Skip to content

fix(ci): run the full clippy matrix in the merge queue + fix libsql-only dead code - #5840

Merged
BenKurrek merged 2 commits into
mainfrom
ci/full-clippy-matrix-in-merge-queue
Jul 8, 2026
Merged

BenKurrek merged 2 commits into
mainfrom
ci/full-clippy-matrix-in-merge-queue

Conversation

@BenKurrek

Copy link
Copy Markdown
Collaborator

Why

Green merges keep breaking main. The merge queue is the enforced production gate (ruleset "Main": required checks + merge queue), but code_style.yml gave merge_group the slim clippy matrix (all-features only) while push-to-main ran the full matrix (all-features, default, libsql-only). Any feature-gated lint failure therefore surfaced only after merge.

That's what happened today: #5726 introduced FilesystemProductionEventStoresInput::Prebuilt, which is constructed only under the postgres feature. The queue linted all-features only (where postgres is on), and every push run since has been red on Clippy (libsql-only): variant Prebuilt is never constructed. Hidden behind it was a second instance the CI log never reached: CallbackScopeResolution::RequestedOnly is constructed only under slack-v2-host-beta.

What

  • cfg-gate Prebuilt behind postgres and RequestedOnly behind slack-v2-host-beta (variant + match arm), completing the pattern the event-store enum already uses for its Config variant. #[allow(dead_code)] would suppress exactly the signal that caught a real enum-shape/feature mismatch.
  • merge_group now runs the full clippy matrix; PRs keep the slim lane for fast feedback; push stays full (post-merge confirmation + cache warming).
  • The required Code Style (fmt + clippy) roll-up now asserts all three lanes were actually in the matrix on merge_group/push runs, so a slim-gate regression fails loudly instead of passing green-but-hollow.

Verification

  • cargo clippy --all --tests --examples --no-default-features --features libsql -- -D warnings — the exact failing CI lane — passes locally with these changes (it fails on both dead-code errors without them).
  • cargo fmt -p ironclaw_reborn_composition -- --check clean; actionlint clean on the workflow (pre-existing style nits only).
  • This PR's own merge-queue run exercises the full matrix on the merged state, so the gate change validates the code fix pre-merge.

Regression coverage: the libsql-only clippy lane itself — after this change it runs in the merge queue on every merge group.

Pre-existing and deliberately not addressed here: building ironclaw_reborn_composition standalone with bare --features libsql --tests hits unrelated dead test doubles (SlackIdentityProviderClient and friends in product_auth/serve/oauth.rs tests); no CI lane builds that shape today.

🤖 Generated with Claude Code

@ironloopai

ironloopai Bot commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

🔎 IronLoop Review Status

Head: bc68ab7ec71d2c2e7de541828bd25e371d0691b3
Result: One or more reviewer results were superseded by a newer PR head.
Next: Run @ironloopai review on the latest PR head.
Updated: 2026-07-08T16:46:19.303Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Superseded N/A N/A 2026-07-08T16:20:00.412Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Superseded by a newer PR head. New head: d8d9f78. Previous verdict: Approved.
Recent activity
Time Reviewer State Detail
2026-07-08T15:26:08.319Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-08T15:26:08.325Z ironloop/common-reviewer (reviewer) Queued Added to the local review work handoff.
2026-07-08T15:26:09.053Z ironloop/common-reviewer (reviewer) Started Reviewer worker started attempt 1.
2026-07-08T15:26:12.084Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (merge_ref) at fd5f72d.
2026-07-08T15:28:52.372Z ironloop/common-reviewer (reviewer) Superseded Old-head reviewer is still running after newer head d8d9f78 replaced it. Codex is reviewing; process live; elapsed 2m 42s; timeout in 17m 18s; last heartbeat 2026-07-08T15:28:52.372Z. Codex emitted stderr output at 2026-07-08T15:28:22.794Z.
2026-07-08T15:28:52.705Z ironloop/common-reviewer (reviewer) Result captured Approved; 0 blocking findings.
2026-07-08T15:28:52.705Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
2026-07-08T16:20:00.412Z ironloop/common-reviewer (reviewer) Superseded A newer PR head replaced this review (d8d9f78).
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent-id-or-alias>
  • @ironloopai status
Run metadata

Admission: webhook accepted the request and IronLoop persisted review state before this projection.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5840 July 8, 2026 15:26 Destroyed
@github-actions github-actions Bot added scope: ci CI/CD workflows size: S 10-49 changed lines risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Jul 8, 2026
@coderabbitai

coderabbitai Bot commented Jul 8, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: eb2cd96a-3a01-47a9-8f48-2cee7121afc4

📥 Commits

Reviewing files that changed from the base of the PR and between d8d9f78 and bc68ab7.

📒 Files selected for processing (2)
  • crates/ironclaw_reborn_composition/src/factory.rs
  • crates/ironclaw_reborn_composition/src/product_auth/serve/oauth.rs

📝 Walkthrough

Summary by CodeRabbit

  • Bug Fixes
    • Improved CI checks so merge-queue plus push runs validate the full required clippy matrix lanes, preventing missing-matrix failures.
    • Fixed conditional builds so PostgreSQL-backed prebuilt event-store handling and Slack beta OAuth callback scope resolution are only compiled when the corresponding features are enabled.
  • Chores
    • Refined code-style workflow matrix behavior so pull_request uses the slim clippy lane set, while merge-group uses the full feature matrix.

Walkthrough

This PR tightens the CI clippy matrix for pull requests, enforces required lanes on merge queue and push runs, and gates two Rust enum variants plus their matching branches behind feature flags.

Changes

CI Matrix and Feature Gating

Layer / File(s) Summary
Clippy matrix event gating and required-lane assertion
.github/workflows/code_style.yml
Slim matrix selection now applies only to pull_request; merge_group uses the full matrix, and a roll-up step checks that required lanes are present for merge queue/push.
Postgres-gated event store variant
crates/ironclaw_reborn_composition/src/factory.rs
FilesystemProductionEventStoresInput::Prebuilt and its builder match arm are compiled only when postgres is enabled.
Slack-gated callback scope resolution
crates/ironclaw_reborn_composition/src/product_auth/serve/oauth.rs
CallbackScopeResolution::RequestedOnly and its resolve_callback_scopes match arm are compiled only when slack-v2-host-beta is enabled.

Estimated code review effort: 2 (Simple) | ~10 minutes

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains why, what, and verification, but it omits most required template sections like Change Type, Linked Issue, and security/trust checklists. Rewrite the PR body using the repository template and fill in every required section, marking N/A where appropriate.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title uses Conventional Commits and accurately summarizes the CI and feature-gating changes.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces conditional compilation attributes (#[cfg(...)]) to gate specific enum variants and their corresponding match arms behind feature flags. Specifically, the Prebuilt variant of FilesystemProductionEventStoresInput is now conditionally compiled under the postgres feature, and the RequestedOnly variant of CallbackScopeResolution is gated under the slack-v2-host-beta feature. There are no review comments, and I have no feedback to provide.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
✅ Approved 0 0 0 f29230e278f6

Head: f29230e278f64b4d5d6c5f040acd5d4a95b25b4a
Next: No reviewer action needed.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

No concrete blocking issues found in the CI matrix change or feature-gated dead-code fixes.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.
  4. Use @ironloopai status to check queued/running/completed/stale/stalled state while reviewers run.

@BenKurrek BenKurrek added the skip-regression-check Bypass regression test CI gate (tests exist but not in tests/ dir) label Jul 8, 2026
@github-actions

github-actions Bot commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 85.16% (282278 / 331449 lines)
  floor:    85.3% (tolerance 0.5pp -> effective floor 84.8%)
  denominator: 331449 lines now vs 320188 at floor capture (+11261 lines, +3.52%) — not a material change

⚠️ 3 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts, ironclaw_skill_learning

Reborn integration-tier coverage

Line coverage (Reborn crates): 85.16% — 282278 / 331449 lines

Per-crate breakdown (65 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 347
ironclaw_skill_learning 0% 0 / 61
ironclaw_wasm_sandbox_core 7.37% 7 / 95
ironclaw_runtime_policy 33.2% 80 / 241
ironclaw_event_projections 43.34% 673 / 1553
ironclaw_run_state 52.36% 222 / 424
ironclaw_authorization 53.54% 461 / 861
ironclaw_triggers 59.99% 1736 / 2894
ironclaw_observability 61.54% 16 / 26
ironclaw_webui_v2 63.12% 2543 / 4029
ironclaw_mcp 63.15% 581 / 920
ironclaw_reborn_cli 63.41% 3816 / 6018
ironclaw_reborn_migration 67.01% 1172 / 1749
ironclaw_memory 67.12% 747 / 1113
ironclaw_dispatcher 67.15% 92 / 137
ironclaw_filesystem 67.44% 3815 / 5657
ironclaw_trust 72.88% 661 / 907
ironclaw_capabilities 74.08% 1658 / 2238
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_reborn_event_store 74.61% 958 / 1284
ironclaw_extractors 74.72% 538 / 720
ironclaw_first_party_extensions 77.62% 5411 / 6971
ironclaw_llm 77.88% 19479 / 25013
ironclaw_product_context 78.57% 11 / 14
ironclaw_wasm_product_adapters 80.58% 1510 / 1874
ironclaw_process_sandbox 80.65% 671 / 832
ironclaw_reborn_openai_compat 80.95% 956 / 1181
ironclaw_memory_native 81.86% 3226 / 3941
ironclaw_wasm 82.54% 950 / 1151
ironclaw_secrets 82.7% 2791 / 3375
ironclaw_events 83.47% 1762 / 2111
ironclaw_processes 84.06% 965 / 1148
ironclaw_turns 84.24% 13099 / 15549
ironclaw_host_api 85.17% 2549 / 2993
ironclaw_product_workflow 85.74% 10626 / 12393
ironclaw_projects 85.92% 659 / 767
ironclaw_network 86.12% 670 / 778
ironclaw_common 86.59% 1472 / 1700
ironclaw_threads 86.62% 4132 / 4770
ironclaw_slack_v2_adapter 86.79% 1806 / 2081
ironclaw_auth 86.96% 2995 / 3444
ironclaw_reborn_config 86.98% 1730 / 1989
ironclaw_reborn_identity 87.03% 557 / 640
ironclaw_product_adapters 87.29% 3207 / 3674
ironclaw_skills 87.35% 4336 / 4964
ironclaw_hooks 87.84% 9916 / 11289
ironclaw_product_adapter_registry 87.96% 526 / 598
ironclaw_reborn_traces 88.23% 11707 / 13268
ironclaw_extensions 88.26% 2631 / 2981
ironclaw_reborn_composition 88.77% 69720 / 78541
ironclaw_host_runtime 88.94% 17522 / 19700
ironclaw_reborn 89.14% 15703 / 17616
ironclaw_conversations 90% 2924 / 3249
ironclaw_approvals 90.51% 1507 / 1665
ironclaw_event_streams 91.48% 1009 / 1103
ironclaw_loop_support 92.46% 14725 / 15926
ironclaw_resources 93.05% 4607 / 4951
ironclaw_attachments 93.06% 630 / 677
ironclaw_reborn_webui_ingress 93.19% 2217 / 2379
ironclaw_telegram_v2_adapter 94.01% 2447 / 2603
ironclaw_agent_loop 94.58% 8776 / 9279
ironclaw_safety 94.8% 3668 / 3869
ironclaw_first_party_extension_ports 95% 3094 / 3257
ironclaw_outbound 95.59% 3556 / 3720

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (4 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_oauth v1-only: consumed only by root ironclaw (src/auth/oauth.rs); no crates/* dependents. Crate's own doc comment confirms v1-only. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

@railway-app

railway-app Bot commented Jul 8, 2026

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5840 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 8, 2026 at 3:36 pm

…nly dead code

The merge queue (the production gate) ran only the slim all-features
clippy lane while pushes to main ran the full matrix, so feature-gated
dead code passed the queue and broke main post-merge: #5726 landed
FilesystemProductionEventStoresInput::Prebuilt, which is constructed
only under the postgres feature, and behind it
CallbackScopeResolution::RequestedOnly is constructed only under
slack-v2-host-beta. Both are dead code in the libsql-only lane, which
before this change only ran on push to main.

- cfg-gate Prebuilt behind postgres and RequestedOnly behind
  slack-v2-host-beta (variant + match arm), matching construction
  reality; #[allow(dead_code)] would hide the signal instead
- merge_group now gets the FULL clippy matrix in code_style.yml; PRs
  keep the slim lane for fast feedback
- the Code Style roll-up asserts all three lanes actually ran on
  merge-queue/push events, so a slim-gate regression cannot silently
  return (the roll-up is a required check)

Regression coverage: the libsql-only clippy lane itself — after this
change it runs in the merge queue, and this PR's own queue run
exercises it on the merged state. Verified locally with the exact
failing lane: cargo clippy --all --tests --examples
--no-default-features --features libsql -- -D warnings.
Regression coverage is the libsql-only clippy lane itself, which this
change adds to the merge queue — there is no unit-testable surface for
a cfg attribute + matrix condition. [skip-regression-check]

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@BenKurrek
BenKurrek force-pushed the ci/full-clippy-matrix-in-merge-queue branch from f29230e to d8d9f78 Compare July 8, 2026 16:19
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5840 July 8, 2026 16:20 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5840 July 8, 2026 16:46 Destroyed
@BenKurrek
BenKurrek merged commit 1f389a7 into main Jul 8, 2026
12 of 14 checks passed
@BenKurrek
BenKurrek deleted the ci/full-clippy-matrix-in-merge-queue branch July 8, 2026 16:46
ilblackdragon added a commit that referenced this pull request Jul 14, 2026
…6018) (#6022)

* ci: add static pre-push checks — include_str/Docker-COPY + hermetic env (#6018)

Categorized main-branch CI history showed the deterministic (non-flaky)
breakages share one trait: a cheap static check would catch them, but the
pre-push gate ran none. Adds three checks mapped to the failure classes.

1. include_str! path + Docker-COPY coverage (scripts/ci/check-include-str-paths.sh)
   Every include_str!("…") target must exist AND be present in the build
   context of each Dockerfile that compiles the referencing crate. Guards the
   #5603 Docker outage class (host build passes, Docker build fails because a
   repo-root prompts/ dir was never COPYd). Excludes #[cfg(test)] includes and
   COPY . . images; attributes per-Dockerfile so Dockerfile.reborn is never
   blamed for a src/ prompt it doesn't compile.
   This surfaced a real latent bug: Dockerfile.test builds --bin ironclaw but
   omitted COPY prompts/ / profiles/ / providers.json (all required by prod
   consts) — fixed here.

2. Hermetic env guard (scripts/ci/check-hermetic-env.sh)
   Delta + function-scoped (git diff -W): flags only newly-added raw
   std::env::set_var/remove_var whose enclosing function lacks an env lock
   guard (lock_env/lock_runtime_env/ENV_MUTEX/EnvGuard). Targets the #6015
   coverage-flake class and Rust 1.82 set_var UB. Quiet on the ~700 existing
   sites; honors // env-hermetic: for genuine single-threaded cases.

3. libsql-only clippy leg
   Added to the pre-push strict branch and quality_gate_strict.sh. Catches the
   cfg/dead_code class (#5840 Prebuilt) that default-feature clippy misses.

Wiring: checks 1 & 2 run on every pre-push (no compile); check 3 under
IRONCLAW_STRICT_LINT. New required code_style.yml `static-checks` job runs
check 1 + both self-test suites (14 cases) server-side.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* ci: harden static pre-push checks per PR #6022 review

Addresses review findings on the include_str/Docker-COPY and hermetic-env
static checks. Each fix ships with a regression case in the self-tests.

check-include-str-paths.sh:
- cfg_test_spans: stop a braceless `#[cfg(test)]` item (e.g. `use x;`) at
  the first `;` instead of running forward to the next unrelated `{`, which
  swallowed real code and hid its include_str! calls (false negative).
- Track full normalized COPY paths and add an `is_covered` nested-path
  check so a narrowed `COPY crates/foo/` covers crates/foo but not sibling
  crates (previously top-segment matching treated all of crates/ as copied).
- Scan the repo-root build.rs (cargo build compiles it too) and flag
  include_str! targets that resolve outside the repo — they exist on the
  host but no Docker COPY can ever include them.

check-hermetic-env.sh:
- Prefer GITHUB_BASE_REF for base-ref resolution so the check works on a
  shallow CI checkout that lacks origin/main.
- Drop `|| true` on the git diff so a diff failure aborts instead of
  silently yielding an empty diff that bypasses the guard.
- Strip `//` comments before the guard-token test so a bare `// EnvGuard`
  comment no longer exempts an adjacent raw set_var.

code_style.yml:
- Broaden the has_code predicate to cover scripts/ci/, .githooks/, and all
  Dockerfile* so changes to the guardrails themselves run static-checks
  instead of being skipped (and accepted by the rollup).
- Run check-hermetic-env.sh against the actual PR diff, not just the
  synthetic self-tests, fetching the PR base tip first.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5840 — bc68ab7e Deployed Jul 8, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows size: S 10-49 changed lines skip-regression-check Bypass regression test CI gate (tests exist but not in tests/ dir)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant