Skip to content

feat(reborn)!: unified extension model — NEA-25 Train A roll-up (#5833-#5850) - #6061

Closed
BenKurrek wants to merge 31 commits into
mainfrom
nea25-rollup
Closed

BenKurrek wants to merge 31 commits into
mainfrom
nea25-rollup

Conversation

@BenKurrek

@BenKurrek BenKurrek commented Jul 13, 2026 •

Copy link
Copy Markdown
Collaborator

NEA-25: unified extension model — Train A roll-up

This is the single, self-contained Train A roll-up. It supersedes #5833 through
#5850 and is the only Train A prerequisite for the second PR train.

Exact audited head: 8410ea98a2fcf97eabff716ca05b785156a05435

Reconciled main: 07f1d65ac5528ca3a7a182c47ad99c28b5efd995

This readiness statement includes the current-main merge and its textual and
semantic conflict resolutions. It covers the PR's behavior, architecture,
migrations, security, tests, and suitability as Train B's foundation.

Train A contract

  • Extension is the only installable object. Tools, channels, and authentication
    are typed projections of its validated manifest.
  • Runtime is execution metadata, not a parallel extension taxonomy.
  • The product wire uses runtime plus typed surfaces; retired top-level
    kind is absent.
  • Slack has one unified extension/provider identity. Retired slack_bot,
    slack_user, and slack_personal survive only in bounded forward-migration,
    rejection, and test enclaves guarded by the taxonomy test.
  • Final outbound delivery remains host-owned. Train A does not create a second
    model-tool delivery path.
  • The explicit inbound/OAuth composition authority is limited to the exact
    host-bundled unified Slack package/provider combination.

Upgrade and concurrency guarantees

  • Persisted predecessor manifests are recognized narrowly, converted before
    strict parsing, fully validated, and committed with bounded CAS. New public
    input still rejects legacy top-level [[capabilities]].
  • Slack installation folding preserves ownership, member sets, activation,
    credential bindings, health, timestamps, installation identity, and manifest
    authority. Conflicts fail explicitly; feature-disabled or unauthoritative
    cleanup preserves the snapshot.
  • Retired personal-installation cleanup requires the exact historical
    host-bundled predecessor bytes and SHA-256, plus matching manifest reference,
    hash, and one of the two known historical cleanup shapes. Copied hashes,
    arbitrary host bundles, local/registry sources, malformed state, duplicate
    authority, and mismatched cleanup are rejected before mutation.
  • Every CAS-capable installation mutation applies to the latest winning
    snapshot and publishes in-memory state only after persistence wins. Fresh
    manifest plus installation is one atomic transition.
  • The explicitly opted-in non-CAS local-development path uses a bounded
    store-owned compatibility worker, so caller cancellation cannot interrupt a
    durable mutation. It is not a hosted multi-writer guarantee.
  • The slack_personal credential transition runs before composition publishes
    durable services, uses bounded versioned CAS, rejects new retired-provider
    writes at durable boundaries, and applies aggregate owner/scope/entry budgets.
  • OAuth callback completion, identity binding, and provider-token compensation
    are decision-owned cancellation-safe transactions.
  • Slack rollback reconciles active A / pending B races without reviving stale A
    or deleting authoritative B.

Deployment and rollback

The credential migration is a one-time stop-the-world cutover:

  1. stop all pre-Train-A writers;
  2. back up durable state;
  3. start the Train A binary and let startup migration finish before traffic;
  4. verify the unified Slack extension/provider state;
  5. resume traffic.

Do not overlap old and new writers. After the data transition, rollback means
restoring the pre-cutover backup or rolling forward; the old binary does not
understand the unified provider identity. CAS-capable state rewrites are
byte-stable after convergence. Legacy non-CAS local startup normalizes in
memory and can repeat the startup compatibility pass.

Explicit Train B exclusions

This PR does not add manifest v3, a resolved-manifest architecture, generic
tool/channel adapters, a generic extension host or loader registry, generic
ingress/delivery coordination, a recipe-driven auth engine, vendor extraction,
or multi-account product behavior. Those are not needed for Train A and are not
smuggled into this foundation.

Audit repairs included

  • canonical runtime/source vocabulary and serialize-only lifecycle responses;
  • exact predecessor provenance for installation cleanup;
  • strict, aggregate-bounded credential migration on libSQL and PostgreSQL;
  • cancellation-safe installation and OAuth transactions;
  • typed surface/direction/connection authority with no raw-TOML semantic reparse;
  • injective versioned provider keys with safe legacy lookup compatibility;
  • durable rejection of new retired-provider writes;
  • stale Slack rollback reconciliation;
  • current served API, browser, and live-QA fixtures;
  • removal of live legacy lifecycle shims and machine-enforced taxonomy scope;
  • updated operator cutover/rollback docs, feature parity, changelog, and skill guidance.

The exhaustive DO/DON'T/code-smell/positive-evidence checklist is committed in
docs/superpowers/specs/2026-07-13-train-a-rollup-hardening-design.md.

Verification on the audited worktree

  • cargo test -p ironclaw_filesystem --all-features — pass, including 9/9
    in-memory/libSQL/PostgreSQL CAS storm tests.
  • cargo test -p ironclaw_extensions --all-features — pass.
  • cargo test -p ironclaw_product_workflow --all-features — pass.
  • cargo test -p ironclaw_webui_v2 --all-features — pass.
  • cargo test -p ironclaw_reborn_composition --all-features — all
    executable tests pass after the merge, including 1,784/1,784 unit tests.
  • Real production PostgreSQL migration lane — 1/1 pass.
  • cargo test -p ironclaw_architecture — pass: 8 composition-boundary, 34
    dependency-boundary, and 4 retired-taxonomy tests.
  • cargo clippy --workspace --all-targets --all-features -- -D warnings — pass.
  • bash scripts/reborn-e2e-rust.sh — pass.
  • Frontend pnpm lint and pnpm test under Node 22 — pass: 737/737 tests in
    90 files; lint includes TypeScript typecheck.
  • uv run --project tests/e2e pytest -q tests/e2e/scenarios/test_reborn_webui_v2_extensions_api.py tests/e2e/scenarios/test_reborn_webui_v2_legacy_extensions.py — 42/42 pass,
    no skips (one harness import warning).
  • Live-QA harness — 179/179 pass with no skips. Python 3.14 emitted pre-existing
    SQLite ResourceWarnings at unchanged test-helper lines; no test failed.
  • QA fixture scrub — 13 files pass.
  • cargo fmt --all -- --check, git diff --check, and
    scripts/pre-commit-safety.sh — pass.
  • Fresh architecture/scope, security/concurrency, and tests/docs reviews — no
    unresolved actionable code finding after accepted fixes and reruns.
  • Official exact-head Tests (Reborn)
    pull-request workflow — pass, including all root, fixture, WebUI, integration
    coverage, and discovered crate-bucket jobs.
  • Official exact-head Reborn E2E
    pull-request workflow — pass, including served WebUI, gateway, substrate,
    architecture, and runtime jobs.

Live merge status

The current-main conflicts are resolved in merge commit
1bd5e82cf2a3c43567c1c0f945a74c4f575f76aa; the final exact head is
8410ea98a2fcf97eabff716ca05b785156a05435. GitHub reports the PR as
MERGEABLE. All exact-head statuses are terminal and non-failing: 59 passed
and 7 intentionally skipped. This includes the pull-request-native Reborn test,
Reborn E2E, code-style/clippy, platform/compatibility, stress, Railway preview,
scope, and regression workflows. There are zero unresolved review threads.

The only remaining merge gate is human review approval (REVIEW_REQUIRED);
GitHub therefore reports the aggregate merge state as BLOCKED despite the
branch being conflict-free and all checks passing.

Superseded source PRs

PR Charter
#5833 capability-surface vocabulary and projection
#5839 strict manifest-v2 host API cutover
#5842 extension-surface discovery
#5845 unified Slack extension identity
#5847 runtime plus surfaces wire
#5848 zero-legacy taxonomy gate
#5849 unified-model guidance
#5850 residual cleanup and tools-view unification

@coderabbitai

coderabbitai Bot commented Jul 13, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 241 files, which is 91 over the limit of 150.

To get a review, narrow the scope:
• coderabbit review --type committed # exclude uncommitted changes
• coderabbit review --dir # limit to a subdirectory
• coderabbit review --base # compare against a closer base

Upgrade to a paid plan to raise the limit.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 19ffec6e-47c9-48fe-9709-7c46953838c5

📥 Commits

Reviewing files that changed from the base of the PR and between 07f1d65 and 6d4cc5b.

⛔ Files ignored due to path filters (5)
  • CHANGELOG.md is excluded by !CHANGELOG.md
  • Cargo.lock is excluded by !**/*.lock, !**/Cargo.lock
  • tests/fixtures/llm_traces/reborn_qa/connect_gmail.json is excluded by !tests/fixtures/**
  • tests/fixtures/llm_traces/reborn_qa/routine_crm_inbox.json is excluded by !tests/fixtures/**
  • tests/fixtures/llm_traces/reborn_qa/routine_meeting_prep.json is excluded by !tests/fixtures/**
📒 Files selected for processing (241)
  • .claude/skills/reborn-extension-surfaces/SKILL.md
  • CLAUDE.md
  • Cargo.toml
  • FEATURE_PARITY.md
  • crates/ironclaw_architecture/tests/reborn_retired_taxonomy.rs
  • crates/ironclaw_auth/src/lib.rs
  • crates/ironclaw_auth/src/oauth.rs
  • crates/ironclaw_capabilities/tests/capability_host_run_state_contract.rs
  • crates/ironclaw_capabilities/tests/capability_host_spawn_contract.rs
  • crates/ironclaw_capabilities/tests/support/mod.rs
  • crates/ironclaw_dispatcher/tests/dispatch_contract.rs
  • crates/ironclaw_dispatcher/tests/event_dispatch_contract.rs
  • crates/ironclaw_dispatcher/tests/runtime_dispatcher_integration.rs
  • crates/ironclaw_dispatcher/tests/support/mod.rs
  • crates/ironclaw_dispatcher/tests/vertical_slice_contract.rs
  • crates/ironclaw_event_projections/tests/extension_lifecycle_projection_contract.rs
  • crates/ironclaw_extensions/src/host_api/capability_provider.rs
  • crates/ironclaw_extensions/src/hosted_mcp_discovery.rs
  • crates/ironclaw_extensions/src/installations.rs
  • crates/ironclaw_extensions/src/lib.rs
  • crates/ironclaw_extensions/src/lifecycle.rs
  • crates/ironclaw_extensions/src/registry.rs
  • crates/ironclaw_extensions/src/v2.rs
  • crates/ironclaw_extensions/tests/discovery_manifest_bound.rs
  • crates/ironclaw_extensions/tests/extension_contract.rs
  • crates/ironclaw_extensions/tests/installations_contract.rs
  • crates/ironclaw_extensions/tests/manifest_v2_contract.rs
  • crates/ironclaw_filesystem/src/cas.rs
  • crates/ironclaw_filesystem/src/cas/tests.rs
  • crates/ironclaw_filesystem/src/catalog.rs
  • crates/ironclaw_filesystem/src/lib.rs
  • crates/ironclaw_filesystem/src/libsql.rs
  • crates/ironclaw_filesystem/src/postgres.rs
  • crates/ironclaw_filesystem/tests/concurrent_cas_storm.rs
  • crates/ironclaw_filesystem/tests/db_root_filesystem_contract.rs
  • crates/ironclaw_first_party_extensions/assets/gmail/manifest.toml
  • crates/ironclaw_first_party_extensions/assets/google-calendar/manifest.toml
  • crates/ironclaw_first_party_extensions/assets/google-docs/manifest.toml
  • crates/ironclaw_first_party_extensions/assets/google-drive/manifest.toml
  • crates/ironclaw_first_party_extensions/assets/google-sheets/manifest.toml
  • crates/ironclaw_first_party_extensions/assets/google-slides/manifest.toml
  • crates/ironclaw_first_party_extensions/assets/nearai-mcp/manifest.toml
  • crates/ironclaw_first_party_extensions/assets/notion-mcp/manifest.toml
  • crates/ironclaw_first_party_extensions/assets/slack/manifest.toml
  • crates/ironclaw_first_party_extensions/assets/slack/prompts/slack/send_message.md
  • crates/ironclaw_first_party_extensions/assets/slack_bot/manifest.toml
  • crates/ironclaw_first_party_extensions/assets/web-access/manifest.toml
  • crates/ironclaw_host_api/src/lib.rs
  • crates/ironclaw_host_api/src/surface.rs
  • crates/ironclaw_host_runtime/Cargo.toml
  • crates/ironclaw_host_runtime/src/first_party_tools/mod.rs
  • crates/ironclaw_host_runtime/src/production.rs
  • crates/ironclaw_host_runtime/src/services/tests.rs
  • crates/ironclaw_host_runtime/src/services/tests/mcp_runtime_adapter.rs
  • crates/ironclaw_host_runtime/src/wasm_credentials.rs
  • crates/ironclaw_host_runtime/tests/builtin_obligation_handler_contract.rs
  • crates/ironclaw_host_runtime/tests/extension_v2_lifecycle_e2e.rs
  • crates/ironclaw_host_runtime/tests/first_party_runtime_contract.rs
  • crates/ironclaw_host_runtime/tests/github_wasm_runtime_contract.rs
  • crates/ironclaw_host_runtime/tests/host_api_contract_composition.rs
  • crates/ironclaw_host_runtime/tests/host_runtime_contract.rs
  • crates/ironclaw_host_runtime/tests/host_runtime_credential_preflight_contract.rs
  • crates/ironclaw_host_runtime/tests/host_runtime_persistent_approvals_contract.rs
  • crates/ironclaw_host_runtime/tests/obligation_services_composition_contract.rs
  • crates/ironclaw_host_runtime/tests/production_trust_contract.rs
  • crates/ironclaw_host_runtime/tests/reborn_durable_restart_integration.rs
  • crates/ironclaw_host_runtime/tests/reborn_e2e_gate.rs
  • crates/ironclaw_host_runtime/tests/reborn_invoke_vertical_slice.rs
  • crates/ironclaw_host_runtime/tests/support/host_runtime_harness.rs
  • crates/ironclaw_host_runtime/tests/support/mod.rs
  • crates/ironclaw_host_runtime/tests/tool_surface_contract.rs
  • crates/ironclaw_mcp/tests/mcp_adapter_contract.rs
  • crates/ironclaw_mcp/tests/mcp_dispatch_integration.rs
  • crates/ironclaw_product_adapter_registry/CLAUDE.md
  • crates/ironclaw_product_adapter_registry/src/lib.rs
  • crates/ironclaw_product_adapter_registry/tests/manifest_ingestion.rs
  • crates/ironclaw_product_adapter_registry/tests/registry_contract.rs
  • crates/ironclaw_product_adapters/src/workflow.rs
  • crates/ironclaw_product_adapters/tests/product_adapter_contract.rs
  • crates/ironclaw_product_adapters/tests/review_findings_contract.rs
  • crates/ironclaw_product_workflow/CLAUDE.md
  • crates/ironclaw_product_workflow/src/binding.rs
  • crates/ironclaw_product_workflow/src/lib.rs
  • crates/ironclaw_product_workflow/src/lifecycle.rs
  • crates/ironclaw_product_workflow/src/policy.rs
  • crates/ironclaw_product_workflow/src/reborn_services.rs
  • crates/ironclaw_product_workflow/src/reborn_services/extension_onboarding.rs
  • crates/ironclaw_product_workflow/src/reborn_services/extensions.rs
  • crates/ironclaw_product_workflow/src/reborn_services/types.rs
  • crates/ironclaw_product_workflow/src/webui_inbound.rs
  • crates/ironclaw_product_workflow/tests/lifecycle_extension_wire_contract.rs
  • crates/ironclaw_product_workflow/tests/product_command_workflow_contract.rs
  • crates/ironclaw_product_workflow/tests/product_workflow_contract.rs
  • crates/ironclaw_product_workflow/tests/reborn_services_contract.rs
  • crates/ironclaw_product_workflow/tests/webui_inbound_contract.rs
  • crates/ironclaw_reborn_cli/src/commands/serve.rs
  • crates/ironclaw_reborn_cli/src/commands/serve_slack.rs
  • crates/ironclaw_reborn_cli/src/runtime/mod.rs
  • crates/ironclaw_reborn_composition/CLAUDE.md
  • crates/ironclaw_reborn_composition/src/blocked_auth_resume.rs
  • crates/ironclaw_reborn_composition/src/error.rs
  • crates/ironclaw_reborn_composition/src/extension_host/available_extension_import.rs
  • crates/ironclaw_reborn_composition/src/extension_host/available_extensions.rs
  • crates/ironclaw_reborn_composition/src/extension_host/extension_activation_credentials.rs
  • crates/ironclaw_reborn_composition/src/extension_host/extension_installation_store.rs
  • crates/ironclaw_reborn_composition/src/extension_host/extension_installation_store/test_fixtures/pre_train_a_slack_manifest.toml
  • crates/ironclaw_reborn_composition/src/extension_host/extension_installation_store/tests.rs
  • crates/ironclaw_reborn_composition/src/extension_host/extension_lifecycle.rs
  • crates/ironclaw_reborn_composition/src/extension_host/extension_lifecycle_capabilities.rs
  • crates/ironclaw_reborn_composition/src/extension_host/extension_lifecycle_command.rs
  • crates/ironclaw_reborn_composition/src/extension_host/gsuite.rs
  • crates/ironclaw_reborn_composition/src/extension_host/lifecycle.rs
  • crates/ironclaw_reborn_composition/src/extension_host/mcp.rs
  • crates/ironclaw_reborn_composition/src/factory.rs
  • crates/ironclaw_reborn_composition/src/factory/auth_tests.rs
  • crates/ironclaw_reborn_composition/src/host_ingress.rs
  • crates/ironclaw_reborn_composition/src/lib.rs
  • crates/ironclaw_reborn_composition/src/lifecycle_auth_continuation.rs
  • crates/ironclaw_reborn_composition/src/observability/hooks/tests.rs
  • crates/ironclaw_reborn_composition/src/product_auth/api/auth.rs
  • crates/ironclaw_reborn_composition/src/product_auth/credentials/product_auth_providers.rs
  • crates/ironclaw_reborn_composition/src/product_auth/durable/accounts.rs
  • crates/ironclaw_reborn_composition/src/product_auth/durable/flows.rs
  • crates/ironclaw_reborn_composition/src/product_auth/durable/interactions.rs
  • crates/ironclaw_reborn_composition/src/product_auth/durable/mod.rs
  • crates/ironclaw_reborn_composition/src/product_auth/durable/tests.rs
  • crates/ironclaw_reborn_composition/src/product_auth/mod.rs
  • crates/ironclaw_reborn_composition/src/product_auth/oauth/oauth_gate.rs
  • crates/ironclaw_reborn_composition/src/product_auth/serve/mod.rs
  • crates/ironclaw_reborn_composition/src/product_auth/serve/oauth.rs
  • crates/ironclaw_reborn_composition/src/provider_identity.rs
  • crates/ironclaw_reborn_composition/src/root/communication_context.rs
  • crates/ironclaw_reborn_composition/src/runtime.rs
  • crates/ironclaw_reborn_composition/src/slack/mod.rs
  • crates/ironclaw_reborn_composition/src/slack/slack_actor_identity.rs
  • crates/ironclaw_reborn_composition/src/slack/slack_channel_connection.rs
  • crates/ironclaw_reborn_composition/src/slack/slack_connectable_channel.rs
  • crates/ironclaw_reborn_composition/src/slack/slack_delivery.rs
  • crates/ironclaw_reborn_composition/src/slack/slack_host_beta.rs
  • crates/ironclaw_reborn_composition/src/slack/slack_host_beta/runtime_setup.rs
  • crates/ironclaw_reborn_composition/src/slack/slack_host_state.rs
  • crates/ironclaw_reborn_composition/src/slack/slack_personal_binding.rs
  • crates/ironclaw_reborn_composition/src/slack/slack_personal_oauth.rs
  • crates/ironclaw_reborn_composition/src/slack/slack_serve.rs
  • crates/ironclaw_reborn_composition/src/slack/slack_serve/e2e_tests.rs
  • crates/ironclaw_reborn_composition/src/webui/facade.rs
  • crates/ironclaw_reborn_composition/tests/facade_factory.rs
  • crates/ironclaw_reborn_composition/tests/facade_factory/product_auth_migration.rs
  • crates/ironclaw_reborn_composition/tests/gsuite.rs
  • crates/ironclaw_reborn_composition/tests/provider_admin_product_command.rs
  • crates/ironclaw_reborn_composition/tests/webui_v2_product_auth.rs
  • crates/ironclaw_reborn_composition/tests/webui_v2_serve.rs
  • crates/ironclaw_reborn_migration/src/convert/extensions.rs
  • crates/ironclaw_reborn_migration/src/extension_ownership.rs
  • crates/ironclaw_runner/tests/loop_driver_host.rs
  • crates/ironclaw_scripts/tests/script_dispatch_integration.rs
  • crates/ironclaw_scripts/tests/script_runner_contract.rs
  • crates/ironclaw_wasm/tests/wasm_dispatch_integration.rs
  • crates/ironclaw_wasm_product_adapters/src/runner.rs
  • crates/ironclaw_wasm_product_adapters/src/runner_immediate_ack.rs
  • crates/ironclaw_webui_v2/CLAUDE.md
  • crates/ironclaw_webui_v2/frontend/src/components/slack-channel-picker.test.tsx
  • crates/ironclaw_webui_v2/frontend/src/components/slack-channel-picker.tsx
  • crates/ironclaw_webui_v2/frontend/src/components/slack-setup-panel.test.ts
  • crates/ironclaw_webui_v2/frontend/src/components/slack-setup-panel.tsx
  • crates/ironclaw_webui_v2/frontend/src/i18n/ar.ts
  • crates/ironclaw_webui_v2/frontend/src/i18n/de.ts
  • crates/ironclaw_webui_v2/frontend/src/i18n/en.ts
  • crates/ironclaw_webui_v2/frontend/src/i18n/es.ts
  • crates/ironclaw_webui_v2/frontend/src/i18n/fr.ts
  • crates/ironclaw_webui_v2/frontend/src/i18n/hi.ts
  • crates/ironclaw_webui_v2/frontend/src/i18n/ja.ts
  • crates/ironclaw_webui_v2/frontend/src/i18n/ko.ts
  • crates/ironclaw_webui_v2/frontend/src/i18n/pt-BR.ts
  • crates/ironclaw_webui_v2/frontend/src/i18n/uk.ts
  • crates/ironclaw_webui_v2/frontend/src/i18n/zh-CN.ts
  • crates/ironclaw_webui_v2/frontend/src/lib/api.ts
  • crates/ironclaw_webui_v2/frontend/src/lib/channel-connect.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/chat/components/auth-oauth-card.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/chat/components/auth-oauth-card.tsx
  • crates/ironclaw_webui_v2/frontend/src/pages/chat/hooks/useChannelOnboarding.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/chat/hooks/useChat.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/chat/lib/runtime-context.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/chat/lib/useChat-send.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/components/channels-tab.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/components/channels-tab.tsx
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/components/configure-modal.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/components/configure-modal.tsx
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/components/extension-card.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/components/extension-card.tsx
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/components/registry-tab.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/components/tools-tab.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/components/tools-tab.tsx
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/extensions-page.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/extensions-page.tsx
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/hooks/useExtensions-catalog.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/hooks/useExtensions-oauth.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/hooks/useExtensions-pairing.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/hooks/useExtensions.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/lib/extension-actions.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/lib/extension-actions.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/lib/extensions-api.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/lib/extensions-schema.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/extensions/lib/extensions-schema.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/settings/components/channels-tab.tsx
  • crates/ironclaw_webui_v2/frontend/src/pages/settings/hooks/useChannels.test.ts
  • crates/ironclaw_webui_v2/frontend/src/pages/settings/hooks/useChannels.ts
  • crates/ironclaw_webui_v2/src/descriptors.rs
  • crates/ironclaw_webui_v2/src/handlers.rs
  • crates/ironclaw_webui_v2/src/lib.rs
  • crates/ironclaw_webui_v2/src/router.rs
  • crates/ironclaw_webui_v2/src/static_assets/assets.rs
  • crates/ironclaw_webui_v2/tests/webui_v2_descriptors_contract.rs
  • crates/ironclaw_webui_v2/tests/webui_v2_handlers_contract.rs
  • crates/ironclaw_webui_v2/tests/webui_v2_operator_route_predicate_contract.rs
  • docs/plans/2026-06-30-slack-personal-oauth.md
  • docs/plans/composition-pubuse.snapshot
  • docs/reborn/contracts/extensions.md
  • docs/reborn/deploy-reborn-cli-docker.md
  • docs/reborn/setup-slack-for-reborn-binary.md
  • docs/superpowers/plans/2026-07-13-train-a-rollup-hardening.md
  • docs/superpowers/specs/2026-07-13-train-a-rollup-hardening-design.md
  • scripts/reborn-e2e-rust.sh
  • scripts/reborn_webui_v2_live_qa/run_live_qa.py
  • scripts/reborn_webui_v2_live_qa/slack_helpers.py
  • scripts/reborn_webui_v2_live_qa/test_run_live_qa.py
  • tests/e2e/scenarios/test_reborn_webui_v2_automation_trace_outbound_api.py
  • tests/e2e/scenarios/test_reborn_webui_v2_extensions_api.py
  • tests/e2e/scenarios/test_reborn_webui_v2_legacy_approval.py
  • tests/e2e/scenarios/test_reborn_webui_v2_legacy_auth_flows.py
  • tests/e2e/scenarios/test_reborn_webui_v2_legacy_extensions.py
  • tests/e2e/scenarios/test_reborn_webui_v2_legacy_settings_search.py
  • tests/integration/support/builder.rs
  • tests/integration/support/extension_surface.rs
  • tests/integration/support/github.rs
  • tests/integration/support/harness/profiles/extension.rs
  • tests/integration/support/harness_mcp.rs
  • tests/integration/support/harness_web_access.rs
  • tests/integration/tool_call.rs
  • tests/support/reborn_parity_qa/binary_e2e.rs
  • tests/support_unit_tests.rs

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6061 July 13, 2026 22:03 Destroyed
@github-actions github-actions Bot added scope: docs Documentation size: XL 500+ changed lines risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Jul 13, 2026
@BenKurrek

Copy link
Copy Markdown
Collaborator Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Jul 13, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@BenKurrek
BenKurrek marked this pull request as ready for review July 13, 2026 22:04
@BenKurrek

Copy link
Copy Markdown
Collaborator Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Jul 13, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request implements the NEA-25 unified extension model, consolidating Slack bot and user-token identities into a single 'slack' extension. It introduces a robust capability-surface taxonomy, replacing legacy 'kind' strings with surface-based declarations (tool, channel, auth). Key changes include the migration of persisted Slack credential accounts, the introduction of a generic provider-identity actor resolver, and the removal of legacy connectable-channel registry logic in favor of extension-surface discovery. I have filtered out comments that were purely explanatory or non-actionable, while retaining those pointing to security risks, logic errors in migration, and test flakiness.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread crates/ironclaw_reborn_composition/src/provider_identity.rs Outdated
…#5850)

Atomic roll-up of the 8-PR NEA-25 taxonomy stack onto current main. Extension is
the only installable product object; tool/channel/auth are derived capability
surfaces; runtime kind controls loading only; manifest projection (v2, host_api
contracts) is the sole surface-discovery source of truth. The connectable-channels
rail and the parallel `kind` taxonomy are removed and pinned by a zero-legacy gate.
slack_bot and slack_personal are retired into one `slack` extension with bounded
forward migrations. Extensions wire carries runtime + surfaces, not a conflated kind.

Supersedes #5833, #5839, #5842, #5845, #5847, #5848, #5849, #5850. Conflicts with
main since the train forked were reconciled preserving main's newer behavior
(#5851 unified slack cleanup, #6054 get_conversation_info DM resolution, #5499
extension import, #6057 TS source conventions). provider_identity domain
duplication removed; the residual is a legitimate up-layer port adapter. See the PR
description for the per-PR crosswalk, resolutions, placement audit, and verification.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@railway-app

railway-app Bot commented Jul 13, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-6061 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 14, 2026 at 3:12 pm

…ed taxonomy

Main advanced 25f8c12->bc80e54ca after the roll-up was based; #5957 (harden
OAuth + per-user extension lifecycles, 81 files, old taxonomy) + #5971 landed.
Rebased the roll-up onto the new main and folded #5957 forward: unified its
channel_connection_facade_slot -> the train's channel_connection_facade (so
#5957's SlackPersonalConnectionCleanupAdapter and the train injector share one
facade field — fixes 40 removal/restore tests), applied the train's L03/L04
renames to #5957's parallel code (from_toml_with_contracts->from_toml,
slack_actor_identity->provider_identity, LifecycleExtensionSurfaceKind->
CapabilitySurfaceKind, SLACK_PERSONAL_PROVIDER_ID->SLACK_PROVIDER_ID), integrated
#5957's cleanup_requirements onto the train structs, re-added the train's
activate_for_channel_setup, and converted the extension-ownership migration
fixture to manifest v2. #5957's removal-cleanup hardening and the train's
taxonomy retirement are both preserved.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6061 July 13, 2026 23:23 Destroyed
@BenKurrek

Copy link
Copy Markdown
Collaborator Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Jul 13, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

- extension_ownership migration fixture: fmt + manifest v2 sections.
- host_runtime extension_v2_lifecycle_e2e: the unified manifest v2 validates a
  capability's required_host_ports at base parse, so an unknown port fails closed
  with the specific UnknownHostPort (not the older section-level
  HostApiSectionRejected) — update the inherited assertion.
- wiring_parity harness-profile subset: the unified Slack manifest declares
  ironclaw.product_adapter/v1 (channel) alongside capability_provider (tools), so
  the test-support bundled-manifest registry must register the product-adapter
  contract too (adds ironclaw_product_adapter_registry dev-dep), matching the
  production composition registry.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6061 July 14, 2026 00:06 Destroyed
@github-actions github-actions Bot added scope: dependencies Dependency updates risk: medium Business logic, config, or moderate-risk modules and removed risk: low Changes to docs, tests, or low-risk modules labels Jul 14, 2026
… tests

github_wasm_runtime_contract.rs's registry_with_slack_user_package parses the
unified Slack manifest (which now declares ironclaw.product_adapter/v1 alongside
capability_provider) with default_host_api_contract_registry(), which lacks the
product-adapter contract -> ManifestV2(UnknownHostApi). Register it (adds the
product_adapter_registry dev-dep to host_runtime), matching production. Same fix
class as the wiring-parity test-support registry.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6061 July 14, 2026 00:28 Destroyed
Same class as extension_v2_lifecycle_e2e: the unified manifest v2 validates a
capability's required_host_ports at base parse, so an unknown port on the
telegram fixture fails closed with the specific UnknownHostPort, not the older
section-level HostApiSectionRejected. Update the inherited assertion.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6061 July 14, 2026 00:47 Destroyed
@github-actions

github-actions Bot commented Jul 14, 2026 •

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 85.69% (305430 / 356429 lines)
  floor:    85.3% (tolerance 0.5pp -> effective floor 84.8%)
  denominator: 356429 lines now vs 320188 at floor capture (+36241 lines, +11.32%) — material change (>5%)

⚠️ 2 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts

Reborn integration-tier coverage

Line coverage (Reborn crates): 85.69% — 305430 / 356429 lines

Per-crate breakdown (63 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 345
ironclaw_runtime_policy 31.75% 80 / 252
ironclaw_event_projections 43.31% 673 / 1554
ironclaw_run_state 53.07% 225 / 424
ironclaw_authorization 53.89% 464 / 861
ironclaw_triggers 59.89% 1792 / 2992
ironclaw_observability 61.54% 16 / 26
ironclaw_mcp 63.03% 578 / 917
ironclaw_webui_v2 63.11% 2671 / 4232
ironclaw_reborn_cli 66.17% 4471 / 6757
ironclaw_dispatcher 67.15% 92 / 137
ironclaw_filesystem 67.67% 4036 / 5964
ironclaw_memory 69.2% 773 / 1117
ironclaw_reborn_migration 71.59% 1552 / 2168
ironclaw_trust 72.88% 661 / 907
ironclaw_capabilities 74.39% 1685 / 2265
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_reborn_event_store 74.67% 958 / 1283
ironclaw_extractors 74.72% 538 / 720
ironclaw_llm 78.36% 20328 / 25941
ironclaw_product_context 78.57% 11 / 14
ironclaw_first_party_extensions 78.81% 5576 / 7075
ironclaw_process_sandbox 80.65% 671 / 832
ironclaw_memory_native 81.22% 3205 / 3946
ironclaw_wasm_product_adapters 81.95% 1448 / 1767
ironclaw_secrets 82.7% 2791 / 3375
ironclaw_events 82.86% 1765 / 2130
ironclaw_reborn_identity 83.59% 433 / 518
ironclaw_wasm 83.97% 1011 / 1204
ironclaw_auth 83.99% 3147 / 3747
ironclaw_reborn_config 84.06% 1814 / 2158
ironclaw_processes 84.44% 993 / 1176
ironclaw_common 84.85% 1490 / 1756
ironclaw_turns 84.99% 13669 / 16084
ironclaw_host_api 85.29% 2685 / 3148
ironclaw_product_workflow 85.63% 10882 / 12708
ironclaw_projects 85.92% 659 / 767
ironclaw_network 86.12% 670 / 778
ironclaw_product_adapter_registry 86.35% 544 / 630
ironclaw_threads 86.7% 4594 / 5299
ironclaw_slack_v2_adapter 86.79% 1806 / 2081
ironclaw_product_adapters 87.18% 3263 / 3743
ironclaw_skills 87.6% 4471 / 5104
ironclaw_hooks 87.78% 9921 / 11302
ironclaw_reborn_traces 88.19% 11946 / 13546
ironclaw_host_runtime 88.61% 17431 / 19671
ironclaw_extensions 89.28% 2933 / 3285
ironclaw_approvals 89.41% 1587 / 1775
ironclaw_runner 89.41% 16916 / 18919
ironclaw_reborn_openai_compat 89.55% 3798 / 4241
ironclaw_reborn_composition 89.65% 82918 / 92495
ironclaw_conversations 90.33% 3121 / 3455
ironclaw_event_streams 90.82% 1009 / 1111
ironclaw_loop_host 92.52% 14811 / 16008
ironclaw_resources 92.82% 4719 / 5084
ironclaw_attachments 93.06% 630 / 677
ironclaw_reborn_webui_ingress 93.19% 2217 / 2379
ironclaw_telegram_v2_adapter 93.62% 2511 / 2682
ironclaw_agent_loop 94.83% 9148 / 9647
ironclaw_safety 95.04% 3677 / 3869
ironclaw_first_party_extension_ports 95.24% 3343 / 3510
ironclaw_outbound 95.59% 3556 / 3720

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (3 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

@BenKurrek

Copy link
Copy Markdown
Collaborator Author

Status: CI green, reconciled onto current main

This roll-up carries the complete intended final state of the 8-PR NEA-25 stack (#5833, #5839, #5842, #5845, #5847, #5848, #5849, #5850) as one atomic PR on current main. All CI checks pass (Code Style, Tests (Reborn), Clippy all-features, Reborn E2E, Formatting).

Reconciliation notes for review:

CodeRabbit note: CodeRabbit skips this PR (207 files > its 150 limit). The train's content was already reviewed via the 8 source PRs (each <150 files, still open); only the ~5-commit reconciliation/CI-fix delta here is new.

The 8 source PRs are preserved (not closed) as the evidence trail; their head SHAs are in the description. Not for merge by automation — @BenKurrek to review + merge.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6061 July 14, 2026 09:35 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6061 July 14, 2026 12:41 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6061 July 14, 2026 12:48 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6061 July 14, 2026 14:08 Destroyed
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6061 July 14, 2026 14:56 Destroyed
@BenKurrek BenKurrek closed this Jul 20, 2026

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-6061 — 6d4cc5b4 Deployed Jul 14, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: dependencies Dependency updates scope: docs Documentation size: XL 500+ changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant