Skip to content

[feat] Add gerrit report configuration options - #5144

Open
panicking wants to merge 4 commits into
Ericsson:masterfrom
panicking:feat/add-gerrit-report-configuration-options
Open

panicking wants to merge 4 commits into
Ericsson:masterfrom
panicking:feat/add-gerrit-report-configuration-options

Conversation

@panicking

Copy link
Copy Markdown

Make the gerrit review labels and quality gate configurable

The gerrit output voted -1 on both Code-Review and Verified whenever a
report was found, so a change which only introduced a STYLE or a LOW
severity issue was rejected by the pipeline in the same way as a change which
introduced a critical issue. Reporting an issue and rejecting a change are
two different decisions, and only the first one should always happen.

The labels themselves were hard-coded as well: their names, their vote values
and the tag of the review could not be changed. A review could not be sent
without votes, and a project which does not use one of the two labels — or
does not permit the CI user to vote on it — could not use this output at all,
because Gerrit rejects the whole review, including its comments, if any of
the votes in it is not permitted.

Configuration

Three new environment variables control the review, next to the existing
CC_REPO_DIR, CC_REPORT_URL and CC_CHANGED_FILES:

Variable Meaning Default
CC_GERRIT_LABELS Comma separated list of the labels to vote on. The vote values used on failure and on success can be given after a slash. An empty value sends the reports as comments without any vote. Code-Review=-1/1,Verified=-1/1
CC_GERRIT_FAIL_ON_SEVERITY The lowest severity level which makes the review fail: UNSPECIFIED, STYLE, LOW, MEDIUM, HIGH or CRITICAL. unset — any report fails the review
CC_GERRIT_TAG Tag of the review. jenkins

Example for a review which reports everything but only rejects a change for a
high severity issue, and which abstains from Code-Review instead of
approving the change:

export CC_GERRIT_LABELS="Verified=-1/1,Code-Review=-1/0"
export CC_GERRIT_FAIL_ON_SEVERITY="HIGH"

Changes made

  • The reports and the votes are decoupled. Every report is still sent as an
    inline comment, but only the reports at or above
    CC_GERRIT_FAIL_ON_SEVERITY result in a negative vote. Minor findings are
    therefore visible in the review without failing the quality gate.
  • The message of the review shows the outcome of the gate, e.g.
    CodeChecker found 3 issue(s) in the code. 1 of them are at or above the 'HIGH' severity. or ... None of them are at or above the 'HIGH' severity., and it tells the reviewers when no vote was cast at all.
  • The labels to vote on, their vote values and the tag of the review are
    configurable. A label which is not listed is not sent, so the reports can
    be published without any vote.
  • The new variables are validated before the conversion. Both
    CodeChecker parse -e gerrit and CodeChecker cmd diff -o gerrit already
    call mandatory_env_var_is_set() before doing any work, so an invalid
    severity level or a malformed label results in an error message instead of
    a silently different review.
  • Unit tests cover the configurable labels, the vote values, the report-only
    mode, the severity gate (including reports without a severity) and the
    validation of the environment variables.
  • The new variables are documented in the help output of CodeChecker parse
    and CodeChecker cmd diff, in docs/web/diff.md and in the Jenkins
    integration guide, whose example build script sets them.

Compatibility

If none of the new variables is set, the generated review is identical to the
previous one, and so is the message. In this case a warning is logged which
points to the new configuration.

Testing

  • The gerrit unit tests of the report-converter
    (pytest tests/unit/output/gerrit): 18 passed, including the 4
    pre-existing tests which pin the legacy behaviour of the output.
  • mypy --ignore-missing-imports codechecker_report_converter, pylint
    with the repository .pylintrc and pycodestyle on the modified Python
    files — clean.
  • The functional tests which also exercise this output
    (analyzer/tests/functional/analyze_and_parse,
    web/tests/functional/diff_local_remote) were not run locally, they need
    a full CodeChecker build.

Known limitation

The exit code of CodeChecker cmd diff and CodeChecker parse is 2 when
there is any report difference, independently of this quality gate, so a
Jenkins build step still fails for a change with only minor findings. A A
severity aware exit policy is a possible follow-up, this change only affects
what is sent to Gerrit.

Commits

  1. [feat] Make the gerrit review labels and tag configurable
  2. [feat] Add severity based quality gate to the gerrit output
  3. [doc] Document the gerrit output environment variables in the CLI help
  4. [doc] Describe the gerrit labels and quality gate in the Jenkins guide

panicking and others added 4 commits October 8, 2026 19:42
The gerrit output always voted on 'Code-Review' and 'Verified' with
-1/+1 whenever a report was found. There was no way to send the reports
without voting, and the vote values could not be adjusted to the label
ranges configured in Gerrit.

The labels to vote on and the vote values used on failure and on success
can now be set with the new 'CC_GERRIT_LABELS' environment variable,
e.g. 'Verified=-1/1,Code-Review=-1/0'. An empty value sends the reports
as comments without any vote. The tag of the review can be set with the
'CC_GERRIT_TAG' environment variable.

The environment variables are validated before the conversion, so a
typo results in an error message instead of a silently different review.
If 'CC_GERRIT_LABELS' is not set then the review keeps its previous
behaviour, but a warning is logged to suggest the new configuration.

Co-Authored-By: Claude Code <noreply@anthropic.com>
The review voted -1 on the configured labels for any report, so a change
which only introduced a 'STYLE' or a 'LOW' severity issue was rejected by
the pipeline in the same way as a change which introduced a critical
issue.

The new 'CC_GERRIT_FAIL_ON_SEVERITY' environment variable sets the
lowest severity level which makes the review fail. Reports with a lower
severity are still sent as inline comments, they just don't result in a
negative vote, so the review remains informative while the vote follows
the quality gate. The message of the review also shows whether any report
reached the configured severity level, and if no label is voted on it
tells the reviewers that no vote was cast.

If the variable is not set then any report makes the review fail, which
is the previous behaviour.

Co-Authored-By: Claude Code <noreply@anthropic.com>
The 'CodeChecker parse -e gerrit' and 'CodeChecker cmd diff -o gerrit'
commands document their environment variables in their help output.
Extend this list with the new 'CC_GERRIT_LABELS',
'CC_GERRIT_FAIL_ON_SEVERITY' and 'CC_GERRIT_TAG' variables, and update
the pasted help output of the diff command in the documentation.

Co-Authored-By: Claude Code <noreply@anthropic.com>
The Jenkins integration guide is the documentation of the gerrit output
for the users who set up the review job, so explain there how the labels
and the severity based quality gate can be configured, and set the new
variables in the example build script.

Co-Authored-By: Claude Code <noreply@anthropic.com>
@panicking panicking changed the title Feat/add gerrit report configuration options [feat] Add gerrit report configuration options Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant