gitFlow/internal/ai/execute.go
dimitar aee63bf321 feat: phase 5 — AI agent integration (OpenAI, Ollama, Anthropic)
Add the AI layer that turns scan results into suggested next actions.

Provider model (internal/ai):
- Provider interface with Name() and Suggest(ctx, ScanResult) returning
  []Suggestion (repo_path, action, message, command, priority 0-2)
- NewProvider factory resolves the configured provider and enforces that
  cloud providers have their API key in the configured env var; Ollama
  needs no key
- OpenAIProvider: Chat Completions with response_format json_object
- OllamaProvider: local /api/chat with format:json for structured output
- AnthropicProvider: Messages API with system prompt and key/version
  headers; all three fall back to provider-appropriate defaults for
  base_url and model
- Shared client: 60s timeout, 4 MiB response cap, JSON encode/decode,
  HTTP error surfaces the upstream status and body

Prompt design (BuildPrompt):
- Renders the full repository status table (name/status/branch/ahead/
  behind/changes) plus strict output rules: exact suggestion schema,
  allowed actions, smallest-safe-step guidance, no invented repositories,
  return [] when healthy

Parsing (parseSuggestions):
- Tolerates ```json fences and surrounding prose, clamps priorities to
  0-2, caps the result, and rejects replies without a JSON array

Suggestion display (presenter.Suggestions):
- "AI SUGGESTIONS" table (repository/action/priority/message/command)
  rendered below the scan table with priority color-coded (red/yellow/
  green); empty results say all repositories are healthy

Guarded execution (--ai-execute, experimental):
- RunConfirmed executes a suggestion's command inside its repository only
  after explicit per-command y/N confirmation, and only for actions on an
  allowlist (commit/push/pull/stash/checkout) so LLM output can never run
  arbitrary shell commands; cancellation aborts remaining suggestions

CLI wiring:
- scan: AI block after the table when --ai is set and format is not json
  (JSON streams stay machine-readable); failures degrade to warnings
- watch: AI is queried only on the first frame and when something changed
  since the previous frame, to avoid hammering the provider every interval
- New --ai-execute flag and provider validation in config (openai/ollama/
  anthropic), included in the config dump

Testing:
- httptest-based provider tests verifying request shape (model, auth
  headers, path), response parsing, API error bodies, HTTP failures, and
  cancellation
- Parse tests: plain/fenced/prose replies, empty arrays, garbage,
  truncated JSON, priority clamping
- Execution tests: unsafe actions and empty commands never run, declined
  confirmations are skipped, confirmed commands execute in the repo dir,
  failing commands surface errors
- Presenter suggestion table and empty-state tests

Verified: go build, go vet, go test -race, gofmt clean; end-to-end smoke
test against a local fake Ollama server (request shape confirmed, table +
suggestions rendered) and the missing-API-key warning path.
2026-08-02 08:48:27 +02:00

59 lines
1.6 KiB
Go

package ai
import (
"context"
"fmt"
"os/exec"
"strings"
)
// safeActions lists the actions whose suggested commands may be executed
// with explicit user confirmation. Anything else is treated as advisory
// only, because the LLM output must never be able to run arbitrary
// commands on the user's machine.
var safeActions = map[string]bool{
"commit": true,
"push": true,
"pull": true,
"stash": true,
"checkout": true,
}
// ConfirmFunc asks the user whether to run a suggestion's command.
type ConfirmFunc func(Suggestion) (bool, error)
// RunConfirmed runs the commands of confirmed suggestions in their
// repository working directories. Suggestions whose action is not in the
// allowlist are never executed. Cancellation stops the remaining
// suggestions.
func RunConfirmed(ctx context.Context, suggestions []Suggestion, confirm ConfirmFunc) error {
for _, s := range suggestions {
if s.Command == "" || !safeActions[s.Action] {
continue
}
ok, err := confirm(s)
if err != nil || !ok {
continue
}
if err := runCommand(ctx, s); err != nil {
return fmt.Errorf("ai: %s: %w", s.RepoPath, err)
}
}
return nil
}
// runCommand executes the suggestion's command inside its repository and
// prints its output.
func runCommand(ctx context.Context, s Suggestion) error {
cmd := exec.CommandContext(ctx, "sh", "-c", s.Command)
cmd.Dir = s.RepoPath
out, err := cmd.CombinedOutput()
if err != nil {
return fmt.Errorf("run %q: %w: %s", s.Command, err, strings.TrimSpace(string(out)))
}
if text := strings.TrimSpace(string(out)); text != "" {
fmt.Println(text)
}
return nil
}