Skip to content

chore(runner): remove dead libsql-secrets feature and its module - #6377

Closed
ilblackdragon wants to merge 1 commit into
mainfrom
chore/remove-libsql-secrets-dead-feature
Closed

ilblackdragon wants to merge 1 commit into
mainfrom
chore/remove-libsql-secrets-dead-feature

Conversation

@ilblackdragon

Copy link
Copy Markdown
Member

What

Removes the libsql-secrets feature from ironclaw_runner and the secrets module it gated.

Why

The feature gated crates/ironclaw_runner/src/secrets.rs — a libSQL-backed FilesystemSecretStore assembly (build_libsql_reborn_secret_store) intended for a standalone-Reborn secret store. But:

  1. No shipped build enabled it. The only enabler was the CI compile self-test scripts/ci/package-feature-flags.sh:53. No production dependency edge, workflow, or Dockerfile selected it — so the module was dead in every shipped binary (the exact feature-gated-dead-code shape .claude/rules/cargo-features.md warns about).
  2. It was duplicated. The production secret-store assembly already lives in ironclaw_reborn_composition — factory.rs::build_secret_store (line 3566) and open_local_dev_secret_store (line 3612) — which does the same libSQL FilesystemSecretStore + SecretsCrypto wiring and more (credential broker, keychain master-key resolution, source-named error mapping). The runner module's own comment admitted it "mirrors the composition-layer tenant/user rewrite … kept local so this crate does not depend on the composition crate."

The reusable primitives (SecretStore, FilesystemSecretStore, SecretsCrypto) remain in ironclaw_secrets and are untouched — this only removes the unused runner-side wiring shim.

Changes

  • Delete src/secrets.rs and tests/secrets.rs
  • Remove the #[cfg(feature = "libsql-secrets")] pub mod secrets; gate in lib.rs
  • Remove the libsql-secrets [features] entry and its stale comment reference on libsql-restart-tests
  • Drop now-orphaned optional deps ironclaw_secrets and secrecy (Cargo.lock reflects only these two leaving the runner)
  • Remove libsql-secrets from package-feature-flags.sh

libsql and ironclaw_filesystem stay optional — still used by webui-user-store / libsql-restart-tests / filesystem-goal-store.

Behavior / risk

Move-only dead-code removal — behavior unchanged, the module was unreachable in every shipped binary. No regression test applies (nothing production-reachable was altered).

Validation

  • cargo clippy -p ironclaw_runner --all-targets --features libsql-restart-tests,webui-user-store -- -D warnings — clean
  • Workspace feature matrix (both legs, per .claude/rules/review-discipline.md for a removed #[cfg] gate):
    • cargo clippy --all --tests --examples -- -D warnings — clean
    • cargo clippy --all --tests --examples --all-features -- -D warnings — clean
  • scripts/ci/test-package-feature-flags.sh self-test — passes

🤖 Generated with Claude Code

The `libsql-secrets` feature gated `crates/ironclaw_runner/src/secrets.rs`
(a libSQL-backed `FilesystemSecretStore` assembly) that no shipped build
enabled — the only enabler was the CI compile self-test in
`scripts/ci/package-feature-flags.sh`. The production secret-store
assembly already lives in `ironclaw_reborn_composition`
(`factory.rs::build_secret_store` / `open_local_dev_secret_store`), which
does the same work and more, so the runner module was dead duplication.

Removes:
- `src/secrets.rs` and `tests/secrets.rs`
- the `secrets` module gate in `lib.rs`
- the `libsql-secrets` `[features]` entry + its stale comment reference
- now-orphaned optional deps `ironclaw_secrets` and `secrecy`
- `libsql-secrets` from `package-feature-flags.sh`

Behavior unchanged: the module was unreachable in every shipped binary.
Verified with workspace feature-matrix clippy (default + all-features).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ironloopai

ironloopai Bot commented Jul 20, 2026 •

Copy link
Copy Markdown
Contributor

🔎 IronLoop Review Status

Head: c462f769144afa3797889e7bce1433febc397d9a
Result: Reviewer output needs human attention or validation.
Next: Review the flagged rows before merging.
Updated: 2026-07-20T23:37:30.997Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Completed Needs validation 0 blocking findings / 0 notes; needs validation 2026-07-20T23:37:30.989Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Needs validation; 0 blocking findings; Static review found no actionable regression in this focused, mechanical removal (6 files; 560 deletions, 4 additions). Independent Rust compilation could not run because Cargo is…
Recent activity
Time Reviewer State Detail
2026-07-20T23:34:50.578Z ironloop/common-reviewer (reviewer) Queued Accepted review request for head c462f76.
2026-07-20T23:34:50.578Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-20T23:34:50.958Z ironloop/common-reviewer (reviewer) Started Reviewer worker started.
2026-07-20T23:34:54.742Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (merge_ref) at 95888ca.
2026-07-20T23:37:30.989Z ironloop/common-reviewer (reviewer) Result captured Needs validation; 0 blocking findings.
2026-07-20T23:37:30.989Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent>
Run metadata

Admission: webhook accepted the request and IronLoop persisted reviewer state before this projection.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6377 July 20, 2026 23:34 Destroyed
@github-actions github-actions Bot added scope: dependencies Dependency updates size: M 50-199 changed lines risk: low Changes to docs, tests, or low-risk modules labels Jul 20, 2026
@coderabbitai

coderabbitai Bot commented Jul 20, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 50a59d96-22d8-419f-b78e-744d7d4a8571

📥 Commits

Reviewing files that changed from the base of the PR and between 4c1be8a and c462f76.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock, !**/Cargo.lock
📒 Files selected for processing (5)
  • crates/ironclaw_runner/Cargo.toml
  • crates/ironclaw_runner/src/lib.rs
  • crates/ironclaw_runner/src/secrets.rs
  • crates/ironclaw_runner/tests/secrets.rs
  • scripts/ci/package-feature-flags.sh
💤 Files with no reviewable changes (3)
  • crates/ironclaw_runner/tests/secrets.rs
  • crates/ironclaw_runner/src/lib.rs
  • crates/ironclaw_runner/src/secrets.rs

📝 Walkthrough

Summary by CodeRabbit

  • Changes
    • Removed the opt-in local libSQL secrets-store feature and its associated configuration.
    • Removed support for building, checking, and testing the deprecated libSQL-backed secrets store.
    • Updated CI packaging to use the remaining supported feature set.

Walkthrough

The libsql-secrets feature and its ironclaw_runner secret-store implementation, tests, dependencies, public module export, and CI feature selection are removed. Other libSQL dependency wiring remains enabled.

Changes

LibSQL secrets removal

Layer / File(s) Summary
Remove secret-store feature and wiring
crates/ironclaw_runner/Cargo.toml, crates/ironclaw_runner/src/lib.rs, crates/ironclaw_runner/src/secrets.rs, crates/ironclaw_runner/tests/secrets.rs, scripts/ci/package-feature-flags.sh
Removes the libsql-secrets feature, related dependencies, public module export, secret-store implementation and integration tests, and the corresponding CI feature flag.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers: serrrfirat

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description covers the change well but misses many required template sections like Summary bullets, Linked Issue, Impact, Rollback, and Review track. Reformat to the repository template and fill in the missing sections, especially Summary bullets, Change Type, Linked Issue, Validation, impacts, rollback, and Review track.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title uses Conventional Commits style and accurately summarizes removal of the dead libsql-secrets runner feature.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the contributor: core 20+ merged PRs label Jul 20, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request removes the libsql-secrets feature and its associated code from the ironclaw_runner crate. This includes deleting the secrets module, its configuration and health check functions, corresponding integration tests, and removing the ironclaw_secrets and secrecy dependencies from Cargo.toml and Cargo.lock. Additionally, the CI script was updated to remove the libsql-secrets feature flag. There are no review comments, so I have no feedback to provide.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
⚠️ Needs validation 0 0 0 c462f769144a

Head: c462f769144afa3797889e7bce1433febc397d9a
Next: Human review or validation is required before merging.

Run details

Status: Current
Needs human: no
Needs validation: yes

Summary

Static review found no actionable regression in this focused, mechanical removal (6 files; 560 deletions, 4 additions). Independent Rust compilation could not run because Cargo is unavailable in the review environment.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.

@github-actions

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 86.34% (322108 / 373088 lines)
  floor:    85.3% (tolerance 0.5pp -> effective floor 84.8%)
  denominator: 373088 lines now vs 320188 at floor capture (+52900 lines, +16.52%) — material change (>5%)

⚠️ 2 Reborn crate(s) have 0 int-tier coverage (target: 0) — ironclaw_prompt_envelope, ironclaw_scripts

Reborn integration-tier coverage

Line coverage (Reborn crates): 86.34% — 322108 / 373088 lines

Per-crate breakdown (65 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_prompt_envelope 0% 0 / 88
ironclaw_scripts 0% 0 / 345
ironclaw_runtime_policy 33.84% 89 / 263
ironclaw_event_projections 43.31% 673 / 1554
ironclaw_observability 61.54% 16 / 26
ironclaw_authorization 62.46% 604 / 967
ironclaw_dispatcher 62.88% 83 / 132
ironclaw_mcp 64.89% 595 / 917
ironclaw_filesystem 68.34% 4121 / 6030
ironclaw_channel_host 68.65% 219 / 319
ironclaw_memory 69.2% 773 / 1117
ironclaw_reborn_migration 70.42% 2362 / 3354
ironclaw_trust 72.88% 661 / 907
ironclaw_wasm_limiter 74.6% 47 / 63
ironclaw_extractors 74.72% 538 / 720
ironclaw_capabilities 75.76% 2103 / 2776
ironclaw_projects 76.48% 400 / 523
ironclaw_reborn_cli 76.99% 10251 / 13314
ironclaw_triggers 77.33% 2531 / 3273
ironclaw_llm 78.36% 20306 / 25915
ironclaw_product_context 78.57% 11 / 14
ironclaw_telegram_extension 80.18% 4842 / 6039
ironclaw_wasm_product_adapters 80.36% 1448 / 1802
ironclaw_process_sandbox 80.65% 671 / 832
ironclaw_first_party_extensions 81.06% 5965 / 7359
ironclaw_memory_native 81.17% 3195 / 3936
ironclaw_events 81.95% 1594 / 1945
ironclaw_network 82.98% 673 / 811
ironclaw_reborn_event_store 83.03% 1169 / 1408
ironclaw_reborn_identity 83.59% 433 / 518
ironclaw_processes 83.76% 939 / 1121
ironclaw_secrets 83.79% 2548 / 3041
ironclaw_wasm 84.44% 1069 / 1266
ironclaw_reborn_config 84.66% 2152 / 2542
ironclaw_product_workflow 84.75% 11088 / 13083
ironclaw_auth 84.97% 3279 / 3859
ironclaw_run_state 85.61% 458 / 535
ironclaw_channel_delivery 85.79% 1383 / 1612
ironclaw_common 86.13% 1714 / 1990
ironclaw_threads 87.22% 4838 / 5547
ironclaw_slack_v2_adapter 87.3% 1491 / 1708
ironclaw_skills 87.58% 4470 / 5104
ironclaw_turns 87.79% 14515 / 16533
ironclaw_product_adapter_registry 88.06% 531 / 603
ironclaw_product_adapters 88.1% 3384 / 3841
ironclaw_reborn_traces 88.2% 11946 / 13544
ironclaw_host_runtime 88.69% 18153 / 20467
ironclaw_reborn_openai_compat 88.79% 3778 / 4255
ironclaw_host_api 88.83% 4635 / 5218
ironclaw_webui 89.33% 7700 / 8620
ironclaw_extensions 89.33% 2955 / 3308
ironclaw_runner 89.62% 17382 / 19396
ironclaw_telegram_v2_adapter 89.65% 2712 / 3025
ironclaw_reborn_composition 89.83% 75482 / 84030
ironclaw_approvals 90.18% 1598 / 1772
ironclaw_conversations 90.39% 3123 / 3455
ironclaw_event_streams 90.82% 1009 / 1111
ironclaw_hooks 90.88% 10075 / 11086
ironclaw_resources 91.67% 4477 / 4884
ironclaw_loop_host 92.24% 15992 / 17338
ironclaw_attachments 93.06% 630 / 677
ironclaw_agent_loop 94.95% 9424 / 9925
ironclaw_safety 95.09% 3682 / 3872
ironclaw_outbound 95.52% 3451 / 3613
ironclaw_first_party_extension_ports 95.62% 3672 / 3840

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (3 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_embeddings v1-only: consumed only by root ironclaw (src/app.rs, src/tools/builtin/memory.rs, src/workspace/mod.rs, src/config/{mod,embeddings}.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657

@railway-app

railway-app Bot commented Jul 20, 2026

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-6377 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw 🕗 Deploying (View Logs) Web Jul 20, 2026 at 11:52 pm

@ilblackdragon

Copy link
Copy Markdown
Member Author

Superseded by #6378, which removes both dead runner feature flags (libsql-secrets + filesystem-goal-store) in one coherent change on top of fresh main (post-#6374). The filesystem-goal-store removal edits the same [features] block, so keeping them separate would have guaranteed a merge conflict.

ilblackdragon added a commit that referenced this pull request Jul 21, 2026
…m-goal-store (#6378)

Continues the runner feature-flag cleanup after #6374 removed
`local_trigger_access` (and with it `webui-user-store` /
`filesystem-local-trigger-access`). Removes the two remaining flags that
no shipped build shape turns off, leaving `libsql-restart-tests` as the
runner's sole flag — a sanctioned CI test-lane selector with zero `src/`
`#[cfg]`.

libsql-secrets:
- Gated `src/secrets.rs`, a libSQL `FilesystemSecretStore` assembly no
  shipped build enabled (only the CI compile self-test). The production
  assembly already lives in `ironclaw_reborn_composition::factory`
  (`build_secret_store` / `open_local_dev_secret_store`).
- Removes the module + `tests/secrets.rs`, the feature, and the now-orphaned
  optional deps `ironclaw_secrets` and `secrecy`.

filesystem-goal-store:
- Gated `FilesystemSubagentGoalStore` + the `await_edge` submodules,
  isolating only `ironclaw_filesystem` (a cheap path dep). It was forwarded
  by composition's *both* `libsql` and `postgres` features and by
  product_workflow — on in every build, i.e. the product, not a build shape.
- Makes `ironclaw_filesystem` an unconditional dep and de-gates the code;
  drops the forwards in composition (`libsql`/`postgres`) and the
  product_workflow dev-dep feature.

De-gating also resolves the pre-existing dead-code warnings in the runner's
zero-feature build (the `await_edge`/`untrusted_text` helpers are now always
compiled and reachable).

Behavior unchanged: both modules/paths were on in every shipped build or
dead in all of them. Verified: runner tests (default), runner clippy
(default + libsql-restart-tests), workspace feature matrix (default +
all-features), and `cargo test -p ironclaw_architecture`.

Supersedes #6377.

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-6377 — c462f769 Deployed Jul 20, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: dependencies Dependency updates size: M 50-199 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant