Skip to content

sync: update Matrix pilot with nearai/main 2026-07-01 - #44

Merged
github-actions[bot] merged 3 commits into
native-matrix-channel-pilotfrom
sync/native-matrix-pilot
Jul 1, 2026
Merged

github-actions[bot] merged 3 commits into
native-matrix-channel-pilotfrom
sync/native-matrix-pilot

Conversation

@personal-upstream-sync

Copy link
Copy Markdown

Automated sync from nearai/ironclaw. The upstream-main branch is an exact fast-forward mirror of nearai/main; this PR imports it into native-matrix-channel-pilot for CI with upstream source winning unrelated-history conflicts. When checks pass, the Matrix pilot branch is fast-forwarded so upstream ancestry is preserved.

henrypark133 and others added 3 commits July 1, 2026 13:02
…erts (nearai#5481)

* test(reborn): system-prompt capture seam for model-visible prompt asserts

Retain the concrete `Arc<TraceLlm>` in the per-thread gateway build
(`RebornThreadBuilder::build`) before it is upcast to `Arc<dyn LlmProvider>`,
stash it on `RebornIntegrationHarness`, and expose a `captured_system_prompts()`
accessor plus an `assert_system_prompt_contains(text)` assertion. This lets
Reborn integration tests inspect the model-visible system prompt without moving
the fake off the vendor-SDK seam, unblocking prompt-injection / prompt-content
assertions (C-SAFETY, C-SKILL, C-PROFILE prompt-line).

Adds one mutation-verified test asserting the composed capability policy reaches
the model as a system-role message.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* test(reborn): address PR review — consolidate seam test + polish assertion

- Fold the system-prompt assertion into the existing one-turn smoke test
  (reborn_integration_greeting.rs) and delete the redundant
  reborn_integration_system_prompt.rs: both drove the identical
  build → submit_turn("hi there") path, asserting different facets of the
  same turn, so a separate test binary bought a full support-tree compile
  for zero new path coverage (root + reborn CLAUDE.md consolidation rule).
- assert_system_prompt_contains: fix doc to say "across all captured
  requests" (not "the turn's requests" — the harness spans turns), and dump
  the captured prompts (UTF-8-safe 200-char truncation) in the failure
  message, matching the sibling seen-dumping egress assertions.
- assertions.rs module doc: cover the new model-prompt assertion and narrow
  the "same RecordingRuntimeHttpEgress log" claim to the egress group only
  (the prompt assertion reads the scripted TraceLlm instead).
- builder.rs: fold ironclaw_llm::Role into the external-crate import group
  and document why captured_system_prompts applies no [baseline..] slice
  (per-thread-fresh TraceLlm, not a shared recorder).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* test(reborn): negative guard for system-prompt assertion + guide update

- reborn_integration_greeting.rs: add a caller-level negative guard proving
  assert_system_prompt_contains discriminates on role, not mere substring
  presence — the user turn text "hi there" is in the captured request but
  only in a User-role message, so the System-only filter must return Err.
  Mutation-verified (swapping the guard string to a real system-prompt line
  flips the test red).
- tests/support/reborn/CLAUDE.md: refresh the stale file map — the
  assertions.rs bullet now names assert_system_prompt_contains and its
  distinct capture source, and the builder.rs accessor list includes
  captured_system_prompts.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…INJECT) (nearai#5483)

* test(reborn): prove credential injection reaches the wire (T0-SECRET-INJECT)

Add int-tier coverage that a dispatched capability's injected secret
actually lands on the outbound HTTP request. A scripted `github.get_repo`
tool call executes the real first-party GitHub WASM capability behind
`GithubHarnessAuthorizer` (which attaches an `InjectCredentialAccountOnce`
obligation); the host egress pipeline resolves the synthetic access token
from the harness `StaticSecretStore` and injects it as
`Authorization: Bearer <token>` before the recording network egress
captures the request. The test asserts the injected credential is present
on that captured request.

Wiring:
- builder.rs: `RebornCapabilityBackend::GithubIssueTools` + `.with_github_issue_tools()`
  (mirrors the `MockMcp`/`BuiltinHttpTools` variant/method/arm pattern).
- assertions.rs: `assert_network_egress_header_contains(url, header, value)` —
  reads the recording *network* egress lane (the runtime-lane `assert_egress_*`
  family is inert for this wiring because `try_with_host_http_egress` overwrites
  the runtime port with the host pipeline over the network recorder).
- harness.rs: bump `github_issue_tools()` and
  `HarnessCapabilityRecorder::network_http_requests()` to `pub(crate)`.

Lane note: the roadmap named `runtime_http_requests()`, but for the GitHub
WASM harness that recorder is inert; the faithful observable is the network
lane. Distinct from the QA-tier `reborn_trace_wasm_github_fixture_parity`
test, which asserts request bodies but never the injected auth header.

Mutation-verified: flipping the injected secret material turns the header
assertion RED (value mismatch on the present `authorization` header).

The token is a synthetic test fixture, never a real credential.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* test(reborn): address PR review findings on secret-injection assertion

Gemini: `assert_network_egress_header_contains` checked only the first
URL-matching request; now checks all matches and succeeds if any carries
the header.

Copilot: the network lane had no `[baseline..]` slice, unlike every other
capture accessor (`baseline_invocation_count`/`baseline_egress_count`/
`baseline_result_count`/`baseline_process_count`). Added the fifth
`baseline_network_count` in the same established spot (group.rs thread
build) plus a `captured_network_requests()` accessor, matching the
existing pattern exactly.

Codex P2 (rejected, documented instead): the bot suspected the test could
pass even if `GithubHarnessAuthorizer`'s `InjectCredentialAccountOnce`
obligation were broken, because the WASM manifest's own
`runtime_credentials` + `SharedHostWasmRuntimeCredentials` restaging is a
second, independent injection mechanism. Verified empirically by removing
the obligation: the run does NOT silently pass — it hangs and times out
waiting for `Completed`, because the two mechanisms are coupled (the
obligation gates whether dispatch can proceed at all). The bot's specific
failure mode does not reproduce. Documented the coupling on
`github_issue_tools()` so future readers don't have to re-derive it.

Re-verified mutation-verify (secret-value flip → RED for the right
reason) against the final combined state.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* test(reborn): round 2 — negative-path coverage, spec docs, softened claim

henrypark133: assert_network_egress_header_contains's two Err branches
(no URL match, URL-matches-but-header/value-mismatch) were never
exercised — a regression that ignored the header name or value could
pass vacuously. Extended the existing test (not a new one, per
consolidate-don't-proliferate) with 3 negative-path assertions against
the same already-captured request: wrong URL, wrong header name, wrong
value — each asserting the specific error-path substring.

henrypark133: tests/support/reborn/CLAUDE.md didn't document
.with_github_issue_tools(), assert_network_egress_header_contains, or
baseline_network_count. Added a "Credential injection (GitHub)"
subsection, folded the assertion into the existing "Richer assertions"
list, and added the baseline to the per-thread baseline list.

CodeRabbit: the github_issue_tools() doc-comment stated an empirically
observed but uncommitted claim ("removing the obligation necessarily
hangs") as a guarantee. Decided via thermo-nuclear-code-quality-review:
soften the wording rather than add a timeout-based regression test — a
timeout assertion is slow and its failure signal is ambiguous (many
unrelated bugs also hang), a worse mutation-test citizen than the
existing fast, specific value-flip mutation-verify which already covers
the claim that actually needs enforcement (the secret VALUE reaches the
wire). Reworded to describe current-harness observation, not a
guaranteed contract re-checked by CI.

Re-verified: keeper test green (with new negative-path assertions),
clippy --all-features clean, fmt clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* test(reborn): round 3 — avoid double-clone, redact credential from error

Copilot: captured_network_requests() cloned twice (once inside
network_http_requests(), again via [..].to_vec()) — since
NetworkHttpRequest can carry injected credential material, this
duplicated sensitive buffers unnecessarily. Switched to Vec::split_off,
which moves the tail out of the already-owned Vec without re-cloning;
the discarded prefix (a prior thread's requests) is simply dropped.

Copilot: assert_network_egress_header_contains's failure message
interpolated value_substr verbatim — for its intended use (asserting
injected Authorization: Bearer <token>) that's often credential-shaped
and would leak into CI logs on failure. Redacted the expected value
from the error text while still reporting the URL, header name, and
observed header names. The "has header" substring survives, so the
existing negative-path assertions needed no changes.

Also folds in the doc-comment relocation from rebasing onto main's
PR-E1 (nearai#5440), which refactored github_issue_tools() into a shared
github_issue_tools_with_credential_result helper — moved the
credential-injection-coupling doc note there (where the actual
try_with_wasm_runtime wiring now lives) and fixed the now-stale
"(below)" reference.

Re-verified: mutation-verify (secret-value flip) still turns the
(redacted) assertion RED for the right reason; clippy --all-features
clean; fmt clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions github-actions Bot added scope: docs size: XS Changed-line size classification risk: low Risk classification contributor: experienced Contributor history classification labels Jul 1, 2026
@github-actions
github-actions Bot merged commit 9014d04 into native-matrix-channel-pilot Jul 1, 2026
15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

contributor: experienced Contributor history classification risk: low Risk classification scope: docs size: XS Changed-line size classification

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant