Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
19 commits
Select commit Hold shift + click to select a range
aabbc70
feat(reborn): port IronHub install flow
serrrfirat Jul 27, 2026
e97c124
fix(reborn-ironhub): preserve skill install source and scope on rollback
serrrfirat Jul 28, 2026
96d7c89
fix(reborn-ironhub): skip host-bundled stamps per entry instead of ab…
serrrfirat Jul 28, 2026
320532b
Merge remote-tracking branch 'origin/main' into firat/pr-4479-merge-c…
serrrfirat Jul 28, 2026
191ccc1
fix(turns): trust verified catalog descriptions instead of denying th…
serrrfirat Jul 28, 2026
44489a3
Merge remote-tracking branch 'origin/main' into firat/pr-4479-merge-c…
serrrfirat Jul 28, 2026
ed73c3b
test(golden): re-bless capability surface hashes after the descriptio…
serrrfirat Jul 28, 2026
773d808
fix(ironhub): return complete, self-describing search results instead…
serrrfirat Jul 28, 2026
4fdcdaf
test(integration): cover the install-then-turn prompt-denial incident…
serrrfirat Jul 28, 2026
b218c05
fix(ironhub): distinguish matched results from the full catalog in se…
serrrfirat Jul 28, 2026
fe78d07
fix(ironhub): measure catalog_total inside the truncation budget
serrrfirat Jul 28, 2026
899b3da
Merge remote-tracking branch 'origin/main' into firat/pr-4479-merge-c…
serrrfirat Jul 29, 2026
26e3523
refactor(extension-host): key persisted manifest sources by ExtensionId
serrrfirat Jul 29, 2026
35677ee
Merge origin/main into firat/pr-4479-merge-conflicts-739070
Jul 29, 2026
a30604e
Merge origin/main into firat/pr-4479-merge-conflicts-739070
serrrfirat Jul 30, 2026
92b81cf
Merge remote-tracking branch 'origin/main' into codex/pr-6754-merge-c…
serrrfirat Jul 30, 2026
65bda61
Merge remote-tracking branch 'origin/main' into codex/pr-6754-merge-c…
serrrfirat Jul 30, 2026
4b279f2
fix(turns): keep prompt validation errors compact
serrrfirat Jul 30, 2026
80665d4
Merge remote-tracking branch 'origin/main' into codex/pr-6754-merge-c…
serrrfirat Jul 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Original file line number Diff line number Diff line change
Expand Up @@ -862,6 +862,7 @@ mod tests {
runtime: RuntimeKind::FirstParty,
safe_name: "tool_search".to_string(),
safe_description: "search".to_string(),
description_trust: Default::default(),
concurrency_hint: ConcurrencyHint::SafeForParallel,
parameters_schema: serde_json::json!({"type": "object"}),
};
Expand Down
5 changes: 5 additions & 0 deletions crates/ironclaw_agent_loop/src/executor/tests.rs
Original file line number Diff line number Diff line change
Expand Up @@ -9122,6 +9122,7 @@ async fn capability_stage_denied_auth_resume_only_fails_matching_call_remaining_
runtime: ironclaw_host_api::RuntimeKind::FirstParty,
safe_name: "demo_list".to_string(),
safe_description: "demo list capability".to_string(),
description_trust: Default::default(),
concurrency_hint: ironclaw_turns::run_profile::ConcurrencyHint::SafeForParallel,
parameters_schema: serde_json::json!({"type":"object","properties":{}}),
},
Expand Down Expand Up @@ -9523,6 +9524,7 @@ async fn capability_stage_denied_auth_resume_one_denied_two_remaining_all_dispat
runtime: ironclaw_host_api::RuntimeKind::FirstParty,
safe_name: "demo_list".to_string(),
safe_description: "demo list capability".to_string(),
description_trust: Default::default(),
concurrency_hint: ironclaw_turns::run_profile::ConcurrencyHint::SafeForParallel,
parameters_schema: serde_json::json!({"type":"object","properties":{}}),
},
Expand All @@ -9533,6 +9535,7 @@ async fn capability_stage_denied_auth_resume_one_denied_two_remaining_all_dispat
runtime: ironclaw_host_api::RuntimeKind::FirstParty,
safe_name: "demo_write".to_string(),
safe_description: "demo write capability".to_string(),
description_trust: Default::default(),
concurrency_hint: ironclaw_turns::run_profile::ConcurrencyHint::SafeForParallel,
parameters_schema: serde_json::json!({"type":"object","properties":{}}),
},
Expand Down Expand Up @@ -9798,6 +9801,7 @@ async fn capability_stage_denied_approval_resume_only_fails_matching_call_remain
runtime: ironclaw_host_api::RuntimeKind::FirstParty,
safe_name: "demo_list".to_string(),
safe_description: "demo list capability".to_string(),
description_trust: Default::default(),
concurrency_hint: ironclaw_turns::run_profile::ConcurrencyHint::SafeForParallel,
parameters_schema: serde_json::json!({"type":"object","properties":{}}),
},
Expand Down Expand Up @@ -10013,6 +10017,7 @@ async fn capability_stage_denied_approval_resume_no_matching_call_dispatches_unr
runtime: ironclaw_host_api::RuntimeKind::FirstParty,
safe_name: "demo_list".to_string(),
safe_description: "demo list capability".to_string(),
description_trust: Default::default(),
concurrency_hint: ironclaw_turns::run_profile::ConcurrencyHint::SafeForParallel,
parameters_schema: serde_json::json!({"type":"object","properties":{}}),
},
Expand Down
1 change: 1 addition & 0 deletions crates/ironclaw_agent_loop/src/executor/tests/support.rs
Original file line number Diff line number Diff line change
Expand Up @@ -411,6 +411,7 @@ impl MockHost {
runtime: RuntimeKind::FirstParty,
safe_name: "demo".to_string(),
safe_description: "demo capability".to_string(),
description_trust: Default::default(),
concurrency_hint: ironclaw_turns::run_profile::ConcurrencyHint::SafeForParallel,
parameters_schema: serde_json::json!({"type":"object","properties":{"input":{"type":"string"}}}),
}];
Expand Down
1 change: 1 addition & 0 deletions crates/ironclaw_agent_loop/src/test_support/mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1079,6 +1079,7 @@ pub fn capability_descriptor(
runtime: RuntimeKind::FirstParty,
safe_name: "demo".to_string(),
safe_description: "demo capability".to_string(),
description_trust: Default::default(),
concurrency_hint,
parameters_schema: serde_json::json!({"type":"object","properties":{"input":{"type":"string"}}}),
}
Expand Down
3 changes: 2 additions & 1 deletion crates/ironclaw_extension_host/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,9 @@ composition-substrate-tests = []
async-trait = "0.1"
base64 = "0.22"
chrono = { version = "0.4", default-features = false, features = ["clock", "serde", "std"] }
ed25519-dalek = "2.2.0"
hmac = "0.13"
hex = "0.4.3"
ironclaw_auth = { path = "../ironclaw_auth" }
ironclaw_approvals = { path = "../ironclaw_approvals" }
ironclaw_authorization = { path = "../ironclaw_authorization" }
Expand Down Expand Up @@ -89,7 +91,6 @@ ironclaw_processes = { path = "../ironclaw_processes", features = ["test-support
ironclaw_product = { path = "../ironclaw_product", features = ["test-support"] }
ironclaw_resources = { path = "../ironclaw_resources", features = ["test-support"] }
ironclaw_slack_extension = { path = "../ironclaw_slack_extension" }
hex = "0.4.3"
http-body-util = "0.1"
tempfile = "3"
tokio = { version = "1", features = ["macros", "rt", "rt-multi-thread", "sync", "time"] }
Expand Down
39 changes: 32 additions & 7 deletions crates/ironclaw_extension_host/src/available_extension_import.rs
Original file line number Diff line number Diff line change
Expand Up @@ -152,6 +152,31 @@ where
pub fn imported_extension_package(
files: Vec<(String, Vec<u8>)>,
reserved_bundled_ids: &[String],
) -> Result<AvailableExtensionPackage, ProductSurfaceFailure> {
extension_package_from_files(files, reserved_bundled_ids, ManifestSource::InstalledLocal)
}

/// Build a registry-installed extension package from already verified files.
///
/// Registry clients own signature, provenance, size, and digest verification.
/// This boundary still applies every extension-host invariant: reserved-id
/// rejection, manifest validation, declared-asset completeness, and WASI
/// component validation.
pub fn registry_extension_package(
files: Vec<(String, Vec<u8>)>,
reserved_bundled_ids: &[String],
) -> Result<AvailableExtensionPackage, ProductSurfaceFailure> {
extension_package_from_files(
files,
reserved_bundled_ids,
ManifestSource::RegistryInstalled,
)
}

fn extension_package_from_files(
files: Vec<(String, Vec<u8>)>,
reserved_bundled_ids: &[String],
source: ManifestSource,
) -> Result<AvailableExtensionPackage, ProductSurfaceFailure> {
let manifest_toml = files
.iter()
Expand All @@ -172,13 +197,13 @@ pub fn imported_extension_package(
reason: format!("host API contract registry rejected imported extension: {error}"),
}
})?;
// Uploads are always validated as InstalledLocal. Only binary-compiled
// packages may claim the HostBundled trust/runtime tier. The extension id
// (and so the package root) is only known once the manifest is parsed,
// so this first pass carries no root.
// Uploaded and registry packages are both untrusted host inputs. Only
// binary-compiled packages may claim the HostBundled trust/runtime tier.
// The extension id (and so the package root) is only known once the
// manifest is parsed, so this first pass carries no root.
let record = ExtensionManifestRecord::from_toml(
manifest_toml,
ManifestSource::InstalledLocal,
source,
&host_ports,
None,
&contracts,
Expand Down Expand Up @@ -207,7 +232,7 @@ pub fn imported_extension_package(
resolved_with_root.root = Some(root.clone());
let record = ExtensionManifestRecord::from_resolved(
record.raw_toml(),
ManifestSource::InstalledLocal,
source,
resolved_with_root,
record.manifest_hash().cloned(),
)
Expand Down Expand Up @@ -258,7 +283,7 @@ pub fn imported_extension_package(
)?,
manifest_toml: record.raw_toml().to_string(),
resolved_manifest: Arc::new(record.resolved().clone()),
source: ManifestSource::InstalledLocal,
source,
package,
cleanup_requirements: Vec::new(),
surface_kinds,
Expand Down
Loading
Loading