Skip to content

chore: promote staging to staging-promote/7234700c-23635804857 (2026-03-27 08:13 UTC) - #1703

Merged
henrypark133 merged 2 commits into
staging-promote/7234700c-23635804857from
staging-promote/2f4eb086-23637233594
Mar 27, 2026
Merged

henrypark133 merged 2 commits into
staging-promote/7234700c-23635804857from
staging-promote/2f4eb086-23637233594

Conversation

@ironclaw-ci

@ironclaw-ci ironclaw-ci Bot commented Mar 27, 2026 •

Copy link
Copy Markdown
Contributor

Auto-promotion from staging CI

Batch range: 7234700c78d985ddc872721bc2a7130eeaa0b8c3..2f4eb08613cefff1af8b7b1a475fda00c84dd855
Promotion branch: staging-promote/2f4eb086-23637233594
Base: staging-promote/7234700c-23635804857
Triggered by: Staging CI batch at 2026-03-27 08:13 UTC

Commits in this batch (2):

Current commits in this promotion (2)

Current base: staging-promote/7234700c-23635804857
Current head: staging-promote/2f4eb086-23637233594
Current range: origin/staging-promote/7234700c-23635804857..origin/staging-promote/2f4eb086-23637233594

Auto-updated by staging promotion metadata workflow

Waiting for gates:

  • Tests: pending
  • E2E: pending
  • Claude Code review: pending (will post comments on this PR)

Auto-created by staging-ci workflow

serrrfirat and others added 2 commits March 27, 2026 10:49
* fix: require Feishu webhook authentication

* fix: handle Feishu v2 webhook token auth

* fix: skip empty verification token write, consistent with app_id/app_secret

Address zmanian review nit #4: only write verification_token to workspace
when present, matching the if-let pattern used for app_id and app_secret.
Functionally identical (the auth check filters empty strings), but
consistent.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix: sanitize tool error results before llm injection

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>

* fix: wrap preflight tool rejection errors for llm safety

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>

* style: apply rustfmt to error-path regressions

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>

* fix: preserve wrapped tool errors in history replay

* fix: address review findings on PR #1639

- Simplify legacy error handling in rebuild_chat_messages_from_db:
  remove redundant "Error: " prefix since legacy errors already contain
  descriptive text (e.g. "Tool 'http' failed: timeout"). Both wrapped
  (new) and plain (legacy) errors now pass through as-is.
- Update existing test assertion to match simplified format.
- Restore error-path doc line on process_tool_result.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: satisfy clippy on builder tool safety helper

---------

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added scope: agent Agent core (agent loop, router, scheduler) scope: channel/web Web gateway channel scope: channel/wasm WASM channel runtime scope: tool/builder Dynamic tool builder size: L 200-499 changed lines risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Mar 27, 2026
@claude

claude Bot commented Mar 27, 2026

Copy link
Copy Markdown

Code review

Found 4 issues:

  1. [CRITICAL:95] Type erasure in process_tool_result() signature — accepting Result<String, impl Display> loses type information and prevents future error recovery or pattern matching. Consider using a trait object or keeping specific error types (ToolError, String).

https://github.com/anthropics/ironclaw/blob/41468f39331f7a611b9a38f61b43384333d56b78/src/tools/execute.rs#L828-L843

let (result_content, tool_message) = preflight_rejection_tool_message(
    self.agent.safety(),
    &tc.name,
    &tc.id,
    &error_msg,
);
  1. [HIGH:95] Workspace I/O on hot path — is_authenticated_webhook() reads verification token from workspace storage on every webhook request, adding synchronous I/O latency. For high-frequency webhooks, consider caching the token or pre-loading during initialization.

https://github.com/anthropics/ironclaw/blob/41468f39331f7a611b9a38f61b43384333d56b78/channels-src/feishu/src/lib.rs#L389-L397

let configured_token =
    channel_host::workspace_read(VERIFICATION_TOKEN_PATH).filter(|token| !token.is_empty());
if !is_authenticated_webhook(
    req.secret_validated,
    configured_token.as_deref(),
    request_verification_token(&event),
) {
  1. [MEDIUM:85] LazyLock duplication across execution paths — process_tool_result() creates a SafetyLayer, and process_builder_tool_result() creates another. Both are static singletons with identical initialization. Consider centralizing in the SafetyLayer module to avoid duplication.

https://github.com/anthropics/ironclaw/blob/41468f39331f7a611b9a38f61b43384333d56b78/src/tools/builder/core.rs#L1-L50

static SAFETY: LazyLock<SafetyLayer> = ...
  1. [MEDIUM:80] Inconsistent error message format across code paths — New code formats errors via process_tool_result() as "Tool 'X' failed: ...", but legacy rebuild_chat_messages_from_db() passes errors through unchanged. This creates a silent contract that new code must always use the centralized function.

https://github.com/anthropics/ironclaw/blob/41468f39331f7a611b9a38f61b43384333d56b78/src/agent/thread_ops.rs#L1907-L1920

let content = if let Some(err) = c.get("error").and_then(|v| v.as_str())
{
    // Both wrapped (new) and legacy (plain) errors pass
    // through as-is. Legacy errors are already descriptive
    // (e.g. "Tool 'http' failed: timeout"), so no prefix needed.
    err.to_string()

@henrypark133
henrypark133 merged commit b3533e2 into staging-promote/7234700c-23635804857 Mar 27, 2026
143 of 144 checks passed
@henrypark133
henrypark133 deleted the staging-promote/2f4eb086-23637233594 branch March 27, 2026 21:55
drchirag1991 pushed a commit to drchirag1991/ironclaw that referenced this pull request Apr 8, 2026
…3637233594

chore: promote staging to staging-promote/184d60ba-23635804857 (2026-03-27 08:13 UTC)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: agent Agent core (agent loop, router, scheduler) scope: channel/wasm WASM channel runtime scope: channel/web Web gateway channel scope: tool/builder Dynamic tool builder size: L 200-499 changed lines staging-promotion

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants