Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
30 commits
Select commit Hold shift + click to select a range
0d05979
adds nova extension
elliotBraem Jun 12, 2026
6ceae85
feat: force-exit on second Ctrl+C in serve command
elliotBraem Jun 12, 2026
8985c8c
fix(serve): reliable force-exit on Ctrl+C and shutdown timeout
elliotBraem Jun 12, 2026
54bdf5d
Merge branch 'nearai:main' into v/barcelona
elliotBraem Jun 12, 2026
55675c7
init
elliotBraem Jun 12, 2026
0c1201b
next
elliotBraem Jun 12, 2026
8bb1c74
wip
elliotBraem Jun 12, 2026
3e38a10
wip
elliotBraem Jun 12, 2026
8f94949
wip
elliotBraem Jun 12, 2026
ffb38b3
script
elliotBraem Jun 12, 2026
20bf00e
Merge branch 'main' into v/barcelona
elliotBraem Jun 14, 2026
a197334
better contract
elliotBraem Jun 13, 2026
370ee5c
ironclaw connected
elliotBraem Jun 13, 2026
8cbd729
create thread works
elliotBraem Jun 14, 2026
3b50fb1
wip
elliotBraem Jun 14, 2026
d7387e3
test(slack): re-home approval→auth→final-reply delivery e2e (#4847) (…
henrypark133 Jun 14, 2026
809d818
wip
elliotBraem Jun 14, 2026
110cecd
feat(runtime-context): surface connected channels, delivery state, an…
henrypark133 Jun 14, 2026
644269d
most working
elliotBraem Jun 14, 2026
e84f81b
working
elliotBraem Jun 14, 2026
8a995a7
feat(reborn): attachment web UX on the WebChat v2 SPA (#4644) (#4738)
ilblackdragon Jun 15, 2026
3aeec4e
working
elliotBraem Jun 15, 2026
b83dae8
Merge branch 'main' into v/barcelona
elliotBraem Jun 15, 2026
934db65
handlers
elliotBraem Jun 15, 2026
684a8e3
improve
elliotBraem Jun 15, 2026
097d3e7
rename
elliotBraem Jun 15, 2026
3117e93
improvements to chat
elliotBraem Jun 15, 2026
41324c2
improve stream
elliotBraem Jun 15, 2026
2744d0f
better conversation api
elliotBraem Jun 15, 2026
370a516
Merge branch 'main' into v/barcelona
elliotBraem Jun 15, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
5 changes: 4 additions & 1 deletion .claude/rules/error-handling.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ Existing rules forbid `.unwrap()` / `.expect()` in production. The footguns belo
- `.ok()?` on `Result` — drops the error entirely.
- `let Ok(x) = ... else { return None }` / `else { return }` — same shape, structured.
- `if let Err(e) = ... { warn!(...) }` followed by caching / inserting / continuing — poisons downstream state with a half-initialized value and hides the failure forever. (#2633 `seed_if_empty` cache.)
- `.map_err(|_| OtherError)` — a closure that ignores its error binding and substitutes a generic error **drops the underlying cause**. A sanitized boundary error built this way (e.g. `RebornServicesError` → HTTP 500) reaches the user as a bare "Internal" with no server-side trail. (#4644: a read-only attachment mount surfaced as an undiagnosable 500 because the landing error was mapped with `map_err(|_| …Internal…)`.) Carry the cause instead: `.map_err(RebornServicesError::internal_from)` (logs the source, returns the sanitized 500), or log the bound error before mapping. The HTTP boundary additionally logs every 5xx as a safety net, but the *cause* only survives if the mapping doesn't discard it.

**Required pattern — fail loud by default:**

Expand All @@ -26,7 +27,9 @@ let projects = store.list_projects(&owner_id).await?;
let rows = store.list_agent_jobs().await.unwrap_or_default(); // silent-ok: dashboard refresh, next poll retries
```

Review flag: added lines containing `unwrap_or_default()`, `.ok()?`, or `else { return` / `else { return None }` on a DB/IO/workspace call must carry a `// silent-ok: <reason>` comment or be rejected.
Review flag: added lines containing `unwrap_or_default()`, `.ok()?`, or `else { return` / `else { return None }` on a DB/IO/workspace/boundary call must carry a `// silent-ok: <reason>` comment or be rejected.

A `map_err(|_| …)` (a closure discarding the error binding) is **not** `silent-ok`-exemptible — a comment does not make the dropped cause reappear. Fix it by carrying the cause (`.map_err(ErrorType::constructor)` / `RebornServicesError::internal_from`) or by logging the bound error before mapping. Reject the line otherwise.

## Persist-Then-Reload Atomicity

Expand Down
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -72,3 +72,4 @@ tests/fixtures/llm_traces/live/*.log

# Local test artifacts
.anvil/
.codegraph/
11 changes: 11 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
[workspace]
members = [".", "crates/ironclaw_common", "crates/ironclaw_host_api", "crates/ironclaw_filesystem", "crates/ironclaw_attachments", "crates/ironclaw_extractors", "crates/ironclaw_memory", "crates/ironclaw_events", "crates/ironclaw_event_projections", "crates/ironclaw_event_streams", "crates/ironclaw_reborn_event_store", "crates/ironclaw_extensions", "crates/ironclaw_processes", "crates/ironclaw_dispatcher", "crates/ironclaw_scripts", "crates/ironclaw_process_sandbox", "crates/ironclaw_mcp", "crates/ironclaw_wasm", "crates/ironclaw_wasm_sandbox_core", "crates/ironclaw_wasm_limiter", "crates/ironclaw_capabilities", "crates/ironclaw_secrets", "crates/ironclaw_network", "crates/ironclaw_host_runtime", "crates/ironclaw_runtime_policy", "crates/ironclaw_authorization", "crates/ironclaw_run_state", "crates/ironclaw_approvals", "crates/ironclaw_resources", "crates/ironclaw_auth", "crates/ironclaw_trust", "crates/ironclaw_turns", "crates/ironclaw_agent_loop", "crates/ironclaw_threads", "crates/ironclaw_prompt_envelope", "crates/ironclaw_hooks", "crates/ironclaw_hooks_postgres", "crates/ironclaw_hooks_libsql", "crates/ironclaw_hooks_parity", "crates/ironclaw_loop_support", "crates/ironclaw_reborn", "crates/ironclaw_reborn_config", "crates/ironclaw_reborn_composition", "crates/ironclaw_reborn_identity", "crates/ironclaw_first_party_extensions", "crates/ironclaw_reborn_cli", "crates/ironclaw_reborn_traces", "crates/ironclaw_reborn_webui_ingress", "crates/ironclaw_reborn_openai_compat", "crates/ironclaw_reborn_openai_compat_storage", "crates/ironclaw_conversations", "crates/ironclaw_product_adapters", "crates/ironclaw_product_workflow", "crates/ironclaw_product_workflow_storage", "crates/ironclaw_product_adapter_registry", "crates/ironclaw_wasm_product_adapters", "crates/ironclaw_telegram_v2_adapter", "crates/ironclaw_slack_v2_adapter", "crates/ironclaw_outbound", "crates/ironclaw_triggers", "crates/ironclaw_architecture", "crates/ironclaw_safety", "crates/ironclaw_skills", "crates/ironclaw_oauth", "crates/ironclaw_llm", "crates/ironclaw_embeddings", "crates/ironclaw_engine", "crates/ironclaw_gateway", "crates/ironclaw_tui", "crates/ironclaw_webui_v2", "crates/ironclaw_webui_v2_static"]
members = [".", "crates/ironclaw_common", "crates/ironclaw_host_api", "crates/ironclaw_filesystem", "crates/ironclaw_attachments", "crates/ironclaw_extractors", "crates/ironclaw_memory", "crates/ironclaw_events", "crates/ironclaw_event_projections", "crates/ironclaw_event_streams", "crates/ironclaw_reborn_event_store", "crates/ironclaw_extensions", "crates/ironclaw_processes", "crates/ironclaw_dispatcher", "crates/ironclaw_scripts", "crates/ironclaw_process_sandbox", "crates/ironclaw_mcp", "crates/ironclaw_wasm", "crates/ironclaw_wasm_sandbox_core", "crates/ironclaw_wasm_limiter", "crates/ironclaw_capabilities", "crates/ironclaw_secrets", "crates/ironclaw_network", "crates/ironclaw_host_runtime", "crates/ironclaw_runtime_policy", "crates/ironclaw_authorization", "crates/ironclaw_run_state", "crates/ironclaw_approvals", "crates/ironclaw_resources", "crates/ironclaw_auth", "crates/ironclaw_trust", "crates/ironclaw_turns", "crates/ironclaw_agent_loop", "crates/ironclaw_threads", "crates/ironclaw_prompt_envelope", "crates/ironclaw_hooks", "crates/ironclaw_hooks_postgres", "crates/ironclaw_hooks_libsql", "crates/ironclaw_hooks_parity", "crates/ironclaw_loop_support", "crates/ironclaw_reborn", "crates/ironclaw_reborn_config", "crates/ironclaw_reborn_composition", "crates/ironclaw_reborn_identity", "crates/ironclaw_first_party_extensions", "crates/ironclaw_reborn_cli", "crates/ironclaw_reborn_traces", "crates/ironclaw_reborn_webui_ingress", "crates/ironclaw_reborn_openai_compat", "crates/ironclaw_reborn_openai_compat_storage", "crates/ironclaw_conversations", "crates/ironclaw_product_adapters", "crates/ironclaw_product_context", "crates/ironclaw_product_workflow", "crates/ironclaw_product_workflow_storage", "crates/ironclaw_product_adapter_registry", "crates/ironclaw_wasm_product_adapters", "crates/ironclaw_telegram_v2_adapter", "crates/ironclaw_slack_v2_adapter", "crates/ironclaw_outbound", "crates/ironclaw_triggers", "crates/ironclaw_architecture", "crates/ironclaw_safety", "crates/ironclaw_skills", "crates/ironclaw_oauth", "crates/ironclaw_llm", "crates/ironclaw_embeddings", "crates/ironclaw_engine", "crates/ironclaw_gateway", "crates/ironclaw_tui", "crates/ironclaw_webui_v2", "crates/ironclaw_webui_v2_static"]
exclude = [
"channels-src/discord",
"channels-src/feishu",
Expand Down
8 changes: 8 additions & 0 deletions app/ironclaw.everything.dev/.changeset/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
# Changesets

Hello and welcome! This folder has been automatically generated by `@changesets/cli`, a build tool that works
with multi-package repos, or single-package repos to help you version and publish your code. You can
find the full documentation for it [in our repository](https://github.com/changesets/changesets)

We have a quick list of common questions to get you started engaging with this project in
[our documentation](https://github.com/changesets/changesets/blob/main/docs/common-questions.md)
11 changes: 11 additions & 0 deletions app/ironclaw.everything.dev/.changeset/config.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
{
"$schema": "https://unpkg.com/@changesets/config@3.1.2/schema.json",
"changelog": "@changesets/cli/changelog",
"commit": false,
"fixed": [],
"linked": [],
"access": "public",
"baseBranch": "main",
"updateInternalDependencies": "patch",
"ignore": []
}
29 changes: 29 additions & 0 deletions app/ironclaw.everything.dev/.env.example
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# Generated from configured bos secrets
# Update values as needed for your local environment

# app.host
CORS_ORIGIN=http://localhost:3000
TENANT_WHITELIST=
ALLOW_OVERRIDE=
ALLOW_UNTRUSTED_SSR=
CSP_STRICT=

# app.api
API_DATABASE_URL=postgres://everythingdev:everythingdev@localhost:5432/api_db
IRONCLAW_BASE_URL=

# app.auth
AUTH_DATABASE_URL=postgres://everythingdev:everythingdev@localhost:5433/auth_db
BETTER_AUTH_SECRET=
GITHUB_CLIENT_SECRET=
FASTNEAR_API_KEY=
TWILIO_ACCOUNT_SID=
TWILIO_AUTH_TOKEN=
TWILIO_PHONE_NUMBER=
NEAR_RELAYER_PRIVATE_KEY=
NEAR_SUB_ACCOUNT_PARENT_KEY_MAINNET=
NEAR_SUB_ACCOUNT_PARENT_KEY_TESTNET=

# plugins.ironclaw
IRONCLAW_API_TOKEN=

62 changes: 62 additions & 0 deletions app/ironclaw.everything.dev/.github/workflows/ci.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
name: CI

on:
push:
branches: [main]
paths-ignore:
- "**.md"
- "docs/**"
- ".changeset/**"
pull_request:
workflow_dispatch:
inputs:
fail_on_critical_high:
description: "Fail the audit step on critical/high vulnerabilities"
required: false
type: boolean
default: false

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: read

jobs:
lint-and-typecheck:
name: Lint and Type Check
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1

- name: Setup Bun
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: "1.2.20"

- name: Install dependencies
run: bun install --frozen-lockfile --ignore-scripts

- name: Run postinstall
run: bun run postinstall

- name: Security audit
id: audit
run: |
bun audit 2>&1 | tee audit-output.txt
if grep -qiE '(critical|high)' audit-output.txt; then
if [ "${{ inputs.fail_on_critical_high }}" = "true" ]; then
echo "::error::Critical or high vulnerabilities found — failing the audit"
exit 1
else
echo "::warning::Critical or high vulnerabilities found — see audit output"
fi
fi

- name: Run Biome lint and format check
run: bun biome ci .

- name: Run typecheck
run: bun typecheck
111 changes: 111 additions & 0 deletions app/ironclaw.everything.dev/.github/workflows/deploy.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,111 @@
name: Deploy

on:
workflow_run:
workflows: [CI]
types: [completed]
workflow_dispatch:

concurrency: ${{ github.workflow }}-${{ github.ref }}

permissions:
contents: write

jobs:
deploy:
name: Deploy Production
if: >
github.event_name == 'workflow_dispatch' ||
(
github.event_name == 'workflow_run' &&
github.event.workflow_run.conclusion == 'success' &&
github.event.workflow_run.event == 'push' &&
github.event.workflow_run.head_branch == 'main'
)
runs-on: ubuntu-latest
env:
NEAR_PRIVATE_KEY: ${{ secrets.NEAR_PRIVATE_KEY }}
ZE_SERVER_TOKEN: ${{ secrets.ZEPHYR_AUTH_TOKEN }}
ZE_USER_EMAIL: ${{ secrets.ZEPHYR_USER_EMAIL }}
RAILWAY_TOKEN: ${{ secrets.RAILWAY_TOKEN }}
TARGET_SHA: ${{ github.event_name == 'workflow_run' && github.event.workflow_run.head_sha || github.sha }}
TARGET_BRANCH: ${{ github.event_name == 'workflow_run' && github.event.workflow_run.head_branch || github.ref_name }}
steps:
- name: Checkout code
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
ref: ${{ env.TARGET_BRANCH }}
fetch-depth: 0

- name: Sync to triggering commit
run: git reset --hard "$TARGET_SHA"

- name: Setup Bun
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: "1.2.20"

- name: Install dependencies
run: bun install --frozen-lockfile --ignore-scripts

- name: Run postinstall
run: bun run postinstall

- name: Install NEAR CLI
run: curl --proto '=https' --tlsv1.2 -LsSf https://github.com/near/near-cli-rs/releases/download/v0.23.5/near-cli-rs-installer.sh | sh

- name: Verify NEAR CLI
run: near --version

- name: Publish with deploy
run: bun run bos publish --deploy

- name: Install Railway CLI
run: npm i -g @railway/cli

- name: Redeploy Railway
run: railway redeploy --service app --yes

- name: Commit and push bos.config.json updates
run: |
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add bos.config.json
git diff --cached --quiet || git commit -m "chore: update deployment URLs [skip ci]"
git push origin HEAD:"$TARGET_BRANCH"

- name: Create GitHub Releases for deployed workspaces
env:
GITHUB_TOKEN: ${{ github.token }}
run: |
shopt -s nullglob
changelogs=( */CHANGELOG.md plugins/*/CHANGELOG.md )
shopt -u nullglob

for changelog in "${changelogs[@]}"; do
pkg_dir=$(dirname "$changelog")

[[ "$(basename "$pkg_dir")" == _* ]] && continue

PKG_JSON="$pkg_dir/package.json"
[ ! -f "$PKG_JSON" ] && continue

VERSION=$(jq -r '.version // empty' "$PKG_JSON")
NAME=$(jq -r '.name // empty' "$PKG_JSON")
[ -z "$VERSION" ] || [ -z "$NAME" ] && continue

TAG="${NAME}@${VERSION}"

if gh release view "$TAG" >/dev/null 2>&1; then
echo "Release $TAG already exists, skipping"
continue
fi

NOTES=$(sed -n "/^## ${VERSION}/,/^## [0-9]/p" "$changelog" | sed '$d' | tail -n +2)
[ -z "$NOTES" ] && NOTES="Release $TAG"

gh release create "$TAG" \
--title "$TAG" \
--notes "$NOTES" \
--target "$TARGET_BRANCH"
done
69 changes: 69 additions & 0 deletions app/ironclaw.everything.dev/.github/workflows/staging.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,69 @@
name: Staging

on:
push:
branches:
- staging
workflow_dispatch:

concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: true

permissions:
contents: write

jobs:
deploy-staging:
name: Deploy Staging
runs-on: ubuntu-latest
env:
NEAR_PRIVATE_KEY: ${{ secrets.NEAR_PRIVATE_KEY }}
ZE_SERVER_TOKEN: ${{ secrets.ZEPHYR_AUTH_TOKEN }}
ZE_USER_EMAIL: ${{ secrets.ZEPHYR_USER_EMAIL }}
RAILWAY_TOKEN: ${{ secrets.RAILWAY_STAGING_TOKEN }}
TARGET_SHA: ${{ github.sha }}
TARGET_BRANCH: ${{ github.ref_name }}
steps:
- name: Checkout code
uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4.3.1
with:
ref: ${{ env.TARGET_BRANCH }}
fetch-depth: 0

- name: Sync to triggering commit
run: git reset --hard "$TARGET_SHA"

- name: Setup Bun
uses: oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6 # v2.2.0
with:
bun-version: "1.2.20"

- name: Install dependencies
run: bun install --frozen-lockfile --ignore-scripts

- name: Run postinstall
run: bun run postinstall

- name: Install NEAR CLI
run: curl --proto '=https' --tlsv1.2 -LsSf https://github.com/near/near-cli-rs/releases/download/v0.23.5/near-cli-rs-installer.sh | sh

- name: Verify NEAR CLI
run: near --version

- name: Publish with deploy
run: bun run bos publish --deploy --env staging

- name: Install Railway CLI
run: npm i -g @railway/cli

- name: Redeploy Railway
run: railway redeploy --service app --yes

- name: Commit and push bos.config.json updates
run: |
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git add bos.config.json
git diff --cached --quiet || git commit -m "chore: update staging deployment URLs [skip ci]"
git push origin HEAD:"$TARGET_BRANCH"
Loading