Skip to content

chore(vendor): pin tinymcp v0.4.0 and tinyskills v0.2.8 - #7054

Merged
senamakel merged 3 commits into
tinyhumansai:mainfrom
oxoxDev:chore/repin-tinymcp-0.4-tinyskills-0.2.8
Oct 7, 2026
Merged

senamakel merged 3 commits into
tinyhumansai:mainfrom
oxoxDev:chore/repin-tinymcp-0.4-tinyskills-0.2.8

Conversation

@oxoxDev

@oxoxDev oxoxDev commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Pins vendor/tinymcp to the v0.4.0 release tag and moves the tinymcp registry record to 0.4.0 with the release's published digests.
  • Pins vendor/tinyskills to the v0.2.8 release tag.
  • Removes the tinymcp entry from scripts/ci/module-pin-exemptions.json: the submodule now sits on its release tag.
  • Refreshes Cargo.lock for both bumps.

Problem

  • OpenCompany is moving its own MCP and skills code onto tinymcp and tinyskills (step one of running many isolated agents on one shared runtime). The library side merged as tinymcp#41 and tinyskills#21. OpenCompany links both through this repository's vendor/ checkouts, so it can only consume them once this tree pins them.
  • The tinymcp registry pin and the submodule pin also need to name the same release, and the exemption that covered their drift no longer applies.

Solution

  • vendor/tinymcp at v0.4.0 (ab2de39).
    • It adds McpCallOutcome metadata on mcp_call_tool results, which this host already forwards as structured tool-call output.
    • It also adds OAuthFlow::refresh with the public-endpoint guard, OAuthFlow::with_client_name, config_doc::parse_with, and redacted Debug for credential types.
    • CONTRACT_VERSION moves to (1, 3); the change is additive.
  • The TINYMCP record moves to 0.4.0 and the v0.4.0 release URL, with each archive's SHA-256 taken verbatim from the release's checksum.toml. The asset set is unchanged.
  • vendor/tinyskills at v0.2.8 (d25ef32) brings the flat SKILL.md parser and renderer, document_digest, slug rule options, authoring budgets, and handle-based materialize_tree. This tree uses none of the changed APIs.
  • Cargo.lock:
    • tinymcp/tinymcp-bus move 0.3.7 → 0.4.0.
    • tinyskills picks up cap-std and its dependencies.
    • tinymemory-* move 1.23.1 → 1.23.4 to match the already-pinned vendor/tinymemory (581a2bc8, version 1.23.4), which the lock on main had not caught up with.

Submission Checklist

  • N/A: pin bump with no host code change; the libraries carry their own tests and were CI-green at merge (tests added or updated)
  • N/A: no Rust logic changed, only the registry record's version and digest constants (diff coverage)
  • N/A: behaviour-only change in vendored libraries (coverage matrix)
  • N/A: no matrix rows change (feature IDs)
  • No new external network dependencies introduced
  • N/A: no release-cut surface changes (manual smoke checklist)
  • N/A: no issue in this repo; tracked by tinymcp#41, tinyskills#21 and the OpenCompany consumer (linked issue)

Impact

  • Desktop/CLI: the loaded tinymcp module is v0.4.0 (contract 1.3, compatible with a 1.x host).
  • MCP behaviour:
    • Successful and failed MCP calls now carry structured outcome metadata.
    • Server and tool names are stripped only of markdown fence characters.
    • Secrets added through with_secrets are scrubbed as strict credentials.
  • Compatibility: no host API used here changed shape.

Related


AI Authored PR Metadata (required for Codex/Linear PRs)

Linear Issue

  • Key: N/A
  • URL: N/A

Commit & Branch

  • Branch: chore/repin-tinymcp-0.4-tinyskills-0.2.8
  • Commit SHA: dc68099

Validation Run

  • N/A: no frontend change (pnpm --filter openhuman-app format:check)
  • N/A: no frontend change (pnpm typecheck)
  • Focused tests: node scripts/ci/check-module-pins.mjs . OK (14 records, all pins accounted for); node scripts/ci/check-submodule-monotonic.mjs upstream/main HEAD OK (vendor/tinymcp, vendor/tinyskills moved forward)
  • N/A: no Rust source formatting changed; cargo fmt --check reports only pre-existing drift in agent/session_store/mod.rs and openhuman-embed/src/runtime/mod.rs, and cargo check is blocked by main (see Validation Blocked) (Rust fmt/check)
  • N/A: no Tauri change (Tauri fmt/check)

Validation Blocked

  • command: cargo test -p openhuman --lib --features "$(bash scripts/ci/product-features.sh)" --no-run
  • error: main at 8c9c480a4e does not compile, with 6 errors this PR does not touch:
    • core/runtime/context.rs:231: init_master_key() returns ().
    • memory/brain.rs:251: Option<BackgroundJob>.
    • memory/engine.rs:254: missing consolidation.
    • voice/live/session.rs:105: missing working_dir.
    • config/schema/types/config_clone.rs:14: missing voice_live.
    • voice/live/persist_tests.rs:30.
  • impact: Rust gates on this PR will be red until main is fixed. The error set is byte-identical with the old pins and with these pins, so this PR adds no errors.

Behavior Changes

  • Intended behavior change: vendored tinymcp v0.4.0 and tinyskills v0.2.8.
  • User-visible effect: none in this tree's UI.

Parity Contract

  • Legacy behavior preserved: yes; additive library APIs, unchanged host call sites.
  • Guard/fallback/dispatch parity checks: module pin check and submodule monotonicity check pass.

Duplicate / Superseded PR Handling

  • Duplicate PR(s): none
  • Canonical PR: this one
  • Resolution: N/A

Summary by CodeRabbit

  • Updates
    • Updated TinyMCP to version 0.4.0. Its downloadable packages and release checksums have been refreshed across the existing supported platforms.
    • Existing platform coverage and lazy loading remain unchanged.

Brings the host primitives for flat SKILL.md documents, digests, slug rules, authoring budgets and handle-based tree materialization (tinyskills#21).
Submodule and registry record move together to the v0.4.0 release (tinymcp#41: structured McpCallOutcome metadata, guarded OAuth refresh, host client name, config_doc parse_with). Registry digests are taken verbatim from the release's checksum.toml. The submodule now sits on the release tag, so the tinymcp pin exemption is removed.
@tinysweeper

tinysweeper Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper reviewed this change across 6 lane(s) and found 0 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below.

State: Reviewing pending checks
Priority: low
Reviewed head: dc68099ab383
Updated: 1791357276 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 1 Active findings 0
Tests 0 Noted findings 0
Documentation 0 Resolved findings 0
Configuration 1 Pending checks/questions 4

Completeness: Complete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

This pull request updates the tinymcp module pin in the registry record from 0.3.7 to 0.4.0, replacing the release URL, archive names, and SHA-256 digests for every listed platform asset (ubuntu 24.04/22.04 x86_64 and arm64, macos 26/15 arm64 and x86_64, windows 2025/2022 x86_64 and windows 11 arm64) in the `pub(crate) const TINYMCP` ModuleRecord (crates/openhuman-core/src/modules/registry/records_mcp_connectors.rs#pub(crate) const TINYMCP: ModuleRecord = ModuleRecord {). It also removes the now-obsolete tinymcp pin exemption entry from scripts/ci/module-pin-exemptions.json, since the rename commits previously carried by the exemption are covered by the 0.4.0 release. Review lanes (critique, security, tests, description) found no correctness or security issues in this data-only change. Reviewers noted they could not independently verify the new SHA-256 digests from the diff alone, and code retrieval plus memory tooling were unavailable during review. End-to-end CI jobs (`Rust E2E (mock backend)`, `Build Playwright E2E Artifact`, `E2E (Playwright / web lane)`, `Desktop E2E (full suite, 3 OS)`) were still pending.

Features

  • Modified — Bump tinymcp module pin to 0.4.0: The registry record for the Model Context Protocol client module now points to v0.4.0: the version and release_url fields were updated and every platform asset's archive name and sha256 digest were replaced, so lazy loads of the module will fetch the 0.4.0 release artifacts for each supported platform. (crates/openhuman-core/src/modules/registry/records_mcp_connectors.rs#pub(crate) const TINYMCP: ModuleRecord = ModuleRecord {)
  • Removed — Drop tinymcp pin exemption: The ci module-pin exemption for tinymcp (previously expecting v0.3.7-3-g50a5af9 to carry test-file rename commits past the release tag) was removed, aligning pin-exemption policy with the new clean v0.4.0 release pin. (scripts/ci/module-pin-exemptions.json)

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

Findings

No active actionable findings.

Pending checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)

Before merge

  • Wait for Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS).
Agent review details

critique

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The change consistently updates the tinymcp release metadata, archive names, and SHA-256 digests to version 0.4.0 across all existing platform assets. No correctness issues are apparent, so it is safe to merge. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

security

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: The registry-only update keeps per-platform assets pinned with SHA-256 digests; no security problems were introduced.
  • Lane summary: The change updates the tinymcp module to version 0.4.0 with per-platform release assets and pinned SHA-256 digests. No security problems are introduced by this registry-only update. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: The change is a data-only version bump with no new logic or branch, so no new test is warranted; the module-pin tooling covers hash and archive verification.
  • Lane summary: This is a data-only version bump: the tinymcp module pin moves from 0.3.7 to 0.4.0 with new archive names, sha256 hashes and release URL, and the matching pin exemption is removed. There is no new logic or branch, nothing that can regress silently, and no test is warranted. The hashes and archives themselves cannot be verified from the diff, but the module-pin tooling covers that. Looks safe to merge. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: The diff matches the description: the tinymcp registry record is bumped to 0.4.0 with new per-platform digests and the obsolete pin exemption is removed.
  • Lane summary: The diff matches the description: it bumps the tinymcp registry record to 0.4.0 with new per-platform digests and removes the now-obsolete tinymcp pin exemption, exactly as the body claims. I could not independently verify the SHA-256 digests or the submodule pointer/Cargo.lock changes (not present in the shown diff), but nothing in the visible change contradicts the description; the change looks sound. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: This change is a tinymcp module pin bump (0.3.7 → 0.4.0: new version, release URLs, archive names and sha256 hashes, plus removal of the now-unneeded pin exemption). No end-to-end test reaches it, and the repository's rules forbid tests from calling real backends or third-party services, so the actual download and behaviour of the new tinymcp release cannot be driven by any harness here; recording that decision. Everything else is a data-table edit with no other external surface. Waiting on end-to-end jobs: `Rust E2E (mock backend)`, `Build Playwright E2E Artifact`, `E2E (Playwright / web lane)`, `Desktop E2E (full suite, 3 OS)`.
  • Unresolved questions/checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)
Evidence and run details
  • Models: gpt-5.6-luna, glm-5.3-flash
  • Spend: $0.000529
  • Tokens: 59110 input · 2893 output · 13656 cached · 0 embedding
Head State Pass summary
dc68099ab383 pending 0 active finding(s), 0 resolved finding(s) (at 1791356959)
dc68099ab383 pending 0 active finding(s), 0 resolved finding(s) (at 1791357276)

tinysweeper 0.1.0

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 7b83b560-d291-4c55-9d7a-7c9834100131
📥 Commits

Reviewing files that changed from the base of the PR and between 8c9c480 and dc68099.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (4)
  • crates/openhuman-core/src/modules/registry/records_mcp_connectors.rs
  • scripts/ci/module-pin-exemptions.json
  • vendor/tinymcp
  • vendor/tinyskills
💤 Files with no reviewable changes (1)
  • scripts/ci/module-pin-exemptions.json

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The TINYMCP registry record now targets version 0.4.0 with updated release assets and checksums. The tinymcp pin exemption was removed. The tinymcp and tinyskills vendor references now point to different commits.

Changes

TinyMCP Update

Layer / File(s) Summary
Update release and vendor references
crates/openhuman-core/src/modules/registry/records_mcp_connectors.rs, scripts/ci/module-pin-exemptions.json, vendor/tinymcp, vendor/tinyskills
The registry record now uses version 0.4.0 release assets and checksums across the existing 11 platforms. The tinymcp pin exemption was removed. Both vendor references changed to new commits.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Suggested reviewers: senamakel

Merge Risk: ⚪ Minimal · up to dc680

The release metadata and vendored dependencies are consistent with their published versions, with no concrete merge-blocking issue identified.

Security Architecture Review

Security architecture risk: 🔵 Low · up to dc680

The inspected release-loading path retains its download restrictions, digest checks, and admission controls. No introduced security weakness was established. Risk remains low rather than minimal because the newly pinned dependency implementations were not available for a complete comparison of their behavior and authority.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A compromised selected native module could affect the loading host process within its existing privileges. The repin therefore affects executable trust, not merely descriptive metadata. No new tenant-wide, cross-service, or infrastructure privilege expansion was established, and the target implementation's effective authority remains unverified.

Trust Boundaries and Controls

  • observed — The existing acquisition path requires agreement between the compiled digest pin and the publisher manifest, hashes downloaded bytes, and checks cached archives against the pin. Cache misses cannot initiate downloads when allow_download is false. These controls constrain attacker-supplied release bytes; they do not independently validate the behavior of an authorized upstream release.

Resilience and Maintainability Implications

  • observed — The inspected cache-publication and resolution mechanisms retain their existing failure-containment behavior across partial failure, concurrent acquisition, and repeated resolution. These mechanisms predate the PR; their preservation does not establish compatibility or safe initialization of the unavailable new module implementation.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 1…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the tinymcp and tinyskills vendor pins, which are the main changes.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

A rabbit checks each archive name,
Then counts the checksums, all the same.
The vendor pins hop to a new place,
While tiny modules keep their pace.
The rabbit bounds away, content with the change.

Comment @coderabbitai help to get the list of available commands.

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking. Approving.

             $0.0007 · 57,402 in / 2,866 out · 5,426 cached (9%)  · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0002 · 16,231 in / 553 out   · 2,035 cached (13%) · gpt-5.6-luna
security:    $0.0002 · 15,495 in / 562 out   · 1,791 cached (12%) · gpt-5.6-luna
tests:       $0.0001 · 6,404 in  / 114 out   · 64 cached (1%)     · glm-5.3-flash
description: $0.0001 · 7,293 in  / 169 out   · 1,408 cached (19%) · glm-5.3-flash
e2e:         $0.0001 · 7,270 in  / 624 out   · 64 cached (1%)     · glm-5.3-flash

@tinysweeper tinysweeper Bot added the priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect. label Oct 7, 2026
@senamakel
senamakel merged commit f4ad38b into tinyhumansai:main Oct 7, 2026
33 of 38 checks passed
CodeGhost21 added a commit to CodeGhost21/openhuman that referenced this pull request Oct 7, 2026
tinyhumansai#7054 refreshed the root Cargo.lock but not crates/openhuman-app's.
senamakel pushed a commit that referenced this pull request Oct 7, 2026
- agent-runtime-boundary: baseline #7044's session-store re-exports
  (openhuman-core session_store, openhuman-embed lib, tinyagents-session
  port). They landed unbaselined, so the lane fails on main as is.
- kernel floor and dep-sim: tinyskills v0.2.8 (#7054) brings cap-std and
  eight related crates into the always-on flows graph. CI measures
  342 packages / 320 names / 3 native; #7054 merged with this lane red.
- legacy memory e2e: a signed-out core reads .openhuman/users/local/
  config.toml, so the test writes and reads that file; it wrote the
  top-level config, which the server never loads, and got the default
  tinyhumans engine back. It checks only that backend = "sqlite" is gone.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants