feat(launcher): Campaign LA LA3 — AcDream.Launcher.Core profile store, composer, supervisor, status tailer

New AcDream.Launcher.Core (BCL-only, ProjectReference: AcDream.Platform
ONLY) plus tests/AcDream.Launcher.Core.Tests, both registered in
AcDream.slnx. This is the file-contract orchestrator core the Avalonia
launcher (LA4) will bind to — the game solution (Core/Runtime/App/
Headless) stays entirely out of this dependency graph, so the launcher
can never accidentally grow a game-protocol coupling.

- Profiles/: LauncherProfileStore owns launcher-profiles.json (spec §5
  schema: version 1, servers[]/accounts[]/characters[]), strict
  camelCase System.Text.Json (UnmappedMemberHandling.Disallow), typed
  CRUD (add/edit/remove server; add/edit/remove account; edit character
  settings), and MergeRoster (fold a reported roster into an account's
  characters[] while preserving user-owned launchMode/plugins/
  loginCommands, adding new rows with default guiSelect, and retaining
  rows absent from the roster — they may be pending-delete). 0600 on
  Linux via File.SetUnixFileMode after save.
- Launching/: SessionConfigComposer builds the pinned session-config
  contract (Headless K1 shape + plugins/loginCommands/
  loginCommandDelayMs/statusFile) from a profile character + install
  record — character selector omitted entirely for guiSelect, policy
  {id:"idle"} only for headless, credential always standardInput/
  session. Passwords never enter this document (proven by a dedicated
  test). LauncherProcessSupervisor spawns a host, feeds the password to
  stdin then closes it, and exposes Starting/Running/Exited lifecycle;
  Stop calls CloseMainWindow falling back to Kill after a timeout, both
  reachable through an injectable ILauncherChildProcess/factory seam so
  the state machine is unit-testable without real OS process timing.
- Status/: StatusEventParser decodes the v1 status.jsonl vocabulary
  (started/connected/characterList/enteredWorld/pluginLoaded/
  pluginFailed/disconnected/exited); an unrecognized "e" or a malformed
  line degrades to a typed Unknown event rather than throwing.
  StatusFileTailer incrementally reads new lines, tolerating a
  not-yet-existing file and a partial trailing line (only advances its
  read position past confirmed '\n' boundaries; a truncated tail is
  simply re-read next poll, never parsed early).
- Integrity/: streaming SHA-256 + hex verify for later pak/download
  checks (LA9/LA10).

Tests: 71 passed (profile CRUD + roster-merge matrix + strict-schema
rejection; composer golden-shape tests for gui/guiSelect/headless +
password-absence; supervisor tests against both an injected fake child
(state-machine determinism) and a real spawned `dotnet --version`
child (genuine cross-platform stdin/exit-code proof); tailer tests
incl. partial-line and not-yet-existing-file; SHA-256 tests). Verified
green on Windows (Release) and native WSL/Linux (Release) — the Linux
0600 test executes its real assertion body under WSL rather than
early-returning.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Erik 2026-08-14 15:49:13 +02:00
parent cb6502c8a5
commit 37d74e4402
31 changed files with 3131 additions and 0 deletions

View file

@ -0,0 +1,61 @@
using System.Security.Cryptography;
namespace AcDream.Launcher.Core.Integrity;
/// <summary>
/// Streaming SHA-256 for pak/download verification, consumed by the
/// install engine (LA9) and the updater (LA10). Kept minimal in this
/// slice: hash a file and compare its hex digest.
/// </summary>
public static class FileIntegrity
{
/// <summary>
/// Computes the lower-case hex SHA-256 digest of a file, streaming it
/// from disk rather than loading it fully into memory (relevant for
/// the ~30&#160;GB pak file LA9 verifies).
/// </summary>
public static string ComputeSha256Hex(string filePath)
{
ArgumentException.ThrowIfNullOrWhiteSpace(filePath);
using FileStream stream = new(
filePath,
FileMode.Open,
FileAccess.Read,
FileShare.Read);
byte[] hash = SHA256.HashData(stream);
return Convert.ToHexStringLower(hash);
}
public static async Task<string> ComputeSha256HexAsync(
string filePath,
CancellationToken cancellationToken = default)
{
ArgumentException.ThrowIfNullOrWhiteSpace(filePath);
await using FileStream stream = new(
filePath,
FileMode.Open,
FileAccess.Read,
FileShare.Read,
bufferSize: 4096,
useAsync: true);
byte[] hash = await SHA256.HashDataAsync(stream, cancellationToken)
.ConfigureAwait(false);
return Convert.ToHexStringLower(hash);
}
/// <summary>Case-insensitive hex comparison — callers may receive an
/// expected digest in either case from a manifest or a hand-typed
/// fixture.</summary>
public static bool Matches(string actualHex, string expectedHex)
{
ArgumentNullException.ThrowIfNull(actualHex);
ArgumentNullException.ThrowIfNull(expectedHex);
return string.Equals(actualHex, expectedHex, StringComparison.OrdinalIgnoreCase);
}
/// <summary>Computes and compares in one call.</summary>
public static bool Verify(string filePath, string expectedHex) =>
Matches(ComputeSha256Hex(filePath), expectedHex);
}