From 0433250bef1d45e6d0100ab59958c24eab334a16 Mon Sep 17 00:00:00 2001 From: let5sne Date: Tue, 14 Jul 2026 13:01:29 +0800 Subject: [PATCH] fix(aihr): reject stale release artifacts --- docs/BRD_IMPLEMENTATION_AUDIT.md | 1 + scripts/release-preflight.sh | 24 ++++++++++++++++++++++++ 2 files changed, 25 insertions(+) diff --git a/docs/BRD_IMPLEMENTATION_AUDIT.md b/docs/BRD_IMPLEMENTATION_AUDIT.md index bee41dc0..9f6d9b9c 100644 --- a/docs/BRD_IMPLEMENTATION_AUDIT.md +++ b/docs/BRD_IMPLEMENTATION_AUDIT.md @@ -253,3 +253,4 @@ - 2026-07-14 M5 试点输出口径复核:严格预检的组织映射数量已与 CSV 的 `formal_org_identity_count` 统一显示为 `org_identity`,并同步行为测试断言;统计逻辑不变,避免把在职组织身份映射数误读为登录次数。未修改生产环境。 - 2026-07-14 BRD 4.7/G3 反馈追溯复核:答案反馈原先只校验客户端传入的 `reviewId` 属于当前租户,可能把其他问题的同租户评审记录绑定到当前反馈;现同时校验评审记录中的脱敏问题文本与反馈问题一致,不一致时仅清空关联、不阻断正常反馈写入,并补源码契约与预检标记。未修改生产环境。 - 2026-07-14 线上只读核对:生产根站、`/h5/` 和 `/prod-api/auth/tenant/list` 均返回 `200`,线上仍加载管理端 `index-CJZ3Ax3Z.js` 与 H5 `index-D4-NrEpb.js`;本轮 `aa7e1508`、`5d85d63c` 两个 BRD 修复提交尚未发布。未执行生产同步、重启或业务数据写入。 +- 2026-07-14 发布证据链复核:`release-preflight.sh` 原先只检查构建产物存在和 hash,旧产物可能被误当成当前提交发布;现增加跨 macOS/Linux 的产物时间门禁,管理端、H5 入口/主资源和后端 jar 必须不早于当前 `HEAD`,否则明确要求重建。该修复只收紧本地发布前检查,未修改生产环境。 diff --git a/scripts/release-preflight.sh b/scripts/release-preflight.sh index 7653051d..c8261e3b 100755 --- a/scripts/release-preflight.sh +++ b/scripts/release-preflight.sh @@ -49,10 +49,34 @@ require_file "$frontend_asset_path" require_file "$mobile_asset_path" grep -q '/h5/' "$mobile_index" || fail "mobile H5 index does not contain the /h5/ base path" +head_epoch="$(git show -s --format=%ct HEAD)" + +file_epoch() { + if stat -f %m "$1" >/dev/null 2>&1; then + stat -f %m "$1" + else + stat -c %Y "$1" + fi +} + +require_fresh_artifact() { + local artifact="$1" + local artifact_epoch + artifact_epoch="$(file_epoch "$artifact")" || fail "cannot read artifact timestamp: $artifact" + [[ "$artifact_epoch" -ge "$head_epoch" ]] || fail "artifact is older than HEAD; rebuild before release: $artifact" +} + +require_fresh_artifact "$frontend_index" +require_fresh_artifact "$frontend_asset_path" +require_fresh_artifact "$mobile_index" +require_fresh_artifact "$mobile_asset_path" +require_fresh_artifact "$backend_jar" + changed_files="$(git status --porcelain)" [[ -z "$changed_files" ]] || fail "worktree has uncommitted changes; commit the release batch before publishing" echo "commit=$(git rev-parse HEAD)" +echo "head_epoch=$head_epoch" echo "worktree=clean" echo "frontend_index_sha256=$(sha256 "$frontend_index")" echo "frontend_asset=$frontend_asset"