This repository was archived by the owner on Aug 21, 2026. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathTest-PublicRelease.ps1
More file actions
265 lines (246 loc) · 10.1 KB
/
Copy pathTest-PublicRelease.ps1
File metadata and controls
265 lines (246 loc) · 10.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
param(
[Parameter(Mandatory = $true)]
[string]$ReleaseDirectory,
[string]$ArchivePath = '',
[string]$SourceDirectory = '',
[string[]]$ForbiddenMarker = @()
)
$ErrorActionPreference = 'Stop'
$releaseRoot = [IO.Path]::GetFullPath($ReleaseDirectory).TrimEnd('\')
$violations = [Collections.Generic.List[string]]::new()
$textExtensions = [Collections.Generic.HashSet[string]]::new(
[StringComparer]::OrdinalIgnoreCase)
foreach ($extension in @('.ps1', '.json', '.txt', '.md', '.xml', '.config')) {
[void]$textExtensions.Add($extension)
}
$privateMarkers = @(
('Deep' + 'Seek'),
('Koikatu' + 'Profiles'),
('Codex.Koikatu.' + 'OneStopManager'),
('Codex\KoikatuManager' + '\Data'),
('3.1-' + ('deep' + 'seek'))
)
$allForbiddenMarkers = @($privateMarkers) + @(
$ForbiddenMarker |
Where-Object { -not [string]::IsNullOrWhiteSpace($_) } |
Select-Object -Unique)
function Add-Violation([string]$Message) {
$script:violations.Add($Message)
}
function Get-RelativePath([string]$Root, [string]$Path) {
return $Path.Substring($Root.Length).TrimStart('\').Replace('\', '/')
}
function Get-Sha256([string]$Path) {
$stream = [IO.File]::OpenRead($Path)
$sha256 = [Security.Cryptography.SHA256]::Create()
try {
return [BitConverter]::ToString(
$sha256.ComputeHash($stream)).Replace('-', '')
}
finally {
$sha256.Dispose()
$stream.Dispose()
}
}
function Test-TextContent([string]$Path, [string]$DisplayPath) {
$content = [IO.File]::ReadAllText($Path, [Text.Encoding]::UTF8)
if ($content -match '(?<![A-Za-z0-9_])[A-Za-z]:\\') {
Add-Violation "Absolute drive path in text file: $DisplayPath"
}
if ($content -match '(?i)C:/Users/|/home/[^/\s]+/') {
Add-Violation "User-home path in text file: $DisplayPath"
}
foreach ($marker in $allForbiddenMarkers) {
if ($content.IndexOf($marker, [StringComparison]::OrdinalIgnoreCase) -ge 0) {
Add-Violation "Private/development marker '$marker' in: $DisplayPath"
}
}
}
function Test-BinaryMarkers([string]$Path, [string]$DisplayPath) {
$bytes = [IO.File]::ReadAllBytes($Path)
$ascii = [Text.Encoding]::ASCII.GetString($bytes)
$unicode = [Text.Encoding]::Unicode.GetString($bytes)
foreach ($marker in $allForbiddenMarkers) {
if ($ascii.IndexOf($marker, [StringComparison]::OrdinalIgnoreCase) -ge 0 -or
$unicode.IndexOf($marker, [StringComparison]::OrdinalIgnoreCase) -ge 0) {
Add-Violation "Private/development marker '$marker' embedded in: $DisplayPath"
}
}
}
if (-not (Test-Path -LiteralPath $releaseRoot -PathType Container)) {
throw "Release directory does not exist: $releaseRoot"
}
$releaseFiles = @(Get-ChildItem -LiteralPath $releaseRoot -Recurse -File -Force)
$relativeFiles = @($releaseFiles | ForEach-Object {
Get-RelativePath $releaseRoot $_.FullName
})
if ($releaseFiles.Count -eq 0) {
Add-Violation 'Release directory is empty.'
}
foreach ($relativePath in $relativeFiles) {
$segments = @($relativePath -split '/')
if ($segments -contains 'Data') {
Add-Violation "User-data directory is present: $relativePath"
}
$leaf = $segments[-1]
if ($leaf -match '(?i)^(settings|instances-v\d+|run-record|operation-manifest|plugin-baseline-v\d+)\.json$' -or
$leaf -match '(?i)\.(pdb|log|bak|tmp|user|suo|dmp)$') {
Add-Violation "Runtime, debug or backup file is present: $relativePath"
}
if ($leaf.Equals('portable.flag', [StringComparison]::OrdinalIgnoreCase)) {
Add-Violation 'portable.flag must not be shipped in the public distribution.'
}
}
$allowedTopLevel = @(
'KoikatuManager.exe',
'README.zh-CN.txt',
'CHANGELOG.zh-CN.md',
'release-manifest.json',
'Tools'
)
foreach ($item in Get-ChildItem -LiteralPath $releaseRoot -Force) {
if ($allowedTopLevel -notcontains $item.Name) {
Add-Violation "Unexpected top-level release item: $($item.Name)"
}
}
foreach ($file in $releaseFiles) {
$relative = Get-RelativePath $releaseRoot $file.FullName
if ($textExtensions.Contains($file.Extension)) {
Test-TextContent $file.FullName $relative
}
else {
Test-BinaryMarkers $file.FullName $relative
}
}
$manifestPath = Join-Path $releaseRoot 'release-manifest.json'
if (-not (Test-Path -LiteralPath $manifestPath -PathType Leaf)) {
Add-Violation 'release-manifest.json is missing.'
}
else {
try {
$manifest = Get-Content -LiteralPath $manifestPath -Raw -Encoding UTF8 |
ConvertFrom-Json
if ($manifest.product -ne 'KoikatuManager' -or $manifest.version -ne '3.8.1') {
Add-Violation 'Release manifest product/version is not the public 3.8.1 identity.'
}
if ($manifest.includesUserData -ne $false) {
Add-Violation 'Release manifest does not explicitly reject bundled user data.'
}
if ($manifest.distributionMode -ne 'installed' -or
$manifest.dataStorage -ne '%LOCALAPPDATA%\KoikatuManager\Data') {
Add-Violation 'Release manifest data-storage policy is invalid.'
}
$manifestFiles = @($manifest.files | ForEach-Object {
([string]$_.path).Replace('\', '/')
})
$expectedManifestFiles = @($relativeFiles |
Where-Object { $_ -ne 'release-manifest.json' } |
Sort-Object)
$actualManifestFiles = @($manifestFiles | Sort-Object)
$manifestDifference = @(Compare-Object $expectedManifestFiles $actualManifestFiles)
if ($manifestDifference.Count -gt 0) {
Add-Violation 'Release manifest file list does not match the release directory.'
}
}
catch {
Add-Violation "Release manifest is invalid JSON: $($_.Exception.Message)"
}
}
if (-not [string]::IsNullOrWhiteSpace($ArchivePath)) {
$resolvedArchive = [IO.Path]::GetFullPath($ArchivePath)
if (-not (Test-Path -LiteralPath $resolvedArchive -PathType Leaf)) {
Add-Violation "Archive does not exist: $resolvedArchive"
}
else {
Add-Type -AssemblyName System.IO.Compression.FileSystem
$archive = [IO.Compression.ZipFile]::OpenRead($resolvedArchive)
try {
$entries = @($archive.Entries | Where-Object {
-not [string]::IsNullOrEmpty($_.Name)
})
$entryNames = @($entries | ForEach-Object {
$_.FullName.Replace('\', '/')
} | Sort-Object)
$directoryNames = @($relativeFiles | Sort-Object)
if (@(Compare-Object $directoryNames $entryNames).Count -gt 0) {
Add-Violation 'ZIP entries do not exactly match the audited release directory.'
}
foreach ($entry in $entries) {
$relative = $entry.FullName.Replace('\', '/')
$diskPath = Join-Path $releaseRoot $relative.Replace('/', '\')
if (-not (Test-Path -LiteralPath $diskPath -PathType Leaf)) {
continue
}
$sha = [Security.Cryptography.SHA256]::Create()
try {
$stream = $entry.Open()
try {
$entryHash = [BitConverter]::ToString(
$sha.ComputeHash($stream)).Replace('-', '')
}
finally {
$stream.Dispose()
}
}
finally {
$sha.Dispose()
}
$diskHash = Get-Sha256 $diskPath
if ($entryHash -ne $diskHash) {
Add-Violation "ZIP content differs from audited file: $relative"
}
}
}
finally {
$archive.Dispose()
}
}
}
if (-not [string]::IsNullOrWhiteSpace($SourceDirectory)) {
$sourceRoot = [IO.Path]::GetFullPath($SourceDirectory).TrimEnd('\')
if (-not (Test-Path -LiteralPath $sourceRoot -PathType Container)) {
Add-Violation "Public source directory does not exist: $sourceRoot"
}
else {
foreach ($file in Get-ChildItem -LiteralPath $sourceRoot -Recurse -File -Force) {
$relative = Get-RelativePath $sourceRoot $file.FullName
if ($relative -match '(^|/)(Data|bin|obj|\.git)(/|$)') {
Add-Violation "Generated/private directory is present in source package: $relative"
continue
}
if ($file.Name -in @(
'IMPLEMENTATION-LOG.zh-CN.md',
'UI-SELF-AUDIT-1.0.zh-CN.md')) {
Add-Violation "Private development history is present in source package: $relative"
}
if ($file.Name -ne 'Test-PublicRelease.ps1' -and
$textExtensions.Contains($file.Extension)) {
$content = [IO.File]::ReadAllText($file.FullName, [Text.Encoding]::UTF8)
$containsPrivateMarker = $false
foreach ($marker in $privateMarkers) {
if ($content.IndexOf(
$marker,
[StringComparison]::OrdinalIgnoreCase) -ge 0) {
$containsPrivateMarker = $true
break
}
}
if ($content -match '(?i)(?<![A-Za-z0-9_])[PZF]:\\' -or
$content -match '(?i)C:\\Users\\[^\\\s]+\\' -or
$containsPrivateMarker) {
Add-Violation "Private machine path or development marker in source: $relative"
}
}
}
}
}
if ($violations.Count -gt 0) {
$details = ($violations | Sort-Object -Unique | ForEach-Object { " - $_" }) -join [Environment]::NewLine
throw "Public release audit failed:$([Environment]::NewLine)$details"
}
Write-Output (
"PUBLIC-RELEASE-AUDIT PASS files={0} bytes={1} archive={2} source={3}" -f
$releaseFiles.Count,
(($releaseFiles | Measure-Object Length -Sum).Sum),
(-not [string]::IsNullOrWhiteSpace($ArchivePath)),
(-not [string]::IsNullOrWhiteSpace($SourceDirectory)))