Skip to content

ci: build IronClaw reborn release binaries with cargo-dist - #6354

Closed
think-in-universe wants to merge 13 commits into
nearai:mainfrom
think-in-universe:codex/reborn-cargo-dist-release
Closed

think-in-universe wants to merge 13 commits into
nearai:mainfrom
think-in-universe:codex/reborn-cargo-dist-release

Conversation

@think-in-universe

Copy link
Copy Markdown
Collaborator

Summary

Prepare the release pipeline to publish ironclaw-v1.0.0-rc.1 binaries with cargo-dist.

This PR scopes cargo-dist releases to the standalone Reborn CLI package while preserving the public ironclaw-v* tag shape used by previous releases. It also keeps Docker image publication disabled for this release path so the workflow only builds and publishes binary release assets.

Changes

  • Configure cargo-dist for the Reborn CLI binary package and seven release targets:
    • aarch64-apple-darwin
    • aarch64-unknown-linux-gnu
    • aarch64-unknown-linux-musl
    • x86_64-apple-darwin
    • x86_64-unknown-linux-gnu
    • x86_64-unknown-linux-musl
    • x86_64-pc-windows-msvc
  • Require cargo-dist artifact jobs before the host job uploads or creates the GitHub release.
  • Keep generated release artifacts separate from Reborn compile evidence artifacts.
  • Add Reborn CLI cargo-dist and WiX metadata so MSI/archive installers build for the shipping ironclaw binary.
  • Prepare root and Reborn CLI package versions for 1.0.0-rc.1.
  • Update smoke-test contracts for the release workflow without hard-coding individual rc patch attempts.

Validation

  • cargo metadata --locked --no-deps --format-version 1
  • git diff --check -- Cargo.toml crates/ironclaw_reborn_cli/Cargo.toml Cargo.lock .github/workflows/release.yml crates/ironclaw_reborn_cli/tests/smoke.rs wix/main.wxs

Notes

After this lands, pushing tag ironclaw-v1.0.0-rc.1 should run the release workflow and publish cargo-dist release assets. Because this is an rc tag, cargo-dist/GitHub will treat it as a prerelease.

@ironloopai

ironloopai Bot commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

🔎 IronLoop Review Status

Head: 37d327a2907124dad016b39640898f62974b0206
Result: One or more review results were superseded by a newer PR head.
Next: Run @ironloopai review on the latest PR head.
Updated: 2026-07-20T14:55:57.515Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Superseded N/A N/A 2026-07-20T14:55:57.505Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Superseded by a newer PR head. New head: 37d327a. Previous verdict: Changes requested.
Recent activity
Time Reviewer State Detail
2026-07-20T14:44:50.601Z ironloop/common-reviewer (reviewer) Queued Accepted review request for head fe73078.
2026-07-20T14:44:50.601Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-20T14:44:50.936Z ironloop/common-reviewer (reviewer) Started Reviewer worker started.
2026-07-20T14:44:54.320Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (merge_ref) at 7e1f985.
2026-07-20T14:48:42.183Z ironloop/common-reviewer (reviewer) Deduplicated Repeated trigger reused the existing reviewer job.
2026-07-20T14:50:54.516Z ironloop/common-reviewer (reviewer) Result captured Changes requested; 2 blocking findings.
2026-07-20T14:50:54.516Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
2026-07-20T14:55:57.505Z ironloop/common-reviewer (reviewer) Superseded A newer PR head replaced this review (37d327a).
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent>
Run metadata

Admission: webhook accepted the request and IronLoop persisted reviewer state before this projection.

@github-actions github-actions Bot added scope: ci CI/CD workflows scope: docs Documentation scope: dependencies Dependency updates size: M 50-199 changed lines labels Jul 20, 2026
@coderabbitai

coderabbitai Bot commented Jul 20, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Summary by CodeRabbit

  • New Features

    • Added automated distribution support for the standalone Reborn ironclaw binary via cargo-dist.
    • Expanded release packaging formats to include Windows installers (shell, PowerShell, MSI).
    • Updated ironclaw and the Reborn CLI versions to 1.0.0-rc.1.
  • Improvements

    • Refined the release workflow to streamline planning/build/upload, keep Docker publication disabled, and tighten publishing gating and validation outcomes.
  • Documentation

    • Updated release workflow documentation to match the new artifact publishing and validation policy.
  • Tests

    • Strengthened tag-only release smoke validation to cover the cargo-dist publish flow and version consistency.

Walkthrough

The release configuration now publishes the standalone Reborn CLI through cargo-dist, aligns workspace and CLI versions at 1.0.0-rc.1, updates artifact gating, and expands smoke tests and documentation for the tag-release path.

Changes

Reborn release publication

Layer / File(s) Summary
Release package contract
Cargo.toml, crates/ironclaw_reborn_cli/Cargo.toml
Workspace and CLI versions are aligned, cargo-dist is scoped to the Reborn package, distribution is enabled, and WiX metadata is added.
Cargo-dist workflow orchestration
.github/workflows/release.yml
The workflow uses cargo-dist planning, updates artifact and host gating, removes the legacy compile dependency, and keeps WASM publication disabled.
Release validation and documentation
.github/workflows/README.md, crates/ironclaw_reborn_cli/tests/smoke.rs
Documentation and smoke tests assert the cargo-dist plan/build/upload path, metadata coherence, and updated WASM and registry-checksum gates.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Possibly related issues

  • nearai/ironclaw issue 6079 — The changes implement its cargo-dist/Reborn CLI release-packaging scope.

Suggested reviewers: ilblackdragon

Sequence Diagram(s)

sequenceDiagram
  participant ReleaseTag
  participant CargoDistPlan
  participant ArtifactBuilds
  participant Host
  ReleaseTag->>CargoDistPlan: plan standalone Reborn CLI release
  CargoDistPlan->>ArtifactBuilds: build local and global artifacts
  ArtifactBuilds->>Host: pass successful artifacts
  Host->>ReleaseTag: publish release metadata and binaries
Loading
🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description covers the main change, but it omits most required template sections and uses prose instead of the requested summary bullets. Fill in the template sections: 2-5 summary bullets, change type, linked issue, validation, security, trust-boundary, DB impact, blast radius, rollback, review follow-through, and review track.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title is conventional-commits style and accurately summarizes the cargo-dist release binary work.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Jul 20, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request configures cargo-dist and WiX installer settings to release the standalone ironclaw_reborn_cli binary (under the display name "ironclaw") instead of the legacy packages. It bumps package versions to 1.0.0-rc.1, updates release CI expectations in the smoke tests, and simplifies the WiX installer configuration by targeting ironclaw.exe and removing legacy binaries. There are no review comments, so I have no feedback to provide.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@think-in-universe think-in-universe changed the title [codex] Build IronClaw release binaries with cargo-dist ci: build IronClaw reborn release binaries with cargo-dist Jul 20, 2026
@think-in-universe
think-in-universe marked this pull request as ready for review July 20, 2026 14:48
Copilot AI review requested due to automatic review settings July 20, 2026 14:48

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@think-in-universe

Copy link
Copy Markdown
Collaborator Author

@claude review

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

❌ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
❌ Changes requested 2 0 2 fe73078c1718

Head: fe73078c1718192ca2885a7708d24e556d56d9e1
Next: Fix the blocking findings, push the PR branch, then re-run this reviewer.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

Blocked: cargo-dist cannot select the allow-listed Reborn CLI from the retained tag format, and the Windows MSI template is placed outside the CLI package cargo-wix builds.

Findings

Blocking: 2 / Notes: 0

Blocking findings

1. ❌ [HIGH] Release tag selects the excluded root package

Location: Cargo.toml:628
ironclaw-v1.0.0-rc.1 is a singular cargo-dist tag for the root package named ironclaw. Since this allow-list excludes that package and retains only ironclaw_reborn_cli, cargo-dist filters out the CLI as tag-not-matched and has no release to plan. The enabled plan job will fail before any assets are built. Align the tag/selection scheme so this public tag resolves to the selected CLI, and add an executable dist plan --tag=... regression check.

2. ❌ [HIGH] Reborn MSI template is in the wrong package directory

Location: wix/main.wxs:60
cargo-dist invokes cargo-wix with crates/ironclaw_reborn_cli/Cargo.toml; cargo-wix searches for WXS files under crates/ironclaw_reborn_cli/wix/. This root-level template is therefore ignored, and the CLI crate has no WXS file, causing the Windows artifact build to fail with no WXS files to create an installer. Place/regenerate the adapted template in the CLI crate (and preserve the root template if legacy MSI creation remains supported).

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.

Comment thread Cargo.toml
allow-dirty = ["ci", "msi"]
# Release only the standalone Reborn CLI through cargo-dist. The workspace root
# still contains the legacy package named `ironclaw`, so keep selection explicit.
packages = ["ironclaw_reborn_cli"]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ironclaw-v1.0.0-rc.1 is parsed as a singular tag for the root ironclaw package. This allow-list excludes that root package, so cargo-dist also rejects the Reborn CLI as tag-not-matched and the enabled plan job has nothing to release. Please validate the exact public tag with dist plan --tag=... after changing the selection scheme.

Comment thread wix/main.wxs
@@ -60,7 +60,7 @@

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cargo-dist builds this MSI using the Reborn CLI manifest, so cargo-wix searches crates/ironclaw_reborn_cli/wix/*.wxs, not this root directory. No WXS exists there, making the Windows artifact job fail. Move or regenerate this template under the CLI crate.

Copilot AI review requested due to automatic review settings July 20, 2026 14:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
Cargo.toml (1)

70-70: 🎯 Functional Correctness | 🟠 Major

Fix the cargo-dist tag/package selection mismatch.

The preserved tag ironclaw-v1.0.0-rc.1 selects the root ironclaw package, but the dist allow-list selects only ironclaw_reborn_cli. Make the exact tag resolve to the Reborn CLI, then verify:

cargo dist plan --tag=ironclaw-v1.0.0-rc.1
  • Cargo.toml#L70-L70: avoid making the root package the singular tag target, or configure an explicit mapping.
  • Cargo.toml#L625-L632: align the cargo-dist package selection with the preserved public tag.

This repeats the prior review finding. (axodotdev.github.io)

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@Cargo.toml` at line 70, Align the preserved tag target and cargo-dist
allow-list so ironclaw-v1.0.0-rc.1 resolves to the ironclaw_reborn_cli package
rather than the root ironclaw package. Update Cargo.toml lines 70-70 to avoid
making the root package the singular tag target or add an explicit mapping, and
update Cargo.toml lines 625-632 to select the Reborn CLI; verify with cargo dist
plan --tag=ironclaw-v1.0.0-rc.1.

Source: MCP tools

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/ironclaw_reborn_cli/tests/smoke.rs`:
- Around line 359-360: Remove the broad !workspace_manifest.contains("\"npm\"")
check from the smoke test and rely on the exact installers assertion to verify
npm is excluded, or scope the npm check specifically to the cargo-dist metadata
section. Update the assertion near the workspace_manifest checks in the smoke
test without changing unrelated manifest validation.

---

Outside diff comments:
In `@Cargo.toml`:
- Line 70: Align the preserved tag target and cargo-dist allow-list so
ironclaw-v1.0.0-rc.1 resolves to the ironclaw_reborn_cli package rather than the
root ironclaw package. Update Cargo.toml lines 70-70 to avoid making the root
package the singular tag target or add an explicit mapping, and update
Cargo.toml lines 625-632 to select the Reborn CLI; verify with cargo dist plan
--tag=ironclaw-v1.0.0-rc.1.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 4e50b007-d29a-4d05-a56f-5243eed51542

📥 Commits

Reviewing files that changed from the base of the PR and between fe73078 and 37d327a.

📒 Files selected for processing (2)
  • Cargo.toml
  • crates/ironclaw_reborn_cli/tests/smoke.rs

Comment on lines +359 to +360
&& workspace_manifest.contains("installers = [\"shell\", \"powershell\", \"msi\"]")
&& !workspace_manifest.contains("\"npm\"")

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Scope the npm assertion to cargo-dist metadata.

!workspace_manifest.contains("\"npm\"") scans the entire root manifest, so an unrelated quoted npm string can fail this release smoke test even when the installer configuration is correct. The exact installers = ["shell", "powershell", "msi"] assertion already excludes npm from the configured installer list; otherwise parse or isolate the dist metadata section.

Proposed fix
             && workspace_manifest.contains("packages = [\"ironclaw_reborn_cli\"]")
             && workspace_manifest.contains("installers = [\"shell\", \"powershell\", \"msi\"]")
-            && !workspace_manifest.contains("\"npm\"")
             && !workspace_manifest.contains("tag-namespace"),
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
&& workspace_manifest.contains("installers = [\"shell\", \"powershell\", \"msi\"]")
&& !workspace_manifest.contains("\"npm\"")
&& workspace_manifest.contains("installers = [\"shell\", \"powershell\", \"msi\"]")
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@crates/ironclaw_reborn_cli/tests/smoke.rs` around lines 359 - 360, Remove the
broad !workspace_manifest.contains("\"npm\"") check from the smoke test and rely
on the exact installers assertion to verify npm is excluded, or scope the npm
check specifically to the cargo-dist metadata section. Update the assertion near
the workspace_manifest checks in the smoke test without changing unrelated
manifest validation.

@think-in-universe

Copy link
Copy Markdown
Collaborator Author

Already resolved in #6327

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: ci CI/CD workflows scope: dependencies Dependency updates scope: docs Documentation size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants