Repository navigation
Install signed IronHub prompt assets - #7217
Conversation
|
🚅 Deployed to the ironclaw-pr-7217 environment in ironclaw-ci-preview
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
📝 WalkthroughSummary by CodeRabbit
WalkthroughIronHub manifests now declare prompt artifacts with paths and SHA-256 digests. Validation enforces prompt limits and metadata. Installation downloads and verifies prompts, then packages them at their manifest-declared paths. ChangesIronHub prompt artifact support
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant IronHubService
participant PromptArtifactOrigin
participant ironhub_tool_package
participant InstalledTool
IronHubService->>PromptArtifactOrigin: download declared prompt artifacts
PromptArtifactOrigin-->>IronHubService: return verified prompt bytes
IronHubService->>ironhub_tool_package: pass prompt paths and contents
ironhub_tool_package->>InstalledTool: materialize prompt files
Suggested reviewers: 🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🔎 Review · PR #7217
1 actionable findings →The prompt download, digest pinning, origin validation, and exact-reference checks are generally sound, but package assembly permits prompt assets to overwrite other extension files. This is a blocking runtime-integrity issue. Automatic · PR opened · attempt 1 of 3 · completed in 1m 46s Run details
|
There was a problem hiding this comment.
🔍 Review complete · PR #7217
The prompt download, digest pinning, origin validation, and exact-reference checks are generally sound, but package assembly permits prompt assets to overwrite other extension files. This is a blocking runtime-integrity issue.
Findings
- 🔴 High · Reject prompt paths that collide with existing package assets —
crates/ironclaw_extension_manager/src/ironhub/package.rs:128
Details are attached to the relevant diff.
Validation and technical details
- Reviewed the complete trusted comparison
refs/ironloop/base(c51a573) throughrefs/ironloop/head(b486da6), covering all five changed files. - Traced package admission through
registry_extension_packageand filesystem materialization throughmaterialize_available_extension; admission searches the first matching asset while materialization writes duplicate paths in sequence. - Verified
git diff --checkfor the trusted comparison completed without whitespace errors. - Could not execute Rust tests because
cargois unavailable in the review environment (cargo: command not found). - Base:
main - Head:
codex/install-ironhub-prompt-assetsatb486da6 - Run:
98164db9-85e6-41e6-a7b3-738ed33c9694
| ), | ||
| }); | ||
| } | ||
| files.extend(prompt_assets); |
There was a problem hiding this comment.
🔴 High · Reject prompt paths that collide with existing package assets
Prompt paths are checked only for duplicates within prompt_assets. They are then appended without checking collisions with manifest.toml, legacy/capabilities.json, the WASM module, or schema assets. The host validates declared assets using the first matching path, but materialization writes every asset sequentially, so a later prompt with the same path overwrites the validated file. For example, a manifest can use its WASM module path as prompt_doc_ref; admission validates the genuine component, then installation replaces it with Markdown, leaving an activated extension that cannot execute. Colliding with manifest.toml can similarly leave persisted package contents inconsistent and break restoration. Reject prompt paths already occupied by any package asset, ideally by enforcing uniqueness across the complete file collection before package admission.
There was a problem hiding this comment.
Addressed in d17c5b000: prompt paths are now rejected when they collide with manifest, capabilities, WASM, or schema assets; a regression test covers attempted WASM replacement.
Verification: cargo test -p ironclaw_extension_manager (142 passed), clippy, fmt, and the Reborn production panic baseline all pass.
Railway preview QA — PASS
Given / When / Then evidence
Exact regression resultThe prior failure was a generic Skipped / remaining risk
|
|
Note GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer. |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@crates/extensions/ironclaw_extension_manager/src/ironhub/tests.rs`:
- Around line 2121-2123: Add an item-level `#[cfg(any(test, feature =
"test-support"))]` attribute directly above
`published_tool_manifest_with_prompt` so the `.expect()`-using fixture helper is
excluded from production builds and panic checks.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: f7624c2e-8f1a-4815-9107-88b06e78e40a
📒 Files selected for processing (5)
crates/extensions/ironclaw_extension_manager/src/ironhub/catalog.rscrates/extensions/ironclaw_extension_manager/src/ironhub/model.rscrates/extensions/ironclaw_extension_manager/src/ironhub/package.rscrates/extensions/ironclaw_extension_manager/src/ironhub/service.rscrates/extensions/ironclaw_extension_manager/src/ironhub/tests.rs
* fix(ironhub): install signed prompt assets * fix(ironhub): reject colliding prompt assets
Summary
prompt_doc_refvalues before package admission, then materialize them through the normal extension package path.Change Type
Linked Issue
None. Coordinated publisher change: nearai/ironhub#271.
Validation
cargo fmt --all -- --checkcargo clippy --all --benches --tests --examples --all-features -- -D warnings— not run repo-wide; scopedcargo clippy -p ironclaw_extension_manager --all-targets --all-features -- -D warningspassed.cargo build— not run separately; the scoped check, test, and clippy builds passed.cargo test -p ironclaw_extension_manager(141 passed)cargo test --features integrationif database-backed or integration behavior changed — not applicable; no database behavior changed.review-prorpr-shepherd --fixwas run before requesting reviewTest Strategy
User behavior: Given an IronHub tool whose signed manifest declares
prompt_doc_ref, when the user installs it, then the prompt document is integrity-verified and available at the declared extension path instead of the install failing.Risk areas:
Tests added or updated:
verified_tool_and_skill_install_through_real_managersnow downloads a signed prompt through mediated egress and reads it back from the installed extension filesystem.What the tests prove: Prompt artifacts remain bounded and digest-pinned from the signed catalog through download and package admission, missing/unreferenced assets fail closed, and a successful install materializes the exact prompt bytes.
Commands run:
cargo check -p ironclaw_extension_manager --testscargo test -p ironclaw_extension_managercargo clippy -p ironclaw_extension_manager --all-targets --all-features -- -D warningscargo fmt --all -- --checkgit diff --checkSecurity Impact
IronHub installs make additional mediated HTTPS downloads only for prompt artifacts covered by the signed catalog. Each artifact is count-, size-, path-, and SHA-256-bounded; package admission requires an exact set match with the signed manifest. No permissions, credentials, sandbox policy, or secret handling changes.
Reborn Trust-Boundary Checklist
serde(default)fields fail closed or have migration tests. An absent field remains backward-compatible; any manifest reference without a published prompt fails exact-set admission.Database Impact
None.
Blast Radius
Limited to IronHub tool catalog parsing, artifact pinning, mediated download, and registry package assembly in
ironclaw_extension_manager. Tools without prompt artifacts retain their previous digest and install behavior. Older catalog payloads remain compatible becausepromptsdefaults to empty.Rollback Plan
Revert this commit to restore the prior consumer behavior. IronHub may continue publishing the additive
promptsfield because older IronClaw clients ignore unknown fields; reverting nearai/ironhub#271 removes the release artifacts as well.Review Follow-Through
This consumer PR requires the coordinated publisher/catalog change in nearai/ironhub#271 before affected tools become installable from a new release.
Review track: C (signed artifact installation and network trust boundary)