Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11), free to diverge. Tree copied sans upstream .git; upstream remote added for future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19. Preserves docs/ARCHITECTURE.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
153 lines
4.4 KiB
JavaScript
153 lines
4.4 KiB
JavaScript
// Caches source file discovery and bounded-concurrency reads for guard scripts.
|
|
import { promises as fs } from "node:fs";
|
|
import path from "node:path";
|
|
|
|
const DEFAULT_SOURCE_FILE_READ_CONCURRENCY = 32;
|
|
export const DEFAULT_SOURCE_FILE_MAX_BYTES = 2 * 1024 * 1024;
|
|
const scanCache = new Map();
|
|
|
|
function normalizeRepoPath(repoRoot, filePath) {
|
|
return path.relative(repoRoot, filePath).split(path.sep).join("/");
|
|
}
|
|
|
|
async function walkFiles(params, rootDir) {
|
|
const out = [];
|
|
let entries;
|
|
try {
|
|
entries = await fs.readdir(rootDir, { withFileTypes: true });
|
|
} catch (error) {
|
|
if (error && typeof error === "object" && "code" in error && error.code === "ENOENT") {
|
|
return out;
|
|
}
|
|
throw error;
|
|
}
|
|
entries.sort((left, right) => left.name.localeCompare(right.name));
|
|
for (const entry of entries) {
|
|
const entryPath = path.join(rootDir, entry.name);
|
|
if (entry.isDirectory()) {
|
|
if (!params.ignoredDirNames.has(entry.name)) {
|
|
out.push(...(await walkFiles(params, entryPath)));
|
|
}
|
|
continue;
|
|
}
|
|
if (entry.isFile() && params.scanExtensions.has(path.extname(entry.name))) {
|
|
out.push(entryPath);
|
|
}
|
|
}
|
|
return out;
|
|
}
|
|
|
|
function normalizeConcurrency(value) {
|
|
if (!Number.isInteger(value) || value < 1) {
|
|
return DEFAULT_SOURCE_FILE_READ_CONCURRENCY;
|
|
}
|
|
return value;
|
|
}
|
|
|
|
function normalizeMaxFileBytes(value) {
|
|
if (!Number.isInteger(value) || value < 1) {
|
|
return DEFAULT_SOURCE_FILE_MAX_BYTES;
|
|
}
|
|
return value;
|
|
}
|
|
|
|
function assertSourceFileWithinLimit(relativeFile, bytes, maxFileBytes) {
|
|
if (bytes <= maxFileBytes) {
|
|
return;
|
|
}
|
|
throw new Error(
|
|
`source scan file exceeds ${maxFileBytes} byte limit: ${relativeFile} (${bytes} bytes)`,
|
|
);
|
|
}
|
|
|
|
async function readBoundedSourceFile(params, filePath, readFile, statFile, maxFileBytes) {
|
|
const relativeFile = normalizeRepoPath(params.repoRoot, filePath);
|
|
const stat = await statFile(filePath);
|
|
assertSourceFileWithinLimit(relativeFile, stat.size, maxFileBytes);
|
|
const content = await readFile(filePath, "utf8");
|
|
assertSourceFileWithinLimit(relativeFile, Buffer.byteLength(content, "utf8"), maxFileBytes);
|
|
return {
|
|
filePath,
|
|
relativeFile,
|
|
content,
|
|
};
|
|
}
|
|
|
|
/**
|
|
* Maps items with bounded worker concurrency while preserving input order.
|
|
*/
|
|
export async function mapWithConcurrency(items, concurrency, mapper) {
|
|
const out = Array.from({ length: items.length });
|
|
const workerCount = Math.min(normalizeConcurrency(concurrency), items.length);
|
|
let nextIndex = 0;
|
|
|
|
async function worker() {
|
|
for (;;) {
|
|
const index = nextIndex;
|
|
nextIndex += 1;
|
|
if (index >= items.length) {
|
|
return;
|
|
}
|
|
out[index] = await mapper(items[index], index);
|
|
}
|
|
}
|
|
|
|
await Promise.all(Array.from({ length: workerCount }, () => worker()));
|
|
return out;
|
|
}
|
|
|
|
/**
|
|
* Collects sorted source files and cached contents for configured scan roots.
|
|
*/
|
|
export async function collectSourceFileContents(params) {
|
|
const useCache = !params.readFile;
|
|
const cacheKey = JSON.stringify({
|
|
repoRoot: params.repoRoot,
|
|
scanRoots: params.scanRoots,
|
|
scanExtensions: [...params.scanExtensions].toSorted((left, right) => left.localeCompare(right)),
|
|
ignoredDirNames: [...params.ignoredDirNames].toSorted((left, right) =>
|
|
left.localeCompare(right),
|
|
),
|
|
maxFileBytes: normalizeMaxFileBytes(params.maxFileBytes),
|
|
});
|
|
if (useCache) {
|
|
const cached = scanCache.get(cacheKey);
|
|
if (cached) {
|
|
return await cached;
|
|
}
|
|
}
|
|
|
|
const promise = (async () => {
|
|
const files = (
|
|
await Promise.all(
|
|
params.scanRoots.map(async (root) => walkFiles(params, path.join(params.repoRoot, root))),
|
|
)
|
|
)
|
|
.flat()
|
|
.toSorted((left, right) =>
|
|
normalizeRepoPath(params.repoRoot, left).localeCompare(
|
|
normalizeRepoPath(params.repoRoot, right),
|
|
),
|
|
);
|
|
|
|
const readFile = params.readFile ?? fs.readFile;
|
|
const statFile = params.statFile ?? fs.stat;
|
|
const maxFileBytes = normalizeMaxFileBytes(params.maxFileBytes);
|
|
return await mapWithConcurrency(files, params.maxConcurrentReads, async (filePath) =>
|
|
readBoundedSourceFile(params, filePath, readFile, statFile, maxFileBytes),
|
|
);
|
|
})();
|
|
|
|
if (useCache) {
|
|
scanCache.set(cacheKey, promise);
|
|
}
|
|
try {
|
|
return await promise;
|
|
} catch (error) {
|
|
if (useCache) {
|
|
scanCache.delete(cacheKey);
|
|
}
|
|
throw error;
|
|
}
|
|
}
|