Skip to content

refactor(host-runtime): isolate pre-authorize runtime-policy+trust seam (§5.3.2 authority-fold, step 1) - #6309

Merged
ilblackdragon merged 2 commits into
mainfrom
authority-fold-step1
Jul 20, 2026
Merged

ilblackdragon merged 2 commits into
mainfrom
authority-fold-step1

Conversation

@ilblackdragon

Copy link
Copy Markdown
Member

Summary

Step 1 of the capability down-path "authority as a fold" slice (design doc §5.3.2). Per the 2026-07-20 §14 feasibility finding (#6307), the request-side mirror DTOs can't retire per-hop because they carry the pre-auth ExecutionContext envelope; the load-bearing first slice is folding envelope derivation into the kernel authorize(). This is the opening, safe move toward that.

It isolates the start of the pre-authorize derivation — the runtime-policy gate + trust evaluation (context.trust) — into one named seam, DefaultHostRuntime::open_pre_authorization, and routes the two byte-identical entry points (invoke_capability, spawn_capability) through it. De-dups the inline copies and names the unit a later slice lifts across the crate boundary into the kernel fold.

Behavior preservation (this is the authorization path — read carefully)

  • invoke_capability keeps its two distinct latency-trace labels (invoke_capability_policy_rejected / invoke_capability_trust_rejected) by matching the returned gate discriminant — metrics unchanged.
  • spawn_capability keeps its no-latency-trace reject path.
  • Only change: the two paths' debug! message text is consolidated into the seam (log text, not a metric or behavior).
  • resume_capability / auth_resume_capability are deliberately not folded in — their reject paths carry an extra blocked-resume side effect (fail_matching_blocked_resume_on_preflight_error); they fold in a later step.
  • No DTO retired; FROZEN_COLLAPSE_DTOS unchanged (mirror retirement comes only after the full fold lands).

Verification

  • cargo test -p ironclaw_host_runtime --all-features — all green (347 + others)
  • cargo clippy -p ironclaw_host_runtime --all-targets --all-features -- -D warnings — clean
  • cargo test -p ironclaw_architecture --test reborn_capability_dto_collapse_ratchet — green
  • cargo test --test reborn_integration_greeting — green (invoke path end-to-end)
  • cargo fmt --all --check — clean

Why draft

This is the first of a multi-step, security-critical slice. Opening as draft so the seam shape can be reviewed before the subsequent steps (fold in resume/auth_resume with their side-effect; then the cross-crate lift of the full derivation into the kernel authorize(); then mirror retirement). Left as a small, independently-reviewable, behavior-preserving increment on purpose.

🤖 Generated with Claude Code

…t seam (§5.3.2 authority-fold step 1)

First step of the capability down-path "authority as a fold" slice (design doc
§5.3.2; the load-bearing first slice per the 2026-07-20 §14 feasibility finding —
the request mirrors carry the pre-auth ExecutionContext envelope, so the fold that
moves envelope derivation into the kernel `authorize()` must land before any mirror
retires).

This commit isolates the *opening* of that pre-authorize derivation — the
runtime-policy gate + trust evaluation (setting `context.trust`) — into one named
seam, `DefaultHostRuntime::open_pre_authorization`, and routes the two
byte-identical entry points (`invoke_capability`, `spawn_capability`) through it.
It de-dups those two inline copies and names the unit a later slice lifts across
the crate boundary into the kernel fold.

Behavior-preserving:
- `invoke_capability` keeps its two distinct latency-trace labels
  (`invoke_capability_policy_rejected` / `invoke_capability_trust_rejected`) by
  matching the returned gate discriminant.
- `spawn_capability` keeps its no-latency-trace reject path.
- Only change: the two paths' `debug!` message *text* is consolidated into the
  seam (a log-text change, not a metric/behavior change).
- `resume_capability` / `auth_resume_capability` are deliberately NOT folded in:
  their reject paths carry an extra blocked-resume side effect
  (`fail_matching_blocked_resume_on_preflight_error`) and fold in a later step.
- No DTO retired; `FROZEN_COLLAPSE_DTOS` unchanged.

Verified: `cargo test -p ironclaw_host_runtime --all-features` (all green),
`cargo clippy -p ironclaw_host_runtime --all-targets --all-features -- -D warnings`
clean, `cargo test -p ironclaw_architecture --test reborn_capability_dto_collapse_ratchet`
green, `cargo test --test reborn_integration_greeting` green, fmt clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ironloopai

ironloopai Bot commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

🔎 IronLoop Review Status

Head: ce8dab721e2bd09136d97c8e281102891555bf47
Result: Reviewer output needs human attention or validation.
Next: Review the flagged rows before merging.
Updated: 2026-07-20T06:33:32.519Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Completed Needs validation 0 blocking findings / 2 notes; needs validation 2026-07-20T06:33:32.510Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Needs validation; 0 blocking findings; Static review found the authorization refactor preserves the policy/trust ordering, invoke latency labels, and resume/auth-resume blocked-run failure side effects. Two documentati…
Recent activity
Time Reviewer State Detail
2026-07-20T05:55:24.796Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
2026-07-20T06:13:42.412Z ironloop/common-reviewer (reviewer) Superseded A newer PR head replaced this review (ce8dab7).
2026-07-20T06:29:33.166Z ironloop/common-reviewer (reviewer) Queued Accepted review request for head ce8dab7.
2026-07-20T06:29:33.166Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-20T06:29:33.533Z ironloop/common-reviewer (reviewer) Started Reviewer worker started.
2026-07-20T06:29:36.194Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (merge_ref) at f03f7a2.
2026-07-20T06:33:32.510Z ironloop/common-reviewer (reviewer) Result captured Needs validation; 0 blocking findings.
2026-07-20T06:33:32.510Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent>
Run metadata

Admission: webhook accepted the request and IronLoop persisted reviewer state before this projection.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6309 July 20, 2026 05:51 Destroyed
@github-actions github-actions Bot added size: M 50-199 changed lines risk: low Changes to docs, tests, or low-risk modules labels Jul 20, 2026
@coderabbitai

coderabbitai Bot commented Jul 20, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 897ff5f6-fb59-484e-a5d0-aed31cd3b453

📥 Commits

Reviewing files that changed from the base of the PR and between 32f2363 and ce8dab7.

📒 Files selected for processing (1)
  • crates/ironclaw_host_runtime/src/production.rs

📝 Walkthrough

Summary by CodeRabbit

  • Bug Fixes
    • Standardized pre-authorization checks across capability invocation, spawning, resuming, and authentication-resuming flows.
    • Improved handling of runtime-policy and host-trust rejections with clear capability outcomes.
    • Ensured blocked operations transition correctly when pre-authorization fails.
    • Improved latency reporting for rejected capability requests.

Walkthrough

DefaultHostRuntime centralizes runtime-policy and host-trust pre-authorization, then routes all four capability dispatch entry points through the shared gate. Rejections return prepared outcomes, with resume paths preserving blocked-transition failure handling.

Changes

Pre-authorization dispatch

Layer / File(s) Summary
Centralized pre-authorization gate
crates/ironclaw_host_runtime/src/production.rs
Adds open_pre_authorization and PreAuthorizationRejected to unify policy enforcement, trust evaluation, context updates, and rejection outcomes.
Capability dispatch integration
crates/ironclaw_host_runtime/src/production.rs
Updates invoke, spawn, resume, and auth-resume paths to use the shared gate; resume paths retain blocked-transition failure side effects.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant CapabilityCaller
  participant DefaultHostRuntime
  participant RuntimePolicy
  participant HostTrust
  participant BlockedTransition
  CapabilityCaller->>DefaultHostRuntime: Dispatch capability
  DefaultHostRuntime->>RuntimePolicy: enforce_runtime_policy
  RuntimePolicy-->>DefaultHostRuntime: Policy result
  DefaultHostRuntime->>HostTrust: evaluate_invocation_trust
  HostTrust-->>DefaultHostRuntime: Trust result
  DefaultHostRuntime->>BlockedTransition: Fail matching blocked state on resume rejection
  DefaultHostRuntime-->>CapabilityCaller: RuntimeCapabilityOutcome
Loading

Possibly related PRs

Suggested reviewers: serrrfirat, henrypark133, think-in-universe

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning It has summary and verification, but misses required template sections like Change Type, Linked Issue, Security Impact, rollback, and the trust-boundary checklist. Add the missing headings and fill in Change Type, Linked Issue, Security Impact, Reborn checklist, Database Impact, Blast Radius, Rollback Plan, Review Follow-Through, and track.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title matches the refactor and clearly describes the host-runtime pre-authorization seam extraction.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the contributor: core 20+ merged PRs label Jul 20, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request refactors the pre-authorization logic in DefaultHostRuntime by consolidating the runtime policy enforcement and trust evaluation steps into a new helper method, open_pre_authorization. This helper returns a new internal enum, PreAuthorizationRejected, which is then handled in both invoke_capability and spawn_capability to reduce code duplication. The feedback suggests deriving Debug on the newly introduced PreAuthorizationRejected enum to improve maintainability, observability, and ease of testing.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment on lines +459 to 462
enum PreAuthorizationRejected {
RuntimePolicy(Box<RuntimeCapabilityOutcome>),
Trust(Box<RuntimeCapabilityOutcome>),
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

For better maintainability, observability, and ease of testing, it is highly recommended to derive Debug on the internal PreAuthorizationRejected enum. Note that if this enum's representation is used for logging or snapshots where compile-time safety for new variants is required, prefer an exhaustive match statement over automated Debug formatting to ensure new variants are consciously classified.

Suggested change
enum PreAuthorizationRejected {
RuntimePolicy(Box<RuntimeCapabilityOutcome>),
Trust(Box<RuntimeCapabilityOutcome>),
}
#[derive(Debug)]
enum PreAuthorizationRejected {
RuntimePolicy(Box<RuntimeCapabilityOutcome>),
Trust(Box<RuntimeCapabilityOutcome>),
}
References
  1. When mapping enum variants to another representation (e.g., strings for logging/snapshots), prefer an exhaustive match statement over automated solutions (like strum or Debug formatting) if the goal is to force a compile-time failure when new variants are added.

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
⚠️ Needs validation 0 0 0 849790ee0a60

Head: 849790ee0a604d5520061934d943c65e826e7a55
Next: Human review or validation is required before merging.

Run details

Status: Current
Needs human: no
Needs validation: yes

Summary

No actionable correctness or security regression found in the focused pre-authorization refactor. Static tracing confirms the gate order, failure outcomes, invoke latency labels, spawn path, and resume isolation are preserved; runtime validation remains required because Cargo is unavailable here.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.

@ilblackdragon

Copy link
Copy Markdown
Member Author

✅ Ready for merge.

Reviewed — a clean, behavior-preserving refactor. It lifts the shared pre-authorize gates (runtime-policy → trust evaluation → context.trust = ...) out of the byte-identical invoke_capability and spawn_capability paths into one open_pre_authorization, returning Result<TrustDecision, PreAuthorizationRejected>. Verified:

  • Behavior preserved: context.trust is still set only on success; each caller still emits its own per-entry-point latency trace (invoke_capability_{policy,trust}_rejected on invoke; spawn had none and still has none) and returns the same runtime_policy_failure / trust_evaluation_failure outcome. The only change is the consolidated debug! text ("before authorization"), which the PR calls out — logs aren't a contract.
  • resume/auth_resume correctly excluded — their reject paths carry the extra fail_matching_blocked_resume_on_preflight_error side effect, so folding them would change behavior.
  • RuntimeCapabilityOutcome is boxed in the reject enum (avoids large_enum_variant).

Validation: cargo clippy -p ironclaw_host_runtime --features test-support,libsql --all-targets clean; full ironclaw_host_runtime test suite (65 tests) green. CI green (0 fail).

@railway-app

railway-app Bot commented Jul 20, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-6309 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 20, 2026 at 6:25 am

…orize seam (authority-fold step 2/4)

Folds the remaining two dispatch entry points into `open_pre_authorization`. The
seam's reject now carries `error_kind: &'static str` so `resume_capability` and
`auth_resume_capability` drive their respective blocked-resume failure side
effects (`fail_matching_blocked_resume_on_preflight_error` /
`fail_matching_blocked_auth_resume_on_preflight_error`) before returning the
outcome — behavior-preserving. All four entry points now share the one seam for
the runtime-policy + trust gates; the per-gate reject side effects are the same
in both gates of a resume path, so they collapse to one arm.

Verified: host_runtime tests green, clippy -D warnings clean, group_journeys +
group_approvals (gate resume + auth-resume) green, fmt clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6309 July 20, 2026 06:13 Destroyed
@github-actions github-actions Bot added size: L 200-499 changed lines and removed size: M 50-199 changed lines labels Jul 20, 2026
@ilblackdragon
ilblackdragon marked this pull request as ready for review July 20, 2026 06:29
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
⚠️ Needs validation 0 2 1 ce8dab721e2b

Head: ce8dab721e2bd09136d97c8e281102891555bf47
Next: Human review or validation is required before merging.

Run details

Status: Current
Needs human: no
Needs validation: yes

Summary

Static review found the authorization refactor preserves the policy/trust ordering, invoke latency labels, and resume/auth-resume blocked-run failure side effects. Two documentation/description drifts need correction. Focused Rust validation could not run because cargo is unavailable in this environment.

Findings

Blocking: 0 / Notes: 2

Non-blocking notes (2)
1. 💬 [MEDIUM] Restore the corrected authority-fold sequence

Location: docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md:2292-2303
This replaces the base branch's feasibility finding with the earlier D1→D5 sequence. That finding established that retiring the request mirrors before folding authority-envelope derivation into authorize() can lose or re-mint correlation, grants, mounts, trust, and actor information. Retain the corrected sequence and record this seam as its first step; otherwise this design note directs follow-up work toward the unsafe ordering the PR summary says was ruled out.

2. 💬 [LOW] Update the PR description for the resumed paths

Location: No specific file location
The PR description says resume_capability and auth_resume_capability were deliberately excluded, but the supplied head routes both through open_pre_authorization (production.rs:781 and :876) and preserves their blocked-run failure side effects. Update the title/body and verification summary so reviewers and release notes describe the complete change.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.
Inline review fallback

Inline comment projection fell back to a body-only PR Review because GitHub rejected the inline payload.
Reason: Unprocessable Entity: "Path could not be resolved" - https://docs.github.com/rest/pulls/reviews#create-a-review-for-a-pull-request

IronLoop preserved the inline review comment payloads below instead of dropping them.

Inline fallback 1: docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md:2292

This reinstates the old D1→D5 plan while deleting the base branch's feasibility finding that D1–D4 cannot safely precede the authority fold. Please retain the corrected sequence and record this seam as the first step; otherwise the design note directs future work toward losing/re-minting pre-authorization authority inputs.

@ilblackdragon

Copy link
Copy Markdown
Member Author

✅ Re-confirmed ready on the updated head ce8dab72 (the refactor now also folds resume/auth_resume — "step 2/4").

Re-reviewed the extension: resume_capability and auth_resume_capability now route through open_pre_authorization too, and both preserve their blocked-run failure side effect — each reject path still calls fail_matching_blocked_{resume,auth_resume}_on_preflight_error(...) (the enum now carries error_kind for that) and returns the same runtime_policy_failure/trust_evaluation_failure outcome. context.trust is still set only on success. Only the debug! text is consolidated. Behavior-preserving across all four entry points.

Validation on this head: cargo clippy -p ironclaw_host_runtime --features test-support,libsql --all-targets clean; full ironclaw_host_runtime test suite green. CI 0 fail.

On the 2 non-blocking notes:

  • Note 1 (design-doc authority-fold sequence) looks like a base-diff artifact: this PR changes only crates/ironclaw_host_runtime/src/production.rs (gh pr diff --name-only), not docs/reborn/…-dto-dyn-local.md, so it isn't altering that sequence here.
  • Note 2 (PR description) is fair — the body still says resume/auth_resume were excluded, but this head includes them. Worth a one-line body/title update for release notes.

@github-actions

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 86.22% (319836 / 370969 lines)
  floor:    85.3% (tolerance 0.5pp -> effective floor 84.8%)
  denominator: 370969 lines now vs 320188 at floor capture (+50781 lines, +15.86%) — material change (>5%)

⚠️ 2 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts

Reborn integration-tier coverage

Line coverage (Reborn crates): 86.22% — 319836 / 370969 lines

Per-crate breakdown (65 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 345
ironclaw_runtime_policy 33.84% 89 / 263
ironclaw_event_projections 43.31% 673 / 1554
ironclaw_observability 61.54% 16 / 26
ironclaw_authorization 62.46% 604 / 967
ironclaw_dispatcher 62.88% 83 / 132
ironclaw_mcp 64.89% 595 / 917
ironclaw_triggers 65.44% 2142 / 3273
ironclaw_filesystem 67.78% 3957 / 5838
ironclaw_channel_host 68.65% 219 / 319
ironclaw_memory 69.2% 773 / 1117
ironclaw_reborn_migration 71.64% 1551 / 2165
ironclaw_trust 72.88% 661 / 907
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_reborn_event_store 74.67% 958 / 1283
ironclaw_extractors 74.72% 538 / 720
ironclaw_capabilities 75.72% 2096 / 2768
ironclaw_projects 76.48% 400 / 523
ironclaw_reborn_cli 77% 10247 / 13307
ironclaw_llm 78.36% 20306 / 25915
ironclaw_product_context 78.57% 11 / 14
ironclaw_telegram_extension 80.18% 4842 / 6039
ironclaw_wasm_product_adapters 80.36% 1448 / 1802
ironclaw_process_sandbox 80.65% 671 / 832
ironclaw_first_party_extensions 81.06% 5965 / 7359
ironclaw_memory_native 81.17% 3195 / 3936
ironclaw_events 81.95% 1594 / 1945
ironclaw_network 82.98% 673 / 811
ironclaw_reborn_identity 83.59% 433 / 518
ironclaw_processes 83.76% 939 / 1121
ironclaw_secrets 83.79% 2548 / 3041
ironclaw_wasm 84.44% 1069 / 1266
ironclaw_auth 84.81% 3233 / 3812
ironclaw_product_workflow 84.91% 11031 / 12992
ironclaw_reborn_config 85.2% 2055 / 2412
ironclaw_run_state 85.61% 458 / 535
ironclaw_channel_delivery 85.79% 1383 / 1612
ironclaw_common 86.13% 1714 / 1990
ironclaw_threads 86.93% 4708 / 5416
ironclaw_turns 87.05% 14951 / 17175
ironclaw_slack_v2_adapter 87.3% 1491 / 1708
ironclaw_skills 87.58% 4470 / 5104
ironclaw_product_adapter_registry 88.06% 531 / 603
ironclaw_product_adapters 88.1% 3384 / 3841
ironclaw_reborn_traces 88.2% 11946 / 13544
ironclaw_hooks 88.35% 10075 / 11404
ironclaw_host_api 88.65% 4389 / 4951
ironclaw_host_runtime 88.7% 18140 / 20451
ironclaw_reborn_openai_compat 89.21% 3778 / 4235
ironclaw_webui 89.33% 7700 / 8620
ironclaw_extensions 89.38% 2971 / 3324
ironclaw_runner 89.65% 17454 / 19469
ironclaw_telegram_v2_adapter 89.7% 2717 / 3029
ironclaw_reborn_composition 90.09% 74860 / 83091
ironclaw_approvals 90.18% 1598 / 1772
ironclaw_conversations 90.39% 3123 / 3455
ironclaw_event_streams 90.82% 1009 / 1111
ironclaw_resources 91.65% 4476 / 4884
ironclaw_loop_host 92.28% 15997 / 17336
ironclaw_attachments 93.06% 630 / 677
ironclaw_agent_loop 94.95% 9416 / 9917
ironclaw_safety 95.09% 3682 / 3872
ironclaw_outbound 95.52% 3451 / 3613
ironclaw_first_party_extension_ports 95.62% 3672 / 3840

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (3 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-6309 — ce8dab72 Deployed Jul 20, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules size: L 200-499 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant