Skip to content

chore: promote staging to main (2026-03-10 05:21 UTC) - #830

Merged
henrypark133 merged 2 commits into
mainfrom
staging-promote/3a2989d0-22888378864
Mar 10, 2026
Merged

henrypark133 merged 2 commits into
mainfrom
staging-promote/3a2989d0-22888378864

Conversation

@ironclaw-ci

@ironclaw-ci ironclaw-ci Bot commented Mar 10, 2026

Copy link
Copy Markdown
Contributor

Auto-promotion from staging CI

Batch range: a868b1422119932a695d787e3fbe176ce97d84f6..3a2989d009c58d12bfaae52b9b1052f82bf07443
Promotion branch: staging-promote/3a2989d0-22888378864
Base: staging-promote/a868b142-22886164216
Triggered by: Staging CI batch at 2026-03-10 05:21 UTC

Waiting for gates:

  • Tests: pending
  • E2E: pending
  • Claude Code review: pending (will post comments on this PR)

Auto-created by staging-ci workflow

ilblackdragon and others added 2 commits March 10, 2026 04:39
* refactor: encapsulate leaked abstractions from main.rs and app.rs into owning modules

Move module-specific initialization logic out of main.rs (1222→665 lines, -46%) and
app.rs (944→780 lines, -17%) into their respective owning modules as public factory
functions. This enforces separation of concerns so that adding a new DB backend, MCP
transport, or channel doesn't require editing main.rs/app.rs.

Key changes:
- Tracing init functions → src/tracing_fmt.rs
- DB connection factory (connect_with_handles + DatabaseHandles) → src/db/mod.rs
- Secrets store factory (create_secrets_store) → src/secrets/mod.rs
- MCP transport dispatch factory (create_client_from_config) → src/tools/mcp/factory.rs
- Orchestrator setup (setup_orchestrator + OrchestratorSetup) → src/orchestrator/mod.rs
- WASM channel setup (setup_wasm_channels) → src/channels/wasm/setup.rs
- Worker entry points (run_worker, run_claude_bridge) → src/worker/mod.rs
- Shared CLI secrets init (init_secrets_store) → src/cli/mod.rs
- Tunnel startup (start_managed_tunnel) → src/tunnel/mod.rs
- Onboard check (check_onboard_needed) → src/setup/mod.rs
- ExtensionManager unified MCP: uses create_client_from_config via McpProcessManager,
  enabling stdio/Unix transports for hot-activated MCP servers
- Deduplicated ~130 lines of secrets store init across cli/mcp.rs and cli/tool.rs
- CLAUDE.md updated with module-owned initialization guideline

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* refactor: address review feedback — deduplicate db factory, extract channel helper

- connect_from_config() now delegates to connect_with_handles() to eliminate
  duplicated backend-matching logic (Copilot review feedback)
- Extract register_channel() helper from setup_wasm_channels() loop body
  to improve readability (Gemini review feedback)

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* style: fix rustfmt line wrapping in setup_wasm_channels

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* test: add integration test for module-owned initialization factories

Exercises the full factory chain end-to-end to verify nothing was lost
when initialization logic was moved from main.rs/app.rs into owning modules:

- connect_with_handles returns Database + populated backend handles
- connect_from_config delegates correctly (produces working Database)
- secrets::create_secrets_store builds working store from DatabaseHandles
- db::create_secrets_store standalone factory round-trips secrets
- Both secrets factories produce compatible stores (cross-read works)
- ExtensionManager constructs with McpProcessManager and is functional
- DatabaseHandles default is empty

All tests run without external services using libsql in-memory/tempfile.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: wire cli/mcp.rs and cli/tool.rs to shared init_secrets_store()

Both files had inline implementations identical to cli::init_secrets_store().
Replace with delegation to complete the claimed deduplication.

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* style: fix rustfmt line wrapping in integration test

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(review): remove unused Config import and deduplicate Error Handling section

- Remove `#[allow(unused_imports)]` and unused `use crate::config::Config`
  from cli/tool.rs (no longer needed after delegating to shared
  `cli::init_secrets_store()`)
- Remove duplicate Error Handling subsection from CLAUDE.md Key Patterns
  (all four bullets already exist in Code Style section and
  review-discipline.md)

Addresses Copilot review comments.

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(review): address remaining Copilot review comments

- secrets/mod.rs: clarify docstring that None is a normal no-db condition
- app.rs: add comment explaining the empty_handles fallback path
- orchestrator/mod.rs: combine duplicated sandbox condition into single block
- setup/mod.rs: document env var reads and thread-safety caveat

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
Co-authored-by: Henry Park <henrypark133@gmail.com>
…ing (#821)

* feat(setup): quick onboarding, preserve .env vars, clean up boot logging (#751, #674)

- Add upsert_bootstrap_vars() to preserve user-added .env vars on re-onboarding
- Add --quick mode: auto-defaults DB + security, asks only LLM provider (2 steps)
- Auto-triggered onboarding uses quick mode for near-instant first run
- Fix NEAR AI model fetch to use cloud-api.near.ai when API key is set
- Handle missing WASM tools/channels directories gracefully
- Downgrade all boot/shutdown tracing::info! to debug (boot screen shows user output)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(setup): gate env_backend variable behind postgres feature flag [skip-regression-check]

Clippy lint fix — not a behavioral change, just moving a variable declaration
inside the cfg(feature = "postgres") block where it's used.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(review): address PR review comments

- WASM loaders: use tokio::fs::metadata, only treat NotFound as empty,
  propagate other IO errors, handle TOCTOU in read_dir
- bootstrap: only ignore NotFound in read_to_string, propagate other errors
- wizard: restore print_info/print_success for migrations in interactive
  mode (gated by !config.quick), keep tracing::debug for diagnostics
- tests: use shared crate::config::helpers::ENV_MUTEX instead of separate
  NEARAI_ENV_MUTEX to prevent cross-test env var races
- README: fix quick mode description to mention model selection, clarify
  auto_setup_database may prompt when DATABASE_URL is set

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* feat(setup): skip prompts for DATABASE_URL in quick mode [skip-regression-check]

auto_setup_database() now uses DATABASE_URL directly without calling
step_database_postgres() (which prompts for confirmation). Quick mode
should be fully non-interactive when env vars are already set.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix(cli): update --quick help text to mention model selection [skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
@github-actions github-actions Bot added scope: agent Agent core (agent loop, router, scheduler) scope: channel Channel infrastructure scope: channel/cli TUI / CLI channel scope: channel/web Web gateway channel scope: channel/wasm WASM channel runtime scope: tool Tool infrastructure scope: tool/builtin Built-in tools scope: tool/wasm WASM tool sandbox scope: tool/mcp MCP client scope: db Database trait / abstraction scope: llm LLM integration scope: orchestrator Container orchestrator scope: worker Container worker scope: secrets Secrets management scope: extensions Extension management scope: setup Onboarding / setup scope: sandbox Docker sandbox scope: docs Documentation size: XL 500+ changed lines risk: high Safety, secrets, auth, or critical infrastructure contributor: new First-time contributor labels Mar 10, 2026
@claude

claude Bot commented Mar 10, 2026

Copy link
Copy Markdown

Code review

No issues found.

@claude

claude Bot commented Mar 10, 2026

Copy link
Copy Markdown

Update: Bug scan review complete.

Found 1 minor issue:

[LOW:50] Empty DatabaseHandles fallback may silently skip secrets store initialization (src/app.rs ~line 288)

The code creates an empty DatabaseHandles as a fallback when database initialization returns early. This causes create_secrets_store() to return None, which gracefully skips credential injection. While this is intentional design for no-database scenarios, adding a debug log when this fallback path is taken would improve observability.

@claude

claude Bot commented Mar 10, 2026

Copy link
Copy Markdown

Code Review - Performance & Production Issues

Found 8 production readiness issues:

  1. [CRITICAL:95] Unwrap calls in production code (src/bootstrap.rs:598, src/channels/wasm/setup.rs:779,782)
    Panics on error instead of graceful handling. Violates CLAUDE.md guideline: no .unwrap()/.expect() in production.

  2. [HIGH:85] N+1 query anti-pattern in secrets (src/channels/wasm/setup.rs:1073-1087)
    Calls secrets.list() then secrets.get_decrypted() for each secret. O(n) queries instead of O(1).

  3. [HIGH:80] Unbounded memory allocation for secrets (src/channels/wasm/setup.rs:1074)
    secrets.list() loads all secrets without pagination or limits. No backpressure handling.

  4. [HIGH:75] Spawned orchestrator task without error handling (src/orchestrator/mod.rs:2572-2576)
    Task startup errors silently logged, no recovery mechanism or handle tracking.

  5. [MEDIUM:70] Sync mutex in async test context (src/config/mod.rs:3081,3102,3121)
    ENV_MUTEX.lock().unwrap() in async tests risks deadlock. Should use async-safe locking.

  6. [MEDIUM:65] String allocations in credential loop (src/channels/wasm/setup.rs:1099,1109,1133)
    .to_uppercase() and .to_string() called per credential. Optimize with Cow or cached strings.

  7. [MEDIUM:60] Fixed-size broadcast channel without backpressure (src/orchestrator/mod.rs:2543)
    Capacity 256 with no indication of dropped events. Risk of silent message loss.

  8. [LOW:50] Unbounded iteration over secrets (src/channels/wasm/setup.rs:1082-1112)
    Linear memory growth with secret count. Consider adding iteration limits for large secret stores.

@claude

claude Bot commented Mar 10, 2026

Copy link
Copy Markdown

Code Review - Clarification

Correction to performance review: The unwrap calls identified are actually in test code (marked with #[test]), not production code. The Security & Safety review correctly identified this.

Verified production issues remaining:

  1. [HIGH:85] N+1 query anti-pattern in secrets (src/channels/wasm/setup.rs)

    • secrets.list() + per-secret get_decrypted() calls. O(n) instead of O(1)
  2. [HIGH:80] Unbounded memory in secrets list (src/channels/wasm/setup.rs)

    • No pagination/limits on secrets.list(). Risk with large secret stores
  3. [HIGH:75] Spawned orchestrator task without error handling (src/orchestrator/mod.rs)

    • Startup errors silently logged, no recovery mechanism
  4. [MEDIUM:70] Sync mutex in async test context (src/config/mod.rs)

    • ENV_MUTEX deadlock risk in async tests
  5. [MEDIUM:65] String allocations in credential loop (src/channels/wasm/setup.rs)

    • .to_uppercase() and .to_string() per credential
  6. [MEDIUM:60] Broadcast channel without backpressure (src/orchestrator/mod.rs)

    • Fixed capacity 256, no indication of dropped events
  7. [LOW:50] Unbounded iteration over secrets (src/channels/wasm/setup.rs)

    • Linear growth with secret count

Base automatically changed from staging-promote/a868b142-22886164216 to main March 10, 2026 20:22
@henrypark133
henrypark133 merged commit 8c094ae into main Mar 10, 2026
99 of 100 checks passed
@henrypark133
henrypark133 deleted the staging-promote/3a2989d0-22888378864 branch March 10, 2026 21:14
@github-actions github-actions Bot mentioned this pull request Mar 10, 2026
bkutasi pushed a commit to bkutasi/ironclaw that referenced this pull request Mar 28, 2026
…888378864

chore: promote staging to main (2026-03-10 05:21 UTC)
drchirag1991 pushed a commit to drchirag1991/ironclaw that referenced this pull request Apr 8, 2026
…888378864

chore: promote staging to main (2026-03-10 05:21 UTC)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: new First-time contributor risk: high Safety, secrets, auth, or critical infrastructure scope: agent Agent core (agent loop, router, scheduler) scope: channel/cli TUI / CLI channel scope: channel/wasm WASM channel runtime scope: channel/web Web gateway channel scope: channel Channel infrastructure scope: db Database trait / abstraction scope: docs Documentation scope: extensions Extension management scope: llm LLM integration scope: orchestrator Container orchestrator scope: sandbox Docker sandbox scope: secrets Secrets management scope: setup Onboarding / setup scope: tool/builtin Built-in tools scope: tool/mcp MCP client scope: tool/wasm WASM tool sandbox scope: tool Tool infrastructure scope: worker Container worker size: XL 500+ changed lines staging-promotion

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants