Gate & ratchet audit: full-inventory report, five fail-opens armed, dead gates deleted - #7373
Conversation
…bstrate list
Gate-audit finding (open-and-shut): SUBSTRATE_CRATES in
reborn_composition_boundaries.rs carried three rows of rot, all invisible
because the loop's `let Some(..) else { continue }` silently skipped any
entry that resolves to no workspace package:
- "ironclaw_storage": no such package exists (verified against
`cargo metadata --no-deps`; the only MISSING name of the 29 listed).
- "ironclaw_approvals" and "ironclaw_assistant" were each listed twice.
The silent skip is replaced with a panic naming the stale entry, so the
list can no longer rot invisibly. Verified by sabotage: adding a bogus
"ironclaw_zzz_probe" row now fails the test with
"is listed in SUBSTRATE_CRATES but is not a workspace package"; the
clean list passes (23/23).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ty gate Gate-audit finding (open-and-shut): SANCTIONED_PATHS in reborn_extension_specificity.rs still exempted `extension_host/extension_installation_store.rs` — a file deleted by #6430. No scanned path matches the fragment (verified with rg across crates/), so the entry exempted nothing; it is also the one exclusion surface in this gate with no staleness check, which is how it outlived its file. Full specificity suite green after removal (8/8). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…om the telegram gates Gate-audit finding (open-and-shut): both cross-tree scans in telegram_extension_gates.rs still carved out `ironclaw_gateway/static` — the v1 monolith's embedded UI, whose crate was deleted with the src/ monolith (no crates/*/ironclaw_gateway directory exists). The exclusions matched nothing; scans now cover the whole tree with no dead carve-outs. Suite green after removal (12/12). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…gate that exists Gate-audit finding (open-and-shut doc rot): the module doc still described the pre-#6447 freeze design — a dangling doc-link to FROZEN_COLLAPSE_DTOS (renamed RETIRED_COLLAPSE_DTOS in #6447), a promised delete-without-trimming failure and an empty-allowlist assertion that do not exist in the file, and a named owner for a collapse that completed. The mechanism itself is armed and untouched; the header now describes the permanent zero-gate it became, and records the two originally-frozen names that deliberately left governance (CapabilityOutcome via #6299 deletion, CapabilityDispatchRequest blessed as the canonical port type). Suite green (2/2). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…e colocated asset Gate-audit finding (open-and-shut doc rot): the BundledAsset allowlist entry's justification still cited include_str! of assets/memory_native/manifest.toml — a path retired when WS2 (#7037) colocated packages; the live include in memory_native_extension.rs reaches crates/extensions/packages/memory-native/manifest.toml. Comment only; the gate's mechanism and counts are untouched. Suite green (2/2). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…floor its twin has Gate-audit finding: reborn_memory_retired_vocabulary.rs had no MIN_SCANNED_FILES floor, unlike its explicit twin reborn_retired_taxonomy.rs — so a partially-moved tree (the CHECKLIST WS0 / #6963 'green while measuring nothing' shape) would scan a fraction of the files and still report the vocabulary clean. The gate was in fact born with an already-dead sanctioned path (its own header records this), so the rot class is not hypothetical for this file. Adds the same 500-file floor (real count ~4000), asserts it in the main gate, and pins the premise on a fixture: a 10-file partial tree scans clean and is rejected by the floor. Suite green (4/4); clippy clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…open
Gate-audit finding (sabotage-verified): product_symbols_in's braced-group
branch closed at the FIRST '}' (group.find('}')), so a nested group —
use ironclaw_assistant::{m::{X}}; — truncated mid-element and recorded
zero symbols. Probed live before the fix: appending
use ironclaw_assistant::{zzz_audit::{ZzzProbe}}; to webui's lib.rs left
transports_name_only_the_frozen_residue_of_product_symbols GREEN, while
the plain-path spelling of the same import correctly failed. The same
truncation dropped qualified elements inside flat groups
({qualified_module::X} recorded nothing).
The group branch now does a balanced-brace walk, splits elements at
depth-0 commas only, and records a qualified/nested element's leading
path segment — the same key the single-path branch records for
ironclaw_assistant::module::X. Flat-element semantics are byte-for-byte
unchanged, so the frozen 100-row webui inventory is untouched (suite
green 6/6 on the live tree). Regression fixtures added to
import_scanner_reads_symbols_out_of_real_use_shapes; the original
sabotage now fails with the gate's own message (re-verified).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…longer exists Gate-audit finding (provably inert): the script's default target is .github/workflows/e2e.yml, deleted when the v1 e2e suites were retired (git log --diff-filter=D shows the removing commit); no workflow, script, hook, doc, or guidance file references check-e2e-matrix-files.sh (verified with rg across the repo including .github and .githooks). A checker nothing runs, pointed at a file nothing provides, is dead weight that reads as coverage. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…eferences Gate-audit finding (provably inert, previously measured): crates/AGENTS.md recorded on 2026-08-05 that the script fails on a clean tree (check 5 false-positives on live test files) and that checks 1/2/3/6 target the deleted v1 src/ tree, passing vacuously. No workflow or hook runs it; its only callers were guidance files, two of which claimed it 'enforces' root-tests feature gating — an enforcement claim the skill-maintainer rules forbid for a check nothing executes. Removed the script and every live reference: the crates/AGENTS.md warning row becomes a tombstone note; the testing skill + exemplar reference drop the false enforcement parenthetical; the architecture-review skill's Verify line drops the dead command; deslop-reborn's allowed-tools drops the permission; .coderabbit.yaml's driver-leak instruction now points at the live enforcement (reborn_persistence_driver_boundary). Two dated docs/internal/ plan snapshots keep their historical mentions. Verified: python3 scripts/ci/check-guidance.py OK (2084 path references) and its self-test OK. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… map Gate-audit finding (stale prose): crates/product/AGENTS.md said '19-sub-owner reborn_services charter map' — the enforced map has had 20 sub-owners since #7235 added the inspector row (counted from the live table). Rather than chase the number, drop both inline counts: the owning maps and their gates are authoritative, and the re-verify commands are already inline (skill-maintainer rule: no counts without a regeneration recipe). check-guidance.py OK. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Gate-audit finding (doc rot with a false coverage claim): the header said naming the FILE reborn_* makes code_style.yml's 'cargo test -p ironclaw_architecture_tests reborn' see it — but that argument is a test-NAME filter (the measurement is documented in reborn_contracts_vendor_census.rs), and none of this file's test fns contains the substring, so that smoke lane runs 0 of them (11 collected by the full plan). Comment-only; the note now records the real semantics so file names are not trusted for lane coverage. Suite green (11/11). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tlet The audit the owner asked for after PR #7157 went red six times across four gates: every architecture-test gate, module charter, CI script, and committed baseline inventoried with a verdict and evidence; the handful worth acting on ranked by friction x weakness; the CI-ergonomics analysis (why failures surface one per ~1h round-trip: no --no-fail-fast anywhere in CI, cancel-in-progress on push, sequential fast-checks steps — measured: two broken gates report 1 failure in 18s under the CI shape vs both in 211s with --no-fail-fast); and the sabotage log for every probe. scripts/preflight-gates.sh is the concrete pre-push proposal: the deterministic-gate classes only (script gates ~10s + architecture suite --no-fail-fast + changed-crate charter tests), covering all four #7157 gate classes locally in one command. Unwired — nothing invokes it. Validated end-to-end on this branch: exit 0, 'every deterministic gate green', 402.8s including gate-binary recompiles. Placement verified: python3 scripts/ci/docs_publication_boundary.py OK. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ries.sh The gate audit's own PR hit the planner's fail-closed arm — 'unmapped test or CI path: scripts/check-boundaries.sh' — exactly the class the arm exists to force a decision on (and the audit's report documents). Per the PR_STATIC_CONTROL_PATHS membership rule (no Reborn test lane exercises either file): - scripts/preflight-gates.sh — the audit's proposed local pre-push gauntlet; referenced by no workflow. - scripts/check-boundaries.sh — deleted by the audit; the entry lets the deletion diff (and any revert) classify instead of failing every downstream Reborn lane. Verified: the planner now produces mode=selected with the architecture-misc bucket for this branch's diff, and python3 scripts/ci/test_reborn_pr_test_plan.py is OK. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
🚅 Deployed to the ironclaw-pr-7373 environment in ironclaw-ci-preview
|
📝 WalkthroughSummary by CodeRabbit
WalkthroughThe PR removes the legacy boundary scripts, hardens architecture tests, adds consolidated preflight execution, and updates gate baselines and the 2026 enforcement audit. ChangesReborn gate enforcement
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant Developer
participant preflight_gates
participant GateCommands
participant ArchitectureTests
participant CharterTests
Developer->>preflight_gates: Run pre-push preflight
preflight_gates->>GateCommands: Run deterministic gates
preflight_gates->>ArchitectureTests: Run architecture suite
preflight_gates->>CharterTests: Run tests for changed crates
GateCommands-->>preflight_gates: Return status
ArchitectureTests-->>preflight_gates: Return status
CharterTests-->>preflight_gates: Return status
preflight_gates-->>Developer: Report failures and exit
🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
🧭 IronLoop Run · ReviewThis comment updates in place as the Run moves through its stages. ⬛ Final result · Stopped
Automatic trigger · attempt 1 of 3 · stopped after 8m 33s IronLoop stopped because the pull request target branch or head changed while this Run was active. |
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.claude/skills/ironclaw-reborn-testing/references/exemplar-tests.md:
- Line 41: Remove the stale scripts/check-boundaries.sh reference from the
guidance at the “GOOD” exemplar, replacing it with the current checker path if
one exists or describing only the feature-gate rule without claiming
enforcement. Also search the guidance layer for any remaining references to the
deleted checker and update them.
In
`@crates/app/ironclaw_architecture_tests/tests/reborn_memory_retired_vocabulary.rs`:
- Around line 57-65: Raise MIN_SCANNED_FILES in the retired-vocabulary scan gate
to a ratcheted lower bound close to the audited normal scan count, rather than
500, so substantially incomplete trees fail loudly. Add a committed boundary
fixture near the new threshold and a regression test proving the scan rejects
it, while preserving acceptance of a normal full-tree scan.
In
`@crates/app/ironclaw_architecture_tests/tests/reborn_transport_product_boundary.rs`:
- Around line 417-435: The unqualified import branch in the element scanner must
retain valid leading identifiers when aliases are split across newlines. Update
the branch after the `rest.starts_with("::")` check to validate and insert
`leading` rather than relying on `split(" as ")` over the full element, and add
a regression fixture covering a newline-separated alias such as `Grouped
as\nAlias`.
In `@scripts/preflight-gates.sh`:
- Around line 27-30: Update scripts/preflight-gates.sh to use set -euo pipefail
for repository setup, and make changed-file discovery fail closed: explicitly
handle failures from git merge-base and git diff with if ! branches, reporting
the failure instead of leaving changed empty. Preserve failure aggregation
within run_gate and ensure setup or discovery errors cannot produce an OK
result.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: e3ceca70-3cdc-4a43-a43b-c67f9adc56da
📒 Files selected for processing (21)
.claude/commands/deslop-reborn.md.claude/skills/ironclaw-reborn-architecture-review/SKILL.md.claude/skills/ironclaw-reborn-skill-maintainer/SKILL.md.claude/skills/ironclaw-reborn-testing/SKILL.md.claude/skills/ironclaw-reborn-testing/references/exemplar-tests.md.coderabbit.yamlcrates/AGENTS.mdcrates/app/ironclaw_architecture_tests/tests/reborn_capability_dto_collapse_ratchet.rscrates/app/ironclaw_architecture_tests/tests/reborn_composition_boundaries.rscrates/app/ironclaw_architecture_tests/tests/reborn_extension_specificity.rscrates/app/ironclaw_architecture_tests/tests/reborn_manifest_reparse_gate.rscrates/app/ironclaw_architecture_tests/tests/reborn_memory_retired_vocabulary.rscrates/app/ironclaw_architecture_tests/tests/reborn_ratchet_support_scanners.rscrates/app/ironclaw_architecture_tests/tests/reborn_transport_product_boundary.rscrates/app/ironclaw_architecture_tests/tests/telegram_extension_gates.rscrates/product/AGENTS.mddocs/internal/gate-audit-2026-08.mdscripts/check-boundaries.shscripts/ci/check-e2e-matrix-files.shscripts/ci/reborn_pr_test_plan.pyscripts/preflight-gates.sh
💤 Files with no reviewable changes (2)
- scripts/ci/check-e2e-matrix-files.sh
- scripts/check-boundaries.sh
| set -uo pipefail | ||
|
|
||
| REPO_ROOT="$(git rev-parse --show-toplevel)" | ||
| cd "${REPO_ROOT}" |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Fail closed when repository or diff discovery fails.
set -uo pipefail allows setup failures to continue. If base_ref resolves but git merge-base or git diff fails, the assignment at Line 69 leaves changed empty. Every charter call then skips, while the script can still report OK.
Keep failure aggregation in run_gate, but handle repository setup and changed-file discovery as explicit failures. Use set -euo pipefail for setup and explicit if ! branches for merge-base and git diff.
As per path instructions, CI and dev tooling must use set -euo pipefail.
Also applies to: 68-75
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@scripts/preflight-gates.sh` around lines 27 - 30, Update
scripts/preflight-gates.sh to use set -euo pipefail for repository setup, and
make changed-file discovery fail closed: explicitly handle failures from git
merge-base and git diff with if ! branches, reporting the failure instead of
leaving changed empty. Preserve failure aggregation within run_gate and ensure
setup or discovery errors cannot produce an OK result.
Source: Path instructions
…the audit The strongest single exhibit for shortlist item 2, contributed by the #7157 branch steward after this audit's cutoff and verified against the gate's code: TOLERANCE = 400 is consulted in exactly one direction (the banked-slack check, ceiling.saturating_sub(lines) > TOLERANCE); the growth check is a bare lines > ceiling. With the in-file 'set to current, not padded' instruction, every ceiling is a hard cap at the observed count — so one line landing on main in any contracts crate reds every open branch at its next fold until someone re-captures. Measured recurrence on #7157: loop_contracts re-captured four times, ~once per fold (14,479 -> 13,850 -> 13,949 -> 13,115 -> 13,181), the last tripped by main's #7361/#7363 adding 66 lines to instruction_bundle.rs — nothing the branch wrote. All four deltas were <= 105 lines: either repair shape in §3.2 (one-line upward tolerance using the existing constant, or mid-window pinning) would have absorbed every one with zero red builds. This audit's own sabotage already proved the jaws (+1 line host_api red / -1 line common red); the fold history shows the operational cost. The repair stays a recommendation — adding growth headroom to a ratchet is the owner's call, not this PR's. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/internal/gate-audit-2026-08.md`:
- Around line 234-250: Correct the inconsistent recapture count in the audit
narrative: the sequence shows four transitions after the initial 14,479 seed,
matching the earlier “four times” statement. Change the later “all five `#7157`
recaptures” wording to “all four” unless adding and defining a separate missing
event.
- Around line 240-242: Correct the suggested Rust expression in the discussion
of the one-line fix so the referenced SIZE_CEILINGS value is dereferenced before
adding TOLERANCE: use an equivalent type-correct checked offset while preserving
the intended comparison against the ceiling.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 8a57578e-b94e-4b3b-8bdc-434fbc9b9f59
📒 Files selected for processing (1)
docs/internal/gate-audit-2026-08.md
Owner-directed repair of the audit's sharpest finding (report §3.2): the gate's TOLERANCE = 400 was consulted in exactly one direction — the banked-slack check — while the growth check was a bare lines > ceiling. Combined with 'set to current, not padded' pins, every ceiling was a hard cap at the exact observed count, so one line landing on main in any contracts crate redded every open branch at its next fold until someone re-captured. Measured on #7157: four loop_contracts re-captures, roughly once per fold, every delta <= 105 lines — the gate generating its own busywork. The growth check now allows GROWTH_TOLERANCE = 150 of working slack above each pin (sized to composition-budget precedent; the reviewed raises this gate has caught were +1,069 and +1,214 lines, far above it), and all six ceilings are re-pinned to the counts the test itself reported with every ceiling at 0 — which also removes the +400 seed padding on common/loop_contracts/prompt_envelope that contradicted the capture rule and put those crates one deleted line from the banked jaw. Sabotage-verified both ways: +1 line in host_api and -1 line in common — both red before this change — now pass; a +151-line probe still fails with the effective-ceiling arithmetic in the message. Full reborn_dependency_boundaries binary green (41/41); clippy clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…rking window Owner-directed companion to the contracts-ceiling repair (same annoying class, other mass gate): merged main-side growth since the 2026-08-05 equalization had drifted +101 LOC and +5 Arc<dyn> sites through the tolerance windows, leaving 49 LOC / 10 sites of live headroom — the next routine composition PR would have gone red on wiring alone (the gate audit measured this the same day it was pinned). Per the TOML's own maintenance instructions: loc_ceiling/loc_observed 40423 -> 40524 and arc_dyn 814 -> 819, measured with the gate's --print, set to current not padded, dated notes appended (not overwritten), and the arch-test record (COMPOSITION_ABSOLUTE_SRC_LOC) moved in the same commit as its file requires. ceiling_bp stays 658 — the WS0 floor is deliberately not re-set. Verified: check-composition-budget.sh OK; its 76-case self-test green; reborn_restructure_baselines green; probe +100 LOC now passes (was red at 49 headroom), probe +160 LOC still fails. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The §3.2 repair moved from recommendation to landed at owner direction; the report's answer, inventory rows, and §7 ledger now say so, with the counting-rule fix promoted to the top remaining recommendation. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ged tree Folds 53 commits of main (through 202b972) into the gate-audit branch. The three conflicts were the ratchet bookkeeping sites; each resolved by keeping both sides' append-only history chains and re-measuring on the merged tree per the file's own capture rule: - composition-budget.toml: loc_ceiling/loc_observed 41810 -> 41820 (gate's own --print; main's pin had drifted to 140 lines of effective headroom) and arc_dyn 816 -> 831 re-equalized — main was live at exactly ZERO dispatch headroom (observed 831 == effective ceiling 831), the audit's Sec 3.2 recurrence class in the wild. - reborn_dependency_boundaries.rs SIZE_CEILINGS: ceilings-at-0 procedure on the merged tree; five surviving pins equal the tree's own report exactly; prompt_envelope re-pins 832 -> 432 (the last row still carrying the +400 seed pad the 2026-08-07 re-pin removed from its siblings). - reborn_restructure_baselines.rs: COMPOSITION_ABSOLUTE_SRC_LOC 41731 -> 41820, moving with the manifest as the tamper alarm requires. Probe-verified on the merged tree: +1 line to host_api passes (red before this branch's GROWTH_TOLERANCE repair), +151 fails with the effective-ceiling arithmetic in the message. Verified green: full architecture suite (40 binaries, --no-fail-fast), composition-budget gate and its 76-case self-test, check-guidance (2090 refs), planner self-test, check-target-tree, clippy -p ironclaw_architecture_tests, and scripts/preflight-gates.sh end-to-end. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Note GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer. |
…osed Two review-round hardenings (the open CodeRabbit Majors): - reborn_dependency_boundaries.rs: extract the size-ceiling comparison into contracts_ceiling_verdict() and pin its four window edges with a committed regression test (contracts_size_ceiling_window_edges_hold) — accept at ceiling+GROWTH_TOLERANCE, reject one line past, accept at ceiling-TOLERANCE, reject one banked line further, and a zero-measure scan reads Banked, never a silent pass. The pre-repair asymmetry (tolerance consulted only downward) can no longer return silently. Live-gate behavior re-probed unchanged after the rewiring: +1 line to host_api passes, +151 fails with the same effective-ceiling message. - preflight-gates.sh: setup and changed-file discovery now fail closed — a missing repo root exits 2, and a failed merge-base/diff widens the charter run to all five crates instead of silently skipping them (the same fallback the missing-base branch already used). A broken setup may cost compile time, never a silent skip. Full boundary binary 42/42 green; clippy clean; preflight-gates.sh end-to-end green on this tree. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Actionable comments posted: 2
♻️ Duplicate comments (4)
.claude/skills/ironclaw-reborn-testing/references/exemplar-tests.md (1)
41-41: 🎯 Functional Correctness | 🟠 MajorRemove the deleted checker reference.
Line 41 still claims enforcement by
scripts/check-boundaries.sh, but this PR deletes that script. The exemplar is not runnable and contradicts the audit's claim that all live references were removed. Replace the script with the current architecture-suite command, or describe only the feature-gate behavior.As per coding guidelines, after moves or renames, update references in agent guidance, contracts, documentation, tests, scripts, manifests, and frontend imports.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.claude/skills/ironclaw-reborn-testing/references/exemplar-tests.md at line 41, Update the exemplar guidance around the “GOOD” feature-gated test example to remove the deleted scripts/check-boundaries.sh reference. Replace it with the current architecture-suite command if applicable, or describe only the feature-gate behavior, ensuring no stale checker references remain.Source: Coding guidelines
docs/internal/gate-audit-2026-08.md (1)
187-187: 📐 Maintainability & Code Quality | 🟡 MinorLabel the 49/10 headroom as pre-change.
The audit reports 49 LOC and 10
Arc<dyn>sites of current headroom. The currentscripts/ci/composition-budget.tomlre-equalizes both metrics to the observed values, with 150 LOC and 15-site tolerances. Mark 49/10 as pre-change values, or replace them with the current 150/15 windows.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@docs/internal/gate-audit-2026-08.md` at line 187, Update the audit entry for check-composition-budget.sh and composition-budget.toml to distinguish the 49 LOC and 10-site headroom as pre-change values, or replace those figures with the current 150 LOC and 15-site tolerance windows. Keep the description consistent with the TOML configuration and its probe results.scripts/ci/composition-budget.toml (1)
69-70: 📐 Maintainability & Code Quality | 🟡 MinorUpdate the stale share observation comment.
Line 69 sets
observed_bp = 572, but the preceding comment still says “observed today is 578 bp.” Align the rationale with the configured observation so the audit trail is consistent.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/ci/composition-budget.toml` around lines 69 - 70, Update the preceding observation comment in the composition budget configuration to state 572 bp instead of 578 bp, matching the observed_bp value while preserving the existing rationale and formatting.scripts/preflight-gates.sh (1)
27-30: 🎯 Functional Correctness | 🟠 MajorFail closed when setup or changed-file discovery fails.
set -uo pipefailallowsgit rev-parse,git merge-base, andgit difffailures to continue. An emptychangedvalue then skips all charter tests, while Line 96 can still reportOK. Useset -euo pipefailfor repository setup. Handlemerge-baseandgit diffwith explicitif !branches that append a failure before continuing the other gates.As per path instructions, CI and dev tooling must use
set -euo pipefailand quoted expansions.Proposed fail-closed shape
-set -uo pipefail +set -euo pipefail ... if git rev-parse --verify --quiet "${base_ref}^{commit}" >/dev/null; then - changed="$(git diff --name-only "$(git merge-base HEAD "${base_ref}")"...HEAD)" + if ! merge_base="$(git merge-base HEAD "${base_ref}")"; then + failures+=("charter tests: merge-base discovery") + changed="" + elif ! changed="$(git diff --name-only "${merge_base}"...HEAD --)"; then + failures+=("charter tests: changed-file discovery") + changed="" + fiAlso applies to: 68-75
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/preflight-gates.sh` around lines 27 - 30, Update scripts/preflight-gates.sh to use set -euo pipefail so repository setup failures from git rev-parse or cd terminate safely, while wrapping changed-file discovery around git merge-base and git diff in explicit if ! branches. On either discovery failure, append a gate failure and continue running the remaining gates; ensure an empty changed set cannot produce a final OK result, and preserve quoted expansions throughout.Source: Path instructions
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In @.claude/skills/ironclaw-reborn-architecture-review/SKILL.md:
- Line 31: Update the route-change testing guidance in the architecture review
skill to require the enforcement-side webui_v2_handlers_contract and composed
webui_v2_serve tests in addition to webui_v2_descriptors_contract.
Alternatively, narrow the existing condition explicitly to declaration-only
changes; ensure helper-gated side effects are tested through their caller.
- Line 31: Add the default-feature Clippy command alongside the existing
all-features command in the validation command list, using `cargo clippy -p
<crate> --all-targets -- -D warnings`; retain the current architecture-test and
conditional WebUI contract-test commands.
---
Duplicate comments:
In @.claude/skills/ironclaw-reborn-testing/references/exemplar-tests.md:
- Line 41: Update the exemplar guidance around the “GOOD” feature-gated test
example to remove the deleted scripts/check-boundaries.sh reference. Replace it
with the current architecture-suite command if applicable, or describe only the
feature-gate behavior, ensuring no stale checker references remain.
In `@docs/internal/gate-audit-2026-08.md`:
- Line 187: Update the audit entry for check-composition-budget.sh and
composition-budget.toml to distinguish the 49 LOC and 10-site headroom as
pre-change values, or replace those figures with the current 150 LOC and 15-site
tolerance windows. Keep the description consistent with the TOML configuration
and its probe results.
In `@scripts/ci/composition-budget.toml`:
- Around line 69-70: Update the preceding observation comment in the composition
budget configuration to state 572 bp instead of 578 bp, matching the observed_bp
value while preserving the existing rationale and formatting.
In `@scripts/preflight-gates.sh`:
- Around line 27-30: Update scripts/preflight-gates.sh to use set -euo pipefail
so repository setup failures from git rev-parse or cd terminate safely, while
wrapping changed-file discovery around git merge-base and git diff in explicit
if ! branches. On either discovery failure, append a gate failure and continue
running the remaining gates; ensure an empty changed set cannot produce a final
OK result, and preserve quoted expansions throughout.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 26a01fd5-4886-4e34-9812-395daceaf3ed
📒 Files selected for processing (24)
.claude/commands/deslop-reborn.md.claude/skills/ironclaw-reborn-architecture-review/SKILL.md.claude/skills/ironclaw-reborn-skill-maintainer/SKILL.md.claude/skills/ironclaw-reborn-testing/SKILL.md.claude/skills/ironclaw-reborn-testing/references/exemplar-tests.md.coderabbit.yamlcrates/AGENTS.mdcrates/app/ironclaw_architecture_tests/tests/reborn_capability_dto_collapse_ratchet.rscrates/app/ironclaw_architecture_tests/tests/reborn_composition_boundaries.rscrates/app/ironclaw_architecture_tests/tests/reborn_dependency_boundaries.rscrates/app/ironclaw_architecture_tests/tests/reborn_extension_specificity.rscrates/app/ironclaw_architecture_tests/tests/reborn_manifest_reparse_gate.rscrates/app/ironclaw_architecture_tests/tests/reborn_memory_retired_vocabulary.rscrates/app/ironclaw_architecture_tests/tests/reborn_ratchet_support_scanners.rscrates/app/ironclaw_architecture_tests/tests/reborn_restructure_baselines.rscrates/app/ironclaw_architecture_tests/tests/reborn_transport_product_boundary.rscrates/app/ironclaw_architecture_tests/tests/telegram_extension_gates.rscrates/product/AGENTS.mddocs/internal/gate-audit-2026-08.mdscripts/check-boundaries.shscripts/ci/check-e2e-matrix-files.shscripts/ci/composition-budget.tomlscripts/ci/reborn_pr_test_plan.pyscripts/preflight-gates.sh
💤 Files with no reviewable changes (2)
- scripts/ci/check-e2e-matrix-files.sh
- scripts/check-boundaries.sh
| ## Verify | ||
|
|
||
| `cargo test -p ironclaw_architecture_tests` · `bash scripts/check-boundaries.sh` (legacy inventory; may be noisy on HEAD, don't treat as the Reborn architecture gate) · `cargo clippy -p <crate> --all-targets --all-features -- -D warnings` · if routes changed: `cargo test -p ironclaw_webui --test webui_v2_descriptors_contract`. | ||
| `cargo test -p ironclaw_architecture_tests` · `cargo clippy -p <crate> --all-targets --all-features -- -D warnings` · if routes changed: `cargo test -p ironclaw_webui --test webui_v2_descriptors_contract`. |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
Run the enforcement-side route tests.
webui_v2_descriptors_contract checks the declared policy table only. Add webui_v2_handlers_contract and the composed webui_v2_serve test, or narrow this condition to declaration-only changes. The exemplar identifies those tests as the enforcement-side coverage.
As per path instructions, test through the caller when a helper gates a side effect.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.claude/skills/ironclaw-reborn-architecture-review/SKILL.md at line 31,
Update the route-change testing guidance in the architecture review skill to
require the enforcement-side webui_v2_handlers_contract and composed
webui_v2_serve tests in addition to webui_v2_descriptors_contract.
Alternatively, narrow the existing condition explicitly to declaration-only
changes; ensure helper-gated side effects are tested through their caller.
Source: Path instructions
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -eu
printf '%s\n' '--- skill excerpt ---'
sed -n '1,90p' .claude/skills/ironclaw-reborn-architecture-review/SKILL.md
printf '%s\n' '--- relevant guidance files ---'
find . -name AGENTS.md -o -name CLAUDE.md -o -path '*/.claude/rules/*' | sort
printf '%s\n' '--- feature/clippy guidance ---'
rg -n -C 3 'clippy|all-features|default.?feature|cfg\\(feature|feature-gated|route|webui_v2_descriptors_contract' AGENTS.md CLAUDE.md .claude crates tests 2>/dev/null | head -240Repository: nearai/ironclaw
Length of output: 2099
🌐 Web query:
nearai ironclaw ".claude/skills/ironclaw-reborn-architecture-review/SKILL.md" clippy
💡 Result:
The command nearai ironclaw .claude/skills/ironclaw-reborn-architecture-review/SKILL.md clippy is a reference to a specific development workflow within the IronClaw project [1][2], an open-source, Rust-based Agent OS maintained by NEAR AI [1][3]. In this context, the command likely instructs an AI assistant or development tool to read and apply the architecture review guidelines contained in the .claude/skills/ironclaw-reborn-architecture-review/SKILL.md file while running clippy (the Rust linter) on the codebase [4][5][6]. Key details regarding these components: * IronClaw: A rearchitected (v1.0+) agent runtime that separates decision-making from action execution [7][8]. Development now prioritizes code in the crates/ directory (the "Reborn" architecture) over the legacy src/ monolith [2][5]. * SKILL.md: Repository-specific agent skills are stored in .claude/skills/*/SKILL.md [5]. The ironclaw-reborn-architecture-review skill specifically provides guidance on maintaining architectural boundaries, abstractions, and re-exports when modifying or adding code to the crates/ directory [9][10][5]. * Clippy: The project uses cargo clippy as its standard linting tool [11][6]. The repository includes a clippy.toml file that defines custom complexity guardrails (e.g., cognitive-complexity-threshold, too-many-arguments-threshold) to ensure code quality in the new architecture [12]. The combined instruction suggests a task to verify code changes against both the project's high-level architectural standards (defined in the SKILL.md file) and its specific static analysis constraints (defined in clippy.toml) [9][12].
Citations:
- 1: https://github.com/nearai/ironclaw
- 2: https://github.com/nearai/ironclaw/blob/main/CLAUDE.md
- 3: https://nearai.mintlify.app/
- 4: https://tessl.io/registry/skills/github/nearai/ironclaw/ironclaw-reborn-architecture-review
- 5: https://github.com/nearai/ironclaw/blob/main/AGENTS.md
- 6: https://github.com/nearai/ironclaw?tab=readme-ov-file
- 7: https://www.near.ai/blog/introducing-ironclaw-1-0
- 8: https://github.com/nearai/ironclaw/releases/tag/ironclaw-v1.0.0
- 9: https://tessl.io/registry/skills/github/nearai/ironclaw/ironclaw-reborn-architecture-review/review
- 10: https://tessl.io/registry/skills/github/nearai/ironclaw/ironclaw-reborn-architecture-review/evals
- 11: https://nearai-ironclaw.mintlify.app/development/testing
- 12: https://github.com/nearai/ironclaw/blob/main/clippy.toml
🌐 Web query:
site:github.com/nearai/ironclaw/blob/main/.claude/skills/ironclaw-reborn-architecture-review/SKILL.md "cargo clippy -p"
💡 Result:
SKILL.md contains:
cargo clippy -p <crate> --all-targets --all-features -- -D warningsIt appears in the Verify section. [1] (github.com)
Citations:
🌐 Web query:
site:github.com/nearai/ironclaw/blob/main/AGENTS.md "default" "all-features" clippy
💡 Result:
There is no single command called default all-features clippy. To run Clippy with all features enabled in a Rust project, use the command cargo clippy --all-features. This ensures that Clippy analyzes the code for all possible feature combinations defined in your Cargo.toml file. If you want to run Clippy while also including default features (which is the standard behavior when using --all-features), you do not need any additional flags.
Citations:
Add the default-feature Clippy lane.
When a change adds, moves, or relies on #[cfg(feature = ...)], add cargo clippy -p <crate> --all-targets -- -D warnings alongside the existing all-features lane, as required by AGENTS.md.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In @.claude/skills/ironclaw-reborn-architecture-review/SKILL.md at line 31, Add
the default-feature Clippy command alongside the existing all-features command
in the validation command list, using `cargo clippy -p <crate> --all-targets --
-D warnings`; retain the current architecture-test and conditional WebUI
contract-test commands.
Source: Coding guidelines
…wn-ratchet Second refresh fold of the day (#7509 + #7365). Conflicts were again the composition bookkeeping pair; resolved by keeping both dated chains and taking the merged tree's own measurement: - composition-budget.toml + reborn_restructure_baselines.rs: main's #7365 re-ratcheted DOWN 41810 -> 41533 (memory-save guidance evicted to the memory-native package); this branch adds no composition code, and the merged tree measures 41533 LOC / 831 Arc<dyn> exactly, so main's banked eviction stands and the arc_dyn re-equalization from the previous fold carries through. Verified with the gate's --print. - Main's three SIZE_CEILINGS bumps (extension_contracts 7947, host_api 19086, loop_contracts 13524) auto-merged; the ceiling gate passes on the merged tree with the windows intact. Verified green: reborn_dependency_boundaries 42/42 (incl. the window-edge fixture), reborn_restructure_baselines, composition-budget gate, clippy clean, fmt clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
crates/app/ironclaw_architecture_tests/tests/reborn_restructure_baselines.rs (1)
153-160: 📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick winReconcile the merged-tree LOC history. The active values are numerically consistent at
41533, but the audit trail is not: the baseline records41_731 → 41_533, while the manifest records41810 → 41820and41810 → 41527. Align both histories with the measured sequence and the finalloc_ceiling/loc_observedvalue.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@crates/app/ironclaw_architecture_tests/tests/reborn_restructure_baselines.rs` around lines 153 - 160, The merged-tree LOC audit history is inconsistent across the baseline and manifest. Update the history in crates/app/ironclaw_architecture_tests/tests/reborn_restructure_baselines.rs (lines 153-160) and scripts/ci/composition-budget.toml (lines 182-196) to reflect the measured sequence, ensuring the final entries match the active loc_ceiling and loc_observed value of 41533.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In
`@crates/app/ironclaw_architecture_tests/tests/reborn_restructure_baselines.rs`:
- Around line 153-160: The merged-tree LOC audit history is inconsistent across
the baseline and manifest. Update the history in
crates/app/ironclaw_architecture_tests/tests/reborn_restructure_baselines.rs
(lines 153-160) and scripts/ci/composition-budget.toml (lines 182-196) to
reflect the measured sequence, ensuring the final entries match the active
loc_ceiling and loc_observed value of 41533.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: 84af5ba0-d3cd-4f6d-8ece-e391c487d7db
📒 Files selected for processing (4)
crates/app/ironclaw_architecture_tests/tests/reborn_dependency_boundaries.rscrates/app/ironclaw_architecture_tests/tests/reborn_extension_specificity.rscrates/app/ironclaw_architecture_tests/tests/reborn_restructure_baselines.rsscripts/ci/composition-budget.toml
💤 Files with no reviewable changes (1)
- crates/app/ironclaw_architecture_tests/tests/reborn_extension_specificity.rs
…ates re-measured on the merged tree Conflicts were the three measurement files only. Ceilings re-measured, not summed (composition 41780 LOC / 838 governed Arc<dyn> sites; contracts-tier ceilings verified passing under the union records). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ead gates deleted (nearai#7373) * test(architecture): drop the dead ironclaw_storage row and arm the substrate list Gate-audit finding (open-and-shut): SUBSTRATE_CRATES in reborn_composition_boundaries.rs carried three rows of rot, all invisible because the loop's `let Some(..) else { continue }` silently skipped any entry that resolves to no workspace package: - "ironclaw_storage": no such package exists (verified against `cargo metadata --no-deps`; the only MISSING name of the 29 listed). - "ironclaw_approvals" and "ironclaw_assistant" were each listed twice. The silent skip is replaced with a panic naming the stale entry, so the list can no longer rot invisibly. Verified by sabotage: adding a bogus "ironclaw_zzz_probe" row now fails the test with "is listed in SUBSTRATE_CRATES but is not a workspace package"; the clean list passes (23/23). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(architecture): prune the dead sanctioned path from the specificity gate Gate-audit finding (open-and-shut): SANCTIONED_PATHS in reborn_extension_specificity.rs still exempted `extension_host/extension_installation_store.rs` — a file deleted by nearai#6430. No scanned path matches the fragment (verified with rg across crates/), so the entry exempted nothing; it is also the one exclusion surface in this gate with no staleness check, which is how it outlived its file. Full specificity suite green after removal (8/8). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(architecture): drop the v1 ironclaw_gateway/static exclusions from the telegram gates Gate-audit finding (open-and-shut): both cross-tree scans in telegram_extension_gates.rs still carved out `ironclaw_gateway/static` — the v1 monolith's embedded UI, whose crate was deleted with the src/ monolith (no crates/*/ironclaw_gateway directory exists). The exclusions matched nothing; scans now cover the whole tree with no dead carve-outs. Suite green after removal (12/12). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(architecture): make the dto-collapse gate's header describe the gate that exists Gate-audit finding (open-and-shut doc rot): the module doc still described the pre-nearai#6447 freeze design — a dangling doc-link to FROZEN_COLLAPSE_DTOS (renamed RETIRED_COLLAPSE_DTOS in nearai#6447), a promised delete-without-trimming failure and an empty-allowlist assertion that do not exist in the file, and a named owner for a collapse that completed. The mechanism itself is armed and untouched; the header now describes the permanent zero-gate it became, and records the two originally-frozen names that deliberately left governance (CapabilityOutcome via nearai#6299 deletion, CapabilityDispatchRequest blessed as the canonical port type). Suite green (2/2). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(architecture): repoint the manifest-reparse allowlist note at the colocated asset Gate-audit finding (open-and-shut doc rot): the BundledAsset allowlist entry's justification still cited include_str! of assets/memory_native/manifest.toml — a path retired when WS2 (nearai#7037) colocated packages; the live include in memory_native_extension.rs reaches crates/extensions/packages/memory-native/manifest.toml. Comment only; the gate's mechanism and counts are untouched. Suite green (2/2). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(architecture): give the memory-vocabulary gate the partial-tree floor its twin has Gate-audit finding: reborn_memory_retired_vocabulary.rs had no MIN_SCANNED_FILES floor, unlike its explicit twin reborn_retired_taxonomy.rs — so a partially-moved tree (the CHECKLIST WS0 / nearai#6963 'green while measuring nothing' shape) would scan a fraction of the files and still report the vocabulary clean. The gate was in fact born with an already-dead sanctioned path (its own header records this), so the rot class is not hypothetical for this file. Adds the same 500-file floor (real count ~4000), asserts it in the main gate, and pins the premise on a fixture: a 10-file partial tree scans clean and is rejected by the floor. Suite green (4/4); clippy clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(architecture): close the transport gate's nested-use-group fail-open Gate-audit finding (sabotage-verified): product_symbols_in's braced-group branch closed at the FIRST '}' (group.find('}')), so a nested group — use ironclaw_assistant::{m::{X}}; — truncated mid-element and recorded zero symbols. Probed live before the fix: appending use ironclaw_assistant::{zzz_audit::{ZzzProbe}}; to webui's lib.rs left transports_name_only_the_frozen_residue_of_product_symbols GREEN, while the plain-path spelling of the same import correctly failed. The same truncation dropped qualified elements inside flat groups ({qualified_module::X} recorded nothing). The group branch now does a balanced-brace walk, splits elements at depth-0 commas only, and records a qualified/nested element's leading path segment — the same key the single-path branch records for ironclaw_assistant::module::X. Flat-element semantics are byte-for-byte unchanged, so the frozen 100-row webui inventory is untouched (suite green 6/6 on the live tree). Regression fixtures added to import_scanner_reads_symbols_out_of_real_use_shapes; the original sabotage now fails with the gate's own message (re-verified). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * ci: delete check-e2e-matrix-files.sh — a gate for a workflow that no longer exists Gate-audit finding (provably inert): the script's default target is .github/workflows/e2e.yml, deleted when the v1 e2e suites were retired (git log --diff-filter=D shows the removing commit); no workflow, script, hook, doc, or guidance file references check-e2e-matrix-files.sh (verified with rg across the repo including .github and .githooks). A checker nothing runs, pointed at a file nothing provides, is dead weight that reads as coverage. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * ci: delete the measured-broken check-boundaries.sh and its guidance references Gate-audit finding (provably inert, previously measured): crates/AGENTS.md recorded on 2026-08-05 that the script fails on a clean tree (check 5 false-positives on live test files) and that checks 1/2/3/6 target the deleted v1 src/ tree, passing vacuously. No workflow or hook runs it; its only callers were guidance files, two of which claimed it 'enforces' root-tests feature gating — an enforcement claim the skill-maintainer rules forbid for a check nothing executes. Removed the script and every live reference: the crates/AGENTS.md warning row becomes a tombstone note; the testing skill + exemplar reference drop the false enforcement parenthetical; the architecture-review skill's Verify line drops the dead command; deslop-reborn's allowed-tools drops the permission; .coderabbit.yaml's driver-leak instruction now points at the live enforcement (reborn_persistence_driver_boundary). Two dated docs/internal/ plan snapshots keep their historical mentions. Verified: python3 scripts/ci/check-guidance.py OK (2084 path references) and its self-test OK. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs(product): stop hardcoding charter sub-owner counts in the family map Gate-audit finding (stale prose): crates/product/AGENTS.md said '19-sub-owner reborn_services charter map' — the enforced map has had 20 sub-owners since nearai#7235 added the inspector row (counted from the live table). Rather than chase the number, drop both inline counts: the owning maps and their gates are authoritative, and the re-verify commands are already inline (skill-maintainer rule: no counts without a regeneration recipe). check-guidance.py OK. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(architecture): correct the scanner-fixture file's name-filter claim Gate-audit finding (doc rot with a false coverage claim): the header said naming the FILE reborn_* makes code_style.yml's 'cargo test -p ironclaw_architecture_tests reborn' see it — but that argument is a test-NAME filter (the measurement is documented in reborn_contracts_vendor_census.rs), and none of this file's test fns contains the substring, so that smoke lane runs 0 of them (11 collected by the full plan). Comment-only; the note now records the real semantics so file names are not trusted for lane coverage. Suite green (11/11). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs(internal): gate & ratchet audit report + proposed preflight gauntlet The audit the owner asked for after PR nearai#7157 went red six times across four gates: every architecture-test gate, module charter, CI script, and committed baseline inventoried with a verdict and evidence; the handful worth acting on ranked by friction x weakness; the CI-ergonomics analysis (why failures surface one per ~1h round-trip: no --no-fail-fast anywhere in CI, cancel-in-progress on push, sequential fast-checks steps — measured: two broken gates report 1 failure in 18s under the CI shape vs both in 211s with --no-fail-fast); and the sabotage log for every probe. scripts/preflight-gates.sh is the concrete pre-push proposal: the deterministic-gate classes only (script gates ~10s + architecture suite --no-fail-fast + changed-crate charter tests), covering all four nearai#7157 gate classes locally in one command. Unwired — nothing invokes it. Validated end-to-end on this branch: exit 0, 'every deterministic gate green', 402.8s including gate-binary recompiles. Placement verified: python3 scripts/ci/docs_publication_boundary.py OK. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * ci(planner): classify preflight-gates.sh and the deleted check-boundaries.sh The gate audit's own PR hit the planner's fail-closed arm — 'unmapped test or CI path: scripts/check-boundaries.sh' — exactly the class the arm exists to force a decision on (and the audit's report documents). Per the PR_STATIC_CONTROL_PATHS membership rule (no Reborn test lane exercises either file): - scripts/preflight-gates.sh — the audit's proposed local pre-push gauntlet; referenced by no workflow. - scripts/check-boundaries.sh — deleted by the audit; the entry lets the deletion diff (and any revert) classify instead of failing every downstream Reborn lane. Verified: the planner now produces mode=selected with the architecture-misc bucket for this branch's diff, and python3 scripts/ci/test_reborn_pr_test_plan.py is OK. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs(internal): add the fold-tripped asymmetric-tolerance exhibit to the audit The strongest single exhibit for shortlist item 2, contributed by the nearai#7157 branch steward after this audit's cutoff and verified against the gate's code: TOLERANCE = 400 is consulted in exactly one direction (the banked-slack check, ceiling.saturating_sub(lines) > TOLERANCE); the growth check is a bare lines > ceiling. With the in-file 'set to current, not padded' instruction, every ceiling is a hard cap at the observed count — so one line landing on main in any contracts crate reds every open branch at its next fold until someone re-captures. Measured recurrence on nearai#7157: loop_contracts re-captured four times, ~once per fold (14,479 -> 13,850 -> 13,949 -> 13,115 -> 13,181), the last tripped by main's nearai#7361/nearai#7363 adding 66 lines to instruction_bundle.rs — nothing the branch wrote. All four deltas were <= 105 lines: either repair shape in §3.2 (one-line upward tolerance using the existing constant, or mid-window pinning) would have absorbed every one with zero red builds. This audit's own sabotage already proved the jaws (+1 line host_api red / -1 line common red); the fold history shows the operational cost. The repair stays a recommendation — adding growth headroom to a ratchet is the owner's call, not this PR's. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(architecture): give the contracts size ceiling upward working slack Owner-directed repair of the audit's sharpest finding (report §3.2): the gate's TOLERANCE = 400 was consulted in exactly one direction — the banked-slack check — while the growth check was a bare lines > ceiling. Combined with 'set to current, not padded' pins, every ceiling was a hard cap at the exact observed count, so one line landing on main in any contracts crate redded every open branch at its next fold until someone re-captured. Measured on nearai#7157: four loop_contracts re-captures, roughly once per fold, every delta <= 105 lines — the gate generating its own busywork. The growth check now allows GROWTH_TOLERANCE = 150 of working slack above each pin (sized to composition-budget precedent; the reviewed raises this gate has caught were +1,069 and +1,214 lines, far above it), and all six ceilings are re-pinned to the counts the test itself reported with every ceiling at 0 — which also removes the +400 seed padding on common/loop_contracts/prompt_envelope that contradicted the capture rule and put those crates one deleted line from the banked jaw. Sabotage-verified both ways: +1 line in host_api and -1 line in common — both red before this change — now pass; a +151-line probe still fails with the effective-ceiling arithmetic in the message. Full reborn_dependency_boundaries binary green (41/41); clippy clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * ci(budget): re-equalize composition pins to observed — restore the working window Owner-directed companion to the contracts-ceiling repair (same annoying class, other mass gate): merged main-side growth since the 2026-08-05 equalization had drifted +101 LOC and +5 Arc<dyn> sites through the tolerance windows, leaving 49 LOC / 10 sites of live headroom — the next routine composition PR would have gone red on wiring alone (the gate audit measured this the same day it was pinned). Per the TOML's own maintenance instructions: loc_ceiling/loc_observed 40423 -> 40524 and arc_dyn 814 -> 819, measured with the gate's --print, set to current not padded, dated notes appended (not overwritten), and the arch-test record (COMPOSITION_ABSOLUTE_SRC_LOC) moved in the same commit as its file requires. ceiling_bp stays 658 — the WS0 floor is deliberately not re-set. Verified: check-composition-budget.sh OK; its 76-case self-test green; reborn_restructure_baselines green; probe +100 LOC now passes (was red at 49 headroom), probe +160 LOC still fails. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs(internal): record the landed zero-slack repairs in the audit report The §3.2 repair moved from recommendation to landed at owner direction; the report's answer, inventory rows, and §7 ledger now say so, with the counting-rule fix promoted to the top remaining recommendation. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * gates: pin the ceiling-window arithmetic; fail preflight discovery closed Two review-round hardenings (the open CodeRabbit Majors): - reborn_dependency_boundaries.rs: extract the size-ceiling comparison into contracts_ceiling_verdict() and pin its four window edges with a committed regression test (contracts_size_ceiling_window_edges_hold) — accept at ceiling+GROWTH_TOLERANCE, reject one line past, accept at ceiling-TOLERANCE, reject one banked line further, and a zero-measure scan reads Banked, never a silent pass. The pre-repair asymmetry (tolerance consulted only downward) can no longer return silently. Live-gate behavior re-probed unchanged after the rewiring: +1 line to host_api passes, +151 fails with the same effective-ceiling message. - preflight-gates.sh: setup and changed-file discovery now fail closed — a missing repo root exits 2, and a failed merge-base/diff widens the charter run to all five crates instead of silently skipping them (the same fallback the missing-base branch already used). A broken setup may cost compile time, never a silent skip. Full boundary binary 42/42 green; clippy clean; preflight-gates.sh end-to-end green on this tree. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Summary
docs/internal/gate-audit-2026-08.md(inventory + per-gate verdicts, ranked shortlist, CI-ergonomics analysis, sabotage log).use ironclaw_assistant::{m::{X}};import passed silently) and the composition substrate list's silent skip of unresolvable entries (which had hidden a phantomironclaw_storagerow plus two duplicates).check-boundaries.sh(measured broken on a clean tree 2026-08-05, never run by CI, cited by two guidance files as "enforcing" gating it never enforced) andcheck-e2e-matrix-files.sh(checker for a workflow deleted with the v1 monolith; zero references).scripts/preflight-gates.sh: the deterministic-gate gauntlet that would have caught all four of feat: explicit channel delivery tool — two lanes, notification channels, delivery heuristics deleted #7157's gate failures before the first push; validated end-to-end on this branch (exit 0, 402.8s incl. recompiles).GROWTH_TOLERANCE = 150(itsTOLERANCE = 400was consulted only in the banked-slack direction — the growth check was a barelines > ceiling), all six pins re-captured to current via the gate's own procedure, and the composition budget's drifted pins re-equalized to observed (49 LOC / 10Arc<dyn>of live headroom restored to the designed 150/15 windows, record constant moved in the same commit). Sabotage-verified both ways: ±1-line probes that redded before now pass; +151-LOC and +160-LOC probes still fail. Remaining judgment calls (CI--no-fail-fast, cfg-test-aware LOC counting, arch-bucket PR selection, etc.) stay as ranked recommendations in the report.unmapped test or CI path: scripts/check-boundaries.sh) — working exactly as designed; both audit-touched script paths are now classified perPR_STATIC_CONTROL_PATHS' membership rule, with the planner self-test green.Change Type
Linked Issue
None (owner-requested audit).
Validation
cargo fmt --all -- --checkcargo clippy -p ironclaw_architecture_tests --all-targets --all-features -- -D warnings(the only crate whose code changed; no production crate touched)cargo test -p ironclaw_architecture_testsgreen after all edits (37 binaries); per-gate runs quoted in each commit messagepython3 scripts/ci/check-guidance.pyOK (2,084 path references) after the guidance edits;python3 scripts/ci/docs_publication_boundary.pyOK for the report placementbash scripts/preflight-gates.shrun end-to-end on this branch--features integration(no database/runtime behavior touched)Test Strategy
User behavior: none — no production code changes. The diff is test-only gate code, guidance, scripts, and an internal report.
Risk areas: none of the listed classes apply (no model/browser/side-effect/persistence/security/provider/cross-component behavior changed).
Tests added or updated:
import_scanner_reads_symbols_out_of_real_use_shapes(transport gate);a_partial_tree_scans_clean_and_hits_the_floor(memory-vocabulary gate); the substrate-list arming is exercised by the existing test now failing on unresolvable rows (probe-verified in the commit).What the tests prove: the transport gate now records symbols from nested and qualified use-groups (the sabotage import that previously passed now fails with the gate's own message); the memory gate refuses a partial tree; the substrate list can no longer rot silently.
Commands run:
cargo test -p ironclaw_architecture_tests(full, green, 328s); per-gatecargo test -p ironclaw_architecture_tests --test <gate>after each edit; sabotage probes via prebuilt gate binaries (documented per commit and in the report's §6 log);check-guidance.py,docs_publication_boundary.py,check-composition-budget.sh,check_no_panics.py --reborn-baselineall green on the final tree.Security Impact
None. (The gate fixes strictly widen what the gates catch; the origin-gate matrix, seals, and trust boundaries are untouched.)
Reborn Trust-Boundary Checklist
N/A — no trust-bearing types, prompts, hashes, status variants, queues, or sandbox naming changed. The only code changes are inside
ironclaw_architecture_tests(test-only crate, no library surface).Database Impact
None.
Blast Radius
crates/app/ironclaw_architecture_tests/tests/— 8 gate files edited (list hygiene, one parser fix, one floor, three comment-only corrections, and the owner-directed contracts-ceiling tolerance + re-pins with the composition record moved inreborn_restructure_baselines.rs). Risk in both directions is probe-tested: newly-armed paths verified red, newly-tolerated routine drift verified green, real-growth thresholds verified still red.scripts/ci/composition-budget.toml— pins re-equalized to observed per the file's own maintenance instructions (dated notes appended, never overwritten);ceiling_bp = 658(the WS0 floor) deliberately untouched.scripts/— two deletions (nothing executes either; verified by reference sweep) and one additive unwired script.crates/AGENTS.md,crates/product/AGENTS.md, three.claudeskills, one command,.coderabbit.yaml: reference removals for the deleted script plus two count/claim corrections;check-guidance.pygreen.docs/internal/gate-audit-2026-08.md— new internal report (inside the publication fence).Rollback Plan
Every commit is independent and revertable in isolation; none changes production behavior. Reverting the transport-parser commit restores the (sabotage-demonstrated) fail-open, so if it must be reverted, re-open the finding. The two script deletions are restorable from git history verbatim.
Review Follow-Through
The report's §3 shortlist and §7 are the remaining owner-decision queue — highest-leverage first: CI
--no-fail-fast+ fast-checks aggregation (measured: two broken gates → one round-trip instead of two), the cfg-test-aware LOC counting rule (25–41% of counted "mass" is inline test context; ~27k relocatable lines of mintable headroom remain — fixing it re-seeds the ceilings this PR just re-pinned, which is fine and expected), arch bucket on anycrates/PR, the two remaining verified fail-opens (slack/telegram BoundaryRule skip; registrar-gate truncation), and theREPORT_ONLYinclude-scan decision. Merge-order note for #7157: its branch carries its own loop_contracts recapture (13,181); whichever lands second takes a trivial numeric conflict on that ceiling row — with the new tolerance, either value passes on the merged tree.Review track: A (docs/tests/chore) — with a C-shaped caveat: it deletes two never-executed CI scripts, so a CI-owner glance at those two commits is warranted.
🤖 Generated with Claude Code