chore(release): verify remote asset hashes

This commit is contained in:
2026-07-14 11:45:02 +08:00
parent 16ff37845d
commit 3b8138ea51
2 changed files with 29 additions and 0 deletions
+2
View File
@@ -163,6 +163,8 @@ curl -k -s https://peilian.njzhmj.top/h5/ | sed -n '1,20p'
```bash
./scripts/release-preflight.sh
RELEASE_REMOTE_URL=https://peilian.njzhmj.top ./scripts/release-preflight.sh
# 发布后核验线上主资源是否与当前本地产物一致
RELEASE_REMOTE_URL=https://peilian.njzhmj.top RELEASE_VERIFY_REMOTE_MATCH=true ./scripts/release-preflight.sh
```
发布时必须保留 preflight 输出、远端备份目录和发布后浏览器回归结果;回滚优先使用对应备份目录恢复,再重启后端服务,不能直接覆盖当前线上目录而不留证据。
+27
View File
@@ -21,6 +21,14 @@ sha256() {
fi
}
sha256_stream() {
if command -v shasum >/dev/null 2>&1; then
shasum -a 256 | awk '{print $1}'
else
sha256sum | awk '{print $1}'
fi
}
frontend_index="frontend/dist/index.html"
mobile_index="mobile-uni/dist/build/h5/index.html"
backend_jar="backend/ruoyi-admin/target/ruoyi-admin.jar"
@@ -63,6 +71,25 @@ if [[ -n "${RELEASE_REMOTE_URL:-}" ]]; then
else
fail "remote tenant list check failed: $remote/prod-api/auth/tenant/list"
fi
if [[ "${RELEASE_VERIFY_REMOTE_MATCH:-false}" == "true" ]]; then
remote_frontend_asset="$(curl -fsS --max-time 15 "$remote/" | sed -nE 's/.*src="(\/assets\/[^" ]+\.js)".*/\1/p' | head -n 1)"
remote_mobile_asset="$(curl -fsS --max-time 15 "$remote/h5/" | sed -nE 's/.*src="(\/h5\/assets\/[^" ]+\.js)".*/\1/p' | head -n 1)"
[[ "$remote_frontend_asset" == /assets/*.js ]] || fail "remote frontend entry asset not found"
[[ "$remote_mobile_asset" == /h5/assets/*.js ]] || fail "remote mobile H5 entry asset not found"
remote_frontend_sha256="$(curl -fsS --max-time 15 "$remote$remote_frontend_asset" | sha256_stream)"
remote_mobile_sha256="$(curl -fsS --max-time 15 "$remote$remote_mobile_asset" | sha256_stream)"
local_frontend_sha256="$(sha256 "$frontend_asset_path")"
local_mobile_sha256="$(sha256 "$mobile_asset_path")"
echo "remote_frontend_asset=$remote_frontend_asset"
echo "remote_frontend_asset_sha256=$remote_frontend_sha256"
echo "remote_mobile_asset=$remote_mobile_asset"
echo "remote_mobile_asset_sha256=$remote_mobile_sha256"
[[ "$remote_frontend_sha256" == "$local_frontend_sha256" ]] || fail "remote frontend asset does not match local build"
[[ "$remote_mobile_sha256" == "$local_mobile_sha256" ]] || fail "remote mobile H5 asset does not match local build"
echo "remote_asset_match=true"
fi
fi
echo "release-preflight: read-only checks passed"