Skip to content

chore: promote staging to main (2026-03-11 03:47 UTC) - #917

Merged
henrypark133 merged 11 commits into
mainfrom
staging-promote/369741fc-22935740447
Mar 11, 2026
Merged

henrypark133 merged 11 commits into
mainfrom
staging-promote/369741fc-22935740447

Conversation

@ironclaw-ci

@ironclaw-ci ironclaw-ci Bot commented Mar 11, 2026

Copy link
Copy Markdown
Contributor

Auto-promotion from staging CI

Batch range: 55b5a462a2d2056cebc8cb4dec1680bff925e01a..369741fc60bf4ec1a28445c23d99db4a7f9c04c3
Promotion branch: staging-promote/369741fc-22935740447
Base: staging-promote/55b5a462-22934480277
Triggered by: Staging CI batch at 2026-03-11 03:47 UTC

Waiting for gates:

  • Tests: pending
  • E2E: pending
  • Claude Code review: pending (will post comments on this PR)

Auto-created by staging-ci workflow

* Add generic host-verified webhook ingress for tools

* Stabilize trace E2E test rig and approval behavior

* Fix webhook security issues from review feedback

- Reject tools without webhook_capability() (was unauthenticated RCE)
- Remove secret-in-query-string fallback (leak via logs/referrers)
- Require approval for event_emit tool (escalation via routine triggers)
- Simplify header_value() (HeaderMap already case-insensitive)
- Redact internal errors from webhook HTTP responses
- Remove unused hmac_timestamp_tolerance_secs field
- Add regression test for tool without webhook capability

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Harden webhook ingress: require auth mechanism, body limit layer, health check

- Reject webhook capabilities that declare no auth mechanism (empty
  WebhookCapability would previously allow unauthenticated access)
- Add DefaultBodyLimit layer to reject oversized payloads before buffering
- Health check (GET) now verifies tool has webhook_capability(), not just
  existence
- Add regression tests for all three fixes

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* Fix auto_approve_tools inconsistency between dispatcher and thread_ops

dispatcher.rs skips all approval checks (including Always) when
auto_approve_tools is true, but thread_ops.rs still required approval
for Always tools. This caused deferred tool calls to unexpectedly halt
in test rigs and auto-approve configurations.

Match dispatcher behavior: short-circuit all approval when
auto_approve_tools is enabled.

[skip-regression-check]

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
@github-actions github-actions Bot added scope: agent Agent core (agent loop, router, scheduler) scope: channel/web Web gateway channel scope: channel/wasm WASM channel runtime scope: tool Tool infrastructure scope: tool/wasm WASM tool sandbox scope: docs Documentation size: XL 500+ changed lines risk: medium Business logic, config, or moderate-risk modules contributor: experienced 6-19 merged PRs labels Mar 11, 2026
@claude

claude Bot commented Mar 11, 2026

Copy link
Copy Markdown

Code review

Found 6 issues:

  1. [MEDIUM:75] Tool trait method returns WASM-specific type, creating circular dependency

The webhook_capability() method in the Tool trait returns Option<crate::tools::wasm::WebhookCapability>, forcing core tool infrastructure to depend on WASM-specific types. This violates CLAUDE.md: "Prefer generic/extensible architectures over hardcoding specific integrations."

https://github.com/anthropics/ironclaw/blob/486e417/src/tools/tool.rs#L335-L337

  1. [MEDIUM:65] Header names hardcoded as strings with inconsistent defaults

Webhook signature header names are Option<String> fields with defaults scattered across src/webhooks/mod.rs. Multiple code paths produce different defaults.

https://github.com/anthropics/ironclaw/blob/486e417/src/tools/wasm/capabilities.rs#L258-L273

  1. [LOW:60] Empty webhook capability configs pass parse-time validation

Schema allows all webhook fields to be None, validating only at runtime. Should fail at parse time (fail-fast principle).

https://github.com/anthropics/ironclaw/blob/486e417/src/tools/wasm/capabilities_schema.rs#L335-L358

  1. [LOW:55] Late-binding shared routine engine slot creates potential race condition

shared_routine_engine_slot is created empty and lazily populated by the agent task. If a webhook request arrives before population, it returns 503.

https://github.com/anthropics/ironclaw/blob/486e417/src/main.rs#L281-L284

  1. [LOW:50] No startup validation for secrets store availability

If webhook routes are registered but secrets store wasn't injected, requests fail at runtime. Should be caught at server startup.

https://github.com/anthropics/ironclaw/blob/486e417/src/webhooks/mod.rs#L712-L714

  1. [LOW:50] Incomplete error context in webhook error handling

Tool webhook errors lack context about what the tool actually returned.

https://github.com/anthropics/ironclaw/blob/486e417/src/webhooks/mod.rs#L640-L650

Green lights: ✓ Constant-time signature verification ✓ No .unwrap() in production code ✓ Comprehensive test coverage ✓ Good separation of concerns ✓ Proper async/Arc usage

@claude

claude Bot commented Mar 11, 2026

Copy link
Copy Markdown

Bug Scan Update:

Found one issue worth investigating:

[LOW:60] Test assertion weakened without explanation

In tests/e2e_advanced_traces.rs, the max tool iterations test assertion was changed from <= 4 to <= 8 while the test comment still states max_tool_iterations=3. Doubling the allowed tool calls could indicate:

  • Legitimate behavioral change (agent now makes more calls)
  • Test being weakened to mask a regression
  • Copy-paste error

https://github.com/anthropics/ironclaw/blob/486e417/tests/e2e_advanced_traces.rs#L1202-L1206

This should be clarified in the PR description or git history.

@claude

claude Bot commented Mar 11, 2026

Copy link
Copy Markdown

Performance & Production Review Update:

Found 2 MEDIUM severity performance/security issues:

[MEDIUM:70] Unbounded query parameters allow potential DoS attacks

Query parameters are collected into HashMap with no size limits. A malicious client could send thousands of query parameters to cause memory exhaustion.

https://github.com/anthropics/ironclaw/blob/486e417/src/webhooks/mod.rs#L99-L122

Recommend: Add query parameter count/size validation in webhook handlers.

[MEDIUM:68] Inefficient header HashMap allocation in hot path

On every webhook request, all HTTP headers are converted to HashMap by cloning both keys and values to Strings (2 allocations per header). For typical webhooks with 25-50 headers, this could be 50-100+ allocations per request.

https://github.com/anthropics/ironclaw/blob/486e417/src/webhooks/mod.rs#L157-L164

Recommend: Use references or BTreeMap, or defer HashMap creation until actually needed by the tool.

Additional LOW-severity findings:

  • Unnecessary Arc clone of routine engine on every webhook
  • String clones in error messages (should use &'static str)
  • Unnecessary UTF-8 lossy conversion for request body

Overall: Good async/await patterns, proper timeouts and body limits. Production-ready with optimizations noted above.

@claude

claude Bot commented Mar 11, 2026

Copy link
Copy Markdown

Security & Safety Review Update:

Found 2 MEDIUM severity security issues that should be addressed before merge:

[MEDIUM:85] Information disclosure via secret names in error messages

Error messages reveal which secrets are configured (e.g., 'Missing webhook secret github_webhook_secret'). Attackers can learn the naming convention and integrated services.

https://github.com/anthropics/ironclaw/blob/486e417/src/webhooks/mod.rs#L281-L323

Recommend: Return generic 'Authentication failed' messages. Log secret names internally only.

[MEDIUM:75] Potential timing side-channel in fallback header lookup

Header fallback lookup has variable timing before constant-time comparison. Attackers could measure response times to determine which header names are configured.

https://github.com/anthropics/ironclaw/blob/486e417/src/webhooks/mod.rs#L284-L292

Recommend: Always attempt both header lookups with constant timing.

Additional LOW-severity findings:

  • Timestamp validation accepts zero if system clock before UNIX_EPOCH (bypass replay protection)
  • No validation that retrieved secrets don't exceed maximum length (DoS risk)
  • Inconsistent HTTP status codes (401 vs 404) could leak which tools exist

Positive: Good use of constant-time comparison (ct_eq) for secret validation, proper signature verification pattern.

ilblackdragon and others added 3 commits March 11, 2026 07:12
Address three deferred implementation items flagged during code review:

1. SIGHUP lock held across .await (#883): Split restart_with_addr into
   merged_router_clone() + install_listener() so the async TcpListener
   bind happens outside the mutex, eliminating lock contention risk.

2. Recursion depth limit for check_strings (#848): Cap JSON traversal
   at 32 levels to prevent stack overflow on pathological tool params.

3. Named error type for add_tokens (#788): Replace Result<(), String>
   with TokenBudgetExceeded { used, limit } for type-safe budget errors.

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
… translations (#929)

* feat(i18n): Add internationalization support with Chinese and English translations
* fix(i18n): fix duplicate keys, broken placeholders, and dead overrides

---------

Co-authored-by: zwb1982 <133180666+zwb1982@users.noreply.github.com>
… translations (#929) (#950)

* feat(i18n): Add internationalization support with Chinese and English translations
* fix(i18n): fix duplicate keys, broken placeholders, and dead overrides

---------

Co-authored-by: jinxin <106428113+italic-jinxin@users.noreply.github.com>
Co-authored-by: zwb1982 <133180666+zwb1982@users.noreply.github.com>
Base automatically changed from staging-promote/55b5a462-22934480277 to main March 11, 2026 17:20
henrypark133 and others added 7 commits March 11, 2026 11:48
* fix(ci): use explicit features in WASM WIT compat test to avoid sqlite3 symbol conflicts

The `import` feature (added in #903) brings in `rusqlite[bundled]` which
conflicts with `libsql-ffi` — both bundle SQLite C code, causing duplicate
symbol linker errors. Use explicit features matching the test matrix instead
of `--all-features`.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* fix: replace rusqlite with libsql in import module to fix sqlite3 symbol conflict

The `import` feature used `rusqlite[bundled]` which bundled its own SQLite
C code, conflicting with `libsql-ffi` (also bundles SQLite). This caused
duplicate `sqlite3_*` symbol linker errors when both features were enabled
via `--all-features`.

Replace `rusqlite` with `libsql` (already a dependency) in the import
reader. The `import` feature now implies `libsql`. This eliminates the
duplicate symbol conflict and allows `--all-features` to compile cleanly.

Also restores `--all-features` in the WASM WIT compat CI test (now safe)
and converts all import test helpers from rusqlite to libsql.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

* style: apply cargo fmt formatting fixes

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
- Use fetch-depth: 0 in update-tag to ensure current_head SHA is available
  even when staging receives new commits during the CI run
- Only merge promotion PRs targeting main; leave chained PRs open to
  prevent delete_branch_on_merge from auto-closing downstream PRs

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
The telegram-tests, windows-build, wasm-wit-compat, and docker-build
jobs were skipped during staging CI because their `if` conditions only
matched `push` and `pull_request` events. When staging-ci.yml calls
test.yml via workflow_call, github.event_name is `schedule` (inherited
from the caller), which matched neither condition.

Invert the conditions to blocklist the one case we want to skip (PRs
targeting staging) instead of allowlisting specific events. This handles
schedule, workflow_dispatch, and any future trigger types.

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
The Claude review step was failing ~40% of the time because:
- --allowedTools didn't include Read, Glob, Grep, Agent, causing 8-9
  permission denials per run and preventing Claude from reading files
  or spawning the subagents the prompt required
- Step 4 spawned N additional scoring agents per issue found, exhausting
  the 50-turn budget before the PR comment could be posted
- Subagents could independently post PR comments, causing fragmented output

Fix: add missing tools to --allowedTools, merge per-issue scoring into
the review agents themselves, and add guardrails ensuring exactly one
consolidated comment is always posted.

Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
chore: promote staging to main (2026-03-11 21:09 UTC)
chore: promote staging to main (2026-03-11 19:17 UTC)
chore: promote staging to main (2026-03-11 07:18 UTC)
@github-actions github-actions Bot added scope: safety Prompt injection defense scope: worker Container worker scope: ci CI/CD workflows scope: dependencies Dependency updates labels Mar 11, 2026
@github-actions github-actions Bot added risk: high Safety, secrets, auth, or critical infrastructure and removed risk: medium Business logic, config, or moderate-risk modules labels Mar 11, 2026
@henrypark133
henrypark133 enabled auto-merge March 11, 2026 23:34
@henrypark133
henrypark133 merged commit d7024f5 into main Mar 11, 2026
27 checks passed
@henrypark133
henrypark133 deleted the staging-promote/369741fc-22935740447 branch March 11, 2026 23:34
@github-actions github-actions Bot mentioned this pull request Mar 11, 2026
bkutasi pushed a commit to bkutasi/ironclaw that referenced this pull request Mar 28, 2026
…935740447

chore: promote staging to main (2026-03-11 03:47 UTC)
drchirag1991 pushed a commit to drchirag1991/ironclaw that referenced this pull request Apr 8, 2026
…935740447

chore: promote staging to main (2026-03-11 03:47 UTC)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: experienced 6-19 merged PRs risk: high Safety, secrets, auth, or critical infrastructure scope: agent Agent core (agent loop, router, scheduler) scope: channel/wasm WASM channel runtime scope: channel/web Web gateway channel scope: ci CI/CD workflows scope: dependencies Dependency updates scope: docs Documentation scope: safety Prompt injection defense scope: tool/wasm WASM tool sandbox scope: tool Tool infrastructure scope: worker Container worker size: XL 500+ changed lines staging-promotion

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants