Repository navigation
feat: migrate textindex service into deepin-anything - #263
Johnson-zs merged 1 commit into
Conversation
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: Johnson-zs The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
552c564 to
fb0a3fa
Compare
deepin pr auto reviewAI 代码审查报告
总体评价
本次 PR 将 dde-file-manager 的 textindex 索引服务与 extractor 迁入 deepin-anything 仓库,作为 user 级 systemd 服务 deepin-anything-index 及其私有子进程 deepin-anything-extractor 运行。代码为 1:1 平移,质量较高,结构清晰,错误处理完善,线程安全措施到位。存在 2 个低危安全漏洞(MD5 哈希用于文件去重、环境变量覆盖提取器路径),均不影响核心安全性。 漏洞统计
漏洞对比统计:新增漏洞 2 个,减少漏洞 0 个,持平 0 个 四维度评分
维度1:语法逻辑(23/25 ✓)
审查内容: 本次 PR 新增 124 个源代码文件(src/ 目录),涵盖 C++ 实现文件和头文件。代码整体语法正确,逻辑清晰,无编译错误。 优点:
问题:
维度2:代码质量(21/25 ✓)
审查内容: 代码组织为清晰的模块结构:src/index(索引服务)、src/extractor(内容提取器)、src/common(共享工具)。文件命名规范,头文件保护宏完整,SPDX 许可证头齐全。 优点:
问题:
维度3:代码性能(18/20 ✓)
审查内容: 代码在性能方面设计合理,采用了多种优化策略。 优点:
问题:
维度4:代码安全(26/30 ✓)
安全漏洞1:MD5 不安全哈希算法用于文件去重(低危)
// 修复前
QCryptographicHash hash(QCryptographicHash::Md5);
// 修复后
QCryptographicHash hash(QCryptographicHash::Sha256);——非常重要 安全漏洞2:环境变量覆盖提取器可执行文件路径(低危)
代码目的匹配度本次 PR 的 commit message 明确表明目的是"将 dde-file-manager 的 textindex 索引服务与 extractor 迁入 deepin-anything 仓库"。审查结论:
代码实现与 commit message 描述的目的完全一致。 改进建议// 1. 使用 SHA-256 替代 MD5(filehash.cpp)
QString computeSha256(const QString &filePath)
{
QFile file(filePath);
if (!file.open(QIODevice::ReadOnly)) {
return {};
}
QCryptographicHash hash(QCryptographicHash::Sha256); // 使用 SHA-256
// 分块读取,避免大文件内存峰值
const qint64 chunkSize = 64 * 1024; // 64KB
while (!file.atEnd()) {
if (!hash.addData(&file, chunkSize)) {
return {};
}
}
return QString::fromLatin1(hash.result().toHex());
}
// 2. 生产构建中禁用环境变量覆盖(processextractor.cpp)
QString extractorToolPath()
{
#ifndef QT_DEBUG
// 生产环境直接使用编译时路径,不接受环境变量覆盖
return QString::fromLatin1(ANYTHING_EXTRACTOR_TOOL);
#else
const QString fromEnv = qEnvironmentVariable("ANYTHING_EXTRACTOR_TOOL");
if (!fromEnv.isEmpty())
return fromEnv;
return QString::fromLatin1(ANYTHING_EXTRACTOR_TOOL);
#endif
}
// 3. 记录异常信息而非静默吞没
try {
// ... Lucene 操作 ...
} catch (const LuceneException &e) {
qWarning() << "ContentDeduplication: Lucene error:" << QString::fromStdWString(e.getError());
return {};
} catch (const std::exception &e) {
qWarning() << "ContentDeduplication: std error:" << e.what();
return {};
}审查清单
|
Move dde-file-manager's textindex service and extractor app into this
repo as the user-level systemd service deepin-anything-index and its
private subprocess deepin-anything-extractor (Phase 1 of the migration
design, docs/design/textindex-migration.md).
- src/index: 1:1 port of src/services/textindex; plugin.cpp rewritten
as main() entry (serviceentry.{h,cpp}); interface XMLs moved here as
the single source of truth; new Type=dbus user unit + activation file
- src/extractor: 1:1 port of dde-file-manager-extractor; comm library
installed to standard libdir, plugins to deepin-anything/extractor
- src/common: ProcessPriorityManager (only shared piece)
- Drop all dfm-base dependencies: bare qDebug logging, direct Dtk6
DConfig access, no LoggerRules/categories
- Rename per naming table: anything_index/deepin_anything_extractor/
anything_extractor_plugin namespaces, new plugin IID, kIndexSystemd-
UnitName, ANYTHING_EXTRACTOR_TOOL (+ env override for debugging),
pinyin dict at /usr/share/deepin-anything-index
- Frozen contracts untouched: D-Bus names/paths/interfaces, dconfig
schema, index data dirs, index versions 6/3/1
- autotests/index: white-box ut-anything-index (63 files, 1101 cases,
all passing), OPT_ENABLE_BUILD_UT gate, run-ut.sh with lcov coverage
- debian: new deepin-anything-index package (Architecture: any,
Replaces: dde-file-manager << 6.6.7) + Build-Depends refresh
将 dde-file-manager 的 textindex 服务与 extractor 迁入本仓库,成为
user 级 systemd 服务 deepin-anything-index 及其私有子进程
deepin-anything-extractor(迁移设计阶段一,详见设计文档)。
- src/index 平移 textindex;plugin.cpp 重写为 main 入口;接口 XML
迁入作为唯一来源;新增 Type=dbus 用户单元与 activation 文件
- src/extractor 平移 extractor;通信库装标准 libdir,插件装新目录
- 去 dfm-base 依赖:裸 qDebug 日志、Dtk6 DConfig 直连、删类别体系
- 按命名定稿表完成更名;冻结契约(D-Bus 名/路径/接口、dconfig、
索引目录、索引版本 6/3/1)一字未动
- 根级 autotests/index 白盒测试 1101 用例全过;run-ut.sh 一键跑 +
lcov 覆盖率报告
- debian 新增 deepin-anything-index 包(any 架构,Replaces 接管)并
恢复/新增构建依赖
Log: textindex 索引服务与 extractor 迁入 deepin-anything
fb0a3fa to
99dce48
Compare
421543c
into
linuxdeepin:develop/snipe-20260923
Move dde-file-manager's textindex service and extractor app into this repo as the user-level systemd service deepin-anything-index and its private subprocess deepin-anything-extractor (Phase 1 of the migration design, docs/design/textindex-migration.md).
将 dde-file-manager 的 textindex 服务与 extractor 迁入本仓库,成为 user 级 systemd 服务 deepin-anything-index 及其私有子进程
deepin-anything-extractor(迁移设计阶段一,详见设计文档)。
Log: textindex 索引服务与 extractor 迁入 deepin-anything