Skip to content

chore: promote staging to staging-promote/368d2f52-23720185295 (2026-03-30 03:01 UTC) - #1747

Merged
henrypark133 merged 10 commits into
staging-promote/368d2f52-23720185295from
staging-promote/8acdd080-23726030902
Mar 30, 2026
Merged

henrypark133 merged 10 commits into
staging-promote/368d2f52-23720185295from
staging-promote/8acdd080-23726030902

Conversation

@ironclaw-ci

@ironclaw-ci ironclaw-ci Bot commented Mar 30, 2026 •

Copy link
Copy Markdown
Contributor

Auto-promotion from staging CI

Batch range: 2f4eb08613cefff1af8b7b1a475fda00c84dd855..8acdd08039071b731fc7fd6be8b6e1c4c18da9c7
Promotion branch: staging-promote/8acdd080-23726030902
Base: staging-promote/368d2f52-23720185295
Triggered by: Staging CI batch at 2026-03-30 03:01 UTC

Commits in this batch (22):

Current commits in this promotion (1)

Current base: staging-promote/368d2f52-23720185295
Current head: staging-promote/8acdd080-23726030902
Current range: origin/staging-promote/368d2f52-23720185295..origin/staging-promote/8acdd080-23726030902

Auto-updated by staging promotion metadata workflow

Waiting for gates:

  • Tests: pending
  • E2E: pending
  • Claude Code review: pending (will post comments on this PR)

Auto-created by staging-ci workflow

…ts (#1529)

* fix(wasm): inject Content-Length: 0 for bodyless mutating requests [skip-version-check]

The WASM host http_request now auto-injects Content-Length: 0 for
POST/PUT/PATCH/DELETE requests with no body, unless the tool already
provides the header. This fixes Gmail returning 411 on trash_message
and proactively covers all other tools (Google Calendar DELETE,
Google Drive DELETE, etc.).

Extracted needs_content_length_zero() with 8 regression tests
covering all HTTP methods and case-insensitive header detection.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix(wasm): use eq_ignore_ascii_case to avoid allocation [skip-version-check]

Replace matches!(method.to_uppercase().as_str(), ...) with
eq_ignore_ascii_case() to avoid a per-request String allocation.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: ilblackdragon@gmail.com <ilblackdragon@gmail.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added scope: tool/wasm WASM tool sandbox size: M 50-199 changed lines risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Mar 30, 2026
G7CNF and others added 9 commits March 29, 2026 23:17
* fix(auth): make shared Google tool status scope-aware

* fix(auth): simplify google docs auth status test

* fix(auth): skip scope expansion for env-var tokens and add dual-source test

Env-var-provided tokens are externally managed, so the scope-expansion
check must not apply — otherwise tools regress to NeedsAuth when no
scopes record exists in the secrets store. Split the token detection
into managed vs env-var paths and only run scope checks for managed
tokens.

Also adds tests verifying: (1) env-var-only tokens return Ready without
scope checks, and (2) when both a managed token and env var are present,
the managed path with scope checks takes priority.

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: ilblackdragon@gmail.com <ilblackdragon@gmail.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
… gate regressions (#1746)

* fix: resolve 11 test failures from multi-tenant bootstrap and sandbox gate regressions

Three root causes fixed:

1. Per-user bootstrap greeting in tests: After the multi-tenant isolation
   PR, `tenant_ctx("test-user")` creates a per-user workspace that seeds
   BOOTSTRAP.md and triggers an unwanted bootstrap greeting. This threw
   off response counting and caused message-drain races in 7 e2e tests.
   Fix: pre-seed the "test-user" workspace in the test rig DB so the
   first tenant_ctx call finds existing documents.

2. Sandbox gate blocking full_job routines: The full_job reliability
   overhaul (#1650) intended to remove the SandboxReadiness gate from
   execute_full_job (since full_job routines dispatch through the
   scheduler, not Docker). The gate was accidentally re-added during
   rebase, breaking 4 routine tests. Fix: remove the gate and clean up
   the unused sandbox_readiness field from EngineContext.

3. Owner-gate tests expecting old failure path: Two tests expected
   RunStatus::Failed from the sandbox gate. With the gate removed, the
   tool is now blocked at execution time by the approval context and the
   job completes normally. Fix: update traces and assertions to match the
   new behavior (RunStatus::Ok, owner_gate_count == 0).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: keep DockerUnavailable gate for full_job routines

Only remove the DisabledByConfig gate — when sandbox is enabled but
Docker is unavailable, full_job routines should still fail rather than
silently running without the expected sandbox isolation.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* refactor: address PR review feedback

- Remove unused `include_completion` param from `owner_gate_trace()`
  and update all 5 call sites
- Use `.expect()` instead of `let _ =` on `seed_if_empty()` in test rig
  to surface seeding failures early
- Rename owner-gate tests from `_blocks_` to `_denies_tool_` to clarify
  the denial-with-success semantics

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* refactor: let per-user bootstrap fire naturally, filter in TestRig

Instead of pre-seeding the "test-user" workspace to prevent the
per-user bootstrap greeting, let it happen naturally and make the
TestRig resilient to it. `wait_for_responses` now transparently
filters bootstrap greetings from the response stream:

- Normal tests: all greetings filtered (bootstrap_greetings_to_keep=0)
- `.with_bootstrap()` tests: 1 greeting kept (the startup greeting),
  additional per-user duplicates filtered

Also updates owner-gate test section headers to match the
denial-with-success semantics.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: assert tool denial event in owner-gate tests

The owner-gate denial tests previously only checked RunStatus::Ok +
owner_gate_count == 0, which could pass if the tool was never called
at all. Now both tests also verify that a tool_result event with
success=false exists for "owner_gate" in the job's event log,
confirming the tool was attempted and blocked by the approval context.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* style: apply rustfmt to collapsed function signature

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: use async lock in bootstrap filter loop, add DisabledByConfig unit test

- Switch TestRig polling loop from `captured_responses()` (try_lock,
  panics on contention) to `captured_responses_async()` (async lock,
  safe under concurrent response pushing)
- Add unit test asserting DisabledByConfig does NOT match the
  DockerUnavailable gate (verifies the intended behavior change)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* fix(slack): respond to thread replies in channels without requiring @mention

Two fixes:

1. Host bug: `on_respond` callback never committed workspace writes or
   injected workspace reader, unlike all other WASM callbacks. Any WASM
   channel persisting state during on_respond silently lost data.

2. Slack WASM channel: track threads where the bot has participated via
   workspace storage. When a message event arrives in a channel thread
   the bot previously replied to, process it without requiring @mention.

Closes #1404

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(slack): log workspace_write error instead of silently discarding

Address code review feedback: handle the Result from workspace_write
when tracking thread participation, logging a warning on failure
instead of using `let _ =` which would silently swallow errors.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(slack): harden thread reply tracking

---------

Co-authored-by: synner88 <29090601+synner88@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Firat Sertgoz <f@nuff.tech>
Co-authored-by: firat.sertgoz <firat.sertgoz@near.ai>
…esh (#1756)

* fix(routines): clone Arc before await in web handler event cache refresh (#1076)

Address review: drop superseded ticker changes, keep only the .cloned()
fix that prevents holding RwLockReadGuard across .await in toggle/delete
handlers. Add regression test for web toggle disabling a system_event
routine.

Closes #1076

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: use explicit block to drop RwLockReadGuard before await

Address review feedback: in Rust 2024, `if let` scrutinee temporaries
live through the body, so the `.cloned()` approach still held the
RwLockReadGuard across `refresh_event_cache().await`. Extract into an
explicit block to ensure the guard is dropped, matching the existing
pattern in `routines_trigger_handler`.

Also add retry loop for `routine_by_name` in the integration test to
avoid flakiness from potential race conditions.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
…1762)

* test(e2e): align wasm reinstall expectations with uninstall cleanup

* test(e2e): clarify wasm reinstall fixture semantics
…2238

chore: promote staging to staging-promote/d567d94c-23755250735 (2026-03-30 18:33 UTC)
…0735

chore: promote staging to staging-promote/d0f7862a-23733136790 (2026-03-30 16:19 UTC)
…6790

chore: promote staging to staging-promote/c75dea0e-23731217718 (2026-03-30 07:31 UTC)
…7718

chore: promote staging to staging-promote/8acdd080-23726030902 (2026-03-30 06:33 UTC)
@henrypark133
henrypark133 merged commit 527b88e into staging-promote/368d2f52-23720185295 Mar 30, 2026
12 of 13 checks passed
@github-actions github-actions Bot added scope: agent Agent core (agent loop, router, scheduler) scope: channel/web Web gateway channel scope: channel/wasm WASM channel runtime scope: extensions Extension management scope: docs Documentation labels Mar 30, 2026
@henrypark133
henrypark133 deleted the staging-promote/8acdd080-23726030902 branch March 30, 2026 19:22
@github-actions github-actions Bot added size: XL 500+ changed lines and removed size: M 50-199 changed lines labels Mar 30, 2026
drchirag1991 pushed a commit to drchirag1991/ironclaw that referenced this pull request Apr 8, 2026
…3726030902

chore: promote staging to staging-promote/4210fabf-23720185295 (2026-03-30 03:01 UTC)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: agent Agent core (agent loop, router, scheduler) scope: channel/wasm WASM channel runtime scope: channel/web Web gateway channel scope: docs Documentation scope: extensions Extension management scope: tool/wasm WASM tool sandbox size: XL 500+ changed lines staging-promotion

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants