Skip to content

fix(ci): stabilize main-equivalent clippy and coverage checks - #5591

Merged
think-in-universe merged 23 commits into
mainfrom
codex/main-ci-checks
Jul 4, 2026
Merged

think-in-universe merged 23 commits into
mainfrom
codex/main-ci-checks

Conversation

@think-in-universe

@think-in-universe think-in-universe commented Jul 3, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Fix all-features clippy by keeping wasmtime-wasi on the WASIp2/component-model path only, avoiding the broken WASIp1 compile path in wasmtime-wasi 46.0.1.
  • Stabilize coverage failures around Reborn live progress streams, NEARAI runtime env isolation, credential header tests, and memory isolation assertions.
  • Make budget gate snapshots durable under feature-union serde behavior by encoding decimal values as strings and adding stricter gate status decode coverage.
  • Make Postgres root filesystem create_dir_all idempotent/race-safe by batching directory prefix inserts and checking file conflicts after insert.
  • Gate postgres-only ironclaw_stress helpers/imports so no-default libsql clippy builds stay warning-free.

Linked Issue

Closes #5590

Validation

  • cargo clippy --all --tests --examples --all-features -- -D warnings
  • cargo test -p ironclaw_resources --no-default-features --features libsql -- --nocapture
  • cargo test -p ironclaw -p ironclaw_reborn_composition --test budget_approval_e2e --no-default-features --features libsql -- --nocapture
  • cargo test -p ironclaw_filesystem --features postgres,libsql --test db_root_filesystem_contract -- --nocapture

Security Impact

No security guarantees are weakened. Credential-header and memory-isolation coverage was adjusted to avoid CI flakes while still asserting that protected payloads and auth headers do not leak through the wrong path.

Database Impact

No schema changes. Runtime behavior changes are limited to durable budget gate JSON compatibility and Postgres filesystem directory creation conflict handling.

Blast Radius

CI/test stability plus narrow runtime persistence/filesystem paths:
ironclaw_resources, ironclaw_filesystem, Reborn projection/runtime tests, WASM dependency features, and ironclaw_stress feature-gated clippy cleanup.

Rollback Plan

Revert this PR. The rollback would restore the prior CI behavior and dependency feature set; no migration rollback is required.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@coderabbitai

coderabbitai Bot commented Jul 3, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Summary by CodeRabbit

  • New Features

    • Added support for a temperature option in Responses requests, with validation and consistent error reporting when out of range.
  • Bug Fixes

    • Improved directory creation in the filesystem to handle conflicts more reliably and avoid partial changes on failure.
    • Tightened persisted budget-gate and resource data handling to better preserve values and reject invalid formats.
    • Legacy Engine v2 routes now fail closed with 404 instead of returning empty results.

Walkthrough

Centralizes wasmtime/wasmtime-wasi under workspace dependencies, converts Decimal and BudgetGateStatus serde to stricter/stable formats, batches PostgreSQL create_dir_all into a single UNNEST insert with conflict detection, shares a live sequence counter via Arc, adds optional temperature validation to the OpenAI-compat Responses API, and updates numerous tests/tooling.

Changes

Core behavior and supporting test updates

Layer / File(s) Summary
Workspace Wasmtime dependencies
Cargo.toml, crates/ironclaw_wasm/Cargo.toml, crates/ironclaw_wasm_limiter/Cargo.toml, crates/ironclaw_wasm_product_adapters/Cargo.toml, crates/ironclaw_wasm_sandbox_core/Cargo.toml, crates/ironclaw_hooks/Cargo.toml
wasmtime (46.0.1, component-model) and wasmtime-wasi are centralized under [workspace.dependencies]; per-crate manifests inherit via workspace = true; root crate gains a dev-dependency on ironclaw_reborn_openai_compat.
Decimal and budget-gate serde
crates/ironclaw_resources/src/lib.rs, crates/ironclaw_resources/src/gate.rs, crates/ironclaw_resources/src/filesystem_store.rs
New decimal_string_or_legacy_number adapter serializes decimals as JSON strings while accepting legacy numbers; BudgetGateStatus gets a manual Deserialize enforcing per-status field rules; tests cover encoding, legacy decoding, and gate persistence/reload.
Batched directory creation
crates/ironclaw_filesystem/src/postgres.rs, crates/ironclaw_filesystem/tests/db_root_filesystem_contract.rs
create_dir_all uses a single INSERT ... SELECT FROM UNNEST(...) ... RETURNING statement with ON CONFLICT DO UPDATE instead of per-prefix checks; a new contract test verifies conflict detection and rollback.
Shared live-update sequencing
crates/ironclaw_reborn_composition/src/projection/live_progress.rs, crates/ironclaw_reborn_composition/src/projection.rs
LiveProjectionPublisher.next_sequence becomes an Arc<AtomicU64> shared across publishers instead of an owned counter, with a comment explaining the shared cursor space.
Runtime env guard refactor
crates/ironclaw_reborn_composition/src/runtime.rs
RuntimeEnvGuard::Drop gates restoration debug assertions on !panicking() and asserts env values match recorded state.
OpenAI-compat temperature support
crates/ironclaw_reborn_openai_compat/src/responses.rs, .../responses_workflow.rs, .../error.rs, .../tests/dto_contract.rs, .../tests/error_contract.rs, tests/responses_api_temperature.rs
OpenAiResponsesCreateRequest gains an optional temperature field validated to 0.0..=2.0, forwarded into the product payload, allowed as an error param, and tested end-to-end via an in-process router.
Responses API route-prefix and Engine v2 404 tests
tests/responses_api_path_prefix.rs, tests/thread_isolation_integration.rs
Route-prefix tests rewritten to use an in-process Axum router asserting JSON error param values; Engine v2 foreign-thread tests now expect 404 instead of empty success responses.
Test assertions and stress-tool cleanup
tests/e2e_trace_memory_isolation.rs, tests/skill_credential_injection.rs, tests/dockerfile_runtime_home.rs, tools/ironclaw_stress/src/main.rs, tools/ironclaw_stress/src/process_metrics.rs
SOUL.md rejection test now checks non-mutation instead of absence; credential-injection test switches to OPTIONS; stress tool gates postgres-only helpers and uses explicit std::env/std::fs paths.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Caller
  participant create_dir_all
  participant PostgreSQL
  Caller->>create_dir_all: create_dir_all(path)
  create_dir_all->>create_dir_all: compute prefix paths
  create_dir_all->>PostgreSQL: INSERT ... SELECT FROM UNNEST(prefixes) ... RETURNING path, is_dir
  PostgreSQL-->>create_dir_all: returned rows
  create_dir_all->>create_dir_all: inspect file-vs-directory conflicts
  create_dir_all-->>Caller: commit or FilesystemError::Backend
Loading
sequenceDiagram
  participant Client
  participant ResponsesWorkflow as OpenAiResponsesWorkflow
  participant Validator as validate_temperature
  participant ProductWorkflow
  Client->>ResponsesWorkflow: POST /v1/responses {temperature}
  ResponsesWorkflow->>Validator: validate_temperature(request.temperature)
  Validator-->>ResponsesWorkflow: Ok or invalid_request(param="temperature")
  ResponsesWorkflow->>ProductWorkflow: submit payload with temperature field
  ProductWorkflow-->>Client: accepted envelope or 400 error
Loading

Possibly related issues

Possibly related PRs

  • nearai/ironclaw#4950: Both PRs modify wasmtime/wasmtime-wasi dependency declarations across workspace and crate manifests.
  • nearai/ironclaw#5362: Overlaps directly in projection.rs/live_progress.rs changing next_sequence from an owned AtomicU64 to a shared Arc<AtomicU64>, plus related runtime.rs guard behavior.
  • nearai/ironclaw#5601: Overlaps in wasmtime-wasi workspace wiring and tools/ironclaw_stress/src/main.rs postgres-feature gating for std::env/VarError usage.
🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title uses Conventional Commits style and accurately summarizes the CI stabilization work.
Description check ✅ Passed The PR description closely follows the template and covers summary, linked issue, validation, impact, blast radius, and rollback.
Linked Issues check ✅ Passed The changes align with #5590 by fixing clippy, coverage, and test-instability issues called out in the linked objective.
Out of Scope Changes check ✅ Passed The touched code paths all support the stated CI-stabilization goals; no clearly unrelated changes are evident from the summary.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5591 July 3, 2026 09:46 Destroyed
@github-actions github-actions Bot added size: XS < 10 changed lines (excluding docs) risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Jul 3, 2026
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5591 July 3, 2026 09:52 Destroyed
@github-actions github-actions Bot added scope: ci CI/CD workflows size: S 10-49 changed lines risk: medium Business logic, config, or moderate-risk modules and removed size: XS < 10 changed lines (excluding docs) risk: low Changes to docs, tests, or low-risk modules labels Jul 3, 2026
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5591 July 3, 2026 09:57 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5591 July 3, 2026 10:00 Destroyed
@github-actions github-actions Bot added size: XS < 10 changed lines (excluding docs) and removed size: S 10-49 changed lines labels Jul 3, 2026
@think-in-universe think-in-universe changed the title [codex] Trigger main CI checks ci(fix): trigger main CI checks Jul 3, 2026
@railway-app

railway-app Bot commented Jul 3, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5591 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 4, 2026 at 6:57 am

@github-actions

github-actions Bot commented Jul 3, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ 3 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_reborn_identity, ironclaw_reborn_traces, ironclaw_webui_v2

Reborn integration-tier coverage

Line coverage (Reborn crates): 17.19% — 11063 / 64362 lines

Per-crate breakdown (11 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_reborn_identity 0% 0 / 230
ironclaw_reborn_traces 0% 0 / 6769
ironclaw_webui_v2 0% 0 / 2785
ironclaw_reborn_event_store 0.73% 6 / 825
ironclaw_reborn_config 1.31% 15 / 1142
ironclaw_product_adapter_registry 5.12% 25 / 488
ironclaw_product_workflow 7.23% 716 / 9905
ironclaw_product_adapters 12.55% 283 / 2255
ironclaw_reborn 23.44% 2041 / 8707
ironclaw_reborn_composition 25.5% 7966 / 31242
ironclaw_product_context 78.57% 11 / 14

This signal is informational: coverage never gates the PR — not the percentage, not the per-crate holes, not the 0-coverage callout.

@ironloopai

ironloopai Bot commented Jul 3, 2026 •

Copy link
Copy Markdown
Contributor

IronLoop Review Status

Head: f48a08a143bde0f000804c52feeea7860a0b019c
Updated: 2026-07-04T06:57:03.616Z
Admission: webhook accepted the request and IronLoop persisted review state before this projection.

Current reviewers:

Reviewer State What it means Last update
none Queued No reviewer jobs scheduled yet. n/a

Recent activity:

Time Reviewer State Detail
n/a n/a Waiting No progress events recorded yet.

Commands:

  • @ironloop review
  • @ironloop review <agent-alias>
  • @ironloop status

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5591 July 3, 2026 11:32 Destroyed
@github-actions github-actions Bot added scope: docs Documentation size: M 50-199 changed lines and removed size: XS < 10 changed lines (excluding docs) labels Jul 3, 2026
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5591 July 4, 2026 03:39 Destroyed
@github-actions github-actions Bot added size: XL 500+ changed lines and removed size: L 200-499 changed lines labels Jul 4, 2026
@italic-jinxin
italic-jinxin marked this pull request as draft July 4, 2026 03:40

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/code_style.yml:
- Line 14: The workflow trigger list in the code_style pipeline includes the
temporary probe branch codex/main-ci-checks, which should not remain as
permanent CI surface. Add a tracking note or issue reference alongside the same
trigger used in coverage.yml, and make sure the workflow clearly marks it for
removal once main CI is confirmed green. Keep the change localized to the
workflow trigger configuration so it is easy to locate and clean up later.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: e86fbcb8-2fd5-4373-a2ea-31d456f5bb00

📥 Commits

Reviewing files that changed from the base of the PR and between 9e67419 and 6de925c.

📒 Files selected for processing (5)
  • .github/workflows/code_style.yml
  • .github/workflows/coverage.yml
  • crates/ironclaw_filesystem/src/postgres.rs
  • crates/ironclaw_filesystem/tests/db_root_filesystem_contract.rs
  • crates/ironclaw_resources/src/gate.rs

Comment thread .github/workflows/code_style.yml Outdated
Comment thread .github/workflows/code_style.yml Outdated
Comment thread .github/workflows/coverage.yml Outdated
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5591 July 4, 2026 04:31 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5591 July 4, 2026 05:11 Destroyed
@italic-jinxin

Copy link
Copy Markdown
Contributor

@claude review

@claude

This comment was marked as resolved.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5591 July 4, 2026 05:28 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5591 July 4, 2026 06:06 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5591 July 4, 2026 06:57 Destroyed
@italic-jinxin
italic-jinxin marked this pull request as ready for review July 4, 2026 06:57

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/responses_api_temperature.rs`:
- Around line 1-32: This caller-level router test should be moved to the
integration tier by renaming or relocating tests/responses_api_temperature.rs so
it follows the repo’s integration-test naming/convention. Keep the same
OpenAiResponsesWorkflow and openai_compat_router_with_state coverage, but ensure
the file is discovered as an integration test by default rather than a
unit-style test. Adjust any module placement or test setup needed so the
public-handler validation remains intact under the integration tier.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 8fa9ce9e-9eb9-46a8-a2cf-054a919a725c

📥 Commits

Reviewing files that changed from the base of the PR and between 6de925c and f48a08a.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock, !**/Cargo.lock
📒 Files selected for processing (9)
  • Cargo.toml
  • crates/ironclaw_reborn_openai_compat/src/error.rs
  • crates/ironclaw_reborn_openai_compat/src/responses.rs
  • crates/ironclaw_reborn_openai_compat/src/responses_workflow.rs
  • crates/ironclaw_reborn_openai_compat/tests/dto_contract.rs
  • crates/ironclaw_reborn_openai_compat/tests/error_contract.rs
  • tests/responses_api_path_prefix.rs
  • tests/responses_api_temperature.rs
  • tests/thread_isolation_integration.rs

Comment thread tests/responses_api_temperature.rs

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5591 — f48a08a1 Deployed Jul 4, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows scope: dependencies Dependency updates scope: docs Documentation size: XL 500+ changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Make main branch CI checks green again

3 participants