Skip to content

Commit e223146

Browse files
committed
Merge upstream main into vps2/f5-api-wiring
2 parents 7bc8549 + 7328cbf commit e223146

219 files changed

Lines changed: 20677 additions & 1966 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.coderabbit.yaml‎

Lines changed: 57 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,8 @@ chat:
1111
knowledge_base:
1212
web_search:
1313
enabled: true
14+
learnings:
15+
scope: local
1416

1517
reviews:
1618
profile: assertive
@@ -46,21 +48,28 @@ reviews:
4648
instructions: >-
4749
Act as an adversarial second-opinion reviewer. Verify PR claims against implementation and
4850
contracts. Trace changed inputs through normal, boundary, error, cancellation, retry, and
49-
default paths and their consumers. Seek plausible counterexamples and regressions from removed
50-
safeguards. Identify assumptions in changed code that depend on facts outside the diff. First
51-
verify repository conventions, tests, and related implementations. When a potential finding
52-
depends on external behavior, use web search and prefer official documentation, specifications,
53-
or upstream repositories. Report only concrete, actionable conflicts or failure modes, citing
54-
the relevant repository location or external source. Prioritize correctness, security, data loss,
55-
lifecycle, and test gaps. Do not report generic best practices, unsupported concerns, speculative
56-
style comments, or unrelated refactors. Search for existing helpers before suggesting abstractions.
51+
default paths and their direct test counterparts. Do not flag defects in files not changed by
52+
this PR unless the defect is directly triggered by changed code and cannot be detected in the
53+
changed file alone. Seek plausible counterexamples and regressions from removed safeguards.
54+
Identify assumptions in changed code that depend on facts outside the diff. First verify
55+
repository conventions, tests, and related implementations. When a potential finding depends on
56+
external behavior, use web search and prefer official documentation, specifications, or upstream
57+
repositories. Report only concrete, actionable conflicts or failure modes, citing the relevant
58+
repository location or external source. Prioritize correctness, security, data loss, lifecycle,
59+
and test gaps. Do not report generic best practices, unsupported concerns, speculative style
60+
comments, or unrelated refactors. When changed code introduces a local implementation of a
61+
cross-cutting concern, check whether it bypasses or duplicates an established repository
62+
abstraction or nearby convention. Report only a concrete inconsistency with behavioral or
63+
maintenance impact, and allow intentional deviations.
5764
5865
- path: "**/*.{ts,tsx,js,jsx,mts,mjs,cts,cjs}"
5966
instructions: >-
6067
Check strict typing and exhaustive behavior across normal, boundary, error,
6168
cancellation, retry, and compatibility paths. Verify promises and errors are handled,
6269
existing helpers are reused, and new code introduces no `any`, unjustified double
6370
assertions, floating promises, duplicated helpers, or increased lint suppressions.
71+
When a refactor adds early-return guards that redirect a subset of inputs to a new
72+
code path, confirm the old branches for those inputs are removed or unreachable.
6473
6574
- path: "{**/*.{test,spec}.{ts,tsx,js,jsx},**/__tests__/**}"
6675
instructions: >-
@@ -76,6 +85,11 @@ reviews:
7685
Flag tests that assert in-flight behavior only after the call completes — these cannot
7786
prove the behavior fires during execution. Check that describe block names match the
7887
actual subjects of the tests they contain.
88+
For tests that assert only mock call counts, confirm a corresponding return-value
89+
assertion exists; a regression that silently returns stale fallback data can satisfy
90+
a call-count check. For code with fallback behavior, verify both the cold-start case
91+
(no prior state) and the warm case (prior state exists) are covered, as they exercise
92+
different branches.
7993
8094
- path: "apps/vscode-e2e/**"
8195
instructions: >-
@@ -115,6 +129,9 @@ reviews:
115129
Check persistence and lifecycle invariants: awaited atomic writes, rollback or explicit
116130
partial-failure behavior, cross-window state consistency, stale listeners/watchers,
117131
cancellation, idempotency, and safe restart/resume without lost or duplicated state.
132+
For async functions that read shared mutable state before an `await` and write it back
133+
after, verify the captured reference is still valid when the write executes; a concurrent
134+
mutation during the await can cause a stale snapshot to overwrite a newer state.
118135
119136
- path: ".github/**"
120137
instructions: >-
@@ -128,8 +145,20 @@ reviews:
128145
during release preparation. Verify documentation describes real behavior and contracts,
129146
and deprioritize prose-only nits that do not affect correctness or usability.
130147
148+
finishing_touches:
149+
docstrings:
150+
enabled: false
151+
131152
pre_merge_checks:
132153
override_requested_reviewers_only: true
154+
docstrings:
155+
mode: off
156+
title:
157+
mode: warning
158+
description:
159+
mode: warning
160+
issue_assessment:
161+
mode: error
133162
custom_checks:
134163
- name: Regression evidence
135164
mode: warning
@@ -140,18 +169,32 @@ reviews:
140169
snapshot. Do not demand tests for unchanged behavior, mechanical configuration, or every
141170
branch without a plausible regression scenario. Cite the changed behavior and missing
142171
evidence.
143-
- name: Trust and persistence invariants
172+
- name: Security boundaries
173+
mode: error
174+
instructions: >-
175+
Fail only when a concrete changed path leaks secrets or PII, trusts or executes
176+
unvalidated input, or bypasses approval or allowlist controls. Cite the changed path
177+
and a plausible triggering scenario; pass when no such changed path exists.
178+
- name: Persistence integrity
144179
mode: error
145180
instructions: >-
146-
Fail only for a concrete changed path that leaks secrets or PII, trusts or executes
147-
unvalidated input, bypasses approval or allowlist controls, can lose persisted state due
148-
to a missing await, non-atomic write, or omitted default propagation, or leaks lifecycle
149-
resources. Cite the path and a plausible triggering scenario; pass when no such changed
150-
path exists.
181+
Fail only when a concrete changed persistence path can lose or corrupt state because an
182+
operation is not awaited, a write is non-atomic, rollback or explicit partial-failure
183+
behavior is missing, or a persisted default is not propagated to a consumer. Cite the
184+
changed path and a plausible triggering scenario; pass when no such changed path exists.
185+
- name: Lifecycle resource cleanup
186+
mode: warning
187+
instructions: >-
188+
Fail only when a concrete changed lifecycle path can leak a listener, watcher, provider,
189+
timer, task, or other resource, or can duplicate work after cancellation, disposal, or
190+
restart. Cite the changed path and a plausible triggering scenario; pass when no such
191+
changed path exists.
151192
152193
tools:
153194
eslint:
154195
enabled: true
196+
github-checks:
197+
enabled: true
155198
actionlint:
156199
enabled: true
157200
shellcheck:

‎.github/workflows/code-qa.yml‎

Lines changed: 71 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -90,8 +90,12 @@ jobs:
9090
run: pnpm lint
9191
- name: Check types
9292
run: pnpm check-types
93+
- name: Validate Code QA workflow
94+
run: pnpm test:code-qa-ci
9395
- name: Model-check task lifecycle protocols
9496
run: pnpm lifecycle:model-check
97+
- name: Validate MCP OAuth integration
98+
run: pnpm mcp:integration-check
9599

96100
build-vsix:
97101
name: Build test VSIX
@@ -123,17 +127,21 @@ jobs:
123127
unit-test:
124128
name: platform-unit-test (${{ matrix.name }})
125129
runs-on: ${{ matrix.os }}
130+
concurrency:
131+
# Duplicate runs for one commit must not race the OS-specific Turbo cache save.
132+
group: unit-test-${{ github.repository }}-${{ github.sha }}-${{ matrix.name }}
133+
cancel-in-progress: false
126134
strategy:
127135
matrix:
128136
include:
129137
- os: ubuntu-latest
130138
name: ubuntu-latest
131139
codecov-flag: ubuntu
132-
upload-coverage: true
140+
collect-coverage: true
133141
- os: windows-latest
134142
name: windows-latest
135143
codecov-flag: windows
136-
upload-coverage: false
144+
collect-coverage: false
137145
steps:
138146
- name: Checkout code
139147
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
@@ -148,12 +156,56 @@ jobs:
148156
restore-keys: |
149157
${{ runner.os }}-turbo-${{ hashFiles('**/pnpm-lock.yaml') }}-
150158
${{ runner.os }}-turbo-
151-
- name: Run non-core coverage
152-
run: pnpm turbo run test:coverage --filter="!@roo-code/core" --log-order grouped --output-logs new-only
159+
# Windows never uploads coverage, so Windows runs the same test
160+
# suites through the uninstrumented Turbo tasks. Ubuntu stays the
161+
# authoritative coverage lane.
162+
- name: Run non-extension package coverage
163+
if: matrix.collect-coverage
164+
run: pnpm turbo run test:coverage --filter="!@roo-code/core" --filter="!zoo-code" --log-order grouped --output-logs new-only
165+
- name: Run non-extension package tests
166+
if: ${{ !matrix.collect-coverage }}
167+
run: pnpm turbo run test --filter="!@roo-code/core" --filter="!zoo-code" --log-order grouped --output-logs new-only
168+
- name: Run extension coverage lanes
169+
if: matrix.collect-coverage
170+
run: pnpm turbo run test:coverage:api test:coverage:core test:coverage:services test:coverage:misc test:coverage:tree-sitter --filter="zoo-code" --concurrency=2 --log-order grouped --output-logs new-only
171+
- name: Run extension test lanes
172+
if: ${{ !matrix.collect-coverage }}
173+
run: pnpm turbo run test:api test:core test:services test:misc test:tree-sitter --filter="zoo-code" --concurrency=2 --log-order grouped --output-logs new-only
174+
- name: Verify extension coverage contract
175+
if: matrix.collect-coverage
176+
run: pnpm --dir src run verify:coverage-contract
177+
- name: Run extension dist smoke test
178+
run: pnpm turbo run test:dist --filter="zoo-code" --log-order grouped --output-logs new-only
153179
- name: Run core unit coverage
180+
if: matrix.collect-coverage
154181
run: pnpm turbo run test:coverage:unit --filter="@roo-code/core" --log-order grouped --output-logs new-only
182+
- name: Run core unit tests
183+
if: ${{ !matrix.collect-coverage }}
184+
run: pnpm turbo run test:unit --filter="@roo-code/core" --log-order grouped --output-logs new-only
155185
- name: Run core integration coverage
186+
if: matrix.collect-coverage
156187
run: pnpm turbo run test:coverage:integration --filter="@roo-code/core" --log-order grouped --output-logs new-only
188+
- name: Run core integration tests
189+
if: ${{ !matrix.collect-coverage }}
190+
run: pnpm turbo run test:integration --filter="@roo-code/core" --log-order grouped --output-logs new-only
191+
- name: Verify extension coverage reports
192+
if: matrix.collect-coverage
193+
run: |
194+
node src/scripts/verify-lcov.mjs src/coverage/api/lcov.info
195+
node src/scripts/verify-lcov.mjs src/coverage/core/lcov.info
196+
node src/scripts/verify-lcov.mjs src/coverage/services/lcov.info
197+
node src/scripts/verify-lcov.mjs src/coverage/misc/lcov.info
198+
node src/scripts/verify-lcov.mjs src/coverage/tree-sitter/lcov.info
199+
- name: Merge extension coverage reports
200+
if: matrix.collect-coverage
201+
run: |
202+
mkdir -p src/coverage/merged
203+
pnpm --dir src run merge:coverage
204+
node src/scripts/verify-lcov.mjs src/coverage/merged/lcov.info
205+
# Validate cache boundaries before publishing any new Turbo entries.
206+
- name: Verify coverage cache inputs
207+
if: matrix.collect-coverage
208+
run: pnpm --dir src run verify:coverage-cache-inputs
157209
- name: Save Turbo cache
158210
if: steps.turbo-cache.outputs.cache-hit != 'true'
159211
uses: actions/cache/save@55cc8345863c7cc4c66a329aec7e433d2d1c52a9 # v6.1.0
@@ -165,54 +217,58 @@ jobs:
165217
# there mostly adds Codecov overhead without changing pass/fail
166218
# behavior.
167219
# Coverage is uploaded in separate steps so each LCOV gets the
168-
# correct flag set. Codecov double-counts overlapping lines when a
169-
# single upload carries multiple flags whose paths overlap, so the
170-
# core lanes and webview lane must be uploaded individually with
171-
# their own flag.
220+
# correct flag set. Extension lanes instrument the same sources, so
221+
# union them before upload; a line is covered when any lane executes
222+
# it. Core and webview reports retain their independent flags.
172223
# See https://docs.codecov.com/docs/flags
173224
- name: Upload non-core coverage to Codecov
174-
if: matrix.upload-coverage
225+
if: matrix.collect-coverage
175226
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
176227
with:
177228
files: >-
178-
src/coverage/lcov.info,
229+
src/coverage/merged/lcov.info,
179230
packages/cloud/coverage/lcov.info,
180231
packages/telemetry/coverage/lcov.info,
181232
apps/cli/coverage/lcov.info
182233
disable_search: true
183234
flags: ${{ matrix.codecov-flag }}
184235
token: ${{ secrets.CODECOV_TOKEN }}
185236
- name: Upload webview JSDOM coverage to Codecov
186-
if: matrix.upload-coverage
237+
if: matrix.collect-coverage
187238
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
188239
with:
189240
files: webview-ui/coverage/lcov.info
190241
disable_search: true
191242
flags: webview-ui
192243
token: ${{ secrets.CODECOV_TOKEN }}
193244
- name: Upload core unit coverage to Codecov
194-
if: matrix.upload-coverage
245+
if: matrix.collect-coverage
195246
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
196247
with:
197248
files: packages/core/coverage/unit/lcov.info
198249
disable_search: true
199250
flags: ${{ matrix.codecov-flag }},core-unit
200251
token: ${{ secrets.CODECOV_TOKEN }}
201252
- name: Upload core integration coverage to Codecov
202-
if: matrix.upload-coverage
253+
if: matrix.collect-coverage
203254
uses: codecov/codecov-action@fb8b3582c8e4def4969c97caa2f19720cb33a72f # v7.0.0
204255
with:
205256
files: packages/core/coverage/integration/lcov.info
206257
disable_search: true
207258
flags: ${{ matrix.codecov-flag }},core-integration
208259
token: ${{ secrets.CODECOV_TOKEN }}
209260
- name: Upload coverage reports to GitHub
210-
if: matrix.upload-coverage
261+
if: matrix.collect-coverage
211262
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
212263
with:
213264
name: coverage-reports-${{ matrix.name }}
214265
path: |
215-
src/coverage/lcov.info
266+
src/coverage/api/lcov.info
267+
src/coverage/core/lcov.info
268+
src/coverage/services/lcov.info
269+
src/coverage/misc/lcov.info
270+
src/coverage/tree-sitter/lcov.info
271+
src/coverage/merged/lcov.info
216272
webview-ui/coverage/lcov.info
217273
packages/cloud/coverage/lcov.info
218274
packages/telemetry/coverage/lcov.info

0 commit comments

Comments
 (0)