Skip to content

ci: allowlist REBORN_COV_COLLECT through the hermetic test wrapper - #7066

Closed
BenKurrek wants to merge 1 commit into
mainfrom
ci/allowlist-reborn-cov-collect
Closed

BenKurrek wants to merge 1 commit into
mainfrom
ci/allowlist-reborn-cov-collect

Conversation

@BenKurrek

Copy link
Copy Markdown
Collaborator

One token. Unblocks any PR touching tests/integration/*.

The defect

scripts/ci/run-hermetic-test-process.sh scrubs the environment down to an explicit allowlist. It passes REBORN_COV_LANE_INDEX, REBORN_COV_LANE_MODE, REBORN_COV_LANE_PARTITIONS and REBORN_COV_LANE_TEST_TIMEOUT — but not REBORN_COV_COLLECT, so the wrapper strips it.

scripts/ci/reborn-coverage-lane-run.sh:54 then reads:

collect_coverage="${REBORN_COV_COLLECT:-true}"

which defaults the stripped value back to coverage mode and calls cargo llvm-cov — whose install step was correctly skipped, because the test plan resolved coverage_mode: "none". The lane dies with error: no such command: llvm-cov.

Why it looks like a test failure

It only fires when coverage is off and the lane selects a non-empty suite list. A PR touching tests/integration/* gets suites on some lanes and empty lists on others, so the same run shows lanes 0/2 failing and 1/3 passing — which reads like a flaky integration test rather than an environment defect. Observed on #7040 (Reborn integration tests (0) and (2)), where every affected suite passes locally.

The fix, and what it deliberately leaves alone

Adds REBORN_COV_COLLECT to the allowlist. Nothing else.

Worth flagging separately: the default is the deeper problem. ${REBORN_COV_COLLECT:-true} means an unset value is read as "collect", so losing the variable fails toward the more expensive branch instead of the safer one — a fail-open default in a script whose whole job is deterministic isolation. Tightening that belongs with whoever owns the lane script, so it is not bundled here.

Provenance

Open PR #6780 already carries this same allowlist line as part of a much larger feature ("deep-link register/install gateway + private manifest source"). This PR is the fix on its own so the queue is not gated on that feature's review; #6780 will see a trivial same-content conflict on the line.

Verified: bash -n clean; diff is one line.

`run-hermetic-test-process.sh` scrubs the environment to an explicit
allowlist. It passes every other `REBORN_COV_LANE_*` variable but not
`REBORN_COV_COLLECT`, so the wrapper strips it — and
`reborn-coverage-lane-run.sh` then reads `${REBORN_COV_COLLECT:-true}`,
defaulting the stripped value back to coverage mode and invoking
`cargo llvm-cov`, whose install step was correctly skipped because the
plan resolved `coverage_mode: "none"`.

The lane fails with `error: no such command: llvm-cov`. It only fires
when coverage is off *and* the lane selects a non-empty suite list, so
it lands on PRs touching `tests/integration/*` and looks like a test
failure rather than an environment defect.

The default is the deeper problem — an unset value means "collect", so
losing the variable fails toward the more expensive branch rather than
the safer one. This change fixes the allowlist only; hardening the
default belongs with whoever owns that script.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@railway-app

railway-app Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-7066 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Aug 3, 2026 at 2:44 pm

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-7066 August 3, 2026 14:35 Destroyed
@github-actions github-actions Bot added size: XS < 10 changed lines (excluding docs) risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Aug 3, 2026
@coderabbitai

coderabbitai Bot commented Aug 3, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Summary by CodeRabbit

  • Bug Fixes
    • Improved hermetic test execution by preserving the coverage collection setting when supported.

Walkthrough

The hermetic test process now preserves REBORN_COV_COLLECT when environment sabotage is inactive. The variable joins the existing coverage lane variables in the environment allowlist.

Changes

Hermetic coverage environment

Layer / File(s) Summary
Coverage variable allowlist
scripts/ci/run-hermetic-test-process.sh
The environment whitelist now preserves REBORN_COV_COLLECT with REBORN_COV_LANE_INDEX and REBORN_COV_LANE_MODE.

Estimated code review effort: 1 (Trivial) | ~2 minutes

Possibly related PRs

  • nearai/ironclaw#6883: Introduced the hermetic test-process framework and its environment-variable allowlist.

Suggested reviewers: serrrfirat

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the defect and fix, but it omits most required template sections, including change type, linked issue, test strategy, security, blast radius, rollback, and review track. Complete the required template sections and record applicable validation, test strategy, security impact, database impact, blast radius, rollback plan, and review track.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title uses Conventional Commits style and accurately summarizes the allowlist change.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@scripts/ci/run-hermetic-test-process.sh`:
- Line 61: The allowlist change in run-hermetic-test-process.sh lacks a
regression test for environment propagation. Add a CI harness test that verifies
REBORN_COV_COLLECT=false reaches the child command while an unrelated variable
remains unset, and ensure the test runs whenever run-hermetic-test-process.sh
changes by updating the relevant workflow configuration.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 77c72dc5-0711-4719-b1c8-656d46153828

📥 Commits

Reviewing files that changed from the base of the PR and between e9e738c and fc944d2.

📒 Files selected for processing (1)
  • scripts/ci/run-hermetic-test-process.sh

CARGO_INCREMENTAL|CARGO_PROFILE_DEV_DEBUG|CARGO_PROFILE_TEST_DEBUG|CARGO_TEST_ARGS|\
RUSTFLAGS|RUST_MIN_STACK|COREPACK_HOME|PLAYWRIGHT_BROWSERS_PATH|\
PROPTEST_CASES|REBORN_COV_LANE_INDEX|REBORN_COV_LANE_MODE|\
PROPTEST_CASES|REBORN_COV_COLLECT|REBORN_COV_LANE_INDEX|REBORN_COV_LANE_MODE|\

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Add a regression test for the allowlist contract.

Test that REBORN_COV_COLLECT=false reaches the child command and that an unrelated variable remains unset. bash -n checks syntax only. It does not verify this behavior.

.github/workflows/reborn-tests.yml:695-708 supplies this variable, while scripts/ci/reborn-coverage-lane-run.sh:51-55 defaults a missing value to true. A future regression could enable coverage and invoke unavailable cargo llvm-cov.

Add the test to the CI harness and ensure it runs when scripts/ci/run-hermetic-test-process.sh changes.

As per coding guidelines, “Guardrails, checks, and hooks require regression tests ... and must run when their own files change.” As per path instructions, “behavior changes need matching workflow updates.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@scripts/ci/run-hermetic-test-process.sh` at line 61, The allowlist change in
run-hermetic-test-process.sh lacks a regression test for environment
propagation. Add a CI harness test that verifies REBORN_COV_COLLECT=false
reaches the child command while an unrelated variable remains unset, and ensure
the test runs whenever run-hermetic-test-process.sh changes by updating the
relevant workflow configuration.

Sources: Coding guidelines, Path instructions

@ironloopai

ironloopai Bot commented Aug 3, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Review · PR #7066

🟢 Completed · Review submitted

Submitted review →

The complete trusted base-to-head comparison is a correct, narrowly scoped CI fix. Adding REBORN_COV_COLLECT to the hermetic wrapper’s explicit environment allowlist preserves the workflow-provided true/false value for the coverage lane without weakening the wrapper’s handling of unrelated variables. No actionable findings.

Automatic · PR opened · attempt 1 of 3 · completed in 1m 8s

Run details
  • Repository: nearai/ironclaw
  • Base: main at e9e738c
  • Head: ci/allowlist-reborn-cov-collect at fc944d2
  • Created: Aug 3, 2026, 2:40 PM UTC
  • Updated: Aug 3, 2026, 2:41 PM UTC
  • Run: ebb36198-2761-4eee-8c7e-b435721029b6
  • Latest attempt: 1 · Completed · 7cdc1f4a-35d7-4f2d-843b-d04cc6b96037

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Review complete · PR #7066

✅ No actionable findings

The complete trusted base-to-head comparison is a correct, narrowly scoped CI fix. Adding REBORN_COV_COLLECT to the hermetic wrapper’s explicit environment allowlist preserves the workflow-provided true/false value for the coverage lane without weakening the wrapper’s handling of unrelated variables. No actionable findings.

Validation and technical details
  • Verified refs/ironloop/base resolves to e9e738c and refs/ironloop/head resolves to fc944d2.
  • Inspected the complete base-to-head diff: one changed allowlist entry in scripts/ci/run-hermetic-test-process.sh.
  • Traced REBORN_COV_COLLECT from .github/workflows/reborn-tests.yml through the hermetic deterministic-suite wrapper to scripts/ci/reborn-coverage-lane-run.sh, which validates true/false and selects cargo llvm-cov versus ordinary cargo test.
  • bash -n scripts/ci/run-hermetic-test-process.sh passed.
  • A direct runtime preservation probe could not execute in this review sandbox because process substitution failed at /dev/fd/63; static inspection confirms the new case-pattern entry follows the existing allowlist mechanism exactly.
  • Base: main
  • Head: ci/allowlist-reborn-cov-collect at fc944d2
  • Run: ebb36198-2761-4eee-8c7e-b435721029b6

@BenKurrek

Copy link
Copy Markdown
Collaborator Author

This PR's CI is not evidence — the Reborn suite was skipped entirely, so here is a local proof instead.

Every Reborn lane on this PR reports skipping: Tests (Reborn), all crate buckets, integration lanes, root tests, CLI smoke, the coverage report. Zero Reborn tests ran. That is a second, separate planner defect, found independently by the WS3 runner-sheds work (PR #7064): reborn_pr_test_plan.py has no rule for repo-root scripts/, and its fail-closed arm skips the whole suite rather than running it. So a PR that changes CI scripts gets its CI silently not run — including this one. #7064 carries the planner fix.

Since CI cannot verify this change, I ran the wrapper itself. Same script, same environment, the single allowlist token as the only variable:

with the fix:    COLLECT=[false]     LANE=[flat-partition]
without it:      COLLECT=[STRIPPED]  LANE=[flat-partition]   ← the defect, reproduced
restored:        COLLECT=[false]     LANE=[flat-partition]

LANE survives in all three runs because REBORN_COV_LANE_MODE is already allowlisted — which isolates the cause to exactly the missing REBORN_COV_COLLECT token and rules out any environmental difference between the runs.

Chain, end to end: CI sets REBORN_COV_COLLECT=false when the plan resolves coverage_mode: "none" → the wrapper strips it → reborn-coverage-lane-run.sh:54 reads ${REBORN_COV_COLLECT:-true} and defaults it back to true → cargo llvm-cov runs → error: no such command: llvm-cov, because the install step was correctly skipped.

Full disclosure on my earlier attempt at this proof: my first A/B compared the patched script against a copy of main's version extracted to /tmp, and that comparison was worthless — main's copy died early on an unrelated relative-path lookup (//scripts/ci/hermetic-network-guard.c) because it had no repo context, so its empty output said nothing about the allowlist. The run above fixes that by toggling the one line in place within the same worktree. Recording it because a proof that was almost wrong is worth flagging alongside the one that is right.

@BenKurrek
BenKurrek added this pull request to the merge queue Aug 3, 2026
@BenKurrek

Copy link
Copy Markdown
Collaborator Author

Superseded — closing as a no-op.

#6780 merged and carried this same allowlist line, so origin/main now has REBORN_COV_COLLECT at run-hermetic-test-process.sh:61 and this branch's diff against main is empty. The defect it was cut for is fixed; the fix just arrived by the other route.

Worth keeping from the investigation, since #6780's body doesn't cover it:

  • The mechanism, confirmed by a controlled A/B on the same script (one token the only variable): with the token COLLECT=[false], without it COLLECT=[STRIPPED], while LANE survived both — isolating the cause and ruling out environmental drift.
  • The deeper issue is untouched and still live: reborn-coverage-lane-run.sh:54 reads ${REBORN_COV_COLLECT:-true}, so an unset value means collect. Losing that variable fails toward the more expensive branch — a fail-open default inside a script whose entire job is deterministic isolation. Whoever owns that lane script should decide whether unset ought to mean false, or whether it should be required outright.
  • This PR could never have been validated by its own CI: it touches only repo-root scripts/, and the PR test planner had no rule for that path, so every Reborn lane reported skipping. That planner gap is fixed in refactor(loop): shed the model gateway and tool disclosure into loop_host (WS3/WS4) #7064 and refactor(sandbox,contracts): merge the sandbox lane and flip mcp onto contracts (WS3) #7065.

@BenKurrek BenKurrek closed this Aug 3, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a manual request Aug 3, 2026

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-7066 — fc944d20 Deployed Aug 3, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules size: XS < 10 changed lines (excluding docs)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants