Skip to content

refactor(memory): move safety, memory tools, readers, scheduler gate and importers to tinymemory (wave 4) - #6837

Merged
senamakel merged 226 commits into
tinyhumansai:mainfrom
senamakel:vendor-extract-w4-memory-rest
Oct 1, 2026
Merged

senamakel merged 226 commits into
tinyhumansai:mainfrom
senamakel:vendor-extract-w4-memory-rest

Conversation

@senamakel

@senamakel senamakel commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Summary

Vendor-extraction wave 4 moves the remaining generic memory code into tinymemory as new library crates.

crates/openhuman-core/src: 598,594 → 591,238 lines (−7,356).

Stacked on #6830 (memory guard). Merge that first. This diff includes its commits until then.

Depends on:

What moved (tinymemory)

  1. tinymemory-safety (new crate). One copy of pii, secrets, checksums, patterns and normalize now replaces three: the host's, tinycortex's and tinymemory-core's (through tinycortex). This was a user decision.
    • The copies disagreed on bare Luhn-valid 13–19 digit runs. The crate exposes that as Policy { bare_card }. The default LuhnOnly is the host's stricter behaviour; tinycortex opts into Policy::corroborated() (opencompany#1201). No consumer changes behaviour.
    • Tests from both copies are ported, 157 in total.
  2. tinymemory-tools (new crate). It holds 14 memory agent tools: memory_tree and its per-mode tools, raw store, vector/hybrid/chunk-context search, and the tool-memory tools.
    • They sit behind a MemoryToolHost trait (guarded provider, source-scope check, query embedder, ingest_document hook). The host implements it as HostMemoryTools.
    • Names, descriptions, schemas, exposure and permissions are pinned against a JSON fixture captured before the move.
    • Several tools stay in the host because they carry host policy or the host ingest path: memory_store, memory_forget, the collapsed tool, the goals tool and ingest_document.
    • tinymemory now depends on tinytools, which was a user decision. It resolves to the single vendored copy through the root [patch].
  3. Source readers → tinymemory-sources. SourceReader takes &Path instead of &Config. tinymemory-core's duplicate readers are removed, so one set remains.
  4. Reconcile helpers → tinymemory-sources. This covers apply_caps_defaults_to_entries and composio_upsert_target.
  5. Scheduler gate → tinymemory-gate (new crate). It holds sampling, the cached policy, the sampler task, wait_for_capacity and the permit.
    • init_global takes a SchedulerGateConfig, and the env-override names are passed in.
    • starship-battery sits behind tinymemory-gate/battery.
    • The host keeps the singleton, the semaphore, the signed-out override and test isolation.
    • It is not in tinymemory-api, whose manifest forbids an async runtime and native probes.
  6. OpenClaw/Hermes memory importers → tinymemory-import (new crate).
    • It takes the workspace path plus an open_target closure. The closure runs after the backup, so a null driver is refused at the same point as before.
    • The host keeps target_memory_backend and the RPC surface.

The goals has_goal_pii/validate_goal_text stay in the host, which the goals contract documents as host policy.

Pins and CI

  • tinymemory exemption: expect is v1.18.0-52-g0f5af00c. check-module-pins shows no tinymemory failure; the other modules' failures already exist on main.
  • ignored-test-baseline.json: lowered, because 13 core #[ignore] tests moved.
  • Lockfiles: only the new crates were added, to the root and app lockfiles.

Verification

  • Vendor:
    • tinymemory default members pass fmt, clippy -D warnings and tests. tinymemory-module still builds.
    • tinycortex: 1,203 tests pass, and clippy is clean.
  • OpenHuman:
    • Every test target builds with product features. The embed and tinyhumans tests and the app manifest also build.
    • Full lib suite: 9,600 passed and 2 failed. Both failures are known on base: credential_scrub::browser_confirmation_token_survives_without_exempting_page_credentials and the flaky composio connected_integrations_cache_is_keyed_per_credential.
    • The moved reader raw-coverage tests pass.
  • CI scripts:
    • Feature forwarding, the gated-test allowlist and submodule monotonic pass.
    • rust:layout and the runtime-boundary check fail only on the entries already failing on base.
  • Not run: json_rpc_e2e and the memory-module e2e suites, which need a built module.

Summary by CodeRabbit

  • Changes
    • Memory and search tools now use consolidated shared implementations; the existing registered tool set remains available, except the former walk and smart_walk tools.
    • Memory safety uses the default strict scrubbing policy, which redacts Luhn-valid 13–19 digit number sequences.
    • Memory source readers, migration, and scheduler-gate behavior have been consolidated without other documented user-facing behavior changes.

senamakel and others added 30 commits September 30, 2026 19:23
Remove the `GeneratedToolRuntimePolicy`, `GeneratedToolRuntimeContext`, and related types from the tool policy module, along with the entire `generated.rs` tools module and its tests. These were part of an earlier design for runtime-generated tool wrappers that is no longer used, and keeping them adds maintenance burden without any current consumers. The deletion also simplifies the `ToolPolicyRequest` struct by removing the `generated_tool` field and the `with_generated_tool_context` builder method, and cleans up the middleware that was populating that context.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The raw coverage end-to-end test for erased host extension was failing due to an incorrect assertion on the expected coverage data. The test now properly validates the coverage output for the erased host extension scenario.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add README documentation for the tools module and its implementation submodules to improve developer onboarding. Restructure the browser and system modules by introducing a security module and moving insert_sql_record into the system module with accompanying tests, enhancing code organization and maintainability.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The `insert_sql_record` tool was listed in the system and utilities documentation but is no longer part of the agent's toolset, so the entry has been removed to keep the reference accurate.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Introduce a new image generation subsystem under the media crate, including prompt handling, view types, and associated tests. This provides the foundational types and logic needed to support image generation workflows within the application.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Added a README file to the media module to provide documentation and usage guidance for developers working with media-related functionality in the openhuman-core crate.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Renamed the `model` field to `model_name` in the inference provider schema to match the actual API contract, fixing a mismatch that caused requests to be rejected by the upstream service.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Updated the pinned commit for the tinyflows vendored dependency to incorporate upstream changes.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
When generating JSON schemas for composio tool contracts, optional fields were being incorrectly treated as required, causing validation failures. This change updates the schema generation logic to properly mark fields as optional when they are not required by the tool contract, ensuring that composio integrations work correctly with tools that have optional parameters.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The catalog probe module was moved into a subdirectory but the integration code still referenced the old flat path, causing a compilation failure. The import and usage now point to the correct module location, restoring the probe functionality.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Introduce an abort guard mechanism for the tinyagents module to handle graceful shutdown of agent tasks. The new abort_guard.rs provides a utility for cancelling in-flight operations when the agent is terminated, ensuring resources are cleaned up properly. The module declaration and README are updated to reflect this addition.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Introduce a stop-hooks mechanism that allows agent components to register cleanup callbacks invoked when a runtime session ends. This enables graceful teardown of resources such as spawned tasks or open connections without requiring manual management in each session host implementation.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The test for stop hooks was not properly asserting that hooks execute in the correct sequence. This change updates the test to validate the order of hook invocations, ensuring that the stop mechanism behaves as intended.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
When an agent delegates a task to another agent, the delegation event was not being recorded in the journal, causing a gap in the audit trail. This change ensures that the delegation is properly journaled, maintaining a complete history of agent interactions.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Updated the pinned commit for the vendor/tinyflows subproject to include recent changes.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Introduce multimodal message types and conversion logic across the agent subsystem, enabling agents to process and route messages that contain multiple content types such as text, images, and audio. This change extends the message model, cost tracking, and tool orchestration to accommodate richer input and output formats.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Updated the vendored tinymemory dependency to incorporate upstream fixes and improvements.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add a README documenting the tinyflows observability module and reorganize the observability implementation by splitting tests into a separate file. This improves code organization and provides clear documentation for developers working with observability features in tinyflows.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
When the run_rows operation receives an empty set of rows, it now returns early with an empty result instead of proceeding with the processing pipeline. This prevents unnecessary computation and avoids potential errors from downstream operations that assume at least one row is present.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The README in the core module was stale and no longer reflected the current architecture, so it has been removed. The rpc_log unit tests have been moved from a separate test file into the main rpc_log module to consolidate test code and simplify the crate structure.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Changed the log level from error to info for successful RPC responses to avoid false alarms in monitoring. Previously, all responses were logged at error level, which caused unnecessary noise in error tracking systems.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
When reading a memory graph, the RPC handler now gracefully handles the case where a source is not found in the registry. Previously this would cause an unhandled error, but now it returns a clear error message to the caller instead.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The sandbox configuration operation was using an incorrect path for resolving configuration values, causing lookups to fail when nested keys were specified. Updated the path resolution logic to properly handle hierarchical key access.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add the tinyflows library as a vendored dependency to support upcoming workflow orchestration features. This provides the necessary runtime components for managing directed acyclic graph execution without introducing an external package manager dependency.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Updated the pinned commit for the tinyconnectors vendored dependency to incorporate upstream changes.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Updated the tinyflows dependency in the Cargo.toml to point to the latest commit in the vendor directory, ensuring compatibility with recent changes and improvements in the external library.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Updated the tinymemory vendored dependency to incorporate upstream fixes and improvements.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Update the pinned commit of the vendor/tinyconnectors submodule to include the latest changes from its upstream repository.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The cron store was scheduling jobs without considering the floor time constraint, causing jobs to run earlier than intended. This change ensures that job scheduling logic properly checks and enforces the floor time before executing jobs, aligning with the expected scheduling behavior.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The cron store was not persisting schedule changes when updating an existing entry, causing updates to be lost after restart. The store now writes the updated schedule to the underlying storage before returning the result.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
senamakel and others added 28 commits October 1, 2026 07:56
Removed the logic that used reaction emojis from the local AI model to determine the mascot's post-turn acknowledgement face, along with the associated emoji sets and the `reaction_emoji` field from event types. The face selection now relies solely on deterministic text cues from the response, simplifying the system and eliminating an unreliable external dependency.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The test file for useHumanMascot had an incorrect import path that prevented the tests from running. The path has been updated to point to the correct location of the module.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
fix(web_chat): remove local-model emoji reactions that blocked reply delivery
…pendencies

Bump the tinymemory crate from version 1.18.0 to 1.19.0 and advance both the tinyagents and tinymemory submodule pointers. The Cargo.lock is updated accordingly, adding the `thiserror`, `log`, `base64`, `futures-util`, `reqwest`, and `sha2` dependencies to support new functionality in the updated submodules.

Auto-committed-on: dragonfly
…-dead

refactor(core): delete dead code (vendor extraction wave 4A)
…r to merged module mains

Co-authored-by: Medulla <medulla@tinyhumans.ai>
…r to merged module mains

Co-authored-by: Medulla <medulla@tinyhumans.ai>
…-tinytools-net

refactor(tools): move network tools to tinytools-std behind NetGate (wave 4)
…r module

Removed leftover merge conflict markers from the tool implementation README and the browser module file, keeping the post-merge version of the content. The conflict in the README was resolved by adopting the updated tool tables that reflect the current registration gates and tool assignments, while the browser module conflict was resolved by removing the `image_info` and `security` module declarations that were part of the conflicting branches.

Auto-committed-on: dragonfly
Updated the vendored tinyagents dependency to incorporate upstream fixes and improvements. No local changes were made to the vendored code.

Auto-committed-on: dragonfly
Replace the direct call to `FixedRecallProvider::guarded` with the `guarded_fixed_recall` helper function in the unscored lane test, aligning with the updated API. The vendor submodule for tinyagents is also advanced to a newer commit.

Auto-committed-on: dragonfly
…-memory-guard

refactor(memory): move guard decorator to tinymemory-guard behind GuardPolicy (wave 4)
Update the pinned commits for the tinyagents and tinymemory vendor submodules to their latest versions.

Auto-committed-on: dragonfly
Updated the tinymemory subproject to point at a newer commit, incorporating upstream changes.

Auto-committed-on: dragonfly
…-pin

fix(vendor): pin tinyagents at merged main, not a local-only commit
Update the tinyconnectors crate from version 0.10.4 to 0.11.0 in Cargo.lock, along with the corresponding vendor submodule commits for both tinyagents and tinyconnectors, to pull in the latest upstream changes.

Auto-committed-on: dragonfly
…-connectors

refactor(composio): replace host duplicates with the tinyconnectors library (wave 4)
…ged module mains

Co-authored-by: Medulla <medulla@tinyhumans.ai>
…-flows

refactor(flows): move cron store and engine helpers to tinyflows (wave 4)
…ed module mains

Co-authored-by: Medulla <medulla@tinyhumans.ai>
…ed module mains

Co-authored-by: Medulla <medulla@tinyhumans.ai>
…-misc

refactor(core): move shell classifier, module artifact selection, tinyjuice seams and text paste to vendor (wave 4)
…to merged module mains

Co-authored-by: Medulla <medulla@tinyhumans.ai>
@senamakel
senamakel merged commit 86c3215 into tinyhumansai:main Oct 1, 2026
24 of 26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p2 Soon. Real but survivable — a rough edge, a gap, a thing that will bite later.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants