Skip to content

fix: reliable network tests and improved tool error messages - #626

Merged
ilblackdragon merged 10 commits into
mainfrom
fix/takeover-444-530
Mar 7, 2026
Merged

ilblackdragon merged 10 commits into
mainfrom
fix/takeover-444-530

Conversation

@zmanian

@zmanian zmanian commented Mar 6, 2026

Copy link
Copy Markdown
Collaborator

Summary

Test plan

  • test_search_returns_error_on_network_failure passes with tightened assertion (no error.contains("error") tautology)
  • health_with_unreachable_url_is_false uses TEST-NET-1
  • test_tool_error_format_includes_tool_name regression test for error format
  • cargo clippy --all --all-features clean

Generated with Claude Code

zmanian and others added 9 commits March 2, 2026 16:02
…ror (#448)

On Windows, multiple wasmtime Engine instances sharing the default
compilation cache directory hit OS error 33 (ERROR_LOCK_VIOLATION)
because Windows holds exclusive file locks on memory-mapped cache
files. This is especially triggered when the Telegram channel WASM
module is loaded at startup and then hot-activated via the Extensions
UI.

Fix by giving each engine its own cache subdirectory on Windows
(~/.cache/ironclaw/wasmtime-tools/ and wasmtime-channels/). On
Unix the shared default cache continues to work as before.

Also adds Windows CI jobs (cargo check + clippy across all feature
flag combinations) to catch Windows-specific issues going forward.

Closes #448

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Gate PathBuf import behind #[cfg(unix)] in container.rs (only used
in Unix socket path), suppress unused_mut on conflicts Vec in
channels.rs (mutations are platform-gated), and add cfg gates on
keychain constants and hex_to_bytes that are only used on macOS/Linux.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Use double-quoted TOML strings with backslash and double-quote
escaping for the cache directory path, preventing breakage or
injection when paths contain special characters (e.g. single
quotes on Unix, backslashes on Windows).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Fix import ordering in container.rs and line wrapping in runtime.rs
to pass the CI formatting check.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
…merge main

- Gate `use std::path::PathBuf` with `#[cfg(unix)]` in sandbox/container.rs
  since all usages are inside `#[cfg(unix)]` functions, fixing Windows clippy
  error (unused import)
- Add two regression tests for `enable_compilation_cache` (#448): one verifies
  explicit cache directory creation and TOML config, another verifies label-based
  isolation between engines
- Resolve merge conflict in test.yml to include both windows-build and
  wasm-wit-compat jobs

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Path is used in non-cfg-gated functions (lines 148, 244) so it must
be available on all platforms. Only PathBuf is unix-specific.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Replace localhost/loopback addresses with 192.0.2.1 (TEST-NET-1) in
network failure tests so they work consistently behind HTTP proxies.
Tighten the catalog.rs error assertion to avoid matching any string
containing "error".

Closes #444 (takeover from hobostay)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Format tool errors as "Tool '<name>' failed: <reason>" instead of the
bare "Error: <reason>" so the LLM can identify which tool failed and
reason about alternatives. Does not short-circuit the agent loop --
errors still flow back to the LLM for reasoning.

Closes #487 (takeover from lustsazeus-lab, PR #530)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actions github-actions Bot added scope: agent Agent core (agent loop, router, scheduler) scope: channel/wasm WASM channel runtime scope: tool/wasm WASM tool sandbox scope: secrets Secrets management scope: setup Onboarding / setup scope: sandbox Docker sandbox scope: ci CI/CD workflows labels Mar 6, 2026
@github-actions github-actions Bot added size: L 200-499 changed lines risk: high Safety, secrets, auth, or critical infrastructure contributor: core 20+ merged PRs labels Mar 6, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request significantly enhances the system's stability and diagnostic capabilities. It improves the reliability of network-related tests by using dedicated test IP ranges, making them more consistent across diverse network environments. Additionally, it refines how tool errors are reported, providing more actionable information to the agent and facilitating better decision-making. A specific fix for WASM compilation caching on Windows also prevents potential file locking conflicts, contributing to overall system robustness.

Highlights

Changelog
  • src/agent/dispatcher.rs
    • Updated the format of tool error messages to include the tool's name.
    • Added a new regression test to verify the improved tool error message format.
  • src/channels/wasm/runtime.rs
    • Refactored the WASM compilation cache enabling logic to use a new, platform-aware enable_compilation_cache function, specifically addressing Windows-related file locking issues.
  • src/sandbox/container.rs
    • Conditionally compiled the PathBuf import for Unix systems only.
  • src/secrets/keychain.rs
    • Applied conditional compilation (#[cfg(any(target_os = "macos", target_os = "linux"))]) to SERVICE_NAME, MASTER_KEY_ACCOUNT constants, and the hex_to_bytes function, limiting their availability to macOS and Linux (and tests for hex_to_bytes).
  • src/setup/channels.rs
    • Added #[allow(unused_mut)] attribute to the conflicts vector in detect_existing_cloudflared function.
  • src/skills/catalog.rs
    • Modified the test_search_returns_error_on_network_failure test to use a TEST-NET-1 IP for more reliable network failure simulation.
    • Broadened the assertion for expected error messages to include various connection and gateway errors.
  • src/tools/wasm/mod.rs
    • Exported the newly introduced enable_compilation_cache function from the runtime module.
  • src/tools/wasm/runtime.rs
    • Introduced a new public function enable_compilation_cache to handle WASM compilation cache configuration, with special handling for Windows to prevent file locking issues by creating per-engine cache directories.
    • Updated the WasmToolRuntime initialization to utilize this new enable_compilation_cache function.
    • Added two new tests (test_enable_compilation_cache_with_explicit_dir and test_enable_compilation_cache_label_isolation) to verify the correct behavior and isolation of the compilation cache.
    • Changed PathBuf import to Path, PathBuf.
  • src/tunnel/custom.rs
    • Updated the health_with_unreachable_url_is_false test to use a TEST-NET-1 IP for the unreachable URL, improving test reliability.
    • Added an explicit assertion message to the health check test.
Ignored Files
  • Ignored by pattern: .github/workflows/** (2)
    • .github/workflows/code_style.yml
    • .github/workflows/test.yml
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here.

You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces two main improvements: making network failure tests more reliable by using TEST-NET-1 IPs, and enhancing tool error messages to include the tool name for better debugging by the LLM. The changes are well-implemented and include corresponding tests. I've provided a suggestion to further improve the error message formatting for better maintainability and effectiveness.

Note: Security Review did not run due to the size of the PR.

Comment thread src/agent/dispatcher.rs Outdated
Comment on lines +711 to +714
Err(e) => format!(
"Tool '{}' failed: {}",
tc.name, e
),

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The new error message format introduces redundancy. The e.to_string() call for a ToolError often produces a string that already includes the tool's name (e.g., Tool http execution failed: ...). Prepended with Tool '{}' failed: , this results in a verbose and repetitive message like Tool 'http' failed: Tool error: Tool http execution failed: connection refused, which could be confusing for the LLM. To make the error message clearer and more concise, consider extracting just the core reason from the error.

                                    Err(e) => {
                                        let reason = match e {
                                            crate::error::Error::Tool(
                                                crate::error::ToolError::ExecutionFailed { reason, .. },
                                            ) => reason,
                                            other => other.to_string(),
                                        };
                                        format!("Tool '{}' failed: {}", tc.name, reason)
                                    },
References
  1. Create specific error variants for different failure modes to provide semantically correct and clear error messages. This comment aims to improve the clarity and conciseness of error messages, aligning with the goal of providing semantically correct and clear error messages.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@ilblackdragon
ilblackdragon merged commit 4ac78a5 into main Mar 7, 2026
22 checks passed
@ilblackdragon
ilblackdragon deleted the fix/takeover-444-530 branch March 7, 2026 05:54
This was referenced Mar 7, 2026
bkutasi pushed a commit to bkutasi/ironclaw that referenced this pull request Mar 28, 2026
)

* fix(wasm): use per-engine cache dirs on Windows to avoid file lock error (nearai#448)

On Windows, multiple wasmtime Engine instances sharing the default
compilation cache directory hit OS error 33 (ERROR_LOCK_VIOLATION)
because Windows holds exclusive file locks on memory-mapped cache
files. This is especially triggered when the Telegram channel WASM
module is loaded at startup and then hot-activated via the Extensions
UI.

Fix by giving each engine its own cache subdirectory on Windows
(~/.cache/ironclaw/wasmtime-tools/ and wasmtime-channels/). On
Unix the shared default cache continues to work as before.

Also adds Windows CI jobs (cargo check + clippy across all feature
flag combinations) to catch Windows-specific issues going forward.

Closes nearai#448

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: silence Windows clippy warnings for platform-gated code

Gate PathBuf import behind #[cfg(unix)] in container.rs (only used
in Unix socket path), suppress unused_mut on conflicts Vec in
channels.rs (mutations are platform-gated), and add cfg gates on
keychain constants and hex_to_bytes that are only used on macOS/Linux.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: escape directory path in TOML cache config to prevent injection

Use double-quoted TOML strings with backslash and double-quote
escaping for the cache directory path, preventing breakage or
injection when paths contain special characters (e.g. single
quotes on Unix, backslashes on Windows).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: resolve cargo fmt formatting errors

Fix import ordering in container.rs and line wrapping in runtime.rs
to pass the CI formatting check.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(ci): restore Path import for all platforms, keep PathBuf unix-only

Path is used in non-cfg-gated functions (lines 148, 244) so it must
be available on all platforms. Only PathBuf is unix-specific.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: use RFC 5737 TEST-NET-1 IPs for reliable network failure tests

Replace localhost/loopback addresses with 192.0.2.1 (TEST-NET-1) in
network failure tests so they work consistently behind HTTP proxies.
Tighten the catalog.rs error assertion to avoid matching any string
containing "error".

Closes nearai#444 (takeover from hobostay)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: include tool name in error messages sent to LLM

Format tool errors as "Tool '<name>' failed: <reason>" instead of the
bare "Error: <reason>" so the LLM can identify which tool failed and
reason about alternatives. Does not short-circuit the agent loop --
errors still flow back to the LLM for reasoning.

Closes nearai#487 (takeover from lustsazeus-lab, PR nearai#530)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: resolve cargo fmt formatting in dispatcher

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
drchirag1991 pushed a commit to drchirag1991/ironclaw that referenced this pull request Apr 8, 2026
)

* fix(wasm): use per-engine cache dirs on Windows to avoid file lock error (nearai#448)

On Windows, multiple wasmtime Engine instances sharing the default
compilation cache directory hit OS error 33 (ERROR_LOCK_VIOLATION)
because Windows holds exclusive file locks on memory-mapped cache
files. This is especially triggered when the Telegram channel WASM
module is loaded at startup and then hot-activated via the Extensions
UI.

Fix by giving each engine its own cache subdirectory on Windows
(~/.cache/ironclaw/wasmtime-tools/ and wasmtime-channels/). On
Unix the shared default cache continues to work as before.

Also adds Windows CI jobs (cargo check + clippy across all feature
flag combinations) to catch Windows-specific issues going forward.

Closes nearai#448

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: silence Windows clippy warnings for platform-gated code

Gate PathBuf import behind #[cfg(unix)] in container.rs (only used
in Unix socket path), suppress unused_mut on conflicts Vec in
channels.rs (mutations are platform-gated), and add cfg gates on
keychain constants and hex_to_bytes that are only used on macOS/Linux.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: escape directory path in TOML cache config to prevent injection

Use double-quoted TOML strings with backslash and double-quote
escaping for the cache directory path, preventing breakage or
injection when paths contain special characters (e.g. single
quotes on Unix, backslashes on Windows).

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: resolve cargo fmt formatting errors

Fix import ordering in container.rs and line wrapping in runtime.rs
to pass the CI formatting check.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(ci): restore Path import for all platforms, keep PathBuf unix-only

Path is used in non-cfg-gated functions (lines 148, 244) so it must
be available on all platforms. Only PathBuf is unix-specific.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: use RFC 5737 TEST-NET-1 IPs for reliable network failure tests

Replace localhost/loopback addresses with 192.0.2.1 (TEST-NET-1) in
network failure tests so they work consistently behind HTTP proxies.
Tighten the catalog.rs error assertion to avoid matching any string
containing "error".

Closes nearai#444 (takeover from hobostay)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: include tool name in error messages sent to LLM

Format tool errors as "Tool '<name>' failed: <reason>" instead of the
bare "Error: <reason>" so the LLM can identify which tool failed and
reason about alternatives. Does not short-circuit the agent loop --
errors still flow back to the LLM for reasoning.

Closes nearai#487 (takeover from lustsazeus-lab, PR nearai#530)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: resolve cargo fmt formatting in dispatcher

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: high Safety, secrets, auth, or critical infrastructure scope: agent Agent core (agent loop, router, scheduler) scope: channel/wasm WASM channel runtime scope: ci CI/CD workflows scope: sandbox Docker sandbox scope: secrets Secrets management scope: setup Onboarding / setup scope: tool/wasm WASM tool sandbox size: L 200-499 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: agent returns raw "[Called tool ...]" text when all tool call attempts fail

2 participants