Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
74 commits
Select commit Hold shift + click to select a range
0c9a3dd
docs(target-arch): resolve the await-edge design question by measurem…
BenKurrek Aug 5, 2026
8b56e2d
docs(ws12): rows 1-2 — package-set tick (64==64/1/0, gate+selftest+in…
BenKurrek Aug 5, 2026
b77fc07
fold: await-edge ruling (D-S) — store measured as journal projection,…
BenKurrek Aug 5, 2026
4c4f4e9
fold: WS12 rows 1-2 — package-set tick (64/64/1/0) + the 74-row §9 ma…
BenKurrek Aug 5, 2026
783b575
fold(7154): squash-port fix/red-main-7119 onto family-world main — de…
BenKurrek Aug 5, 2026
4aa656c
test(extractors): issue-number + assertion-rationale doc refinement (…
BenKurrek Aug 5, 2026
533d095
docs(target-arch): record D-R — the loopback credential-guard ruling,…
BenKurrek Aug 5, 2026
993ec64
review(7154): CodeRabbit round-1 triage — fail-closed tracing-target …
BenKurrek Aug 5, 2026
297d4f9
fix(assistant): re-point the one field-form tracing target the #7146 …
BenKurrek Aug 5, 2026
d5797ed
fold: the #7154 defect train through the rename+family map — loopback…
BenKurrek Aug 5, 2026
0c6c0cf
closure fixups: execute the mapping-audit findings — prompt_envelope …
BenKurrek Aug 5, 2026
9e68ba3
merge origin/main (#6831 standardized messaging framework) into the c…
BenKurrek Aug 5, 2026
b2ced45
docs(ws12): second-reviewer security spot-audit + extension-journey r…
BenKurrek Aug 6, 2026
ddc5dd2
fold: WS12 rows 5-6 — extension journeys + §12.1 second-reviewer secu…
BenKurrek Aug 6, 2026
bb06522
ratchet(closure): lock the budget gate at the program's end state
BenKurrek Aug 6, 2026
245bae3
docs(ws12): gauntlet report — row 3 ticked (full gauntlet green, 0 RE…
BenKurrek Aug 6, 2026
4a65201
fold: WS12 rows 3-4 verification — full gauntlet green (0 REAL), pari…
BenKurrek Aug 6, 2026
8d13454
docs(guidance): set the crate/family guidance convention
BenKurrek Aug 6, 2026
864d93e
fix(tests): per-test isolated Postgres databases for the two WS12 par…
BenKurrek Aug 6, 2026
05668c9
docs(reborn): record §12.13 D-T (parity-suite isolation ruling) and c…
BenKurrek Aug 6, 2026
3c646e8
docs(extensions): family guidance layer — AGENTS.md rewrite to the gu…
BenKurrek Aug 6, 2026
022f38f
docs(guidance): substrates + lanes family guidance per guidance-conve…
BenKurrek Aug 6, 2026
93af288
docs(crates-map): rewrite the three top-level maps family-first after…
BenKurrek Aug 6, 2026
e3be23c
docs(crates-map): package directories carry their own README.md (coor…
BenKurrek Aug 6, 2026
d55b154
docs(guidance): contracts + events family guidance layer per docs/reb…
BenKurrek Aug 6, 2026
5db1a3f
docs(target-arch): three measured corrections surfaced by the guidanc…
BenKurrek Aug 6, 2026
83f1676
docs(kernel): family guidance layer — perimeter AGENTS.md, nine crate…
BenKurrek Aug 6, 2026
85db706
docs(domains): family guidance layer — AGENTS.md boundary doc, 12 cra…
BenKurrek Aug 6, 2026
5e95f76
docs(target-arch): repair the corrupted kernel bullet and correct two…
BenKurrek Aug 6, 2026
0d3d751
test(arch): govern the ProtocolAuthEvidence test seam — WS12 audit F1
BenKurrek Aug 6, 2026
c449a68
test(integration): join the gsuite credential-injection journey — WS1…
BenKurrek Aug 6, 2026
3ac3bfe
docs(target-arch): correct five measured dependency claims in familie…
BenKurrek Aug 6, 2026
2648ed9
Merge remote-tracking branch 'origin/docs/family-substrates-lanes' in…
BenKurrek Aug 6, 2026
c58b6ca
Merge remote-tracking branch 'origin/docs/family-kernel' into docs/gu…
BenKurrek Aug 6, 2026
6a4bf6c
Merge remote-tracking branch 'origin/docs/family-domains' into docs/g…
BenKurrek Aug 6, 2026
bcaf480
Merge remote-tracking branch 'origin/docs/family-extensions' into doc…
BenKurrek Aug 6, 2026
ce0d1bb
Merge remote-tracking branch 'origin/docs/crates-map' into docs/guidance
BenKurrek Aug 6, 2026
777bd58
Merge branch 'program-closure' into docs/guidance
BenKurrek Aug 6, 2026
71cf60c
fold: security follow-ups — pin the test-seam mint constructors (F1) …
BenKurrek Aug 6, 2026
5c16055
docs(guidance): family AGENTS.md + crate READMEs + guidance consolida…
BenKurrek Aug 6, 2026
0ea85ec
docs(target-arch): record the closed scan evasions (F4) and the secre…
BenKurrek Aug 6, 2026
2581935
Merge remote-tracking branch 'origin/docs/family-loop-product-app' in…
BenKurrek Aug 6, 2026
e76b70c
docs(target-arch): correct the app-family layer, config's consumer se…
BenKurrek Aug 6, 2026
15d4c48
docs(stale-sweep): fix agent guidance outside crates/ for the family …
BenKurrek Aug 6, 2026
7d33b59
Merge remote-tracking branch 'origin/docs/stale-sweep' into docs/guid…
BenKurrek Aug 6, 2026
4dff436
Merge branch 'program-closure' into docs/guidance
BenKurrek Aug 6, 2026
5184b68
docs(ws12): tick row 7 — the fresh-agent placement probe passed on th…
BenKurrek Aug 6, 2026
d865e72
Merge branch 'program-closure' into docs/guidance
BenKurrek Aug 6, 2026
a288613
docs(target-arch): the product→loop_host recount was wrong on the day…
BenKurrek Aug 6, 2026
cfdbe6b
Merge branch 'program-closure' into docs/guidance
BenKurrek Aug 6, 2026
c7229fe
review(7263): CodeRabbit round-1 triage — 4 code fixes (2 sabotage-pr…
BenKurrek Aug 6, 2026
0720766
Merge remote-tracking branch 'origin/program-closure' into docs/guidance
BenKurrek Aug 6, 2026
6c3831d
review(7263): CodeRabbit round-2 — rejection-body read keeps its caus…
BenKurrek Aug 6, 2026
5db4640
Merge remote-tracking branch 'origin/program-closure' into docs/guidance
BenKurrek Aug 6, 2026
ae3492a
review(7263): CodeRabbit round-3 — shared Postgres test provisioner (…
BenKurrek Aug 6, 2026
485a207
docs: move the guidance convention into this PR so its citations resolve
BenKurrek Aug 6, 2026
bf31d20
Merge remote-tracking branch 'origin/program-closure' into docs/guidance
BenKurrek Aug 6, 2026
778955d
fix(ci): give the hoisted postgres provisioner its safety rationales
BenKurrek Aug 6, 2026
e0957f1
merge origin/main into the closure batch
BenKurrek Aug 6, 2026
ef38082
Merge remote-tracking branch 'origin/program-closure' into docs/guidance
BenKurrek Aug 6, 2026
b851e1b
Merge remote-tracking branch 'origin/main' into program-closure
BenKurrek Aug 6, 2026
1a88f6f
Merge remote-tracking branch 'origin/program-closure' into docs/guidance
BenKurrek Aug 6, 2026
14554a7
Merge remote-tracking branch 'origin/main' into program-closure
BenKurrek Aug 6, 2026
7fd54fb
Merge remote-tracking branch 'origin/program-closure' into docs/guidance
BenKurrek Aug 6, 2026
d2b589c
Merge remote-tracking branch 'origin/main' into program-closure
BenKurrek Aug 6, 2026
aeb3c20
Merge remote-tracking branch 'origin/program-closure' into docs/guidance
BenKurrek Aug 6, 2026
935cbc3
Merge remote-tracking branch 'origin/main' into program-closure
BenKurrek Aug 6, 2026
667e764
Merge remote-tracking branch 'origin/program-closure' into docs/guidance
BenKurrek Aug 6, 2026
8ce6fbe
Merge remote-tracking branch 'origin/main' into program-closure
BenKurrek Aug 6, 2026
f1be131
Merge remote-tracking branch 'origin/program-closure' into docs/guidance
BenKurrek Aug 6, 2026
29d2934
Merge remote-tracking branch 'origin/main' into program-closure
BenKurrek Aug 6, 2026
b41b6c2
Merge remote-tracking branch 'origin/program-closure' into docs/guidance
BenKurrek Aug 6, 2026
cf76f6a
Merge remote-tracking branch 'origin/main' into docs/guidance
BenKurrek Aug 6, 2026
f3c434d
fix(ci): classify the three planner-unknown paths this PR touches
BenKurrek Aug 6, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
146 changes: 29 additions & 117 deletions .claude/commands/add-sse-event.md
Original file line number Diff line number Diff line change
@@ -1,122 +1,34 @@
---
description: Scaffold a new SSE event end-to-end (Rust backend to web frontend)
allowed-tools: Read, Edit, Write, Glob, Grep, Bash(cargo fmt:*), Bash(cargo clippy:*), Bash(cargo test:*)
description: Retired v1 SSE scaffold — redirects to the Reborn projection/streaming path (full rewrite pending)
allowed-tools: Read, Glob, Grep
argument-hint: <event_name> [description]
model: opus
---

> # ⚠ DO NOT FOLLOW THIS COMMAND — IT TARGETS A DELETED CODEBASE
>
> **Every file path in the steps below is gone.** This procedure scaffolds into
> the retired v1 gateway SSE path: `src/channels/` (Steps 1–3),
> `crates/ironclaw_gateway/static/` (Steps 4–5), and `src/agent/` / `src/worker/`
> (Step 6) — the final checklist names the same dead files. The
> `ironclaw_gateway` crate and the entire root `src/` monolith were deleted from
> the tree; none of these files exist and none should be created. Only Step 7
> (`cargo fmt` / `clippy`) still means anything. Following this command produces
> new files in a directory layout the build does not know about.
>
> **This command needs rewriting onto the `ironclaw_webui` streaming path** —
> the Reborn projection/SSE frame served by `crates/product/ironclaw_webui`, with the
> client side in `crates/product/ironclaw_webui/frontend/`, over the event-stream
> substrate (`ironclaw_event_log` → `ironclaw_event_projections` →
> `ironclaw_event_streams`). That rewrite has not been done: the correct
> Reborn procedure is **not** written down here, and this banner deliberately
> does not guess at it.
>
> Until then, for a new user-visible event start from the `reborn-feature`
> skill and `.claude/rules/gateway-events.md` (the live Reborn events and
> transport-projection rules), not from the steps below.
>
> *Identified in PR #6944 (WS11.3 guidance drift hotfixes), which found the
> paths dead but scoped the rewrite out — replacing a scaffold procedure is new
> guidance, not a drift fix.*

Add a new SSE event called `$ARGUMENTS` to the IronClaw web gateway. This involves changes across 5 files in a specific order. Follow each step exactly.

## Step 1: Add `StatusUpdate` variant

**File**: `src/channels/channel.rs`

Find the `StatusUpdate` enum and add a new variant. Use the event name in PascalCase. Include any fields the event needs as named fields (not a generic String).

Example for reference (existing variants):
```rust
pub enum StatusUpdate {
Thinking(String),
ToolStarted { name: String },
ToolCompleted { name: String, success: bool },
Status(String),
ApprovalNeeded {
request_id: String,
tool_name: String,
description: String,
parameters: serde_json::Value,
},
}
```

## Step 2: Map to `SseEvent` in web channel

**File**: `src/channels/web/mod.rs`

Find the `send_status` method in the `Channel` impl for `WebChannel`. Add a match arm for the new `StatusUpdate` variant that maps it to an `SseEvent`. The SSE event name should be snake_case.

Look at existing match arms for the pattern. The event data is serialized as JSON.

## Step 3: Add types if needed

**File**: `src/channels/web/types.rs`

If the event carries structured data beyond a simple string, add a serializable DTO struct here. Use `#[derive(Debug, Clone, Serialize, Deserialize)]`. Follow the existing patterns in the file.

## Step 4: Add frontend handler

**File**: ~~`crates/ironclaw_gateway/static/js/core/sse.js`~~ — **deleted; do not create.** The Reborn client lives in `crates/product/ironclaw_webui/frontend/`.

In the `connectSSE()` function, add a new `eventSource.addEventListener()` for the snake_case event name. Parse the JSON data and call a handler function.

Create the handler function that updates the DOM. Put it in the split file that matches its surface — e.g. `js/core/onboarding.js` for auth/onboarding handlers, `js/surfaces/chat.js` for chat message handlers, `js/surfaces/jobs.js` for sandbox job events. Follow existing patterns:
- `showApproval(data)` for complex card-style UI
- `addMessage(role, content)` for simple text
- `setStatus(text, spinning)` for status bar updates

## Step 5: Add CSS if needed

**File**: ~~`crates/ironclaw_gateway/static/styles/`~~ — **deleted; do not create.** Reborn styling lives with the SPA under `crates/product/ironclaw_webui/frontend/`.

If the event needs custom UI (cards, badges, etc.), add styles. Follow the existing naming conventions (`.approval-card`, `.log-entry`, etc.).

## Step 6: Send the event from Rust

Identify where in the backend this event should be triggered. Common locations:
- `src/agent/agent_loop.rs` - During message processing or tool execution
- `src/worker/job.rs` - During job execution
- `src/agent/heartbeat.rs` - During periodic execution

Use the existing pattern:
```rust
let _ = self.channels.send_status(
&message.channel,
StatusUpdate::YourNewVariant { ... },
&message.metadata,
).await;
```

## Step 7: Quality gate

Run `cargo fmt` and `cargo clippy --all --benches --tests --examples --all-features` to verify the changes compile cleanly.

## Checklist

Before finishing, verify:
- [ ] `StatusUpdate` variant added in `channel.rs`
- [ ] Match arm added in `web/mod.rs` `send_status`
- [ ] DTO added in `types.rs` (if needed)
- [ ] `addEventListener` added in `app.js`
- [ ] Handler function created in `app.js`
- [ ] CSS styles added (if needed)
- [ ] Event sent from appropriate backend location
- [ ] `cargo fmt` clean
- [ ] `cargo clippy` clean
- [ ] Non-web channels unaffected (they ignore unknown StatusUpdate variants)
# This command's scaffold procedure was retired with the v1 codebase

The step-by-step procedure this command used to carry scaffolded into the
deleted v1 gateway SSE path (`src/channels/`, `crates/ironclaw_gateway/static/`,
`src/agent/` / `src/worker/`). The `ironclaw_gateway` crate and the entire root
`src/` monolith were deleted from the tree; none of those files exist and none
should be created. The dead steps were removed rather than left behind a
warning banner (2026-08-05 stale-docs sweep; the paths were first found dead in
PR #6944, which scoped the rewrite out).
Comment on lines +10 to +16

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

Fix the retired-path sentence.

Line 10 is not grammatical: “used to carry scaffolded into” is unclear. Replace it with “used to scaffold the deleted v1 gateway SSE path.”

Proposed wording fix
-The step-by-step procedure this command used to carry scaffolded into the
+The step-by-step procedure this command used to scaffold the
 deleted v1 gateway SSE path (`src/channels/`, `crates/ironclaw_gateway/static/`,
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
The step-by-step procedure this command used to carry scaffolded into the
deleted v1 gateway SSE path (`src/channels/`, `crates/ironclaw_gateway/static/`,
`src/agent/` / `src/worker/`). The `ironclaw_gateway` crate and the entire root
`src/` monolith were deleted from the tree; none of those files exist and none
should be created. The dead steps were removed rather than left behind a
warning banner (2026-08-05 stale-docs sweep; the paths were first found dead in
PR #6944, which scoped the rewrite out).
The step-by-step procedure this command used to scaffold the
deleted v1 gateway SSE path (`src/channels/`, `crates/ironclaw_gateway/static/`,
`src/agent/` / `src/worker/`). The `ironclaw_gateway` crate and the entire root
`src/` monolith were deleted from the tree; none of those files exist and none
should be created. The dead steps were removed rather than left behind a
warning banner (2026-08-05 stale-docs sweep; the paths were first found dead in
PR `#6944`, which scoped the rewrite out).
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/commands/add-sse-event.md around lines 10 - 16, Update the
retired-path sentence in the command documentation to use the grammatical
wording “used to scaffold the deleted v1 gateway SSE path.” Keep the surrounding
explanation and deleted-path references unchanged.


**The Reborn replacement procedure has not been written.** A correct rewrite
targets the `ironclaw_webui` streaming path — the Reborn projection/SSE frame
served by `crates/product/ironclaw_webui`, with the client side in
`crates/product/ironclaw_webui/frontend/`, over the event-stream substrate
(`crates/events/ironclaw_event_log` → `crates/events/ironclaw_event_projections`
→ `crates/events/ironclaw_event_streams`). This stub deliberately does not
guess at the step list.

Until the rewrite lands, to add a new user-visible event `$ARGUMENTS`:

1. Start from the `reborn-feature` skill (`.claude/skills/reborn-feature/SKILL.md`)
to wire the feature across the layers.
2. Read `.claude/rules/gateway-events.md` — the live Reborn events and
transport-projection rules.
3. Find the current server-side stream seam with
`grep -n "stream_events" crates/product/ironclaw_webui/src/webui_v2/handlers.rs`
and the client consumption in `crates/product/ironclaw_webui/frontend/src/`.
34 changes: 19 additions & 15 deletions .claude/commands/deslop-reborn.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,18 +21,19 @@ crate and skip the selection cascade in §1 — but still run the §1 Reborn/leg
a legitimate Reborn target. Otherwise pick one per §1.

## 0. Environment & state
- **Reborn-only.** New feature and quality work targets the Reborn stack in `crates/`, never the v1
`src/` monolith (root CLAUDE.md, "Where to Build — Reborn-First"). This loop only touches `crates/`
Reborn crates. It must **skip the legacy enclave** — crates that serve *only* the retiring v1
monolith. That enclave is now empty — `ironclaw_engine`, `ironclaw_tui`, `ironclaw_gateway`, and
`ironclaw_oauth` have all been removed, so every crate under `crates/` that the workspace builds
is a legitimate target. Two caveats you can check in the root `Cargo.toml`: `tools/ironclaw_silk_decoder`
- **Reborn-only.** All work targets the Reborn stack in `crates/` (root CLAUDE.md, "Where to Build
— the Reborn stack in `crates/`"). The v1 `src/` monolith and its legacy enclave
(`ironclaw_engine`, `ironclaw_tui`, `ironclaw_gateway`, `ironclaw_oauth`) have all been removed,
so every crate under `crates/` that the workspace builds is a legitimate target. Two caveats you can check in the root `Cargo.toml`: `tools/ironclaw_silk_decoder`
is in `exclude`, so workspace-wide `cargo` commands never see it; and a crate with no consumers
may be queued for deletion rather than for de-slopping (`grep -rl "<crate>" crates/*/Cargo.toml
Cargo.toml`). Verify each candidate's status with the orientation recipe (§1) before picking it.
may be queued for deletion rather than for de-slopping (`grep -rl --include=Cargo.toml "<crate>"
crates/ Cargo.toml` — the family layout means `crates/*/Cargo.toml` matches nothing). Verify each
candidate's status with the orientation recipe (§1) before picking it.
- **Local gate reality.** You can prove `cargo fmt`, `cargo clippy`, per-crate `cargo test -p <crate>`,
the workspace unit-test tier, and the architecture-boundary test (`cargo test -p ironclaw_architecture_tests`)
locally. The **integration tier** (`cargo test --features integration`) needs a running PostgreSQL;
locally. The **backend-integration tier** (crate-level feature-gated suites, e.g.
`cargo test -p ironclaw_hooks --features integration` — the workspace-root `integration` feature is
empty and does nothing) needs Docker for its Postgres testcontainers;
the **live tier** (`-- --ignored`) needs Postgres + LLM API keys; **Reborn e2e**
(`scripts/reborn-e2e-rust.sh`) may need Docker. If a fix touches those paths, implement it fully and
mark the gate **"CI-deferred (needs Postgres/Docker/keys)"** in the PR body. Never weaken or delete
Expand All @@ -45,10 +46,12 @@ a legitimate Reborn target. Otherwise pick one per §1.
open PR holds.

## 1. Pick ONE un-de-slopped Reborn crate — stop at first viable
List the crates (`ls crates/`). A crate is a **candidate** when ALL hold:
- **it is a Reborn crate, not legacy-enclave.** Verify: `grep -rl "<crate_name>" crates/*/Cargo.toml Cargo.toml`
— if the **only** consumer is the root `Cargo.toml` package, it's v1-only; skip it. When unsure,
consult the `ironclaw-reborn-orientation` skill (it maps which side each crate is on).
List the crates (`ls crates/*/` — the top level is the ten family directories, crates are one level
down, plus `crates/extensions/packages/*`). A crate is a **candidate** when ALL hold:
- **it has real consumers.** Verify: `grep -rl --include=Cargo.toml "<crate_name>" crates/ Cargo.toml`
— the legacy enclave is gone (every workspace crate is Reborn), so this check now exists to catch
crates with no consumers that may be queued for deletion instead. When unsure,
consult the `ironclaw-reborn-orientation` skill.
Comment on lines +49 to +54

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Make the consumer check exclude the candidate's own manifest.

The command searches for <crate_name> in every Cargo.toml. It also matches the candidate's own [package] name, so a crate with no consumers can pass the “real consumers” check.

Use dependency metadata and exclude the package itself.

Proposed validation
-- **it has real consumers.** Verify: `grep -rl --include=Cargo.toml "<crate_name>" crates/ Cargo.toml`
+- **it has real consumers.** Verify that another package lists `<crate_name>` as a dependency:
+  `cargo metadata --no-deps --format-version 1 | jq -e --arg crate "<crate_name>" '
+    [.packages[] | select(.name != $crate)
+      | select(any(.dependencies[]?; .name == $crate))] | length > 0'`
📝 Committable suggestion

‼️ IMPORTANT
Carefully review the code before committing. Ensure that it accurately replaces the highlighted code, contains no missing lines, and has no issues with indentation. Thoroughly test & benchmark the code to ensure it meets the requirements.

Suggested change
List the crates (`ls crates/*/` — the top level is the ten family directories, crates are one level
down, plus `crates/extensions/packages/*`). A crate is a **candidate** when ALL hold:
- **it has real consumers.** Verify: `grep -rl --include=Cargo.toml "<crate_name>" crates/ Cargo.toml`
— the legacy enclave is gone (every workspace crate is Reborn), so this check now exists to catch
crates with no consumers that may be queued for deletion instead. When unsure,
consult the `ironclaw-reborn-orientation` skill.
List the crates (`ls crates/*/` — the top level is the ten family directories, crates are one level
down, plus `crates/extensions/packages/*`). A crate is a **candidate** when ALL hold:
- **it has real consumers.** Verify that another package lists `<crate_name>` as a dependency:
`cargo metadata --no-deps --format-version 1 | jq -e --arg crate "<crate_name>" '
[.packages[] | select(.name != $crate)
| select(any(.dependencies[]?; .name == $crate))] | length > 0'`
— the legacy enclave is gone (every workspace crate is Reborn), so this check now exists to catch
crates with no consumers that may be queued for deletion instead. When unsure,
consult the `ironclaw-reborn-orientation` skill.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/commands/deslop-reborn.md around lines 49 - 54, Update the
consumer-check instructions near the crate candidate criteria to use Cargo
dependency metadata rather than grepping all manifests indiscriminately. Ensure
the validation excludes the candidate package’s own manifest and only counts
actual dependency references from other workspace crates.

- **not already in the ledger DESLOPPED list** (§0),
- **not the hot surface of an open PR** (§0) — leave those to the build/review loops,
- it has real source to review (skip thin aggregator/facade crates with ~no `src` — though their
Expand Down Expand Up @@ -267,8 +270,9 @@ cargo build --workspace --all-targets # sealing a pub can break OTHER cr
cargo clippy --all --benches --tests --examples --all-features
```
Sealing a public item can break **other** crates — the workspace build/clippy catches that; fix the
fallout or keep the item public with a note. If the crate has an **integration** path, run
`cargo test --features integration` when Postgres is reachable; if it has a **Reborn e2e** path
fallout or keep the item public with a note. If the crate has an **integration** feature, run
`cargo test -p <crate> --features integration` when Docker is reachable (the workspace-root
`integration` feature is empty — the flag only means something per-crate); if it has a **Reborn e2e** path
(turns, runtime lanes, host services, authorization, approvals, networking, secrets, product
workflow, capability dispatch), run `scripts/reborn-e2e-rust.sh`. Any tier you cannot run here (needs
Postgres/Docker/keys) → note it **"CI-deferred"** in the PR body. Everything runnable must be **green
Expand Down
10 changes: 3 additions & 7 deletions .claude/commands/trace.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
description: Trace a data flow or bug through the IronClaw codebase end-to-end
allowed-tools: Read, Glob, Grep, Bash(cargo test:*), Bash(bash scripts/codebase-graph.sh:*), mcp__codebase-memory__search_graph, mcp__codebase-memory__get_code_snippet, mcp__codebase-memory__trace_path, mcp__codebase-memory__get_architecture, mcp__codebase-memory__query_graph, mcp__codebase-memory__index_repository, mcp__codebase-memory__detect_changes
allowed-tools: Read, Glob, Grep, Bash(cargo test:*), Bash(bash scripts/codebase-graph.sh:*), mcp__codebase-memory-mcp__search_graph, mcp__codebase-memory-mcp__get_code_snippet, mcp__codebase-memory-mcp__trace_path, mcp__codebase-memory-mcp__get_architecture, mcp__codebase-memory-mcp__query_graph, mcp__codebase-memory-mcp__index_repository, mcp__codebase-memory-mcp__detect_changes
argument-hint: <symptom or feature name>
model: sonnet
---
Expand All @@ -19,19 +19,15 @@ Everything is **Reborn** (`crates/`) — the v1 `src/` monolith and its crates (
|---|---|---|
| Browser JS | `crates/product/ironclaw_webui/frontend/src` API client and page modules | `rg -n "apiFetch\(" crates/product/ironclaw_webui/frontend/src` |
| Route + policy | `crates/product/ironclaw_webui/src/webui_v2/descriptors.rs`, `router.rs`, `handlers.rs` | `grep -n "WEBUI_V2_PATTERN_\|_descriptor" crates/product/ironclaw_webui/src/webui_v2/descriptors.rs` |
| Product surface | `ProductSurface` in `ironclaw_host_api`, descriptors in `crates/product/ironclaw_assistant/src/reborn_services.rs` | `rg -n "ProductSurface|ProductView|ProductSurfaceCommandDescriptor" crates/contracts/ironclaw_host_api crates/product/ironclaw_assistant` |
| Product surface | `ProductSurface` in `ironclaw_product_contracts` (`crates/contracts/ironclaw_product_contracts/src/surface.rs`), descriptors in `crates/product/ironclaw_assistant/src/reborn_services.rs` | `rg -n "ProductSurface|ProductView|ProductSurfaceCommandDescriptor" crates/contracts/ironclaw_product_contracts crates/product/ironclaw_assistant` |
| Composition | `crates/app/ironclaw_composition/src` | `rg -n "build_.*service|impl .*Service" crates/app/ironclaw_composition/src` |
| Turn accept | `SessionThreadService::accept_inbound_message` (`crates/domains/ironclaw_threads`) → `TurnCoordinator::submit_turn` (`crates/kernel/ironclaw_turns/src/coordinator.rs`) | `grep -rn --include='*.rs' "submit_turn(" crates/` |
| Claim + execute | `TurnRunScheduler` → `RebornTurnRunExecutor` (`crates/loop/ironclaw_turn_runner/src/`) | `grep -n "claim_next_run\|invoke_driver" crates/loop/ironclaw_turn_runner/src/turn_scheduler.rs crates/loop/ironclaw_turn_runner/src/turn_run_executor.rs` |
| Loop | `PlannedDriver` (`crates/loop/ironclaw_turn_runner/src/planned_driver.rs`) → `CanonicalAgentLoopExecutor` (`crates/loop/ironclaw_agent_loop/src/executor.rs`) → host ports (`crates/loop/ironclaw_loop_host`) | `grep -rn "invoke_capability\|stream_model" crates/loop/ironclaw_agent_loop/src/executor` |
| Model call | `crates/loop/ironclaw_loop_host/src/model_gateway.rs` → `ironclaw_llm` provider chain | `grep -n "complete_model_request\|CompletionRequest" crates/loop/ironclaw_loop_host/src/model_gateway.rs` |
| Effects | `CapabilityHost::invoke_json` (`crates/kernel/ironclaw_capabilities/src/host.rs`) → dispatcher → wasm/scripts/mcp/first-party lanes | `grep -n "invoke_json" crates/kernel/ironclaw_capabilities/src/host.rs` |
| Effects | `CapabilityHost::invoke_json` (`crates/kernel/ironclaw_capabilities/src/host/`) → dispatcher → wasm / script-sandbox / mcp / first-party lanes | `grep -n "invoke_json" crates/kernel/ironclaw_capabilities/src/host/invoke.rs` |
| Reply to browser | SSE projection drain: `stream_events` (`crates/product/ironclaw_webui/src/webui_v2/handlers.rs`) over `ProjectionStream` | `grep -n "stream_events" crates/product/ironclaw_webui/src/webui_v2/handlers.rs` |

## v1 anchors (legacy maintenance only)

*(This section used to carry a v1 flow map through `src/agent/`, `src/channels/web/`, `src/tools/`, `src/bridge/` and `crates/ironclaw_gateway`. Every one of those paths has been deleted with the monolith; the Reborn anchors above are the only map.)*

## Tracing instructions

1. **Read** each file on the relevant path, focusing on the functions that handle the data.
Expand Down
6 changes: 3 additions & 3 deletions .claude/rules/skills.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
paths:
- "crates/domains/ironclaw_skills/**"
- "crates/app/ironclaw_composition/src/extension_host/bundled_skills.rs"
- "crates/extensions/ironclaw_extension_host/src/bundled_skills.rs"
- "skills/**"
---
# Skills System
Expand Down Expand Up @@ -64,8 +64,8 @@ When parser behavior changes, update this file in the same PR
## Selection Pipeline

1. **Gating** -- Check binary/env/config requirements; skip skills whose prerequisites are missing
2. **Scoring** -- Deterministic scoring: keywords (10/5 pts, cap 30) + patterns (20 pts, cap 40) + tags (3 pts, cap 15). `exclude_keywords` veto (score = 0 if any present). Pattern (regex) scoring is gated on `SKILLS_REGEX_ACTIVATION_ENABLED` (default `true`); when `false`, regex activation contributes 0 and only keywords/tags/explicit mentions can select a skill.
3. **Budget** -- Select top-scoring skills within `SKILLS_MAX_TOKENS` prompt budget
2. **Scoring** -- Deterministic scoring: keywords (10/5 pts, cap 30) + patterns (20 pts, cap 40) + tags (3 pts, cap 15). `exclude_keywords` veto (score = 0 if any present). Pattern (regex) scoring is gated on the config-file setting `[skills] regex_activation_enabled` (default `true`; `SkillsSection` in `crates/app/ironclaw_config/src/config_file.rs` — there is no env var for it); when `false`, regex activation contributes 0 and only keywords/tags/explicit mentions can select a skill.
3. **Budget** -- Select top-scoring skills within the prompt token budget (`DEFAULT_MAX_SKILL_CONTEXT_TOKENS = 4000` in `crates/loop/ironclaw_loop_host/src/skill_activation/activation.rs`, overridable via `set_max_context_tokens`; the former `SKILLS_MAX_TOKENS` env var is not read by anything)
4. **Attenuation** -- Minimum trust across active skills determines tool ceiling; installed skills lose dangerous tools

## Skill Tools
Expand Down
8 changes: 6 additions & 2 deletions .claude/rules/testing.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,8 +31,12 @@ Read `.claude/skills/ironclaw-reborn-testing/SKILL.md` and
3. **Architecture:** dependency and composition boundaries —
`cargo test -p ironclaw_architecture_tests`.
4. **Backend/runtime integration:** DB-, Docker-, or runtime-shaped behavior —
use the owning feature-gated suite and `cargo test --features integration`
when required by its guide.
use the owning crate's feature-gated suite
(`cargo test -p <owning-crate> --features integration`, e.g.
`-p ironclaw_hooks` for the Postgres/libSQL hooks parity matrix) when its
guide requires it. The workspace-root `integration` feature is empty with no
consumers, so a bare root `cargo test --features integration` adds nothing
over `cargo test`.
Comment on lines +34 to +39

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

rg -n -C 2 -- '--features integration|test-support' \
  .claude/rules/testing.md \
  .claude/skills/ironclaw-reborn-testing/SKILL.md

rg -n -C 2 '^\[features\]|integration|test-support' \
  crates/loop/ironclaw_hooks/Cargo.toml \
  Cargo.toml \
  .github/workflows/platform-and-compat.yml

Repository: nearai/ironclaw

Length of output: 27853


🏁 Script executed:

#!/usr/bin/env bash
set -euo pipefail

# Inspect the exact feature/test manifest for ironclaw_hooks and the two documented guidance ranges.
sed -n '1,130p' crates/loop/ironclaw_hooks/Cargo.toml
printf '\n--- .claude docs snippets ---\n'
sed -n '28,42p' .claude/rules/testing.md
sed -n '22,32p' .claude/skills/ironclaw-reborn-testing/SKILL.md

# Deterministic Cargo manifest invariant check: read package manifest text and check which features
# each [[test]] target requires without installing/making/cleaning dependencies.
python3 - <<'PY'
from pathlib import Path
p = Path("crates/loop/ironclaw_hooks/Cargo.toml")
text = p.read_text()
lines = text.splitlines()
in_test = False
test = {}
for i, line in enumerate(lines, start=1):
    stripped = line.strip()
    if stripped == "[[[[test]]]]:.format(7): # not valid, adjust
    pass
PY

Repository: nearai/ironclaw

Length of output: 7768


Align the backend-integration commands with ironclaw_hooks test requirements.

.claude/rules/testing.md and .claude/skills/ironclaw-reborn-testing/SKILL.md#L30 give cargo test -p <crate> --features integration, while the full Postgres coverage workflow uses --features integration,test-support. ironclaw_hooks has contract tests gated on test-support (predicate_state_postgres_contract and predicate_state_libsql_contract) and a separate multi_host_adversarial test gated on integration; decide whether backend integration runs the full crate feature set or explicitly includes test-support in the canonical command.

📍 Affects 2 files
  • .claude/rules/testing.md#L34-L39 (this comment)
  • .claude/skills/ironclaw-reborn-testing/SKILL.md#L23-L23
  • .claude/skills/ironclaw-reborn-testing/SKILL.md#L30-L30
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/rules/testing.md around lines 34 - 39, Update the
backend-integration guidance consistently in .claude/rules/testing.md:34-39 and
.claude/skills/ironclaw-reborn-testing/SKILL.md:23 and :30 to use the canonical
ironclaw_hooks feature set including both integration and test-support, so the
contract tests and multi_host_adversarial coverage run together.

5. **Recorded model behavior:** hermetic fixtures for tool choice/request shape;
validate with `scripts/ci/check-reborn-qa-fixtures.sh`.
6. **Browser/E2E:** user-visible WebUI flows under `tests/e2e/`.
Expand Down
Loading
Loading