Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
55 commits
Select commit Hold shift + click to select a range
93fd4fc
ci:delete cppcheck.yml and codeql.yml
xengine-qyt May 8, 2026
a596e04
ci:add configure codeql
xengine-qyt May 8, 2026
26bd7a2
Update CodeQL workflow for improved analysis
xengine-qyt May 8, 2026
2894d0a
Update issue templates
xengine-qyt May 8, 2026
254a8c8
feat: add agentic workflows for issue triage and auto fix
xengine-qyt May 8, 2026
ba13dce
Create FUNDING.yml
xengine-qyt May 8, 2026
be0fc3e
ci:update ai agent
xengine-qyt May 8, 2026
4ec8f7d
added:VSClean.bat
xengine-qyt May 8, 2026
d7ba414
Potential fix for code scanning alert no. 79
xengine-qyt May 8, 2026
47f2d17
Potential fix for code scanning alert no. 78
xengine-qyt May 8, 2026
bd307f0
Potential fix for code scanning alert no. 77
xengine-qyt May 8, 2026
b5812fd
Potential fix for code scanning alert no. 75
xengine-qyt May 8, 2026
09e713c
Potential fix for code scanning alert no. 74
xengine-qyt May 8, 2026
aaf3daa
Potential fix for code scanning alert no. 72
xengine-qyt May 8, 2026
b4fb820
Potential fix for code scanning alert no. 71
xengine-qyt May 8, 2026
644861c
Potential fix for code scanning alert no. 70
xengine-qyt May 8, 2026
e338305
Potential fix for code scanning alert no. 69
xengine-qyt May 8, 2026
cc113bb
Potential fix for code scanning alert no. 68
xengine-qyt May 8, 2026
680bd23
Potential fix for code scanning alert no. 14
xengine-qyt May 8, 2026
6075892
Potential fix for code scanning alert no. 13
xengine-qyt May 8, 2026
caf321b
Potential fix for code scanning alert no. 2
xengine-qyt May 8, 2026
bb13443
Potential fix for code scanning alert no. 1
xengine-qyt May 8, 2026
aaaddfb
add agent workflows
xengine-qyt May 9, 2026
49b1e0c
improved:build mode
xengine-qyt May 9, 2026
048db5d
fix engine id to openai
xengine-qyt May 9, 2026
663a8a2
fix engine id to openai
xengine-qyt May 9, 2026
5cc2aa2
ci:delete code ql configure and update auto md issue
xengine-qyt Jun 24, 2026
f97e255
update:vs to 2026 and depend library
xengine-qyt Jun 24, 2026
65dd153
Merge pull request #72 from libxengine/autofix/warning/alert-79
xengine-qyt Jun 24, 2026
3fdd7b6
Merge pull request #73 from libxengine/autofix/warning/alert-78
xengine-qyt Jun 24, 2026
dfb75cc
Merge pull request #74 from libxengine/autofix/warning/alert-77
xengine-qyt Jun 24, 2026
f321b87
Merge pull request #75 from libxengine/autofix/warning/alert-75
xengine-qyt Jun 24, 2026
636a01d
Merge pull request #81 from libxengine/autofix/high/alert-68
xengine-qyt Jun 24, 2026
14146d7
Merge pull request #80 from libxengine/autofix/high/alert-69
xengine-qyt Jun 24, 2026
dce33f6
Merge pull request #79 from libxengine/autofix/high/alert-70
xengine-qyt Jun 24, 2026
36e42b8
Merge pull request #78 from libxengine/autofix/high/alert-71
xengine-qyt Jun 24, 2026
926fc69
Merge pull request #85 from libxengine/autofix/high/alert-1
xengine-qyt Jun 24, 2026
90c1201
Merge pull request #84 from libxengine/autofix/high/alert-2
xengine-qyt Jun 24, 2026
ddbe577
Merge pull request #77 from libxengine/autofix/high/alert-72
xengine-qyt Jun 24, 2026
8436aad
Merge pull request #76 from libxengine/autofix/high/alert-74
xengine-qyt Jun 24, 2026
3263a71
modify:build warn
xengine-qyt Jul 9, 2026
3f7ee55
modify:match runtime crt for every compiler choice
xengine-qyt Aug 1, 2026
86b8545
fixed:build error and warn
xengine-qyt Aug 1, 2026
730dd02
Merge pull request #83 from libxengine/autofix/warning/alert-13
xengine-qyt Aug 1, 2026
95524ba
Merge pull request #82 from libxengine/autofix/warning/alert-14
xengine-qyt Aug 1, 2026
5b375f6
Potential fix for code scanning alert no. 82
xengine-qyt Aug 1, 2026
451b53d
fixed:get count connect number incorrect for session of up storage
xengine-qyt Aug 1, 2026
6153f82
modify:ci scan code warn
xengine-qyt Aug 1, 2026
191184e
update:depend library
xengine-qyt Aug 5, 2026
a39f1cc
fixed:lost paramter check
xengine-qyt Aug 5, 2026
57e1dee
Potential fix for code scanning alert no. 84
xengine-qyt Aug 5, 2026
d663c76
Merge pull request #87 from libxengine/autofix/warning/alert-84
xengine-qyt Aug 5, 2026
806c4be
Merge pull request #86 from libxengine/autofix/warning/alert-82
xengine-qyt Aug 5, 2026
d234ea8
update:vs to 2026 for example
xengine-qyt Aug 6, 2026
3ad6912
update:CHANGELOG and configure
xengine-qyt Aug 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .github/FUNDING.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
# These are supported funding model platforms

custom: # paypal and afdian ['https://paypal.me/libxengine', 'https://www.afdian.com/a/xengine']
10 changes: 10 additions & 0 deletions .github/ISSUE_TEMPLATE/custom.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
---
name: Custom issue template
about: Describe this issue template's purpose here.
title: ''
labels: ''
assignees: ''

---


1,179 changes: 1,179 additions & 0 deletions .github/workflows/auto-code.lock.yml

Large diffs are not rendered by default.

123 changes: 123 additions & 0 deletions .github/workflows/auto-code.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,123 @@
---
on:
issues:
types: [labeled]

engine:
id: copilot
env:
COPILOT_PROVIDER_BASE_URL: "https://ark.cn-beijing.volces.com/api/v3"
COPILOT_PROVIDER_BEARER_TOKEN: ${{ secrets.OPENAI_API_KEY }}
COPILOT_MODEL: doubao-seed-evolving
COPILOT_PROVIDER_TYPE: openai
COPILOT_PROVIDER_WIRE_API: responses

features:
dangerously-disable-sandbox-agent: "controlled environment for issue triage automation"
sandbox:
agent: false
strict: false

network:
allowed:
- defaults
- ark.cn-beijing.volces.com

tools:
github:
min-integrity: none

permissions:
contents: read
issues: read
pull-requests: read
copilot-requests: write

safe-outputs:
threat-detection: false
create-pull-request:
base-branch: develop
protected-files: allowed
add-comment:
max: 1
---

# 自动处理 Issue

当 Issue 被打上 `bug` 或 `enhancement` 或 `feature` 标签时触发。其他标签直接退出,不做任何操作。

## 判断任务类型

读取 Issue #${{ github.event.issue.number }} 当前的标签:
- 如果包含 `bug` 标签 → 执行【Bug 修复流程】
- 如果包含 `feature` 标签 → 执行【新功能开发流程】
- 如果包含 `enhancement` 标签 → 执行【功能改进开发流程】
- 其他情况 → 直接退出

## 任务执行限制
- 根据需求查找相对应的可能关联的代码文件
- 尽量只读取相关代码文件和文档,不去操作无关代码和文件
- 尽量减少操作时间和步骤,减少TOKEN和时间消耗

---


## Bug 修复流程

1. 阅读 Issue 的完整标题和正文,理解问题现象
2. 浏览仓库相关代码和文档,定位问题所在的文件和函数
3. 分析根本原因
4. 实现修复方案,注意:
- 保持与现有代码风格一致
- 只修改必要的部分,不做无关改动
5. 创建 Pull Request,标题格式:`fix: <Issue 标题>`,描述中说明:
- 问题根因
- 修复方式
- 如何验证
6. 在原 Issue 下使用用户提问的语言进行回复,说明已提交 PR 及修复思路

如果问题过于复杂或信息不足,在 Issue 下用中文说明原因,不创建 PR。

---

## 新功能开发流程

1. 阅读 Issue 的完整标题和正文,理解需求目标
2. 浏览仓库相关代码结构和文档,找到最相关的模块和文件
3. 制定实现方案:
- 需要新增哪些文件或函数
- 需要修改哪些现有文件
4. 按方案实现代码,注意:
- 保持与现有代码风格一致
- 新增函数/类需要添加注释
- 如果涉及接口变更,同步更新相关调用方
5. 创建 Pull Request,标题格式:`feat: <Issue 标题>`,描述中说明:
- 实现了哪些功能
- 涉及哪些文件改动
- 如何验证/测试
6. 在原 Issue 下使用用户提问的语言进行回复,说明已提交 PR、实现思路和测试建议

如果需求描述不清晰或实现风险过大,在 Issue 下用中文说明原因,不创建 PR。

---

## 功能改进开发流程

1. 阅读 Issue 的完整标题和正文,明确功能改进与优化的具体目标(如性能提升、代码结构重构、用户体验优化等)。
2. 浏览仓库相关代码,评估受影响的范围,定位需要进行优化或重构的核心文件及函数。
3. 制定改进方案,需特别注意:
- **向下兼容性**:确保本次改进不会破坏现有的公开接口(API)和已有功能。
- **防御性编程**:优化逻辑的同时,不能降低代码的健壮性。
4. 按照方案实施代码改动,注意:
- 保持与现有代码风格高度一致。
- 仅针对性能、可读性或结构进行局部优化,严禁引入未经需求的无关大范围改动。
5. 创建 Pull Request,根据改进的核心侧重点选择标题格式:
- 侧重于代码重构/可读性优化:`refactor: <Issue 标题>`
- 侧重于运行运行效率/性能优化:`perf: <Issue 标题>`
在 PR 描述中说明:
- 优化的动机与改进点
- 改进前后的对比或预期收益
- 验证优化是否生效的测试方法
6. 在原 Issue 下使用用户提问的语言进行回复,说明已提交 PR、优化思路及预期的提升效果。

如果功能改进可能带来重大的破坏性变更(Breaking Changes)或者现有代码结构不支持盲目优化,在 Issue 下用中文说明原因,保持维持原状,不创建 PR。
194 changes: 194 additions & 0 deletions .github/workflows/codeql-to-commit.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,194 @@
name: Auto Copilot Autofix (High & Medium Only)

on:
workflow_dispatch:
workflow_run:
workflows: ["CodeQL Advanced"]
types: [completed]

jobs:
auto-fix:
runs-on: ubuntu-latest
if: ${{ github.event_name == 'workflow_dispatch' || github.event.workflow_run.conclusion == 'success' }}
permissions:
security-events: read
contents: write
pull-requests: write

steps:
- name: Trigger Autofix for High & Medium alerts
env:
GH_TOKEN: ${{ secrets.AUTOFIX_TOKEN }}
OWNER: ${{ github.repository_owner }}
REPO: ${{ github.event.repository.name }}
run: |
set +e
DEFAULT_BRANCH=$(gh api /repos/$OWNER/$REPO --jq '.default_branch')
echo "Default branch: $DEFAULT_BRANCH"

ALERTS=$(gh api "/repos/$OWNER/$REPO/code-scanning/alerts?state=open&per_page=100" \
--jq '[.[] | select(.rule.security_severity_level == "critical" or .rule.security_severity_level == "high" or .rule.security_severity_level == "medium" or .rule.severity == "warning") | {number: .number, level: (.rule.security_severity_level // .rule.severity)}]')

COUNT=$(echo $ALERTS | jq 'length')
echo "Found $COUNT alerts with high / medium / warning"
echo "$ALERTS" | jq -r '.[] | " Alert #\(.number) [\(.level)]"'

if [ "$COUNT" -eq 0 ]; then
echo "No alerts to process, exiting."
exit 0
fi

for ROW in $(echo $ALERTS | jq -r '.[] | @base64'); do
_jq() { echo "$ROW" | base64 -d | jq -r "$1"; }

NUMBER=$(_jq '.number')
SEC_LEVEL=$(_jq '.level')
BRANCH="autofix/${SEC_LEVEL}/alert-${NUMBER}"

echo "--- Alert #$NUMBER [$SEC_LEVEL] ---"

# 检查是否已有 autofix
EXISTING=$(gh api \
/repos/$OWNER/$REPO/code-scanning/alerts/$NUMBER/autofix \
--jq '.status' 2>/dev/null || echo "none")

if [ "$EXISTING" = "success" ]; then
echo "✅ Fix already exists"
else
echo "⏳ Generating fix..."
gh api -X POST \
/repos/$OWNER/$REPO/code-scanning/alerts/$NUMBER/autofix || {
echo "⚠️ Failed to trigger autofix for #$NUMBER, skipping"
continue
}

for i in 1 2 3; do
sleep 30
EXISTING=$(gh api \
/repos/$OWNER/$REPO/code-scanning/alerts/$NUMBER/autofix \
--jq '.status' 2>/dev/null || echo "none")
echo " Attempt $i: status = $EXISTING"
[ "$EXISTING" = "success" ] && break
done
fi

if [ "$EXISTING" != "success" ]; then
echo "⚠️ Autofix not available for alert #$NUMBER (status: $EXISTING), skipping"
continue
fi

# 检查分支是否已存在
BRANCH_STATUS=$(gh api \
/repos/$OWNER/$REPO/git/refs/heads/$BRANCH \
--silent 2>/dev/null && echo "exists" || echo "not_found")
echo "DEBUG branch status: $BRANCH_STATUS"

if [ "$BRANCH_STATUS" = "not_found" ]; then
# 创建分支
SHA=$(gh api /repos/$OWNER/$REPO/git/refs/heads/$DEFAULT_BRANCH \
--jq '.object.sha')

gh api -X POST /repos/$OWNER/$REPO/git/refs \
-f ref="refs/heads/$BRANCH" \
-f sha="$SHA" 2>/dev/null || true
echo "🌿 Created branch: $BRANCH"

# 提交 fix
COMMIT_RESULT=$(gh api -X POST \
/repos/$OWNER/$REPO/code-scanning/alerts/$NUMBER/autofix/commits \
-f target_ref="$BRANCH" 2>&1)
echo "DEBUG commit result: $COMMIT_RESULT"

if echo "$COMMIT_RESULT" | grep -q "target_ref"; then
echo "✅ Committed fix to branch: $BRANCH"
else
echo "⚠️ No code changes generated, deleting branch and skipping"
gh api -X DELETE \
/repos/$OWNER/$REPO/git/refs/heads/$BRANCH 2>/dev/null || true
continue
fi
else
# 分支已存在,检查是否已有 open PR
EXISTING_PR=$(gh pr list \
--repo "$OWNER/$REPO" \
--head "$BRANCH" \
--state open \
--json number \
--jq '.[0].number // empty')

if [ -n "$EXISTING_PR" ]; then
echo "⏭️ PR #$EXISTING_PR already exists, skipping"
continue
fi

echo "🌿 Branch exists, creating PR with existing branch"
fi

# 获取 alert 详情
ALERT_INFO=$(gh api \
/repos/$OWNER/$REPO/code-scanning/alerts/$NUMBER)

ALERT_TITLE=$(echo $ALERT_INFO | jq -r '.rule.description')
ALERT_HELP=$(echo $ALERT_INFO | jq -r '.rule.help // "暂无详细说明"' | head -c 800)
ALERT_TAGS=$(echo $ALERT_INFO | jq -r '.rule.tags // [] | join(", ")')
ALERT_FILE=$(echo $ALERT_INFO | jq -r '.most_recent_instance.location.path // "未知文件"')
ALERT_LINE=$(echo $ALERT_INFO | jq -r '.most_recent_instance.location.start_line // "未知行"')
ALERT_URL=$(echo $ALERT_INFO | jq -r '.html_url')
CWE_TAGS=$(echo $ALERT_INFO | jq -r '[.rule.tags[] | select(startswith("external/cwe/"))] | join(", ")')

AUTOFIX_DESC=$(gh api \
/repos/$OWNER/$REPO/code-scanning/alerts/$NUMBER/autofix \
--jq '.description // "暂无 AI 修复说明"')

# 创建 Draft PR
gh pr create \
--repo "$OWNER/$REPO" \
--base "$DEFAULT_BRANCH" \
--head "$BRANCH" \
--draft \
--title "[Autofix][$SEC_LEVEL] Alert #$NUMBER: $ALERT_TITLE" \
--body "## 🤖 Copilot Autofix 自动修复报告

---

### 📋 基本信息

| 字段 | 内容 |
|------|------|
| **Alert ID** | [#$NUMBER]($ALERT_URL) |
| **安全级别** | $SEC_LEVEL |
| **规则名称** | $ALERT_TITLE |
| **问题文件** | \`$ALERT_FILE\` 第 $ALERT_LINE 行 |
| **CWE 分类** | $CWE_TAGS |
| **规则标签** | $ALERT_TAGS |

---

### 🔍 问题说明

$ALERT_HELP

---

### 🤖 AI 修复思路

$AUTOFIX_DESC

---

### ✅ Review 检查清单

- [ ] 理解了漏洞的成因和影响范围
- [ ] 确认 AI 修复逻辑正确,没有遗漏边界情况
- [ ] 确认修复没有改变原有业务逻辑
- [ ] 确认没有引入新的安全问题
- [ ] CI / 单元测试全部通过
- [ ] 如有必要,已补充对应的测试用例

---

> 此 PR 由 GitHub Copilot Autofix 自动生成,请仔细审核后再 merge。" && \
echo "🎉 PR created for alert #$NUMBER" || \
echo "❌ Failed to create PR for alert #$NUMBER"

done
17 changes: 13 additions & 4 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,8 @@ jobs:
matrix:
include:
- language: c-cpp
build-mode: manual

steps:
- name: Checkout repository
uses: actions/checkout@v6
Expand All @@ -49,17 +51,24 @@ jobs:
chmod +x ./XEngine_LINEnv.sh
sudo ./XEngine_LINEnv.sh -i 3

- name: make pre
run: |
cd XEngine_Source
make BUILDTYPE=1

- name: Initialize CodeQL
uses: github/codeql-action/init@v3
uses: github/codeql-action/init@v4
with:
languages: ${{ matrix.language }}
build-mode: manual
queries: security-and-quality

- name: make
- name: make check
run: |
cd XEngine_Source
make
make BUILDTYPE=2

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
uses: github/codeql-action/analyze@v4
with:
category: "/language:${{ matrix.language }}"
Loading
Loading