chore: update reviewer agent memory

This commit is contained in:
tiennm99 committed 2026-09-28 15:01:41 +07:00
1 parent b8b4ffbbcb
commit cca6018572
3 files changed
+19 -5

No files matched your search

+2 -1
View File
@@ -1,5 +1,6 @@
- [Anti-cheat invariant and its known bypass](project-anti-cheat-invariant.md) — pano coords are the answers; the import-walk test does not cover the debug API that leaks them.
- [Anti-cheat invariant and its known bypass](project-anti-cheat-invariant.md) — pano coords are the answers; debug API now prod-gated, preview envs and sessionId reuse still open.
- [Quality gate blind spots](project-quality-gates-blind-spots.md) — no-undef is now on, but no gate checks React prop/state contracts, e2e stub drift, or whether /docs matches the code.
- [Scoring ladder vs leaderboard boards](project-scoring-ladder-and-boards.md) — one frozen ladder again, and the top-200 trim permanently resets anyone outside the window.
- [Free-tier budgets are the real ceiling](project-free-tier-budgets.md) — ~27 Redis commands per round against 500K/month, and nothing counts them.
- [Bundled Next docs are unreadable](project-nextdocs-blocked.md) — node_modules is hook-blocked, so check Next 16 conventions on nextjs.org (middleware.js is now proxy.js).
- [PGlite hook-timeout flake](project-pglite-hook-timeout.md) — ~7s PGlite init per file vs 10s default hookTimeout; files FAIL with tests skipped.
@@ -58,7 +58,9 @@ fires, so the daily row in `npm run stats` stays inflatable — cosmetic, not a
**How to apply:** whenever a mode makes the answer repeatable (daily, replay,
shared link), check what it credits before accepting a client-side attempt limit.
`src/lib/daily.js` is server-only and holds the day's answer, but it is NOT in the
`FORBIDDEN` list of the client-safety walk in `tests/regions.test.js` (still only
data/panos, pano-index, pano-db, pano-history, data/boundaries). The walk guards
only what is named in it — check the list on any new server-only module.
Update 2026-09-28: `lib/daily.js` IS now on the `FORBIDDEN` list, and both
`/api/debug/*` routes are gated by `src/lib/debug-access.js` (404 in production
without `DEBUG_ACCESS_KEY`; always open on Vercel preview and dev). The remaining
open questions are whether preview deployments share production Redis/Neon, and
that `/api/new-game` still reuses a client-supplied `sessionId` (already caused
one skip-DEL race, patched client-side only).
@@ -0,0 +1,11 @@
---
name: project-pglite-hook-timeout
description: Intermittent vitest failures (whole files FAIL, tests skipped) come from PGlite init in beforeAll exceeding the 10s default hookTimeout on the ARM dev box
metadata:
type: project
---
On the 4-core ARM workspace, `new PGlite()` takes ~7s uncontended (measured 2026-09-28); the 7 test files that call seedPanoFixtures in beforeAll all init it concurrently, so a loaded run exceeds vitest's 10s default hookTimeout. Signature: "N files failed | M skipped", immediate rerun green. CI (GitHub x64) is fast enough to hide it.
**Why:** a file-level beforeAll timeout skips every test in the file, which looks like random flakiness.
**How to apply:** when a report of "files failed, tests skipped, rerun passed" comes in, check hookTimeout in vitest configs first (`npx vitest run --hookTimeout=2500` reproduces deterministically).