Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -51,5 +51,5 @@ bin-go/
.seo/blog-drafts/
.seo/skills/
.seo/patches/
# Fixed mise release archives fetched by task sync-mise, embedded per target.
# Legacy mise build resources from older checkouts; no longer used or embedded.
/packages/cli/internal/adapters/runtime/mise/assets/
4 changes: 0 additions & 4 deletions .goreleaser.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -15,10 +15,6 @@ version: 2

project_name: one-cli

before:
hooks:
- go run ./packages/cli/tools/sync-mise --all

builds:
- id: one
dir: packages/cli
Expand Down
20 changes: 9 additions & 11 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,8 +17,8 @@ one --version # 验证装好

> **fresh-clone 提示**:`packages/cli/internal/resources/bundled/` 整个目录是 gitignore 的——
> registry / templates / dashboard dist 都由 `task sync-bundled` +
> `task sync-web` 按需重建。`sync-bundled` 还会运行 `sync-mise`,下载并校验
> 当前平台的固定 mise 压缩包用于内置,作为 `task vet` / `test` / `build` 的依赖自动跑。
> `task sync-web` 按需重建。这些任务作为 `task vet` / `test` / `build` 的依赖自动运行;
> mise 不再是内嵌资源,构建与普通测试不需要下载 mise。
> 第一次 `task install` 会触发 `pnpm install + vite build`,~30s;之后
> task fingerprint 命中,几乎零成本。如果你直接跑 `go build` 而不走 Taskfile,
> 会看到 `pattern all:_templates: no matching files found` 这种报错——跑一次
Expand Down Expand Up @@ -74,17 +74,15 @@ CI;`task pre-push` 额外运行 Go race detector。远端五项检查会在 PR
- 公开 API(`packages/cli/pkg/`)改动要考虑 semver;详见 [CLAUDE.md 的 Public API stability](./CLAUDE.md)
- 加新错误码:在 `packages/cli/internal/platform/errors/codes.go` 注册 `Code` 常量 + `Codes` map 条目;测试会强制对应;改完跑 `task gen-error-codes` 刷新文档

### 内置 mise
### mise 运行时

发布的 One 文件内置对应平台的 mise 压缩包,首次运行从自身解压,不下载 mise。
`task sync-mise` 在构建时下载并校验本机平台资源;`task sync-mise-all` 准备五个平台。
`task build`、检查任务自动准备本机资源,`task build-all` 和 GoReleaser 自动准备全部平台。
资源位于被忽略的 `packages/cli/internal/adapters/runtime/mise/assets/`,不提交二进制资源。
资源已准备且摘要匹配时可离线构建。首次构建需要访问 GitHub Releases。
One 发布文件不包含 mise 程序或压缩包。实际运行时优先使用 `ONE_MISE_BINARY`,其次使用 PATH 中兼容的 mise,否则复用或从官方 GitHub Release 下载固定版本。最低兼容版本和托管版本分别维护;系统或托管程序被删除后,下一次需要 runtime 时重新解析并按需恢复。

升级时更新 `internal/adapters/runtime/mise/miserelease/release.go` 中的版本、压缩包和解压后程序的 SHA256,
以及 runtime 最低版本和相关文档;重新执行 `task sync-mise-all`。上游许可证保留于
`third_party/mise/LICENSE`,也包含在内置的原始压缩包和 One 发布归档中。
托管程序位于 `$XDG_DATA_HOME/one/runtimes/mise/<version>/<platform>/`,默认 `~/.local/share/one/runtimes/mise/`;工具、配置、状态和缓存分别使用对应 XDG 根下的 `one/mise/`。One 在托管子进程中设置四个 `MISE_*_DIR`,并关闭自动更新。外部 mise 沿用原目录。旧版 One 缓存中校验通过的同版本程序可以离线迁移,原缓存保留。

升级时验证上游校验文件的签名,更新 `packages/cli/internal/adapters/runtime/mise/miserelease/release.go` 中的版本、压缩包和程序 SHA256,再更新需要提高的 runtime 最低版本及相关文档。托管版本随 One 更新,不通过 `mise self-update` 维护。上游许可证保留于 `third_party/mise/LICENSE` 和 One 发布归档。

下载器及安装器测试使用本地 HTTP fixture,覆盖并发、重试、取消、摘要和删除修复。`ONE_TEST_MISE_BINARY=/absolute/path/to/mise go test ./packages/cli/tests/e2e -run Mise` 启用真实配置与信任测试;其中托管迁移测试要求与仓库固定摘要一致的官方程序。真实下载和多平台冒烟验证在发布前单独执行,不作为普通构建的资源依赖。

### 改 templates(`packages/templates/<id>/`)

Expand Down
19 changes: 2 additions & 17 deletions Taskfile.yml
Original file line number Diff line number Diff line change
Expand Up @@ -55,8 +55,6 @@ tasks:
- 'packages/kernel/**/*.go'
- 'packages/cli/cmd/**/*.go'
- 'packages/cli/internal/**/*.go'
- 'packages/cli/internal/adapters/runtime/mise/assets/*.tar.gz'
- 'packages/cli/internal/adapters/runtime/mise/assets/*.zip'
- 'packages/cli/internal/adapters/deploy/kustomize/templates/*'
- 'packages/cli/internal/platform/i18n/locales/*.json'
- 'packages/cli/internal/resources/bundled/**/*'
Expand Down Expand Up @@ -188,12 +186,12 @@ tasks:

build-all:
desc: Cross-compile every supported platform under go-dist/
deps: [sync-bundled, sync-mise-all, sync-web]
deps: [sync-bundled, sync-web]
dir: '{{.CLI_DIR}}'
cmds:
- rm -rf ../../go-dist
- mkdir -p ../../go-dist
- for: { var: PLATFORMS, default: ['darwin/amd64', 'darwin/arm64', 'linux/amd64', 'linux/arm64', 'windows/amd64'] }
- for: ['darwin/amd64', 'darwin/arm64', 'linux/amd64', 'linux/arm64', 'windows/amd64']
cmd: |
plat={{.ITEM}}
os=${plat%/*}
Expand Down Expand Up @@ -366,20 +364,7 @@ tasks:
generates:
- 'apps/dashboard/dist/index.html'

sync-mise:
desc: Fetch and verify the pinned mise archive embedded for the local platform
run: once
cmds:
- go run ./packages/cli/tools/sync-mise

sync-mise-all:
desc: Fetch and verify mise archives for all release platforms
run: once
cmds:
- go run ./packages/cli/tools/sync-mise --all

sync-bundled:
deps: [sync-mise]
desc: Regenerate registry/_templates/_skills under packages/cli/internal/resources/bundled (go:embed sources)
run: once
summary: |
Expand Down
24 changes: 24 additions & 0 deletions apps/docs/content/docs/en/installation.md
Original file line number Diff line number Diff line change
Expand Up @@ -85,6 +85,30 @@ On Windows, the archive is `one-cli_windows_amd64.zip`.

For normal upgrades, rerun the install command. Use `ONE_FORCE` only for downgrade or repair.

## mise Runtime

One does not bundle mise. When a command needs it, One uses an explicit `ONE_MISE_BINARY` first, then a compatible mise on PATH (minimum 2026.9.7), then its own verified installation. If none is available, it downloads the pinned official mise 2026.9.7 release, verifies both archive and executable SHA256, and installs it atomically. Supported targets are macOS/Linux x64 and arm64, and Windows x64; Linux uses musl releases. [Official distribution](https://mise.jdx.dev/installing-mise.html).

Selection happens again on each invocation. Removing system mise switches to the managed runtime; a missing or damaged managed executable is repaired automatically. A compatible system installation takes priority again when restored. Invalid explicit overrides report an error instead of falling back. No shell activation is required.

| Managed content | Default location | Root override |
|---|---|---|
| mise executable | `~/.local/share/one/runtimes/mise/<version>/<platform>/` | `XDG_DATA_HOME` |
| Tools and plugins | `~/.local/share/one/mise/` | `XDG_DATA_HOME` |
| Global configuration | `~/.config/one/mise/` | `XDG_CONFIG_HOME` |
| State and trust records | `~/.local/state/one/mise/` | `XDG_STATE_HOME` |
| Disposable cache | `~/.cache/one/mise/` | `XDG_CACHE_HOME` |

The same effective Home convention applies on Windows. XDG roots must be absolute. For managed mise, One sets `MISE_DATA_DIR`, `MISE_CONFIG_DIR`, `MISE_STATE_DIR`, and `MISE_CACHE_DIR` in the child environment, replacing inherited values. External mise retains its existing directory settings. Project configuration stays in the project. Switching to managed mise can require reinstalling tools and granting trust again; One does not copy external configuration or trust records.

Managed mise updates with One; automatic self-updates are disabled for that child process. Manually replacing it with `mise self-update` causes the next invocation to restore the pinned executable. A verified executable from an older One cache can be migrated without downloading, preserving the old file. Cache cleanup does not remove tools or trust records.

**Offline use:** a valid external, managed, or migratable legacy executable can be reused offline. A fresh environment without any of them needs network access. Prepare mise and the required tools/dependencies beforehand, or point `ONE_MISE_BINARY` to a compatible external executable. `ONE_RUNTIME=builtin` is a temporary diagnostic escape hatch using existing tools.

Download, migration, or verification failures return `MISE_INSTALL_FAILED`. Check network/proxy access to GitHub Releases and permissions on One's runtime directory, then retry the same command. Help, dry-run, and static project/configuration generation do not prepare mise.

Use `one mise --version`, `one mise doctor`, or `one mise trust <config-path>` to work with the same selected runtime. Review configuration before trusting it; `MISE_PARANOID=1` requires explicit trust. Arguments, IO, and exit codes are forwarded, without One project secrets; use `one run` when those secrets are needed.

## Configure Provider Credentials

Provider credentials are configured once with `one configure add <domain>/<backend> --profile <name>` and can be reused across workspaces. Current configurable pairs are:
Expand Down
2 changes: 1 addition & 1 deletion apps/docs/content/docs/zh/create.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,7 +50,7 @@ one create my-app --yes --env-provider infisical
| 工具环境 | mise | 自动生成根 `.mise/conf.d/one.toml`;后续 `one add` 自动生成项目配置 |
| Git 检查 | hk | 创建共享检查配置并安装本地提交钩子;后续 `one add` 增量加入语言检查 |

创建和添加项目只生成配置,不下载工具。首次运行时 One 从自身解压内置 mise,用户无需单独安装或下载 mise;正常命令保持不变。工具版本与已有 workspace 的启用方式见 [`one configure mise`](/zh/docs/configure/#mise-工作区工具配置)。
创建和添加项目只生成配置,不下载工具。首次运行时 One 优先使用兼容的系统 mise,否则按需下载并托管;本地没有可用版本时需要联网,正常命令保持不变。工具版本与已有 workspace 的启用方式见 [`one configure mise`](/zh/docs/configure/#mise-工作区工具配置)。

空工作区先保持语言无关:首次添加 Go 模块时创建根 `go.work` 并登记该模块;首次添加 JS/TS 项目时创建根 `package.json` 和 `pnpm-workspace.yaml`。后续项目增量加入,两套配置可以共存。Git hooks 从创建工作区时就由 hk 提供,纯 Go 工作区不生成 Node 配置;JS 工作区也不再依赖 Husky 或 commitlint。工作区不默认安装版本管理工具或生成 Changesets 配置,发布流程由项目按需配置。

Expand Down
2 changes: 1 addition & 1 deletion apps/docs/content/docs/zh/error-codes.md
Original file line number Diff line number Diff line change
Expand Up @@ -693,7 +693,7 @@ A managed mise configuration was modified or changed during generation.

### `MISE_INSTALL_FAILED`

One could not extract, verify, or prepare its bundled mise runtime.
One could not download, migrate, verify, or prepare its managed mise runtime.

> 没有默认 remediation。具体恢复方式请看错误的 `context` 字段。

Expand Down
6 changes: 3 additions & 3 deletions apps/docs/content/docs/zh/hk.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ title: one hk
description: 使用 hk 统一工作区检查、显式修复和 Git 提交检查。
---

`one hk` 通过 One 内置的 mise 运行固定版本的 hk。Go、JS/TS 和混合工作区使用同一套入口,不需要为了 Git hooks 安装 Husky 或 commitlint。
`one hk` 通过 One 选择的 mise(优先系统版本,否则按需下载并托管) 运行固定版本的 hk。Go、JS/TS 和混合工作区使用同一套入口,不需要为了 Git hooks 安装 Husky 或 commitlint。

## 日常使用

Expand Down Expand Up @@ -34,7 +34,7 @@ one mise exec -- pnpm exec oxfmt --write package.json
one configure hooks
```

Git 启动器记录本次 One 可执行文件的位置,并通过它运行内置 mise;不依赖终端的 mise 激活状态。移动或更换 One 安装位置后,可以重新执行 `one configure hooks`。
Git 启动器记录本次 One 可执行文件的位置,并通过它解析和运行 mise;不依赖终端的 mise 激活状态。移动或更换 One 安装位置后,可以重新执行 `one configure hooks`。

## 默认检查

Expand All @@ -48,7 +48,7 @@ Git 启动器记录本次 One 可执行文件的位置,并通过它运行内

提交检查不调用 Go 模板中包含 `go mod tidy` 的 `task check`。构建、类型检查和测试仍可通过项目原有命令执行,也可以自行加入 hk 配置。

工具版本由 mise 提供,首次需要时下载并缓存。mise 本身已经内置在 One 中;hk 是单独安装的工作区工具。JS 检查使用项目依赖,需要先安装依赖;`one dev <project>` 会准备开发依赖,也可运行 `one mise exec -- pnpm install`。
工具版本由 mise 提供,首次需要时下载并缓存。mise 本身优先使用系统版本,本地没有可用程序时由 One 下载并托管;hk 是单独安装的工作区工具。JS 检查使用项目依赖,需要先安装依赖;`one dev <project>` 会准备开发依赖,也可运行 `one mise exec -- pnpm install`。

## 配置与项目增量更新

Expand Down
28 changes: 21 additions & 7 deletions apps/docs/content/docs/zh/installation.md
Original file line number Diff line number Diff line change
Expand Up @@ -87,20 +87,34 @@ Windows 归档名是 `one-cli_windows_amd64.zip`。

## One 自动管理 mise

新建 workspace 的 `one run` 和 `one dev` 使用 mise 管理工具环境。**发布的 `one` 文件已内置当前平台的 mise 2026.9.7,无需单独安装,首次使用也无需下载 mise。** One 校验内置压缩包,解压并校验可执行文件后放入自己的缓存;后续运行复用缓存。macOS、Linux 的 x64 / arm64 和 Windows x64 发布文件分别携带对应平台资源。[官方二进制分发说明](https://mise.jdx.dev/installing-mise.html)。
新建 workspace 的 `one run` 和 `one dev` 使用 mise 管理工具环境。**One 安装包不包含 mise;实际使用时优先采用 PATH 中兼容的 mise,否则复用或从官方 GitHub Release 下载固定版本 2026.9.7。** 下载后校验压缩包和程序 SHA256,再原子安装。支持 macOS、Linux 的 x64 / arm64 和 Windows x64;Linux 使用 musl 资源。[官方二进制分发说明](https://mise.jdx.dev/installing-mise.html)。

不需要激活 shell。配置信任遵循 mise 自身规则;默认模式下执行命令可能自动信任当前配置,设置 `MISE_PARANOID=1` 后需先显式审查并信任配置;Node、Go 等工具下载由 mise 处理,应用依赖仍由包管理器安装,尚未安装的工具和依赖仍可能需要联网。旧 workspace 在显式启用前继续沿用已有工具,详见 [`one configure mise`](/zh/docs/configure/#mise-工作区工具配置)。
每次需要 runtime 时重新检查:系统 mise 被删除、版本过旧或不可执行时,One 转用托管版本;托管程序缺失或损坏时自动恢复。系统版本重新可用后恢复系统优先。显式设置 `ONE_MISE_BINARY` 的路径或版本有误时直接报错,不自动回退。

缓存位于 `$XDG_CACHE_HOME/one/runtimes/mise/<version>/<platform>/`,未设置时使用 `~/.cache/one/runtimes/mise/`。One 默认使用内置固定版本,仅在子进程 PATH 中加入缓存目录。缓存损坏会从内置资源重新解压,无需联网。内置 mise 随 One 升级;One 会关闭该子进程的 mise 自动升级和更新提示。内置资源会增加 One 发布文件体积;运行时需要可写、可执行的缓存目录。
不需要激活 shell。配置信任遵循 mise 自身规则;设置 `MISE_PARANOID=1` 后需先显式审查并信任配置。旧 workspace 在显式启用前继续沿用已有工具,详见 [`one configure mise`](/zh/docs/configure/#mise-工作区工具配置)。

| 托管内容 | 默认目录 | 自定义根目录 |
|---|---|---|
| mise 程序 | `~/.local/share/one/runtimes/mise/<version>/<platform>/` | `XDG_DATA_HOME` |
| Node、Go、插件等 | `~/.local/share/one/mise/` | `XDG_DATA_HOME` |
| mise 全局配置 | `~/.config/one/mise/` | `XDG_CONFIG_HOME` |
| 状态、信任记录 | `~/.local/state/one/mise/` | `XDG_STATE_HOME` |
| 可清理缓存 | `~/.cache/one/mise/` | `XDG_CACHE_HOME` |

Windows 同样使用有效用户 Home 下的对应目录。XDG 根必须是绝对路径。托管模式会在子进程中设置 `MISE_DATA_DIR`、`MISE_CONFIG_DIR`、`MISE_STATE_DIR`、`MISE_CACHE_DIR`,覆盖继承的同名变量;外部 mise 保留原目录设置。项目配置文件仍留在项目内。切换到托管模式时,工具可能需要重新安装,配置可能需要重新授权;不复制系统配置或信任记录。

One 仅修改子进程 PATH。托管版本随 One 更新,自动升级和更新提示在该子进程中关闭;自行用 `mise self-update` 替换托管程序后,下次运行会按固定摘要修复。旧版 One 缓存中的同版本程序经校验后可迁移,旧文件保留。缓存与程序、工具、状态分开,清理缓存不会删除工具或信任记录。
Comment thread
caorushizi marked this conversation as resolved.

**离线使用**:已有可用系统版本、托管程序或可迁移旧缓存时无需下载 mise。全新环境没有这些程序时需要联网;可提前安装兼容 mise 或用 `ONE_MISE_BINARY` 指定已准备的程序。Node、Go、hk 和项目依赖也须提前安装,mise 程序可用并不代表这些工具已可离线使用。

| 变量 | 用途 |
|---|---|
| `ONE_MISE_BINARY` | 显式使用其他 mise 可执行文件的绝对路径,最低支持版本为 2026.9.7 |
| `ONE_MISE_BINARY` | 显式指定 mise 可执行文件的绝对路径,外部程序最低支持版本为 2026.9.7 |
| `ONE_RUNTIME=builtin` | 临时诊断时使用机器原有工具,跳过 mise |

解压、写入或校验失败返回 `MISE_INSTALL_FAILED`;不会执行不完整的文件。修复缓存权限后重试原命令,内置资源损坏时重新安装 One。显式指定的 mise 文件不存在时返回 `MISE_NOT_FOUND`。`--dry-run`、创建项目和生成配置不会解压 runtime。
下载、迁移、写入或校验失败返回 `MISE_INSTALL_FAILED`;检查到 GitHub Releases 的网络/代理及托管目录权限后重试原命令。显式外部文件不存在时返回 `MISE_NOT_FOUND`。帮助、`--dry-run`、创建项目和生成配置不准备 runtime。

需要访问 mise 的原生命令时,使用 `one mise`,无需把缓存目录加入 PATH:
需要访问 mise 的原生命令时,使用 `one mise`,无需把托管程序目录加入 PATH:

```bash
one mise --version
Expand All @@ -110,7 +124,7 @@ one mise trust apps/web/.mise/conf.d/one.toml
one mise exec -- pnpm install
```

`trust` 请在审查对应配置后运行;自定义配置同样遵循 mise 的信任规则。安装依赖的例子应在 workspace 根目录执行。`one mise` 原样转发参数、IO 和退出码,不额外注入 One 项目密钥;需要项目密钥时继续使用 `one run`。`one mise --help` 展示 One 的入口说明,不触发解压。
`trust` 请在审查对应配置后运行;自定义配置同样遵循 mise 的信任规则。安装依赖的例子应在 workspace 根目录执行。`one mise` 原样转发参数、IO 和退出码,不额外注入 One 项目密钥;需要项目密钥时继续使用 `one run`。`one mise --help` 展示 One 的入口说明,不探测或下载 mise。

## 配置 Provider 凭据

Expand Down
Loading
Loading