Skip to content

Install signed IronHub prompt assets - #7217

Merged
serrrfirat merged 3 commits into
mainfrom
codex/install-ironhub-prompt-assets
Aug 6, 2026
Merged

serrrfirat merged 3 commits into
mainfrom
codex/install-ironhub-prompt-assets

Conversation

@serrrfirat

Copy link
Copy Markdown
Collaborator

Summary

  • Download, size-check, and SHA-256-verify prompt documents published in signed IronHub tool entries.
  • Match published prompt paths exactly against each manifest's prompt_doc_ref values before package admission, then materialize them through the normal extension package path.
  • Bound prompt artifact counts and include prompt path/digest pairs in install pinning.
  • Add regression coverage through the real extension/skill managers, including filesystem read-back of the installed prompt.

Change Type

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • CI/Infrastructure
  • Security
  • Dependencies

Linked Issue

None. Coordinated publisher change: nearai/ironhub#271.

Validation

  • cargo fmt --all -- --check
  • cargo clippy --all --benches --tests --examples --all-features -- -D warnings — not run repo-wide; scoped cargo clippy -p ironclaw_extension_manager --all-targets --all-features -- -D warnings passed.
  • cargo build — not run separately; the scoped check, test, and clippy builds passed.
  • Relevant tests pass: cargo test -p ironclaw_extension_manager (141 passed)
  • cargo test --features integration if database-backed or integration behavior changed — not applicable; no database behavior changed.
  • Manual testing — not applicable; the deterministic caller-path test performs verified download, install, and filesystem read-back.
  • If a coding agent was used and supports it, review-pr or pr-shepherd --fix was run before requesting review

Test Strategy

User behavior: Given an IronHub tool whose signed manifest declares prompt_doc_ref, when the user installs it, then the prompt document is integrity-verified and available at the declared extension path instead of the install failing.

Risk areas:

  • Model behavior
  • Browser
  • Side effect
  • Persistence
  • Security or permissions
  • External provider
  • Cross-component behavior

Tests added or updated:

  • Unit or contract: Missing prompt assets fail closed; prompt digest changes alter the pinned tool digest; prompt artifact count limits are enforced.
  • Reborn integration: Not applicable: the turn runner and model loop are unchanged; the owning install caller is covered through real extension and skill managers.
  • Recorded fixture: Not applicable: no model selection or tool-argument behavior changed.
  • Browser E2E: Not applicable: no WebUI surface changed.
  • Backend or runtime: verified_tool_and_skill_install_through_real_managers now downloads a signed prompt through mediated egress and reads it back from the installed extension filesystem.
  • Live canary: Not applicable: the coordinated IronHub catalog release is not deployed until Publish manifest prompt assets in the signed tool catalog ironhub#271 merges.

What the tests prove: Prompt artifacts remain bounded and digest-pinned from the signed catalog through download and package admission, missing/unreferenced assets fail closed, and a successful install materializes the exact prompt bytes.

Commands run:

  • cargo check -p ironclaw_extension_manager --tests
  • cargo test -p ironclaw_extension_manager
  • cargo clippy -p ironclaw_extension_manager --all-targets --all-features -- -D warnings
  • cargo fmt --all -- --check
  • git diff --check

Security Impact

IronHub installs make additional mediated HTTPS downloads only for prompt artifacts covered by the signed catalog. Each artifact is count-, size-, path-, and SHA-256-bounded; package admission requires an exact set match with the signed manifest. No permissions, credentials, sandbox policy, or secret handling changes.

Reborn Trust-Boundary Checklist

  • Public policy/evidence/trust-bearing types: Not applicable; this adds an internal signed-catalog artifact map, not a public policy constructor.
  • Untrusted content enters prompts only through an envelope/escaping primitive. No prompt-rendering path changes; assets continue through the existing admitted extension package/host path.
  • Hashes declare purpose; trust/binding/authenticity uses SHA-256/BLAKE3 or separate authenticity check. SHA-256 binds artifact bytes; Ed25519 catalog verification remains the authenticity check.
  • New/changed status, exit, policy, runtime, or error variants: Not applicable; none added.
  • Security/durability serde(default) fields fail closed or have migration tests. An absent field remains backward-compatible; any manifest reference without a published prompt fails exact-set admission.
  • Queues/maps/buffers/counters have bounds and overflow-safe arithmetic. Prompt artifacts are capped at 64 and each download uses the existing metadata byte limit.
  • Driver/operator-visible errors have stable class semantics. Existing catalog/product error variants are preserved.
  • Sandbox/native/host names accurately describe trust boundary. No runtime lane or sandbox naming changes.

Database Impact

None.

Blast Radius

Limited to IronHub tool catalog parsing, artifact pinning, mediated download, and registry package assembly in ironclaw_extension_manager. Tools without prompt artifacts retain their previous digest and install behavior. Older catalog payloads remain compatible because prompts defaults to empty.

Rollback Plan

Revert this commit to restore the prior consumer behavior. IronHub may continue publishing the additive prompts field because older IronClaw clients ignore unknown fields; reverting nearai/ironhub#271 removes the release artifacts as well.

Review Follow-Through

This consumer PR requires the coordinated publisher/catalog change in nearai/ironhub#271 before affected tools become installable from a new release.


Review track: C (signed artifact installation and network trust boundary)

@railway-app

railway-app Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-7217 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Aug 6, 2026 at 8:08 am

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-7217 August 5, 2026 09:09 Destroyed
@github-actions github-actions Bot added the size: L 200-499 changed lines label Aug 5, 2026
@coderabbitai

coderabbitai Bot commented Aug 5, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 1655e584-b251-4e87-a517-91e9bdf3c020

📥 Commits

Reviewing files that changed from the base of the PR and between d9a2d6c and d17c5b0.

📒 Files selected for processing (2)
  • crates/extensions/ironclaw_extension_manager/src/ironhub/package.rs
  • crates/extensions/ironclaw_extension_manager/src/ironhub/tests.rs

📝 Walkthrough

Summary by CodeRabbit

  • New Features

    • Tool packages can now include published prompt artifacts.
    • Prompt artifacts are downloaded, checksum-verified, and included during installation.
    • Prompt metadata supports file paths and SHA-256 integrity verification.
  • Bug Fixes

    • Improved validation detects invalid paths, mismatched or missing prompts, oversized prompt sets, and metadata inconsistencies.

Walkthrough

IronHub manifests now declare prompt artifacts with paths and SHA-256 digests. Validation enforces prompt limits and metadata. Installation downloads and verifies prompts, then packages them at their manifest-declared paths.

Changes

IronHub prompt artifact support

Layer / File(s) Summary
Prompt artifact contract and validation
crates/extensions/ironclaw_extension_manager/src/ironhub/model.rs, crates/extensions/ironclaw_extension_manager/src/ironhub/catalog.rs, crates/extensions/ironclaw_extension_manager/src/ironhub/tests.rs
Adds the prompt artifact map and a limit of 64 artifacts. Manifest validation checks prompt paths, metadata, count, and digest material.
Prompt package assembly
crates/extensions/ironclaw_extension_manager/src/ironhub/package.rs
Accepts published prompt assets, validates path and manifest-reference correspondence, and adds prompt files to the package. Tests cover missing assets, collisions, and digest changes.
Prompt download and installation coverage
crates/extensions/ironclaw_extension_manager/src/ironhub/service.rs, crates/extensions/ironclaw_extension_manager/src/ironhub/tests.rs
Downloads and verifies declared prompts before passing them to package construction. Installation fixtures verify prompt retrieval and materialization at the expected path.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Sequence Diagram(s)

sequenceDiagram
  participant IronHubService
  participant PromptArtifactOrigin
  participant ironhub_tool_package
  participant InstalledTool
  IronHubService->>PromptArtifactOrigin: download declared prompt artifacts
  PromptArtifactOrigin-->>IronHubService: return verified prompt bytes
  IronHubService->>ironhub_tool_package: pass prompt paths and contents
  ironhub_tool_package->>InstalledTool: materialize prompt files
Loading

Suggested reviewers: benkurrek

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the main change; Conventional Commits style is preferred but not mandatory.
Description check ✅ Passed The description is complete and covers changes, validation, security, trust boundaries, blast radius, rollback, and follow-up.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the risk: low Changes to docs, tests, or low-risk modules label Aug 5, 2026
@github-actions github-actions Bot added the contributor: core 20+ merged PRs label Aug 5, 2026
@ironloopai

ironloopai Bot commented Aug 5, 2026 •

Copy link
Copy Markdown
Contributor

🔎 Review · PR #7217

🟢 Completed · Review submitted

1 actionable findings →

The prompt download, digest pinning, origin validation, and exact-reference checks are generally sound, but package assembly permits prompt assets to overwrite other extension files. This is a blocking runtime-integrity issue.

Automatic · PR opened · attempt 1 of 3 · completed in 1m 46s

Run details
  • Repository: nearai/ironclaw
  • Base: main at c51a573
  • Head: codex/install-ironhub-prompt-assets at b486da6
  • Created: Aug 5, 2026, 9:14 AM UTC
  • Updated: Aug 5, 2026, 9:16 AM UTC
  • Run: 98164db9-85e6-41e6-a7b3-738ed33c9694
  • Latest attempt: 1 · Completed · febbb0f4-a366-4c3b-ae52-e179ae9c8274

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Review complete · PR #7217

⚠️ 1 finding · 1 blocking

The prompt download, digest pinning, origin validation, and exact-reference checks are generally sound, but package assembly permits prompt assets to overwrite other extension files. This is a blocking runtime-integrity issue.

Findings

  1. 🔴 High · Reject prompt paths that collide with existing package assets — crates/ironclaw_extension_manager/src/ironhub/package.rs:128
    Details are attached to the relevant diff.
Validation and technical details
  • Reviewed the complete trusted comparison refs/ironloop/base (c51a573) through refs/ironloop/head (b486da6), covering all five changed files.
  • Traced package admission through registry_extension_package and filesystem materialization through materialize_available_extension; admission searches the first matching asset while materialization writes duplicate paths in sequence.
  • Verified git diff --check for the trusted comparison completed without whitespace errors.
  • Could not execute Rust tests because cargo is unavailable in the review environment (cargo: command not found).
  • Base: main
  • Head: codex/install-ironhub-prompt-assets at b486da6
  • Run: 98164db9-85e6-41e6-a7b3-738ed33c9694

),
});
}
files.extend(prompt_assets);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 High · Reject prompt paths that collide with existing package assets

Prompt paths are checked only for duplicates within prompt_assets. They are then appended without checking collisions with manifest.toml, legacy/capabilities.json, the WASM module, or schema assets. The host validates declared assets using the first matching path, but materialization writes every asset sequentially, so a later prompt with the same path overwrites the validated file. For example, a manifest can use its WASM module path as prompt_doc_ref; admission validates the genuine component, then installation replaces it with Markdown, leaving an activated extension that cannot execute. Colliding with manifest.toml can similarly leave persisted package contents inconsistent and break restoration. Reject prompt paths already occupied by any package asset, ideally by enforcing uniqueness across the complete file collection before package admission.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in d17c5b000: prompt paths are now rejected when they collide with manifest, capabilities, WASM, or schema assets; a regression test covers attempted WASM replacement.
Verification: cargo test -p ironclaw_extension_manager (142 passed), clippy, fmt, and the Reborn production panic baseline all pass.

@serrrfirat

Copy link
Copy Markdown
Collaborator Author

Railway preview QA — PASS

Given / When / Then evidence

Case Result Observed evidence
Install the official YouTube IronHub entry through the production chat caller PASS The turn discovered official youtube v0.2.0, verified its signed artifact digest, downloaded and installed it, and returned an installed lifecycle result instead of operation_failed.
Distinguish installation success from credential activation PASS Installation completed; activation stopped at the expected YouTube credential gate. The response listed all six YouTube capabilities.
Read back durable UI state PASS /extensions/registry showed YouTube v0.2.0 under Installed with finish setup, Configure, and 6 capabilities. A full page refresh preserved the same state.
Cleanup only test-created state PASS Removed the YouTube extension through its scoped registry action; the UI confirmed YouTube removed and returned it to Available extensions.

Exact regression result

The prior failure was a generic operation_failed while importing a native manifest whose prompt_doc_ref assets were present in the signed IronHub catalog but omitted by the Ironclaw consumer. On this exact head, the same official YouTube v0.2.0 catalog entry installs successfully. This validates the PR's prompt-artifact download/materialization path through the live caller.

Skipped / remaining risk

  • Credential entry and live YouTube API calls were skipped: this PR changes signed package installation, not credential setup or provider execution.
  • No unrelated auth, permission-role, streaming, responsive-layout, or browser cases were selected.
  • The install was exercised against the current signed IronHub catalog and the preview's real mediated download path; external catalog availability remains an environmental dependency.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/extensions/ironclaw_extension_manager/src/ironhub/tests.rs`:
- Around line 2121-2123: Add an item-level `#[cfg(any(test, feature =
"test-support"))]` attribute directly above
`published_tool_manifest_with_prompt` so the `.expect()`-using fixture helper is
excluded from production builds and panic checks.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: f7624c2e-8f1a-4815-9107-88b06e78e40a

📥 Commits

Reviewing files that changed from the base of the PR and between 2f125c3 and d9a2d6c.

📒 Files selected for processing (5)
  • crates/extensions/ironclaw_extension_manager/src/ironhub/catalog.rs
  • crates/extensions/ironclaw_extension_manager/src/ironhub/model.rs
  • crates/extensions/ironclaw_extension_manager/src/ironhub/package.rs
  • crates/extensions/ironclaw_extension_manager/src/ironhub/service.rs
  • crates/extensions/ironclaw_extension_manager/src/ironhub/tests.rs

Comment thread crates/extensions/ironclaw_extension_manager/src/ironhub/tests.rs
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-7217 August 6, 2026 08:02 Destroyed
@serrrfirat
serrrfirat enabled auto-merge August 6, 2026 08:15
@serrrfirat
serrrfirat added this pull request to the merge queue Aug 6, 2026
Merged via the queue into main with commit d739b31 Aug 6, 2026
45 checks passed
@serrrfirat
serrrfirat deleted the codex/install-ironhub-prompt-assets branch August 6, 2026 08:58
@serrrfirat serrrfirat mentioned this pull request Aug 10, 2026
21 of 29 tasks
l3ocifer pushed a commit to l3ocifer/frick-ironclaw that referenced this pull request Sep 3, 2026
* fix(ironhub): install signed prompt assets

* fix(ironhub): reject colliding prompt assets

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-7217 — d17c5b00 Deployed Aug 6, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules size: L 200-499 changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants