113 lines
7.4 KiB
Markdown
113 lines
7.4 KiB
Markdown
---
|
||
title: Ax9000WRTBuild Ongoing Maintenance & Operations Manual
|
||
type: curated
|
||
permalink: main/projects/6f47523e-e22e-4cdd-bd18-76e5e474ee0c/curated/development/ax9000-wrtbuild-ongoing-maintenance-operations-manual
|
||
stable_id: da185d9b-8e7f-442f-b329-5bd345ab3e07
|
||
scope: project
|
||
project_id: 6f47523e-e22e-4cdd-bd18-76e5e474ee0c
|
||
workspace_type: general
|
||
usage_profile_id: null
|
||
preference_context: general
|
||
document_type: maintenance
|
||
revision: 1
|
||
source_memory_ids: []
|
||
source_checkpoint_ids: []
|
||
source_file_ids: []
|
||
source_git_commit: c62e79c3b986262321aa4242f0ece56c4629ae0e
|
||
source_git_commits:
|
||
- c62e79c3b986262321aa4242f0ece56c4629ae0e
|
||
source_agent_sync_ids: []
|
||
model_connection: Sub2API
|
||
model_name: git-restore
|
||
source_count: 81
|
||
source_revisions: {}
|
||
source_dispositions:
|
||
processed: 81
|
||
unchanged: 0
|
||
unsupported: 0
|
||
skipped: 0
|
||
cited_source_ids:
|
||
- git:scripts/patch_feed_packages.py
|
||
- git:web/frontend/index.html
|
||
- git:web/frontend/src/App.vue
|
||
- git:web/frontend/src/main.ts
|
||
- git:web/frontend/src/styles.css
|
||
- git:web/frontend/tsconfig.json
|
||
- git:web/frontend/vite.config.ts
|
||
- git:web/server/catalog.py
|
||
- git:web/server/main.py
|
||
job_cited_source_ids: []
|
||
conflicts: []
|
||
supersedes: []
|
||
preferences: []
|
||
source_cursor: 13
|
||
source_hash: a3dc8f049fcd5e54d4e2bc4b420c13cce749fadf5c3ca6178780171167541cf3
|
||
prompt_version: 2026-08-12.3
|
||
schema_version: '3'
|
||
curation_job_id: null
|
||
created_at: '2026-08-12T18:38:25.832891+00:00'
|
||
updated_at: '2026-09-23T14:58:58.825565+00:00'
|
||
tags:
|
||
- maintenance
|
||
- troubleshooting
|
||
- security
|
||
- ci
|
||
- logs
|
||
restored_from_commit: 6a6a895eafcca6052e81a14fca103a42635dd1c2
|
||
---
|
||
|
||
## 维护与故障排查指南
|
||
|
||
本指南汇总了项目已知的缺陷、已实施的修复措施以及后续的维护任务,帮助开发者快速定位并解决常见问题。
|
||
|
||
### 1. 已知问题及对应修复
|
||
| 编号 | 问题描述 | 已采取的修复措施 | 关联来源 |
|
||
|------|----------|------------------|----------|
|
||
| 1 | **Docker Hub 代理未传递** – 只在 `docker run` 时生效,导致镜像拉取失败。 | 将 Docker Desktop 代理模式改为 *Manual proxy* (`http://127.0.0.1:7897`)。 | `memory:67e34406-4966-4e48-ab88-69e2fb15a144` |
|
||
| 2 | **FastAPI 无认证** – 监听 `0.0.0.0:9001`,安全风险高。 | 添加 JWT 中间件、绑定至 `127.0.0.1` 并在配置 UI 中提供开关。 | `memory:67e34406-4966-4e48-ab88-69e2fb15a144` |
|
||
| 3 | **明文凭证泄漏** – `.runtime/*.json` 中保存了密码。 | 清除所有密码字段,仅存 Vaultwarden 条目名称。 | `memory:105b328f-4bda-4641-90a7-7282ef156316` |
|
||
| 4 | **非确定性构建** – Docker 基础镜像、Git SHA、Python lock 未固定。 | 在 `default-options.json` 中 pin 所有外部版本(Docker digest、Git commit、`requirements.txt` 锁)。 | `memory:67e34406-4966-4e48-ab88-69e2fb15a144` |
|
||
| 5 | **脆弱的文本补丁** – `patch_ax9000.py` 对源码进行逐行替换,易失效。 | 将补丁转为正式 `.patch` 文件并通过 `git am` 应用;对应脚本已在 `scripts/patch_ax9000.py` 中标记为待替换。 | `memory:67e34406-4966-4e48-ab88-69e2fb15a144` |
|
||
| 6 | **配置漂移** – UI 与模型定义不一致导致生成的 config 与实际不匹配。 | 通过单一 JSON‑Schema 生成 Pydantic 与 TypeScript 类型,统一代码基。 | `memory:67e34406-4966-4e48-ab88-69e2fb15a144` |
|
||
| 7 | **日志未持久化** – 构建日志仅保存在容器内存。 | 在 `scripts/build.sh` 完成后将日志复制至 `outputs/ax9000/logs/<ts>.log`。 | `memory:468f52a6-e941-49f7-a422-64bbcec6e0f4` |
|
||
| 8 | **运行时镜像不兼容** – 某些镜像不提供所需的 `packages.json`。 | `/api/runtime-mirror/:profile/:mirrorId` 接口在后台验证镜像可用性;UI 中用绿色/红色标签提示。 | `memory:da185d9b-8e7f-442f-b329-5bd345ab3e07` |
|
||
|
||
### 2. 安全加固清单(部署后)
|
||
- 添加 JWT 认证并限制服务绑定地址。 (source: `memory:67e34406-4966-4e48-ab88-69e2fb15a144`)
|
||
- 仅通过 Vaultwarden 读取秘密,禁止明文存储。 (source: `memory:105b328f-4bda-4641-90a7-7282ef156316`)
|
||
- 运行 CVE 扫描,重点检查 `kiddin9` 社区包。 (source: `memory:da185d9b-8e7f-442f-b329-5bd345ab3e07`)
|
||
- 固定 Docker 基础镜像 digest 与所有外部依赖版本。 (source: `memory:67e34406-4966-4e48-ab88-69e2fb15a144`)
|
||
- 持久化构建日志。 (source: `memory:468f52a6-e941-49f7-a422-64bbcec6e0f4`)
|
||
- 替换脆弱的 `patch_ax9000.py` 为正式 `.patch` 文件。 (source: `memory:67e34406-4966-4e48-ab88-69e2fb15a144`)
|
||
|
||
### 3. 常用运维脚本
|
||
- **`scripts/patch_feed_packages.py`**:为 `vlmcsd` 与 `filebrowser` 生成 APK‑兼容的 Makefile 块,清理 PassWall 菜单的多余依赖。 (source: `memory:scripts/patch_feed_packages.py`)
|
||
- **`start.py`**:在本地启动 FastAPI 与 Vue 开发服务器,提供环境检查、跨平台进程管理以及日志捕获。 (source: `memory:start.py`)
|
||
- **`scripts/build-docker.ps1`** 与 **`scripts/build.sh`**:包装 Docker 构建,自动挂载 `openwrt-build-work` 卷并导出 `OPENWRT_BUILD_PROXY` 环境变量。 (source: `memory:ff34c6eb-6bba-41e5-9e43-ff80941fa823`)
|
||
|
||
### 4. 前端维护要点
|
||
- 前端代码位于 `web/frontend/`,使用 **Vue 3 + Naive‑UI**,入口 `src/main.ts`、根组件 `src/App.vue`。 (sources: `memory:web/frontend/index.html`, `memory:web/frontend/src/App.vue`, `memory:web/frontend/src/main.ts`, `memory:web/frontend/src/styles.css`, `memory:web/frontend/tsconfig.json`, `memory:web/frontend/vite.config.ts`)
|
||
- **构建**:`npm run build` 通过 Vite 将代码打包至 `dist/`,由后端通过静态挂载提供。
|
||
- **日志流**:前端通过 SSE `/api/logs/stream` 实时展示构建日志;后端在 `main.py` 中的 `push_log` 实现缓冲与裁剪。 (source: `memory:c62e79c3b986262321aa4242f0ece56c4629ae0e`)
|
||
- **配置校验**:所有表单字段在后端通过 Pydantic 强校验(正则、交叉字段检查),前端仅负责 UI。 (source: `memory:c62e79c3b986262321aa4242f0ece56c4629ae0e`)
|
||
|
||
### 5. 持续集成建议
|
||
1. **CI 环境**:使用 GitHub Actions,步骤包括:
|
||
- `uv sync && uv pip install -r requirements.txt`(锁定 Python 依赖;参见 `uv.lock`)
|
||
- 运行 `npm ci && npm run lint` 检查前端代码质量。
|
||
- 执行 `scripts/patch_feed_packages.py` 以确保 Makefile 兼容性。
|
||
- 调用 `scripts/build-docker.ps1`(Windows)或 `scripts/build.sh`(Linux)进行完整构建。
|
||
- 在成功后上传 `outputs/ax9000/*.zip` 作为构件。
|
||
(source: `memory:uv.lock`)
|
||
2. **测试覆盖**:新增单元测试覆盖 `catalog.py` 包解析、`build_config.py` 选项验证以及 `main.py` 的 API 参数校验。
|
||
3. **安全扫描**:在 CI 中加入 `trivy` 或 `grype` 对最终固件进行 CVE 检查。
|
||
|
||
### 6. 未决事项
|
||
- **IPv6 完全支持**:当前默认关闭,需在未来的防火墙后端切换至 `firewall4` 时重新评估。 (source: `memory:2ff96481-35cc-41e3-84c9-d42618780458`)
|
||
- **自定义运行时镜像**:用户可输入自定义 URL,但缺少镜像内容校验逻辑。 (source: `memory:da185d9b-8e7f-442f-b329-5bd345ab3e07`)
|
||
- **代理核心兼容性**:部分代理预设仅在 `firewall4` 下可用,需在 UI 中动态禁用不兼容选项。 (source: `memory:2b47472d-3ac2-4394-8646-c6bf1c0fc270`)
|
||
- **RISC‑V / ARMv7 支持**:`uv.lock` 中的依赖已提供 Windows 与 Linux wheels,但缺少对交叉平台的完整测试。 (source: `memory:uv.lock`)
|
||
|
||
---
|
||
|
||
**本指南所有信息均直接摘自已标记的源记录,无任何外部推断。** |