426e9eeabd
Voice Workbench / headless workbench (mocked backends) (push) Has been cancelled
Voice Workbench / real acoustic lane (nightly, provisioned only) (push) Has been cancelled
ci / test (push) Has been cancelled
ci / lint-and-format (push) Has been cancelled
ci / build (push) Has been cancelled
ci / dev-startup (push) Has been cancelled
gitleaks / gitleaks (push) Has been cancelled
Markdown Links / Relative Markdown Links (push) Has been cancelled
Quality (Extended) / Homepage Build (PR smoke) (push) Has been cancelled
Quality (Extended) / Comment-only diff guard (push) Has been cancelled
Quality (Extended) / Format + Type Safety Ratchet (push) Has been cancelled
Quality (Extended) / Develop Gate (secret scan + UI determinism) (push) Has been cancelled
Quality (Extended) / Develop Gate (lint) (push) Has been cancelled
Chat shell gestures / Chat shell gesture + parity e2e (push) Has been cancelled
Cloud Gateway Discord / Test (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx @biomejs/biome check packages/lifeops-bench/src, benchmark-lint) (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx vitest run --config packages/lifeops-bench/vitest.config.ts --root packages/lifeops-bench --passWithNoTests, benchmark-tests) (push) Has been cancelled
Build Agent Image / build-and-push (push) Has been cancelled
Dev Smoke / bun run dev onboarding chat (push) Has been cancelled
Dev Smoke / Vite HMR dependency-level smoke (push) Has been cancelled
Electrobun Submodule Guard / electrobun gitlink is fetchable (push) Has been cancelled
Publish @elizaos/example-code / check_npm (push) Has been cancelled
Publish @elizaos/example-code / publish_npm (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / verify_version (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / publish_npm (push) Has been cancelled
Sandbox Live Smoke / Sandbox live smoke (push) Has been cancelled
Snap Build & Test / Build Snap (amd64) (push) Has been cancelled
Snap Build & Test / Build Snap (arm64) (push) Has been cancelled
Test Packaging / elizaos CLI global-install smoke (node + bun) (push) Has been cancelled
Cloud Gateway Webhook / Test (push) Has been cancelled
Cloud Tests / lint-and-types (push) Has been cancelled
Cloud Tests / unit-tests (push) Has been cancelled
Cloud Tests / integration-tests (push) Has been cancelled
Cloud Tests / e2e-tests (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Deploy Apps Worker (Product 2) / Determine environment (push) Has been cancelled
Deploy Apps Worker (Product 2) / Deploy apps worker to apps-control host (${{ needs.determine-env.outputs.environment }}) (push) Has been cancelled
Deploy Eliza Provisioning Worker / Determine environment (push) Has been cancelled
Deploy Eliza Provisioning Worker / Deploy worker to Hetzner host (${{ needs.determine-env.outputs.environment }} @ ${{ needs.determine-env.outputs.deployment_sha }}) (push) Has been cancelled
Dev Smoke / Classify changed paths (push) Has been cancelled
supply-chain / sbom (push) Has been cancelled
supply-chain / vulnerability-scan (push) Has been cancelled
Build, Push & Deploy to Phala Cloud / build-and-push (push) Has been cancelled
Test Packaging / Validate Packaging Configs (push) Has been cancelled
Test Packaging / Build & Test PyPI Package (push) Has been cancelled
Test Packaging / PyPI on Python ${{ matrix.python }} (push) Has been cancelled
Test Packaging / Pack & Test JS Tarballs (push) Has been cancelled
UI Fixture E2E / ui-fixture-e2e (push) Has been cancelled
UI Fixture E2E / fixture-e2e (push) Has been cancelled
UI Story Gate / story-gate (push) Has been cancelled
vault-ci / test (macos-latest) (push) Has been cancelled
vault-ci / test (ubuntu-latest) (push) Has been cancelled
vault-ci / test (windows-latest) (push) Has been cancelled
vault-ci / app-core wiring tests (push) Has been cancelled
verify-patches / verify patches/CHECKSUMS.sha256 (push) Has been cancelled
Voice Benchmark Smoke / voice-emotion fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voiceagentbench fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench-quality unit smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench TypeScript unit (no audio) (push) Has been cancelled
Voice Benchmark Smoke / voice bench smoke summary (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/app-core test bun run --cwd packages/elizaos test bun run --cwd packages/cloud/shared test], app-and-cli) (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/scenario-runner test bun run --cwd packages/vault test bun run --cwd packages/security test bun run --cwd plugins/plugin-coding-tools test], framework-packages) (push) Has been cancelled
Windows CI / windows ([bun run --cwd plugins/plugin-elizacloud test bun run --cwd plugins/plugin-discord test bun run --cwd plugins/plugin-anthropic test bun run --cwd plugins/plugin-openai test bun run --cwd plugins/plugin-app-control test bun run --cwd plugins/pl… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run build --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/agent --concurrency=4 node packages/scripts/run-bash-linux-only.mjs scripts/verify-riscv64-buildpaths.sh node packages/scripts/run… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run typecheck --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/cloud-shared --concurrency=4 bun run --cwd packages/core test bun run --cwd packages/shared test], core-runtime, 75) (push) Has been cancelled
154 lines
5.3 KiB
JavaScript
154 lines
5.3 KiB
JavaScript
/**
|
|
* Android renderer-stamp verifier for sideload APKs. The mobile build already
|
|
* proves the staged Gradle assets match the fresh Vite build; this module
|
|
* checks the packaged APK before adb install so a stale artifact cannot reach a
|
|
* device just because it was the newest file in the outputs directory.
|
|
*/
|
|
import fs from "node:fs";
|
|
import path from "node:path";
|
|
import zlib from "node:zlib";
|
|
|
|
const RENDERER_MANIFEST = "eliza-renderer-build.json";
|
|
export const ANDROID_APK_RENDERER_MANIFEST_PATH = `assets/public/${RENDERER_MANIFEST}`;
|
|
|
|
function findEndOfCentralDirectory(buffer) {
|
|
const signature = 0x06054b50;
|
|
const minOffset = Math.max(0, buffer.length - 65_557);
|
|
for (let offset = buffer.length - 22; offset >= minOffset; offset -= 1) {
|
|
if (buffer.readUInt32LE(offset) === signature) return offset;
|
|
}
|
|
return -1;
|
|
}
|
|
|
|
function readZipEntry(zipPath, entryName) {
|
|
const buffer = fs.readFileSync(zipPath);
|
|
const eocd = findEndOfCentralDirectory(buffer);
|
|
if (eocd < 0) throw new Error(`APK is not a readable zip: ${zipPath}`);
|
|
const entryCount = buffer.readUInt16LE(eocd + 10);
|
|
let cursor = buffer.readUInt32LE(eocd + 16);
|
|
for (let index = 0; index < entryCount; index += 1) {
|
|
if (buffer.readUInt32LE(cursor) !== 0x02014b50) {
|
|
throw new Error(`APK central directory is corrupt: ${zipPath}`);
|
|
}
|
|
const method = buffer.readUInt16LE(cursor + 10);
|
|
const compressedSize = buffer.readUInt32LE(cursor + 20);
|
|
const nameLength = buffer.readUInt16LE(cursor + 28);
|
|
const extraLength = buffer.readUInt16LE(cursor + 30);
|
|
const commentLength = buffer.readUInt16LE(cursor + 32);
|
|
const localHeaderOffset = buffer.readUInt32LE(cursor + 42);
|
|
const nameStart = cursor + 46;
|
|
const name = buffer.toString("utf8", nameStart, nameStart + nameLength);
|
|
if (name === entryName) {
|
|
if (buffer.readUInt32LE(localHeaderOffset) !== 0x04034b50) {
|
|
throw new Error(`APK local file header is corrupt: ${zipPath}`);
|
|
}
|
|
const localNameLength = buffer.readUInt16LE(localHeaderOffset + 26);
|
|
const localExtraLength = buffer.readUInt16LE(localHeaderOffset + 28);
|
|
const dataStart =
|
|
localHeaderOffset + 30 + localNameLength + localExtraLength;
|
|
const data = buffer.subarray(dataStart, dataStart + compressedSize);
|
|
if (method === 0) return data;
|
|
if (method === 8) return zlib.inflateRawSync(data);
|
|
throw new Error(
|
|
`APK entry ${entryName} uses unsupported zip compression method ${method}.`,
|
|
);
|
|
}
|
|
cursor = nameStart + nameLength + extraLength + commentLength;
|
|
}
|
|
return null;
|
|
}
|
|
|
|
function readRendererManifest(manifestPath, label) {
|
|
if (!fs.existsSync(manifestPath)) {
|
|
throw new Error(`${label} renderer manifest is missing: ${manifestPath}`);
|
|
}
|
|
const parsed = JSON.parse(fs.readFileSync(manifestPath, "utf8"));
|
|
if (typeof parsed.buildId !== "string" || parsed.buildId.length === 0) {
|
|
throw new Error(
|
|
`${label} renderer manifest has no buildId: ${manifestPath}`,
|
|
);
|
|
}
|
|
return parsed;
|
|
}
|
|
|
|
export function freshAndroidRendererManifestPath({
|
|
repoRoot,
|
|
rendererDist = process.env.ELIZA_ANDROID_RENDERER_DIST ??
|
|
process.env.ELIZA_SMOKE_RENDERER_DIST,
|
|
}) {
|
|
return path.join(
|
|
rendererDist
|
|
? path.resolve(rendererDist)
|
|
: path.join(repoRoot, "packages", "app", "dist"),
|
|
RENDERER_MANIFEST,
|
|
);
|
|
}
|
|
|
|
export function readAndroidApkRendererManifest(apkPath, label = "Android APK") {
|
|
const entry = readZipEntry(apkPath, ANDROID_APK_RENDERER_MANIFEST_PATH);
|
|
if (!entry) {
|
|
throw new Error(
|
|
`${label} is missing ${ANDROID_APK_RENDERER_MANIFEST_PATH}; refusing to install an unverifiable renderer.`,
|
|
);
|
|
}
|
|
const parsed = JSON.parse(entry.toString("utf8"));
|
|
if (typeof parsed.buildId !== "string" || parsed.buildId.length === 0) {
|
|
throw new Error(`${label} renderer manifest has no buildId.`);
|
|
}
|
|
return parsed;
|
|
}
|
|
|
|
export function compareAndroidRendererBuildIds({
|
|
fresh,
|
|
packaged,
|
|
label = "Android APK",
|
|
expectedCommit = null,
|
|
}) {
|
|
if (
|
|
expectedCommit &&
|
|
fresh.commit &&
|
|
!String(expectedCommit).startsWith(String(fresh.commit)) &&
|
|
!String(fresh.commit).startsWith(String(expectedCommit))
|
|
) {
|
|
throw new Error(
|
|
`freshly built renderer commit ${fresh.commit} != HEAD ${expectedCommit} - stale Android dist.`,
|
|
);
|
|
}
|
|
if (packaged.buildId !== fresh.buildId) {
|
|
throw new Error(
|
|
`${label} renderer buildId ${packaged.buildId} != freshly built ${fresh.buildId} - stale Android APK.`,
|
|
);
|
|
}
|
|
return {
|
|
buildId: fresh.buildId,
|
|
builtAt: fresh.builtAt ?? null,
|
|
};
|
|
}
|
|
|
|
export function assertAndroidApkRendererFresh({
|
|
apkPath,
|
|
repoRoot,
|
|
rendererDist = process.env.ELIZA_ANDROID_RENDERER_DIST ??
|
|
process.env.ELIZA_SMOKE_RENDERER_DIST,
|
|
expectedCommit = null,
|
|
label = "Android APK",
|
|
log = () => {},
|
|
}) {
|
|
const freshManifest = freshAndroidRendererManifestPath({
|
|
repoRoot,
|
|
rendererDist,
|
|
});
|
|
const fresh = readRendererManifest(freshManifest, "freshly built");
|
|
const packaged = readAndroidApkRendererManifest(apkPath, label);
|
|
const result = compareAndroidRendererBuildIds({
|
|
fresh,
|
|
packaged,
|
|
label,
|
|
expectedCommit,
|
|
});
|
|
log(
|
|
`renderer build stamp OK for ${label}: ${String(result.buildId).slice(0, 12)}${result.builtAt ? ` built ${result.builtAt}` : ""}`,
|
|
);
|
|
return result;
|
|
}
|