Skip to content

chore: promote staging to staging-promote/0a9d8165-24418728605 (2026-04-14 20:19 UTC) - #2472

Merged
henrypark133 merged 5 commits into
mainfrom
staging-promote/d63601ea-24420891050
Apr 18, 2026
Merged

henrypark133 merged 5 commits into
mainfrom
staging-promote/d63601ea-24420891050

Conversation

@ironclaw-ci

@ironclaw-ci ironclaw-ci Bot commented Apr 14, 2026 •

Copy link
Copy Markdown
Contributor

Auto-promotion from staging CI

Batch range: a53eac5c2dec6b6cd5c08189086093fde64aa9cb..d63601eaed6c31f73c57328bc924f3c1ebaf41a8
Promotion branch: staging-promote/d63601ea-24420891050
Base: staging-promote/0a9d8165-24418728605
Triggered by: Staging CI batch at 2026-04-14 20:19 UTC

Commits in this batch (39):

Current commits in this promotion (0)

Current base: main
Current head: staging-promote/d63601ea-24420891050
Current range: origin/main..origin/staging-promote/d63601ea-24420891050

  • (no non-merge commits in range)

Auto-updated by staging promotion metadata workflow

Waiting for gates:

  • Tests: pending
  • E2E: pending
  • Claude Code review: pending (will post comments on this PR)

Auto-created by staging-ci workflow

pranavraja99 and others added 5 commits April 14, 2026 12:44
Document the /v1/responses endpoints (create, get) including
streaming SSE events, structured context (x_context), and
multi-turn conversation support via previous_response_id.

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* feat: add google turorial

* feat: update zh google tutorial

* feat: update firewall rules

* feat: update zh files
* Fix WASM channel owner_id fallback

* ci: ignore rand advisory

* ci: satisfy cargo-deny path dependency versions

* fix(telegram): handle null/string owner_id and propagate to WASM config

The bundled Telegram capabilities.json ships `"owner_id": null`. The
previous code only called `Value::as_i64()`, which returns `None` for
`Null`, so the fallback silently produced no owner — the fix never
actually worked for Telegram.

Changes:
- Handle `Null`, `String`, and `Number` variants in
  `owner_actor_id_for_channel()` so the real production payload works.
- Propagate the *resolved* owner_id into the WASM runtime config map
  regardless of whether it came from runtime config or capabilities
  fallback (previously only the runtime-config path injected it).
- Add `tracing::debug!` for non-scalar owner_id values to aid debugging.
- Add tests: null config, missing capabilities file, empty string,
  non-scalar value, and caller-level register_channel tests that verify
  config injection and null-owner-id handling.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: drop overlapping Cargo.toml and deny.toml changes per review

Revert cosmetic Cargo.toml attribute reorder and deny.toml comment
shortening that overlap with #2370 already on staging, avoiding
potential merge conflicts.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: log debug warning for non-integer numeric owner_id in capabilities

When as_i64() returns None for a numeric owner_id (e.g., 1.0), emit a
debug log to aid debugging instead of silently returning None. Adds a
regression test for the float case.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* ci: retrigger checks

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Co-authored-by: Zaki <zaki@iqlusion.io>
* fix(ci): exclude test files from PR size classification

Test code shouldn't inflate PR size labels — a 1-line fix with 500
lines of tests was getting classified as XL instead of XS.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* ci: retrigger with skip-regression-check label

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Zaki <zaki@iqlusion.io>
…) (#2401)

The `rewrite_telegram_api_url_for_testing()`, `rewrite_http_url_for_testing()`,
and their supporting constants/helpers were gated behind
`#[cfg(any(test, debug_assertions))]`, which means they shipped in all debug
builds — including development/staging deployments. An attacker who could set
`IRONCLAW_TEST_TELEGRAM_API_BASE_URL` or `IRONCLAW_TEST_HTTP_REWRITE_MAP`
environment variables on such a deployment could redirect Telegram API traffic
(and other HTTP traffic) to an arbitrary host.

Changes:
- Narrow all test URL rewrite constants, functions, and helpers from
  `#[cfg(any(test, debug_assertions))]` to `#[cfg(test)]`
- Add missing `#[cfg(test)]` to `TELEGRAM_TEST_API_BASE_ENV` (was ungated)
- Wrap the call site in `http_request()` with `#[cfg(test)]`/`#[cfg(not(test))]`
  blocks so production builds use `logical_url` directly
- Remove the now-unnecessary `#[cfg(not(...))]` stub functions that returned None

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added scope: channel/wasm WASM channel runtime scope: ci CI/CD workflows scope: docs Documentation size: XL 500+ changed lines risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Apr 14, 2026
@claude

claude Bot commented Apr 14, 2026

Copy link
Copy Markdown

Code review

Found 4 issues:

  1. [CRITICAL:100] Logging level violation in test URL rewriting instrumentation

    The log statement at line 397-399 in src/channels/wasm/wrapper.rs uses tracing::info!() for test instrumentation. Per CLAUDE.md: "info! and warn! output appears in the REPL and corrupts the terminal UI. Use debug! for internal diagnostics." This test-gated code will still corrupt the REPL/TUI when tests run.

    Fix: Change to tracing::debug!() instead.

    https://github.com/neardotorg/ironclaw/blob/3992795c9ef00740ce90243f5b12837d83d85440/src/channels/wasm/wrapper.rs#L397-L399

  2. [MEDIUM:85] Debug assertions support removed without migration path

    The PR changes test URL rewriters from #[cfg(any(test, debug_assertions))] to #[cfg(test)] only (lines 4153, 4183 in wrapper.rs), removing the old #[cfg(not(...))] stub functions. This breaks URL rewriting in cargo run debug builds, a common mode for local development with fake servers.

    Impact: Developers using local integration testing with fake API servers will lose the ability to test with debug builds. The old code supported this intentionally.

    Decision needed: Was this intentional? If so, should be documented. If unintentional, revert gate to debug_assertions or add a feature flag.

    https://github.com/neardotorg/ironclaw/blob/3992795c9ef00740ce90243f5b12837d83d85440/src/channels/wasm/wrapper.rs#L4151-L4154

  3. [MEDIUM:80] Owner ID fallback classifier missing caller-level test

    The new owner_actor_id_for_channel() function (lines 359-405 in setup.rs) gates credential scoping. Per CLAUDE.md "Test Through the Caller, Not Just the Helper" rule: when a classifier gates side effects and has multiple inputs, unit tests alone are insufficient. The helper tests (lines 697-787) verify the function in isolation, but the async integration tests (lines 789-847) all use the same test_loaded_channel() helper and don't vary the capabilities file scenarios sufficiently. Missing: test case where config has no entry but capabilities provides one, to verify the fallback order.

    Recommendation: Add a test that explicitly validates the fallback order when config is empty and capabilities provides an owner_id.

    https://github.com/neardotorg/ironclaw/blob/3992795c9ef00740ce90243f5b12837d83d85440/src/channels/wasm/setup.rs#L359-L405

  4. [MEDIUM:75] Unnecessary string allocations in initialization hot path

    The owner_actor_id_for_channel() function performs multiple unnecessary string allocations:

    • Line 368: .map(ToString::to_string) clones even when result is returned as Option
    • Line 384: id.map(|id| id.to_string()) converts i64 to string eagerly
    • Line 391: Some(trimmed.to_string()) allocates when original string could be used

    While not critical at boot time, these represent unnecessary GC pressure.

    Recommendation: Minimize allocations by keeping strings as references longer in the Option chain, or use Cow<str> for the trimmed case.

    https://github.com/neardotorg/ironclaw/blob/3992795c9ef00740ce90243f5b12837d83d85440/src/channels/wasm/setup.rs#L364-L405

Base automatically changed from staging-promote/0a9d8165-24418728605 to main April 18, 2026 00:59
@henrypark133
henrypark133 merged commit d63601e into main Apr 18, 2026
38 of 45 checks passed
@henrypark133
henrypark133 deleted the staging-promote/d63601ea-24420891050 branch April 18, 2026 01:00

This branch had an error being deployed

1 failed and 3 inactive deployments
humble-cat / staging-cameron — d63601ea Deployed Apr 14, 2026 by railway-app[bot]
ironclaw-nearai / production — d63601ea Deployed Apr 14, 2026 by railway-app[bot]
venice-ironclaw / production — d63601ea Deployed Apr 14, 2026 by railway-app[bot]
cosmose-ironclaw / production — d63601ea Deployed Apr 14, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: channel/wasm WASM channel runtime scope: ci CI/CD workflows scope: docs Documentation size: XL 500+ changed lines staging-promotion

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants