Skip to content

ci: revive the nightly deep tier + make Platform & Compat and Reborn E2E requirable - #5841

Merged
BenKurrek merged 9 commits into
mainfrom
ci/deep-tier-and-requirable-rollups
Jul 8, 2026
Merged

BenKurrek merged 9 commits into
mainfrom
ci/deep-tier-and-requirable-rollups

Conversation

@BenKurrek

@BenKurrek BenKurrek commented Jul 8, 2026 •

Copy link
Copy Markdown
Collaborator

Follow-up to #5840 (merge-queue full clippy matrix). That PR closes the gate for feature-matrix lints; this one revives the silently-dead deep tier and makes the remaining deterministic workflows requirable as status checks.

Why

Nightly Deep CI has never had a successful run — not once since its creation on 2026-05-06. 65 of its 74 retained runs are startup_failure with zero jobs executed. Root cause: reusable-workflow call-contract violations, validated by GitHub at trigger time, which kill the entire run before any job — including the in-run nightly-alert job, so nothing ever reported it (contrast: "Nightly E2E failed" #4108 exists because that workflow fails after starting). Three stacked violations:

  1. platform-and-compat.yml's version-check job declares job-level pull-requests: read + issues: read; nightly granted only contents: read. A called workflow may not request more than the caller grants — validated even though the job is event-gated off schedule runs. (Present since roughly day one.)
  2. reborn-tests.yml's coverage-report job declares pull-requests: write — same class (landed with the coverage ratchet).
  3. reborn-tests.yml references secrets.SCCACHE_* (2026-07-03 sccache rollout) and the call site didn't pass secrets: inherit.

Separately: Platform & Compat's deep jobs never ran under nightly anyway. github.event_name == 'workflow_call' never matches — in a reusable workflow, event_name reflects the caller's event (schedule). Windows Build, Benchmark Compilation, and Docker Build are all skipped in the last nightly run that executed jobs at all (run 28702916492).

Also, per the CI-contract direction: Platform & Compat had no stable roll-up (unrequirable), and Reborn E2E didn't run in the merge queue.

What

  • nightly-deep-ci.yml: secrets: inherit + caller-side permissions supersets on the reborn-tests and platform-and-compat calls — unbreaks nightly startup.
  • platform-and-compat.yml: new deep workflow_call marker input (default true, only materializes under workflow_call); windows-build / wasm-wit-compat / bench-compile / docker-build gate on it instead of the never-true event_name == 'workflow_call'.
  • nightly-watchdog.yml (new): dead-man's switch at 08:00 UTC. Checks the latest scheduled Nightly Deep CI run from outside it and drives the existing .github/scripts/nightly-alert-issue.sh issue contract. Alarms on: missing run, run older than 26h (cron never fired), or any non-success conclusion — including startup_failure, which the in-run alert structurally cannot report.
  • platform-and-compat.yml: stable Platform & Compat roll-up job (skip-tolerant of event/scope-gated jobs, requirable as a status check). Deleted the vestigial matrix-config job: test_matrix had no consumer, and windows_matrix's SLIM branch was unreachable (windows-build never runs on PR/merge_group). Docker images now also build in the merge queue when the merge group touches Dockerfile*/.dockerignore.
  • reborn-e2e.yml: runs in the merge queue. merge_group trigger + a changes scope job (merge_group doesn't support paths:); the pull_request trigger drops its paths: filter in favor of the same scope job so the Reborn E2E roll-up reports on every PR — a prerequisite for making it a required check without wedging the queue. Out-of-scope PRs/merge-groups skip the heavy jobs and the roll-up passes fast.
  • .github/workflows/README.md (new): the CI tier contract (PR = fast feedback, merge queue = production gate, push = confirm + caches, nightly = deep), the required-check inventory, the reusable-workflow gotchas above, and the deliberately-accepted gaps.

Validation

Dispatched Nightly Deep CI from this branch via workflow_dispatch:

  • At the first commit (secrets fix only): still startup_failure, 0 jobs — which is how the permissions class was found.
  • At head (secrets + permissions): run 28955520314 spawns 43 jobs and executes. Startup validation passes for the first time in the workflow's existence.

actionlint clean on all touched workflows (pre-existing style nits only). The Windows/bench/docker skip diagnosis is empirical (job conclusions from run 28702916492).

Queue cost

Reborn E2E adds ~5–9 min wall-clock per merge group (recent main-push run times), running in parallel with Tests (Reborn) (~10–15 min), so queue latency is roughly unchanged. Docker builds enter the queue only for Dockerfile-touching merge groups.

After this lands

  1. Watch a few merge groups and tomorrow's 04:00 UTC nightly.
  2. Then add Platform & Compat and Reborn E2E to the required checks in ruleset "Main" (Settings → Rules → Rulesets → Main), alongside the existing Code Style (fmt + clippy) and Tests (Reborn).
  3. Expect the watchdog to open/refresh "Nightly Deep CI failed" until nightly is genuinely green — the deep suites have real failures behind the startup failures, so there is a burn-down behind a green nightly.

🤖 Generated with Claude Code


Round 2 (9f9f223): alert every nightly, Slack mirror, stress threshold

Reborn Playwright and IronClaw Stress turned out to be failing nightly with no alerting at all — the same silent-failure class, two more instances. Diagnoses:

  • IronClaw Stress (red on every retained scheduled run): the nightly bottleneck suite capped p95 at 1500ms, but its model-tail case injects a synthetic 2.0s model wait by design — the ceiling was structurally unsatisfiable (measured p95 2.05s = the synthetic wait + ~50ms of real work; every case at 0.00% failures — the system itself is healthy). Raised the nightly cap to 2500ms (PR mode already ran at 3000ms). Proper follow-up: per-case ceilings in ironclaw_stress.
  • Reborn Playwright (flaky-red): last night failed on test_reborn_legacy_looping_tool_calls_stop_at_low_iteration_boundary asserting failure_category == "driver_protocol_violation" while the runtime now emits "iteration_limit" — the expectation was already realigned on main by the error-classification refactor refactor(errors): static enforcement that failures surface, not swallow #5651 (merged 2026-07-08); no change needed here, tonight should pass.
  • Nightly E2E: two v1-gateway tests failing since 2026-07-05 (test_auth_required_sse_without_duplicate_response, test_chat_reply_always_auto_approves_next_same_tool) — real burn-down items, tracked by the existing Nightly E2E failed #4108 alert issue; not addressed in this CI-plumbing PR.

Changes:

  • ironclaw-stress.yml + reborn-playwright.yml: schedule-only alert jobs driving the shared nightly-alert-issue.sh (issue titles IronClaw Stress nightly failed / Reborn Playwright nightly failed).
  • nightly-watchdog.yml: generalized to a matrix over all four nightlies — startup failures and cron-never-fired alarm everywhere, not just Deep CI.
  • nightly-alert-issue.sh: optional Slack mirror — when the SLACK_CI_ALERTS_WEBHOOK_URL repo secret is set (a Slack incoming-webhook URL), every failure posts a one-liner (run + issue links) and every recovery posts a close-out to the CI alerts channel. Absent secret = silent no-op, delivery is best-effort and never fails the alert job. All five call sites pass it through.
  • README: nightly-alerting section (including the caveat that in-run alerts can't attach their own run's logs; the watchdog's 08:00 pass backfills them).

Operator setup for Slack (one-time): create a Slack app → enable Incoming Webhooks → add a webhook for the alerts channel → gh secret set SLACK_CI_ALERTS_WEBHOOK_URL --repo nearai/ironclaw.


Round 3 (ec493db): alerting simplified per review direction — Slack-only, one path

  • GitHub-issue alerting removed entirely: nightly-alert-issue.sh + its test harness deleted; in-run nightly-alert jobs removed from nightly-deep-ci.yml and nightly-e2e.yml (and the round-2 stress/playwright ones). Net −745 lines.
  • nightly-watchdog.yml is the single alerting path: 08:00 UTC, checks all four nightlies' latest scheduled runs, posts failures (workflow, conclusion, failed job names, run link) to Slack via the existing secrets.SLACK_WEBHOOK_URL — the same webhook live-canary already reports through, so no new secret or channel setup is needed. Successes post nothing. A detected failure also turns the watchdog's matrix job red, so its run history doubles as the failure record.
  • Housekeeping after merge: manually close the open "Nightly E2E failed" issue Nightly E2E failed #4108 — nothing auto-closes it now.

Round 4 (09e0a8f): review fixes + legacy suite frozen

  • Review triage: IronLoop's blocking finding fixed — the merge-queue docker arm no longer requires has_legacy_tests (the classifier only matches the literal Dockerfile, so Dockerfile.reborn/.dockerignore-only merge groups were skipping the build). Dropped the dead has_engine_replay_risk scope output (CodeRabbit). The watchdog if: always() comment is superseded by the round-3 single-step design. All threads replied.
  • Legacy v1 suite frozen (team decision): nightly no longer invokes test.yml, leaving it invoked nowhere until src/ is removed. Documented loudly in the workflow header + README, including the consequence (test.yml is the only place the root ironclaw package's tests run) and the revert path (restore the call job for a v1 fix). Explicit freeze with a paper trail — not the silent-death mode.
  • Validation complete across the fleet: Reborn Playwright dispatched from main → success (confirms refactor(errors): static enforcement that failures surface, not swallow #5651 realigned the failing expectation); IronClaw Stress dispatched from this branch → success (confirms the 2500ms threshold). Together with the 57/57 Deep CI run, every nightly fix in this PR is empirically validated.

Round 5: legacy fully out of the nightly fleet

  • nightly-e2e.yml deleted and Nightly E2E removed from the watchdog matrix. It was the v1 browser suite's scheduler and — like pre-revival Deep CI — had zero successful runs in retained history (its own alert issue Nightly E2E failed #4108 says there is no prior green run to attribute against). Its standing failures are v1 /api/chat tests, frozen with the rest of v1.
  • Combined with round 4's freeze of test.yml, no legacy v1 test suite is invoked by any scheduled workflow. test.yml and e2e.yml remain in-tree (callable manually), documented in the README to be deleted together with src/.
  • The nightly fleet is now: Nightly Deep CI, Reborn Playwright, IronClaw Stress — all three empirically validated green today — with the watchdog covering exactly those three.
  • After merge: manually close Nightly E2E failed #4108 (nothing auto-closes it now).

…E2E requirable

Nightly Deep CI has startup-failed every night since 2026-06-20 with
zero jobs: reborn-tests.yml references secrets.SCCACHE_* (sccache-dist)
and nightly's call site did not pass secrets, which fails workflow
validation at trigger time. The in-run nightly-alert job dies with the
run, so nothing reported it. Separately, Platform & Compat's deep jobs
(Windows build, bench compile, docker build) were gated on
github.event_name == 'workflow_call', which never matches — in a
reusable workflow event_name reflects the caller's event — so nightly's
"deep reuse" of those jobs silently skipped (all three are 'skipped' in
the last nightly run that executed jobs at all).

- nightly-deep-ci.yml: pass `secrets: inherit` to the reborn-tests call
- platform-and-compat.yml: add a `deep` workflow_call marker input
  (default true, materializes only under workflow_call) and gate
  windows-build / wasm-wit-compat / bench-compile / docker-build on it
  instead of the never-true event_name comparison
- nightly-watchdog.yml (new): dead-man's switch that inspects the
  latest scheduled Nightly Deep CI run from outside it — startup
  failures and never-fired crons now raise/update the same "Nightly
  Deep CI failed" issue via .github/scripts/nightly-alert-issue.sh
- platform-and-compat.yml: add a stable "Platform & Compat" roll-up job
  (skip-tolerant, requirable as a status check), delete the vestigial
  matrix-config job (test_matrix had no consumer; windows_matrix's SLIM
  branch was unreachable because windows-build never runs on PR or
  merge_group), and build Docker images in the merge queue when the
  merge group touches Dockerfile inputs
- reborn-e2e.yml: run in the merge queue — merge_group trigger plus a
  changes job mirroring the pull_request/push paths filters
  (merge_group does not support paths), with the "Reborn E2E" roll-up
  reporting on every queue entry so it can become a required check
- .github/workflows/README.md (new): the CI tier contract,
  required-check inventory, deep-tier gotchas, and deliberately
  accepted gaps

Verified with actionlint (no findings beyond pre-existing SC2129 style
nits). Reborn E2E queue cost is ~5-9 min based on recent main runs.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@ironloopai

ironloopai Bot commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

🔎 IronLoop Review Status

Head: e485d8af1e0ce7004c9ef3cc183946121578ef86
Result: One or more reviewer results were superseded by a newer PR head.
Next: Run @ironloopai review on the latest PR head.
Updated: 2026-07-08T16:48:14.259Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Superseded N/A N/A 2026-07-08T15:40:34.084Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Superseded by a newer PR head. New head: 3679938. Previous verdict: Changes requested.
Recent activity
Time Reviewer State Detail
2026-07-08T15:30:48.602Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-08T15:30:48.610Z ironloop/common-reviewer (reviewer) Queued Added to the local review work handoff.
2026-07-08T15:30:49.551Z ironloop/common-reviewer (reviewer) Started Reviewer worker started attempt 1.
2026-07-08T15:30:52.707Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (merge_ref) at efc8005.
2026-07-08T15:36:48.714Z ironloop/common-reviewer (reviewer) Superseded Old-head reviewer is still running after newer head 3679938 replaced it. Codex is reviewing; process live; elapsed 5m 57s; timeout in 14m 3s; last heartbeat 2026-07-08T15:36:48.714Z. Codex emitted stderr output at 2026-07-08T15:36:22.211Z.
2026-07-08T15:37:06.460Z ironloop/common-reviewer (reviewer) Result captured Changes requested; 1 blocking finding.
2026-07-08T15:37:06.460Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
2026-07-08T15:40:34.084Z ironloop/common-reviewer (reviewer) Superseded A newer PR head replaced this review (3679938).
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent-id-or-alias>
  • @ironloopai status
Run metadata

Admission: webhook accepted the request and IronLoop persisted review state before this projection.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5841 July 8, 2026 15:30 Destroyed
@github-actions github-actions Bot added scope: ci CI/CD workflows scope: docs Documentation size: L 200-499 changed lines risk: medium Business logic, config, or moderate-risk modules labels Jul 8, 2026
@coderabbitai

coderabbitai Bot commented Jul 8, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: fd8100d6-be3a-483e-a4ef-7942716e4441

📥 Commits

Reviewing files that changed from the base of the PR and between a1262e2 and b6a6737.

📒 Files selected for processing (1)
  • .github/workflows/README.md

📝 Walkthrough

Summary by CodeRabbit

  • New Features

    • Added a nightly watchdog that checks scheduled CI runs and alerts on missing, stale, or failed executions.
    • Added broader CI coverage for merge queues and reusable deep checks.
  • Bug Fixes

    • Improved CI gating so heavy jobs run only when relevant changes are detected.
    • Added a single stable roll-up check to make CI results clearer and more reliable.
  • Documentation

    • Added guidance describing the CI tiers, enforcement rules, and known exceptions.

Walkthrough

This PR updates CI contracts and gating across reusable workflows, switches E2E scope detection to job logic, moves nightly alerting out of workflow runs, and raises one nightly stress threshold.

Changes

CI workflow contract and gating changes

Layer / File(s) Summary
CI contract documentation
.github/workflows/README.md
Updates the workflow README with CI tier definitions, merge-queue invariants, required check rules, nightly deep reuse notes, alerting, and accepted gaps.
Deep input and docker-risk detection
.github/workflows/platform-and-compat.yml
Adds the reusable workflow deep input, introduces has_docker_risk, and removes the engine replay risk classification from the non-diff and diff paths.
Deep job gating
.github/workflows/platform-and-compat.yml
Switches deep-only jobs to inputs.deep, rewrites windows-build matrix selection, and broadens docker-build gating for merge-group and reusable deep runs.
Platform compatibility roll-up
.github/workflows/platform-and-compat.yml
Adds the platform-compat aggregator job that runs if: always(), depends on multiple platform/compat jobs, and fails when any dependency result is not success or skipped.
Scope-based E2E gating
.github/workflows/reborn-e2e.yml
Removes PR path filtering, adds a merge-group trigger, computes has_e2e_scope in a changes job, gates the E2E jobs on that output, and short-circuits the roll-up when no scope is present.
Nightly reusable-call changes
.github/workflows/nightly-deep-ci.yml, .github/workflows/nightly-e2e.yml
Removes the in-workflow nightly E2E alert job, updates nightly deep reusable-call permissions and secrets: inherit, and documents that watchdog handles scheduled failure reporting.
Nightly watchdog evaluation
.github/workflows/nightly-watchdog.yml
Adds the watchdog workflow triggers, nightly matrix, run inspection logic, Slack alerting, and failure exit behavior for stale or failed scheduled runs.
Ironclaw stress threshold
.github/workflows/ironclaw-stress.yml
Updates the nightly libsql bottleneck suite comments and raises the max p95 limit from 1500 to 2500.

Estimated code review effort: 4 (Complex) | ~45 minutes

Possibly related PRs

  • nearai/ironclaw#4829: Changes the Reborn E2E flow that this PR now gates with scope detection and merge-queue handling.
  • nearai/ironclaw#5113: Adds the reusable platform-and-compat workflow that this PR now drives with deep and new gating.
  • nearai/ironclaw#5449: Introduces the Reborn Playwright workflow that the new nightly watchdog now monitors.
🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning #4108 is not really resolved: the PR removes Nightly E2E instead of preserving the scheduled check and auto-close path. Either keep Nightly E2E scheduled until it passes and closes #4108, or add explicit deprecation/closure handling that satisfies the issue.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title uses Conventional Commits style and accurately summarizes the CI revamp.
Description check ✅ Passed The description is detailed and covers summary, validation, and rollout context, with only some template sections left implicit.
Out of Scope Changes check ✅ Passed The changes stay within the stated CI revamp, watchdog, docs, and nightly-fleet cleanup scope.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the contributor: core 20+ merged PRs label Jul 8, 2026

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
❌ Changes requested 1 0 1 4779368199f7

Head: 4779368199f73e24c025263c34b5dbba8a1d8f21
Next: Fix the blocking findings, push the PR branch, then re-run this reviewer.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

Found one blocking CI gating issue in the new Platform & Compat merge-queue Docker path.

Findings

Blocking: 1 / Notes: 0

Blocking findings

1. ❌ [MEDIUM] Docker-risk merge groups still skip the Docker build

Location: .github/workflows/platform-and-compat.yml:347-351
The new merge_group Docker path is still guarded by needs.changes.outputs.has_legacy_tests == 'true'. scripts/ci/classify-test-scope.sh returns has_legacy_tests=false for Docker inputs such as Dockerfile.reborn and .dockerignore, while the new has_docker_risk regex returns true for them. As a result, a merge group that only changes Dockerfile.reborn or .dockerignore skips docker-build, and the roll-up accepts the skipped job, leaving the deterministic Docker failure to show up only after merge. Either classify all Docker-risk paths as test-relevant or exempt the Docker-risk merge_group arm from the legacy-tests guard.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.
  4. Use @ironloopai status to check queued/running/completed/stale/stalled state while reviewers run.

(github.event_name == 'push' || (github.event_name == 'workflow_call' && inputs.include_docker))
(github.event_name == 'push' ||
(inputs.deep == true && inputs.include_docker) ||
(github.event_name == 'merge_group' && needs.changes.outputs.has_docker_risk == 'true'))

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This merge_group Docker arm is still behind has_legacy_tests == 'true'. The classifier reports has_legacy_tests=false for Dockerfile.reborn and .dockerignore, even though the new has_docker_risk regex reports true, so those changes skip docker-build and the roll-up treats the skip as passing.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in 176fb97 — the merge_group arm no longer requires has_legacy_tests: it now gates on docs_only != 'true' && has_docker_risk == 'true' alone, so a Dockerfile.reborn/.dockerignore-only merge group builds the images. The push/deep arms keep the has_legacy_tests gate unchanged.

@github-actions

github-actions Bot commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 85.17% (282279 / 331449 lines)
  floor:    85.3% (tolerance 0.5pp -> effective floor 84.8%)
  denominator: 331449 lines now vs 320188 at floor capture (+11261 lines, +3.52%) — not a material change

⚠️ 3 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts, ironclaw_skill_learning

Reborn integration-tier coverage

Line coverage (Reborn crates): 85.17% — 282279 / 331449 lines

Per-crate breakdown (65 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 347
ironclaw_skill_learning 0% 0 / 61
ironclaw_wasm_sandbox_core 7.37% 7 / 95
ironclaw_runtime_policy 33.2% 80 / 241
ironclaw_event_projections 43.34% 673 / 1553
ironclaw_run_state 52.36% 222 / 424
ironclaw_authorization 53.54% 461 / 861
ironclaw_triggers 59.99% 1736 / 2894
ironclaw_observability 61.54% 16 / 26
ironclaw_webui_v2 63.12% 2543 / 4029
ironclaw_mcp 63.15% 581 / 920
ironclaw_reborn_cli 63.41% 3816 / 6018
ironclaw_reborn_migration 67.01% 1172 / 1749
ironclaw_memory 67.12% 747 / 1113
ironclaw_dispatcher 67.15% 92 / 137
ironclaw_filesystem 67.44% 3815 / 5657
ironclaw_trust 72.88% 661 / 907
ironclaw_capabilities 74.08% 1658 / 2238
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_reborn_event_store 74.61% 958 / 1284
ironclaw_extractors 74.72% 538 / 720
ironclaw_first_party_extensions 77.62% 5411 / 6971
ironclaw_llm 77.88% 19480 / 25013
ironclaw_product_context 78.57% 11 / 14
ironclaw_wasm_product_adapters 80.58% 1510 / 1874
ironclaw_process_sandbox 80.65% 671 / 832
ironclaw_reborn_openai_compat 80.95% 956 / 1181
ironclaw_memory_native 81.86% 3226 / 3941
ironclaw_wasm 82.54% 950 / 1151
ironclaw_secrets 82.7% 2791 / 3375
ironclaw_events 83.47% 1762 / 2111
ironclaw_processes 84.06% 965 / 1148
ironclaw_turns 84.24% 13099 / 15549
ironclaw_host_api 85.17% 2549 / 2993
ironclaw_product_workflow 85.74% 10626 / 12393
ironclaw_projects 85.92% 659 / 767
ironclaw_network 86.12% 670 / 778
ironclaw_common 86.59% 1472 / 1700
ironclaw_threads 86.62% 4132 / 4770
ironclaw_slack_v2_adapter 86.79% 1806 / 2081
ironclaw_auth 86.96% 2995 / 3444
ironclaw_reborn_config 86.98% 1730 / 1989
ironclaw_reborn_identity 87.03% 557 / 640
ironclaw_product_adapters 87.29% 3207 / 3674
ironclaw_skills 87.35% 4336 / 4964
ironclaw_hooks 87.84% 9916 / 11289
ironclaw_product_adapter_registry 87.96% 526 / 598
ironclaw_reborn_traces 88.23% 11707 / 13268
ironclaw_extensions 88.26% 2631 / 2981
ironclaw_reborn_composition 88.77% 69720 / 78541
ironclaw_host_runtime 88.94% 17522 / 19700
ironclaw_reborn 89.14% 15703 / 17616
ironclaw_conversations 90% 2924 / 3249
ironclaw_approvals 90.51% 1507 / 1665
ironclaw_event_streams 91.48% 1009 / 1103
ironclaw_loop_support 92.46% 14725 / 15926
ironclaw_resources 93.05% 4607 / 4951
ironclaw_attachments 93.06% 630 / 677
ironclaw_reborn_webui_ingress 93.19% 2217 / 2379
ironclaw_telegram_v2_adapter 94.01% 2447 / 2603
ironclaw_agent_loop 94.58% 8776 / 9279
ironclaw_safety 94.8% 3668 / 3869
ironclaw_first_party_extension_ports 95% 3094 / 3257
ironclaw_outbound 95.59% 3556 / 3720

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (4 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_oauth v1-only: consumed only by root ironclaw (src/auth/oauth.rs); no crates/* dependents. Crate's own doc comment confirms v1-only. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

A dispatched validation run of the previous commit still startup-failed:
secrets: inherit fixed one violation, but called-workflow jobs that
declare job-level permissions beyond the caller's grant also fail
validation at trigger time (even when those jobs are event-gated off
schedule runs). platform-and-compat's version-check declares
pull-requests/issues read; reborn-tests' coverage-report declares
pull-requests: write. Grant those supersets at the call sites.

Also corrects the incident window in the comments and README: retained
history shows zero successful Nightly Deep CI runs since its creation
on 2026-05-06 (65 of 74 runs are startup_failures), not merely since
2026-06-20 — the permissions violations date to day one, the secrets
one to the 2026-07-03 sccache rollout.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5841 July 8, 2026 15:40 Destroyed

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/nightly-watchdog.yml:
- Around line 73-83: The “Drive the nightly alert issue” step can be skipped
when the evaluate step fails, which breaks the watchdog’s dead-man’s switch
behavior. Add an always-run condition to this step in the nightly-watchdog
workflow, matching the existing pattern used by the nightly-alert job in
nightly-deep-ci.yml, so the alert issue is still created or refreshed even if
steps.evaluate exits non-zero.

In @.github/workflows/platform-and-compat.yml:
- Around line 14-26: The `has_engine_replay_risk` job condition is still using
`github.event_name == 'workflow_call'`, which fails inside this reusable
workflow because it sees the caller’s event instead of `workflow_call`. Update
the job’s condition to use `inputs.deep` consistently with the other jobs, or
make it unconditional if that is the intended behavior, and reference the
existing reusable-workflow gating pattern in
`.github/workflows/platform-and-compat.yml`.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 5995fdac-d1f9-4021-b4ae-80e20af0bf0b

📥 Commits

Reviewing files that changed from the base of the PR and between 1ae9310 and 4779368.

📒 Files selected for processing (5)
  • .github/workflows/README.md
  • .github/workflows/nightly-deep-ci.yml
  • .github/workflows/nightly-watchdog.yml
  • .github/workflows/platform-and-compat.yml
  • .github/workflows/reborn-e2e.yml

Comment thread .github/workflows/nightly-watchdog.yml Outdated
Comment thread .github/workflows/platform-and-compat.yml
…eshold

Reborn Playwright and IronClaw Stress were failing nightly with no
alerting at all — same silent-failure class the deep-CI revival fixed,
in two more places. Diagnosis of the standing failures:

- IronClaw Stress (red every retained scheduled run): the nightly
  bottleneck suite caps p95 at 1500ms, but its model-tail case injects
  a synthetic 2.0s model wait by design — the ceiling was structurally
  unsatisfiable (measured p95 2.05s = the 2.0s wait + ~50ms real work;
  every case at 0.00% failures). Raised to 2500ms with a comment; the
  PR-mode variant already ran at 3000ms. Per-case ceilings in
  ironclaw_stress are the proper follow-up.
- Reborn Playwright (flaky-red): last night's failure was
  test_reborn_legacy_looping_tool_calls_stop_at_low_iteration_boundary
  asserting failure_category == "driver_protocol_violation" while the
  runtime now emits "iteration_limit" — already realigned on main by
  the error-classification refactor (#5651); no change needed here.

Alerting changes:

- ironclaw-stress.yml + reborn-playwright.yml: schedule-only alert jobs
  driving .github/scripts/nightly-alert-issue.sh, same contract as the
  Nightly E2E / Nightly Deep CI alerts.
- nightly-watchdog.yml: generalized to a matrix over all four nightlies
  (Deep CI, E2E, Playwright, Stress) — startup failures and
  cron-never-fired now alarm for every nightly, not just Deep CI.
- nightly-alert-issue.sh: optional Slack mirror. When the
  SLACK_CI_ALERTS_WEBHOOK_URL repo secret is set (Slack incoming
  webhook), every failure posts a one-liner with run + issue links and
  every recovery posts a close-out; absent secret = silent no-op.
  Delivery is best-effort and never fails the alert job. All five call
  sites pass the secret through.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5841 July 8, 2026 16:04 Destroyed
Per review direction: failures post to Slack, nothing else, one code
path, no GitHub issues.

- nightly-watchdog.yml is now the only alerting mechanism: at 08:00 UTC
  it checks each nightly's latest scheduled run (Nightly Deep CI,
  Nightly E2E, Reborn Playwright, IronClaw Stress) and posts failures —
  workflow, conclusion, failed job names, run link — to the Slack
  channel behind the existing secrets.SLACK_WEBHOOK_URL (the same
  webhook live-canary reports through; no new secret needed). Missing
  runs, stale runs (>26h, cron never fired), and startup_failures alarm
  too — the cases an in-run alert job structurally cannot see. A
  detected failure turns the watchdog matrix job red so its run history
  doubles as the failure record. Successes post nothing.
- Removed the GitHub-issue alerting entirely: nightly-alert-issue.sh
  and its test harness are deleted, and the in-run nightly-alert jobs
  are removed from nightly-deep-ci.yml and nightly-e2e.yml along with
  the round-2 stress/playwright alert jobs.

Housekeeping after merge: close the open "Nightly E2E failed" issue
(#4108) manually — nothing auto-closes it now.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@railway-app

railway-app Bot commented Jul 8, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5841 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 8, 2026 at 4:58 pm

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5841 July 8, 2026 16:12 Destroyed
@github-actions github-actions Bot added size: XL 500+ changed lines and removed size: L 200-499 changed lines labels Jul 8, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/README.md (1)

107-110: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Drop the stale paths: reference.

reborn-e2e.yml now derives scope from its changes job and merge-group trigger; there are no PR paths: filters to keep in sync anymore. Leaving this bullet as-is will send future edits to the wrong contract.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/README.md around lines 107 - 110, Remove the outdated note
about keeping `reborn-e2e.yml`’s `paths:` filters in sync, since that workflow
now derives scope from its `changes` job and merge-group trigger only. Update
the guidance in the README section about scope classifiers to reference the
current contract in `reborn-e2e.yml` and the `changes` job, so future edits
point to the right workflow mechanism.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/README.md:
- Around line 107-110: Remove the outdated note about keeping `reborn-e2e.yml`’s
`paths:` filters in sync, since that workflow now derives scope from its
`changes` job and merge-group trigger only. Update the guidance in the README
section about scope classifiers to reference the current contract in
`reborn-e2e.yml` and the `changes` job, so future edits point to the right
workflow mechanism.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 517cdec9-e740-4e59-ab29-ddf9a33d9ddd

📥 Commits

Reviewing files that changed from the base of the PR and between 4779368 and ec493db.

📒 Files selected for processing (7)
  • .github/scripts/nightly-alert-issue.sh
  • .github/scripts/nightly-alert-issue.test.sh
  • .github/workflows/README.md
  • .github/workflows/ironclaw-stress.yml
  • .github/workflows/nightly-deep-ci.yml
  • .github/workflows/nightly-e2e.yml
  • .github/workflows/nightly-watchdog.yml
💤 Files with no reviewable changes (2)
  • .github/scripts/nightly-alert-issue.sh
  • .github/scripts/nightly-alert-issue.test.sh

- docker-build: the merge_group arm no longer requires has_legacy_tests.
  The scope classifier matches only the literal `Dockerfile`, so a
  Dockerfile.reborn/.dockerignore-only merge group reported
  has_legacy_tests=false and skipped the Docker build exactly when it
  should run (IronLoop blocking finding). push/deep arms keep the gate.
- changes: drop has_engine_replay_risk — no consumer in this workflow,
  and its workflow_call arm could never fire (github.event_name is the
  caller's event in reusable workflows).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5841 July 8, 2026 16:24 Destroyed
… nightly

Deliberate freeze pending v1 (src/) removal, per team decision: nightly
no longer calls the Legacy Tests workflow, leaving test.yml invoked
nowhere. Documented loudly in the workflow header and the CI README —
including the consequence that test.yml is the only place the root
`ironclaw` package's tests run, and that a v1 fix landing before src/
is deleted should temporarily restore the call job. This is an explicit
freeze with a paper trail, not the silent-death mode this workflow's
history is infamous for; delete test.yml together with src/.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5841 July 8, 2026 16:29 Destroyed

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/README.md (1)

111-114: 📐 Maintainability & Code Quality | 🟠 Major | ⚡ Quick win

Stale guidance: references reborn-e2e.yml paths: filters that this PR removes.

Line 114 instructs keeping reborn-e2e.yml's changes regex in sync with its paths: filters. However, this PR's scope-based E2E gating change removes PR path filtering from reborn-e2e.yml in favor of a has_e2e_scope changes job. The guidance should be updated to reflect the new scope-detection model rather than the removed paths: filters.

📝 Suggested update
 - **Scope classifiers** (`scripts/ci/classify-test-scope.sh` and per-workflow
   `changes` jobs) are curated allowlists. Adding a new crate or test directory
-  requires updating them, or the queue's scoped checks silently narrow. Keep
-  `reborn-e2e.yml`'s `changes` regex in sync with its `paths:` filters.
+  requires updating them, or the queue's scoped checks silently narrow. Keep
+  `reborn-e2e.yml`'s `changes` regex in sync with the scope it is intended to
+  detect (formerly `paths:` filters, now the `has_e2e_scope` job).
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/README.md around lines 111 - 114, Update the
scope-classifier guidance in the README to match the new E2E gating flow: remove
the outdated reference to keeping reborn-e2e.yml’s changes regex in sync with
its paths filters, and instead describe that the has_e2e_scope changes job is
now the source of truth for PR-based E2E scope detection. Keep the note about
scripts/ci/classify-test-scope.sh and other per-workflow changes jobs being
curated allowlists, but align the reborn-e2e.yml guidance with the new
scope-based model.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/README.md:
- Around line 111-114: Update the scope-classifier guidance in the README to
match the new E2E gating flow: remove the outdated reference to keeping
reborn-e2e.yml’s changes regex in sync with its paths filters, and instead
describe that the has_e2e_scope changes job is now the source of truth for
PR-based E2E scope detection. Keep the note about
scripts/ci/classify-test-scope.sh and other per-workflow changes jobs being
curated allowlists, but align the reborn-e2e.yml guidance with the new
scope-based model.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 16d6fbee-b2ba-4a44-a9da-a02de7155c50

📥 Commits

Reviewing files that changed from the base of the PR and between 176fb97 and 09e0a8f.

📒 Files selected for processing (2)
  • .github/workflows/README.md
  • .github/workflows/nightly-deep-ci.yml

Completes the legacy freeze: nightly-e2e.yml (the scheduler for
e2e.yml's full v1 browser suite) is deleted and Nightly E2E is dropped
from the watchdog matrix. Like Nightly Deep CI before its revival, it
had zero successful runs in retained history — its own alert issue
notes there is no prior green run on main to attribute against — and
its standing failures (v1 /api/chat auth-gate SSE dedup and approval
tests) are v1 work the team has frozen pending src/ removal.

e2e.yml itself stays (workflow_call/workflow_dispatch), frozen
alongside test.yml; both are documented in the CI README to be deleted
together with src/. The nightly fleet is now Nightly Deep CI, Reborn
Playwright, and IronClaw Stress — all three validated green today —
with the watchdog covering exactly those three.

After merge: manually close the open "Nightly E2E failed" issue #4108
(the freeze resolves it; nothing auto-closes it).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5841 July 8, 2026 16:34 Destroyed
…eeze

The Emulate-backed full-path tests are the only scheduled coverage for
install -> OAuth -> model-routed tool call -> provider mutation, and per
tests/e2e/CLAUDE.md they boot the legacy gateway binary, so they froze
with v1. Note in the CI README that a Reborn-native port through
`ironclaw-reborn serve` is the follow-up that restores this tier —
deliberately NOT re-homed into the Reborn nightlies as-is, which would
have smuggled the legacy binary back in.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5841 July 8, 2026 16:39 Destroyed

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/nightly-watchdog.yml (1)

39-91: 🩺 Stability & Availability | 🟡 Minor | ⚡ Quick win

Add a timeout to the Slack webhook POST. The empty gh run list case already falls through to missing; the remaining failure mode is curl hanging forever if Slack stalls.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/nightly-watchdog.yml around lines 39 - 91, Add a timeout
to the Slack webhook POST in the “Check latest scheduled run and post failures
to Slack” step so the workflow cannot hang indefinitely if Slack is slow or
unresponsive. Update the curl invocation that sends the JSON payload to use an
explicit timeout/retry-safe setting, and keep the existing fallback warning
behavior intact in the same run block where text and payload are built.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In @.github/workflows/README.md:
- Around line 106-113: Tighten the v1 freeze wording in the README section that
discusses the legacy suites and nightly scheduling: the current “invoked
nowhere” phrasing is too absolute given the documented manual/temporary restore
paths. Update the text around the legacy v1 suites, nightly-e2e, test.yml,
e2e.yml, and nightly-deep-ci.yml references so it says the suites are not
scheduled by nightly rather than unusable, while preserving the guidance about
temporary restoration and deletion alongside src/.

---

Outside diff comments:
In @.github/workflows/nightly-watchdog.yml:
- Around line 39-91: Add a timeout to the Slack webhook POST in the “Check
latest scheduled run and post failures to Slack” step so the workflow cannot
hang indefinitely if Slack is slow or unresponsive. Update the curl invocation
that sends the JSON payload to use an explicit timeout/retry-safe setting, and
keep the existing fallback warning behavior intact in the same run block where
text and payload are built.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 94ec6578-cce5-4426-bd39-f3c4b8844744

📥 Commits

Reviewing files that changed from the base of the PR and between 09e0a8f and a1262e2.

📒 Files selected for processing (3)
  • .github/workflows/README.md
  • .github/workflows/nightly-e2e.yml
  • .github/workflows/nightly-watchdog.yml
💤 Files with no reviewable changes (1)
  • .github/workflows/nightly-e2e.yml

Comment on lines +106 to +113
- **The legacy v1 suites are deliberately invoked nowhere** — v1 (`src/`) is
frozen pending removal. `test.yml` (the only place the root `ironclaw`
package's tests run) is no longer called by nightly, and the former
`nightly-e2e.yml` scheduler for the v1 browser suite (`e2e.yml` full mode)
is deleted — it had zero successful runs in retained history. Until `src/`
is deleted, a v1 bug fix that must land should temporarily restore the
`deterministic-deep-tests` call in `nightly-deep-ci.yml` (and/or dispatch
`e2e.yml` manually). Delete `test.yml` and `e2e.yml` together with `src/`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '\n== repo rule files ==\n'
git ls-files | rg '(^|/)(CLAUDE\.md|AGENTS\.md|\.claude/.*|\.github/workflows/README\.md)$' || true

printf '\n== relevant README excerpt ==\n'
nl -ba .github/workflows/README.md | sed -n '96,120p'

printf '\n== repo rules excerpt ==\n'
for f in CLAUDE.md AGENTS.md .claude/rules.md .claude/rules/*; do
  [ -f "$f" ] && { echo "--- $f"; nl -ba "$f" | sed -n '1,220p'; }
done

Repository: nearai/ironclaw

Length of output: 6378


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '\n== README lines 100-118 ==\n'
sed -n '100,118p' .github/workflows/README.md | cat -n

printf '\n== doc/review rules ==\n'
for f in .claude/rules/doc-hygiene.md .claude/rules/review-discipline.md .claude/rules/tool-evidence.md; do
  echo "--- $f"
  sed -n '1,220p' "$f" | cat -n
done

Repository: nearai/ironclaw

Length of output: 12969


Tighten the v1 freeze wording. .github/workflows/README.md:106-113

“Invoked nowhere” overstates the contract; the next sentence still leaves manual/temporary restore paths. Say “not scheduled by nightly” so the doc doesn’t read as if test.yml/e2e.yml are unusable. .claude/rules/review-discipline.md treats stale contract wording as a bug.

♻️ Suggested wording fix
-- **The legacy v1 suites are deliberately invoked nowhere** — v1 (`src/`)
-  is frozen pending removal.
+- **The legacy v1 suites are not scheduled by nightly** — v1 (`src/`)
+  is frozen pending removal.
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
- **The legacy v1 suites are deliberately invoked nowhere** — v1 (`src/`) is
frozen pending removal. `test.yml` (the only place the root `ironclaw`
package's tests run) is no longer called by nightly, and the former
`nightly-e2e.yml` scheduler for the v1 browser suite (`e2e.yml` full mode)
is deleted — it had zero successful runs in retained history. Until `src/`
is deleted, a v1 bug fix that must land should temporarily restore the
`deterministic-deep-tests` call in `nightly-deep-ci.yml` (and/or dispatch
`e2e.yml` manually). Delete `test.yml` and `e2e.yml` together with `src/`.
- **The legacy v1 suites are not scheduled by nightly** — v1 (`src/`) is
frozen pending removal. `test.yml` (the only place the root `ironclaw`
package's tests run) is no longer called by nightly, and the former
`nightly-e2e.yml` scheduler for the v1 browser suite (`e2e.yml` full mode)
is deleted — it had zero successful runs in retained history. Until `src/`
is deleted, a v1 bug fix that must land should temporarily restore the
`deterministic-deep-tests` call in `nightly-deep-ci.yml` (and/or dispatch
`e2e.yml` manually). Delete `test.yml` and `e2e.yml` together with `src/`.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/README.md around lines 106 - 113, Tighten the v1 freeze
wording in the README section that discusses the legacy suites and nightly
scheduling: the current “invoked nowhere” phrasing is too absolute given the
documented manual/temporary restore paths. Update the text around the legacy v1
suites, nightly-e2e, test.yml, e2e.yml, and nightly-deep-ci.yml references so it
says the suites are not scheduled by nightly rather than unusable, while
preserving the guidance about temporary restoration and deletion alongside src/.

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5841 — e485d8af Deployed Jul 8, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows scope: docs Documentation size: XL 500+ changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Nightly E2E failed

1 participant