fix(aihr): reject stale release artifacts

This commit is contained in:
2026-07-14 13:01:29 +08:00
parent d50bfbf788
commit 0433250bef
2 changed files with 25 additions and 0 deletions
+1
View File
@@ -253,3 +253,4 @@
- 2026-07-14 M5 试点输出口径复核:严格预检的组织映射数量已与 CSV 的 `formal_org_identity_count` 统一显示为 `org_identity`,并同步行为测试断言;统计逻辑不变,避免把在职组织身份映射数误读为登录次数。未修改生产环境。
- 2026-07-14 BRD 4.7/G3 反馈追溯复核:答案反馈原先只校验客户端传入的 `reviewId` 属于当前租户,可能把其他问题的同租户评审记录绑定到当前反馈;现同时校验评审记录中的脱敏问题文本与反馈问题一致,不一致时仅清空关联、不阻断正常反馈写入,并补源码契约与预检标记。未修改生产环境。
- 2026-07-14 线上只读核对:生产根站、`/h5/` 和 `/prod-api/auth/tenant/list` 均返回 `200`,线上仍加载管理端 `index-CJZ3Ax3Z.js` 与 H5 `index-D4-NrEpb.js`;本轮 `aa7e1508`、`5d85d63c` 两个 BRD 修复提交尚未发布。未执行生产同步、重启或业务数据写入。
- 2026-07-14 发布证据链复核:`release-preflight.sh` 原先只检查构建产物存在和 hash,旧产物可能被误当成当前提交发布;现增加跨 macOS/Linux 的产物时间门禁,管理端、H5 入口/主资源和后端 jar 必须不早于当前 `HEAD`,否则明确要求重建。该修复只收紧本地发布前检查,未修改生产环境。
+24
View File
@@ -49,10 +49,34 @@ require_file "$frontend_asset_path"
require_file "$mobile_asset_path"
grep -q '/h5/' "$mobile_index" || fail "mobile H5 index does not contain the /h5/ base path"
head_epoch="$(git show -s --format=%ct HEAD)"
file_epoch() {
if stat -f %m "$1" >/dev/null 2>&1; then
stat -f %m "$1"
else
stat -c %Y "$1"
fi
}
require_fresh_artifact() {
local artifact="$1"
local artifact_epoch
artifact_epoch="$(file_epoch "$artifact")" || fail "cannot read artifact timestamp: $artifact"
[[ "$artifact_epoch" -ge "$head_epoch" ]] || fail "artifact is older than HEAD; rebuild before release: $artifact"
}
require_fresh_artifact "$frontend_index"
require_fresh_artifact "$frontend_asset_path"
require_fresh_artifact "$mobile_index"
require_fresh_artifact "$mobile_asset_path"
require_fresh_artifact "$backend_jar"
changed_files="$(git status --porcelain)"
[[ -z "$changed_files" ]] || fail "worktree has uncommitted changes; commit the release batch before publishing"
echo "commit=$(git rev-parse HEAD)"
echo "head_epoch=$head_epoch"
echo "worktree=clean"
echo "frontend_index_sha256=$(sha256 "$frontend_index")"
echo "frontend_asset=$frontend_asset"