惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
Apple Machine Learning Research
Apple Machine Learning Research
宝玉的分享
宝玉的分享
博客园 - 叶小钗
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 司徒正美
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - Franky
爱范儿
爱范儿
罗磊的独立博客
IT之家
IT之家
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
N
Netflix TechBlog - Medium
云风的 BLOG
云风的 BLOG
P
Proofpoint News Feed
U
Unit 42
Engineering at Meta
Engineering at Meta
WordPress大学
WordPress大学
博客园 - 三生石上(FineUI控件)
T
Tailwind CSS Blog
H
Help Net Security
博客园_首页
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
人人都是产品经理
人人都是产品经理

Recent Commits to openclaw:main

test: merge chat side-result checks · openclaw/openclaw@ddd2c2a test: merge cron history checks · openclaw/openclaw@f7eb746 test: merge responsive navigation shell checks · openclaw/openclaw@c2e4b47 docs(changelog): add codex oauth fixes · openclaw/openclaw@628e6cd test: merge navigation routing cases · openclaw/openclaw@5d8cecb Tests: mock channel registry bundled fallback · openclaw/openclaw@2b08233 Secrets: avoid broad web search discovery for single plugin config · openclaw/openclaw@a464f59 test: merge config view browser checks · openclaw/openclaw@20cf511 fix(status): align oauth health with runtime · openclaw/openclaw@eed7116 feat: add macOS screen snapshots for monitor preview (#67954) thanks … · openclaw/openclaw@f377db1 fix: report shared auth scopes in hello-ok (#67810) thanks @BunsDev · openclaw/openclaw@0b6c39b Auto-reply: avoid eager bundled route fallback · openclaw/openclaw@3ea1bf4 Tests: narrow session binding contract setup · openclaw/openclaw@54e4e16 fix(macOS): enable undo/redo in webchat composer text input (#34962) · openclaw/openclaw@00951dc Tests: speed up channel setup promotion · openclaw/openclaw@82b529a Docs: refresh agent instructions · openclaw/openclaw@5775fe2 fix(auth): serialize OAuth refresh across agents to fix #26322 (#67876) · openclaw/openclaw@8e79080 test: allow ollama public surface boundary test · openclaw/openclaw@7d4f1a6 Docs: add test performance guardrails · openclaw/openclaw@89706d3 Tests: restore context-engine usage proof · openclaw/openclaw@e4c4f95 Tests: slim context engine runtime coverage · openclaw/openclaw@74c198f ci: retry failed custom checkouts · openclaw/openclaw@0ee5baf test: trim duplicate provider auth onboarding cases · openclaw/openclaw@1ffc02e matrix: fix sessions_spawn --thread subagent session spawning (#67643) · openclaw/openclaw@1ce2596 test: reduce auth choice fixture churn · openclaw/openclaw@857b9cd test: mock health status config boundaries · openclaw/openclaw@9d5ab4a test: mock onboard config io boundary · openclaw/openclaw@299694d test: mock legacy state plugin boundaries · openclaw/openclaw@2713089 test: mock channel install boundaries · openclaw/openclaw@b945248 test: mock doctor preview channel boundaries · openclaw/openclaw@b1a3ad4
fix: proxy direct APNs HTTP2 sessions (#74905) · openclaw...
jesse-merhi · 2026-05-04 · via Recent Commits to openclaw:main

@@ -0,0 +1,120 @@

1+

import fs from "node:fs";

2+

import path from "node:path";

3+

const SOURCE_ROOTS = ["src", "extensions"];

4+

const DEFAULT_SKIPPED_DIR_NAMES = new Set(["node_modules", "dist", "coverage", ".generated"]);

5+6+

function isCodeFile(filePath) {

7+

if (filePath.endsWith(".d.ts")) {

8+

return false;

9+

}

10+

return /\.(?:[cm]?ts|[cm]?js|tsx|jsx)$/u.test(filePath);

11+

}

12+13+

function collectFilesSync(rootDir, options) {

14+

const skipDirNames = options.skipDirNames ?? DEFAULT_SKIPPED_DIR_NAMES;

15+

const files = [];

16+

const stack = [rootDir];

17+18+

while (stack.length > 0) {

19+

const current = stack.pop();

20+

if (!current) {

21+

continue;

22+

}

23+

let entries = [];

24+

try {

25+

entries = fs.readdirSync(current, { withFileTypes: true });

26+

} catch {

27+

continue;

28+

}

29+

for (const entry of entries) {

30+

const fullPath = path.join(current, entry.name);

31+

if (entry.isDirectory()) {

32+

if (!skipDirNames.has(entry.name)) {

33+

stack.push(fullPath);

34+

}

35+

continue;

36+

}

37+

if (entry.isFile() && options.includeFile(fullPath)) {

38+

files.push(fullPath);

39+

}

40+

}

41+

}

42+43+

return files;

44+

}

45+46+

function toPosixPath(filePath) {

47+

return filePath.replaceAll("\\", "/");

48+

}

49+50+

const FORBIDDEN_HTTP2_MODULES = new Set(["node:http2", "http2"]);

51+

const ALLOWED_PRODUCTION_FILES = new Set(["src/infra/push-apns-http2.ts"]);

52+53+

function isTestFile(relativePath) {

54+

return (

55+

/(?:^|\/)(?:test|test-fixtures)\//u.test(relativePath) ||

56+

/\.test\.[cm]?[jt]sx?$/u.test(relativePath)

57+

);

58+

}

59+60+

function lineNumberForOffset(content, offset) {

61+

return content.slice(0, offset).split(/\r?\n/u).length;

62+

}

63+64+

function collectHttp2ImportOffenders(filePath) {

65+

const relativePath = toPosixPath(path.relative(process.cwd(), filePath));

66+

if (ALLOWED_PRODUCTION_FILES.has(relativePath) || isTestFile(relativePath)) {

67+

return [];

68+

}

69+70+

const content = fs.readFileSync(filePath, "utf8");

71+

const offenders = [];

72+

const patterns = [

73+

/\bimport\s+(?:type\s+)?[\s\S]*?\bfrom\s*["']([^"']+)["']/gu,

74+

/\bexport\s+(?:type\s+)?[\s\S]*?\bfrom\s*["']([^"']+)["']/gu,

75+

/\bimport\s*\(\s*["']([^"']+)["']\s*\)/gu,

76+

/\brequire\s*\(\s*["']([^"']+)["']\s*\)/gu,

77+

];

78+79+

for (const pattern of patterns) {

80+

for (const match of content.matchAll(pattern)) {

81+

const specifier = match[1];

82+

if (specifier && FORBIDDEN_HTTP2_MODULES.has(specifier)) {

83+

offenders.push({

84+

file: relativePath,

85+

line: lineNumberForOffset(content, match.index ?? 0),

86+

specifier,

87+

});

88+

}

89+

}

90+

}

91+92+

return offenders;

93+

}

94+95+

function collectSourceFiles() {

96+

return SOURCE_ROOTS.flatMap((root) =>

97+

collectFilesSync(path.join(process.cwd(), root), {

98+

includeFile: isCodeFile,

99+

}),

100+

);

101+

}

102+103+

function main() {

104+

const offenders = collectSourceFiles().flatMap(collectHttp2ImportOffenders);

105+

if (offenders.length === 0) {

106+

console.log("OK: raw node:http2 imports stay behind the APNs proxy wrapper.");

107+

return;

108+

}

109+110+

console.error("Raw node:http2 imports are only allowed in src/infra/push-apns-http2.ts.");

111+

for (const offender of offenders.toSorted(

112+

(a, b) => a.file.localeCompare(b.file) || a.line - b.line,

113+

)) {

114+

console.error(`- ${offender.file}:${offender.line} imports ${offender.specifier}`);

115+

}

116+

console.error("Use connectApnsHttp2Session() so APNs HTTP/2 honors managed proxy policy.");

117+

process.exit(1);

118+

}

119+120+

main();