Skip to content

fix(host-runtime): auth-gate fingerprint includes setup; + #6299 CodeRabbit cleanups - #6303

Merged
ilblackdragon merged 5 commits into
mainfrom
refactor/reborn-coderabbit-cleanup-6299
Jul 20, 2026
Merged

ilblackdragon merged 5 commits into
mainfrom
refactor/reborn-coderabbit-cleanup-6299

Conversation

@ilblackdragon

Copy link
Copy Markdown
Member

Summary

Follow-up to #6299 (capability-result collapse), addressing the review findings
that were left for a follow-up so #6299 could land. Two independent commits:

1. fix(host-runtime): include credential setup in the auth-gate fingerprint (IronLoop, blocking)

The deterministic auth-gate id (stable_auth_gate_id) hashed the capability,
required secret handles, and each credential requirement's
provider/requester/provider_scopes — but not its setup
(RuntimeCredentialAccountSetup, including OAuth setup scopes). Two auth
requirements identical except for setup (a ManualToken record vs a later
OAuth/Pairing record, or two OAuth setups with different setup scopes) derived
the same for_auth_gate key. At the loop-host persist seam the write-once
gate-record store then reports GateRecordAlreadyExists and — treating a
deterministic-key collision as a benign byte-identical re-raise — keeps the
stale record; the runner reloads it and renders the wrong authentication
flow.

Fix: fold a canonical setup token into the fingerprint (stable_setup_token,
exhaustive over the enum, OAuth setup scopes sorted). Distinct setups now derive
distinct keys and never reach the collision branch with a stale record.
stable_auth_gate_id is the sole auth-gate fingerprint minter (verified), so
this closes it at the single source. Regression test
auth_required_outcome_changes_gate_when_only_setup_changes varies only
setup and fails before / passes after.

2. refactor(reborn): CodeRabbit test-only cleanups

  • Extract the byte-identical assert_recoverable_failure test helper (in
    local_dev/outbound_delivery.rs + local_dev/project_create.rs) into one
    #[cfg(test)] pub(crate) helper in local_dev.rs.
  • Extract a shared approval_gate_ref(&Resolution) -> LoopGateRef helper in
    ironclaw_runner/tests/hooks_integration.rs, replacing the same
    Blocked::Approval → origin() → LoopGateRef shape repeated 6×.
  • Fix a stale doc comment on RebornCapabilityBackend::gate_record_store in
    tests/integration/support/group.rs (the host-runtime arm always returns Some).

CodeRabbit's Cargo.toml feature-gate nit does not apply: ironclaw_capabilities
has no [features] section and the consumed FilesystemReplayPayloadStore is a
production type, so the bare dev-dependency is correct.

Verification

  • cargo test -p ironclaw_host_runtime --all-features --lib — 347 passed
    (incl. the new auth-gate regression).
  • cargo test -p ironclaw_reborn_composition --lib local_dev — 236 passed.
  • cargo test -p ironclaw_runner --test hooks_integration — 49 passed.
  • cargo clippy -p ironclaw_host_runtime -p ironclaw_loop_host --all-targets --all-features -- -D warnings — clean; cargo fmt --all --check — clean.

🤖 Generated with Claude Code

ilblackdragon and others added 2 commits July 20, 2026 03:17
…cleanups)

Follow-up to #6299 (capability-result collapse). Test-only maintainability
cleanups CodeRabbit flagged; no production behavior change.

- Extract the duplicated `assert_recoverable_failure` test helper (byte-identical
  in `local_dev/outbound_delivery.rs` and `local_dev/project_create.rs`) into one
  `#[cfg(test)] pub(crate)` helper in `local_dev.rs`; both submodule test blocks
  import it.
- Extract a shared `approval_gate_ref(&Resolution) -> LoopGateRef` helper in
  `ironclaw_runner/tests/hooks_integration.rs`, replacing the same
  `Resolution::Blocked(Blocked::Approval) → origin() → LoopGateRef` shape repeated
  6× (centralizing the panic/expect messages).
- Fix a stale doc comment on `RebornCapabilityBackend::gate_record_store` in
  `tests/integration/support/group.rs`: the host-runtime arm always returns `Some`
  (`HostRuntimeCapabilityHarness::gate_record_store`), so only the `Recording`
  backend yields `None`.

CodeRabbit's Cargo.toml feature-gate nit does not apply: `ironclaw_capabilities`
has no `[features]` section, and the consumed `FilesystemReplayPayloadStore` is a
production type, so the bare dev-dependency is correct.

Verified: `cargo test -p ironclaw_reborn_composition --lib local_dev` (236 passed)
and `cargo test -p ironclaw_runner --test hooks_integration` (49 passed).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…int (#6299 IronLoop)

The deterministic auth-gate id (`stable_auth_gate_id`) hashed the capability,
required secret handles, and each credential requirement's
provider/requester/`provider_scopes` — but NOT its `setup`
(`RuntimeCredentialAccountSetup`, including OAuth setup scopes). Two auth
requirements that agree on everything else but differ in setup (e.g. a
ManualToken record vs a later OAuth or Pairing record, or two OAuth setups with
different setup scopes) therefore derived the SAME `for_auth_gate` key.

At the loop-host persist seam the write-once gate-record store then reports
`GateRecordAlreadyExists` and — treating a deterministic-key collision as a
benign byte-identical re-raise — keeps the STALE record. The runner reloads it
and renders the wrong authentication flow (`credential_requirements` from the
first, obsolete record).

Fix: fold a canonical `setup` token into the fingerprint via `stable_setup_token`
(exhaustive match over `RuntimeCredentialAccountSetup`, OAuth setup scopes sorted
to match the `provider_scopes` canonicalization). Distinct setups now derive
distinct keys and never reach the collision branch with a stale record; the
"byte-identical" assumption at `capability_port.rs` is now sound (comment
updated to say why).

Regression test `auth_required_outcome_changes_gate_when_only_setup_changes`
holds provider/requester/`provider_scopes` fixed and varies ONLY `setup`
(ManualToken vs OAuth vs Pairing, plus two OAuth setups with different setup
scopes); it fails before this fix (all share one gate id) and passes after.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ironloopai

ironloopai Bot commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

🔎 IronLoop Review Status

Head: 963f47e3397c78216c9289df970890ee26426ab4
Result: One or more review results were superseded by a newer PR head.
Next: Run @ironloopai review on the latest PR head.
Updated: 2026-07-20T04:00:07.832Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Superseded N/A N/A 2026-07-20T04:00:07.819Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Superseded by a newer PR head. New head: 963f47e.
Recent activity
Time Reviewer State Detail
2026-07-20T03:49:19.801Z ironloop/common-reviewer (reviewer) Result captured Changes requested; 1 blocking finding.
2026-07-20T03:49:19.801Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
2026-07-20T03:56:52.940Z ironloop/common-reviewer (reviewer) Superseded A newer PR head replaced this review (b27540c).
2026-07-20T03:57:05.764Z ironloop/common-reviewer (reviewer) Queued Accepted review request for head b27540c.
2026-07-20T03:57:05.764Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-20T03:57:06.522Z ironloop/common-reviewer (reviewer) Started Reviewer worker started.
2026-07-20T03:57:08.786Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (merge_ref) at 902eaaa.
2026-07-20T04:00:07.819Z ironloop/common-reviewer (reviewer) Superseded A newer PR head replaced this review (963f47e).
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent>
Run metadata

Admission: webhook accepted the request and IronLoop persisted reviewer state before this projection.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6303 July 20, 2026 03:25 Destroyed
@coderabbitai

coderabbitai Bot commented Jul 20, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 653b1f52-58c2-4675-8cda-97a30a84f9ea

📥 Commits

Reviewing files that changed from the base of the PR and between 7c63e05 and b27540c.

📒 Files selected for processing (1)
  • crates/ironclaw_host_runtime/src/production.rs

📝 Walkthrough

Summary by CodeRabbit

  • Bug Fixes

    • Improved stable authentication gate identification to account for full credential setup and OAuth/provider scope differences, preventing collisions (including delimiter-ambiguous scope lists).
    • Clarified deterministic gate-record reuse behavior when a matching record already exists.
  • Tests

    • Added regression coverage to ensure gate IDs change when only credential setup varies, and that the new scope encoding is injective.
    • Updated integration and local-dev tests to use shared helpers for recoverable failure assertions and approval gate reference extraction.
  • Documentation

    • Clarified durable gate-record store behavior across runtime backends.

Walkthrough

stable_auth_gate_id now fingerprints credential setup and canonical scope lists, with regression coverage for setup and delimiter collisions. Test-only assertion and approval gate-reference helpers are centralized, and gate-record documentation is clarified.

Changes

Auth gate identity

Layer / File(s) Summary
Stable credential setup fingerprint
crates/ironclaw_host_runtime/src/production.rs, crates/ironclaw_loop_host/src/capability_port.rs, tests/integration/support/group.rs
Auth gate IDs encode setup variants and scope lists deterministically; tests cover setup and delimiter-ambiguous scope differences, while persistence comments and documentation describe the identity contract.

Test helper consolidation

Layer / File(s) Summary
Shared recoverable failure assertions
crates/ironclaw_reborn_composition/src/runtime/local_dev*
Local-dev tests reuse a shared recoverable-failure assertion while retaining summary extraction behavior.
Approval gate reference extraction
crates/ironclaw_runner/tests/hooks_integration.rs
Approval integration tests reuse a helper that extracts LoopGateRef values and preserve prefix, actor, mint, and TTL assertions.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related PRs

Suggested reviewers: serrrfirat

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description covers summary and validation, but omits most required template sections like change type, security, rollback, and trust-boundary checklist. Add the missing template sections: Change Type, Linked Issue, Security Impact, Reborn Trust-Boundary Checklist, Database Impact, Blast Radius, Rollback Plan, Review Follow-Through, and Review track.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed Conventional-commit style title is aligned with the auth-gate fingerprint fix and reborn cleanup changes.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added size: M 50-199 changed lines risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Jul 20, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request resolves a collision issue in stable_auth_gate_id by incorporating the credential-account setup into the fingerprint token generation, and adds corresponding regression tests. It also refactors test helpers across multiple files to reduce code duplication, such as assert_recoverable_failure and approval_gate_ref. Feedback is provided to optimize stable_setup_token by returning std::borrow::Cow<'static, str> instead of String to avoid unnecessary heap allocations for static variants.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment on lines +2156 to +2168
fn stable_setup_token(setup: &ironclaw_host_api::RuntimeCredentialAccountSetup) -> String {
use ironclaw_host_api::RuntimeCredentialAccountSetup as Setup;
match setup {
Setup::ManualToken => "manual_token".to_string(),
Setup::OAuth { scopes } => {
let mut scopes = scopes.clone();
scopes.sort();
format!("oauth:{}", scopes.join(","))
}
Setup::Pairing => "pairing".to_string(),
Setup::Retired => "retired".to_string(),
}
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

To avoid unnecessary heap allocations for static variants (like ManualToken, Pairing, and Retired), we can return std::borrow::Cow<'static, str> instead of String. This keeps the code efficient and avoids allocating memory for static strings while still allowing dynamic formatting for the OAuth variant.

Suggested change
fn stable_setup_token(setup: &ironclaw_host_api::RuntimeCredentialAccountSetup) -> String {
use ironclaw_host_api::RuntimeCredentialAccountSetup as Setup;
match setup {
Setup::ManualToken => "manual_token".to_string(),
Setup::OAuth { scopes } => {
let mut scopes = scopes.clone();
scopes.sort();
format!("oauth:{}", scopes.join(","))
}
Setup::Pairing => "pairing".to_string(),
Setup::Retired => "retired".to_string(),
}
}
fn stable_setup_token(setup: &ironclaw_host_api::RuntimeCredentialAccountSetup) -> std::borrow::Cow<'static, str> {
use ironclaw_host_api::RuntimeCredentialAccountSetup as Setup;
match setup {
Setup::ManualToken => std::borrow::Cow::Borrowed("manual_token"),
Setup::OAuth { scopes } => {
let mut scopes = scopes.clone();
scopes.sort();
std::borrow::Cow::Owned(format!("oauth:{}", scopes.join(",")))
}
Setup::Pairing => std::borrow::Cow::Borrowed("pairing"),
Setup::Retired => std::borrow::Cow::Borrowed("retired"),
}
}

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
❌ Changes requested 1 0 1 f7fc2f698220

Head: f7fc2f6982203bb3d4b4736c93b9f1bf2bb5b9b7
Next: Fix the blocking findings, push the PR branch, then re-run this reviewer.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

The auth-gate fingerprint still collides for distinct OAuth setup scope vectors containing commas, so the stale gate-record failure remains possible.

Findings

Blocking: 1 / Notes: 0

Blocking findings

1. ❌ [MEDIUM] Encode OAuth setup scopes unambiguously in the gate fingerprint

Location: crates/ironclaw_host_runtime/src/production.rs:2163
scopes.join(",") is not an injective representation. For example, OAuth setups with scopes = ["a,b"] and scopes = ["a", "b"] produce the same token, while provider_scopes and every other fingerprint field can be identical. Setup scopes have no validation here that forbids commas, so these distinct auth flows still derive the same gate key and can hit the GateRecordAlreadyExists path with a stale record. Use an unambiguous canonical encoding (for example, length-prefixed elements or canonical serialized data) and add this collision case to the regression test.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.

Setup::OAuth { scopes } => {
let mut scopes = scopes.clone();
scopes.sort();
format!("oauth:{}", scopes.join(","))

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

join(",") is ambiguous: scopes = ["a,b"] and scopes = ["a", "b"] yield the same setup token. Since setup scopes are not validated to reject commas, these distinct auth flows can still share a gate key and retain a stale GateRecord. Please use an unambiguous canonical encoding and add this regression case.

@railway-app

railway-app Bot commented Jul 20, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-6303 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 20, 2026 at 4:12 am

…6303 IronLoop)

`scopes.join(",")` is not injective: `["a,b"]` and `["a", "b"]` produce the same
token, and setup/provider scopes are unvalidated for commas — so two distinct
OAuth auth flows could still derive the same `auth-{sha256}` gate key and hit the
`GateRecordAlreadyExists` stale-record path.

Add `canonical_scope_list` — sort (scope sets are order-independent) then
length-prefix each element (`<byte_len>:<scope>`) so distinct sets never share
an encoding regardless of characters — and route BOTH the per-requirement
`provider_scopes` and the OAuth `stable_setup_token` scopes through it.

Regression: extended `auth_required_outcome_changes_gate_when_only_setup_changes`
with the `["a,b"]` vs `["a", "b"]` collision case — verified it fails on the old
`join(",")`. clippy + fmt clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6303 July 20, 2026 03:43 Destroyed
@ilblackdragon

Copy link
Copy Markdown
Member Author

Addressed the blocking finding (7c63e0552).

MED — non-injective scope encoding. scopes.join(",") collided ["a,b"] with ["a", "b"], and setup/provider scopes aren't validated for commas — so two distinct OAuth flows could still derive the same auth-{sha256} key and hit the stale-record GateRecordAlreadyExists path.

Added canonical_scope_list: sort (scope sets are order-independent), then length-prefix each element (<byte_len>:<scope>) so distinct sets can never share an encoding regardless of characters. Routed both the per-requirement provider_scopes join and the OAuth stable_setup_token scopes through it (the pre-existing provider_scopes join had the same latent ambiguity).

Regression: extended auth_required_outcome_changes_gate_when_only_setup_changes with the ["a,b"] vs ["a", "b"] collision case — verified it fails on the old join(","). clippy + fmt clean.

(FWIW I'd independently opened #6304 for the original setup-omission finding before spotting this PR — closed it in favor of yours, which is more complete.)

@ironloopai review

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
❌ Changes requested 1 0 1 7c63e055224c

Head: 7c63e055224c0aad8ddf71d91035d453514ed070
Next: Fix the blocking findings, push the PR branch, then re-run this reviewer.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

The auth-gate fingerprint implementation is sound on inspection, but its new provider-scope collision path lacks a regression test.

Findings

Blocking: 1 / Notes: 0

Blocking findings

1. ❌ [MEDIUM] Add a provider_scopes-only collision regression

Location: crates/ironclaw_host_runtime/src/production.rs:2699-2704
This collision case varies Setup::OAuth.scopes, while requirement_with keeps provider_scopes fixed at ["read"]. It therefore still passes if the provider_scopes call at the fingerprint were reverted to join(","), leaving that changed collision path unprotected. Add a case with fixed ManualToken setup and provider_scopes ["a,b"] versus ["a", "b"], asserting distinct gate IDs.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.

// delimiter must not collide with two scopes that join to the same
// string — `["a,b"]` and `["a", "b"]` are DIFFERENT scope sets. Before
// the length-prefixed `canonical_scope_list`, both encoded to "a,b".
let one_comma_scope = gate_id(Setup::OAuth {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This only exercises the OAuth setup-scope encoding; provider_scopes stays fixed. Please add a ManualToken case varying only provider_scopes between ["a,b"] and ["a", "b"], so a regression of that separate fingerprint input is caught.

…ion (#6303 IronLoop)

The existing collision case varied OAuth setup scopes while holding
provider_scopes fixed, so it still passed if only the provider_scopes encoding
were reverted to join(","). Add a fixed-ManualToken case with provider_scopes
["a,b"] vs ["a", "b"] asserting distinct gate ids — verified it fails when only
the provider_scopes call is reverted.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6303 July 20, 2026 03:56 Destroyed
@ilblackdragon

Copy link
Copy Markdown
Member Author

Addressed the follow-up (b27540c09): added a provider_scopes-only collision case (fixed ManualToken setup, provider_scopes ["a,b"] vs ["a", "b"]) so a revert of the provider_scopes encoding alone is caught — verified it fails when only that call is reverted to join(","). clippy + fmt clean.

(The Reborn E2E / WebUI v2 smoke reds look transient — they pass on the sibling PRs #6300/#6291/#6253 and the failed jobs logged no assertion; re-running them.) @ironloopai review

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6303 July 20, 2026 04:00 Destroyed
@github-actions

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 86.2% (319556 / 370720 lines)
  floor:    85.3% (tolerance 0.5pp -> effective floor 84.8%)
  denominator: 370720 lines now vs 320188 at floor capture (+50532 lines, +15.78%) — material change (>5%)

⚠️ 2 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts

Reborn integration-tier coverage

Line coverage (Reborn crates): 86.2% — 319556 / 370720 lines

Per-crate breakdown (65 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 345
ironclaw_runtime_policy 33.84% 89 / 263
ironclaw_event_projections 43.31% 673 / 1554
ironclaw_observability 61.54% 16 / 26
ironclaw_authorization 62.46% 604 / 967
ironclaw_dispatcher 62.88% 83 / 132
ironclaw_mcp 64.89% 595 / 917
ironclaw_triggers 65.44% 2142 / 3273
ironclaw_filesystem 67.78% 3957 / 5838
ironclaw_channel_host 68.65% 219 / 319
ironclaw_memory 69.2% 773 / 1117
ironclaw_reborn_migration 71.64% 1551 / 2165
ironclaw_trust 72.88% 661 / 907
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_reborn_event_store 74.67% 958 / 1283
ironclaw_extractors 74.72% 538 / 720
ironclaw_capabilities 75.72% 2096 / 2768
ironclaw_projects 76.48% 400 / 523
ironclaw_reborn_cli 77% 10247 / 13307
ironclaw_llm 78.36% 20306 / 25915
ironclaw_product_context 78.57% 11 / 14
ironclaw_telegram_extension 80.18% 4842 / 6039
ironclaw_wasm_product_adapters 80.36% 1448 / 1802
ironclaw_process_sandbox 80.65% 671 / 832
ironclaw_first_party_extensions 81.06% 5965 / 7359
ironclaw_memory_native 81.17% 3195 / 3936
ironclaw_events 81.95% 1594 / 1945
ironclaw_network 82.98% 673 / 811
ironclaw_reborn_identity 83.59% 433 / 518
ironclaw_processes 83.76% 939 / 1121
ironclaw_secrets 83.79% 2548 / 3041
ironclaw_wasm 84.44% 1069 / 1266
ironclaw_auth 84.81% 3233 / 3812
ironclaw_product_workflow 84.91% 11031 / 12992
ironclaw_reborn_config 85.2% 2055 / 2412
ironclaw_run_state 85.61% 458 / 535
ironclaw_channel_delivery 85.79% 1383 / 1612
ironclaw_common 86.13% 1714 / 1990
ironclaw_turns 86.7% 14703 / 16958
ironclaw_threads 86.93% 4708 / 5416
ironclaw_slack_v2_adapter 87.3% 1491 / 1708
ironclaw_skills 87.6% 4471 / 5104
ironclaw_product_adapter_registry 88.06% 531 / 603
ironclaw_product_adapters 88.1% 3384 / 3841
ironclaw_reborn_traces 88.2% 11946 / 13544
ironclaw_hooks 88.35% 10075 / 11404
ironclaw_host_api 88.65% 4389 / 4951
ironclaw_host_runtime 88.71% 18120 / 20426
ironclaw_reborn_openai_compat 89.21% 3778 / 4235
ironclaw_webui 89.33% 7700 / 8620
ironclaw_extensions 89.38% 2971 / 3324
ironclaw_runner 89.65% 17454 / 19469
ironclaw_telegram_v2_adapter 89.7% 2717 / 3029
ironclaw_reborn_composition 90.09% 74847 / 83084
ironclaw_approvals 90.18% 1598 / 1772
ironclaw_conversations 90.39% 3123 / 3455
ironclaw_event_streams 90.82% 1009 / 1111
ironclaw_resources 91.65% 4476 / 4884
ironclaw_loop_host 92.28% 15997 / 17336
ironclaw_attachments 93.06% 630 / 677
ironclaw_agent_loop 94.95% 9416 / 9917
ironclaw_safety 95.09% 3682 / 3872
ironclaw_outbound 95.52% 3451 / 3613
ironclaw_first_party_extension_ports 95.62% 3672 / 3840

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (3 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

@ilblackdragon
ilblackdragon merged commit 0e08c59 into main Jul 20, 2026
65 checks passed
@ilblackdragon
ilblackdragon deleted the refactor/reborn-coderabbit-cleanup-6299 branch July 20, 2026 04:18
ilblackdragon added a commit that referenced this pull request Jul 20, 2026
…uest-side) collapse plan (#6306)

§14 status log was stale — it listed the §5.3 five-channel flip as "in flight on
integration/reborn-flip-base" and said "CapabilityOutcome is retained for Stage 2b
to delete", but that work has landed on main:

- Move the §5.3 flip stack from "In flight" to "Merged"; record #6293 (Stage 2b —
  CapabilityOutcome + all result mirrors DELETED), #6299 (the stack squash-landed on
  main, reconciled with #6279/#6277/#6292/#6296), and #6303 (auth-gate setup
  fingerprint fix + injective encoding).
- Fix the Slice C.1 bullet: the Resolution/Blocked/Suspension/HostFailure channel
  enums are now merged too.
- Add the remaining work under "Not started": the Slice C down-path (request-side)
  collapse — the 9 request mirrors still frozen in FROZEN_COLLAPSE_DTOS — with the
  concrete risk-ordered slice sequence (D1 dispatch→Authorized, D2 authorize(&Invocation),
  D3 loop membrane mints Invocation, D4 resume/auth-resume, D5 security-milestone
  seal inline, D6 ratchet-to-empty + measure).

Docs-only; the frozen contract (§1–§13) is unchanged, only the mutable §14 log.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-6303 — 963f47e3 Deployed Jul 20, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant