参考所有分组,完成尽量多的内容
结论:OPFS负向守护补充showDirectoryPicker,禁止浏览器目录选择绕过OPFS持久化路径;未扩展smoke功能行为。
This commit is contained in:
@@ -18,8 +18,8 @@ Hard rules:
|
||||
add browser filesystem paths that bypass OPFS.
|
||||
- Browser app and wasm bridge code must not persist CNC programs, LinuxCNC
|
||||
parameter files, or mirrored workspace files through non-OPFS browser storage
|
||||
APIs such as Local Storage, IndexedDB, File Picker writes, WebKit filesystem
|
||||
APIs, or FileReader-backed import paths.
|
||||
APIs such as Local Storage, IndexedDB, File Picker reads/writes, Directory
|
||||
Picker access, WebKit filesystem APIs, or FileReader-backed import paths.
|
||||
|
||||
Allowed project code:
|
||||
|
||||
|
||||
@@ -734,7 +734,11 @@ grep -F 'signature must include the blocker wrapper script, analyzer script' doc
|
||||
grep -F 'sha256sum test-linuxcnc-wasm-blockers.sh' test-linuxcnc-wasm-blockers.sh >/dev/null
|
||||
grep -F 'browser app/wasm code must not add filesystem persistence outside OPFS' test-native.sh >/dev/null
|
||||
grep -F 'browser app/wasm code must not add filesystem persistence outside OPFS' test-linuxcnc-wasm-cmake-safe-probe.sh >/dev/null
|
||||
grep -F 'showDirectoryPicker' test-native.sh >/dev/null
|
||||
grep -F 'showDirectoryPicker' test-linuxcnc-wasm-cmake-safe-probe.sh >/dev/null
|
||||
grep -F 'reject browser app/wasm storage APIs that could bypass it' docs/linuxcnc-source-policy.md >/dev/null
|
||||
grep -F 'Directory' docs/linuxcnc-source-policy.md >/dev/null
|
||||
grep -F 'Picker access' docs/linuxcnc-source-policy.md >/dev/null
|
||||
grep -F 'Persistent native, source-link, source-syntax, and wasm-safe CMake probe' docs/linuxcnc-source-policy.md >/dev/null
|
||||
grep -F 'copies and byte-compares `cnc_sim.js` and `cnc_sim.wasm` under' docs/linuxcnc-source-policy.md >/dev/null
|
||||
grep -F '`CNC_SIM_BUILD_JOBS` must be a positive integer and defaults to `8`.' docs/linuxcnc-source-policy.md >/dev/null
|
||||
|
||||
@@ -763,7 +763,7 @@ grep -F -- './test-web-wasm-node-smoke.sh' build-wasm.sh >/dev/null
|
||||
grep -F -- './test-web-wasm-browser-smoke.sh' build-wasm.sh >/dev/null
|
||||
grep -F 'const opfsOptions = options.opfs ?? (isOpfsAvailable() ? {} : false)' web/src/wasm-core.js >/dev/null
|
||||
grep -F 'OPFS cannot be disabled in browser contexts with OPFS support' web/src/wasm-core.js >/dev/null
|
||||
if grep -R -n -E 'localStorage|sessionStorage|indexedDB|showOpenFilePicker|showSaveFilePicker|webkitRequestFileSystem|FileReader' web/src; then
|
||||
if grep -R -n -E 'localStorage|sessionStorage|indexedDB|showOpenFilePicker|showSaveFilePicker|showDirectoryPicker|webkitRequestFileSystem|FileReader' web/src; then
|
||||
echo "browser app/wasm code must not add filesystem persistence outside OPFS" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
@@ -389,7 +389,7 @@ grep -F '"parameters/rs274ngc.var"' web/test-browser-wasm-smoke-opfs-parameter-s
|
||||
grep -F '"parameters/rs274ngc.var.bak"' web/test-browser-wasm-smoke-opfs-parameter-sections.js >/dev/null
|
||||
grep -F 'const opfsOptions = options.opfs ?? (isOpfsAvailable() ? {} : false)' web/src/wasm-core.js >/dev/null
|
||||
grep -F 'OPFS cannot be disabled in browser contexts with OPFS support' web/src/wasm-core.js >/dev/null
|
||||
if grep -R -n -E 'localStorage|sessionStorage|indexedDB|showOpenFilePicker|showSaveFilePicker|webkitRequestFileSystem|FileReader' web/src; then
|
||||
if grep -R -n -E 'localStorage|sessionStorage|indexedDB|showOpenFilePicker|showSaveFilePicker|showDirectoryPicker|webkitRequestFileSystem|FileReader' web/src; then
|
||||
echo "browser app/wasm code must not add filesystem persistence outside OPFS" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user