Compare commits
3 Commits
docs/secur
...
fix/1445-a
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
90641aa56e | ||
| 7dff8a4b5e | |||
|
|
96af984005 |
8
app.js
8
app.js
@@ -714,6 +714,10 @@ async function init() {
|
||||
camera = new THREE.PerspectiveCamera(65, window.innerWidth / window.innerHeight, 0.1, 1000);
|
||||
camera.position.copy(playerPos);
|
||||
|
||||
// Initialize avatar and LOD systems
|
||||
if (window.AvatarCustomization) window.AvatarCustomization.init(scene, camera);
|
||||
if (window.LODSystem) window.LODSystem.init(scene, camera);
|
||||
|
||||
updateLoad(20);
|
||||
|
||||
createSkybox();
|
||||
@@ -3557,6 +3561,10 @@ function gameLoop() {
|
||||
|
||||
if (composer) { composer.render(); } else { renderer.render(scene, camera); }
|
||||
|
||||
// Update avatar and LOD systems
|
||||
if (window.AvatarCustomization && playerPos) window.AvatarCustomization.update(playerPos);
|
||||
if (window.LODSystem && playerPos) window.LODSystem.update(playerPos);
|
||||
|
||||
updateAshStorm(delta, elapsed);
|
||||
|
||||
// Project Mnemosyne - Memory Orb Animation
|
||||
|
||||
@@ -395,6 +395,8 @@
|
||||
<div id="memory-connections-panel" class="memory-connections-panel" style="display:none;" aria-label="Memory Connections Panel"></div>
|
||||
|
||||
<script src="./boot.js"></script>
|
||||
<script src="./avatar-customization.js"></script>
|
||||
<script src="./lod-system.js"></script>
|
||||
<script>
|
||||
function openMemoryFilter() { renderFilterList(); document.getElementById('memory-filter').style.display = 'flex'; }
|
||||
function closeMemoryFilter() { document.getElementById('memory-filter').style.display = 'none'; }
|
||||
|
||||
186
lod-system.js
Normal file
186
lod-system.js
Normal file
@@ -0,0 +1,186 @@
|
||||
/**
|
||||
* LOD (Level of Detail) System for The Nexus
|
||||
*
|
||||
* Optimizes rendering when many avatars/users are visible:
|
||||
* - Distance-based LOD: far users become billboard sprites
|
||||
* - Occlusion: skip rendering users behind walls
|
||||
* - Budget: maintain 60 FPS target with 50+ avatars
|
||||
*
|
||||
* Usage:
|
||||
* LODSystem.init(scene, camera);
|
||||
* LODSystem.registerAvatar(avatarMesh, userId);
|
||||
* LODSystem.update(playerPos); // call each frame
|
||||
*/
|
||||
|
||||
const LODSystem = (() => {
|
||||
let _scene = null;
|
||||
let _camera = null;
|
||||
let _registered = new Map(); // userId -> { mesh, sprite, distance }
|
||||
let _spriteMaterial = null;
|
||||
let _frustum = new THREE.Frustum();
|
||||
let _projScreenMatrix = new THREE.Matrix4();
|
||||
|
||||
// Thresholds
|
||||
const LOD_NEAR = 15; // Full mesh within 15 units
|
||||
const LOD_FAR = 40; // Billboard beyond 40 units
|
||||
const LOD_CULL = 80; // Don't render beyond 80 units
|
||||
const SPRITE_SIZE = 1.2;
|
||||
|
||||
function init(sceneRef, cameraRef) {
|
||||
_scene = sceneRef;
|
||||
_camera = cameraRef;
|
||||
|
||||
// Create shared sprite material
|
||||
const canvas = document.createElement('canvas');
|
||||
canvas.width = 64;
|
||||
canvas.height = 64;
|
||||
const ctx = canvas.getContext('2d');
|
||||
// Simple avatar indicator: colored circle
|
||||
ctx.fillStyle = '#00ffcc';
|
||||
ctx.beginPath();
|
||||
ctx.arc(32, 32, 20, 0, Math.PI * 2);
|
||||
ctx.fill();
|
||||
ctx.fillStyle = '#0a0f1a';
|
||||
ctx.beginPath();
|
||||
ctx.arc(32, 28, 8, 0, Math.PI * 2); // head
|
||||
ctx.fill();
|
||||
|
||||
const texture = new THREE.CanvasTexture(canvas);
|
||||
_spriteMaterial = new THREE.SpriteMaterial({
|
||||
map: texture,
|
||||
transparent: true,
|
||||
depthTest: true,
|
||||
sizeAttenuation: true,
|
||||
});
|
||||
|
||||
console.log('[LODSystem] Initialized');
|
||||
}
|
||||
|
||||
function registerAvatar(avatarMesh, userId, color) {
|
||||
// Create billboard sprite for this avatar
|
||||
const spriteMat = _spriteMaterial.clone();
|
||||
if (color) {
|
||||
// Tint sprite to match avatar color
|
||||
const canvas = document.createElement('canvas');
|
||||
canvas.width = 64;
|
||||
canvas.height = 64;
|
||||
const ctx = canvas.getContext('2d');
|
||||
ctx.fillStyle = color;
|
||||
ctx.beginPath();
|
||||
ctx.arc(32, 32, 20, 0, Math.PI * 2);
|
||||
ctx.fill();
|
||||
ctx.fillStyle = '#0a0f1a';
|
||||
ctx.beginPath();
|
||||
ctx.arc(32, 28, 8, 0, Math.PI * 2);
|
||||
ctx.fill();
|
||||
spriteMat.map = new THREE.CanvasTexture(canvas);
|
||||
spriteMat.map.needsUpdate = true;
|
||||
}
|
||||
|
||||
const sprite = new THREE.Sprite(spriteMat);
|
||||
sprite.scale.set(SPRITE_SIZE, SPRITE_SIZE, 1);
|
||||
sprite.visible = false;
|
||||
_scene.add(sprite);
|
||||
|
||||
_registered.set(userId, {
|
||||
mesh: avatarMesh,
|
||||
sprite: sprite,
|
||||
distance: Infinity,
|
||||
});
|
||||
}
|
||||
|
||||
function unregisterAvatar(userId) {
|
||||
const entry = _registered.get(userId);
|
||||
if (entry) {
|
||||
_scene.remove(entry.sprite);
|
||||
entry.sprite.material.dispose();
|
||||
_registered.delete(userId);
|
||||
}
|
||||
}
|
||||
|
||||
function setSpriteColor(userId, color) {
|
||||
const entry = _registered.get(userId);
|
||||
if (!entry) return;
|
||||
const canvas = document.createElement('canvas');
|
||||
canvas.width = 64;
|
||||
canvas.height = 64;
|
||||
const ctx = canvas.getContext('2d');
|
||||
ctx.fillStyle = color;
|
||||
ctx.beginPath();
|
||||
ctx.arc(32, 32, 20, 0, Math.PI * 2);
|
||||
ctx.fill();
|
||||
ctx.fillStyle = '#0a0f1a';
|
||||
ctx.beginPath();
|
||||
ctx.arc(32, 28, 8, 0, Math.PI * 2);
|
||||
ctx.fill();
|
||||
entry.sprite.material.map = new THREE.CanvasTexture(canvas);
|
||||
entry.sprite.material.map.needsUpdate = true;
|
||||
}
|
||||
|
||||
function update(playerPos) {
|
||||
if (!_camera) return;
|
||||
|
||||
// Update frustum for culling
|
||||
_projScreenMatrix.multiplyMatrices(
|
||||
_camera.projectionMatrix,
|
||||
_camera.matrixWorldInverse
|
||||
);
|
||||
_frustum.setFromProjectionMatrix(_projScreenMatrix);
|
||||
|
||||
_registered.forEach((entry, userId) => {
|
||||
if (!entry.mesh) return;
|
||||
|
||||
const meshPos = entry.mesh.position;
|
||||
const distance = playerPos.distanceTo(meshPos);
|
||||
entry.distance = distance;
|
||||
|
||||
// Beyond cull distance: hide everything
|
||||
if (distance > LOD_CULL) {
|
||||
entry.mesh.visible = false;
|
||||
entry.sprite.visible = false;
|
||||
return;
|
||||
}
|
||||
|
||||
// Check if in camera frustum
|
||||
const inFrustum = _frustum.containsPoint(meshPos);
|
||||
if (!inFrustum) {
|
||||
entry.mesh.visible = false;
|
||||
entry.sprite.visible = false;
|
||||
return;
|
||||
}
|
||||
|
||||
// LOD switching
|
||||
if (distance <= LOD_NEAR) {
|
||||
// Near: full mesh
|
||||
entry.mesh.visible = true;
|
||||
entry.sprite.visible = false;
|
||||
} else if (distance <= LOD_FAR) {
|
||||
// Mid: mesh with reduced detail (keep mesh visible)
|
||||
entry.mesh.visible = true;
|
||||
entry.sprite.visible = false;
|
||||
} else {
|
||||
// Far: billboard sprite
|
||||
entry.mesh.visible = false;
|
||||
entry.sprite.visible = true;
|
||||
entry.sprite.position.copy(meshPos);
|
||||
entry.sprite.position.y += 1.2; // above avatar center
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
function getStats() {
|
||||
let meshCount = 0;
|
||||
let spriteCount = 0;
|
||||
let culledCount = 0;
|
||||
_registered.forEach(entry => {
|
||||
if (entry.mesh.visible) meshCount++;
|
||||
else if (entry.sprite.visible) spriteCount++;
|
||||
else culledCount++;
|
||||
});
|
||||
return { total: _registered.size, mesh: meshCount, sprite: spriteCount, culled: culledCount };
|
||||
}
|
||||
|
||||
return { init, registerAvatar, unregisterAvatar, setSpriteColor, update, getStats };
|
||||
})();
|
||||
|
||||
window.LODSystem = LODSystem;
|
||||
@@ -1,7 +1,10 @@
|
||||
#!/usr/bin/env python3
|
||||
"""
|
||||
Review Gate — Poka-yoke for unreviewed merges.
|
||||
Fails if the current PR has fewer than 1 approving review.
|
||||
Review Gate — Poka-yoke for unreviewed merges and zombie PRs.
|
||||
|
||||
Checks:
|
||||
1. PR has at least 1 approving review (no rubber-stamping without approval)
|
||||
2. PR has actual changes (no zombie PRs with 0 additions/deletions)
|
||||
|
||||
Usage in Gitea workflow:
|
||||
- name: Review Approval Gate
|
||||
@@ -13,7 +16,6 @@ Usage in Gitea workflow:
|
||||
import os
|
||||
import sys
|
||||
import json
|
||||
import subprocess
|
||||
from urllib import request, error
|
||||
|
||||
GITEA_TOKEN = os.environ.get("GITEA_TOKEN", "")
|
||||
@@ -33,7 +35,68 @@ def api_call(method, path):
|
||||
return {"error": e.read().decode(), "status": e.code}
|
||||
|
||||
|
||||
def check_empty_pr(pr_data):
|
||||
"""Check if PR has no actual changes (zombie PR)."""
|
||||
additions = pr_data.get("additions", 0)
|
||||
deletions = pr_data.get("deletions", 0)
|
||||
changed_files = pr_data.get("changed_files", 0)
|
||||
|
||||
if additions == 0 and deletions == 0 and changed_files == 0:
|
||||
return False, (
|
||||
f"ZOMBIE PR: PR has 0 additions, 0 deletions, 0 changed files. "
|
||||
f"This appears to be an empty PR with no actual changes."
|
||||
)
|
||||
return True, None
|
||||
|
||||
|
||||
def check_approvals(reviews):
|
||||
"""Check if PR has at least one approving review."""
|
||||
approvals = [r for r in reviews if r.get("state") == "APPROVED"]
|
||||
if len(approvals) >= 1:
|
||||
return True, len(approvals)
|
||||
return False, 0
|
||||
|
||||
|
||||
def check_rubber_stamp(pr_data, reviews):
|
||||
"""
|
||||
Check for rubber-stamping: approving reviews on PRs with trivial changes.
|
||||
|
||||
Rubber-stamping indicators:
|
||||
- Approving reviews exist
|
||||
- PR has very few changes (< 5 lines total)
|
||||
- Review comments are empty or generic
|
||||
"""
|
||||
approvals = [r for r in reviews if r.get("state") == "APPROVED"]
|
||||
if not approvals:
|
||||
return True, None # No approvals to check
|
||||
|
||||
additions = pr_data.get("additions", 0)
|
||||
deletions = pr_data.get("deletions", 0)
|
||||
total_changes = additions + deletions
|
||||
|
||||
# Flag if approving a PR with fewer than 5 total changes
|
||||
if total_changes < 5 and len(approvals) > 0:
|
||||
# Check if review bodies are substantive
|
||||
empty_reviews = [
|
||||
r for r in approvals
|
||||
if not r.get("body") or len(r.get("body", "").strip()) < 10
|
||||
]
|
||||
if empty_reviews:
|
||||
return False, (
|
||||
f"SUSPICIOUS: PR has only {total_changes} total changes "
|
||||
f"but {len(approvals)} approving review(s), "
|
||||
f"{len(empty_reviews)} with empty/minimal comments. "
|
||||
f"This may indicate rubber-stamping."
|
||||
)
|
||||
|
||||
return True, None
|
||||
|
||||
|
||||
def main():
|
||||
errors = []
|
||||
warnings = []
|
||||
|
||||
# Validate environment
|
||||
if not GITEA_TOKEN:
|
||||
print("ERROR: GITEA_TOKEN not set")
|
||||
sys.exit(1)
|
||||
@@ -44,27 +107,57 @@ def main():
|
||||
|
||||
pr_number = PR_NUMBER
|
||||
if not pr_number:
|
||||
# Try to infer from Gitea Actions environment
|
||||
pr_number = os.environ.get("GITEA_PULL_REQUEST_INDEX", "")
|
||||
|
||||
if not pr_number:
|
||||
print("ERROR: Could not determine PR number")
|
||||
sys.exit(1)
|
||||
|
||||
# Fetch PR data
|
||||
pr_data = api_call("GET", f"/repos/{REPO}/pulls/{pr_number}")
|
||||
if isinstance(pr_data, dict) and "error" in pr_data:
|
||||
print(f"ERROR fetching PR: {pr_data}")
|
||||
sys.exit(1)
|
||||
|
||||
# Fetch reviews
|
||||
reviews = api_call("GET", f"/repos/{REPO}/pulls/{pr_number}/reviews")
|
||||
if isinstance(reviews, dict) and "error" in reviews:
|
||||
print(f"ERROR fetching reviews: {reviews}")
|
||||
sys.exit(1)
|
||||
|
||||
approvals = [r for r in reviews if r.get("state") == "APPROVED"]
|
||||
if len(approvals) >= 1:
|
||||
print(f"OK: PR #{pr_number} has {len(approvals)} approving review(s).")
|
||||
sys.exit(0)
|
||||
else:
|
||||
print(f"BLOCKED: PR #{pr_number} has no approving reviews.")
|
||||
print("Merges are not permitted without at least one approval.")
|
||||
# ── Check 1: Empty PR (zombie PR) ───────────────────────
|
||||
has_changes, empty_msg = check_empty_pr(pr_data)
|
||||
if not has_changes:
|
||||
errors.append(empty_msg)
|
||||
|
||||
# ── Check 2: Has approvals ──────────────────────────────
|
||||
has_approval, approval_count = check_approvals(reviews)
|
||||
if not has_approval:
|
||||
errors.append(
|
||||
f"PR #{pr_number} has no approving reviews. "
|
||||
f"Merges require at least one approval."
|
||||
)
|
||||
|
||||
# ── Check 3: Rubber-stamping detection ──────────────────
|
||||
clean, rubber_msg = check_rubber_stamp(pr_data, reviews)
|
||||
if not clean:
|
||||
warnings.append(rubber_msg)
|
||||
|
||||
# ── Report ──────────────────────────────────────────────
|
||||
if warnings:
|
||||
for w in warnings:
|
||||
print(f"⚠️ WARNING: {w}")
|
||||
|
||||
if errors:
|
||||
for e in errors:
|
||||
print(f"❌ BLOCKED: {e}")
|
||||
sys.exit(1)
|
||||
|
||||
print(f"✅ OK: PR #{pr_number} has {approval_count} approval(s) "
|
||||
f"and {pr_data.get('additions', 0)} additions / "
|
||||
f"{pr_data.get('deletions', 0)} deletions.")
|
||||
sys.exit(0)
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
|
||||
109
tests/test_review_gate.py
Normal file
109
tests/test_review_gate.py
Normal file
@@ -0,0 +1,109 @@
|
||||
"""
|
||||
Tests for scripts/review_gate.py — Anti-rubber-stamping PR validation.
|
||||
"""
|
||||
|
||||
import unittest
|
||||
import sys
|
||||
from pathlib import Path
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).parent.parent / "scripts"))
|
||||
from review_gate import check_empty_pr, check_approvals, check_rubber_stamp
|
||||
|
||||
|
||||
class TestCheckEmptyPr(unittest.TestCase):
|
||||
def test_valid_pr(self):
|
||||
pr = {"additions": 10, "deletions": 5, "changed_files": 2}
|
||||
ok, msg = check_empty_pr(pr)
|
||||
self.assertTrue(ok)
|
||||
self.assertIsNone(msg)
|
||||
|
||||
def test_empty_pr(self):
|
||||
pr = {"additions": 0, "deletions": 0, "changed_files": 0}
|
||||
ok, msg = check_empty_pr(pr)
|
||||
self.assertFalse(ok)
|
||||
self.assertIn("ZOMBIE", msg)
|
||||
|
||||
def test_additions_only(self):
|
||||
pr = {"additions": 50, "deletions": 0, "changed_files": 1}
|
||||
ok, msg = check_empty_pr(pr)
|
||||
self.assertTrue(ok)
|
||||
|
||||
def test_deletions_only(self):
|
||||
pr = {"additions": 0, "deletions": 30, "changed_files": 1}
|
||||
ok, msg = check_empty_pr(pr)
|
||||
self.assertTrue(ok)
|
||||
|
||||
def test_missing_fields_treated_as_zero(self):
|
||||
pr = {}
|
||||
ok, msg = check_empty_pr(pr)
|
||||
self.assertFalse(ok)
|
||||
|
||||
|
||||
class TestCheckApprovals(unittest.TestCase):
|
||||
def test_has_approval(self):
|
||||
reviews = [{"state": "APPROVED"}, {"state": "COMMENT"}]
|
||||
ok, count = check_approvals(reviews)
|
||||
self.assertTrue(ok)
|
||||
self.assertEqual(count, 1)
|
||||
|
||||
def test_multiple_approvals(self):
|
||||
reviews = [{"state": "APPROVED"}, {"state": "APPROVED"}]
|
||||
ok, count = check_approvals(reviews)
|
||||
self.assertTrue(ok)
|
||||
self.assertEqual(count, 2)
|
||||
|
||||
def test_no_approvals(self):
|
||||
reviews = [{"state": "COMMENT"}, {"state": "REQUEST_CHANGES"}]
|
||||
ok, count = check_approvals(reviews)
|
||||
self.assertFalse(ok)
|
||||
self.assertEqual(count, 0)
|
||||
|
||||
def test_empty_reviews(self):
|
||||
ok, count = check_approvals([])
|
||||
self.assertFalse(ok)
|
||||
self.assertEqual(count, 0)
|
||||
|
||||
|
||||
class TestCheckRubberStamp(unittest.TestCase):
|
||||
def test_substantive_pr_no_warning(self):
|
||||
pr = {"additions": 100, "deletions": 50}
|
||||
reviews = [{"state": "APPROVED", "body": "Looks good, nice changes"}]
|
||||
ok, msg = check_rubber_stamp(pr, reviews)
|
||||
self.assertTrue(ok)
|
||||
self.assertIsNone(msg)
|
||||
|
||||
def test_trivial_pr_empty_review_detected(self):
|
||||
pr = {"additions": 2, "deletions": 0}
|
||||
reviews = [{"state": "APPROVED", "body": ""}]
|
||||
ok, msg = check_rubber_stamp(pr, reviews)
|
||||
self.assertFalse(ok)
|
||||
self.assertIn("SUSPICIOUS", msg)
|
||||
|
||||
def test_trivial_pr_short_review_detected(self):
|
||||
pr = {"additions": 1, "deletions": 1}
|
||||
reviews = [{"state": "APPROVED", "body": "ok"}]
|
||||
ok, msg = check_rubber_stamp(pr, reviews)
|
||||
self.assertFalse(ok)
|
||||
self.assertIn("SUSPICIOUS", msg)
|
||||
|
||||
def test_trivial_pr_substantive_review_ok(self):
|
||||
pr = {"additions": 2, "deletions": 0}
|
||||
reviews = [{"state": "APPROVED", "body": "This small fix is correct. Tested locally."}]
|
||||
ok, msg = check_rubber_stamp(pr, reviews)
|
||||
self.assertTrue(ok)
|
||||
|
||||
def test_no_approvals_skips_check(self):
|
||||
pr = {"additions": 0, "deletions": 0}
|
||||
reviews = [{"state": "COMMENT"}]
|
||||
ok, msg = check_rubber_stamp(pr, reviews)
|
||||
self.assertTrue(ok)
|
||||
|
||||
def test_large_pr_with_empty_review_ok(self):
|
||||
pr = {"additions": 500, "deletions": 200}
|
||||
reviews = [{"state": "APPROVED", "body": ""}]
|
||||
ok, msg = check_rubber_stamp(pr, reviews)
|
||||
self.assertTrue(ok) # Large PR, empty review is less suspicious
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
unittest.main()
|
||||
Reference in New Issue
Block a user