mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
* fix(prompts): point agents at Makefile, drop raw uv run instructions backend.md:23-26 literally instructed raw uv run ruff/mypy/pytest (copied from the human-facing CLAUDE.md), so agents bypassed the Makefile's UV_NO_SYNC=1 + private UV_CACHE_DIR venv-corruption guard. Replace with make targets across backend/developer/qa/cell_pm + a universal rule in base.md. Regenerate verbs.md from the updated regen script (baked instruction now make foundation-check) and align the Makefile drift message. Ships with the bash-guard deny in the next commit so agents don't loop fighting the guard. * feat(bash-guard): deny raw uv/pip/conda/poetry, point at Makefile When a Makefile is present, deny raw uv run/uv pip/uv lock/add/remove, pip/pip3 install/uninstall, conda install/create/run, poetry run/install/add and remediate to make quality/gate/lint/test. Skipped when no Makefile (Makefile-less projects not blocked). ROBOCO_GUARD_SKIP_PM=1 (grok path) nudges exit 0 instead of the run-canceling exit 2. Overrides the prior bare-uv-run-allowed stance by CEO direction; the /app-targeted blocks above keep priority. * feat(grok): deny raw uv/pip/conda/poetry via native --deny + PM-skip nudge Add _RAW_PM_DENY (uv run/pip install/lock/add/remove, pip/pip3 install, conda install/create/run, poetry run/install/add) to _deny_rules so grok's graceful native --deny blocks raw package-manager commands (model adapts to make, run continues — unlike a hook deny which cancels the run). The bash-guard hook keeps the compound-command fallback (cd x && uv run) and nudges exit 0 there via ROBOCO_GUARD_SKIP_PM=1 in the grok hook env, never canceling. * test(bash-guard): align existing tests with W1 Makefile-gate policy Raw uv run / pip install are now Makefile-gated (W1, CEO item #15), so two existing bash-guard invariants reverse: - test_allows_pytest_even_if_suite_uses_requests keeps its HTTP-injection allow-path intent but uses bare `python -m pytest` (raw `uv run` is now denied); the deny case is covered by test_bash_guard_makefile_guardrail. - test_allows_pip_install_in_workspace -> test_denies_pip_install_when_makefile_ present: a workspace clone carries a Makefile, so bare pip install is now denied -> agents use `make` / `uv sync --extra dev`. Makefile-less skips stay covered. Gate: 12994 passed, 439 skipped, 94.81% cov (DB env :55432 user renzof); the lone flaky integration error passes in isolation (DB-state race, not W1). --------- Co-authored-by: Renn F <rennf93@users.noreply.github.com>
39 lines
1.1 KiB
Markdown
39 lines
1.1 KiB
Markdown
# Backend Cell
|
|
|
|
## Team: `backend`
|
|
|
|
## Tech Stack
|
|
- **Language**: Python
|
|
- **Framework**: FastAPI
|
|
- **Database**: PostgreSQL
|
|
- **Cache/Queue**: Redis
|
|
- **Vector Store**: PostgreSQL + pgvector (via piragi)
|
|
- **Container**: Docker
|
|
|
|
## Your Teammates
|
|
- `be-pm` - Backend PM (your PM)
|
|
- `be-dev-1`, `be-dev-2` - Backend Developers
|
|
- `be-qa` - Backend QA
|
|
- `be-doc` - Backend Documenter
|
|
- `main-pm` - Main PM (escalation path)
|
|
|
|
## Development Standards
|
|
```bash
|
|
# Before any commit — use the Makefile, never raw `uv run`/`pip`/`conda`/`poetry`.
|
|
# The Makefile sets UV_NO_SYNC=1 + a private UV_CACHE_DIR to prevent venv
|
|
# corruption; bare `uv run` bypasses both.
|
|
make lint # ruff format + ruff check + mypy + vulture (formats in place)
|
|
make gate # fast pre-submit: ruff format --check + ruff check + mypy + xenon
|
|
make quality # full merge gate (lint+types+tests+cov+xenon+bandit+audit+...)
|
|
make test # pytest with coverage
|
|
|
|
# Coverage target: 80%
|
|
```
|
|
|
|
## Common Patterns
|
|
- RESTful API design
|
|
- Pydantic models for validation
|
|
- SQLAlchemy for ORM
|
|
- Dependency injection
|
|
- Structured logging with structlog
|