Skip to content

Install the packages the catalog already publishes - #7442

Merged
serrrfirat merged 7 commits into
mainfrom
codex/takeover-pr-7076
Aug 11, 2026
Merged

serrrfirat merged 7 commits into
mainfrom
codex/takeover-pr-7076

Conversation

@serrrfirat

Copy link
Copy Markdown
Collaborator

Supersedes #7076. The original implementation is by @neo-sky; this takeover preserves their authored commit and carries forward the review fixes from @serrrfirat.

Summary

  • Install every companion file published for an IronHub skill, with normalized-path validation, digest verification, aggregate size/count ceilings, bounded concurrency, and a bounded download barrier.
  • Add declarative HTTP Basic credential targets; the host composes RFC 7617 credentials at mediated egress while sandbox execution rejects the target.
  • Redact plaintext, encoded, and percent-encoded derived Basic authorization values from provider responses, and retain VAPID's collision-safe injection/redaction behavior from current main.
  • Rebase the focused work onto current main without the stale merge commits from Install the packages the catalog already publishes #7076.

Change Type

  • Bug fix
  • New feature
  • Refactor
  • Documentation
  • CI/Infrastructure
  • Security
  • Dependencies

Linked Issue

Related #7076. This replacement PR gives credit to @neo-sky and is intended to supersede the stale PR while using a same-repository branch for Railway preview deployment.

Validation

  • cargo fmt --all -- --check
  • cargo clippy --all --benches --tests --examples --all-features -- -D warnings (passed before the final rebase; the affected packages were rerun after rebase with --all-targets --all-features -D warnings)
  • cargo build (covered by the stricter Clippy builds and test builds)
  • Relevant tests pass: affected crate suites, sandbox plan tests, runtime HTTP egress contract, and the full architecture suite
  • cargo test -p <owning-crate> --features integration (not applicable: the affected crates do not expose a relevant database-backed integration feature)
  • Manual testing (not applicable: deterministic manager/runtime contract tests cover the changed seams)
  • Three-agent takeover audit covered intent, implementation, and regression/security risk before publication

Test Strategy

User behavior:

  • Installing an IronHub skill materializes every declared companion file only after path, digest, per-file, and aggregate validation.
  • Installing a tool with an HTTP Basic credential declaration persists its manifest while leaving account-mediated activation unchanged.
  • Runtime HTTP egress injects the host-composed Basic header without allowing reflected raw or percent-encoded credentials to escape redaction.

Risk areas:

  • Model behavior
  • Browser
  • Side effect
  • Persistence
  • Security or permissions
  • External provider
  • Cross-component behavior

Tests added or updated:

  • Unit or contract: bundle path/digest/count/size/concurrency behavior, Basic declaration validation, sandbox rejection, and host API wire round trips.
  • Reborn integration: Not added. Installation and egress are covered through separate production manager/runtime seams; the existing root integration harness does not currently connect an installed manifest directly to egress.
  • Recorded fixture: Not applicable: deterministic signed catalog responses and local runtime response fixtures cover this behavior without a recorded provider exchange.
  • Browser E2E: Not applicable: no WebUI behavior changes.
  • Backend or runtime: the runtime HTTP egress contract asserts collision handling and raw plus percent-encoded derived-secret redaction; the sandbox planner asserts Basic/VAPID rejection.
  • Live canary: Not applicable: no provider mutation or live credentials are needed to verify the deterministic install and injection paths.

What the tests prove:

  • Normalized duplicate destinations cannot overwrite one another, and files cannot escape the install root.
  • Companion downloads are bounded, ordered for installation, digest-verified, and subject to total count/size/time ceilings.
  • Basic authorization is composed only at host egress, cannot overwrite an existing header, and is redacted even when a response percent-encodes it.
  • Current-main VAPID behavior remains collision-safe and redacted after the rebase.

Commands run:

  • cargo fmt --all -- --check — pass after rebase.
  • cargo test -p ironclaw_host_api -p ironclaw_extension_contracts -p ironclaw_skills -p ironclaw_extension_manager — pass after rebase.
  • cargo test -p ironclaw_sandbox plan_tests:: — 17 passed after rebase.
  • cargo test -p ironclaw_host_runtime --test runtime_http_egress_contract — 83 passed after rebase.
  • cargo test -p ironclaw_architecture_tests — pass after rebase.
  • python3 scripts/ci/docs_publication_boundary.py — pass after rebase.
  • cargo clippy -p ironclaw_host_api -p ironclaw_extension_contracts -p ironclaw_skills -p ironclaw_extension_manager -p ironclaw_host_runtime -p ironclaw_sandbox --all-targets --all-features -- -D warnings — pass after rebase.
  • cargo clippy --all --benches --tests --examples --all-features -- -D warnings — pass before the final rebase onto current main.
  • bash scripts/reborn-e2e-rust.sh architecture-runtime — pass before the final rebase.
  • Full ironclaw_sandbox suite before rebase: 215 passed; 3 existing Docker-backed tests could not run because /var/run/docker.sock was absent. The focused 17-test planner suite passes after rebase.

Security Impact

Basic credentials remain host-side and are composed only at mediated runtime egress. The change registers derived base64 and complete Authorization values, including the redaction variants needed when a provider percent-encodes a reflected credential. Bundle paths are normalized before writes, duplicate destinations fail closed, and file/count/aggregate/time limits bound remote catalog input.

Reborn Trust-Boundary Checklist

  • Public policy/evidence/trust-bearing types: Basic is declarative manifest vocabulary; untrusted declarations pass the canonical validate_declaration boundary, while only host runtime code resolves and injects credentials.
  • Untrusted content enters prompts only through an envelope/escaping primitive. Not applicable to this change: no prompt construction changes.
  • Hashes declare purpose; SHA-256 verifies each catalog companion file and the aggregate artifact digest remains a content-integrity digest.
  • New/changed status, exit, policy, runtime, or error variants: all RuntimeCredentialTarget match sites were audited in contracts, host runtime, sandbox planner, and tests.
  • Security/durability serde(default) fields fail closed or have migration tests. The optional catalog files field preserves empty-list compatibility; every populated entry is fully validated before installation.
  • Queues/maps/buffers/counters have bounds and overflow-safe arithmetic. File count, per-file bytes, total bytes, concurrency, and barrier time are bounded; totals use checked arithmetic.
  • Driver/operator-visible errors have stable class semantics. Validation and download failures remain explicit manager/catalog errors and do not report successful installation.
  • Sandbox/native/host names accurately describe trust boundary. The sandbox planner rejects host-composed Basic and VAPID targets; native host egress owns composition.

Database Impact

None. No migration or schema change; existing package manifests without companion files and credential targets other than Basic keep their prior shape and behavior.

Blast Radius

IronHub catalog parsing/downloads, skill bundle installation, extension channel credential declarations, sandbox plan validation, and native runtime HTTP credential injection/redaction. Architecture ceilings move only for the new contract vocabulary: ironclaw_extension_contracts 7,851 → 7,858 and ironclaw_host_api 18,974 → 18,994.

Rollback Plan

Revert this PR. Existing packages without companion files and non-Basic credential targets retain their previous behavior, so rollback does not require a data migration.

Review Follow-Through

  • Original implementation credit remains with @neo-sky via commit authorship and this explicit attribution.
  • Review fixes from @serrrfirat are retained, including normalized-path collision rejection, deterministic bounded downloads, canonical declaration validation, header-collision rejection, and full derived-value redaction.
  • Reviewer judgment is welcome on whether a future root integration fixture should connect installed manifest state directly to runtime egress; this PR does not overstate the two existing crate-level production seams as one end-to-end test.
  • The original Install the packages the catalog already publishes #7076 is left open for its author/maintainers to close or redirect.

Review track: C (security/runtime behavior)

neo-sky and others added 5 commits August 10, 2026 15:46
Skills publish a files list for the scripts and assets they ship, but the catalog entry never deserialized it and the install path passed an empty bundle, so only SKILL.md landed. Files now install alongside it, digest-verified through the same download path and bounded by the limits ironclaw_skills already enforces, and they feed the skill artifact digest while a skill with no files keeps the digest it has today. Tools using HTTP Basic could not publish an extension manifest, so they listed and failed at install; the new basic target carries only the username and the host owns the join and the base64, with a colon or control character rejected at the host boundary, at the channel descriptor, and again at injection.
@railway-app

railway-app Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

🚅 Deployed to the ironclaw-pr-7442 environment in ironclaw-ci-preview

Service Status Web Updated (UTC)
ironclaw ✅ Success (View Logs) Web Aug 10, 2026 at 10:21 pm

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-7442 August 10, 2026 13:09 Destroyed
@coderabbitai

coderabbitai Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Summary by CodeRabbit

  • New Features

    • Skills can include multiple bundled files with verified downloads and bounded concurrency.
    • Added host-composed Basic authentication and expanded credential injection to JSON bodies and VAPID authorization.
    • Scoped skill installations now preserve supplied files.
  • Bug Fixes

    • Improved path normalization, collision detection, and safe bundle installation.
    • Added safeguards against invalid credentials and conflicting authorization headers.
    • Enhanced redaction for injected credentials.
  • Documentation

    • Updated credential and skill contract documentation.

Walkthrough

The PR adds validated host-composed Basic Authorization credentials and extends IronHub skill installation to support validated, verified, concurrently downloaded bundled files with rollback coverage.

Changes

Basic credential injection

Layer / File(s) Summary
Credential contracts and validation
crates/contracts/..., crates/lanes/..., docs/reborn/...
Adds RuntimeCredentialTarget::Basic, validates usernames, updates sandbox handling, and documents supported targets.
Basic injection and redaction
crates/kernel/ironclaw_host_runtime/...
Composes RFC 7617 credentials, rejects header collisions, zeroizes temporary buffers, and propagates redaction values. Tests cover invalid inputs and dispatch prevention.

Bundled skill installation

Layer / File(s) Summary
Bundle path normalization and installation API
crates/domains/ironclaw_skills/...
Exports path normalization, rejects duplicate normalized destinations, and forwards bundled files through scoped installation.
Bundle model, digest, and manifest validation
crates/extensions/ironclaw_extension_manager/src/ironhub/{model.rs,catalog.rs}
Adds bundled-file metadata, deterministic digests, path checks, collision checks, and count and size limits.
Concurrent download and materialization
crates/extensions/ironclaw_extension_manager/src/ironhub/service.rs, crates/extensions/ironclaw_extension_manager/Cargo.toml
Downloads and verifies bundled files with bounded concurrency and passes them through initial and replacement installation.
Bundle installation and rollback coverage
crates/extensions/ironclaw_extension_manager/src/ironhub/tests.rs
Covers validation boundaries, concurrency, checksum failures, materialization, credentialed manifests, and rollback restoration.

Estimated code review effort: 4 (Complex) | ~60 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Manifest
  participant HostRuntime
  participant Upstream
  Manifest->>HostRuntime: Declare Basic credential target
  HostRuntime->>HostRuntime: Validate and compose Authorization
  HostRuntime->>Upstream: Dispatch request with redacted credential handling
  Upstream-->>HostRuntime: Return response
Loading
sequenceDiagram
  participant IronHub
  participant ExtensionManager
  participant ScopedInstallation
  participant Filesystem
  IronHub->>ExtensionManager: Provide manifest and bundled files
  ExtensionManager->>ExtensionManager: Download and verify files
  ExtensionManager->>ScopedInstallation: Submit bundled installation files
  ScopedInstallation->>Filesystem: Materialize normalized paths
Loading

Possibly related PRs

Suggested reviewers: benkurrek

🚥 Pre-merge checks | ✅ 4
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly describes the main companion-file installation change, although it does not use the preferred Conventional Commits format.
Description check ✅ Passed The description follows the template and documents scope, validation, security, trust boundaries, database impact, blast radius, rollback, and review follow-through.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added scope: docs Documentation scope: dependencies Dependency updates size: XL 500+ changed lines risk: low Changes to docs, tests, or low-risk modules contributor: core 20+ merged PRs labels Aug 10, 2026
@ironloopai

ironloopai Bot commented Aug 10, 2026 •

Copy link
Copy Markdown
Contributor

🧭 IronLoop Run · Review

This comment updates in place as the Run moves through its stages.

🟩 Final result · Completed

🟨 Queued → 🟦 Working → 🟦 Posting results → 🟩 Completed

Automatic trigger · attempt 1 of 3 · completed in 28m

IronLoop completed the review and posted it to GitHub.

🔗 Result

Open submitted review →

Run details

Run: 353ff46b-31b1-42e1-9160-8ecab2c45d15
Base: main at 0f771d4
Head: codex/takeover-pr-7076 at 2fd57da
Created: 2026-08-10 13:10 UTC
Updated: 2026-08-10 13:38 UTC

@ironloopai ironloopai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 IronLoop review

Found an install-path validation defect and a contract-documentation inconsistency.

Findings: 🟠 Medium 1 · 🟡 Low 1

🟠 Medium · Reject file/directory bundle path collisions

Inline on crates/extensions/ironclaw_extension_manager/src/ironhub/catalog.rs:374. See the inline comment for details.

🟡 Low · Synchronize the host-runtime credential contract

The owning host-runtime contract still says only header, query, and path targets are supported and that body targets are out of scope. This change documents Basic, JSON-body, and VAPID targets elsewhere, leaving contradictory guidance for manifest and runtime consumers. Update the owning contract alongside this support.

Validation

  • ✅ Bundled-skill installation regression — The focused bounded companion-download and installation test passed.
  • ✅ Basic credential egress regression — The focused Basic composition and response-redaction test passed.
  • ✅ Architecture boundary suite — The repository architecture test suite passed.
Review details
  • Run: 353ff46b-31b1-42e1-9160-8ecab2c45d15
  • Workflow: Review
  • Attempts: 1

)));
}
};
if !bundle_destinations.insert(destination) {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 IronLoop review · Inline finding

🟠 Medium · Reject file/directory bundle path collisions

The set only rejects equal normalized paths. A signed companion such as `SKILL.md/helper` or `.ironclaw-install.json/helper` passes validation, creates a directory where the generated primary file/sidecar must be written, and makes installation fail later. Likewise, `scripts` plus `scripts/run.py` passes validation. Reject ancestor/descendant destination collisions before download and installation.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in 10ab7c9e81: catalog validation now rejects normalized ancestor/descendant destinations, including collisions beneath generated SKILL.md and .ironclaw-install.json, before artifact downloads.
Verification: regression test plus the full ironclaw_extension_manager suite (155 tests), runtime HTTP egress contract (83 tests), architecture suite, formatting, and zero-warning clippy.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed across 10ab7c9e81 and f027bef5ef: the catalog rejects generated-file and ancestor/descendant collisions before download, and the owning skills-domain validator now enforces the same invariant through the public scoped install path before filesystem writes.
Verification: ironclaw_skills (187 tests), ironclaw_extension_manager (155 tests), architecture suite, formatting, and zero-warning clippy.

@serrrfirat

serrrfirat commented Aug 10, 2026 •

Copy link
Copy Markdown
Collaborator Author

Railway preview QA — PASS

Given / When / Then matrix

Acceptance Intended contract Actual contract exercised Evidence Result
Required Given the signed IronHub entry for presentation-generation declares assets/near-presentation-template.html, when the user installs that exact skill, then the bundle installs successfully and remains installed on read-back. Natural-language /chat journey discovered the exact catalog entry and invoked the visible ironhub_install activity for presentation-generation v0.1.0. Installation rendered lifecycle.phase = "installed" with artifact digest sha256:eb8e43021535a16729d85ec331efd607b4d5f79579f54d3d9585f45635447e3d. After refresh, an installed-skills read-back reported presentation-generation present at /skills/presentation-generation, version 0.1.0. PASS
Required Given the Wazuh package declares HTTP Basic credential targets, when installed without credentials, then the manifest persists without activating and the UI exposes the credential blocker. Visible /extensions/registry Wazuh card → Install. No credentials were entered. Wazuh moved from AVAILABLE to FINISH SETUP, rendered two credential fields, and remained FINISH SETUP after refresh. PASS
Supplemental The corrected companion artifact is live and matches the signed catalog metadata. Direct read-only probe of the signed catalog artifact before browser QA. HTTP 200, 10,137 bytes, SHA-256 840a839c1f145351401cae9ddc916140935711a811bb6bb1bab873b93b492dd8; size and digest both matched. PASS
Supplemental The preview serves the exact PR head. Commit-scoped Railway status/check query. Railway reported success for head 2fd57da5736db8aef4efa51da493a065b1a7de13; frontend asset assets/app-DYvnwsw7.js. PASS

Status derivation

  • Required passed: 2
  • Required failed: 0
  • Required blocked/not executed: 0
  • Overall: PASS

Regression result

The previously failing companion-skill case is fixed. The live signed catalog now references a provider-safe path-addressed release asset, the exact artifact downloads with matching size and digest, and presentation-generation installs and survives installed-state read-back through the deployed PR.

Directly naming deferred IronHub capabilities in an initial chat turn produced an unavailable response, so that attempt was not credited. The normal user journey then discovered and invoked the exact ironhub_install activity successfully; no substitute provider or package was used.

Skipped / remaining risk

  • A live Wazuh HTTP request was not attempted because the preview has no Wazuh endpoints or credentials. This is a live-provider canary rather than the installation regression; the browser run verified that the Basic declarations persist and correctly block activation pending credentials.
  • Runtime Basic header composition and reflected-secret redaction remain covered by the PR's deterministic runtime contract tests rather than this credential-free Railway preview.

Cleanup

  • Removed test-installed presentation-generation; installed-skills read-back confirmed it was absent and the count returned from 33 to 32.
  • Removed test-installed Wazuh; registry read-back confirmed it returned to AVAILABLE.
  • Deleted all three QA conversations created by this run; sidebar returned to No conversations yet.
  • Browser tabs finalized best effort.

@serrrfirat

Copy link
Copy Markdown
Collaborator Author

Railway QA root cause: the IronHub signed catalog URL for the presentation-generation companion file used a ~-encoded nested path, but GitHub normalized the uploaded release asset name. The installer correctly rejected the unavailable signed URL; this is upstream release-packaging, not an Ironclaw installer defect.

Fix opened with regression coverage: nearai/ironhub#276. After that PR is merged and the signed IronHub catalog is republished, I will rerun the exact builtin.ironhub_install skill case against this PR preview.

@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-7442 August 10, 2026 21:33 Destroyed

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
crates/domains/ironclaw_skills/src/management/install_bundle.rs (1)

399-420: 🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win

Duplicate detection covers only exact normalized equality; ancestor/descendant destinations still pass the domain validator.

destinations is a BTreeSet<String> and the check is !destinations.insert(destination). A bundle containing scripts and scripts/run.py, or SKILL.md/helper, passes validate_install_bundle_files. The catalog layer in crates/extensions/ironclaw_extension_manager/src/ironhub/catalog.rs now rejects those, but this crate owns the install-bundle contract and install_from_url_for_scope is public API reachable by other callers. Move the ancestor/descendant rejection here so validation fails before any write, and keep the catalog check as a fast pre-download gate.

Confirm no equivalent check already lives in the unshown ranges of this file before applying.

#!/bin/bash
# Description: Check whether install_bundle.rs already rejects ancestor/descendant destinations,
# and enumerate all callers of the bundle install path.
set -euo pipefail

fd -t f 'install_bundle.rs' crates/domains/ironclaw_skills | while IFS= read -r f; do
  echo "== $f =="
  rg -n 'strip_prefix|starts_with|BTreeSet|destinations|SKILL_FILE_NAME|INSTALL_METADATA_FILE_NAME' "$f"
done

echo "== callers of validate_install_bundle_files / SkillInstallRequest.files =="
rg -nP --type=rust -C3 '\bvalidate_install_bundle_files\s*\(|files\s*:\s*&' crates/domains/ironclaw_skills

echo "== external callers of install_from_url_for_scope =="
rg -nP --type=rust -C3 '\binstall_from_url_for_scope\s*\(' crates
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@crates/domains/ironclaw_skills/src/management/install_bundle.rs` around lines
399 - 420, Update validate_install_bundle_files around the destinations BTreeSet
check to reject any destination that is an ancestor or descendant of another
normalized path, not only exact duplicates, before installation writes occur.
First verify the unshown portions of install_bundle.rs do not already provide
equivalent validation; preserve the catalog’s existing pre-download check and
ensure install_from_url_for_scope callers receive the domain validation error.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@crates/extensions/ironclaw_extension_manager/src/ironhub/catalog.rs`:
- Around line 356-359: In the bundle destination initialization, replace the
hardcoded "SKILL.md" entry with the publicly exported
ironclaw_skills::SKILL_FILE_NAME constant, while retaining
INSTALL_METADATA_FILE_NAME unchanged.

In `@crates/extensions/ironclaw_extension_manager/src/ironhub/tests.rs`:
- Around line 1368-1370: Update the test fixture setup around skill_file_size
and skill_file_sha to bind skill_file_size to expected_bundled_file.len(), and
add an assertion that expected_bundled_file and tampered_bundled_file have equal
lengths so the test remains focused on checksum verification.

---

Outside diff comments:
In `@crates/domains/ironclaw_skills/src/management/install_bundle.rs`:
- Around line 399-420: Update validate_install_bundle_files around the
destinations BTreeSet check to reject any destination that is an ancestor or
descendant of another normalized path, not only exact duplicates, before
installation writes occur. First verify the unshown portions of
install_bundle.rs do not already provide equivalent validation; preserve the
catalog’s existing pre-download check and ensure install_from_url_for_scope
callers receive the domain validation error.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 67a633f7-d1ad-41e3-a326-1b474e2d93da

📥 Commits

Reviewing files that changed from the base of the PR and between 0f646ed and 10ab7c9.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock, !**/Cargo.lock
📒 Files selected for processing (20)
  • crates/app/ironclaw_architecture_tests/tests/reborn_dependency_boundaries.rs
  • crates/contracts/ironclaw_extension_contracts/src/channel.rs
  • crates/contracts/ironclaw_host_api/src/http.rs
  • crates/contracts/ironclaw_host_api/tests/host_api_contract.rs
  • crates/domains/ironclaw_skills/src/lib.rs
  • crates/domains/ironclaw_skills/src/management.rs
  • crates/domains/ironclaw_skills/src/management/install_bundle.rs
  • crates/domains/ironclaw_skills/src/scoped_management.rs
  • crates/extensions/ironclaw_extension_manager/Cargo.toml
  • crates/extensions/ironclaw_extension_manager/src/ironhub/catalog.rs
  • crates/extensions/ironclaw_extension_manager/src/ironhub/model.rs
  • crates/extensions/ironclaw_extension_manager/src/ironhub/service.rs
  • crates/extensions/ironclaw_extension_manager/src/ironhub/tests.rs
  • crates/kernel/ironclaw_host_runtime/src/egress/credential.rs
  • crates/kernel/ironclaw_host_runtime/tests/runtime_http_egress_contract.rs
  • crates/lanes/ironclaw_sandbox/src/plan.rs
  • crates/lanes/ironclaw_sandbox/src/plan_tests.rs
  • docs/reborn/contracts/extensions.md
  • docs/reborn/contracts/host-runtime.md
  • docs/reborn/contracts/secrets.md

Comment thread crates/extensions/ironclaw_extension_manager/src/ironhub/catalog.rs
Comment thread crates/extensions/ironclaw_extension_manager/src/ironhub/tests.rs
@railway-app
railway-app Bot temporarily deployed to ironclaw-ci-preview / ironclaw-pr-7442 August 10, 2026 22:13 Destroyed

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
crates/domains/ironclaw_skills/src/management/install_bundle.rs (1)

30-39: 🗄️ Data Integrity & Integration | 🟠 Major | 🏗️ Heavy lift

Replace the raw bundle-path contract with a validated domain type.

normalize_install_bundle_relative_path returns String, while SkillInstallFile retains relative_path: &str. The catalog validates one string value, but the scoped installation contract still transports raw paths. Use one validated InstallBundleRelativePath newtype and construct it at the manifest boundary. Make SkillInstallFile carry that type.

  • crates/domains/ironclaw_skills/src/management/install_bundle.rs#L30-L39: define the validated path newtype with the canonical template and replace SkillInstallFile.relative_path.
  • crates/domains/ironclaw_skills/src/lib.rs#L70-L76: re-export the typed path API.
  • crates/domains/ironclaw_skills/src/management.rs#L24-L30: re-export the typed path API from the contract owner.
  • crates/domains/ironclaw_skills/src/scoped_management.rs#L194-L208: accept typed bundle-file paths through the scoped installation boundary.
  • crates/extensions/ironclaw_extension_manager/src/ironhub/catalog.rs#L360-L392: convert manifest paths once at the external boundary and use typed destinations for collision checks.

As per coding guidelines, “Do not pass raw String, &str, uuid::Uuid, booleans, or magic strings between internal modules.”

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@crates/domains/ironclaw_skills/src/management/install_bundle.rs` around lines
30 - 39, Replace the raw bundle-path contract with a validated
InstallBundleRelativePath newtype using the canonical normalization template,
and make SkillInstallFile.relative_path carry it. In
crates/domains/ironclaw_skills/src/management/install_bundle.rs#L30-L39, define
the type and construct it through validation; re-export its API in
crates/domains/ironclaw_skills/src/lib.rs#L70-L76 and
crates/domains/ironclaw_skills/src/management.rs#L24-L30. Update
crates/domains/ironclaw_skills/src/scoped_management.rs#L194-L208 to accept
typed paths, and in
crates/extensions/ironclaw_extension_manager/src/ironhub/catalog.rs#L360-L392
convert manifest paths once at the boundary and use the validated type for
collision checks.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@crates/domains/ironclaw_skills/src/management/install_bundle.rs`:
- Around line 30-39: Replace the raw bundle-path contract with a validated
InstallBundleRelativePath newtype using the canonical normalization template,
and make SkillInstallFile.relative_path carry it. In
crates/domains/ironclaw_skills/src/management/install_bundle.rs#L30-L39, define
the type and construct it through validation; re-export its API in
crates/domains/ironclaw_skills/src/lib.rs#L70-L76 and
crates/domains/ironclaw_skills/src/management.rs#L24-L30. Update
crates/domains/ironclaw_skills/src/scoped_management.rs#L194-L208 to accept
typed paths, and in
crates/extensions/ironclaw_extension_manager/src/ironhub/catalog.rs#L360-L392
convert manifest paths once at the boundary and use the validated type for
collision checks.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: e2b38f4b-2aa1-42f3-8d47-432b992fa620

📥 Commits

Reviewing files that changed from the base of the PR and between 10ab7c9 and f027bef.

📒 Files selected for processing (6)
  • crates/domains/ironclaw_skills/src/lib.rs
  • crates/domains/ironclaw_skills/src/management.rs
  • crates/domains/ironclaw_skills/src/management/install_bundle.rs
  • crates/domains/ironclaw_skills/src/scoped_management.rs
  • crates/extensions/ironclaw_extension_manager/src/ironhub/catalog.rs
  • crates/extensions/ironclaw_extension_manager/src/ironhub/tests.rs

@serrrfirat
serrrfirat added this pull request to the merge queue Aug 11, 2026
Merged via the queue into main with commit 2b87cf5 Aug 11, 2026
53 checks passed
@serrrfirat
serrrfirat deleted the codex/takeover-pr-7076 branch August 11, 2026 10:09
l3ocifer pushed a commit to l3ocifer/frick-ironclaw that referenced this pull request Sep 3, 2026
* Install the packages the catalog already publishes

Skills publish a files list for the scripts and assets they ship, but the catalog entry never deserialized it and the install path passed an empty bundle, so only SKILL.md landed. Files now install alongside it, digest-verified through the same download path and bounded by the limits ironclaw_skills already enforces, and they feed the skill artifact digest while a skill with no files keeps the digest it has today. Tools using HTTP Basic could not publish an extension manifest, so they listed and failed at install; the new basic target carries only the username and the host owns the join and the base64, with a colon or control character rejected at the host boundary, at the channel descriptor, and again at injection.

* fix(ironhub): address package install review findings (nearai#7076)

* fix(ironhub): address review round — header-collision rejection, constant-derived caps, egress contract tests (nearai#7076)

* refactor(skills): drop unused validate_install_bundle_relative_path wrapper (nearai#7076)

* fix(runtime): harden derived credential redaction (nearai#7076)

* fix(skills): reject bundle path collisions at domain boundary

---------

Co-authored-by: neo-sky <brandon.m.henderson93@gmail.com>

This branch was successfully deployed

No deployments
ironclaw-ci-preview / ironclaw-pr-7442 — f027bef5 Deployed Aug 10, 2026 by railway-app[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: core 20+ merged PRs risk: low Changes to docs, tests, or low-risk modules scope: dependencies Dependency updates scope: docs Documentation size: XL 500+ changed lines

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants