Repository navigation
Conversation
Brings the host primitives for flat SKILL.md documents, digests, slug rules, authoring budgets and handle-based tree materialization (tinyskills#21).
Submodule and registry record move together to the v0.4.0 release (tinymcp#41: structured McpCallOutcome metadata, guarded OAuth refresh, host client name, config_doc parse_with). Registry digests are taken verbatim from the release's checksum.toml. The submodule now sits on the release tag, so the tinymcp pin exemption is removed.
Tiny Sweeper reviewTiny Sweeper reviewed this change across 6 lane(s) and found 0 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below. State: Reviewing pending checks Review snapshot
Completeness: Complete What changedThis pull request updates the tinymcp module pin in the registry record from 0.3.7 to 0.4.0, replacing the release URL, archive names, and SHA-256 digests for every listed platform asset (ubuntu 24.04/22.04 x86_64 and arm64, macos 26/15 arm64 and x86_64, windows 2025/2022 x86_64 and windows 11 arm64) in the `pub(crate) const TINYMCP` ModuleRecord (crates/openhuman-core/src/modules/registry/records_mcp_connectors.rs#pub(crate) const TINYMCP: ModuleRecord = ModuleRecord {). It also removes the now-obsolete tinymcp pin exemption entry from scripts/ci/module-pin-exemptions.json, since the rename commits previously carried by the exemption are covered by the 0.4.0 release. Review lanes (critique, security, tests, description) found no correctness or security issues in this data-only change. Reviewers noted they could not independently verify the new SHA-256 digests from the diff alone, and code retrieval plus memory tooling were unavailable during review. End-to-end CI jobs (`Rust E2E (mock backend)`, `Build Playwright E2E Artifact`, `E2E (Playwright / web lane)`, `Desktop E2E (full suite, 3 OS)`) were still pending. Features
TestsNo supported feature-to-test mapping was produced. Test execution is not inferred. FindingsNo active actionable findings. Pending checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS) Before merge
Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (4)
💤 Files with no reviewable changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe TINYMCP registry record now targets version 0.4.0 with updated release assets and checksums. The ChangesTinyMCP Update
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to The release metadata and vendored dependencies are consistent with their published versions, with no concrete merge-blocking issue identified. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The inspected release-loading path retains its download restrictions, digest checks, and admission controls. No introduced security weakness was established. Risk remains low rather than minimal because the newly pinned dependency implementations were not available for a complete comparison of their behavior and authority. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
A rabbit checks each archive name, Comment |
There was a problem hiding this comment.
tinysweeper found nothing blocking. Approving.
$0.0007 · 57,402 in / 2,866 out · 5,426 cached (9%) · gpt-5.6-luna, glm-5.3-flash
critique: $0.0002 · 16,231 in / 553 out · 2,035 cached (13%) · gpt-5.6-luna
security: $0.0002 · 15,495 in / 562 out · 1,791 cached (12%) · gpt-5.6-luna
tests: $0.0001 · 6,404 in / 114 out · 64 cached (1%) · glm-5.3-flash
description: $0.0001 · 7,293 in / 169 out · 1,408 cached (19%) · glm-5.3-flash
e2e: $0.0001 · 7,270 in / 624 out · 64 cached (1%) · glm-5.3-flash
tinyhumansai#7054 refreshed the root Cargo.lock but not crates/openhuman-app's.
- agent-runtime-boundary: baseline #7044's session-store re-exports (openhuman-core session_store, openhuman-embed lib, tinyagents-session port). They landed unbaselined, so the lane fails on main as is. - kernel floor and dep-sim: tinyskills v0.2.8 (#7054) brings cap-std and eight related crates into the always-on flows graph. CI measures 342 packages / 320 names / 3 native; #7054 merged with this lane red. - legacy memory e2e: a signed-out core reads .openhuman/users/local/ config.toml, so the test writes and reads that file; it wrote the top-level config, which the server never loads, and got the default tinyhumans engine back. It checks only that backend = "sqlite" is gone.
Summary
vendor/tinymcpto the v0.4.0 release tag and moves thetinymcpregistry record to 0.4.0 with the release's published digests.vendor/tinyskillsto the v0.2.8 release tag.tinymcpentry fromscripts/ci/module-pin-exemptions.json: the submodule now sits on its release tag.Cargo.lockfor both bumps.Problem
vendor/checkouts, so it can only consume them once this tree pins them.tinymcpregistry pin and the submodule pin also need to name the same release, and the exemption that covered their drift no longer applies.Solution
vendor/tinymcpatv0.4.0(ab2de39).McpCallOutcomemetadata onmcp_call_toolresults, which this host already forwards as structured tool-call output.OAuthFlow::refreshwith the public-endpoint guard,OAuthFlow::with_client_name,config_doc::parse_with, and redactedDebugfor credential types.CONTRACT_VERSIONmoves to (1, 3); the change is additive.TINYMCPrecord moves to0.4.0and the v0.4.0 release URL, with each archive's SHA-256 taken verbatim from the release'schecksum.toml. The asset set is unchanged.vendor/tinyskillsatv0.2.8(d25ef32) brings the flatSKILL.mdparser and renderer,document_digest, slug rule options, authoring budgets, and handle-basedmaterialize_tree. This tree uses none of the changed APIs.Cargo.lock:tinymcp/tinymcp-busmove 0.3.7 → 0.4.0.tinyskillspicks upcap-stdand its dependencies.tinymemory-*move 1.23.1 → 1.23.4 to match the already-pinnedvendor/tinymemory(581a2bc8, version 1.23.4), which the lock onmainhad not caught up with.Submission Checklist
Impact
with_secretsare scrubbed as strict credentials.Related
AI Authored PR Metadata (required for Codex/Linear PRs)
Linear Issue
Commit & Branch
Validation Run
pnpm --filter openhuman-app format:check)pnpm typecheck)node scripts/ci/check-module-pins.mjs .OK (14 records, all pins accounted for);node scripts/ci/check-submodule-monotonic.mjs upstream/main HEADOK (vendor/tinymcp, vendor/tinyskills moved forward)cargo fmt --checkreports only pre-existing drift inagent/session_store/mod.rsandopenhuman-embed/src/runtime/mod.rs, andcargo checkis blocked bymain(see Validation Blocked) (Rust fmt/check)Validation Blocked
command:cargo test -p openhuman --lib --features "$(bash scripts/ci/product-features.sh)" --no-runerror:mainat8c9c480a4edoes not compile, with 6 errors this PR does not touch:core/runtime/context.rs:231:init_master_key()returns().memory/brain.rs:251:Option<BackgroundJob>.memory/engine.rs:254: missingconsolidation.voice/live/session.rs:105: missingworking_dir.config/schema/types/config_clone.rs:14: missingvoice_live.voice/live/persist_tests.rs:30.impact:Rust gates on this PR will be red untilmainis fixed. The error set is byte-identical with the old pins and with these pins, so this PR adds no errors.Behavior Changes
Parity Contract
Duplicate / Superseded PR Handling
Summary by CodeRabbit