Skip to content

test(reborn): add runtime lane dispatch smoke coverage - #3109

Merged
serrrfirat merged 2 commits into
reborn-integrationfrom
reborn-integration-tests-phase2-runtime-lanes
Apr 30, 2026
Merged

serrrfirat merged 2 commits into
reborn-integrationfrom
reborn-integration-tests-phase2-runtime-lanes

Conversation

@serrrfirat

Copy link
Copy Markdown
Collaborator

Summary

Implements issue #3067 Phase 2 runtime-lane smoke coverage now that Script/MCP (#3027) and WIT WASM (#3097) are both on reborn-integration.

Adds caller-level tests that drive each real runtime lane through the public RuntimeDispatcher / RuntimeAdapter seam instead of only through crate-local runtime contracts:

  • Script lane dispatch smoke in crates/ironclaw_scripts/tests/script_dispatch_integration.rs
    • manifest command/args are used
    • invocation input is passed as JSON stdin
    • success reconciles resources
    • non-zero exit and invalid JSON release reservations and emit sanitized dispatch failures
  • MCP lane dispatch smoke in crates/ironclaw_mcp/tests/mcp_dispatch_integration.rs
    • manifest transport/command/args are used
    • invocation input reaches the client adapter
    • success reconciles resources
    • client failure and output-limit failure release reservations and emit sanitized dispatch failures
  • WASM lane dispatch smoke in crates/ironclaw_wasm/tests/wasm_dispatch_integration.rs
    • component bytes are loaded through RootFilesystem virtual paths
    • canonical WIT/component-model exports are exercised
    • fresh instance per dispatch is proven
    • guest trap releases the reservation and emits sanitized dispatch failure

Also updates stale dispatcher test fixtures from obsolete trust = "sandbox" to trust = "untrusted", matching the current manifest parser.

Verification

cargo fmt --all -- --check
CARGO_TARGET_DIR=/tmp/ironclaw-reborn-integration-target cargo test -p ironclaw_dispatcher -p ironclaw_scripts -p ironclaw_mcp -p ironclaw_wasm
CARGO_TARGET_DIR=/tmp/ironclaw-reborn-integration-target cargo clippy -q -p ironclaw_dispatcher -p ironclaw_scripts -p ironclaw_mcp -p ironclaw_wasm --all-targets -- -D warnings
CARGO_TARGET_DIR=/tmp/ironclaw-reborn-integration-target cargo test -p ironclaw_architecture
python3.11 scripts/check_no_panics.py --base origin/reborn-integration --head HEAD
bash scripts/pre-commit-safety.sh
git diff --check

Links

@github-actions github-actions Bot added scope: dependencies Dependency updates size: S 10-49 changed lines risk: low Changes to docs, tests, or low-risk modules labels Apr 30, 2026
@github-actions github-actions Bot added the contributor: core 20+ merged PRs label Apr 30, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces comprehensive integration tests for the MCP, Script, and WASM dispatch lanes, while updating test fixtures to use the 'untrusted' trust level. Feedback identifies a trust level inconsistency in a manifest, a potential resource exhaustion vulnerability where expensive WASM compilation occurs before resource reservation, and resource leaks in test helpers due to the use of .keep() on temporary directories.

name = "GitHub MCP"
version = "0.1.0"
description = "GitHub MCP adapter"
trust = "third_party"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The trust value "third_party" is inconsistent with the other test fixtures updated in this PR, which now use "untrusted". According to the PR description, fixtures are being updated to match the current manifest parser.

Suggested change
trust = "third_party"
trust = "untrusted"

Comment on lines +149 to +154
let prepared = self
.runtime
.prepare(request.capability_id.as_str(), &wasm_bytes)
.map_err(|error| DispatchError::Wasm {
kind: wasm_error_kind(&error),
})?;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Expensive WASM preparation (compilation) is performed before checking or creating a resource reservation. This is inconsistent with the MCP and Script lanes, and could allow a burst of requests to exhaust host CPU/memory during the compilation phase before the governor can apply concurrency limits. Consider moving the reservation logic to the beginning of dispatch_json.

References
  1. Prioritize addressing contention and resource exhaustion issues, as these are considered high-priority correctness concerns.

}

fn mounted_empty_extension_root() -> LocalFilesystem {
let storage = tempfile::tempdir().unwrap().keep();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Using .keep() on a TempDir prevents the directory from being deleted when the test finishes, leading to resource leaks in the /tmp directory. Consider returning the TempDir from this helper and binding it in the test function to manage its lifetime without leaking.

References
  1. Encapsulate complex logic within helper functions and expose a simpler interface or data structure tailored to the caller's needs, such as returning resource handles to the caller for lifetime management.

}

fn mounted_empty_extension_root() -> LocalFilesystem {
let storage = tempfile::tempdir().unwrap().keep();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Using .keep() on a TempDir prevents the directory from being deleted when the test finishes, leading to resource leaks in the /tmp directory. Consider returning the TempDir from this helper and binding it in the test function to manage its lifetime without leaking.

References
  1. Encapsulate complex logic within helper functions and expose a simpler interface or data structure tailored to the caller's needs, such as returning resource handles to the caller for lifetime management.

}

fn mounted_empty_extension_root() -> LocalFilesystem {
let storage = tempfile::tempdir().unwrap().keep();

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Using .keep() on a TempDir prevents the directory from being deleted when the test finishes, leading to resource leaks in the /tmp directory. Consider returning the TempDir from this helper and binding it in the test function to manage its lifetime without leaking.

References
  1. Encapsulate complex logic within helper functions and expose a simpler interface or data structure tailored to the caller's needs, such as returning resource handles to the caller for lifetime management.

@serrrfirat
serrrfirat merged commit 9314f85 into reborn-integration Apr 30, 2026
17 checks passed
@serrrfirat
serrrfirat deleted the reborn-integration-tests-phase2-runtime-lanes branch April 30, 2026 11:40
theredspoon pushed a commit to theredspoon/ironclaw that referenced this pull request Jun 21, 2026
* test(reborn): add runtime lane dispatch smoke coverage

* test(reborn): harden runtime lane smoke coverage
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: dependencies Dependency updates size: S 10-49 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant