Skip to content

feat(reborn): add script and mcp runtime lanes - #3027

Merged
serrrfirat merged 1 commit into
reborn-integrationfrom
reborn-land-04c-script-mcp-runtimes
Apr 29, 2026
Merged

serrrfirat merged 1 commit into
reborn-integrationfrom
reborn-land-04c-script-mcp-runtimes

Conversation

@serrrfirat

@serrrfirat serrrfirat commented Apr 28, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Carves the smaller non-WASM runtime lane substrates from the Reborn stack.

Adds:

crates/ironclaw_scripts
crates/ironclaw_mcp

ironclaw_scripts includes:

  • ScriptRuntime
  • ScriptRuntimeConfig
  • ScriptExecutionRequest / ScriptExecutionResult
  • ScriptBackend contract and backend request/output shapes
  • declared-capability/runtime validation before resource reservation
  • reservation/reconcile/release flow
  • output limit enforcement

ironclaw_mcp includes:

  • McpRuntime
  • McpRuntimeConfig
  • McpExecutionRequest / McpExecutionResult
  • McpClient contract and client request/output shapes
  • declared-capability/runtime validation before resource reservation
  • reservation/reconcile/release flow
  • output limit enforcement

Current status

Rebased onto current reborn-integration after the prerequisite substrate stack landed, including #3023, #3072, and #3076.

The diff is now narrowed to only:

crates/ironclaw_scripts
crates/ironclaw_mcp
Cargo.toml / Cargo.lock membership for those crates

This slice is independent of the remaining in-flight Reborn PRs (#3028 WASM runtime lane and #3071 CapabilityHost base).

Scope boundary

This PR intentionally does not include:

  • WASM runtime lane (ironclaw_wasm) — separate PR
  • dispatcher adapter wiring
  • host runtime composition
  • CapabilityHost
  • built-in obligation handling
  • secrets/network substrates
  • production app wiring or user-visible behavior changes

Exposure checklist

Does this affect existing src/ runtime behavior? no
Does this alter app startup/config defaults? no
Does this expose new routes/CLI/user-visible APIs? no
Does this create a second writer for existing production state? no
Are all Reborn paths feature-gated or unused by default? yes, unused internal crate substrate
Are docs/status labels accurate: implemented slice vs product complete? yes, Script/MCP runtime lane substrate only

TDD note

Copied the Script/MCP contract tests first against RED stubs and confirmed cargo test -p ironclaw_scripts -p ironclaw_mcp failed due missing runtime/client/backend types before porting the implementations.

Verification

Passed after rebasing onto current reborn-integration:

cargo fmt --all -- --check
cargo test -p ironclaw_scripts -p ironclaw_mcp
cargo clippy -p ironclaw_scripts -p ironclaw_mcp --all-targets -- -D warnings
cargo test -p ironclaw_architecture
python3.11 scripts/check_no_panics.py --base origin/reborn-integration --head HEAD
bash scripts/pre-commit-safety.sh
git diff --check
cargo tree -p ironclaw_scripts -e normal | grep -E 'ironclaw_(authorization|approvals|capabilities|dispatcher|host_runtime|processes|run_state|secrets|network|wasm)' || true
cargo tree -p ironclaw_mcp -e normal | grep -E 'ironclaw_(authorization|approvals|capabilities|dispatcher|host_runtime|processes|run_state|secrets|network|wasm)' || true

Boundary greps returned no forbidden normal Reborn dependencies.

Refs #2987.

@github-actions github-actions Bot added scope: db/postgres PostgreSQL backend scope: docs Documentation scope: dependencies Dependency updates DB MIGRATION PR adds or modifies PostgreSQL or libSQL migration definitions size: XL 500+ changed lines labels Apr 28, 2026
@github-actions github-actions Bot added risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Apr 28, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a major architectural update for IronClaw Reborn, adding ten new crates that implement core services for authorization, process lifecycle management, and scoped filesystem access. The review feedback focuses on enhancing system reliability and error handling. Key recommendations include explicitly logging errors in background process tasks to prevent silent failures and replacing brittle string-based 'not found' error detection with a dedicated NotFound variant in the FilesystemError enum for better type safety and consistency across the new crates.

Comment thread crates/ironclaw_processes/src/lib.rs Outdated
Comment on lines +1196 to +1221
tokio::spawn(async move {
match executor.execute(request).await {
Ok(result) => {
if let Ok(record) = store.complete(&scope, process_id).await
&& let Some(result_store) = &result_store
{
let _ = result_store
.complete(&record.scope, record.process_id, result.output)
.await;
}
}
Err(error) => {
if let Ok(record) = store.fail(&scope, process_id, error.kind).await
&& let Some(result_store) = &result_store
&& let Some(error_kind) = record.error_kind.clone()
{
let _ = result_store
.fail(&record.scope, record.process_id, error_kind)
.await;
}
}
}
if let Some(registry) = cancellation_registry {
registry.unregister(&scope, process_id);
}
});

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The error handling within the spawned task for a background process is currently 'best effort' and silently ignores failures from store.complete and store.fail. These errors should be surfaced via tracing::warn! to ensure reliability and visibility. Additionally, if these functions handle errors internally and return (), they should not be awaited with the ? operator.

References
  1. When performing background persistence or state updates, errors should be surfaced via tracing::warn! to ensure reliability in short-lived or detached contexts.
  2. Functions that handle errors internally and return () should not be awaited with the ? operator.

Comment on lines +767 to +776
fn is_not_found(error: &FilesystemError) -> bool {
match error {
FilesystemError::Backend { reason, .. } => {
reason.contains("No such file")
|| reason.contains("not found")
|| reason.contains("entity not found")
}
_ => false,
}
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

This function relies on string matching on the error reason to detect 'not found' errors, which is brittle. To improve robustness and reduce duplication across crates, please introduce a specific NotFound variant to the FilesystemError enum in the ironclaw_filesystem crate. This allows for type-safe error handling and avoids relying on generic substring matching.

References
  1. Create specific error variants for different failure modes to provide semantically correct and clear error messages.
  2. When classifying errors by matching substrings, avoid overly generic patterns that can cause false positives. Prefer specific markers or explicit error variants.

Comment thread crates/ironclaw_processes/src/lib.rs Outdated
Comment on lines +1847 to +1856
fn is_not_found(error: &FilesystemError) -> bool {
match error {
FilesystemError::Backend { reason, .. } => {
reason.contains("No such file")
|| reason.contains("not found")
|| reason.contains("os error 2")
}
_ => false,
}
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

This is_not_found helper function relies on brittle string matching. To improve robustness and reduce duplication, consider adding a specific NotFound variant to the FilesystemError enum in the ironclaw_filesystem crate. This would allow for type-safe error checking and remove the need for this helper function in multiple places.

References
  1. Create specific error variants for different failure modes to provide semantically correct and clear error messages.
  2. When classifying errors by matching substrings, avoid overly generic patterns that can cause false positives.

Comment on lines +787 to +796
fn is_not_found(error: &FilesystemError) -> bool {
match error {
FilesystemError::Backend { reason, .. } => {
reason.contains("No such file")
|| reason.contains("not found")
|| reason.contains("os error 2")
}
_ => false,
}
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

This is_not_found helper function is duplicated across several crates and relies on brittle string matching. Following repository standards, please introduce a specific NotFound variant to the FilesystemError enum in the ironclaw_filesystem crate to enable type-safe error handling and eliminate the need for substring matching.

References
  1. Create specific error variants for different failure modes to provide semantically correct and clear error messages.
  2. When classifying errors by matching substrings, avoid overly generic patterns that can cause false positives.

@serrrfirat serrrfirat added the reborn IronClaw Reborn architecture and landing work label Apr 29, 2026
@serrrfirat
serrrfirat force-pushed the reborn-land-04c-script-mcp-runtimes branch 3 times, most recently from 52a047d to 8b04d38 Compare April 29, 2026 13:25
@serrrfirat
serrrfirat marked this pull request as ready for review April 29, 2026 13:28
@serrrfirat
serrrfirat force-pushed the reborn-land-04c-script-mcp-runtimes branch from 8b04d38 to 18e2857 Compare April 29, 2026 13:35
@serrrfirat
serrrfirat force-pushed the reborn-land-04c-script-mcp-runtimes branch from 18e2857 to d81d27a Compare April 29, 2026 13:44
@serrrfirat
serrrfirat merged commit 70aaa84 into reborn-integration Apr 29, 2026
18 checks passed
@serrrfirat
serrrfirat deleted the reborn-land-04c-script-mcp-runtimes branch April 29, 2026 13:53
theredspoon pushed a commit to theredspoon/ironclaw that referenced this pull request Jun 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs DB MIGRATION PR adds or modifies PostgreSQL or libSQL migration definitions reborn IronClaw Reborn architecture and landing work risk: medium Business logic, config, or moderate-risk modules scope: db/postgres PostgreSQL backend scope: dependencies Dependency updates scope: docs Documentation size: XL 500+ changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant