Skip to content
Closed
Show file tree
Hide file tree
Changes from 3 commits
Commits
Show all changes
29 commits
Select commit Hold shift + click to select a range
bace9bf
chore: make local admission resource safe
qnbs Aug 24, 2026
a3287ed
fix: avoid cache key secret scan false positive
qnbs Aug 24, 2026
a656835
fix: harden local admission policy checks
qnbs Aug 24, 2026
e295616
fix: close admission review gaps
qnbs Aug 24, 2026
c36b9f0
fix: close admission review gaps
qnbs Aug 24, 2026
3445f7e
fix: harden admission review controls
qnbs Aug 24, 2026
cef5001
fix: close admission review gaps
qnbs Aug 24, 2026
b4f281b
fix: harden admission edge cases
qnbs Aug 24, 2026
591671e
fix: close local admission review gaps
qnbs Aug 24, 2026
43f3565
fix: harden bounded admission cleanup
qnbs Aug 24, 2026
9ce0697
fix: close workflow and admission review gaps
qnbs Aug 24, 2026
71fa70f
fix: close admission trigger review gaps
qnbs Aug 24, 2026
161550e
fix: harden local admission termination and release policy checks
qnbs Aug 24, 2026
a4117a4
fix: fail closed on unresolved admission state
qnbs Aug 24, 2026
bd9f10d
fix: close review gaps in admission policy guards
qnbs Aug 24, 2026
35adf7f
fix: harden qualification and diff policy checks
qnbs Aug 24, 2026
8a5ab2d
fix: close release mutation and aggregate guard gaps
qnbs Aug 24, 2026
0947aa3
fix: close latest review gaps in local admission
qnbs Aug 24, 2026
d017ee8
fix: close scanner descriptors on allocation failure
qnbs Aug 24, 2026
811d391
fix: close workflow policy bypass classes
qnbs Aug 24, 2026
cad6b34
fix: normalize quoted workflow policy keys
qnbs Aug 24, 2026
1807529
fix: close review policy edge cases
qnbs Aug 24, 2026
b303cb2
fix: close admission review edge cases
qnbs Aug 24, 2026
05359d5
fix: close subprocess and workflow policy races
qnbs Aug 24, 2026
52fb719
refactor: converge local admission authorities
qnbs Aug 24, 2026
e4c285e
fix: close exact-tree admission review findings
qnbs Aug 24, 2026
d93e992
fix: close process and workflow policy review findings
qnbs Aug 24, 2026
df19fae
fix: close latest workflow admission findings
qnbs Aug 24, 2026
9bbeded
fix: close final workflow admission review findings
qnbs Aug 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .cursor/rules/800-testing-standards.mdc
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ alwaysApply: false

| Tier | Befehle |
|------|---------|
| **Lokal schnell** | `lint`, `typecheck`, `i18n:check`; optional `pnpm exec vitest run` **ohne** `--coverage` |
| **Lokal schnell** | `pnpm run ci:prepush` (änderungsbewusst; `DEFERRED_TO_REQUIRED_CI` für Docs/Workflows/Tooling); optional `pnpm exec vitest run <path>` **ohne** `--coverage` |
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Outdated
| **CI schwer** | Vitest **mit** Coverage (Schwellen 63/55/54/62 — lines/branches/functions/statements), `CI=true pnpm run test:e2e`, LHCI, `bundle:budget` |

- Merge-Bar = **grüner GitHub-Workflow**, nicht voller lokaler E2E auf schwacher Hardware.
Expand Down
2 changes: 1 addition & 1 deletion .cursorrules
Original file line number Diff line number Diff line change
Expand Up @@ -63,7 +63,7 @@ Kurz und konkret:

- Wenn der Nutzer **Deutsch** wünscht: Antworten auf **Deutsch**; Code- und API-Bezeichner unverändert nach Repo-Konvention.
- Zusätzliche Repo-Leitplanken: **`.cursor/index.mdc`** (Manifest, `alwaysApply`) und **`.cursor/rules/*.mdc`** (001 Security, 100 KI/Storage, 150 i18n/Content, 200 Architektur, 300 UI, 800 Testing, 850 Doku/MCP). Nach Code-Änderungen optional **`pnpm run graphify:update`** bzw. `graphify:bootstrap`.
- Qualität lokal (schnell): `pnpm run lint`, `typecheck`, `i18n:check`; schwere Suites CI-first — siehe **`docs/CI.md`** und Regel **`800-testing-standards.mdc`**.
- Qualität lokal (schnell): `pnpm run ci:prepush` (änderungsbewusst; Docs/Workflow/Tooling-Diffs melden `DEFERRED_TO_REQUIRED_CI`), `node scripts/ci-prepush-lowend.mjs --full` auf leistungsfähiger Hardware; schwere Suites CI-first — siehe **`docs/CI.md`** und Regel **`800-testing-standards.mdc`**.
- Bestehende Projekt-Tools (z. B. **Biome**, **Vitest**, **Playwright**, **Vite**) vor neuen Hilfsmitteln bevorzugen.
- Keine unnötigen neuen Markdown-Dateien; Ausnahme: ausdrücklich gewünschte Doku (z. B. diese Rules).

Expand Down
4 changes: 2 additions & 2 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
Expand Up @@ -120,7 +120,7 @@ types.ts → Core shared interfaces and types
3. Implement the real **root-cause** fix (code **+ tests + i18n + docs**), or reply with evidence
if false-positive / by-design. **Never** add a new `biome-ignore` (suppression ratchet fails
CI — refactor instead; run `node scripts/check-suppressions.mjs`).
4. Local gate (sequential): lint + typecheck + targeted vitest green.
4. Local admission (sequential): `pnpm run ci:prepush`; it is change-aware and may explicitly defer TypeScript to required cloud CI for docs/workflow-only changes.
5. Commit + push; reply to **every** thread citing the resolving commit, then resolve it → **0 unresolved**.
6. Re-trigger: `gh pr comment <N> --body "@coderabbitai review"`; check the **full** review history,
not just the latest status (a rate-limited latest status can hide an earlier real review).
Expand Down Expand Up @@ -169,7 +169,7 @@ On any non-trivial code change add a single-line comment explaining **why**, not
- Conventional Commits format: `feat:`, `fix:`, `docs:`, `refactor:`, `test:`, `chore:`
- Pre-commit: after explicit `pnpm run hooks:install`, `simple-git-hooks` runs Biome on staged files; CI is mandatory regardless
- **⚠️ Constrained local hardware — do NOT run heavy suites locally.** This machine has ~3–4 GB RAM. **Never** run the full Vitest **coverage** suite, **Playwright E2E**, **Stryker mutation**, **Lighthouse CI**, or the **Storybook test-runner** locally — they are **CI-only by design**. Run **one heavy command at a time** (no parallel `vitest`/`biome`/`tsc`/`vite`).
- Local preflight (sequential, minimal): `pnpm run lint` → `pnpm run typecheck` → `pnpm run i18n:check` (only when locale JSON changed) → **targeted** `pnpm exec vitest run <path>` (no `--coverage`). Run `pnpm run build && pnpm run smoke:prod` only when you touched `vite.config.ts`, `packages/ai-core`, or `workers/`. Coverage, E2E, Lighthouse, Stryker, and Storybook are **CI gate jobs** — let GitHub Actions run them.
- Local preflight (sequential, minimal): `pnpm run ci:prepush` → optional targeted `pnpm exec vitest run <path>` (no `--coverage`). The admission gate classifies changes and reports `DEFERRED_TO_REQUIRED_CI` for provably docs/workflow/tooling-only TypeScript impact; use `node scripts/ci-prepush-lowend.mjs --full` on capable hardware. Run `pnpm run build && pnpm run smoke:prod` only when you touched `vite.config.ts`, `packages/ai-core`, or `workers/`. Coverage, E2E, Lighthouse, Stryker, and Storybook are **CI gate jobs** — let GitHub Actions run them.
- **Vitest watch-mode hard rule:** Never run `pnpm test`, `npm run test`, a bare Vitest command, or an untargeted wrapper. Always use `pnpm exec vitest run <path>`; CI is the only place that runs the full coverage suite.
- CI pipeline (see [`docs/CI.md`](../docs/CI.md)): **`security` → `quality`** (Biome + `tsc` + Vitest matrix) **→ `build` / `e2e` / `storybook` in parallel** → **`lighthouse`** after build → **`deploy`** on `main` after build+e2e
- Branch protection should require the **`quality`** job (and other checks your team enables); job ids match `.github/workflows/ci.yml`
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -189,6 +189,9 @@ jobs:
- name: Doc metrics drift gate (locale/key counts, stale PLANNED status)
run: pnpm run docs:check

- name: Workflow governance policy gate
run: node scripts/check-workflow-policy.mjs

- name: CSP source synchronization and parity
run: pnpm run csp:verify

Expand Down
132 changes: 132 additions & 0 deletions .github/workflows/tauri-intel-qualification.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,132 @@
# Non-publishing Intel qualification; this workflow never creates a release or latest.json.
name: Tauri Intel qualification

on:
workflow_dispatch:
inputs:
qualification_ref:
description: Exact branch, tag, or SHA to qualify (defaults to the dispatched ref)
required: false
type: string

permissions:
contents: read

concurrency:
group: tauri-intel-qualification-${{ github.ref }}
Comment thread
qnbs marked this conversation as resolved.
Outdated
cancel-in-progress: true

jobs:
qualify:
name: ${{ matrix.role }} (${{ matrix.runner }})
runs-on: ${{ matrix.runner }}
timeout-minutes: 60
strategy:
fail-fast: false
matrix:
include:
- runner: macos-15-intel
role: primary-production-candidate
- runner: macos-26-intel
role: advisory-forward-compatibility

steps:
- name: Check out the exact qualification ref
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
ref: ${{ inputs.qualification_ref || github.sha }}
fetch-depth: 1
persist-credentials: false
Comment thread
qnbs marked this conversation as resolved.

- name: Record source ref
run: |
set -euo pipefail
printf 'source_ref=%s\n' "$(git rev-parse HEAD)" > qualification-source.txt
printf 'requested_ref=%s\n' "${{ inputs.qualification_ref || github.sha }}" >> qualification-source.txt
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Outdated
cat qualification-source.txt

- uses: ./.github/actions/setup

- uses: dtolnay/rust-toolchain@29eef336d9b2848a0b548edc03f92a220660cdb8 # stable

- uses: Swatinem/rust-cache@f0d9c3887740aee45f6153b24b3a6b815192ec16 # v2
with:
workspaces: src-tauri
cache-all-crates: true
prefix-key: "intel-qual-v1"

- name: Install macOS packaging dependency
run: brew install create-dmg

- name: Prepare non-publishing bundle configuration
run: |
set -euo pipefail
# QNBS-v3: qualification must not publish or mutate release metadata.
jq '.bundle.createUpdaterArtifacts = false' src-tauri/tauri.conf.json > src-tauri/tauri.conf.json.tmp
mv src-tauri/tauri.conf.json.tmp src-tauri/tauri.conf.json
printf 'updater_artifacts=disabled\n' > qualification-config.txt
printf 'release_publication=disabled\n' >> qualification-config.txt
cat qualification-config.txt

- name: Build non-publishing Tauri bundle
run: |
set -euo pipefail
pnpm exec tauri build

- name: Verify Intel architecture and deployment target
shell: bash
run: |
set -euo pipefail
test "$(uname -s)" = "Darwin"
host_arch="$(uname -m)"
test "$host_arch" = "x86_64"

app="$(find src-tauri/target/release/bundle -type d -name '*.app' -print -quit)"
test -n "$app"
executable_name="$(/usr/libexec/PlistBuddy -c 'Print :CFBundleExecutable' "$app/Contents/Info.plist")"
executable="$app/Contents/MacOS/$executable_name"
test -x "$executable"

file "$executable" | tee qualification-file.txt
grep -Eq 'x86_64|64-bit executable' qualification-file.txt
lipo -info "$executable" | tee qualification-lipo.txt
grep -Eq 'x86_64|Non-fat file' qualification-lipo.txt
Comment thread
qnbs marked this conversation as resolved.
Outdated

load_commands="$(otool -l "$executable")"
printf '%s\n' "$load_commands" > qualification-otool.txt
minimum_os="$(awk '/LC_BUILD_VERSION/{mode="build"; next} /LC_VERSION_MIN_MACOSX/{mode="legacy"; next} mode == "build" && $1 == "minos"{print $2; exit} mode == "legacy" && $1 == "version"{print $2; exit}' qualification-otool.txt)"
test "$minimum_os" = "11.0"

dmg="$(find src-tauri/target/release/bundle -type f -name '*.dmg' -print -quit)"
test -n "$dmg"
test -s "$dmg"

cat > qualification-result.json <<EOF
{
"runner": "${{ matrix.runner }}",
"role": "${{ matrix.role }}",
"sourceRef": "$(git rev-parse HEAD)",
"hostArchitecture": "$host_arch",
"binaryArchitecture": "x86_64",
"minimumMacOS": "$minimum_os",
"appBundle": "$app",
"dmg": "$dmg",
"updaterBundle": "NOT_PRODUCED: non-publishing qualification",
Comment thread
qnbs marked this conversation as resolved.
"releasePublication": false
}
EOF
cat qualification-result.json

- name: Upload qualification evidence
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
Comment thread
qnbs marked this conversation as resolved.
with:
name: tauri-intel-qualification-${{ matrix.runner }}
path: |
qualification-source.txt
qualification-config.txt
qualification-result.json
qualification-file.txt
qualification-lipo.txt
qualification-otool.txt
if-no-files-found: error
retention-days: 30
3 changes: 3 additions & 0 deletions .gitleaks.toml
Original file line number Diff line number Diff line change
Expand Up @@ -26,10 +26,13 @@ useDefault = true
# archive caching — static, non-secret cache-namespace strings. Flagged by the same generic-api-key
# heuristic: YAML `key:` field name next to a hyphenated alphanumeric string. Reviewed 2026-08-19:
# both are cache keys with a fixed literal suffix (`-v1`), not credentials.
# intel-qualification-v1 was the original non-secret Rust-cache namespace in this PR; the current
# workflow uses intel-qual-v1, but the historical commit remains in the PR scan range.
[allowlist]
description = "Cache-key / record-key literals flagged by generic-api-key's key-adjacent-string heuristic — not credentials"
regexes = [
'''^idb_passphrase_sentinel_v1$''',
'''^apt-cef-harness-deps-v1$''',
'''^apt-tauri-linux-deps-v1$''',
'''^intel-qualification-v1$''',
]
9 changes: 6 additions & 3 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ The app supports a multi-provider AI stack (Gemini, OpenAI, Claude, Grok, OpenRo
```bash
pnpm run ci:prepush
```
This gate is mandatory before every push and after every local correction before re-pushing; it runs sequentially with a single-checker project typecheck, i18n parity/quality and bundle checks, release/doc truth, and lightweight native guardrails. The pre-commit hook separately runs staged-file Biome checks. Full repository lint, coverage, E2E, Storybook, Lighthouse, and mutation checks belong to cloud CI. If branch switching or a lockfile/package-manifest change makes pnpm report dependency verification errors, run `node scripts/dependency-state.mjs reconcile` and rerun the complete pre-push gate.
This gate is mandatory before every push and after every local correction before re-pushing; it is change-aware: docs/workflow/tooling-only changes explicitly defer TypeScript to required CI, while application, contract, dependency, build, mixed, or ambiguous changes run bounded single-checker `tsgo` locally. It always runs the cheap policy guards applicable to the change. The pre-commit hook separately runs staged-file Biome checks. Full repository lint, coverage, E2E, Storybook, Lighthouse, and mutation checks belong to cloud CI. Use `node scripts/ci-prepush-lowend.mjs --full` for complete local admission on capable hardware. If branch switching or a lockfile/package-manifest change makes pnpm report dependency verification errors, run `node scripts/dependency-state.mjs reconcile` and rerun the complete pre-push gate.
Optional targeted smoke test: `pnpm exec vitest run <path>` **without** `--coverage`.
**Hard rule:** Never invoke `pnpm test`, `npm run test`, or a bare Vitest wrapper; always use an explicit `pnpm exec vitest run <path>` command to avoid watch-mode hangs on constrained hardware. Never start multiple heavyweight processes concurrently.
4. **Audit cloud CI logs, fix locally, then re-push** – If the cloud CI run fails, inspect the logs via GitHub web UI or `gh run watch`, reproduce the specific failing test or lint error in isolation, fix it locally (quick tier to verify), commit, and push again for another cloud CI run.
Expand Down Expand Up @@ -295,8 +295,11 @@ procedure.
### Philosophy

- **Cloud CI-first:** The canonical quality gate is GitHub Actions. Low-end local machines should run only the "Quick" tier.
- **Quick tier (local, before every push):** `pnpm run ci:prepush` runs the project typecheck with
one checker, i18n parity/quality/bundle/content checks, release/doc truth, and lightweight desktop guardrails sequentially;
- **Quick tier (local, before every push):** `pnpm run ci:prepush` performs change-aware admission with
bounded policy checks. It runs one-checker TypeScript validation only for TypeScript-impacting,
dependency, build, native-contract, mixed, or ambiguous changes. For provably docs/workflow-only
changes it reports `DEFERRED_TO_REQUIRED_CI` rather than launching a full project scan. The complete
local tier is `node scripts/ci-prepush-lowend.mjs --full` on capable hardware;
the pre-commit hook separately runs staged-file Biome checks. Run the gate again after every
correction before re-pushing; do not
push based only on a targeted test or a changed-file lint run. Optionally:
Expand Down
8 changes: 5 additions & 3 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,9 @@ pnpm run build # Production build to dist/
pnpm run smoke:prod # Headless mount check on dist/ (run AFTER build; catches prod-only crashes)
pnpm run lint # Biome lint (--error-on-warnings — warnings fail like CI)
pnpm run lint:fix # Biome auto-fix (lint + format)
pnpm run typecheck # TypeScript type check — EXACT CI command (tsgo --project tsconfig.tsgo.json --noEmit --checkers 4). typecheck:single = lighter single-checker (may miss errors the gate catches; do not trust for the gate)
pnpm run typecheck # Full TypeScript check (cloud quality authority; tsgo --project tsconfig.tsgo.json --noEmit --checkers 4)
pnpm run ci:prepush # Change-aware local admission; docs/workflow-only changes defer TS to required CI
node scripts/ci-prepush-lowend.mjs --full # Complete local admission on capable hardware
pnpm exec vitest run <path> # Targeted Vitest single run (CI mode)
pnpm exec vitest run <path> --coverage # Targeted Vitest coverage run
pnpm run bench # Vitest perf benchmarks (tests/bench) — baseline gate for the Y.Doc-as-SoT / Local-First migration
Expand All @@ -41,9 +43,9 @@ pnpm run token:audit # audit-tokens.mjs — design-token usage gate (CI b

**Vitest watch-mode hard rule:** Never invoke `pnpm test`, `npm run test`, or a bare Vitest wrapper. Always use an explicit targeted `pnpm exec vitest run <path>` command; watch mode hangs the constrained development hardware.

**Mandatory pre-push gate:** Run `pnpm run ci:prepush` before every push and again after every local correction before re-pushing. It runs the full repository lint, then the exact CI typecheck and i18n checks sequentially. A targeted test or changed-file lint run alone is insufficient. If pnpm reports dependency verification after a branch or lockfile change, run `pnpm install --frozen-lockfile` first. The pre-commit hook does not replace this gate.
**Mandatory pre-push gate:** Run `pnpm run ci:prepush` before every push and again after every local correction before re-pushing. It performs change-aware, bounded local admission and emits explicit `PASS`, `FAIL`, `DEFERRED_TO_REQUIRED_CI`, or `LOCAL_RESOURCE_FAILURE` states. Docs/workflow/tooling-only changes do not launch the full TypeScript project scan; required GitHub CI remains the merge authority. Use `node scripts/ci-prepush-lowend.mjs --full` for complete local admission on capable hardware. If pnpm reports dependency verification after a branch or lockfile change, run `pnpm run deps:reconcile` first. The pre-commit hook does not replace this gate.

**Quality gate (local pre-push subset):** `pnpm run ci:prepush` runs the full repository lint followed by the exact CI typecheck and i18n checks; CI additionally runs full-suite coverage and heavy jobs. Locally use only the targeted form `pnpm exec vitest run <path> --coverage` when debugging coverage. Full pipeline graph: [`docs/CI.md`](docs/CI.md). Coverage thresholds: lines 74, branches 60, functions 67, statements 72 (see `vitest.config.ts`).
**Quality gate (local pre-push subset):** `pnpm run ci:prepush` runs applicable policy guards and only the TypeScript validation justified by the outgoing change class; deferred TypeScript is explicitly closed by required cloud CI. CI additionally runs full-suite coverage and heavy jobs. Full pipeline graph: [`docs/CI.md`](docs/CI.md). Coverage thresholds: lines 74, branches 60, functions 67, statements 72 (see `vitest.config.ts`).
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Outdated

**CI pipeline order:** `security` → `quality` (Biome + tsgo + Vitest matrix) → `build` / `e2e` / `storybook` (parallel) → `lighthouse` (after build) → `deploy` on `main`. `ci-success` is a required-status aggregator (`needs: [security, quality, build]`) so branch protection can require one context instead of three/four individual ones — see `docs/CI.md`. Two additional jobs run in parallel with `quality`, both path-scoped via the `changes` job (legitimately `skipping` on PRs that don't touch their directory, which `ci-success` treats as a pass for that job only): `rust-tauri` (`src-tauri/**` — fmt/check/clippy/test, needs the GTK/WebKit apt-get steps) and `core-rust` (`crates/**` — same fmt/check/clippy/test for the renderer-neutral Rust Core, no GUI deps so no apt-get steps needed).

Expand Down
Loading
Loading