Files
roboco/tests/unit/services/test_git_merge_method_fallback.py
96401f4c10 feat(forge): Phases 2+2.1+3 — Gitea + GitLab providers, per-call routing, local-merge fallback (#575)
* feat(forge): Phase 2 — Gitea provider, per-call routing, host registry

Gitea support lands behind the Phase-1 seam:

- GiteaProvider (services/forge/gitea.py): Gitea v1 transport addressed
  by instance host (api base from the project's git_url). Where Gitea's
  wire contract diverges from GitHub's, the provider adapts responses
  back into the shapes GitService already classifies (ShapedResponse):
  `token` auth scheme, duplicate-PR 409→422 with the "already exists"
  text GitService keys on, commit statuses reshaped into check_runs /
  workflow_runs envelopes, APPROVE→APPROVED review mapping, Do-keyed
  POST merge, merge-method repo keys, label-color '#' prefix,
  client-side head/base PR filtering. Deliberate postures per the spec:
  zero-workflows fail-open (statuses-free repo → no_ci_configured) and
  merge_branch as a shaped 501 (env-sync cascade lands on missing_ref;
  the shared local-git fallback is Phase-2.1).
- ForgeRouter (services/forge/router.py): GitService._forge now routes
  per call from RepoRef.host — every existing call site unchanged in
  shape. RepoRef gains an optional host; _parse_git_url returns the
  host-stamped ref and it is threaded through GitService/release
  executor instead of being rebuilt from strings (helpers re-signatured
  to take RepoRef).
- Host registry (services/forge/registry.py): in-memory host→provider
  map, self-healing — ProjectService.get/get_by_slug re-register on
  every read; provider_for resolves gitea projects by git_url host.
- Registration validation now accepts git_provider="gitea"; GitLab
  remains recognized-but-rejected. Panel: the read-only Forge badge
  becomes a real picker (Auto-detect / GitHub-GHE / Gitea / GitLab
  disabled).

Plain git (clone/fetch/push) needs no changes — the Basic-auth
extraheader works on Gitea unchanged. Gates: mypy 392 files, xenon A,
full unit suite 6356 green, integration suite 2257 green.

* feat(forge): live-Gitea contract suite + scheme support + slash-safe refs

Hardening from running the provider against a real dockerized Gitea
1.22.6 (the spec's Phase-2 contract suite, now committed as the
env-gated tests/e2e_smoke/test_gitea_live.py — self-seeding: creates its
own repo, pushes real commits, and drives PR open → duplicate reshape →
list/filter → diff → review → labels → commit-status CI reshapes →
squash merge → branch delete → release, plus a live verification of the
x-access-token Basic-auth git-CLI claim).

Two real findings fixed:
- Branch refs weren't URL-encoded — every RoboCo branch carries slashes
  (feature/backend/...), and Gitea's router 404s on the extra path
  segments. list_ci_runs + delete_branch_ref now quote the ref
  (regression-pinned in the unit suite).
- The API base hardcoded https; a LAN instance serving plain http is a
  real deployment shape. GiteaProvider gains a scheme (recorded per host
  by the registry from the project's git_url).

ShapedResponse moves to forge/shaping.py (shared by the upcoming GitLab
transport, which needs its text override for diff reassembly).

* feat(forge): Phase 3 GitLab provider + Phase 2.1 local-merge fallback

GitLabProvider (services/forge/gitlab.py): GitLab v4 transport addressed
by host+scheme, subgroup-safe (the MR project path packs into
RepoRef.owner, URL-encoded per call). Adapters translate MR semantics
into the GitHub shapes GitService classifies: iid→number,
source/target_branch→head/base with a merged bool, per-file diffs
reassembled into unified-diff text (ShapedResponse text override,
3-page cap), approve-vs-note review routing (GitLab has no
request-changes verb), pipelines/statuses reshaped into
workflow_runs/check_runs, merge-method repo-key mapping, duplicate-MR
409→422. Reviewer mirroring is skipped (needs numeric ids RoboCo
doesn't store); provisioning stays Phase 4. gitlab.com now auto-detects
at registration like github.com; self-hosted GitLab sets the provider
explicitly (panel picker enabled).

Phase 2.1: neither Gitea nor GitLab has GitHub's server-side merges
API — their merge_branch returns a shaped 501 and
GitService.sync_env_branch now runs the shared local-git fallback
(_local_merge_branch: throwaway clone → ancestor check → merge → push;
a conflict aborts with the remote untouched; same status vocabulary as
the merges-API path).

Also aligns the whole tree with the full gate's tests/-scoped mypy
(provider-test responder typing, e2e_smoke's stale owner/repo shapes).
Gates: mypy 1229 files clean, xenon A, unit suite 6393 green, forge
suites 85 green, panel typecheck/lint clean.

---------

Co-authored-by: Renn F <rennf93@users.noreply.github.com>
2026-07-19 08:12:34 +02:00

250 lines
8.3 KiB
Python

"""GitService falls back to a permitted merge method when the repo refuses one.
A repo with squash merges disabled returns 405 ("Squash merges are not allowed")
on the default squash merge. Without a fallback the PM strands on an open,
mergeable PR — code built, QA passed, docs written, one API call from done.
merge_pull_request must look up a method the repo permits and retry once.
"""
from __future__ import annotations
from pathlib import Path
from typing import Any
from unittest.mock import AsyncMock, MagicMock
import pytest
import roboco.services.git as git_module
from roboco.exceptions import GitError
from roboco.services.forge import RepoRef
from roboco.services.git import GitService
def _git_service() -> GitService:
svc = GitService.__new__(GitService)
svc.log = MagicMock()
return svc
def _resp(
status_code: int, *, is_success: bool, json_data: dict[str, Any] | None = None
) -> Any:
payload = json_data or {}
return type(
"R",
(),
{
"status_code": status_code,
"is_success": is_success,
"text": "",
"json": lambda _self=None, _p=payload: _p,
},
)()
class _FakeClient:
def __init__(self, resp: Any) -> None:
self._resp = resp
async def __aenter__(self) -> _FakeClient:
return self
async def __aexit__(self, *_a: Any) -> bool:
return False
async def get(self, _url: str, **_kwargs: Any) -> Any:
return self._resp
@pytest.mark.asyncio
async def test_first_allowed_skips_disabled_method(
monkeypatch: pytest.MonkeyPatch,
) -> None:
svc = _git_service()
resp = _resp(
200,
is_success=True,
json_data={
"allow_squash_merge": False,
"allow_merge_commit": True,
"allow_rebase_merge": True,
},
)
monkeypatch.setattr(
git_module.httpx, "AsyncClient", lambda *_a, **_k: _FakeClient(resp)
)
method = await svc._first_allowed_merge_method(
RepoRef("o", "r"), "tok", exclude="squash"
)
assert method == "merge" # squash disabled + excluded -> next permitted
@pytest.mark.asyncio
async def test_first_allowed_returns_none_when_lookup_fails(
monkeypatch: pytest.MonkeyPatch,
) -> None:
svc = _git_service()
resp = _resp(403, is_success=False)
monkeypatch.setattr(
git_module.httpx, "AsyncClient", lambda *_a, **_k: _FakeClient(resp)
)
assert await svc._first_allowed_merge_method(RepoRef("o", "r"), "tok") is None
@pytest.mark.asyncio
async def test_merge_retries_with_allowed_method_on_405(
monkeypatch: pytest.MonkeyPatch,
) -> None:
svc = _git_service()
monkeypatch.setattr(
svc, "_get_project_token_or_raise", AsyncMock(return_value="tok")
)
monkeypatch.setattr(
svc, "_parse_github_remote", lambda _ws: RepoRef("owner", "repo")
)
monkeypatch.setattr(
svc, "_delete_pr_branch_best_effort", AsyncMock(return_value=None)
)
monkeypatch.setattr(
svc, "_project_default_branch", AsyncMock(return_value="master")
)
monkeypatch.setattr(svc, "_sync_target_branch", AsyncMock(return_value="abc123"))
monkeypatch.setattr(
svc, "_first_allowed_merge_method", AsyncMock(return_value="merge")
)
calls: list[str] = []
async def fake_call(_repo_ref: RepoRef, _pr: int, _token: str, method: str) -> Any:
calls.append(method)
return (
_resp(200, is_success=True)
if method == "merge"
else _resp(405, is_success=False)
)
monkeypatch.setattr(svc, "_call_merge_api", fake_call)
target, commit = await svc.merge_pull_request(Path("/tmp/ws"), 7, "squash", "proj")
assert calls == ["squash", "merge"] # refused squash, retried with merge
assert target == "master"
assert commit == "abc123"
@pytest.mark.asyncio
async def test_merge_does_not_retry_when_method_allowed(
monkeypatch: pytest.MonkeyPatch,
) -> None:
svc = _git_service()
monkeypatch.setattr(
svc, "_get_project_token_or_raise", AsyncMock(return_value="tok")
)
monkeypatch.setattr(
svc, "_parse_github_remote", lambda _ws: RepoRef("owner", "repo")
)
monkeypatch.setattr(
svc, "_delete_pr_branch_best_effort", AsyncMock(return_value=None)
)
monkeypatch.setattr(
svc, "_project_default_branch", AsyncMock(return_value="master")
)
monkeypatch.setattr(svc, "_sync_target_branch", AsyncMock(return_value="abc123"))
lookup = AsyncMock(return_value="merge")
monkeypatch.setattr(svc, "_first_allowed_merge_method", lookup)
calls: list[str] = []
async def fake_call(_repo_ref: RepoRef, _pr: int, _token: str, method: str) -> Any:
calls.append(method)
return _resp(200, is_success=True)
monkeypatch.setattr(svc, "_call_merge_api", fake_call)
await svc.merge_pull_request(Path("/tmp/ws"), 7, "squash", "proj")
assert calls == ["squash"] # allowed first time, no second call
lookup.assert_not_awaited() # fallback lookup never triggered
@pytest.mark.asyncio
async def test_merge_already_merged_pr_is_idempotent_success(
monkeypatch: pytest.MonkeyPatch,
) -> None:
"""The CEO ``merge_pull_request`` path treats an already-merged PR as
idempotent success (not GitError) — a merge PUT on an already-merged PR
returns the same 405 as a genuine refusal, so they must be disambiguated.
"""
svc = _git_service()
monkeypatch.setattr(
svc, "_get_project_token_or_raise", AsyncMock(return_value="tok")
)
monkeypatch.setattr(
svc, "_parse_github_remote", lambda _ws: RepoRef("owner", "repo")
)
delete_branch = AsyncMock(return_value=None)
monkeypatch.setattr(svc, "_delete_pr_branch_best_effort", delete_branch)
monkeypatch.setattr(
svc, "_project_default_branch", AsyncMock(return_value="master")
)
sync_target = AsyncMock(return_value="abc123")
monkeypatch.setattr(svc, "_sync_target_branch", sync_target)
# No fallback retry would help (already merged => 405 either way); make the
# fallback lookup return None so the code falls straight through to the
# already-merged disambiguation.
monkeypatch.setattr(
svc, "_first_allowed_merge_method", AsyncMock(return_value=None)
)
# The GitHub merge PUT "refuses" (405) because the PR is already merged.
monkeypatch.setattr(
svc, "_call_merge_api", AsyncMock(return_value=_resp(405, is_success=False))
)
# ... and the PR is in fact already merged on GitHub.
monkeypatch.setattr(svc, "_pr_is_merged", AsyncMock(return_value=True))
target, commit = await svc.merge_pull_request(Path("/tmp/ws"), 42, "squash", "proj")
# Idempotent success, not a raise.
assert target == "master"
assert commit == "abc123"
# The post-merge steps still run (branch cleanup, target sync) so the
# caller's state stays consistent with "the PR is merged".
delete_branch.assert_awaited_once()
sync_target.assert_awaited_once()
@pytest.mark.asyncio
async def test_merge_raises_when_not_merged_and_refused(
monkeypatch: pytest.MonkeyPatch,
) -> None:
"""A genuine merge refusal (not mergeable, NOT already-merged) still raises
GitError — the idempotency guard must not mask a real failure."""
svc = _git_service()
monkeypatch.setattr(
svc, "_get_project_token_or_raise", AsyncMock(return_value="tok")
)
monkeypatch.setattr(
svc, "_parse_github_remote", lambda _ws: RepoRef("owner", "repo")
)
delete_branch = AsyncMock(return_value=None)
monkeypatch.setattr(svc, "_delete_pr_branch_best_effort", delete_branch)
monkeypatch.setattr(
svc, "_project_default_branch", AsyncMock(return_value="master")
)
monkeypatch.setattr(svc, "_sync_target_branch", AsyncMock(return_value="abc123"))
monkeypatch.setattr(
svc, "_first_allowed_merge_method", AsyncMock(return_value=None)
)
monkeypatch.setattr(
svc, "_call_merge_api", AsyncMock(return_value=_resp(405, is_success=False))
)
# PR is NOT merged — this is a real conflict, not an idempotent retry.
monkeypatch.setattr(svc, "_pr_is_merged", AsyncMock(return_value=False))
with pytest.raises(GitError):
await svc.merge_pull_request(Path("/tmp/ws"), 42, "squash", "proj")
# No post-merge cleanup ran — the merge did not land.
delete_branch.assert_not_awaited()