Skip to content

Pin native module releases to the host Rust toolchain - #6632

Closed
senamakel wants to merge 2 commits into
tinyhumansai:mainfrom
senamakel:fix-module-rustc-skew
Closed

senamakel wants to merge 2 commits into
tinyhumansai:mainfrom
senamakel:fix-module-rustc-skew

Conversation

@senamakel

@senamakel senamakel commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Pin the six affected native modules to releases built with the host's Rust 1.96.1 toolchain.
  • Take every platform digest from each release's published checksum.toml, and advance the three vendored module gitlinks and both Cargo lockfiles.
  • Align CI's native module fixtures with the product pins, extend the module pin gate to the three recently added modules, and add a release smoke check for toolchain warnings.

Problem

OpenHuman logs module rustc differs from host when it loads modules built with a floating Rust toolchain. The host pins Rust 1.96.1, but the six modules named in #6614 were still pinned to older archives.

Solution

The affected releases are tinymemory v1.16.1, tinyjuice v0.3.3, tinyruntime v0.2.6, tinyconnectors v0.10.2, tinyruntime-nodejs v0.2.3, and tinyruntime-python v0.2.3. Each release tag includes its merged toolchain pin. All 24 published macOS archives across macOS 15/26 and arm64/x86_64 were checked against their release checksum and their embedded TinyBus ABI descriptor; every archive reports rustc 1.96.1.

The provider modules are released separately from tinyruntime. Their exact shared-contract drift remains declared in module-pin-exemptions.json; the stale TinyMemory and TinyMCP exemptions are removed.

Submission Checklist

  • Tests added or updated: the module pin suite now includes the three recently registered module sources; existing failure-path assertions remain in that suite.
  • Diff coverage ≥ 80% — CI will report the changed-line gate; full coverage was not run locally.
  • Coverage matrix: N/A, no feature row or business behavior changed.
  • Affected feature IDs: N/A, release artifacts and CI pins only.
  • No new external network dependencies introduced; the product still downloads from the same pinned GitHub release sources.
  • Manual smoke checklist updated with native module loading and warning inspection.
  • Linked issue: Closes #6614 below.

Impact

Desktop module loading on macOS, Windows, and Linux uses newly pinned native archives. There is no data migration. The ABI, manifest, and digest admission checks remain intact.

Related

AI Authored PR Metadata

Linear Issue

Commit & Branch

  • Branch: fix-module-rustc-skew
  • Commits: eca36c83c9, fa3be4adb7 (kept separate).

Validation Run

  • pnpm --filter openhuman-app format:check — N/A; no frontend source changed and this worktree has no Node install.
  • pnpm typecheck — N/A; no frontend source changed.
  • Focused tests: 25 module pin tests; TinyMemory capability and CI digest Rust tests.
  • Rust fmt/check: root cargo fmt --all -- --check and locked root workspace cargo check.
  • Tauri fmt/check: locked cargo check --manifest-path crates/openhuman-app/Cargo.toml.
  • Workflow syntax: actionlint -shellcheck= on all four edited workflows. Existing unrelated ShellCheck findings prevent the unfiltered invocation from passing.

Validation Blocked

  • pnpm test:coverage: not run locally; the complete changed-line coverage check did not finish in CI Fast because its test lanes failed.
  • The same upstream base already fails Rust Quality and Feature-Gate Smoke. The PR run also reports frontend and Rust test fixture failures in files this PR does not change. This PR fixes that base run's Module Pin Gate failure.
  • Impact: the PR remains unmergeable until the unrelated base/test lane failures are repaired and changed-line coverage can be measured. The coverage checklist item above remains unchecked.

Behavior Changes

  • Intended behavior change: published module binaries and the host use the same rustc release.
  • User-visible effect: module loading no longer emits the toolchain mismatch warning for these six modules.

Parity Contract

  • Legacy behavior preserved: the module registry, release cache, and permissive TinyBus admission path remain in place.
  • Guard/fallback/dispatch parity checks: 13 module pins pass the registry/submodule gate, and both focused Rust pin tests pass.

Duplicate / Superseded PR Handling

  • Duplicate PR(s): none.
  • Canonical PR: this PR.
  • Resolution: N/A.

@senamakel
senamakel requested a review from a team September 24, 2026 18:53
@tinysweeper

tinysweeper Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

This PR updates module version pins to align with host Rust toolchain, adds new submodules to pin validation, and removes stale exemptions, but introduces CI failures due to missing submodule pointers and premature exemption removal. 6 active findings remain.

State: Changes requested
Priority: critical
Reviewed head: fa3be4adb790
Updated: 1790277418 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 6 Active findings 22
Tests 1 Noted findings 0
Documentation 1 Resolved findings 46
Configuration 5 Pending checks/questions 4

Completeness: Complete
Test assessment: Test coverage is assessed from changed tests and lane evidence; execution is not claimed without trusted check data.

What changed

The review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below.

Features

  • Modified — Bump tinymemory registry pin to 1.16.1: Updates the downloaded native module version and SHA-256 checksums for tinymemory across CI workflows, ensuring the module matches the host Rust toolchain. (crates/openhuman-core/src/modules/memory/capabilities.rs, .github/workflows/ci-full.yml, .github/workflows/ci-lite.yml, .github/workflows/e2e-playwright.yml, .github/workflows/e2e-reusable.yml)
  • Modified — Bump tinyjuice registry pin to 0.3.3: Updates the downloaded native module version and SHA-256 checksums for tinyjuice across CI workflows, ensuring the module matches the host Rust toolchain. (crates/openhuman-core/src/modules/registry/records_memory_juice.rs, .github/workflows/ci-full.yml, .github/workflows/ci-lite.yml, .github/workflows/e2e-playwright.yml, .github/workflows/e2e-reusable.yml)
  • Modified — Bump tinyconnectors registry pin to 0.10.2: Updates the downloaded native module version and SHA-256 checksums for tinyconnectors across all platforms, ensuring the module matches the host Rust toolchain. (crates/openhuman-core/src/modules/registry/records_mcp_connectors.rs)
  • Modified — Bump tinyruntime, tinyruntime-nodejs, tinyruntime-python registry pins: Updates the runtime providers to new versions (0.2.6, 0.2.3, 0.2.3 respectively) with updated SHA-256 checksums, ensuring they match the host Rust toolchain. (crates/openhuman-core/src/modules/registry/records_runtime.rs)
  • Added — Add tinybox, tinychannels, tinyhosts to pin-checking scripts: Extends the module pin verification gate to cover three new vendor submodules, ensuring their pins are checked alongside existing modules. (scripts/ci/check-module-pins.mjs, scripts/ci/fetch-submodule-tags.sh, scripts/__tests__/module-pins.test.mjs)
  • Removed — Remove tinymcp and tinymemory pin exemptions: Removes drift exemptions for tinymcp and tinymemory from the exemption list, tightening pin enforcement. However, the submodules are not yet updated, which will cause CI failures. (scripts/ci/module-pin-exemptions.json)
  • Modified — Update tinyruntime-nodejs and tinyruntime-python exemptions: Updates the expected submodule version for the runtime providers to v0.2.6 and adjusts reasons to reflect independent publishing. (scripts/ci/module-pin-exemptions.json)
  • Added — Add native modules smoke test step to release manual: Adds a manual smoke test checklist item to exercise each native module and verify no rustc version mismatch warnings. (docs/RELEASE-MANUAL-SMOKE.md)

Tests

  • addition — Adds tinybox, tinychannels, tinyhosts to the list of expected submodule paths in submodulesPresent() check.: Test will fail because these vendor submodules are not yet added to the repository, causing the pin gate to break. (scripts/__tests__/module-pins.test.mjs)

Findings

  • high · critique · Add submodules before requiring them in the pin gate — These entries make `check-module-pins.mjs` run git/tag checks against `vendor/tinybox`, `vendor/tinychannels`, and `vendor/tinyhosts`, but the complete diff contains no correspondi (scripts/ci/check\-module\-pins\.mjs:80)
  • high · critique · Add vendor submodules before referencing them in tests — `submodulesPresent()` now requires these three directories to be real tagged repositories, but this change does not add them as vendor submodules. Consequently the test helper retu (scripts/\_\_tests\_\_/module\-pins\.test\.mjs:87)
  • high · critique · Add submodules for tinybox, tinychannels, tinyhosts before referencing them — This adds three paths to an unconditional `git -C` loop, but the complete change does not add corresponding submodule entries/gitlinks. On a checkout where any of these directories (scripts/ci/fetch\-submodule\-tags\.sh:14)
  • high · critique · Update the vendored runtime pins with the registry release — This revision only changes the explanation for the independently published runtime providers; it does not advance the vendored `tinyruntime` submodule to the registry's runtime rel (scripts/ci/check\-module\-pins\.mjs:94)
  • high · critique · Advance the vendored TinyJuice pin with the registry release — The registry now selects TinyJuice 0.3.3, while this complete diff contains no corresponding `vendor/tinyjuice` submodule update. The module-pin check requires the registry release (crates/openhuman\-core/src/modules/registry/records\_memory\_juice\.rs:90)
  • high · critique · Pin TinyJuice to the registry release — The workflow now downloads TinyJuice 0.3.3, but the registry context for the current branch does not show a TinyJuice 0.3.3 record; the visible registry update is for `tinymcp` 0.3 (\.github/workflows/e2e\-playwright\.yml:78)
  • medium · critique · Refresh the runtime release documentation — The updated registry now advertises tinyruntime 0.2.6, but the unchanged module documentation immediately above still says the digests are v0.2.2's and describes the record as havi (crates/openhuman\-core/src/modules/registry/records\_runtime\.rs:26)
  • medium · critique · Exercise the pinned TinyConnectors release end to end — This changes the native module selected for every TinyConnectors installation, including all archive names and checksums, but the change adds no test that resolves the registry ent (crates/openhuman\-core/src/modules/registry/records\_mcp\_connectors\.rs:97)
  • medium · security · Exercise the TinyConnectors 0.10.2 release end to end — This changes the native module selected for connector use and all of its platform checksums, but the change adds no test that resolves the 0.10.2 registry entry, admits and loads a (crates/openhuman\-core/src/modules/registry/records\_mcp\_connectors\.rs:97)
  • medium · security · Exercise the TinyJuice 0.3.3 release end to end — This changes the native TinyJuice release selected by the registry, including every platform archive and checksum, but the change adds no registry-driven test that admits and loads (crates/openhuman\-core/src/modules/registry/records\_memory\_juice\.rs:90)
  • high · tests · Advance vendor/tinyruntime submodule to v0.2.6 — The registry record for `tinyruntime` is bumped from v0.2.5 to v0.2.6, and the corresponding submodule pointer at `vendor/tinyruntime` must be updated to match. The diff does not i (crates/openhuman\-core/src/modules/registry/records\_runtime\.rs:26)
  • high · tests · Advance vendor/tinyjuice submodule to v0.3.3 — The registry record for `tinyjuice` is bumped from v0.3.2 to v0.3.3, but the vendored submodule at `vendor/tinyjuice` remains unchanged in this diff. Advance the submodule pointer (crates/openhuman\-core/src/modules/registry/records\_memory\_juice\.rs:90)
  • high · tests · Advance vendor/tinymemory submodule to v1.16.1 — The `ARTIFACT_CAPABILITIES_PIN` is bumped to `1.16.1`, and all workflow `memory_version` pins are updated to match the registry. The diff does not update the `vendor/tinymemory` su (crates/openhuman\-core/src/modules/memory/capabilities\.rs:13)
  • medium · tests · Retain the tinymcp exemption until the submodule matches the registry — The diff removes the tinymcp exemption from `module-pin-exemptions.json` without updating the `vendor/tinymcp` submodule pointer to a tag that matches the registry version (still v (scripts/ci/module\-pin\-exemptions\.json:24)
  • medium · tests · Retain the tinymemory exemption until the submodule matches the registry — The diff removes the tinymemory exemption from `module-pin-exemptions.json` without updating the `vendor/tinymemory` submodule pointer to a tag that matches the new registry versio (scripts/ci/module\-pin\-exemptions\.json:24)
  • critical · description · Retain the tinymcp exemption until the registry pin matches the submodule — The PR removes the tinymcp exemption from `module-pin-exemptions.json` without updating the registry pin to a version that matches the submodule tag. The submodule is at `v0.3.2-15 (\(pull request description\))
  • high · description · Add vendor submodules before referencing them in scripts — The pin-check script, the tag-fetching script, and the test file now reference `vendor/tinybox`, `vendor/tinychannels`, and `vendor/tinyhosts`, but no corresponding submodule entri (\(pull request description\))
  • high · e2e · Update vendored runtime submodule pin to match registry — The registry record for tinyruntime now advertises v0.2.6, but the diff does not include a corresponding update to the `vendor/tinyruntime` submodule gitlink. The module-pin check (crates/openhuman\-core/src/modules/registry/records\_runtime\.rs:26)
  • high · e2e · Add vendor submodules for tinybox, tinychannels, tinyhosts before referencing t… — The PIN_MAP and fetch-submodule-tags.sh now reference vendor/tinybox, vendor/tinychannels, and vendor/tinyhosts, but these submodules have not been added to .gitmodules or the tree (scripts/ci/check\-module\-pins\.mjs:80)
  • medium · e2e · End-to-end job `Rust Feature-Gate Smoke (gates off)` will not run on this change — `Rust Feature-Gate Smoke (gates off)` in `.github/workflows/ci-lite.yml` will not run for this pull request: the forge reports it as skipped, so a job condition was false for this (\.github/workflows/ci\-lite\.yml)
  • medium · e2e · Ensure the Rust Feature-Gate Smoke job runs on this change — The CI status shows that the `Rust Feature-Gate Smoke (gates off)` job is not triggered. This job verifies the module-pin check and other gates. Without it, a regression in the pin (\.github/workflows/ci\-lite\.yml)
  • medium · e2e · Exercise the TinyJuice 0.3.3 release end to end — The registry pins TinyJuice v0.3.3 with updated platform assets and checksums, but no end-to-end test actually loads this module, calls its compression/retrieval methods, or verifi (crates/openhuman\-core/src/modules/registry/records\_memory\_juice\.rs:90)

Resolved this pass

  • Update the vendored runtime pins with the registry release
  • Retain exemptions until the registry pins are updated
  • Add submodules for tinybox, tinychannels, tinyhosts before referencing them
  • Add vendor submodules before referencing them in test paths
  • Refresh the runtime release documentation
  • End-to-end job `Rust Feature-Gate Smoke (gates off)` will not run on this change
  • Update the vendored runtime pins with the registry release
  • Retain exemptions until the registry pins are updated
  • Add submodules for tinybox, tinychannels, tinyhosts before referencing them
  • Add vendor submodules before referencing them in test paths
  • Refresh the runtime release documentation
  • End-to-end job `Rust Feature-Gate Smoke (gates off)` will not run on this change
  • Refresh the runtime release documentation
  • Update the vendored runtime pins with the registry release
  • Retain exemptions until the registry pins are updated
  • Update the vendored runtime pins with the registry release
  • Retain exemptions until the registry pins are updated
  • Add submodules for tinybox, tinychannels, tinyhosts before referencing them
  • Add vendor submodules before referencing them in test paths
  • Refresh the runtime release documentation
  • End-to-end job `Rust Feature-Gate Smoke (gates off)` will not run on this change
  • Update the vendored runtime pins with the registry release
  • Retain exemptions until the registry pins are updated
  • Add submodules for tinybox, tinychannels, tinyhosts before referencing them
  • Add vendor submodules before referencing them in test paths
  • Refresh the runtime release documentation
  • Update the vendored runtime pins with the registry release
  • Retain exemptions until the registry pins are updated
  • Add submodules for tinybox, tinychannels, tinyhosts before referencing them
  • Add vendor submodules before referencing them in test paths
  • Refresh the runtime release documentation
  • End-to-end job `Rust Feature-Gate Smoke (gates off)` will not run on this change
  • Update the vendored runtime pins with the registry release
  • Retain exemptions until the registry pins are updated
  • Add submodules for tinybox, tinychannels, tinyhosts before referencing them
  • Add vendor submodules before referencing them in test paths
  • End-to-end job `Rust Feature-Gate Smoke (gates off)` will not run on this change
  • Update the vendored runtime pins with the registry release
  • Retain exemptions until the registry pins are updated
  • Add submodules for tinybox, tinychannels, tinyhosts before referencing them
  • Add vendor submodules before referencing them in test paths
  • Refresh the runtime release documentation
  • End-to-end job `Rust Feature-Gate Smoke (gates off)` will not run on this change
  • Update the vendored runtime pins with the registry release
  • Refresh the runtime release documentation
  • Refresh the runtime release documentation

Pending checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)

Before merge

  • Address Add submodules before requiring them in the pin gate (scripts/ci/check\-module\-pins\.mjs).
  • Address Add vendor submodules before referencing them in tests (scripts/\_\_tests\_\_/module\-pins\.test\.mjs).
  • Address Add submodules for tinybox, tinychannels, tinyhosts before referencing them (scripts/ci/fetch\-submodule\-tags\.sh).
  • Address Update the vendored runtime pins with the registry release (scripts/ci/check\-module\-pins\.mjs).
  • Address Advance the vendored TinyJuice pin with the registry release (crates/openhuman\-core/src/modules/registry/records\_memory\_juice\.rs).
  • Address Pin TinyJuice to the registry release (\.github/workflows/e2e\-playwright\.yml).
  • Address Advance vendor/tinyruntime submodule to v0.2.6 (crates/openhuman\-core/src/modules/registry/records\_runtime\.rs).
  • Address Advance vendor/tinyjuice submodule to v0.3.3 (crates/openhuman\-core/src/modules/registry/records\_memory\_juice\.rs).
  • Address Advance vendor/tinymemory submodule to v1.16.1 (crates/openhuman\-core/src/modules/memory/capabilities\.rs).
  • Address Retain the tinymcp exemption until the registry pin matches the submodule (\(pull request description\)).
  • Address Add vendor submodules before referencing them in scripts (\(pull request description\)).
  • Address Update vendored runtime submodule pin to match registry (crates/openhuman\-core/src/modules/registry/records\_runtime\.rs).
  • Address Add vendor submodules for tinybox, tinychannels, tinyhosts before referencing t… (scripts/ci/check\-module\-pins\.mjs).
  • Wait for Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS).

How this fits together

flowchart LR
  n0["entry"]:::impacted
  n1["path"]:::impacted
  n2["join"]:::impacted
  n3["readRustModule"]:::impacted
  n4["readRegistry"]:::impacted
  n0 -->|calls| n3
  n1 -->|uses| n0
  n3 -->|calls| n2
  n4 -->|uses| n0
  n4 -->|uses| n1
  n4 -->|calls| n2
  n4 -->|calls| n3
  classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
  classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
  classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
  classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Loading
Agent review details

critique

  • Conclusion: Failure
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 13 files; 8 findings. (2 observation(s) grouped into shared inline comments) _The code index is behind this pull request (indexed at `b17623827a7a`), so retrieved context may be out of date._ _5 memory call(s) failed (model: cortex: v1/recall: timed out after 10s), so this review saw part of what the engine holds._
  • Evidence: scripts/ci/check\-module\-pins\.mjs — Add submodules before requiring them in the pin gate
  • Evidence: scripts/\_\_tests\_\_/module\-pins\.test\.mjs — Add vendor submodules before referencing them in tests
  • Evidence: scripts/ci/fetch\-submodule\-tags\.sh — Add submodules for tinybox, tinychannels, tinyhosts before referencing them
  • Evidence: scripts/ci/check\-module\-pins\.mjs — Update the vendored runtime pins with the registry release
  • Evidence: crates/openhuman\-core/src/modules/registry/records\_memory\_juice\.rs — Advance the vendored TinyJuice pin with the registry release
  • Evidence: \.github/workflows/e2e\-playwright\.yml — Pin TinyJuice to the registry release
  • Evidence: crates/openhuman\-core/src/modules/registry/records\_runtime\.rs — Refresh the runtime release documentation
  • Evidence: crates/openhuman\-core/src/modules/registry/records\_mcp\_connectors\.rs — Exercise the pinned TinyConnectors release end to end

security

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 12 files; 2 findings. 1 file was not security-reviewed: docs/RELEASE-MANUAL-SMOKE.md (prose or tabular data). (1 observation(s) grouped into shared inline comments) _The code index is behind this pull request (indexed at `b17623827a7a`), so retrieved context may be out of date._ _5 memory call(s) failed (model: cortex: v1/recall: timed out after 10s), so this review saw part of what the engine holds._
  • Evidence: crates/openhuman\-core/src/modules/registry/records\_mcp\_connectors\.rs — Exercise the TinyConnectors 0.10.2 release end to end
  • Evidence: crates/openhuman\-core/src/modules/registry/records\_memory\_juice\.rs — Exercise the TinyJuice 0.3.3 release end to end

tests

  • Conclusion: Failure
  • Scope reviewed: all assigned evidence
  • Lane summary: This PR updates module registry pins and workflow checksum pins for tinyruntime, tinymemory, tinyjuice, and tinyconnectors, adds pin monitoring for three new submodules, and removes drift exemptions for tinymcp and tinymemory. However, the corresponding vendor submodule pointers are not updated, and the exemption removals are premature without those submodule updates. The module-pin verification gate will fail on CI if merged as-is. (6 earlier finding(s) still open) (2 observation(s) grouped into shared inline comments) _The code index is behind this pull request (indexed at `b17623827a7a`), so retrieved context may be out of date._ _5 memory call(s) failed (model: cortex: v1/recall: timed out after 10s), so this review saw part of what the engine holds._
  • Evidence: crates/openhuman\-core/src/modules/registry/records\_runtime\.rs — Advance vendor/tinyruntime submodule to v0.2.6
  • Evidence: crates/openhuman\-core/src/modules/registry/records\_memory\_juice\.rs — Advance vendor/tinyjuice submodule to v0.3.3
  • Evidence: crates/openhuman\-core/src/modules/memory/capabilities\.rs — Advance vendor/tinymemory submodule to v1.16.1
  • Evidence: scripts/ci/module\-pin\-exemptions\.json — Retain the tinymcp exemption until the submodule matches the registry
  • Evidence: scripts/ci/module\-pin\-exemptions\.json — Retain the tinymemory exemption until the submodule matches the registry

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Failure
  • Scope reviewed: all assigned evidence
  • Lane summary: This pull request updates module version pins and checksums to align with the host Rust toolchain (1.96.1), adds three new vendor submodules to the pin-checking scripts, and removes stale exemption entries. However, it introduces CI failures and validation gaps by referencing non-existent vendor submodules (tinybox, tinychannels, tinyhosts) and removing the tinymcp exemption without updating its registry pin, which will break the module pin gate. The change is not safe to merge until the submodules are added and the tinymcp pin is reconciled. (4 earlier finding(s) still open) _The code index is behind this pull request (indexed at `b17623827a7a`), so retrieved context may be out of date._ _5 memory call(s) failed (model: cortex: v1/recall: timed out after 10s), so this review saw part of what the engine holds._
  • Evidence: \(pull request description\) — Retain the tinymcp exemption until the registry pin matches the submodule
  • Evidence: \(pull request description\) — Add vendor submodules before referencing them in scripts

e2e

  • Conclusion: Failure
  • Scope reviewed: all assigned evidence
  • Lane summary: This pull request bumps several native module versions (tinyjuice, tinyconnectors, tinyruntime, and runtime providers), updates CI workflow pins, adds new submodules (tinybox, tinychannels, tinyhosts) to the module-pin checks, and adjusts pin exemptions. Multiple earlier concerns remain unresolved: submodule pins are not updated to match the new registry releases, the removed exemptions are premature, the newly referenced submodules do not exist in the tree, and the Rust Feature-Gate Smoke job will not run. The new module version bumps for tinyjuice and tinyruntime lack end-to-end test coverage; no test loads these modules and verifies their runtime behaviour. (2 findings discarded for not matching a changed line) Waiting on end-to-end jobs: `Rust E2E (mock backend)`, `Build Playwright E2E Artifact`, `E2E (Playwright / web lane)`, `Desktop E2E (full suite, 3 OS)`. (4 earlier finding(s) still open) (2 observation(s) grouped into shared inline comments) _The code index is behind this pull request (indexed at `b17623827a7a`), so retrieved context may be out of date._ _5 memory call(s) failed (model: cortex: v1/recall: timed out after 10s), so this review saw part of what the engine holds._
  • Unresolved questions/checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)
  • Evidence: crates/openhuman\-core/src/modules/registry/records\_runtime\.rs — Update vendored runtime submodule pin to match registry
  • Evidence: scripts/ci/check\-module\-pins\.mjs — Add vendor submodules for tinybox, tinychannels, tinyhosts before referencing t…
  • Evidence: \.github/workflows/ci\-lite\.yml — End-to-end job `Rust Feature-Gate Smoke (gates off)` will not run on this change
  • Evidence: \.github/workflows/ci\-lite\.yml — Ensure the Rust Feature-Gate Smoke job runs on this change
  • Evidence: crates/openhuman\-core/src/modules/registry/records\_memory\_juice\.rs — Exercise the TinyJuice 0.3.3 release end to end
Evidence and run details
  • Models: ladder/vectors, gpt-5.6-luna, deepseek-v4-flash
  • Spend: $0.027739
  • Tokens: 1035415 input · 62695 output · 100346 cached · 1865 embedding
Head State Pass summary
fa3be4adb790 changes requested 6 active finding(s), 0 resolved finding(s) (at 1790276268)
fa3be4adb790 changes requested 22 active finding(s), 46 resolved finding(s) (at 1790277418)

tinysweeper 0.1.0

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: cf109333-b92f-473b-b4cf-d931eafd5652

📥 Commits

Reviewing files that changed from the base of the PR and between 4f09c43 and fa3be4a.

⛔ Files ignored due to path filters (2)
  • Cargo.lock is excluded by !**/*.lock
  • crates/openhuman-app/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (16)
  • .github/workflows/ci-full.yml
  • .github/workflows/ci-lite.yml
  • .github/workflows/e2e-playwright.yml
  • .github/workflows/e2e-reusable.yml
  • crates/openhuman-core/src/modules/memory/capabilities.rs
  • crates/openhuman-core/src/modules/registry/records_mcp_connectors.rs
  • crates/openhuman-core/src/modules/registry/records_memory_juice.rs
  • crates/openhuman-core/src/modules/registry/records_runtime.rs
  • docs/RELEASE-MANUAL-SMOKE.md
  • scripts/__tests__/module-pins.test.mjs
  • scripts/ci/check-module-pins.mjs
  • scripts/ci/fetch-submodule-tags.sh
  • scripts/ci/module-pin-exemptions.json
  • vendor/tinyconnectors
  • vendor/tinyjuice
  • vendor/tinyruntime

Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The PR updates native module release versions and checksums in core registry records and CI download steps. It advances related vendor references and revises module-pin tracking and the release smoke checklist.

Changes

Native module release pins

Layer / File(s) Summary
Registry release pins and vendor references
crates/openhuman-core/src/modules/memory/capabilities.rs, crates/openhuman-core/src/modules/registry/records_*.rs, vendor/tinyconnectors, vendor/tinyjuice, vendor/tinyruntime
Updates memory, connector, juice, and runtime release pins. Platform archive names and SHA-256 hashes change with the registry releases. Three vendor commit references also change.
CI module download pins
.github/workflows/ci-full.yml, .github/workflows/ci-lite.yml, .github/workflows/e2e-playwright.yml, .github/workflows/e2e-reusable.yml
Updates the pinned memory and juice module versions, download URLs, and checksums used by CI and E2E jobs. Checksum verification remains in the download steps.
Pin tracking and release checks
scripts/ci/check-module-pins.mjs, scripts/ci/fetch-submodule-tags.sh, scripts/ci/module-pin-exemptions.json, scripts/__tests__/module-pins.test.mjs, .github/workflows/ci-lite.yml, docs/RELEASE-MANUAL-SMOKE.md
Revises runtime provider pin descriptions and exemptions, adds vendor submodule paths to pin checks, removes a hardcoded subsystem count from a comment, and adds a native-module release smoke checklist.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Suggested reviewers: yellowsnnowmann

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Out of Scope Changes check ❓ Inconclusive The reviewed source, CI, script, documentation, and vendored gitlink changes have a direct connection to #6614 because they pin, verify, or validate native modules built with the host toolchain. The s… Provide reviewable evidence for the changes in Cargo.lock and crates/openhuman-app/Cargo.lock, or confirm that those changes are generated dependency updates required by the toolchain-alignment work.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The changes satisfy the coding objective in #6614. The six registry pins now select releases reported as built with Rust 1.96.1, matching the host toolchain. CI fixtures use the same versions and dige…
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 7 files. (9 skipped: 9 …
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the primary change: updating native module release pins to match the host Rust toolchain.
Full details: Out of Scope Changes check

Explanation

The reviewed source, CI, script, documentation, and vendored gitlink changes have a direct connection to #6614 because they pin, verify, or validate native modules built with the host toolchain. The summary also reports changes to Cargo.lock and crates/openhuman-app/Cargo.lock, but both paths are excluded from review. Their purpose and scope cannot be independently established.

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

A rabbit checks each checksum twice,
Then hops along the version line.
New module tags are tucked in place,
While vendor pointers keep the pace.
The smoke-check list gets one more row,
And off through tidy pins we go.

Comment @coderabbitai help to get the list of available commands.

tinysweeper[bot]
tinysweeper Bot previously requested changes Sep 24, 2026

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 3 lane(s) blocking, worst finding is critical.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.1265 · 990,900 in / 27,281 out · 52,570 cached (5%) · ladder/vectors, gpt-5.6-luna, deepseek-v4-flash · 1,865 embedded
critique:    $0.0494 · 518,883 in / 12,791 out · 32,254 cached (6%) · gpt-5.6-luna, deepseek-v4-flash
security:    $0.0749 · 367,634 in / 6,151 out  · 18,268 cached (5%) · gpt-5.6-luna
tests:       $0.0006 · 29,563 in  / 2,525 out  · 1,024 cached (3%)  · deepseek-v4-flash
description: $0.0004 · 20,887 in  / 1,090 out  · 1,024 cached (5%)  · deepseek-v4-flash
e2e:         $0.0007 · 33,536 in  / 2,102 out  · 0 cached (0%)      · deepseek-v4-flash

Comment thread crates/openhuman-core/src/modules/registry/records_runtime.rs
Comment thread scripts/ci/module-pin-exemptions.json
Comment thread scripts/ci/fetch-submodule-tags.sh
Comment thread scripts/__tests__/module-pins.test.mjs
@tinysweeper tinysweeper Bot added the priority: p0 Drop what you are doing. Data loss, a live break, or an exploitable hole. label Sep 24, 2026
@senamakel
senamakel dismissed tinysweeper[bot]’s stale review September 24, 2026 19:09

All four findings were checked against the committed tree and answered in-thread: the runtime gitlink is updated, TinyMemory and TinyMCP match their registry tags, and the three queried submodules already exist in the upstream base. The 13-record pin gate and 25 module-pin tests pass. GitHub could not re-request the tinysweeper app by login, so this stale review is dismissed after the findings were explicitly declined with evidence.

@senamakel
senamakel marked this pull request as draft September 24, 2026 19:15

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 4 lane(s) blocking, worst finding is critical.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0277 · 1,035,415 in / 62,695 out · 100,346 cached (10%) · ladder/vectors, gpt-5.6-luna, deepseek-v4-flash · 1,865 embedded
critique:    $0.0130 · 483,940 in   / 24,032 out · 56,907 cached (12%)  · gpt-5.6-luna, deepseek-v4-flash
security:    $0.0110 · 403,940 in   / 12,823 out · 18,351 cached (5%)   · gpt-5.6-luna
tests:       $0.0019 · 66,843 in    / 10,573 out · 2,048 cached (3%)    · deepseek-v4-flash
description: $0.0008 · 23,339 in    / 6,910 out  · 0 cached (0%)        · deepseek-v4-flash
e2e:         $0.0009 · 35,866 in    / 6,391 out  · 2,048 cached (6%)    · deepseek-v4-flash

// have independent releases but share the tinyruntime source contract, so
// `sharesWith` checks that contract against the exact accepted drift.
const PIN_MAP = {
tinybox: { submodule: "vendor/tinybox" },

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high critique confident

Add submodules before requiring them in the pin gate

These entries make check-module-pins.mjs run git/tag checks against vendor/tinybox, vendor/tinychannels, and vendor/tinyhosts, but the complete diff contains no corresponding gitlink or .gitmodules addition. On a checkout of this change those paths are absent, so the gate fails closed instead of checking pins. Add the three submodule entries and pinned gitlinks before adding them to PIN_MAP.


Additional e2e observation

priority high confident

Add vendor submodules for tinybox, tinychannels, tinyhosts before referencing t…

[RULE] submodule-absent

The PIN_MAP and fetch-submodule-tags.sh now reference vendor/tinybox, vendor/tinychannels, and vendor/tinyhosts, but these submodules have not been added to .gitmodules or the tree. The CI check will fail immediately when it tries to fetch tags or compare pins because the directories do not exist. Add the missing submodules first.

[RULE] missing-submodule ·

*/
function submodulesPresent() {
const paths = [
"vendor/tinybox",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high critique confident

Add vendor submodules before referencing them in tests

submodulesPresent() now requires these three directories to be real tagged repositories, but this change does not add them as vendor submodules. Consequently the test helper returns false on a normal checkout and any end-to-end pin-check coverage guarded by this probe is skipped, while the production gate still fails when it tries to inspect the missing paths. Add the submodules before including them in this list.

[RULE] missing-submodule ·

cd "$(dirname "$0")/../.."

for module in \
vendor/tinybox vendor/tinychannels vendor/tinyhosts \

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high critique confident

Add submodules for tinybox, tinychannels, tinyhosts before referencing them

This adds three paths to an unconditional git -C loop, but the complete change does not add corresponding submodule entries/gitlinks. On a checkout where any of these directories is absent, git -C "$module" rev-parse fails under set -e, aborting the script before the existing module tags are fetched and causing the module-pin gate to fail. Add and initialize these submodules (or guard missing paths if they are intentionally optional) before including them here.

[RULE] missing-submodule ·

submodule: null,
sharesWith: "vendor/tinyruntime",
reason: "published from the tinyruntime release; no repository of its own",
reason: "published independently; shares the vendored tinyruntime bus contract",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high critique confident

Update the vendored runtime pins with the registry release

This revision only changes the explanation for the independently published runtime providers; it does not advance the vendored tinyruntime submodule to the registry's runtime release. The module-pin gate therefore still has a registry/submodule release mismatch once the runtime records advertise the newer release. Update the relevant vendored runtime gitlink together with the registry pin.

[RULE] module-pin-mismatch ·

object_path: "/ai/tinyhumans/tinyjuice/Compression",
version: "0.3.2",
release_url: "https://github.com/tinyhumansai/tinyjuice/releases/tag/v0.3.2",
version: "0.3.3",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high critique confident

Advance the vendored TinyJuice pin with the registry release

The registry now selects TinyJuice 0.3.3, while this complete diff contains no corresponding vendor/tinyjuice submodule update. The module-pin check requires the registry release and vendored source to describe the same release; leaving the vendor pin at the previous release will fail that check and leaves CI/local builds compiling a different module from the one the registry advertises. Update the TinyJuice submodule pin to the 0.3.3 release together with this record.


Additional security observation

priority medium confident

Exercise the TinyJuice 0.3.3 release end to end

[RULE] missing-release-integration-test

This changes the native TinyJuice release selected by the registry, including every platform archive and checksum, but the change adds no registry-driven test that admits and loads the 0.3.3 artifact and exercises compression or retrieval. A wrong archive name, digest, unavailable asset, or incompatible wire contract will otherwise only be discovered when compaction is first used. Add an end-to-end regression test for this release and a representative TinyJuice operation.


Additional tests observation

priority high confident

Advance vendor/tinyjuice submodule to v0.3.3

[RULE] submodule-pin-mismatch

The registry record for tinyjuice is bumped from v0.3.2 to v0.3.3, but the vendored submodule at vendor/tinyjuice remains unchanged in this diff. Advance the submodule pointer to the commit tagged v0.3.3 to satisfy the pin-consistency gate.


Additional e2e observation

priority medium confident

Exercise the TinyJuice 0.3.3 release end to end

[RULE] e2e-uncovered

The registry pins TinyJuice v0.3.3 with updated platform assets and checksums, but no end-to-end test actually loads this module, calls its compression/retrieval methods, or verifies correct behaviour. A typo in an archive name, a missing digest, or an incompatible module contract would go undetected until a user enables compaction. Add an end-to-end test that loads the module and exercises a representative operation.

[RULE] module-pin-mismatch ·

object_path: "/ai/tinyhumans/connectors/Composio",
version: "0.10.1",
release_url: "https://github.com/tinyhumansai/tinyconnectors/releases/tag/v0.10.1",
version: "0.10.2",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium security confident

Exercise the TinyConnectors 0.10.2 release end to end

This changes the native module selected for connector use and all of its platform checksums, but the change adds no test that resolves the 0.10.2 registry entry, admits and loads a pinned asset, and exercises its connector contract. A wrong archive name or digest, unavailable release asset, or incompatible wire API will therefore only be discovered when a user first uses connectors. Add a registry-driven integration test covering the updated release and a representative operation.


Additional critique observation

priority medium confident

Exercise the pinned TinyConnectors release end to end

[RULE] missing-release-integration-test

This changes the native module selected for every TinyConnectors installation, including all archive names and checksums, but the change adds no test that resolves the registry entry, loads the pinned artifact, and exercises its contract. A wrong asset name or digest, unavailable release, or incompatible 0.10.2 wire API will otherwise only be discovered when a user first invokes connector functionality. Add a registry-driven integration test that loads this release and performs a representative connector operation.

[RULE] missing-release-integration-test ·

/// so bumping the pin without re-reading the list is a red test rather than a
/// silent over-claim.
pub(crate) const ARTIFACT_CAPABILITIES_PIN: &str = "1.16.0";
pub(crate) const ARTIFACT_CAPABILITIES_PIN: &str = "1.16.1";

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high tests confident

Advance vendor/tinymemory submodule to v1.16.1

The ARTIFACT_CAPABILITIES_PIN is bumped to 1.16.1, and all workflow memory_version pins are updated to match the registry. The diff does not update the vendor/tinymemory submodule pointer, which must point to the v1.16.1 commit for check-module-pins.mjs to pass. Without this, the pin comparison will fail because the submodule's tag does not match the registry version.

[RULE] submodule-pin-mismatch ·

"submodule": "vendor/tinymemory",
"expect": "v1.16.0-26-g46f92206",
"reason": "The source contract includes the unreleased LLM and embeddings crate split from tinymemory main, while the registry retains the published v1.16.0 native-memory artifact and its release-published digests. This exact source/artifact split is temporary and must be removed when a release containing this contract is pinned."
"expect": "v0.2.6",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium tests confident

Retain the tinymcp exemption until the submodule matches the registry

The diff removes the tinymcp exemption from module-pin-exemptions.json without updating the vendor/tinymcp submodule pointer to a tag that matches the registry version (still v0.3.2). The submodule remains at v0.3.2-15-g10786a47, which will cause the pin consistency check to fail because the registry expects a release tag. Keep the exemption until the submodule is advanced to a commit that satisfies the registry pin, or until the registry pin is moved to a release that matches the submodule.

[RULE] premature-exemption-removal ·

"submodule": "vendor/tinymemory",
"expect": "v1.16.0-26-g46f92206",
"reason": "The source contract includes the unreleased LLM and embeddings crate split from tinymemory main, while the registry retains the published v1.16.0 native-memory artifact and its release-published digests. This exact source/artifact split is temporary and must be removed when a release containing this contract is pinned."
"expect": "v0.2.6",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium tests confident

Retain the tinymemory exemption until the submodule matches the registry

The diff removes the tinymemory exemption from module-pin-exemptions.json without updating the vendor/tinymemory submodule pointer to a tag that matches the new registry version v1.16.1. The submodule remains at v1.16.0-26-g46f92206, which will cause the pin consistency check to fail. Keep the exemption until the submodule is advanced to a commit that corresponds to v1.16.1, or remove it only after the submodule pointer is updated.

[RULE] premature-exemption-removal ·

object_path: "/ai/tinyhumans/runtime/Runtime",
version: "0.2.5",
release_url: "https://github.com/tinyhumansai/tinyruntime/releases/tag/v0.2.5",
version: "0.2.6",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high e2e confident

Update vendored runtime submodule pin to match registry

The registry record for tinyruntime now advertises v0.2.6, but the diff does not include a corresponding update to the vendor/tinyruntime submodule gitlink. The module-pin check requires both pins to describe the same release; leaving the submodule at v0.2.5 will cause that check to fail. Add the submodule update (and similarly for the runtime provider records).


Additional critique observation

priority medium confident

Refresh the runtime release documentation

[RULE] stale-documentation

The updated registry now advertises tinyruntime 0.2.6, but the unchanged module documentation immediately above still says the digests are v0.2.2's and describes the record as having been introduced for that release. That is false after this change and can mislead maintainers about the provenance of the checksums and the release history. Update the documentation to describe v0.2.6 (and clarify the sidecar release versions if needed) alongside the registry bump.


Additional tests observation

priority high confident

Advance vendor/tinyruntime submodule to v0.2.6

[RULE] submodule-pin-mismatch

The registry record for tinyruntime is bumped from v0.2.5 to v0.2.6, and the corresponding submodule pointer at vendor/tinyruntime must be updated to match. The diff does not include a submodule pointer change, so the module-pin check (check-module-pins.mjs) will compare the registry version against the submodule's tag and fail. The same applies to tinyruntime-nodejs (v0.2.3) and tinyruntime-python (v0.2.3), which share the vendor/tinyruntime bus contract per their sharesWith entries. Update all three submodule pointers before merging.

[RULE] module-pin-mismatch ·

@tinysweeper tinysweeper Bot added priority: p1 Next. Wrong behaviour a user will hit, or a security weakness behind a condition. and removed priority: p0 Drop what you are doing. Data loss, a live break, or an exploitable hole. labels Sep 24, 2026
@senamakel senamakel closed this Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p1 Next. Wrong behaviour a user will hit, or a security weakness behind a condition.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Startup: multiple bundled modules compiled against a different Rust version than the host

1 participant