Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
57 changes: 57 additions & 0 deletions .greptile/config.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
{
"strictness": 2,
"commentTypes": ["logic", "syntax", "style"],

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

commentTypes includes "style", but instructions forbid generic formatting/naming/stylistic comments, and Greptile’s nitpickiness docs say omit "style" (use ["logic", "syntax"]) for “code quality without style nitpicks.” Prefer dropping "style" so the category filter matches the stated PRKS review policy; keeping it fights the noise-reduction goal of this config.

"effort": "base",
"ignorePatterns": "frontend/vendor/**\ndocs/screenshots/**\ndata/**\ndata_testing/**\nartifacts/**\n**/*.zip\n**/*.woff2\n**/*.wasm",
"instructions": "Prioritize concrete correctness bugs, regressions, security defects, data-integrity failures, broken architecture invariants, unsafe persistence/filesystem behavior, concurrency or state-lifecycle bugs, and missing regression coverage. Do not comment on generic formatting, naming, stylistic preference, speculative refactors, or optional cleanup unless it violates an explicit PRKS repository rule. When a finding is based on a repository rule, identify the governing document or invariant. Distinguish currently implemented behavior from staged, proposed, or in-transition architecture; do not require future functionality merely because a design document describes it. Prefer actionable findings with a concrete failure mode over best-practice advice.",
"rules": [
{
"id": "privacy-safe-logging",
"rule": "Backend changes must preserve PRKS privacy-safe logging. Flag code that can log user or library content, request bodies or query strings, titles, notes, annotations, names, filenames or absolute paths, user URLs, headers, raw browser messages or stacks, qpdf stderr, or unsanitized exception text.",
"scope": ["backend/**"],
"severity": "high"
},
{
"id": "database-migration-safety",
"rule": "Database and schema changes must keep fresh-database schema and migrations coherent, preserve transactional and version-order guarantees, safely upgrade supported older databases, and reject unsupported newer schemas where applicable. Flag concrete parity, atomicity, ordering, or compatibility regressions.",
"scope": ["backend/db_*.py", "backend/**/*.sql"],
"severity": "high"
},
{
"id": "managed-file-lifecycle",
"rule": "Changes that create, replace, retarget, restore, or delete managed files must preserve path containment, ownership/reference checks, crash-safe durability boundaries, cleanup recovery, and canonical-versus-derived state invariants. Flag races, orphan/leak paths, stale derived state, or deletion of still-referenced bytes.",
"scope": ["backend/**"],
"severity": "high"
},
{
"id": "test-storage-isolation",
"rule": "Tests and test helpers must never operate on production data/ or a live PRKS_STORAGE tree. Flag any path, environment, fixture, or fallback that could reach production storage during tests.",
"scope": ["tests/**", "run_tests.py"],
"severity": "high"
},
{
"id": "ui-design-contract",
"rule": "User-visible frontend changes must conform to DESIGN.md. Flag concrete conflicts with the documented component, selection, focus, accessibility, density, navigation, workspace, or interaction model; do not invent generic design preferences beyond that contract.",
"scope": ["frontend/**"],
"severity": "medium"
},
{
"id": "workspace-context-ownership",
"rule": "Workspace, split-view, tab, route, editor, PDF, and contextual-panel changes must preserve TabContext ownership and documented workspace lifecycle semantics. Flag cross-context state leaks, unintended remounts, duplicate tabs, invalid Secondary-tree mutation, lost leave guards, or focus/URL changes that contradict the scoped frontend rules.",
"scope": ["frontend/js/**"],
"severity": "high"
},
{
"id": "e2e-quality",
"rule": "E2E changes must preserve isolation and deterministic synchronization. Flag arbitrary sleeps, fixed ports, shared mutable state, weakened or vacuous assertions, hidden retries, production-storage access, and browser-level tests where the same regression can be covered adequately by a substantially faster unit, API, Node, or static test.",
"scope": ["tests/e2e/**"],
"severity": "medium"
},
{
"id": "workflow-safety",
"rule": "GitHub Actions changes must preserve least-privilege permissions, safe handling of untrusted pull-request input, pinned actions where required by repository policy, correct cache/artifact boundaries, and truthful failure propagation. Flag workflows that can accidentally report success after a failed required step.",
"scope": [".github/workflows/**"],
"severity": "high"
}
]
}
51 changes: 51 additions & 0 deletions .greptile/files.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
{
"files": [
{
"path": "AGENTS.md",
"description": "Repository-wide PRKS engineering, safety, testing, storage, and issue-tracking rules."
},
{
"path": "SECURITY.md",
"description": "PRKS security boundaries, deployment assumptions, sensitive-data constraints, and vulnerability scope."
},
{
"path": "backend/AGENTS.md",
"description": "Backend persistence, privacy-safe logging, filesystem, backup/restore, database, indexing, durability, and cross-domain invariants.",
"scope": ["backend/**"]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Include production rules for test-only changes

When a PR changes only a test such as tests/test_backup_restore.py, this scope excludes backend/AGENTS.md, so Greptile will not receive the backend persistence rules that govern the behavior under test. The analogous frontend/** scope has the same problem for frontend/offline tests; add the corresponding test paths to these scopes, or leave the production authority files unscoped, so test-only reviews receive the required domain invariants.

AGENTS.md reference: AGENTS.md:L26-L26

Useful? React with 👍 / 👎.

},
{
"path": "frontend/AGENTS.md",
"description": "Frontend runtime, workspace, TabContext, navigation, offline/PWA, interaction, and cross-boundary behavior invariants.",
"scope": ["frontend/**"]
Comment on lines +17 to +19

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation recommended

1. Backend sync reviews miss contracts 🐞 Bug ≡ Correctness

The frontend/AGENTS.md context is scoped exclusively to frontend/**, although
backend/AGENTS.md requires its offline/PWA contract and additional sync documents for backend sync
work. Backend-only changes to sync handlers and durable-operation behavior therefore omit the shared
contract that governs their correctness.
Agent Prompt
## Issue description
Backend sync reviews do not receive the shared frontend and offline/local-first contracts that `backend/AGENTS.md` explicitly requires.

## Fix Focus Areas
- .greptile/files.json[17-19]
- backend/AGENTS.md[7-19]

## Recommended Fix
Expand the scoped context for backend sync surfaces to include `frontend/AGENTS.md`, and add scoped entries for `docs/agent-context/sync-map.md`, `docs/agent-rules/offline-pwa.md`, and `docs/local-first-rollout-status.md`. Use backend sync and durable-operation path patterns so unrelated backend reviews do not load these documents.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

},
{
"path": "DESIGN.md",
"description": "Authoritative PRKS visual and interaction design contract for user-visible frontend changes.",
"scope": ["frontend/**"]
},
{
"path": "tests/AGENTS.md",
"description": "Test-layer routing, storage safety, and rules for loading the production-domain invariants exercised by a test.",
"scope": ["tests/**"]
},
{
"path": "tests/e2e/AGENTS.md",
"description": "Browser E2E isolation, synchronization, tiering, performance, and debugging policy.",
"scope": ["tests/e2e/**"]
Comment on lines +31 to +34

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation recommended

3. Tour reviews miss safety rules 🐞 Bug ≡ Correctness

The context list registers the general test and E2E instructions but omits
tests/ux_tour/AGENTS.md. Changes under tests/ux_tour/** therefore lack the suite-specific
artifact retention, isolation, discovery, and user-interaction requirements mandated by the
repository routing rules.
Agent Prompt
## Issue description
Greptile does not receive the dedicated UX Interaction Tour instructions when reviewing that test suite.

## Fix Focus Areas
- .greptile/files.json[26-35]
- tests/ux_tour/AGENTS.md[1-37]

## Recommended Fix
Add `tests/ux_tour/AGENTS.md` to the context files with scope `tests/ux_tour/**`. Keep the existing general `tests/AGENTS.md` entry so both the base test policy and the suite-specific refinements apply.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

},
{
"path": "docs/work-identity-model.md",
"description": "Approved-in-direction Work/Manifestation/Asset architecture design. Treat it as staged architecture: use it only when reviewing implementation that touches this model, and do not assume every proposed slice is already implemented.",
"scope": [
"backend/db_*.py",
"backend/**/*work*.py",
"backend/**/*manifestation*.py",
"backend/**/*asset*.py",
Comment on lines +40 to +43

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation recommended

2. Model reviews lose design context 🐞 Bug ≡ Correctness

The docs/work-identity-model.md scopes rely mainly on filenames containing work,
manifestation, or asset, rather than all implementation surfaces that use the model. Known
model-sensitive files such as backend/backup_restore.py, tests/test_backup_restore.py, and
generic E2E modules consequently receive no design context when changed.
Agent Prompt
## Issue description
The work-identity design context is selected by narrow filename patterns that exclude existing implementation and test files which exercise that model.

## Fix Focus Areas
- .greptile/files.json[39-47]
- backend/backup_restore.py[1249-1249]
- tests/e2e/test_app.py[1199-1223]

## Recommended Fix
Extend the document's scope with the existing backup/restore and generic E2E paths that implement or verify work identity. Audit current references to the model and its identifiers, then add each applicable path or a suitably bounded directory glob so model changes consistently receive this context.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

"frontend/**/*work*.js",
"tests/**/*work*.py",
"tests/**/*manifestation*.py",
"tests/**/*asset*.py"
]
}
]
}
Loading