Implement NetEase Integration Phase C pinned data supply chain - #24
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implementation summary
Implements NetEase Integration Phase C from the merged Phase B state by adding pinned G79/X19 upstream snapshots, deterministic generated OpenAudit Packs/reports, GPL/MIT license-boundary notices, SOURCE.json provenance, an offline verifier/regenerator, a maintainer-only synchronization command, Makefile targets, and committed-pack runtime integration tests.
Modified files
cmd/sync-netease-rules/main.goMakefiledocs/bundled-rules-phase-c-netease.mdinternal/engine/bundled_runtime_test.goTHIRD_PARTY_NOTICES.mdthird_party/netease-sensitive-words/LICENSEthird_party/netease-sensitive-words/NOTICE.mdthird_party/netease-sensitive-words/SOURCE.jsonthird_party/netease-sensitive-words/upstream/G79SensitiveWords.jsonthird_party/netease-sensitive-words/upstream/X19SensitiveWords.jsondata/bundled/NETEASE-NOTICE.mddata/bundled/netease-g79.json.gzdata/bundled/netease-g79.report.jsondata/bundled/netease-x19.json.gzdata/bundled/netease-x19.report.jsonPinned upstream
97d3236b999c5f95c7adac1debf7fffb81d8bda22026-06-23T00:00:00Z2026-06-19T22:03:48ZSource SHA-256 values
SensitiveWords/G79SensitiveWords.json:f398f68c5af1b2b92e01b8dc895ddecef86b72cf2783c798566bab604b5aa07dSensitiveWords/X19SensitiveWords.json:5f8f7e4d6b2436a4b47e5d8c5fa2e936d06b6c18e45689ebf8aa712097baeba4LICENSE:3972dc9744f6499f0f9b2dbf76696f2ae7ad8af9b23dde66d6af86c9dfb36986Generated artifact SHA-256 values
data/bundled/netease-g79.json.gz:0f8d487d940685753896f20d6473482d1de5743e2392e2b7acfb4e36fe4ef2d7data/bundled/netease-g79.report.json:4925fc6ec4dea0adffdac09294587ef9b3c7899089a0008cbd0bda8b9430e975data/bundled/netease-x19.json.gz:be30a7d16847b25446d630b01164088a203b320b6fccfe364ae9dbbafb66a3e5data/bundled/netease-x19.report.json:45c7f1fc578ef4c2263ed60e8bfb0afd96647293b40a42702daddabfbe8d87e2File locations
third_party/netease-sensitive-words/upstream/G79SensitiveWords.json,third_party/netease-sensitive-words/upstream/X19SensitiveWords.jsonthird_party/netease-sensitive-words/LICENSEthird_party/netease-sensitive-words/SOURCE.jsondata/bundled/netease-g79.json.gz,data/bundled/netease-g79.report.json,data/bundled/netease-x19.json.gz,data/bundled/netease-x19.report.jsonActual counts and compatibility
G79:
X19:
Synchronization and rollback design
go run ./cmd/sync-netease-rulessupports offline verification, deterministic regeneration, and maintainer-only download mode. Download mode rejects floating refs, only accepts the reviewed 40-character pinned commit, downloads only the three allowlisted HTTPS upstream paths, uses finite timeouts, enforces response-size and status checks, restricts redirects, avoids credential forwarding, validates JSON/LICENSE content before replacement, stages through temporary files, and preserves prior snapshots on failure with rollback-oriented replacement.Offline reproducibility design
make verify-bundled-neteaseperforms no network access and should not modify tracked files. It reads committed source snapshots, regenerates G79/X19 Packs and reports in memory using the pinned commit timestamp, validatesSOURCE.jsonwith typed JSON decoding and hash/path/provenance checks, and compares regenerated bytes and SHA-256 values to committed artifacts.make regenerate-bundled-neteaserewrites deterministic artifacts from committed snapshots;git diff --exit-codepasses after regeneration.GPL-3.0 handling and MIT boundary
The full upstream GPL-3.0 license is preserved verbatim. Notices state that the upstream JSON and generated Packs/reports derived from it are GPL-3.0-covered material, while OpenAudit's root MIT license applies only to independently authored OpenAudit code and does not relicense third-party data. The notices also avoid claiming that repository layout alone is a definitive legal conclusion.
Runtime defaults
Phase B defaults remain conservative:
bundled_rules.enabled: false,bundled_rules.netease.enabled: false, both datasets disabled by default, Shield/Intercept group defaults inert until global/provider/dataset enablement is explicit, and Replace/Nickname/Remind remain disabled by default.Tests and exact results
gofmt -w cmd/sync-netease-rules/main.go internal/engine/bundled_runtime_test.go: passedgo test ./internal/bundled/... ./internal/engine/... ./internal/rules/... ./internal/config/...: passedgo test ./cmd/sync-netease-rules: passed ([no test files])make verify-bundled-netease: passedgit diff --check: passedgo test ./...: passedgo test -race ./internal/bundled/... ./internal/engine/...: passedgo vet ./...: passedgo build ./...: passedCGO_ENABLED=0 go build ./...: passedmake fmt-check: passedmake smoke: passedmake e2e: passedmake gosec: passed with 0 issuesmake govulncheck: failed becausegovulncheckcould not fetch the vulnerability DB:Get "https://vuln.go.dev/index/modules.json.gz": Forbiddenmake regenerate-bundled-netease && git diff --exit-code: passed after commitKnown limitations / deferred work
PCRE2 support, Docker/release packaging, release archives, automatic updates, and runtime downloads remain deferred. The runtime remains RE2-only and skips incompatible regexes while reporting them.