Skip to content

feat(reborn): complete operator setup state - #4859

Merged
think-in-universe merged 10 commits into
mainfrom
codex/reborn-complete-operator-setup-4592
Jun 23, 2026
Merged

think-in-universe merged 10 commits into
mainfrom
codex/reborn-complete-operator-setup-4592

Conversation

@think-in-universe

@think-in-universe think-in-universe commented Jun 14, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Validate operator setup profile IDs and WebUI access token input at the product facade boundary.
  • Treat the redacted WebUI token sentinel as unchanged, enforce token min/max byte limits, and fail closed for actual profile/token mutations until an owning persistence service is wired.
  • Keep provider/model setup wired through the typed LLM config service and add contract coverage for validation, no-op redacted tokens, and fail-closed host mutations.

Change Type

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • CI/Infrastructure
  • Security
  • Dependencies

Linked Issue

Closes #4592.

Validation

  • cargo +1.92.0 fmt --package ironclaw_product_workflow --package ironclaw_webui_v2
  • cargo clippy --all --benches --tests --examples --all-features -- -D warnings
  • cargo build
  • Relevant tests pass: cargo +1.92.0 test -p ironclaw_product_workflow run_operator_setup_ --test reborn_services_contract -- --nocapture
  • Relevant tests pass: cargo +1.92.0 test -p ironclaw_product_workflow get_operator_setup_returns_snapshot_from_llm_config --test reborn_services_contract -- --nocapture
  • cargo test --features integration if database-backed or integration behavior changed
  • Manual testing: not run; product-workflow contract tests cover the setup facade behavior
  • If a coding agent was used and supports it, review-pr or pr-shepherd --fix was run before requesting review

Security Impact

Touches secret-bearing operator setup input. Token values remain SecretString, are never echoed in setup responses, redacted sentinel input is treated as unchanged, token byte length is bounded, and unwired profile/token mutations fail closed before provider writes.

Reborn Trust-Boundary Checklist

  • Public policy/evidence/trust-bearing types: no new trust-bearing public types; setup request validation stays inside the product facade.
  • Untrusted content enters prompts only through an envelope/escaping primitive. No prompt path changed.
  • Hashes declare purpose; trust/binding/authenticity uses SHA-256/BLAKE3 or separate authenticity check. No hash path changed.
  • New/changed status, exit, policy, runtime, or error variants: downstream match sites audited. Command/output: no new variants; existing validation and service-unavailable errors are reused.
  • Security/durability serde(default) fields fail closed or have migration tests. Existing defaulted optional setup fields validate and fail closed for unwired host mutations.
  • Queues/maps/buffers/counters have bounds and overflow-safe arithmetic. Token/profile field byte limits are bounded.
  • Driver/operator-visible errors have stable class semantics (Transient, Permanent, Misconfigured, PolicyDenied or equivalent). Uses existing validation and service-unavailable classes.
  • Sandbox/native/host names accurately describe trust boundary. No sandbox/native host naming changed.

Database Impact

None. No migrations or persistence schema changes.

Blast Radius

Operator setup facade and WebUI v2 operator setup documentation. Provider/model setup behavior remains routed through the existing LLM config service; profile/WebUI access mutation requests now fail closed instead of reporting uncommitted success.

Rollback Plan

Revert this PR to restore the prior operator setup response behavior.

Review Follow-Through

Addressed review feedback for redacted token sentinel handling, explicit token upper bound validation, and fail-closed behavior for unwired profile/WebUI access mutations. The cargo-deny CI failure was a Docker Hub timeout while building the cargo-deny action container and is being rerun.


Review track: C (security/runtime/DB/CI)

Copilot AI review requested due to automatic review settings June 14, 2026 14:07

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions github-actions Bot added size: M 50-199 changed lines scope: docs Documentation risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Jun 14, 2026
@coderabbitai

coderabbitai Bot commented Jun 14, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ab17d8f6-64a1-4209-8620-2da580e2b414

📥 Commits

Reviewing files that changed from the base of the PR and between 0f8d28a and 34dbdaf.

📒 Files selected for processing (3)
  • crates/ironclaw_product_workflow/src/reborn_services.rs
  • crates/ironclaw_product_workflow/tests/reborn_services_contract.rs
  • crates/ironclaw_webui_v2/CLAUDE.md

📝 Walkthrough

Summary by CodeRabbit

  • New Features

    • Operator setup WebUI step status/messages are now derived from internal host-state, providing consistent profile and webui_access step completion.
  • Bug Fixes

    • Operator setup now enforces stricter profile_id and webui_access_token validation (trimming, length/emptiness checks).
    • Redacted/unchanged tokens are treated as no-ops and are never echoed back.
    • When wiring is missing, host-mutation attempts fail closed and avoid provider changes.
  • Documentation

    • Updated WebUI operator setup API docs to reflect the validated/no-echo and fail-closed behavior.
  • Tests

    • Expanded contract tests for validation failures, redaction handling, and unwired host-mutation cases.

Walkthrough

Operator setup now validates profile_id and webui_access_token, rejects unwired host mutation attempts, and renders profile/webui_access steps from host state instead of diagnostics-derived "not wired" output. Tests and docs were updated to match the new contract.

Changes

Operator setup validation and host-state rendering

Layer / File(s) Summary
Validation helpers and host state
crates/ironclaw_product_workflow/src/reborn_services.rs
Imports ExposeSecret, adds operator-setup validation error construction, validates profile_id and webui_access_token with byte bounds and redacted-sentinel handling, rejects unwired host mutations, and introduces OperatorSetupHostState plus the updated setup_response_from_llm_snapshot signature.
Host-state rendering and service wiring
crates/ironclaw_product_workflow/src/reborn_services.rs
setup_response_from_llm_snapshot derives profile and webui_access messages from OperatorSetupHostState, renders both steps as Complete, and the get/run/diagnostics paths pass either default or constructed host state into the response builder.
Contract coverage and operator setup docs
crates/ironclaw_product_workflow/tests/reborn_services_contract.rs, crates/ironclaw_webui_v2/CLAUDE.md
Updates setup contract tests to expect empty diagnostics and Complete profile/webui_access steps, adds validation-failure and fail-closed host-mutation coverage, checks redacted token non-echo behavior, and rewords operator setup documentation to match the new facade behavior.

Sequence Diagram

sequenceDiagram
  participant run_operator_setup
  participant validate_operator_setup_profile_id
  participant validate_operator_setup_webui_access_token
  participant reject_unwired_operator_setup_host_mutation
  participant setup_response_from_llm_snapshot

  run_operator_setup->>validate_operator_setup_profile_id: profile_id
  validate_operator_setup_profile_id-->>run_operator_setup: validated profile_id or InvalidValue
  run_operator_setup->>validate_operator_setup_webui_access_token: webui_access_token
  validate_operator_setup_webui_access_token-->>run_operator_setup: token accepted flag or InvalidValue
  run_operator_setup->>reject_unwired_operator_setup_host_mutation: host mutation intent
  reject_unwired_operator_setup_host_mutation-->>run_operator_setup: Unavailable or continue
  run_operator_setup->>setup_response_from_llm_snapshot: OperatorSetupHostState
  setup_response_from_llm_snapshot-->>run_operator_setup: RebornOperatorSetupResponse
Loading

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

  • nearai/ironclaw#4801 — Shares the setup_response_from_llm_snapshot / OperatorSetupHostState operator-setup path and the diagnostics embedding update in reborn_services.rs.

Suggested reviewers

  • hanakannzashi
  • italic-jinxin

Poem

A token walks in, veiled and light,
Profile trims its edges just right.
Complete steps bloom where diagnostics once sighed,
And unwired writes are politely denied. 🔐

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed PR title follows Conventional Commits style with type(scope): summary format; clearly describes the main change to complete operator setup state validation.
Description check ✅ Passed Description includes all required template sections with substantive content: summary with bullet points, change type selections, linked issue, validation checkboxes, security impact, trust boundary checklist, blast radius, and rollback plan.
Linked Issues check ✅ Passed PR satisfies core objectives from #4592: validates profile/WebUI token input at facade boundary, treats redacted sentinel as no-op, bounds token/profile byte limits, fails closed for unwired mutations before provider writes, and documents changes.
Out of Scope Changes check ✅ Passed All changes directly support operator setup validation and state handling within the linked issue scope; no extraneous refactors or unrelated modifications present.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request implements validation and state tracking for profile selection and WebUI access tokens within the operator setup API, transitioning these steps from "Unsupported" to "Complete" in the setup response. It also adds corresponding contract tests and updates documentation. Feedback on the changes suggests updating validate_operator_setup_webui_access_token to explicitly check for and ignore the redacted sentinel value (••••••••) to prevent it from being incorrectly treated as a newly updated token.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread crates/ironclaw_product_workflow/src/reborn_services.rs
@think-in-universe
think-in-universe force-pushed the codex/reborn-complete-operator-setup-4592 branch from 3bbb657 to 8477b38 Compare June 14, 2026 14:12

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_product_workflow/src/reborn_services.rs`:
- Around line 1555-1561: The run_operator_setup function validates profile_id
and webui_access_token at lines 1555-1557 but constructs OperatorSetupHostState
from these transient values without first persisting them through the owning
typed services. Wire the validated profile_id and webui_access_token_updated
through the appropriate persistence/service layer to actually commit these
changes, then derive OperatorSetupHostState only from the write outcomes. If the
persistence path does not yet exist, fail the operation rather than reporting
success on uncommitted state.
- Around line 619-629: The validate_operator_setup_webui_access_token function
currently only enforces a minimum length check but lacks an upper-bound
validation for the token. Add a maximum length check after the existing
minimum-length validation using a defined constant (similar to
OPERATOR_SETUP_WEBUI_TOKEN_MIN_BYTES) to enforce a hard upper limit on the
webui_access_token field, returning an operator_setup_validation_error if the
token exceeds this maximum to prevent unbounded growth of this secret input.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 29ba51bd-8649-45ab-a3f0-5100b887f7b0

📥 Commits

Reviewing files that changed from the base of the PR and between e1a83d6 and 3bbb657.

📒 Files selected for processing (3)
  • crates/ironclaw_product_workflow/src/reborn_services.rs
  • crates/ironclaw_product_workflow/tests/reborn_services_contract.rs
  • crates/ironclaw_webui_v2/CLAUDE.md

Comment thread crates/ironclaw_product_workflow/src/reborn_services.rs
Comment thread crates/ironclaw_product_workflow/src/reborn_services.rs
Copilot AI review requested due to automatic review settings June 14, 2026 14:31

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_webui_v2/CLAUDE.md`:
- Line 124: The phrase "unchanged redacted tokens" in the CLAUDE.md file at line
124 is ambiguous and conflates two different concepts: UI-masked tokens versus
output filtering/redaction. Replace "unchanged redacted tokens" with "unchanged
masked tokens (not modified by the user)" to clarify that you are referring to
user-facing masked display tokens that were not edited by the user, making it
clear these are treated as no-ops rather than describing output filtering
behavior.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 80c5b4b2-d249-4e3a-b344-153ac40a80bb

📥 Commits

Reviewing files that changed from the base of the PR and between 8477b38 and 972710e.

📒 Files selected for processing (3)
  • crates/ironclaw_product_workflow/src/reborn_services.rs
  • crates/ironclaw_product_workflow/tests/reborn_services_contract.rs
  • crates/ironclaw_webui_v2/CLAUDE.md

Comment thread crates/ironclaw_webui_v2/CLAUDE.md Outdated

@think-in-universe think-in-universe left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review skill pass for current head fd5ff4036185e73ef4e07ea3725b82a79abeffe4.

Findings: 2 test-coverage comments. Security, correctness, performance, and conventions reviewers returned no production findings.

Comment thread crates/ironclaw_product_workflow/src/reborn_services.rs
Comment thread crates/ironclaw_product_workflow/src/reborn_services.rs
Copilot AI review requested due to automatic review settings June 16, 2026 06:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Copy link
Copy Markdown
Collaborator Author

Human final review guidance for #4859:

Focus on the operator setup trust boundary rather than broad style. In particular, verify that provider/model setup still flows through the typed LLM config service, profile/WebUI token mutations fail closed until persistence is wired, the masked token sentinel is treated as no-op, and token/profile byte limits reject before any provider write. CI is green at head 06b87924b; the remaining risk is whether the fail-closed product behavior matches the intended rollout plan for #4592.

@think-in-universe

Copy link
Copy Markdown
Collaborator Author

@claude review

@claude

claude Bot commented Jun 17, 2026

Copy link
Copy Markdown

Code Review Summary

Reviewed PR #4859 across four independent passes (Security & Safety, Architecture & Patterns, Bug Scan, Performance & Production).

Result: No issues found.

Detailed Analysis

Security & Safety: ✓ No vulnerabilities found

  • SecretString handling is correct
  • No .unwrap()/.expect() in production code
  • Bounds checking properly implemented
  • Sentinel-based redaction correctly prevents secret exposure in logs

Architecture & Patterns: ✓ Design is sound

  • Validation functions correctly gate side effects before LLM config mutations
  • Fail-closed semantics for unwired features properly enforced
  • Error boundary hygiene maintained per product_workflow module spec
  • Test coverage validates both rejection and side-effect prevention

Bug Scan: ✓ No logical errors found

  • Boundary condition checks verified as correct:
    • Profile ID: max 128 bytes (test rejects 129 ✓)
    • Token: min 16 bytes (test rejects 9 ✓), max 4096 bytes (test rejects 4097 ✓)
  • Sentinel handling correct (trim → compare → return false)
  • No off-by-one errors or state machine violations

Performance & Production: ✓ No runtime issues found

  • No blocking operations in async code
  • No N+1 patterns or unbounded loops
  • O(1) validation with bounded memory
  • Proper secret exposure scope (local variables only)

Summary

The PR correctly implements operator setup validation with:

  • Comprehensive input validation with appropriate bounds
  • Proper fail-closed semantics for unwired persistence features
  • Clear test coverage including both validation rejection and side-effect prevention
  • Updated documentation accurately reflecting the new behavior

@think-in-universe

Copy link
Copy Markdown
Collaborator Author

✅ Code review update for current head 06b87924b1d3ba70d36107258e779a0a363efcfa.

I reviewed the new commit 06b87924 (Add operator setup mutation guard tests). The commit is test-only and adds caller-path coverage in crates/ironclaw_product_workflow/tests/reborn_services_contract.rs for operator setup profile/token validation and unwired host mutation rejection. The tests exercise RebornServices::run_operator_setup(...) through the facade and verify provider upsert/activation calls remain at zero on those failure paths.

No blocking Codex findings.

Status checked:

  • CI/check rollup is green.
  • GitHub reports the branch as mergeable (MERGEABLE) with mergeStateStatus=BLOCKED because review is still required, not because of conflicts.
  • No unresolved review threads are present.

Human final-review guidance: focus on whether the setup facade should continue failing closed for profile/WebUI-token host mutations until their persistence layer is wired, and whether the test cases cover the intended side-effect boundary: validation and unavailable-host errors must occur before any LLM provider config write.

Copilot AI review requested due to automatic review settings June 23, 2026 08:48

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@think-in-universe

Copy link
Copy Markdown
Collaborator Author

@claude review

@claude

claude Bot commented Jun 23, 2026

Copy link
Copy Markdown

Found 1 critical issue: Lines 1997-2004 validate profile_id and webui_access_token_updated, but then discard these values and hardcode host_state with None and false. This makes validation results dead code and response messages unreachable. Also found 2 medium issues with sentinel pattern coupling and profile_id echo logic.

Comment thread crates/ironclaw_product_workflow/src/reborn_services.rs Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_product_workflow/src/reborn_services.rs`:
- Line 683: The constant OPERATOR_SETUP_WEBUI_TOKEN_MIN_BYTES has been changed
to 32 bytes, but two test fixtures still use a 24-byte token that now fails
length validation before reaching the unwired host mutations check. In the test
functions
run_operator_setup_rejects_unwired_host_mutations_before_provider_write and
run_operator_setup_rejects_token_only_host_mutation_before_provider_write,
replace the token "webui-secret-token-value" with a token that is at least 32
bytes long to allow the tests to progress past validation and properly test the
unwired host mutations rejection behavior as originally intended.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 0f9bc297-c078-43bc-8359-0599f2a7dd4e

📥 Commits

Reviewing files that changed from the base of the PR and between f58c350 and 03b3a6e.

📒 Files selected for processing (2)
  • crates/ironclaw_product_workflow/src/reborn_services.rs
  • crates/ironclaw_product_workflow/tests/reborn_services_contract.rs

Comment thread crates/ironclaw_product_workflow/src/reborn_services.rs
Copilot AI review requested due to automatic review settings June 23, 2026 10:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

italic-jinxin
italic-jinxin previously approved these changes Jun 23, 2026
@think-in-universe
think-in-universe added this pull request to the merge queue Jun 23, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Jun 23, 2026
# Conflicts:
#	crates/ironclaw_product_workflow/tests/reborn_services_contract.rs

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_product_workflow/tests/reborn_services_contract.rs`:
- Around line 5761-5795: The test
pause_resume_automation_forward_caller_scope_to_product_facade only validates
the caller scope (tenant_id, user_id, agent_id, project_id) for the pause action
in calls[0], but the resume action in calls[1] only checks action and
automation_id. Add assertions after the calls[1].automation_id check to verify
that calls[1].caller.tenant_id, calls[1].caller.user_id,
calls[1].caller.agent_id, and calls[1].caller.project_id all match the expected
values (caller.tenant_id, caller.user_id, expected_agent_id, and
caller.project_id respectively), using the same pattern as the pause assertions.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 9df4998a-846f-4f35-9d45-530ce1bdc0cd

📥 Commits

Reviewing files that changed from the base of the PR and between d908d59 and 0f8d28a.

📒 Files selected for processing (3)
  • crates/ironclaw_product_workflow/src/reborn_services.rs
  • crates/ironclaw_product_workflow/tests/reborn_services_contract.rs
  • crates/ironclaw_webui_v2/CLAUDE.md

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Inline review comments failed to post. This is likely due to GitHub's internal server error or limits when posting large numbers of comments. If you are seeing this consistently it is likely a permissions issue. Please check "Moderation" -> "Code review limits" under your organization settings.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_product_workflow/tests/reborn_services_contract.rs`:
- Around line 5761-5795: The test
pause_resume_automation_forward_caller_scope_to_product_facade only validates
the caller scope (tenant_id, user_id, agent_id, project_id) for the pause action
in calls[0], but the resume action in calls[1] only checks action and
automation_id. Add assertions after the calls[1].automation_id check to verify
that calls[1].caller.tenant_id, calls[1].caller.user_id,
calls[1].caller.agent_id, and calls[1].caller.project_id all match the expected
values (caller.tenant_id, caller.user_id, expected_agent_id, and
caller.project_id respectively), using the same pattern as the pause assertions.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 9df4998a-846f-4f35-9d45-530ce1bdc0cd

📥 Commits

Reviewing files that changed from the base of the PR and between d908d59 and 0f8d28a.

📒 Files selected for processing (3)
  • crates/ironclaw_product_workflow/src/reborn_services.rs
  • crates/ironclaw_product_workflow/tests/reborn_services_contract.rs
  • crates/ironclaw_webui_v2/CLAUDE.md
🛑 Comments failed to post (1)
crates/ironclaw_product_workflow/tests/reborn_services_contract.rs (1)

5761-5795: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Assert caller scope on the resume call as well.

Line 5792+ only checks action/automation_id for the resume path; it doesn’t verify tenant/user/agent/project propagation like the pause path. That leaves the test name’s “forward caller scope” contract only half-covered.

Suggested test hardening
     assert_eq!(calls[1].action, AutomationMutationAction::Resume);
     assert_eq!(calls[1].automation_id, "trigger-alpha");
+    assert_eq!(calls[1].caller.tenant_id, caller.tenant_id);
+    assert_eq!(calls[1].caller.user_id, caller.user_id);
+    assert_eq!(calls[1].caller.agent_id, expected_agent_id);
+    assert_eq!(calls[1].caller.project_id, caller.project_id);
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@crates/ironclaw_product_workflow/tests/reborn_services_contract.rs` around
lines 5761 - 5795, The test
pause_resume_automation_forward_caller_scope_to_product_facade only validates
the caller scope (tenant_id, user_id, agent_id, project_id) for the pause action
in calls[0], but the resume action in calls[1] only checks action and
automation_id. Add assertions after the calls[1].automation_id check to verify
that calls[1].caller.tenant_id, calls[1].caller.user_id,
calls[1].caller.agent_id, and calls[1].caller.project_id all match the expected
values (caller.tenant_id, caller.user_id, expected_agent_id, and
caller.project_id respectively), using the same pattern as the pause assertions.

hanakannzashi
hanakannzashi previously approved these changes Jun 23, 2026
@think-in-universe
think-in-universe added this pull request to the merge queue Jun 23, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Jun 23, 2026
@think-in-universe
think-in-universe added this pull request to the merge queue Jun 23, 2026
Merged via the queue into main with commit e849e83 Jun 23, 2026
43 checks passed
@think-in-universe
think-in-universe deleted the codex/reborn-complete-operator-setup-4592 branch June 23, 2026 14:46
BenKurrek added a commit that referenced this pull request Jun 24, 2026
#4859 ("complete operator setup state") consolidated the operator setup
reason codes — a wired LLM config no longer emits
operator_setup_profile_not_wired / operator_setup_webui_access_not_wired.
The aggregate diagnostics contract test predates #4859 and was missed in
that update; it merged unnoticed because reborn-tests has been dead since
#5081. Assert the codes the path actually emits now (including
operator_doctor_workspace_path_blocked) and drop the retired setup codes.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: docs Documentation size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Reborn] First-run setup API for provider, model, profile, and WebUI access

6 participants