ryan
c68038ad06
Merge remote-tracking branch 'wavelet/feat/cordis-alignment' into cordis
...
# Conflicts:
# .agents/skills/cache-framework/SKILL.md
# .agents/skills/clickhouse-batchwriter/SKILL.md
# .agents/skills/database-migration/SKILL.md
# .agents/skills/file-upload/SKILL.md
# .agents/skills/logstore/SKILL.md
# .agents/skills/new-api/SKILL.md
# .agents/skills/new-api/references/handler_example.go
# .agents/skills/new-api/references/logics_example.go
# .agents/skills/new-api/references/service_example.go
# .agents/skills/new-async-task/SKILL.md
# .agents/skills/new-async-task/references/CODE-EXAMPLES.md
# .agents/skills/new-setting/SKILL.md
# .agents/skills/push-notification/SKILL.md
# .agents/skills/release-guide/SKILL.md
# .auto/checks.sh
# .auto/ideas.md
# .auto/log.jsonl
# .auto/measure.sh
# .auto/prompt.md
# .dockerignore
# .env.example
# .github/copilot-instructions.md
# .github/workflows/build-release.yml
# .gitignore
# .golangci.yml
# AGENTS.md
# Makefile
# README.md
# backend/cmd/app.go
# backend/cmd/app_test.go
# backend/cmd/banner.go
# backend/cmd/banner_test.go
# backend/docs/docs.go
# backend/docs/swagger.json
# backend/docs/swagger.yaml
# backend/go.mod
# backend/go.sum
# backend/main.go
# config.example.yaml
# docker/Dockerfile
# docker/Dockerfile.backend
# docker/Dockerfile.cross
# scripts/swagger.sh
# scripts/update_go_license.sh
2026-08-30 14:30:56 +08:00
ryan
3b24d248a7
docs(autoresearch): proposals for the five deferred architectural items
2026-08-29 19:32:35 +08:00
ryan
350bd422f5
chore(autoresearch): log iter 35
2026-08-29 19:31:41 +08:00
ryan
db9d12f8c9
chore(autoresearch): log iter 34
2026-08-29 19:20:50 +08:00
ryan
578b4618ce
chore(autoresearch): log iter 33
2026-08-29 19:15:27 +08:00
ryan
608cce19c9
docs(autoresearch): lesson 12 and harness standing notes
2026-08-29 19:06:00 +08:00
ryan
6e5ed979e4
chore(autoresearch): log iter 32
2026-08-29 19:05:17 +08:00
ryan
22a491ff37
chore(autoresearch): log iter 31
2026-08-29 18:57:29 +08:00
ryan
5193bd0451
autoresearch iter 31: isolate lint result cache per checkout in harness
2026-08-29 18:55:36 +08:00
ryan
53fc3a81dc
chore(autoresearch): log iter 30
2026-08-29 18:51:56 +08:00
ryan
f29ac19673
chore(autoresearch): log iter 29
2026-08-29 18:46:21 +08:00
ryan
4412093d05
chore(autoresearch): log iter 28 discard
2026-08-29 18:42:44 +08:00
ryan
8b746e1d0e
chore(autoresearch): log iter 27
2026-08-29 18:34:01 +08:00
Ryan
53ae3007d0
fix(cordis): fail-closed auth guards for user/message_gateway/admin ( #1 )
...
* autoresearch iter 23: fail-closed auth guarding for user/message_gateway
Both plugins resolve contracts.AuthService in Apply to build their route
middleware, but declared only DBService in Inject(). The kernel gates a
plugin's Apply solely on declared deps, and cmd/app.go registers user
before auth, so user mounted first, core.Inject failed, and loginMW
silently degraded to a pass-through closure — leaving /api/v1/user
change-password, profile and access-tokens unguarded. message_gateway
was saved only by its later list position.
Declare AuthService in Inject() for both, and pin the property with a
reconcile-level test that mirrors production registration order and
asserts the real auth middleware reaches the route table.
* autoresearch iter 24: make auth middleware fallbacks fail closed
user, message_gateway and admin each fell back to a c.Next() closure when
contracts.AuthService could not be resolved, so a route would be served as
if authenticated. For admin this is reachable at runtime: OnDispose calls
service.ResetServices(), which nils the global the per-request guard reads,
so requests still in flight during dispose bypass authorization entirely.
Add ginutil.AuthUnavailable() and bind every fallback to it, with a test
that drives each plugin's registered guard without an auth service present
and asserts the request is aborted rather than passed through.
* chore(autoresearch): log iter 23 (fail-open auth ordering, proven)
* autoresearch iter 24 follow-up: let staticcheck infer the auth guard type
* docs(autoresearch): log iters 24-25 and lessons 9-11 (declared-dep bug class, gate discipline)
2026-08-29 11:21:04 +08:00
ryan
b3c4d6cb99
docs(autoresearch): lessons 6-8 (audit verification, counting doubles, gate+veto discipline)
2026-08-29 09:56:24 +08:00
ryan
6011effade
chore(autoresearch): log iter 22 (debt 79 -> 54)
2026-08-29 09:55:24 +08:00
ryan
b6f2221280
chore(autoresearch): log iter 21
2026-08-29 09:41:30 +08:00
ryan
9c0f31fad0
chore(autoresearch): log iter 20
...
Note: iter 20's commit also captured an in-flight edit to
docs/superpowers/plans/2026-08-29-cordis-config-extension.md belonging to a
concurrent session, because it used 'git add -A'. Content is intact; later
iterations stage explicit paths only.
2026-08-29 09:35:50 +08:00
ryan
ae8bbd98f8
chore(autoresearch): log iter 19
2026-08-29 09:24:33 +08:00
ryan
020ebebfaa
chore(autoresearch): log iter 18
2026-08-29 09:12:03 +08:00
ryan
d80f9d209b
chore(autoresearch): log iter 17
2026-08-29 09:03:54 +08:00
ryan
84946977bf
chore(autoresearch): log iter 16 (perf, contract batch)
2026-08-29 08:52:18 +08:00
ryan
5df282f296
chore(autoresearch): log iter 15 (perf, proven)
2026-08-29 08:45:21 +08:00
ryan
2654eb6e2c
chore(autoresearch): correct iter 14 log (debt held at 79, kept via proven-fix gate)
2026-08-29 08:39:53 +08:00
ryan
45bf1d8933
chore(autoresearch): log iter 14
2026-08-29 08:39:38 +08:00
ryan
00ab727791
chore(autoresearch): log iter 12 (debt 80 -> 79)
2026-08-29 08:35:26 +08:00
ryan
2c8020188d
chore(autoresearch): log iter 11 (debt 84 -> 80)
2026-08-29 08:33:56 +08:00
ryan
643bfca996
chore(autoresearch): log iter 10 (debt 87 -> 84, errorlint 12 -> 0)
2026-08-29 08:30:33 +08:00
ryan
f7fd980429
chore(autoresearch): log iter 9 (debt 89 -> 87)
2026-08-29 08:27:21 +08:00
ryan
a529700ed3
chore(autoresearch): log iter 8 (proven bug fix, debt held at 89)
2026-08-29 08:24:09 +08:00
ryan
03f48a9a80
chore(autoresearch): log iter 7 (debt 92 -> 89)
2026-08-29 08:21:24 +08:00
ryan
bf364f4036
chore(autoresearch): log iter 6, distinguish compile-level from assertion-level proof
2026-08-29 08:17:59 +08:00
ryan
ce33997c23
autoresearch iter 6: reject negative cursor instead of silently using 0
...
parsePositiveInt reported invalidity through a bool that both call sites
discarded, and returned (false, nil) whenever Atoi succeeded on a negative
number. GetLogs therefore accepted ?cursor=-5 and served it as cursor 0
('latest') instead of the documented 400. Validity now travels through the
error result, which no caller can ignore.
2026-08-29 08:16:50 +08:00
ryan
58c34ad5c1
chore(autoresearch): log iter 5 (4 bare goroutines hardened, gate widened)
2026-08-29 08:13:17 +08:00
ryan
57b39f7fcf
chore(autoresearch): log iter 4 (proven bug fix, debt held at 93)
2026-08-29 08:08:16 +08:00
ryan
5b84fd906d
chore(autoresearch): log iter 3 (debt 95 -> 93)
2026-08-29 08:03:26 +08:00
ryan
4e6209bf61
chore(autoresearch): log iter 2 (debt 100 -> 95)
2026-08-29 07:59:39 +08:00
ryan
edf0c0e934
chore(autoresearch): log iter 1 (debt 102 -> 100, proven fix)
2026-08-29 07:57:10 +08:00
ryan
5971e2a9ed
chore(autoresearch): re-baseline harness on pinned real-risk yardstick
...
The committed golangci gate now reports 0 issues, so the previous
lint_issues metric was saturated and could no longer measure progress.
Measure debt against an immutable .auto/lint.ref.yaml snapshot that adds
analyzers for genuine defects (panics, error unwrapping, dead stores,
missing enum cases, method ordering, suppression hygiene) while excluding
cosmetic churn (tagliatelle, wrapcheck). Guard enforces build, vet, tests,
the Cordis architecture gate, and anti-cheat floors: the yardstick cannot
be edited, the project gate may only be strengthened, nolint directives may
only shrink, and no test may disappear.
2026-08-29 07:52:03 +08:00
ryan
4d6be2fa77
fix(drivers): propagate app-lifetime context through inproc cron/worker drivers
...
cron 触发与 worker 执行的任务现在继承应用生命周期 context(关闭时级联取消,带超时子上下文),
替代裸 context.Background()。contextcheck 清零。
lint_issues 26→24
2026-08-28 17:04:44 +08:00
ryan
02b93a3b20
chore(autoresearch): log iter 2-3
2026-08-28 16:53:51 +08:00
ryan
867fcb2288
refactor: revive cleanup — unused params to _, add missing doc comments
...
- admin/db_helper GetCache/GetUserService/GetAuthService: ctx -> _ (签名对称保留)
- validateMergedStorageConfig / ParseMigrationTargetConfig / MockStorageService.Put 未用参数 -> _
- SetDBServiceForTest、StorageDriver 常量组补充文档注释
lint_issues 33→26
2026-08-28 16:53:32 +08:00
ryan
cf85a56aa7
refactor: eliminate string/magic-number literals (goconst, mnd) and fix const-type grouping (SA9004)
...
- upload/task: taskCategoryUpload/taskQueueDefault 常量替代 8 处字面量
- admin: 复用既有 logDBNameSQLite 常量替代 3 处 "sqlite" 字面量
- pkg/cache/disk: defaultCleanupInterval 命名常量
- driver_asynq_worker/executor: 分离 contextKey 类型常量组
lint_issues 45→34, tests 44/44
2026-08-28 16:38:18 +08:00
ryan
528240026d
chore(lint): unify formatting on golangci-lint fmt (gofumpt), uncap issue reporting, fix gofumpt drift
...
- make format 现在与 code-check 使用同一格式化器(golangci-lint fmt),消除 goimports -local 与 gofumpt 的格式拉锯
- .golangci.yml 关闭默认 50/3 截断,完整上报所有问题(只增强不弱化)
- 全库 gofumpt 规范化(203 files, 纯格式无行为变更)
2026-08-28 16:31:53 +08:00
ryan
078ad9b2f3
chore(autoresearch): init cordis-quality session files
2026-08-28 16:21:34 +08:00
ryan
2b69f4d8d7
#60 GeoIP 共享单例化:消除访问日志 region 解析每批次的 mmdb 重建开销与无界缓存,ctx 贯穿下载路径
...
Result: {"status":"keep","total_issues":8,"eslint_errors":0,"eslint_problems":0,"eslint_warnings":0,"golint_canonicalheader":0,"golint_errname":0,"golint_errorlint":1,"golint_exhaustive":0,"golint_forcetypeassert":0,"golint_gosec":0,"golint_intrange":0,"golint_modernize":3,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":0,"golint_recvcheck":1,"golint_test_testifylint":0,"golint_test_thelper":0,"golint_test_total":0,"golint_test_usetesting":0,"golint_total":8,"golint_usestdlibvars":0,"golint_vetx_total":0,"golint_wastedassign":0,"measure_s":81,"tsc_errors":0,"vitest_failed":0,"vitest_total":126}
2026-08-26 13:48:44 +08:00
ryan
b56f27632a
#59 -shuffle=on 扫描抓到测试顺序依赖:config_version RAM 配置缓存跨测试污染,setup/cleanup 接入 ram.ResetForTest() 修复
...
Result: {"status":"keep","total_issues":8,"eslint_errors":0,"eslint_problems":0,"eslint_warnings":0,"golint_canonicalheader":0,"golint_errname":0,"golint_errorlint":1,"golint_exhaustive":0,"golint_forcetypeassert":0,"golint_gosec":0,"golint_intrange":0,"golint_modernize":3,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":0,"golint_recvcheck":1,"golint_test_testifylint":0,"golint_test_thelper":0,"golint_test_total":0,"golint_test_usetesting":0,"golint_total":8,"golint_usestdlibvars":0,"golint_vetx_total":0,"golint_wastedassign":0,"measure_s":66,"tsc_errors":0,"vitest_failed":0,"vitest_total":126}
2026-08-26 13:35:20 +08:00
ryan
fc733d0295
#57 enqueue 修复的同型残留收口:SendFlaredPong/SendRelayPong 合并 select 随机选择 bug,委托 client.enqueue 去重修复
...
Result: {"status":"keep","total_issues":8,"eslint_errors":0,"eslint_problems":0,"eslint_warnings":0,"golint_canonicalheader":0,"golint_errname":0,"golint_errorlint":1,"golint_exhaustive":0,"golint_forcetypeassert":0,"golint_gosec":0,"golint_intrange":0,"golint_modernize":3,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":0,"golint_recvcheck":1,"golint_test_testifylint":0,"golint_test_thelper":0,"golint_test_total":0,"golint_test_usetesting":0,"golint_total":8,"golint_usestdlibvars":0,"golint_vetx_total":0,"golint_wastedassign":0,"measure_s":77,"tsc_errors":0,"vitest_failed":0,"vitest_total":126}
2026-08-26 13:20:35 +08:00
ryan
453f7e5d90
周期性 -race 重跑抓到真实 bug:wsClientCore.enqueue close 后 select 随机选择致契约违反;确定性先查 done 修复+测试循环加固+gofmt 存量漂移清理
...
Result: {"status":"keep","total_issues":8,"eslint_errors":0,"eslint_problems":0,"eslint_warnings":0,"golint_canonicalheader":0,"golint_errname":0,"golint_errorlint":1,"golint_exhaustive":0,"golint_forcetypeassert":0,"golint_gosec":0,"golint_intrange":0,"golint_modernize":3,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":0,"golint_recvcheck":1,"golint_test_testifylint":0,"golint_test_thelper":0,"golint_test_total":0,"golint_test_usetesting":0,"golint_total":8,"golint_usestdlibvars":0,"golint_vetx_total":0,"golint_wastedassign":0,"measure_s":95,"tsc_errors":0,"vitest_failed":0,"vitest_total":126}
2026-08-26 13:14:59 +08:00
ryan
63e3b85294
富交互页 a11y 抽查收尾:8+3 页扫描,修复 cloudflare 筛选器无名/access-token amber 对比度/notifications 缺 h1 共 3 处,全部复扫归零;基准 total_issues 保持 8
...
Result: {"status":"keep","total_issues":8,"eslint_errors":0,"eslint_problems":0,"eslint_warnings":0,"golint_canonicalheader":0,"golint_errname":0,"golint_errorlint":1,"golint_exhaustive":0,"golint_forcetypeassert":0,"golint_gosec":0,"golint_intrange":0,"golint_modernize":3,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":0,"golint_recvcheck":1,"golint_test_testifylint":0,"golint_test_thelper":0,"golint_test_total":0,"golint_test_usetesting":0,"golint_total":8,"golint_usestdlibvars":0,"golint_vetx_total":0,"golint_wastedassign":0,"measure_s":85,"tsc_errors":0,"vitest_failed":0,"vitest_total":126}
2026-08-26 13:05:16 +08:00