Repository navigation
Conversation
…t contract, knowledge map - Add scripts/guardrails/domains.manifest.json (24 domains, 4 layers) and check:domain-boundaries enforcing exclusive ownership and downward imports; four pre-existing edges allowlisted with reasons. - Fix check:engine-prisma import patterns (ran on string-blanked text and could never match); add self-tests for both guardrails. - Add report:domain-impact and --filter= on check:tests:node/next for DOMAIN-level verification (labelled, non-authoritative). - Rewrite AGENTS.md as the single operating contract; CLAUDE.md, copilot instructions become pointers; CONTRIBUTING.md keeps human-only content; scoped AGENTS.md for lib/engine, app/api, scripts. - Add docs/architecture (index, domains, dependency-rules, data-flow, testing, ADRs 0001-0002, audit-2026-09-22) and correct stale claims in existing docs; remove self-declared deprecated docs. - .gitignore hygiene; regenerate docs/config-snapshot.md blocks. No engine, schema, or runtime behavior changes.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 132449f9d7
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| { | ||
| message: "value-imports '@prisma/client'", | ||
| regex: /^\s*(?:import|export)\s+(?!type\b)[^;]*?\bfrom\s+['"]@prisma\/client['"]/m, | ||
| }, | ||
| { message: "requires '@prisma/client'", regex: /\brequire\s*\(\s*['"]@prisma\/client['"]\s*\)/ }, |
There was a problem hiding this comment.
Detect side-effect and dynamic Prisma imports
When a file under lib/authority uses import '@prisma/client' or await import('@prisma/client'), neither this from-only expression nor the require expression matches it. The domain checker ignores external packages, and the repository backstop scans lib/engine but not lib/authority, so such an import can pass the full guardrail suite despite the authority purity invariant; add patterns and fixtures for these ESM forms.
AGENTS.md reference: AGENTS.md:L37-L40
Useful? React with 👍 / 👎.
| const ownerByFile = new Map<string, string>(); | ||
| for (const [id, domain] of Object.entries(manifest.data.domains)) { | ||
| for (const file of fg.sync(domain.owns, { cwd: ROOT, onlyFiles: true })) { | ||
| ownerByFile.set(normalize(file), id); |
There was a problem hiding this comment.
Preserve domain ownership for deleted files
When a change only deletes a mapped source file, changedFiles() returns its old path, but this map is populated by globbing only files that still exist. The deleted path is consequently reported as outside the domain map, its owning domain is omitted, and the report does not recommend that domain's tests or invariants even though it promises impact information for everything changed versus main; ownership for deleted paths should be matched from the manifest patterns or the base revision.
AGENTS.md reference: AGENTS.md:L26-L28
Useful? React with 👍 / 👎.
| while ((match = IMPORT_FROM_REGEX.exec(stripped)) !== null) { | ||
| const isTypeOnly = match[2] !== undefined; | ||
| const specifier = match[3]; | ||
| if (isTypeOnly || specifier === undefined) continue; | ||
| specifiers.push(specifier); |
There was a problem hiding this comment.
Exclude inline type-only imports from boundary edges
For valid TypeScript such as import { type Foo } from '../other-domain.js' or export { type Foo } from ..., match[2] is undefined because type occurs inside the specifier list, so the guardrail records a runtime edge and can reject an import that is erased during compilation. The repository already uses this inline type syntax, so the parser should distinguish an all-type specifier list from mixed/value imports.
Useful? React with 👍 / 👎.
| "buckets", | ||
| "config", | ||
| "observability" |
There was a problem hiding this comment.
Prevent runtime domains from importing service domains
The adapters-runtime domain is in the runtime layer, but this allowlist grants it blanket access to the service-layer buckets and observability domains, so isAllowedEdge accepts imports in the opposite direction from the declared surface → service → runtime → core flow. Existing bucket dependencies should be represented as exact legacy exceptions or moved to a lower layer rather than permitting every current and future runtime file to import these service domains.
AGENTS.md reference: AGENTS.md:L31-L35
Useful? React with 👍 / 👎.
Summary
Architecture-only change to make Cherry navigable and safely modifiable by coding agents. No runtime, engine, schema, or product behavior changes.
scripts/guardrails/domains.manifest.jsondeclares 24 domains in 4 layers (core → runtime → service → surface) with owned paths, allowed imports, tests, docs, invariants. Newcheck:domain-boundaries(innpm run check) enforces total, exclusive ownership and downward value-import direction; four pre-existing edges are allowlisted with reasons and must be removed when fixed. Self-test with fixture.check:engine-prismafixed. Its@prisma/client/lib/prismaimport regexes ran after string literals were blanked and could never match; onlyprisma.usage was caught. Import patterns now run on raw source (type-only imports allowed). Self-test added. Existing engine/authority code passes.npm run report:domain-impact -- <paths>prints owner domain, allowed imports, dependents, tests, docs, invariants.--filter=<globs>oncheck:tests:node/check:tests:next(output labelled FILTERED, never authoritative).AGENTS.mdrewritten as a 113-line navigation + execution contract (what never changes, where things live, bootstrap, FAST/DOMAIN/FULL/DB verification, schema changes, workflow, parallel-agent rules, done/handoff).CLAUDE.mdand.github/copilot-instructions.mdare pointers;CONTRIBUTING.mdkeeps human-only content. ScopedAGENTS.mdinlib/engine/,app/api/,scripts/.docs/architecture/{index,domains,dependency-rules,data-flow,testing}.md, ADRs 0001/0002, andaudit-2026-09-22.md(baseline, verified findings, risks, ordered next work).@/alias;withUseron 9 of 35 routes; CI steps;checkruns tests;.jsspecifiers are the norm;fromLegacymay not use time/DB; guardrail-runtime allowlist;/devgating isproxy.ts;/signinhas no page; legacy test paths; duplicate guardrail numbers;getServerSession. Five self-declared-deprecated docs andDOC_REWRITE_TASK.mdremoved..gitignore: ignore.evidence/latest.json, stop ignoring the trackedscripts/audit/full-checkout-audit.mts, drop duplicate*.pem.docs/config-snapshot.mdregenerated forpackage.json,.gitignore, both registries.Testing
Node 24.15.0 (nvm),
npm ci,CHERRY_TMP_ROOTset,CHERRY_VINE_SIGNATURE_MODE=enforce.npm run checknpm testnpm run buildnpm run check:domain-boundariestests/node/guardrails/{domain-boundaries,engine-prisma-import}.test.tsBaseline on
main(19ec86d): check 2m32s pass, test 2m58s pass (240 files), build pass only withCHERRY_VINE_SIGNATURE_MODE=enforce.Blocker, pre-existing, not introduced here.
check:side-effects:diffcomparesexpiresBydates inscripts/side-effects.allowlist.jsonagainst the HEAD commit date. All tenlegacy-comboentries expired on 2026-06-01, so any commit dated after that failsnpm run check(verified on this branch after committing:Legacy-combo entry expired (2026-06-01): lib/autopilot/engineDecisionId.ts).mainstill passes only because its HEAD is dated 2026-04-29. CI on this PR will be red at that guardrail. I did not extend the dates or weaken the check; that is a policy decision. Options: (a) remediate the ten files (remove time+persistence combos), or (b) set a newexpiresBywith an owner in a separateguardrails:commit. Everything else in the gate passed.Risk
lib/,app/, orcomponents/changed;lib/engine/AGENTS.mdandapp/api/AGENTS.mdare documentation.check:domain-boundariesfails on any new file underlib/,app/,components/,types/that no domain owns. Cost: one line in the manifest. Intentional.check:engine-prismais stricter than before (value imports of@prisma/client/lib/prismainlib/engine/**,lib/authority/**now fail). Current code passes.withUsernormalization, dead-module deletion, bank CSV history. Seedocs/architecture/audit-2026-09-22.md"Recommended next work".Engine Impact
lib/engine/AGENTS.mdis documentation only.