Skip to content

test(reborn): annotate the §4.3 store ratchet with per-entry achievable-floor status - #6216

Merged
ilblackdragon merged 2 commits into
mainfrom
refactor/reborn-ratchet-annotate-remaining-stores
Jul 18, 2026
Merged

ilblackdragon merged 2 commits into
mainfrom
refactor/reborn-ratchet-annotate-remaining-stores

Conversation

@ilblackdragon

Copy link
Copy Markdown
Member

What

The mechanical §4.3 store consolidations are complete (A1–A8: approvals, authorization, processes, run-state, budget-gate, and the whole outbound family). Every entry still in FROZEN_INMEMORY_STORES is blocked on non-mechanical work OR is a justified keep — so the §10 "shrink to empty" goal is not reachable by a swap.

This annotates each remaining allowlist entry with its verified status so the next contributor picks up a scoped task instead of re-deriving the blocker. Comments are stripped by the scanner — documentation only, the enforced string set is unchanged (entries reordered to group the justified keeps).

Per-entry status

  • turns cluster — DEFERRED (production inmemory-turn-state authority; needs a no-livelock concurrency proof + a built filesystem variant, some cross-crate).
  • InMemoryBoundedSubagentGoalStore, InMemoryOpenAiCompatRefStore — JUSTIFIED bounded caches (capacity-bounded evict-oldest / bounded-LRU + filesystem-free contract boundary), NOT persistence debt; a durable variant would be semantically wrong.
  • InMemoryExtensionInstallationStore — BLOCKED cross-crate (the Filesystem variant in composition depends on a composition-internal contract registry; can't move down to ironclaw_extensions).
  • InMemorySecretStore — security-sensitive.
  • InMemorySessionStore — BUILD-FIRST (no filesystem variant; auth-adjacent).

Also reconciles the module-doc "definition of done" to note the two justified caches (a future PR may formally split them into a justified-keep list).

Verification

No production code changes. Ratchet self-tests + the frozen-set contract still pass (4 tests); fmt + pre-commit clean.

Stack

Stacked on #6214. Closes out the §4.3 store-consolidation axis with documented evidence of the achievable floor.

🤖 Generated with Claude Code

@ironloopai

ironloopai Bot commented Jul 18, 2026 •

Copy link
Copy Markdown
Contributor

🔎 IronLoop Review Status

Head: 5985c26f34925ec66185ad43d631395d015bc716
Result: One or more review results were superseded by a newer PR head.
Next: Run @ironloopai review on the latest PR head.
Updated: 2026-07-18T03:30:14.160Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Superseded N/A N/A 2026-07-18T01:07:23.253Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Superseded by a newer PR head. New head: 843cfba. Previous verdict: Approved.
Recent activity
Time Reviewer State Detail
2026-07-18T00:31:07.676Z ironloop/common-reviewer (reviewer) Queued Accepted review request for head cf8a845.
2026-07-18T00:31:07.676Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-18T00:31:08.589Z ironloop/common-reviewer (reviewer) Started Reviewer worker started.
2026-07-18T00:31:11.013Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (merge_ref) at 16e5812.
2026-07-18T00:35:23.864Z ironloop/common-reviewer (reviewer) Result captured Approved; 0 blocking findings.
2026-07-18T00:35:23.864Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
2026-07-18T01:07:23.253Z ironloop/common-reviewer (reviewer) Superseded A newer PR head replaced this review (843cfba).
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent>
Run metadata

Admission: webhook accepted the request and IronLoop persisted reviewer state before this projection.

@coderabbitai

coderabbitai Bot commented Jul 18, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Summary by CodeRabbit

  • Documentation

    • Clarified the completion criteria for in-memory store tracking.
    • Added status details and rationale for listed bounded caches.
    • Updated the inventory and organization of the documented allowlist.
  • Tests

    • No test behavior or validation logic was changed.

Walkthrough

The ratchet test’s contract comments now describe completion as empty debt, document bounded-cache exceptions and inventory status, and reorder entries in the frozen in-memory store list. Test logic and public declarations are unchanged.

Changes

In-memory store ratchet

Layer / File(s) Summary
Ratchet contract and inventory documentation
crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs
The definition-of-done wording and FROZEN_INMEMORY_STORES documentation now describe debt status, bounded-cache exceptions, triage notes, and deferred entries; the allowlist ordering was adjusted without changing its set of entries.

Estimated code review effort: 1 (Trivial) | ~3 minutes

Possibly related PRs

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed Conventional Commits style is used and the title accurately matches the store-ratchet documentation change.
Description check ✅ Passed The description is detailed and covers summary plus verification, but it omits several template sections like issue, security, and rollback.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6216 July 18, 2026 00:31 Destroyed
@github-actions github-actions Bot added size: XS < 10 changed lines (excluding docs) risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Jul 18, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the documentation and comments in reborn_inmemory_store_ratchet.rs to reflect the current status of the remaining in-memory stores after the mechanical consolidations (A1–A8) have been completed. It categorizes the remaining stores into deferred, justified keeps (bounded caches), blocked, security-sensitive, and build-first categories, providing clear context for future refactoring efforts. There are no review comments, so no feedback is provided.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
✅ Approved 0 5 5 cf8a84512d6b

Head: cf8a84512d6b9cc7ae7409e119073e34047276ce
Next: No reviewer action needed.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

This is a bounded, reviewable stack layer changing one architecture-test documentation file (52 additions, 15 deletions). The enforced allowlist set is unchanged and no runtime behavior changes. Static checks passed, with five non-blocking accuracy/completeness issues in the new annotations.

Findings

Blocking: 0 / Notes: 5

Non-blocking notes (5)
1. 💬 [LOW] Referenced store-triage worklog is absent

Location: crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs:64
The target tree contains no .worklog/reborn-refactor.md, so future contributors cannot access the cited “full analysis.” Commit/link an available source of truth or remove this reference.

2. 💬 [LOW] CheckpointState filesystem variant already exists

Location: crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs:70-71
FilesystemCheckpointStateStore already exists in ironclaw_loop_host, has contract tests, and is wired in composition. Separate InMemoryCheckpointStateStore from the stores that genuinely still need a filesystem implementation so the next task is scoped correctly.

3. 💬 [LOW] Justified-cache rationale contradicts production filesystem stores

Location: crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs:76-79
The blanket claim that durable variants would be semantically wrong conflicts with the code: FilesystemSubagentGoalStore is explicitly the production store for libSQL/Postgres, and serving wires FilesystemOpenAiCompatRefStore. The in-memory implementations may remain justified test/fallback implementations, but the annotation should state that rationale instead.

4. 💬 [LOW] OpenAI compatibility store is not LRU

Location: crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs:83-85
The implementation evicts the mapping with the minimum created_at; lookups and mutations do not refresh recency. Describe it as bounded oldest-created eviction rather than LRU.

5. 💬 [LOW] Three remaining entries are explicitly untriaged

Location: crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs:102-107
This block says the three crate-private stores are “not yet individually triaged,” contradicting the preceding claim that every entry has a verified per-entry status and a scoped next task. Add a concrete status for each entry or soften the overall completeness claim.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.

/// justified keep — so the §10 "shrink to empty" goal is not reachable by a
/// swap. Each entry is annotated with WHAT it needs, so the next contributor
/// picks up a scoped task instead of re-deriving the blocker. See
/// `../.worklog/reborn-refactor.md` (store triage) for the full analysis.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This referenced worklog is not present anywhere in the target tree, so future contributors cannot consult the claimed full analysis. Please link an available source of truth or remove the reference.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed on this branch: the worklog reference is removed — the annotations themselves are now the source of truth, and the completeness claim was softened to match.

// `inmemory-turn-state` production runtime authority (pessimistic Mutex,
// no-CAS-livelock); a `FilesystemTurnStateStore<InMemoryBackend>` swap needs
// a concurrency stress test PROVING it keeps the no-livelock property first.
// Checkpoint/LoopCheckpoint/InstructionMaterialization also need a filesystem

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

FilesystemCheckpointStateStore is already implemented in ironclaw_loop_host, contract-tested, and wired by composition. Please distinguish InMemoryCheckpointStateStore from the stores that still need a filesystem variant.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed: the turns-cluster note now distinguishes InMemoryCheckpointStateStore (its FilesystemCheckpointStateStore already exists in ironclaw_loop_host, contract-tested and composition-wired — only the test-seam swap + allowlist trim remain) from LoopCheckpoint/InstructionMaterialization, which still need filesystem variants built.

// --- peripheral stores (outside §4.3's five core domains; listed so the
// ratchet stays exhaustive and no new InMemory store slips in) ---
// --- JUSTIFIED KEEPS — bounded in-memory CACHES, not persistence-store debt.
// A durable `Filesystem*` variant would be semantically wrong (you do not

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This rationale conflicts with existing production adapters: libSQL/Postgres use FilesystemSubagentGoalStore, and OpenAI-compatible serving uses FilesystemOpenAiCompatRefStore. The in-memory types may be justified test/fallback implementations, but durable storage is not semantically wrong for these contracts.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed: the justified-keeps section now states that durable production variants already exist and are wired (FilesystemSubagentGoalStore in the libSQL/Postgres runner adapters, FilesystemOpenAiCompatRefStore in OpenAI-compatible serving), and frames the in-memory types as the bounded volatile role beside those stores rather than missing consolidations.

// order) cache of in-flight subagent-spawn goals — goal_store.rs.
"InMemoryBoundedSubagentGoalStore",
"InMemoryExtensionInstallationStore",
// OpenAiCompatRef: bounded-LRU (`max_mappings`/`with_capacity`) AND the

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is not LRU: eviction selects the minimum created_at, and accesses do not update recency. Please describe it as oldest-created eviction.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed: described as capacity-bounded with oldest-created eviction (evicts the minimum created_at; reads do not refresh recency — explicitly noted as NOT an LRU), matching refs.rs's min_by_key(created_at).

"InMemorySessionStore",
// --- pub(crate) stores the visibility-aware scanner also inventories
// (same debt class, just crate-private) ---
// (crate-private; not yet individually triaged — assess build-vs-justified

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

These entries are explicitly untriaged, which conflicts with the preceding claim that every remaining entry has a verified status and scoped task. Please annotate each one or soften the completeness claim.

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed: the header claim is softened — triaged entries carry their scoped task, and the pub(crate) trio is explicitly labeled untriaged instead of being covered by a blanket verified-status claim.

@railway-app

railway-app Bot commented Jul 18, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-6216 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 18, 2026 at 3:30 am

@ilblackdragon
ilblackdragon force-pushed the refactor/reborn-consolidate-delivered-gate-route-store branch from 66d7cf2 to 154913a Compare July 18, 2026 01:07
@ilblackdragon
ilblackdragon force-pushed the refactor/reborn-ratchet-annotate-remaining-stores branch from cf8a845 to 843cfba Compare July 18, 2026 01:07
ilblackdragon added a commit that referenced this pull request Jul 18, 2026
…> CompositeRootFilesystem (§4.4.1)

First §4.4.1 slice (deployment-mode-as-type cleanup), on a fresh axis now that the
mechanical §4.3 store family is complete. `LocalDevRootFilesystem` was a
`pub(crate) type LocalDevRootFilesystem = CompositeRootFilesystem;` alias — a pure
redundant indirection whose `LocalDev` prefix falsely read as a deployment tier
when it is just the composition's `CompositeRootFilesystem` (the same type
factory.rs already used directly, interchangeably, in dozens of places). This is
the doc's §4.4.1 bucket-(b): mis-prefixed shared substrate → de-prefix to the
honest type.

Inlined the alias to `ironclaw_filesystem::CompositeRootFilesystem` across the 4
composition files that used it (factory/runtime/openai_compat_serve/turn_run_snapshot,
~54 sites), deleted the alias, and repointed the imports (the alias was exported
from `crate::factory`; consumers now import the real type from
`ironclaw_filesystem`). The private, genuinely-local-dev
`LocalDevRootFilesystemBundle` struct keeps its name (word-boundary rename left it
untouched; it is not on the ratchet — visibility-aware scanner skips private types).

R2 ratchet (`reborn_localdev_typename`): drop `LocalDevRootFilesystem` from the
frozen allowlist — one fewer deployment-mode-as-type leak.

Pure type-alias inline, semantically identical. Verified: `cargo build -p
ironclaw_reborn_composition` (default + libsql+slack) clean; localdev ratchet 4;
clippy -D warnings clean; local_dev composition tests 233 pass; fmt + pre-commit clean.

Stacked on #6216.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6216 July 18, 2026 01:07 Destroyed
@ilblackdragon
ilblackdragon force-pushed the refactor/reborn-consolidate-delivered-gate-route-store branch from 154913a to b375388 Compare July 18, 2026 01:10
ilblackdragon added a commit that referenced this pull request Jul 18, 2026
…dings on #6216)

- Drop the reference to a worklog not present in the tree.
- InMemoryCheckpointStateStore: FilesystemCheckpointStateStore already
  exists in ironclaw_loop_host (contract-tested, composition-wired) — the
  entry needs a test-seam swap, not a store built; LoopCheckpoint/
  InstructionMaterialization still need variants built.
- Justified-keeps section acknowledges the production filesystem variants
  that already exist and are wired (FilesystemSubagentGoalStore,
  FilesystemOpenAiCompatRefStore) — the in-memory types are the bounded
  volatile role beside them, not missing consolidations.
- OpenAiCompatRef eviction described as oldest-created (min created_at,
  reads do not refresh recency), not LRU.
- Completeness claim softened: the pub(crate) trio is explicitly
  untriaged rather than claimed verified.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@ilblackdragon
ilblackdragon force-pushed the refactor/reborn-ratchet-annotate-remaining-stores branch from 843cfba to 636f29d Compare July 18, 2026 01:12
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6216 July 18, 2026 01:12 Destroyed
ilblackdragon added a commit that referenced this pull request Jul 18, 2026
…> CompositeRootFilesystem (§4.4.1)

First §4.4.1 slice (deployment-mode-as-type cleanup), on a fresh axis now that the
mechanical §4.3 store family is complete. `LocalDevRootFilesystem` was a
`pub(crate) type LocalDevRootFilesystem = CompositeRootFilesystem;` alias — a pure
redundant indirection whose `LocalDev` prefix falsely read as a deployment tier
when it is just the composition's `CompositeRootFilesystem` (the same type
factory.rs already used directly, interchangeably, in dozens of places). This is
the doc's §4.4.1 bucket-(b): mis-prefixed shared substrate → de-prefix to the
honest type.

Inlined the alias to `ironclaw_filesystem::CompositeRootFilesystem` across the 4
composition files that used it (factory/runtime/openai_compat_serve/turn_run_snapshot,
~54 sites), deleted the alias, and repointed the imports (the alias was exported
from `crate::factory`; consumers now import the real type from
`ironclaw_filesystem`). The private, genuinely-local-dev
`LocalDevRootFilesystemBundle` struct keeps its name (word-boundary rename left it
untouched; it is not on the ratchet — visibility-aware scanner skips private types).

R2 ratchet (`reborn_localdev_typename`): drop `LocalDevRootFilesystem` from the
frozen allowlist — one fewer deployment-mode-as-type leak.

Pure type-alias inline, semantically identical. Verified: `cargo build -p
ironclaw_reborn_composition` (default + libsql+slack) clean; localdev ratchet 4;
clippy -D warnings clean; local_dev composition tests 233 pass; fmt + pre-commit clean.

Stacked on #6216.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ilblackdragon
ilblackdragon force-pushed the refactor/reborn-consolidate-delivered-gate-route-store branch from b375388 to 8d453ff Compare July 18, 2026 01:20
ilblackdragon added a commit that referenced this pull request Jul 18, 2026
…dings on #6216)

- Drop the reference to a worklog not present in the tree.
- InMemoryCheckpointStateStore: FilesystemCheckpointStateStore already
  exists in ironclaw_loop_host (contract-tested, composition-wired) — the
  entry needs a test-seam swap, not a store built; LoopCheckpoint/
  InstructionMaterialization still need variants built.
- Justified-keeps section acknowledges the production filesystem variants
  that already exist and are wired (FilesystemSubagentGoalStore,
  FilesystemOpenAiCompatRefStore) — the in-memory types are the bounded
  volatile role beside them, not missing consolidations.
- OpenAiCompatRef eviction described as oldest-created (min created_at,
  reads do not refresh recency), not LRU.
- Completeness claim softened: the pub(crate) trio is explicitly
  untriaged rather than claimed verified.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@ilblackdragon
ilblackdragon force-pushed the refactor/reborn-ratchet-annotate-remaining-stores branch from 636f29d to bb310b2 Compare July 18, 2026 01:20
ilblackdragon added a commit that referenced this pull request Jul 18, 2026
…> CompositeRootFilesystem (§4.4.1)

First §4.4.1 slice (deployment-mode-as-type cleanup), on a fresh axis now that the
mechanical §4.3 store family is complete. `LocalDevRootFilesystem` was a
`pub(crate) type LocalDevRootFilesystem = CompositeRootFilesystem;` alias — a pure
redundant indirection whose `LocalDev` prefix falsely read as a deployment tier
when it is just the composition's `CompositeRootFilesystem` (the same type
factory.rs already used directly, interchangeably, in dozens of places). This is
the doc's §4.4.1 bucket-(b): mis-prefixed shared substrate → de-prefix to the
honest type.

Inlined the alias to `ironclaw_filesystem::CompositeRootFilesystem` across the 4
composition files that used it (factory/runtime/openai_compat_serve/turn_run_snapshot,
~54 sites), deleted the alias, and repointed the imports (the alias was exported
from `crate::factory`; consumers now import the real type from
`ironclaw_filesystem`). The private, genuinely-local-dev
`LocalDevRootFilesystemBundle` struct keeps its name (word-boundary rename left it
untouched; it is not on the ratchet — visibility-aware scanner skips private types).

R2 ratchet (`reborn_localdev_typename`): drop `LocalDevRootFilesystem` from the
frozen allowlist — one fewer deployment-mode-as-type leak.

Pure type-alias inline, semantically identical. Verified: `cargo build -p
ironclaw_reborn_composition` (default + libsql+slack) clean; localdev ratchet 4;
clippy -D warnings clean; local_dev composition tests 233 pass; fmt + pre-commit clean.

Stacked on #6216.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6216 July 18, 2026 01:20 Destroyed
@ilblackdragon

Copy link
Copy Markdown
Member Author

✅ Ready for merge

CI green (18 pass / 0 fail) on the restacked head.

All five IronLoop factual findings fixed with replies: the missing-worklog reference removed; InMemoryCheckpointStateStore distinguished from stores needing variants built (its FilesystemCheckpointStateStore already exists, contract-tested and wired); the justified-keeps section acknowledges the production FilesystemSubagentGoalStore/FilesystemOpenAiCompatRefStore variants; eviction described as oldest-created (verified against refs.rs's min_by_key(created_at)), not LRU; the completeness claim softened to label the pub(crate) trio explicitly untriaged.

🤖 Generated with Claude Code

Base automatically changed from refactor/reborn-consolidate-delivered-gate-route-store to refactor/reborn-consolidate-triggered-run-delivery-store July 18, 2026 03:03
@ilblackdragon
ilblackdragon force-pushed the refactor/reborn-consolidate-triggered-run-delivery-store branch from fb2bc20 to 6bbbbd2 Compare July 18, 2026 03:04
ilblackdragon added a commit that referenced this pull request Jul 18, 2026
…dings on #6216)

- Drop the reference to a worklog not present in the tree.
- InMemoryCheckpointStateStore: FilesystemCheckpointStateStore already
  exists in ironclaw_loop_host (contract-tested, composition-wired) — the
  entry needs a test-seam swap, not a store built; LoopCheckpoint/
  InstructionMaterialization still need variants built.
- Justified-keeps section acknowledges the production filesystem variants
  that already exist and are wired (FilesystemSubagentGoalStore,
  FilesystemOpenAiCompatRefStore) — the in-memory types are the bounded
  volatile role beside them, not missing consolidations.
- OpenAiCompatRef eviction described as oldest-created (min created_at,
  reads do not refresh recency), not LRU.
- Completeness claim softened: the pub(crate) trio is explicitly
  untriaged rather than claimed verified.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@ilblackdragon
ilblackdragon force-pushed the refactor/reborn-ratchet-annotate-remaining-stores branch from bb310b2 to 86e9f90 Compare July 18, 2026 03:04
ilblackdragon added a commit that referenced this pull request Jul 18, 2026
…> CompositeRootFilesystem (§4.4.1)

First §4.4.1 slice (deployment-mode-as-type cleanup), on a fresh axis now that the
mechanical §4.3 store family is complete. `LocalDevRootFilesystem` was a
`pub(crate) type LocalDevRootFilesystem = CompositeRootFilesystem;` alias — a pure
redundant indirection whose `LocalDev` prefix falsely read as a deployment tier
when it is just the composition's `CompositeRootFilesystem` (the same type
factory.rs already used directly, interchangeably, in dozens of places). This is
the doc's §4.4.1 bucket-(b): mis-prefixed shared substrate → de-prefix to the
honest type.

Inlined the alias to `ironclaw_filesystem::CompositeRootFilesystem` across the 4
composition files that used it (factory/runtime/openai_compat_serve/turn_run_snapshot,
~54 sites), deleted the alias, and repointed the imports (the alias was exported
from `crate::factory`; consumers now import the real type from
`ironclaw_filesystem`). The private, genuinely-local-dev
`LocalDevRootFilesystemBundle` struct keeps its name (word-boundary rename left it
untouched; it is not on the ratchet — visibility-aware scanner skips private types).

R2 ratchet (`reborn_localdev_typename`): drop `LocalDevRootFilesystem` from the
frozen allowlist — one fewer deployment-mode-as-type leak.

Pure type-alias inline, semantically identical. Verified: `cargo build -p
ironclaw_reborn_composition` (default + libsql+slack) clean; localdev ratchet 4;
clippy -D warnings clean; local_dev composition tests 233 pass; fmt + pre-commit clean.

Stacked on #6216.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6216 July 18, 2026 03:04 Destroyed
@ilblackdragon

Copy link
Copy Markdown
Member Author

Post-restack confirmation: rebased onto the updated chain after the #6212/#6214/#6221 merges. CI fully green — 18 pass / 0 fail. Still ready for merge.

Base automatically changed from refactor/reborn-consolidate-triggered-run-delivery-store to main July 18, 2026 03:29
ilblackdragon and others added 2 commits July 18, 2026 03:30
…evable-floor status

The mechanical §4.3 store consolidations are complete (A1–A8: approvals,
authorization, processes, run-state, budget-gate, and the whole outbound family —
OutboundState/TriggeredRunDelivery/DeliveredGateRoute). Every entry still in
`FROZEN_INMEMORY_STORES` is blocked on non-mechanical work OR is a justified keep,
so the §10 "shrink to empty" goal is not reachable by a swap.

This annotates each remaining allowlist entry with its VERIFIED status so the
next contributor picks up a scoped task instead of re-deriving the blocker
(comments are stripped by the scanner — documentation only, the enforced string
set is unchanged; entries reordered to group the justified keeps):

- turns cluster — DEFERRED (production `inmemory-turn-state` authority; needs a
  no-livelock concurrency proof + a built filesystem variant, some cross-crate).
- `InMemoryBoundedSubagentGoalStore`, `InMemoryOpenAiCompatRefStore` — JUSTIFIED
  bounded CACHES (capacity-bounded evict-oldest / bounded-LRU + filesystem-free
  contract boundary), NOT persistence debt; a durable variant would be wrong.
- `InMemoryExtensionInstallationStore` — BLOCKED cross-crate (the Filesystem
  variant in composition depends on a composition-internal contract registry;
  can't move down to `ironclaw_extensions`).
- `InMemorySecretStore` — security-sensitive.
- `InMemorySessionStore` — BUILD-FIRST (no filesystem variant; auth-adjacent).

Also reconciles the module-doc "definition of done" to note the two justified
caches. No production code changes; ratchet self-tests + the frozen-set contract
still pass (4 tests).

Stacked on #6214.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…dings on #6216)

- Drop the reference to a worklog not present in the tree.
- InMemoryCheckpointStateStore: FilesystemCheckpointStateStore already
  exists in ironclaw_loop_host (contract-tested, composition-wired) — the
  entry needs a test-seam swap, not a store built; LoopCheckpoint/
  InstructionMaterialization still need variants built.
- Justified-keeps section acknowledges the production filesystem variants
  that already exist and are wired (FilesystemSubagentGoalStore,
  FilesystemOpenAiCompatRefStore) — the in-memory types are the bounded
  volatile role beside them, not missing consolidations.
- OpenAiCompatRef eviction described as oldest-created (min created_at,
  reads do not refresh recency), not LRU.
- Completeness claim softened: the pub(crate) trio is explicitly
  untriaged rather than claimed verified.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@ilblackdragon
ilblackdragon force-pushed the refactor/reborn-ratchet-annotate-remaining-stores branch from 86e9f90 to 5985c26 Compare July 18, 2026 03:30
ilblackdragon added a commit that referenced this pull request Jul 18, 2026
…> CompositeRootFilesystem (§4.4.1)

First §4.4.1 slice (deployment-mode-as-type cleanup), on a fresh axis now that the
mechanical §4.3 store family is complete. `LocalDevRootFilesystem` was a
`pub(crate) type LocalDevRootFilesystem = CompositeRootFilesystem;` alias — a pure
redundant indirection whose `LocalDev` prefix falsely read as a deployment tier
when it is just the composition's `CompositeRootFilesystem` (the same type
factory.rs already used directly, interchangeably, in dozens of places). This is
the doc's §4.4.1 bucket-(b): mis-prefixed shared substrate → de-prefix to the
honest type.

Inlined the alias to `ironclaw_filesystem::CompositeRootFilesystem` across the 4
composition files that used it (factory/runtime/openai_compat_serve/turn_run_snapshot,
~54 sites), deleted the alias, and repointed the imports (the alias was exported
from `crate::factory`; consumers now import the real type from
`ironclaw_filesystem`). The private, genuinely-local-dev
`LocalDevRootFilesystemBundle` struct keeps its name (word-boundary rename left it
untouched; it is not on the ratchet — visibility-aware scanner skips private types).

R2 ratchet (`reborn_localdev_typename`): drop `LocalDevRootFilesystem` from the
frozen allowlist — one fewer deployment-mode-as-type leak.

Pure type-alias inline, semantically identical. Verified: `cargo build -p
ironclaw_reborn_composition` (default + libsql+slack) clean; localdev ratchet 4;
clippy -D warnings clean; local_dev composition tests 233 pass; fmt + pre-commit clean.

Stacked on #6216.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6216 July 18, 2026 03:30 Destroyed

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs`:
- Around line 26-35: The ratchet in the test around FROZEN_INMEMORY_STORES does
not detect newly added frozen stores. Add a checked-in baseline and compare the
current frozen set against it, failing when entries are added while allowing
removals; alternatively remove the “only shrinks” guarantee from the surrounding
comment and failure text.
- Around line 57-111: Add inline source anchors to the durable-variant and
wiring claims in FROZEN_INMEMORY_STORES, citing the defining and integration
symbols for FilesystemCheckpointStateStore, FilesystemSubagentGoalStore,
FilesystemOpenAiCompatRefStore, and FilesystemExtensionInstallationStore. Keep
FilesystemSessionStore described as an unimplemented open gap because no crates/
source exists, and trim any unsupported claims rather than leaving them uncited.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: cf4571cc-557f-43ae-b73d-7747c87b4b45

📥 Commits

Reviewing files that changed from the base of the PR and between a900da5 and 5985c26.

📒 Files selected for processing (1)
  • crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs

Comment on lines +26 to +35
//! Definition of done for this axis (§10): the **debt** shrinks to empty — every
//! persistence-store duplicate becomes `Filesystem*Store<InMemoryBackend>` in
//! tests. The mechanical consolidations (A1–A8: approvals, authorization,
//! processes, run-state, budget-gate, and the whole outbound family) are done;
//! see the annotated `FROZEN_INMEMORY_STORES` below for the per-entry status of
//! the remainder. Note two entries (`InMemoryBoundedSubagentGoalStore`,
//! `InMemoryOpenAiCompatRefStore`) are **justified bounded caches**, not
//! persistence debt — a future PR may formally split them into a justified-keep
//! list; for now they stay frozen with a do-not-consolidate note. Until then
//! this frozen set is the contract.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

git ls-files | rg '(^|/)reborn_inmemory_store_ratchet\.rs$|(^|/)CLAUDE\.md$|(^|/)AGENTS\.md$|(^|/)\.claude/rules'
printf '\n--- file outline ---\n'
ast-grep outline crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs --view expanded
printf '\n--- relevant file slice ---\n'
sed -n '1,240p' crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs

Repository: nearai/ironclaw

Length of output: 17702


Enforce the “only shrinks” ratchet.
added.is_empty() only rejects names outside the current allowlist. If a new InMemory*Store is added to both the code and FROZEN_INMEMORY_STORES, this test still passes, so the “never add” / “only shrinks” contract is not enforced. Add a checked-in baseline/diff check, or drop that guarantee from the comment and failure text.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs` around
lines 26 - 35, The ratchet in the test around FROZEN_INMEMORY_STORES does not
detect newly added frozen stores. Add a checked-in baseline and compare the
current frozen set against it, failing when entries are added while allowing
removals; alternatively remove the “only shrinks” guarantee from the surrounding
comment and failure text.

Comment on lines +57 to +111
/// **Status of the remainder (assessed 2026-07-18, after the mechanical §4.3
/// slices A1–A8 landed the approvals/authorization/processes/run-state/budget-gate
/// and the whole outbound family).** The clean mechanical consolidations are
/// DONE; every entry still here is blocked on non-mechanical work OR is a
/// justified keep — except the trailing pub(crate) trio, which is not yet
/// individually triaged. Triaged entries are annotated with WHAT they need, so
/// the next contributor picks up a scoped task instead of re-deriving the
/// blocker; untriaged entries say so explicitly.
const FROZEN_INMEMORY_STORES: &[&str] = &[
// --- remaining Slice-A domain store: turns (do last, reconcile-then-delete;
// `InMemoryTurnStateStore` is also the `inmemory-turn-state` production
// runtime authority, so it is not a mechanical delete) ---
// --- turns cluster: DEFERRED, not mechanical. `InMemoryTurnStateStore` is the
// `inmemory-turn-state` production runtime authority (pessimistic Mutex,
// no-CAS-livelock); a `FilesystemTurnStateStore<InMemoryBackend>` swap needs
// a concurrency stress test PROVING it keeps the no-livelock property first.
// `FilesystemCheckpointStateStore` already EXISTS in `ironclaw_loop_host`
// (contract-tested, composition-wired) — that entry only needs the test-seam
// swap + allowlist trim; LoopCheckpoint/InstructionMaterialization still need
// a filesystem variant BUILT (cross-crate in `ironclaw_loop_host`). ---
"InMemoryTurnStateStore",
"InMemoryCheckpointStateStore",
"InMemoryLoopCheckpointStore",
"InMemoryInstructionMaterializationStore",
// --- peripheral stores (outside §4.3's five core domains; listed so the
// ratchet stays exhaustive and no new InMemory store slips in) ---
// --- JUSTIFIED KEEPS — bounded in-memory caches serving the test/no-durable
// fallback role. Durable production variants ALREADY EXIST and are wired
// (`FilesystemSubagentGoalStore` in the libSQL/Postgres runner adapters;
// `FilesystemOpenAiCompatRefStore` in OpenAI-compatible serving) — these
// in-memory types are not missing consolidations, they are the bounded
// volatile role next to those stores. Do NOT swap them for a durable
// store in tests that specifically exercise the bounded/evicting cache
// semantics. ---
// BoundedSubagentGoal: capacity-bounded, evict-oldest (VecDeque insertion
// order) cache of in-flight subagent-spawn goals — goal_store.rs.
"InMemoryBoundedSubagentGoalStore",
"InMemoryExtensionInstallationStore",
// OpenAiCompatRef: capacity-bounded with oldest-created eviction (evicts the
// minimum `created_at`; reads do not refresh recency — NOT an LRU) AND the
// crate's documented filesystem-free default so contract-only consumers pull
// no `ironclaw_filesystem` dep (openai_compat CLAUDE.md).
"InMemoryOpenAiCompatRefStore",
// --- BLOCKED — cross-crate placement. `FilesystemExtensionInstallationStore`
// exists but in high `ironclaw_reborn_composition` and depends on a
// composition-internal contract registry, so it can't move DOWN to
// `ironclaw_extensions` (whose own tests need an in-memory store). Needs the
// filesystem store (or its contract dep) relocated first. Prod already wires
// Filesystem. ---
"InMemoryExtensionInstallationStore",
// --- SECURITY-SENSITIVE — secrets subsystem; deliberate careful work, not a
// mechanical swap. ---
"InMemorySecretStore",
// --- BUILD-FIRST — no filesystem variant exists. `InMemorySessionStore`
// (webui login sessions, TTL-expiring bearer tokens) would gain restart
// durability from a `FilesystemSessionStore`, but that store must be BUILT
// (auth-adjacent — handle with care). ~63 usages. ---
"InMemorySessionStore",
// --- pub(crate) stores the visibility-aware scanner also inventories
// (same debt class, just crate-private) ---
// (crate-private; not yet individually triaged — assess build-vs-justified
// when picked up, same as the peripheral set above). ---

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

set -euo pipefail

printf '\n== File outline ==\n'
wc -l crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs
sed -n '1,220p' crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs

printf '\n== Search referenced symbols ==\n'
rg -n "FilesystemCheckpointStateStore|FilesystemSubagentGoalStore|FilesystemOpenAiCompatRefStore|FilesystemExtensionInstallationStore|InMemoryTurnStateStore|InMemoryCheckpointStateStore|InMemoryLoopCheckpointStore|InMemoryInstructionMaterializationStore|InMemoryBoundedSubagentGoalStore|InMemoryOpenAiCompatRefStore|InMemoryExtensionInstallationStore|InMemorySecretStore|InMemorySessionStore" crates -g '!target'

printf '\n== CLAUDE/AGENTS invariant mentions ==\n'
rg -n "load-bearing claims|Everything Goes Through Tools|LLM data is never deleted|Trusted-ingress seal|Test through the caller|filesystem variant|bounded in-memory caches|composition-internal contract registry|no-CAS-livelock|oldest-created eviction|FilesystemSessionStore|FilesystemExtensionInstallationStore" CLAUDE.md AGENTS.md .claude -g '!target'

Repository: nearai/ironclaw

Length of output: 50372


🏁 Script executed:

set -euo pipefail
sed -n '1,220p' crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs

Repository: nearai/ironclaw

Length of output: 11287


🏁 Script executed:

set -euo pipefail

printf '\n== FilesystemCheckpointStateStore definition/re-export ==\n'
rg -n "pub struct FilesystemCheckpointStateStore|pub use filesystem_checkpoint_state::FilesystemCheckpointStateStore" \
  crates/ironclaw_loop_host/src crates/ironclaw_loop_host/tests

printf '\n== FilesystemSubagentGoalStore definition/wiring ==\n'
rg -n "pub struct FilesystemSubagentGoalStore|FilesystemSubagentGoalStore::new|FilesystemSubagentGoalStore" \
  crates/ironclaw_runner crates/ironclaw_reborn_composition/src/runtime.rs crates/ironclaw_reborn_composition/tests

printf '\n== FilesystemOpenAiCompatRefStore definition/wiring ==\n'
rg -n "pub struct FilesystemOpenAiCompatRefStore|FilesystemOpenAiCompatRefStore::with_root|FilesystemOpenAiCompatRefStore" \
  crates/ironclaw_reborn_composition/src crates/ironclaw_reborn_composition/tests crates/ironclaw_reborn_openai_compat crates/ironclaw_reborn_composition/src/llm_admin

printf '\n== FilesystemExtensionInstallationStore definition/wiring ==\n'
rg -n "pub(crate) struct FilesystemExtensionInstallationStore|FilesystemExtensionInstallationStore::load_at|FilesystemExtensionInstallationStore::default_state_path|FilesystemExtensionInstallationStore" \
  crates/ironclaw_reborn_composition/src crates/ironclaw_reborn_composition/tests crates/ironclaw_extensions crates/ironclaw_reborn_composition/src/extension_host

printf '\n== Bounded-cache semantics ==\n'
rg -n "capacity-bounded|evict-oldest|oldest-created|LRU|reads do not refresh recency|minimum `created_at`|VecDeque insertion order" \
  crates/ironclaw_runner/src crates/ironclaw_reborn_openai_compat crates/ironclaw_reborn_composition/src crates/ironclaw_reborn_composition/tests

printf '\n== FilesystemSessionStore search ==\n'
rg -n "FilesystemSessionStore" crates

Repository: nearai/ironclaw

Length of output: 12381


Add source anchors to the ratchet notes The status block makes load-bearing claims about durable variants and wiring; cite the defining/writing sites inline, or trim the prose. For example: FilesystemCheckpointStateStore (crates/ironclaw_loop_host/src/filesystem_checkpoint_state.rs:44, re-exported in crates/ironclaw_loop_host/src/lib.rs:79), FilesystemSubagentGoalStore (crates/ironclaw_runner/src/subagent/goal_store.rs:79, wired in crates/ironclaw_reborn_composition/src/runtime.rs:305,368), FilesystemOpenAiCompatRefStore (crates/ironclaw_reborn_openai_compat/src/refs_storage.rs:37, wired in crates/ironclaw_reborn_composition/src/llm_admin/openai_compat_serve.rs:176), and FilesystemExtensionInstallationStore (crates/ironclaw_reborn_composition/src/extension_host/extension_installation_store.rs:19, loaded in crates/ironclaw_reborn_composition/src/factory.rs:1925,3326,3367). FilesystemSessionStore still has no crates/ hit, so keep that one framed as an open gap.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@crates/ironclaw_architecture/tests/reborn_inmemory_store_ratchet.rs` around
lines 57 - 111, Add inline source anchors to the durable-variant and wiring
claims in FROZEN_INMEMORY_STORES, citing the defining and integration symbols
for FilesystemCheckpointStateStore, FilesystemSubagentGoalStore,
FilesystemOpenAiCompatRefStore, and FilesystemExtensionInstallationStore. Keep
FilesystemSessionStore described as an unimplemented open gap because no crates/
source exists, and trim any unsupported claims rather than leaving them uncited.

Source: Coding guidelines

@github-actions

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 85.59% (306535 / 358149 lines)
  floor:    85.3% (tolerance 0.5pp -> effective floor 84.8%)
  denominator: 358149 lines now vs 320188 at floor capture (+37961 lines, +11.86%) — material change (>5%)

⚠️ 2 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts

Reborn integration-tier coverage

Line coverage (Reborn crates): 85.59% — 306535 / 358149 lines

Per-crate breakdown (65 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 345
ironclaw_runtime_policy 31.75% 80 / 252
ironclaw_event_projections 43.31% 673 / 1554
ironclaw_observability 61.54% 16 / 26
ironclaw_authorization 62.46% 604 / 967
ironclaw_mcp 64.89% 595 / 917
ironclaw_triggers 65.44% 2142 / 3273
ironclaw_dispatcher 67.15% 92 / 137
ironclaw_filesystem 67.69% 3932 / 5809
ironclaw_channel_host 68.65% 219 / 319
ironclaw_memory 69.2% 773 / 1117
ironclaw_reborn_migration 71.64% 1551 / 2165
ironclaw_trust 72.88% 661 / 907
ironclaw_reborn_cli 73.98% 7095 / 9591
ironclaw_capabilities 74.36% 1685 / 2266
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_reborn_event_store 74.67% 958 / 1283
ironclaw_extractors 74.72% 538 / 720
ironclaw_projects 76.48% 400 / 523
ironclaw_llm 78.27% 20216 / 25827
ironclaw_product_context 78.57% 11 / 14
ironclaw_telegram_extension 80.18% 4842 / 6039
ironclaw_wasm_product_adapters 80.36% 1448 / 1802
ironclaw_process_sandbox 80.65% 671 / 832
ironclaw_first_party_extensions 81.06% 5965 / 7359
ironclaw_memory_native 81.22% 3205 / 3946
ironclaw_events 81.43% 1539 / 1890
ironclaw_secrets 82.79% 2794 / 3375
ironclaw_network 82.98% 673 / 811
ironclaw_reborn_identity 83.59% 433 / 518
ironclaw_processes 83.76% 939 / 1121
ironclaw_run_state 83.96% 424 / 505
ironclaw_reborn_config 84.02% 1830 / 2178
ironclaw_wasm 84.44% 1069 / 1266
ironclaw_auth 84.81% 3233 / 3812
ironclaw_product_workflow 84.91% 11031 / 12992
ironclaw_turns 85.13% 13737 / 16136
ironclaw_host_api 85.37% 2701 / 3164
ironclaw_channel_delivery 85.79% 1383 / 1612
ironclaw_common 86.13% 1714 / 1990
ironclaw_threads 86.93% 4708 / 5416
ironclaw_slack_v2_adapter 87.3% 1491 / 1708
ironclaw_skills 87.58% 4470 / 5104
ironclaw_hooks 87.78% 9921 / 11302
ironclaw_product_adapter_registry 88.06% 531 / 603
ironclaw_product_adapters 88.1% 3384 / 3841
ironclaw_reborn_traces 88.2% 11946 / 13544
ironclaw_reborn_composition 88.38% 70500 / 79769
ironclaw_webui 88.42% 7333 / 8293
ironclaw_host_runtime 88.76% 18005 / 20284
ironclaw_extensions 89.38% 2971 / 3324
ironclaw_runner 89.5% 16990 / 18983
ironclaw_reborn_openai_compat 89.5% 3778 / 4221
ironclaw_telegram_v2_adapter 89.7% 2717 / 3029
ironclaw_approvals 90.18% 1598 / 1772
ironclaw_conversations 90.39% 3123 / 3455
ironclaw_event_streams 90.82% 1009 / 1111
ironclaw_resources 91.65% 4476 / 4884
ironclaw_loop_host 92.25% 15051 / 16316
ironclaw_attachments 93.06% 630 / 677
ironclaw_agent_loop 94.88% 9184 / 9680
ironclaw_safety 95.04% 3677 / 3869
ironclaw_outbound 95.52% 3451 / 3613
ironclaw_first_party_extension_ports 95.62% 3672 / 3840

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (3 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

@ilblackdragon

Copy link
Copy Markdown
Member Author

Post-restack confirmation (after #6213's merge): rebased onto main, CI fully green on the current head. Still ready for merge.

@ilblackdragon
ilblackdragon merged commit 2e8b2ae into main Jul 18, 2026
65 checks passed
@ilblackdragon
ilblackdragon deleted the refactor/reborn-ratchet-annotate-remaining-stores branch July 18, 2026 03:48
ilblackdragon added a commit that referenced this pull request Jul 18, 2026
…> CompositeRootFilesystem (§4.4.1) (#6218)

* test(reborn): annotate the §4.3 store ratchet with the per-entry achievable-floor status

The mechanical §4.3 store consolidations are complete (A1–A8: approvals,
authorization, processes, run-state, budget-gate, and the whole outbound family —
OutboundState/TriggeredRunDelivery/DeliveredGateRoute). Every entry still in
`FROZEN_INMEMORY_STORES` is blocked on non-mechanical work OR is a justified keep,
so the §10 "shrink to empty" goal is not reachable by a swap.

This annotates each remaining allowlist entry with its VERIFIED status so the
next contributor picks up a scoped task instead of re-deriving the blocker
(comments are stripped by the scanner — documentation only, the enforced string
set is unchanged; entries reordered to group the justified keeps):

- turns cluster — DEFERRED (production `inmemory-turn-state` authority; needs a
  no-livelock concurrency proof + a built filesystem variant, some cross-crate).
- `InMemoryBoundedSubagentGoalStore`, `InMemoryOpenAiCompatRefStore` — JUSTIFIED
  bounded CACHES (capacity-bounded evict-oldest / bounded-LRU + filesystem-free
  contract boundary), NOT persistence debt; a durable variant would be wrong.
- `InMemoryExtensionInstallationStore` — BLOCKED cross-crate (the Filesystem
  variant in composition depends on a composition-internal contract registry;
  can't move down to `ironclaw_extensions`).
- `InMemorySecretStore` — security-sensitive.
- `InMemorySessionStore` — BUILD-FIRST (no filesystem variant; auth-adjacent).

Also reconciles the module-doc "definition of done" to note the two justified
caches. No production code changes; ratchet self-tests + the frozen-set contract
still pass (4 tests).

Stacked on #6214.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* docs(reborn): correct the ratchet per-entry annotations (IronLoop findings on #6216)

- Drop the reference to a worklog not present in the tree.
- InMemoryCheckpointStateStore: FilesystemCheckpointStateStore already
  exists in ironclaw_loop_host (contract-tested, composition-wired) — the
  entry needs a test-seam swap, not a store built; LoopCheckpoint/
  InstructionMaterialization still need variants built.
- Justified-keeps section acknowledges the production filesystem variants
  that already exist and are wired (FilesystemSubagentGoalStore,
  FilesystemOpenAiCompatRefStore) — the in-memory types are the bounded
  volatile role beside them, not missing consolidations.
- OpenAiCompatRef eviction described as oldest-created (min created_at,
  reads do not refresh recency), not LRU.
- Completeness claim softened: the pub(crate) trio is explicitly
  untriaged rather than claimed verified.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* refactor(reborn): inline the redundant LocalDevRootFilesystem alias -> CompositeRootFilesystem (§4.4.1)

First §4.4.1 slice (deployment-mode-as-type cleanup), on a fresh axis now that the
mechanical §4.3 store family is complete. `LocalDevRootFilesystem` was a
`pub(crate) type LocalDevRootFilesystem = CompositeRootFilesystem;` alias — a pure
redundant indirection whose `LocalDev` prefix falsely read as a deployment tier
when it is just the composition's `CompositeRootFilesystem` (the same type
factory.rs already used directly, interchangeably, in dozens of places). This is
the doc's §4.4.1 bucket-(b): mis-prefixed shared substrate → de-prefix to the
honest type.

Inlined the alias to `ironclaw_filesystem::CompositeRootFilesystem` across the 4
composition files that used it (factory/runtime/openai_compat_serve/turn_run_snapshot,
~54 sites), deleted the alias, and repointed the imports (the alias was exported
from `crate::factory`; consumers now import the real type from
`ironclaw_filesystem`). The private, genuinely-local-dev
`LocalDevRootFilesystemBundle` struct keeps its name (word-boundary rename left it
untouched; it is not on the ratchet — visibility-aware scanner skips private types).

R2 ratchet (`reborn_localdev_typename`): drop `LocalDevRootFilesystem` from the
frozen allowlist — one fewer deployment-mode-as-type leak.

Pure type-alias inline, semantically identical. Verified: `cargo build -p
ironclaw_reborn_composition` (default + libsql+slack) clean; localdev ratchet 4;
clippy -D warnings clean; local_dev composition tests 233 pass; fmt + pre-commit clean.

Stacked on #6216.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-6216 — 5985c26f Deployed Jul 18, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules size: XS < 10 changed lines (excluding docs)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant