Pull Request已成功合入, 合并人@openharmony_ci
(感谢 zhenghui25 的贡献)AI检视任务后台执行中,稍候返回结果。
The AI Review task is being executed in the background and will return results shortly.
您可通过评论"list commands"来查询命令列表。
You can leave a "list commands" comment to get commands list.


感谢提交 Pull Requests !此PR未通过DCO校验。
校验失败可能原因:
1. 未签署“DCO协议”(开发者原创声明协议),在线签署、查看签署状态。
2. Commits 中未包含 Signed-off-by信息,参考FAQ处理。
修复上述问题后,在PR的评论框输入“check dco” ,单击”评论”,系统将再次进行DCO校验。
当前检测到如下Commits 未包含Signed-off-by信息:
Thanks for submitting a pull request. This pull request has not passed the DCO check.
Possible causes:
1. You have not signed the Developer Certificate of Origin (DCO). Sign the DCO and check DCO status.
2. The commits do not contain the Signed-off-by information. To resolve this issue, see FAQs.
After resolving the preceding issues, enter check dco in the comment box of this pull request and click Comment. The system will check DCO status again.
The following commits do not contain the Signed-off-by information:


感谢提交 Pull Requests!如果您提交的PR已经开发完毕,请评论 "start build" 触发门禁,更多交互操作,请访问OpenHarmony社区支持命令清单。如果需要调整订阅PR、Issue的变更状态,请访问订阅链接。
Thanks for submitting the pull request. If your Pull Request has already been developed, you can leave a "start build" comment to trigger the gated system. For more commands, please visit OpenHarmony Command List. If you need to change the subscription of a Pull Request or Issue, please visit the link.


start build


首次触发
门禁构建开始,包含静态检查、代码编译和测试【part_compile编译, dayu600_7885测试, ohos-host_mini_tdd编译, dayu200测试, master_inner_build编译, dayu600_7885编译, x86_64_virt编译, dayu200编译, dayu200_tdd编译】,预计在60分钟内完成,门禁结果会同步发送到注册邮箱。您可以通过如下链接跟踪门禁进展:http://dcp.openharmony.cn/workbench/cicd/detail/6a72b55c64650f998b9fcdba/runlist


代码门禁通过
您可以通过如下链接查看门禁报告:http://dcp.openharmony.cn/workbench/cicd/detail/6a72b55c64650f998b9fcdba/runlist
静态检查:
| # | check type | result | report |
|---|---|---|---|
| 1 | codeCheck | pass | >>> |
编译测试:
| # | Device | build result | test result | package |
|---|---|---|---|---|
| 1 | dayu200 | success | success | >>> |
| 2 | dayu200_tdd | success | NA | >>> |
| 3 | part_compile | success(IGNORE) | NA | >>> |
| 4 | master_inner_build | success | NA | >>> |
| 5 | ohos-host_mini_tdd | success | NA | >>> |
| 6 | dayu600_7885 | success | success(IGNORE) | >>> |
| 7 | x86_64_virt | success | NA | >>> |


您好,Committer @JiDong-CS1 @steven-q @linshuqing @chennian ,请分配检视人员检视该PR,可以通过命令"assign [@someone_id]"分配检视人员,也可以直接评论"assign"分配给自己进行检视。
Hello, Committer @JiDong-CS1 @steven-q @linshuqing @chennian . Please assign someone to review the PR. You can assign a reviewer by using the command "assign [@someone_id]", or you can comment "assign" to review the PR by yourself.


验证结果已超过12小时,之前验证结果无效,自动重新触发构建,请关注最新验证结果


start build


本地或库上代码有更新,全量重新构建,重置所有关联PR的验证状态
门禁构建开始,包含静态检查、代码编译和测试【ohos-host_mini_tdd编译, dayu600_7885测试, dayu200_tdd编译, x86_64_virt编译, dayu200编译, dayu600_7885编译, part_compile编译, dayu200测试, master_inner_build编译】,预计在60分钟内完成,门禁结果会同步发送到注册邮箱。您可以通过如下链接跟踪门禁进展:http://dcp.openharmony.cn/workbench/cicd/detail/6a7428b964650f998b1f9d2c/runlist


代码门禁通过
您可以通过如下链接查看门禁报告:http://dcp.openharmony.cn/workbench/cicd/detail/6a7428b964650f998b1f9d2c/runlist
静态检查:
| # | check type | result | report |
|---|---|---|---|
| 1 | codeCheck | pass | >>> |
编译测试:
| # | Device | build result | test result | package |
|---|---|---|---|---|
| 1 | dayu200 | success | success | >>> |
| 2 | dayu200_tdd | success | NA | >>> |
| 3 | part_compile | success(IGNORE) | NA | >>> |
| 4 | master_inner_build | success | NA | >>> |
| 5 | ohos-host_mini_tdd | success | NA | >>> |
| 6 | dayu600_7885 | success | success | >>> |
| 7 | x86_64_virt | success | NA | >>> |


您好,Committer @JiDong-CS1 @steven-q @linshuqing @chennian ,请分配检视人员检视该PR,可以通过命令"assign [@someone_id]"分配检视人员,也可以直接评论"assign"分配给自己进行检视。
Hello, Committer @JiDong-CS1 @steven-q @linshuqing @chennian . Please assign someone to review the PR. You can assign a reviewer by using the command "assign [@someone_id]", or you can comment "assign" to review the PR by yourself.


关联的issue:
https://gitcode.com/openharmony/account_os_account/issues/3038
修改描述:
测试用例(附上截图):
TDD:3条失败用例于修改无关,dev用例测试通过

XTS:
手工用例:
综合代码修改检视报告
📋 检视摘要 (Executive Summary)
基本信息
801da333930fcaeaa196230d8b794a0f9cc550d2feat: enable BTI branch protector for account SOs变更文件列表
frameworks/account_iam/BUILD.gnaccount_iam_innerkitsbranch_protector_frt = "bti"frameworks/authorization/BUILD.gnauthorization_innerkitsbranch_protector_frt = "bti"frameworks/osaccount/native/BUILD.gnos_account_innerkitsbranch_protector_frt = "bti"interfaces/kits/napi/authorization/BUILD.gnauthorization_napibranch_protector_frt = "bti"interfaces/kits/napi/common/BUILD.gnaccount_napi_commonbranch_protector_frt = "bti"interfaces/kits/napi/domain_account/BUILD.gndomain_account_napibranch_protector_frt = "bti"interfaces/kits/napi/osaccount/BUILD.gnosaccountbranch_protector_frt = "bti"✅ 检查项目清单
🔐 Security Review(安全检查)
小计: 6/6 通过 ✅
🔍 Logic Analyzer(逻辑分析)
"bti"是构建系统唯一支持的合法值(cxx.gni:408)branch_protector_ret = "pac_ret"紧随其后branch_protector_ret = "pac_ret",组合后产出-mbranch-protection=pac-ret+b-key+bti(cxx.gni:418-420)support_branch_protector_bti仅在target_cpu=="arm64" && is_ohos && is_standard_system时为 true(security_config.gni:45-49),非 arm64 平台自动跳过,不会破坏 x86 模拟器编译小计: 5/5 通过 ✅
📊 DFX Reviewer(DFX检查)
小计: 4/4 通过 ✅(N/A 维度)
📋 Code Review Checklist(规范检查)
兼容性检查:
AGENTS.md 约束检查:
interfaces/kits/的接口签名account_mgr_service.cppos_account.gni中的 feature flag属性合法性验证:
branch_protector_frt是构建系统正式支持的属性(cxx.gni:291白名单已声明,cxx.gni:407-412已实现处理逻辑)"bti"与构建系统判断条件invoker.branch_protector_frt == "bti"匹配(cxx.gni:408)小计: 9/9 通过 ✅
🧪 Test Coverage Reviewer(测试覆盖度检查)
小计: 3/3 通过 ✅
🎨 Coding Style Review(编码风格检查)
branch_protector_frt使用下划线命名,与branch_protector_ret风格一致"bti"字符串,与"pac_ret"风格一致branch_protector_ret之后,风格统一feat: <description>符合 Conventional Commits 规范Signed-off-by: zhenghui25 <zhenghui25@h-partners.com>已包含小计: 7/7 通过 ✅
🎯 总体评价
整体评分: 100/100 (🟢 优秀)
整体风险等级: 🟢 低风险
是否建议上库: ✅ 是(建议补充编译验证)
📊 问题统计
检视澄清说明
🔍 检视依据(代码级证据)
1. 构建系统对
branch_protector_frt的处理逻辑文件:
/home/zhenghui/duli/build/templates/cxx/cxx.gni属性白名单声明 (line 291):
属性处理逻辑 (line 407-426):
结论:
branch_protector_frt = "bti"+branch_protector_ret = "pac_ret"组合产出-mbranch-protection=pac-ret+b-key+bti+-Wl,-z,force-bti。2.
support_branch_protector_bti平台守卫文件:
/home/zhenghui/duli/build/config/security/security_config.gni结论: BTI 仅在 arm64 + OHOS 标准系统下生效,x86 模拟器自动跳过,不会破坏编译。
3. 7 个目标的属性放置一致性验证
branch_protector_ret行号branch_protector_frt行号frameworks/account_iam/BUILD.gnframeworks/authorization/BUILD.gnframeworks/osaccount/native/BUILD.gninterfaces/kits/napi/authorization/BUILD.gninterfaces/kits/napi/common/BUILD.gninterfaces/kits/napi/domain_account/BUILD.gninterfaces/kits/napi/osaccount/BUILD.gn总结与建议
关键发现
本次提交无致命、严重、警告问题。所有 6 个检视维度均 100% 通过。
最终评价
代码质量评分
整体评分: 100/100 (🟢 优秀)
上库决策
是否建议上库: ✅ 是
上库前置条件
附录
A. 检查文件列表
B. 参考文档
build/templates/cxx/cxx.gni:407-426build/config/security/security_config.gni:45-49AGENTS.md§3.1, §5.1C. 检视信息
报告生成时间: 2026-08-06
报告生成工具: Comprehensive Code Review Skill v1.3
兼容性上库自检:
日志规范自检:
安全编码自检:
是否已执行L0用例