chore(runner): remove dead libsql-secrets feature and its module - #6377
ilblackdragon wants to merge 1 commit into
Conversation
The `libsql-secrets` feature gated `crates/ironclaw_runner/src/secrets.rs` (a libSQL-backed `FilesystemSecretStore` assembly) that no shipped build enabled — the only enabler was the CI compile self-test in `scripts/ci/package-feature-flags.sh`. The production secret-store assembly already lives in `ironclaw_reborn_composition` (`factory.rs::build_secret_store` / `open_local_dev_secret_store`), which does the same work and more, so the runner module was dead duplication. Removes: - `src/secrets.rs` and `tests/secrets.rs` - the `secrets` module gate in `lib.rs` - the `libsql-secrets` `[features]` entry + its stale comment reference - now-orphaned optional deps `ironclaw_secrets` and `secrecy` - `libsql-secrets` from `package-feature-flags.sh` Behavior unchanged: the module was unreachable in every shipped binary. Verified with workspace feature-matrix clippy (default + all-features). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
🔎 IronLoop Review StatusHead: Current reviewers:
Reviewer summaries
Recent activity
Available commands
Run metadataAdmission: webhook accepted the request and IronLoop persisted reviewer state before this projection. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (5)
💤 Files with no reviewable changes (3)
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe ChangesLibSQL secrets removal
Estimated code review effort: 2 (Simple) | ~10 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 3 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (3 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Code Review
This pull request removes the libsql-secrets feature and its associated code from the ironclaw_runner crate. This includes deleting the secrets module, its configuration and health check functions, corresponding integration tests, and removing the ironclaw_secrets and secrecy dependencies from Cargo.toml and Cargo.lock. Additionally, the CI script was updated to remove the libsql-secrets feature flag. There are no review comments, so I have no feedback to provide.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
There was a problem hiding this comment.
⚠️ IronLoop Review: reviewer
Review at a glance
| Verdict | Blocking | Notes | Inline | Head |
|---|---|---|---|---|
| 0 | 0 | 0 | c462f769144a |
Head: c462f769144afa3797889e7bce1433febc397d9a
Next: Human review or validation is required before merging.
Run details
Status: Current
Needs human: no
Needs validation: yes
Summary
Static review found no actionable regression in this focused, mechanical removal (6 files; 560 deletions, 4 additions). Independent Rust compilation could not run because Cargo is unavailable in the review environment.
Findings
None.
Developer follow-up
After fixing this feedback:
- Push the fix to this PR branch.
- Re-run this reviewer with
@ironloopai review --agent reviewerif you only changed this reviewer's findings. - Re-run all reviewers with
@ironloopai reviewwhen the fix may affect multiple areas.
Coverage ratchetReborn integration-tier coverageLine coverage (Reborn crates): 86.34% — 322108 / 373088 lines Per-crate breakdown (65 crates, lowest-covered first)
This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors. Exemptions (3 entry/entries excluded from the accounting above)
|
|
🚅 Deployed to the ironclaw-pr-6377 environment in ironclaw-ci-preview
|
…m-goal-store (#6378) Continues the runner feature-flag cleanup after #6374 removed `local_trigger_access` (and with it `webui-user-store` / `filesystem-local-trigger-access`). Removes the two remaining flags that no shipped build shape turns off, leaving `libsql-restart-tests` as the runner's sole flag — a sanctioned CI test-lane selector with zero `src/` `#[cfg]`. libsql-secrets: - Gated `src/secrets.rs`, a libSQL `FilesystemSecretStore` assembly no shipped build enabled (only the CI compile self-test). The production assembly already lives in `ironclaw_reborn_composition::factory` (`build_secret_store` / `open_local_dev_secret_store`). - Removes the module + `tests/secrets.rs`, the feature, and the now-orphaned optional deps `ironclaw_secrets` and `secrecy`. filesystem-goal-store: - Gated `FilesystemSubagentGoalStore` + the `await_edge` submodules, isolating only `ironclaw_filesystem` (a cheap path dep). It was forwarded by composition's *both* `libsql` and `postgres` features and by product_workflow — on in every build, i.e. the product, not a build shape. - Makes `ironclaw_filesystem` an unconditional dep and de-gates the code; drops the forwards in composition (`libsql`/`postgres`) and the product_workflow dev-dep feature. De-gating also resolves the pre-existing dead-code warnings in the runner's zero-feature build (the `await_edge`/`untrusted_text` helpers are now always compiled and reachable). Behavior unchanged: both modules/paths were on in every shipped build or dead in all of them. Verified: runner tests (default), runner clippy (default + libsql-restart-tests), workspace feature matrix (default + all-features), and `cargo test -p ironclaw_architecture`. Supersedes #6377. Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
What
Removes the
libsql-secretsfeature fromironclaw_runnerand thesecretsmodule it gated.Why
The feature gated
crates/ironclaw_runner/src/secrets.rs— a libSQL-backedFilesystemSecretStoreassembly (build_libsql_reborn_secret_store) intended for a standalone-Reborn secret store. But:scripts/ci/package-feature-flags.sh:53. No production dependency edge, workflow, orDockerfileselected it — so the module was dead in every shipped binary (the exact feature-gated-dead-code shape.claude/rules/cargo-features.mdwarns about).ironclaw_reborn_composition—factory.rs::build_secret_store(line 3566) andopen_local_dev_secret_store(line 3612) — which does the same libSQLFilesystemSecretStore+SecretsCryptowiring and more (credential broker, keychain master-key resolution, source-named error mapping). The runner module's own comment admitted it "mirrors the composition-layer tenant/user rewrite … kept local so this crate does not depend on the composition crate."The reusable primitives (
SecretStore,FilesystemSecretStore,SecretsCrypto) remain inironclaw_secretsand are untouched — this only removes the unused runner-side wiring shim.Changes
src/secrets.rsandtests/secrets.rs#[cfg(feature = "libsql-secrets")] pub mod secrets;gate inlib.rslibsql-secrets[features]entry and its stale comment reference onlibsql-restart-testsironclaw_secretsandsecrecy(Cargo.lockreflects only these two leaving the runner)libsql-secretsfrompackage-feature-flags.shlibsqlandironclaw_filesystemstay optional — still used bywebui-user-store/libsql-restart-tests/filesystem-goal-store.Behavior / risk
Move-only dead-code removal — behavior unchanged, the module was unreachable in every shipped binary. No regression test applies (nothing production-reachable was altered).
Validation
cargo clippy -p ironclaw_runner --all-targets --features libsql-restart-tests,webui-user-store -- -D warnings— clean.claude/rules/review-discipline.mdfor a removed#[cfg]gate):cargo clippy --all --tests --examples -- -D warnings— cleancargo clippy --all --tests --examples --all-features -- -D warnings— cleanscripts/ci/test-package-feature-flags.shself-test — passes🤖 Generated with Claude Code