Skip to content

arch(ws-16): wire live planned runtime composition - #3652

Merged
henrypark133 merged 5 commits into
reborn-integrationfrom
arch/ws-16
May 15, 2026
Merged

henrypark133 merged 5 commits into
reborn-integrationfrom
arch/ws-16

Conversation

@henrypark133

@henrypark133 henrypark133 commented May 14, 2026 •

Copy link
Copy Markdown
Collaborator

Context

Live runtime wiring branch. It composes the planned driver, registry, resolver, coordinator, runner, host factory, and real host-port adapters into a production runtime builder.

Master spec: docs/reborn/agent-loop-skeleton.md
Workstream brief: docs/reborn/agent-loop-briefs/live-runtime-wiring.md
Stack base: arch/ws-14

Latest stack maintenance on 2026-05-14:

  • Rebased this branch onto its current stack base after the WS0 prompt-authority fix and the follow-up WS8/WS14-parent/WS16/WS17 conflict resolutions.
  • Pushed the updated branch with force-with-lease where the remote already existed, or published it as a new branch where it did not.
  • Verified the final ancestry chain from origin/reborn-integration through WS17 before publishing the PR descriptions.

What landed

  • RebornRuntimeLoopComposition and build_default_planned_runtime(...).
  • Composition of registry, planned resolver, DefaultTurnCoordinator, TurnRunnerWorker, host factory, and profiled capability port creation.
  • RebornLoopDriverHostFactory::create_host(...) now requires profiled capabilities for planned runs instead of silently falling back to EmptyLoopCapabilityPort.
  • Reborn CLI runtime-readiness snapshot initializes both text-only and planned driver/profile state.
  • Default-path smoke tests over the real planned runtime composition.

Reviewer focus

  • Planned runs should fail closed when required host metadata or profiled capability services are missing.
  • Runtime composition should stay in Reborn/composition-owned code, not leak into the framework crate.
  • The CLI/readiness snapshot should report planned state without mutating v1 runtime state.

Non-goals / deferred work

  • Product no-profile inbound cutover is WS17.
  • Tool-result completion evidence remains a follow-up caveat; WS17 proves no-profile assistant completion and cancellation behavior.
  • This branch should not remove the text-only rollback/default path.

Validation

  • git diff --check
  • cargo fmt --check
  • cargo test -p ironclaw_reborn --test loop_driver_host default_planned_runtime -- --nocapture
  • cargo test -p ironclaw_reborn --test loop_driver_host turn_runner_worker_drives_script_capability_through_real_host_runtime -- --nocapture
  • cargo test -p ironclaw_reborn --test loop_driver_host planned_host_factory -- --nocapture

Stack position

[#3550 ws-0] state/checkpoint foundation -> reborn-integration
   |-- #3551 ws-1 strategy alpha -> ws-0
   |-- #3552 ws-2 strategy beta -> ws-0
   |-- #3553 ws-3 strategy gamma -> ws-0
   |-- #3643 ws-3.5 loop family registry -> ws-0
   '-- #3554 level1-merged -> ws-0
         |-- #3555 ws-4 planner facade -> level1
         |-- #3556 ws-5 default strategies -> level1
         '-- #3557 level2-merged -> level1
               '-- #3596 ws-6a canonical executor -> level2
                     '-- #3597 ws-7 PlannedDriver adapter -> ws-6a
                           '-- #3598 ws-8 integration/test support -> ws-7
                                 |-- #3644 ws-9 capability host wiring -> ws-8
                                 |-- #3645 ws-10 checkpoint load/resume -> ws-8
                                 |-- #3646 ws-11 input port -> ws-8
                                 |-- #3647 ws-12 progress port -> ws-8
                                 |-- #3648 ws-13 cancellation accessor -> ws-8
                                 |-- #3649 ws-15 prompt/identity context -> ws-8
                                 '-- #3650 ws-14-parent integrated host ports -> ws-8
                                       '-- #3651 ws-14 planned default registration -> ws-14-parent
                                             '-- #3652 ws-16 live runtime wiring -> ws-14
                                                   '-- #3653 ws-17 product live cutover -> ws-16

@github-actions github-actions Bot added size: L 200-499 changed lines scope: docs Documentation risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels May 14, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request implements the WS-16 workstream, establishing the Reborn runtime composition and integrating real host adapters. It introduces a centralized build_default_planned_runtime helper to coordinate the driver registry, run profile resolver, turn coordinator, and runner worker. Significant updates were made to RebornLoopDriverHostFactory to support profiled capabilities and driver-specific requirements. The PR also adds extensive integration tests and updates the workstream documentation for WS-14, WS-16, and WS-17. I have no feedback to provide.

@zmanian

zmanian commented May 14, 2026

Copy link
Copy Markdown
Collaborator

Review notes — WS16 live runtime wiring

Composition-only (good — no edits to src/app.rs, src/main.rs, ironclaw_engine, or any product entry point). Per-driver capability gating is fail-closed: DriverCapabilityRequirement::ProfiledCapabilitiesRequired rejects host creation when factory is missing; unknown drivers without requirements metadata are rejected (only the explicit text-only allowlist passes); capability resolver error sanitization is tested against RAW_SECRET_TOKEN leak. Two items to track.

Production readiness gate from #3602 not invoked

build_default_planned_runtime accepts model_route_resolver: None, cancellation_factory: None, skill_context_source: None, identity_context_source: None and constructs successfully. The production_readiness module exists but is not called.

The WS17 brief pushes readiness-check ownership to WS17 (#3653), which adds build_product_live_planned_runtime with per-component fail-closed checks. That's the correct split — just flagging explicitly so the readiness gate doesn't fall between the cracks. Issue #3602 ("Wire Reborn loop production readiness gate into startup composition") will close on whatever PR actually calls the gate from a production entry point. Today, no PR does.

identity_context_source: None contradicts the WS14 brief

The planned-driver-registration brief language says: "identity_source = None is allowed only for helper-level WS-14 tests; it is not valid for the WS-16 runtime smoke." The runtime constructor allows it; tests pass None. Either the brief or the constructor should tighten — currently they disagree.

Title misreads as cutover

"wire live planned runtime composition" reads like product cutover to anyone glancing at the PR list. This is helper composition, not user-visible wiring. Consider "compose live planned runtime helper" or similar — small wording change, prevents downstream confusion.

Minor

  • LEGACY_TEXT_ONLY_DRIVER_ID = "lightweight_loop" allowlist in loop_driver_host.rs deserves a comment pointing at its origin and an end-of-life note.
  • DefaultPlannedRuntimeBuildError doesn't impl From for its variants; manual .map_err works but thiserror would match repo style.
  • RebornRuntimeLoopComposition fields are all pub — fine for a composition root return, but consider whether the worker/sender should be consumed (Arc cloned out) rather than exposed mutably.
  • CLI RuntimeShellReport::initialize swallows registration errors via .is_ok() — a failure in text-only or planned registration is indistinguishable in the snapshot output. Minor for a smoke shell.

Builder methods relaxing from Arc<F: Trait + 'static> to Arc<dyn Trait> improves composition ergonomics — good.

@serrrfirat

Copy link
Copy Markdown
Collaborator

Summary

Reviewed WS16 PR #3652 only.
Base 8d39d6d0a5f23af947677cd137b621854d002638 → head fb72b490bcb5056087cf5b6df2d55cfd34fd8d03.

Live planned runtime helper leaves route and safety/policy/budget invariants optional/no-op.

Validation:

  • cargo check -p ironclaw_reborn ✅

Findings

# Sev Category File:Line Issue Fix suggestion
1 High Correctness / Runtime composition crates/ironclaw_reborn/src/runtime.rs:60-76, crates/ironclaw_reborn/src/runtime.rs:149-160, crates/ironclaw_reborn/src/loop_driver_host.rs:1249-1255 DefaultPlannedRuntimeParts.model_route_resolver is optional and helper only wires it if present. Host config still permits missing route snapshots unless require_model_route_snapshot is set. Live routed gateways fail late on first model call; non-routed gateways can proceed without pinned route, weakening resume/cutover invariant. Require model-route resolver or force require_model_route_snapshot=true for live planned runtime composition. Add model-call test with routed gateway and missing resolver.
2 High Security / Policy boundary crates/ironclaw_reborn/src/runtime.rs:60-76, crates/ironclaw_reborn/src/runtime.rs:136-160, crates/ironclaw_reborn/src/loop_driver_host.rs:999-1004 build_default_planned_runtime has no way to supply model_policy_guard, model_budget_accountant, or safety_context, so live adopters get NoOpPolicyGuard, NoOpBudgetAccountant, and no prompt safety context from host factory defaults. Expose/wire policy guard, budget accountant, and safety context in DefaultPlannedRuntimeParts; fail closed if required production hooks missing. Add tests proving model policy/budget/safety are active in live planned runtime.

Security/data-flow notes

  • Capability path has stronger requirements, but model path remains optionally unguarded.

Missing tests

  • Live planned model-call path with route resolver absent must fail at composition/startup.
  • Policy denied / budget exceeded path through build_default_planned_runtime.

henrypark133 and others added 2 commits May 15, 2026 12:59
Squash of #3651 (1 commit) onto reborn-integration.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Squash of #3652 (4 commits) onto reborn-integration stack.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Base automatically changed from arch/ws-14 to reborn-integration May 15, 2026 22:07
henrypark133 and others added 2 commits May 15, 2026 15:18
Address PR #3652 review feedback that lands within WS16 scope:

- Require `identity_context_source` in `DefaultPlannedRuntimeParts`.
  The WS-14 planned-driver brief states `identity_source = None` is
  only valid for helper-level WS-14 tests, not the WS-16 runtime
  smoke or WS-17 cutover. Compile-time enforcement now matches the
  written contract, and the smoke test supplies a static source.
- Add `From` impls on `DefaultPlannedRuntimeBuildError` so the
  builder uses plain `?` instead of `.map_err` for each variant.
- Document the `LEGACY_TEXT_ONLY_DRIVER_ID` allowlist with its
  origin and end-of-life condition.
- Replace `.is_ok()` swallow in the Reborn CLI runtime-shell snapshot
  with a `ComponentStatus` that surfaces registration errors so a
  failed text-only or planned driver registration is distinguishable
  from a successful one in the shell output.

Out of scope for WS16 (deferred to WS17 per PR description):
production readiness gate invocation, model route resolver
requirement, model policy/budget/safety wiring.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
# Conflicts:
#	crates/ironclaw_reborn/src/loop_driver_host.rs
@github-actions github-actions Bot added size: XL 500+ changed lines and removed size: L 200-499 changed lines labels May 15, 2026
@henrypark133

Copy link
Copy Markdown
Collaborator Author

Review feedback resolution

Addressed the in-scope items from @zmanian and @serrrfirat in 5c2b265:

  • identity_context_source now required in DefaultPlannedRuntimeParts — the WS-14 brief states `identity_source = None` is invalid for the WS-16 runtime smoke and WS-17 cutover. Compile-time enforcement now matches the contract; the smoke test supplies a `StaticIdentityContextSource`.
  • `From` impls on `DefaultPlannedRuntimeBuildError` for `DriverRegistryError` and `DefaultPlannedDriverRegistrationError` — the builder uses plain `?` instead of `.map_err(...)` per variant.
  • `LEGACY_TEXT_ONLY_DRIVER_ID` documented with origin and end-of-life condition (retire after WS-17 product cutover and downstream migrations).
  • CLI `RuntimeShellReport` no longer swallows errors via `.is_ok()` — replaced with a `ComponentStatus { Initialized | Failed(reason) }` enum so failed text-only or planned registration is distinguishable in the snapshot output.

Then merged `origin/reborn-integration` in 3f9f1c9 (ws-13 cancellation fixes #3684, #3685): resolved import conflict in `loop_driver_host.rs` (dropped unused `AlwaysAliveRunCancellationFactory`, kept `CapabilityResolveError`, picked up `TurnStateRunCancellationFactory`); updated `RebornLoopDriverHostFactory::new` + `ThreadCheckpointLoopExitEvidencePort::new` callers for new signatures.

Deferred to WS-17 (#3653) — comment posted there

Per this PR's stated non-goals, the following remain out of scope here and are tracked on #3653:

Subjective items not applied

  • PR title rename ("compose live planned runtime helper") — commit `4b75f26` is already on the branch; not retitling.
  • `pub` field visibility on `RebornRuntimeLoopComposition` — kept as a composition-root return; consumers need direct field access (registry, coordinator, worker, host_factory, wake_sender) to wire downstream surfaces.
  • `thiserror` migration — `ironclaw_reborn` does not depend on `thiserror` today; manual `Display`/`Error` impls remain functional and consistent with the crate. The `From` impls land the ergonomic part of the nit.

Validation

  • `cargo fmt --check`
  • `cargo build --workspace`
  • `cargo clippy -p ironclaw_reborn -p ironclaw_reborn_cli --tests --all-features` (one pre-existing `derivable_impls` warning, not introduced by this PR)
  • `cargo test -p ironclaw_reborn --test loop_driver_host` — 83 passed
  • `cargo test -p ironclaw_reborn` — all suites green

# Conflicts:
#	crates/ironclaw_reborn/src/lib.rs
@henrypark133
henrypark133 marked this pull request as ready for review May 15, 2026 22:46
@henrypark133
henrypark133 merged commit 63101d8 into reborn-integration May 15, 2026
12 of 13 checks passed
@henrypark133
henrypark133 deleted the arch/ws-16 branch May 15, 2026 22:46
theredspoon pushed a commit to theredspoon/ironclaw that referenced this pull request Jun 21, 2026
Squash of nearai#3652 (4 commits) onto reborn-integration stack.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
theredspoon pushed a commit to theredspoon/ironclaw that referenced this pull request Jun 21, 2026
Address PR nearai#3652 review feedback that lands within WS16 scope:

- Require `identity_context_source` in `DefaultPlannedRuntimeParts`.
  The WS-14 planned-driver brief states `identity_source = None` is
  only valid for helper-level WS-14 tests, not the WS-16 runtime
  smoke or WS-17 cutover. Compile-time enforcement now matches the
  written contract, and the smoke test supplies a static source.
- Add `From` impls on `DefaultPlannedRuntimeBuildError` so the
  builder uses plain `?` instead of `.map_err` for each variant.
- Document the `LEGACY_TEXT_ONLY_DRIVER_ID` allowlist with its
  origin and end-of-life condition.
- Replace `.is_ok()` swallow in the Reborn CLI runtime-shell snapshot
  with a `ComponentStatus` that surfaces registration errors so a
  failed text-only or planned driver registration is distinguishable
  from a successful one in the shell output.

Out of scope for WS16 (deferred to WS17 per PR description):
production readiness gate invocation, model route resolver
requirement, model policy/budget/safety wiring.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
theredspoon pushed a commit to theredspoon/ironclaw that referenced this pull request Jun 21, 2026
arch(ws-16): wire live planned runtime composition
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: docs Documentation size: XL 500+ changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants