refactor(reborn): clean up capability activity lifecycle - #5145
Merged
Merged
Conversation
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR cleans up the Reborn capability activity lifecycle so activity rows, gate prompts, terminal states, and WebUI rendering all use the same stable identity instead of recovering state from UI order or active-run inference.
The three issues are different symptoms of the same contract gap:
run_id,gate_ref, gate kind), so the WebUI can trust the read model instead of synthesizing rows from nearby run status.gate_declinedand render as a neutral declined state instead of red ERR/failed UI.Fixes
Fixes #5028
Fixes #5120
Fixes #5148
Checkpoint compatibility
The default loop checkpoint schema is intentionally bumped from
reborn:default-loop-v1/ version 1 toreborn:default-loop-v2/ version 2.The v2 payload makes parked
activity_idrequired for pending approval/auth resumes. That is the clean contract this refactor relies on: a blocked gate must always know the exact activity row it will resume, decline, or fail. Older v1 checkpoints could omit this identity and sometimes derive it from a resume token; tokenless auth gates made that fallback impossible, which is the edge case that could leave activity running forever.This PR does not migrate old v1 blocked checkpoints. A v1 checkpoint loaded under the v2 run profile is rejected at the checkpoint metadata boundary instead of being decoded as if it satisfied the new invariant. This matches the branch goal of prioritizing the v2 activity/gate identity model over old blocked-run compatibility.
Testing
cargo fmt --checkgit diff --checkcargo check/cargo clippyfor the touched Reborn, loop-support, agent-loop, host-runtime, hooks, and product-workflow cratesironclaw_agent_loop,ironclaw_loop_support,ironclaw_host_runtime,ironclaw_reborn_composition,ironclaw_turns, and WebUI JSbash build.sh --no-vendorironclaw_reborn_composition,ironclaw_memory, WASM channels, and first-party WASM buildsCARGO_PROFILE_DEV_DEBUG=0 CARGO_PROFILE_TEST_DEBUG=0 cargo test --no-default-features --features postgres,libsql,html-to-markdown,bedrock,import -- --nocapture --test-threads=1Note: on local macOS, the same root full test command under default intra-binary parallelism can still abort at the process level with
mach_msg failedbefore producing a Rust test failure. The serial full run passed, and the PR/CI runners remain the source of truth for Linux default-parallel execution.