From 1dd640da873c1bda839108893d6b9c193bc86dc6 Mon Sep 17 00:00:00 2001 From: CI Bot Date: Tue, 28 Jul 2026 17:20:23 +0800 Subject: [PATCH] =?UTF-8?q?fix(ci):=20=E5=B0=86AI=20Code=20Review=E6=8E=A5?= =?UTF-8?q?=E5=85=A5CI=E9=97=A8=E7=A6=81=E4=BD=93=E7=B3=BB=EF=BC=8C?= =?UTF-8?q?=E4=B8=A5=E9=87=8D=E9=97=AE=E9=A2=98=E6=8B=A6=E6=88=AA=E5=90=88?= =?UTF-8?q?=E5=B9=B6?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - 在ci-pipeline中新增code-review job,与code-review.yml逻辑一致 - 将code-review加入CI Gate的needs列表和REQUIRED_GENERAL检查项 - AI审查发现阻塞级问题时,CI Gate失败,阻止PR合并 问题:AI Code Review只发表评论不参与门禁,有严重安全/质量问题的代码也能合并。 修复:将code-review纳入CI Gate,审查脚本exit 1(阻塞级问题)时CI整体失败。 注意:LLM调用异常时脚本exit 0(fail-open策略),不阻塞正常合并。 --- .gitea/workflows/ci-pipeline.yml | 71 ++++++++++++++++++++++++++++++++ 1 file changed, 71 insertions(+) diff --git a/.gitea/workflows/ci-pipeline.yml b/.gitea/workflows/ci-pipeline.yml index 195721213..b2795ca80 100755 --- a/.gitea/workflows/ci-pipeline.yml +++ b/.gitea/workflows/ci-pipeline.yml @@ -323,6 +323,73 @@ jobs: [ -f /tmp/ci_job_start_time ] && START_TIME=$(cat /tmp/ci_job_start_time) python3 scripts/ci/ci_trace_report.py --service xiaoxia-saas-ci --status $STATUS --start-time "$START_TIME" || true + code-review: + name: AI Code Review + runs-on: ci-l2 + timeout-minutes: 8 + if: github.event_name == 'pull_request' && !github.event.pull_request.draft + steps: + - name: Checkout code + shell: sh + env: + GITHUB_TOKEN: ${{ github.token }} + run: | + curl -sH "Authorization: token $GITHUB_TOKEN" "${GITHUB_API_URL}/repos/${GITHUB_REPOSITORY}/raw/scripts/ci/step_checkout.sh?ref=${GITHUB_SHA}" | bash + - name: Record job start time + shell: sh + run: bash scripts/ci/step_timer_start.sh + - name: Install dependencies + shell: sh + run: | + if ! python3 -m pip --version >/dev/null 2>&1; then + apt-get update -qq && apt-get install -y -qq python3-pip python3-venv >/dev/null 2>&1 + fi + if ! python3 -m pip --version >/dev/null 2>&1; then + python3 -m ensurepip --upgrade 2>/dev/null || curl -sS https://bootstrap.pypa.io/get-pip.py | python3 + fi + python3 -m pip install --quiet requests + - name: Run AI Code Review + shell: sh + env: + GITEA_API_URL: ${{ gitea.server_url }} + GITEA_TOKEN: ${{ secrets.REVIEW_GITEA_TOKEN }} + REPO_NAME: ${{ gitea.repository }} + PR_NUMBER: ${{ gitea.event.pull_request.number }} + PR_HEAD_SHA: ${{ gitea.event.pull_request.head.sha }} + LLM_PROVIDER: "coze" + LLM_BASE_URL: ${{ secrets.LLM_BASE_URL }} + LLM_API_KEY: ${{ secrets.LLM_API_KEY }} + COZE_BOT_ID: ${{ secrets.COZE_BOT_ID }} + LLM_MODEL: ${{ secrets.LLM_MODEL }} + MAX_DIFF_CHARS: "30000" + LLM_TIMEOUT: "120" + run: | + python3 scripts/ci_code_review.py + - name: Job duration summary + if: always() + shell: sh + run: bash scripts/ci/step_timer_end.sh + - name: Notify on failure + continue-on-error: true + if: failure() + shell: sh + env: + CI_NOTIFY_WEBHOOK: ${{ secrets.CI_NOTIFY_WEBHOOK }} + run: | + set +e + NOTIFY_MODE=failure JOB_NAME="AI Code Review" python3 scripts/ci_notify.py + - name: Report CI trace + if: always() + shell: sh + env: + AGENTLOOP_LICENSE_KEY: ${{ secrets.AGENTLOOP_LICENSE_KEY }} + run: | + STATUS="ok" + [ ${{ job.status }} = "success" ] || STATUS="error" + START_TIME="" + [ -f /tmp/ci_job_start_time ] && START_TIME=$(cat /tmp/ci_job_start_time) + python3 scripts/ci/ci_trace_report.py --service xiaoxia-saas-ci --status $STATUS --start-time "$START_TIME" || true + unit-tests: needs: check-frontend-only if: always() && needs.check-frontend-only.outputs.skip_backend != 'true' @@ -1680,6 +1747,7 @@ jobs: - validate-code-quality - validate-type-check - validate-migration + - code-review - unit-tests - integration-tests - frontend-lint @@ -1707,6 +1775,7 @@ jobs: RESULT_CODE_QUALITY: ${{ needs.validate-code-quality.result }} RESULT_TYPE_CHECK: ${{ needs.validate-type-check.result }} RESULT_MIGRATION: ${{ needs.validate-migration.result }} + RESULT_CODE_REVIEW: ${{ needs.code-review.result }} RESULT_UNIT_TESTS: ${{ needs.unit-tests.result }} RESULT_INTEGRATION: ${{ needs.integration-tests.result }} RESULT_FRONTEND_LINT: ${{ needs.frontend-lint.result }} @@ -1721,6 +1790,7 @@ jobs: echo " validate-code-quality: $RESULT_CODE_QUALITY" echo " validate-type-check: $RESULT_TYPE_CHECK" echo " validate-migration: $RESULT_MIGRATION" + echo " code-review: $RESULT_CODE_REVIEW" echo " unit-tests: $RESULT_UNIT_TESTS" echo " integration-tests: $RESULT_INTEGRATION" echo " frontend-lint: $RESULT_FRONTEND_LINT" @@ -1739,6 +1809,7 @@ jobs: "validate-code-quality:$RESULT_CODE_QUALITY" "validate-type-check:$RESULT_TYPE_CHECK" "validate-migration:$RESULT_MIGRATION" + "code-review:$RESULT_CODE_REVIEW" "frontend-lint:$RESULT_FRONTEND_LINT" "build-pr:$RESULT_BUILD_PR" )