Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
103 commits
Select commit Hold shift + click to select a range
93007af
refactor(contracts): move extension runtime descriptors to a neutral …
BenKurrek Aug 3, 2026
737cf50
refactor(sandbox): merge the sandbox lane into one crate (WS3)
BenKurrek Aug 3, 2026
adbbb58
docs(target-architecture): record the WS3 corrections with their evid…
BenKurrek Aug 3, 2026
38be2e2
chore(sandbox): drop imports the merge left unused
BenKurrek Aug 3, 2026
925e7e6
fix(ci): let the Reborn PR planner plan guidance edits and crate dele…
BenKurrek Aug 3, 2026
5ed3ac5
fix(arch): give the retained resource exceptions an owning issue, not…
BenKurrek Aug 3, 2026
50be425
test(contracts): pin the asset-path validator that moved into extensi…
BenKurrek Aug 3, 2026
84af779
test(coverage): re-capture the host_runtime floor and floor the new s…
BenKurrek Aug 3, 2026
bce21dc
docs(target-architecture): record the coverage ratchet as a move-sens…
BenKurrek Aug 3, 2026
5be9872
Merge origin/main into ws3/sandbox-and-mcp
BenKurrek Aug 3, 2026
8d89b41
fix(extension-manager): repoint ironhub onto the moved ExtensionAsset…
BenKurrek Aug 3, 2026
50712f0
test(coverage): exempt the WS3 move's no-region lines and record the …
BenKurrek Aug 3, 2026
a723345
docs(sandbox,mcp): correct the wiring inventory and record the projec…
BenKurrek Aug 3, 2026
9a250ff
refactor(extensions): move the skill-install executor to extension_su…
BenKurrek Aug 3, 2026
86b05a8
docs(sandbox): record that the Docker fail-closed switch is wired to …
BenKurrek Aug 3, 2026
f50504c
docs(host_runtime): record the executor/adapter seam in crate guidance
BenKurrek Aug 3, 2026
e07b3b0
refactor(host_runtime): keep the install-input error path log-free
BenKurrek Aug 3, 2026
8be0715
ci(coverage): re-capture the host_runtime floor for the WS3 executor …
BenKurrek Aug 3, 2026
482bea4
refactor(wasm): move wit/ inside its owning crate (Wave 3)
BenKurrek Aug 3, 2026
21533fd
build(wasm): rebuild first-party artifacts for the moved wit/ path
BenKurrek Aug 3, 2026
80daab9
docs(target-arch): record the WS7 artifact-rebuild cost of guest path…
BenKurrek Aug 3, 2026
5a1b315
Merge remote-tracking branch 'origin/main' into wave3/wit-move
BenKurrek Aug 3, 2026
f9b4ae7
Merge origin/main into ws3/sandbox-and-mcp
BenKurrek Aug 3, 2026
25e9aab
Merge origin/main into ws3/first-party-tools
BenKurrek Aug 4, 2026
1f66b58
ci(planner): classify the path classes that blocked the wit/ move
BenKurrek Aug 4, 2026
96d0d46
refactor(host-runtime): split obligations into its three chartered ow…
BenKurrek Aug 4, 2026
452a2d6
refactor(operator,contracts): route operator secrets through a produc…
BenKurrek Aug 4, 2026
ec1ba88
test(sandbox): put the Docker security check behind the fail-closed gate
BenKurrek Aug 4, 2026
6150a3f
docs(reborn): stop calling the unwired script lane an execution lane
BenKurrek Aug 4, 2026
756205f
fix(ci): pin the WIT scope probes and the embedded-asset owner pairing
BenKurrek Aug 4, 2026
043bc6c
docs(host-runtime): state the obligation visibility rule as it holds
BenKurrek Aug 4, 2026
c735e0c
fix(architecture): put the operator secrets boundary entry on the rig…
BenKurrek Aug 4, 2026
93ab9e6
docs(sandbox): state the Docker-gate claim as the search that checks it
BenKurrek Aug 4, 2026
d249a1d
Merge remote-tracking branch 'origin/main' into ws3/sandbox-and-mcp
BenKurrek Aug 4, 2026
ae1162a
merge(ws3): sandbox lane + mcp contracts flip (#7065)
BenKurrek Aug 4, 2026
b4925fd
merge(wave3): move wit/ inside its owning crate (#7084)
BenKurrek Aug 4, 2026
e3a9724
merge(ws3): move the skill-install executor to extension_support (#7080)
BenKurrek Aug 4, 2026
177eee8
merge(ws3): route operator secrets through a product_contracts port (…
BenKurrek Aug 4, 2026
9ea9cf1
merge(ws3): split obligations into its three chartered owners (#7090)
BenKurrek Aug 4, 2026
935ffe1
fix(coverage): re-anchor the exemptions the merge shifted
BenKurrek Aug 4, 2026
75909be
Merge origin/main (#7094 Wave 2 close-out) and re-baseline the WS3 nu…
BenKurrek Aug 4, 2026
8e299a7
refactor(layers): re-layer processes -> kernel and skills -> substrat…
BenKurrek Aug 4, 2026
29aac22
docs(target-arch): close the WS3/WS4 rows this work satisfies, with e…
BenKurrek Aug 4, 2026
4512e03
Merge origin/main into the consolidated WS3/WS4 branch
BenKurrek Aug 4, 2026
939af48
ci(coverage): recapture the two composed floors from a real measurement
BenKurrek Aug 4, 2026
2349548
fix(network): compile the test rewrite seam out of production builds …
BenKurrek Aug 4, 2026
9fbffd1
docs(coverage): verify the extension_support floor drop is compositio…
BenKurrek Aug 4, 2026
3c3189c
fix(host_runtime): collapse a duplicated obligation predicate and qui…
BenKurrek Aug 4, 2026
af14776
fix(ci): a shipped package prompt is an asset, not prose — it was sel…
BenKurrek Aug 4, 2026
ba79cb6
fix(harness): refresh the latency-runner lockfile after the sandbox c…
BenKurrek Aug 4, 2026
b57ac8e
fix(skills): stop rejecting inline bundle installs and stop dropping …
BenKurrek Aug 4, 2026
05534b6
refactor(capabilities): split host.rs along its six workflows (WS3 Ro…
BenKurrek Aug 4, 2026
f2e69ad
docs(target-arch): retract the "W7 is Wave 5" premise and tighten the…
BenKurrek Aug 4, 2026
8355cef
Merge branch 'ws3/row2-hostsplit' into ws3/consolidated
BenKurrek Aug 4, 2026
85f55ee
test(architecture): fix drifted ratchet baselines and fail on slack (…
BenKurrek Aug 4, 2026
aaf6515
Merge remote-tracking branch 'origin/main' into ws3/consolidated
BenKurrek Aug 4, 2026
05fc53f
docs(checklist): strike the egress-threat text the same row already r…
BenKurrek Aug 4, 2026
31726cc
ci(composition): bound composition's absolute production LOC (#7151)
BenKurrek Aug 4, 2026
61fece8
refactor(host_runtime): shed the catalog defaults downward (WS3 row 3)
BenKurrek Aug 4, 2026
def71bf
fix(operator): name the port call in LlmKeyStoreError::Store
BenKurrek Aug 4, 2026
5079ca6
Merge branch 'ws3/row3-catalog' into ws3/consolidated
BenKurrek Aug 4, 2026
324a1f6
test(architecture): inventory same-layer dependency edges (#7149)
BenKurrek Aug 4, 2026
05ad65a
revert(skills): restore the hidden-field install guards — the review …
BenKurrek Aug 4, 2026
f417a40
test(architecture): census LLM-vendor names in the contracts family (…
BenKurrek Aug 4, 2026
a2f9623
Merge remote-tracking branch 'origin/main' into ws3/consolidated
BenKurrek Aug 4, 2026
ca4acb3
test(architecture): make the two new gates visible to CI's test-name …
BenKurrek Aug 4, 2026
1a60f01
docs(target-architecture): record the four enforcement additions and …
BenKurrek Aug 4, 2026
24f96ab
Merge origin/main into ws/enforcement-gates-7147
BenKurrek Aug 4, 2026
966061f
fix(capabilities): make the auth-required enrichment total, dropping …
BenKurrek Aug 4, 2026
7ba9c4e
refactor(capabilities): return the authorization policy helpers to au…
BenKurrek Aug 4, 2026
68ac1dd
fix(docs,ci): correct the guest WIT path and delete a test that never…
BenKurrek Aug 4, 2026
7f242ae
test(host-api): pin the process-sandbox capability literal as a valid id
BenKurrek Aug 4, 2026
54ceefd
Merge origin/main into ws/enforcement-gates-7147
BenKurrek Aug 4, 2026
f4f1236
test(ci): pin the pre-commit staged-path selector after the WIT move
BenKurrek Aug 4, 2026
f39d086
Merge remote-tracking branch 'origin/main' into ws/enforcement-gates-…
BenKurrek Aug 4, 2026
1e971dc
chore(ci): re-seed composition loc_ceiling at the merged-tree count (…
BenKurrek Aug 4, 2026
c16d0f2
Merge remote-tracking branch 'origin/main' into ws3-consolidated-merge
BenKurrek Aug 4, 2026
9b4536c
chore(ci): move the absolute-mass record with its re-seeded ceiling (…
BenKurrek Aug 4, 2026
54e6757
Merge remote-tracking branch 'origin/main' into ws3-consolidated-merge
BenKurrek Aug 4, 2026
ace2fa7
WS5: repoint conversations' turn vocabulary to host_api; record the s…
BenKurrek Aug 4, 2026
20fcf8a
Merge ws3/consolidated (54e6757414) into ws5/conversations-turns-sever
BenKurrek Aug 4, 2026
57971c2
WS5: record the trigger-poller bound mapping and the step-1 blocker
BenKurrek Aug 4, 2026
790b739
WS3: lanes consume a narrow reserve/reconcile/release port (#7067)
BenKurrek Aug 4, 2026
7a89c2b
Merge remote-tracking branch 'origin/ws3/consolidated' into ws3-gover…
BenKurrek Aug 4, 2026
caa9fc8
WS5: descend SubmitTurnResponse to host_api::turn; record the port-in…
BenKurrek Aug 4, 2026
8b901f4
Merge remote-tracking branch 'origin/main' into ws3-consolidated-merge
BenKurrek Aug 4, 2026
2153f0b
WS10: convert the loud path-keyed gates to inventory keying before th…
BenKurrek Aug 4, 2026
f858cfb
WS10: pin the hermetic suite's WebUI frontend resolution
BenKurrek Aug 4, 2026
ccf284c
fix(ci): restore the entry tail the exemptions-union resolution dropped
BenKurrek Aug 4, 2026
23cabea
WS10: classify the repo-root scripts this PR touches in the test planner
BenKurrek Aug 4, 2026
d13fe3f
WS10: name the new gates so the Code Style lane actually runs them
BenKurrek Aug 4, 2026
3038fdf
docs(ws10): record the two gate defects this PR's own CI surfaced
BenKurrek Aug 4, 2026
2ce58fa
Merge remote-tracking branch 'origin/main' into ws3-consolidated-merge
BenKurrek Aug 4, 2026
cac037b
WS5: sever conversations -> turns by port inversion; register 4 -> 3
BenKurrek Aug 4, 2026
6563d80
chore(ci): exempt the consolidation's internal-move re-attributions t…
BenKurrek Aug 4, 2026
6769fd9
Merge remote-tracking branch 'origin/ws3/lane-governor-port' into ws/…
BenKurrek Aug 4, 2026
35388b1
Merge remote-tracking branch 'origin/ws5/conversations-turns-sever' i…
BenKurrek Aug 4, 2026
108344c
Merge remote-tracking branch 'origin/ws10/loud-path-inventory' into w…
BenKurrek Aug 4, 2026
6e82bc2
Merge remote-tracking branch 'origin/ws/enforcement-gates-7147' into …
BenKurrek Aug 4, 2026
89080c5
chore(arch): reconcile the same-layer inventory and downgrade pins wi…
BenKurrek Aug 4, 2026
c804c62
chore(batch): green-up — clippy doc-gap fix, enum-body classifier ext…
BenKurrek Aug 4, 2026
a651aa3
Merge remote-tracking branch 'origin/main' into ws/waves-0-4-batch
BenKurrek Aug 4, 2026
34bf097
chore(batch): delete the never-wired no-egress test fixture that reds…
BenKurrek Aug 4, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
2 changes: 1 addition & 1 deletion .claude/commands/triage-prs.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ For each open PR, determine the primary module it touches by examining the `file
| **Storage & Memory** | `crates/ironclaw_filesystem/`, `crates/ironclaw_memory*/`, `crates/ironclaw_libsql_runtime/`, `migrations/` |
| **Security** | `crates/ironclaw_safety/`, `crates/ironclaw_secrets/`, `crates/ironclaw_trust/`, `crates/ironclaw_authorization/`, `crates/ironclaw_approvals/` |
| **Config & Setup** | `crates/ironclaw_reborn_config/` |
| **Sandbox & Processes** | `crates/ironclaw_process_sandbox/`, `crates/ironclaw_processes/`, `crates/ironclaw_scripts/`, `crates/ironclaw_wasm*/` |
| **Sandbox & Processes** | `crates/ironclaw_sandbox/`, `crates/ironclaw_processes/`, `crates/ironclaw_wasm*/` |
| **Hooks** | `crates/ironclaw_hooks/` |
| **Events & Projections** | `crates/ironclaw_events/`, `crates/ironclaw_event_projections/`, `crates/ironclaw_event_streams/` |
| **CI/CD & Docs** | `.github/`, `README.md`, `CLAUDE.md`, `*.md` (no src) |
Expand Down
4 changes: 2 additions & 2 deletions .claude/rules/safety-and-sandbox.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@ paths:
- "crates/ironclaw_safety/**"
- "crates/ironclaw_host_runtime/**"
- "crates/ironclaw_processes/**"
- "crates/ironclaw_process_sandbox/**"
- "crates/ironclaw_sandbox/**"
- "crates/ironclaw_wasm/**"
- "crates/ironclaw_mcp/**"
- "crates/ironclaw_webui/**"
Expand Down Expand Up @@ -112,7 +112,7 @@ and the owning host-runtime/process-sandbox crates.
filesystem as containment for a subprocess.
- **The only real containment for an OS process is the sandbox it runs in.** Any
deployment that authenticates more than one user MUST route process spawns through
the sandboxed port (`TenantSandboxProcessPort`, backed by `ironclaw_process_sandbox`)
the sandboxed port (`TenantSandboxProcessPort`, backed by `ironclaw_sandbox`)
whose mount is derived from the turn scope — never through the unsandboxed
`HostProcessPort` (renamed from `LocalHostProcessPort`, §4.4 Bucket 2 — `Host`
names the boundary: a process run directly on the host). `HostProcessPort` /
Expand Down
2 changes: 1 addition & 1 deletion .githooks/pre-commit
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ set -euo pipefail
STAGED=$(git diff --cached --name-only)

NEEDS_CHECK=false
if echo "$STAGED" | grep -qE '^wit/|^channels-src/|^tools-src/'; then
if echo "$STAGED" | grep -qE '^crates/ironclaw_wasm/wit/|^channels-src/|^tools-src/'; then
NEEDS_CHECK=true
fi

Expand Down
52 changes: 43 additions & 9 deletions .github/workflows/code_style.yml
Original file line number Diff line number Diff line change
Expand Up @@ -205,24 +205,46 @@ jobs:
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6
with:
persist-credentials: false
# `working-directory:` is a YAML key, not a shell command — it cannot glob
# or resolve a path at runtime, so the family move (crates/<family>/
# ironclaw_webui, PROPOSAL §5) is resolved once here through the shared
# crate inventory (scripts/ci/crate-dir.sh -> scripts/ci/lib/crate_tree.py)
# rather than left as a literal every step below would need updating.
# `env` populated via $GITHUB_ENV is available to a later step's
# `working-directory:` (docs.github.com/actions: context availability for
# jobs.<job_id>.steps.working-directory includes `env`), so every
# subsequent step in THIS job can read it back through ${{ env.* }}.
- name: Resolve WebUI frontend directory
run: |
set -euo pipefail
webui_dir="$(bash scripts/ci/crate-dir.sh ironclaw_webui)"
echo "WEBUI_FRONTEND_DIR=${webui_dir}/frontend" >> "$GITHUB_ENV"
- name: Enable pnpm
run: corepack enable pnpm
- name: Install Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v4
with:
node-version: "22"
cache: "pnpm"
cache-dependency-path: crates/ironclaw_webui/frontend/pnpm-lock.yaml
# actions/setup-node hashes this list to build the cache key
# (verified against the pinned commit's bundled dist/setup/index.js:
# `hashFiles` walks one globber built from every newline-separated
# pattern and only throws when the COMBINED walk finds nothing), so
# the flat line stays live for today's tree and the nested line picks
# up the family move without either one needing to be conditional.
cache-dependency-path: |
crates/ironclaw_webui/frontend/pnpm-lock.yaml
crates/*/ironclaw_webui/frontend/pnpm-lock.yaml
# `no-undef` over WebUI v2 JavaScript catches production modules that reference a
# symbol they never imported. The VM-based component suites stub
# every collaborator through a `vm` context, so that class of bug (e.g. an
# htm `${Component}` used without an import) passes the unit tests and only
# surfaces at runtime — this is the gate the eval harness cannot provide.
- name: Install WebUI v2 frontend deps
working-directory: crates/ironclaw_webui/frontend
working-directory: ${{ env.WEBUI_FRONTEND_DIR }}
run: pnpm install --frozen-lockfile
- name: Lint WebUI v2 JS
working-directory: crates/ironclaw_webui/frontend
working-directory: ${{ env.WEBUI_FRONTEND_DIR }}
run: pnpm lint
# The full vitest suite (chat, extensions, telegram/slack panels, gate
# routing, channels tab, configure modal — the vm-tsx harness) previously
Expand All @@ -231,14 +253,14 @@ jobs:
# vm-tsx setup file is declared in vite.config.ts setupFiles; no extra
# CI configuration beyond node + pnpm is needed.
- name: WebUI v2 frontend tests (vitest)
working-directory: crates/ironclaw_webui/frontend
working-directory: ${{ env.WEBUI_FRONTEND_DIR }}
run: pnpm test
# The SPA build is embedded into the serve binary at compile time through
# Cargo's OUT_DIR (see ironclaw_webui/build.rs), so a frontend that lints
# and tests but does not build still breaks downstream binary builds.
# Keep the build in the same job so the three gates travel together.
- name: Build WebUI v2 frontend
working-directory: crates/ironclaw_webui/frontend
working-directory: ${{ env.WEBUI_FRONTEND_DIR }}
run: pnpm build

clippy:
Expand Down Expand Up @@ -270,14 +292,20 @@ jobs:
with:
node-version: "22"
cache: "pnpm"
cache-dependency-path: crates/ironclaw_webui/frontend/pnpm-lock.yaml
# See the webui-v2-js-lint job above for why this is a depth-tolerant
# glob list rather than a single literal.
cache-dependency-path: |
crates/ironclaw_webui/frontend/pnpm-lock.yaml
crates/*/ironclaw_webui/frontend/pnpm-lock.yaml
- name: Enable pnpm
if: contains(matrix.flags, '--all-features')
run: corepack enable pnpm
- name: Install WebUI frontend dependencies
if: contains(matrix.flags, '--all-features')
run: |
cd crates/ironclaw_webui/frontend
set -euo pipefail
webui_dir="$(bash scripts/ci/crate-dir.sh ironclaw_webui)"
cd "${webui_dir}/frontend"
pnpm install --frozen-lockfile
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
Expand Down Expand Up @@ -338,14 +366,20 @@ jobs:
with:
node-version: "22"
cache: "pnpm"
cache-dependency-path: crates/ironclaw_webui/frontend/pnpm-lock.yaml
# See the webui-v2-js-lint job above for why this is a depth-tolerant
# glob list rather than a single literal.
cache-dependency-path: |
crates/ironclaw_webui/frontend/pnpm-lock.yaml
crates/*/ironclaw_webui/frontend/pnpm-lock.yaml
- name: Enable pnpm
if: contains(matrix.flags, '--all-features')
run: corepack enable pnpm
- name: Install WebUI frontend dependencies
if: contains(matrix.flags, '--all-features')
run: |
cd crates/ironclaw_webui/frontend
set -euo pipefail
webui_dir="$(bash scripts/ci/crate-dir.sh ironclaw_webui)"
cd "${webui_dir}/frontend"
pnpm install --frozen-lockfile
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
Expand Down
30 changes: 26 additions & 4 deletions .github/workflows/coverage.yml
Original file line number Diff line number Diff line change
Expand Up @@ -160,7 +160,16 @@ jobs:
with:
node-version: "22"
cache: "pnpm"
cache-dependency-path: crates/ironclaw_webui/frontend/pnpm-lock.yaml
# actions/setup-node hashes this list to build the cache key
# (verified against the pinned commit's bundled dist/setup/index.js:
# `hashFiles` walks one globber built from every newline-separated
# pattern and only throws when the COMBINED walk finds nothing), so
# the flat line stays live for today's tree and the nested line picks
# up the family move (crates/<family>/ironclaw_webui, PROPOSAL §5)
# without either one needing to be conditional.
cache-dependency-path: |
crates/ironclaw_webui/frontend/pnpm-lock.yaml
crates/*/ironclaw_webui/frontend/pnpm-lock.yaml

- name: Enable pnpm
if: contains(matrix.flags, '--all-features')
Expand All @@ -169,7 +178,9 @@ jobs:
- name: Install WebUI frontend dependencies
if: contains(matrix.flags, '--all-features')
run: |
cd crates/ironclaw_webui/frontend
set -euo pipefail
webui_dir="$(bash scripts/ci/crate-dir.sh ironclaw_webui)"
cd "${webui_dir}/frontend"
pnpm install --frozen-lockfile

- name: Generate coverage
Expand Down Expand Up @@ -238,14 +249,25 @@ jobs:
with:
node-version: "22"
cache: "pnpm"
cache-dependency-path: crates/ironclaw_webui/frontend/pnpm-lock.yaml
# actions/setup-node hashes this list to build the cache key
# (verified against the pinned commit's bundled dist/setup/index.js:
# `hashFiles` walks one globber built from every newline-separated
# pattern and only throws when the COMBINED walk finds nothing), so
# the flat line stays live for today's tree and the nested line picks
# up the family move (crates/<family>/ironclaw_webui, PROPOSAL §5)
# without either one needing to be conditional.
cache-dependency-path: |
crates/ironclaw_webui/frontend/pnpm-lock.yaml
crates/*/ironclaw_webui/frontend/pnpm-lock.yaml

- name: Enable pnpm
run: corepack enable pnpm

- name: Install WebUI frontend dependencies
run: |
cd crates/ironclaw_webui/frontend
set -euo pipefail
webui_dir="$(bash scripts/ci/crate-dir.sh ironclaw_webui)"
cd "${webui_dir}/frontend"
pnpm install --frozen-lockfile

# Pre-build the reborn binary under the same llvm-cov env so the E2E
Expand Down
12 changes: 11 additions & 1 deletion .github/workflows/docker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -79,11 +79,21 @@ jobs:
- name: Extract version from the ironclaw CLI Cargo.toml
id: version
run: |
set -euo pipefail
# The shipped image is the Reborn CLI (`ironclaw`), so the release
# version is that package's version — NOT the root workspace manifest,
# which is the test-only `ironclaw_reborn_integration_tests` package
# pinned at 0.1.0 since Tier B deleted the v1 monolith.
VERSION=$(grep '^version' crates/ironclaw_reborn_cli/Cargo.toml | head -1 | sed 's/.*"\(.*\)"/\1/')
#
# Resolved through the shared crate inventory (scripts/ci/crate-dir.sh)
# rather than the flat `crates/ironclaw_reborn_cli` literal, so this
# step needs no edit when the crate moves into a family directory
# (PROPOSAL §5). If resolution ever fails, `set -e` aborts here before
# `grep` runs against an empty/garbage path — belt-and-suspenders with
# the version-format guard immediately below, which already catches
# an empty VERSION either way.
reborn_cli_dir="$(bash scripts/ci/crate-dir.sh ironclaw_reborn_cli)"
VERSION=$(grep '^version' "${reborn_cli_dir}/Cargo.toml" | head -1 | sed 's/.*"\(.*\)"/\1/')
if [[ ! "${VERSION}" =~ ^[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z.-]+)?$ ]]; then
echo "::error::Extracted version '${VERSION}' must match MAJOR.MINOR.PATCH[-prerelease] (Docker tags forbid '+')"
exit 1
Expand Down
4 changes: 3 additions & 1 deletion .github/workflows/ironclaw-stress.yml
Original file line number Diff line number Diff line change
Expand Up @@ -264,7 +264,9 @@ jobs:

- name: Install WebUI frontend dependencies
run: |
cd crates/ironclaw_webui/frontend
set -euo pipefail
webui_dir="$(bash scripts/ci/crate-dir.sh ironclaw_webui)"
cd "${webui_dir}/frontend"
pnpm install --frozen-lockfile

- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
Expand Down
19 changes: 15 additions & 4 deletions .github/workflows/nightly-deep-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -116,10 +116,21 @@ jobs:
# Targets the dispatch routing logic itself. Keep this pointed at a file
# with real mutable statements — a pure `pub use` re-export file yields
# zero mutants and makes this step silently vacuous.
run: >-
scripts/mutation-audit.sh
-p ironclaw_capabilities
crates/ironclaw_capabilities/src/dispatch.rs
#
# The crate directory is resolved through the shared inventory
# (scripts/ci/crate-dir.sh) rather than the flat `crates/
# ironclaw_capabilities` literal, so this step needs no edit when the
# crate moves into a family directory (PROPOSAL §5) — a stale literal
# here used to be a SILENT failure: cargo-mutants would match zero
# mutants under a path that no longer exists and report a clean run
# over code it never read. `set -e` aborts here if resolution itself
# fails; scripts/mutation-audit.sh's own file-existence guard is the
# second layer, catching dispatch.rs being renamed within a crate that
# still resolves.
run: |
set -euo pipefail
capabilities_dir="$(bash scripts/ci/crate-dir.sh ironclaw_capabilities)"
scripts/mutation-audit.sh -p ironclaw_capabilities "${capabilities_dir}/src/dispatch.rs"
- name: Upload mutation triage queue
if: always()
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
Expand Down
25 changes: 19 additions & 6 deletions .github/workflows/platform-and-compat.yml
Original file line number Diff line number Diff line change
Expand Up @@ -113,11 +113,16 @@ jobs:
# and every WASM ABI check silently skips — the WS10 failure mode
# (#6963). `crates/ironclaw_wasm_product_adapters/` was also dropped:
# that crate no longer exists, so the alternative had been matching
# nothing. scripts/ci/ws12_workflow_contracts.py pins this regex
# nothing. The bare `wit/` alternative went the same way when the WIT
# directory moved inside its owning crate (CHECKLIST WS4): the ABI
# files are `crates/ironclaw_wasm/wit/*.wit` now, already in scope via
# the `ironclaw_wasm` crate alternative, which unlike a repo-root
# prefix survives the WS7 family move too.
# scripts/ci/ws12_workflow_contracts.py pins this regex
# against the real crate inventory and against a real first-party
# extension manifest path, so a renamed, moved or deleted crate fails
# loudly here instead of quietly falling out of scope.
if has_match '^(wit/|crates/([^/]+/)*ironclaw_common/|crates/([^/]+/)*ironclaw_wasm/|crates/([^/]+/)*packages/[^/]+/(manifest\.toml|wasm-src/)|registry/|scripts/build-wasm-extensions\.sh$|scripts/check-version-bumps\.sh$|\.github/workflows/(platform-and-compat|nightly-deep-ci)\.yml$)'; then
if has_match '^(crates/([^/]+/)*ironclaw_common/|crates/([^/]+/)*ironclaw_wasm/|crates/([^/]+/)*packages/[^/]+/(manifest\.toml|wasm-src/)|registry/|scripts/build-wasm-extensions\.sh$|scripts/check-version-bumps\.sh$|\.github/workflows/(platform-and-compat|nightly-deep-ci)\.yml$)'; then
has_direct_wasm_abi_risk=true
fi
echo "has_direct_wasm_abi_risk=$has_direct_wasm_abi_risk" >> "$GITHUB_OUTPUT"
Expand Down Expand Up @@ -264,12 +269,16 @@ jobs:
with:
node-version: "22"
cache: "pnpm"
cache-dependency-path: crates/ironclaw_webui/frontend/pnpm-lock.yaml
cache-dependency-path: |
crates/ironclaw_webui/frontend/pnpm-lock.yaml
crates/*/ironclaw_webui/frontend/pnpm-lock.yaml
- name: Enable pnpm
run: corepack enable pnpm
- name: Install WebUI frontend dependencies
run: |
cd crates/ironclaw_webui/frontend
set -euo pipefail
webui_dir="$(bash scripts/ci/crate-dir.sh ironclaw_webui)"
cd "${webui_dir}/frontend"
pnpm install --frozen-lockfile
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
Expand Down Expand Up @@ -310,12 +319,16 @@ jobs:
with:
node-version: "22"
cache: "pnpm"
cache-dependency-path: crates/ironclaw_webui/frontend/pnpm-lock.yaml
cache-dependency-path: |
crates/ironclaw_webui/frontend/pnpm-lock.yaml
crates/*/ironclaw_webui/frontend/pnpm-lock.yaml
- name: Enable pnpm
run: corepack enable pnpm
- name: Install WebUI frontend dependencies
run: |
cd crates/ironclaw_webui/frontend
set -euo pipefail
webui_dir="$(bash scripts/ci/crate-dir.sh ironclaw_webui)"
cd "${webui_dir}/frontend"
pnpm install --frozen-lockfile
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
Expand Down
15 changes: 13 additions & 2 deletions .github/workflows/reborn-e2e.yml
Original file line number Diff line number Diff line change
Expand Up @@ -203,7 +203,16 @@ jobs:
with:
node-version: "24"
cache: "pnpm"
cache-dependency-path: crates/ironclaw_webui/frontend/pnpm-lock.yaml
# actions/setup-node hashes this list to build the cache key
# (verified against the pinned commit's bundled dist/setup/index.js:
# `hashFiles` walks one globber built from every newline-separated
# pattern and only throws when the COMBINED walk finds nothing), so
# the flat line stays live for today's tree and the nested line picks
# up the family move (crates/<family>/ironclaw_webui, PROPOSAL §5)
# without either one needing to be conditional.
cache-dependency-path: |
crates/ironclaw_webui/frontend/pnpm-lock.yaml
crates/*/ironclaw_webui/frontend/pnpm-lock.yaml

- name: Enable pnpm
run: corepack enable pnpm
Expand All @@ -213,7 +222,9 @@ jobs:

- name: Install WebUI frontend dependencies
run: |
cd crates/ironclaw_webui/frontend
set -euo pipefail
webui_dir="$(bash scripts/ci/crate-dir.sh ironclaw_webui)"
cd "${webui_dir}/frontend"
pnpm install --frozen-lockfile

- name: Install Python
Expand Down
15 changes: 13 additions & 2 deletions .github/workflows/reborn-playwright.yml
Original file line number Diff line number Diff line change
Expand Up @@ -51,14 +51,25 @@ jobs:
with:
node-version: "22"
cache: "pnpm"
cache-dependency-path: crates/ironclaw_webui/frontend/pnpm-lock.yaml
# actions/setup-node hashes this list to build the cache key
# (verified against the pinned commit's bundled dist/setup/index.js:
# `hashFiles` walks one globber built from every newline-separated
# pattern and only throws when the COMBINED walk finds nothing), so
# the flat line stays live for today's tree and the nested line picks
# up the family move (crates/<family>/ironclaw_webui, PROPOSAL §5)
# without either one needing to be conditional.
cache-dependency-path: |
crates/ironclaw_webui/frontend/pnpm-lock.yaml
crates/*/ironclaw_webui/frontend/pnpm-lock.yaml

- name: Enable pnpm
run: corepack enable pnpm

- name: Install WebUI frontend dependencies
run: |
cd crates/ironclaw_webui/frontend
set -euo pipefail
webui_dir="$(bash scripts/ci/crate-dir.sh ironclaw_webui)"
cd "${webui_dir}/frontend"
pnpm install --frozen-lockfile

- name: Restore Rust cache
Expand Down
Loading
Loading