Repository navigation
chore: bump tinymemory to v1.23.9 and tinychannels to v0.1.11 - #7130
Conversation
Takes tinymemory #238: PreTurn.observed_actor, so a logged user turn can be attributed to who sent it. openhuman builds PreTurn only through PreTurn::new, so nothing breaks. Both lockfiles move the three tinymemory crates 1.23.8 -> 1.23.9 and nothing else.
Takes tinychannels tinyhumansai#50 (ChannelMessage.sender_name, the sender's display name; a WhatsApp LID-only sender stays <lid>@lid instead of +<lid>) and tinyhumansai#47 (tokio-tungstenite 0.29 -> 0.30). - The gitlink and the compiled registry pin move together. The record points at the v0.1.11 release; each of its 11 platform digests is copied from the release's published checksum.toml, which matches GitHub's own asset digest. The release covers the same 11 platforms. - The gitlink now sits on the tag, so the source/module skew (13 commits past v0.1.10, tinychannels#49 among them) is gone and its exemption in module-pin-exemptions.json is removed. - sender_name: None at the 38 ChannelMessage literals that name every field; the 4 that spread from another message keep working. - Lockfiles: the three tinychannels crates 0.1.10 -> 0.1.11; tinychannels now depends on tokio-tungstenite 0.30.0, added beside the 0.29.0 that openhuman, axum and tinyliveagents keep, with tungstenite 0.30.0. Their dependencies already resolve in the lock (rand 0.10.2, sha1 0.11.0).
Tiny Sweeper reviewTiny Sweeper reviewed this change across 6 lane(s) and found 0 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below. State: Reviewing pending checks Review snapshot
Completeness: Complete What changedThe review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below. FeaturesNone identified with supported citations. TestsNo supported feature-to-test mapping was produced. Test execution is not inferred. FindingsNo active actionable findings. Pending checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS) Before merge
How this fits togetherflowchart LR
n0["...ram_help_replies_with_remote_command_list<br/>changed"]:::changed
n1["...legram_new_status_and_sessions_round_trip<br/>changed"]:::changed
n2["...and_telegram_sessions_reports_empty_store<br/>changed"]:::changed
n3["...and_telegram_status_replies_without_agent<br/>changed"]:::changed
n4["...mand_unknown_provider_sends_helpful_error<br/>changed"]:::changed
n5["...out_target_channel_still_consumes_command<br/>changed"]:::changed
n6["vec"]:::impacted
n7["from_model"]:::impacted
n8["fixed"]:::impacted
n9["runtime_context"]:::impacted
n10["TurnModelSource"]:::impacted
n0 -->|calls| n9
n0 -->|tests| n9
n1 -->|calls| n6
n1 -->|tests| n6
n1 -->|calls| n9
n1 -->|tests| n9
n2 -->|calls| n9
n2 -->|tests| n9
n3 -->|calls| n9
n3 -->|tests| n9
n4 -->|calls| n9
n4 -->|tests| n9
n5 -->|calls| n9
n5 -->|tests| n9
n9 -->|calls| n6
n9 -->|calls| n7
n9 -->|calls| n8
n9 -->|uses| n10
classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (2)
📒 Files selected for processing (15)
💤 Files with no reviewable changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 5 remain after this review. 📝 WalkthroughWalkthroughChannel message fixtures and a thread-ID derivation message now initialize ChangesChannel message fixtures
TinyChannels release update
TinyMemory reference update
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other Suggested reviewers: Merge Risk: ⚪ Minimal · up to No confirmed issue blocks merging. The selected TinyChannels revision still needs normal CI build validation. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to No introduced security issue was established. The release update retains the existing host selection and download configuration, but the exact selected dependency code and published binaries were unavailable for inspection. Their identity-handling and integrity guarantees therefore remain partly unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
A rabbit checks each message field, Comment |
There was a problem hiding this comment.
tinysweeper found nothing blocking. Approving.
$0.0262 · 285,257 in / 11,444 out · 27,020 cached (9%) · gpt-5.6-luna, glm-5.3-flash
critique: $0.0140 · 129,510 in / 3,646 out · 14,307 cached (11%) · gpt-5.6-luna
security: $0.0118 · 114,338 in / 3,351 out · 12,713 cached (11%) · gpt-5.6-luna
tests: $0.0001 · 9,852 in / 226 out · 0 cached (0%) · glm-5.3-flash
description: $0.0001 · 11,337 in / 122 out · 0 cached (0%) · glm-5.3-flash
e2e: $0.0001 · 10,731 in / 826 out · 0 cached (0%) · glm-5.3-flash
Summary
2abc14a9→f2b55881): tinymemory #238,PreTurn.observed_actor, so a logged user turn can carry who sent it.20cc992a→bb54fd41):ChannelMessage.sender_name, the sender's display name. A WhatsApp sender known only by its LID now stays<lid>@lidinstead of becoming+<lid>.tokio-tungstenite0.29 → 0.30.sender_name: Nonein theChannelMessageliterals that name every field. The behaviour that uses the new fields stacks on this PR.Problem
module-pin-exemptions.json), so source and module disagreed.Solution
Two signed commits.
tinymemory (
chore(memory): bump tinymemory to v1.23.9)PreTurn.observed_actor. openhuman buildsPreTurnonly throughPreTurn::new(0 struct literals in any crate), so nothing breaks.tinychannels (
chore(channels): bump tinychannels to v0.1.11)ChannelMessage.sender_name: Option<String>(#[serde(default)]).ChannelMessagenow also derivesDefault.RuntimeChannelMessage(tinychannels-runtime/src/dispatch.rs) is unchanged, so the destructure inchannels/runtime/dispatch/processor/turn.rsstill compiles.ChannelMessage { … }literals...base_msg.clone(),..first.clone(),..Default::default()) and need nothing.sender_name: None. 36 are in core test files; the other two arethreads/store/bus.rs(production) andtests/raw_coverage/channels_round24_raw_coverage_e2e.rs.ChannelMessageliteral, and no literal without a spread lacks the field.modules/registry/records_extra.rs(tinychannels):versionandrelease_url→ v0.1.11, and all 11 platform entries get the v0.1.11 archive name and sha256.checksum.toml, and each one equals GitHub's own asset digest. None was computed locally..tar.gz+ 3 Windows.zip), so coverage is unchanged.tinychannelsentry inscripts/ci/module-pin-exemptions.json, which expectedv0.1.10-13-g20cc992a, is deleted. The checker fails an exemption that no longer matches, and the file says to delete it once the pins are reconciled.Cargo.lockandcrates/openhuman-app/Cargo.lockeach:tinychannels,tinychannels-busandtinychannels-runtime0.1.10 → 0.1.11;tinychannels' dependency attokio-tungstenite 0.30.0;tokio-tungstenite 0.30.0andtungstenite 0.30.0beside the 0.29.0 copies that openhuman,axumandtinyliveagentskeep using.connect,rustls-tls-webpki-roots, no default features, no native-tls), read from the index feature maps.rand 0.10.2,sha1 0.11.0,webpki-roots 0.26.11, …), so no other package changes. That is 38 added (two of them blank separators) and 4 removed lines per lockfile; the mobile and profiling lockfiles hold neither dependency. CI's--lockedlanes verify the result.git grep -F -f <the 11 old v0.1.10 digests>outsidevendor/finds 0 on this branch and 11 on main, the control showing the grep works. Nothing outsidevendor/namesv0.1.10-13or20cc992any more.Behaviour change to know about: WhatsApp LID-only contacts start a new thread
tinychannels::channel::derive_inbound_thread_id(tinychannels-bus/src/channel/session.rs, called fromchannels/bus/subscriber.rs). The key ischannel:<channel>/<sender>/<reply_target>, plus#thread:<ts>on every provider except Telegram.+<lid>and is now<lid>@lid, so its thread key changes. After this upgrade, that contact's next message opens a new thread. The old thread stays in the list but is not continued.+.Submission Checklist
sender_name: Nonein existing test fixtures and one production literal (threads/store/bus.rs), keeping today's behaviour. The existing channel suites cover those fixtures, andsender_nameis tested in tinychannels feat: split screen intelligence from accessibility and add dedicated settings #50.modules::registry_tests. CI's diff-cover gate is the authority.tokio-tungstenite0.30 replaces 0.29 for tinychannels only.Impact
sender_name/observed_actor.Related
AI Authored PR Metadata (required for Codex/Linear PRs)
Linear Issue
Commit & Branch
M3gA-Mind:chore/bump-tinymemory-tinychannelsValidation Run
pnpm --filter openhuman-app format:check: N/A, no frontend changepnpm typecheck: N/A, no frontend changecargo fmt --all -- --checkok;prettier --check scripts/ci/module-pin-exemptions.jsonok. Read checks as above.Validation Blocked
command:N/Aerror:N/Aimpact:N/ABehavior Changes
<lid>@lid.Parity Contract
sender_nameisNonewherever openhuman builds a message;observed_actoris unused until the stacked PRs.Duplicate / Superseded PR Handling
Summary by CodeRabbit