From 70e2597295bf8a0b7b5002900694bf9c0992d77f Mon Sep 17 00:00:00 2001 From: wangdequan Date: Mon, 8 Jun 2026 09:26:36 +0800 Subject: [PATCH] =?UTF-8?q?=E6=8C=89=E8=A7=84=E5=88=92=E7=BB=A7=E7=BB=AD?= =?UTF-8?q?=E5=B7=A5=E4=BD=9C?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 结论:补齐 OPFS G-code 程序文件名的自定义路径与非法遍历/嵌套路径拒绝验证,覆盖 Node OPFS 与 Chromium OPFS 路径,并通过 host/WASM/browser 聚合验证。 --- wasm-port/docs/compatibility-validation.md | 10 ++++---- wasm-port/docs/drift-report.md | 5 ++-- wasm-port/docs/source-reuse-map.md | 3 ++- wasm-port/tests/browser/ini_panel_smoke.html | 23 ++++++++++++++++++- .../tests/opfs/node/verify_file_service.mjs | 18 +++++++++++++++ 5 files changed, 51 insertions(+), 8 deletions(-) diff --git a/wasm-port/docs/compatibility-validation.md b/wasm-port/docs/compatibility-validation.md index a728be5..d531e04 100644 --- a/wasm-port/docs/compatibility-validation.md +++ b/wasm-port/docs/compatibility-validation.md @@ -101,7 +101,8 @@ tool table, parameter, G-code, preview-cache, and session-snapshot storage targets. It also validates the host-side session snapshot JSON envelope and round-trip store, including unsupported format/version, session-id mismatch, non-object metadata/payload rejection, custom snapshot filenames, and invalid -snapshot filename rejection, plus pure-text machine file and G-code stores +snapshot filename rejection, plus pure-text machine file and G-code stores, +including G-code program filename rejection for traversal or nested paths, without defining CNC machine-state or file-format semantics. It now also validates the OPFS-to-WASM parameter-file bridge with a mock interpreter SDK to ensure the host boundary copies text into and out of the WASM filesystem without defining @@ -115,7 +116,8 @@ The browser INI/OPFS smoke script serves `wasm-port/` over localhost and runs Chromium headless against a test page that imports the JS SDK, loads the INI WASM module, queries vendored LinuxCNC INI parsing through the SDK, and performs an OPFS text-file, generic session snapshot, custom snapshot filename, -invalid snapshot filename/envelope, machine file, and G-code text round trip. +invalid snapshot filename/envelope, machine file, G-code text round trip, and +G-code filename path-model rejection. The browser interpreter smoke script serves `wasm-port/` over localhost and runs Chromium headless against a test page that loads the interpreter-core @@ -186,8 +188,8 @@ The validation fails if: | --- | --- | | `tests/wasm/node/verify_ini_wasm.sh` | Validates the browser-facing INI WASM module can be built from vendored LinuxCNC `inifile.cc`, loaded through the JS SDK in Node, and queried through the exported C ABI. | | `tests/wasm/node/verify_interp_wasm.sh` | Validates the initial interpreter-core WASM module can be built from vendored LinuxCNC interpreter source, loaded through the interpreter JS SDK, run the first fixture group through `Interp::execute()` and selected file fixtures through `Interp::open()`/`read()`/`execute()`, match the native canonical event plus required state readback fixtures, and run parameter-file restore/save through vendored LinuxCNC `Interp::restore_parameters()` and `Interp::save_parameters()`. | -| `tests/opfs/node/verify_file_service.sh` | Validates the host-owned OPFS text-file adapter, path model, session snapshot store including custom filenames and envelope/path rejection paths, machine file store, G-code text store, OPFS-to-WASM parameter/tool-table bridges, and grouped machine-session loading without moving file persistence, parameter semantics, or tool-table semantics into the WASM core. | -| `tests/browser/verify_ini_panel_browser.sh` | Validates the INI SDK, INI/interpreter WASM module loading, OPFS text-file round trip, generic session snapshot round trip plus custom filename and envelope/path rejection paths, machine file text round trip, G-code text round trip, and the INI panel UI's machine-session load, G-code run, and canonical-event display paths in a real browser runtime. | +| `tests/opfs/node/verify_file_service.sh` | Validates the host-owned OPFS text-file adapter, path model, session snapshot store including custom filenames and envelope/path rejection paths, machine file store, G-code text store including filename rejection paths, OPFS-to-WASM parameter/tool-table bridges, and grouped machine-session loading without moving file persistence, parameter semantics, or tool-table semantics into the WASM core. | +| `tests/browser/verify_ini_panel_browser.sh` | Validates the INI SDK, INI/interpreter WASM module loading, OPFS text-file round trip, generic session snapshot round trip plus custom filename and envelope/path rejection paths, machine file text round trip, G-code text round trip plus filename rejection paths, and the INI panel UI's machine-session load, G-code run, and canonical-event display paths in a real browser runtime. | | `tests/browser/verify_interp_browser.sh` | Validates the interpreter-core WASM module loads through the interpreter JS SDK in a real browser runtime and runs selected positive and negative canonical fixtures through vendored LinuxCNC `Interp::execute()` plus `Interp::open()`/`read()`/`execute()` via the exported C ABI, including OPFS-backed parameter-file restore/save and tool-table load/save through vendored LinuxCNC source. | | `tests/host/verify_host_smokes.sh` | Runs the current host-side Node, WASM interpreter-core, OPFS, and browser smoke validation with shared WASM builds. | diff --git a/wasm-port/docs/drift-report.md b/wasm-port/docs/drift-report.md index 6e782d4..7340967 100644 --- a/wasm-port/docs/drift-report.md +++ b/wasm-port/docs/drift-report.md @@ -71,8 +71,9 @@ semantic rewrites: file and G-code storage, parameter/tool-table bridge copying into the interpreter SDK filesystem, grouped machine-session loading, explicit session file-name overrides, invalid INI-derived machine file names, generic - session snapshot custom filenames plus envelope/path rejection paths, and a - Chromium localhost round trip for those persistence paths. + session snapshot custom filenames plus envelope/path rejection paths, G-code + program filename rejection paths, and a Chromium localhost round trip for + those persistence paths. - Host-side smoke validation is aggregated by `tests/host/verify_host_smokes.sh` so Node, WASM, OPFS, and browser checks run from one command. diff --git a/wasm-port/docs/source-reuse-map.md b/wasm-port/docs/source-reuse-map.md index cd693cf..9398455 100644 --- a/wasm-port/docs/source-reuse-map.md +++ b/wasm-port/docs/source-reuse-map.md @@ -87,7 +87,8 @@ Current validation is intentionally mechanical: filenames under the session directory, and validates its format, version, session id, metadata, payload shape, and filename boundary. `runtime/opfs/machine-file-store.js` adds pure-text storage for INI, tool - table, parameter file, and G-code program content. + table, parameter file, and G-code program content, with G-code program + filenames constrained by `runtime/opfs/path-model.js`. `runtime/opfs/linuxcnc-parameter-bridge.js` copies OPFS-backed parameter files into the interpreter SDK filesystem and writes back the LinuxCNC-saved parameter file plus backup. `runtime/opfs/linuxcnc-tool-table-bridge.js` diff --git a/wasm-port/tests/browser/ini_panel_smoke.html b/wasm-port/tests/browser/ini_panel_smoke.html index 4f6b9d9..c84f32b 100644 --- a/wasm-port/tests/browser/ini_panel_smoke.html +++ b/wasm-port/tests/browser/ini_panel_smoke.html @@ -9,7 +9,11 @@