Skip to content

refactor(contracts): extract ironclaw_loop_contracts and flip agent_loop (WS1.2) - #6975

Merged
BenKurrek merged 18 commits into
mainfrom
ws1/loop-contracts
Jul 31, 2026
Merged

BenKurrek merged 18 commits into
mainfrom
ws1/loop-contracts

Conversation

@BenKurrek

@BenKurrek BenKurrek commented Jul 31, 2026 •

Copy link
Copy Markdown
Collaborator

Stacked on #6967 — merges after it; diff shown here is against that branch.

WS1.2: carve the loop tier's neutral contracts out of the turn kernel into crates/ironclaw_loop_contracts (PROPOSAL §6.1.4), flip ironclaw_agent_loop onto it, and land the enforcement + CI registration the new crate owes. Flat tree — the contracts/ family directory arrives in Wave 5.

Exceptions: 15 → 13

exception disposition
ironclaw_agent_loop → ironclaw_turns deleted — the edge is gone, not waived. agent_loop's manifest is now {common, host_api, loop_contracts} and the contracts-only rule resolves with no exception to consume.
ironclaw_hooks → ironclaw_turns deleted — same; hooks dropped the dependency outright.
ironclaw_conversations → ironclaw_turns survives, and the lead sheet was wrong about it (below).

WS0_LAYER_MATRIX_EXCEPTION_BASELINE lowered 15 → 13. Both deletions were confirmed by the stale-exception detector before I touched the list, not asserted.

The conversations straggler does not belong to this group

PROPOSAL §8.3 and PLAN both say conversations → turns falls with the port repoints here. Re-verified against the live tree, it does not and cannot: InboundTurnService is generic over C: TurnCoordinator + ?Sized, holds Arc<C>, and calls submit_turn(SubmitTurnRequest { … }) (inbound.rs:37,245); trusted_trigger.rs classifies TurnError / AdmissionRejectionReason. That is turn admission authority, not vocabulary and not a loop port — no contracts crate dissolves it. Its exception now records that evidence and reads removes_in = "WS5", matching §6.4.2, which already lists conversations' target deps as filesystem/host_api/safety/triggers "+ turn vocabulary via host_api", with no coordinator. The ≤ 12 target in the WS1 verify row needs WS5, not WS1.

What moved, and four things the lead sheet did not predict

Moved to ironclaw_loop_contracts (git mv, history preserved): all of turns::run_profile/** except two implementations; the LoopExit claim DTOs; RedactedCheckpointPayload + its ceiling; the three contract test suites (run_profile_contract, skill_context_service_contract, memory_prompt_context_service).

  1. The two HostManagedLoop*Port implementations did not move. §6.1.4 forbids a contracts crate from implementing its own ports; §6.7.2 assigns them to loop_host. So prompt.rs and the impl half of model.rs stayed in turns::host_managed_ports/ — a module whose doc comment says exactly that and says nothing new belongs in it — awaiting the WS4 loop_host re-charter. The contract half of model.rs (gateway / accountant / policy-guard traits + their request/error/outcome DTOs) moved.
  2. turns::origin had to move too, to host_api::turn. run_profile/runtime_context.rs carries Option<ProductTurnContext> on LoopRuntimeContext, so the type had to be reachable from a contracts crate. It is turn-scoped vocabulary consumed by kernel, substrates, loops and products — §6.1.1's turn charter verbatim — so it went to host_api, not to loop_contracts. GateResumeDisposition followed for the same reason (AgentLoopDriverResumeRequest and ResumeTurnRequest both carry it).
  3. CheckpointStateStorePort is only half-movable. RedactedCheckpointPayload + MAX_CHECKPOINT_STATE_PAYLOAD_BYTES moved. The LoopCheckpointStore trait did not: its methods return TurnError and its record carries TurnTimestamp, neither of which §6.1.4 assigns to this crate. The ceiling is now a literal in contracts, with an equality pin against ironclaw_processes::MAX_PROCESS_CHECKPOINT_PAYLOAD_BYTES in ironclaw_turns (which depends on both) so the two cannot drift.
  4. LoopExit::validate split from its DTO. The claim vocabulary moved; the validation (policy, violation taxonomy, applier) stayed — "a LoopExit is a claim, not truth" is kernel authority. Three private methods became pub because the kernel now calls them across a crate boundary: LoopBlockedKind::to_blocked_reason, LoopFailureKind::to_sanitized_failure, LoopCompleted::has_durable_completion_ref. to_blocked_reason returned Result<BlockedReason, ()>; it is now Option<BlockedReason> — behavior-identical, and () is not a public error type.
    Because LoopBlockedKind and LoopFailureKind are #[non_exhaustive], the kernel's exhaustive-match guards could no longer be exhaustive from another crate. Rather than weaken them to _ arms, the compiler-checked variant guards now live beside the enums in loop_contracts (blocked_kind_gate_correspondence_is_exhaustive, failure_kind_category_strings_are_exhaustive) and the kernel's behavioral suites keep loud _ arms pointing at them. The "a new variant breaks a test" property is preserved, in the crate where it can be.

One documented conflict, recorded rather than papered over: instruction_bundle.rs embeds one prompt asset via include_str!, and §6.1.4 says a contracts crate holds no prompt content. It moved anyway because hooks consumes InstructionMaterializationStore and leaving it behind would have kept the hooks → turns exception alive. The resolution §6.7.2 points at — hoist InstructionBundleBuilder to loop_host, leave the types here — is a WS4 item. It is called out in the new crate's CLAUDE.md under "Known debt".

New-crate disciplines (all in this PR)

  • Boundary rule for ironclaw_loop_contracts in reborn_dependency_boundaries.rs — new crates are unruled by default.
  • §11.2.3 contracts purity, both halves. Internal: an allowlist ({host_api, common, prompt_envelope}), not a blocklist, so a future kernel dep cannot slip past a list of today's offenders. External: a new reborn_contracts_crates_hold_no_framework_dependencies covering all four contracts crates — every existing metadata helper in that file filters to ironclaw_* names, so frameworks were invisible to them. One documented carve-out: tokio with rt only, for the single JoinHandle in CommunicationContextFetch::Spawned, pinned in the test and the manifest.
  • §11.2.4 port-location scan — new reborn_loop_port_location_scan.rs: every Loop*Port trait is defined once, in the crate frozen in LOOP_PORT_OWNERS (11 in loop_contracts; LoopExitEvidencePort in turns as kernel validation authority; LoopAttachmentReadPort in loop_host as an internal seam), plus the re-export-path half. It found a real pre-existing violation: runner/src/loop_exit_applier.rs re-exported LoopExitEvidencePort (and the applier + evidence requests) from ironclaw_turns, giving them two import paths. Converted to a plain use; the three internal consumers repoint. Ships with positive + negative fixtures per §11.2.11 — the predicate is anchored so HookedLoopModelPort / HostManagedLoopPromptPort are correctly out of scope.
  • CI registration (row 29, the known selector trap): root members, [package.metadata.ironclaw] layer = "contracts", classify-test-scope.sh's shared arm, reborn-crate-test-buckets.sh → agent-runtime. Verified rather than assumed: discover-reborn-package-crates.sh picks the crate up through the shipped-binary closure and needs no allowlist entry; both CI self-tests pass and the bash/python crate inventories agree at 64. Note for a follow-up, not fixed here: ironclaw_libsql_runtime and ironclaw_memory_mem0 are still missing from classify-test-scope.sh, so a diff touching only those crates classifies has_reborn_tests=false today — the trap in its live form, and the reason this row exists.
  • #![warn(unreachable_pub)], directory-of-modules lib.rs, crate CLAUDE.md. Ports are deliberately not sealed — they exist to be implemented above this crate; the sealed pattern stays with agent_loop's strategy slots, and the crate guide says so.
  • reborn_extension_specificity.rs's three PATH_TERM_COLLISIONS carve-outs repointed with the files (the scanner caught the staleness itself).

Un-masking

Unfiltered per-crate rosters before and after, every test classified:

crate before after accounting
ironclaw_turns 363 189 −186 / +12. 170 reappear verbatim in loop_contracts; 5 in host_api (the origin suite); 11 stayed in turns under the renamed module path (run_profile::{model,prompt}::tests::* → host_managed_ports::…, identical names); +1 new (the checkpoint-ceiling pin).
ironclaw_host_api 374 379 +5, exactly the 5 origin tests. Nothing lost.
ironclaw_loop_contracts — 173 170 moved + 3 new exhaustiveness guards.
ironclaw_agent_loop 504 504 identical roster
ironclaw_hooks 347 347 identical roster
ironclaw_loop_host 572 572 identical roster
ironclaw_runner 467 467 identical roster

Zero tests lost, zero unclassified, no surviving test edited for content. The only test-body edits are import repoints and the two _ arms described above.

Wire-shape proof for the hand-split DTOs

The highest-severity risk in this PR is that hand-splitting ~350 lines of serde DTOs out of loop_exit.rs silently changed a persisted wire shape (these ride journal rows). The proof it did not:

crates/ironclaw_turns/src/loop_exit/tests/mod.rs — 1,206 lines, 86 tests, including the five that pin the JSON contract of exactly the moved types (loop_exit_wire_shape_rejects_raw_payload_fields_and_recovery_required_variant, loop_failed_accepts_retired_diagnostic_ref_but_does_not_serialize_it, the snake_case serialization pair, and the policy-minting deserialization guard) — stayed in the kernel and its diff against the parent is import repoints plus the two _ arms, nothing else. Not one assertion, fixture, or expected-JSON literal was touched, and all 86 pass against the relocated types. A test suite that was not allowed to move is the only honest way to prove a move was faithful.

The whole crate's public surface was also diffed against the old ironclaw_turns::run_profile export list, so nothing could fall out of the API silently during the lib.rs rewrite:

  • 233 exports on the parent → 240 on the new crate root, and the arithmetic closes exactly: 233 − 4 + 11 = 240.
  • 0 unexpectedly missing.
  • 4 deliberately absent: the two HostManagedLoop*Port impls that stayed in the kernel, plus CapabilityActivityId and ProductTurnContext — run_profile re-exported those two from the turn vocabulary, and this crate deliberately does not, so each type keeps exactly one import path. Callers now take them from ironclaw_host_api::turn (a scripted repoint, not a hand edit).
  • 11 added: exactly the LoopExit DTO half (9 types) plus RedactedCheckpointPayload and MAX_CHECKPOINT_STATE_PAYLOAD_BYTES.

Verification

cargo fmt --check; clippy --all-targets --all-features -D warnings on all 16 touched crates; unfiltered cargo test -p on loop_contracts / host_api / turns / agent_loop / hooks / loop_host / runner; full cargo test -p ironclaw_architecture (green, including the two new tests). Also run: check_no_panics.py --reborn-baseline (OK, 1157 files — keying unchanged, no baseline regeneration owed), check-include-str-paths.sh, check-composition-budget.sh, and both CI script self-tests. CI is the arbiter for the workspace lanes.

Coverage manifests

tests/integration/coverage-floor.toml's [[crate]] ironclaw_turns entry drops its floor_covered_lines = 9515 numerator: 13,951 of the crate's 25,356 source lines moved out, so that absolute floor is structurally unreachable rather than regressed. floor_percent is retained unchanged rather than weakened. The recapture obligation — real numbers for ironclaw_turns and a new entry for ironclaw_loop_contracts, both from this PR's own merged artifact — is written into the file so it cannot be forgotten. No changed-coverage exemption is pre-written: per #6963's recipe those line numbers come from this PR's own gate output, not from a guess.

Checklist rows ticked: WS1.2 (with all four dispositions recorded), WS4's agent_loop flip; WS1's verify row and the new-crate CI row annotated with what is and is not now true.

BenKurrek and others added 9 commits July 31, 2026 11:59
…ire the turns shims (WS1.1)

`ironclaw_host_api::turn` becomes the complete canonical turn vocabulary:
it absorbs `TurnStatus` (with the inseparable `GateKind`/`BlockedReason`
gate correspondence), `EventCursor`, and `RunOriginAdapter`. The three
`ironclaw_turns` re-export shims named by CHECKLIST WS1.1 are deleted —
`src/ids.rs`, `src/scope.rs`, and the whole `src/product_adapter/`
module, whose `fakes.rs` moves beside the traits it implements in
`host_api::product_adapter::test_support`.

`ids.rs` carried `pub type GateRef = TurnGateRef`: a second name for a
host_api type that collided with the unrelated
`ironclaw_host_api::ids::GateRef` (an opaque uuid GateRecord key, versus
turns' bounded `gate:`-prefixed routing string). The alias is retired
rather than relocated, so the workspace now has exactly one `GateRef`.

The six vocabulary-only consumers — auth, event_streams, outbound,
telegram_extension, triggers, event_projections — import from
`ironclaw_host_api::turn` and drop their `ironclaw_turns` dependency
entirely. Five `*→turns` LAYER_MATRIX_EXCEPTIONS are therefore not
waived but obsolete: the edges no longer exist. The §11.2.2 ratchet
baseline moves 20 → 15.

No behavior change. `RunOriginAdapter`'s validation error becomes
`Result<_, String>` (matching every other bounded ref in
`host_api::turn`) with a byte-identical message pinned by a test, so
both production `e.to_string()` call sites are unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
WS1.1's box is ticked with what the change actually landed, including the
three lead-sheet corrections it turned up: the row named `TurnStatus` but
not `EventCursor`/`RunOriginAdapter` (which the six consumers genuinely
needed), `GateKind`/`BlockedReason` could not be left behind without
duplicating the single `GateKind -> TurnStatus` match table, and deleting
`ids.rs` forced retiring its `GateRef` alias rather than relocating it.

Two decisions confirmed outside the doc and never recorded:

- Strategy B (family dirs + focused crates) — confirmed 2026-07-31 by the
  owner, recorded retroactively; it was made in practice at program start.
- The `tools/` row's `default-members` trim — resolved as no trim.

Also surfaces #6963 on the WS0 blocking-prerequisite row's first line
(it was already cited mid-paragraph) and records the §11.2.2 exception
ratchet moving 20 -> 15.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…TurnGateRef contract

CodeRabbit review round on #6967.

Import repoints (accepted): every `use` line this PR already rewrote now
names `ironclaw_host_api::turn` directly instead of routing through
`ironclaw_turns`' prelude — 57 files across extension_host, product,
composition, runner, loop_host, conversations, the integration harness,
and the stress tool, plus three inside `ironclaw_turns` itself so the
crate stops consuming its own facade. Import lines this PR did not touch
are left for their consumer's own repoint slot.

TurnGateRef contract pinned (refutation): two review comments claimed
`TurnGateRef::new` only accepts `gate:approval-`/`gate:auth-` prefixes
and that fixtures like "gate-alpha" and "stress-gate:{run_id}" fail
construction. They do not — `TurnGateRef` is `bounded_ref!` (non-empty,
<= 256 bytes, no control characters); `LoopGateRef` is the prefix-
validated family via `loop_ref!(.., "gate:")`. The misreading traces to
this PR's own AGENTS.md wording ("bounded `gate:`-prefixed routing
string"), which stated a minting convention as if it were validation.
That wording is corrected and the distinction is now pinned by a test.

Also: drop a stale cross-file line reference in a product test comment.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The `tools/` row resolved the `default-members` trim as "no trim" but
kept a trailing "The `tools/`/`default-members` half is still open."
from before that decision, so the row asserted both states. Drop the
stale sentence.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Finishes the remediation deferred last round, now that the settled run
(job 91246493989) provides authoritative line numbers. Manifest-only —
no .rs file changes, so the changed-line set the gate computes is
unchanged and these numbers stay valid for the next run.

Derived, not transcribed: the gate was replayed locally against its own
merged lcov from that run, reproducing CI's failure byte-identically
first (95.17%, 138/145, same 13 files, same 7 lines), then re-run after
each entry. Final local result: 100.00% (138/138), branch 100% (4/4),
exit 0. All 45 gate self-tests pass.

Two classes, both verified rather than asserted:

- 13 files x 20 lines - declaration lines (fn params, return types,
  struct fields) whose only edit is the type NAME: GateRef ->
  TurnGateRef, or ironclaw_turns::X -> ironclaw_host_api::turn::X.
  Declarations are not executable, so these files contribute a zero
  denominator and trip the fail-closed empty_denominator branch.

- 7 lines x 3 files - executable, instrumented, and genuinely not
  exercised by the integration tier. Each checked against the base
  merged lcov (main @ 67088a4, the PR's own base sha): identical 0
  hits before and after, so no coverage was lost. approval_prompt_
  context_view is uncovered across its whole signature at base
  (lines 505-511); the background spawn-mode arm and the invalid-gate-
  ref error path likewise.

This includes the two entries I refused to guess last round -
turn_events.rs (three identical candidate lines by text; the settled
run disambiguates it as 510) and await_edge/store.rs (no verbatim twin
after the repoint; authoritatively 268-272).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…oop (WS1.2)

Carve the loop tier's neutral contracts out of the turn kernel into a new
contracts-layer crate per PROPOSAL 6.1.4, and repoint every consumer.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…new crate

Enforcement, CI registration, and guidance for the WS1.2 extraction.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@coderabbitai

coderabbitai Bot commented Jul 31, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 338 files, which is 38 over the limit of 300.

To get a review, narrow the scope:
• coderabbit review --committed # exclude uncommitted changes
• coderabbit review --dir # limit to a subdirectory
• coderabbit review --base # compare against a closer base

Usage-priced reviews support at most 300 files.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 7c6d3982-7ad7-4e83-8852-e8d68054f689

📥 Commits

Reviewing files that changed from the base of the PR and between 2e65225 and 3472ed4.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock, !**/Cargo.lock
📒 Files selected for processing (338)
  • Cargo.toml
  • crates/AGENTS.md
  • crates/Architecture.md
  • crates/ironclaw_agent_loop/Cargo.toml
  • crates/ironclaw_agent_loop/src/default_planner.rs
  • crates/ironclaw_agent_loop/src/executor.rs
  • crates/ironclaw_agent_loop/src/executor/assistant_reply.rs
  • crates/ironclaw_agent_loop/src/executor/budget.rs
  • crates/ironclaw_agent_loop/src/executor/canonical.rs
  • crates/ironclaw_agent_loop/src/executor/capabilities.rs
  • crates/ironclaw_agent_loop/src/executor/capability_helpers.rs
  • crates/ironclaw_agent_loop/src/executor/checkpoint.rs
  • crates/ironclaw_agent_loop/src/executor/exit_helpers.rs
  • crates/ironclaw_agent_loop/src/executor/failure_explanation.rs
  • crates/ironclaw_agent_loop/src/executor/gates.rs
  • crates/ironclaw_agent_loop/src/executor/input.rs
  • crates/ironclaw_agent_loop/src/executor/latency.rs
  • crates/ironclaw_agent_loop/src/executor/loop_exit.rs
  • crates/ironclaw_agent_loop/src/executor/mapping.rs
  • crates/ironclaw_agent_loop/src/executor/model.rs
  • crates/ironclaw_agent_loop/src/executor/pipeline.rs
  • crates/ironclaw_agent_loop/src/executor/post_capability.rs
  • crates/ironclaw_agent_loop/src/executor/prompt.rs
  • crates/ironclaw_agent_loop/src/executor/reply_admission.rs
  • crates/ironclaw_agent_loop/src/executor/tests.rs
  • crates/ironclaw_agent_loop/src/executor/tests/cancellation.rs
  • crates/ironclaw_agent_loop/src/executor/tests/failure_matrix.rs
  • crates/ironclaw_agent_loop/src/executor/tests/support.rs
  • crates/ironclaw_agent_loop/src/executor/tests/support/compaction.rs
  • crates/ironclaw_agent_loop/src/executor/turn_stop.rs
  • crates/ironclaw_agent_loop/src/state.rs
  • crates/ironclaw_agent_loop/src/state/model_recovery.rs
  • crates/ironclaw_agent_loop/src/state/signature.rs
  • crates/ironclaw_agent_loop/src/state/slots.rs
  • crates/ironclaw_agent_loop/src/state/terminal_warning.rs
  • crates/ironclaw_agent_loop/src/strategies/active_task_compaction.rs
  • crates/ironclaw_agent_loop/src/strategies/batch.rs
  • crates/ironclaw_agent_loop/src/strategies/budget.rs
  • crates/ironclaw_agent_loop/src/strategies/capability.rs
  • crates/ironclaw_agent_loop/src/strategies/compaction.rs
  • crates/ironclaw_agent_loop/src/strategies/context.rs
  • crates/ironclaw_agent_loop/src/strategies/drain.rs
  • crates/ironclaw_agent_loop/src/strategies/gate.rs
  • crates/ironclaw_agent_loop/src/strategies/mod.rs
  • crates/ironclaw_agent_loop/src/strategies/model.rs
  • crates/ironclaw_agent_loop/src/strategies/progress.rs
  • crates/ironclaw_agent_loop/src/strategies/recovery.rs
  • crates/ironclaw_agent_loop/src/strategies/reply_admission.rs
  • crates/ironclaw_agent_loop/src/strategies/stop.rs
  • crates/ironclaw_agent_loop/src/test_support/compaction.rs
  • crates/ironclaw_agent_loop/src/test_support/mod.rs
  • crates/ironclaw_agent_loop/tests/deferred_followups.rs
  • crates/ironclaw_agent_loop/tests/executor_happy_paths.rs
  • crates/ironclaw_agent_loop/tests/safety_nets.rs
  • crates/ironclaw_agent_loop/tests/state_lifecycle.rs
  • crates/ironclaw_agent_loop/tests/strategy_interactions.rs
  • crates/ironclaw_architecture/tests/reborn_dependency_boundaries.rs
  • crates/ironclaw_architecture/tests/reborn_extension_specificity.rs
  • crates/ironclaw_architecture/tests/reborn_loop_port_location_scan.rs
  • crates/ironclaw_capabilities/Cargo.toml
  • crates/ironclaw_capabilities/src/replay_payload.rs
  • crates/ironclaw_capabilities/tests/replay_payload_store_contract.rs
  • crates/ironclaw_extension_host/Cargo.toml
  • crates/ironclaw_extension_host/src/extension_lifecycle_capabilities.rs
  • crates/ironclaw_extension_host/src/host_remediation_contract_tests.rs
  • crates/ironclaw_first_party_extension_ports/Cargo.toml
  • crates/ironclaw_first_party_extension_ports/src/activation.rs
  • crates/ironclaw_first_party_extension_ports/src/assets.rs
  • crates/ironclaw_first_party_extension_ports/src/execution.rs
  • crates/ironclaw_first_party_extension_ports/src/setup_markers.rs
  • crates/ironclaw_first_party_extension_ports/src/skill_activation_capability.rs
  • crates/ironclaw_first_party_extension_ports/src/skills.rs
  • crates/ironclaw_first_party_extensions/Cargo.toml
  • crates/ironclaw_first_party_extensions/src/coding/mod.rs
  • crates/ironclaw_hooks/Cargo.toml
  • crates/ironclaw_hooks/src/dispatch/mod.rs
  • crates/ironclaw_hooks/src/middleware/capability_port.rs
  • crates/ironclaw_hooks/src/middleware/checkpoint_port.rs
  • crates/ironclaw_hooks/src/middleware/gate_ref.rs
  • crates/ironclaw_hooks/src/middleware/model_port.rs
  • crates/ironclaw_hooks/src/middleware/prompt_port.rs
  • crates/ironclaw_hooks/src/middleware/resolver.rs
  • crates/ironclaw_hooks/src/middleware/transcript_port.rs
  • crates/ironclaw_hooks/src/registry.rs
  • crates/ironclaw_hooks/src/self_authored.rs
  • crates/ironclaw_hooks/src/telemetry.rs
  • crates/ironclaw_hooks/tests/foundation_pipeline.rs
  • crates/ironclaw_host_api/src/safe_summary.rs
  • crates/ironclaw_host_api/src/turn.rs
  • crates/ironclaw_host_runtime/Cargo.toml
  • crates/ironclaw_host_runtime/src/memory_context.rs
  • crates/ironclaw_host_runtime/src/production.rs
  • crates/ironclaw_host_runtime/src/services.rs
  • crates/ironclaw_host_runtime/src/user_profile_source.rs
  • crates/ironclaw_host_runtime/tests/first_party_coding_tools.rs
  • crates/ironclaw_host_runtime/tests/host_runtime_services_contract.rs
  • crates/ironclaw_host_runtime/tests/memory_prompt_context.rs
  • crates/ironclaw_host_runtime/tests/user_profile_roundtrip.rs
  • crates/ironclaw_loop_contracts/CLAUDE.md
  • crates/ironclaw_loop_contracts/Cargo.toml
  • crates/ironclaw_loop_contracts/prompts/capability_surface_usage_policy.md
  • crates/ironclaw_loop_contracts/src/checkpoint_payload.rs
  • crates/ironclaw_loop_contracts/src/compaction.rs
  • crates/ironclaw_loop_contracts/src/content_digest.rs
  • crates/ironclaw_loop_contracts/src/context_budget.rs
  • crates/ironclaw_loop_contracts/src/driver.rs
  • crates/ironclaw_loop_contracts/src/host/capability.rs
  • crates/ironclaw_loop_contracts/src/host/checkpoint.rs
  • crates/ironclaw_loop_contracts/src/host/context.rs
  • crates/ironclaw_loop_contracts/src/host/error.rs
  • crates/ironclaw_loop_contracts/src/host/input.rs
  • crates/ironclaw_loop_contracts/src/host/mod.rs
  • crates/ironclaw_loop_contracts/src/host/model.rs
  • crates/ironclaw_loop_contracts/src/host/progress.rs
  • crates/ironclaw_loop_contracts/src/host/refs.rs
  • crates/ironclaw_loop_contracts/src/host/run_context.rs
  • crates/ironclaw_loop_contracts/src/host/transcript.rs
  • crates/ironclaw_loop_contracts/src/host/validate.rs
  • crates/ironclaw_loop_contracts/src/instruction_bundle.rs
  • crates/ironclaw_loop_contracts/src/lib.rs
  • crates/ironclaw_loop_contracts/src/loop_exit.rs
  • crates/ironclaw_loop_contracts/src/memory_context.rs
  • crates/ironclaw_loop_contracts/src/milestones.rs
  • crates/ironclaw_loop_contracts/src/model.rs
  • crates/ironclaw_loop_contracts/src/model_observation.rs
  • crates/ironclaw_loop_contracts/src/model_work.rs
  • crates/ironclaw_loop_contracts/src/policy.rs
  • crates/ironclaw_loop_contracts/src/prompt_text.rs
  • crates/ironclaw_loop_contracts/src/refs.rs
  • crates/ironclaw_loop_contracts/src/resolution.rs
  • crates/ironclaw_loop_contracts/src/resolver.rs
  • crates/ironclaw_loop_contracts/src/runtime_context.rs
  • crates/ironclaw_loop_contracts/src/skill_context.rs
  • crates/ironclaw_loop_contracts/src/snapshot.rs
  • crates/ironclaw_loop_contracts/src/snippet_ref.rs
  • crates/ironclaw_loop_contracts/src/system_inference.rs
  • crates/ironclaw_loop_contracts/tests/memory_prompt_context_service.rs
  • crates/ironclaw_loop_contracts/tests/run_profile_contract.rs
  • crates/ironclaw_loop_contracts/tests/skill_context_service_contract.rs
  • crates/ironclaw_loop_host/Cargo.toml
  • crates/ironclaw_loop_host/src/await_edge_port.rs
  • crates/ironclaw_loop_host/src/budget_accountant.rs
  • crates/ironclaw_loop_host/src/budget_cost_table.rs
  • crates/ironclaw_loop_host/src/cancellation_port.rs
  • crates/ironclaw_loop_host/src/cancellation_port/tests.rs
  • crates/ironclaw_loop_host/src/capability_allow_set.rs
  • crates/ironclaw_loop_host/src/capability_info.rs
  • crates/ironclaw_loop_host/src/capability_port.rs
  • crates/ironclaw_loop_host/src/capability_port/provider_input.rs
  • crates/ironclaw_loop_host/src/capability_port/provider_validation.rs
  • crates/ironclaw_loop_host/src/capability_port/surface_snapshot.rs
  • crates/ironclaw_loop_host/src/capability_port/tests/runtime_lifecycle_tests.rs
  • crates/ironclaw_loop_host/src/capability_surface_filter.rs
  • crates/ironclaw_loop_host/src/compaction_task.rs
  • crates/ironclaw_loop_host/src/external_tool_capability.rs
  • crates/ironclaw_loop_host/src/filesystem_skill_bundle_source.rs
  • crates/ironclaw_loop_host/src/identity_context.rs
  • crates/ironclaw_loop_host/src/input_port.rs
  • crates/ironclaw_loop_host/src/input_queue.rs
  • crates/ironclaw_loop_host/src/lib.rs
  • crates/ironclaw_loop_host/src/memory_context.rs
  • crates/ironclaw_loop_host/src/model_capability_view.rs
  • crates/ironclaw_loop_host/src/model_visible_scrub.rs
  • crates/ironclaw_loop_host/src/prompt_context_budget.rs
  • crates/ironclaw_loop_host/src/result_read.rs
  • crates/ironclaw_loop_host/src/skill_bundle_context_source.rs
  • crates/ironclaw_loop_host/src/skill_bundle_source.rs
  • crates/ironclaw_loop_host/src/skill_context.rs
  • crates/ironclaw_loop_host/src/subagent_prompt_port.rs
  • crates/ironclaw_loop_host/src/subagent_spawn_port.rs
  • crates/ironclaw_loop_host/src/subagent_spawn_port/tests.rs
  • crates/ironclaw_loop_host/src/surface_disclosure.rs
  • crates/ironclaw_loop_host/src/synthetic_capability.rs
  • crates/ironclaw_loop_host/src/system_inference.rs
  • crates/ironclaw_loop_host/src/thread_scope.rs
  • crates/ironclaw_loop_host/src/user_profile_context.rs
  • crates/ironclaw_loop_host/tests/compaction_task_contract.rs
  • crates/ironclaw_loop_host/tests/host_capability_port_composition.rs
  • crates/ironclaw_loop_host/tests/thread_loop_host_contract.rs
  • crates/ironclaw_product/Cargo.toml
  • crates/ironclaw_product/src/communication_context.rs
  • crates/ironclaw_product/src/project_create_capability.rs
  • crates/ironclaw_product/src/projection.rs
  • crates/ironclaw_product/src/projection/display_preview.rs
  • crates/ironclaw_product/src/projection/live_progress.rs
  • crates/ironclaw_product/src/projection/tests.rs
  • crates/ironclaw_product/src/projection/tests/display_preview.rs
  • crates/ironclaw_product/src/projection/tests/display_preview_runtime.rs
  • crates/ironclaw_product/src/projection/tests/failure_explanation.rs
  • crates/ironclaw_product/src/projection/tests/live_progress_stream.rs
  • crates/ironclaw_product/src/projection/tests/runtime_stream.rs
  • crates/ironclaw_product/src/projection/turn_events.rs
  • crates/ironclaw_product/src/reborn_services/types.rs
  • crates/ironclaw_product/tests/inbound_turn_contract.rs
  • crates/ironclaw_product/tests/reborn_services_contract.rs
  • crates/ironclaw_product/tests/support/planned_agent_loop.rs
  • crates/ironclaw_reborn_composition/Cargo.toml
  • crates/ironclaw_reborn_composition/src/error.rs
  • crates/ironclaw_reborn_composition/src/factory.rs
  • crates/ironclaw_reborn_composition/src/lib.rs
  • crates/ironclaw_reborn_composition/src/llm_admin/openai_compat_serve.rs
  • crates/ironclaw_reborn_composition/src/memory_provider_factory.rs
  • crates/ironclaw_reborn_composition/src/model_gateway_assembly.rs
  • crates/ironclaw_reborn_composition/src/observability/budget.rs
  • crates/ironclaw_reborn_composition/src/root/default_system_prompt.rs
  • crates/ironclaw_reborn_composition/src/root/product_live_adapters.rs
  • crates/ironclaw_reborn_composition/src/runtime.rs
  • crates/ironclaw_reborn_composition/src/runtime/capability_host.rs
  • crates/ironclaw_reborn_composition/src/runtime/capability_host/outbound_delivery.rs
  • crates/ironclaw_reborn_composition/src/runtime/capability_host/refreshing_capability_port.rs
  • crates/ironclaw_reborn_composition/src/runtime/capability_host/shell_tests.rs
  • crates/ironclaw_reborn_composition/src/runtime/capability_host/tests.rs
  • crates/ironclaw_reborn_composition/src/runtime/production.rs
  • crates/ironclaw_reborn_composition/src/runtime/skills.rs
  • crates/ironclaw_reborn_composition/src/runtime/tests/core.rs
  • crates/ironclaw_reborn_composition/src/runtime/tests/outbound_delivery.rs
  • crates/ironclaw_reborn_composition/src/test_support/budget_gateway.rs
  • crates/ironclaw_reborn_composition/src/test_support/refreshing_capability_port.rs
  • crates/ironclaw_reborn_composition/src/test_support/result_read.rs
  • crates/ironclaw_reborn_composition/tests/budget_approval_e2e.rs
  • crates/ironclaw_reborn_composition/tests/budget_e2e.rs
  • crates/ironclaw_reborn_composition/tests/product_live_adapters.rs
  • crates/ironclaw_reborn_composition/tests/refreshing_capability_port_test_support.rs
  • crates/ironclaw_reborn_composition/tests/runtime.rs
  • crates/ironclaw_reborn_composition/tests/trigger_poller_e2e.rs
  • crates/ironclaw_reborn_composition/tests/webui_v2_e2e.rs
  • crates/ironclaw_runner/Cargo.toml
  • crates/ironclaw_runner/src/driver_registry.rs
  • crates/ironclaw_runner/src/failure_categories.rs
  • crates/ironclaw_runner/src/failure_lane.rs
  • crates/ironclaw_runner/src/failure_summary.rs
  • crates/ironclaw_runner/src/hook_gate_refs.rs
  • crates/ironclaw_runner/src/loop_driver_host.rs
  • crates/ironclaw_runner/src/loop_driver_host/compaction_tests.rs
  • crates/ironclaw_runner/src/loop_driver_host/config.rs
  • crates/ironclaw_runner/src/loop_driver_host/model_gateway.rs
  • crates/ironclaw_runner/src/loop_driver_host/port_adapters.rs
  • crates/ironclaw_runner/src/loop_driver_host/tests.rs
  • crates/ironclaw_runner/src/loop_exit_applier.rs
  • crates/ironclaw_runner/src/loop_exit_applier/tests/mod.rs
  • crates/ironclaw_runner/src/loop_exit_applier/tests/support.rs
  • crates/ironclaw_runner/src/milestone_events.rs
  • crates/ironclaw_runner/src/model_failure_mapping.rs
  • crates/ironclaw_runner/src/model_gateway.rs
  • crates/ironclaw_runner/src/model_gateway_error_mapping.rs
  • crates/ironclaw_runner/src/model_routes.rs
  • crates/ironclaw_runner/src/planned_driver.rs
  • crates/ironclaw_runner/src/planned_driver_factory.rs
  • crates/ironclaw_runner/src/production_readiness.rs
  • crates/ironclaw_runner/src/runtime.rs
  • crates/ironclaw_runner/src/subagent/await_edge/boot_recovery.rs
  • crates/ironclaw_runner/src/subagent/await_edge/mod.rs
  • crates/ironclaw_runner/src/subagent/await_edge/resolver.rs
  • crates/ironclaw_runner/src/subagent/await_edge/store.rs
  • crates/ironclaw_runner/src/subagent/capability_surface.rs
  • crates/ironclaw_runner/src/subagent/flavors.rs
  • crates/ironclaw_runner/src/subagent/prompt_material.rs
  • crates/ironclaw_runner/src/subagent/untrusted_text.rs
  • crates/ironclaw_runner/src/text_loop_driver.rs
  • crates/ironclaw_runner/src/tool_disclosure.rs
  • crates/ironclaw_runner/src/tool_disclosure_port.rs
  • crates/ironclaw_runner/src/turn_run_executor.rs
  • crates/ironclaw_runner/src/turn_runner.rs
  • crates/ironclaw_runner/tests/driver_registry.rs
  • crates/ironclaw_runner/tests/llm_gateway.rs
  • crates/ironclaw_runner/tests/model_routes.rs
  • crates/ironclaw_runner/tests/planned_driver_e2e.rs
  • crates/ironclaw_runner/tests/production_readiness.rs
  • crates/ironclaw_turns/AGENTS.md
  • crates/ironclaw_turns/CLAUDE.md
  • crates/ironclaw_turns/Cargo.toml
  • crates/ironclaw_turns/src/agent_turn_runtime.rs
  • crates/ironclaw_turns/src/checkpoint_state.rs
  • crates/ironclaw_turns/src/coordinator.rs
  • crates/ironclaw_turns/src/host_managed_ports/mod.rs
  • crates/ironclaw_turns/src/host_managed_ports/model.rs
  • crates/ironclaw_turns/src/host_managed_ports/prompt.rs
  • crates/ironclaw_turns/src/lib.rs
  • crates/ironclaw_turns/src/loop_exit.rs
  • crates/ironclaw_turns/src/loop_exit/tests/mod.rs
  • crates/ironclaw_turns/src/origin.rs
  • crates/ironclaw_turns/src/process_projection/loop_checkpoint.rs
  • crates/ironclaw_turns/src/process_projection/metadata.rs
  • crates/ironclaw_turns/src/process_projection/runtime.rs
  • crates/ironclaw_turns/src/process_projection/tests.rs
  • crates/ironclaw_turns/src/request.rs
  • crates/ironclaw_turns/src/run_profile/CLAUDE.md
  • crates/ironclaw_turns/src/runner.rs
  • crates/ironclaw_turns/src/status.rs
  • crates/ironclaw_turns/tests/agent_loop_host_contract.rs
  • docs/reborn/contracts/host-api.md
  • docs/reborn/contracts/loop-exit.md
  • docs/reborn/target-architecture/CHECKLIST.md
  • scripts/ci/classify-test-scope.sh
  • scripts/ci/reborn-crate-test-buckets.sh
  • scripts/reborn-e2e-rust.sh
  • tests/integration/changed-coverage-exemptions.toml
  • tests/integration/coverage-exemptions.toml
  • tests/integration/coverage-floor.toml
  • tests/integration/group_triggers/scenario_trigger_self_create_denied.rs
  • tests/integration/model_recovery.rs
  • tests/integration/profile.rs
  • tests/integration/safety.rs
  • tests/integration/support/assertions.rs
  • tests/integration/support/builder.rs
  • tests/integration/support/comm_context.rs
  • tests/integration/support/doubles/empty_identity_context_source.rs
  • tests/integration/support/doubles/harness_capability_port_factory.rs
  • tests/integration/support/doubles/host_runtime_harness_capability_port_factory.rs
  • tests/integration/support/doubles/recording_capability_result_writer.rs
  • tests/integration/support/doubles/recording_delegating_capability_port.rs
  • tests/integration/support/doubles/recording_test_capability_port.rs
  • tests/integration/support/doubles/static_capability_surface_profile_resolver.rs
  • tests/integration/support/group.rs
  • tests/integration/support/group_options.rs
  • tests/integration/support/harness/mod.rs
  • tests/integration/support/harness/recorder.rs
  • tests/integration/support/scope_gateway.rs
  • tests/integration/support/triggered_submit.rs
  • tests/reborn_approval_traces_parity.rs
  • tests/reborn_failure_retry_resume_e2e.rs
  • tests/reborn_identity_project_scope_isolation_parity.rs
  • tests/reborn_identity_prompt_scope_isolation_parity.rs
  • tests/reborn_identity_tenant_scope_isolation_parity.rs
  • tests/reborn_qa_connect_flows.rs
  • tests/reborn_qa_smoke_scenarios_e2e.rs
  • tests/reborn_recorded_trace_parity.rs
  • tests/reborn_response_order_parity.rs
  • tests/reborn_trace_coding_read_tools_parity.rs
  • tests/reborn_trace_core_builtin_tools_parity.rs
  • tests/reborn_trace_error_path_parity.rs
  • tests/reborn_trace_file_tools_parity.rs
  • tests/reborn_trace_first_party_tool_coverage.rs
  • tests/support/reborn_parity_qa/binary_e2e.rs
  • tests/support/reborn_parity_qa/model_replay.rs
  • tests/support/reborn_parity_qa/qa_trace.rs
  • tools/ironclaw_stress/Cargo.toml
  • tools/ironclaw_stress/src/user_turn.rs

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@railway-app

railway-app Bot commented Jul 31, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-6975 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Jul 31, 2026 at 9:55 pm

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6975 July 31, 2026 19:47 Destroyed
@github-actions github-actions Bot added size: XL 500+ changed lines scope: docs Documentation scope: dependencies Dependency updates risk: medium Business logic, config, or moderate-risk modules contributor: core 20+ merged PRs labels Jul 31, 2026
…he two crates

The claim types moved to ironclaw_loop_contracts with WS1.2; the validator
policy and the trusted applier stayed in the turn kernel.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6975 July 31, 2026 19:49 Destroyed
The two HostManagedLoop*Port impls stayed in ironclaw_turns, so same-crate
links to them no longer resolve; the TurnRunId link target became redundant
when the import repoint fully qualified it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6975 July 31, 2026 19:51 Destroyed
Removing the ironclaw_runner re-export (required by the new port-location
scan) left two workspace-root test-support files importing the turn kernel's
evidence types through it. They now import from ironclaw_turns::loop_exit
directly, which is the single sanctioned path.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
#6967 landed as a squash, so this branch carries the parent's original
commits while main carries their collapsed equivalent. Merging reconciles
the two shapes; the result must be main plus exactly the WS1.2 delta.

# Conflicts:
#	crates/ironclaw_architecture/tests/reborn_dependency_boundaries.rs
#	crates/ironclaw_host_api/src/turn.rs
#	crates/ironclaw_host_runtime/tests/memory_prompt_context.rs
#	crates/ironclaw_loop_contracts/src/host/checkpoint.rs
#	crates/ironclaw_loop_contracts/src/memory_context.rs
#	crates/ironclaw_loop_contracts/tests/memory_prompt_context_service.rs
#	crates/ironclaw_loop_host/src/subagent_spawn_port.rs
#	crates/ironclaw_product/src/communication_context.rs
#	crates/ironclaw_product/src/projection/tests.rs
#	crates/ironclaw_product/src/projection/turn_events.rs
#	crates/ironclaw_product/src/reborn_services/types.rs
#	crates/ironclaw_reborn_composition/src/llm_admin/openai_compat_serve.rs
#	crates/ironclaw_reborn_composition/src/runtime.rs
#	crates/ironclaw_reborn_composition/src/runtime/capability_host/tests.rs
#	crates/ironclaw_reborn_composition/src/runtime/tests/core.rs
#	crates/ironclaw_runner/src/loop_exit_applier/tests/mod.rs
#	crates/ironclaw_runner/src/loop_exit_applier/tests/support.rs
#	crates/ironclaw_runner/src/subagent/await_edge/resolver.rs
#	crates/ironclaw_turns/src/agent_turn_runtime.rs
#	crates/ironclaw_turns/src/coordinator.rs
#	crates/ironclaw_turns/src/lib.rs
#	crates/ironclaw_turns/src/loop_exit.rs
#	crates/ironclaw_turns/src/loop_exit/tests/mod.rs
#	crates/ironclaw_turns/src/origin.rs
#	crates/ironclaw_turns/src/process_projection/runtime.rs
#	crates/ironclaw_turns/src/process_projection/tests.rs
#	crates/ironclaw_turns/src/request.rs
#	crates/ironclaw_turns/src/status.rs
#	crates/ironclaw_turns/tests/agent_loop_host_contract.rs
#	docs/reborn/target-architecture/CHECKLIST.md
#	tests/integration/support/comm_context.rs
#	tests/integration/support/harness/mod.rs
#	tests/integration/support/harness/recorder.rs
#	tests/integration/support/triggered_submit.rs
#	tests/support/reborn_parity_qa/binary_e2e.rs
#	tools/ironclaw_stress/src/user_turn.rs
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6975 July 31, 2026 20:17 Destroyed
…scan

Two artifacts of collapsing onto main:

- Cargo.lock pinned thiserror 2.0.18 for the new ironclaw_loop_contracts
  entry while main's dependency bump moved the workspace to 2.0.19. The
  auto-merge kept the stale pin because the bump predates the crate, so
  --locked builds failed.
- ironclaw_product's failure-summary test reaches into another crate's
  source with include_str! and scans it for 'impl LoopFailureKind'. WS1.2
  moved that impl to ironclaw_loop_contracts, so the include still resolved
  and matched nothing. Repointed to follow the code.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6975 July 31, 2026 20:23 Destroyed
scripts/reborn-e2e-rust.sh pins exact test names for the deterministic
gate. The capability-failure rehydration test moved from
ironclaw_turns::run_profile::host::capability to
ironclaw_loop_contracts::host::capability, so its selector matched zero
tests and the gate failed closed.

Swept all 10 pinned selectors in that script (4 lib + 6 integration
target); this was the only stale one. Each now resolves to exactly one
test, verified by running the selector.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6975 July 31, 2026 20:39 Destroyed
@github-actions

github-actions Bot commented Jul 31, 2026 •

Copy link
Copy Markdown
Contributor

Coverage ratchet

Ratchet mode: ENFORCING

RATCHET PASS: global
  observed: 85.87% (323263 / 376442 lines)
  floor:    85.11% (tolerance 0.5pp -> effective floor 84.61%)
  denominator: 376442 lines now vs 375097 at floor capture (+1345 lines, +0.36%) — not a material change

RATCHET PASS: ironclaw_runner
  observed: 86% (15134 / 17597 lines)
  floor:    85.55% (tolerance 0.5pp -> effective floor 85.05%)
  floor_covered_lines: 14658 (tolerance 20 lines -> effective floor 14638)
  denominator: 17597 lines now vs 17133 at floor capture (+464 lines, +2.71%) — not a material change

RATCHET PASS: ironclaw_processes
  observed: 88.76% (5889 / 6635 lines)
  floor:    88.07% (tolerance 0.5pp -> effective floor 87.57%)
  floor_covered_lines: 5839 (tolerance 20 lines -> effective floor 5819)
  denominator: 6635 lines now vs 6630 at floor capture (+5 lines, +0.08%) — not a material change

RATCHET PASS: ironclaw_turns
  observed: 88.46% (3709 / 4193 lines)
  floor:    85.11% (tolerance 0.5pp -> effective floor 84.61%)

RATCHET PASS: ironclaw_authorization
  observed: 86.59% (723 / 835 lines)
  floor:    62.51% (tolerance 0.5pp -> effective floor 62.01%)
  floor_covered_lines: 612 (tolerance 20 lines -> effective floor 592)
  denominator: 835 lines now vs 979 at floor capture (-144 lines, -14.71%) — material change (>5%)

RATCHET PASS: ironclaw_approvals
  observed: 91.05% (1820 / 1999 lines)
  floor:    85.86% (tolerance 0.5pp -> effective floor 85.36%)
  floor_covered_lines: 1822 (tolerance 20 lines -> effective floor 1802)
  denominator: 1999 lines now vs 2122 at floor capture (-123 lines, -5.8%) — material change (>5%)

RATCHET PASS: ironclaw_secrets
  observed: 85.81% (2896 / 3375 lines)
  floor:    84.01% (tolerance 0.5pp -> effective floor 83.51%)
  floor_covered_lines: 2795 (tolerance 20 lines -> effective floor 2775)
  denominator: 3375 lines now vs 3327 at floor capture (+48 lines, +1.44%) — not a material change

RATCHET PASS: ironclaw_filesystem
  observed: 76.79% (5892 / 7673 lines)
  floor:    75.93% (tolerance 0.5pp -> effective floor 75.43%)
  floor_covered_lines: 5826 (tolerance 20 lines -> effective floor 5806)
  denominator: 7673 lines now vs 7673 at floor capture (+0 lines, +0%) — not a material change

RATCHET PASS: ironclaw_llm
  observed: 79.22% (20885 / 26364 lines)
  floor:    79.22% (tolerance 0.5pp -> effective floor 78.72%)
  floor_covered_lines: 20885 (tolerance 20 lines -> effective floor 20865)
  denominator: 26364 lines now vs 26364 at floor capture (+0 lines, +0%) — not a material change

RATCHET PASS: ironclaw_triggers
  observed: 94.88% (3092 / 3259 lines)
  floor:    86.04% (tolerance 0.5pp -> effective floor 85.54%)
  floor_covered_lines: 2804 (tolerance 20 lines -> effective floor 2784)
  denominator: 3259 lines now vs 3259 at floor capture (+0 lines, +0%) — not a material change

RATCHET PASS: ironclaw_product
  observed: 87.38% (22831 / 26129 lines)
  floor:    86.94% (tolerance 0.5pp -> effective floor 86.44%)
  floor_covered_lines: 21367 (tolerance 20 lines -> effective floor 21347)
  denominator: 26129 lines now vs 24576 at floor capture (+1553 lines, +6.32%) — material change (>5%)

RATCHET PASS: ironclaw_outbound
  observed: 94.68% (4271 / 4511 lines)
  floor:    93.49% (tolerance 0.5pp -> effective floor 92.99%)
  floor_covered_lines: 4105 (tolerance 20 lines -> effective floor 4085)
  denominator: 4511 lines now vs 4391 at floor capture (+120 lines, +2.73%) — not a material change

RATCHET PASS: ironclaw_extension_host
  observed: 84.99% (24337 / 28635 lines)
  floor:    83.82% (tolerance 0.5pp -> effective floor 83.32%)
  floor_covered_lines: 22271 (tolerance 20 lines -> effective floor 22251)
  denominator: 28635 lines now vs 26569 at floor capture (+2066 lines, +7.78%) — material change (>5%)

RATCHET PASS: ironclaw_events
  observed: 80.55% (1197 / 1486 lines)
  floor:    80.55% (tolerance 0.5pp -> effective floor 80.05%)
  floor_covered_lines: 1197 (tolerance 20 lines -> effective floor 1177)
  denominator: 1486 lines now vs 1486 at floor capture (+0 lines, +0%) — not a material change

RATCHET PASS: ironclaw_safety
  observed: 92.75% (4468 / 4817 lines)
  floor:    92.44% (tolerance 0.5pp -> effective floor 91.94%)
  floor_covered_lines: 3973 (tolerance 20 lines -> effective floor 3953)
  denominator: 4817 lines now vs 4298 at floor capture (+519 lines, +12.08%) — material change (>5%)

RATCHET PASS: ironclaw_host_runtime
  observed: 88.41% (21338 / 24135 lines)
  floor:    88.23% (tolerance 0.5pp -> effective floor 87.73%)
  floor_covered_lines: 20538 (tolerance 20 lines -> effective floor 20518)
  denominator: 24135 lines now vs 23277 at floor capture (+858 lines, +3.69%) — not a material change

Reborn integration-tier coverage

Line coverage (Reborn crates): 85.87% — 323263 / 376442 lines

Per-crate breakdown (61 crates, lowest-covered first)
Crate Line % Covered / Total
ironclaw_host_ingress 42.5% 17 / 40
ironclaw_memory 53.48% 630 / 1178
ironclaw_projects 72.36% 233 / 322
ironclaw_capabilities 74.59% 2876 / 3856
ironclaw_trust 75.79% 748 / 987
ironclaw_extractors 75.88% 538 / 709
ironclaw_reborn_cli 76.1% 11084 / 14566
ironclaw_observability 76.19% 32 / 42
ironclaw_filesystem 76.79% 5892 / 7673
ironclaw_wasm 78.84% 704 / 893
ironclaw_llm 79.22% 20885 / 26364
ironclaw_events 80.55% 1197 / 1486
ironclaw_loop_contracts 82.4% 5637 / 6841
ironclaw_first_party_extensions 82.57% 6784 / 8216
ironclaw_memory_native 82.85% 2850 / 3440
ironclaw_host_api 83.08% 10225 / 12307
ironclaw_libsql_runtime 83.3% 384 / 461
ironclaw_auth 83.94% 6697 / 7978
ironclaw_operator 84.47% 5309 / 6285
ironclaw_hooks 84.57% 9896 / 11702
ironclaw_event_projections 84.81% 854 / 1007
ironclaw_reborn_event_store 84.93% 1206 / 1420
ironclaw_extension_host 84.99% 24337 / 28635
ironclaw_reborn_config 85.29% 2110 / 2474
ironclaw_network 85.31% 894 / 1048
ironclaw_reborn_composition 85.51% 21793 / 25487
ironclaw_secrets 85.81% 2896 / 3375
ironclaw_runner 86% 15134 / 17597
ironclaw_authorization 86.59% 723 / 835
ironclaw_webui 86.95% 11935 / 13727
ironclaw_wasm_limiter 87.06% 74 / 85
ironclaw_common 87.33% 1641 / 1879
ironclaw_product 87.38% 22831 / 26129
ironclaw_reborn_traces 87.61% 11720 / 13377
ironclaw_scripts 87.87% 420 / 478
ironclaw_threads 88.14% 5189 / 5887
ironclaw_host_runtime 88.41% 21338 / 24135
ironclaw_turns 88.46% 3709 / 4193
ironclaw_telegram_extension 88.52% 586 / 662
ironclaw_skills 88.58% 2784 / 3143
ironclaw_process_sandbox 88.64% 281 / 317
ironclaw_processes 88.76% 5889 / 6635
ironclaw_reborn_openai_compat 89.4% 3644 / 4076
ironclaw_telegram_v2_adapter 89.43% 1573 / 1759
ironclaw_extensions 89.55% 6249 / 6978
ironclaw_loop_host 90.47% 18043 / 19944
ironclaw_resources 90.76% 4084 / 4500
ironclaw_approvals 91.05% 1820 / 1999
ironclaw_reborn_identity 91.3% 451 / 494
ironclaw_mcp 91.97% 1420 / 1544
ironclaw_conversations 92.08% 2383 / 2588
ironclaw_event_streams 92.5% 1048 / 1133
ironclaw_safety 92.75% 4468 / 4817
ironclaw_agent_loop 93.52% 10430 / 11153
ironclaw_slack_extension 93.94% 3689 / 3927
ironclaw_first_party_extension_ports 94.66% 3758 / 3970
ironclaw_outbound 94.68% 4271 / 4511
ironclaw_triggers 94.88% 3092 / 3259
ironclaw_prompt_envelope 97.46% 192 / 197
ironclaw_runtime_policy 97.6% 855 / 876
ironclaw_attachments 98.23% 831 / 846

This table itself is informational and never gates the PR on its own — not the percentage, not the per-crate holes, not the 0-coverage callout. A separate coverage ratchet (dry-run until enforce=true; see tests/integration/coverage-floor.toml) can fail the build on specific configured floors.

Exemptions (18 entry/entries excluded from the accounting above)
Module / Crate Reason Issue
crate: ironclaw_gateway v1-only: consumed only by root ironclaw (src/channels/web/platform/static_files.rs, src/channels/web/handlers/frontend.rs); no crates/* dependents. Covered by "Tests (Legacy)". #5657
crate: ironclaw_tui v1-only: consumed only by root ironclaw (src/main.rs, src/channels/tui.rs); no crates/* dependents. Crate's own doc comment confirms it bridges INTO v1, not Reborn. Covered by "Tests (Legacy)". #5657
crates/ironclaw_attachments/src/lib.rs Declarative crate facade: module declarations, constants, and re-exports only; executable attachment modules remain covered. #6524
crates/ironclaw_extension_host/src/ingress/mod.rs Declarative ingress module facade and documentation only; executable router modules remain covered. #6524
crates/ironclaw_host_api/src/lib.rs Declarative crate facade: module declarations and re-exports only; executable host API modules remain covered. #6524
crates/ironclaw_host_api/src/product_adapter/mod.rs Declarative product-adapter facade: module declarations and re-exports only; executable adapter modules remain covered. #6524
crates/ironclaw_llm/src/rig_adapter/tests/finish_reason_tests.rs Test-only module stored under src/ for private adapter access; cargo-llvm-cov omits test harness source from production LCOV while the exercised rig_adapter.rs production lines remain coverage-gated. #6284
crates/ironclaw_loop_contracts/src/lib.rs Declaration-only public facade with no executable Rust statements; rustc emits no LCOV source record. Executable loop-contract behavior remains covered in the owned implementation modules. #6524
crates/ironclaw_outbound/src/error.rs Declarative error vocabulary only; variants have no LLVM-instrumentable production statements. #6524
crates/ironclaw_outbound/src/lib.rs Declarative crate facade: module declarations and re-exports only; executable outbound modules remain covered. #6524
crates/ironclaw_product/src/lib.rs Declaration-only public facade with no executable Rust statements; rustc emits no LCOV source record. Executable product behavior remains covered in the owned implementation modules. #6524
crates/ironclaw_product/src/lib.rs Declarative crate facade: module declarations and re-exports only; executable product modules remain covered. #6524
crates/ironclaw_product/src/scoped_fs/mod.rs Declarative scoped-filesystem facade and documentation only; executable scoped filesystem modules remain covered. #6524
crates/ironclaw_reborn_composition/src/support/fs/mod.rs Declarative composition support facade: module declarations and re-exports only; executable filesystem adapters remain covered. #6524
crates/ironclaw_slack_extension/src/lib.rs Declarative Slack crate facade: module declarations and re-exports only; executable Slack modules remain covered. #6524
crates/ironclaw_telegram_extension/src/lib.rs Declarative Telegram crate facade: module declarations and re-exports only; executable Telegram modules remain covered. #6524
crates/ironclaw_threads/src/lib.rs Declaration-only public facade with no executable Rust statements; rustc emits no LCOV source record. Executable thread behavior remains covered in the owned implementation modules. #6524
crates/ironclaw_webui/src/webui_v2/mod.rs Declaration-only WebUI v2 facade with no executable Rust statements; rustc emits no LCOV source record. Executable route behavior remains covered in the owned implementation modules. #6524

The changed-coverage manifest carried a WS1.1 exemption for
crates/ironclaw_turns/src/run_profile/runtime_context.rs:575-576. WS1.2
moved that file into ironclaw_loop_contracts, so the gate's fail-closed
path validator rejected the manifest before reaching its line-level
verdict.

Deleted rather than repointed: WS1.1 merged, so those lines are baseline
on main, and this PR's diff pairs the file as a 99%-similarity rename
whose only changed lines are imports. Repointing would re-exempt lines the
gate no longer flags. All 19 remaining entries verified to resolve.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-6975 July 31, 2026 21:10 Destroyed
BenKurrek and others added 2 commits July 31, 2026 17:39
…tions

Merge brings in tests/e2e/scenarios/test_reborn_webui_v2_custom_mcp.py,
added on main after the last merge-down; the WebUI-smoke and E2E roll-up
reds were purely the missing file.

Exemptions derived by replaying scripts/ci/reborn_changed_coverage.py
against this PR's own merged lcov artifact until it exits 0 (100% line
244/244, 100% branch 8/8) - never estimated. Three classes:

- type-path repoints on declaration/expression fragments;
- verbatim-moved bodies in the new crate. Explicitly NOT counter-attribution:
  those files are instrumented in this lcov and partially hit (loop_exit
  195/109, model 86/52, checkpoint_payload 32/16), which proves the crate is
  measured. The same bodies were equally unexercised by the integration tier
  before the move, when they sat in ironclaw_turns and simply were not
  changed lines;
- one crate-root inner attribute the uninstrumentable-line classifier does
  not recognise on a declaration-only facade.

Also adds the #6524 declaration-only facade entry for the new crate's
lib.rs to the informational per-crate coverage summary.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@BenKurrek

Copy link
Copy Markdown
Collaborator Author

Coordinator sign-off (Wave 1 slot 2 — WS1.2 ironclaw_loop_contracts extraction + agent_loop/hooks flip).

Verified across the full lifecycle, on the final head with the complete 64-check set settled green:

  • Exceptions 15 → 13, both removals structural (agent_loop → turns, hooks → turns — manifest deps deleted, not waived), with the honest correction that the documented 12 was wrong: conversations → turns is turn-admission authority (generic over TurnCoordinator, calls submit_turn), evidenced on the exception annotation with a WS5 horizon.
  • Un-masking exact: zero tests lost (170 moved verbatim into the new crate, 5 to host_api, rosters elsewhere byte-identical); four inventory corrections recorded where the docs had aged; the port-location scan caught and closed a real pre-existing dual-import violation in runner.
  • Every CI red this PR hit was diagnosed to root cause and fixed at source — the workspace-invisible root-tests/ consumers, the stale lock pin vs a concurrent deps bump, the moved include_str! scan, the name-keyed test selector, the stale exemption path, and a coverage-gate verdict replayed locally against CI's own artifact to 100% line / 100% branch before pushing. Two rationale classes in the exemption manifest were corrected against my own instructions when verification disproved them — the manifest says what is true, not what was convenient.
  • Main merged down through Henry's feat(extensions): register hosted MCP servers #6930 with zero conflicts (disjoint territory); final delta re-verified as exactly this PR's own work.
  • Recorded for later governance: ~14k lines formerly ratcheted under ironclaw_turns now sit in the new crate, which has no coverage floor by the floor file's own opt-in design — a deliberate choice someone should make when the contracts tier stabilizes.

Ready to merge. Stack note: #6977 (ws1/extension-contracts) auto-retargets to main on this merge and its own collapse + full validation follows.

@BenKurrek
BenKurrek merged commit 5ae8277 into main Jul 31, 2026
63 checks passed
@BenKurrek
BenKurrek deleted the ws1/loop-contracts branch July 31, 2026 22:42
BenKurrek added a commit that referenced this pull request Aug 1, 2026
…n record with shipped reality (#6995)

* docs(target-architecture): Wave 1 truth audit — reconcile the decision record with shipped reality

Wave 1 merged as seven PRs (#6967, #6975, #6977, #6979, #6980, #6981,
#6982). This audits the north-star docs against merged `main` at
`a50ad0638` and closes every gap where the decision record no longer
matches what shipped.

Docs-only: five `.md` files under `docs/reborn/target-architecture/`.
House style throughout — dated ✎ amendments, prior text quoted where a
clause is corrected, no silent rewrites (`git diff --word-diff` removes
nothing but the words each amendment quotes back).

Highlights:
- §8.3's exception-dissolution proof corrected: `conversations → turns`
  is turn admission authority, not vocabulary; the wave's "20 → 12"
  milestone was wrong by construction and the true end-state is 13.
- §6.1.1–§6.1.4 gain as-built module inventories; the #6930 amendment
  placing `hosted_mcp` in `host_api` is superseded by #6977's relocation.
- §12.1a records the evidence-mint finding: the `host-auth-mint` feature
  seal was vacuous, replaced by witness grants — plus two residuals, one
  from the slice and one this audit verified against the ratchet source.
- The coverage-governance gap (~14k lines now ungated by the floor
  file's opt-in design) moves from a sign-off comment onto the ratchet row.
- Duplicate-type findings, the `llm_costs`/`ModelCostTable` deferral, the
  surviving `product → loop_host` sites, and issues #6945/#6978 all gain
  owning rows.

Verification: docs-only diff; `cargo test -p ironclaw_architecture` green.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(target-architecture): tighten the Wave 1 audit where review found it overstated

Six review findings triaged against the built tree; four were real.

- `families/contracts.md` landing marker claimed "everything else in
  this file was built as written". Three `ironclaw_loop_contracts`
  divergences contradict it and are now named at the marker and marked
  at the entry: the manifest holds `ironclaw_extension_contracts` and
  holds neither `ironclaw_common` nor `ironclaw_prompt_envelope`; the
  `tokio` carve-out; the embedded prompt asset.
- The evidence-mint guarantee said "compile-time impossibility" and
  "enforced by constructor visibility plus a workspace string-scan pin"
  in one breath. Split: the compiler enforces no-mint-without-a-grant
  (so nothing outside a workspace crate can mint at all); an
  architecture test — a line-oriented substring scan with two named
  evasions — decides which workspace crate may hold one.
- That deferral had no home. §12.1a said "hardening the scan is WS10
  work, listed there"; it was not listed. Added to the WS10 guardrail
  row with both evasions and the call-site census that backstops them.
- CHECKLIST WS8's `common/src/event.rs` row still closed with "stays in
  `common` as a deletion candidate" under an "executed by #6982"
  header. The file is deleted; the tail now says so.

Plus two clarity fixes where a reader could reach a wrong number: the
`(66)`/`(64)` figures in §9/§13 are that table's 2026-07-30 measurement
and now say so beside the live 67, and the row-1 edge count now states
that six of row 1's seven fell while the register moved by seven,
because `auth → turns` is row 9.

Dated amendments only; every replaced phrase is quoted in place.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
l3ocifer pushed a commit to l3ocifer/frick-ironclaw that referenced this pull request Sep 3, 2026
…oop (WS1.2) (nearai#6975)

* refactor(contracts): complete the turn vocabulary in host_api and retire the turns shims (WS1.1)

`ironclaw_host_api::turn` becomes the complete canonical turn vocabulary:
it absorbs `TurnStatus` (with the inseparable `GateKind`/`BlockedReason`
gate correspondence), `EventCursor`, and `RunOriginAdapter`. The three
`ironclaw_turns` re-export shims named by CHECKLIST WS1.1 are deleted —
`src/ids.rs`, `src/scope.rs`, and the whole `src/product_adapter/`
module, whose `fakes.rs` moves beside the traits it implements in
`host_api::product_adapter::test_support`.

`ids.rs` carried `pub type GateRef = TurnGateRef`: a second name for a
host_api type that collided with the unrelated
`ironclaw_host_api::ids::GateRef` (an opaque uuid GateRecord key, versus
turns' bounded `gate:`-prefixed routing string). The alias is retired
rather than relocated, so the workspace now has exactly one `GateRef`.

The six vocabulary-only consumers — auth, event_streams, outbound,
telegram_extension, triggers, event_projections — import from
`ironclaw_host_api::turn` and drop their `ironclaw_turns` dependency
entirely. Five `*→turns` LAYER_MATRIX_EXCEPTIONS are therefore not
waived but obsolete: the edges no longer exist. The §11.2.2 ratchet
baseline moves 20 → 15.

No behavior change. `RunOriginAdapter`'s validation error becomes
`Result<_, String>` (matching every other bounded ref in
`host_api::turn`) with a byte-identical message pinned by a test, so
both production `e.to_string()` call sites are unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs(target-architecture): tick WS1.1 and close PLAN decision round #1

WS1.1's box is ticked with what the change actually landed, including the
three lead-sheet corrections it turned up: the row named `TurnStatus` but
not `EventCursor`/`RunOriginAdapter` (which the six consumers genuinely
needed), `GateKind`/`BlockedReason` could not be left behind without
duplicating the single `GateKind -> TurnStatus` match table, and deleting
`ids.rs` forced retiring its `GateRef` alias rather than relocating it.

Two decisions confirmed outside the doc and never recorded:

- Strategy B (family dirs + focused crates) — confirmed 2026-07-31 by the
  owner, recorded retroactively; it was made in practice at program start.
- The `tools/` row's `default-members` trim — resolved as no trim.

Also surfaces nearai#6963 on the WS0 blocking-prerequisite row's first line
(it was already cited mid-paragraph) and records the §11.2.2 exception
ratchet moving 20 -> 15.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* refactor(contracts): repoint touched imports to host_api and pin the TurnGateRef contract

CodeRabbit review round on nearai#6967.

Import repoints (accepted): every `use` line this PR already rewrote now
names `ironclaw_host_api::turn` directly instead of routing through
`ironclaw_turns`' prelude — 57 files across extension_host, product,
composition, runner, loop_host, conversations, the integration harness,
and the stress tool, plus three inside `ironclaw_turns` itself so the
crate stops consuming its own facade. Import lines this PR did not touch
are left for their consumer's own repoint slot.

TurnGateRef contract pinned (refutation): two review comments claimed
`TurnGateRef::new` only accepts `gate:approval-`/`gate:auth-` prefixes
and that fixtures like "gate-alpha" and "stress-gate:{run_id}" fail
construction. They do not — `TurnGateRef` is `bounded_ref!` (non-empty,
<= 256 bytes, no control characters); `LoopGateRef` is the prefix-
validated family via `loop_ref!(.., "gate:")`. The misreading traces to
this PR's own AGENTS.md wording ("bounded `gate:`-prefixed routing
string"), which stated a minting convention as if it were validation.
That wording is corrected and the distinction is now pinned by a test.

Also: drop a stale cross-file line reference in a product test comment.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs(target-architecture): remove the row-97 self-contradiction

The `tools/` row resolved the `default-members` trim as "no trim" but
kept a trailing "The `tools/`/`default-members` half is still open."
from before that decision, so the row asserted both states. Drop the
stale sentence.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* ci(coverage): complete the WS1.1 changed-coverage exemptions

Finishes the remediation deferred last round, now that the settled run
(job 91246493989) provides authoritative line numbers. Manifest-only —
no .rs file changes, so the changed-line set the gate computes is
unchanged and these numbers stay valid for the next run.

Derived, not transcribed: the gate was replayed locally against its own
merged lcov from that run, reproducing CI's failure byte-identically
first (95.17%, 138/145, same 13 files, same 7 lines), then re-run after
each entry. Final local result: 100.00% (138/138), branch 100% (4/4),
exit 0. All 45 gate self-tests pass.

Two classes, both verified rather than asserted:

- 13 files x 20 lines - declaration lines (fn params, return types,
  struct fields) whose only edit is the type NAME: GateRef ->
  TurnGateRef, or ironclaw_turns::X -> ironclaw_host_api::turn::X.
  Declarations are not executable, so these files contribute a zero
  denominator and trip the fail-closed empty_denominator branch.

- 7 lines x 3 files - executable, instrumented, and genuinely not
  exercised by the integration tier. Each checked against the base
  merged lcov (main @ 67088a4, the PR's own base sha): identical 0
  hits before and after, so no coverage was lost. approval_prompt_
  context_view is uncovered across its whole signature at base
  (lines 505-511); the background spawn-mode arm and the invalid-gate-
  ref error path likewise.

This includes the two entries I refused to guess last round -
turn_events.rs (three identical candidate lines by text; the settled
run disambiguates it as 510) and await_edge/store.rs (no verbatim twin
after the repoint; authoritatively 268-272).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* refactor(contracts): extract ironclaw_loop_contracts and flip agent_loop (WS1.2)

Carve the loop tier's neutral contracts out of the turn kernel into a new
contracts-layer crate per PROPOSAL 6.1.4, and repoint every consumer.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* refactor(contracts): pin the loop-contract boundary and register the new crate

Enforcement, CI registration, and guidance for the WS1.2 extraction.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs(reborn): split the loop-exit contract's ownership claim across the two crates

The claim types moved to ironclaw_loop_contracts with WS1.2; the validator
policy and the trusted applier stayed in the turn kernel.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs(contracts): repoint the three intra-doc links the crate split broke

The two HostManagedLoop*Port impls stayed in ironclaw_turns, so same-crate
links to them no longer resolve; the TurnRunId link target became redundant
when the import repoint fully qualified it.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(tests): repoint the loop-exit evidence imports the port rule moved

Removing the ironclaw_runner re-export (required by the new port-location
scan) left two workspace-root test-support files importing the turn kernel's
evidence types through it. They now import from ironclaw_turns::loop_exit
directly, which is the single sanctioned path.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(collapse): reconcile the lock pin and the moved failure-category scan

Two artifacts of collapsing onto main:

- Cargo.lock pinned thiserror 2.0.18 for the new ironclaw_loop_contracts
  entry while main's dependency bump moved the workspace to 2.0.19. The
  auto-merge kept the stale pin because the bump predates the crate, so
  --locked builds failed.
- ironclaw_product's failure-summary test reaches into another crate's
  source with include_str! and scans it for 'impl LoopFailureKind'. WS1.2
  moved that impl to ironclaw_loop_contracts, so the include still resolved
  and matched nothing. Repointed to follow the code.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(ci): repoint the exact-test selector WS1.2 moved

scripts/reborn-e2e-rust.sh pins exact test names for the deterministic
gate. The capability-failure rehydration test moved from
ironclaw_turns::run_profile::host::capability to
ironclaw_loop_contracts::host::capability, so its selector matched zero
tests and the gate failed closed.

Swept all 10 pinned selectors in that script (4 lib + 6 integration
target); this was the only stale one. Each now resolves to exactly one
test, verified by running the selector.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(coverage): drop the exemption WS1.2 made stale

The changed-coverage manifest carried a WS1.1 exemption for
crates/ironclaw_turns/src/run_profile/runtime_context.rs:575-576. WS1.2
moved that file into ironclaw_loop_contracts, so the gate's fail-closed
path validator rejected the manifest before reaching its line-level
verdict.

Deleted rather than repointed: WS1.1 merged, so those lines are baseline
on main, and this PR's diff pairs the file as a 99%-similarity rename
whose only changed lines are imports. Repointing would re-exempt lines the
gate no longer flags. All 19 remaining entries verified to resolve.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(coverage): merge main and derive the WS1.2 changed-coverage exemptions

Merge brings in tests/e2e/scenarios/test_reborn_webui_v2_custom_mcp.py,
added on main after the last merge-down; the WebUI-smoke and E2E roll-up
reds were purely the missing file.

Exemptions derived by replaying scripts/ci/reborn_changed_coverage.py
against this PR's own merged lcov artifact until it exits 0 (100% line
244/244, 100% branch 8/8) - never estimated. Three classes:

- type-path repoints on declaration/expression fragments;
- verbatim-moved bodies in the new crate. Explicitly NOT counter-attribution:
  those files are instrumented in this lcov and partially hit (loop_exit
  195/109, model 86/52, checkpoint_payload 32/16), which proves the crate is
  measured. The same bodies were equally unexercised by the integration tier
  before the move, when they sat in ironclaw_turns and simply were not
  changed lines;
- one crate-root inner attribute the uninstrumentable-line classifier does
  not recognise on a declaration-only facade.

Also adds the nearai#6524 declaration-only facade entry for the new crate's
lib.rs to the informational per-crate coverage summary.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
l3ocifer pushed a commit to l3ocifer/frick-ironclaw that referenced this pull request Sep 3, 2026
…n record with shipped reality (nearai#6995)

* docs(target-architecture): Wave 1 truth audit — reconcile the decision record with shipped reality

Wave 1 merged as seven PRs (nearai#6967, nearai#6975, nearai#6977, nearai#6979, nearai#6980, nearai#6981,
nearai#6982). This audits the north-star docs against merged `main` at
`a50ad0638` and closes every gap where the decision record no longer
matches what shipped.

Docs-only: five `.md` files under `docs/reborn/target-architecture/`.
House style throughout — dated ✎ amendments, prior text quoted where a
clause is corrected, no silent rewrites (`git diff --word-diff` removes
nothing but the words each amendment quotes back).

Highlights:
- §8.3's exception-dissolution proof corrected: `conversations → turns`
  is turn admission authority, not vocabulary; the wave's "20 → 12"
  milestone was wrong by construction and the true end-state is 13.
- §6.1.1–§6.1.4 gain as-built module inventories; the nearai#6930 amendment
  placing `hosted_mcp` in `host_api` is superseded by nearai#6977's relocation.
- §12.1a records the evidence-mint finding: the `host-auth-mint` feature
  seal was vacuous, replaced by witness grants — plus two residuals, one
  from the slice and one this audit verified against the ratchet source.
- The coverage-governance gap (~14k lines now ungated by the floor
  file's opt-in design) moves from a sign-off comment onto the ratchet row.
- Duplicate-type findings, the `llm_costs`/`ModelCostTable` deferral, the
  surviving `product → loop_host` sites, and issues nearai#6945/nearai#6978 all gain
  owning rows.

Verification: docs-only diff; `cargo test -p ironclaw_architecture` green.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(target-architecture): tighten the Wave 1 audit where review found it overstated

Six review findings triaged against the built tree; four were real.

- `families/contracts.md` landing marker claimed "everything else in
  this file was built as written". Three `ironclaw_loop_contracts`
  divergences contradict it and are now named at the marker and marked
  at the entry: the manifest holds `ironclaw_extension_contracts` and
  holds neither `ironclaw_common` nor `ironclaw_prompt_envelope`; the
  `tokio` carve-out; the embedded prompt asset.
- The evidence-mint guarantee said "compile-time impossibility" and
  "enforced by constructor visibility plus a workspace string-scan pin"
  in one breath. Split: the compiler enforces no-mint-without-a-grant
  (so nothing outside a workspace crate can mint at all); an
  architecture test — a line-oriented substring scan with two named
  evasions — decides which workspace crate may hold one.
- That deferral had no home. §12.1a said "hardening the scan is WS10
  work, listed there"; it was not listed. Added to the WS10 guardrail
  row with both evasions and the call-site census that backstops them.
- CHECKLIST WS8's `common/src/event.rs` row still closed with "stays in
  `common` as a deletion candidate" under an "executed by nearai#6982"
  header. The file is deleted; the tail now says so.

Plus two clarity fixes where a reader could reach a wrong number: the
`(66)`/`(64)` figures in §9/§13 are that table's 2026-07-30 measurement
and now say so beside the live 67, and the row-1 edge count now states
that six of row 1's seven fell while the register moved by seven,
because `auth → turns` is row 9.

Dated amendments only; every replaced phrase is quoted in place.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-6975 — 3472ed4e Deployed Jul 31, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: medium Business logic, config, or moderate-risk modules scope: dependencies Dependency updates scope: docs Documentation size: XL 500+ changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant