Finish whole-repository checks: opt-in rules stay off under group levels, a status line, budget and key errors said once - #49
Merged
Merged
Conversation
…a status line, budget and key errors said once A level for maintainability turned on hardcoded values, which left the default rules in 0.26: on a 950-file project it doubled a whole check, 1,846 requests where the default rules need 943, and a jevgate.toml ceiling of 1,000 stopped it halfway. A group now turns on the rules it runs by default, or every rule of an opt-in group. A check draws a status line on a terminal, says before its first request when its request budget cannot cover it, names where the budget is set (the old message advised a flag that cannot raise jevgate.toml's ceiling), ends in one line without a key, and reads the macOS Keychain without a terminal, as Git and agent hooks run.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A whole-repository check of nodehaven-online (950 files, TypeScript, Python, SpacetimeDB) with 0.30/0.31 printed nothing for 70 seconds, spent its 1,000-request budget and left 377 files unchecked, advising a
--max-requeststhat cannot raise the ceiling jevgate.toml sets. With this branch the same check, same config, empty cache, finishes: 930 requests, 73 s, $0.046, with a status line all along; a rerun from the cache takes 2.2 s.What caused it
maintainability = "consider". A level for a group judged every rule of it, so hardcoded values — out of the default rules since 0.26, right 6 times in 37 on unseen projects — ran too. It asks about every module constant (one request per file, one question each) and every function with a literal, and many rechecks and locates follow: 1,846 requests for a whole check, where the three default maintainability rules need 943.concurrency = 4makes it about 13 a second).Changes
security,documentation). Hardcoded values runs when named ("maintainability/hardcoded-values" = "consider",--rule hardcoded-values) or withall. Applies to[rules]levels,rules = [...]and--rule;--skip-rule maintainabilitystill skips all of it.jevgate initwrites hardcoded values on its own line. This changes which rules run for configurations that set a level onmaintainability— the one public-behavior change here.JevGate · first pass · 312/768 answered · 23s, per stage (test-file purposes, planning, first pass, each follow-up round, composing).note!/say!erase it first; it is gone before the findings. Off in CI, with--watch,--format jsonl, when stderr is not a terminal, and for checks under 0.4 s.this check needs at least N requests, more than max_requests = 1000 in jevgate.toml allows…and how to finish; each unsent file saysRequest budget reached (max_requests = 1000 in jevgate.toml); rerun to continue from the cached answers, or raise the budget(or--max-requests Nwhen the flag set it).jevgate: No API key configured. …, exit 2, nothing else. The report keeps each file's error (MCP and JSON consumers unchanged), Git hooks still let the change through saying why, and a watcher looks for a key again on its next snapshot.auth loginsaved and let changes through unchecked. Without a terminal the Keychain dialog is turned off (SecKeychainSetUserInteractionAllowed), so a read macOS would prompt for fails at once with a message saying to runjevgate auth statusonce in a terminal. Verified with a throwaway item: the creating binary reads it with the dialog off and no terminal; a binary the item does not trust fails in 0.6 s with no dialog.(would fail the gate)instead of(fails the gate)when the gate was not evaluated.initsuggestmax_costrather than a pull-request-sizedmax_requests.Measured
max_requests = 1000,concurrency = 4)No question, state or composition changed: cached answers stay valid, and runs of
--rule all(the corpus harness) ask exactly what they asked. Tests: 898 unit + 79 CLI + 3 pass;cargo +1.90.0 check --lockedpasses;jevgate check --base mainpasses the default gate (notes only).Not in this PR
Function packs never cross a file boundary, so 373 of nodehaven's 611 function requests hold one function. Packing across files with today's edit-stable runs would ask 318 (first pass -36%; axios -23%, chi -31%, flask -11%, starlette -16% in dry runs). It changes what Jev sees — the 0.28 pack merge flipped about a fifth of function-simplification reviews, the one rule that blocks by default — so it needs the corpus measurement AGENTS.md asks for, and is left as a proposal.