Repository navigation
fix(ci): harden the lint gate and enable Ruff security rules (#537, #539) - #538
Draft
liujuanjuan1984 wants to merge 3 commits into
Draft
liujuanjuan1984 wants to merge 3 commits into
liujuanjuan1984 wants to merge 3 commits into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
目的
本 PR 收口此前审查发现的两项 CI / 静态检查问题(按评审要求合并在同一 PR,不再拆分):
S(flake8-bandit)安全规则,且src/中 24 处assert需要按最佳实践收敛。提交记录
8d7dfecfix(ci): reject pre-commit rewrites in the lint gate ([Bug] CI 的 lint 门禁被重试掩盖:pre-commit 自动修复不会导致失败 #537)9b5a143test(ci): pin the shared repo-state fingerprint contract ([Bug] CI 的 lint 门禁被重试掩盖:pre-commit 自动修复不会导致失败 #537)a3a5636chore(lint): enable Ruff security rules and converge src asserts ([Enhancement] 启用 Ruff 安全规则集(S)并收敛 24 处 assert #539)一、lint 门禁:不再被重试掩盖(#537)
问题
scripts/lint.sh对pre-commit run --all-files最多重试 3 次,任意一次成功即返回 0;而trailing-whitespace、end-of-file-fixer、ruff check --fix、ruff format都是自动修复型钩子(改写文件时返回非 0)。于是第 1 次失败并就地修好、第 2 次必然通过 → CI 绿灯,但提交内容并不满足仓库规范。修复前实测(探针文件 +
git add):bash ./scripts/lint.sh→ 重试后 退出码 0。变更
scripts/health_common.sh:把doctor.sh原有的工作区指纹函数抽取为共享的repo_state_fingerprint()(搬迁,非新造)。scripts/doctor.sh:改用共享函数,删除本地重复定义。scripts/lint.sh:复用同一指纹判定;若pre-commit改写了工作区文件 → 立即失败并给出明确提示;对未改写文件的瞬时失败仍保留重试与既有环境变量接口;失败时返回 pre-commit 的真实退出码。tests/scripts/test_script_health_contract.py:更新 doctor 契约(含负向断言,锁定指纹只有一处实现),新增 lint 门禁契约测试。二、启用 Ruff 安全规则并收敛 assert(#539)
问题
[tool.ruff.lint] select = ["E", "F", "I", "B", "UP"]缺少S,作为对外提供 A2A/JSON-RPC 服务的运行时存在静态安全规则缺口。实测启用后src/有 24 处S101,scripts/另有 1 处S607。变更(对齐 codex-a2a 的既有做法)
pyproject.toml:规则集加入S;按兄弟仓库codex-a2a的既有配置,对tests/**使用per-file-ignores豁免S(测试模块本就要用assert与假凭证),不扩大豁免范围。src/的 24 处assert全部收敛:session_id/message_id/workspace_id/request_body/parsed):改为显式typing.cast(...)收窄——与 codex-a2a 中cast(ReviewStartControlParams, parsed_params)等既有写法一致。assert raw_result is not None):改为显式raise UpstreamContractError(...),保留运行期检查且不受python -O影响。agent_card.py2 处扩展 URI 顺序):改为显式raise RuntimeError(...)。session_lifecycle.py末尾的assert method == method_unshare_session改为显式elif+ 兜底raise UpstreamContractError,去掉“用 assert 表达分支”的写法。scripts/conformance_probe.py:S607通过shutil.which("git")解析绝对路径消除;残留的S603是静态误报(固定参数 + 已解析的绝对路径),按 codex-a2a 同类写法就地# noqa: S603并写明原因。CONTRIBUTING.md:说明S对发布代码启用、tests/**豁免的原因与不可扩大。tests/**豁免范围。验证证据
uv run ruff check→ All checks passed!(含S)uv run ruff format --check→ 198 files already formatteduv run mypy src/opencode_a2a→ Success: no issues found in 89 source filesuv run pre-commit run --all-files→ 全部 Passed,且未改写任何文件(同时验证新门禁不误伤)bash ./scripts/lint.sh→ 退出码 1,输出ERROR: pre-commit rewrote repository files; the lint gate rejects hook-generated edits.,不再重试bash ./scripts/doctor.sh→ 退出码 0;覆盖率 93.46%(门禁 ≥90%),构建与 wheel 冒烟测试通过.venv、*.cache、dist/、run/等均被.gitignore覆盖Validate Default Toolchain、Validate Protobuf 6 Compatibility、Runtime Matrix (3.11/3.12/3.13)全部 pass影响与风险
AGENTS.md、doctor.sh的既有要求一致。cast替换的是“前置校验已保证非空”的收窄断言;raw_result守卫保留为显式异常,因此失败路径行为不变。agent_card的模块契约不变量改为显式异常,在python -O下依然生效(比原来的assert更强)。关联