Files
xiaoxia-saas/scripts/ci/run_validate.sh
T
CI Bot 80c3432c67
CI/CD Pipeline / Build Staging API Image (pull_request) Has been skipped
CI/CD Pipeline / Build Staging Web Image (pull_request) Has been skipped
CI/CD Pipeline / Build Staging Worker Image (pull_request) Has been skipped
CI/CD Pipeline / Deploy Staging (Watchtower auto-deploy) (pull_request) Has been skipped
CI/CD Pipeline / Build Production API Image (pull_request) Has been skipped
CI/CD Pipeline / Build Production Web Image (pull_request) Has been skipped
CI/CD Pipeline / Build Production Worker Image (pull_request) Has been skipped
CI/CD Pipeline / Staging E2E Tests (pull_request) Has been skipped
CI/CD Pipeline / Staging API Integration Tests (pull_request) Has been skipped
CI/CD Pipeline / Deploy Production (pull_request) Has been skipped
CI/CD Pipeline / ACR Image Cleanup (pull_request) Has been skipped
CI/CD Pipeline / Production Browser E2E (pull_request) Has been skipped
CI/CD Pipeline / Check if frontend-only change (pull_request) Successful in 11s
CI/CD Pipeline / Frontend Unit Tests (pull_request) Has been skipped
Preview Deploy / Deploy Preview Environment (pull_request) Failing after 17s
AI Code Review / AI Code Review (pull_request) Successful in 2m5s
CI/CD Pipeline / Frontend Lint (pull_request) Successful in 4m8s
CI/CD Pipeline / Unit Tests (pull_request) Successful in 4m6s
CI/CD Pipeline / Validate Code Quality And Tests (pull_request) Failing after 6m5s
PR Automation / Auto Merge on CI Green + Approved (pull_request) Successful in 6m22s
PR Automation / Auto Approve on CI Green (pull_request) Successful in 6m27s
CI/CD Pipeline / Integration Tests (pull_request) Failing after 1m34s
fix(ci): 修复PG/Redis连接探测 - 等网络就绪再探测,避免空host假阳性
修复两个关键bug:
1. 容器刚healthy时端口映射和IP可能还没就绪,改为循环等待
   healthy + (有映射端口 or 有容器IP) 才进入下一步
2. 容器IP为空时 socket.connect(('', port)) 不报错导致假阳性,
   改为先验证IP/端口格式合法再尝试连接

优化:将healthy检查和网络就绪检查合并到一个循环,
同时展示当前状态,方便调试。
2026-07-19 22:53:00 +08:00

246 lines
8.6 KiB
Bash
Executable File

#!/bin/bash
# CI Validate Job 主脚本:代码质量全量检查
# 包含:密钥扫描、格式检查、类型检查、安全扫描、依赖漏洞检查、死代码检测、Alembic迁移验证
set -eu
echo "=== CI Validate: 开始全量代码质量检查 ==="
# --- 密钥检测 ---
echo ""
echo "=== [1/8] Secret detection (detect-secrets) ==="
python3 -m pip install -q detect-secrets
detect-secrets --version
detect-secrets scan \
--all-files \
--exclude-files '(^|/)(tests|test|e2e|__tests__|spec|docs|node_modules|site-packages|migrations|alembic|.gitea|.git|.pytest_cache|.next|dist|build)/' \
--exclude-files '\.(md|rst|txt|lock|example|sample|min\.js|min\.css|spec\.ts|test\.ts|test\.py)$' \
--exclude-files '(package-lock|yarn\.lock|poetry\.lock|Pipfile\.lock)$' \
--disable-plugin Base64HighEntropyString \
--disable-plugin HexHighEntropyString \
--disable-plugin BasicAuthDetector \
--disable-plugin KeywordDetector \
--disable-plugin IPPublicDetector \
> /tmp/secrets-scan.json 2>&1
FOUND=$(python3 -c "
import json
try:
with open('/tmp/secrets-scan.json') as f:
data = json.load(f)
results = data.get('results', {})
total = sum(len(v) for v in results.values())
print(total)
except Exception:
print('error')
")
echo "Secrets detected: $FOUND"
if [ "$FOUND" != "0" ] && [ "$FOUND" != "error" ]; then
echo ""
echo "=== Secret details ==="
python3 -c "
import json
with open('/tmp/secrets-scan.json') as f:
data = json.load(f)
for fpath, items in data.get('results', {}).items():
for item in items:
line = item.get('line_number', '?')
stype = item.get('type', '?')
hashed = item.get('hashed_secret', '')[:16]
print(f' {fpath}:{line} [{stype}] {hashed}...')
"
echo ""
echo "ERROR: Potential secrets detected in code!"
exit 1
fi
echo "✅ Secret scan passed"
# --- 增量/全量模式判断 ---
echo ""
echo "=== [2/8] Code quality checks ==="
SCAN_MODE="full"
CHANGED_PY_FILES=""
if [ "${GITHUB_EVENT_NAME:-}" = "pull_request" ] && [ -n "${GITHUB_REF_NAME:-}" ] && [ -n "${GITHUB_TOKEN:-}" ]; then
PR_NUMBER=$(echo "$GITHUB_REF" | sed 's|refs/pull/||; s|/.*||')
API_URL="${GITHUB_API_URL}/repos/${GITHUB_REPOSITORY}/pulls/${PR_NUMBER}/files?limit=100"
set +e
RESPONSE=$(curl -s -w "\n%{http_code}" -H "Authorization: token ${GITHUB_TOKEN}" "$API_URL")
HTTP_CODE=$(echo "$RESPONSE" | tail -n1)
BODY=$(echo "$RESPONSE" | sed '$d')
set -e
if [ "$HTTP_CODE" = "200" ]; then
CHANGED_PY_FILES=$(echo "$BODY" | python3 -c "
import json, sys
try:
files = json.load(sys.stdin)
py_files = [f['filename'] for f in files if f['filename'].endswith('.py') and f['status'] != 'removed']
print(' '.join(py_files))
except Exception:
print('')
")
if [ -n "$CHANGED_PY_FILES" ]; then
SCAN_MODE="incremental"
echo "Incremental mode: $(echo "$CHANGED_PY_FILES" | wc -w) Python files changed"
else
SCAN_MODE="skip_py"
echo "No Python files changed in this PR"
fi
else
echo "WARN: API returned HTTP $HTTP_CODE, falling back to full scan"
fi
else
echo "Full scan mode (not a PR event)"
fi
if [ "$SCAN_MODE" = "incremental" ]; then
python3 -m compileall -q $CHANGED_PY_FILES
python3 -m black --check --fast $CHANGED_PY_FILES
python3 -m isort --check-only $CHANGED_PY_FILES
RUFF_FILES=$(echo "$CHANGED_PY_FILES" | tr ' ' '\n' | grep -v '^scripts/' | tr '\n' ' ')
if [ -n "$RUFF_FILES" ]; then
python3 -m ruff check $RUFF_FILES --statistics
else
echo "No ruff-checkable files changed, skipping"
fi
elif [ "$SCAN_MODE" = "skip_py" ]; then
echo "No Python files changed - skipping Python lint checks"
else
echo "Full scan mode"
python3 -m compileall -q alembic apps packages tests scripts
python3 -m black --check --fast alembic apps packages tests scripts
python3 -m isort --check-only alembic apps packages tests scripts
python3 -m ruff check apps packages tests --statistics
fi
echo "✅ Code quality checks passed"
# --- Mypy 类型检查 ---
echo ""
echo "=== [3/8] Type check (mypy) ==="
bash scripts/ci/mypy_check.sh
echo "✅ Mypy type check passed"
# --- Bandit 安全扫描 ---
echo ""
echo "=== [4/8] Security scan (bandit) ==="
bandit -r apps packages -q -ll
echo "✅ Bandit security scan passed"
# --- Pip-audit 依赖漏洞扫描(仅告警) ---
echo ""
echo "=== [5/8] Python dependency vulnerability scan (pip-audit, advisory only) ==="
python3 -m pip install -q pip-audit
pip-audit --version
EXIT_CODE=0
for req_file in requirements.txt requirements-base.txt requirements-dev.txt; do
if [ -f "$req_file" ]; then
echo "--- Scanning $req_file ---"
pip-audit -r "$req_file" --desc on 2>&1 | head -40 || EXIT_CODE=$?
echo ""
fi
done
echo "pip-audit scan completed (advisory mode - warnings only, not blocking CI)"
# --- Vulture 死代码检测(仅告警) ---
echo ""
echo "=== [6/8] Dead code detection (vulture, advisory only) ==="
set +e
python3 -m pip install -q vulture
vulture --version
echo "告警模式,不阻断CI。置信度>=90%建议尽快确认。"
echo ""
vulture apps packages scripts \
--exclude "tests,test,migrations,.gitea,docs,node_modules,site-packages,*/test_*.py,*/conftest.py" \
--min-confidence 70 \
2>&1 | sort -t'(' -k2 -rn | head -80
echo ""
echo "=== vulture scan summary ==="
echo "发现潜在死代码(可能包含框架装饰器注册的函数,为误报)"
echo "建议:定期人工审查高置信度(>=90%)条目"
set -e
# --- Release 脚本语法校验 ---
echo ""
echo "=== [7/8] Release scripts syntax validation ==="
bash -n scripts/backup_postgres.sh
bash -n scripts/restore_postgres_plan.sh
bash -n scripts/init_production_env.sh
echo "✅ Release scripts syntax OK"
# --- Alembic 迁移验证 ---
echo ""
echo "=== [8/8] Alembic migrations validation (with isolated PG) ==="
PG_CONTAINER=ci-pg-validate-${GITHUB_RUN_ID:-$$}
docker rm -f "$PG_CONTAINER" 2>/dev/null || true
docker run -d --name "$PG_CONTAINER" \
--shm-size=256m \
-e POSTGRES_USER=postgres \
-e POSTGRES_PASSWORD=postgres \
-e POSTGRES_DB=xiaoxia_saas \
-P \
--health-cmd "pg_isready -U postgres" \
--health-interval 3s \
--health-timeout 3s \
--health-retries 20 \
postgres:16-alpine
# 等待PG容器healthy + 网络就绪(端口映射和IP可能比healthy晚几秒钟)
for i in $(seq 1 40); do
HEALTH=$(docker inspect --format='{{.State.Health.Status}}' "$PG_CONTAINER" 2>/dev/null || echo "starting")
MAPPED_PORT=$(docker port "$PG_CONTAINER" 5432/tcp 2>/dev/null | cut -d: -f2 | grep -E '^[0-9]+$' || true)
CONTAINER_IP=$(docker inspect --format='{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' "$PG_CONTAINER" 2>/dev/null | grep -E '^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+$' || true)
if echo "$HEALTH" | grep -q healthy && { [ -n "$MAPPED_PORT" ] || [ -n "$CONTAINER_IP" ]; }; then
echo "PostgreSQL ready - healthy: $HEALTH, mapped port: ${MAPPED_PORT:-N/A}, container IP: ${CONTAINER_IP:-N/A}"
break
fi
echo "Waiting for PostgreSQL + network... ($i/40) health=$HEALTH port=${MAPPED_PORT:-none} ip=${CONTAINER_IP:-none}"
sleep 2
done
# 双模式探测:先试端口映射,再试容器IP,哪个通就用哪个
PG_HOST=""
PG_PORT=""
if [ -n "$MAPPED_PORT" ]; then
echo "Trying mapped port mode (127.0.0.1:$MAPPED_PORT)..."
for i in $(seq 1 15); do
if python3 -c "import socket; s=socket.socket(); s.settimeout(2); s.connect(('127.0.0.1', $MAPPED_PORT)); s.close()" 2>/dev/null; then
PG_HOST="127.0.0.1"
PG_PORT="$MAPPED_PORT"
echo "✅ Mapped port mode works: 127.0.0.1:$MAPPED_PORT"
break
fi
sleep 2
done
fi
if [ -z "$PG_HOST" ] && [ -n "$CONTAINER_IP" ]; then
echo "Trying container IP mode ($CONTAINER_IP:5432)..."
for i in $(seq 1 15); do
if python3 -c "import socket; s=socket.socket(); s.settimeout(2); s.connect(('$CONTAINER_IP', 5432)); s.close()" 2>/dev/null; then
PG_HOST="$CONTAINER_IP"
PG_PORT="5432"
echo "✅ Container IP mode works: $CONTAINER_IP:5432"
break
fi
sleep 2
done
fi
if [ -z "$PG_HOST" ]; then
echo "ERROR: 无法通过任何方式连接到PostgreSQL容器"
echo "mapped port=${MAPPED_PORT:-none}, container IP=${CONTAINER_IP:-none}"
echo "当前runner的Docker网络可能存在配置异常,请联系运维检查runner环境"
exit 1
fi
echo "Using PostgreSQL: $PG_HOST:$PG_PORT"
export DATABASE_URL="postgresql+psycopg://postgres:postgres@$PG_HOST:$PG_PORT/xiaoxia_saas"
PYTHONPATH="$PWD/apps/api:$PWD" python3 -m alembic upgrade head
echo "✅ Alembic migrations applied successfully"
docker rm -f "$PG_CONTAINER" 2>/dev/null || true
echo ""
echo "=== CI Validate: 所有检查通过 ✅ ==="