Skip to content

feat(shell) add saved output refs for Reborn shell - #4154

Merged
serrrfirat merged 9 commits into
reborn-integrationfrom
codex/reborn-shell-output-files
May 29, 2026
Merged

serrrfirat merged 9 commits into
reborn-integrationfrom
codex/reborn-shell-output-files

Conversation

@serrrfirat

@serrrfirat serrrfirat commented May 27, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • capture large Reborn local shell output through the generic process-output path, returning a bounded model-facing preview plus saved-output metadata
  • stream oversized stdout/stderr into owner-only temp files instead of buffering the full output in memory
  • model saved-output storage and sanitization with explicit types, including RAII cleanup for scratch files on timeout/cancellation paths
  • sanitize the model-facing preview before returning it, and keep raw combined output scratch-only until the final saved output is written after sanitization
  • redact or block secret-like saved content, preserve binary saved output when no sanitization is needed, cap saved streams at 16 MiB each, and clean stale saved/scratch output files after a 24-hour retention window
  • render shell-facing saved-output messages in the shell tool with focused coverage for redacted, blocked, capped, and unsaved cases

Verification

  • cargo fmt --package ironclaw_host_runtime
  • cargo clippy -p ironclaw_host_runtime --lib --tests -- -D warnings
  • cargo test -p ironclaw_host_runtime process_
  • cargo test -p ironclaw_host_runtime --test first_party_builtin_tools builtin_shell
  • git diff --check

Note

  • cargo test -p ironclaw_host_runtime still fails on two unrelated skill_install tests: builtin_skill_install_accepts_content_when_network_is_denied and builtin_skill_install_rejects_hidden_url_install_fields (Authorization vs expected behavior).

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@github-actions github-actions Bot added size: XL 500+ changed lines risk: high Safety, secrets, auth, or critical infrastructure scope: agent Agent core (agent loop, router, scheduler) scope: channel Channel infrastructure scope: channel/cli TUI / CLI channel scope: channel/web Web gateway channel scope: channel/wasm WASM channel runtime scope: tool Tool infrastructure scope: tool/builtin Built-in tools scope: tool/wasm WASM tool sandbox scope: db/postgres PostgreSQL backend scope: workspace Persistent memory / workspace scope: orchestrator Container orchestrator scope: worker Container worker scope: secrets Secrets management scope: config Configuration scope: extensions Extension management scope: setup Onboarding / setup scope: sandbox Docker sandbox scope: hooks Git/event hooks scope: ci CI/CD workflows scope: docs Documentation contributor: core 20+ merged PRs scope: dependencies Dependency updates DB MIGRATION PR adds or modifies PostgreSQL or libSQL migration definitions and removed size: XL 500+ changed lines risk: high Safety, secrets, auth, or critical infrastructure labels May 27, 2026
@serrrfirat
serrrfirat changed the base branch from main to reborn-integration May 27, 2026 22:52
@serrrfirat serrrfirat removed size: XL 500+ changed lines risk: low Changes to docs, tests, or low-risk modules scope: agent Agent core (agent loop, router, scheduler) scope: channel Channel infrastructure scope: channel/cli TUI / CLI channel scope: channel/web Web gateway channel scope: channel/wasm WASM channel runtime scope: tool Tool infrastructure scope: tool/builtin Built-in tools scope: tool/wasm WASM tool sandbox scope: db/postgres PostgreSQL backend scope: workspace Persistent memory / workspace scope: orchestrator Container orchestrator scope: worker Container worker scope: secrets Secrets management scope: config Configuration scope: extensions Extension management scope: setup Onboarding / setup scope: sandbox Docker sandbox scope: hooks Git/event hooks scope: ci CI/CD workflows scope: docs Documentation scope: dependencies Dependency updates DB MIGRATION PR adds or modifies PostgreSQL or libSQL migration definitions labels May 29, 2026
…eborn-shell-output-files

# Conflicts:
#	crates/ironclaw_host_runtime/src/lib.rs
#	crates/ironclaw_host_runtime/src/process_port.rs
@github-actions github-actions Bot added size: XL 500+ changed lines risk: low Changes to docs, tests, or low-risk modules labels May 29, 2026
@serrrfirat
serrrfirat merged commit c4194c3 into reborn-integration May 29, 2026
22 checks passed
@serrrfirat
serrrfirat deleted the codex/reborn-shell-output-files branch May 29, 2026 11:22
theredspoon pushed a commit to theredspoon/ironclaw that referenced this pull request Jun 21, 2026
* Add saved output refs for Reborn shell

* Tighten Reborn shell output capture

* Harden Reborn shell output capture lifecycle

* Sanitize Reborn shell previews before saving

* fix(reborn): tenant-scope shell saved-output dir + GC (nearai#4154 review blockers #1, #4)

Saved shell-command output files previously landed directly in shared
std::env::temp_dir() (per-file 0o600, but the parent dir was world-listable),
and cleanup_stale_command_outputs() walked all of /tmp and unlinked any entry
that matched the well-known prefixes — both ambient surfaces let one principal
on the same host enumerate or delete another principal's saved output.

Route every saved output through a per-scope subdirectory derived from
RebornSandboxScopeKey (the same SHA-256-of-tenant/user/agent/project digest
the Reborn sandbox transport uses for workspace_path) under
<tempdir>/ironclaw-command-outputs/<scope_digest>/, created with owner-only
0o700. Both scratch streams and final sanitized outputs live inside that
directory, and the 24h GC scan is scoped to it — so two distinct
(tenant, user, agent, project) tuples produce disjoint, non-enumerable
directories and the cross-principal-delete surface closes by construction.

Closes blockers #1 and #4 from the PR-nearai#4154 review. Blocker #2 (typed
saved_output_read capability) and finding #3 (24h GC vs never-delete
retention) remain serrrfirat-owned design decisions and are intentionally
out of scope here.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* fix: address saved shell output review findings

* fix: publish shell saved output through file_read

---------

Co-authored-by: Zaki <zaki@manian.org>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules size: XL 500+ changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants