Repository navigation
test(reborn): freeze the LocalDev* type-name ratchet (§4.4/§10) - #6205
Conversation
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
🔎 IronLoop Review StatusHead: Current reviewers:
Reviewer summaries
Recent activity
Available commands
Run metadataAdmission: webhook accepted the request and IronLoop persisted reviewer state before this projection. |
📝 WalkthroughSummary by CodeRabbit
WalkthroughAdds shared Rust scanner utilities for exported type definitions, migrates the InMemoryStore ratchet to them, and introduces a LocalDev type allowlist ratchet with duplicate and cfg-gating tests. ChangesAnti-slippage ratchet scanning
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant RatchetTest
participant collect_type_defs
participant scan_type_defs
participant duplicate_definitions
RatchetTest->>collect_type_defs: scan crates for matching exported types
collect_type_defs->>scan_type_defs: parse Rust source
scan_type_defs-->>collect_type_defs: identifiers and cfg_gated flags
collect_type_defs-->>RatchetTest: occurrence map
RatchetTest->>duplicate_definitions: validate multiplicity
duplicate_definitions-->>RatchetTest: duplicate definitions
Possibly related PRs
🚥 Pre-merge checks | ✅ 3 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (3 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
❌ IronLoop Review: reviewer
Review at a glance
| Verdict | Blocking | Notes | Inline | Head |
|---|---|---|---|---|
| ❌ Changes requested | 1 | 0 | 1 | 7a2d4e513642 |
Head: 7a2d4e513642817c457726e35e954fc9228ef504
Next: Fix the blocking findings, push the PR branch, then re-run this reviewer.
Run details
Status: Current
Needs human: no
Needs validation: no
Summary
The focused stack-layer review found one blocking correctness issue: the new architecture ratchet does not reliably distinguish Rust type definitions from non-code text and misses valid trait syntax.
Findings
Blocking: 1 / Notes: 0
Blocking findings
1. ❌ [MEDIUM] The line scanner does not enforce an exact Rust type inventory
Location: crates/ironclaw_architecture/tests/reborn_localdev_typename_ratchet.rs:157-186
This scans isolated lines without tracking comments or string literals. A line beginning pub struct LocalDevFoo inside a block comment or multiline/raw string is therefore counted as a definition; it can cause false CI failures or keep an allowlisted name present after the real type is deleted. Conversely, the declared trait coverage misses valid definitions such as pub unsafe trait LocalDevFoo. Because exact set membership is the sole behavior introduced here, use Rust-aware lexing/parsing and extend the self-test with block-comment, raw-string, and qualified-trait cases.
Developer follow-up
After fixing this feedback:
- Push the fix to this PR branch.
- Re-run this reviewer with
@ironloopai review --agent reviewerif you only changed this reviewer's findings. - Re-run all reviewers with
@ironloopai reviewwhen the fix may affect multiple areas.
| /// Line-based scan: pull the identifier from any `pub`/`pub(crate)` | ||
| /// `struct`/`enum`/`trait`/`type` definition whose name starts with `LocalDev`. | ||
| fn scan_source_for_localdev_type_defs(source: &str, out: &mut BTreeSet<String>) { | ||
| for line in source.lines() { |
There was a problem hiding this comment.
This line-oriented scan is not an exact type-definition scanner: it counts pub struct LocalDevFoo inside block comments or multiline/raw strings, while missing valid declarations such as pub unsafe trait LocalDevFoo. That can either create false CI failures or let non-code text keep an allowlisted name alive after the real type is deleted. Please use Rust-aware lexing/parsing and add self-test cases for those contexts.
There was a problem hiding this comment.
Addressed in ee85b4c by consolidating both §10 ratchets onto one hardened scanner (tests/ratchet_support/mod.rs) instead of duplicating a weaker copy: comments and plain/raw string literals are stripped by a minimal lexer before matching (so definition-shaped text in them neither adds a false positive nor keeps an allowlisted name alive), pub unsafe trait / pub(crate) unsafe trait / auto trait declarations are matched, and the scan is occurrence-preserving with a multiplicity check. That last part surfaced a real subtlety your comment predicted: composition's factory.rs defines the same LocalDev* alias twice under mutually exclusive #[cfg] gates (incl. rustfmt-split multi-line gates) — the duplicate check now exempts a name only when every occurrence is cfg-gated, and a mixed gated/ungated pair still fails. Self-tests cover comment/string fixtures, unsafe-trait forms, same-file duplicates, and both cfg-pair shapes.
d0a8e97 to
92dbd8b
Compare
7a2d4e5 to
a6061d9
Compare
…4 Bucket 2) The §4.4 Bucket-2 trust-boundary rename: `Host` states the boundary this port crosses (an OS process run directly on the host, unsandboxed, no tenant mount containment — the §6 shell cross-tenant escape surface) where `Local` obscured it (`docs/reborn/2026-05-11-trust-boundary-stack-note.md`). Pure identifier rename, behavior-preserving; the sibling `pub(crate)` helpers `LocalHostProcessEnvMode`/`LocalHostWorkdirAlias` are renamed to `Host*` for consistency, and the struct doc now states the boundary explicitly. No `Local*` type name here is the deployment-mode `LocalDev*` family (that is the #6205 ratchet); this advances the broader §4.4 name audit. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
🚅 Deployed to the ironclaw-pr-6205 environment in ironclaw-ci-preview
|
92dbd8b to
5d950f6
Compare
a6061d9 to
cb64b5b
Compare
…4 Bucket 2) The §4.4 Bucket-2 trust-boundary rename: `Host` states the boundary this port crosses (an OS process run directly on the host, unsandboxed, no tenant mount containment — the §6 shell cross-tenant escape surface) where `Local` obscured it (`docs/reborn/2026-05-11-trust-boundary-stack-note.md`). Pure identifier rename, behavior-preserving; the sibling `pub(crate)` helpers `LocalHostProcessEnvMode`/`LocalHostWorkdirAlias` are renamed to `Host*` for consistency, and the struct doc now states the boundary explicitly. No `Local*` type name here is the deployment-mode `LocalDev*` family (that is the #6205 ratchet); this advances the broader §4.4 name audit. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…* (§4.4 Bucket 3)
The §4.4 Bucket-3 name-audit rename: these types are this-**node**'s submission
records to Trace Commons, not a deployment mode — `Node` says that where `Local`
was a false friend for the `Local*` deployment-mode audit. Renames the four types
(`LocalTraceSubmission{Record,Status,HistoryEvent,HistoryKind}` ->
`NodeTraceSubmission*`) across `ironclaw_reborn_traces` and its v1 consumers
(`src/agent`, `src/channels/web`) via the `crate::trace_contribution` re-export.
Pure identifier rename, behavior-preserving and **wire-safe**: the struct/enum
names never appear in serialized output (serde emits field names and the
`rename_all = "snake_case"` variant strings `submitted`/`revoked`/… — unchanged),
and no persisted record-kind/string tag used the type name. Removes four
false-friend `Local*` names so the eventual §4.4 `Local*` type-name ban (the
#6205 ratchet's endgame) doesn't have to permanently allowlist them.
`ironclaw_reborn_traces` tests green (215); clippy `-D warnings` + `cargo fmt`
clean. large_file arch-exempts added for the three >1,500-line files the rename's
lines touch (contribution.rs 17K, plus two v1 files) — no logic change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
5d950f6 to
661b020
Compare
cb64b5b to
7aa2029
Compare
…4 Bucket 2) The §4.4 Bucket-2 trust-boundary rename: `Host` states the boundary this port crosses (an OS process run directly on the host, unsandboxed, no tenant mount containment — the §6 shell cross-tenant escape surface) where `Local` obscured it (`docs/reborn/2026-05-11-trust-boundary-stack-note.md`). Pure identifier rename, behavior-preserving; the sibling `pub(crate)` helpers `LocalHostProcessEnvMode`/`LocalHostWorkdirAlias` are renamed to `Host*` for consistency, and the struct doc now states the boundary explicitly. No `Local*` type name here is the deployment-mode `LocalDev*` family (that is the #6205 ratchet); this advances the broader §4.4 name audit. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…* (§4.4 Bucket 3)
The §4.4 Bucket-3 name-audit rename: these types are this-**node**'s submission
records to Trace Commons, not a deployment mode — `Node` says that where `Local`
was a false friend for the `Local*` deployment-mode audit. Renames the four types
(`LocalTraceSubmission{Record,Status,HistoryEvent,HistoryKind}` ->
`NodeTraceSubmission*`) across `ironclaw_reborn_traces` and its v1 consumers
(`src/agent`, `src/channels/web`) via the `crate::trace_contribution` re-export.
Pure identifier rename, behavior-preserving and **wire-safe**: the struct/enum
names never appear in serialized output (serde emits field names and the
`rename_all = "snake_case"` variant strings `submitted`/`revoked`/… — unchanged),
and no persisted record-kind/string tag used the type name. Removes four
false-friend `Local*` names so the eventual §4.4 `Local*` type-name ban (the
#6205 ratchet's endgame) doesn't have to permanently allowlist them.
`ironclaw_reborn_traces` tests green (215); clippy `-D warnings` + `cargo fmt`
clean. large_file arch-exempts added for the three >1,500-line files the rename's
lines touch (contribution.rs 17K, plus two v1 files) — no logic change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
47bc5b4 to
661b020
Compare
7aa2029 to
3fec1bd
Compare
…4 Bucket 2) The §4.4 Bucket-2 trust-boundary rename: `Host` states the boundary this port crosses (an OS process run directly on the host, unsandboxed, no tenant mount containment — the §6 shell cross-tenant escape surface) where `Local` obscured it (`docs/reborn/2026-05-11-trust-boundary-stack-note.md`). Pure identifier rename, behavior-preserving; the sibling `pub(crate)` helpers `LocalHostProcessEnvMode`/`LocalHostWorkdirAlias` are renamed to `Host*` for consistency, and the struct doc now states the boundary explicitly. No `Local*` type name here is the deployment-mode `LocalDev*` family (that is the #6205 ratchet); this advances the broader §4.4 name audit. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…* (§4.4 Bucket 3)
The §4.4 Bucket-3 name-audit rename: these types are this-**node**'s submission
records to Trace Commons, not a deployment mode — `Node` says that where `Local`
was a false friend for the `Local*` deployment-mode audit. Renames the four types
(`LocalTraceSubmission{Record,Status,HistoryEvent,HistoryKind}` ->
`NodeTraceSubmission*`) across `ironclaw_reborn_traces` and its v1 consumers
(`src/agent`, `src/channels/web`) via the `crate::trace_contribution` re-export.
Pure identifier rename, behavior-preserving and **wire-safe**: the struct/enum
names never appear in serialized output (serde emits field names and the
`rename_all = "snake_case"` variant strings `submitted`/`revoked`/… — unchanged),
and no persisted record-kind/string tag used the type name. Removes four
false-friend `Local*` names so the eventual §4.4 `Local*` type-name ban (the
#6205 ratchet's endgame) doesn't have to permanently allowlist them.
`ironclaw_reborn_traces` tests green (215); clippy `-D warnings` + `cargo fmt`
clean. large_file arch-exempts added for the three >1,500-line files the rename's
lines touch (contribution.rs 17K, plus two v1 files) — no logic change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…* (§4.4 Bucket 3)
The §4.4 Bucket-3 name-audit rename: these types are this-**node**'s submission
records to Trace Commons, not a deployment mode — `Node` says that where `Local`
was a false friend for the `Local*` deployment-mode audit. Renames the four types
(`LocalTraceSubmission{Record,Status,HistoryEvent,HistoryKind}` ->
`NodeTraceSubmission*`) across `ironclaw_reborn_traces` and its v1 consumers
(`src/agent`, `src/channels/web`) via the `crate::trace_contribution` re-export.
Pure identifier rename, behavior-preserving and **wire-safe**: the struct/enum
names never appear in serialized output (serde emits field names and the
`rename_all = "snake_case"` variant strings `submitted`/`revoked`/… — unchanged),
and no persisted record-kind/string tag used the type name. Removes four
false-friend `Local*` names so the eventual §4.4 `Local*` type-name ban (the
#6205 ratchet's endgame) doesn't have to permanently allowlist them.
`ironclaw_reborn_traces` tests green (215); clippy `-D warnings` + `cargo fmt`
clean. large_file arch-exempts added for the three >1,500-line files the rename's
lines touch (contribution.rs 17K, plus two v1 files) — no logic change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…for LocalDev ratchet Addresses the IronLoop finding on #6205 (line-oriented scan matches comment/string text and misses `pub unsafe trait`) by consolidating both §10 ratchets onto one hardened scanner instead of duplicating a weaker copy: - New `tests/ratchet_support/mod.rs`: comment/string-stripping lexer, `pub`/`pub(crate)`/`pub(super)`/`pub(in ...)` visibility, `unsafe`/`auto` modifiers, occurrence-preserving scans, production-scoped walk (skips tests/, examples/, benches/), and a multiplicity check. - `reborn_inmemory_store_ratchet.rs` refactored onto the shared module (behavior identical; self-tests preserved). - `reborn_localdev_typename_ratchet.rs` gains everything above plus cfg-aware multiplicity: the composition factory defines durable/ no-durable alias pairs for the same `LocalDev*` name under mutually exclusive `#[cfg(...)]` gates (including rustfmt-split multi-line gates) — those are exempt from the duplicate check only when every occurrence is cfg-gated; a mixed pair still fails. Regression tests cover the cfg pair (single- and multi-line), the mixed pair, same-file duplicates, and marker-bearing comment/string fixtures. Also rebased onto #6204's current head. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
✅ Ready for mergeReviewed, all findings addressed, CI fully green (18 pass / 0 fail) on head What was done:
🤖 Generated with Claude Code |
…4 Bucket 2) The §4.4 Bucket-2 trust-boundary rename: `Host` states the boundary this port crosses (an OS process run directly on the host, unsandboxed, no tenant mount containment — the §6 shell cross-tenant escape surface) where `Local` obscured it (`docs/reborn/2026-05-11-trust-boundary-stack-note.md`). Pure identifier rename, behavior-preserving; the sibling `pub(crate)` helpers `LocalHostProcessEnvMode`/`LocalHostWorkdirAlias` are renamed to `Host*` for consistency, and the struct doc now states the boundary explicitly. No `Local*` type name here is the deployment-mode `LocalDev*` family (that is the #6205 ratchet); this advances the broader §4.4 name audit. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…simplification) Adds the deployment-mode-as-type ratchet §4.4/§10 of docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md calls for on the `Local*` axis, ahead of Slice B (collapsing the `LocalDev*` shadow runtime to a `DeploymentConfig` value). `crates/ironclaw_architecture/tests/reborn_localdev_typename_ratchet.rs` scans `crates/` for `pub`/`pub(crate)` `LocalDev*` type definitions (struct/enum/trait/ type alias) and asserts the set exactly equals a checked-in frozen allowlist (the current 31): - a NEW `LocalDev*` type fails — a deployment mode must resolve to policy data at the composition edge, never grow another type; - deleting one without trimming the allowlist also fails — so the list shrinks in lock-step as Slice B lands (§10: compare set membership, never a count). Definition of done for this axis: the allowlist reaches empty — local-dev is one `DeploymentConfig` constant, no `LocalDev*` type remains. Scoped to `LocalDev*` specifically (clean empty-set goal); the broader §4.4 name audit — Bucket 2 renames (`LocalFilesystem`->`DiskFilesystem`, `LocalHostProcessPort`->`HostProcessPort`) and Bucket 3 false positives (`Locale`, `HostedMcp*`, `LocalTraceSubmission*`) — is a separate concern. Ships with its own scanner self-test (per "guardrails are code"). The scanner is exhaustive: it surfaced 9 `LocalDev*` types a line-oriented grep had missed (synthetic-capability + extension-surface + auth-read-model families). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…for LocalDev ratchet Addresses the IronLoop finding on #6205 (line-oriented scan matches comment/string text and misses `pub unsafe trait`) by consolidating both §10 ratchets onto one hardened scanner instead of duplicating a weaker copy: - New `tests/ratchet_support/mod.rs`: comment/string-stripping lexer, `pub`/`pub(crate)`/`pub(super)`/`pub(in ...)` visibility, `unsafe`/`auto` modifiers, occurrence-preserving scans, production-scoped walk (skips tests/, examples/, benches/), and a multiplicity check. - `reborn_inmemory_store_ratchet.rs` refactored onto the shared module (behavior identical; self-tests preserved). - `reborn_localdev_typename_ratchet.rs` gains everything above plus cfg-aware multiplicity: the composition factory defines durable/ no-durable alias pairs for the same `LocalDev*` name under mutually exclusive `#[cfg(...)]` gates (including rustfmt-split multi-line gates) — those are exempt from the duplicate check only when every occurrence is cfg-gated; a mixed pair still fails. Regression tests cover the cfg pair (single- and multi-line), the mixed pair, same-file duplicates, and marker-bearing comment/string fixtures. Also rebased onto #6204's current head. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
ee85b4c to
1269253
Compare
…4 Bucket 2) The §4.4 Bucket-2 trust-boundary rename: `Host` states the boundary this port crosses (an OS process run directly on the host, unsandboxed, no tenant mount containment — the §6 shell cross-tenant escape surface) where `Local` obscured it (`docs/reborn/2026-05-11-trust-boundary-stack-note.md`). Pure identifier rename, behavior-preserving; the sibling `pub(crate)` helpers `LocalHostProcessEnvMode`/`LocalHostWorkdirAlias` are renamed to `Host*` for consistency, and the struct doc now states the boundary explicitly. No `Local*` type name here is the deployment-mode `LocalDev*` family (that is the #6205 ratchet); this advances the broader §4.4 name audit. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@crates/ironclaw_architecture/tests/ratchet_support/mod.rs`:
- Around line 16-19: Update the duplicate-detection logic around the
matched-definition cfg handling to prove that cfg predicates are mutually
exclusive before suppressing a duplicate; do not treat mere presence of #[cfg]
as sufficient, and account for definitions in separate modules. Preserve valid
mutually exclusive alias pairs, while keeping identical or overlapping
predicates—including the LocalDev fixture’s disabled-feature combination—as
duplicates. Add regression cases covering identical and overlapping gates, and
revise the documentation near the matched-definition model to describe the
behavior actually enforced.
In `@crates/ironclaw_architecture/tests/reborn_localdev_typename_ratchet.rs`:
- Line 48: Update the KEYWORDS constant in the LocalDev typename scanner to
include "union " so named Rust unions are inventoried alongside structs, enums,
traits, and type aliases. Add a regression fixture covering a pub union
LocalDev* declaration and assert it is detected, preserving the documented
§4.4/§10 freeze guarantees.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: b03b519a-4e07-45aa-9269-4876aaf853b4
📒 Files selected for processing (3)
crates/ironclaw_architecture/tests/ratchet_support/mod.rscrates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rscrates/ironclaw_architecture/tests/reborn_localdev_typename_ratchet.rs
| /// One matched definition: where it was found and whether the definition line | ||
| /// sits under a `#[cfg(...)]` attribute (mutually exclusive compile branches — | ||
| /// e.g. the durable/no-durable alias pairs in composition's `factory.rs` — are | ||
| /// legitimate same-name definitions, not duplicate debt). |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟠 Major | 🏗️ Heavy lift
Prove cfg exclusivity before suppressing duplicates.
Line 45 equates “every occurrence has a #[cfg]” with “mutually exclusive.” Identical or overlapping gates—and unrelated gates in separate modules—are therefore hidden from both ratchets.
The current LocalDev fixture at Lines 230-236 also overlaps when inmemory-turn-state, libsql, and postgres are disabled. Preserve predicates and prove disjointness, or narrowly exempt explicitly reviewed alias pairs. Add identical/overlapping-gate regression cases that remain duplicates.
As per coding guidelines, “Comments and documentation that promise guarantees must match the behavior implemented in code and covered by tests.”
Also applies to: 34-46
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@crates/ironclaw_architecture/tests/ratchet_support/mod.rs` around lines 16 -
19, Update the duplicate-detection logic around the matched-definition cfg
handling to prove that cfg predicates are mutually exclusive before suppressing
a duplicate; do not treat mere presence of #[cfg] as sufficient, and account for
definitions in separate modules. Preserve valid mutually exclusive alias pairs,
while keeping identical or overlapping predicates—including the LocalDev
fixture’s disabled-feature combination—as duplicates. Add regression cases
covering identical and overlapping gates, and revise the documentation near the
matched-definition model to describe the behavior actually enforced.
Source: Coding guidelines
| TypeDefOccurrence, collect_type_defs, duplicate_definitions, scan_type_defs, workspace_root, | ||
| }; | ||
|
|
||
| const KEYWORDS: &[&str] = &["struct ", "enum ", "trait ", "type "]; |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Include Rust unions in the LocalDev* inventory.
pub union LocalDevState { ... } defines a named type but bypasses this scanner, violating the §4.4/§10 freeze. Add "union " and a scanner regression fixture.
Proposed fix
-const KEYWORDS: &[&str] = &["struct ", "enum ", "trait ", "type "];
+const KEYWORDS: &[&str] = &["struct ", "enum ", "trait ", "type ", "union "];As per coding guidelines, every bug fix requires regression coverage and documented guarantees must match behavior.
Also applies to: 140-182
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@crates/ironclaw_architecture/tests/reborn_localdev_typename_ratchet.rs` at
line 48, Update the KEYWORDS constant in the LocalDev typename scanner to
include "union " so named Rust unions are inventoried alongside structs, enums,
traits, and type aliases. Add a regression fixture covering a pub union
LocalDev* declaration and assert it is detected, preserving the documented
§4.4/§10 freeze guarantees.
Source: Coding guidelines
…* (§4.4 Bucket 3)
The §4.4 Bucket-3 name-audit rename: these types are this-**node**'s submission
records to Trace Commons, not a deployment mode — `Node` says that where `Local`
was a false friend for the `Local*` deployment-mode audit. Renames the four types
(`LocalTraceSubmission{Record,Status,HistoryEvent,HistoryKind}` ->
`NodeTraceSubmission*`) across `ironclaw_reborn_traces` and its v1 consumers
(`src/agent`, `src/channels/web`) via the `crate::trace_contribution` re-export.
Pure identifier rename, behavior-preserving and **wire-safe**: the struct/enum
names never appear in serialized output (serde emits field names and the
`rename_all = "snake_case"` variant strings `submitted`/`revoked`/… — unchanged),
and no persisted record-kind/string tag used the type name. Removes four
false-friend `Local*` names so the eventual §4.4 `Local*` type-name ban (the
#6205 ratchet's endgame) doesn't have to permanently allowlist them.
`ironclaw_reborn_traces` tests green (215); clippy `-D warnings` + `cargo fmt`
clean. large_file arch-exempts added for the three >1,500-line files the rename's
lines touch (contribution.rs 17K, plus two v1 files) — no logic change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Coverage ratchetReborn integration-tier coverageLine coverage (Reborn crates): 85.94% — 304812 / 354688 lines Per-crate breakdown (62 crates, lowest-covered first)
This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors. Exemptions (3 entry/entries excluded from the accounting above)
|
|
Post-rebase confirmation: after #6204's squash-merge, this branch was rebased onto |
…4 Bucket 2) The §4.4 Bucket-2 trust-boundary rename: `Host` states the boundary this port crosses (an OS process run directly on the host, unsandboxed, no tenant mount containment — the §6 shell cross-tenant escape surface) where `Local` obscured it (`docs/reborn/2026-05-11-trust-boundary-stack-note.md`). Pure identifier rename, behavior-preserving; the sibling `pub(crate)` helpers `LocalHostProcessEnvMode`/`LocalHostWorkdirAlias` are renamed to `Host*` for consistency, and the struct doc now states the boundary explicitly. No `Local*` type name here is the deployment-mode `LocalDev*` family (that is the #6205 ratchet); this advances the broader §4.4 name audit. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…* (§4.4 Bucket 3)
The §4.4 Bucket-3 name-audit rename: these types are this-**node**'s submission
records to Trace Commons, not a deployment mode — `Node` says that where `Local`
was a false friend for the `Local*` deployment-mode audit. Renames the four types
(`LocalTraceSubmission{Record,Status,HistoryEvent,HistoryKind}` ->
`NodeTraceSubmission*`) across `ironclaw_reborn_traces` and its v1 consumers
(`src/agent`, `src/channels/web`) via the `crate::trace_contribution` re-export.
Pure identifier rename, behavior-preserving and **wire-safe**: the struct/enum
names never appear in serialized output (serde emits field names and the
`rename_all = "snake_case"` variant strings `submitted`/`revoked`/… — unchanged),
and no persisted record-kind/string tag used the type name. Removes four
false-friend `Local*` names so the eventual §4.4 `Local*` type-name ban (the
#6205 ratchet's endgame) doesn't have to permanently allowlist them.
`ironclaw_reborn_traces` tests green (215); clippy `-D warnings` + `cargo fmt`
clean. large_file arch-exempts added for the three >1,500-line files the rename's
lines touch (contribution.rs 17K, plus two v1 files) — no logic change.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…4 Bucket 2) (#6206) * refactor(reborn): rename LocalHostProcessPort -> HostProcessPort (§4.4 Bucket 2) The §4.4 Bucket-2 trust-boundary rename: `Host` states the boundary this port crosses (an OS process run directly on the host, unsandboxed, no tenant mount containment — the §6 shell cross-tenant escape surface) where `Local` obscured it (`docs/reborn/2026-05-11-trust-boundary-stack-note.md`). Pure identifier rename, behavior-preserving; the sibling `pub(crate)` helpers `LocalHostProcessEnvMode`/`LocalHostWorkdirAlias` are renamed to `Host*` for consistency, and the struct doc now states the boundary explicitly. No `Local*` type name here is the deployment-mode `LocalDev*` family (that is the #6205 ratchet); this advances the broader §4.4 name audit. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * docs(reborn): repoint guidance at HostProcessPort after the rename Addresses the IronLoop finding on #6206: the source rename left live agent/safety guidance naming the old type. Updates the three guidance files — .claude/rules/safety-and-sandbox.md (prose + the re-verify rg audit command, keeping `ProcessBackendKind::LocalHost` which is not renamed), crates/ironclaw_host_runtime/AGENTS.md, and tests/integration/CLAUDE.md (`.with_live_shell()` docs). The security semantics are unchanged: the unsandboxed port remains single-user-local only, with the rename noted inline so greps for the old name still land on the rule. Historical plan/spec docs (arch-simplification note, dated superpowers spec) deliberately keep the old name — they narrate the pre-rename state and the rename mapping itself. [skip-regression-check] documentation-only follow-up to the rename. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…* (§4.4 Bucket 3) (#6207) * refactor(reborn): rename LocalHostProcessPort -> HostProcessPort (§4.4 Bucket 2) The §4.4 Bucket-2 trust-boundary rename: `Host` states the boundary this port crosses (an OS process run directly on the host, unsandboxed, no tenant mount containment — the §6 shell cross-tenant escape surface) where `Local` obscured it (`docs/reborn/2026-05-11-trust-boundary-stack-note.md`). Pure identifier rename, behavior-preserving; the sibling `pub(crate)` helpers `LocalHostProcessEnvMode`/`LocalHostWorkdirAlias` are renamed to `Host*` for consistency, and the struct doc now states the boundary explicitly. No `Local*` type name here is the deployment-mode `LocalDev*` family (that is the #6205 ratchet); this advances the broader §4.4 name audit. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * docs(reborn): repoint guidance at HostProcessPort after the rename Addresses the IronLoop finding on #6206: the source rename left live agent/safety guidance naming the old type. Updates the three guidance files — .claude/rules/safety-and-sandbox.md (prose + the re-verify rg audit command, keeping `ProcessBackendKind::LocalHost` which is not renamed), crates/ironclaw_host_runtime/AGENTS.md, and tests/integration/CLAUDE.md (`.with_live_shell()` docs). The security semantics are unchanged: the unsandboxed port remains single-user-local only, with the rename noted inline so greps for the old name still land on the rule. Historical plan/spec docs (arch-simplification note, dated superpowers spec) deliberately keep the old name — they narrate the pre-rename state and the rename mapping itself. [skip-regression-check] documentation-only follow-up to the rename. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * refactor(reborn): rename LocalTraceSubmission* -> NodeTraceSubmission* (§4.4 Bucket 3) The §4.4 Bucket-3 name-audit rename: these types are this-**node**'s submission records to Trace Commons, not a deployment mode — `Node` says that where `Local` was a false friend for the `Local*` deployment-mode audit. Renames the four types (`LocalTraceSubmission{Record,Status,HistoryEvent,HistoryKind}` -> `NodeTraceSubmission*`) across `ironclaw_reborn_traces` and its v1 consumers (`src/agent`, `src/channels/web`) via the `crate::trace_contribution` re-export. Pure identifier rename, behavior-preserving and **wire-safe**: the struct/enum names never appear in serialized output (serde emits field names and the `rename_all = "snake_case"` variant strings `submitted`/`revoked`/… — unchanged), and no persisted record-kind/string tag used the type name. Removes four false-friend `Local*` names so the eventual §4.4 `Local*` type-name ban (the #6205 ratchet's endgame) doesn't have to permanently allowlist them. `ironclaw_reborn_traces` tests green (215); clippy `-D warnings` + `cargo fmt` clean. large_file arch-exempts added for the three >1,500-line files the rename's lines touch (contribution.rs 17K, plus two v1 files) — no logic change. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
§4.4/§10 ratchet — freeze the
LocalDev*type-name inventoryStacked on #6204. Adds the deployment-mode-as-type ratchet §4.4/§10 of
docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.mdcalls for, ahead of Slice B (collapsing theLocalDev*shadow runtime to aDeploymentConfigvalue).§4.4's rule: a deployment mode is a config value, never a type the kernel or a substrate names. Today a whole
LocalDev*type family encodes local-dev as types (approval/capability/lease/mount/network/outbound policy, the store aliases, the root filesystem, the turn-state store, the synthetic-capability + extension-surface families). This test freezes that inventory and enforces the direction.What it does
crates/ironclaw_architecture/tests/reborn_localdev_typename_ratchet.rsscanscrates/forpub/pub(crate)LocalDev*type definitions (struct/enum/trait/type alias) and asserts the set exactly equals a frozen allowlist (the current 31):LocalDev*type → fails: resolve the mode to policy data at the composition edge, don't grow another type.Definition of done for this axis: the allowlist reaches empty — local-dev is one
DeploymentConfigconstant, noLocalDev*type remains.Notes
LocalDev*(clean empty-set goal). The broader §4.4 name audit — Bucket 2 renames (LocalFilesystem→DiskFilesystem,LocalHostProcessPort→HostProcessPort) and Bucket 3 false positives (Locale,HostedMcp*= hosted MCP endpoint not deployment mode,LocalTraceSubmission*) — is a separate concern, deliberately not folded in so this ratchet stays high-signal.LocalDev*types a line-oriented grep had missed (synthetic-capability, extension-surface, auth-read-model, capability-wiring families) — exactly the §4.4.1 category-3 "genuine local-only mechanism" cluster Slice B must promote to first-party capabilities.Safety
Test-only, ships with a scanner self-test. No production code touched.
🤖 Generated with Claude Code
Update (review pass)
ee85b4ca8consolidates both §10 ratchets onto a shared hardened scanner (tests/ratchet_support/mod.rs) — comment/string stripping, restricted-visibility +unsafe/automatching, occurrence-preserving scans, production-scoped walk — so this PR now also refactorsreborn_inmemory_store_ratchet.rsonto that module (behavior identical, self-tests preserved). The LocalDev ratchet additionally gains cfg-aware multiplicity: factory's durable/no-durable#[cfg]-gated alias pairs (incl. multi-line gates) are exempt from the duplicate check only when every occurrence is gated; mixed pairs still fail. Regression-tested for all of the above.