fix: review hardening — full push-range diff, fail-closed diff fetch, crash-safe queue, 403 self-heal

- push reviews now fetch ONE compare diff (before...after) instead of
  slicing to the first 20 commits under a head-sha status; new-branch
  pushes (zero before-sha) fall back to the head commit diff
- truncated diffs can no longer yield a clean pass: verdict capped at
  warn and status description prefixed 'partial review (diff truncated)'
- any diff-fetch failure (throw / empty body on a non-empty push or PR)
  short-circuits to status 'warning' ('review unavailable — diff fetch
  failed (not blocking)') with a ledger row; a diffless prompt is never
  sent to the model
- accepted jobs persist to sqlite (queue_jobs) before the pending status
  posts; startup re-enqueues rows that never reached a final state, so
  restarts no longer strand shas at 'pending'
- 403 on status/comment posts self-heals: admin-scoped token (config
  admin_token) adds shre-reviewer as collaborator (write), retries once
- scripts/wire-repos.mjs: idempotent estate-wide webhook + collaborator
  wiring over GET /repos/search
- tests: 32 -> 51 (truncation cap, persisted-queue reconciliation,
  collab-retry stubs, fetchDiff routing)

Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
Nirav Patel
2026-08-19 09:12:10 -04:00
co-authored by Claude Fable 5
parent f35a75f787
commit e32c600215
14 changed files with 508 additions and 37 deletions
+84
View File
@@ -0,0 +1,84 @@
import { test } from 'node:test';
import assert from 'node:assert/strict';
import { withCollabRetry } from '../src/lib/access.js';
const err = (status, msg = `http ${status}`) => Object.assign(new Error(msg), { status });
const noLog = () => {};
function adminStub() {
const calls = [];
return {
calls,
addCollaborator(owner, repo, username, permission) {
calls.push({ owner, repo, username, permission });
return Promise.resolve();
}
};
}
test('403 adds collaborator (write) then retries once and succeeds', async () => {
const admin = adminStub();
let attempts = 0;
const out = await withCollabRetry(async () => {
attempts++;
if (attempts === 1) throw err(403);
return 'ok';
}, { adminGitea: admin, owner: 'nirpa', repo: 'newrepo', botUsername: 'shre-reviewer', log: noLog });
assert.equal(out, 'ok');
assert.equal(attempts, 2);
assert.deepEqual(admin.calls, [{ owner: 'nirpa', repo: 'newrepo', username: 'shre-reviewer', permission: 'write' }]);
});
test('non-403 errors are rethrown without touching collaborators', async () => {
const admin = adminStub();
await assert.rejects(
() => withCollabRetry(() => Promise.reject(err(500)), {
adminGitea: admin, owner: 'o', repo: 'r', botUsername: 'b', log: noLog
}),
/http 500/
);
assert.equal(admin.calls.length, 0);
});
test('403 with no admin client rethrows the original 403', async () => {
await assert.rejects(
() => withCollabRetry(() => Promise.reject(err(403)), {
adminGitea: null, owner: 'o', repo: 'r', botUsername: 'b', log: noLog
}),
(e) => e.status === 403
);
});
test('retry happens exactly once: second 403 propagates', async () => {
const admin = adminStub();
let attempts = 0;
await assert.rejects(
() => withCollabRetry(() => { attempts++; return Promise.reject(err(403)); }, {
adminGitea: admin, owner: 'o', repo: 'r', botUsername: 'b', log: noLog
}),
(e) => e.status === 403
);
assert.equal(attempts, 2);
assert.equal(admin.calls.length, 1);
});
test('addCollaborator failure propagates (no infinite loop)', async () => {
const admin = {
addCollaborator: () => Promise.reject(err(422, 'bad permission'))
};
let attempts = 0;
await assert.rejects(
() => withCollabRetry(() => { attempts++; return Promise.reject(err(403)); }, {
adminGitea: admin, owner: 'o', repo: 'r', botUsername: 'b', log: noLog
}),
/bad permission/
);
assert.equal(attempts, 1);
});
test('success path never consults the admin client', async () => {
const out = await withCollabRetry(() => Promise.resolve(42), {
adminGitea: undefined, owner: 'o', repo: 'r', botUsername: 'b', log: noLog
});
assert.equal(out, 42);
});