test: keep release validation independent of dependency churn - #5489
Conversation
Signed-off-by: huangruiteng <huangrt01@163.com>
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewer: model_agent | GPT-6 | OpenAI
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
动机
维护者在源码工作区同时安装前端依赖和验证发布时,需要稳定检查真实源码与首次遥测告知。
npm 更换依赖目录时,旧源码扫描进入该目录并报文件消失;另一个测试仍要求旧告知版本而误判当前合法告知。修改后只扫描自有源码,并验证当前告知,同时继续拒绝首次告知发送统计。
51 项隔离测试通过;依赖目录即使不可扫描也不影响自有源码普查,自有源码不可读仍报错,首次 CLI JSON 告知与不发送约束保留。
本 PR 只修正发布验证,不改变 runtime、遥测默认开关、上传内容、权限、源码路由或前端行为,也不降低整版发布门禁。
改动思路
APPROVE,完整 head 90676df647fbc1bd5784e8e3b435aa8da20a51ae。最强反对理由是为了消除一次依赖文件消失就吞掉整个扫描的错误,从而漏掉真正的源码。当前设计在既有 _web_sources 中,使用标准库 top-down walk,在进入 node_modules 之前排除;onerror 仍抛出自有源码错误。没有并行扫描框架、runtime helper 或产品状态。
隐私测试独立写明版本 6 对应的安装画像与重叠时钟告知,不从实现常量读回作为 oracle。原有 JSON purity、不启动 sender、不记录发送/counter 状态的断言继续保留。这里是已复现的验证维护缺陷,无独立 traversal 规范;产品 route 与隐私约束由既有独立断言保持。
具体改动
两个文件 +46/-6 全部阅读。architecture 文件的 _web_sources 替换先 rglob 再过滤的错误顺序,按目录原地 prune,收集自有 .ts 后保持排序;node_modules 名字是既有目录范围,不是用 substring 猜语义状态。小 callback 专门保留 source I/O 错误边界,避免 os.walk 默认忽略失败。
新增两个耐久反例:真实 walk 旁放依赖目录,scandir 一旦进入它就模拟 concurrent replacement 的 FileNotFoundError,普查仍返回实际自有 route.ts;自有目录产生 PermissionError 时必须向上传播。原 route literal 与唯一 Python owner 普查仍执行,源码读失败不会因更宽异常处理变成通过。
source CLI entrypoint 文件只把过期 notice version 5 改为独立版本 6 并解释告知边界;实际 subprocess CLI、JSON parse、首次不发送和未记录发送状态的检查不变。源码工作区隔离 HOME/TMP 后真实运行 51 项测试,无失败或跳过;另一组 exact-head 重跑也通过,未继承提交前的 source identity。
对主干的风险
唯一的范围收窄是先前就声明不属于普查的依赖子树,现在在 I/O 之前排除。自有源码继续扫描,文件读取/parse 失败仍显式报错,生产 route 声明数量没有放宽。两个注入故障的测试只控制 filesystem error 的触发,不提供被检验的结果;生产 CLI 仍真实执行。没有新枚举、权限、Actor 名称、opt-in 契约或默认遥测改变,不需前端/Lark companion。
Ruff、diff、public-boundary、exact-scope quality 和 native premerge 通过;premerge 两项 selected、四项 direct,零 failure/hold。第一次 semantic check 因仓库根 typescript dev dependency 缺失失败,安装声明的 npm 工具链后同一检查真实通过,原失败保留。两项既有 registry warnings 与此测试 diff 无关;CI 根据 wait_for_ci=false 未查询。该结果不等于整版 Python、模型或发布产物资格已通过。
我的整体评价
APPROVE,无阻塞发现。已有测试被修复为验证真实源码和当前隐私行为,保留相反失败方向,不增加一次性 smoke、测试框架或运行时结构。未来结构评估已应用:在唯一局部 enumerator 前置排除,淘汰无效后过滤;与 #5474 的 HOME 隔离分属不同已复现失败,没有重复 product owner。限制是 native semantic scanner 仍需要声明的 npm dev tools。
English verdict: APPROVE - exact head 90676df; first-party census survives dependency churn while source errors remain visible; current CLI first-notice JSON/no-send contract retained; 51 exact-head tests, public boundary, quality and risk premerge passed. Test-only change.
Release validation could fail when npm concurrently replaced a dependency directory during the Chat route census, and the source CLI disclosure test still asserted notice version 5 after version 6 expanded the public privacy disclosure. Prune node_modules before traversal, keep first-party I/O errors visible, and independently pin version 6 while retaining JSON-purity and no-send assertions.
Focused validation: 51 tests pass, including dependency-churn and unreadable-source negative cases; changed-file Ruff and diff checks pass. No runtime, telemetry default, permission or frontend behavior changes. The existing route census remains authoritative for first-party spellings.
Native risk premerge and exact-scope quality now pass on head 90676df. The first semantic check failed because root npm dev dependencies were absent; npm ci --ignore-scripts restored the declared toolchain and the same check passed. Complete exact-head review and native ready=true were verified before the authorized merge: #5489 (review).