Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .coderabbit.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,9 @@ reviews:
- path: "**/*.{ts,tsx,js,jsx,mjs,cjs,sh,zsh}"
instructions: |
Apply `.github/review-bot-rules/runtime-no-hacky-sleeps.md` during review. For production runtime, script, and build changes, flag fixed sleeps, timers, delayed dispatch, polling, or wall-clock waits used as synchronization. Pass for tests, pure presentation timing, dedicated cancellation-aware retry/timeout abstractions with tests, and existing delay code not worsened.
- path: "**/*.{swift,ts,tsx,js,jsx,mjs,cjs}"
instructions: |
Apply `.github/review-bot-rules/user-facing-errors.md` during review. For production user-facing errors, alerts, command output, API error bodies, and recovery copy, flag implementation leaks such as upstream vendor names, internal provider names, environment variables, database or migration details, raw upstream messages, internal billing ids, or unredacted payloads.

pre_merge_checks:
custom_checks:
Expand Down Expand Up @@ -56,6 +59,10 @@ reviews:
mode: error
instructions: |
For production Swift changes, fail when the diff violates `.github/review-bot-rules/swift-logging.md`: `print`, `debugPrint`, `dump`, or `NSLog` in app/runtime code; ad hoc file/stdout logging for diagnostics; MainActor-coupled file-scoped Logger constants; or logs that expose secrets or personal data. Do not require new logs for new code paths; only check logging that the diff adds or materially changes. Pass for CLI output, tests, debug-only logs, and explicitly sanitized provider diagnostics.
- name: "cmux user-facing error privacy"
mode: error
instructions: |
For production changes, fail when the diff violates `.github/review-bot-rules/user-facing-errors.md`: user-facing errors, alerts, command output, API error bodies, or recovery copy must not expose upstream vendor names, internal provider names, provider-specific flags, templates, snapshots, manifests, environment variables, database or migration details, raw upstream messages, billing item ids, billing customer ids, unrelated team ids, credentials, tokens, headers, private keys, refresh tokens, session ids, or unredacted payload dumps. Pass for tests, docs, operational runbooks, developer-only comments, safe generic terms like billing/team/Cloud VM service, and explicitly advanced help text for user-configured settings.
Comment thread
coderabbitai[bot] marked this conversation as resolved.
- name: "cmux SwiftUI state layout"
mode: error
instructions: |
Expand Down
1 change: 1 addition & 0 deletions .github/review-bot-rules/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,5 +18,6 @@ Current rules:
- `swift-file-package-boundaries.md`
- `swift-logging.md`
- `swiftui-state-layout.md`
- `user-facing-errors.md`

Open source repository note: review bots should apply the configuration from the base branch. A PR that edits these rules should not be able to weaken its own review.
23 changes: 23 additions & 0 deletions .github/review-bot-rules/user-facing-errors.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
# User-Facing Error Messages

Flag production changes that add or materially change user-facing errors, alerts, command output, API error bodies, or recovery copy when they expose implementation details.

Fail when user-facing text includes:

- Upstream vendor or service names unless the user explicitly configured that vendor in the product UI.
- Internal provider names, provider-specific flags, templates, snapshots, manifests, environment variable names, database or migration details.
- Raw upstream error messages, stack traces, request ids from third-party systems, billing item ids, billing customer ids, or team ids unless the user supplied that exact id in the request.
- Secret material, credentials, tokens, headers, private keys, refresh tokens, session ids, or unredacted payload dumps.

Expected shape:

- State what happened in cmux/product terms.
- Give one or two concrete next actions the user can take.
- Put only safe, minimal diagnostics in `details`.
- Keep provider, billing, database, and auth implementation details in sanitized logs or internal telemetry, not in user-visible text.

Allowed cases:

- Developer-only comments, tests, docs, and operational runbooks that are not shown to end users.
- Existing public CLI flags or config keys in help text when the user asked for advanced configuration help.
- Generic terms such as "billing", "team", "Cloud VM service", or "Cloud VM state".
9 changes: 9 additions & 0 deletions .greptile/rules.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,3 +15,12 @@ Review production Swift and runtime changes for:
- Production logging that bypasses unified logging or leaks sensitive data.
- SwiftUI state and layout patterns that cause stale state, broad invalidation, or render-time mutation.
- Architectural fixes that patch symptoms while leaving bad state representable.
- User-facing errors, alerts, command output, API error bodies, and recovery copy that expose implementation details.

## User-Facing Error Messages

For production user-facing errors, alerts, command output, API error bodies, and recovery copy, do not expose implementation details.

Flag copy that includes upstream vendor or service names, internal provider names, provider-specific flags, templates, snapshots, manifests, environment variable names, database or migration details, raw upstream error messages, stack traces, request ids from third-party systems unless the user supplied that exact id, billing item ids, billing customer ids, team ids not supplied by the user, credentials, tokens, headers, private keys, refresh tokens, session ids, or unredacted payload dumps.

Error copy should say what happened in cmux terms, provide concrete user actionables, and keep only safe minimal diagnostics in `details`. Provider, billing, database, and auth implementation details belong in sanitized logs or internal telemetry.
Loading
Loading