name: OpenCode Gitea Integration on: issues: types: [opened] issue_comment: types: [created] pull_request_review_comment: types: [created] workflow_dispatch: inputs: prompt: description: "Istruzione manuale per OpenCode" required: true jobs: opencode-gitea: if: | github.event_name == 'workflow_dispatch' || (github.event_name == 'issues' && (contains(github.event.issue.body, '/oc') || contains(github.event.issue.body, '/opencode'))) || (github.event_name != 'issues' && github.event.comment.user.login != 'opencode-bot' && (contains(github.event.comment.body, '/oc') || contains(github.event.comment.body, '/opencode'))) runs-on: ubuntu-latest timeout-minutes: 40 env: GITEA_API_URL: "https://gitea.maribit.it" GITEA_TOKEN: ${{ secrets.BOT_GITEA_TOKEN }} REPO_FULL_NAME: ${{ github.repository }} COMMENT_BODY: ${{ github.event.comment.body || github.event.issue.body || github.event.inputs.prompt }} COMMENT_AUTHOR: ${{ github.event.comment.user.login || github.event.issue.user.login || github.actor }} COMMENT_ID: ${{ github.event.comment.id }} IS_PR_EVENT: ${{ github.event_name == 'pull_request_review_comment' }} IS_MANUAL: ${{ github.event_name == 'workflow_dispatch' }} PR_NUMBER_FROM_EVENT: ${{ github.event.pull_request.number }} PR_HEAD_REF_FROM_EVENT: ${{ github.event.pull_request.head.ref }} ISSUE_NUMBER: ${{ github.event.issue.number }} ISSUE_TITLE: ${{ github.event.issue.title }} ISSUE_BODY: ${{ github.event.issue.body }} RUN_NUMBER: ${{ github.run_number }} # --- OpenCode --- OPENCODE_ZEN_API_KEY: ${{ secrets.OPENCODE_ZEN_API_KEY }} OPENCODE_API_BASE: https://opencode.ai OPENCODE_MODEL: opencode/big-pickle MAX_ITERATIONS: "4" steps: - name: Verifica autorizzazione utente run: | ALLOWED_USERS="maria nicola" if [ "$IS_MANUAL" = "true" ]; then exit 0 fi if ! echo " $ALLOWED_USERS " | grep -q " $COMMENT_AUTHOR "; then echo "Utente '$COMMENT_AUTHOR' non autorizzato a invocare OpenCode. Interrompo." exit 1 fi # Feedback immediato: 👀 sul commento (o sulla issue). Le reazioni NON generano # eventi issue_comment -> nessun doppio run. - name: Reagisci al comando (👀) id: react run: | API="$GITEA_API_URL/api/v1/repos/$REPO_FULL_NAME" if [ -n "$COMMENT_ID" ]; then RPATH="issues/comments/$COMMENT_ID/reactions" elif [ -n "$ISSUE_NUMBER" ]; then RPATH="issues/$ISSUE_NUMBER/reactions" else RPATH="" fi echo "path=$RPATH" >> "$GITHUB_OUTPUT" if [ -n "$RPATH" ]; then curl -s -X POST "$API/$RPATH" \ -H "Authorization: token $GITEA_TOKEN" \ -H "Content-Type: application/json" \ -d '{"content":"eyes"}' >/dev/null || true fi - name: Checkout repository uses: actions/checkout@v4 with: fetch-depth: 0 - name: Install OpenCode CLI run: | curl -fsSL https://opencode.ai/install | bash echo "$HOME/.opencode/bin" >> "$GITHUB_PATH" # Agent "reviewer" read-only: legge ed esegue i test (bash), MAI edita. # Creato solo nel runner ed escluso dai commit, così non sporca il repo. - name: Configura agent reviewer (read-only) run: | mkdir -p .opencode/agents cat > .opencode/agents/reviewer.md <<'EOF' --- description: Revisore read-only che verifica gli acceptance criteria eseguendo i test, senza modificare il codice. mode: primary permission: edit: deny webfetch: deny bash: allow tools: write: false edit: false bash: true --- Sei un revisore di codice rigoroso in SOLA LETTURA. Non modificare mai i file: puoi solo leggere il codice ed eseguire comandi di verifica (build, lint, test). Stabilisci se ogni Acceptance Criterion del piano è oggettivamente soddisfatto sul codice attuale. EOF grep -qxF '.opencode/' .git/info/exclude 2>/dev/null || echo '.opencode/' >> .git/info/exclude - name: Determina contesto (issue / PR / manuale) e branch di lavoro id: ctx run: | set -e git config --global user.name "OpenCode Bot" git config --global user.email "opencode-bot@maribit.it" API="$GITEA_API_URL/api/v1/repos/$REPO_FULL_NAME" if [ "$IS_MANUAL" = "true" ]; then IS_PR=false PR_NUMBER="" BRANCH_NAME="opencode-manual-$RUN_NUMBER" elif [ "$IS_PR_EVENT" = "true" ]; then IS_PR=true PR_NUMBER="$PR_NUMBER_FROM_EVENT" BRANCH_NAME="$PR_HEAD_REF_FROM_EVENT" else ISSUE_JSON=$(curl -s -H "Authorization: token $GITEA_TOKEN" "$API/issues/$ISSUE_NUMBER") if [ "$(echo "$ISSUE_JSON" | jq -r '.pull_request // empty')" != "" ]; then IS_PR=true PR_NUMBER="$ISSUE_NUMBER" PR_JSON=$(curl -s -H "Authorization: token $GITEA_TOKEN" "$API/pulls/$PR_NUMBER") BRANCH_NAME=$(echo "$PR_JSON" | jq -r '.head.ref') else IS_PR=false PR_NUMBER="" BRANCH_NAME="opencode-issue-$ISSUE_NUMBER" fi fi if [ -z "$BRANCH_NAME" ] || [ "$BRANCH_NAME" = "null" ]; then echo "BRANCH_NAME non valido ('$BRANCH_NAME'). Interrompo." exit 1 fi # Chiave univoca per il file di piano (branch con '/' -> '-'). PLAN_KEY=$(printf '%s' "$BRANCH_NAME" | tr '/' '-') echo "is_pr=$IS_PR" >> "$GITHUB_OUTPUT" echo "pr_number=$PR_NUMBER" >> "$GITHUB_OUTPUT" echo "branch_name=$BRANCH_NAME" >> "$GITHUB_OUTPUT" echo "plan_key=$PLAN_KEY" >> "$GITHUB_OUTPUT" if [ "$IS_PR" = "true" ]; then git fetch origin "$BRANCH_NAME" git checkout -B "$BRANCH_NAME" "origin/$BRANCH_NAME" elif git ls-remote --exit-code --heads origin "$BRANCH_NAME" >/dev/null 2>&1; then git fetch origin "$BRANCH_NAME" git checkout -B "$BRANCH_NAME" "origin/$BRANCH_NAME" else git checkout -b "$BRANCH_NAME" fi - name: Raccogli contesto aggiuntivo (diff + commenti, se PR) run: | API="$GITEA_API_URL/api/v1/repos/$REPO_FULL_NAME" : > /tmp/context.txt if [ "${{ steps.ctx.outputs.is_pr }}" = "true" ]; then PR_NUMBER="${{ steps.ctx.outputs.pr_number }}" echo "== Diff della PR ==" >> /tmp/context.txt curl -s -H "Authorization: token $GITEA_TOKEN" "$API/pulls/$PR_NUMBER.diff" >> /tmp/context.txt echo "== Commenti recenti ==" >> /tmp/context.txt curl -s -H "Authorization: token $GITEA_TOKEN" "$API/issues/$PR_NUMBER/comments" \ | jq -r '.[] | "- (\(.user.login)): \(.body)"' >> /tmp/context.txt || true fi - name: Pulisci il comando dal trigger run: | CLEAN_PROMPT=$(printf '%s' "$COMMENT_BODY" | sed -e 's|/opencode||g' -e 's|/oc||g') printf '%s' "$CLEAN_PROMPT" > /tmp/clean_prompt.txt - name: "Fase 1 — Plan (analisi read-only)" if: steps.ctx.outputs.is_pr != 'true' run: | CLEAN_PROMPT=$(cat /tmp/clean_prompt.txt) CONTEXT=$(cat /tmp/context.txt 2>/dev/null || true) mkdir -p issue_plans PLAN_FILE="issue_plans/${{ steps.ctx.outputs.plan_key }}.md" opencode run --agent plan --model "$OPENCODE_MODEL" \ "Sei in modalità PLAN (SOLA LETTURA): NON modificare alcun file. Analizza il codebase e la richiesta, poi produci un piano di lavoro in Markdown con questa struttura ESATTA: # Piano ## Obiettivo ## Task (elenco numerato di task atomici; per ciascuno i file coinvolti) ## Acceptance Criteria (checklist '- [ ] ...' di criteri oggettivi e verificabili) ## Verifica (come testare: comandi da lanciare, cosa controllare) Richiesta ($COMMENT_AUTHOR): $CLEAN_PROMPT Contesto: $ISSUE_TITLE - $ISSUE_BODY $CONTEXT Restituisci SOLO il documento Markdown del piano." | tee "$PLAN_FILE" cp "$PLAN_FILE" /tmp/plan.md git add "$PLAN_FILE" git commit -m "OpenCode: piano di lavoro (${{ steps.ctx.outputs.plan_key }})" || echo "Nessun piano da committare." - name: "Fase 2 — Build & Review loop" run: | CLEAN_PROMPT=$(cat /tmp/clean_prompt.txt) CONTEXT=$(cat /tmp/context.txt 2>/dev/null || true) PLAN=""; [ -f /tmp/plan.md ] && PLAN="$(cat /tmp/plan.md)" REVIEW_FEEDBACK="(prima iterazione: nessun feedback)" for i in $(seq 1 "$MAX_ITERATIONS"); do echo "::group::Iterazione $i — BUILD" opencode run --agent build --auto --model "$OPENCODE_MODEL" \ "Sei in modalità BUILD. Implementa il piano completando TUTTI i task e soddisfacendo TUTTI gli Acceptance Criteria. Applica le modifiche ai file. === PIANO === ${PLAN:-Nessun piano formale. Richiesta: $CLEAN_PROMPT} === CONTESTO (diff/commenti PR, se presente) === $CONTEXT === FEEDBACK DELLA REVIEW PRECEDENTE (correggi SOLO questi punti) === $REVIEW_FEEDBACK" echo "::endgroup::" echo "::group::Iterazione $i — REVIEW" opencode run --agent reviewer --auto --model "$OPENCODE_MODEL" \ "Verifica sul codice ATTUALE se OGNI Acceptance Criterion del piano è soddisfatto. Puoi eseguire build/lint/test ma NON modificare i file. === PIANO === ${PLAN:-Richiesta originale: $CLEAN_PROMPT} Scrivi come ULTIMA riga ESATTAMENTE una di queste: - 'VERDICT: PASS' se tutti i criteri sono soddisfatti - 'VERDICT: FAIL' altrimenti, seguita da un elenco puntato dei criteri NON soddisfatti e di cosa manca." | tee /tmp/review.txt echo "::endgroup::" if grep -q 'VERDICT: PASS' /tmp/review.txt; then echo "✅ Acceptance criteria soddisfatti all'iterazione $i." exit 0 fi REVIEW_FEEDBACK="$(cat /tmp/review.txt)" echo "⚠️ Criteri non ancora soddisfatti: procedo con l'iterazione $((i+1))." done echo "Raggiunto il tetto di $MAX_ITERATIONS iterazioni senza PASS completo:" echo "le modifiche parziali verranno comunque pushate per revisione umana." - name: Pusha modifiche e apri/aggiorna la PR id: push run: | API="$GITEA_API_URL/api/v1/repos/$REPO_FULL_NAME" BRANCH_NAME="${{ steps.ctx.outputs.branch_name }}" git add . git commit -m "OpenCode (big-pickle): $BRANCH_NAME" || echo "Niente di nuovo da committare oltre al loop." if git diff --quiet origin/main..HEAD 2>/dev/null; then echo "Nessuna modifica rispetto a main: niente da pushare." echo "pr_number=" >> "$GITHUB_OUTPUT" exit 0 fi git push origin "$BRANCH_NAME" if [ "${{ steps.ctx.outputs.is_pr }}" = "true" ]; then PR_NUMBER="${{ steps.ctx.outputs.pr_number }}" else RESP=$(curl -s -X POST "$API/pulls" \ -H "Authorization: token $GITEA_TOKEN" \ -H "Content-Type: application/json" \ -d "{\"base\":\"main\",\"head\":\"$BRANCH_NAME\",\"title\":\"PR Automatica OpenCode: $BRANCH_NAME\",\"body\":\"Generata da big-pickle su richiesta di @$COMMENT_AUTHOR. Piano: issue_plans/${{ steps.ctx.outputs.plan_key }}.md\"}") PR_NUMBER=$(echo "$RESP" | jq -r '.number // empty') # Se la PR per questo branch esiste già, recuperane il numero. if [ -z "$PR_NUMBER" ]; then PR_NUMBER=$(curl -s -H "Authorization: token $GITEA_TOKEN" "$API/pulls?state=open&limit=50" \ | jq -r --arg b "$BRANCH_NAME" '.[] | select(.head.ref==$b) | .number' | head -n1) fi fi echo "pr_number=$PR_NUMBER" >> "$GITHUB_OUTPUT" # Passo finale: la review dell'agente viene postata come REVIEW sulla PR # (event COMMENT: evita i vincoli sul self-approve del proprio branch). - name: Posta la review sulla PR if: always() continue-on-error: true run: | API="$GITEA_API_URL/api/v1/repos/$REPO_FULL_NAME" PR_NUMBER="${{ steps.push.outputs.pr_number }}" [ -z "$PR_NUMBER" ] && PR_NUMBER="${{ steps.ctx.outputs.pr_number }}" if [ -z "$PR_NUMBER" ] || [ ! -s /tmp/review.txt ]; then echo "Nessuna PR o nessuna review da postare." exit 0 fi # Il verdetto guida lo stato nativo della review. if grep -q 'VERDICT: PASS' /tmp/review.txt; then EVENT="APPROVE" else EVENT="REQUEST_CHANGES" fi BODY=$(jq -Rs . < /tmp/review.txt) # encoding JSON-safe del testo review post_review() { curl -s -o /tmp/review_resp.json -w '%{http_code}' \ -X POST "$API/pulls/$PR_NUMBER/reviews" \ -H "Authorization: token $GITEA_TOKEN" \ -H "Content-Type: application/json" \ -d "{\"body\":$BODY,\"event\":\"$1\"}" } CODE=$(post_review "$EVENT") echo "Review '$EVENT' -> HTTP $CODE" # Gitea rifiuta APPROVE/REQUEST_CHANGES sulla PR di cui il bot è autore: # in quel caso ripiega su un commento di review (event=COMMENT). if [ "$CODE" -ge 300 ]; then echo "Fallback a event=COMMENT (probabile self-review su PR del bot). Risposta:" cat /tmp/review_resp.json 2>/dev/null || true echo CODE=$(post_review "COMMENT") echo "Review 'COMMENT' -> HTTP $CODE" fi - name: Reazione finale 🚀 if: success() && steps.react.outputs.path != '' continue-on-error: true run: | API="$GITEA_API_URL/api/v1/repos/$REPO_FULL_NAME" curl -s -X POST "$API/${{ steps.react.outputs.path }}" \ -H "Authorization: token $GITEA_TOKEN" \ -H "Content-Type: application/json" \ -d '{"content":"rocket"}' >/dev/null || true - name: Reazione in caso di errore 😕 if: failure() && steps.react.outputs.path != '' continue-on-error: true run: | API="$GITEA_API_URL/api/v1/repos/$REPO_FULL_NAME" curl -s -X POST "$API/${{ steps.react.outputs.path }}" \ -H "Authorization: token $GITEA_TOKEN" \ -H "Content-Type: application/json" \ -d '{"content":"confused"}' >/dev/null || true