fix: close marketplace client review findings

This commit is contained in:
brother7 committed 2026-08-28 21:05:54 +08:00
1 parent 8dfa542860
commit 1614f7efc1
25 files changed
+1224 -143

No files matched your search

+47 -1
View File
@@ -14,6 +14,7 @@ import {
collectForbiddenResourcePaths,
verifyBundledCodingPluginResources,
defaultProductExecutable,
readPackagedMarketplaceTrustSource,
validatePiArtifactMetadata,
verifyMarketplaceClientArtifact,
} from '../../scripts/lib/pi-product-artifact.mjs';
@@ -198,7 +199,8 @@ describe('final Pi product artifact verification', () => {
const trustSource = `export const CODE_OWNED_PLUGIN_SIGNING_KEYS = Object.freeze(
{} as Readonly<Record<string, string>>,
);`;
);
export const sourceMarker = 'makelore.plugin-trust.code-owned.v1';`;
expect(verifyMarketplaceClientArtifact(artifact, trustSource)).toMatchObject({
schema2SkillOnly: true,
productionTrust: 'official-key-absent-fail-closed',
@@ -229,6 +231,50 @@ describe('final Pi product artifact verification', () => {
)).toThrow('empty code-owned fail-closed store');
});
it('proves Marketplace trust from the packaged app.asar rather than checkout source', async () => {
const root = await mkdtemp(path.join(tmpdir(), 'makelore-marketplace-trust-asar-'));
roots.push(root);
const source = path.join(root, 'source');
await mkdir(path.join(source, 'dist-electron'), { recursive: true });
await writeFile(path.join(source, 'dist-electron', 'main.js'), [
'const CODE_OWNED_PLUGIN_SIGNING_KEYS = Object.freeze({});',
'const unrelatedConfiguration = process.env.NIANCODE_E2E;',
'export const marketplace = true;',
].join('\n'));
const appAsar = path.join(root, 'app.asar');
await createPackage(source, appAsar);
await expect(readPackagedMarketplaceTrustSource(appAsar)).resolves.toBe(
'CODE_OWNED_PLUGIN_SIGNING_KEYS = Object.freeze({})',
);
});
it('recognizes a minified trust table only when its packaged provenance marker is present', async () => {
const root = await mkdtemp(path.join(tmpdir(), 'makelore-marketplace-compiled-trust-asar-'));
roots.push(root);
const source = path.join(root, 'source');
await mkdir(path.join(source, 'dist-electron'), { recursive: true });
await writeFile(path.join(source, 'dist-electron', 'main.js'), [
'const dC = Object.freeze({});',
'function createTrust() { return Object.freeze({ get: load, sourceMarker: "makelore.plugin-trust.code-owned.v1" }); }',
].join('\n'));
const appAsar = path.join(root, 'app.asar');
await createPackage(source, appAsar);
await expect(readPackagedMarketplaceTrustSource(appAsar)).resolves.toContain(
'makelore.plugin-trust.code-owned.v1',
);
expect(verifyMarketplaceClientArtifact(
Buffer.from([
'makelore-plugin-release.v1', 'skill_only', 'plugin_signature_invalid',
'signing key is not trusted', '/api/coding/plugin-marketplace',
'plugin-marketplace\\/install\\/', 'plugin-marketplace\\/update\\/',
'effectiveSkillIds', 'pluginReleaseIds',
'/api/coding/plugin-marketplace/catalog', '/api/coding/plugin-marketplace/library',
'免费获取', '我的插件',
].join('\n')),
'const dC = Object.freeze({}); sourceMarker: makelore.plugin-trust.code-owned.v1',
)).toMatchObject({ productionTrust: 'official-key-absent-fail-closed' });
});
it('rejects a packaged plugin tree that drops an SDK asset or catalog marker', async () => {
const fixture = await bundledResourceFixture();
await rm(path.join(