Skip to content

improvement(audits): enforce console, helper, render-path, persist, and deployment-flag rules - #8559

Merged
waleedlatif1 merged 15 commits into
stagingfrom
improvement/guardrails-wave-2
Oct 2, 2026
Merged

waleedlatif1 merged 15 commits into
stagingfrom
improvement/guardrails-wave-2

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

Enforces written rules that no check covered, without adding scripts: every rule is a Biome rule or a pattern in an existing audit, and every existing violation is fixed (no baselines).

  • noConsole (Biome, error, no autofix) for runtime code; off where console is the interface (scripts/, tests, CLIs, script migrations, the logger itself, SDK examples). Runtime hits now use createLogger (docs routes, OTEL exporter); two justified biome-ignores (the hydration handler wraps console.error; the test-env skip notice must reach the runner)
  • check:utils now bans the inline forms of toError, isRecordLike, omit/filterUndefined, conditional truncate, and the escapeRegExp regex; 21 files moved to the shared helpers (identical semantics). Allow annotations now work above formatter-wrapped statements
  • Client render-path rules in check:utils: ES2023 array methods (toSorted etc.) on client paths (server-only route/metadata files excluded), non-lazy useRef(new X()) incl. nested generics (≈38 sites moved to the (ref.current ??= new X()) idiom), and equal h-N w-N → size-N (85 pairs; same CSS)
  • check:zustand-v5: persist without a partialize whitelist (canvas-mode store fixed; persisted shape unchanged)
  • check:client-boundary: deployment-shape flags read from env-flags in client code ('use client' surfaces, stores/, hooks/, blocks/, namespace imports), flag list derived from deployment-shape.ts. The one existing exception, stores/panel/store.ts reading isChatEnabled at module init, carries a // client-boundary-allow: reason (needs a product decision)

Type of Change

  • Improvement (guardrails + behavior-preserving fixes)

Testing

  • bun run lint, bunx turbo run type-check, bun run check:audits, root bun run test; vitest on every touched area (home/stream, use-chat, composer, mcp oauth, workflow-diff, tables, browser-session, sim-cli, desktop, emcn)
  • Each detector proven to fail on a probe and to skip legitimate look-alikes
  • A shared scripts/source-kind.ts directive classifier is used by both client-path checks; the one exception (stores/panel/store.ts reading isChatEnabled at module init) uses the script's existing // client-boundary-allow: annotation. Two independent audits plus a /simplify pass: every helper swap is semantically identical; every useRef conversion has no reassignment, no pre-init read, and unchanged identity (children receiving a stable Map instead of a ref); size-* compiled with Tailwind 4 to identical CSS

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

🤖 Generated with Claude Code

Runtime code logs through createLogger from @sim/logger. Scripts, CLIs,
script-migrations, the logger itself, SDK examples, and tests keep console
as their interface. Autofix is disabled so lint --unsafe never silently
deletes a console call.
…nd width

useRef(new X()) built a throwaway X on every render; the refs now
lazy-init through ??= as sim-react-performance.md prescribes. Equal
h-N w-N pairs become size-N per sim-styling.md.
Adds toError, isRecordLike, filterUndefined, omit, truncate, and
escapeRegExp idioms from CLAUDE.md, plus render-path rules: ES2023
array methods in browser code, useRef(new X()), and h-N w-N pairs.
…persist

sim-stores.md requires persist to whitelist durable fields; check:zustand-v5
now fails on a persist with no partialize or one that spreads the whole
state. canvas-mode was the one store without it.
…t settings surfaces

check:client-boundary now fails when a 'use client' module under the
workspace, organization, or standalone settings surfaces imports isHosted,
isBillingEnabled, isChatEnabled, or an enterprise feature flag from
env-flags instead of reading the seeded deployment shape.
…al prefilters

The h-N/w-N, toError, and truncate patterns backtrack from every word
boundary; a cheap literal test per file keeps the scan at ~1s of CPU.
…missed

Allocate Map/Set ref containers once instead of on every render, and drop the
redundant processedRemovalIds alias in the toast provider.
…yment-shape rule

- check:utils: match useRef(new X()) with nested generics, honor utils-lint-allow
  above formatter-wrapped statements, drop h-screen/w-screen from the size-N rule,
  and skip server-only App Router files in the ES2023 rule
- deployment-shape rule: cover stores/, hooks/, blocks/ and surface hooks, read
  namespace imports, derive the flag list from deployment-shape.ts, parse long
  import clauses whole, and allowlist the panel store's module-init isChatEnabled
- zustand persist message names the hoisted-options escape
- biome: allow console in *.integration.ts, *.spec.ts, and desktop e2e
…k:utils

- move leadingDirective/directiveOn into scripts/source-kind.ts; check:utils uses it
  instead of its own 'use client' regex, and multi-line block-comment headers now parse
- replace the deployment-shape allowlist with a client-boundary-allow annotation on
  the panel store's isChatEnabled import
- exempt all of packages/utils/src by prefix (drops the stale retry.test.ts entry)
- build both truncate patterns from one shared fragment and prefilter
- add literal prefilters to isRecordLike, fromEntries, and useRef patterns and
  memoize prefilter results per file
- trim the deployment-shape rationale to a CLAUDE.md pointer
…els directly

useSpeechToText returns its stable, in-place-filled Float32Array instead of a
nullable ref; MicButton and the composer, search, and user-input props follow.
@waleedlatif1
waleedlatif1 requested a review from a team as a code owner October 2, 2026 07:36
@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 2, 2026 8:07am UTC

Request Review

@greptile-apps

greptile-apps Bot commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Low risk] Enforces code style rules across the codebase.

The PR appears safe to merge based on the issues reviewed.

Summary

The PR adds audits for shared-helper use, client compatibility, Zustand persistence, deployment flags, and console logging, with corresponding code changes. The changes since the previous review refine the persist-import audit and clarify the array-method guidance.

Reviews (3) · Last reviewed commit: "improvement(audits): follow aliased pers..."

Comment thread scripts/check-utils-enforcement.ts Outdated
Comment thread scripts/check-zustand-v5-selectors.ts

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 118 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread scripts/check-utils-enforcement.ts Outdated
Comment thread scripts/source-kind.ts Outdated
Comment thread scripts/check-zustand-v5-selectors.ts Outdated
Comment thread scripts/check-utils-enforcement.ts Outdated
…state partialize, strip inline directive comments
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 122 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread .claude/rules/sim-react-performance.md Outdated
Comment thread scripts/check-utils-enforcement.ts Outdated
Comment thread scripts/check-zustand-v5-selectors.ts Outdated
…== for filterUndefined, state the .with scope
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 122 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit 588b8ce into staging Oct 2, 2026
36 checks passed
@waleedlatif1
waleedlatif1 deleted the improvement/guardrails-wave-2 branch October 2, 2026 16:48

This branch was successfully deployed

1 active deployment
Preview — db24cc98 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant