Pull Request已成功合入, 合并人@CANN-robot
(感谢 duanbingzhe 的贡献)Thanks for your pull-request.
The full list of commands accepted by me can be found at here.
You can get sig-info at here.
You can self-configure the PR merge rules for this repository. For more details, please refer to Here.
For more, you also can visit HICANN.
PR Approval Progress
✅ Congratulations! All modules have met the lgtm and approve requirements.
Module Approval Details
| module | lgtm status | approve status |
|---|---|---|
| repo-cann/cannbot-sentry | ✅ guanxinghua, hangdu (2/2) | ✅ guanxinghua (1/1) |
💡 Tip:
- Committer can comment
/approveor/lgtm- Commenting
/approveimplies both code review (lgtm) and intent to merge (approve)
CLA Signature Pass
duanbingzhe, thanks for your pull request. All authors of the commits have signed the CLA. 👍


/compile


| 🚀 CI 流水线已启动 |
|---|
| 📋 执行详情: 点击查看流水线 |


e.repoPath 被直接插进双引号 shell 字符串(git cat-file --filters --path="${e.repoPath}"),而 repoPath 来自 git ls-tree -r -z 的原始路径——-z 模式路径永不转义,除 NUL 外任意字节都可能出现。数据仓里一个名为 sub"; cmd; ".jsonl.gz 的文件即可在导入方机器上执行任意命令(LFS 模式导入时触发)。旧路径 git cat-file -p ${e.oid} 只插十六进制 oid 是安全的,这条是本 PR 新开的注入面;仓内其它拼 shell 的点(sid / prefix / branch / remote 地址)都做了白名单校验,这里建议对齐:改用 spawnSync argv 形式(['cat-file', '--filters', \--path={e.repoPath}\`, e.oid]`)彻底绕开 shell,或对 repoPath 加 `^[\w./-]+` 校验。


规则表与泄漏哨兵都只覆盖小写 b 的 "CANNbay",但源码里大量用户可见字符串硬编码的是大写 B 的 CANNBay(UploadToCannbayDialog.tsx 的「上传到 CANNBay」、SessionList.tsx / session 页的 title="Upload to CANNBay"、LocalFileImport.tsx 的 "Fetch from CANNBay"、cli/commands/upload.ts、tui/components/UploadPanel.tsx 等,均在发包清单内)。GLOBAL_RULES 对 .ts/.tsx 不含 CANNBay → context-insight 成品里 Bay 名一半是 contextBay(branding.ts 三元生效)、一半仍是 CANN 品牌;tests/context-pack.test.ts 的 forbidden 列表也没有 'CANNBay',哨兵测不出来。注意不能简单加全局 CANNBay→contextBay 规则:v1 路由 import-from-cannbay/route.ts / upload-session/route.ts 硬编码了 https://gitcode.com/guanxinghua/CANNBay.git 仓 URL,替换会断链。建议 UI 字符串改用 BAY_NAME 常量(源码级修复,两品牌同时受益),哨兵补扫 'CANNBay'(排除那两个 v1 路由文件或其中的 URL)。


同样的大写 B 缺口:CANNBay 规则只挂在 MD_RULES(仅 .md 生效),而 src 里有多处硬编码——src/cli/cpx-upload.ts:455 日志 'insight Web UI「CANNBay」列表可见'、src/cli/cpx-cli.ts 帮助文本的「无感上传 CANNBay」等,均随 files 白名单(src)进 context-cpx 成品;tests/context-pack.test.ts 的 forbidden 列表也只扫小写 'CANNbay'。cpx 源码里没有 CANNBay 形态的仓 URL(insight 侧才有 v1 URL 的坑),可以直接把 CANNBay → contextBay 提进 GLOBAL_RULES,哨兵同步补 'CANNBay' 扫描。


if (!fs.existsSync(gaPath)) 只在工作树无 .gitattributes 时才从 origin/main 物化,但同一镜像的工作树可能留有过期的剔除版:默认模式的 uploadFolder 会在本镜像 sparse-checkout 出的 .gitattributes 里剔除 filter=lfs 行并写回工作树(else if 分支),之后 cpx 以 LFS 模式上传会把该行重新加回 origin/main。此时 insight 侧设 CANNBAY2_LFS=1 导入指针会话:工作树 .gitattributes 存在但缺 *.gz filter=lfs 声明 → cat-file --filters 不做 smudge → LFS 指针文本被当作 gzip 内容落盘,导入在解压环节报出费解错误。建议与 ensureLfsGitattributes 的判定对齐:LFS 模式下只要工作树副本缺 ^\*\.gz\s+filter=lfs 声明就刷新(用 git show origin/main:.gitattributes 覆盖),而不是仅看文件是否存在。


/approve


/compile


| 🚀 CI 流水线已启动 |
|---|
| 📋 执行详情: 点击查看流水线 |


/compile


| 🚀 CI 流水线已启动 |
|---|
| 📋 执行详情: 点击查看流水线 |


概述
双包触达:insight v0.2.29、cpx v0.1.4(45 文件,+1822/-116)。
已变基最新 master(含上游测试目录迁移 tests/ut/ 适配)。
✨ 新增功能
CANNBAY2_LFS=1opt-in):.jsonl.gz以 LFS 指针出仓,容量脱离 git 仓 1GiB 配额(实测单会话最大 933MB);
insight 导入侧
cat-file --filters按需拉实体;缺省行为不变pack-context.mjs打包期品牌变换产出context-insight/context-cpx变体(字面量替换 + 泄漏哨兵 IT);格式契约不品牌化,两品牌数据互通
-v,输出品牌化版本串🔧 修复问题
挑战-应答,凭据经一次性 credential helper;pushMirror 统一 push 出口
检查排除 export-view 产物
governed标记失效,82MB 会话多耗 ~38s——修复后免解压直传
⚡ 性能优化
(3.8s → 0.4s)、合并请求 + 并发导入池
✅ 验证
insight 1595 用例、cpx 169 用例全过;版本三处单轨同步