Skip to content

chore: promote staging to staging-promote/e35099de-24682241364 (2026-04-20 19:04 UTC) - #2758

Merged
henrypark133 merged 2 commits into
mainfrom
staging-promote/336bdb1e-24684983862
Apr 21, 2026
Merged

henrypark133 merged 2 commits into
mainfrom
staging-promote/336bdb1e-24684983862

Conversation

@ironclaw-ci

@ironclaw-ci ironclaw-ci Bot commented Apr 20, 2026 •

Copy link
Copy Markdown
Contributor

Auto-promotion from staging CI

Batch range: 7fb41555a9e55677d1aaea29ca567a5b369c2b05..336bdb1ec84af0b510468da66824e3f1e47af69f
Promotion branch: staging-promote/336bdb1e-24684983862
Base: staging-promote/e35099de-24682241364
Triggered by: Staging CI batch at 2026-04-20 19:04 UTC

Commits in this batch (52):

Current commits in this promotion (2)

Current base: staging-promote/e35099de-24682241364
Current head: staging-promote/336bdb1e-24684983862
Current range: origin/staging-promote/e35099de-24682241364..origin/staging-promote/336bdb1e-24684983862

Auto-updated by staging promotion metadata workflow

Waiting for gates:

  • Tests: pending
  • E2E: pending
  • Claude Code review: pending (will post comments on this PR)

Auto-created by staging-ci workflow

serrrfirat and others added 2 commits April 20, 2026 20:38
* fix(gateway): keep engine threads out of chat sidebar

* fix: address review findings (iteration 1)

* fix: address review findings (iteration 2)
…ers (#2546) (#2747)

* fix(bridge): sanitize orchestrator failures before showing them to users (#2546)

When the engine returned `ThreadOutcome::Failed { error }` the raw string
reached the user verbatim through `BridgeOutcome::Respond(format!("Error: {error}"))`.
The string includes multiple layers of wrapping (`Orchestrator error: effect
execution error: ...`), the Monty-hosted Python traceback with internal file
paths (`File "orchestrator.py", line 907`), and the upstream HTTP body
(`HTTP 502 Bad Gateway`). This is what the QA bug bash reported: a 502 from
the LLM provider surfaced the whole stack to a user on staging.

Add a shared `bridge::user_facing_errors` module that classifies failure
strings into intent-level categories (LLM unavailable, rate-limited, context
too large, auth failure, iteration limit, unknown) and returns a short,
user-safe message for each. Route `ThreadOutcome::Failed` through a named
helper (`bridge_outcome_for_failed_thread`) that logs the full raw error
server-side via `tracing::warn!` and responds with the sanitized text.

Extensive unit tests cover both the classifier and the router-side helper,
including the exact 502 traceback from the issue as a regression fixture
plus 413 (#2276) and context-length (#2408) variants.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(bridge): tighten failure classification patterns from PR #2747 review

- Drop overly broad substring matches ("tokens used", "unauthorized",
  "request failed", "provider nearai") that caused misclassification.
- Reword AuthFailure user message to be channel-agnostic.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added scope: channel/web Web gateway channel size: XL 500+ changed lines risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Apr 20, 2026
@claude

claude Bot commented Apr 20, 2026

Copy link
Copy Markdown

Code review

Found 2 issues:

  1. [HIGH:85] Unbounded JavaScript Map growth in threadChannelHints

The new threadChannelHints Map accumulates entries for every deep-linked engine thread with no eviction or size limit. In long-running browser sessions (e.g., 24+ hours), this could grow to thousands of entries and leak memory. Each entry persists for the lifetime of the page session even after threads are closed.

Recommendation: Implement bounded cache with LRU eviction (cap at 100 threads) or TTL-based cleanup.

https://github.com/anthropics/ironclaw/blob/34210b016441acbb1fc85f03dea557a1a0b526a8/crates/ironclaw_gateway/static/js/core/bootstrap.js#L79-L84

https://github.com/anthropics/ironclaw/blob/34210b016441acbb1fc85f03dea557a1a0b526a8/crates/ironclaw_gateway/static/js/core/history.js#L40-L46

  1. [MEDIUM:75] Stringly-typed channel field should be enum

The new channel: Option<String> field in HistoryResponse hardcodes values like "engine" and "gateway" across multiple code paths and the frontend. Per CLAUDE.md design patterns ("Prefer strong types over strings"), this should be an enum to prevent typos and enforce type safety at the wire boundary. A typo like "engien" would silently propagate to the frontend.

Recommendation: Define enum ChannelHint { Engine, Gateway } and serialize with #[serde(rename_all = "snake_case")].

https://github.com/anthropics/ironclaw/blob/34210b016441acbb1fc85f03dea557a1a0b526a8/src/channels/web/types.rs#L124-L133

https://github.com/anthropics/ironclaw/blob/34210b016441acbb1fc85f03dea557a1a0b526a8/src/channels/web/features/chat/mod.rs#L621-L625


Strengths

  • Excellent error sanitization: 60+ comprehensive tests covering regression fixture ([Bug Bash 4/16] Orchestrator surfaces raw HTTP 502 Bad Gateway error to user #2546 Python traceback), rate limiting, context overflow, auth failures, and defensive pattern matching. Clear separation of concerns with server-side logging of raw error and sanitized user-facing copy.
  • Channel-agnostic user copy: Error messages avoid channel-specific verbs ("reconnect") and work across web/CLI/Telegram channels.
  • Well-scoped architectural change: Correctly reverts engine thread merge with clear rationale (foreground threads rotate per message, shouldn't surface as permanent sidebar entries) and includes regression test validating new behavior.
  • No security vulnerabilities: Thorough analysis found no command injection, XSS, auth bypass, or secrets leakage patterns.

Base automatically changed from staging-promote/e35099de-24682241364 to main April 21, 2026 03:18
@henrypark133
henrypark133 merged commit 336bdb1 into main Apr 21, 2026
342 of 452 checks passed
@henrypark133
henrypark133 deleted the staging-promote/336bdb1e-24684983862 branch April 21, 2026 03:18

This branch had an error being deployed

1 failed and 5 inactive deployments
Ironclaw-QA / production — 336bdb1e Deployed Apr 20, 2026 by railway-app[bot]
ironclaw-nearai / production — 336bdb1e Deployed Apr 20, 2026 by railway-app[bot]
venice-ironclaw / production — 336bdb1e Deployed Apr 20, 2026 by railway-app[bot]
cosmose-ironclaw / production — 336bdb1e Deployed Apr 20, 2026 by railway-app[bot]
humble-cat / staging-cameron — 336bdb1e Deployed Apr 20, 2026 by railway-app[bot]
Near Foundation Ironclaw / production — 336bdb1e Deployed Apr 20, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: channel/web Web gateway channel size: XL 500+ changed lines staging-promotion

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants