feat: Gitea 自动代码审查服务

基于 OpenCodeReview 的 webhook 服务:监听 Gitea 的 push 与 Pull Request 事件,
调用 OCR 审查 diff,把结果发布回 Gitea,并按阻断阈值决定是否自动合并。

主要能力:
- Push / PR 事件触发,支持分支 glob 过滤与 PR-only / push-only 范围
- PR 内联评论(按 diff 行号定位)、汇总评论、Issue 生命周期、提交状态
- 可配置阻断阈值(严重级别 / 类别 / 任意意见)
- 无阻断问题时自动合并,审查覆盖不完整时拒绝合并
- 内置 Web 后台:仓库配置、任务日志、失败重跑、连通性自检
- SQLite 持久化,worker 重启回收卡死任务,失败自动重试

实现为独立服务而非 Gitea Action:本机 act_runner 指向的实例不可达,
且后台配置与任务历史需要独立进程承载。
This commit is contained in:
2026-09-20 12:09:46 +08:00
commit ed172bf369
18 changed files with 3451 additions and 0 deletions
+218
View File
@@ -0,0 +1,218 @@
/**
* Unit tests for diff parsing, branch matching, and job claiming.
* Run with: node --test tests/
*/
import { strict as assert } from "node:assert";
import { test } from "node:test";
import { rmSync } from "node:fs";
import { parseUnifiedDiff, addedLineNumbers, diffLineNumbers, pickAnchorLine } from "../app/lib/diff.js";
import { branchMatches } from "../app/lib/review.js";
import { severityAtLeast, parseList } from "../app/lib/ocr.js";
import { normalizeBaseUrl } from "../app/lib/gitea.js";
import {
openDatabase, upsertRepository, enqueueJob, claimNextJob, updateJob,
getBranchState, setBranchState, findJobBySha, recordDelivery, jobStats,
} from "../app/lib/db.js";
// Hunk headers must agree with the body line counts: the parser advances the
// new-file cursor from the header, so an inconsistent fixture would silently
// shift every later line number.
const SAMPLE = `diff --git a/src/app.js b/src/app.js
index 1111111..2222222 100644
--- a/src/app.js
+++ b/src/app.js
@@ -1,4 +1,5 @@
const a = 1;
-const b = 2;
+const b = 3;
+const c = 4;
module.exports = { a, b };
@@ -20,3 +21,4 @@ function later() {
const x = 1;
return 1;
}
+const d = 5;
diff --git a/new.txt b/new.txt
new file mode 100644
--- /dev/null
+++ b/new.txt
@@ -0,0 +1,2 @@
+hello
+world
diff --git a/gone.txt b/gone.txt
deleted file mode 100644
--- a/gone.txt
+++ /dev/null
@@ -1,1 +0,0 @@
-bye
`;
test("parseUnifiedDiff tracks paths, status and hunk line maps", () => {
const files = parseUnifiedDiff(SAMPLE);
assert.deepEqual([...files.keys()], ["src/app.js", "new.txt", "gone.txt"]);
assert.equal(files.get("src/app.js").status, "modified");
assert.equal(files.get("new.txt").status, "added");
assert.equal(files.get("gone.txt").status, "deleted");
assert.equal(files.get("src/app.js").hunks.length, 2);
});
test("addedLineNumbers only reports added new-file lines", () => {
const files = parseUnifiedDiff(SAMPLE);
assert.deepEqual([...addedLineNumbers(files.get("src/app.js"))].sort((a, b) => a - b), [2, 3, 24]);
assert.deepEqual([...addedLineNumbers(files.get("new.txt"))].sort((a, b) => a - b), [1, 2]);
assert.deepEqual([...addedLineNumbers(files.get("gone.txt"))], []);
});
test("diffLineNumbers includes context lines", () => {
const files = parseUnifiedDiff(SAMPLE);
const lines = diffLineNumbers(files.get("src/app.js"));
// Context (1, 4, 5, 21, 22, 23) and added (2, 3, 24) lines are all renderable.
assert.deepEqual([...lines].sort((a, b) => a - b), [1, 2, 3, 4, 5, 21, 22, 23, 24]);
// The deleted old-file line 2 has no new-file counterpart.
assert.ok(!lines.has(6));
});
test("pickAnchorLine prefers added lines inside the hunk", () => {
const files = parseUnifiedDiff(SAMPLE);
const entry = files.get("src/app.js");
assert.deepEqual(pickAnchorLine(entry, 2, 3), { line: 2, inDiff: true });
assert.deepEqual(pickAnchorLine(entry, 3, 3), { line: 3, inDiff: true });
assert.deepEqual(pickAnchorLine(entry, 24, 24), { line: 24, inDiff: true });
});
test("pickAnchorLine falls back to context then to the start line", () => {
const files = parseUnifiedDiff(SAMPLE);
const entry = files.get("src/app.js");
// Line 1 is context in the hunk, so it is still rendered inline.
assert.deepEqual(pickAnchorLine(entry, 1, 1), { line: 1, inDiff: true });
// Line 999 is outside every hunk: keep it, but flag it as not inline.
assert.deepEqual(pickAnchorLine(entry, 999, 999), { line: 999, inDiff: false });
});
test("branchMatches honours glob patterns and ref prefixes", () => {
assert.ok(branchMatches("main", "*"));
assert.ok(branchMatches("main", ""));
assert.ok(branchMatches("refs/heads/main", "main"));
assert.ok(branchMatches("release/1.2", "release/*"));
assert.ok(!branchMatches("feature/x", "release/*"));
assert.ok(branchMatches("feature/x", "main, feature/*"));
assert.ok(branchMatches("a/b/c", "a/**"));
});
test("severityAtLeast compares known severities and rejects unknown ones", () => {
assert.ok(severityAtLeast("critical", "high"));
assert.ok(severityAtLeast("high", "high"));
assert.ok(!severityAtLeast("medium", "high"));
assert.ok(!severityAtLeast("", "low"));
assert.ok(!severityAtLeast("bogus", "low"));
});
test("parseList trims and drops empties", () => {
assert.deepEqual(parseList("critical, high ,,low"), ["critical", "high", "low"]);
assert.deepEqual(parseList(""), []);
assert.deepEqual(parseList(null), []);
});
test("normalizeBaseUrl accepts root and api/v1 forms", () => {
for (const input of ["http://h", "http://h/", "http://h/api/v1", "http://h/api/v1/"]) {
assert.equal(normalizeBaseUrl(input), "http://h");
}
});
function tempDb(name) {
const path = `F:\\tmp\\cr-test-${name}-${process.pid}.db`;
for (const suffix of ["", "-wal", "-shm"]) rmSync(path + suffix, { force: true });
const db = openDatabase(path);
return {
db,
cleanup() {
db.close();
for (const suffix of ["", "-wal", "-shm"]) rmSync(path + suffix, { force: true });
},
};
}
test("job queue claims once and records terminal state", () => {
const { db, cleanup } = tempDb("queue");
try {
const repo = upsertRepository(db, { owner: "o", name: "r" });
const jobId = enqueueJob(db, { repoId: repo.id, trigger: "push", refName: "main", toSha: "a".repeat(40) });
const first = claimNextJob(db);
assert.equal(first.id, jobId);
assert.equal(first.status, "running");
assert.equal(first.attempts, 1);
assert.equal(claimNextJob(db), null, "a claimed job is not handed out twice");
updateJob(db, jobId, { status: "succeeded", findings: 2, blocking: 1 });
assert.deepEqual(jobStats(db), { queued: 0, running: 0, succeeded: 1, failed: 0, skipped: 0 });
assert.equal(findJobBySha(db, repo.id, "a".repeat(40)), undefined, "finished jobs are not treated as in-flight");
} finally {
cleanup();
}
});
test("findJobBySha blocks duplicate in-flight reviews", () => {
const { db, cleanup } = tempDb("dedupe");
try {
const repo = upsertRepository(db, { owner: "o", name: "r" });
const sha = "b".repeat(40);
enqueueJob(db, { repoId: repo.id, trigger: "push", refName: "main", toSha: sha });
assert.ok(findJobBySha(db, repo.id, sha));
const claimed = claimNextJob(db);
assert.ok(findJobBySha(db, repo.id, sha), "running jobs still count");
updateJob(db, claimed.id, { status: "skipped" });
assert.equal(findJobBySha(db, repo.id, sha), undefined);
} finally {
cleanup();
}
});
test("webhook deliveries are deduplicated by delivery id", () => {
const { db, cleanup } = tempDb("delivery");
try {
assert.equal(recordDelivery(db, "d-1"), true);
assert.equal(recordDelivery(db, "d-1"), false);
assert.equal(recordDelivery(db, "d-2"), true);
} finally {
cleanup();
}
});
test("repository defaults and branch state round-trip", () => {
const { db, cleanup } = tempDb("repo");
try {
const repo = upsertRepository(db, { owner: "kgod", name: "demo" });
assert.equal(repo.base_branch, "main");
assert.equal(repo.block_severity, "critical,high");
assert.equal(repo.review_scope, "both");
assert.equal(repo.create_issue, 1);
const updated = upsertRepository(db, { id: repo.id, auto_merge: 1, merge_method: "rebase" });
assert.equal(updated.auto_merge, 1);
assert.equal(updated.merge_method, "rebase");
assert.equal(getBranchState(db, repo.id, "main"), undefined);
setBranchState(db, repo.id, "main", "c".repeat(40));
assert.equal(getBranchState(db, repo.id, "main").last_sha, "c".repeat(40));
setBranchState(db, repo.id, "main", "d".repeat(40));
assert.equal(getBranchState(db, repo.id, "main").last_sha, "d".repeat(40));
} finally {
cleanup();
}
});
test("upsertRepository does not clobber unset fields", () => {
const { db, cleanup } = tempDb("patch");
try {
const repo = upsertRepository(db, { owner: "o", name: "r", issue_labels: "review" });
upsertRepository(db, { id: repo.id, auto_merge: 1 });
const after = db.prepare("SELECT * FROM repositories WHERE id = ?").get(repo.id);
assert.equal(after.issue_labels, "review");
assert.equal(after.auto_merge, 1);
} finally {
cleanup();
}
});