Skip to content

feat: migrate textindex service into deepin-anything - #263

Merged
Johnson-zs merged 1 commit into
linuxdeepin:develop/snipe-20260923from
Johnson-zs:develop/snipe-20260923
Sep 29, 2026
Merged

Johnson-zs merged 1 commit into
linuxdeepin:develop/snipe-20260923from
Johnson-zs:develop/snipe-20260923

Conversation

@Johnson-zs

Copy link
Copy Markdown

Move dde-file-manager's textindex service and extractor app into this repo as the user-level systemd service deepin-anything-index and its private subprocess deepin-anything-extractor (Phase 1 of the migration design, docs/design/textindex-migration.md).

  • src/index: 1:1 port of src/services/textindex; plugin.cpp rewritten as main() entry (serviceentry.{h,cpp}); interface XMLs moved here as the single source of truth; new Type=dbus user unit + activation file
  • src/extractor: 1:1 port of dde-file-manager-extractor; comm library installed to standard libdir, plugins to deepin-anything/extractor
  • src/common: ProcessPriorityManager (only shared piece)
  • Drop all dfm-base dependencies: bare qDebug logging, direct Dtk6 DConfig access, no LoggerRules/categories
  • Rename per naming table: anything_index/deepin_anything_extractor/ anything_extractor_plugin namespaces, new plugin IID, kIndexSystemd- UnitName, ANYTHING_EXTRACTOR_TOOL (+ env override for debugging), pinyin dict at /usr/share/deepin-anything-index
  • Frozen contracts untouched: D-Bus names/paths/interfaces, dconfig schema, index data dirs, index versions 6/3/1
  • autotests/index: white-box ut-anything-index (63 files, 1101 cases, all passing), OPT_ENABLE_BUILD_UT gate, run-ut.sh with lcov coverage
  • debian: new deepin-anything-index package (Architecture: any, Replaces: dde-file-manager << 6.6.7) + Build-Depends refresh

将 dde-file-manager 的 textindex 服务与 extractor 迁入本仓库,成为 user 级 systemd 服务 deepin-anything-index 及其私有子进程
deepin-anything-extractor(迁移设计阶段一,详见设计文档)。

  • src/index 平移 textindex;plugin.cpp 重写为 main 入口;接口 XML 迁入作为唯一来源;新增 Type=dbus 用户单元与 activation 文件
  • src/extractor 平移 extractor;通信库装标准 libdir,插件装新目录
  • 去 dfm-base 依赖:裸 qDebug 日志、Dtk6 DConfig 直连、删类别体系
  • 按命名定稿表完成更名;冻结契约(D-Bus 名/路径/接口、dconfig、 索引目录、索引版本 6/3/1)一字未动
  • 根级 autotests/index 白盒测试 1101 用例全过;run-ut.sh 一键跑 + lcov 覆盖率报告
  • debian 新增 deepin-anything-index 包(any 架构,Replaces 接管)并 恢复/新增构建依赖

Log: textindex 索引服务与 extractor 迁入 deepin-anything

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry, we are unable to review this pull request

The GitHub API does not allow us to fetch diffs exceeding 20000 lines

@deepin-ci-robot

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: Johnson-zs

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@Johnson-zs
Johnson-zs force-pushed the develop/snipe-20260923 branch 5 times, most recently from 552c564 to fb0a3fa Compare September 29, 2026 06:40
@deepin-ci-robot

Copy link
Copy Markdown

deepin pr auto review

AI 代码审查报告

项目: linuxdeepin/deepin-anything
PR: #263 - feat: migrate textindex service into deepin-anything
作者: Johnson-zs
分支: develop/snipe-20260923 → develop/snipe-20260923
提交: fb0a3fa (1 commit, 241 files, +43278/-26)
审查时间: 2026-09-29


总体评价

项目 结果
总分 88 / 100
等级 良好
风险级别 Low
审查结论 代码审查通过(有轻微建议)

本次 PR 将 dde-file-manager 的 textindex 索引服务与 extractor 迁入 deepin-anything 仓库,作为 user 级 systemd 服务 deepin-anything-index 及其私有子进程 deepin-anything-extractor 运行。代码为 1:1 平移,质量较高,结构清晰,错误处理完善,线程安全措施到位。存在 2 个低危安全漏洞(MD5 哈希用于文件去重、环境变量覆盖提取器路径),均不影响核心安全性。


漏洞统计

类型 数量
当前漏洞总数 2
新增漏洞 2
修复漏洞 0
持平漏洞 0

漏洞对比统计:新增漏洞 2 个,减少漏洞 0 个,持平 0 个


四维度评分

维度 得分 满分 状态 评价词
语法逻辑 23 25 ✓ 语法正确,逻辑清晰
代码质量 21 25 ✓ 代码结构清晰,注释完整
代码性能 18 20 ✓ 性能良好,资源使用合理
代码安全 26 30 ✓ 存在 2 个安全漏洞

维度1:语法逻辑(23/25 ✓)

语法正确,逻辑清晰

审查内容:

本次 PR 新增 124 个源代码文件(src/ 目录),涵盖 C++ 实现文件和头文件。代码整体语法正确,逻辑清晰,无编译错误。

优点:

  • 信号处理(main.cpp)使用 async-signal-safe 的 write() 系统调用,实现正确
  • QSaveFile 原子写入确保状态文件完整性(indexstatestore.cpp)
  • RAII 模式广泛使用(ScopeGuard、QSharedPointer、Qt 父子对象所有权)
  • 线程安全通过 QMutex、QAtomicInteger 和 std::mutex 正确保证
  • 边界条件处理完善(空路径检查、null 检查、范围验证)
  • QProcess 生命周期管理正确(start → waitForStarted → finished → deleteLater)
  • ControllerPipe 的消息帧解析正确处理了部分消息和大小验证

问题:

  1. 多处 catch(...) 块静默吞没异常,未记录日志(contentdeduplication.cpp:5559, ocrdeduplication.cpp:5701, taskhandler.cpp 多处, indextask.cpp:13593 等),可能隐藏潜在 bug(-2 分)

维度2:代码质量(21/25 ✓)

代码结构清晰,注释完整

审查内容:

代码组织为清晰的模块结构:src/index(索引服务)、src/extractor(内容提取器)、src/common(共享工具)。文件命名规范,头文件保护宏完整,SPDX 许可证头齐全。

优点:

  • SPDX 许可证头覆盖所有源文件
  • 清晰的模块划分和命名空间隔离(anything_index、deepin_anything_extractor、anything_extractor_plugin)
  • 函数文档注释完整(filehash.h、pluginloader.h、pathexcludematcher.h 等)
  • 配置值全部进行范围验证(textindexconfig.cpp loadAllConfigs())
  • D-Bus 接口 XML 文件作为唯一来源维护
  • 1101 个白盒测试用例覆盖全面

问题:

  1. taskhandler.cpp 达 1471 行,函数过长,建议拆分为更小的处理单元(-2 分)
  2. 注释语言混用(中英文混合),如 systemdcpuutils.cpp 中注释为中文而 ocrextractor.cpp 为英文,建议统一(-2 分)

维度3:代码性能(18/20 ✓)

性能良好,资源使用合理

审查内容:

代码在性能方面设计合理,采用了多种优化策略。

优点:

  • ProcessExtractorProxy 使用空闲超时机制(60秒),避免长时间持有提取器进程
  • VFS 监控使用 recvmmsg 批量接收事件,减少系统调用开销
  • CPU 配额管理使用引用计数(g_limitedTaskCount),避免重复设置
  • 配置值通过单例模式缓存,带 mutex 保护并发读取
  • 文件系统监控使用 inotify + VFS 双通道,覆盖挂载点
  • 索引任务支持批量提交(batchCommitInterval),减少 I/O 开销
  • 事件收集器限制单次处理事件数(kMaxEventsPerDrain=2048),防止事件饥饿

问题:

  1. FileHash::computeMd5() 使用 hash.addData(&file) 一次性读取整个文件,大文件场景下可能导致内存峰值(-1 分)
  2. PathExcludeMatcher::shouldExclude() 线性遍历所有模式,模式较多时可考虑使用前缀树优化(-1 分)

维度4:代码安全(26/30 ✓)

存在 2 个安全漏洞

安全漏洞1:MD5 不安全哈希算法用于文件去重(低危)

  • 文件: src/index/utils/filehash.cpp:11-20
  • 函数: FileHash::computeMd5()
  • 描述: 使用 QCryptographicHash::Md5 计算文件内容哈希,用于内容去重。MD5 已被证明存在碰撞漏洞,不属于安全哈希算法。虽然此处用于文件去重而非密码学安全场景,碰撞风险对去重功能影响较小,但仍建议使用更安全的哈希算法。
  • 建议: 将 QCryptographicHash::Md5 替换为 QCryptographicHash::Sha256,提高碰撞抵抗力
  • 修复示例:
// 修复前
QCryptographicHash hash(QCryptographicHash::Md5);

// 修复后
QCryptographicHash hash(QCryptographicHash::Sha256);

——非常重要

安全漏洞2:环境变量覆盖提取器可执行文件路径(低危)

  • 文件: src/index/extractor/processextractor.cpp:33-35
  • 函数: extractorToolPath()
  • 描述: ANYTHING_EXTRACTOR_TOOL 环境变量可覆盖提取器可执行文件路径。若攻击者能控制环境变量,可执行任意二进制文件。虽然该功能文档标注为调试用途,且服务运行在用户级别(非特权),但在共享环境或被注入环境变量的场景下存在风险。
  • 建议: 在生产构建中移除环境变量覆盖逻辑,或增加路径白名单校验(仅允许指定目录下的可执行文件)
    ——非常重要

代码目的匹配度

本次 PR 的 commit message 明确表明目的是"将 dde-file-manager 的 textindex 索引服务与 extractor 迁入 deepin-anything 仓库"。审查结论:

  1. 迁移完整性: src/index 平移了 textindex 服务,src/extractor 平移了 extractor 应用,src/common 提取了共享的 ProcessPriorityManager ——符合迁移目的
  2. 去依赖化: 成功移除 dfm-base 依赖,使用裸 qDebug 日志和 Dtk6 DConfig 直连——符合设计目标
  3. 冻结契约: D-Bus 名称/路径/接口、dconfig schema、索引目录、索引版本 6/3/1 保持不变——符合冻结要求
  4. 测试覆盖: 1101 个白盒测试用例全部通过——迁移质量验证到位
  5. 打包配置: 新增 deepin-anything-index 包,正确设置 Replaces: dde-file-manager << 6.6.7——迁移接管正确

代码实现与 commit message 描述的目的完全一致。


改进建议

// 1. 使用 SHA-256 替代 MD5(filehash.cpp)
QString computeSha256(const QString &filePath)
{
    QFile file(filePath);
    if (!file.open(QIODevice::ReadOnly)) {
        return {};
    }

    QCryptographicHash hash(QCryptographicHash::Sha256);  // 使用 SHA-256
    // 分块读取,避免大文件内存峰值
    const qint64 chunkSize = 64 * 1024;  // 64KB
    while (!file.atEnd()) {
        if (!hash.addData(&file, chunkSize)) {
            return {};
        }
    }

    return QString::fromLatin1(hash.result().toHex());
}

// 2. 生产构建中禁用环境变量覆盖(processextractor.cpp)
QString extractorToolPath()
{
#ifndef QT_DEBUG
    // 生产环境直接使用编译时路径,不接受环境变量覆盖
    return QString::fromLatin1(ANYTHING_EXTRACTOR_TOOL);
#else
    const QString fromEnv = qEnvironmentVariable("ANYTHING_EXTRACTOR_TOOL");
    if (!fromEnv.isEmpty())
        return fromEnv;
    return QString::fromLatin1(ANYTHING_EXTRACTOR_TOOL);
#endif
}

// 3. 记录异常信息而非静默吞没
try {
    // ... Lucene 操作 ...
} catch (const LuceneException &e) {
    qWarning() << "ContentDeduplication: Lucene error:" << QString::fromStdWString(e.getError());
    return {};
} catch (const std::exception &e) {
    qWarning() << "ContentDeduplication: std error:" << e.what();
    return {};
}

审查清单

  • 已按四维度标准完成代码分析(语法逻辑、代码质量、代码性能、代码安全)
  • 代码安全维度第一行包含"存在 2 个安全漏洞"
  • 安全漏洞已按等级分类(低危)
  • 安全漏洞逐条编号,每条以"——非常重要"结尾
  • 包含漏洞对比统计行(新增/减少/持平)
  • 每个维度标记✓/✕与评价词一致
  • 审查结论考虑了 commit message 的目的
  • 问题定位准确,行号和函数名正确

Move dde-file-manager's textindex service and extractor app into this
repo as the user-level systemd service deepin-anything-index and its
private subprocess deepin-anything-extractor (Phase 1 of the migration
design, docs/design/textindex-migration.md).

- src/index: 1:1 port of src/services/textindex; plugin.cpp rewritten
  as main() entry (serviceentry.{h,cpp}); interface XMLs moved here as
  the single source of truth; new Type=dbus user unit + activation file
- src/extractor: 1:1 port of dde-file-manager-extractor; comm library
  installed to standard libdir, plugins to deepin-anything/extractor
- src/common: ProcessPriorityManager (only shared piece)
- Drop all dfm-base dependencies: bare qDebug logging, direct Dtk6
  DConfig access, no LoggerRules/categories
- Rename per naming table: anything_index/deepin_anything_extractor/
  anything_extractor_plugin namespaces, new plugin IID, kIndexSystemd-
  UnitName, ANYTHING_EXTRACTOR_TOOL (+ env override for debugging),
  pinyin dict at /usr/share/deepin-anything-index
- Frozen contracts untouched: D-Bus names/paths/interfaces, dconfig
  schema, index data dirs, index versions 6/3/1
- autotests/index: white-box ut-anything-index (63 files, 1101 cases,
  all passing), OPT_ENABLE_BUILD_UT gate, run-ut.sh with lcov coverage
- debian: new deepin-anything-index package (Architecture: any,
  Replaces: dde-file-manager << 6.6.7) + Build-Depends refresh

将 dde-file-manager 的 textindex 服务与 extractor 迁入本仓库,成为
user 级 systemd 服务 deepin-anything-index 及其私有子进程
deepin-anything-extractor(迁移设计阶段一,详见设计文档)。

- src/index 平移 textindex;plugin.cpp 重写为 main 入口;接口 XML
  迁入作为唯一来源;新增 Type=dbus 用户单元与 activation 文件
- src/extractor 平移 extractor;通信库装标准 libdir,插件装新目录
- 去 dfm-base 依赖:裸 qDebug 日志、Dtk6 DConfig 直连、删类别体系
- 按命名定稿表完成更名;冻结契约(D-Bus 名/路径/接口、dconfig、
  索引目录、索引版本 6/3/1)一字未动
- 根级 autotests/index 白盒测试 1101 用例全过;run-ut.sh 一键跑 +
  lcov 覆盖率报告
- debian 新增 deepin-anything-index 包(any 架构,Replaces 接管)并
  恢复/新增构建依赖

Log: textindex 索引服务与 extractor 迁入 deepin-anything
@Johnson-zs
Johnson-zs force-pushed the develop/snipe-20260923 branch from fb0a3fa to 99dce48 Compare September 29, 2026 07:12
@Johnson-zs
Johnson-zs merged commit 421543c into linuxdeepin:develop/snipe-20260923 Sep 29, 2026
16 of 17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants