Skip to content

v6.2.0

Choose a tag to compare

@github-actions github-actions released this 06 Oct 05:54
· 44 commits to main since this release

OhGithubLost v6.2.0

下载链路重做(端点 / 路由 / 完整性)+ 文件预览 + 隐私承诺。九条构建腿全绿。
Download pipeline rebuilt (endpoints, routing, integrity), plus file previews and a privacy commitment.

新增 / Added

  • 文件预览:图片(可缩放)、SVG(矢量渲染)、XML 与文本(语法高亮)。
    在仓库页**长按文件 →「打开方式」**可在「内置预览 / 编辑器 / 浏览器」之间选择。
    File previews for images (zoomable), SVG (vector), XML and text; long-press a file
    in the repository page and pick "Open with".
  • Action 构建产物下载控件:运行详情页列出产物(名称 / 大小 / 有效期),
    已过期的条目直接禁用。
    Build-artifact download control in the run detail page; expired artifacts are disabled.
  • 编辑器长按菜单:复制 / 剪切 / 粘贴 / 全选(只读态自动裁掉剪切与粘贴)。
    Long-press selection menu in the code editor.
  • 引导页最后一页《开源协议与隐私承诺》(15 语言全文):
    保证不收集数据(无遥测 / 分析 / 广告 / 追踪 SDK,令牌只在本机),
    并明确排除可选的 Web 浏览器版本 —— 该功能默认关闭,开启前会再次单独提示。
    A licence-and-privacy page as the final onboarding step, guaranteeing no data
    collection while explicitly excluding the optional Web build.

变更 / Changed

  • 内置加速通道改为 https://proxy.344977.xyz/(单前缀转发完整原始链接),
    同意协议版本 1 → 2(地址变更属实质修改,需重新征求同意)。
    Built-in acceleration channel switched to proxy.344977.xyz; consent version 1 → 2.
  • 加速路由改为纯函数判定(ogLAccelCandidates):签名族(Release 附件 /
    Action 日志 / 产物)按 500KB 阈值;raw 族仅「内置通道 + 公开仓库」才加速。
    Routing is now a pure function: signed assets follow a 500 KB threshold; raw assets
    accelerate only on the built-in channel for public repositories.
  • 仓库文件取法按是否加速分流:不加速走 API
    (/repos/{o}/{r}/contents/{path} + Accept: application/vnd.github.raw,
    实测支持 Range,多连接分片不退化);加速才把 raw 链接交给代理。
    Repository files now use the Contents API with the raw media type when not
    accelerating, and only hand raw links to the proxy when accelerating.
  • README 仓库内图片:内置 + 公开时改走 raw + 代理 —— raw 不限流,而
    Contents API 认证后也只有 5000 次/小时,一次 README 几十张图很容易吃配额。
    README images use raw through the proxy on the built-in channel: raw is not
    rate-limited, unlike the 5 000/hour authenticated Contents API.
  • 登录页极简化:删掉「怎么拿令牌」引导、「向导进度」四步清单与重复标题,
    保留安全说明、输入、显示/隐藏、登录与游客入口(文件缩小 27%)。
    Login page simplified; the how-to guide and step checklist are gone.
  • 下载管理页的状态与分类标签改为走 i18n(此前是域层硬编码中文)。
    Download status/category labels are now localised.

修复 / Fixed

  • 私有仓库下载完全没带认证头(Release 附件 / Action 产物 / 仓库文件三处都会
    401/404)。私有仓库此前实际上无法下载。
    Private-repository downloads carried no auth header and failed outright.
  • 下载后不校验完整性:现在比对 GitHub 提供的 SHA-256;不匹配判为失败且
    不导出到 SAF;没有摘要可比对时如实标注「未校验」,绝不谎称已验证。
    Downloads are now verified against GitHub's SHA-256 digest; mismatches fail and are
    never exported. Resources without a digest are honestly labelled "not verified".
  • 文件名零净化:新增净化(只取末段、剔控制字符、拒 ..、绕开 Windows
    保留设备名、限长 120 并保住扩展名)。
    Download file names are now sanitised.
  • 非 http(s) 地址被放行:新增协议白名单,入队与全部降级地址一律校验。
    A scheme allow-list now rejects anything that is not http/https.
  • 跨域重定向的令牌外泄风险:此前依赖 Dart SDK 未文档化的"自动剥离
    Authorization"行为;现在显式不跟随重定向,并校验跳转目标(拒绝回环 / 私网 /
    链路本地,含云元数据 169.254.169.254)。
    Redirects are no longer followed implicitly, and redirect targets are validated.
  • 构建:Windows 两条腿 spec 从未被应用 —— Windows runner 无 PyYAML,注入器
    走了手写的兜底解析器,而它几乎解析不出内容,导致编译宏全部未注入。
    已重写为缩进驱动解析器,与 PyYAML 结果逐字段一致。
    Windows builds never applied the platform spec because the dependency-free YAML
    fallback parser was broken; it has been rewritten.
  • 构建:Android 五条腿未跟进 Kotlin DSL 迁移 —— 模板已生成
    build.gradle.kts,spec 仍指向 build.gradle,注入被静默跳过,
    compileSdk 停在 36 且 desugaring 未开。注入器现在缺目标文件即报错退出,
    失败点从编译期前移到注入期。
    Android legs had not followed the Kotlin DSL migration; the injector now fails
    loudly instead of silently skipping.
  • 发布:Linux 的 deb / rpm / AppImage 从未真正发布过 —— 发布作业没有
    actions/checkout
    ,工作目录是空的,tool/linux_packages.py 根本找不到;
    而该步骤带 || true,把错误整个吞掉。v5.6.0、v6.0.0、v6.2.0 的 Release 里
    裸放安装包数量均为 0。已补上签出步骤,并把「脚本不存在」改为响亮失败
    (单个格式打包失败仍只告警,不拖垮发布)。
    Linux .deb / .rpm / AppImage were never actually published: the release job had no
    actions/checkout, so the packaging script was absent, and || true swallowed it.

移除 / Removed

  • main 上的 Web 残留:.github/workflows/web.yml(挂在 push:[main],每次推 main
    都白跑一遍且带 contents: write)、tool/web_build.py、docs/WEB.md。
  • 5 个已被 platform_spec.yaml + 统一注入器取代的旧脚本
    (inject_android_gradle / inject_android_icon / inject_android_manifest /
    inject_desktop_shell / inject_windows_cmake)。
  • 2 个零引用僵尸文档(docs/ANIMATION_PLAN.md、docs/RELEASE_NOTES.md)。

已知限制 / Known limitations

  • 私有仓库的 raw 内容无法走加速(README 仓库内图片、仓库文件)。raw 端点
    没有签名机制,私有内容必须直接带令牌 —— 交给代理等于泄露令牌。这是硬约束。
    Raw content of private repositories cannot be accelerated: the raw endpoint has no
    signing mechanism, so delegating it to a proxy would leak the token.
  • 音频不做内置播放:Contents API 对超过 1 MB 的文件不返回内容,音频必然超限。
    请下载后用系统播放器打开。
    No in-app audio playback: the Contents API returns no content above 1 MB.
  • Web 功能不在隐私承诺范围内(见引导页最后一页);该功能默认关闭。
    The Web build is excluded from the privacy commitment; it is off by default.
  • macOS / iOS 自 v5.6.0 起弃用。
  • Linux 需要 glibc ≥ 2.35(Ubuntu 22.04 一代及以上)。
  • Linux 裸放安装包本版仅 3 / 6:deb(两架构)与 rpm(x86_64)已产出,
    rpm(arm64)与两个 AppImage 尚未产出。三种包在 zip / 7z 里都齐全,
    详见「产物」一节。

产物 / Artifacts

Android arm64-v8a / armeabi-v7a / x86_64 / universal-APK / AAB、
Windows x64 / arm64、Linux x64 / arm64,每份均含 zip 与 7z。

Linux 裸放安装包:本版只产出了 3 / 6(如实说明)

这三种包此前从未真正发布过 —— 本版第一次让它们开始产出,但仍未齐备:

amd64 / x86_64 arm64
.deb ✅ ✅
.rpm ✅ ❌ Ubuntu 的 rpm 缺少 aarch64 平台定义,无法在 x86_64 宿主上交叉构建
.AppImage ❌ ❌ appimagetool 未接受到 ARCH 环境变量,退出码 1

三种包在 zip / 7z 里都齐全 —— deb / rpm / AppImage 一并打进了
OGL-v6.2.0-Linux.*.zip 与 .7z,所以功能上不缺,只是没有裸放直传。
裸放安装包是本版新增的,缺失项会在后续版本补齐。