同步移动端工程、设备控制改进与发布资料
This commit is contained in:
@@ -2,6 +2,7 @@ from __future__ import annotations
|
||||
|
||||
import argparse
|
||||
import ipaddress
|
||||
import json
|
||||
import os
|
||||
import re
|
||||
import subprocess
|
||||
@@ -15,7 +16,14 @@ PRIVATE_CREDENTIAL = PurePosixPath("测试相关资料/核桃派的用户名和
|
||||
EXAMPLE_CREDENTIAL = PurePosixPath(
|
||||
"测试相关资料/核桃派的用户名和密码和ip/用户名密码ip.example.txt"
|
||||
)
|
||||
PRIVATE_MOBILE_REGISTRATION = PurePosixPath(
|
||||
"移动端相关内容/安卓app/如何安卓测试/测试设备登记/测试设备.local.json"
|
||||
)
|
||||
EXAMPLE_MOBILE_REGISTRATION = PRIVATE_MOBILE_REGISTRATION.with_name("测试设备.example.json")
|
||||
BINARY_EXTENSIONS = {
|
||||
".apk",
|
||||
".aab",
|
||||
".jar",
|
||||
".deb",
|
||||
".dll",
|
||||
".docx",
|
||||
@@ -120,7 +128,7 @@ def _host_text_patterns() -> list[re.Pattern[str]]:
|
||||
def _private_value_markers() -> tuple[str, ...]:
|
||||
path = WORKSPACE_ROOT.joinpath(*PRIVATE_CREDENTIAL.parts)
|
||||
if not path.is_file():
|
||||
return ()
|
||||
return _mobile_value_markers()
|
||||
fields: dict[str, str] = {}
|
||||
for raw_line in path.read_text(encoding="utf-8").splitlines():
|
||||
line = raw_line.strip()
|
||||
@@ -132,13 +140,36 @@ def _private_value_markers() -> tuple[str, ...]:
|
||||
key, value = (part.strip() for part in line.split(separator, 1))
|
||||
fields[key] = value
|
||||
public_values = {fields.get(key, "") for key in PUBLIC_IMAGE_KEYS}
|
||||
return tuple(
|
||||
return _mobile_value_markers() + tuple(
|
||||
value
|
||||
for key in CURRENT_DEVICE_KEYS
|
||||
if len(value := fields.get(key, "")) >= 4 and value not in public_values
|
||||
)
|
||||
|
||||
|
||||
def _mobile_value_markers() -> tuple[str, ...]:
|
||||
path = WORKSPACE_ROOT.joinpath(*PRIVATE_MOBILE_REGISTRATION.parts)
|
||||
if not path.is_file():
|
||||
return ()
|
||||
try:
|
||||
document = json.loads(path.read_text(encoding="utf-8"))
|
||||
devices = document["devices"]
|
||||
if not isinstance(devices, list):
|
||||
raise ValueError
|
||||
values = []
|
||||
for device in devices:
|
||||
if not isinstance(device, dict):
|
||||
raise ValueError
|
||||
serial = device.get("serial", "")
|
||||
if not isinstance(serial, str):
|
||||
raise ValueError
|
||||
if serial and "<" not in serial and len(serial) >= 4:
|
||||
values.append(serial)
|
||||
return tuple(values)
|
||||
except (OSError, UnicodeError, ValueError, KeyError, TypeError):
|
||||
raise HygieneError("移动端真实登记损坏,无法安全提取私有标识;未输出内容。") from None
|
||||
|
||||
|
||||
def _binary_markers(private_values: tuple[str, ...] = ()) -> list[bytes]:
|
||||
markers: list[bytes] = []
|
||||
host_values = {
|
||||
@@ -178,7 +209,7 @@ def _text_issues(
|
||||
if any(pattern.search(text) for pattern in _host_text_patterns()):
|
||||
issues.append("包含开发电脑专属路径、用户名或主机名")
|
||||
if any(value in text for value in private_values):
|
||||
issues.append("包含当前设备私有凭据值")
|
||||
issues.append("包含当前设备私有凭据或测试手机标识")
|
||||
|
||||
key_header = re.compile("-----BEGIN " + r"(?:OPENSSH |RSA |EC |DSA )?PRIVATE KEY-----")
|
||||
if key_header.search(text):
|
||||
@@ -217,9 +248,12 @@ def audit_paths(paths: list[PurePosixPath], *, scan_binary: bool) -> list[tuple[
|
||||
findings: list[tuple[str, str]] = []
|
||||
private_values = _private_value_markers()
|
||||
for relative in paths:
|
||||
if relative == PRIVATE_CREDENTIAL:
|
||||
if relative in (PRIVATE_CREDENTIAL, PRIVATE_MOBILE_REGISTRATION):
|
||||
findings.append((relative.as_posix(), "真实凭据进入 Git 候选集合"))
|
||||
continue
|
||||
if relative.suffix.lower() in {".jks", ".keystore"}:
|
||||
findings.append((relative.as_posix(), "签名密钥文件进入 Git 候选集合"))
|
||||
continue
|
||||
path = WORKSPACE_ROOT.joinpath(*relative.parts)
|
||||
if not path.is_file():
|
||||
continue
|
||||
@@ -243,6 +277,15 @@ def _check_repository_contract(paths: list[PurePosixPath], staged: bool) -> list
|
||||
ignored = _git("check-ignore", "--quiet", "--", PRIVATE_CREDENTIAL.as_posix(), check=False)
|
||||
if ignored.returncode != 0:
|
||||
findings.append((PRIVATE_CREDENTIAL.as_posix(), "真实凭据未被 .gitignore 精确排除"))
|
||||
mobile_ignored = _git("check-ignore", "--quiet", "--", PRIVATE_MOBILE_REGISTRATION.as_posix(), check=False)
|
||||
if mobile_ignored.returncode != 0:
|
||||
findings.append((PRIVATE_MOBILE_REGISTRATION.as_posix(), "真实手机登记未被 .gitignore 排除"))
|
||||
if staged:
|
||||
mobile_example = _git("cat-file", "-e", f":{EXAMPLE_MOBILE_REGISTRATION.as_posix()}", check=False)
|
||||
if mobile_example.returncode != 0:
|
||||
findings.append((EXAMPLE_MOBILE_REGISTRATION.as_posix(), "手机空白登记示例不在 Git 索引"))
|
||||
elif EXAMPLE_MOBILE_REGISTRATION not in paths:
|
||||
findings.append((EXAMPLE_MOBILE_REGISTRATION.as_posix(), "手机空白登记示例不在 Git 候选集合"))
|
||||
|
||||
if staged:
|
||||
example_in_index = _git("cat-file", "-e", f":{EXAMPLE_CREDENTIAL.as_posix()}", check=False)
|
||||
|
||||
Reference in New Issue
Block a user