Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
72 commits
Select commit Hold shift + click to select a range
93007af
refactor(contracts): move extension runtime descriptors to a neutral …
BenKurrek Aug 3, 2026
737cf50
refactor(sandbox): merge the sandbox lane into one crate (WS3)
BenKurrek Aug 3, 2026
adbbb58
docs(target-architecture): record the WS3 corrections with their evid…
BenKurrek Aug 3, 2026
38be2e2
chore(sandbox): drop imports the merge left unused
BenKurrek Aug 3, 2026
925e7e6
fix(ci): let the Reborn PR planner plan guidance edits and crate dele…
BenKurrek Aug 3, 2026
5ed3ac5
fix(arch): give the retained resource exceptions an owning issue, not…
BenKurrek Aug 3, 2026
50be425
test(contracts): pin the asset-path validator that moved into extensi…
BenKurrek Aug 3, 2026
84af779
test(coverage): re-capture the host_runtime floor and floor the new s…
BenKurrek Aug 3, 2026
bce21dc
docs(target-architecture): record the coverage ratchet as a move-sens…
BenKurrek Aug 3, 2026
5be9872
Merge origin/main into ws3/sandbox-and-mcp
BenKurrek Aug 3, 2026
8d89b41
fix(extension-manager): repoint ironhub onto the moved ExtensionAsset…
BenKurrek Aug 3, 2026
50712f0
test(coverage): exempt the WS3 move's no-region lines and record the …
BenKurrek Aug 3, 2026
a723345
docs(sandbox,mcp): correct the wiring inventory and record the projec…
BenKurrek Aug 3, 2026
9a250ff
refactor(extensions): move the skill-install executor to extension_su…
BenKurrek Aug 3, 2026
86b05a8
docs(sandbox): record that the Docker fail-closed switch is wired to …
BenKurrek Aug 3, 2026
f50504c
docs(host_runtime): record the executor/adapter seam in crate guidance
BenKurrek Aug 3, 2026
e07b3b0
refactor(host_runtime): keep the install-input error path log-free
BenKurrek Aug 3, 2026
8be0715
ci(coverage): re-capture the host_runtime floor for the WS3 executor …
BenKurrek Aug 3, 2026
482bea4
refactor(wasm): move wit/ inside its owning crate (Wave 3)
BenKurrek Aug 3, 2026
21533fd
build(wasm): rebuild first-party artifacts for the moved wit/ path
BenKurrek Aug 3, 2026
80daab9
docs(target-arch): record the WS7 artifact-rebuild cost of guest path…
BenKurrek Aug 3, 2026
5a1b315
Merge remote-tracking branch 'origin/main' into wave3/wit-move
BenKurrek Aug 3, 2026
f9b4ae7
Merge origin/main into ws3/sandbox-and-mcp
BenKurrek Aug 3, 2026
25e9aab
Merge origin/main into ws3/first-party-tools
BenKurrek Aug 4, 2026
1f66b58
ci(planner): classify the path classes that blocked the wit/ move
BenKurrek Aug 4, 2026
96d0d46
refactor(host-runtime): split obligations into its three chartered ow…
BenKurrek Aug 4, 2026
452a2d6
refactor(operator,contracts): route operator secrets through a produc…
BenKurrek Aug 4, 2026
ec1ba88
test(sandbox): put the Docker security check behind the fail-closed gate
BenKurrek Aug 4, 2026
6150a3f
docs(reborn): stop calling the unwired script lane an execution lane
BenKurrek Aug 4, 2026
756205f
fix(ci): pin the WIT scope probes and the embedded-asset owner pairing
BenKurrek Aug 4, 2026
043bc6c
docs(host-runtime): state the obligation visibility rule as it holds
BenKurrek Aug 4, 2026
c735e0c
fix(architecture): put the operator secrets boundary entry on the rig…
BenKurrek Aug 4, 2026
93ab9e6
docs(sandbox): state the Docker-gate claim as the search that checks it
BenKurrek Aug 4, 2026
d249a1d
Merge remote-tracking branch 'origin/main' into ws3/sandbox-and-mcp
BenKurrek Aug 4, 2026
ae1162a
merge(ws3): sandbox lane + mcp contracts flip (#7065)
BenKurrek Aug 4, 2026
b4925fd
merge(wave3): move wit/ inside its owning crate (#7084)
BenKurrek Aug 4, 2026
e3a9724
merge(ws3): move the skill-install executor to extension_support (#7080)
BenKurrek Aug 4, 2026
177eee8
merge(ws3): route operator secrets through a product_contracts port (…
BenKurrek Aug 4, 2026
9ea9cf1
merge(ws3): split obligations into its three chartered owners (#7090)
BenKurrek Aug 4, 2026
935ffe1
fix(coverage): re-anchor the exemptions the merge shifted
BenKurrek Aug 4, 2026
75909be
Merge origin/main (#7094 Wave 2 close-out) and re-baseline the WS3 nu…
BenKurrek Aug 4, 2026
8e299a7
refactor(layers): re-layer processes -> kernel and skills -> substrat…
BenKurrek Aug 4, 2026
29aac22
docs(target-arch): close the WS3/WS4 rows this work satisfies, with e…
BenKurrek Aug 4, 2026
4512e03
Merge origin/main into the consolidated WS3/WS4 branch
BenKurrek Aug 4, 2026
939af48
ci(coverage): recapture the two composed floors from a real measurement
BenKurrek Aug 4, 2026
2349548
fix(network): compile the test rewrite seam out of production builds …
BenKurrek Aug 4, 2026
9fbffd1
docs(coverage): verify the extension_support floor drop is compositio…
BenKurrek Aug 4, 2026
3c3189c
fix(host_runtime): collapse a duplicated obligation predicate and qui…
BenKurrek Aug 4, 2026
af14776
fix(ci): a shipped package prompt is an asset, not prose — it was sel…
BenKurrek Aug 4, 2026
ba79cb6
fix(harness): refresh the latency-runner lockfile after the sandbox c…
BenKurrek Aug 4, 2026
b57ac8e
fix(skills): stop rejecting inline bundle installs and stop dropping …
BenKurrek Aug 4, 2026
05534b6
refactor(capabilities): split host.rs along its six workflows (WS3 Ro…
BenKurrek Aug 4, 2026
f2e69ad
docs(target-arch): retract the "W7 is Wave 5" premise and tighten the…
BenKurrek Aug 4, 2026
8355cef
Merge branch 'ws3/row2-hostsplit' into ws3/consolidated
BenKurrek Aug 4, 2026
aaf6515
Merge remote-tracking branch 'origin/main' into ws3/consolidated
BenKurrek Aug 4, 2026
05fc53f
docs(checklist): strike the egress-threat text the same row already r…
BenKurrek Aug 4, 2026
61fece8
refactor(host_runtime): shed the catalog defaults downward (WS3 row 3)
BenKurrek Aug 4, 2026
def71bf
fix(operator): name the port call in LlmKeyStoreError::Store
BenKurrek Aug 4, 2026
5079ca6
Merge branch 'ws3/row3-catalog' into ws3/consolidated
BenKurrek Aug 4, 2026
05ad65a
revert(skills): restore the hidden-field install guards — the review …
BenKurrek Aug 4, 2026
a2f9623
Merge remote-tracking branch 'origin/main' into ws3/consolidated
BenKurrek Aug 4, 2026
966061f
fix(capabilities): make the auth-required enrichment total, dropping …
BenKurrek Aug 4, 2026
7ba9c4e
refactor(capabilities): return the authorization policy helpers to au…
BenKurrek Aug 4, 2026
68ac1dd
fix(docs,ci): correct the guest WIT path and delete a test that never…
BenKurrek Aug 4, 2026
7f242ae
test(host-api): pin the process-sandbox capability literal as a valid id
BenKurrek Aug 4, 2026
f4f1236
test(ci): pin the pre-commit staged-path selector after the WIT move
BenKurrek Aug 4, 2026
c16d0f2
Merge remote-tracking branch 'origin/main' into ws3-consolidated-merge
BenKurrek Aug 4, 2026
54e6757
Merge remote-tracking branch 'origin/main' into ws3-consolidated-merge
BenKurrek Aug 4, 2026
8b901f4
Merge remote-tracking branch 'origin/main' into ws3-consolidated-merge
BenKurrek Aug 4, 2026
ccf284c
fix(ci): restore the entry tail the exemptions-union resolution dropped
BenKurrek Aug 4, 2026
2ce58fa
Merge remote-tracking branch 'origin/main' into ws3-consolidated-merge
BenKurrek Aug 4, 2026
6563d80
chore(ci): exempt the consolidation's internal-move re-attributions t…
BenKurrek Aug 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .claude/commands/triage-prs.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ For each open PR, determine the primary module it touches by examining the `file
| **Storage & Memory** | `crates/ironclaw_filesystem/`, `crates/ironclaw_memory*/`, `crates/ironclaw_libsql_runtime/`, `migrations/` |
| **Security** | `crates/ironclaw_safety/`, `crates/ironclaw_secrets/`, `crates/ironclaw_trust/`, `crates/ironclaw_authorization/`, `crates/ironclaw_approvals/` |
| **Config & Setup** | `crates/ironclaw_reborn_config/` |
| **Sandbox & Processes** | `crates/ironclaw_process_sandbox/`, `crates/ironclaw_processes/`, `crates/ironclaw_scripts/`, `crates/ironclaw_wasm*/` |
| **Sandbox & Processes** | `crates/ironclaw_sandbox/`, `crates/ironclaw_processes/`, `crates/ironclaw_wasm*/` |
| **Hooks** | `crates/ironclaw_hooks/` |
| **Events & Projections** | `crates/ironclaw_events/`, `crates/ironclaw_event_projections/`, `crates/ironclaw_event_streams/` |
| **CI/CD & Docs** | `.github/`, `README.md`, `CLAUDE.md`, `*.md` (no src) |
Expand Down
4 changes: 2 additions & 2 deletions .claude/rules/safety-and-sandbox.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ paths:
- "crates/ironclaw_safety/**"
- "crates/ironclaw_host_runtime/**"
- "crates/ironclaw_processes/**"
- "crates/ironclaw_process_sandbox/**"
- "crates/ironclaw_sandbox/**"
- "crates/ironclaw_wasm/**"
- "crates/ironclaw_mcp/**"
- "crates/ironclaw_webui/**"
Expand Down Expand Up @@ -112,7 +112,7 @@ and the owning host-runtime/process-sandbox crates.
filesystem as containment for a subprocess.
- **The only real containment for an OS process is the sandbox it runs in.** Any
deployment that authenticates more than one user MUST route process spawns through
the sandboxed port (`TenantSandboxProcessPort`, backed by `ironclaw_process_sandbox`)
the sandboxed port (`TenantSandboxProcessPort`, backed by `ironclaw_sandbox`)
whose mount is derived from the turn scope — never through the unsandboxed
`HostProcessPort` (renamed from `LocalHostProcessPort`, §4.4 Bucket 2 — `Host`
names the boundary: a process run directly on the host). `HostProcessPort` /
Expand Down
2 changes: 1 addition & 1 deletion .githooks/pre-commit
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ set -euo pipefail
STAGED=$(git diff --cached --name-only)

NEEDS_CHECK=false
if echo "$STAGED" | grep -qE '^wit/|^channels-src/|^tools-src/'; then
if echo "$STAGED" | grep -qE '^crates/ironclaw_wasm/wit/|^channels-src/|^tools-src/'; then

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
# Description: Find any test exercising the pre-commit hook's staged-path detection.
fd . scripts/ci -e sh -e py | xargs -I{} rg -n "check-version-bumps|pre-commit" {} 2>/dev/null

Repository: nearai/ironclaw

Length of output: 546


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '--- relevant docs invariants ---\n'
for f in CLAUDE.md AGENTS.md .claude/rules; do
  if [ -e "$f" ]; then
    echo "## $f"
    sed -n '1,220p' "$f" | grep -n -E 'guardrail|guardrails|hook|hook\.|pre-commit|hook\.|test|tests|repo invariant|invariant' || true
  fi
done

printf '\n--- .githooks/pre-commit ---\n'
if [ -e .githooks/pre-commit ]; then
  nl -ba .githooks/pre-commit | sed -n '1,80p'
fi

printf '\n--- tests mentioning check-version-bumps/pre-commit ---\n'
rg -n 'check-version-bumps|pre-commit|staged-path|Stage|stages|crates/ironclaw_wasm/wit/|wit/' scripts .github tests . tests 2>/dev/null | head -200

printf '\n--- files in scripts/ci with context ---\n'
fd . scripts/ci -e sh -e py | while read -r f; do
  echo "## $f"
  wc -l "$f"
  rg -n 'check-version-bumps|pre-commit|staged-path|Stage|stages|crates/ironclaw_wasm/wit/|wit/' "$f" || true
done

Repository: nearai/ironclaw

Length of output: 244


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '%s\n' '--- relevant docs invariants ---'
for f in CLAUDE.md AGENTS.md .claude/rules; do
  if [ -e "$f" ]; then
    echo "## $f"
    sed -n '1,260p' "$f" | grep -n -E 'guardrail|guardrails|hook|pre-commit|test|tests|invariant|checks|must handle|multiline|run when.*change' || true
  fi
done

printf '%s\n' ''
printf '%s\n' '--- .githooks/pre-commit ---'
if [ -e .githooks/pre-commit ]; then
  nl -ba .githooks/pre-commit | sed -n '1,120p'
fi

printf '%s\n' ''
printf '%s\n' '--- tests/config mentioning check-version-bumps/pre-commit ---'
rg -n 'check-version-bumps|pre-commit|staged-path|Stage|stages|crates/ironclaw_wasm/wit/|wit/' scripts .github scripts tests . 2>/dev/null | head -250

printf '%s\n' ''
printf '%s\n' '--- scripts/ci file list and relevant matches ---'
if [ -d scripts/ci ]; then
  fd . scripts/ci -e sh -e py -e pyi -e sh --max-files 80 || true
  fd . scripts/ci -e sh -e py -e pyi --max-files 80 | while read -r f; do
    matches="$(rg -n 'check-version-bumps|pre-commit|staged-path|Stage|stages|crates/ironclaw_wasm/wit/|wit/' "$f" 2>/dev/null || true)"
    if [ -n "$matches" ]; then
      echo "## $f"
      wc -l "$f"
      echo "$matches"
    fi
  done
fi

Repository: nearai/ironclaw

Length of output: 4900


🏁 Script executed:

#!/bin/bash
set -euo pipefail

printf '%s\n' '--- .claude/rules/testing.md ---'
if [ -e .claude/rules/testing.md ]; then
  sed -n '1,260p' .claude/rules/testing.md | grep -n -E 'guardrail|hooks|check|test|staged|git|CI|workflow|multi' || true
fi

printf '%s\n' ''
printf '%s\n' '--- .githooks/pre-commit contents ---'
if [ -e .githooks/pre-commit ]; then
  awk '{printf "%6d: %s\n", NR, $0}' .githooks/pre-commit | sed -n '1,120p'
fi

printf '%s\n' ''
printf '%s\n' '--- searches for staged-path detection coverage ---'
rg -n 'check-version-bumps|version-bumps|pre_commit|pre-commit|git diff|git diff-tree|git ls-files|staged|Stage|stages|crates/ironclaw_wasm/wit/|wit/' .githooks scripts .github scripts tests integration 2>/dev/null | head -260 || true

printf '%s\n' ''
printf '%s\n' '--- script/file existence and sizes ---'
for f in .githooks/pre-commit scripts/check-version-bumps.sh .github/workflows check-version-bumps; do
  if [ -e "$f" ]; then
    echo "$f $(wc -l "$f" 2>/dev/null | awk '{print $1}') bytes=$(wc -c "$f" | awk '{print $1}')"
  else
    echo "missing $f"
  fi
done

Repository: nearai/ironclaw

Length of output: 50371


Add regression coverage for the staged-path matcher.

.githooks/pre-commit changed the gated path selector from ^wit/ to ^crates/ironclaw_wasm/wit/|^channels-src/|^tools-src/; CLAUDE.md/AGENTS.md require behavior-changing hooks to pin the behavior with a regression test. Add a staged-file-path check test, preferably under tests/integration/, so the relocated WIT detection cannot regress silently.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.githooks/pre-commit at line 11, Add regression coverage under
tests/integration/ for the staged-path matcher used by the pre-commit hook,
verifying relocated WIT paths under crates/ironclaw_wasm/wit/ and the existing
channels-src/ and tools-src/ paths are detected while unrelated paths are not.
Keep the test aligned with the selector in .githooks/pre-commit so future
changes cannot silently break this behavior.

Source: Coding guidelines

NEEDS_CHECK=true
fi

Expand Down
9 changes: 7 additions & 2 deletions .github/workflows/platform-and-compat.yml
Original file line number Diff line number Diff line change
Expand Up @@ -113,11 +113,16 @@ jobs:
# and every WASM ABI check silently skips — the WS10 failure mode
# (#6963). `crates/ironclaw_wasm_product_adapters/` was also dropped:
# that crate no longer exists, so the alternative had been matching
# nothing. scripts/ci/ws12_workflow_contracts.py pins this regex
# nothing. The bare `wit/` alternative went the same way when the WIT
# directory moved inside its owning crate (CHECKLIST WS4): the ABI
# files are `crates/ironclaw_wasm/wit/*.wit` now, already in scope via
# the `ironclaw_wasm` crate alternative, which unlike a repo-root
# prefix survives the WS7 family move too.
# scripts/ci/ws12_workflow_contracts.py pins this regex
# against the real crate inventory and against a real first-party
# extension manifest path, so a renamed, moved or deleted crate fails
# loudly here instead of quietly falling out of scope.
if has_match '^(wit/|crates/([^/]+/)*ironclaw_common/|crates/([^/]+/)*ironclaw_wasm/|crates/([^/]+/)*packages/[^/]+/(manifest\.toml|wasm-src/)|registry/|scripts/build-wasm-extensions\.sh$|scripts/check-version-bumps\.sh$|\.github/workflows/(platform-and-compat|nightly-deep-ci)\.yml$)'; then
if has_match '^(crates/([^/]+/)*ironclaw_common/|crates/([^/]+/)*ironclaw_wasm/|crates/([^/]+/)*packages/[^/]+/(manifest\.toml|wasm-src/)|registry/|scripts/build-wasm-extensions\.sh$|scripts/check-version-bumps\.sh$|\.github/workflows/(platform-and-compat|nightly-deep-ci)\.yml$)'; then
has_direct_wasm_abi_risk=true
fi
echo "has_direct_wasm_abi_risk=$has_direct_wasm_abi_risk" >> "$GITHUB_OUTPUT"
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/reborn-tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -122,6 +122,7 @@ jobs:
fi

python3 scripts/ci/test_reborn_pr_test_plan.py
python3 scripts/ci/test_pre_commit_staged_paths.py
scripts/ci/discover-reborn-package-crates.sh \
> "${RUNNER_TEMP}/reborn-canonical-packages.json"
plan="$(
Expand Down
42 changes: 23 additions & 19 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion Cargo.toml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
[workspace]
members = [".", "crates/ironclaw_common", "crates/ironclaw_observability", "crates/ironclaw_host_api", "crates/ironclaw_host_ingress", "crates/ironclaw_libsql_runtime", "crates/ironclaw_filesystem", "crates/ironclaw_attachments", "crates/ironclaw_extractors", "crates/ironclaw_memory", "crates/extensions/packages/memory-native", "crates/extensions/packages/mem0", "crates/ironclaw_events", "crates/ironclaw_event_projections", "crates/ironclaw_event_streams", "crates/ironclaw_reborn_event_store", "crates/ironclaw_extensions", "crates/ironclaw_extension_host", "crates/ironclaw_extension_manager", "crates/ironclaw_processes", "crates/ironclaw_scripts", "crates/ironclaw_process_sandbox", "crates/ironclaw_mcp", "crates/ironclaw_wasm", "crates/ironclaw_wasm_limiter", "crates/ironclaw_capabilities", "crates/ironclaw_secrets", "crates/ironclaw_network", "crates/ironclaw_host_runtime", "crates/ironclaw_runtime_policy", "crates/ironclaw_authorization", "crates/ironclaw_approvals", "crates/ironclaw_resources", "crates/ironclaw_auth", "crates/ironclaw_trust", "crates/ironclaw_turns", "crates/ironclaw_loop_contracts", "crates/ironclaw_extension_contracts", "crates/ironclaw_product_contracts", "crates/ironclaw_agent_loop", "crates/ironclaw_threads", "crates/ironclaw_prompt_envelope", "crates/ironclaw_hooks", "crates/ironclaw_loop_host", "crates/ironclaw_runner", "crates/ironclaw_reborn_config", "crates/ironclaw_operator", "crates/ironclaw_reborn_composition", "crates/ironclaw_reborn_identity", "crates/extensions/ironclaw_extension_support", "crates/ironclaw_first_party_extension_ports", "crates/ironclaw_reborn_cli", "crates/ironclaw_reborn_traces", "crates/ironclaw_webui", "crates/ironclaw_reborn_openai_compat", "crates/ironclaw_conversations", "crates/ironclaw_product", "crates/extensions/packages/telegram", "crates/extensions/packages/slack", "crates/ironclaw_outbound", "crates/ironclaw_triggers", "crates/ironclaw_projects", "crates/ironclaw_architecture", "crates/ironclaw_safety", "crates/ironclaw_skills", "crates/ironclaw_llm", "tools/ironclaw_stress"]
members = [".", "crates/ironclaw_common", "crates/ironclaw_observability", "crates/ironclaw_host_api", "crates/ironclaw_host_ingress", "crates/ironclaw_libsql_runtime", "crates/ironclaw_filesystem", "crates/ironclaw_attachments", "crates/ironclaw_extractors", "crates/ironclaw_memory", "crates/extensions/packages/memory-native", "crates/extensions/packages/mem0", "crates/ironclaw_events", "crates/ironclaw_event_projections", "crates/ironclaw_event_streams", "crates/ironclaw_reborn_event_store", "crates/ironclaw_extensions", "crates/ironclaw_extension_host", "crates/ironclaw_extension_manager", "crates/ironclaw_processes", "crates/ironclaw_sandbox", "crates/ironclaw_mcp", "crates/ironclaw_wasm", "crates/ironclaw_wasm_limiter", "crates/ironclaw_capabilities", "crates/ironclaw_secrets", "crates/ironclaw_network", "crates/ironclaw_host_runtime", "crates/ironclaw_runtime_policy", "crates/ironclaw_authorization", "crates/ironclaw_approvals", "crates/ironclaw_resources", "crates/ironclaw_auth", "crates/ironclaw_trust", "crates/ironclaw_turns", "crates/ironclaw_loop_contracts", "crates/ironclaw_extension_contracts", "crates/ironclaw_product_contracts", "crates/ironclaw_agent_loop", "crates/ironclaw_threads", "crates/ironclaw_prompt_envelope", "crates/ironclaw_hooks", "crates/ironclaw_loop_host", "crates/ironclaw_runner", "crates/ironclaw_reborn_config", "crates/ironclaw_operator", "crates/ironclaw_reborn_composition", "crates/ironclaw_reborn_identity", "crates/extensions/ironclaw_extension_support", "crates/ironclaw_first_party_extension_ports", "crates/ironclaw_reborn_cli", "crates/ironclaw_reborn_traces", "crates/ironclaw_webui", "crates/ironclaw_reborn_openai_compat", "crates/ironclaw_conversations", "crates/ironclaw_product", "crates/extensions/packages/telegram", "crates/extensions/packages/slack", "crates/ironclaw_outbound", "crates/ironclaw_triggers", "crates/ironclaw_projects", "crates/ironclaw_architecture", "crates/ironclaw_safety", "crates/ironclaw_skills", "crates/ironclaw_llm", "tools/ironclaw_stress"]

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Low · Refresh the standalone latency harness lockfile after the crate consolidation

Replacing ironclaw_scripts and ironclaw_process_sandbox with ironclaw_sandbox changes transitive dependencies of harness/latency/runner, but its separately committed Cargo.lock was not regenerated. It still lists both removed packages and records the old host-runtime/loop-host dependency graphs. Consequently, a reproducible invocation such as cargo run --locked --manifest-path harness/latency/runner/Cargo.toml will reject the stale lockfile, while the documented unlocked command rewrites a tracked file as a side effect. Regenerate and commit harness/latency/runner/Cargo.lock against the consolidated manifests.

default-members = ["crates/ironclaw_reborn_cli"]
exclude = [
"crates/ironclaw_silk_decoder",
Expand Down
2 changes: 0 additions & 2 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,6 @@ COPY crates/ crates/
COPY tools/ironclaw_stress/ tools/ironclaw_stress/
COPY skills/ skills/
COPY tests/ tests/
COPY wit/ wit/
COPY providers.json providers.json
RUN mkdir -p src \
&& printf 'fn main() {}\n' > src/main.rs \
Expand Down Expand Up @@ -68,7 +67,6 @@ COPY tools/ironclaw_stress/ tools/ironclaw_stress/
COPY migrations/ migrations/
COPY skills/ skills/
COPY tests/ tests/
COPY wit/ wit/
COPY providers.json providers.json
RUN mkdir -p src \
&& printf 'fn main() {}\n' > src/main.rs \
Expand Down
2 changes: 1 addition & 1 deletion FEATURE_PARITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -747,7 +747,7 @@ CLAUDE.md for the full mapping + gap catalog.
| SSRF IPv6 transition bypass block | ✅ | ❌ | Block IPv4-mapped IPv6 bypasses |
| Cron webhook SSRF guard | ✅ | ❌ | SSRF checks on webhook delivery |
| Loopback-first | ✅ | 🚧 | HTTP binds 0.0.0.0 |
| Docker sandbox | ✅ | ❌ | Orchestrator/worker containers; opt-in `sandbox.docker.gpus` passthrough; Reborn defines a typed `SandboxProcessPlan` contract (`ironclaw_process_sandbox`) with plan validation only — no production execution backend is wired for it yet |
| Docker sandbox | ✅ | ❌ | Orchestrator/worker containers; opt-in `sandbox.docker.gpus` passthrough; Reborn defines a typed `SandboxProcessPlan` contract (`ironclaw_sandbox`) with plan validation only — no production execution backend is wired for it yet |
| Podman support | ✅ | ❌ | `--container` accepts both Docker + Podman |
| WASM sandbox | ❌ | ✅ | IronClaw innovation |
| Sandbox env sanitization | ✅ | 🚧 | Shell tool scrubs env vars (secret detection); Reborn process sandbox rejects sensitive raw env values in plans and uses placeholders for brokered credentials, but production secure-capture and MITM transport wiring remain partial |
Expand Down
5 changes: 2 additions & 3 deletions crates/AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -110,12 +110,11 @@ Boundary rule: if you need an upstream crate in a low-level crate, stop and chec
| `ironclaw_network` | `ironclaw_network/AGENTS.md`, `ironclaw_network/CLAUDE.md`, `docs/reborn/contracts/network.md` | Network policy boundary, URL targets, resolver, hardened transport, host/provider HTTP egress. | Runtime-lane behavior above boundary or manual credential injection. |
| `ironclaw_host_runtime` | `ironclaw_host_runtime/AGENTS.md`, `ironclaw_host_runtime/CLAUDE.md` | Host-side Reborn service composition: production services, obligations, HTTP egress, redaction, secrets/network/resource mediation. | Product workflow, runtime-specific request shapes, duplicate network/secret logic. |
| `ironclaw_processes` | `ironclaw_processes/AGENTS.md`, `ironclaw_processes/CLAUDE.md` | Process lifecycle, cancellation, stores, status/output helpers, `ProcessHost`, wrappers. | Authorization, approval policy, runtime lane internals beyond adapter contracts. |
| `ironclaw_scripts` | `ironclaw_scripts/AGENTS.md`, `ironclaw_scripts/CLAUDE.md` | Script runtime lane over host-mediated filesystem/events/resources/dispatcher/HTTP, Docker/backend output parsing. | Manual credentials, direct provider HTTP, duplicated dispatcher/process/resource policy. |
| `ironclaw_mcp` | `ironclaw_mcp/AGENTS.md`, `ironclaw_mcp/CLAUDE.md` | MCP runtime lane, execution request/result types, JSON-RPC exchange, client abstraction, HTTP adapter, resource accounting. | Direct outbound networking, ad-hoc credential injection, product workflow. |
| `ironclaw_wasm` | `ironclaw_wasm/AGENTS.md`, `ironclaw_wasm/CLAUDE.md`, `docs/reborn/contracts/wasm.md`, `wit/tool.wit` | WASM runtime lane, component/WIT bindings, folded `wasm_sandbox_core` primitives, store, host adapters, runtime config. | Privileged host effects outside mediated APIs; copied secrets/network/resource logic; product/runtime-specific dependencies inside `wasm_sandbox_core`. |
| `ironclaw_wasm` | `ironclaw_wasm/AGENTS.md`, `ironclaw_wasm/CLAUDE.md`, `docs/reborn/contracts/wasm.md`, `ironclaw_wasm/wit/tool.wit` | WASM runtime lane, component/WIT bindings, folded `wasm_sandbox_core` primitives, store, host adapters, runtime config. | Privileged host effects outside mediated APIs; copied secrets/network/resource logic; product/runtime-specific dependencies inside `wasm_sandbox_core`. |
| `ironclaw_wasm_limiter` | `Cargo.toml`, `src/lib.rs` | Shared `wasmtime::ResourceLimiter` for WASM tool and hook runtimes. | Product adapter workflow, policy decisions, or runtime-specific side effects beyond limiter accounting. |
| `ironclaw_extensions` | `ironclaw_extensions/AGENTS.md`, `ironclaw_extensions/CLAUDE.md` | Declarative extension manifests (`src/v2.rs` and `src/v3.rs`; v3 is the current schema), capability descriptors, side-effect-free in-memory registry, installation records. | Execution of any kind (WASM/MCP/process), secrets, trust decisions. |
| `ironclaw_process_sandbox` | `ironclaw_process_sandbox/CLAUDE.md` | Typed `SandboxProcessPlan` contract and validation only: install/credentialed-run phase separation in plan types. No production execution backend is wired for this capability today. | Process lifecycle/stores (`ironclaw_processes`); raw Docker flags for extensions; adding an execution backend here. |
| `ironclaw_sandbox` | `ironclaw_sandbox/AGENTS.md`, `ironclaw_sandbox/CLAUDE.md` | The sandboxed-process lane (WS3 merge of `ironclaw_process_sandbox` + `host_runtime::sandbox_process` + `ironclaw_scripts`): typed `SandboxProcessPlan` contract and validation, the Docker/broker/credential-firewall/CA machinery behind `ironclaw_host_api::process::SandboxCommandTransport`, and the script runtime lane. Sole declarer of `bollard`/`rcgen`/`libc`. No production execution backend is wired for `system.process_sandbox.run` today. | Process lifecycle/stores (`ironclaw_processes`); raw Docker flags for extensions; dispatcher composition; manual credentials; direct provider HTTP. |

### Turns, threads, loops

Expand Down
2 changes: 1 addition & 1 deletion crates/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,7 @@ A good rule of thumb: if a change adds new authority or persistence, put it in t
| --- | --- | --- |
| `ironclaw_capabilities` | `ironclaw_capabilities` | Caller-facing capability invocation host. Coordinates authorization, approvals, process transitions, and neutral runtime dispatch. |
| `ironclaw_processes` | `ironclaw_processes` | Host-tracked background process lifecycle. Owns lifecycle mechanics, not capability policy. |
| `ironclaw_scripts` | `ironclaw_scripts` | Script/CLI capability runner contracts. Executes declared commands through a host-selected backend. |
| `ironclaw_sandbox` | `ironclaw_sandbox` | The sandboxed-process lane: `SandboxProcessPlan` validation, the Docker/broker/credential-firewall/CA machinery behind `SandboxCommandTransport`, and the script/CLI capability runner. |
| `ironclaw_mcp` | `ironclaw_mcp` | Adapts manifest-declared MCP tools into IronClaw capabilities without granting ambient filesystem, secret, or network authority. |
| `ironclaw_wasm` | `ironclaw_wasm` | Reborn WASM component runtime lane. Owns component-model/WIT runtime surface plus the folded domain-free `wasm_sandbox_core` primitives. |
| `ironclaw_wasm_limiter` | `ironclaw_wasm_limiter` | Shared `wasmtime::ResourceLimiter` used by WASM tool and hook runtimes so memory/table/instance limits do not drift. |
Expand Down
23 changes: 23 additions & 0 deletions crates/extensions/ironclaw_extension_support/AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -37,9 +37,32 @@
- Deterministic tool behavior behind narrow explicit request types.
- Scoped handles granted by host runtime or composition.

## The Executor/Adapter Seam

Every tool here is an **executor**, never a capability handler. That means:

- It takes a request type this crate defines (`GsuiteDispatchRequest`,
`WebAccessDispatchRequest`, `SkillUrlFetchContext`, …) carrying only
contracts-layer values the host hands it per invocation — `ResourceScope`,
`CapabilityId`, `Arc<dyn RuntimeHttpEgress>`, `Arc<dyn RootFilesystem>`.
- It returns this crate's own error type (`…DispatchError`,
`SkillManagementCapabilityError`), which carries a
`RuntimeDispatchErrorKind` and optionally the `ResourceUsage` burned before
the failure. The caller maps it.
- The `FirstPartyCapabilityHandler` impl, the `CapabilityManifest` that declares
the tool, and the registry insertion live **outside** — in
`ironclaw_host_runtime::first_party_tools` for the always-on builtins, or in
the binary's `FirstPartyHandlerRegistrar` for the binary-registered ones.

`ironclaw_host_runtime` and `ironclaw_extensions` are on this crate's forbidden
list (`reborn_dependency_boundaries.rs`), so this is enforced, not a
convention. If an executor cannot be written without one of them, the seam is
in the wrong place — move less, not the rule.

## Do Not Move In Here

- Host runtime composition, authorization, approvals, resource accounting, or capability registry wiring.
- Capability-handler implementations or the capability manifests that declare them.
- Loop-facing skill context ports, turn-run adapters, or Reborn composition wiring.
- Raw secrets, network clients, dispatcher handles, or ambient host authority.

Expand Down
Loading
Loading