fix: review hardening — full push-range diff, fail-closed diff fetch, crash-safe queue, 403 self-heal

- push reviews now fetch ONE compare diff (before...after) instead of
  slicing to the first 20 commits under a head-sha status; new-branch
  pushes (zero before-sha) fall back to the head commit diff
- truncated diffs can no longer yield a clean pass: verdict capped at
  warn and status description prefixed 'partial review (diff truncated)'
- any diff-fetch failure (throw / empty body on a non-empty push or PR)
  short-circuits to status 'warning' ('review unavailable — diff fetch
  failed (not blocking)') with a ledger row; a diffless prompt is never
  sent to the model
- accepted jobs persist to sqlite (queue_jobs) before the pending status
  posts; startup re-enqueues rows that never reached a final state, so
  restarts no longer strand shas at 'pending'
- 403 on status/comment posts self-heals: admin-scoped token (config
  admin_token) adds shre-reviewer as collaborator (write), retries once
- scripts/wire-repos.mjs: idempotent estate-wide webhook + collaborator
  wiring over GET /repos/search
- tests: 32 -> 51 (truncation cap, persisted-queue reconciliation,
  collab-retry stubs, fetchDiff routing)

Co-Authored-By: Claude Fable 5 <[email protected]>
This commit is contained in:
Nirav Patel
2026-08-19 09:12:10 -04:00
co-authored by Claude Fable 5
parent f35a75f787
commit e32c600215
14 changed files with 508 additions and 37 deletions
+51
View File
@@ -0,0 +1,51 @@
import { test } from 'node:test';
import assert from 'node:assert/strict';
import { openDb, enqueueJob, finishJob, recoverPendingJobs } from '../src/lib/db.js';
const JOB = (over = {}) => ({
event: 'push', owner: 'nirpa', repo: 'demo', sha: 'a'.repeat(40),
ref: 'refs/heads/main', before: 'b'.repeat(40), prIndex: null, prTitle: null,
pusher: 'nirpa', authors: ['nirpa'], commitShas: ['a'.repeat(40)],
commitMessages: ['msg'], ...over
});
test('enqueued jobs that never finish are recovered on startup', () => {
const db = openDb(':memory:');
const id1 = enqueueJob(db, JOB({ sha: '1'.repeat(40) }));
const id2 = enqueueJob(db, JOB({ sha: '2'.repeat(40) }));
const id3 = enqueueJob(db, JOB({ sha: '3'.repeat(40), prIndex: 7 }));
finishJob(db, id2, 'pass');
const pending = recoverPendingJobs(db);
assert.equal(pending.length, 2);
assert.deepEqual(pending.map(p => p.id), [id1, id3]);
// job payload round-trips intact
assert.equal(pending[0].job.sha, '1'.repeat(40));
assert.equal(pending[1].job.prIndex, 7);
assert.deepEqual(pending[0].job.commitMessages, ['msg']);
});
test('finished jobs are not recovered again', () => {
const db = openDb(':memory:');
const id = enqueueJob(db, JOB());
finishJob(db, id, 'warn');
assert.equal(recoverPendingJobs(db).length, 0);
});
test('unparseable persisted job is marked done, not re-run forever', () => {
const db = openDb(':memory:');
db.prepare(`INSERT INTO queue_jobs (repo, sha, job) VALUES ('a/b', 'c', '{broken')`).run();
assert.equal(recoverPendingJobs(db).length, 0);
// and it is now terminal
assert.equal(recoverPendingJobs(db).length, 0);
const row = db.prepare(`SELECT state, outcome FROM queue_jobs`).get();
assert.equal(row.state, 'done');
assert.equal(row.outcome, 'unparseable-job');
});
test('recovery is ordered oldest first', () => {
const db = openDb(':memory:');
const ids = [enqueueJob(db, JOB()), enqueueJob(db, JOB()), enqueueJob(db, JOB())];
const pending = recoverPendingJobs(db);
assert.deepEqual(pending.map(p => p.id), ids);
});