Chore sync staging with main - #1891
Conversation
…2140 chore: promote staging to staging-promote/ed4d9293-23582522167 (2026-03-26 18:18 UTC)
…1675 chore: promote staging to staging-promote/ed4d9293-23582522167 (2026-03-26 21:08 UTC)
…2167 chore: promote staging to staging-promote/4c043bf0-23573031775 (2026-03-26 07:26 UTC)
…1775 chore: promote staging to main (2026-03-26 01:33 UTC)
…5316 chore: promote staging to staging-promote/1d577782-23620402154 (2026-03-27 00:14 UTC)
…2154 chore: promote staging to main (2026-03-26 22:07 UTC)
Co-authored-by: ironclaw-ci[bot] <266877842+ironclaw-ci[bot]@users.noreply.github.com>
…3594 chore: promote staging to staging-promote/7234700c-23635804857 (2026-03-27 08:13 UTC)
McpToolAnnotations used snake_case field names (destructive_hint, read_only_hint, etc.) but the MCP specification and all compliant servers send camelCase (destructiveHint, readOnlyHint, etc.). Because every field had #[serde(default)], serde silently defaulted them all to false when the camelCase keys didn't match — so requires_approval() always returned false and destructive MCP tools (e.g. pods_delete, resources_delete) bypassed user approval entirely. Fix: add #[serde(rename_all = "camelCase")] to McpToolAnnotations. Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> Co-authored-by: Illia Polosukhin <ilblackdragon@gmail.com>
…2238 chore: promote staging to staging-promote/d567d94c-23755250735 (2026-03-30 18:33 UTC)
…0735 chore: promote staging to staging-promote/d0f7862a-23733136790 (2026-03-30 16:19 UTC)
…6790 chore: promote staging to staging-promote/c75dea0e-23731217718 (2026-03-30 07:31 UTC)
…7718 chore: promote staging to staging-promote/8acdd080-23726030902 (2026-03-30 06:33 UTC)
…0902 chore: promote staging to staging-promote/368d2f52-23720185295 (2026-03-30 03:01 UTC)
…5295 chore: promote staging to staging-promote/70214c4a-23719079615 (2026-03-29 22:05 UTC)
…9615 chore: promote staging to staging-promote/86389dab-23706696435 (2026-03-29 21:07 UTC)
…6435 chore: promote staging to staging-promote/e0e530e6-23703082447 (2026-03-29 10:07 UTC)
…2447 chore: promote staging to staging-promote/a8e83210-23702343584 (2026-03-29 06:21 UTC)
…3584 chore: promote staging to staging-promote/8a320ae9-23693265249 (2026-03-29 05:32 UTC)
…5249 chore: promote staging to staging-promote/fd41bdf4-23691145719 (2026-03-28 20:05 UTC)
…5719 chore: promote staging to staging-promote/de5a1c7b-23688974037 (2026-03-28 18:06 UTC)
…4037 chore: promote staging to staging-promote/9bb19a98-23687925861 (2026-03-28 16:06 UTC)
…5861 chore: promote staging to staging-promote/9ba10eac-23686921981 (2026-03-28 15:07 UTC)
…1981 chore: promote staging to staging-promote/8f8cb7f7-23680994633 (2026-03-28 14:09 UTC)
…4633 chore: promote staging to staging-promote/7234700c-23635804857 (2026-03-28 08:09 UTC)
…4857 chore: promote staging to main (2026-03-27 07:25 UTC)
…4551 chore: promote staging to staging-promote/8fe6298a-23774093847 (2026-03-31 02:03 UTC)
…3847 chore: promote staging to staging-promote/adb30b69-23770143313 (2026-03-31 00:15 UTC)
…3313 chore: promote staging to main (2026-03-30 22:09 UTC)
chore(ironclaw): release v0.24.0
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Syncs staging with main by aligning MCP protocol deserialization with the MCP spec and updating release metadata/artifacts to the 0.24.0 release.
Changes:
- Deserialize
McpToolAnnotationsusing spec-compliant camelCase field names and add a regression test to ensure destructive tools require approval. - Update Slack/Discord/Feishu channel registry entries to newer artifact versions and release URLs.
- Bump crate version to
0.24.0and add the0.24.0changelog entry.
Reviewed changes
Copilot reviewed 6 out of 7 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
src/tools/mcp/protocol.rs |
Ensures MCP tool annotations deserialize from camelCase (per spec) and adds a test preventing destructive tools from bypassing approval. |
registry/channels/slack.json |
Updates Slack channel registry version and artifact URL/SHA to the 0.24.0 release. |
registry/channels/feishu.json |
Updates Feishu channel registry version and artifact URL/SHA to the 0.24.0 release. |
registry/channels/discord.json |
Updates Discord channel registry version and artifact URL/SHA to the 0.24.0 release. |
CHANGELOG.md |
Adds the 0.24.0 release section. |
Cargo.toml |
Bumps the workspace package version to 0.24.0. |
Cargo.lock |
Updates the locked ironclaw package version to 0.24.0. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
There was a problem hiding this comment.
Code Review
This pull request bumps the project version to 0.24.0 and updates the changelog with a comprehensive list of recent additions, fixes, and improvements. Key changes include the implementation of OIDC JWT authentication, multi-tenant isolation, and various reliability fixes for workers and routines. Additionally, the McpToolAnnotations struct was updated to correctly handle camelCase deserialization from MCP-compliant servers, supported by a new regression test. I have no feedback to provide.
Chore sync staging with main
Summary
Change Type
Linked Issue
Validation
cargo fmt --all -- --checkcargo clippy --all --benches --tests --examples --all-features -- -D warningscargo buildcargo test --features integrationif database-backed or integration behavior changedreview-prorpr-shepherd --fixwas run before requesting reviewSecurity Impact
Database Impact
Blast Radius
Rollback Plan
Review Follow-Through
Review track: