Conversation
Tiny Sweeper reviewThis PR updates module version pins to align with host Rust toolchain, adds new submodules to pin validation, and removes stale exemptions, but introduces CI failures due to missing submodule pointers and premature exemption removal. 6 active findings remain. State: Changes requested Review snapshot
Completeness: Complete What changedThe review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below. Features
Tests
Findings
Resolved this pass
Pending checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS) Before merge
How this fits togetherflowchart LR
n0["entry"]:::impacted
n1["path"]:::impacted
n2["join"]:::impacted
n3["readRustModule"]:::impacted
n4["readRegistry"]:::impacted
n0 -->|calls| n3
n1 -->|uses| n0
n3 -->|calls| n2
n4 -->|uses| n0
n4 -->|uses| n1
n4 -->|calls| n2
n4 -->|calls| n3
classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (16)
Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe PR updates native module release versions and checksums in core registry records and CI download steps. It advances related vendor references and revises module-pin tracking and the release smoke checklist. ChangesNative module release pins
Estimated code review effort: 3 (Moderate) | ~20 minutes Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
Full details: Out of Scope Changes checkExplanation The reviewed source, CI, script, documentation, and vendored gitlink changes have a direct connection to ✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
A rabbit checks each checksum twice, Comment |
There was a problem hiding this comment.
Requesting changes: 3 lane(s) blocking, worst finding is critical.
Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.
$0.1265 · 990,900 in / 27,281 out · 52,570 cached (5%) · ladder/vectors, gpt-5.6-luna, deepseek-v4-flash · 1,865 embedded
critique: $0.0494 · 518,883 in / 12,791 out · 32,254 cached (6%) · gpt-5.6-luna, deepseek-v4-flash
security: $0.0749 · 367,634 in / 6,151 out · 18,268 cached (5%) · gpt-5.6-luna
tests: $0.0006 · 29,563 in / 2,525 out · 1,024 cached (3%) · deepseek-v4-flash
description: $0.0004 · 20,887 in / 1,090 out · 1,024 cached (5%) · deepseek-v4-flash
e2e: $0.0007 · 33,536 in / 2,102 out · 0 cached (0%) · deepseek-v4-flash
All four findings were checked against the committed tree and answered in-thread: the runtime gitlink is updated, TinyMemory and TinyMCP match their registry tags, and the three queried submodules already exist in the upstream base. The 13-record pin gate and 25 module-pin tests pass. GitHub could not re-request the tinysweeper app by login, so this stale review is dismissed after the findings were explicitly declined with evidence.
There was a problem hiding this comment.
Requesting changes: 4 lane(s) blocking, worst finding is critical.
Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.
$0.0277 · 1,035,415 in / 62,695 out · 100,346 cached (10%) · ladder/vectors, gpt-5.6-luna, deepseek-v4-flash · 1,865 embedded
critique: $0.0130 · 483,940 in / 24,032 out · 56,907 cached (12%) · gpt-5.6-luna, deepseek-v4-flash
security: $0.0110 · 403,940 in / 12,823 out · 18,351 cached (5%) · gpt-5.6-luna
tests: $0.0019 · 66,843 in / 10,573 out · 2,048 cached (3%) · deepseek-v4-flash
description: $0.0008 · 23,339 in / 6,910 out · 0 cached (0%) · deepseek-v4-flash
e2e: $0.0009 · 35,866 in / 6,391 out · 2,048 cached (6%) · deepseek-v4-flash
| // have independent releases but share the tinyruntime source contract, so | ||
| // `sharesWith` checks that contract against the exact accepted drift. | ||
| const PIN_MAP = { | ||
| tinybox: { submodule: "vendor/tinybox" }, |
There was a problem hiding this comment.
Add submodules before requiring them in the pin gate
These entries make check-module-pins.mjs run git/tag checks against vendor/tinybox, vendor/tinychannels, and vendor/tinyhosts, but the complete diff contains no corresponding gitlink or .gitmodules addition. On a checkout of this change those paths are absent, so the gate fails closed instead of checking pins. Add the three submodule entries and pinned gitlinks before adding them to PIN_MAP.
Additional e2e observation
Add vendor submodules for tinybox, tinychannels, tinyhosts before referencing t…
[RULE] submodule-absent
The PIN_MAP and fetch-submodule-tags.sh now reference vendor/tinybox, vendor/tinychannels, and vendor/tinyhosts, but these submodules have not been added to .gitmodules or the tree. The CI check will fail immediately when it tries to fetch tags or compare pins because the directories do not exist. Add the missing submodules first.
[RULE] missing-submodule ·
| */ | ||
| function submodulesPresent() { | ||
| const paths = [ | ||
| "vendor/tinybox", |
There was a problem hiding this comment.
Add vendor submodules before referencing them in tests
submodulesPresent() now requires these three directories to be real tagged repositories, but this change does not add them as vendor submodules. Consequently the test helper returns false on a normal checkout and any end-to-end pin-check coverage guarded by this probe is skipped, while the production gate still fails when it tries to inspect the missing paths. Add the submodules before including them in this list.
[RULE] missing-submodule ·
| cd "$(dirname "$0")/../.." | ||
|
|
||
| for module in \ | ||
| vendor/tinybox vendor/tinychannels vendor/tinyhosts \ |
There was a problem hiding this comment.
Add submodules for tinybox, tinychannels, tinyhosts before referencing them
This adds three paths to an unconditional git -C loop, but the complete change does not add corresponding submodule entries/gitlinks. On a checkout where any of these directories is absent, git -C "$module" rev-parse fails under set -e, aborting the script before the existing module tags are fetched and causing the module-pin gate to fail. Add and initialize these submodules (or guard missing paths if they are intentionally optional) before including them here.
[RULE] missing-submodule ·
| submodule: null, | ||
| sharesWith: "vendor/tinyruntime", | ||
| reason: "published from the tinyruntime release; no repository of its own", | ||
| reason: "published independently; shares the vendored tinyruntime bus contract", |
There was a problem hiding this comment.
Update the vendored runtime pins with the registry release
This revision only changes the explanation for the independently published runtime providers; it does not advance the vendored tinyruntime submodule to the registry's runtime release. The module-pin gate therefore still has a registry/submodule release mismatch once the runtime records advertise the newer release. Update the relevant vendored runtime gitlink together with the registry pin.
[RULE] module-pin-mismatch ·
| object_path: "/ai/tinyhumans/tinyjuice/Compression", | ||
| version: "0.3.2", | ||
| release_url: "https://github.com/tinyhumansai/tinyjuice/releases/tag/v0.3.2", | ||
| version: "0.3.3", |
There was a problem hiding this comment.
Advance the vendored TinyJuice pin with the registry release
The registry now selects TinyJuice 0.3.3, while this complete diff contains no corresponding vendor/tinyjuice submodule update. The module-pin check requires the registry release and vendored source to describe the same release; leaving the vendor pin at the previous release will fail that check and leaves CI/local builds compiling a different module from the one the registry advertises. Update the TinyJuice submodule pin to the 0.3.3 release together with this record.
Additional security observation
Exercise the TinyJuice 0.3.3 release end to end
[RULE] missing-release-integration-test
This changes the native TinyJuice release selected by the registry, including every platform archive and checksum, but the change adds no registry-driven test that admits and loads the 0.3.3 artifact and exercises compression or retrieval. A wrong archive name, digest, unavailable asset, or incompatible wire contract will otherwise only be discovered when compaction is first used. Add an end-to-end regression test for this release and a representative TinyJuice operation.
Additional tests observation
Advance vendor/tinyjuice submodule to v0.3.3
[RULE] submodule-pin-mismatch
The registry record for tinyjuice is bumped from v0.3.2 to v0.3.3, but the vendored submodule at vendor/tinyjuice remains unchanged in this diff. Advance the submodule pointer to the commit tagged v0.3.3 to satisfy the pin-consistency gate.
Additional e2e observation
Exercise the TinyJuice 0.3.3 release end to end
[RULE] e2e-uncovered
The registry pins TinyJuice v0.3.3 with updated platform assets and checksums, but no end-to-end test actually loads this module, calls its compression/retrieval methods, or verifies correct behaviour. A typo in an archive name, a missing digest, or an incompatible module contract would go undetected until a user enables compaction. Add an end-to-end test that loads the module and exercises a representative operation.
[RULE] module-pin-mismatch ·
| object_path: "/ai/tinyhumans/connectors/Composio", | ||
| version: "0.10.1", | ||
| release_url: "https://github.com/tinyhumansai/tinyconnectors/releases/tag/v0.10.1", | ||
| version: "0.10.2", |
There was a problem hiding this comment.
Exercise the TinyConnectors 0.10.2 release end to end
This changes the native module selected for connector use and all of its platform checksums, but the change adds no test that resolves the 0.10.2 registry entry, admits and loads a pinned asset, and exercises its connector contract. A wrong archive name or digest, unavailable release asset, or incompatible wire API will therefore only be discovered when a user first uses connectors. Add a registry-driven integration test covering the updated release and a representative operation.
Additional critique observation
Exercise the pinned TinyConnectors release end to end
[RULE] missing-release-integration-test
This changes the native module selected for every TinyConnectors installation, including all archive names and checksums, but the change adds no test that resolves the registry entry, loads the pinned artifact, and exercises its contract. A wrong asset name or digest, unavailable release, or incompatible 0.10.2 wire API will otherwise only be discovered when a user first invokes connector functionality. Add a registry-driven integration test that loads this release and performs a representative connector operation.
[RULE] missing-release-integration-test ·
| /// so bumping the pin without re-reading the list is a red test rather than a | ||
| /// silent over-claim. | ||
| pub(crate) const ARTIFACT_CAPABILITIES_PIN: &str = "1.16.0"; | ||
| pub(crate) const ARTIFACT_CAPABILITIES_PIN: &str = "1.16.1"; |
There was a problem hiding this comment.
Advance vendor/tinymemory submodule to v1.16.1
The ARTIFACT_CAPABILITIES_PIN is bumped to 1.16.1, and all workflow memory_version pins are updated to match the registry. The diff does not update the vendor/tinymemory submodule pointer, which must point to the v1.16.1 commit for check-module-pins.mjs to pass. Without this, the pin comparison will fail because the submodule's tag does not match the registry version.
[RULE] submodule-pin-mismatch ·
| "submodule": "vendor/tinymemory", | ||
| "expect": "v1.16.0-26-g46f92206", | ||
| "reason": "The source contract includes the unreleased LLM and embeddings crate split from tinymemory main, while the registry retains the published v1.16.0 native-memory artifact and its release-published digests. This exact source/artifact split is temporary and must be removed when a release containing this contract is pinned." | ||
| "expect": "v0.2.6", |
There was a problem hiding this comment.
Retain the tinymcp exemption until the submodule matches the registry
The diff removes the tinymcp exemption from module-pin-exemptions.json without updating the vendor/tinymcp submodule pointer to a tag that matches the registry version (still v0.3.2). The submodule remains at v0.3.2-15-g10786a47, which will cause the pin consistency check to fail because the registry expects a release tag. Keep the exemption until the submodule is advanced to a commit that satisfies the registry pin, or until the registry pin is moved to a release that matches the submodule.
[RULE] premature-exemption-removal ·
| "submodule": "vendor/tinymemory", | ||
| "expect": "v1.16.0-26-g46f92206", | ||
| "reason": "The source contract includes the unreleased LLM and embeddings crate split from tinymemory main, while the registry retains the published v1.16.0 native-memory artifact and its release-published digests. This exact source/artifact split is temporary and must be removed when a release containing this contract is pinned." | ||
| "expect": "v0.2.6", |
There was a problem hiding this comment.
Retain the tinymemory exemption until the submodule matches the registry
The diff removes the tinymemory exemption from module-pin-exemptions.json without updating the vendor/tinymemory submodule pointer to a tag that matches the new registry version v1.16.1. The submodule remains at v1.16.0-26-g46f92206, which will cause the pin consistency check to fail. Keep the exemption until the submodule is advanced to a commit that corresponds to v1.16.1, or remove it only after the submodule pointer is updated.
[RULE] premature-exemption-removal ·
| object_path: "/ai/tinyhumans/runtime/Runtime", | ||
| version: "0.2.5", | ||
| release_url: "https://github.com/tinyhumansai/tinyruntime/releases/tag/v0.2.5", | ||
| version: "0.2.6", |
There was a problem hiding this comment.
Update vendored runtime submodule pin to match registry
The registry record for tinyruntime now advertises v0.2.6, but the diff does not include a corresponding update to the vendor/tinyruntime submodule gitlink. The module-pin check requires both pins to describe the same release; leaving the submodule at v0.2.5 will cause that check to fail. Add the submodule update (and similarly for the runtime provider records).
Additional critique observation
Refresh the runtime release documentation
[RULE] stale-documentation
The updated registry now advertises tinyruntime 0.2.6, but the unchanged module documentation immediately above still says the digests are v0.2.2's and describes the record as having been introduced for that release. That is false after this change and can mislead maintainers about the provenance of the checksums and the release history. Update the documentation to describe v0.2.6 (and clarify the sidecar release versions if needed) alongside the registry bump.
Additional tests observation
Advance vendor/tinyruntime submodule to v0.2.6
[RULE] submodule-pin-mismatch
The registry record for tinyruntime is bumped from v0.2.5 to v0.2.6, and the corresponding submodule pointer at vendor/tinyruntime must be updated to match. The diff does not include a submodule pointer change, so the module-pin check (check-module-pins.mjs) will compare the registry version against the submodule's tag and fail. The same applies to tinyruntime-nodejs (v0.2.3) and tinyruntime-python (v0.2.3), which share the vendor/tinyruntime bus contract per their sharesWith entries. Update all three submodule pointers before merging.
[RULE] module-pin-mismatch ·
Summary
checksum.toml, and advance the three vendored module gitlinks and both Cargo lockfiles.Problem
OpenHuman logs
module rustc differs from hostwhen it loads modules built with a floating Rust toolchain. The host pins Rust 1.96.1, but the six modules named in #6614 were still pinned to older archives.Solution
The affected releases are tinymemory v1.16.1, tinyjuice v0.3.3, tinyruntime v0.2.6, tinyconnectors v0.10.2, tinyruntime-nodejs v0.2.3, and tinyruntime-python v0.2.3. Each release tag includes its merged toolchain pin. All 24 published macOS archives across macOS 15/26 and arm64/x86_64 were checked against their release checksum and their embedded TinyBus ABI descriptor; every archive reports rustc 1.96.1.
The provider modules are released separately from tinyruntime. Their exact shared-contract drift remains declared in
module-pin-exemptions.json; the stale TinyMemory and TinyMCP exemptions are removed.Submission Checklist
Closes #6614below.Impact
Desktop module loading on macOS, Windows, and Linux uses newly pinned native archives. There is no data migration. The ABI, manifest, and digest admission checks remain intact.
Related
AI Authored PR Metadata
Linear Issue
Commit & Branch
fix-module-rustc-skeweca36c83c9,fa3be4adb7(kept separate).Validation Run
pnpm --filter openhuman-app format:check— N/A; no frontend source changed and this worktree has no Node install.pnpm typecheck— N/A; no frontend source changed.cargo fmt --all -- --checkand locked root workspacecargo check.cargo check --manifest-path crates/openhuman-app/Cargo.toml.actionlint -shellcheck=on all four edited workflows. Existing unrelated ShellCheck findings prevent the unfiltered invocation from passing.Validation Blocked
pnpm test:coverage: not run locally; the complete changed-line coverage check did not finish in CI Fast because its test lanes failed.Behavior Changes
Parity Contract
Duplicate / Superseded PR Handling