feat(config): 涉密内容外置到配置目录(档案 140)

把散落在代码里的真实部署值统一收进 config/,代码改为引用配置,
使仓库副本/开源导出不再带出生产域名、IP、内网路径与凭据。

新增 config/:platform.env.example(模板)· load.sh(shell 加载器)·
index.cjs(node 加载器)· README.md(键一览与优先级)。
真实值放 config/platform.env —— 已 .gitignore 排除,不入库、不进导出。

TS 侧新增 src/platform-paths.ts 作部署路径的唯一解析处(零副作用):
platformDir/stateDir/backupDir/artifactDir/installDir/scriptPath。
config.ts 接入这些字段;内置中继种子由生产 URL 改为空(改由
DSHS_OVERLAY_BOOTSTRAP_SEEDS 提供)。修掉 5 处硬编码绝对路径,
src/** 注释中性化 116 行/53 文件。

scripts/** 36 个内部运维脚本:真令牌/PG 口令/隧道目标/主机号/路径
一律改从配置取;web/wake.html 的注册域白名单改为运行时从
location.hostname 推导;test/** 夹具 119 行/13 文件改 RFC 2606/5737
保留值,并把「内置种子必须为空」固化为回归断言。

取证:tsc 0 错;npm test 373/375(唯一失败 lease 属既有);
全仓扫描(大小写不敏感)代码面涉密标识 = 0;已部署 47 并零回归
(/opt/dsh/* 未搬家,/var/lib/dshs/platform 未被误建)。
This commit is contained in:
admin committed 2026-09-19 15:12:19 +08:00
1 parent 9c2e7975ac
commit 452924d89c
100 files changed
+1167 -453

No files matched your search

+29 -24
View File
@@ -126,7 +126,7 @@ function refusingFetch(calls) {
test('B1 纯函数:载荷稳定、路径派生、地址清洗', () => {
// 同源约定:引导地址(中继入口)→ 目录端点 = 同 origin + 固定路径
assert.equal(directoryUrlFor('https://ai1net.com/dshs-relay'), `https://ai1net.com${DIRECTORY_PATH}`)
assert.equal(directoryUrlFor('https://example.net/dshs-relay'), `https://example.net${DIRECTORY_PATH}`)
assert.equal(directoryUrlFor('http://127.0.0.1:8080/dshs-relay'), `http://127.0.0.1:8080${DIRECTORY_PATH}`)
// 已经是目录地址 ⇒ 原样
assert.equal(directoryUrlFor(`https://a.example${DIRECTORY_PATH}`), `https://a.example${DIRECTORY_PATH}`)
@@ -134,7 +134,7 @@ test('B1 纯函数:载荷稳定、路径派生、地址清洗', () => {
assert.equal(directoryUrlFor('wss://a.example/dshs-relay'), `https://a.example${DIRECTORY_PATH}`)
// 中继地址归一化:只改协议、⛔ 不动 path(`/dshs-relay` 是 nginx location 的判据)
assert.equal(toRelayUrl('https://ai1net.com/dshs-relay'), 'wss://ai1net.com/dshs-relay')
assert.equal(toRelayUrl('https://example.net/dshs-relay'), 'wss://example.net/dshs-relay')
assert.equal(toRelayUrl('http://127.0.0.1:20080/dshs-relay'), 'ws://127.0.0.1:20080/dshs-relay')
assert.equal(toRelayUrl('wss://a.example/x'), 'wss://a.example/x')
assert.equal(toRelayUrl('file:///etc/passwd'), undefined, '非 http/ws 协议必须拒绝')
@@ -178,20 +178,21 @@ test('B1 纯函数:载荷稳定、路径派生、地址清洗', () => {
'http://100.64.7.7/dshs-relay',
'http://relaybox/dshs-relay',
'http://[::1]/dshs-relay',
'https://ai1net.com/dshs-relay',
'https://example.net/dshs-relay',
'https://relay.example.com/dshs-relay',
]),
['https://ai1net.com/dshs-relay', 'https://relay.example.com/dshs-relay'],
['https://example.net/dshs-relay', 'https://relay.example.com/dshs-relay'],
)
// 常量位:只锚一条、指向**已持证书的门户**(第二地域留空 ⇒ 不新增域名成本)
assert.equal(DEFAULT_OVERLAY_SEED, 'https://ai1net.com/dshs-relay')
// ⛔ 内置种子**刻意留空** —— 种子是**具体部署的入口地址**,一律由配置提供
// (`DSHS_OVERLAY_BOOTSTRAP_SEEDS`,见 `config/platform.env`)⇒ 代码内不留真实域名。
assert.equal(DEFAULT_OVERLAY_SEED, '', '内置种子不得写死生产域名')
// 语义去重:`wss://host/dshs-relay` 与 `https://host/dshs-relay` 是**同一个端点**(都走 443)
// ⇒ 目录里只该出现第一条(否则读目录的人会以为有两个中继)
assert.deepEqual(
publicRelayEntries(['wss://ai1net.com/dshs-relay', 'https://ai1net.com/dshs-relay']),
['wss://ai1net.com/dshs-relay'],
publicRelayEntries(['wss://example.net/dshs-relay', 'https://example.net/dshs-relay']),
['wss://example.net/dshs-relay'],
)
// …而 `http://`(80)与 `wss://`(443)**不是**同一个端点 ⇒ 两条都留
assert.deepEqual(publicRelayEntries(['wss://a.example/x', 'http://a.example/x']), [
@@ -210,7 +211,7 @@ test('B1 纯函数:载荷稳定、路径派生、地址清洗', () => {
test('B2 验签:正例通过;改内容 / 换密钥 / 无受信密钥一律拒绝', () => {
const keys = makeKeys()
const other = makeKeys()
const origin = 'https://ai1net.com/dshs-relay'
const origin = 'https://example.net/dshs-relay'
const { doc, sig } = signedDoc(origin, keys.privatePem)
// 正例:PEM 与**裸 32 字节 hex**两条解析路径都要能验
@@ -248,7 +249,7 @@ test('B2 验签:正例通过;改内容 / 换密钥 / 无受信密钥一律
test('B3 决策:env 压制一切 / 新鲜缓存不联网 / 取不到则降级', async () => {
const keys = makeKeys()
const seed = 'https://ai1net.com/dshs-relay'
const seed = 'https://example.net/dshs-relay'
// ① env 显式 ⇒ 压制引导链(**一次网络都不发**)
{
@@ -279,7 +280,7 @@ test('B3 决策:env 压制一切 / 新鲜缓存不联网 / 取不到则降级'
fetchImpl: refusingFetch(calls),
})
assert.equal(r.source, 'cache')
assert.equal(r.url, 'wss://ai1net.com/dshs-relay')
assert.equal(r.url, 'wss://example.net/dshs-relay')
assert.deepEqual(calls, [], '新鲜缓存不许联网')
} finally {
rmSync(dir, { recursive: true, force: true })
@@ -298,7 +299,7 @@ test('B3 决策:env 压制一切 / 新鲜缓存不联网 / 取不到则降级'
fetchImpl: refusingFetch(calls),
})
assert.equal(r.source, 'seed-fallback')
assert.equal(r.url, 'wss://ai1net.com/dshs-relay')
assert.equal(r.url, 'wss://example.net/dshs-relay')
assert.ok(calls.length >= 1, '应当尝试过取目录')
assert.equal(existsSync(file), false, '取不到目录**不许**留下缓存')
} finally {
@@ -320,7 +321,7 @@ test('B3 决策:env 压制一切 / 新鲜缓存不联网 / 取不到则降级'
fetchImpl: refusingFetch([]),
})
assert.equal(r.source, 'stale-cache')
assert.equal(r.url, 'wss://ai1net.com/dshs-relay')
assert.equal(r.url, 'wss://example.net/dshs-relay')
// 缓存**被改坏 / 换了密钥** ⇒ 当作没有缓存(读也要验签)
assert.equal(readCachedDirectory(file, [makeKeys().publicPem], Date.now()), undefined)
} finally {
@@ -496,13 +497,16 @@ test('B6 签名不对的目录:既不写缓存也不采用(有旧缓存则
test('B7 端点契约:只公布公网地址、签名可被受信公钥验过、无密钥即不可用', async () => {
const keys = makeKeys()
// 夹具用引导地址(RFC 2606 保留域):**不等于**内置种子常量 ——
// 后者刻意留空(生产入口地址一律由配置提供),所以这里必须自带一个公网形态的夹具。
const FIXTURE_SEED = 'https://relay.example.net/dshs-relay'
// 服务端逻辑:候选 = 显式中继入口 + 种子;**过滤回环/私网**后再组装
const relays = publicRelayEntries(['ws://127.0.0.1:20080/dshs-relay', DEFAULT_OVERLAY_SEED])
const bootstrap = publicRelayEntries([DEFAULT_OVERLAY_SEED])
const relays = publicRelayEntries(['ws://127.0.0.1:20080/dshs-relay', FIXTURE_SEED])
const bootstrap = publicRelayEntries([FIXTURE_SEED])
const doc = buildDirectoryDocument({ relays, bootstrap, network: 'ops', now: Date.now() })
const sig = signDirectory(doc, keys.privatePem)
assert.deepEqual(relays, [DEFAULT_OVERLAY_SEED], '回环地址不得出现在目录里')
assert.deepEqual(relays, [FIXTURE_SEED], '回环地址不得出现在目录里')
assert.deepEqual(Object.keys(doc).sort(), [
'bootstrap',
'issuedAt',
@@ -539,7 +543,8 @@ test('S0 夹具自检:缓存读写是字节级可复现的(避免"测试夹
const { dir, file } = tmpCacheFile()
try {
const now = Date.now()
const { doc, sig } = signedDoc(DEFAULT_OVERLAY_SEED, keys.privatePem, { now })
const FIXTURE_SEED = 'https://relay.example.net/dshs-relay'
const { doc, sig } = signedDoc(FIXTURE_SEED, keys.privatePem, { now })
writeCachedDirectory(file, doc, sig, now)
const raw = readFileSync(file, 'utf8')
const parsed = JSON.parse(raw)
@@ -685,8 +690,8 @@ test('序④·L1-E 撤销后回到未配状态(可回滚)', async () => {
* **同源优先**(序④):没有它,「多一条兜底入口」落不成「CF / 门户 conf 挂时还能连」——
* `relays[]` 首位 = 主入口,客户端会一直去连它,兜底项永远轮不到。
*/
const FB_MAIN = 'https://ai1net.com/dshs-relay'
const FB_ALT = 'https://relay-direct.ai1net.com/dshs-relay'
const FB_MAIN = 'https://example.net/dshs-relay'
const FB_ALT = 'https://relay-direct.example.net/dshs-relay'
/** 造一份"两个入口都在"的目录,并只让**兜底 origin** 答得出(主 origin 抛错)。 */
function twoEntryDoc(keys) {
@@ -704,7 +709,7 @@ test('序④·L1-F 同源优先:主 origin 不可达时采用兜底 origin 的
const logs = []
const fetchImpl = async (url) => {
calls.push(String(url))
if (String(url).startsWith('https://ai1net.com/')) throw new Error('cf unreachable')
if (String(url).startsWith('https://example.net/')) throw new Error('cf unreachable')
return new Response(body, { status: 200, headers: { 'content-type': 'application/json' } })
}
const r = await resolveOverlayRelay({
@@ -717,14 +722,14 @@ test('序④·L1-F 同源优先:主 origin 不可达时采用兜底 origin 的
// ① 逐个 origin 试,主 origin 被拒后才到兜底
assert.equal(calls.length, 2)
assert.ok(
logs.some((l) => l.includes('拒绝 https://ai1net.com/dshs-overlay/bootstrap')),
logs.some((l) => l.includes('拒绝 https://example.net/dshs-overlay/bootstrap')),
'缺"逐 origin 拒绝原因"这一行',
)
// ② 采用的是**兜底项**,而不是 relays[] 首位(这是本单 D6 的实质判据)
assert.equal(r.source, 'seed-directory')
assert.equal(r.url, 'wss://relay-direct.ai1net.com/dshs-relay')
assert.equal(r.url, 'wss://relay-direct.example.net/dshs-relay')
assert.ok(
logs.some((l) => l.includes('同源优先') && l.includes('wss://relay-direct.ai1net.com/dshs-relay')),
logs.some((l) => l.includes('同源优先') && l.includes('wss://relay-direct.example.net/dshs-relay')),
'缺"为什么走了兜底"这一行(可解释性)',
)
})
@@ -742,6 +747,6 @@ test('序④·L1-G 主 origin 通时选择与今天逐字一致(relays[] 首
fetchImpl,
log: (l) => logs.push(l),
})
assert.equal(r.url, 'wss://ai1net.com/dshs-relay')
assert.equal(r.url, 'wss://example.net/dshs-relay')
assert.equal(logs.some((l) => l.includes('同源优先')), false, '首位命中时不该有多余日志')
})