已合并
[feat] insight v0.2.29 / cpx v0.1.4: CANNBay LFS 上传模式 + context 双名发布;修复 push 鉴权与构建缓存误判 #14
duanbingzhe创建于 19 天前
[feat] insight v0.2.29 / cpx v0.1.4: CANNBay LFS 上传模式 + context 双名发布;修复 push 鉴权与构建缓存误判 #14
已合并
duanbingzhe创建于 19 天前
duanbingzhe成员
19 天前

概述

双包触达:insight v0.2.29、cpx v0.1.4(45 文件,+1822/-116)。
已变基最新 master(含上游测试目录迁移 tests/ut/ 适配)。

✨ 新增功能

  • CANNBay LFS 上传模式(双包实现,CANNBAY2_LFS=1 opt-in):.jsonl.gz
    以 LFS 指针出仓,容量脱离 git 仓 1GiB 配额(实测单会话最大 933MB);
    insight 导入侧 cat-file --filters 按需拉实体;缺省行为不变
  • context 双名发布:pack-context.mjs 打包期品牌变换产出
    context-insight / context-cpx 变体(字面量替换 + 泄漏哨兵 IT);
    格式契约不品牌化,两品牌数据互通
  • CLI 版本旗标:insight 补 -v,输出品牌化版本串

🔧 修复问题

  • CANNBay push 鉴权失败:pushUrl 内嵌凭据被 atomgit 拒绝——改 401
    挑战-应答,凭据经一次性 credential helper;pushMirror 统一 push 出口
  • start.sh 构建缓存误判:每次启动 ~15s 无谓全量重建——staleness
    检查排除 export-view 产物
  • cpx 治理快路径失效:meta 路径误传致 governed 标记失效,82MB 会话
    多耗 ~38s——修复后免解压直传

⚡ 性能优化

  • cannbay2 读路径提速:blob 批量预取(列表首开 120s → ~10s)、分批物化
    (3.8s → 0.4s)、合并请求 + 并发导入池

✅ 验证

insight 1595 用例、cpx 169 用例全过;版本三处单轨同步

likedislike
Pull Request已成功合入, 合并人@CANN-robot
(感谢 duanbingzhe 的贡献)
Dduanbingzhe成员
19 天前 创建了 pull request,commit 5c860545
CANN-robotCANN-robot成员
19 天前 添加了label:stat/needs-squash
CANN-robotCANN-robot成员
19 天前 添加了label:cann-cla/yes
CANN-robot
CANN-robot成员
19 天前 评论:

Thanks for your pull-request.
The full list of commands accepted by me can be found at here.
You can get sig-info at here.
You can self-configure the PR merge rules for this repository. For more details, please refer to Here.
For more, you also can visit HICANN.


PR Approval Progress

✅ Congratulations! All modules have met the lgtm and approve requirements.

Module Approval Details

module lgtm status approve status
repo-cann/cannbot-sentry ✅ guanxinghua, hangdu (2/2) ✅ guanxinghua (1/1)

💡 Tip:

  • Committer can comment /approve or /lgtm
  • Commenting /approve implies both code review (lgtm) and intent to merge (approve)

CLA Signature Pass

duanbingzhe, thanks for your pull request. All authors of the commits have signed the CLA. 👍

likedislike
Dduanbingzhe成员
19 天前 关联了issue:[Feature]:压缩超限无法上传
duanbingzhe成员
19 天前 评论:

/compile

likedislike
Dduanbingzhe成员
19 天前 预合并成功(commit_id: 443e84af6ca886e7682f874ff49fd14729a312ed)
CANN-robot
CANN-robot成员
19 天前 评论:
🚀 CI 流水线已启动
📋 执行详情: 点击查看流水线
likedislike
CANN-robotCANN-robot成员
19 天前 添加了label:ci-pipeline-running
CANN-robotCANN-robot成员
19 天前 删除了label:ci-pipeline-running
CANN-robotCANN-robot成员
19 天前 添加了label:ci-pipeline-passed
hangdu成员19 天前进行代码检视2
packages/insight/src/lib/cannbay2/mirror.ts
已过期
@@ -496,0 +621,4 @@
621+ const rel = targetRelOf(e.repoPath.slice(prefix.length));
622+ const target = path.join(dir, 'materialized', rel);
623+ fs.mkdirSync(path.dirname(target), { recursive: true });
624+ fs.writeFileSync(target, runGit(`git cat-file --filters --path="${e.repoPath}" ${e.oid}`, dir, 300_000, { raw: true }));
hangdu19 天前评论:

e.repoPath 被直接插进双引号 shell 字符串(git cat-file --filters --path="${e.repoPath}"),而 repoPath 来自 git ls-tree -r -z 的原始路径——-z 模式路径永不转义,除 NUL 外任意字节都可能出现。数据仓里一个名为 sub"; cmd; ".jsonl.gz 的文件即可在导入方机器上执行任意命令(LFS 模式导入时触发)。旧路径 git cat-file -p ${e.oid} 只插十六进制 oid 是安全的,这条是本 PR 新开的注入面;仓内其它拼 shell 的点(sid / prefix / branch / remote 地址)都做了白名单校验,这里建议对齐:改用 spawnSync argv 形式(['cat-file', '--filters', \--path={e.repoPath}\`, e.oid]`)彻底绕开 shell,或对 repoPath 加 `^[\w./-]+` 校验。

likedislike
System
系统消息系统
19 天前 评论:

changed this line on dd9b1179 view diff detail

hangdu成员19 天前进行代码检视1
packages/insight/scripts/pack-context.mjs
@@ -0,0 +44,4 @@
44+// 通用规则(全部文本文件;精确字符串替换,非正则)
45+const GLOBAL_RULES = [
46+ { find: 'CANNBot-Insight', replace: 'Context-Insight', minHits: 1 },
47+ { find: '"CANNbay"', replace: '"contextBay"', minHits: 1 },
hangdu19 天前评论:

规则表与泄漏哨兵都只覆盖小写 b 的 "CANNbay",但源码里大量用户可见字符串硬编码的是大写 B 的 CANNBay(UploadToCannbayDialog.tsx 的「上传到 CANNBay」、SessionList.tsx / session 页的 title="Upload to CANNBay"、LocalFileImport.tsx 的 "Fetch from CANNBay"、cli/commands/upload.ts、tui/components/UploadPanel.tsx 等,均在发包清单内)。GLOBAL_RULES 对 .ts/.tsx 不含 CANNBay → context-insight 成品里 Bay 名一半是 contextBay(branding.ts 三元生效)、一半仍是 CANN 品牌;tests/context-pack.test.ts 的 forbidden 列表也没有 'CANNBay',哨兵测不出来。注意不能简单加全局 CANNBay→contextBay 规则:v1 路由 import-from-cannbay/route.ts / upload-session/route.ts 硬编码了 https://gitcode.com/guanxinghua/CANNBay.git 仓 URL,替换会断链。建议 UI 字符串改用 BAY_NAME 常量(源码级修复,两品牌同时受益),哨兵补扫 'CANNBay'(排除那两个 v1 路由文件或其中的 URL)。

likedislike
hangdu成员19 天前进行代码检视2
packages/cpx/scripts/pack-context.mjs
已过期
@@ -0,0 +48,4 @@
48+const MD_RULES = [
49+ { find: 'cannbot-proxy', replace: 'context-cpx', minHits: 1 },
50+ { find: 'cannbot-insight', replace: 'context-insight', minHits: 1 },
51+ { find: 'CANNBay', replace: 'contextBay', minHits: 0 },
hangdu19 天前评论:

同样的大写 B 缺口:CANNBay 规则只挂在 MD_RULES(仅 .md 生效),而 src 里有多处硬编码——src/cli/cpx-upload.ts:455 日志 'insight Web UI「CANNBay」列表可见'、src/cli/cpx-cli.ts 帮助文本的「无感上传 CANNBay」等,均随 files 白名单(src)进 context-cpx 成品;tests/context-pack.test.ts 的 forbidden 列表也只扫小写 'CANNbay'。cpx 源码里没有 CANNBay 形态的仓 URL(insight 侧才有 v1 URL 的坑),可以直接把 CANNBay → contextBay 提进 GLOBAL_RULES,哨兵同步补 'CANNBay' 扫描。

likedislike
System
系统消息系统
19 天前 评论:

changed this line on dd9b1179 view diff detail

Dduanbingzhe成员
19 天前 预合并成功(commit_id: 51ae889ab19fd43c999e5ca3297b1a99fe9eccc2)
Dduanbingzhe成员
19 天前 推送  2 个提交:a5e3b5c1-[test] 变基遗留测试归位:tests/ 根 5 个用例迁入 tests/ut/(context-pack 品牌哨兵 ×2 / cannbay2-lfs / cannbay2-prefetch / cannbay-lfs),相对导入与 PKG_DIR 定位加深一层——vitest 只收 ut/e2e,遗落根下等于静默失收集,dd9b1179-[fix] 双名发布品牌面与 LFS 导入安全加固(PR #14 审查意见):mirror.ts cat-file --filters 改 spawnSync argv——repoPath 出自 ls-tree -z 原始输出可含任意字节,内插 shell 双引号即命令注入面(IT 新增注入探针用例负向验证:旧实现真实执行注入命令);insight UI 字符串全部改 BAY_NAME 常量(上传按钮/弹窗/CLI/TUI/导入向导/v1 路由错误消息,仓 URL 保留),哨兵补扫 CANNBay(v1 仓 URL 豁免),重建 export-view bundle;cpx CANNBay/CANNbay 提进 GLOBAL_RULES + 哨兵同步;修复变基漏适配的 e2e fixture 路径(tests/ut/data)
Dduanbingzhe成员
19 天前 预合并成功(commit_id: 48606d122dd0883147834147c7e81a781474c379)
CANN-robotCANN-robot成员
19 天前 删除了label:cann-cla/yes
CANN-robotCANN-robot成员
19 天前 删除了label:ci-pipeline-passed
CANN-robot
CANN-robot成员
19 天前 评论:

Notification

This pull request has been changed(code update) or closed, so removes the following label(s): ci-pipeline-passed.

likedislike
CANN-robotCANN-robot成员
19 天前 添加了label:cann-cla/yes
Dduanbingzhe成员
19 天前 解决了最后一个问题
hangdu成员19 天前进行代码检视2
packages/insight/src/lib/cannbay2/mirror.ts
@@ -465,0 +578,4 @@
578+ // 按需拉取 LFS 实体(本地 .git/lfs/objects 缓存,重复导入零下载)。
579+ // --filters 的属性解析读工作树 .gitattributes——读路径镜像默认无 checkout,
580+ // 需从 origin/main 物化一份(上传路径的 sparse 流程本就含 /.gitattributes)。
581+ if (remote.lfs) {
hangdu19 天前评论:

if (!fs.existsSync(gaPath)) 只在工作树无 .gitattributes 时才从 origin/main 物化,但同一镜像的工作树可能留有过期的剔除版:默认模式的 uploadFolder 会在本镜像 sparse-checkout 出的 .gitattributes 里剔除 filter=lfs 行并写回工作树(else if 分支),之后 cpx 以 LFS 模式上传会把该行重新加回 origin/main。此时 insight 侧设 CANNBAY2_LFS=1 导入指针会话:工作树 .gitattributes 存在但缺 *.gz filter=lfs 声明 → cat-file --filters 不做 smudge → LFS 指针文本被当作 gzip 内容落盘,导入在解压环节报出费解错误。建议与 ensureLfsGitattributes 的判定对齐:LFS 模式下只要工作树副本缺 ^\*\.gz\s+filter=lfs 声明就刷新(用 git show origin/main:.gitattributes 覆盖),而不是仅看文件是否存在。

likedislike
hangdu成员
19 天前 评论:

已在 head(3ab1202)验证修复:materializeSession 判定对齐 ensureLfsGitattributes——缺 *.gz filter=lfs 声明即从 origin/main 刷新,不再仅看文件存在;IT ⑥(cannbay2-lfs.test.ts)完整复现过期副本序列并断言实体字节恢复(本机无 git-lfs 该组按设计跳过,CI 已覆盖)。

Dduanbingzhe成员
19 天前 预合并成功(commit_id: 533915eaa5d06d6c1570b9dea593b14c6336f75c)
Dduanbingzhe成员
19 天前 推送  1 个提交:3ab12027-[fix] LFS 导入 .gitattributes 过期副本自动刷新(PR #14 审查意见):materializeSession 判定对齐 ensureLfsGitattributes——缺 *.gz filter=lfs 声明即从 origin/main 刷新(非仅看文件存在),堵住默认模式上传剔除过 lfs 行的副本残留导致 --filters 不做 smudge、指针文本被当 gzip 落盘的路径;IT ⑥ 回归锁复现过期副本序列,负向验证旧判定真实失败
Dduanbingzhe成员
19 天前 预合并成功(commit_id: ae5b2030dc238c49c7d623f56ff444b90dd33a63)
CANN-robotCANN-robot成员
19 天前 删除了label:cann-cla/yes
CANN-robotCANN-robot成员
19 天前 添加了label:cann-cla/yes
Hhangdu成员
19 天前 解决了最后一个问题
guanxinghua成员
19 天前 评论:

/approve

likedislike
CANN-robotCANN-robot成员
19 天前 添加了label:approved
hangdu成员
19 天前 评论:

/lgtm

likedislike
CANN-robotCANN-robot成员
19 天前 添加了label:lgtm
duanbingzhe成员
19 天前 评论:

/compile

likedislike
Dduanbingzhe成员
19 天前 预合并成功(commit_id: 2ad86d853288e0bdd01277da0c23947d8e5a6b40)
CANN-robot
CANN-robot成员
19 天前 评论:
🚀 CI 流水线已启动
📋 执行详情: 点击查看流水线
likedislike
CANN-robotCANN-robot成员
19 天前 添加了label:ci-pipeline-running
CANN-robotCANN-robot成员
19 天前 删除了label:ci-pipeline-running
CANN-robotCANN-robot成员
19 天前 添加了label:ci-pipeline-failed
duanbingzhe成员
19 天前 评论:

/compile

likedislike
CANN-robot
CANN-robot成员
19 天前 评论:
🚀 CI 流水线已启动
📋 执行详情: 点击查看流水线
likedislike
CANN-robotCANN-robot成员
19 天前 删除了label:ci-pipeline-failed
CANN-robotCANN-robot成员
19 天前 添加了label:ci-pipeline-running
CANN-robotCANN-robot成员
19 天前 删除了label:ci-pipeline-running
CANN-robotCANN-robot成员
19 天前 添加了label:ci-pipeline-passed
CANN-robotCANN-robot成员
19 天前 关闭了关联的issue
CANN-robotCANN-robot成员
19 天前 合入了pull request