ts'
import { errorArgument } from '../scripts/site-vendor/console/runtime/errors.ts'
import { css } from '../scripts/site-vendor/console/runtime/style.ts'
import { createSubscriptions } from '../scripts/site-vendor/console/runtime/subscriptions.ts'
test('Embedded source maps reject omitted dependencies and content from a different release', () => {
const upstream = Buffer.from('export const value = 1;\n')
const map = { sources: ['../../src/owned.js', '../../node_modules/library/index.js'], sourcesContent: ['owned', upstream.toString()] }
let mapBytes = Buffer.from(JSON.stringify(map))
const record = { source: { archive: 'parent', member: 'index.js.map', sha256: hash(mapBytes) }, externalPrefix: '../../node_modules/', sources: [{ path: map.sources[1], upstream: { archive: 'library', member: 'index.js', sha256: hash(upstream) } }] }
const read = member => member.archive === 'parent' ? mapBytes : upstream
assert.equal(verifyMappedSources(record, read), 1)
assert.throws(() => verifyMappedSources({ ...record, sources: [] }, read), /Empty embedded/)
assert.throws(() => verifyMappedSources({ ...record, sources: [...record.sources, ...record.sources] }, read), /Duplicate/)
const changed = Buffer.from('export const value = 2;\n')
const otherVersion = structuredClone(record)
otherVersion.sources[0].upstream.sha256 = hash(changed)
assert.throws(() => verifyMappedSources(otherVersion, member => member.archive === 'parent' ? mapBytes : changed), /content differs/)
for (const changedMap of [
{ ...map, sources: [...map.sources, '../../node_modules/hidden/index.js'], sourcesContent: [...map.sourcesContent, 'hidden'] },
{ ...map, sourcesContent: ['owned', null] },
]) {
mapBytes = Buffer.from(JSON.stringify(changedMap))
assert.throws(() => verifyMappedSources({ ...record, source: { ...record.source, sha256: hash(mapBytes) } }, read), /inventory changed|content differs/)
}
})
test('Embedded transforms compare exact target bytes and reject duplicate or altered evidence', () => {
const input = Buffer.from('export const value = 1;')
const output = Buffer.from('exports.value = 1;')
const source = { archive: 'upstream', member: 'index.js', sha256: hash(input) }
const target = { archive: 'consumer', member: 'index.js', sha256: hash(output) }
const read = member => member.archive === 'upstream' ? input : output
const transform = () => output.toString()
assert.equal(verifyTransformedSources([{ source, target }], read, transform), 1)
assert.throws(() => verifyTransformedSources([{ source, target }], read, () => `${output}\n`), /transform differs/)
assert.throws(() => verifyTransformedSources([{ source: { ...source, sha256: hash('changed') }, target }], read, transform), /member changed/)
assert.throws(() => verifyTransformedSources([{ source, target }, { source, target }], read, transform), /Duplicate/)
})
test('Embedded notices retain exact headers and reject missing or changed mapped sources', () => {
const source = '// Copyright owner\n// Full permission and disclaimer.\nconst value = 1;'
const text = '// Copyright owner\n// Full permission and disclaimer.\n'
+1 -1
View File
@@ -111,7 +111,7 @@ test('Console notice CLI rejects omitted package or embedded attribution before
const manifestPath = path.join(root, 'scripts/site-vendor/manifest.json')
fs.mkdirSync(path.dirname(manifestPath), { recursive: true })
const original = JSON.parse(fs.readFileSync('scripts/site-vendor/manifest.json', 'utf8'))
for (const name of ['console-feed', 'parcel-bundler', 'styled-components', 'chromium-string-utils', 'stylis-rule-sheet']) {
for (const name of ['console-feed', 'parcel-bundler', 'styled-components', 'chromium-string-utils', 'stylis-rule-sheet', '@babel/runtime (react-inspector embedded)', 'regenerator-runtime', 'simple-html-tokenizer']) {
for (const field of ['components', 'notices']) {
const manifest = structuredClone(original)
const group = manifest.groups.find(group => group.name === 'console')