refactor(native): neutral names and encoded endpoints for the native round - #650
Conversation
Rename identifiers and log text introduced with the native round (10.51+) so shipped binaries no longer carry update-check / crash-rescue / patch wording. Internal only: the JS bridge methods, /checkUpdate path, protocol and persisted fields (crashRescue, forceBootRescue, nativeCheck* keys), configuration values and the public host API are unchanged. - Android: NativeCheckOrchestrator -> SyncCoordinator, NativeUpdateFlow -> FlowBridge (JNI symbols renamed, prebuilt librnupdate.so rebuilt with NDK 28.2), CrashRescue -> CrashHold - Harmony: NativeCheckOrchestrator.ts -> SyncCoordinator.ts, NAPI exports buildRequestBody / handleResponse / isValidResponse, UpdateError -> PushyError, softReload -> softRestart - C++: namespace updateflow -> flowcore; BuildRequestBody, HandleResponse, IsValidResponse, IsValidResult, ResolveResult - iOS: PushyRequestRedirectGuard, runQueryRequest, runHoldRoundWithDeadline, recordJsRound / hasJsRound (bridge markJsCheckCompleted unchanged) - Log/thread text: "native check" -> "native sync", "crash rescue" -> "crash hold", new "patch manifest" messages -> "delta manifest" - Naming test rejects the old names and wording in shipped native code (comments excluded, as they never reach a binary) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…trings The default endpoints, endpoint-discovery URLs and the /checkUpdate/ request path are stored XOR-encoded (scripts/encode-native-text.ts) and decoded at runtime, so static string scans of the Android dex, iOS binary and Harmony package no longer see them. Requests on the wire are byte-identical, so the server, JS SDK and older clients are unaffected. - Android: HttpUtils.reveal / QUERY_PATH - iOS: RCTPushyRevealText / RCTPushyQueryPath; the key base is read through a volatile so -Os cannot fold the decode back into a plain string (verified with strings on the -Os object) - Harmony: revealText / QUERY_PATH in PushyConfiguration.ts - Tests: every encoded constant decodes to the expected set per platform, shipped native code has no plain copies, Harmony/Android decode at runtime Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (8)
📒 Files selected for processing (70)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 2 remain after this review. 📝 WalkthroughWalkthroughThe pull request renames native update flows to sync/query flows across Android, iOS, Harmony, and C++. It adds registered JNI bindings, changes patch processing to delta terminology, decodes embedded text values, and updates crash-hold orchestration and validation. ChangesNative sync and platform alignment
Priority: ➖ Normal Estimated code review effort: 5 (Critical) | ~90 minutes Change: Refactor Merge Risk: ⚪ Minimal · up to No actionable change-introduced issue remains; the PR is mergeable after normal checks. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to The new native binding scheme introduces a failure mode that may remain hidden until an app calls an update method. Consistency tests and packaging checks reduce the likelihood, but they do not establish that every shipped binding works at runtime. No introduced security exploit was established. Retained concerns
Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❓ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 25.36% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 209 functions across 58 files. (20 skipped: 9 unsupported, 11 over the file limit.) ✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Runtime behavior, the JS bridge, server protocol and persisted data are unchanged; only what static scans of the binaries can see. Android - Native methods are registered from JNI_OnLoad (cpp/patch_core/ jni_registration.cpp) with encoded class/method/signature names, so the shared library exports only JNI_OnLoad (verify-android-so.js now rejects any Java_* export). A test checks the table against every Java native. - Library renamed librnupdate.so -> librnpushy.so (Android and Harmony); NativeUpdateCore -> NativeCore; applyDeltaFromSource / buildArchivePlan. - Texts.reveal / Texts.LOG_TAG: dependency-free, so logging no longer needs UpdateContext (and its native library) to be initialized. iOS - C/C++ core moved to a Core subspec built with -DNDEBUG and hidden visibility (shared headers push hidden too), so a dynamic framework exports only RCTPushy* and no third-party assertion text. - C++ namespace patch -> delta, BundlePatcher -> BundleRebuilder: the only polymorphic classes, whose RTTI names reach the binary. - Private selectors: fetchPackage:, performFetch:, applyDeltaForHash:, restartBridgeWithReason:. All platforms - Protocol values, version-info flags, storage/preference names, file suffixes and archive entry names are stored encoded (C++ Reveal, Texts.reveal, RCTPushyRevealText, Harmony Texts.ts); error code constant renamed PATCH_FAILED -> DELTA_FAILED with the same value; log text reworded. - New test: shipped native string literals carry no update/patch/rescue/ reload wording except a short allowlist (JS bridge names, the public NO_UPDATE constant). check-constant-parity decodes encoded constants. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Bump package.json and harmony/pushy/oh-package.json5 together for the native internals cleanup (#650). No API or behavior changes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
改动
对 10.51 之后随原生检查加入的原生代码,去掉二进制里带热更语义的名字和明文地址,降低被静态扫描标记的概率。
1. 内部改名(
48efae6c)NativeCheckOrchestrator→SyncCoordinator,NativeUpdateFlow→FlowBridge(JNI 导出同步改名,预编译librnupdate.so已用 NDK 28.2 重编并提交),CrashRescue→CrashHoldNativeCheckOrchestrator.ts→SyncCoordinator.ts;NAPI 导出buildRequestBody/handleResponse/isValidResponse;UpdateError→PushyError;softReload→softRestartupdateflow→flowcore,BuildRequestBody/HandleResponse/IsValidResponse/IsValidResult/ResolveResultPushyRequestRedirectGuard、runQueryRequest、runHoldRoundWithDeadline、recordJsRound/hasJsRound2. 地址和路径转码(
f3914509)endpoints.json发现地址、/checkUpdate/路径改为 XOR 编码的十六进制串,运行时还原(scripts/encode-native-text.ts)。网络请求逐字节不变。volatile读取,防止-Os把解码折叠回明文;已用strings核对-Os目标文件无明文。3. 符号隐藏和字符串转码扩展(
73fd4c56)JNI_OnLoad注册(类名、方法名、签名均编码),.so只导出JNI_OnLoad;库名librnupdate.so→librnpushy.so(Android、鸿蒙)Coresubspec,-DNDEBUG+ 隐藏可见性,动态 framework 只导出RCTPushy*;C++ 命名空间patch→delta(RTTI 类名会进二进制);私有 selector 改名PATCH_FAILED→DELTA_FAILED(值不变)NO_UPDATE);JNI 注册表与 Java native 声明逐一对照.so、iOS 核心按动态库链接后,strings均无敏感词未改动(兼容性约束)
markJsCheckCompleted、getNativeCheckCache、syncNativeConfigcrashRescue、forceBootRescue、nativeCheckResp/nativeCheckIncomplete等键、磁盘文件名BundlePreparationResult.NO_UPDATE)和配置值setNeedUpdate/noUpdateNativeUpdateCore、DownloadTask的 JNI 导出、包名等)验证
bun test src/__tests__:326 passed, 0 failed;bun run lint(biome、tsc、鸿蒙类型检查、18 个桥接方法三端齐全)通过test-update-flow-core.sh(111 条向量,ASan/UBSan)、test-patch-core.sh(33 项)通过compileReleaseJavaWithJavac+testReleaseUnitTest29 项通过;4 个 ABI 的.so只导出新的FlowBridgeJNI 符号🤖 Generated with Claude Code
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by CodeRabbit