Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
22 commits
Select commit Hold shift + click to select a range
b3bebcc
test(architecture): drop the dead ironclaw_storage row and arm the su…
BenKurrek Aug 7, 2026
c802191
test(architecture): prune the dead sanctioned path from the specifici…
BenKurrek Aug 7, 2026
f6dbb7c
test(architecture): drop the v1 ironclaw_gateway/static exclusions fr…
BenKurrek Aug 7, 2026
7255f19
test(architecture): make the dto-collapse gate's header describe the …
BenKurrek Aug 7, 2026
d7ab4d2
test(architecture): repoint the manifest-reparse allowlist note at th…
BenKurrek Aug 7, 2026
f3f5f75
test(architecture): give the memory-vocabulary gate the partial-tree …
BenKurrek Aug 7, 2026
77581e2
test(architecture): close the transport gate's nested-use-group fail-…
BenKurrek Aug 7, 2026
f614311
ci: delete check-e2e-matrix-files.sh — a gate for a workflow that no …
BenKurrek Aug 7, 2026
42be139
ci: delete the measured-broken check-boundaries.sh and its guidance r…
BenKurrek Aug 7, 2026
720101f
docs(product): stop hardcoding charter sub-owner counts in the family…
BenKurrek Aug 7, 2026
58f05bd
test(architecture): correct the scanner-fixture file's name-filter claim
BenKurrek Aug 7, 2026
488ac8e
docs(internal): gate & ratchet audit report + proposed preflight gaun…
BenKurrek Aug 7, 2026
e206c28
ci(planner): classify preflight-gates.sh and the deleted check-bounda…
BenKurrek Aug 7, 2026
d995a3d
docs(internal): add the fold-tripped asymmetric-tolerance exhibit to …
BenKurrek Aug 7, 2026
1edbd01
test(architecture): give the contracts size ceiling upward working slack
BenKurrek Aug 7, 2026
13b54a7
ci(budget): re-equalize composition pins to observed — restore the wo…
BenKurrek Aug 7, 2026
480c8bf
docs(internal): record the landed zero-slack repairs in the audit report
BenKurrek Aug 7, 2026
9dad9df
Merge origin/main: fold #7157's landed chain into the audit's repairs
BenKurrek Aug 8, 2026
e11be12
Merge origin/main: fold #7228's product_contracts raise into the merg…
BenKurrek Aug 8, 2026
c54aff1
Merge origin/main into booming-newsstand: union re-measure on the mer…
BenKurrek Aug 12, 2026
028c902
gates: pin the ceiling-window arithmetic; fail preflight discovery cl…
BenKurrek Aug 12, 2026
edd719f
Merge origin/main into booming-newsstand: fold #7365's composition do…
BenKurrek Aug 12, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .claude/commands/deslop-reborn.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
description: One iteration of the IronClaw Reborn de-slop loop — take ONE Reborn crate, fan out parallel review sub-agents (thermo-nuclear quality, paranoid architect, interface/contract/invariants, test-coverage/wiring), synthesize, apply fixes/refactors/missing tests, open a PR. Stop.
disable-model-invocation: true
allowed-tools: Bash(cargo fmt:*), Bash(cargo clippy:*), Bash(cargo test:*), Bash(cargo build:*), Bash(git:*), Bash(gh:*), Bash(grep:*), Bash(rg:*), Bash(ls:*), Bash(wc:*), Bash(scripts/check-boundaries.sh:*), Bash(scripts/reborn-e2e-rust.sh:*), Read, Grep, Glob, Edit, Write, Agent
allowed-tools: Bash(cargo fmt:*), Bash(cargo clippy:*), Bash(cargo test:*), Bash(cargo build:*), Bash(git:*), Bash(gh:*), Bash(grep:*), Bash(rg:*), Bash(ls:*), Bash(wc:*), Bash(scripts/reborn-e2e-rust.sh:*), Read, Grep, Glob, Edit, Write, Agent
argument-hint: "[crate name, e.g. ironclaw_turns]"
---

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,6 @@ Layer discipline here is enforced by machines, not vibes: `cargo test -p ironcla

## Verify

`cargo test -p ironclaw_architecture_tests` · `bash scripts/check-boundaries.sh` (legacy inventory; may be noisy on HEAD, don't treat as the Reborn architecture gate) · `cargo clippy -p <crate> --all-targets --all-features -- -D warnings` · if routes changed: `cargo test -p ironclaw_webui --test webui_v2_descriptors_contract`.
`cargo test -p ironclaw_architecture_tests` · `cargo clippy -p <crate> --all-targets --all-features -- -D warnings` · if routes changed: `cargo test -p ironclaw_webui --test webui_v2_descriptors_contract`.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win

Run the enforcement-side route tests.

webui_v2_descriptors_contract checks the declared policy table only. Add webui_v2_handlers_contract and the composed webui_v2_serve test, or narrow this condition to declaration-only changes. The exemplar identifies those tests as the enforcement-side coverage.

As per path instructions, test through the caller when a helper gates a side effect.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/ironclaw-reborn-architecture-review/SKILL.md at line 31,
Update the route-change testing guidance in the architecture review skill to
require the enforcement-side webui_v2_handlers_contract and composed
webui_v2_serve tests in addition to webui_v2_descriptors_contract.
Alternatively, narrow the existing condition explicitly to declaration-only
changes; ensure helper-gated side effects are tested through their caller.

Source: Path instructions


📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -eu
printf '%s\n' '--- skill excerpt ---'
sed -n '1,90p' .claude/skills/ironclaw-reborn-architecture-review/SKILL.md
printf '%s\n' '--- relevant guidance files ---'
find . -name AGENTS.md -o -name CLAUDE.md -o -path '*/.claude/rules/*' | sort
printf '%s\n' '--- feature/clippy guidance ---'
rg -n -C 3 'clippy|all-features|default.?feature|cfg\\(feature|feature-gated|route|webui_v2_descriptors_contract' AGENTS.md CLAUDE.md .claude crates tests 2>/dev/null | head -240

Repository: nearai/ironclaw

Length of output: 2099


🌐 Web query:

nearai ironclaw ".claude/skills/ironclaw-reborn-architecture-review/SKILL.md" clippy

💡 Result:

The command nearai ironclaw .claude/skills/ironclaw-reborn-architecture-review/SKILL.md clippy is a reference to a specific development workflow within the IronClaw project [1][2], an open-source, Rust-based Agent OS maintained by NEAR AI [1][3]. In this context, the command likely instructs an AI assistant or development tool to read and apply the architecture review guidelines contained in the .claude/skills/ironclaw-reborn-architecture-review/SKILL.md file while running clippy (the Rust linter) on the codebase [4][5][6]. Key details regarding these components: * IronClaw: A rearchitected (v1.0+) agent runtime that separates decision-making from action execution [7][8]. Development now prioritizes code in the crates/ directory (the "Reborn" architecture) over the legacy src/ monolith [2][5]. * SKILL.md: Repository-specific agent skills are stored in .claude/skills/*/SKILL.md [5]. The ironclaw-reborn-architecture-review skill specifically provides guidance on maintaining architectural boundaries, abstractions, and re-exports when modifying or adding code to the crates/ directory [9][10][5]. * Clippy: The project uses cargo clippy as its standard linting tool [11][6]. The repository includes a clippy.toml file that defines custom complexity guardrails (e.g., cognitive-complexity-threshold, too-many-arguments-threshold) to ensure code quality in the new architecture [12]. The combined instruction suggests a task to verify code changes against both the project's high-level architectural standards (defined in the SKILL.md file) and its specific static analysis constraints (defined in clippy.toml) [9][12].

Citations:


🌐 Web query:

site:github.com/nearai/ironclaw/blob/main/.claude/skills/ironclaw-reborn-architecture-review/SKILL.md "cargo clippy -p"

💡 Result:

SKILL.md contains:

cargo clippy -p <crate> --all-targets --all-features -- -D warnings

It appears in the Verify section. [1] (github.com)

Citations:


🌐 Web query:

site:github.com/nearai/ironclaw/blob/main/AGENTS.md "default" "all-features" clippy

💡 Result:

There is no single command called default all-features clippy. To run Clippy with all features enabled in a Rust project, use the command cargo clippy --all-features. This ensures that Clippy analyzes the code for all possible feature combinations defined in your Cargo.toml file. If you want to run Clippy while also including default features (which is the standard behavior when using --all-features), you do not need any additional flags.

Citations:


Add the default-feature Clippy lane.

When a change adds, moves, or relies on #[cfg(feature = ...)], add cargo clippy -p <crate> --all-targets -- -D warnings alongside the existing all-features lane, as required by AGENTS.md.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.claude/skills/ironclaw-reborn-architecture-review/SKILL.md at line 31, Add
the default-feature Clippy command alongside the existing all-features command
in the validation command list, using `cargo clippy -p <crate> --all-targets --
-D warnings`; retain the current architecture-test and conditional WebUI
contract-test commands.

Source: Coding guidelines


**Worked good/bad examples** (before/after shapes, live exemplars, re-verify commands): [references/worked-examples.md](references/worked-examples.md) — the living curriculum; update it as the code evolves.
2 changes: 1 addition & 1 deletion .claude/skills/ironclaw-reborn-skill-maintainer/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ Every rule below counters a rot pattern this repo's guidance is prone to. Guidan
2. **Verify every concrete reference at write time — and make it re-verifiable.** Branches die silently; prefer in-tree worked examples over branch/PR refs. For each cited path/symbol, keep a one-line grep a maintainer can re-run.
3. **No universal claims without a count.** Avoid absolute docs coverage claims. Write "most; fall back to Cargo.toml + lib.rs" or generate the list.
4. **Triggers live in frontmatter `description`, nowhere else.** The runtime surfaces only frontmatter for selection; a "when to use" buried in the body is invisible. Description = triggering conditions only — never a workflow summary (agents will follow the summary and skip the body).
5. **Never claim enforcement that doesn't exist.** Before writing "enforced by X", run X. If you add a check to `scripts/pre-commit-safety.sh` or `scripts/check-boundaries.sh`, add its self-test — and know there are two hook install paths (`.githooks/` vs `scripts/dev-setup.sh` symlink); a check is only real if both run it.
5. **Never claim enforcement that doesn't exist.** Before writing "enforced by X", run X. If you add a check to `scripts/pre-commit-safety.sh`, add its self-test — and know there are two hook install paths (`.githooks/` vs `scripts/dev-setup.sh` symlink); a check is only real if both run it.
6. **After any extraction/move/rename, grep the guidance layer** for old paths in the same PR: `.claude/`, `AGENTS.md`, `CLAUDE.md`, `crates/AGENTS.md`, `docs/reborn/contracts/`, skill bodies.
7. **Runtime-skill spec must track the parser.** `crates/domains/ironclaw_skills/src/types.rs` supports `requires.config`, `requires.skills`, `activation.setup_marker`, and silently truncates >20 keywords / >5 patterns (`enforce_limits`). If you use or change parser behavior, update `.claude/rules/skills.md` in the same PR.
8. **Codex parity check.** Codex cannot load Claude skills; it reads AGENTS.md. When a skill carries a rule Codex must also follow, the AGENTS.md hierarchy needs the pointer *with enough inline substance* ("read `.claude/skills/<name>/SKILL.md`" works — skills are plain markdown).
Expand Down
2 changes: 1 addition & 1 deletion .claude/skills/ironclaw-reborn-testing/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ Pick the tier first; everything else follows. The repo's tier knowledge lives in

- **Regression-per-fix is mechanically checked for conventionally marked fix/high-risk changes** (commit-msg hook + `regression-test-check.yml`). Escape hatch `[skip-regression-check]` exists — using it on a real fix will be questioned in review.
- **Consolidate, don't proliferate**: extend the existing test that already drives the path (a case, a scripted turn, an assertion) before standing up a new file. Say why an existing test couldn't absorb a genuinely new scenario.
- **Persistence = both backends.** PostgreSQL + libSQL parity where production-facing; the model is `ironclaw_hooks`' dual-backend shape (`crates/loop/ironclaw_hooks/src/postgres_backend/` + `crates/loop/ironclaw_hooks/src/libsql_backend/`, proved equivalent by `crates/loop/ironclaw_hooks/tests/parity_matrix.rs` and `crates/loop/ironclaw_hooks/tests/multi_host_adversarial.rs`). Feature-gate integration tests (`check-boundaries.sh` enforces the gating for root `tests/`).
- **Persistence = both backends.** PostgreSQL + libSQL parity where production-facing; the model is `ironclaw_hooks`' dual-backend shape (`crates/loop/ironclaw_hooks/src/postgres_backend/` + `crates/loop/ironclaw_hooks/src/libsql_backend/`, proved equivalent by `crates/loop/ironclaw_hooks/tests/parity_matrix.rs` and `crates/loop/ironclaw_hooks/tests/multi_host_adversarial.rs`). Feature-gate integration tests.
- **The backend-integration tier is NOT a PR gate unless the workflow says so** (re-verify: `grep -n integration .github/workflows/platform-and-compat.yml`): full Postgres coverage may run post-merge or nightly. A green PR does not prove the tier ran; run it locally when your change is DB/runtime-shaped — crate-level, e.g. `cargo test -p ironclaw_hooks --features integration,test-support` (the workspace-root `integration` feature is empty; a bare root `cargo test --features integration` runs nothing extra).
- **Never add a silent self-skip to PR-gated tests.** `if docker_missing { return }` hides the suite from CI. Existing Docker sandbox canaries still need migration; new tests should skip loudly via feature gates or explicit env opt-outs.
- **Capability results and terminal errors have their own test shape** — recoverable failures must remain model-visible outcomes, while host failures are terminal; test the caller against the capability-access contract and its real redaction/evidence validation.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ When a predicate selects what goes out the wire, the test must construct the rea

**BAD for PR-gated coverage**: `if docker_unavailable { return }` — the container security suite silently vanishes from CI and no gate notices. Existing Docker sandbox canaries still use soft skips; don't copy that pattern into new gate coverage.

**GOOD**: make absence loud — feature-gate the test (`#![cfg(all(feature = "postgres", feature = "integration"))]`, which `scripts/check-boundaries.sh` enforces for root `tests/`), or require an explicit opt-out env var and *fail* when the dependency is missing without it. A skipped security test that doesn't announce itself is indistinguishable from coverage.
**GOOD**: make absence loud — feature-gate the test (`#![cfg(all(feature = "postgres", feature = "integration"))]`), or require an explicit opt-out env var and *fail* when the dependency is missing without it. A skipped security test that doesn't announce itself is indistinguishable from coverage.
Comment thread
coderabbitai[bot] marked this conversation as resolved.

## 6. Naming your contract's tests

Expand Down
3 changes: 2 additions & 1 deletion .coderabbit.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -107,7 +107,8 @@ reviews:
keep ironclaw_hooks_postgres / ironclaw_hooks_libsql in parity via hooks_parity).
Multi-step DB operations must be wrapped in a transaction. Driver types
(tokio_postgres::, libsql::) must not leak outside the allowed modules
(scripts/check-boundaries.sh).
(enforced by reborn_persistence_driver_boundary in
crates/app/ironclaw_architecture_tests).
- path: "**/*.wit"
instructions: |
Hand-written WIT contracts define the trusted/untrusted WASM ABI. Interface changes
Expand Down
5 changes: 2 additions & 3 deletions crates/AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -142,9 +142,8 @@ workspace gate (`cargo fmt`, workspace clippy, `cargo test`) is the root
`AGENTS.md`'s; test tiers and the regression rules are
`.claude/rules/testing.md`.

> **Do not reach for `scripts/check-boundaries.sh`.** Measured 2026-08-05: it
> fails on a clean tree (its check 5 grep false-positives on live test files)
> and checks 1/2/3/6 target the deleted v1 `src/` tree, passing vacuously.
> The legacy `check-boundaries.sh` script is deleted (measured 2026-08-05: it
> failed on a clean tree and its v1-targeted checks passed vacuously).
> Boundary enforcement for `crates/` is the architecture suite above.

## Cross-family change routes
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -9,26 +9,18 @@
//! that **"the §10 mirror-DTO ratchet's allowlist is what makes this safe: the
//! old [shapes] are frozen entries that may only disappear."**
//!
//! This is that ratchet. It freezes the current set of collapse-target DTOs and
//! fails on any change:
//! The collapse COMPLETED (#6447 retired the last request DTOs), so this file
//! is no longer the shrinking freeze that §9 describes — it is the permanent
//! zero-gate that survives it: [`RETIRED_COLLAPSE_DTOS`] names the retired
//! mirror shapes, and the test fails if any of them is ever re-declared
//! (the exact §1.1 Mechanism 1 failure, attempted after the fact).
//!
//! - a **second definition** of a frozen name (a downstream crate re-declaring an
//! upstream request "for decoupling" — the exact §1.1 Mechanism 1 failure) —
//! flagged by the multiplicity check;
//! - **deleting** one without trimming [`FROZEN_COLLAPSE_DTOS`] also fails — so
//! the allowlist shrinks in lock-step as the collapse lands (§10: compare set
//! membership, never a count), and reviewers watch it get shorter toward the
//! §3 end state (`Invocation` + the surviving per-lane requests + the five
//! result channels — zero mirrors).
//!
//! Definition of done for this axis: every entry below is deleted (its fields
//! now carried by `Invocation`/`Authorized`, its result variants by
//! `Resolution`), and this file is deleted with the last of them (enforced —
//! the test fails on an empty allowlist).
//!
//! Owner: the §3 capability-path collapse slice series under the #6168
//! umbrella (authorize → dispatch → result-channel migration) trims this list
//! in the same PRs that delete the types; reviewers hold additions to zero.
//! Two of the ten originally-frozen names are deliberately NOT here:
//! `CapabilityOutcome` (deleted by #6299 before the retired-list conversion)
//! and `CapabilityDispatchRequest` (its removal was a blessing, not a
//! deletion — it survives as the canonical port type in
//! `ironclaw_host_api::dispatch`). Reintroducing the former fires nothing;
//! add it below if that ever becomes a live hazard.
//!
//! Scanner semantics (shared with the other §10 ratchets — see
//! [`ratchet_support`]): comments/strings stripped before matching; covers
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,15 +20,13 @@ use ratchet_support::{crate_path, workspace_root};
const SUBSTRATE_CRATES: &[&str] = &[
"ironclaw_auth",
"ironclaw_host_api",
"ironclaw_storage",
"ironclaw_filesystem",
"ironclaw_event_log",
"ironclaw_event_projections",
"ironclaw_event_streams",
"ironclaw_extension_registry",
"ironclaw_authorization",
"ironclaw_approvals",
"ironclaw_approvals",
"ironclaw_resources",
"ironclaw_trust",
"ironclaw_capabilities",
Expand All @@ -47,16 +45,21 @@ const SUBSTRATE_CRATES: &[&str] = &[
"ironclaw_openai_compat",
"ironclaw_telegram_extension",
"ironclaw_assistant",
"ironclaw_assistant",
"ironclaw_triggers",
];

#[test]
fn no_substrate_crate_depends_on_composition_root() {
let dependencies = workspace_dependencies();
for substrate in SUBSTRATE_CRATES {
// Fail closed on an unresolvable entry: the silent `continue` this
// replaces let `ironclaw_storage` sit in this list long after the
// crate was deleted — a row that resolves to nothing polices nothing.
let Some(actual) = dependencies.get(*substrate) else {
continue;
panic!(
"{substrate} is listed in SUBSTRATE_CRATES but is not a workspace package; \
remove the stale entry (or fix the name) so this list keeps matching the tree"
);
};
assert!(
!actual.iter().any(|dep| dep == COMPOSITION_CRATE),
Expand Down
Loading
Loading