Skip to content

test: isolate Trace Commons coverage from local state - #6714

Open
ogarciarevett wants to merge 5 commits into
nearai:mainfrom
ogarciarevett:fix/trace-commons-test-state
Open

ogarciarevett wants to merge 5 commits into
nearai:mainfrom
ogarciarevett:fix/trace-commons-test-state

Conversation

@ogarciarevett

@ogarciarevett ogarciarevett commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • isolate the Trace Commons parity tests from developer enrollment state
  • re-run each affected test in a child process with a temporary IRONCLAW_BASE_DIR configured before process startup
  • assert the child resolves that isolated directory before exercising the tools

Change Type

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • CI/Infrastructure
  • Security
  • Dependencies

Linked Issue

Closes #6359.

Validation

  • cargo fmt --all -- --check
  • cargo clippy --all --benches --tests --examples --all-features -- -D warnings
  • cargo build
  • Relevant tests pass: the full reborn_trace_first_party_tool_coverage binary passed 26 tests with 2 intentional ignores
  • cargo test --features integration if database-backed or integration behavior changed — not applicable; this isolates a test harness path and changes no database behavior
  • Manual testing: reproduced RED with an enabled policy.json under a controlled IRONCLAW_BASE_DIR, then reran the same exact test GREEN; after review, both focused tests also pass with a deliberately hostile parent value because the child overrides it before startup
  • If a coding agent was used and supports it, review-pr or pr-shepherd --fix was run before requesting review — not available in this environment; scripts/pre-commit-safety.sh passed

Additional required checks:

  • cargo test — 607 passed across the default suites
  • scripts/pre-commit-safety.sh — passed

Test Strategy

User behavior: developers with prior Trace Commons enrollment can run the root Trace Commons parity coverage without their local policy changing the result.

Risk areas:

  • Model behavior
  • Browser
  • Side effect
  • Persistence
  • Security or permissions
  • External provider
  • Cross-component behavior

Tests added or updated:

  • Unit or contract: not applicable; the affected behavior is in the existing root harness test.
  • Reborn integration: updated tests/reborn_trace_first_party_tool_coverage.rs.
  • Recorded fixture: not applicable; model choice is unchanged.
  • Browser E2E: not applicable; no browser surface changed.
  • Backend or runtime: not applicable; no backend or runtime implementation changed.
  • Live canary: not applicable; the regression is local filesystem isolation.

What the tests prove: an enrolled policy outside the test cannot make the Trace Commons status result report enrolled: true, and neither scenario mutates process-global environment while its test binary is running.

Commands run:

IRONCLAW_BASE_DIR=<controlled-enrolled-state> cargo +1.96.0 test -p ironclaw_reborn_integration_tests --test reborn_trace_first_party_tool_coverage reborn_trace_trace_commons_first_party_tools_parity -- --exact --nocapture
cargo +1.96.0 test -p ironclaw_reborn_integration_tests --test reborn_trace_first_party_tool_coverage
cargo +1.96.0 fmt --all -- --check
cargo +1.96.0 clippy --all --benches --tests --examples --all-features -- -D warnings
cargo +1.96.0 build
cargo +1.96.0 test
scripts/pre-commit-safety.sh

Security Impact

None. The change only redirects test state to temporary child-process directories and does not alter production file access.

Reborn Trust-Boundary Checklist

N/A: test-harness isolation only; no production trust-bearing types, ingress, policy, runtime, status, or serialization behavior changed.

Database Impact

None.

Blast Radius

Only the two Trace Commons cases in reborn_trace_first_party_tool_coverage; each child process owns one temporary directory.

Rollback Plan

Revert these test-only commits.

Review Follow-Through

Child-process isolation uses the existing env-based API without adding a production seam. If the capability harness gains explicit path injection later, these tests can adopt it and drop the re-exec helper.


Review track: A (tests)

@ironloopai

ironloopai Bot commented Jul 27, 2026 •

Copy link
Copy Markdown
Contributor

🔎 IronLoop Review Status

Head: ea84a89b179ad79271a80bb37757a0693aba00ce
Result: One or more review results were superseded by a newer PR head.
Next: Run @ironloopai review on the latest PR head.
Updated: 2026-07-27T15:40:08.239Z

Current reviewers:

Reviewer State Verdict Findings Last update
ironloop/common-reviewer (reviewer) Superseded N/A N/A 2026-07-27T13:39:04.666Z
Reviewer summaries
Reviewer Detail
ironloop/common-reviewer (reviewer) Superseded by a newer PR head. New head: dcd0714. Previous verdict: Approved.
Recent activity
Time Reviewer State Detail
2026-07-27T13:14:04.440Z ironloop/common-reviewer (reviewer) Queued Accepted review request for head 8fec156.
2026-07-27T13:14:04.440Z ironloop/common-reviewer (reviewer) Queued Waiting for this reviewer lane to become available.
2026-07-27T13:14:04.718Z ironloop/common-reviewer (reviewer) Started Reviewer worker started.
2026-07-27T13:14:07.876Z ironloop/common-reviewer (reviewer) Workspace ready Prepared isolated checkout (merge_ref) at 065591d.
2026-07-27T13:17:44.765Z ironloop/common-reviewer (reviewer) Result captured Approved; 0 blocking findings.
2026-07-27T13:17:44.765Z ironloop/common-reviewer (reviewer) Completed Review completed and terminal status was persisted.
2026-07-27T13:39:04.666Z ironloop/common-reviewer (reviewer) Superseded A newer PR head replaced this review (dcd0714).
Available commands
  • @ironloopai help
  • @ironloopai agents
  • @ironloopai review
  • @ironloopai review --agent <agent>
Run metadata

Admission: webhook accepted the request and IronLoop persisted reviewer state before this projection.

@github-actions github-actions Bot added size: XS < 10 changed lines (excluding docs) risk: low Changes to docs, tests, or low-risk modules contributor: new First-time contributor labels Jul 27, 2026
@coderabbitai

coderabbitai Bot commented Jul 27, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 97223f9b-5764-4aaa-aeb1-b4dae626cef9

📥 Commits

Reviewing files that changed from the base of the PR and between 0350459 and 41f0c92.

📒 Files selected for processing (1)
  • tests/reborn_trace_first_party_tool_coverage.rs

📝 Walkthrough

Summary by CodeRabbit

  • Tests
    • Improved end-to-end test isolation for Trace Commons checks by running targeted assertions in a separate child process with a fresh temporary base directory.
    • Added validation that path resolution uses the isolated temporary directory during these runs.
    • Updated existing parity and pilot tool visibility tests so only the isolated process performs the environment-dependent verification.

Walkthrough

Trace Commons coverage tests now execute in isolated child processes with a temporary IRONCLAW_BASE_DIR; parity coverage verifies path resolution, and pilot-tool visibility coverage uses the same isolation flow.

Changes

Trace Commons coverage isolation

Layer / File(s) Summary
Initialize and apply isolated base directory
tests/reborn_trace_first_party_tool_coverage.rs
A helper creates a temporary base directory, reruns the targeted test in a child process, validates single-test success, and applies the flow to parity and pilot-tool visibility coverage.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

  • nearai/ironclaw#5280: Extends Trace Commons first-party coverage and uses the same test file and isolation behavior.

Suggested reviewers: think-in-universe

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title follows Conventional Commits style and accurately summarizes the test isolation change.
Description check ✅ Passed The description is mostly complete and covers summary, issue link, validation, test strategy, and impact sections.
Linked Issues check ✅ Passed The PR implements #6359 by isolating the Trace Commons harness with a temporary base dir and verifying the child uses it.
Out of Scope Changes check ✅ Passed The diff stays confined to the targeted test harness file and shows no unrelated code changes.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ IronLoop Review: reviewer

Review at a glance

Verdict Blocking Notes Inline Head
✅ Approved 0 0 0 8fec1561cfe0

Head: 8fec1561cfe00d467f4509e22f30d100fb66e038
Next: No reviewer action needed.

Run details

Status: Current
Needs human: no
Needs validation: no

Summary

Approved after focused review of the test-only isolation change; no actionable regressions found.

Findings

None.

Developer follow-up

After fixing this feedback:

  1. Push the fix to this PR branch.
  2. Re-run this reviewer with @ironloopai review --agent reviewer if you only changed this reviewer's findings.
  3. Re-run all reviewers with @ironloopai review when the fix may affect multiple areas.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/reborn_trace_first_party_tool_coverage.rs`:
- Around line 81-97: Replace the OnceLock-based process-global setup in
setup_trace_commons_base_dir with an isolated approach that does not mutate
IRONCLAW_BASE_DIR during tests: configure the variable before the test process
starts or pass an explicit base-directory path through the Trace Commons
harness. Ensure compute_ironclaw_base_dir and all related tests use that
injected/configured path without relying on test ordering or unsynchronized
environment access.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: a666ae20-db2d-4cc1-9077-fde51e52fdff

📥 Commits

Reviewing files that changed from the base of the PR and between 6f930f2 and 8fec156.

📒 Files selected for processing (1)
  • tests/reborn_trace_first_party_tool_coverage.rs

Comment thread tests/reborn_trace_first_party_tool_coverage.rs Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/reborn_trace_first_party_tool_coverage.rs`:
- Around line 84-87: Update the child-detection logic in the helper around
TRACE_COMMONS_TEST_CHILD so an inherited sentinel alone cannot bypass spawning.
Validate that the marker matches the freshly created temporary path or another
per-invocation value established by this helper, and only then use the inherited
IRONCLAW_BASE_DIR; otherwise continue through the normal spawn path without
panicking.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 22e67e13-3749-4c87-9058-a61e4f41fd1d

📥 Commits

Reviewing files that changed from the base of the PR and between 8fec156 and dcd0714.

📒 Files selected for processing (1)
  • tests/reborn_trace_first_party_tool_coverage.rs

Comment thread tests/reborn_trace_first_party_tool_coverage.rs Outdated
@ogarciarevett

Copy link
Copy Markdown
Contributor Author

@ironloopai review

@ironloopai

ironloopai Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

Caution

Command not authorized

Only repository owners, members, and collaborators can start IronLoop work.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
tests/reborn_trace_first_party_tool_coverage.rs (1)

92-99: 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Do not equate child-process success with test execution.

libtest/Cargo report success when --exact matches zero tests, so a stale test_name would make this coverage gate pass without running. Capture the child stdout and assert the child ran exactly one test, or emit and check a child completion marker.

Repo invariant: landed tests must run in CI rather than silently skip.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@tests/reborn_trace_first_party_tool_coverage.rs` around lines 92 - 99, Update
the isolated test process launched by the test harness around the current_exe
Command to verify that exactly one test actually ran, rather than relying solely
on status.success(). Capture the child output and assert libtest’s executed-test
count, or add and validate a dedicated completion marker, so stale test_name
values cannot make the coverage gate pass without execution.

Source: Path instructions

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@tests/reborn_trace_first_party_tool_coverage.rs`:
- Around line 92-99: Update the isolated test process launched by the test
harness around the current_exe Command to verify that exactly one test actually
ran, rather than relying solely on status.success(). Capture the child output
and assert libtest’s executed-test count, or add and validate a dedicated
completion marker, so stale test_name values cannot make the coverage gate pass
without execution.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: a40a276f-0b6d-4196-bf3b-d6ecc4b527af

📥 Commits

Reviewing files that changed from the base of the PR and between dcd0714 and 0350459.

📒 Files selected for processing (1)
  • tests/reborn_trace_first_party_tool_coverage.rs

@ogarciarevett

Copy link
Copy Markdown
Contributor Author

Addressed the latest CodeRabbit finding in 41f0c92. The isolated child now captures libtest output and requires the exact 1 passed; 0 failed summary in addition to a successful exit.

Mutation verification: replacing the child test name with a stale value now fails the parent and reports 0 passed; restored, the full target passes (26 passed, 2 intentionally ignored). cargo fmt --check, focused all-feature clippy with -D warnings, scripts/pre-commit-safety.sh, and git diff --check also pass.

@ogarciarevett

Copy link
Copy Markdown
Contributor Author

@ironloopai review

@ironloopai

ironloopai Bot commented Jul 28, 2026

Copy link
Copy Markdown
Contributor

Caution

Command not authorized

Only repository owners, members, and collaborators can start IronLoop work.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: new First-time contributor risk: low Changes to docs, tests, or low-risk modules size: XS < 10 changed lines (excluding docs)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

reborn_trace_first_party_tool_coverage reads real $HOME state, fails locally / passes in CI

2 participants