Repository navigation
Conversation
owent
marked this pull request as ready for review
September 23, 2026 14:35
Copilot stopped reviewing on behalf of
owent due to an error
September 23, 2026 14:36
There was a problem hiding this comment.
Note
Copilot was unable to run its full agentic suite in this review.
Copilot review overview
Review effort: Lite
Findings: 2
Open (4)
This edit removes the explicit security/behavior contract about the Python downloader (official… · New The URL allowlist is hard-coded as full path prefixes, which duplicates repo identity in multiple… · New This change deletes the entire historical plan and replaces it with a brief statement. If the plan… · New Docstring formatting: this URL line lost the indentation/alignment used by surrounding docstring… · New
What changed in this PR
This PR updates the legacy Python shim and documentation to reflect the repository’s move to owent/xresconv-cli, while keeping compatibility with older xresloader/... GitHub release asset URLs and bumping the Rust crate version to 2.0.1.
Changes:
- Point Python shim (API/page links) and README/docs to
owent/xresconv-cliand allow both old/new release asset URL prefixes. - Extend Python shim unit tests to cover both owners and reject spoofed owners.
- Update release/versioning docs and bump
Cargo.tomlto2.0.1with corresponding HISTORY entry.
| File | Description |
|---|---|
| xresconv_cli.py | Switch GitHub owner endpoints and relax asset URL validation to accept both org paths |
| tests/test_python_shim.py | Add coverage for both owners; assert rejection of foreign/spoofed owners |
| doc/migration-contract.md | Update CI/release verification narrative and links |
| doc/ai/validation.md | Record CI + tag-release verification evidence and the Python shim fix validation |
| doc/ai/source-index.md | Refresh CI evidence references to recent successful runs |
| doc/ai/requirements-coverage.md | Update statements about Rust project existence and scope boundaries |
| README.md | Update release links and release process examples to new versions/org |
| Plan.md | Replace detailed plan with a short “done” pointer to contract/validation docs |
| HISTORY.md | Add 2.0.1 entry documenting the Python shim URL validation fix |
| Cargo.toml | Bump crate version to 2.0.1 |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| @@ -58,7 +58,9 @@ XML 的 `option` 仍是已有后端命令片段,其内部引号由配置作者 | |||
| 不修改 XML/输入数据,不自动删除旧版。已缓存二进制不会在每次启动时联网升级。 | |||
Comment on lines
+109
to
115
| allowed_paths = ( | ||
| "/owent/xresconv-cli/releases/download/", | ||
| "/xresloader/xresconv-cli/releases/download/", | ||
| ) | ||
| if (parsed.scheme != "https" or parsed.netloc != "github.com" | ||
| or not parsed.path.startswith("/xresloader/xresconv-cli/releases/download/")): | ||
| or not parsed.path.startswith(allowed_paths)): | ||
| raise RuntimeError("invalid GitHub release asset URL") |
| 继续从上述外部验收项开始;不要把历史“尚未实现/下一步 P1”描述重新当作现状。 | ||
| 下载或发布失败先检查当前 Release 状态,已有公开版本不覆盖;回滚说明见迁移合同。 | ||
| 以前的 44/46 测试计数及“草稿即发布”状态已由本轮实测纠正,历史审计保留于验证记录与 Git。 | ||
| 当前无未完成任务。Rust 迁移、兼容测试、跨平台构建和公开发布的证据见 [迁移合同](doc/migration-contract.md) 与 [验证记录](doc/ai/validation.md)。 |
|
|
||
| Rust 版本发布页(含各平台预编译二进制): | ||
| https://github.com/xresloader/xresconv-cli/releases | ||
| https://github.com/owent/xresconv-cli/releases |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


公开 v2.0.0 Release 的资产 URL 使用规范仓库路径
owent/xresconv-cli。旧 Python 入口只接受旧组织路径,导致首次自动下载报invalid GitHub release asset URL。本变更接受规范和旧组织路径,保留 GitHub 主机限制,并将 Cargo 版本更新为已发布的 v2.0.1。同时清理已完成的 Plan 待办,记录常规 CI、首次 tag 发布、v2.0.1 发布及公开下载验收。按用户指示,规则注入、Skill 发现和 Python 2.7 运行不再作为验收门禁。
验证:Windows 本地
cargo fmt/check/test/clippy --locked全通过(83 个 Rust 测试、13 个 Python 离线 unittest);v2.0.1 发布流水线 20 个 job 全通过。公开 latest Release 的 11 个包及校验和核验通过,全部可解压;Windows x64 和 Linux x64 GNU/musl 解压后可运行。旧 Python 入口从空缓存下载并运行 v2.0.1,退出 0。