refactor(host-runtime): isolate pre-authorize runtime-policy+trust seam (§5.3.2 authority-fold, step 1) - #6309
Conversation
…t seam (§5.3.2 authority-fold step 1) First step of the capability down-path "authority as a fold" slice (design doc §5.3.2; the load-bearing first slice per the 2026-07-20 §14 feasibility finding — the request mirrors carry the pre-auth ExecutionContext envelope, so the fold that moves envelope derivation into the kernel `authorize()` must land before any mirror retires). This commit isolates the *opening* of that pre-authorize derivation — the runtime-policy gate + trust evaluation (setting `context.trust`) — into one named seam, `DefaultHostRuntime::open_pre_authorization`, and routes the two byte-identical entry points (`invoke_capability`, `spawn_capability`) through it. It de-dups those two inline copies and names the unit a later slice lifts across the crate boundary into the kernel fold. Behavior-preserving: - `invoke_capability` keeps its two distinct latency-trace labels (`invoke_capability_policy_rejected` / `invoke_capability_trust_rejected`) by matching the returned gate discriminant. - `spawn_capability` keeps its no-latency-trace reject path. - Only change: the two paths' `debug!` message *text* is consolidated into the seam (a log-text change, not a metric/behavior change). - `resume_capability` / `auth_resume_capability` are deliberately NOT folded in: their reject paths carry an extra blocked-resume side effect (`fail_matching_blocked_resume_on_preflight_error`) and fold in a later step. - No DTO retired; `FROZEN_COLLAPSE_DTOS` unchanged. Verified: `cargo test -p ironclaw_host_runtime --all-features` (all green), `cargo clippy -p ironclaw_host_runtime --all-targets --all-features -- -D warnings` clean, `cargo test -p ironclaw_architecture --test reborn_capability_dto_collapse_ratchet` green, `cargo test --test reborn_integration_greeting` green, fmt clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
🔎 IronLoop Review StatusHead: Current reviewers:
Reviewer summaries
Recent activity
Available commands
Run metadataAdmission: webhook accepted the request and IronLoop persisted reviewer state before this projection. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
📝 WalkthroughSummary by CodeRabbit
Walkthrough
ChangesPre-authorization dispatch
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant CapabilityCaller
participant DefaultHostRuntime
participant RuntimePolicy
participant HostTrust
participant BlockedTransition
CapabilityCaller->>DefaultHostRuntime: Dispatch capability
DefaultHostRuntime->>RuntimePolicy: enforce_runtime_policy
RuntimePolicy-->>DefaultHostRuntime: Policy result
DefaultHostRuntime->>HostTrust: evaluate_invocation_trust
HostTrust-->>DefaultHostRuntime: Trust result
DefaultHostRuntime->>BlockedTransition: Fail matching blocked state on resume rejection
DefaultHostRuntime-->>CapabilityCaller: RuntimeCapabilityOutcome
Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 3 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (3 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Code Review
This pull request refactors the pre-authorization logic in DefaultHostRuntime by consolidating the runtime policy enforcement and trust evaluation steps into a new helper method, open_pre_authorization. This helper returns a new internal enum, PreAuthorizationRejected, which is then handled in both invoke_capability and spawn_capability to reduce code duplication. The feedback suggests deriving Debug on the newly introduced PreAuthorizationRejected enum to improve maintainability, observability, and ease of testing.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
| enum PreAuthorizationRejected { | ||
| RuntimePolicy(Box<RuntimeCapabilityOutcome>), | ||
| Trust(Box<RuntimeCapabilityOutcome>), | ||
| } |
There was a problem hiding this comment.
For better maintainability, observability, and ease of testing, it is highly recommended to derive Debug on the internal PreAuthorizationRejected enum. Note that if this enum's representation is used for logging or snapshots where compile-time safety for new variants is required, prefer an exhaustive match statement over automated Debug formatting to ensure new variants are consciously classified.
| enum PreAuthorizationRejected { | |
| RuntimePolicy(Box<RuntimeCapabilityOutcome>), | |
| Trust(Box<RuntimeCapabilityOutcome>), | |
| } | |
| #[derive(Debug)] | |
| enum PreAuthorizationRejected { | |
| RuntimePolicy(Box<RuntimeCapabilityOutcome>), | |
| Trust(Box<RuntimeCapabilityOutcome>), | |
| } |
References
- When mapping enum variants to another representation (e.g., strings for logging/snapshots), prefer an exhaustive
matchstatement over automated solutions (likestrumorDebugformatting) if the goal is to force a compile-time failure when new variants are added.
There was a problem hiding this comment.
⚠️ IronLoop Review: reviewer
Review at a glance
| Verdict | Blocking | Notes | Inline | Head |
|---|---|---|---|---|
| 0 | 0 | 0 | 849790ee0a60 |
Head: 849790ee0a604d5520061934d943c65e826e7a55
Next: Human review or validation is required before merging.
Run details
Status: Current
Needs human: no
Needs validation: yes
Summary
No actionable correctness or security regression found in the focused pre-authorization refactor. Static tracing confirms the gate order, failure outcomes, invoke latency labels, spawn path, and resume isolation are preserved; runtime validation remains required because Cargo is unavailable here.
Findings
None.
Developer follow-up
After fixing this feedback:
- Push the fix to this PR branch.
- Re-run this reviewer with
@ironloopai review --agent reviewerif you only changed this reviewer's findings. - Re-run all reviewers with
@ironloopai reviewwhen the fix may affect multiple areas.
|
✅ Ready for merge. Reviewed — a clean, behavior-preserving refactor. It lifts the shared pre-authorize gates (runtime-policy → trust evaluation →
Validation: |
|
🚅 Deployed to the ironclaw-pr-6309 environment in ironclaw-ci-preview
|
…orize seam (authority-fold step 2/4) Folds the remaining two dispatch entry points into `open_pre_authorization`. The seam's reject now carries `error_kind: &'static str` so `resume_capability` and `auth_resume_capability` drive their respective blocked-resume failure side effects (`fail_matching_blocked_resume_on_preflight_error` / `fail_matching_blocked_auth_resume_on_preflight_error`) before returning the outcome — behavior-preserving. All four entry points now share the one seam for the runtime-policy + trust gates; the per-gate reject side effects are the same in both gates of a resume path, so they collapse to one arm. Verified: host_runtime tests green, clippy -D warnings clean, group_journeys + group_approvals (gate resume + auth-resume) green, fmt clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
There was a problem hiding this comment.
⚠️ IronLoop Review: reviewer
Review at a glance
| Verdict | Blocking | Notes | Inline | Head |
|---|---|---|---|---|
| 0 | 2 | 1 | ce8dab721e2b |
Head: ce8dab721e2bd09136d97c8e281102891555bf47
Next: Human review or validation is required before merging.
Run details
Status: Current
Needs human: no
Needs validation: yes
Summary
Static review found the authorization refactor preserves the policy/trust ordering, invoke latency labels, and resume/auth-resume blocked-run failure side effects. Two documentation/description drifts need correction. Focused Rust validation could not run because cargo is unavailable in this environment.
Findings
Blocking: 0 / Notes: 2
Non-blocking notes (2)
1. 💬 [MEDIUM] Restore the corrected authority-fold sequence
Location: docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md:2292-2303
This replaces the base branch's feasibility finding with the earlier D1→D5 sequence. That finding established that retiring the request mirrors before folding authority-envelope derivation into authorize() can lose or re-mint correlation, grants, mounts, trust, and actor information. Retain the corrected sequence and record this seam as its first step; otherwise this design note directs follow-up work toward the unsafe ordering the PR summary says was ruled out.
2. 💬 [LOW] Update the PR description for the resumed paths
Location: No specific file location
The PR description says resume_capability and auth_resume_capability were deliberately excluded, but the supplied head routes both through open_pre_authorization (production.rs:781 and :876) and preserves their blocked-run failure side effects. Update the title/body and verification summary so reviewers and release notes describe the complete change.
Developer follow-up
After fixing this feedback:
- Push the fix to this PR branch.
- Re-run this reviewer with
@ironloopai review --agent reviewerif you only changed this reviewer's findings. - Re-run all reviewers with
@ironloopai reviewwhen the fix may affect multiple areas.
Inline review fallback
Inline comment projection fell back to a body-only PR Review because GitHub rejected the inline payload.
Reason: Unprocessable Entity: "Path could not be resolved" - https://docs.github.com/rest/pulls/reviews#create-a-review-for-a-pull-request
IronLoop preserved the inline review comment payloads below instead of dropping them.
Inline fallback 1: docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md:2292
This reinstates the old D1→D5 plan while deleting the base branch's feasibility finding that D1–D4 cannot safely precede the authority fold. Please retain the corrected sequence and record this seam as the first step; otherwise the design note directs future work toward losing/re-minting pre-authorization authority inputs.
|
✅ Re-confirmed ready on the updated head Re-reviewed the extension: Validation on this head: On the 2 non-blocking notes:
|
Coverage ratchetReborn integration-tier coverageLine coverage (Reborn crates): 86.22% — 319836 / 370969 lines Per-crate breakdown (65 crates, lowest-covered first)
This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors. Exemptions (3 entry/entries excluded from the accounting above)
|
Summary
Step 1 of the capability down-path "authority as a fold" slice (design doc §5.3.2). Per the 2026-07-20 §14 feasibility finding (#6307), the request-side mirror DTOs can't retire per-hop because they carry the pre-auth
ExecutionContextenvelope; the load-bearing first slice is folding envelope derivation into the kernelauthorize(). This is the opening, safe move toward that.It isolates the start of the pre-authorize derivation — the runtime-policy gate + trust evaluation (
context.trust) — into one named seam,DefaultHostRuntime::open_pre_authorization, and routes the two byte-identical entry points (invoke_capability,spawn_capability) through it. De-dups the inline copies and names the unit a later slice lifts across the crate boundary into the kernel fold.Behavior preservation (this is the authorization path — read carefully)
invoke_capabilitykeeps its two distinct latency-trace labels (invoke_capability_policy_rejected/invoke_capability_trust_rejected) by matching the returned gate discriminant — metrics unchanged.spawn_capabilitykeeps its no-latency-trace reject path.debug!message text is consolidated into the seam (log text, not a metric or behavior).resume_capability/auth_resume_capabilityare deliberately not folded in — their reject paths carry an extra blocked-resume side effect (fail_matching_blocked_resume_on_preflight_error); they fold in a later step.FROZEN_COLLAPSE_DTOSunchanged (mirror retirement comes only after the full fold lands).Verification
cargo test -p ironclaw_host_runtime --all-features— all green (347 + others)cargo clippy -p ironclaw_host_runtime --all-targets --all-features -- -D warnings— cleancargo test -p ironclaw_architecture --test reborn_capability_dto_collapse_ratchet— greencargo test --test reborn_integration_greeting— green (invoke path end-to-end)cargo fmt --all --check— cleanWhy draft
This is the first of a multi-step, security-critical slice. Opening as draft so the seam shape can be reviewed before the subsequent steps (fold in resume/auth_resume with their side-effect; then the cross-crate lift of the full derivation into the kernel
authorize(); then mirror retirement). Left as a small, independently-reviewable, behavior-preserving increment on purpose.🤖 Generated with Claude Code