sync: update Matrix pilot with nearai/main 2026-07-01 - #44
Merged
github-actions[bot] merged 3 commits intoJul 1, 2026
Merged
Conversation
…erts (nearai#5481) * test(reborn): system-prompt capture seam for model-visible prompt asserts Retain the concrete `Arc<TraceLlm>` in the per-thread gateway build (`RebornThreadBuilder::build`) before it is upcast to `Arc<dyn LlmProvider>`, stash it on `RebornIntegrationHarness`, and expose a `captured_system_prompts()` accessor plus an `assert_system_prompt_contains(text)` assertion. This lets Reborn integration tests inspect the model-visible system prompt without moving the fake off the vendor-SDK seam, unblocking prompt-injection / prompt-content assertions (C-SAFETY, C-SKILL, C-PROFILE prompt-line). Adds one mutation-verified test asserting the composed capability policy reaches the model as a system-role message. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * test(reborn): address PR review — consolidate seam test + polish assertion - Fold the system-prompt assertion into the existing one-turn smoke test (reborn_integration_greeting.rs) and delete the redundant reborn_integration_system_prompt.rs: both drove the identical build → submit_turn("hi there") path, asserting different facets of the same turn, so a separate test binary bought a full support-tree compile for zero new path coverage (root + reborn CLAUDE.md consolidation rule). - assert_system_prompt_contains: fix doc to say "across all captured requests" (not "the turn's requests" — the harness spans turns), and dump the captured prompts (UTF-8-safe 200-char truncation) in the failure message, matching the sibling seen-dumping egress assertions. - assertions.rs module doc: cover the new model-prompt assertion and narrow the "same RecordingRuntimeHttpEgress log" claim to the egress group only (the prompt assertion reads the scripted TraceLlm instead). - builder.rs: fold ironclaw_llm::Role into the external-crate import group and document why captured_system_prompts applies no [baseline..] slice (per-thread-fresh TraceLlm, not a shared recorder). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * test(reborn): negative guard for system-prompt assertion + guide update - reborn_integration_greeting.rs: add a caller-level negative guard proving assert_system_prompt_contains discriminates on role, not mere substring presence — the user turn text "hi there" is in the captured request but only in a User-role message, so the System-only filter must return Err. Mutation-verified (swapping the guard string to a real system-prompt line flips the test red). - tests/support/reborn/CLAUDE.md: refresh the stale file map — the assertions.rs bullet now names assert_system_prompt_contains and its distinct capture source, and the builder.rs accessor list includes captured_system_prompts. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…INJECT) (nearai#5483) * test(reborn): prove credential injection reaches the wire (T0-SECRET-INJECT) Add int-tier coverage that a dispatched capability's injected secret actually lands on the outbound HTTP request. A scripted `github.get_repo` tool call executes the real first-party GitHub WASM capability behind `GithubHarnessAuthorizer` (which attaches an `InjectCredentialAccountOnce` obligation); the host egress pipeline resolves the synthetic access token from the harness `StaticSecretStore` and injects it as `Authorization: Bearer <token>` before the recording network egress captures the request. The test asserts the injected credential is present on that captured request. Wiring: - builder.rs: `RebornCapabilityBackend::GithubIssueTools` + `.with_github_issue_tools()` (mirrors the `MockMcp`/`BuiltinHttpTools` variant/method/arm pattern). - assertions.rs: `assert_network_egress_header_contains(url, header, value)` — reads the recording *network* egress lane (the runtime-lane `assert_egress_*` family is inert for this wiring because `try_with_host_http_egress` overwrites the runtime port with the host pipeline over the network recorder). - harness.rs: bump `github_issue_tools()` and `HarnessCapabilityRecorder::network_http_requests()` to `pub(crate)`. Lane note: the roadmap named `runtime_http_requests()`, but for the GitHub WASM harness that recorder is inert; the faithful observable is the network lane. Distinct from the QA-tier `reborn_trace_wasm_github_fixture_parity` test, which asserts request bodies but never the injected auth header. Mutation-verified: flipping the injected secret material turns the header assertion RED (value mismatch on the present `authorization` header). The token is a synthetic test fixture, never a real credential. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * test(reborn): address PR review findings on secret-injection assertion Gemini: `assert_network_egress_header_contains` checked only the first URL-matching request; now checks all matches and succeeds if any carries the header. Copilot: the network lane had no `[baseline..]` slice, unlike every other capture accessor (`baseline_invocation_count`/`baseline_egress_count`/ `baseline_result_count`/`baseline_process_count`). Added the fifth `baseline_network_count` in the same established spot (group.rs thread build) plus a `captured_network_requests()` accessor, matching the existing pattern exactly. Codex P2 (rejected, documented instead): the bot suspected the test could pass even if `GithubHarnessAuthorizer`'s `InjectCredentialAccountOnce` obligation were broken, because the WASM manifest's own `runtime_credentials` + `SharedHostWasmRuntimeCredentials` restaging is a second, independent injection mechanism. Verified empirically by removing the obligation: the run does NOT silently pass — it hangs and times out waiting for `Completed`, because the two mechanisms are coupled (the obligation gates whether dispatch can proceed at all). The bot's specific failure mode does not reproduce. Documented the coupling on `github_issue_tools()` so future readers don't have to re-derive it. Re-verified mutation-verify (secret-value flip → RED for the right reason) against the final combined state. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * test(reborn): round 2 — negative-path coverage, spec docs, softened claim henrypark133: assert_network_egress_header_contains's two Err branches (no URL match, URL-matches-but-header/value-mismatch) were never exercised — a regression that ignored the header name or value could pass vacuously. Extended the existing test (not a new one, per consolidate-don't-proliferate) with 3 negative-path assertions against the same already-captured request: wrong URL, wrong header name, wrong value — each asserting the specific error-path substring. henrypark133: tests/support/reborn/CLAUDE.md didn't document .with_github_issue_tools(), assert_network_egress_header_contains, or baseline_network_count. Added a "Credential injection (GitHub)" subsection, folded the assertion into the existing "Richer assertions" list, and added the baseline to the per-thread baseline list. CodeRabbit: the github_issue_tools() doc-comment stated an empirically observed but uncommitted claim ("removing the obligation necessarily hangs") as a guarantee. Decided via thermo-nuclear-code-quality-review: soften the wording rather than add a timeout-based regression test — a timeout assertion is slow and its failure signal is ambiguous (many unrelated bugs also hang), a worse mutation-test citizen than the existing fast, specific value-flip mutation-verify which already covers the claim that actually needs enforcement (the secret VALUE reaches the wire). Reworded to describe current-harness observation, not a guaranteed contract re-checked by CI. Re-verified: keeper test green (with new negative-path assertions), clippy --all-features clean, fmt clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * test(reborn): round 3 — avoid double-clone, redact credential from error Copilot: captured_network_requests() cloned twice (once inside network_http_requests(), again via [..].to_vec()) — since NetworkHttpRequest can carry injected credential material, this duplicated sensitive buffers unnecessarily. Switched to Vec::split_off, which moves the tail out of the already-owned Vec without re-cloning; the discarded prefix (a prior thread's requests) is simply dropped. Copilot: assert_network_egress_header_contains's failure message interpolated value_substr verbatim — for its intended use (asserting injected Authorization: Bearer <token>) that's often credential-shaped and would leak into CI logs on failure. Redacted the expected value from the error text while still reporting the URL, header name, and observed header names. The "has header" substring survives, so the existing negative-path assertions needed no changes. Also folds in the doc-comment relocation from rebasing onto main's PR-E1 (nearai#5440), which refactored github_issue_tools() into a shared github_issue_tools_with_credential_result helper — moved the credential-injection-coupling doc note there (where the actual try_with_wasm_runtime wiring now lives) and fixed the now-stale "(below)" reference. Re-verified: mutation-verify (secret-value flip) still turns the (redacted) assertion RED for the right reason; clippy --all-features clean; fmt clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
github-actions
Bot
merged commit Jul 1, 2026
9014d04
into
native-matrix-channel-pilot
15 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automated sync from nearai/ironclaw. The
upstream-mainbranch is an exact fast-forward mirror ofnearai/main; this PR imports it intonative-matrix-channel-pilotfor CI with upstream source winning unrelated-history conflicts. When checks pass, the Matrix pilot branch is fast-forwarded so upstream ancestry is preserved.