Skip to content

feat(node-setup): #21 register-node esbuild 单文件 bundle (闭合 #19 打包缺口) + 镜像/CI 设计 + profiles - #183

Merged
jhfnetboy merged 2 commits into
mainfrom
feat/21-register-bundle
Jul 18, 2026
Merged

jhfnetboy merged 2 commits into
mainfrom
feat/21-register-bundle

Conversation

@jhfnetboy

Copy link
Copy Markdown
Member

#21(镜像+CI)起步,从最有价值、本地可验证的一块入手:板侧 register-node 打包,顺带闭合 #19 遗留的「板侧 @aastar 包缺失」缺口。

改动

  • build-register-bundle.sh(新):esbuild 把 register-node.mjs + @aastar/operator+core+viem bundle 成 register-node.bundle.mjs(~2MB,tree-shaken,纯 JS 无 native → 跨 arch)。板侧只需 node register-node.bundle.mjs,零 node_modules / 零解析问题。
    • 试过 pnpm deploy:symlink 拷不动 + 拉进 vitest/vite 达 230M,弃。esbuild 单文件是干净解。
  • setup-server.py:attempt_onchain_register 优先用 bundle,无则回落源文件(dev)。
  • .gitignore:bundle 是构建产物,不入库。
  • community-node-image-ci-design.md(新):chore: align EIP-712 domain names — PaymentPayload use "aastar.io" #21 整体设计——CI 产物 / 整盘 .wic / 刷机方案×傻瓜度 / T1–T10 真板验收矩阵(含 KMS /pop、一键注册等本地测不了、留给真板的部分)。
  • community-profiles/(新):3 种刷机组合 profile(独立 KMS / 独立 DVT / 联合)+ README(含安全实测路径:板 B 从 SD 卡启动,备用卡克隆测最安全)。

已测 ✅

build-register-bundle.sh 产出的 bundle 从空目录跑通 Sepolia dryRun(@aastar/operator@0.43.0,读到 minStake=30 GToken / requireStake=true)。py_compile / bash -n 通过。

#21 剩余(多轮,本 PR 不含)

TA/CA 交叉编译 CI(Docker,可能需 self-hosted)、整盘 .wic 镜像组装(libguestfs/loop)、发布流水线 + manifest。真板刷机实测待读卡器/备用卡(板 B 是活的生产节点,已全量备份)。

https://claude.ai/code/session_015cWRdv3oPjoQ21PEjwo9m5

…#19 packaging gap) + image/CI design + profiles

#21 起步(最有价值可测的一块):板侧 register-node 打包。
- build-register-bundle.sh: esbuild 把 register-node.mjs + @aastar/operator+core+viem
  bundle 成 register-node.bundle.mjs(~2MB,tree-shaken,纯JS无native→跨arch)。板侧只需
  `node register-node.bundle.mjs`,零 node_modules。已测:空目录跑通 Sepolia dryRun(operator@0.43.0)。
  (试过 pnpm deploy:symlink+dev依赖 230M,弃。)
- setup-server.py: attempt_onchain_register 优先用 bundle,无则回落源文件(dev)。
- .gitignore: bundle 构建产物不入库。
- community-node-image-ci-design.md: #21 整体设计(CI 产物/整盘镜像/刷机方案×傻瓜度/T1-T10 验收矩阵)。
- community-profiles/: 3 种刷机组合 profile(独立KMS/独立DVT/联合) + README(含安全实测路径)。

闭合 #19 的板侧 @aastar 打包缺口。#21 剩:TA/CA 交叉编译 CI、整盘 .wic、发布流水线(多轮)。

Claude-Session: https://claude.ai/code/session_015cWRdv3oPjoQ21PEjwo9m5
@github-actions

Copy link
Copy Markdown

Security Audit Report

Date: Sat Jul 18 13:42:26 UTC 2026
Commit: 3371acb

Cargo Audit Results

�[1m�[33mwarning�[0m: profiles for the non root package will be ignored, specify profiles at the workspace root:
package:   /home/runner/work/AirAccount/AirAccount/kms/host/Cargo.toml
workspace: /home/runner/work/AirAccount/AirAccount/Cargo.toml
�[1m�[92m    Updating�[0m crates.io index
�[1m�[92m     Locking�[0m 1 package to latest compatible version
�[1m�[92m    Updating�[0m kms v0.28.1 (/home/runner/work/AirAccount/AirAccount/kms/host) -> v0.29.0
�[1m�[92mnote�[0m: pass `--verbose` to see 57 unchanged dependencies behind latest
�[0m�[0m�[1m�[32m    Fetching�[0m advisory database from `https://github.com/RustSec/advisory-db.git`
�[0m�[0m�[1m�[32m      Loaded�[0m 1166 security advisories (from /home/runner/.cargo/advisory-db)
�[0m�[0m�[1m�[32m    Updating�[0m crates.io index
�[0m�[0m�[1m�[31merror:�[0m not found: Couldn't load Cargo.lock
Caused by:
  -

... [查看完整报告](artifacts)

@clestons clestons left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ APPROVE — 板侧打包缺口闭合,方案干净,安全卫生到位

kms/node-setup 用 esbuild 把 register-node + @aastar/operator/core + viem 打成单文件 bundle,板侧零 node_modules 跑。放弃 pnpm deploy(symlink + 230M)选 esbuild 单文件是对的取舍。逐文件看过:

对的地方

  • setup-server.py:优先 register-node.bundle.mjs,无则回落源 .mjs;下面 os.path.exists(reg_script) 守卫仍在,两者都缺 → 返回 None → 回落手动登记,不阻断向导。行为保持、fallback 安全。
  • 安全卫生:profile 全是 REPLACE_ME 占位;committed 地址都是公开的(ERC-4337 EntryPoint 0x0000000071727De... + Sepolia validator/gtoken/staking 合约地址,链上可查,非机密)。[secrets] 明确「首启/向导生成,绝不烤进镜像」;TA 签名私钥文档写 CI 注入(GH Secrets/OIDC→KMS),不落仓库。没有密钥泄漏。
  • .gitignore 正确忽略 register-node.bundle.mjs 构建产物。
  • build-register-bundle.sh:set -euo pipefail、mktemp staging + trap rm EXIT 清理、esbuild 双路径查找(.bin → .pnpm)、SDK 版本写进 banner。稳。

一个真 nit(建议修,非阻塞)
build-register-bundle.sh 里 esbuild 是 cd "$STAGE" 后跑的,--outfile="$OUT"。默认 OUT=$HERE/...(绝对路径)没问题;但用法注释写了 ./build-register-bundle.sh [输出路径] —— 若有人传相对路径做 $1,--outfile 会相对 STAGE(临时目录)解析,产物写进 temp 后被 EXIT trap 删掉,脚本还打 ✅「成功」,预期位置却没文件。建议进 STAGE 前把 OUT 规范成绝对路径:

OUT="${1:-$HERE/register-node.bundle.mjs}"
OUT="$(mkdir -p "$(dirname "$OUT")" && cd "$(dirname "$OUT")" && pwd)/$(basename "$OUT")"

无 crypto/绑定逻辑改动(不碰那批安全铁律),findings 仅一处 build 脚本健壮性,不触发 Codex PK。合并交作者。#21 后续(TA/CA 交叉编译 CI、.wic 整盘镜像、真板刷机实测)按 PR 说明留待多轮,合理。


Reviewed by clestons (local-model tier, PR-Daemon)。

esbuild 在 $STAGE 临时目录里跑,相对输出路径会把产物写进临时目录 → trap 删掉却仍打 ✅。
OUT 转绝对路径(便携 case 判断,不依赖 realpath -m)。

Claude-Session: https://claude.ai/code/session_015cWRdv3oPjoQ21PEjwo9m5
@jhfnetboy
jhfnetboy merged commit 7359157 into main Jul 18, 2026
7 checks passed
@jhfnetboy
jhfnetboy deleted the feat/21-register-bundle branch July 18, 2026 13:58
@github-actions github-actions Bot locked and limited conversation to collaborators Jul 18, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants