chore(runner): remove dead feature flags (libsql-secrets, filesystem-goal-store) - #6378
Conversation
…m-goal-store Continues the runner feature-flag cleanup after #6374 removed `local_trigger_access` (and with it `webui-user-store` / `filesystem-local-trigger-access`). Removes the two remaining flags that no shipped build shape turns off, leaving `libsql-restart-tests` as the runner's sole flag — a sanctioned CI test-lane selector with zero `src/` `#[cfg]`. libsql-secrets: - Gated `src/secrets.rs`, a libSQL `FilesystemSecretStore` assembly no shipped build enabled (only the CI compile self-test). The production assembly already lives in `ironclaw_reborn_composition::factory` (`build_secret_store` / `open_local_dev_secret_store`). - Removes the module + `tests/secrets.rs`, the feature, and the now-orphaned optional deps `ironclaw_secrets` and `secrecy`. filesystem-goal-store: - Gated `FilesystemSubagentGoalStore` + the `await_edge` submodules, isolating only `ironclaw_filesystem` (a cheap path dep). It was forwarded by composition's *both* `libsql` and `postgres` features and by product_workflow — on in every build, i.e. the product, not a build shape. - Makes `ironclaw_filesystem` an unconditional dep and de-gates the code; drops the forwards in composition (`libsql`/`postgres`) and the product_workflow dev-dep feature. De-gating also resolves the pre-existing dead-code warnings in the runner's zero-feature build (the `await_edge`/`untrusted_text` helpers are now always compiled and reachable). Behavior unchanged: both modules/paths were on in every shipped build or dead in all of them. Verified: runner tests (default), runner clippy (default + libsql-restart-tests), workspace feature matrix (default + all-features), and `cargo test -p ironclaw_architecture`. Supersedes #6377. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
🔎 IronLoop Review StatusHead: Current reviewers:
Reviewer summaries
Recent activity
Available commands
Run metadataAdmission: webhook accepted the request and IronLoop persisted reviewer state before this projection. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (9)
💤 Files with no reviewable changes (5)
📝 WalkthroughSummary by CodeRabbit
WalkthroughChangesRunner feature consolidation
Estimated code review effort: 3 (Moderate) | ~20 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 3 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (3 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Code Review
This pull request simplifies the codebase by removing the libsql-secrets and filesystem-goal-store feature flags from ironclaw_runner and related crates. It deletes the secrets module and its associated tests, removes dependencies on ironclaw_secrets and secrecy, and makes the filesystem-backed goal store and await edge modules always compiled rather than conditionally compiled. There are no review comments to assess, and I have no additional feedback to provide.
Important
The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.
There was a problem hiding this comment.
⚠️ IronLoop Review: reviewer
Review at a glance
| Verdict | Blocking | Notes | Inline | Head |
|---|---|---|---|---|
| 0 | 0 | 0 | 9840cb8fd0d8 |
Head: 9840cb8fd0d8e793efbe68f8e7b5125c15953287
Next: Human review or validation is required before merging.
Run details
Status: Current
Needs human: no
Needs validation: yes
Summary
No concrete correctness or security defect found in the focused feature cleanup. Runtime validation could not run because this environment has no Cargo/Rust toolchain.
Findings
None.
Developer follow-up
After fixing this feedback:
- Push the fix to this PR branch.
- Re-run this reviewer with
@ironloopai review --agent reviewerif you only changed this reviewer's findings. - Re-run all reviewers with
@ironloopai reviewwhen the fix may affect multiple areas.
Coverage ratchetReborn integration-tier coverageLine coverage (Reborn crates): 86.4% — 321687 / 372336 lines Per-crate breakdown (65 crates, lowest-covered first)
This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors. Exemptions (3 entry/entries excluded from the accounting above)
|
|
🚅 Deployed to the ironclaw-pr-6378 environment in ironclaw-ci-preview
|
What
Trims
ironclaw_runnerfrom three feature flags to one. Removeslibsql-secretsandfilesystem-goal-store; keepslibsql-restart-tests(a CI test-lane selector). This continues the runner feature-flag cleanup after #6374 removedlocal_trigger_access(and with itwebui-user-store/filesystem-local-trigger-access).Supersedes #6377 (which removed
libsql-secretsalone) — folded in here becausefilesystem-goal-storeis referenced inside thelibsql-secretsblock, so splitting them would guarantee a merge conflict.Why these two are dead / mis-gated
Per
.claude/rules/cargo-features.md, a feature must earn its build. Neither did:libsql-secrets— gatedsrc/secrets.rs, a libSQLFilesystemSecretStoreassembly that no shipped build enabled (only the CI compile self-testpackage-feature-flags.sh). The production secret-store assembly already lives inironclaw_reborn_composition::factory(build_secret_store/open_local_dev_secret_store), so the runner module was dead duplication.filesystem-goal-store— gatedFilesystemSubagentGoalStore+ theawait_edgesubmodules, isolating onlyironclaw_filesystem(a cheap path dep, not a heavy external one). It was forwarded by composition's bothlibsqlandpostgresfeatures and by product_workflow → on in every build. That's the rule's "if every artifact enables it, it's the product," not a build shape.Changes
src/secrets.rs,tests/secrets.rs; drop thesecretsmodule gate; remove orphaned optional depsironclaw_secrets+secrecy.ironclaw_filesysteman unconditional runner dep; de-gategoal_store.rs(18#[cfg]sites) andawait_edge/mod.rs(4 submodule gates); remove the redundant dev-dep dupe.ironclaw_runner/filesystem-goal-storeforwards inironclaw_reborn_composition(libsql/postgres) and thefilesystem-goal-storefeature on product_workflow's dev-dep.package-feature-flags.sh: runner now emits just--features libsql-restart-tests.After this,
libsqlhas nosrc/user left — it survives only aslibsql-restart-tests' test-lane dep.Behavior / risk
Move-only dead-code removal — behavior unchanged:
libsql-secretswas dead in every shipped build;filesystem-goal-storecode was on in every shipped build. De-gating also resolves the pre-existing dead-code warnings in the runner's zero-feature build (theawait_edge/untrusted_texthelpers are now always compiled and reachable).Validation
cargo test -p ironclaw_runner(default) — 339+ pass; the previously feature-gated goal-store/await-edge tests now run by defaultcargo clippy -p ironclaw_runner --all-targets(default and--features libsql-restart-tests) — clean.claude/rules/review-discipline.md, both legs):cargo clippy --all --tests --examples -- -D warningsand--all-features— both cleancargo test -p ironclaw_architecture— pass (dependency edges changed)scripts/ci/test-package-feature-flags.sh— pass🤖 Generated with Claude Code