-
Notifications
You must be signed in to change notification settings - Fork 1.5k
Gate & ratchet audit: full-inventory report, five fail-opens armed, dead gates deleted #7373
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
22 commits
Select commit
Hold shift + click to select a range
b3bebcc
test(architecture): drop the dead ironclaw_storage row and arm the su…
BenKurrek c802191
test(architecture): prune the dead sanctioned path from the specifici…
BenKurrek f6dbb7c
test(architecture): drop the v1 ironclaw_gateway/static exclusions fr…
BenKurrek 7255f19
test(architecture): make the dto-collapse gate's header describe the …
BenKurrek d7ab4d2
test(architecture): repoint the manifest-reparse allowlist note at th…
BenKurrek f3f5f75
test(architecture): give the memory-vocabulary gate the partial-tree …
BenKurrek 77581e2
test(architecture): close the transport gate's nested-use-group fail-…
BenKurrek f614311
ci: delete check-e2e-matrix-files.sh — a gate for a workflow that no …
BenKurrek 42be139
ci: delete the measured-broken check-boundaries.sh and its guidance r…
BenKurrek 720101f
docs(product): stop hardcoding charter sub-owner counts in the family…
BenKurrek 58f05bd
test(architecture): correct the scanner-fixture file's name-filter claim
BenKurrek 488ac8e
docs(internal): gate & ratchet audit report + proposed preflight gaun…
BenKurrek e206c28
ci(planner): classify preflight-gates.sh and the deleted check-bounda…
BenKurrek d995a3d
docs(internal): add the fold-tripped asymmetric-tolerance exhibit to …
BenKurrek 1edbd01
test(architecture): give the contracts size ceiling upward working slack
BenKurrek 13b54a7
ci(budget): re-equalize composition pins to observed — restore the wo…
BenKurrek 480c8bf
docs(internal): record the landed zero-slack repairs in the audit report
BenKurrek 9dad9df
Merge origin/main: fold #7157's landed chain into the audit's repairs
BenKurrek e11be12
Merge origin/main: fold #7228's product_contracts raise into the merg…
BenKurrek c54aff1
Merge origin/main into booming-newsstand: union re-measure on the mer…
BenKurrek 028c902
gates: pin the ceiling-window arithmetic; fail preflight discovery cl…
BenKurrek edd719f
Merge origin/main into booming-newsstand: fold #7365's composition do…
BenKurrek File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
Run the enforcement-side route tests.
webui_v2_descriptors_contractchecks the declared policy table only. Addwebui_v2_handlers_contractand the composedwebui_v2_servetest, or narrow this condition to declaration-only changes. The exemplar identifies those tests as the enforcement-side coverage.As per path instructions, test through the caller when a helper gates a side effect.
🤖 Prompt for AI Agents
Source: Path instructions
📐 Maintainability & Code Quality | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: nearai/ironclaw
Length of output: 2099
🌐 Web query:
nearai ironclaw ".claude/skills/ironclaw-reborn-architecture-review/SKILL.md" clippy💡 Result:
The command
nearai ironclaw .claude/skills/ironclaw-reborn-architecture-review/SKILL.md clippyis a reference to a specific development workflow within the IronClaw project [1][2], an open-source, Rust-based Agent OS maintained by NEAR AI [1][3]. In this context, the command likely instructs an AI assistant or development tool to read and apply the architecture review guidelines contained in the.claude/skills/ironclaw-reborn-architecture-review/SKILL.mdfile while runningclippy(the Rust linter) on the codebase [4][5][6]. Key details regarding these components: * IronClaw: A rearchitected (v1.0+) agent runtime that separates decision-making from action execution [7][8]. Development now prioritizes code in thecrates/directory (the "Reborn" architecture) over the legacysrc/monolith [2][5]. * SKILL.md: Repository-specific agent skills are stored in.claude/skills/*/SKILL.md[5]. Theironclaw-reborn-architecture-reviewskill specifically provides guidance on maintaining architectural boundaries, abstractions, and re-exports when modifying or adding code to thecrates/directory [9][10][5]. * Clippy: The project usescargo clippyas its standard linting tool [11][6]. The repository includes aclippy.tomlfile that defines custom complexity guardrails (e.g.,cognitive-complexity-threshold,too-many-arguments-threshold) to ensure code quality in the new architecture [12]. The combined instruction suggests a task to verify code changes against both the project's high-level architectural standards (defined in the SKILL.md file) and its specific static analysis constraints (defined in clippy.toml) [9][12].Citations:
🌐 Web query:
site:github.com/nearai/ironclaw/blob/main/.claude/skills/ironclaw-reborn-architecture-review/SKILL.md "cargo clippy -p"💡 Result:
SKILL.mdcontains:It appears in the Verify section. [1] (github.com)
Citations:
🌐 Web query:
site:github.com/nearai/ironclaw/blob/main/AGENTS.md "default" "all-features" clippy💡 Result:
There is no single command called default all-features clippy. To run Clippy with all features enabled in a Rust project, use the command cargo clippy --all-features. This ensures that Clippy analyzes the code for all possible feature combinations defined in your Cargo.toml file. If you want to run Clippy while also including default features (which is the standard behavior when using --all-features), you do not need any additional flags.
Citations:
Add the default-feature Clippy lane.
When a change adds, moves, or relies on
#[cfg(feature = ...)], addcargo clippy -p <crate> --all-targets -- -D warningsalongside the existing all-features lane, as required byAGENTS.md.🤖 Prompt for AI Agents
Source: Coding guidelines