feat(config): 涉密内容外置到配置目录(档案 140)
把散落在代码里的真实部署值统一收进 config/,代码改为引用配置, 使仓库副本/开源导出不再带出生产域名、IP、内网路径与凭据。 新增 config/:platform.env.example(模板)· load.sh(shell 加载器)· index.cjs(node 加载器)· README.md(键一览与优先级)。 真实值放 config/platform.env —— 已 .gitignore 排除,不入库、不进导出。 TS 侧新增 src/platform-paths.ts 作部署路径的唯一解析处(零副作用): platformDir/stateDir/backupDir/artifactDir/installDir/scriptPath。 config.ts 接入这些字段;内置中继种子由生产 URL 改为空(改由 DSHS_OVERLAY_BOOTSTRAP_SEEDS 提供)。修掉 5 处硬编码绝对路径, src/** 注释中性化 116 行/53 文件。 scripts/** 36 个内部运维脚本:真令牌/PG 口令/隧道目标/主机号/路径 一律改从配置取;web/wake.html 的注册域白名单改为运行时从 location.hostname 推导;test/** 夹具 119 行/13 文件改 RFC 2606/5737 保留值,并把「内置种子必须为空」固化为回归断言。 取证:tsc 0 错;npm test 373/375(唯一失败 lease 属既有); 全仓扫描(大小写不敏感)代码面涉密标识 = 0;已部署 47 并零回归 (/opt/dsh/* 未搬家,/var/lib/dshs/platform 未被误建)。
This commit is contained in:
1 parent
9c2e7975ac
commit
452924d89c
100 files changed
+1167
-453
No files matched your search
@@ -153,7 +153,7 @@ test('U1 逻辑名唯一入口:旧形态 / 新形态 / `u:<租户>` 里的冒
|
||||
// ① 规范形态
|
||||
assert.equal(logicalName('u:5', 'w-1'), 'u:5/w-1')
|
||||
assert.deepEqual(parseLogicalName('ops/manager'), { network: 'ops', hostId: 'manager' })
|
||||
assert.deepEqual(parseLogicalName('u:5/w-106'), { network: 'u:5', hostId: 'w-106' })
|
||||
assert.deepEqual(parseLogicalName('u:5/w-2'), { network: 'u:5', hostId: 'w-2' })
|
||||
|
||||
// ② 兼容形态:`network:hostId`(运维习惯写法)
|
||||
assert.deepEqual(parseLogicalName('ops:manager'), { network: 'ops', hostId: 'manager' })
|
||||
@@ -163,7 +163,7 @@ test('U1 逻辑名唯一入口:旧形态 / 新形态 / `u:<租户>` 里的冒
|
||||
|
||||
// ③ 旧形态(R5 时代的扁平 hostId)⇒ 落在运维网,**旧配置照旧可用**
|
||||
assert.deepEqual(parseLogicalName('manager'), { network: OPS_NETWORK, hostId: 'manager' })
|
||||
assert.deepEqual(parseLogicalName('w-106'), { network: OPS_NETWORK, hostId: 'w-106' })
|
||||
assert.deepEqual(parseLogicalName('w-2'), { network: OPS_NETWORK, hostId: 'w-2' })
|
||||
|
||||
// ④ 非法 ⇒ **抛**(配置错就炸,不静默变成"谁也没匹配上")
|
||||
assert.throws(() => parseLogicalName('u:5'), /网络段/)
|
||||
@@ -205,8 +205,8 @@ test('U2 旧客户端(不声明 network)+ 旧扁平白名单 ⇒ 一切照
|
||||
const srv = new RelayServer({
|
||||
port: 0,
|
||||
keys: new Map([
|
||||
['w-106', wSecret],
|
||||
['w-47', w47Secret],
|
||||
['w-2', wSecret],
|
||||
['w-1', w47Secret],
|
||||
['manager', mSecret],
|
||||
]),
|
||||
instancePortBase: BASE,
|
||||
@@ -223,21 +223,21 @@ test('U2 旧客户端(不声明 network)+ 旧扁平白名单 ⇒ 一切照
|
||||
})
|
||||
|
||||
// ① **旧客户端握手**:HELLO 里根本没有 network 字段(= 现网 47/106 上正在跑的那一版)
|
||||
const { ws: rawWs, frame: ack } = await rawHello(url, 'w-106', wSecret, String(legacyPort), randomBytes(16).toString('hex'))
|
||||
const { ws: rawWs, frame: ack } = await rawHello(url, 'w-2', wSecret, String(legacyPort), randomBytes(16).toString('hex'))
|
||||
t.after(() => rawWs.close())
|
||||
assert.ok(ack !== undefined, '旧客户端必须能注册(否则这次改动就是硬断)')
|
||||
assert.equal(ack.type, MUX.HELLO_ACK, '旧客户端应拿到 HELLO_ACK')
|
||||
const parsed = JSON.parse(ack.payload.toString('utf8'))
|
||||
assert.equal(parsed.network, OPS_NETWORK, 'HELLO_ACK 应回显服务端认定的网 = ops')
|
||||
assert.equal(parsed.name, logicalName(OPS_NETWORK, 'w-106'))
|
||||
assert.ok(await waitFor(() => srv.isOnline('w-106')), '默认网络(ops)里应看到它')
|
||||
assert.equal(parsed.name, logicalName(OPS_NETWORK, 'w-2'))
|
||||
assert.ok(await waitFor(() => srv.isOnline('w-2')), '默认网络(ops)里应看到它')
|
||||
assert.ok(
|
||||
await waitFor(() => srv.localPortOf('w-106', legacyPort) !== undefined),
|
||||
await waitFor(() => srv.localPortOf('w-2', legacyPort) !== undefined),
|
||||
'旧客户端照样拿到回环落点(R1–R4 的行为不变)',
|
||||
)
|
||||
|
||||
// ② 不传 `networkId` 的真 client = ops(默认值即现网事实);旧扁平白名单照旧拨得动
|
||||
const worker = new RelayClient({ url, hostId: 'w-47', secret: w47Secret, ports: [servePort], log: () => {} })
|
||||
const worker = new RelayClient({ url, hostId: 'w-1', secret: w47Secret, ports: [servePort], log: () => {} })
|
||||
const dialer = new RelayClient({ url, hostId: 'manager', secret: mSecret, ports: [], dialer: true, log: () => {} })
|
||||
worker.start()
|
||||
dialer.start()
|
||||
@@ -249,14 +249,14 @@ test('U2 旧客户端(不声明 network)+ 旧扁平白名单 ⇒ 一切照
|
||||
assert.equal(worker.status().network, OPS_NETWORK, '不声明网络 ⇒ 默认 ops(不是空、不是 undefined)')
|
||||
assert.ok(await waitFor(() => dialer.status().state === 'up'), '拨号方未注册')
|
||||
assert.deepEqual(srv.status().dialers, ['manager'], '/status 的 dialers 仍按旧写法展示(不破坏既有消费者)')
|
||||
const duplex = await dialer.openStream('w-47', servePort)
|
||||
const duplex = await dialer.openStream('w-1', servePort)
|
||||
assert.equal(await dialRoundTrip(duplex, 'legacy-ok', 'ops:'.length), 'ops:legacy-ok', '字节要真的过去')
|
||||
duplex.destroy()
|
||||
})
|
||||
|
||||
/* ─────────── U3:跨网隔离是**结构性**的(拒绝点在 relay) ─────────── */
|
||||
|
||||
test('U3 跨网隔离:u:test-network 的合法拨号方拨 ops/w-106 ⇒ relay 拒,且**不泄露**目标在哪张网', async (t) => {
|
||||
test('U3 跨网隔离:u:test-network 的合法拨号方拨 ops/w-2 ⇒ relay 拒,且**不泄露**目标在哪张网', async (t) => {
|
||||
const wSecret = randomBytes(32).toString('hex')
|
||||
const opsSecret = randomBytes(32).toString('hex')
|
||||
const foreignSecret = randomBytes(32).toString('hex')
|
||||
@@ -266,7 +266,7 @@ test('U3 跨网隔离:u:test-network 的合法拨号方拨 ops/w-106 ⇒ relay
|
||||
const srv = new RelayServer({
|
||||
port: 0,
|
||||
keys: new Map([
|
||||
['w-106', wSecret],
|
||||
['w-2', wSecret],
|
||||
['manager', opsSecret],
|
||||
// 序③:`dt` 真正属于 U_TEST(密钥表说了算)⇒ 它能进自己的网,然后在 **DIAL 那一步**
|
||||
// 被跨网判据挡住 —— 这才是本用例要测的那道门,而不是『压根没登记』那道。
|
||||
@@ -286,7 +286,7 @@ test('U3 跨网隔离:u:test-network 的合法拨号方拨 ops/w-106 ⇒ relay
|
||||
})
|
||||
await srv.start()
|
||||
const url = `ws://127.0.0.1:${srv.boundPort}${PATH}`
|
||||
const worker = new RelayClient({ url, hostId: 'w-106', secret: wSecret, ports: [workerPort], log: () => {} })
|
||||
const worker = new RelayClient({ url, hostId: 'w-2', secret: wSecret, ports: [workerPort], log: () => {} })
|
||||
const foreign = new RelayClient({
|
||||
url,
|
||||
hostId: 'dt',
|
||||
@@ -304,7 +304,7 @@ test('U3 跨网隔离:u:test-network 的合法拨号方拨 ops/w-106 ⇒ relay
|
||||
echo.close()
|
||||
await srv.stop()
|
||||
})
|
||||
const opsUp = await waitFor(() => srv.isOnline('w-106'))
|
||||
const opsUp = await waitFor(() => srv.isOnline('w-2'))
|
||||
assert.ok(opsUp, 'ops 侧 worker 未注册')
|
||||
const foreignUp = await waitFor(() => srv.isOnline('dt', U_TEST))
|
||||
assert.ok(foreignUp, `别网拨号方未注册;最近日志:${logs.slice(-10).join(' | ')}`)
|
||||
@@ -313,8 +313,8 @@ test('U3 跨网隔离:u:test-network 的合法拨号方拨 ops/w-106 ⇒ relay
|
||||
const nets = srv.status().networks
|
||||
assert.deepEqual(
|
||||
nets.find((n) => n.network === OPS_NETWORK)?.sessions,
|
||||
['w-106'],
|
||||
'ops 网里应只有 w-106',
|
||||
['w-2'],
|
||||
'ops 网里应只有 w-2',
|
||||
)
|
||||
assert.deepEqual(nets.find((n) => n.network === U_TEST)?.sessions, ['dt'], '别张网里应只有 dt')
|
||||
|
||||
@@ -322,7 +322,7 @@ test('U3 跨网隔离:u:test-network 的合法拨号方拨 ops/w-106 ⇒ relay
|
||||
const before = srv.status().counters.refused
|
||||
let foreignMsg = ''
|
||||
await assert.rejects(
|
||||
() => foreign.openStream('w-106', workerPort),
|
||||
() => foreign.openStream('w-2', workerPort),
|
||||
(err) => {
|
||||
foreignMsg = err instanceof Error ? err.message : String(err)
|
||||
return true
|
||||
@@ -347,7 +347,7 @@ test('U3 跨网隔离:u:test-network 的合法拨号方拨 ops/w-106 ⇒ relay
|
||||
)
|
||||
// 目标侧没有任何流被建立(不是"建了再断")
|
||||
assert.equal(
|
||||
srv.status().endpoints.find((e) => e.hostId === 'w-106' && e.network === OPS_NETWORK && e.port === workerPort)?.streams,
|
||||
srv.status().endpoints.find((e) => e.hostId === 'w-2' && e.network === OPS_NETWORK && e.port === workerPort)?.streams,
|
||||
0,
|
||||
'被拒的跨网拨号不得在目标侧留下流',
|
||||
)
|
||||
@@ -358,7 +358,7 @@ test('U3 跨网隔离:u:test-network 的合法拨号方拨 ops/w-106 ⇒ relay
|
||||
ops.start()
|
||||
t.after(() => ops.stop())
|
||||
assert.ok(await waitFor(() => ops.status().state === 'up'), 'ops 拨号方未注册')
|
||||
const duplex = await ops.openStream('w-106', workerPort)
|
||||
const duplex = await ops.openStream('w-2', workerPort)
|
||||
assert.equal(await dialRoundTrip(duplex, 'same-net', 'ops:'.length), 'ops:same-net')
|
||||
duplex.destroy()
|
||||
})
|
||||
|
||||
Reference in new issue
Block a user