Skip to content

test(reborn): W6-API2 — webui_v2 mid-gate approval refresh over real gate dispatch - #5743

Merged
henrypark133 merged 12 commits into
mainfrom
w6-api2-authgate
Jul 7, 2026
Merged

henrypark133 merged 12 commits into
mainfrom
w6-api2-authgate

Conversation

@henrypark133

Copy link
Copy Markdown
Collaborator

Summary

STACKED on open PR #5735 (w6-gate-dispatch) — merges after it. Builds on that branch's TurnRunSnapshotSource seam and submit_approval_resolution/submit_auth_resolution helpers.

  • T1 (WebUI-API-2, shipped, approval leg only): tests/integration/webui_v2_gate_refresh.rs — a browser refresh mid-gate must let the user rediscover and resolve the pending gate. Mounts the real webui_v2 router over a hand-built RebornServices facade wired with the harness's own turn-state-converged ApprovalInteractionService. A fresh stream_events drain from after_cursor: None (the SSE handler is a polling wrapper over the same drain, per W5-WEBUI-SPIKE) surfaces the persisted GatePrompt event for the blocked run/gate; resolution goes through the real WEBUI_V2_PATTERN_RESOLVE_GATE HTTP route (POST .../gates/{gate_ref}/resolve), not a direct-resume test shortcut. Asserts the run completes and the approved write actually re-dispatched and persisted.

  • T1 (auth leg / 5b) and T2(a) (submit_auth_resolution e2e): NOT shipped — precise blocker found, no fiction-wiring.
    Investigated deeply (see reasoning below) and confirmed: manual-token auth gates never create an AuthFlowRecord. DefaultAuthInteractionService::resolve's find_gate requires an AuthFlowRecord whose continuation is exactly AuthContinuationRef::TurnGateResume{turn_run_ref, gate_ref}. Grepping every TurnGateResume construction site in ironclaw_reborn_composition, the only place that ever creates one is oauth_gate.rs (GoogleOAuthGateProviderRegistry) — i.e. Google OAuth-gated capabilities. GitHub (github.get_repo, the only auth-gated capability any int-tier harness profile wires — live_auth_gate(), live_auth_and_approval()) is manual-token/PAT based; its BlockedAuth block never touches oauth_gate.rs and creates no AuthFlowRecord at all. This is why resolve_auth_gate's existing test-support shape (seed a scope-visible credential account + direct TurnCoordinator::resume_turn) isn't a shortcut — it's the only way, because there's genuinely nothing for AuthFlowRecordSource/find_gate to find. Cross-confirmed independently via auth_prompt.rs: the Slack-notification auth-prompt rendering explicitly falls back to synthesizing a view straight from credential_requirements precisely because manual-token gates have no flow/challenge to read.

    Consequence: submit_auth_resolution's real dispatch arm is untestable against every existing int-tier harness profile (none wire a Google-OAuth-gated capability). Reaching one needs a new harness profile (OAuth extension asset + provider config + PKCE/state + scripted callback claim) or manually fabricating an AuthFlowRecord via the public AuthFlowManager::create_flow/complete_manual_token API — both a materially separate, bigger seam than "wire a test over existing profiles." Full trace is in the (local-only, not committed) plan doc; happy to paste inline if useful for follow-up planning.

  • T2(b) (triggered run parked on BlockedAuth records the delivery outcome): NOT shipped — same-class blocker.
    build_triggered_run_delivery_hook needs &RebornRuntime (SlackHostBetaRuntimeParts::from_runtime), a composition path built only by build_reborn_runtime. RebornIntegrationGroup/HostRuntimeCapabilityHarness (this branch's harness) are built via build_reborn_services directly — a separate, parallel composition that never produces a RebornRuntime. No bridge exists between the two object graphs from outside the crate. Even setting that aside, GitHub's BlockedAuth has no AuthFlowRecord either (same finding as above), so a Delivered outcome for a personal-scope triggered run parked on auth needs the same OAuth-gate plumbing. Ships no new test beyond the already-merged triggered_delivery_outcome.rs (proves the Denied/project-scoped arm through the real public factory).

Mutation evidence (T1 approval leg)

  • Resolved with a stale/wrong gate_ref in the HTTP POST → 409 conflict (RED), reverted → 200 OK (GREEN).
  • Filtered the replayed GatePrompt search on a deliberately-wrong gate_ref → assertion panic listing the actual correctly-shaped GatePrompt event present in the drain (RED, confirms the assertion discriminates rather than being vacuously true), reverted → GREEN.

Test tails

test approval_gate_rediscovered_and_resolved_after_refresh ... ok
test result: ok. 7 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 1.00s

Regression (unchanged, still green):

reborn_group_journeys:                        9 passed
reborn_group_approvals:                       9 passed
reborn_integration_triggered_delivery_outcome: 1 passed

cargo fmt clean. cargo clippy --all --benches --tests --examples --all-features: 0 warnings.

Test plan

  • cargo test --features integration --test reborn_integration_webui_v2_gate_refresh
  • cargo test --features integration --test reborn_group_journeys (regression)
  • cargo test --features integration --test reborn_integration_triggered_delivery_outcome (regression)
  • cargo test --features integration --test reborn_group_approvals (regression)
  • cargo fmt / cargo clippy --all --benches --tests --examples --all-features

🤖 Generated with Claude Code

henrypark133 and others added 2 commits July 6, 2026 14:51
…table

Issue #5722: RebornIntegrationGroup's real runs live in a turn-state store
disjoint from the harness's own local-dev composition, so the interaction
services built from local_dev_{approval,auth}_interaction_service_for_test
could never find the group's runs (WorkflowRejected{ScopeNotFound}). Adds
a TurnRunSnapshotSource seam so the turn-run locator can read from a
caller-supplied store instead of always deriving it from
local_runtime.turn_state; production callers are unaffected (same value,
now behind a trait object). Wires this into RebornIntegrationGroup via a
new opt-in with_real_gate_dispatch_services() flag, and adds
submit_approval_resolution/submit_auth_resolution so tests can drive the
literal submit_inbound dispatch arm instead of the harness's direct
TurnCoordinator::resume_turn shortcut.

Also adds an integration-tier proof that build_triggered_run_delivery_hook
assembles a working driver over a real local-dev RebornRuntime and records
outcomes through the caller-supplied TriggeredRunDeliveryStore — the
factory-construction path crate-tier tests don't cover (they construct the
driver directly).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…gate dispatch

A browser refresh mid-gate must let the user rediscover and resolve the
pending gate. Mounts the real webui_v2 router over a hand-built RebornServices
facade wired with the harness's own turn-state-converged
ApprovalInteractionService (the same seam with_real_gate_dispatch_services
uses for DefaultProductWorkflow); a fresh stream_events drain from
after_cursor: None (the SSE handler is a polling wrapper over the same drain)
surfaces the persisted GatePrompt event, and resolution goes through the real
WEBUI_V2_PATTERN_RESOLVE_GATE HTTP route, not a direct-resume test shortcut.

Two other legs of this seam (auth-gate mid-gate refresh, and a real
AuthFlowRecord-backed submit_auth_resolution proof) turned out to be
unreachable with the current int-tier harness: manual-token auth gates
(GitHub, the only auth-gated capability any harness profile wires) never
create an AuthFlowRecord at all — only Google-OAuth-gated capabilities do
(oauth_gate.rs), and no harness profile wires one. Reaching either needs a
new OAuth-gated capability profile, tracked as a follow-up rather than
fiction-wired around here.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@ironloopai

ironloopai Bot commented Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

❌ IronLoop Review Status

Head: e962f84078defad1c69d9c1ad5d2614361d398ef
Result: Reviewer planning is blocked by the trusted agent configuration.
Next: Fix the target repository's .ironloop/agents.yaml and agent instruction files, then re-run @ironloop review or update the pull request.
Updated: 2026-07-07T03:20:14.271Z

Stage Status Detail
received reached GitHub delivered the event to IronLoop.
admitted reached The event passed routing and authorization.
config blocked Trusted agent config is invalid: Invalid type: Expected Object but received true
reviewer jobs pending No reviewer jobs were queued because configuration loading failed.
Configuration error

Message: Trusted agent config is invalid: Invalid type: Expected Object but received true

  • reviewers.0.auto_review: Invalid type: Expected Object but received true
Available commands
  • @ironloop agents
  • @ironloop review
  • @ironloop review --agent <agent-id-or-alias>
  • @ironloop status
Run metadata

Origin: auto
Event: pull_request.synchronize
Config path: .ironloop/agents.yaml
Trusted ref: 1255f8716eaf438489186b6a5c20200ab393b9e2
Delivery: c3fa81f0-79b2-11f1-8983-899c17f3fe77

@coderabbitai

coderabbitai Bot commented Jul 6, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: e8df908a-d337-4049-aa68-6d8a36f648af

📥 Commits

Reviewing files that changed from the base of the PR and between 1255f87 and e962f84.

📒 Files selected for processing (1)
  • tests/integration/webui_v2_product_api.rs

📝 Walkthrough

Summary by CodeRabbit

  • Tests
    • Added an end-to-end approval-flow scenario that verifies approval prompts still appear and can be resolved correctly after a page refresh.
    • Confirmed the approved change is applied successfully and the workspace reflects the expected result.

Walkthrough

Adds a new integration test that simulates a browser refresh during an active approval gate: it drains the event stream from a fresh cursor, locates the pending GatePrompt, resolves the gate through the real webui_v2 router endpoint, waits for turn completion, and verifies the resulting workspace file.

Changes

Approval gate rediscovery and resolution test

Layer / File(s) Summary
Gate refresh/resolve integration test
tests/integration/webui_v2_product_api.rs
Adds TurnEventProjectionSource/TurnStatus imports and a new test that replays events after a simulated refresh, resolves a real approval gate via the router, and asserts the approved workspace side-effect.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related issues

Possibly related PRs

  • nearai/ironclaw#5654: Provides the local_dev_approval_interaction_service_for_test wiring this new test relies on to build real approval services.
  • nearai/ironclaw#5655: Introduces the build_webui_event_stream_for_test helper and webui_v2 harness reused by this test's stream-refresh logic.
  • nearai/ironclaw#5735: Adds the real gate dispatch/TurnRunSnapshotSource harness plumbing that this test's gate resolution depends on.

Reviewer note: No sandbox/trust/secrets/egress surface touched here — this is a test-only file wiring against existing RebornServices/router seams. Verify the test actually asserts on TurnStatus::Completed and the persisted file path rather than relying on timing (no sleep-based waits should replace this if not already enforced by AGENTS.md's async test invariants); confirm after_cursor: None truly re-derives gate state from projection replay rather than an in-memory cache, since that's the entire point of the "refresh" scenario (W5-WEBUI-API-2) and a false pass here would mask a real gate-rediscovery bug.

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The summary and test plan are strong, but several required template sections are missing or unfilled, including change type, linked issue, and rollback plan. Fill the missing template sections: Change Type, Linked Issue, Security Impact, DB Impact, Blast Radius, Rollback Plan, Review Follow-Through, and Review track.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed Conventional Commit format is present and the subject matches the new webui_v2 approval-refresh integration test.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5743 July 6, 2026 22:42 Destroyed
@github-actions github-actions Bot added scope: dependencies Dependency updates size: XS < 10 changed lines (excluding docs) risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Jul 6, 2026

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Verdict: ✅ Approved
Findings: 0 blocking / 0 notes
Next: No reviewer action needed.
Head: 517733762cc2c121cb66df1d820374114c118ed0

Run details

Status: Current
Needs human: no
Needs validation: no

**Inline candidates:** 0

Summary

No concrete blocking issues found. The PR adds a focused integration test for rediscovering and resolving a WebUI v2 approval gate after a cold event-stream replay, and registers it in Cargo.toml.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloop review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloop review when the fix may affect multiple areas.
  4. Use @ironloop status to check queued/running/completed/stale/stalled state while reviewers run.

@henrypark133 henrypark133 left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review (multi-agent)

Intent: Add integration coverage for WebUI v2 approval gate rediscovery and resolution after browser refresh using real gate dispatch.
Stats: 1 finding (from 1 raw, 1 after dedup) across 1 file. Reviewers run: security, bugs, performance, tests, conventions, local-patterns, maintainability, approach. Reviewers failed: none. Body-only: 0

Maintainability

  1. Low Keep the gate-refresh case in the WebUI product API bin (Cargo.toml:557-559, confidence 75) — anchor: tests/integration/CLAUDE.md:65
    This registers a new one-test integration binary for a WebUI v2 product-API scenario that already has an owning test file. That splits the same hand-built RebornServices/WebUI facade setup across bins and makes future WebUI product API coverage harder to scan or consolidate.

Comment thread Cargo.toml Outdated
name = "reborn_integration_web_access"
path = "tests/integration/web_access.rs"

[[test]]

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Low — Keep the gate-refresh case in the WebUI product API bin.

This registers a new one-test integration binary for a WebUI v2 product-API scenario that already has an owning test file. That splits the same hand-built RebornServices/WebUI facade setup across bins and makes future WebUI product API coverage harder to scan or consolidate.

Fix: Move approval_gate_rediscovered_and_resolved_after_refresh into tests/integration/webui_v2_product_api.rs and delete this [[test]] entry. Keep any setup local there unless another scenario needs the exact same bundle.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Moved approval_gate_rediscovered_and_resolved_after_refresh into tests/integration/webui_v2_product_api.rs (test content unchanged) and dropped the reborn_integration_webui_v2_gate_refresh [[test]] entry. All imports it needed were already present in the product-API bin except TurnStatus. Full binary now runs 11/11 green.

@railway-app

railway-app Bot commented Jul 6, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5743 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 7, 2026 at 3:28 am

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5743 July 6, 2026 23:11 Destroyed
@ironloopai

ironloopai Bot commented Jul 6, 2026 •

Copy link
Copy Markdown
Contributor

🗂️ Archived IronLoop Review: reviewer

This result is from an older PR head and is no longer the active review.

Field Value
Status Superseded
Verdict ✅ Approved
Findings 0 blocking / 0 notes
Reviewed head 71e088ccb6e3
Archived summary

No concrete blocking issues found. The PR adds a focused integration test for rediscovering and resolving a pending approval gate after a WebUI refresh.

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Verdict: ✅ Approved
Findings: 0 blocking / 0 notes
Next: No reviewer action needed.
Head: 83812002a7068507aa31d394ebf26698cb8298c6

Run details

Status: Current
Needs human: no
Needs validation: no

**Inline candidates:** 0

Summary

No blocking issues found. The PR adds a focused integration test for rediscovering and resolving a WebUI v2 approval gate after a cold event stream refresh, and registers it in Cargo.toml.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloop review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloop review when the fix may affect multiple areas.
  4. Use @ironloop status to check queued/running/completed/stale/stalled state while reviewers run.

henrypark133 and others added 3 commits July 6, 2026 16:58
- Collapse TurnRunSnapshotSource/TriggerTurnSnapshotSource into one
  shared trait at crate-root turn_run_snapshot module; trigger_poller's
  SnapshotActiveRunLookup now maps TurnError -> TriggerError at its own
  boundary instead of duplicating the trait + blanket impls + a wrapper
  struct that turned out unnecessary once both consumers share the type.
- submit_auth_resolution now takes &GateRef (matching
  submit_approval_resolution), converting to &str only at the envelope
  boundary.
- Extract a shared verified_resolution_envelope helper for the
  approval/auth submit_inbound envelope builders.
- Fix group_approvals module doc to describe both tests now present.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…_api bin

Move approval_gate_rediscovered_and_resolved_after_refresh into the
existing W5-WEBUI-API-1 product-API test binary instead of registering
a second one-test bin for the same hand-built RebornServices/WebUI
facade setup. Test content is unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actions github-actions Bot added risk: low Changes to docs, tests, or low-risk modules and removed risk: medium Business logic, config, or moderate-risk modules labels Jul 7, 2026
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5743 July 7, 2026 00:06 Destroyed

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Verdict: ✅ Approved
Findings: 0 blocking / 0 notes
Next: No reviewer action needed.
Head: 9bf3419d98bbeb2ba1bfe2b9d1441d1e9896479d

Run details

Status: Current
Needs human: no
Needs validation: no

**Inline candidates:** 0

Summary

No concrete correctness, security, maintainability, or test-coverage issues found in the PR. The change adds a focused integration test for rediscovering and resolving a pending WebUI approval gate after a refresh.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloop review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloop review when the fix may affect multiple areas.
  4. Use @ironloop status to check queued/running/completed/stale/stalled state while reviewers run.

henrypark133 and others added 2 commits July 6, 2026 17:12
No in-crate consumer imports it via the runtime module path; all of
them (trigger_poller, auth_interaction, test_support via super::*)
resolve it through crate::turn_run_snapshot directly.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5743 July 7, 2026 00:13 Destroyed

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Verdict: ✅ Approved
Findings: 0 blocking / 0 notes
Next: No reviewer action needed.
Head: 71e088ccb6e306cd18cd3cbedf96e85ca826a623

Run details

Status: Current
Needs human: no
Needs validation: no

**Inline candidates:** 0

Summary

No concrete blocking issues found. The PR adds a focused integration test for rediscovering and resolving a pending approval gate after a WebUI refresh.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloop review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloop review when the fix may affect multiple areas.
  4. Use @ironloop status to check queued/running/completed/stale/stalled state while reviewers run.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5743 July 7, 2026 01:00 Destroyed

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Verdict: ✅ Approved
Findings: 0 blocking / 0 notes
Next: No reviewer action needed.
Head: 5c2bf6603b0a05168e23f4a7b353b1c847d564bb

Run details

Status: Current
Needs human: no
Needs validation: no

**Inline candidates:** 0

Summary

Reviewed the test-only change adding WebUI v2 approval gate refresh coverage. I did not find concrete correctness, security, or maintainability issues introduced by the PR.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloop review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloop review when the fix may affect multiple areas.
  4. Use @ironloop status to check queued/running/completed/stale/stalled state while reviewers run.

Base automatically changed from w6-gate-dispatch to main July 7, 2026 03:11
Copilot AI review requested due to automatic review settings July 7, 2026 03:20
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5743 July 7, 2026 03:20 Destroyed

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

github-actions Bot commented Jul 7, 2026

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 85.38% (273556 / 320385 lines)
  floor:    85.3% (tolerance 0.5pp -> effective floor 84.8%)
  denominator: 320385 lines now vs 320188 at floor capture (+197 lines, +0.06%) — not a material change

⚠️ 3 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts, ironclaw_skill_learning

Reborn integration-tier coverage

Line coverage (Reborn crates): 85.38% — 273556 / 320385 lines

Per-crate breakdown (65 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 347
ironclaw_skill_learning 0% 0 / 61
ironclaw_wasm_sandbox_core 7.37% 7 / 95
ironclaw_runtime_policy 33.2% 80 / 241
ironclaw_event_projections 43.34% 673 / 1553
ironclaw_run_state 52.73% 222 / 421
ironclaw_authorization 53.54% 461 / 861
ironclaw_triggers 60.32% 1736 / 2878
ironclaw_observability 61.54% 16 / 26
ironclaw_reborn_cli 64.58% 3988 / 6175
ironclaw_webui_v2 65.47% 2391 / 3652
ironclaw_filesystem 65.86% 3212 / 4877
ironclaw_reborn_migration 67.01% 1172 / 1749
ironclaw_memory 67.12% 747 / 1113
ironclaw_dispatcher 67.15% 92 / 137
ironclaw_mcp 67.42% 569 / 844
ironclaw_trust 72.88% 661 / 907
ironclaw_reborn_event_store 73.27% 940 / 1283
ironclaw_capabilities 74.08% 1658 / 2238
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_extractors 74.72% 538 / 720
ironclaw_first_party_extensions 77.62% 5410 / 6970
ironclaw_llm 77.67% 19045 / 24519
ironclaw_product_context 78.57% 11 / 14
ironclaw_wasm_product_adapters 80.58% 1510 / 1874
ironclaw_process_sandbox 80.65% 671 / 832
ironclaw_reborn_openai_compat 80.95% 956 / 1181
ironclaw_memory_native 81.86% 3226 / 3941
ironclaw_secrets 82.33% 2716 / 3299
ironclaw_wasm 82.54% 950 / 1151
ironclaw_events 83.44% 1759 / 2108
ironclaw_processes 84.06% 965 / 1148
ironclaw_host_api 84.67% 3125 / 3691
ironclaw_threads 84.9% 3251 / 3829
ironclaw_turns 85.72% 9829 / 11467
ironclaw_projects 85.92% 659 / 767
ironclaw_network 86.12% 670 / 778
ironclaw_product_workflow 86.3% 10662 / 12354
ironclaw_auth 86.32% 2727 / 3159
ironclaw_common 86.59% 1472 / 1700
ironclaw_slack_v2_adapter 86.79% 1806 / 2081
ironclaw_reborn_config 86.98% 1730 / 1989
ironclaw_product_adapters 87.16% 3170 / 3637
ironclaw_reborn_traces 87.35% 10325 / 11820
ironclaw_skills 87.36% 4335 / 4962
ironclaw_hooks 87.84% 9915 / 11288
ironclaw_product_adapter_registry 87.96% 526 / 598
ironclaw_extensions 88.26% 2631 / 2981
ironclaw_reborn_identity 88.43% 344 / 389
ironclaw_reborn_composition 89.04% 68525 / 76961
ironclaw_host_runtime 89.12% 17249 / 19355
ironclaw_conversations 90.11% 2924 / 3245
ironclaw_approvals 90.51% 1507 / 1665
ironclaw_reborn 91.17% 17238 / 18908
ironclaw_event_streams 91.48% 1009 / 1103
ironclaw_reborn_webui_ingress 91.68% 2094 / 2284
ironclaw_loop_support 92.34% 14093 / 15262
ironclaw_attachments 93.06% 630 / 677
ironclaw_telegram_v2_adapter 94.01% 2447 / 2603
ironclaw_resources 94.25% 3625 / 3846
ironclaw_agent_loop 94.49% 8290 / 8773
ironclaw_safety 94.81% 3669 / 3870
ironclaw_first_party_extension_ports 95% 3094 / 3257
ironclaw_outbound 95.59% 3556 / 3720

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (4 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_oauth v1-only: consumed only by root ironclaw (src/auth/oauth.rs); no crates/* dependents. Crate's own doc comment confirms v1-only. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5743 — e962f840 Deployed Jul 7, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: dependencies Dependency updates size: XS < 10 changed lines (excluding docs)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants