Skip to content

docs: refresh Reborn ProductSurface routing design - #6444

Merged
ilblackdragon merged 2 commits into
mainfrom
agent/urbit-causal-routing-docs
Jul 22, 2026
Merged

ilblackdragon merged 2 commits into
mainfrom
agent/urbit-causal-routing-docs

Conversation

@ilblackdragon

Copy link
Copy Markdown
Member

What changed

  • Adds the Urbit/terminal takeaway to the Reborn architecture simplification note as a new causal-routing section for ProductSurface.
  • Tightens product/channel vocabulary around terminal-like adapters, direct terminals, and external channel adapters.
  • Refreshes the mutable implementation status log against current origin/main, including the merged authorize fold, origin-gate matrix, generic extension runtime, and in-memory-store ratchet cleanup.

Why

Channels should start or resume a durable path into the Reborn kernel, then render projected state back out. They should not own canonical run, gate, invocation, approval, or delivery truth.

Validation

  • git diff --check
  • Doc-only change, Rust tests not run.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@ironloopai

ironloopai Bot commented Jul 22, 2026 •

Copy link
Copy Markdown
Contributor

🔎 IronLoop Review Status

Head: 325b65e26f0f52ff33e5624f1c9781134f9396a5
Result: One or more review results were superseded by a newer PR head.
Next: Run @ironloopai review on the latest PR head.
Updated: 2026-07-22T23:39:41.819Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Superseded N/A N/A 2026-07-22T06:50:06.047Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Superseded by a newer PR head. New head: 18b613a. Previous verdict: Changes requested.
Recent activity
Time Reviewer State Detail
2026-07-22T05:28:49.906Z ironloop/common-reviewer (reviewer) Superseded A newer PR head replaced this review (788513e).
2026-07-22T06:44:25.884Z ironloop/common-reviewer (reviewer) Queued Accepted review request for head 56b337a.
2026-07-22T06:44:25.884Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-22T06:44:26.717Z ironloop/common-reviewer (reviewer) Started Reviewer worker started.
2026-07-22T06:44:28.588Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (head_ref) at 56b337a.
2026-07-22T06:48:31.164Z ironloop/common-reviewer (reviewer) Superseded A newer PR head replaced this review (18b613a).
2026-07-22T06:50:06.047Z ironloop/common-reviewer (reviewer) Result captured Changes requested; 1 blocking finding.
2026-07-22T06:50:06.047Z ironloop/common-reviewer (reviewer) Superseded A newer PR head replaced this review (18b613a).
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent>
Run metadata

Admission: webhook accepted the request and IronLoop persisted reviewer state before this projection.

@coderabbitai

coderabbitai Bot commented Jul 22, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Summary by CodeRabbit

  • Documentation
    • Updated the architecture design note with a revised revision-log and a new causal routing contract, clarifying routing responsibilities between product terminals/channels and the kernel.
    • Refined terminology and composition framing around product terminals/channels as adapters over the simplified ProductSurface model.
    • Clarified origin-to-gate behavior, including reviewed allowlist handling for Ungated scenarios.
    • Refreshed enforcement criteria, implementation status, and references to match the latest facade snapshot and terminology.

Walkthrough

The Reborn architecture design note updates ProductSurface terminology and contracts, introduces kernel-owned causal routing, reframes terminals and channels as adapters, and refreshes enforcement, implementation status, validation instructions, and references.

Changes

Reborn architecture simplification

Layer / File(s) Summary
Product surface and causal routing
docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md
Defines the 87-method ProductSurface facade, actor/session binding, reviewed Ungated handling, and durable kernel-owned causal paths.
Product composition and routing surfaces
docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md
Describes product terminals and channels as ProductSurface adapters and ties routing surfaces to recorded causal paths.
Enforcement and implementation status
docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md
Updates enforcement ratchets, implementation snapshots, remaining work, validation commands, and architecture references.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers: benkurrek

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description covers summary, rationale, and validation, but omits most required template sections like Change Type, Linked Issue, Test Strategy, and impact checklists. Fill every required template section, especially Change Type, Linked Issue, complete Test Strategy fields, Security Impact, impact checklists, Rollback Plan, and Review Follow-Through.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly matches a documentation-only refresh of the Reborn ProductSurface routing design and follows Conventional Commits style.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6444 July 22, 2026 05:23 Destroyed
@github-actions github-actions Bot added scope: docs Documentation size: XS < 10 changed lines (excluding docs) risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Jul 22, 2026
@ilblackdragon
ilblackdragon force-pushed the agent/urbit-causal-routing-docs branch from dc0ce7c to 788513e Compare July 22, 2026 05:23
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6444 July 22, 2026 05:35 Destroyed
@railway-app

railway-app Bot commented Jul 22, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-6444 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 22, 2026 at 6:57 am

@ilblackdragon
ilblackdragon force-pushed the agent/urbit-causal-routing-docs branch from 788513e to 56b337a Compare July 22, 2026 06:40
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6444 July 22, 2026 06:40 Destroyed
@ilblackdragon
ilblackdragon marked this pull request as ready for review July 22, 2026 06:44
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@ilblackdragon
ilblackdragon force-pushed the agent/urbit-causal-routing-docs branch from 56b337a to 18b613a Compare July 22, 2026 06:48
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6444 July 22, 2026 06:48 Destroyed

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md`:
- Around line 1147-1169: Soften the present-tense guarantees in the architecture
passage around ProductSurface calls and durable events to describe the target
architecture rather than current behavior. Replace assertions that every event
already carries complete correlation and adapters never maintain delivery truth
with “must” or equivalent intent language, consistent with §14, until the event
schema, path contract, and conformance tests enforce these requirements.
- Around line 804-806: Revise the facade description to state actor binding as
the target state rather than an already enforced guarantee. Update the wording
around the “ONLY surface” and sealing claims to avoid asserting that
invoke/query are actor-bound until the caller ingress is removed or backed by
implementation and conformance tests.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 032b58c8-72ef-4c30-89d9-1e5ad9256a0f

📥 Commits

Reviewing files that changed from the base of the PR and between d5d40d9 and 56b337a.

📒 Files selected for processing (1)
  • docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md

Comment thread docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md Outdated
Comment on lines +1147 to +1169
This is not observability garnish. It is routing truth. Every `ProductSurface`
call either starts that path (`open_conversation`, `submit_turn`, `invoke`) or
continues it (`events`, `reply`, `resolve_gate`, `cancel`, `query`). Every durable
event and projection emitted for a turn, invocation, gate, outcome, or delivery
attempt carries enough typed correlation to answer:

- who or what caused this (`Actor`, `InvocationOrigin`, `RoutineId` /
`TurnRunId`);
- under which scope and authority it ran (`ResourceScope`, `Authorized`,
approval/auth/resource gate records);
- which product terminal/channel can observe or render it (conversation binding,
projection cursor, reply target, delivery attempt);
- whether replay must return a recorded result, re-enter `authorize()`, or report
`HostFailure::Uncertain` (§11.3).

The prohibition that falls out is simple: **adapters render from projected path
state; they do not maintain hidden delivery truth.** Slack timestamps, Telegram
message ids, WebUI tabs, HTTP request ids, and OpenAI-compat request ids are
terminal/device coordinates. They may be stored as external refs or delivery
metadata, but they are never canonical run, gate, invocation, or approval
authority. If a side effect succeeds, fails, blocks, resumes, or becomes
uncertain, that fact is recorded on the kernel path first and only then rendered
back through the terminal/channel.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift

Soften present-tense causal-routing guarantees until implemented.

This states that every durable event carries complete routing correlation and that adapters never own delivery truth, while §14 explicitly says causal routing is design-only and has no first-class path contract yet. Use “must”/“target architecture” wording until the event schema, path contract, and conformance tests enforce it.

As per coding guidelines, cross-layer guarantees must be enforced by code or tests, or softened to describe intent.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md` around
lines 1147 - 1169, Soften the present-tense guarantees in the architecture
passage around ProductSurface calls and durable events to describe the target
architecture rather than current behavior. Replace assertions that every event
already carries complete correlation and adapters never maintain delivery truth
with “must” or equivalent intent language, consistent with §14, until the event
schema, path contract, and conformance tests enforce these requirements.

Source: Coding guidelines

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md`:
- Around line 2272-2282: Update the completion snapshot table to add evidence
citations for each load-bearing Done, Landed, and Live claim, prioritizing the
product facade, origin→gate matrix, generic extension/channel runtime, and
InMemory*Store deletion rows. Cite exact defining symbols, implementation files,
or ratchet tests from the relevant write sites, while preserving the existing
status descriptions and keeping the citations specific enough to verify each
claim.
- Around line 2432-2435: Update the documentation validation instructions in the
architecture simplification document to require running `mint dev` and `mint
broken-links` from the `docs/` directory before merging, in addition to the
existing checks.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 55632451-26e1-4161-8a47-7f5cc38fed96

📥 Commits

Reviewing files that changed from the base of the PR and between 56b337a and 18b613a.

📒 Files selected for processing (1)
  • docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md

Comment on lines +2272 to +2282
| Result DTO collapse | **Done** — `CapabilityOutcome` and result mirrors are deleted; `host_api::Resolution` is canonical. |
| Request-side DTO collapse | **Done** — retired request mirror DTO names are banned; `LoopRequest`, tuple parts, and private `RuntimeLaneRequest` carry the remaining distinct states. |
| Request/witness vocabulary | **Done** — `Invocation`, `Actor`, `InvocationOrigin`, `Authorized`, and dispatch-through-witness are live. |
| Pre-flight authority fold | **Done** — trust, grants, approvals, credentials, resources, and lane resolution are folded through `authorize()`. |
| Origin→gate matrix | **Live, tightening remains** — matrices are descriptor data and ratcheted; `LoopRun` ungated set is a reviewed 17-id seed to shrink. |
| `InMemory*Store` mirror deletion | **Done for tracked domain stores** — the ratchet was deleted after the allowlist reached empty. |
| Generic extension/channel runtime | **Landed** — `ChannelAdapter` + `ironclaw_extension_host`; Slack/Telegram are extension adapters, not bespoke product trees. |
| Product facade collapse | **Started, mostly remaining** — `invoke`/`query` exist and the facade is frozen at 87 methods; migrations to descriptors/views remain. |
| Deployment mode as data | **Partial** — renames/ratchets are live, but profile enums and profile-edge branching still exist. |
| Causal routing / product terminal path | **Design added here, implementation pending** — no first-class duct/path contract yet. |
| Recoverability endgame | **Partial** — vocabulary and model-visible recovery base are live; conformance/diagnostic observation remain. |

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Add write-site evidence to the completion snapshot.

The Done/Landed/Live claims are load-bearing but lack exact defining symbols, implementation files, or ratchet tests in this table. Add those citations, especially for the facade, origin matrix, extension runtime, and store deletion claims.

As per coding guidelines, load-bearing Markdown claims must cite evidence from the definition or write site.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md` around
lines 2272 - 2282, Update the completion snapshot table to add evidence
citations for each load-bearing Done, Landed, and Live claim, prioritizing the
product facade, origin→gate matrix, generic extension/channel runtime, and
InMemory*Store deletion rows. Cite exact defining symbols, implementation files,
or ratchet tests from the relevant write sites, while preserving the existing
status descriptions and keeping the citations specific enough to verify each
claim.

Source: Coding guidelines

Comment on lines +2432 to +2435
- Urbit Arvo / Gall routing analogy for §5.2.10: official Arvo overview
(`https://docs.urbit.org/build-on-urbit/app-school/1-arvo`), Gall agent
overview (`https://docs.urbit.org/build-on-urbit/app-school/2-agent`), and
kernel/vane docs (`https://docs.urbit.org/urbit-os/kernel/arvo`).

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

cd docs
mint dev
mint broken-links

Repository: nearai/ironclaw

Length of output: 233


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf 'Top-level guidance files:\n'
git ls-files | rg '(^|/)(AGENTS\.md|CLAUDE\.md|\.claude/rules/.*)$' || true

printf '\nSearch for docs validation references:\n'
rg -n "mint dev|mint broken-links|broken-links|docs validation" docs .github .claude AGENTS.md CLAUDE.md -S || true

Repository: nearai/ironclaw

Length of output: 5202


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf 'Docs tree overview:\n'
git ls-files docs | sed -n '1,120p'

printf '\nRelevant excerpt around the changed lines:\n'
sed -n '2426,2440p' docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md

Repository: nearai/ironclaw

Length of output: 6824


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf 'Look for mint config or docs package hints:\n'
fd -a 'mint*' docs .github .claude 2>/dev/null || true
fd -a 'package.json' docs .github 2>/dev/null || true
rg -n '"broken-links"|"mint"' docs .github -S || true

Repository: nearai/ironclaw

Length of output: 378


Run the docs checks from docs/. git diff --check doesn’t cover the required Mintlify validation; add mint dev and mint broken-links before merge.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md` around
lines 2432 - 2435, Update the documentation validation instructions in the
architecture simplification document to require running `mint dev` and `mint
broken-links` from the `docs/` directory before merging, in addition to the
existing checks.

Source: Coding guidelines

…uting-docs

# Conflicts:
#	docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6444 July 22, 2026 23:39 Destroyed

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md`:
- Around line 2492-2499: Update the validation summary for this documentation
change to include running mint dev and mint broken-links from the docs
directory, alongside git diff --check. Ensure all three documented checks are
listed before merge.
- Around line 824-826: Update the 87 frozen trait methods statement to describe
the freeze ratchet’s actual counting method: extracting method names from the
RebornServicesApi trait block and comparing set membership, rather than counting
file-wide async fn occurrences across impls and tests. Add a citation or link to
the relevant freeze-ratchet test as evidence for this load-bearing claim, while
preserving the existing date and reconciliation context.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: ebe199e1-fb50-4a77-9cc1-aaf4a29d726e

📥 Commits

Reviewing files that changed from the base of the PR and between 18b613a and 325b65e.

📒 Files selected for processing (1)
  • docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md

Comment on lines +824 to +826
**87 frozen trait methods** as of 2026-07-22 (the original 2026-07-17 audit
counted 88 before the first shrink/additive conduit reconciliation; file-wide
`async fn` counts include impls and tests), and most

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Align the 87-method count with the freeze ratchet.

Lines 824-826 attribute the count to file-wide async fn counting, including impls and tests, but crates/ironclaw_architecture/tests/reborn_facade_method_freeze_ratchet.rs extracts methods from the RebornServicesApi trait block and compares set membership. Document the trait-block extraction instead.

As per coding guidelines, load-bearing Markdown claims must cite evidence from the definition or write site.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md` around
lines 824 - 826, Update the 87 frozen trait methods statement to describe the
freeze ratchet’s actual counting method: extracting method names from the
RebornServicesApi trait block and comparing set membership, rather than counting
file-wide async fn occurrences across impls and tests. Add a citation or link to
the relevant freeze-ratchet test as evidence for this load-bearing claim, while
preserving the existing date and reconciliation context.

Source: Coding guidelines

Comment on lines +2492 to +2499
For a docs-only update to this file, run:

```bash
git diff --check
cd docs
mint dev
mint broken-links
```

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Run the documented Mint checks before merge.

The validation summary reports only git diff --check; this docs/**/* change also requires mint dev and mint broken-links from docs/.

As per coding guidelines, documentation changes must be tested with those commands.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/reborn/2026-07-17-architecture-simplification-dto-dyn-local.md` around
lines 2492 - 2499, Update the validation summary for this documentation change
to include running mint dev and mint broken-links from the docs directory,
alongside git diff --check. Ensure all three documented checks are listed before
merge.

Source: Coding guidelines

@ilblackdragon
ilblackdragon merged commit de17222 into main Jul 22, 2026
42 of 43 checks passed
@ilblackdragon
ilblackdragon deleted the agent/urbit-causal-routing-docs branch July 22, 2026 23:47

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-6444 — 325b65e2 Deployed Jul 22, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: docs Documentation size: XS < 10 changed lines (excluding docs)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant