From 193246753955ee49b190316c9b5c30ebc1663a1a Mon Sep 17 00:00:00 2001 From: locpham Date: Tue, 1 Sep 2026 11:31:10 +0700 Subject: [PATCH] V45.34: ban cai phai SACH - engine.spec loai dev config (DB/.secret_key/plugin_dirs.json/sf_scan_state.json) khoi bundle; build_install.ps1 + build_windows.ps1 fail-fast neu dist dinh config dev (reset ve mac dinh cho nguoi dung moi) --- build_install.ps1 | 13 ++++++++++++- build_windows.ps1 | 9 +++++++++ engine.spec | 8 +++++++- 3 files changed, 28 insertions(+), 2 deletions(-) diff --git a/build_install.ps1 b/build_install.ps1 index 1eacb44..037999b 100644 --- a/build_install.ps1 +++ b/build_install.ps1 @@ -39,7 +39,18 @@ if ($LASTEXITCODE -ne 0) { exit 1 } -Write-Host "== [4/4] Copy vao install\ ==" +Write-Host "== [4/4] Verify bundle sach (khong config dev) + copy vao install\ ==" +# Ban cai phai reset ve mac dinh: KHONG duoc mang theo DB/password/secret/ +# plugin-dirs/scan-state cua dev sang may nguoi dung moi. +$devFiles = Get-ChildItem "dist\daw_engine" -Recurse -File -ErrorAction SilentlyContinue | Where-Object { + $_.Name -in @(".secret_key", "plugin_dirs.json", "sf_scan_state.json", "sf_scan_state.json.bak-root") -or + $_.Extension -eq ".db" +} +if ($devFiles) { + Write-Host "ERROR: bundle chua config dev - DUNG TAO BAN CAI:" -ForegroundColor Red + $devFiles | ForEach-Object { Write-Host " $($_.FullName)" -ForegroundColor Red } + exit 1 +} New-Item -ItemType Directory -Force "install" | Out-Null if (Test-Path "install\daw_engine") { Remove-Item -Recurse -Force "install\daw_engine" } Copy-Item "dist\daw_engine\*" "install\daw_engine\" -Recurse -Force diff --git a/build_windows.ps1 b/build_windows.ps1 index a5f71ae..c0d2ee8 100644 --- a/build_windows.ps1 +++ b/build_windows.ps1 @@ -137,6 +137,15 @@ if ($doEngine) { if ($LASTEXITCODE -ne 0) { Fail "pyinstaller that bai" } python tools\verify_bundle.py if ($LASTEXITCODE -ne 0) { Fail "Bundle thieu asset - dung build, kiem tra engine.spec datas" } + # Ban cai phai SACH: khong duoc mang theo DB/password/secret/scan-state cua dev. + $devFiles = Get-ChildItem "dist\daw_engine" -Recurse -File -ErrorAction SilentlyContinue | Where-Object { + $_.Name -in @(".secret_key", "plugin_dirs.json", "sf_scan_state.json", "sf_scan_state.json.bak-root") -or + $_.Extension -eq ".db" + } + if ($devFiles) { + $devFiles | ForEach-Object { Write-Host " DEV-CONFIG: $($_.FullName)" -ForegroundColor Red } + Fail "Bundle chua config dev - DUNG TAO BAN CAI" + } if (-not (Test-Path "dist\daw_engine\daw_engine.exe")) { Fail "dist\daw_engine\daw_engine.exe khong ton tai (onedir build loi?)" } if (Test-Path "src-tauri\resources\daw_engine") { Remove-Item -Recurse -Force "src-tauri\resources\daw_engine" } New-Item -ItemType Directory -Force "src-tauri\resources\daw_engine" | Out-Null diff --git a/engine.spec b/engine.spec index 4a27a72..0f8c36b 100644 --- a/engine.spec +++ b/engine.spec @@ -42,7 +42,13 @@ if _SPEC_ROOT not in _sys.path: # Assets cua app: bundle QUA IMPORT SYSTEM (collect_data_files) — an toan nhat. # Loai tru storage (57MB soundfonts/uploads — vo ich, config.py da chuyen # storage sang %APPDATA%\\SonicForgeDAW khi frozen) va __pycache__. -datas = collect_data_files('app', excludes=['**/storage/**', '**/__pycache__/**', '**/*.pyc']) +# LOAI CA DEV CONFIG O app/ ROOT: bundle cai dat phai SAC — khong duoc mang +# theo DB/password/secret/scan-state cua dev sang may nguoi dung moi. +datas = collect_data_files('app', excludes=[ + '**/storage/**', '**/__pycache__/**', '**/*.pyc', + '**/*.db', '**/.secret_key', '**/plugin_dirs.json', '**/sf_scan_state.json', + '**/*.bak-root', +]) # Fallback cuoi cung: neu collect_data_files van tra ve rong (phong moi truong # hop ky la), dung datas TINH absolute — tinh huong xau nhat van co du assets. if not datas: