Skip to content

pruefbyte local, embedded OCR and installable releases - #3

Merged
testudor merged 4 commits into
mainfrom
feat/local-review
Oct 7, 2026
Merged

testudor merged 4 commits into
mainfrom
feat/local-review

Conversation

@testudor

@testudor testudor commented Oct 6, 2026

Copy link
Copy Markdown
Collaborator

Summary

pruefbyte local: run the CI review before pushing

  • Reviews the current branch the way the CI job reviews its merge request, and prints the findings instead of posting them.
  • It covers commits plus staged, unstaged and untracked changes; --committed limits it to commits. It reads them from a snapshot commit built with a throwaway index, so the user's index, branch and files are untouched.
  • Uses the same code as CI for:
    • loading config: .pruefbyte.yml and OCR rule files at the merge base
    • merging rules
    • OCR options
    • severity filtering
    • the fail_on_severity exit code (3)
  • A test runs one branch through both paths and checks that OCR gets identical arguments, rules and provider settings.
  • The API key is the first one found of:
    • PRUEFBYTE_LLM_API_KEY
    • the developer's own OCR config (api_key, or api_key_cmd run in the real environment)
    • the provider's env var
  • No GitLab token is needed. --format json gives machine-readable output.

Config

  • .pruefbyte.yml may set llm.provider (OCR built-ins only), so provider and model live in the repo and GitLab variables hold only secrets.
  • A repo can choose the provider only when the global config leaves it unset, so a merged repo file can't send the operator's shared key to another vendor.

Embedded OCR and installation

  • Release binaries (GoReleaser, build tag embedocr) embed the gzip-compressed OCR pinned in internal/ocrbin/VERSION.
  • The OCR binaries are downloaded for all six platforms and checked against OCR's published checksums. At runtime the binary is unpacked into the user cache directory and checked again.
  • Resolution order: ocr.binary if set, then the built-in copy, then ocr on the PATH.
  • The Docker image uses the same VERSION file. Archives ship LICENSE.open-code-review.
  • The module is now github.com/feinarbyte/pruefbyte, so go install …@latest works (without OCR; that path needs ocr on the PATH).
  • v* tags publish a GitHub release with archives for Linux, macOS and Windows on amd64 and arm64. Archive names carry no version, so releases/latest/download/… URLs stay stable.
  • The README documents mise, curl, PowerShell, Go and Docker installs.
  • CI's build job now runs a GoReleaser snapshot of all six binaries with OCR embedded, with the OCR downloads cached.

Two /code-review high --fix passes ran. Their fixes are included, along with fixes for the findings they left open.

Test plan

  • go test ./...: local vs CI equivalence, snapshot leaves the repo untouched, repo provider rules, api_key_cmd, OCR unpacking (first use, reuse, tamper, checksum mismatch)
  • golangci-lint shows 0 issues with and without -tags embedocr; actionlint and goreleaser check pass
  • Real OCR v1.12.10: pruefbyte local ran end to end on this repo, with both PATH OCR and embedded OCR, failing as expected on an invalid key; the repo was unchanged
  • GoReleaser snapshot: six archives of 17–19 MB, each with both licenses
  • Docker image builds and runs the pinned OCR
  • This PR's CI, including the first GoReleaser build on GitHub
  • After merging: tag v0.1.0, then check the release assets, the curl/PowerShell install and mise use -g github:feinarbyte/pruefbyte
  • A real review with a valid API key

🤖 Generated with Claude Code

testudor and others added 4 commits October 6, 2026 15:52
`pruefbyte local` reviews the current branch the way the CI job reviews
its merge request and prints the findings instead of posting them. It
shares the CI's config loading (.pruefbyte.yml and OCR rule files at the
merge base), rule merging, OCR options, severity filtering and the
fail_on_severity exit code. By default it reviews the working tree too,
via a snapshot commit built with a throwaway index, so nothing in the
repository changes. The API key falls back to the developer's own OCR
config and then to the provider's env var.

.pruefbyte.yml may now set llm.provider (OCR built-ins only), so
provider and model live in the repository and GitLab variables hold
only secrets.

Installation: the module is now github.com/feinarbyte/pruefbyte so
`go install` works, and v* tags publish GoReleaser binaries for Linux,
macOS and Windows on amd64 and arm64. Every CI run builds them as a
snapshot.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- A repository may set llm.provider only when the global config leaves
  it unset, so a merged .pruefbyte.yml cannot send the operator's shared
  API key to another vendor.
- Run api_key_cmd from the developer's OCR config in pruefbyte with the
  real environment (keychains, pass, ~/ paths), not under ocr's private
  HOME.
- Snapshot starts from a copy of the real index (sparse checkouts, no
  full rehash); CRLF-insensitive .pruefbyte.yml change note; JSON output
  always has a findings array; keep the real Toplevel error.
- Share the OCR invocation between CI and local runs, and the line range
  formatting between comments and terminal output.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Release builds (GoReleaser, build tag embedocr) now carry the ocr binary
for their platform, gzip-compressed, so a single download is all a
developer needs for `pruefbyte local`. A before hook runs
`go run ./internal/ocrbin/fetch`, which downloads the OCR release pinned
in internal/ocrbin/VERSION for all six platforms and checks each against
OCR's sha256sum.txt. On first use pruefbyte unpacks its copy into the
user cache directory, verified against the same checksum.

ocr.binary now defaults to automatic: a configured binary, else the
built-in copy, else ocr from the PATH. The built-in copy comes before
PATH so local runs use exactly the OCR version CI uses.

The Docker image reads the same VERSION file, release archives ship
OCR's license as LICENSE.open-code-review, and CI caches the downloads.
Plain go build/test/install and the Docker image embed nothing.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- Windows api_key_cmd: build the cmd.exe command line ourselves so quoted
  arguments survive.
- Do not use a key from the developer's OCR config when it belongs to a
  different endpoint than this review uses.
- Error when PRUEFBYTE_LLM_PROVIDER overrides the provider a repository's
  .pruefbyte.yml sets, instead of mixing provider and model.
- Strip control characters from model text printed to the terminal.
- Local output: drop repeated findings like CI, show OCR warnings, label
  the hidden count correctly.
- Snapshot takes the HEAD the caller already resolved.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@testudor
testudor merged commit 9d2d6b8 into main Oct 7, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant