Skip to content

fix(reborn): close foundation fail-closed gaps - #2997

Merged
serrrfirat merged 1 commit into
reborn-integrationfrom
reborn-foundation-review-fixes
Apr 28, 2026
Merged

serrrfirat merged 1 commit into
reborn-integrationfrom
reborn-foundation-review-fixes

Conversation

@serrrfirat

Copy link
Copy Markdown
Collaborator

Summary

Fixes two fail-closed foundation issues surfaced from downstream PR review feedback:

  • Caps approval fingerprint canonical JSON traversal depth so deeply nested invocation input returns a controlled HostApiError instead of risking stack overflow.
  • Rejects negative USD resource estimates before reservation state mutation so reservations cannot credit active reserved balances.

Changes

  • ironclaw_host_api

    • Makes canonical_json(...) return Result<serde_json::Value, HostApiError>.
    • Adds a MAX_CANONICAL_JSON_DEPTH guard.
    • Adds a 10k-deep nested input regression test for invocation fingerprints.
  • ironclaw_resources

    • Adds ResourceError::InvalidEstimate.
    • Validates estimate.usd >= 0 in reserve_with_id(...) before acquiring/mutating reservation state.
    • Adds a regression test proving negative USD estimates are rejected and reserved balance remains unchanged.

Verification

cargo test -p ironclaw_host_api -p ironclaw_resources
cargo clippy -p ironclaw_host_api -p ironclaw_resources --all-targets -- -D warnings
cargo fmt --check
git diff --check

Loading
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs reborn IronClaw Reborn architecture and landing work risk: low Changes to docs, tests, or low-risk modules size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants