nearai/ironclaw
50.3
Weak · 29 September 2026
994k
lines of production code
Rust
with TypeScript
2
measurements over time
What this system is
This system is a secure, self-hosted AI agent runtime that manages autonomous agent loops, tool execution, and multi-channel integrations. It provides a structured interface for users to interact with AI models through a WebUI, CLI, and OpenAI-compatible API, while enforcing strict security boundaries via sandboxed execution, capability-based authorization, and secret management. The platform supports a wide range of extensions and skills, allowing agents to perform actions across various services like Slack, Google Workspace, and GitHub, all within a durable, file-backed architecture.
Features
Add GCP deployment configuration and bootstrap scripts
New deployment artifacts have been added to support running the IronClaw application on Google Cloud Platform. This includes a systemd unit for the Cloud SQL Auth Proxy to manage database connectivity, a systemd unit for the main IronClaw service that pulls and runs the application container from Artifact Registry, an example environment file detailing required configuration variables (such as database URLs and API keys), and a shell script to automate the VM setup process including Docker installation, proxy verification, and service initialization.
deploy · high confidence
Add latency evidence harness
A new latency evidence harness has been added to measure and compare the performance of the system under various workloads. The runner supports both LibSQL and Postgres backends, executing specific operational patterns such as file system put/get, exact queries, append tails, sequence reservation, trigger seeding, control plane snapshots, turn lifecycles, and WebUI sessions. It allows users to configure warmup periods, sample counts, concurrency levels, and payload sizes to generate detailed latency reports including p50, p95, and p99 percentiles.
harness/latency/runner · high confidence
Add latency evidence harness for hosted persistence comparison
A new latency harness has been added to the \harness/latency\ directory to compare the performance of libSQL and PostgreSQL backends in a hosted single-tenant environment. This tooling includes a scoring script (\score.sh\) that runs specific workload scenarios—such as \put\_get\, \query\_exact\, and \webui\_session\—against both databases, allowing developers to measure and validate latency characteristics of the hosted substrate build and control-plane paths.
harness · high confidence
Add optional WeChat voice note decoding and infrastructure stress testing tools
This update introduces two new developer tools in the \tools/\ directory. The \ironclaw\_silk\_decoder\ is a standalone helper binary that converts WeChat raw SILK v3 voice notes into WAV format; it is isolated in its own crate to avoid requiring \libclang\ for the main build and provides crash isolation for untrusted audio input. The \ironclaw\_stress\ tool is a synthetic workload harness designed to identify infrastructure bottlenecks in storage, thread, and process-journal paths, featuring scenarios for chat turns, resource governor pressure, and scripted tool-call workloads with durable write read-back verification.
tools · high confidence
Extension host documentation and build-time skill embedding
The extension host crate now includes a comprehensive README detailing its public surface, dependencies, and architectural invariants (such as vendor-blindness and separation from the manager). Additionally, a new build script embeds Reborn skills from the repository's \skills/\ directory into the binary at compile time, validating skill names and manifest consistency while ensuring no symlinks are included in the bundled skill files.
_crates/extensions/ironclaw\_extension\host · high confidence
Google Docs extension adds semantic editing and verification tools
The Google Docs extension now includes high-level semantic operations—inspect\_document, apply\_text\_edits, create\_table\_with\_data, and verify\_document—alongside the existing low-level actions like insert\_text and format\_text. These new tools allow users to inspect document structure, apply validated text replacements atomically, create and populate tables in a single step, and verify document content against expectations, reducing the need for manual index management and providing built-in provider read-back for safer edits.
crates/extensions/packages/google-docs · high confidence
Introduce CodeRabbit AI review configuration and standardize project scaffolding files
The repository now includes a \.coderabbit.yaml\ configuration file that sets up CodeRabbit as the primary AI reviewer, defining specific review profiles, path filters, and detailed instructions for Rust, migrations, and security-critical areas. This change also adds standard project scaffolding files including \.dockerignore\, \.gitattributes\, \.mcp.json\, \.node-version\, \.nvmrc\, and \.sqlfluff\ to standardize development environment and tooling configurations.
(repo-wide) · high confidence
Introduce G Suite extension support with Gmail and Google Calendar capabilities
This change adds the core support layer for G Suite extensions, enabling Gmail and Google Calendar integrations. It introduces a credential resolution system that enforces visibility policies—allowing user-reusable Google accounts to be shared across the G Suite family (Gmail, Calendar, Docs, Drive, Sheets, Slides) while restricting admin-managed accounts to explicitly granted extensions. The implementation includes an executor and handlers for Gmail (list, get, send, draft, reply, trash) and Google Calendar (list calendars/events, get, create, update, delete, find free slots, add attendees, set reminder) capabilities, complete with network policies targeting Google APIs and input/output limits.
_crates/extensions/ironclaw\_extension\support/src/gsuite · high confidence
Introduce WebChat v2 HTTP route surface
The WebUI now exposes a new v2 HTTP route surface under \/api/webchat/v2/\ that provides a structured, host-composed API for chat threads, notifications, automations, extensions, skills, LLM configuration, and operator diagnostics. This surface introduces a dedicated route descriptor table, a sanitized error vocabulary, and an operator-only inspector API with live SSE updates, while enforcing strict boundaries so handlers interact only with the \ProductSurface\ service and never access internal runtime state directly.
_crates/product/ironclaw\_webui/src/webui\v2 · high confidence
Introduce durable, file-backed user notification inbox
This change adds a new, durable notification inbox subsystem within the \ironclaw\_notifications\ crate. It introduces a file-based storage backend (\NotificationInboxStore\) that persists user notification records to disk using a versioned JSON schema, ensuring notifications survive restarts. The implementation includes strict validation for notification IDs and lifecycle references, enforces a maximum record limit per user (1,000) and page size (100), and supports key notification types such as approval requirements, authentication needs, and automation run statuses (blocked, failed, completed). It also defines the error handling model for backend unavailability, serialization issues, and access denials, providing a robust foundation for reliable user-facing notification delivery.
_crates/domains/ironclaw\notifications/src · high confidence
Introduce ironclaw\_mcp lane for host-mediated MCP tool execution
The \ironclaw\_mcp\ crate is added to provide a dedicated execution lane for manifest-declared Model Context Protocol (MCP) tools. It adapts MCP tool calls into host capabilities, enforcing strict security boundaries: all network traffic must pass through a host-mediated HTTP egress seam (no direct outbound connections), resource usage is governed by a host-owned budget port (the lane has no independent budget authority), and all error messages are sanitized through a centralized diagnostics module to prevent leaking secrets or internal state. The implementation includes a Streamable-HTTP client with session management, a JSON-RPC codec, and a discovery module that validates and bounds the tool catalog from remote servers.
_crates/lanes/ironclaw\mcp · high confidence
Introduce provider-neutral memory contract and safety boundaries
The \ironclaw\_memory\ crate now defines the core provider-neutral contract for the memory system, including the \MemoryService\ trait, scoped path types (\MemoryDocumentScope\, \MemoryDocumentPath\), and a prompt-write safety registry that protects critical system files (e.g., \soul.md\, \agents.md\) from unauthorized modification. It also establishes a metadata model for document hygiene and a redacted event system (\MemorySignificantEvent\) for audit logging, ensuring that all memory operations are validated against scope and safety policies before reaching the native provider implementation.
_crates/domains/ironclaw\memory/src · high confidence
Introduces Reborn loop infrastructure: budget accounting, subagent await-edges, and capability ports
The \ironclaw\_loop\_host\ crate now includes the core wiring for the Reborn agent loop architecture. A new budget accounting system (\GovernorBackedAccountant\) tracks model costs, reserves resources, and handles approval gates for model calls. Subagent lifecycle management is supported via \AwaitEdgeWriter\ and \AwaitEdgeSettler\ traits, which handle the delivery and settlement of background subagent results. Additionally, the host now exposes robust capability invocation ports, including detailed input normalization, schema validation, and trajectory observation for provider tool calls.
_crates/loop/ironclaw\_loop\host/src · high confidence
Introduces durable inbound action ledger and structured approval interaction service
The assistant now tracks inbound product actions through a durable ledger (\action.rs\) that ensures idempotency for webhook deliveries by fingerprinting events and recording phases from received to settled. Additionally, a new approval interaction module (\approval\_interaction/\) provides a structured service for listing and resolving pending approval gates, including read models for gate status, resolvers for dispatching approvals, and typed rejection handling, while \admin\_user\_directory.rs\ implements the admin user service contract for tenant-scoped user management and secret provisioning.
_crates/product/ironclaw\assistant/src · high confidence
Introduces host-managed model and prompt port implementations
The turn kernel now includes concrete host-managed adapters for the loop's model and prompt contracts. The new \HostManagedLoopModelPort\ enforces a 75-second idle timeout on model calls to prevent hung providers from wedging the runner, while also handling budget accounting and milestone emission. The new \HostManagedLoopPromptPort\ provides a text-only prompt interface that validates request scoping, enforces message limits (default 32, max 128), and integrates with safety contexts and instruction materialization stores. These modules serve as temporary implementations until the planned \ironclaw\_loop\_host\ re-charter moves them to their final location.
_crates/kernel/ironclaw\_turns/src/host\_managed\ports · high confidence
Introduces loop-tier contract definitions for checkpointing, compaction, and prompt assembly
This change establishes the \ironclaw\_loop\_contracts\ crate, defining the vocabulary and ports that allow the agent loop, hooks, and host adapters to communicate with the turn kernel without direct dependency. It introduces contracts for opaque loop checkpoint payloads (with a 64KB ceiling), host-managed context compaction (including modes like window eviction and capability overflow), and deterministic instruction bundle assembly for model prompts. Additionally, it defines the \LoopExit\ claim structure for terminal loop states, memory prompt context services for retrieving user-scoped snippets, and milestone emission types for tracking loop progress, ensuring that prompt construction and state management are strictly bounded and validated at the kernel boundary.
_crates/contracts/ironclaw\_loop\contracts/src · high confidence
Introduces post-turn hooks and memory curation
The turn runner now supports an \AfterTurn\ lifecycle point that fires only for terminal, actor-bearing conversation turns. This mechanism enables automatic memory curation by recording the full ordered transcript of completed runs into the memory service, while strictly excluding unbound, scheduled, or subagent runs to prevent uncontrolled background work or duplicate counting.
_crates/loop/ironclaw\_turn\runner/src · high confidence
Introduces the IronClaw Agent Loop Host Boundary Contract
This change establishes the formal host-boundary interface for the agent loop by adding a new \host\ module to the \ironclaw\_loop\_contracts\ crate. It defines the structured data transfer objects (DTOs) and asynchronous traits that govern communication between the loop driver and the host environment. Key additions include the \LoopCapabilityPort\ for managing provider tool calls and capability surfaces, \LoopCheckpointPort\ for durable state management, \LoopContextPort\ for paginated context loading, and \LoopInputPort\ for polling run inputs. The module also introduces a comprehensive error handling system via \AgentLoopHostError\ with granular failure kinds (such as \ContextOverflow\ and \BudgetApprovalRequired\) and a \LoopProgressEvent\ enum to expose detailed lifecycle events like compaction and recovery stages to the host.
_crates/contracts/ironclaw\_loop\contracts/src/host · high confidence
IronHub extension catalog integration with signed verification and secure installation
The IronHub extension manager now supports browsing, inspecting, and installing tools and skills from the signed IronHub catalog. This change introduces three new built-in capabilities (search, info, and install) that allow users to discover catalog entries, view their provenance and artifact digests, and install verified content. The system enforces security by verifying Ed25519-signed manifests against known public keys, restricting network access to specific artifact hosts (including GitHub and IronHub domains), and requiring explicit user acknowledgement for unverified community content. Installation is secured via HMAC-SHA256 signatures on delivery payloads, nonce-based replay protection, and strict validation of artifact digests and schema/prompt assets against the published manifest.
_crates/extensions/ironclaw\_extension\manager/src/ironhub · high confidence
LLM crate guidance and provider configuration consolidated
The \ironclaw\_llm\ crate now includes canonical documentation and configuration files to standardize provider setup and internal ownership. A new \CONTRACT.md\ defines the module's file map and enforces a sub-owner map for ten distinct concerns (such as providers, auth-sessions, and decorators), while \AGENTS.md\ and \README.md\ provide orientation and usage guidelines. Additionally, \assets/providers.json\ has been introduced to declaratively define available LLM providers (including NEAR AI, OpenAI, Anthropic, and GitHub Copilot), their authentication methods, and default model settings, replacing or supplementing previous configuration approaches.
_crates/domains/ironclaw\llm · high confidence
Native memory backend with filesystem-backed storage and prompt-write safety
The memory-native extension now provides a pluggable memory backend architecture, introducing a \MemoryBackend\ trait and a \MemoryBackendFilesystemAdapter\ that exposes memory documents as virtual filesystem files under \/memory\. This change consolidates previous SQL-specific repositories into a single \FilesystemMemoryDocumentRepository\ that leverages the unified \RootFilesystem\ for storage, including support for full-text search, vector search, and versioning. The implementation enforces prompt-write safety policies on protected paths (such as \SOUL.md\ and \BOOTSTRAP.md\) and includes a hash-guarded chunking indexer to keep search indexes consistent with document content. A contract test harness has also been added to ensure all repository implementations adhere to scope isolation and data integrity invariants.
crates/extensions/packages/memory-native/src · high confidence
New API capacity and database-write stress workloads with bottleneck analysis
The \tools/ironclaw\_stress\ harness now includes new workloads to measure API capacity (including scripted tool-call patterns with durable write read-back) and database write behavior (including long-lived idle process writes). It also introduces a bottleneck analysis report that aggregates failure rates, process metrics, stage latencies, and database probe deltas to identify performance regressions and suggest next probes.
_tools/ironclaw\stress · high confidence
New IronClaw Reborn CLI with comprehensive configuration and extension management
The \ironclaw\ command-line interface has been introduced, providing a structured way to manage the IronClaw agent runtime. Users can now initialize configuration stubs (\config init\), inspect and modify settings like LLM API keys and Google OAuth credentials (\config get\, \config set\, \config list\), and run a diagnostic health check (\doctor\). The CLI also supports managing local extensions (\extension search\, \install\, \remove\) and installing tools or skills from the IronHub catalog (\ironhub search\, \install\). Shell completion scripts are generated automatically for supported shells, and the CLI defaults to the \serve\ command if no subcommand is specified.
_crates/app/ironclaw\cli/src · high confidence
New LLM operator control-plane for Reborn runtime configuration
The \ironclaw\_operator\ crate introduces the operator control-plane for Reborn, providing the backend services that manage LLM provider selection, API key storage, and runtime reloading. It adds a \ProviderActiveModelReader\ to track the live active model for accurate usage pricing, a \FilesystemModelSelectionPolicyStore\ to persist tenant-scoped model selection policies, and a \LlmKeyStore\ to securely store API key values in the operator secret store. The \RebornLlmConfigService\ and \RebornLlmReloadAdapter\ coordinate the resolution of LLM configurations from boot settings and provider catalogs, enabling hot-swapping of the active LLM provider without restart. Additionally, it includes a public callback route for NEAR AI OAuth login to activate the provider.
_crates/product/ironclaw\operator/src · high confidence
New OAuth login surface for WebChat v2 with Google and GitHub support
The WebChat v2 interface now includes a complete OAuth authentication flow, allowing users to log in using Google or GitHub accounts. This change introduces the backend logic for the OAuth code flow, including PKCE handling, CSRF protection, and session management. Users will see login buttons for Google and GitHub on the WebChat v2 interface, and successful authentication grants access to the application via a secure session.
_crates/product/ironclaw\webui/src · high confidence
New OpenAI-compatible API surface for chat completions and responses
This change introduces a new HTTP route crate (\ironclaw\_openai\_compat\) that exposes an OpenAI-compatible interface for chat completions and the Responses API. It provides endpoints for creating and retrieving chat completions (\/v1/chat/completions\), listing models (\/v1/models\), and managing Responses (create, retrieve, cancel) via both \/api/v1/responses\ and \/v1/responses\ paths. The implementation includes full request/response DTOs for chat messages, tools, and usage (including a custom \cost\ field for USD spend), and handles content normalization for text and inline images. It also defines the ingress policies, error mappings, and workflow structures required to translate these API calls into the underlying product surface operations.
_crates/product/ironclaw\_openai\compat/src · high confidence
New Railway preview QA skill for automated PR testing
A new developer skill named 'railway-test' has been added to the \.claude/skills\ directory to automate quality assurance for pull requests deployed on Railway. This skill enables browser-based acceptance testing against the exact PR head, including a script (\preview\_state.sh\) to verify deployment status and asset hashes, and reference documents (\test-recipes.md\, \streaming-cadence.md\) that define test matrices and specific validation procedures for features like streaming cadence. Users can now invoke this skill to automatically validate that PR changes behave as intended in the live preview environment before merging.
.claude/skills/railway-test · high confidence
New URL-based skill installation support with GitHub integration
The \ironclaw\_extension\_support\ module now includes a new \url\_install\ subsystem that enables installing skills directly from URLs. This implementation extracts skill metadata and files from HTTPS sources, with specific support for GitHub repositories and blob URLs (parsing owner/repo/branch structures and resolving download links). It handles ZIP bundle extraction with strict security constraints, including path normalization to prevent directory traversal, limits on total unzipped bytes and individual file sizes, and a whitelist of allowed code-artifact hosts (GitHub domains). Network access is mediated through the host's \RuntimeHttpEgress\ capability, ensuring no direct kernel dependency.
_crates/extensions/ironclaw\_extension\support/src/skills · high confidence
New WASM test tools for ASCII art, Hacker News, and market data
Added three new WebAssembly-based test tools to the IronClaw agent platform: an ASCII renderer that generates simple drawings (cat, dog, robot) without network access, a Hacker News top-stories tool that returns canned fixture data while exercising network-policy obligations, and a market-data tool that provides a fake S&P 500 snapshot to test credential-provisioning flows. These tools serve as fixtures for validating tool installation, capability dispatch, and security gate behaviors.
test-tools/ascii-renderer/wasm-src, test-tools/hacker-news/wasm-src, test-tools/market-data/wasm-src · high confidence
New WebUI v2 API routes for run management
The WebUI v2 now exposes three new API endpoints for managing AI runs: cancel a run, resolve a gate, and retry a run. These are implemented as POST routes under \/api/webchat/v2/threads/{thread\_id}/runs/{run\_id}/\ with specific suffixes for each action. Each endpoint is configured with a 4 KiB body limit, a mutation rate limit, and is classified as a user action for audit tracing.
(repo-wide) · high confidence
New auth canary and build tooling scripts
Added a fresh-machine auth canary runner (\scripts/auth\_canary/run\_canary.py\) that bootstraps a Python environment, installs Playwright, builds the binary, and executes a focused auth matrix (smoke, full, and channel profiles) against a local instance. Introduced a live auth canary (\scripts/auth\_live\_canary/run\_live\_canary.py\) with seeded and browser modes to verify real provider-backed auth (Google, GitHub, Notion) through the Responses API and browser UI, including a helper to bootstrap Google storage state for browser consent bypass. Added \scripts/build-test-tools.sh\ to build WASM test fixture bundles and \scripts/build-wasm-extensions.sh\ to compile local-source WASM extensions against current WIT definitions. Included CI quality scripts: \scripts/check-type-duplicates.py\ to detect semantic duplicate Rust types, \scripts/check-version-bumps.sh\ to enforce WIT and extension version bumps, and \scripts/check\_no\_panics.py\ to forbid panics in production Rust code.
scripts · high confidence
New built-in first-party tool capabilities for HTTP, JSON, memory, and outbound delivery
The host runtime now exposes a suite of new built-in tools that the agent can use directly. The \builtin.http\ and \builtin.http.save\ capabilities allow outbound HTTP requests with strict resource ceilings (e.g., 15 MB output limit, 30s timeout) and classify 4xx/5xx responses as operation failures. The \builtin.json\ tool provides bounded parsing, querying, and aggregation of JSON data. Memory operations are now handled via a dedicated \memory\ module that enforces mount-based write permissions and input schema normalization. Additionally, \builtin.outbound\_deliver\ enables sending content to connected channels (like Slack) with durable delivery tracking, and \builtin.attach\_workspace\_file\_to\_reply\ allows registering files for automatic inclusion in final assistant replies.
_crates/kernel/ironclaw\_host\_runtime/src/first\_party\tools · high confidence
New capability authorization and lease management crate
The \ironclaw\_authorization\ crate introduces the kernel's default-deny authorization layer, evaluating whether a caller's grants and active capability leases permit a requested effect. It provides \GrantAuthorizer\ and \LeaseBackedAuthorizer\ implementations that enforce trust ceilings and scope constraints, while managing a \CapabilityLease\ state machine that ensures single-winner, fingerprint-matched claims for resumed approvals. The crate also enforces strict architectural boundaries by preventing dependencies on workflow or runtime crates, and simplifies lease persistence by using a unified filesystem-backed store (with an in-memory backend for tests) instead of bespoke in-memory implementations.
_crates/kernel/ironclaw\authorization · high confidence
New configuration layer for IronClaw Reborn runtime
The \ironclaw\_config\ crate now provides the boot-time configuration foundation for the standalone Reborn binary. It introduces a three-layer config model (catalog, selection, runtime) where operators can define LLM provider selections, budget ceilings, and memory provider bindings in a new \config.toml\ file. The system automatically seeds a sparse first-run config, resolves the state root and boot profile from environment variables, and enforces strict validation for budget thresholds and deprecated configuration keys.
_crates/app/ironclaw\config/src · high confidence
New declarative extension manifest schema and registry infrastructure
The extension registry now supports a new manifest schema version (v2) with a comprehensive validation and projection system. This includes declarative admin configuration forms for deployment-owned values, a canonicalization engine to merge and deduplicate installation rows, and a capability provider host-API contract for validating tool declarations. The registry also introduces hosted MCP discovery to automatically generate capabilities from discovered tools, a product adapter contract for resolving product-specific sections, and a package definition retention policy allowing tenant-registered definitions to be retained in the catalog upon removal.
_crates/extensions/ironclaw\_extension\registry/src · high confidence
New durable process lifecycle and cancellation system
The \ironclaw\_processes\ crate now provides a complete, file-system-backed process lifecycle management system. It introduces a durable journal (\ProcessJournalStore\) that tracks process states (queued, leased, suspended, killed, recovered) and supports checkpointing to allow safe resumption after failures. A new \ProcessCancellationRegistry\ enables cooperative cancellation of in-flight processes via tokens, and a \ProcessHost\ API exposes status, kill, and result-awaiting capabilities to the host runtime. Additionally, \BackgroundProcessManager\ coordinates the execution loop, lease recovery, and supervisor handling for background capability processes.
_crates/kernel/ironclaw\processes/src · high confidence
New event log substrate with redacted runtime events and cursor-based replay
The \ironclaw\_event\_log\ crate now provides the core vocabulary and traits for recording runtime and audit events. It introduces \RuntimeEvent\ and \SecurityAuditEvent\ types with strict redaction invariants that sanitize error details and prevent leakage of secrets or host paths. The crate defines best-effort delivery traits (\EventSink\, \AuditSink\) that guarantee runtime outcomes are never altered by sink failures, alongside explicit-error durable log traits (\DurableEventLog\, \DurableAuditLog\) that support monotonic, cursor-based replay. Replay is strictly cursor-driven to allow backend compaction without breaking consumer resume positions, and returns a \ReplayGap\ error if a requested cursor predates the earliest retained entry, forcing consumers to request a snapshot or rebase.
_crates/events/ironclaw\_event\log · high confidence
New event projection service for runtime and audit logs
A new \ironclaw\_event\_projections\ crate has been added to provide replay-derived, metadata-only read models over the durable runtime and audit logs. This service exposes typed DTOs (such as \ThreadTimeline\, \RunStatusProjection\, and \CapabilityActivityProjection\) to upper layers, replacing direct parsing of durable event rows. It enforces strict security and architectural boundaries: projections are non-mutating (no writes to durable logs or kernel state), metadata-only (raw inputs, secrets, and host paths are sanitized or excluded), and scope-bound (reads are filtered by tenant, user, and agent). The implementation includes a bounded replay mechanism with explicit rebase-required errors to prevent silent data skipping, and a checkpoint cache to optimize state reconstruction.
_crates/events/ironclaw\_event\projections · high confidence
New extension contract types for channel surfaces, auth prompts, and device linking
The \ironclaw\_extension\_contracts\ crate now exposes a comprehensive set of data structures and traits that define how extensions interact with the host. This includes \ChannelDescriptor\ and \ChannelSurfaces\ to declare and implement channel capabilities (ingress, reply, and delivery), \AuthPromptView\ and related types to handle authentication challenges like OAuth, manual tokens, and pairing, and \DeviceLink\ types to manage multi-step vendor device-linking flows. These contracts standardize the interface between extension packages and the host runtime, replacing the previous monolithic \ProductAdapter\ with a more modular, capability-based approach.
_crates/contracts/ironclaw\_extension\contracts/src · high confidence
New extension management product surface and admin configuration views
The \ironclaw\_extension\_manager\ crate now exposes a dedicated product-facing layer for extension lifecycle and configuration. This includes new admin configuration views (\admin\_configuration.rs\) that allow operators to query and replace manifest-declared configuration groups, and a channel configuration product service (\channel\_config\_product\_service.rs\) that projects extension setup fields to the WebUI. Extension lifecycle operations (search, install, activate, remove) are now handled via new capability handlers (\extension\_lifecycle\_capabilities.rs\) and a command executor (\extension\_lifecycle\_command.rs\), with unified install/activate guidance (\install\_guidance.rs\) to correctly report device-link requirements and prevent false completion states.
_crates/extensions/ironclaw\_extension\manager/src · high confidence
New host API contracts for authorization, actions, and capability visibility
This release introduces a new set of contracts in the \ironclaw\_host\_api\ crate that standardize how the system handles authorization, actions, and capability visibility. The \action.rs\ file defines a normalized \Action\ enum (e.g., \ReadFile\, \WriteFile\, \Dispatch\, \UseSecret\) to ensure policy, approvals, and audit logs reason about a consistent shape of operations. The \approval.rs\ file introduces \ApprovalRequest\ and \ApprovalScope\ structures, enabling scoped, reusable grants for user-mediated authority, along with \InvocationFingerprint\ for deterministic request hashing. The \authorized.rs\ file implements a sealed \Authorized\ witness type, ensuring that only the kernel can mint proof of authority, thereby structurally preventing unauthorized dispatches. Additionally, \capability.rs\ and \capability\_surface.rs\ define \CapabilityDescriptor\, \CapabilityGrant\, and \CapabilitySurfacePolicy\ to manage capability declarations, grants with constraints (effects, mounts, network, secrets), and visibility ceilings for model-facing surfaces. The \audit.rs\ file provides \AuditEnvelope\ for durable, redacted provenance of authorization decisions. Finally, \credential\_redaction.rs\ adds robust redaction primitives to prevent accidental leakage of secrets in model-visible results, fixing false-positive scrubbing issues.
_crates/contracts/ironclaw\_host\api/src · high confidence
New identity and project persistence layer in ironclaw\_identity
The \ironclaw\_identity\ crate now provides the canonical identity layer, mapping external OAuth logins (Google, GitHub) to stable \UserId\s and serving as the durable home for the minimal user profile (email, display name). It introduces a filesystem-backed identity store that uses compare-and-swap primitives for atomic resolve-link-create operations and verified-email cross-provider linking. Additionally, the crate now owns the Project entity, membership ACLs, and the project access-gating service, persisting them via the same \ScopedFilesystem\ substrate to ensure tenant isolation and live authorization resolution without caching.
_crates/domains/ironclaw\identity · high confidence
New ironclaw\_attachments crate centralizes inbound attachment landing and budgets
A new \ironclaw\_attachments\ crate has been added to the \domains\ family to serve as the single, channel-agnostic landing path for inbound attachment bytes. It introduces shared attachment size ceilings (\DEFAULT\_ATTACHMENT\_BUDGETS\) and browser-facing capability contracts (\AttachmentCapabilities\) so the WebUI and server stay in lockstep on allowed formats and limits. The crate provides the \InboundAttachmentLander\ and \InboundAttachmentReader\ ports, with a default \ProjectScopedAttachmentLander\ that writes bytes through the project-scoped filesystem authority, ensuring landed files are readable by the agent's file tools in subsequent turns. It also handles document text extraction on landing, enforces per-file and batch size limits, and manages stale attachment cleanup, consolidating logic previously spread across multiple crates.
_crates/domains/ironclaw\auth · high confidence
New ironclaw\_network crate for hardened outbound HTTP egress
The \ironclaw\_network\ crate introduces a centralized, hardened boundary for all outbound HTTP requests, ensuring that every egress call is policy-checked, DNS-resolved with private-IP denial, and sent through a pinned \reqwest\ transport. It enforces a fail-closed policy model where requests are denied if no matching target pattern exists, supports host-mediated redirect following (limiting hops to 3 and stripping all headers on each hop to prevent credential leakage), and scrubs sensitive URL and header buffers on drop to protect injected secrets. The crate also provides a debug-only, env-gated test seam (\IRONCLAW\_REBORN\_TEST\_HTTP\_REWRITE\_MAP\) that allows E2E harnesses to redirect vendor egress to loopback addresses without weakening production security guarantees.
_crates/substrates/ironclaw\network · high confidence
New kernel crate for durable approval resolution and policy management
The \ironclaw\_approvals\ crate introduces the kernel's consent stage, which resolves pending approval requests into scoped capability leases or durable denials. It owns the persistence layer for approval requests and model-visible gate records, and manages user-facing policy stores including a global auto-approve toggle and per-capability permission overrides (always allow, ask each time, disabled). The crate enforces a fail-closed resolution workflow where the approval authority record is persisted before the lease is issued, ensuring that approval decisions are durable even if lease issuance fails.
_crates/kernel/ironclaw\approvals · high confidence
New outbound delivery policy and routing infrastructure
The \ironclaw\_outbound\ crate introduces a comprehensive backend for managing outbound communication state. It adds durable communication preferences, allowing users to configure notification targets (with a cap of 8) and support for legacy migration from single-slot defaults. A new delivered-gate routing system tracks approval prompts delivered to personal targets (e.g., Slack DMs) to correctly resolve replies back to the originating run scope, with a 48-hour TTL for these routes. The system also implements a new delivery resolution engine that distinguishes between requested outbound messages and run notifications (including progress, approval, and auth prompts), and provides a registry for discovering and validating outbound delivery targets with specific capabilities. Additionally, it supports explicit model-initiated channel deliveries with content and per-run caps, and manages reply attachment intents and publication lifecycles.
_crates/domains/ironclaw\outbound/src · high confidence
New product-auth HTTP route surface for credential and device-link management
The product-auth module now exposes a comprehensive set of HTTP handlers for managing user credentials and device connections. Users can list, select, recover, and refresh credential accounts via dedicated endpoints, while device-linking operations (start, poll, input, cancel) are handled through their own routes to ensure vendor calls are properly driven. The module also introduces new paths for manual token setup and submission, OAuth flow start and callback processing, and lifecycle cleanup for extension credentials. These routes enforce strict scope derivation from authenticated callers, require invocation IDs to bind operations to active interaction contexts, and delegate durable state management to the underlying auth engine services.
_crates/product/ironclaw\_webui/src/product\auth · high confidence
New product-contract vocabulary for account setup, actor identity, and admin user management
The \ironclaw\_product\_contracts\ crate now exposes the core domain types and dependency-inversion ports that define how the product boundary interacts with channel hosts and the admin surface. This includes the \ExtensionAccountSetupDescriptor\ and \AccountConnectionStatusSource\ for managing external account pairing lifecycles, the \ProductActorUserResolver\ for resolving external channel actors to internal users, and the \AdminUserService\ and \AdminApiTokenMinter\ ports for the admin user directory and session token minting. These contracts establish the read-only registry surface and the specific DTOs (like \AdminUserRecord\) that the WebUI and extension hosts consume, separating the product's mutable state from the host's implementation.
_crates/contracts/ironclaw\_product\contracts/src · high confidence
New runtime policy resolver and capability planner in the kernel
The \ironclaw\_runtime\_policy\ crate has been introduced to centralize the deterministic resolution of deployment modes, runtime profiles, and organizational constraints into an \EffectiveRuntimePolicy\. This pure-logic layer enforces safety invariants such as monotonic safety (authority can only be reduced, never increased) and fail-closed behavior for invalid configurations. It also includes a capability planner that maps resolved policies to concrete backend selections (filesystem, process, network, secrets) for individual capabilities, ensuring that structural incompatibilities are caught before execution.
_crates/kernel/ironclaw\_runtime\policy · high confidence
New sandbox execution and idle management scripts
Added \ironclaw-exec\ and \ironclaw-sandbox-idle\ to the sandbox environment. The \ironclaw-exec\ script provides a robust mechanism for running sandbox commands with bounded timeouts, descendant-complete process cleanup (using subreaper and signal propagation), and structured outcome reporting via nonces. The \ironclaw-sandbox-idle\ script manages the container's idle state, ensuring proper signal handling and process reaping for orphaned children while waiting for commands.
docker/sandbox · high confidence
New sandboxed process and script execution lane
The \ironclaw\_sandbox\ crate consolidates the previous process sandbox, host runtime sandbox, and script execution logic into a single, unified lane. It introduces a typed \SandboxProcessPlan\ contract that enforces strict validation—rejecting raw secrets, unsafe commands, and invalid paths—before dispatching commands to a Docker-based backend. This backend supports persistent per-user containers, managed egress proxies for network isolation, and explicit credential bindings, while the script lane provides a resource-governed execution path for extension capabilities.
_crates/lanes/ironclaw\sandbox/src · high confidence
New self-hosted mem0 memory provider extension
A new optional memory provider extension (\mem0.local.memory\) is available, allowing deployments to replace the native filesystem memory backend with a self-hosted mem0 OSS service. This extension implements the standard \ironclaw\_memory::MemoryService\ contract, exposing the same five memory tools (read, write, search, tree, profile\_set) to the model, but maps them to the mem0 REST API using verbatim storage (\infer=false\) and scoped namespaces for isolation. It is off by default and requires explicit configuration of a self-hosted base URL to activate.
crates/extensions/packages/mem0 · high confidence
New self-hosted runner for live OAuth canary testing
Added infrastructure to deploy a dedicated GitHub Actions runner on Railway for the \private-oauth\ live canary lane. This setup uses a persistent volume to store the runner binary, Rust toolchain caches, and the ironclaw libsql database containing rotated OAuth refresh tokens, ensuring state survives container restarts. The entrypoint script handles first-boot registration and supports two methods for seeding the required OAuth database: via a base64-encoded environment variable or a short-lived Cloudflare tunnel URL generated by a new helper script.
infra · high confidence
New shared primitives crate for validated identities, attachments, and environment overrides
The \ironclaw\_common\ crate now provides a centralized, domain-free layer of cross-cutting primitives shared across the workspace. Users benefit from stricter type safety via validated identity newtypes (\CredentialName\, \ExtensionName\, \McpServerName\, \ExternalThreadId\) that enforce canonical formatting and length limits while maintaining wire compatibility with legacy data. Attachment handling is unified through a single source of truth for MIME types, file extensions, and text extraction strategies, ensuring consistent behavior for images, documents, and audio across all channels. Additionally, thread-safe environment variable overrides replace unsafe global state mutations, allowing for more reliable configuration management and testing.
_crates/contracts/ironclaw\_common, crates/kernel/ironclaw\_trust, crates/product/ironclaw\_host\ingress · high confidence
New tenant-scoped secret and credential store with AES-256-GCM encryption and OS keychain support
The \ironclaw\_secrets\ crate now provides a complete, tenant-scoped boundary for storing and leasing secret material and credentials. Secrets are encrypted at rest using AES-256-GCM with per-record HKDF-SHA256 key derivation, and ciphertexts are authenticated against additional data (AAD) bound to the specific tenant, user, and resource scope to prevent cross-owner tampering. The store supports compare-and-swap writes for versioned secrets and manages one-shot access leases. Credential management includes a stable placeholder registry for sandboxed invocations and just-in-time session minting, ensuring real credentials are never exposed to untrusted containers. On macOS and Linux, the system can automatically resolve the master key from the OS keychain (Keychain Services, GNOME Keyring, or KWallet) or the \SECRETS\_MASTER\_KEY\ environment variable, while enforcing strict entropy and length validation on key material.
_crates/substrates/ironclaw\secrets/src · high confidence
New trace contribution and text extraction crates with strict redaction and format handling
This change introduces two new domain crates: \ironclaw\_extractors\ and \ironclaw\_trace\_commons\. The \ironclaw\_extractors\ crate provides a pure, format-aware text extraction layer (supporting PDF, Office, RTF, and text/code) with built-in decompression-bomb caps and a strict \ExtractionError\ type that ensures parser diagnostics never leak into model-facing outputs. The \ironclaw\_trace\_commons\ crate implements the Trace Commons client, handling the autonomous turn-end capture pipeline, envelope building, disk queuing, and submission to the Trace DAO service. It enforces deterministic redaction of sensitive JSON before data leaves the machine and includes a periodic flush worker to retry failed submissions.
_crates/domains/ironclaw\_trace\commons · high confidence
New turn coordination kernel with activation streak caps and admission controls
The \ironclaw\_turns\ crate introduces a new turn coordination layer that enforces deterministic limits on autonomous agent behavior and manages turn admission. It adds derived activation-streak caps (e.g., \SYSTEM\_WAKE\_STREAK\_CAP\ of 16) to prevent infinite loops by refusing reactive wakes after consecutive system-provenanced activations, and implements a structured admission system with configurable limits per tenant, user, project, or agent. The kernel also provides a \TurnCoordinator\ API for prepared-context turns, external tool cataloging, and loop exit validation, ensuring that autonomous agents operate within bounded, auditable constraints.
_crates/kernel/ironclaw\turns/src · high confidence
Reborn Docker image overhaul: new config profiles, secure entrypoint, and SSH support
The Reborn Docker image has been rebuilt with a new runtime configuration schema (ironclaw.runtime/v1) and a hardened entrypoint. New default configuration profiles are provided for local development, production, and hosted single-tenant deployments, standardizing settings for identity, runner concurrency, and LLM providers. The entrypoint script now manages secure home directory ownership to prevent boot failures from root-written files, supports Railway volume mounts, and includes a new SSH subsystem (start-sshd.sh) that allows operators to enable secure, key-based agent access via the IRONCLAW\_REBORN\_SSH\_PUBLIC\_KEY environment variable.
docker/reborn · high confidence
Rebuilt coding tools with structured document support and safer file handling
The coding capabilities in the ironclaw extension have been rewritten to provide structured editing for Office documents (.docx, .xlsx, .pptx) and HTML-to-PDF conversion, while improving safety and performance for standard file operations. \read\_file\ now returns an addressable JSON structure for OOXML files instead of flattened text, enabling precise edits via the new \document\_edit\ tool without risking document corruption. File reads and writes now enforce strict byte and line limits to prevent excessive context usage, and binary files are handled more gracefully during reads to avoid hard failures on logs with stray non-UTF-8 bytes. The \grep\ and \glob\ tools have been reborn with better path resolution, exclusion handling, and result limiting to prevent hangs or excessive resource consumption.
_crates/extensions/ironclaw\_extension\support/src/coding · high confidence
Sandbox process infrastructure for managed egress and credential firewall
This change introduces the core sandbox-process components required for the managed egress proxy and credential firewall. It adds connection attribution logic to map shared-proxy traffic to specific tenants and users via Docker container labels, a broker module to configure network and secret broker endpoints for sandboxed containers, and a certificate authority to issue short-lived leaf certificates for proxy TLS termination. It also implements a credential firewall chokepoint that stages and validates secret grants ahead of proxy consumption, hardens Docker daemon connectivity with bounded retries and remote-host restrictions, and defines container identity and workspace modes to ensure correct user ownership and permissions.
_crates/lanes/ironclaw\_sandbox/src/sandbox\process · high confidence
Ship WebChat v2 static assets and router
The WebChat v2 single-page application is now served directly from the \ironclaw\_webui\ crate. This change embeds the compiled frontend assets and provides an Axum router that serves them under the \/chat\, \/settings\, and other root paths, while maintaining legacy \/v2\ redirects for compatibility. The router handles client-side routing by returning the SPA shell for unknown paths and substitutes a per-request CSP nonce into the HTML to ensure security compliance.
_crates/product/ironclaw\_webui/src/webui\_v2/static\assets · high confidence
Slack channel adapter v2 introduces native Agent streaming and unified protocol handling
The Slack integration has been replaced with a new v2 adapter (\slack\_v2\) that supports Slack's native Agent streaming surface via \chat.startStream\, \chat.appendStream\, and \chat.stopStream\ endpoints, enabling progressive replies and session status updates. The adapter now normalizes all inbound Slack Events API payloads through a generic ingress router, handling complex scenarios like thread broadcasts, file shares, and canvas mentions with improved context fetching. Outbound delivery uses a new restricted-egress boundary for secure attachment transfers and message posting, with robust error classification for retries and authorization failures. The implementation includes a centralized API endpoint inventory to ensure lockstep with the manifest's egress allowlist, and introduces a new binding-ref grammar for reply targets that supports both shared channels and personal DMs.
crates/extensions/packages/slack/src · high confidence
Slack personal tool now supports all 16 core messaging operations with standardized error handling
The Slack personal (user-token) WASM tool has been expanded to support all 16 core operations of the standardized messaging framework, including search, conversation management, history retrieval, and message actions (send, edit, delete, react). All API responses are now mapped to the standardized messaging error taxonomy, ensuring consistent error reporting and improved reliability for users interacting with Slack via the tool.
crates/extensions/packages/slack/wasm-src · high confidence
Slack replies now use native progressive streaming with durable checkpoints
The Slack extension now delivers agent responses via Slack's native streaming API (startStream, appendStream, stopStream) instead of posting a single final message. This provides users with real-time, progressive updates including live answer text, collapsible task cards, and session status indicators. The implementation includes a durable checkpoint system that persists the state of the streaming message, allowing the system to safely resume and deduplicate updates after interruptions or retries without duplicating content in the Slack thread.
_crates/extensions/packages/slack/src/reply\sink · high confidence
Structure-preserving editing for DOCX, XLSX, and PPTX with HTML-to-PDF rendering
The \ironclaw\_documents\ crate now provides structured, format-aware editing for Word, Excel, and PowerPoint files (\.docx\, \.xlsx\, \.pptx\) while preserving all untargeted document parts—such as styles, images, and themes—byte-for-byte. For Word documents, the editor correctly surfaces tracked changes (redlines) on read and supports accepting or rejecting them, fixing a previous regression where deleted text was incorrectly visible. Excel edits allow setting cell formulas while automatically dropping stale cached values to ensure correct recalculation, and PowerPoint edits support cloning slides to preserve layout and theme inheritance. Additionally, the crate introduces a deterministic HTML-to-PDF renderer that converts a specific subset of HTML (headings, paragraphs, lists, and inline emphasis) into PDFs using standard fonts, ensuring consistent output across environments.
_crates/substrates/ironclaw\documents · high confidence
Structured extension activation with credential gating and admin configuration
The extension host now enforces a structured activation lifecycle that requires product authentication credentials before extensions using runtime credentials can activate, and introduces a manifest-driven admin configuration service for tenant administrators to manage extension settings securely. This change adds an activation credential gate that fails closed if required credentials are missing, an owner-side activation transaction that handles hosted MCP discovery and credential rechecks, and an immutable active snapshot system to ensure stable extension bindings during upgrades. Additionally, a new admin configuration service and store provide a durable, revisioned, and idempotent way for administrators to submit and manage extension configuration values, with secrets stored separately from non-secret metadata.
_crates/extensions/ironclaw\_extension\host/src · high confidence
Structured thread storage and attachment context handling
The thread service now persists transcripts and metadata using a filesystem-backed record system with explicit indexes for message lookup and thread listing, replacing previous storage mechanisms. It introduces a new capability display preview envelope to track and display the status and output of background capabilities, and adds structured attachment context rendering so that file references, extracted text, and image pointers are injected into model prompts and stripped from final outputs to prevent data leakage.
_crates/domains/ironclaw\threads/src · high confidence
WebUI documentation and artifact handling updates
This crate now includes AGENTS.md, CONTRACT.md, and README.md to document the WebChat v2 route surface, gateway assembly, and authentication subsystems, establishing the module spec and dependency boundaries. Additionally, the WebUI now exposes handlers for run and thread artifacts, allowing users to download artifacts associated with specific runs and threads via the \/api/webchat/v2/threads/{thread\_id}/runs/{run\_id}/artifact\ and \/api/webchat/v2/threads/{thread\_id}/artifact\ endpoints, as well as admin-scoped thread scrape artifacts.
_crates/product/ironclaw\webui · high confidence
WebUI v2 frontend scaffolding and build toolchain
The WebUI v2 frontend directory is now established with a complete build and development environment. This includes a Vite-based SPA entrypoint, a Storybook configuration for component cataloging (with strict accessibility checks and a controlled MCP dev addon), and a service worker enabling Web Push notifications with deep-linking. The toolchain enforces source conventions (TypeScript-only, no legacy tagged templates) and bundle budgets via custom scripts, while a dedicated NEAR wallet connect popup is provided as an isolated entrypoint.
_crates/product/ironclaw\webui/frontend · high confidence
Removals
Removal of legacy NEAR Agent source code
The legacy NEAR Agent implementation has been removed from the source tree. This change deletes the core configuration module (src/config.rs), the error handling definitions (src/error.rs), the library entry point (src/lib.rs), and the main application entry point (src/main.rs), effectively stripping out the previous monolithic agent framework and its associated startup logic, channel management, and LLM provider wiring.
src · high confidence
Removal of legacy PostgreSQL history and analytics persistence layer
The \src/history\ module, which previously provided PostgreSQL-based storage for job history, conversations, and analytics, has been removed. This deletes the \Store\ implementation for persisting agent jobs and conversation messages, as well as the \Analytics\ module that exposed job statistics, tool usage metrics, and estimation accuracy data. Users relying on the previous database-backed audit trail and learning/analytics features will no longer have access to these capabilities through this component.
src/history · high confidence
Removal of legacy agent framework components
The legacy agent implementation has been removed from the codebase. This change deletes the core \Agent\ loop, the \Router\ for message intent parsing, the \Scheduler\ for parallel job execution, the \Worker\ for per-job LLM reasoning, and the \SelfRepair\ module for detecting stuck jobs. Users will no longer have access to the previous monolithic agent architecture that handled message routing, job scheduling, and self-repair through these specific modules.
src/agent · high confidence
Removal of legacy channel subsystem
The legacy channel subsystem has been removed, deleting the \Channel\ trait, \IncomingMessage\/\OutgoingResponse\ types, and the \ChannelManager\. This eliminates the CLI, HTTP, Slack, and Telegram channel implementations from \src/channels\, indicating a migration to a new channel architecture or integration method.
src/channels · high confidence
Removal of legacy estimation subsystem
The entire \src/estimation\ module has been removed, deleting the legacy cost, time, value, and learning estimators along with their associated tests. This eliminates the previous capability to estimate job costs, durations, and profitability based on tool usage and historical learning models.
src/estimation · high confidence
Removal of legacy evaluation and built-in tool modules
The \src/evaluation\ module (including metrics collection and success evaluation logic) and the \src/tools/builtin\ directory (containing stub implementations for echo, HTTP, JSON, time, e-commerce, restaurant, marketplace, and TaskRabbit tools) have been deleted. This removes the previous rule-based job evaluation system and the set of placeholder built-in tools that returned 'not yet implemented' messages, streamlining the codebase by eliminating these unused or incomplete components.
src/tools · high confidence
Removal of legacy in-memory job context and state management
The \src/context\ module, which previously provided an in-memory system for managing job lifecycles, conversation history, and action records, has been removed. This includes the deletion of \ContextManager\ (which handled concurrent job isolation and memory), \JobContext\ and \JobState\ (which defined the job state machine and transitions), and \Memory\ (which tracked conversation and action history). Users relying on this specific in-memory context implementation for job tracking and state transitions will no longer have access to these components in this location.
src/context · high confidence
Removal of legacy safety module
The \src/safety\ module, which previously provided prompt injection defense, input validation, and policy enforcement for tool outputs, has been removed from the codebase. This deletion eliminates the legacy safety layer that sanitized external data and validated inputs before processing.
src/safety · high confidence
Removed legacy Anthropic and OpenAI LLM provider implementations
The legacy \src/llm\ module has been removed, deleting the standalone \AnthropicProvider\ and \OpenAiProvider\ implementations along with their associated reasoning, provider trait, and module definition files. This change eliminates the previous direct integration code for these providers, indicating a shift to a different architecture or provider management strategy for LLM interactions.
src/llm · high confidence
Security
Introduces a secure, registry-anchored hook lifecycle ownership model
The hook dispatcher now strictly enforces that lifecycle events (such as dispatch, decision, and failure notifications) are owned by the extension that registered the hook, rather than trusting the provider field carried in the event payload. This change, located in the new \lifecycle\_owner\ module, prevents potential spoofing where a synthesized event could impersonate another extension. Additionally, the dispatcher now implements a robust failure policy where gate and mutator hooks fail closed (blocking execution) on errors like timeouts or panics, while observer and lifecycle hooks fail isolated (dropping the result but continuing), with all misbehaving hooks being poisoned for the remainder of the turn run.
_crates/loop/ironclaw\hooks/src · high confidence
Architecture
Agent loop executor refactored into modular, stage-based pipeline
The agent loop execution engine has been restructured from a monolithic implementation into a modular, stage-based pipeline. The new architecture introduces a \DefaultPlanner\ that composes specific strategies (context, compaction, capability, model, gate, recovery, reply admission, stop, drain, and budget) and a \CanonicalAgentLoopExecutor\ that drives the loop through distinct, testable stages such as \BudgetStage\, \AssistantReplyStage\, and \CapabilityStage\. This change improves the maintainability and testability of the loop mechanics by isolating concerns like budget enforcement, capability dispatch, and reply handling into separate modules, while preserving the existing strategy composition interface.
_crates/loop/ironclaw\_agent\loop/src · high confidence
Host runtime obligation handling is split into three dedicated modules
The obligation handling logic in the host runtime has been refactored from a single file into three distinct modules to separate concerns: \handler.rs\ now owns the decision logic for which obligations apply and their pre/post-dispatch actions; \staged\_handoffs.rs\ manages one-shot secret material and per-invocation network policy staging; and \process\_store.rs\ handles post-start cleanup, discarding handoffs, and reconciling resource reservations. This split ensures no single file fuses these responsibilities, improving maintainability and clarity of the obligation lifecycle.
_crates/kernel/ironclaw\_host\runtime/src/obligations · high confidence
New extension support crate for first-party tools and skills
A new \ironclaw\_extension\_support\ crate has been introduced to host concrete implementation logic for first-party userland extensions, including web access, G Suite integration, and skill management. This change consolidates previously scattered or host-runtime-adjacent code into a dedicated module, providing the actual execution behavior for capabilities like web search, file access, and skill installation/removal, while the host runtime retains responsibility for declaration, authorization, and lifecycle wiring.
_crates/extensions/ironclaw\_extension\support/src · high confidence
Unified filesystem backend with lock-free CAS and composite mounting
The \ironclaw\_filesystem\ crate now provides a single, unified \RootFilesystem\ trait that all storage backends implement, replacing the previous per-crate store implementations. This change introduces a composite filesystem (\CompositeRootFilesystem\) that dispatches operations to mounted backends by longest-prefix match, enforcing strict capability validation at mount time to prevent misconfiguration. To resolve runtime wedging caused by mutex convoys under high contention, the crate includes a shared, mutex-free compare-and-swap (CAS) helper (\cas\_update\) that uses optimistic retries with jittered exponential backoff and bounded timeouts. The update also adds a fault-injection decorator for testing, a placeholder HSM backend to demonstrate the new dispatch seam, and an in-memory reference backend that serves as the default for tests.
_crates/substrates/ironclaw\filesystem/src · high confidence
Behavioural changes
7 commits (2 fixes) modifying crates/extensions/packages/slack/wasm
A change to existing behaviour in crates/extensions/packages/slack/wasm — 7 commits (2 fixs), 1 file.
crates/extensions/packages/slack/wasm · medium confidence · unverified
Admin-scoped secret provisioning and automation trigger migration
The system now supports administrators provisioning secrets for arbitrary target users via a new \FilesystemAdminSecretProvisioner\ in \admin\_secrets.rs\, allowing admin-scoped access to user-specific secret stores. Additionally, a one-time migration (\trigger\_delivery\_migration.rs\) rewrites legacy per-trigger delivery targets into the routine's prompt to ensure automated triggers continue delivering results correctly after the retired \delivery\_target\ field is removed. The automation subsystem also introduces a new \TriggerPoller\ with lifecycle management, active run lookup, and trusted fire submission, replacing the previous delivery mechanism.
_crates/app/ironclaw\composition/src · high confidence
Capability invocation and authorization logic restructured into the kernel
The capability invocation, authorization, and dispatch workflows have been moved into the \ironclaw\_capabilities\ kernel crate. This change centralizes the handling of capability invocations, including the authorization fold, approval and authentication resume paths, and the dispatch of pre-bound capability adapters. Users will see this as a refactoring of the underlying runtime mechanics; the external behavior for invoking capabilities remains consistent, but the internal handling of authorization decisions, lease management, and error mapping is now managed by the kernel's \CapabilityHost\ and \RuntimeDispatcher\ components.
_crates/kernel/ironclaw\capabilities/src · high confidence
Conversation state persistence migrates to a filesystem-backed store
Conversation binding and inbound-message state is now persisted to disk via a new \ConversationStateStore\ that writes a single JSON envelope to \/conversations/state.json\ on a \ScopedFilesystem\. This replaces the previous in-memory-only approach (and the legacy libSQL/Postgres adapters) with a tenant-isolated, file-based backend that uses compare-and-swap retries for concurrency control. The migration preserves the existing \ConversationStateRepository\ contract and includes durable serialization adapters to ensure backward compatibility with previously stored records.
_crates/domains/ironclaw\conversations/src · high confidence
Database schema expanded to support multi-tenant users, OAuth identities, and a new root filesystem backend
The database schema has been significantly expanded with migrations V14 through V33. Multi-tenant user management is now supported via new \users\ and \api\_tokens\ tables, replacing static environment variables, while \user\_identities\ enables OAuth and social login linking. Security and operational improvements include \channel\_identities\ and \pairing\_requests\ for secure channel authorization, \conversation\_source\_channel\ to prevent cross-channel approval hijacking, and \job\_token\_budget\ columns to enforce agent token limits. The legacy file storage is augmented by a new \root\_filesystem\_entries\ backend with event-sourced sequences and ordered index rows, alongside fixes for LIKE-injection vulnerabilities in workspace file listing and a bump to the WASM fuel limit.
migrations · high confidence
Enforce pre-commit version checks and pre-push quality gates
The repository now installs Git hooks in .githooks to enforce code quality and consistency before commits and pushes. The pre-commit hook blocks commits that modify WIT or extension sources unless version bumps are correctly registered, ensuring ABI compatibility. The pre-push hook runs a series of quality gates, including a clean merge check against the base branch, static analysis for Docker COPY coverage and hermetic environment usage, and optional strict linting or E2E provider replays, preventing regressions from reaching the remote repository.
.githooks · high confidence
Enhanced secret redaction and new fuzz testing for the safety layer
The \ironclaw\_safety\ crate now provides more robust protection against secret leaks by redacting complete PEM and SSH private-key blocks (previously only the begin sentinels were hidden) and rejecting matches that cross message boundaries. It also adds validated redaction for all retention boundaries. To ensure these detection and sanitization primitives remain reliable, the crate now includes a comprehensive fuzz-testing suite (using \cargo-fuzz\) covering the sanitizer, validator, leak detector, and credential detection logic, along with new benchmarks to track performance.
_crates/substrates/ironclaw\safety · high confidence
Event store performance optimization via write-behind coalescing and filesystem-backed durability
The event store now uses a \CoalescingEventSink\ to buffer runtime events and flush them as batched multi-row inserts, significantly reducing database round-trips during high-throughput periods. This optimization is best-effort and may drop events under extreme load to avoid blocking the application, though crash loss is limited to a sub-second tail. Additionally, the durable log implementation has migrated to a filesystem-backed abstraction (\FilesystemDurableEventLog\), routing writes through a unified \ScopedFilesystem\ layer instead of direct SQL calls, which simplifies the storage backend dispatch and prepares for future tenant-isolation improvements.
_crates/events/ironclaw\_event\store/src · high confidence
GitHub extension restructured with v3 manifest and compact tool responses
The GitHub extension has been reorganized under \crates/extensions/packages/github\ with a new \manifest.toml\ (schema \reborn.extension\_manifest.v3\) that defines 49 tools and authentication configuration. For users, this brings two key behavioral changes: the \github.get\_file\_content\ tool now returns decoded UTF-8 text instead of base64-encoded content, and high-cardinality list/search tools (such as \list\_repos\, \list\_pull\_requests\, and \search\_issues\_pull\_requests\) return compact summaries rather than full provider objects, requiring calls to specific detail tools (like \get\_repo\ or \get\_pull\_request\) for complete information.
crates/extensions/packages/github · high confidence
Google Drive, Sheets, and Slides extensions migrated to new WASM-based package structure
The Google Drive, Google Sheets, and Google Slides extensions have been restructured into a new package format where the tool logic runs as WebAssembly (WASM) guests. This change introduces new manifest definitions, input/output schemas, and prompt documents for each extension, while the core functionality (such as file management in Drive and spreadsheet operations in Sheets) remains consistent. Users will experience these extensions as data-only packages that rely on shared Google OAuth credentials, with the underlying implementation now leveraging a standardized WASM runtime for better portability and security isolation.
crates/extensions/packages/google-drive, crates/extensions/packages/google-sheets, crates/extensions/packages/google-slides · high confidence
Host runtime capability handling and extension discovery refactored
The host runtime now centralizes how capabilities are discovered, validated, and processed. A new capability catalog resolves extension schemas and enforces visibility rules before publishing them to the model, while a dedicated response processor unifies the handling of capability outcomes (success, auth/approval requirements, and failures) across fresh invocations and resumes. Extension discovery is now bounded and tolerant to prevent malformed manifests from blocking the system. Additionally, document outputs from capabilities like Google Drive downloads are now extracted and sanitized on the host side before reaching the model, and first-party capability handlers are dispatched through a standardized request and result structure.
_crates/kernel/ironclaw\_host\runtime/src · high confidence
Host runtime service graph and extension tool binding refactored
The host runtime's service composition and extension tool execution paths have been restructured. A new \HostRuntimeServices\ builder pattern replaces the previous construction method, allowing explicit wiring of root filesystems (Postgres or LibSQL) and resource governors. A dedicated production wiring validation layer (\ProductionWiringConfig\) now enforces that critical components like trust policies, event sinks, and credential brokers are correctly configured before the runtime is exposed, preventing silent misconfigurations in production. Additionally, extension tools are now bound to their specific runtime lanes via a new \ExtensionLaneToolBinder\, which pre-associates extension packages with their execution lanes and routes capability calls through a standardized \ToolAdapter\ interface, ensuring consistent resource accounting and error handling across all extension types.
_crates/kernel/ironclaw\_host\runtime/src/services · high confidence
Introduces projection stream admission, access control, and redaction validation
The \ironclaw\_event\_streams\ crate now enforces strict limits and security checks on projection streams. It introduces an admission policy that caps concurrent streams per tenant, user, scope, and globally (defaulting to 64 per tenant, 16 per actor, 8 per scope, and 512 global) to prevent resource exhaustion. Access is governed by an authorization policy, and all stream payloads are validated against a redaction validator that rejects envelopes containing sensitive sentinels (such as raw prompts, secrets, or host paths) before delivery. The \EventStreamManager\ coordinates these checks alongside live update subscriptions and snapshot fetching.
_crates/events/ironclaw\_event\streams/src · high confidence
Mark codebase memory snapshot as binary in Git
The compressed codebase knowledge graph snapshot (graph.db.zst) is now explicitly treated as a binary file in Git. This prevents line-ending conversions and ensures that conflict resolution requires regenerating the snapshot rather than attempting to merge the compressed data.
.codebase-memory · high confidence
New documentation and shared WASM resource limiter crate
This change introduces two new crates with accompanying documentation. The \ironclaw\_prompt\_envelope\ crate provides a \wrap\_untrusted\ primitive that prefixes untrusted content (from memory, hooks, or skills) with a trust marker, rejects instruction-hijack phrases, and enforces a 4 KiB byte budget to prevent context-window flooding. The \ironclaw\_wasm\_limiter\ crate centralizes the \WasmResourceLimiter\ implementation, previously duplicated in \ironclaw\_wasm\, to ensure consistent resource ceilings (memory, tables, instances) across all WASM hosts (\ironclaw\_wasm\ and \ironclaw\_hooks\) and adds logic to roll back pending memory growth if an OS-level allocation fails.
_crates/contracts/ironclaw\_prompt\_envelope, crates/lanes/ironclaw\_wasm\limiter · high confidence
New product-adapter contract module with strict auth evidence sealing and capability definitions
The \product\_adapter\ module in \ironclaw\_host\_api\ has been restructured to enforce stricter security boundaries and clearer capability declarations. Protocol authentication evidence is now sealed using witness tokens (replacing the previous \host-auth-mint\ cargo feature), ensuring that verified claims can only be minted by specific trusted components (\ironclaw\_webui\ for bearer/session and \ironclaw\_extension\_host\ for channel/webhook) and cannot be forged or replayed. Additionally, the module introduces typed capability flags (\ProductCapabilityFlag\) that allow adapters to declare supported features like inbound messages, attachments, and push delivery, enabling the workflow layer to apply safe presentation defaults. Identity types for adapters and installations are also standardized with strict validation rules to prevent injection attacks.
_crates/contracts/ironclaw\_host\_api/src/product\adapter · high confidence
Process journal store rewritten for batched writes and legacy migration
The process journal store has been completely rewritten to replace the previous per-command transaction model with a group-commit funnel that batches up to 64 commands into a single transaction, significantly reducing backend lock contention and improving write throughput. The new implementation includes a dedicated flusher task for command batching, an asynchronous observer delivery system to prevent re-entrancy deadlocks, and a comprehensive migration layer that imports legacy turn records, runs, checkpoints, and idempotency data from the deployed filesystem into the new journal format.
_crates/kernel/ironclaw\_processes/src/journal\store · high confidence
Process sandbox container enforces egress lockdown via iptables
The Docker entrypoint script for the process sandbox now supports an 'egress lockdown' mode. When the IRONCLAW\_EGRESS\_LOCKDOWN environment variable is set to 'broker-only', the container restricts all outbound network traffic to only the specified broker proxy, dropping all other connections via iptables rules. This ensures that sandboxed processes can only communicate with the designated broker, enhancing security by preventing unauthorized network access.
docker · high confidence
Resource governor journal retries through full libSQL write attempts to prevent write-lane starvation
The \ironclaw\_resources\ crate now implements a robust retry policy for its delta journal when the underlying libSQL backend reports \BackendBusy\. Previously, transient database congestion could cause the journal to give up, leading to write-lane starvation and cascading failures in the resource governor. The new logic ensures the journal continues retrying through a full libSQL writer attempt (including checkout timeouts and busy timeouts), preventing transient database load from blocking resource reservations and reconciliations.
_crates/kernel/ironclaw\resources · high confidence
Secure, staged credential injection for outbound HTTP requests
The host runtime now enforces a strict, staged credential-injection pipeline for all outbound HTTP egress. Instead of allowing raw secrets or manual headers to be passed directly, credentials are resolved from a secret store or staged obligations, injected into request headers, query parameters, or JSON bodies, and then redacted from responses. This change blocks sensitive headers (like Authorization or Cookie) and manual credentials in runtime requests to prevent leaks, while ensuring that secret material is zeroized immediately after use and that response bodies are sanitized against credential leaks.
_crates/kernel/ironclaw\_host\runtime/src/egress · high confidence
Shared libSQL runtime enforces single-writer admission and bounded connection pools
The \ironclaw\_libsql\_runtime\ crate now provides a centralized connection-admission layer for libSQL databases, ensuring that all writers queue behind a single-slot writer lane to prevent write-lane starvation and cascading failures. It exposes a bounded reader pool (8 connections) and a strict single-writer pool, with read leases restricted to query-only operations via \PRAGMA query\_only = ON\. The runtime includes typed failure classifications for retry logic, configurable connection timeouts (10s checkout deadline), and safeguards against reentrant writer acquisition, isolating the libSQL driver dependencies from the rest of the workspace.
_crates/substrates/ironclaw\_libsql\runtime · high confidence
Skill activation now falls back to name and description when no keywords are defined
The skill selection logic now supports a \NameAndDescription\ activation strategy that scores skills based on their name and description fields when explicit activation keywords or tags are missing. This change ensures that agent-authored skills, which often lack explicit activation metadata, remain discoverable and selectable by the model. The system preserves the existing \CriteriaOnly\ behavior as the default for backward compatibility, while allowing explicit mention or \skill\_activate\ calls to bypass criteria-based activation entirely when needed.
_crates/domains/ironclaw\skills/src · high confidence
Standardized first-party extension package inventory
The extension support crate now centrally defines the inventory and onboarding metadata for all bundled first-party integrations (GitHub, Gmail, Google Workspace, Notion, Slack, Telegram, Web Access, and NEAR AI). Each integration is represented by a dedicated module that bundles its manifest, input/output JSON schemas, prompt documentation, and WASM binaries (where applicable) into a unified \PackageBundle\. This change introduces a structured, host-mediated trust model where effect grants (such as OAuth scopes and network access) are explicitly declared per package, and standardizes the onboarding flow with consistent credential instructions and setup URLs for user-facing configuration.
_crates/extensions/ironclaw\_extension\support/src/packages · high confidence
Structured automation execution and deterministic no-result suppression
The trigger domain now uses a structured \TriggerExecutionSpec\ to define automation goals, success criteria, output instructions, and a new \no\_result\text\ field. This enables deterministic suppression of trigger runs that produce no results: when the execution policy is set to \SuppressWhenNothingToReport\, the system injects a specific instruction into the prompt to call \builtin\\_structured\_result\ with \outcome: nothing\_to\_report\ instead of returning an empty or negative response. The crate also introduces \TriggerCapabilityCallFacts\ to expose exact run capability facts and implements fire-time access checks to ensure the trigger creator retains authorization at execution time.
_crates/domains/ironclaw\triggers/src · high confidence
Telegram extension restructured into a single package with separated bot and personal account access
The Telegram extension has been consolidated into a single \telegram\ package (\crates/extensions/packages/telegram\) that manages both the workspace bot channel and the user's personal linked account. This change separates the two access paths: the workspace bot now uses a generic generated-code pairing service, while personal account access uses device linking over MTProto. The package includes a new manifest defining 15 tools for the linked account (such as send, edit, delete, and search messages) and updates the README and agent guidance to reflect the new structure. Existing installations are migrated automatically on restart without requiring a database schema change.
crates/extensions/packages/telegram · high confidence
WASM tool runtime adopts typed WIT component-model ABI
The WASM execution lane now uses the \near:agent@0.4.1\ WIT contract for tool invocations, replacing the retired JSON-pointer/length (\invoke-json\) ABI. Guests must target this specific contract version; components compiled against other versions fail closed with an unsupported-contract error during instantiation. Tool responses are now typed (\WitToolOutcome::Success\/\Failure\) rather than opaque blobs, and guest-reported failures include structured error codes and messages. The lane also enforces stricter sandboxing: host capabilities are deny-by-default, execution uses fresh component instances per call, and guest error text is scrubbed for secrets and bounded to 4 KiB before crossing the sandbox boundary.
_crates/lanes/ironclaw\wasm · high confidence
Fixes
Agent turns now persist activation provenance and lineage metadata through terminal transitions
The process projection layer in \crates/kernel/ironclaw\_turns/src/process\_projection\ now ensures that subagent activation provenance, subagent depth, and spawn tree descendant caps are preserved in the durable process journal when a run completes. Previously, these lineage fields were lost during the terminal metadata rewrite, which caused autonomous-wake capabilities to silently stop firing after the first completed run. This change also introduces a comprehensive set of tests to verify that activation provenance survives serialization and round-trips correctly through the durable metadata envelope.
_crates/kernel/ironclaw\_turns/src/process\projection · high confidence
Test coverage
Added comprehensive test coverage for loop host core contracts; Added comprehensive test coverage for the Ironclaw host runtime; Added comprehensive test coverage for the ironclaw\_filesystem crate; Added comprehensive tests for the Railway sandbox process; Added comprehensive tests for the ironclaw\_hooks predicate state backends; Added contract and smoke tests for CLI documentation, extension lifecycle, and binary behavior; Added contract tests for Reborn configuration resolution and profiles; Added contract tests for conversation state persistence and inbound turn handling; Added contract tests for native memory components; Added contract tests for outbound policy and state store; Added contract tests for process journal durability and host lifecycle; Added contract tests for product-tier vocabulary and stream responses; Added contract tests for reply document bounds and inbound seal verification; Added contract tests for the EventStreamManager; Added contract tests for the capability host authorization and dispatch flow; Added contract tests for the durable notification inbox store; Added contract tests for the extension host lifecycle, ingress routing, and admin configuration; Added contract tests for the extension registry; Added contract tests for the reborn event store and filesystem log; Added contract tests for the secret store and dependency boundaries; Added contract tests for thread service and structured finalization; Added end-to-end tests for admin API, auth flows, and budget controls; Added integration and contract tests for the sandbox subsystem; Added integration tests for Google Calendar and Gmail extension capabilities; Added integration tests for agent loop executor behavior; Added repository contract tests for the trigger storage layer; Added test coverage for turn coordination, activation provenance, and metadata compatibility; Added test harness for the planned agent loop; Added test support harnesses for the Ironclaw host runtime; Added tests for Slack inbound event normalization; Added tests for loop exit validation and serialization; Added tests for operator config failure handling and idempotency ledger behavior; Added tests for skill routing accuracy and descriptor linting; Added tests for the Slack extension's manifest consistency, channel conformance, and reply sink reliability; Added tests for the turn runner lifecycle and driver registry; Contract tests for memory, run profiles, skills, and structured results; Contract tests for the OpenAI-compatible API surface; Expanded contract test coverage for assistant subsystems; Expanded test coverage for WebUI v2 authentication, security, and network limits; Introduce repo-wide scenario test coverage map and E2E authoring guidance; New architecture ratchets enforce Reborn design contracts and prevent regression; Refactored runtime context tests into a dedicated module.
Dependencies
Introduce IronClaw Reborn workspace with new crate structure and dependencies
The project has been restructured into a new Rust workspace named IronClaw Reborn, introducing a layered architecture with distinct crates for contracts (host API, product, extension, loop), application components (CLI, composition, config), and various domain/substrate/loop/kernel modules. This change establishes the foundational dependency graph for the new architecture, including the standalone CLI binary (\ironclaw\), the composition root, and the WebUI, while removing the legacy monolithic source structure.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 43 → 50 (+7.0)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.17) — scores are not directly comparable.
Lenses
- Code Health 77 → 78 (+0.3)
- Architecture 76 → 75 (-0.7)
- Maturity 87 → 87 (-0.1)
- Readiness 51 → 41 (-9.8)
- Security 23 → 46 (+22.9)
- Domain Modelling 91 → 93 (+2.1)
- Event-Driven 80 → 80 (+0.0)
- Event Sourcing 100 → 100 (+0.0)
- Accessibility 55 → 55 (+0.0)
- Performance 100 (new)
Resolved (106)
- CfgParser._expression (cognitive 25) (scripts/check_no_panics.py)
- CfgParser._expression (cyclomatic 17) (scripts/check_no_panics.py)
- Documentation: no contributor guidance (README.md)
- Documentation: no installation or build instructions (README.md)
- Documentation: no installation or build instructions (docs/internal/reborn/README.md)
- Documentation: no usage examples (README.md)
- FileTooLong: scripts/check_no_panics.py (scripts/check_no_panics.py)
- Hotspot: crates/app/ironclaw_cli/src/commands/config/set.rs (crates/app/ironclaw_cli/src/commands/config/set.rs)
- Hotspot: crates/app/ironclaw_cli/src/commands/traces/mod.rs (crates/app/ironclaw_cli/src/commands/traces/mod.rs)
- Hotspot: crates/app/ironclaw_cli/src/runtime/mod.rs (crates/app/ironclaw_cli/src/runtime/mod.rs)
- Hotspot: crates/contracts/ironclaw_common/src/llm_costs.rs (crates/contracts/ironclaw_common/src/llm_costs.rs)
- Hotspot: crates/contracts/ironclaw_host_api/src/messaging.rs (crates/contracts/ironclaw_host_api/src/messaging.rs)
- Hotspot: crates/contracts/ironclaw_loop_contracts/src/content_digest.rs (crates/contracts/ironclaw_loop_contracts/src/content_digest.rs)
- Hotspot: crates/contracts/ironclaw_loop_contracts/src/host/progress.rs (crates/contracts/ironclaw_loop_contracts/src/host/progress.rs)
- Hotspot: crates/domains/ironclaw_attachments/src/project_scoped.rs (crates/domains/ironclaw_attachments/src/project_scoped.rs)
- Hotspot: crates/domains/ironclaw_extractors/src/lib.rs (crates/domains/ironclaw_extractors/src/lib.rs)
- Hotspot: crates/domains/ironclaw_llm/src/agent_message.rs (crates/domains/ironclaw_llm/src/agent_message.rs)
- Hotspot: crates/domains/ironclaw_llm/src/reasoning.rs (crates/domains/ironclaw_llm/src/reasoning.rs)
- Hotspot: crates/domains/ironclaw_llm/src/recording.rs (crates/domains/ironclaw_llm/src/recording.rs)
- Hotspot: crates/domains/ironclaw_llm/src/smart_routing.rs (crates/domains/ironclaw_llm/src/smart_routing.rs)
- …and 86 more
New (162)
- Duplicated block (10 lines × 2) (scripts/reborn_qa_matrix/audit_quality_loop_status.py)
- Duplicated block (10 lines × 2) (scripts/reborn_webui_v2_live_qa/run_live_qa.py)
- Duplicated block (10 lines × 3) (scripts/telegram_smoke/run_smoke.py)
- Duplicated block (10 lines × 4) (scripts/workflow_canary/scenarios/bug_logger.py)
- Duplicated block (10–12 lines × 2) (scripts/live-canary/notify_slack.py)
- Duplicated block (10–15 lines × 2) (scripts/live_canary/common.py)
- Duplicated block (11 lines × 2) (scripts/reborn_qa_matrix/audit_defect_traceability.py)
- Duplicated block (11 lines × 2) (scripts/slack_smoke/run_smoke.py)
- Duplicated block (11–12 lines × 4) (scripts/reborn_webui_v2_live_qa/google_api_helpers.py)
- Duplicated block (12 lines × 2) (scripts/reborn_webui_v2_live_qa/run_live_qa.py)
- Duplicated block (12 lines × 2) (scripts/reborn_webui_v2_live_qa/run_live_qa.py)
- Duplicated block (12 lines × 2) (scripts/workflow_canary/scenarios/calendar_prep.py)
- Duplicated block (12–13 lines × 2) (scripts/ci/check-guidance.py)
- Duplicated block (13 lines × 2) (scripts/live_canary/common.py)
- Duplicated block (13 lines × 2) (scripts/reborn_webui_v2_live_qa/run_live_qa.py)
- Duplicated block (13–17 lines × 3) (scripts/reborn_webui_v2_live_qa/run_live_qa.py)
- Duplicated block (14 lines × 2) (scripts/reborn_qa_matrix/report_coverage.py)
- Duplicated block (14–15 lines × 2) (scripts/slack_smoke/run_smoke.py)
- Duplicated block (14–16 lines × 2) (scripts/reborn_webui_v2_live_qa/run_live_qa.py)
- Duplicated block (15 lines × 2) (scripts/ci/regression-test-check.py)
- …and 142 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
nearai/ironclaw was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit b0b999d96781516ee05e6ba961d6f3ead900da96 — the exact code this score is about.
- Scored under rubric-2026.09.17 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-70910855e4b4.