mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-12 21:53:00 -06:00
84c7d45f15
* refactor(qqbot): remove bundled extension source Mechanical deletion half of the #107295 squashed rebase; the catalog repoint and host integration land in the follow-up commit. Co-authored-by: sliverp <870080352@qq.com> * refactor(qqbot): install plugin from Tencent package Squashed rebase of #107295 onto current main. Repoints the official external channel catalog at @tencent-connect/openclaw-qqbot@2.0.1 and adapts onboarding, doctor migrations, secrets, build guards, and tests. Documents the known limitation that the external package does not support structured SecretRef clientSecret values; operators move those to QQBOT_CLIENT_SECRET or clientSecretFile before upgrading. Co-authored-by: sliverp <870080352@qq.com> * fix(doctor): reuse shared hasOwnKey record helper The rebased QQBot migration carried its own hasOwnKey export, colliding with the one main now ships in legacy-config-record-shared.ts. Co-authored-by: sliverp <870080352@qq.com> * fix(plugins): carry catalog integrity through the update bridge The externalized-bundled-plugin bridge dropped the official catalog's expectedIntegrity pin, so bundled-user updates installed the external npm package without integrity verification. The bridge now carries the pin for the catalog's exact npm spec and both bridge install calls pass it through; update-channel spec overrides intentionally skip the pin since it only covers the pinned version. Co-authored-by: sliverp <870080352@qq.com> * chore(plugin-sdk): refresh per-entrypoint API baselines The QQBot compat export and bundled-type removal shift 26 entrypoint closure hashes in the new split baseline layout. Co-authored-by: sliverp <870080352@qq.com> * refactor(qqbot): drop helper reintroduced during rebase Main's coercion consolidation added this file after the deletion commit's base; its only consumers were the removed qqbot sources. Co-authored-by: sliverp <870080352@qq.com> --------- Co-authored-by: Peter Steinberger <steipete@gmail.com>
383 lines
13 KiB
TypeScript
383 lines
13 KiB
TypeScript
// Verify Plugin Npm Published Runtime tests cover verify plugin npm published runtime script behavior.
|
|
import { describe, expect, it } from "vitest";
|
|
import {
|
|
collectPluginNpmPublishedRuntimeErrors,
|
|
findPackedPackageReadmePath,
|
|
parseVerifyPublishedPluginRuntimeArgs,
|
|
parseNpmReadmeMetadata,
|
|
readPluginNpmCommandOptions,
|
|
readPositiveIntEnv,
|
|
resolveNpmPackFilename,
|
|
runPluginNpmCommand,
|
|
usage,
|
|
} from "../../scripts/verify-plugin-npm-published-runtime.mts";
|
|
|
|
describe("plugin npm publish verifier args", () => {
|
|
it("parses help and package specs before npm calls", () => {
|
|
expect(parseVerifyPublishedPluginRuntimeArgs(["--help"])).toEqual({ help: true, spec: "" });
|
|
expect(parseVerifyPublishedPluginRuntimeArgs(["--", "@openclaw/discord@2026.5.2"])).toEqual({
|
|
help: false,
|
|
spec: "@openclaw/discord@2026.5.2",
|
|
});
|
|
});
|
|
|
|
it("rejects unknown and extra args before npm calls", () => {
|
|
expect(() => parseVerifyPublishedPluginRuntimeArgs([])).toThrow(usage());
|
|
expect(() => parseVerifyPublishedPluginRuntimeArgs(["--wat"])).toThrow(
|
|
"Unknown plugin npm verifier option: --wat",
|
|
);
|
|
expect(() =>
|
|
parseVerifyPublishedPluginRuntimeArgs(["@openclaw/discord@2026.5.2", "extra"]),
|
|
).toThrow("Unexpected plugin npm verifier argument: extra");
|
|
});
|
|
});
|
|
|
|
describe("plugin npm publish verifier retry limits", () => {
|
|
it("rejects loose numeric retry env values instead of parsing prefixes", () => {
|
|
expect(() =>
|
|
readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_VERIFY_ATTEMPTS", 90, {
|
|
OPENCLAW_PLUGIN_NPM_VERIFY_ATTEMPTS: "2tries",
|
|
}),
|
|
).toThrow("invalid OPENCLAW_PLUGIN_NPM_VERIFY_ATTEMPTS: 2tries");
|
|
expect(() =>
|
|
readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_VERIFY_DELAY_MS", 10000, {
|
|
OPENCLAW_PLUGIN_NPM_VERIFY_DELAY_MS: "1e3",
|
|
}),
|
|
).toThrow("invalid OPENCLAW_PLUGIN_NPM_VERIFY_DELAY_MS: 1e3");
|
|
expect(() =>
|
|
readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_README_VERIFY_ATTEMPTS", 6, {
|
|
OPENCLAW_PLUGIN_NPM_README_VERIFY_ATTEMPTS: "0",
|
|
}),
|
|
).toThrow("invalid OPENCLAW_PLUGIN_NPM_README_VERIFY_ATTEMPTS: 0");
|
|
});
|
|
|
|
it("accepts strict positive retry env values and defaults", () => {
|
|
expect(readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_VERIFY_ATTEMPTS", 90, {})).toBe(90);
|
|
expect(
|
|
readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_README_VERIFY_DELAY_MS", 10000, {
|
|
OPENCLAW_PLUGIN_NPM_README_VERIFY_DELAY_MS: "2500",
|
|
}),
|
|
).toBe(2500);
|
|
});
|
|
});
|
|
|
|
describe("plugin npm publish verifier command limits", () => {
|
|
it("bounds npm command runtime and captured output by default", () => {
|
|
expect(readPluginNpmCommandOptions({})).toStrictEqual({
|
|
encoding: "utf8",
|
|
killSignal: "SIGKILL",
|
|
maxBuffer: 16 * 1024 * 1024,
|
|
stdio: ["ignore", "pipe", "pipe"],
|
|
timeout: 5 * 60 * 1000,
|
|
});
|
|
});
|
|
|
|
it("accepts strict npm command timeout and buffer overrides", () => {
|
|
expect(
|
|
readPluginNpmCommandOptions({
|
|
OPENCLAW_PLUGIN_NPM_COMMAND_MAX_BUFFER_BYTES: "33554432",
|
|
OPENCLAW_PLUGIN_NPM_COMMAND_TIMEOUT_MS: "120000",
|
|
}),
|
|
).toMatchObject({
|
|
maxBuffer: 32 * 1024 * 1024,
|
|
timeout: 120000,
|
|
});
|
|
});
|
|
|
|
it("rejects loose npm command timeout and buffer overrides", () => {
|
|
expect(() =>
|
|
readPluginNpmCommandOptions({
|
|
OPENCLAW_PLUGIN_NPM_COMMAND_TIMEOUT_MS: "60s",
|
|
}),
|
|
).toThrow("invalid OPENCLAW_PLUGIN_NPM_COMMAND_TIMEOUT_MS: 60s");
|
|
expect(() =>
|
|
readPluginNpmCommandOptions({
|
|
OPENCLAW_PLUGIN_NPM_COMMAND_MAX_BUFFER_BYTES: "16mb",
|
|
}),
|
|
).toThrow("invalid OPENCLAW_PLUGIN_NPM_COMMAND_MAX_BUFFER_BYTES: 16mb");
|
|
});
|
|
|
|
it("runs npm metadata commands with bounded exec options", () => {
|
|
const calls: unknown[] = [];
|
|
const output = runPluginNpmCommand(["view", "@openclaw/discord", "readme"], {
|
|
env: {
|
|
OPENCLAW_PLUGIN_NPM_COMMAND_MAX_BUFFER_BYTES: "1024",
|
|
OPENCLAW_PLUGIN_NPM_COMMAND_TIMEOUT_MS: "2500",
|
|
},
|
|
execFileSyncImpl(command: string, args: string[], options: unknown) {
|
|
calls.push({ args, command, options });
|
|
return JSON.stringify("# Discord");
|
|
},
|
|
});
|
|
|
|
expect(output).toBe(JSON.stringify("# Discord"));
|
|
expect(calls).toStrictEqual([
|
|
{
|
|
args: ["view", "@openclaw/discord", "readme"],
|
|
command: "npm",
|
|
options: {
|
|
encoding: "utf8",
|
|
killSignal: "SIGKILL",
|
|
maxBuffer: 1024,
|
|
stdio: ["ignore", "pipe", "pipe"],
|
|
timeout: 2500,
|
|
},
|
|
},
|
|
]);
|
|
});
|
|
});
|
|
|
|
describe("collectPluginNpmPublishedRuntimeErrors", () => {
|
|
it("flags published plugin packages with TypeScript entries and no compiled runtime output", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
spec: "@openclaw/discord@2026.5.2",
|
|
packageJson: {
|
|
name: "@openclaw/discord",
|
|
version: "2026.5.2",
|
|
openclaw: {
|
|
extensions: ["./index.ts"],
|
|
},
|
|
},
|
|
files: ["package.json", "openclaw.plugin.json", "index.ts"],
|
|
}),
|
|
).toEqual([
|
|
"@openclaw/discord@2026.5.2 requires compiled runtime output for TypeScript entry ./index.ts: expected ./dist/index.js, ./dist/index.mjs, ./dist/index.cjs, ./index.js, ./index.mjs, ./index.cjs",
|
|
]);
|
|
});
|
|
|
|
it("accepts published plugin packages with explicit runtimeExtensions", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/zalo",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./index.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
},
|
|
},
|
|
files: ["package.json", "openclaw.plugin.json", "index.ts", "dist/index.js"],
|
|
}),
|
|
).toStrictEqual([]);
|
|
});
|
|
|
|
it("flags plugin npm packages without an OpenClaw plugin manifest", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/searxng-plugin",
|
|
version: "2026.6.11",
|
|
openclaw: {
|
|
extensions: ["./index.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
},
|
|
},
|
|
files: ["package.json", "dist/index.js"],
|
|
}),
|
|
).toEqual([
|
|
"@openclaw/searxng-plugin@2026.6.11 plugin npm package must include openclaw.plugin.json",
|
|
]);
|
|
});
|
|
|
|
it("flags reservation packages before they can pass plugin runtime verification", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/tavily-plugin",
|
|
version: "0.0.0",
|
|
description: "Bootstrap reservation",
|
|
},
|
|
files: ["package.json", "README.md"],
|
|
}),
|
|
).toEqual([
|
|
"@openclaw/tavily-plugin@0.0.0 plugin npm package must include openclaw.plugin.json",
|
|
]);
|
|
});
|
|
|
|
it("flags missing explicit runtimeExtensions outputs", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/line",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./src/index.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
},
|
|
},
|
|
files: ["package.json", "openclaw.plugin.json", "src/index.ts"],
|
|
}),
|
|
).toEqual(["@openclaw/line@2026.5.3 runtime extension entry not found: ./dist/index.js"]);
|
|
});
|
|
|
|
it("flags runtimeExtensions length mismatches", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/acpx",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./index.ts", "./tools.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
},
|
|
},
|
|
files: ["package.json", "openclaw.plugin.json", "dist/index.js"],
|
|
}),
|
|
).toEqual([
|
|
"@openclaw/acpx@2026.5.3 package.json openclaw.runtimeExtensions length (1) must match openclaw.extensions length (2)",
|
|
]);
|
|
});
|
|
|
|
it("flags blank runtimeExtensions entries instead of falling back to inferred outputs", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/whatsapp",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./src/index.ts"],
|
|
runtimeExtensions: [" "],
|
|
},
|
|
},
|
|
files: ["package.json", "openclaw.plugin.json", "src/index.ts", "dist/index.js"],
|
|
}),
|
|
).toEqual([
|
|
"@openclaw/whatsapp@2026.5.3 package.json openclaw.runtimeExtensions[0] must be a non-empty string",
|
|
]);
|
|
});
|
|
|
|
it("flags published plugin packages with TypeScript setup entries and no compiled setup runtime", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/line",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./index.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
setupEntry: "./setup-entry.ts",
|
|
},
|
|
},
|
|
files: [
|
|
"package.json",
|
|
"openclaw.plugin.json",
|
|
"index.ts",
|
|
"dist/index.js",
|
|
"setup-entry.ts",
|
|
],
|
|
}),
|
|
).toEqual([
|
|
"@openclaw/line@2026.5.3 requires compiled runtime output for TypeScript entry ./setup-entry.ts: expected ./dist/setup-entry.js, ./dist/setup-entry.mjs, ./dist/setup-entry.cjs, ./setup-entry.js, ./setup-entry.mjs, ./setup-entry.cjs",
|
|
]);
|
|
});
|
|
|
|
it("accepts published plugin packages with explicit runtimeSetupEntry", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/example-channel",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./index.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
setupEntry: "./setup-entry.ts",
|
|
runtimeSetupEntry: "./dist/setup-entry.js",
|
|
},
|
|
},
|
|
files: ["package.json", "openclaw.plugin.json", "dist/index.js", "dist/setup-entry.js"],
|
|
}),
|
|
).toStrictEqual([]);
|
|
});
|
|
|
|
it("flags missing explicit runtimeSetupEntry outputs", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/matrix",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./index.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
setupEntry: "./setup-entry.ts",
|
|
runtimeSetupEntry: "./dist/setup-entry.js",
|
|
},
|
|
},
|
|
files: ["package.json", "openclaw.plugin.json", "dist/index.js"],
|
|
}),
|
|
).toEqual(["@openclaw/matrix@2026.5.3 runtime setup entry not found: ./dist/setup-entry.js"]);
|
|
});
|
|
|
|
it("flags runtimeSetupEntry without setupEntry", () => {
|
|
expect(
|
|
collectPluginNpmPublishedRuntimeErrors({
|
|
packageJson: {
|
|
name: "@openclaw/twitch",
|
|
version: "2026.5.3",
|
|
openclaw: {
|
|
extensions: ["./index.ts"],
|
|
runtimeExtensions: ["./dist/index.js"],
|
|
runtimeSetupEntry: "./dist/setup-entry.js",
|
|
},
|
|
},
|
|
files: ["package.json", "openclaw.plugin.json", "dist/index.js", "dist/setup-entry.js"],
|
|
}),
|
|
).toEqual([
|
|
"@openclaw/twitch@2026.5.3 package.json openclaw.runtimeSetupEntry requires openclaw.setupEntry",
|
|
]);
|
|
});
|
|
});
|
|
|
|
describe("resolveNpmPackFilename", () => {
|
|
it("uses the final tarball filename from plain npm pack output", () => {
|
|
const noisyOutput = [
|
|
"npm notice",
|
|
"npm notice package: @openclaw/msteams@2026.5.24-beta.1",
|
|
"openclaw-msteams-2026.5.24-beta.1.tgz",
|
|
"",
|
|
].join("\n");
|
|
|
|
expect(resolveNpmPackFilename(noisyOutput)).toBe("openclaw-msteams-2026.5.24-beta.1.tgz");
|
|
});
|
|
|
|
it("rejects path-like tarball output instead of reading outside the pack directory", () => {
|
|
const unsafeOutputs = [
|
|
"../openclaw-msteams.tgz",
|
|
"nested/openclaw-msteams.tgz",
|
|
"nested\\openclaw-msteams.tgz",
|
|
"/tmp/openclaw-msteams.tgz",
|
|
"C:\\temp\\openclaw-msteams.tgz",
|
|
"openclaw-msteams\u0000.tgz",
|
|
];
|
|
|
|
for (const output of unsafeOutputs) {
|
|
expect(() => resolveNpmPackFilename(output)).toThrow(
|
|
"npm pack did not report a tarball filename",
|
|
);
|
|
}
|
|
});
|
|
});
|
|
|
|
describe("findPackedPackageReadmePath", () => {
|
|
it("finds a root package README without accepting nested documentation files", () => {
|
|
expect(
|
|
findPackedPackageReadmePath(["package.json", "docs/README.md", "README.md", "dist/index.js"]),
|
|
).toBe("README.md");
|
|
expect(findPackedPackageReadmePath(["package.json", "docs/README.md"])).toBe("");
|
|
});
|
|
});
|
|
|
|
describe("parseNpmReadmeMetadata", () => {
|
|
it("accepts non-empty npm readme metadata", () => {
|
|
expect(parseNpmReadmeMetadata(JSON.stringify("# Plugin\n\nInstall it."))).toBe(
|
|
"# Plugin\n\nInstall it.",
|
|
);
|
|
});
|
|
|
|
it("rejects empty or unsupported npm readme metadata", () => {
|
|
expect(parseNpmReadmeMetadata(JSON.stringify(""))).toBe("");
|
|
expect(parseNpmReadmeMetadata(JSON.stringify(null))).toBe("");
|
|
expect(parseNpmReadmeMetadata("{")).toBe("");
|
|
});
|
|
});
|