Skip to content

chore: promote staging to staging-promote/764e5867-24277535589 (2026-04-11 09:13 UTC) - #2333

Merged
henrypark133 merged 4 commits into
mainfrom
staging-promote/88b87c0a-24279348444
Apr 18, 2026
Merged

henrypark133 merged 4 commits into
mainfrom
staging-promote/88b87c0a-24279348444

Conversation

@ironclaw-ci

@ironclaw-ci ironclaw-ci Bot commented Apr 11, 2026 •

Copy link
Copy Markdown
Contributor

Auto-promotion from staging CI

Batch range: a53eac5c2dec6b6cd5c08189086093fde64aa9cb..88b87c0ae1144ddf739d725b268b725b81f17258
Promotion branch: staging-promote/88b87c0a-24279348444
Base: staging-promote/764e5867-24277535589
Triggered by: Staging CI batch at 2026-04-11 09:13 UTC

Commits in this batch (8):

Current commits in this promotion (4)

Current base: staging-promote/764e5867-24277535589
Current head: staging-promote/88b87c0a-24279348444
Current range: origin/staging-promote/764e5867-24277535589..origin/staging-promote/88b87c0a-24279348444

Auto-updated by staging promotion metadata workflow

Waiting for gates:

  • Tests: pending
  • E2E: pending
  • Claude Code review: pending (will post comments on this PR)

Auto-created by staging-ci workflow

serrrfirat and others added 4 commits April 11, 2026 17:09
The TUI (Ratatui-based terminal UI) is the richer, more polished
interactive experience with sidebar, log broadcaster, and context
display. The REPL is a bare-bones fallback. Since the `tui` cargo
feature is already compiled in by default, the runtime should match.

Users can still opt out with CLI_MODE=repl in env or DB settings.

[skip-regression-check]

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Re-applies two changes that were reverted on main (92388b7) to unblock
the staging-promote merge. Neither existed on staging:

- Fix Telegram message splitting to count UTF-16 code units instead of
  Unicode scalar values (emoji like 😀 are 2 UTF-16 units, not 1)
- Add "DB MIGRATION" auto-label for PRs touching migration files

Original commits: 6f7575d (#1961), 7be3b91 (#1967)

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat: user-facing temperature setting for LLM requests

Add a configurable default sampling temperature (0.0–2.0) that users
can set via the web settings UI or API. The setting flows into the
main conversational agent loop via ReasoningContext, replacing the
hardcoded 0.7 default. Per-request temperature (e.g. from the
OpenAI-compatible endpoint) still takes precedence.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* feat: admin-scoped settings fallback for multi-tenant

Admin-set defaults now propagate to all members who haven't overridden
the value themselves. Three layers of change:

1. TenantScope::get_setting_with_admin_fallback() — checks user scope
   first, then falls back to __admin__ scope. Used by the dispatcher
   for temperature and selected_model.

2. Config::from_db_with_toml() — layers admin-scope settings between
   TOML and per-user DB settings during resolution. Priority:
   TOML < admin DB < per-user DB.

3. Settings API — GET/PUT/DELETE /api/settings/{key}?scope=admin lets
   admins read/write to the shared default scope. Non-admins get 403.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: clamp temperature to 0.0-2.0 before reaching provider

Address review comment on #2275: the backend must guard against
bad DB values and per-request overrides that bypass the frontend
range enforcement. Some providers reject out-of-range temperatures
outright.

Clamped at both the read site (dispatcher reading DB settings) and
the use site (reasoning.rs respond_with_tools) for defense in depth.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: address PR #2275 review feedback

- Strip admin-only LLM keys (ollama_base_url, openai_compatible_base_url,
  llm_builtin_overrides, llm_custom_providers) from the admin-scope merge
  in `Config::from_db_with_toml` and `Config::re_resolve_llm_with_secrets`
  when the resolving user is not an operator. Defense-in-depth so a
  non-admin member never inherits private/loopback provider endpoints
  from admin defaults.
- Preserve per-request `reason_ctx.temperature` precedence in the
  dispatcher: settings-derived temperature only applies when no value
  was already set by the API caller. Extract `resolve_settings_temperature`
  helper for direct unit testing.
- Add regression tests covering admin-scope strip behavior for both
  operator and non-operator paths, plus the temperature precedence rule
  including range clamping.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added scope: agent Agent core (agent loop, router, scheduler) scope: channel/web Web gateway channel scope: llm LLM integration scope: config Configuration scope: ci CI/CD workflows size: XL 500+ changed lines risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Apr 11, 2026
@claude

claude Bot commented Apr 11, 2026

Copy link
Copy Markdown

Code review

Found 6 issues:

  1. [HIGH:95] Settings handlers lack admin-scope support for list/export/import endpoints

The PR adds admin-scope query parameter support to settings_get_handler, settings_set_handler, and settings_delete_handler, but settings_list_handler(), settings_export_handler(), and settings_import_handler() were not updated. This creates an inconsistency where admins can set admin-default settings but cannot easily view or bulk-manage them.

https://github.com/anthropics/ironclaw/blob/70862ed57cbce000c915bb3b2a423a2e1d105652/src/channels/web/handlers/settings.rs#L45-L90

  1. [MEDIUM:85] Admin-scope filtering duplication in Config

The Config::from_db_with_toml() (lines 289-306) and Config::re_resolve_llm_with_secrets() (lines 419-429) methods both implement identical admin-scope merging logic. This duplication should be extracted into a shared private helper function to avoid divergence.

https://github.com/anthropics/ironclaw/blob/70862ed57cbce000c915bb3b2a423a2e1d105652/src/config/mod.rs#L283-L320

  1. [MEDIUM:75] Telegram UTF-16 fix uses byte-indexing without boundary validation

The prefix_within_utf16_limit() function correctly computes byte offsets via char iteration, but callers do not assert that the returned window_bytes is a valid char boundary before slicing. Add explicit is_char_boundary() assertions per UTF-8 safety rules.

https://github.com/anthropics/ironclaw/blob/70862ed57cbce000c915bb3b2a423a2e1d105652/channels-src/telegram/src/lib.rs#L383-L449

  1. [MEDIUM:75] Increased database query load in critical path

The temperature setting feature introduces 2 additional get_setting_with_admin_fallback() calls per conversation (at iteration 0), each of which executes 2 sequential database queries. For multi-user systems, resolve_with_secrets() and re_resolve_llm_with_secrets() both call get_all_settings() twice, creating O(N) query multiplication.

https://github.com/anthropics/ironclaw/blob/70862ed57cbce000c915bb3b2a423a2e1d105652/src/agent/dispatcher.rs#L601-L628

  1. [MEDIUM:70] Temperature setting not validated in settings_set_handler

The PR adds temperature to Settings with no validation in settings_set_handler, relying on the dispatcher to clamp values later. This violates defense-in-depth: a malformed API client or DB corruption could persist invalid values. Add a validation check in the handler before storing.

https://github.com/anthropics/ironclaw/blob/70862ed57cbce000c915bb3b2a423a2e1d105652/src/channels/web/handlers/settings.rs#L133-L175

  1. [MEDIUM:70] Expensive settings merge operation in hot path

The Settings::merge_from() method serializes to JSON 3 times per call, invoked in both resolve_with_secrets() and re_resolve_llm_with_secrets(). For N users this is O(N) JSON serialization overhead. Implement field-by-field merging or a single merge_json() helper instead.

https://github.com/anthropics/ironclaw/blob/70862ed57cbce000c915bb3b2a423a2e1d105652/src/settings.rs#L1170-L1189

Base automatically changed from staging-promote/764e5867-24277535589 to main April 18, 2026 00:59
@henrypark133
henrypark133 merged commit 88b87c0 into main Apr 18, 2026
479 of 521 checks passed
@henrypark133
henrypark133 deleted the staging-promote/88b87c0a-24279348444 branch April 18, 2026 01:00

This branch had an error being deployed

1 failed and 4 inactive deployments
cosmose-ironclaw / production — 88b87c0a Deployed Apr 11, 2026 by railway-app[bot]
venice-ironclaw / production — 88b87c0a Deployed Apr 11, 2026 by railway-app[bot]
ironclaw-nearai / production — 88b87c0a Deployed Apr 11, 2026 by railway-app[bot]
humble-cat / staging-cameron — 88b87c0a Deployed Apr 11, 2026 by railway-app[bot]
pleasing-possibility / production — 88b87c0a Deployed Apr 11, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: agent Agent core (agent loop, router, scheduler) scope: channel/web Web gateway channel scope: ci CI/CD workflows scope: config Configuration scope: llm LLM integration size: XL 500+ changed lines staging-promotion

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants