Skip to content

fix: hide trigger creation internals - #5909

Closed
ironloopai[bot] wants to merge 4 commits into
mainfrom
ironloop/issue-5707-513e2590-7c1
Closed

ironloopai[bot] wants to merge 4 commits into
mainfrom
ironloop/issue-5707-513e2590-7c1

Conversation

@ironloopai

@ironloopai ironloopai Bot commented Jul 10, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Add a trigger_create-specific display preview that shows a user-friendly routine title, name, schedule type, timezone, and next run time.
  • Prevent raw trigger IDs, agent/project IDs, cron expressions, prompts, command references, and created_at metadata from appearing in the displayed confirmation preview.
  • Add a regression test for the routine creation preview path.

Validation

  • git diff --check
  • git diff --check HEAD~1 HEAD
  • Not run: cargo fmt --check and targeted cargo test because cargo is not installed in this runtime.

Closes #5707.

Opened by IronLoop after verifying the local implementation branch.

@ironloopai

ironloopai Bot commented Jul 10, 2026 •

Copy link
Copy Markdown
Contributor Author

🔎 IronLoop Review Status

Head: a6f2563f15e3fe25a80a7ebd43f626475160e415
Result: 1/1 reviewers completed without blocking findings.
Next: Ready for normal human review and CI checks.
Updated: 2026-07-11T15:23:14.535Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Completed Approved 0 blocking findings / 0 notes 2026-07-11T15:23:14.526Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Approved; 0 blocking findings; No concrete blocking issues found. The change scopes trigger_create display-preview formatting to redacted routine-focused fields and adds focused regression coverage for canonica…
Recent activity
Time Reviewer State Detail
2026-07-11T15:18:35.808Z ironloop/common-reviewer (reviewer) Queued Accepted review request for head a6f2563.
2026-07-11T15:18:35.808Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-11T15:18:35.888Z ironloop/common-reviewer (reviewer) Started Reviewer worker started.
2026-07-11T15:18:44.606Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (merge_ref) at 94f8381.
2026-07-11T15:23:14.526Z ironloop/common-reviewer (reviewer) Result captured Approved; 0 blocking findings.
2026-07-11T15:23:14.526Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent>
  • @ironloopai status
Run metadata

Admission: webhook accepted the request and IronLoop persisted reviewer state before this projection.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5909 July 10, 2026 04:49 Destroyed
@github-actions github-actions Bot added size: M 50-199 changed lines risk: low Changes to docs, tests, or low-risk modules contributor: regular 2-5 merged PRs labels Jul 10, 2026

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
❌ Changes requested 1 0 1 e91b8db6236e

Head: e91b8db6236e36003ad317176d8e92d100b51ea2
Next: Fix the blocking findings, push the PR branch, then re-run this reviewer.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

Found one trigger-create preview redaction gap that should be fixed before merge.

Findings

Blocking: 1 / Notes: 0

Blocking findings

1. ❌ [MEDIUM] Trigger-create input can still fall back to raw JSON preview

Location: crates/ironclaw_reborn_composition/src/projection/display_preview.rs:591-594
The new trigger_create redaction only applies when trigger_create_input_summary returns Some. If the model sends an invalid but expected malformed shape, such as the parser-style {"operation":"parse","data":{...}} wrapper that the trigger schema explicitly rejects, there is no top-level name or schedule, so this branch falls through to the generic JSON summary. That generic fallback will expose nested routine configuration such as prompt or cron expression in the display preview/failure card, undermining the new guarantee that trigger creation hides internal configuration. For matched trigger_create capability IDs, return a safe generic routine summary instead of falling through when the specialized summary is empty, and add a regression test for a malformed/wrapped trigger_create input.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.
  4. Use @ironloopai status to check queued/running/completed/failed/superseded state while reviewers run.

Comment thread crates/ironclaw_reborn_composition/src/projection/display_preview.rs Outdated
@railway-app

railway-app Bot commented Jul 10, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-5909 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 11, 2026 at 3:06 pm

@ironloopai

ironloopai Bot commented Jul 10, 2026 •

Copy link
Copy Markdown
Contributor Author

🔧 IronLoop Resolve Status

Issue: #5909
Current step: No resolve changes were needed.
Next: No code change is needed unless new feedback or CI failures appear.
Updated: 2026-07-11T14:37:53.054Z

Current resolve:

Developer State Branch Result Last update
ironloop/small-fix-resolver (resolver) No changes ironloop/issue-5707-513e2590-7c1 developer workspace has no new commits to publish 2026-07-11T14:37:50.190Z
Recent activity

Each row is one developer job. Phase details below belong to that job.

Developer Current state Branch Last update Latest phase
ironloop/small-fix-resolver (resolver) No changes ironloop/issue-5707-513e2590-7c1 2026-07-11T14:37:50.190Z Threads resolved: All captured review threads were marked resolved.

Phase log:

ironloop/small-fix-resolver (resolver)

Time Phase Detail
2026-07-11T14:34:59.234Z Accepted Accepted resolve request.
2026-07-11T14:34:59.234Z Queued Developer job entered the queue.
2026-07-11T14:34:59.367Z Running Worker claimed the developer job.
2026-07-11T14:35:42.306Z Running Prepared resolve workspace.
2026-07-11T14:37:50.190Z No changes developer workspace has no new commits to publish
2026-07-11T14:37:53.048Z Threads resolved All captured review threads were marked resolved.
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai implement
  • @ironloopai implement --agent <agent>
  • @ironloopai resolve
  • @ironloopai resolve --agent <agent>
Run metadata

Admission: webhook accepted the request and IronLoop persisted developer state before this projection.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5909 July 10, 2026 05:50 Destroyed
@hanakannzashi

Copy link
Copy Markdown
Contributor

@ironloopai resolve

Address all unresolved review feedback and fix the current failing CI checks.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5909 July 11, 2026 14:33 Destroyed
@hanakannzashi

Copy link
Copy Markdown
Contributor

@ironloopai resolve

Address all unresolved review feedback and fix the current failing CI checks after the base update.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-5909 July 11, 2026 14:58 Destroyed
@github-actions

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 85.27% (292934 / 343552 lines)
  floor:    85.3% (tolerance 0.5pp -> effective floor 84.8%)
  denominator: 343552 lines now vs 320188 at floor capture (+23364 lines, +7.3%) — material change (>5%)

⚠️ 2 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts

Reborn integration-tier coverage

Line coverage (Reborn crates): 85.27% — 292934 / 343552 lines

Per-crate breakdown (63 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 345
ironclaw_runtime_policy 31.75% 80 / 252
ironclaw_event_projections 43.31% 673 / 1554
ironclaw_run_state 52.36% 222 / 424
ironclaw_authorization 53.66% 462 / 861
ironclaw_triggers 59.89% 1792 / 2992
ironclaw_observability 61.54% 16 / 26
ironclaw_webui_v2 62.76% 2659 / 4237
ironclaw_reborn_cli 62.88% 3851 / 6124
ironclaw_mcp 63.03% 578 / 917
ironclaw_reborn_migration 67.09% 1215 / 1811
ironclaw_filesystem 67.1% 3833 / 5712
ironclaw_dispatcher 67.15% 92 / 137
ironclaw_memory 69.2% 773 / 1117
ironclaw_trust 72.88% 661 / 907
ironclaw_capabilities 74.39% 1685 / 2265
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_reborn_event_store 74.67% 958 / 1283
ironclaw_extractors 74.72% 538 / 720
ironclaw_first_party_extensions 77.66% 5400 / 6953
ironclaw_llm 78.32% 20260 / 25869
ironclaw_product_context 78.57% 11 / 14
ironclaw_process_sandbox 80.65% 671 / 832
ironclaw_wasm_product_adapters 80.71% 1448 / 1794
ironclaw_reborn_openai_compat 81.16% 978 / 1205
ironclaw_memory_native 81.22% 3205 / 3946
ironclaw_secrets 82.7% 2791 / 3375
ironclaw_wasm 82.72% 996 / 1204
ironclaw_events 82.86% 1765 / 2130
ironclaw_auth 83.87% 3078 / 3670
ironclaw_reborn_config 84.33% 1814 / 2151
ironclaw_processes 84.44% 993 / 1176
ironclaw_turns 84.66% 13447 / 15884
ironclaw_common 84.85% 1490 / 1756
ironclaw_host_api 85.17% 2664 / 3128
ironclaw_product_workflow 85.56% 10836 / 12665
ironclaw_projects 85.92% 659 / 767
ironclaw_threads 86.04% 4234 / 4921
ironclaw_network 86.12% 670 / 778
ironclaw_slack_v2_adapter 86.79% 1806 / 2081
ironclaw_product_adapters 86.98% 3207 / 3687
ironclaw_reborn_identity 87.03% 557 / 640
ironclaw_skills 87.6% 4471 / 5104
ironclaw_hooks 87.75% 9917 / 11302
ironclaw_product_adapter_registry 88.06% 531 / 603
ironclaw_reborn_traces 88.19% 11946 / 13546
ironclaw_host_runtime 88.41% 17188 / 19442
ironclaw_extensions 89.03% 2864 / 3217
ironclaw_reborn_composition 89.05% 76308 / 85688
ironclaw_approvals 89.24% 1584 / 1775
ironclaw_runner 89.29% 16694 / 18697
ironclaw_conversations 90.33% 3120 / 3454
ironclaw_event_streams 90.82% 1009 / 1111
ironclaw_loop_support 92.51% 14752 / 15947
ironclaw_resources 92.83% 4736 / 5102
ironclaw_attachments 93.06% 630 / 677
ironclaw_reborn_webui_ingress 93.19% 2217 / 2379
ironclaw_telegram_v2_adapter 93.62% 2511 / 2682
ironclaw_agent_loop 94.66% 8771 / 9266
ironclaw_safety 94.88% 3671 / 3869
ironclaw_first_party_extension_ports 95.24% 3343 / 3510
ironclaw_outbound 95.59% 3556 / 3720

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (3 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

@hanakannzashi

Copy link
Copy Markdown
Contributor

@ironloopai review

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
✅ Approved 0 0 0 a6f2563f15e3

Head: a6f2563f15e3fe25a80a7ebd43f626475160e415
Next: No reviewer action needed.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

No concrete blocking issues found. The change scopes trigger_create display-preview formatting to redacted routine-focused fields and adds focused regression coverage for canonical and wrapped inputs.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.
  4. Use @ironloopai status to check queued/running/completed/failed/superseded state while reviewers run.

@italic-jinxin

Copy link
Copy Markdown
Contributor
image

It still seems like there are problems.

@italic-jinxin italic-jinxin added human-verified Manually tested and verified contributor: core 20+ merged PRs contributor: regular 2-5 merged PRs and removed contributor: regular 2-5 merged PRs contributor: core 20+ merged PRs human-verified Manually tested and verified labels Jul 13, 2026
@italic-jinxin

Copy link
Copy Markdown
Contributor

PR #5909 did not fully resolve the issue because it addressed only the trigger_create activity preview. It did not cover other routine operations such as list, pause, resume, and remove, nor did it prevent the assistant’s final response from exposing internal details. As a result, trigger IDs, raw cron expressions, stored prompts, capability names, and host metadata could still appear through other user-facing paths.

open pr #6038 to resolve it.

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-5909 — a6f2563f Deployed Jul 11, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: regular 2-5 merged PRs risk: low Changes to docs, tests, or low-risk modules size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Routine creation response exposes internal implementation details

3 participants