feat(node-setup): #21 register-node esbuild 单文件 bundle (闭合 #19 打包缺口) + 镜像/CI 设计 + profiles - #183
Merged
Merged
Conversation
…#19 packaging gap) + image/CI design + profiles #21 起步(最有价值可测的一块):板侧 register-node 打包。 - build-register-bundle.sh: esbuild 把 register-node.mjs + @aastar/operator+core+viem bundle 成 register-node.bundle.mjs(~2MB,tree-shaken,纯JS无native→跨arch)。板侧只需 `node register-node.bundle.mjs`,零 node_modules。已测:空目录跑通 Sepolia dryRun(operator@0.43.0)。 (试过 pnpm deploy:symlink+dev依赖 230M,弃。) - setup-server.py: attempt_onchain_register 优先用 bundle,无则回落源文件(dev)。 - .gitignore: bundle 构建产物不入库。 - community-node-image-ci-design.md: #21 整体设计(CI 产物/整盘镜像/刷机方案×傻瓜度/T1-T10 验收矩阵)。 - community-profiles/: 3 种刷机组合 profile(独立KMS/独立DVT/联合) + README(含安全实测路径)。 闭合 #19 的板侧 @aastar 打包缺口。#21 剩:TA/CA 交叉编译 CI、整盘 .wic、发布流水线(多轮)。 Claude-Session: https://claude.ai/code/session_015cWRdv3oPjoQ21PEjwo9m5
Security Audit ReportDate: Sat Jul 18 13:42:26 UTC 2026 Cargo Audit Results |
clestons
approved these changes
Jul 18, 2026
clestons
left a comment
Contributor
There was a problem hiding this comment.
✅ APPROVE — 板侧打包缺口闭合,方案干净,安全卫生到位
kms/node-setup 用 esbuild 把 register-node + @aastar/operator/core + viem 打成单文件 bundle,板侧零 node_modules 跑。放弃 pnpm deploy(symlink + 230M)选 esbuild 单文件是对的取舍。逐文件看过:
对的地方
setup-server.py:优先register-node.bundle.mjs,无则回落源.mjs;下面os.path.exists(reg_script)守卫仍在,两者都缺 → 返回 None → 回落手动登记,不阻断向导。行为保持、fallback 安全。- 安全卫生:profile 全是
REPLACE_ME占位;committed 地址都是公开的(ERC-4337 EntryPoint0x0000000071727De...+ Sepolia validator/gtoken/staking 合约地址,链上可查,非机密)。[secrets]明确「首启/向导生成,绝不烤进镜像」;TA 签名私钥文档写 CI 注入(GH Secrets/OIDC→KMS),不落仓库。没有密钥泄漏。 .gitignore正确忽略register-node.bundle.mjs构建产物。build-register-bundle.sh:set -euo pipefail、mktemp staging +trap rm EXIT清理、esbuild 双路径查找(.bin→.pnpm)、SDK 版本写进 banner。稳。
一个真 nit(建议修,非阻塞)
build-register-bundle.sh 里 esbuild 是 cd "$STAGE" 后跑的,--outfile="$OUT"。默认 OUT=$HERE/...(绝对路径)没问题;但用法注释写了 ./build-register-bundle.sh [输出路径] —— 若有人传相对路径做 $1,--outfile 会相对 STAGE(临时目录)解析,产物写进 temp 后被 EXIT trap 删掉,脚本还打 ✅「成功」,预期位置却没文件。建议进 STAGE 前把 OUT 规范成绝对路径:
OUT="${1:-$HERE/register-node.bundle.mjs}"
OUT="$(mkdir -p "$(dirname "$OUT")" && cd "$(dirname "$OUT")" && pwd)/$(basename "$OUT")"无 crypto/绑定逻辑改动(不碰那批安全铁律),findings 仅一处 build 脚本健壮性,不触发 Codex PK。合并交作者。#21 后续(TA/CA 交叉编译 CI、.wic 整盘镜像、真板刷机实测)按 PR 说明留待多轮,合理。
Reviewed by clestons (local-model tier, PR-Daemon)。
esbuild 在 $STAGE 临时目录里跑,相对输出路径会把产物写进临时目录 → trap 删掉却仍打 ✅。 OUT 转绝对路径(便携 case 判断,不依赖 realpath -m)。 Claude-Session: https://claude.ai/code/session_015cWRdv3oPjoQ21PEjwo9m5
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
#21(镜像+CI)起步,从最有价值、本地可验证的一块入手:板侧 register-node 打包,顺带闭合 #19 遗留的「板侧 @aastar 包缺失」缺口。
改动
build-register-bundle.sh(新):esbuild 把register-node.mjs+@aastar/operator+core+viembundle 成register-node.bundle.mjs(~2MB,tree-shaken,纯 JS 无 native → 跨 arch)。板侧只需node register-node.bundle.mjs,零 node_modules / 零解析问题。pnpm deploy:symlink 拷不动 + 拉进 vitest/vite 达 230M,弃。esbuild 单文件是干净解。setup-server.py:attempt_onchain_register优先用 bundle,无则回落源文件(dev)。.gitignore:bundle 是构建产物,不入库。community-node-image-ci-design.md(新):chore: align EIP-712 domain names — PaymentPayload use "aastar.io" #21 整体设计——CI 产物 / 整盘 .wic / 刷机方案×傻瓜度 / T1–T10 真板验收矩阵(含 KMS /pop、一键注册等本地测不了、留给真板的部分)。community-profiles/(新):3 种刷机组合 profile(独立 KMS / 独立 DVT / 联合)+ README(含安全实测路径:板 B 从 SD 卡启动,备用卡克隆测最安全)。已测 ✅
build-register-bundle.sh产出的 bundle 从空目录跑通 Sepolia dryRun(@aastar/operator@0.43.0,读到 minStake=30 GToken / requireStake=true)。py_compile/bash -n通过。#21 剩余(多轮,本 PR 不含)
TA/CA 交叉编译 CI(Docker,可能需 self-hosted)、整盘
.wic镜像组装(libguestfs/loop)、发布流水线 + manifest。真板刷机实测待读卡器/备用卡(板 B 是活的生产节点,已全量备份)。https://claude.ai/code/session_015cWRdv3oPjoQ21PEjwo9m5