Skip to content

chore: bump tinymemory to v1.23.9 and tinychannels to v0.1.11 - #7130

Merged
M3gA-Mind merged 2 commits into
tinyhumansai:mainfrom
M3gA-Mind:chore/bump-tinymemory-tinychannels
Oct 8, 2026
Merged

M3gA-Mind merged 2 commits into
tinyhumansai:mainfrom
M3gA-Mind:chore/bump-tinymemory-tinychannels

Conversation

@M3gA-Mind

@M3gA-Mind M3gA-Mind commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • tinymemory v1.23.8 → v1.23.9 (2abc14a9 → f2b55881): tinymemory #238, PreTurn.observed_actor, so a logged user turn can carry who sent it.
  • tinychannels v0.1.10 (+13) → v0.1.11 (20cc992a → bb54fd41):
  • Only what the bumps need: sender_name: None in the ChannelMessage literals that name every field. The behaviour that uses the new fields stacks on this PR.

Problem

  • The observed-actor and sender-name work needs the released APIs.
  • openhuman's tinychannels source was 13 commits past the v0.1.10 module it downloads (an exemption in module-pin-exemptions.json), so source and module disagreed.

Solution

Two signed commits.

tinymemory (chore(memory): bump tinymemory to v1.23.9)

  • The only API change is PreTurn.observed_actor. openhuman builds PreTurn only through PreTurn::new (0 struct literals in any crate), so nothing breaks.
  • Lockfiles: the three tinymemory crates 1.23.8 → 1.23.9; nothing else.

tinychannels (chore(channels): bump tinychannels to v0.1.11)

  • API: the only public change is ChannelMessage.sender_name: Option<String> (#[serde(default)]). ChannelMessage now also derives Default. RuntimeChannelMessage (tinychannels-runtime/src/dispatch.rs) is unchanged, so the destructure in channels/runtime/dispatch/processor/turn.rs still compiles.
  • Literals: openhuman has 42 ChannelMessage { … } literals.
    • 4 spread from another message (..base_msg.clone(), ..first.clone(), ..Default::default()) and need nothing.
    • The other 38 name every field and get sender_name: None. 36 are in core test files; the other two are threads/store/bus.rs (production) and tests/raw_coverage/channels_round24_raw_coverage_e2e.rs.
    • Checked by script: each insertion sits inside a ChannelMessage literal, and no literal without a spread lacks the field.
  • Registry modules/registry/records_extra.rs (tinychannels): version and release_url → v0.1.11, and all 11 platform entries get the v0.1.11 archive name and sha256.
    • Every digest is copied from the release's published checksum.toml, and each one equals GitHub's own asset digest. None was computed locally.
    • v0.1.11 ships exactly the 11 platforms the old record pinned (8 Linux/macOS .tar.gz + 3 Windows .zip), so coverage is unchanged.
  • Source/module skew removed: the gitlink now sits on the v0.1.11 tag, which contains the 13 commits the old pin carried past v0.1.10 (tinychannels feat(local-ai): sequential multi-model downloads + multimodal local runtime #48 mail transport, feat(cli): integrate clap_complete for shell command completions #49 DashScope context overflow). The tinychannels entry in scripts/ci/module-pin-exemptions.json, which expected v0.1.10-13-g20cc992a, is deleted. The checker fails an exemption that no longer matches, and the file says to delete it once the pins are reconciled.
  • Lockfiles, edited by hand (no re-resolve). Cargo.lock and crates/openhuman-app/Cargo.lock each:
    • move tinychannels, tinychannels-bus and tinychannels-runtime 0.1.10 → 0.1.11;
    • point tinychannels' dependency at tokio-tungstenite 0.30.0;
    • add tokio-tungstenite 0.30.0 and tungstenite 0.30.0 beside the 0.29.0 copies that openhuman, axum and tinyliveagents keep using.
    • The two new entries' checksums come from the crates.io index. Their dependency lists follow tinychannels' features (connect, rustls-tls-webpki-roots, no default features, no native-tls), read from the index feature maps.
    • Every dependency already resolves in the lock (rand 0.10.2, sha1 0.11.0, webpki-roots 0.26.11, …), so no other package changes. That is 38 added (two of them blank separators) and 4 removed lines per lockfile; the mobile and profiling lockfiles hold neither dependency. CI's --locked lanes verify the result.
  • Stale-pin audit: git grep -F -f <the 11 old v0.1.10 digests> outside vendor/ finds 0 on this branch and 11 on main, the control showing the grep works. Nothing outside vendor/ names v0.1.10-13 or 20cc992 any more.

Behaviour change to know about: WhatsApp LID-only contacts start a new thread

  • openhuman keys a channel conversation by tinychannels::channel::derive_inbound_thread_id (tinychannels-bus/src/channel/session.rs, called from channels/bus/subscriber.rs). The key is channel:<channel>/<sender>/<reply_target>, plus #thread:<ts> on every provider except Telegram.
  • A WhatsApp contact known only by its LID was +<lid> and is now <lid>@lid, so its thread key changes. After this upgrade, that contact's next message opens a new thread. The old thread stays in the list but is not continued.
  • Contacts with a phone number keep their key and their thread. No openhuman code parses a sender's leading +.

Submission Checklist

  • N/A: new tests. A dependency bump; the code change is sender_name: None in existing test fixtures and one production literal (threads/store/bus.rs), keeping today's behaviour. The existing channel suites cover those fixtures, and sender_name is tested in tinychannels feat: split screen intelligence from accessibility and add dedicated settings #50.
  • Diff coverage ≥ 80%: the changed Rust lines are fixture fields executed by the existing channel tests, plus the production literal on the thread-store bus path its tests exercise. The registry record is data checked by modules::registry_tests. CI's diff-cover gate is the authority.
  • N/A: coverage matrix. No feature row changes.
  • N/A: feature IDs. No matrix feature affected.
  • No new external network dependencies introduced. The module downloads from the same release host at a new tag. tokio-tungstenite 0.30 replaces 0.29 for tinychannels only.
  • N/A: manual smoke checklist. No release-cut surface changes beyond the module version (the WhatsApp LID effect is described above).
  • N/A: linked issue. Dependency bump for tinymemory #238 and tinychannels feat: split screen intelligence from accessibility and add dedicated settings #50; no issue.

Impact

  • Desktop: a host built from this commit pins the tinychannels module at v0.1.11 for the same 11 platforms.
  • WhatsApp LID-only contacts start a new thread after the upgrade (above). Nothing else changes until the stacked PRs read sender_name / observed_actor.

Related


AI Authored PR Metadata (required for Codex/Linear PRs)

Linear Issue

  • Key: N/A
  • URL: N/A

Commit & Branch

  • Branch: M3gA-Mind:chore/bump-tinymemory-tinychannels
  • Commit SHA: d51b818

Validation Run

  • pnpm --filter openhuman-app format:check: N/A, no frontend change
  • pnpm typecheck: N/A, no frontend change
  • Focused tests: none run locally. Per the current fleet rule, CI on GitHub is the only build and test run.
  • Rust fmt/check (if changed): cargo fmt --all -- --check ok; prettier --check scripts/ci/module-pin-exemptions.json ok. Read checks as above.
  • Tauri fmt/check (if changed): N/A

Validation Blocked

  • command: N/A
  • error: N/A
  • impact: N/A

Behavior Changes

  • Intended behavior change: none in openhuman code. From tinychannels: a WhatsApp LID-only sender is <lid>@lid.
  • User-visible effect: a WhatsApp LID-only contact's next message after the upgrade opens a new thread.

Parity Contract

  • Legacy behavior preserved: sender_name is None wherever openhuman builds a message; observed_actor is unused until the stacked PRs.
  • Guard/fallback/dispatch parity checks: module admission still checks each archive's sha256 against the registry, now the published v0.1.11 digests.

Duplicate / Superseded PR Handling

  • Duplicate PR(s): none
  • Canonical PR: this one
  • Resolution (closed/superseded/updated): N/A

Summary by CodeRabbit

  • Updates
    • Updated TinyChannels to version 0.1.11, with refreshed downloads for Ubuntu, macOS, and Windows.
  • Maintenance
    • Updated channel and thread test coverage to reflect current message details. No user-facing behavior changes are included.

Takes tinymemory #238: PreTurn.observed_actor, so a logged user turn can
be attributed to who sent it. openhuman builds PreTurn only through
PreTurn::new, so nothing breaks. Both lockfiles move the three tinymemory
crates 1.23.8 -> 1.23.9 and nothing else.
Takes tinychannels tinyhumansai#50 (ChannelMessage.sender_name, the sender's display
name; a WhatsApp LID-only sender stays <lid>@lid instead of +<lid>) and
tinyhumansai#47 (tokio-tungstenite 0.29 -> 0.30).

- The gitlink and the compiled registry pin move together. The record
  points at the v0.1.11 release; each of its 11 platform digests is copied
  from the release's published checksum.toml, which matches GitHub's own
  asset digest. The release covers the same 11 platforms.
- The gitlink now sits on the tag, so the source/module skew (13 commits
  past v0.1.10, tinychannels#49 among them) is gone and its exemption in
  module-pin-exemptions.json is removed.
- sender_name: None at the 38 ChannelMessage literals that name every
  field; the 4 that spread from another message keep working.
- Lockfiles: the three tinychannels crates 0.1.10 -> 0.1.11; tinychannels
  now depends on tokio-tungstenite 0.30.0, added beside the 0.29.0 that
  openhuman, axum and tinyliveagents keep, with tungstenite 0.30.0. Their
  dependencies already resolve in the lock (rand 0.10.2, sha1 0.11.0).
@tinysweeper

tinysweeper Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper reviewed this change across 6 lane(s) and found 0 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below.

State: Reviewing pending checks
Priority: none
Reviewed head: d51b8187fc99
Updated: 1791461780 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 2 Active findings 0
Tests 10 Noted findings 0
Documentation 0 Resolved findings 0
Configuration 1 Pending checks/questions 4

Completeness: Complete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

The review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below.

Features

None identified with supported citations.

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

Findings

No active actionable findings.

Pending checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)

Before merge

  • Wait for Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS).

How this fits together

flowchart LR
  n0["...ram_help_replies_with_remote_command_list<br/>changed"]:::changed
  n1["...legram_new_status_and_sessions_round_trip<br/>changed"]:::changed
  n2["...and_telegram_sessions_reports_empty_store<br/>changed"]:::changed
  n3["...and_telegram_status_replies_without_agent<br/>changed"]:::changed
  n4["...mand_unknown_provider_sends_helpful_error<br/>changed"]:::changed
  n5["...out_target_channel_still_consumes_command<br/>changed"]:::changed
  n6["vec"]:::impacted
  n7["from_model"]:::impacted
  n8["fixed"]:::impacted
  n9["runtime_context"]:::impacted
  n10["TurnModelSource"]:::impacted
  n0 -->|calls| n9
  n0 -->|tests| n9
  n1 -->|calls| n6
  n1 -->|tests| n6
  n1 -->|calls| n9
  n1 -->|tests| n9
  n2 -->|calls| n9
  n2 -->|tests| n9
  n3 -->|calls| n9
  n3 -->|tests| n9
  n4 -->|calls| n9
  n4 -->|tests| n9
  n5 -->|calls| n9
  n5 -->|tests| n9
  n9 -->|calls| n6
  n9 -->|calls| n7
  n9 -->|calls| n8
  n9 -->|uses| n10
  classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
  classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
  classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
  classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Loading
Agent review details

critique

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 12 files; 0 findings. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

security

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 12 files; 0 findings. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: This is a mechanical dependency bump: the tinychannels module moves to v0.1.11 with refreshed hashes, the now-stale pin exemption for tinychannels is removed, and every test fixture gains the new `sender_name: None` field required by the updated bus contract. No behaviour is changed in this repo's own code, so no new tests are owed here; the new field itself is upstream tinychannels territory and its coverage belongs to that PR. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The description accurately matches the diff: it covers the `sender_name: None` fixture insertions, the tinychannels registry bump to v0.1.11 with new digests, the removal of the now-matching module-pin exemption, and the WhatsApp LID-only thread-key behaviour change. The change looks sound as a dependency bump. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: The PR plumbs a new `sender_name` field (always `None` in tests) and bumps the tinychannels module pin from 0.1.10 to 0.1.11 with new asset hashes. The field plumbing is mechanical and exercised by the changed in-repo tests; the module-version bump is the only externally observable surface, and no end-to-end test in the searched harness references the new version or hashes — the Rust E2E job that would exercise module loading is still pending, so I cannot confirm coverage either way. Everything else looks sound. Waiting on end-to-end jobs: `Rust E2E (mock backend)`, `Build Playwright E2E Artifact`, `E2E (Playwright / web lane)`, `Desktop E2E (full suite, 3 OS)`.
  • Unresolved questions/checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)
Evidence and run details
  • Models: gpt-5.6-luna, glm-5.3-flash
  • Spend: $0.026237
  • Tokens: 285257 input · 11444 output · 27020 cached · 0 embedding
Head State Pass summary
d51b8187fc99 pending 0 active finding(s), 0 resolved finding(s) (at 1791461780)

tinysweeper 0.1.0

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 53b93bf7-6ead-4e50-8d95-c50659444ead
📥 Commits

Reviewing files that changed from the base of the PR and between 1bf1ec4 and d51b818.

⛔ Files ignored due to path filters (2)
  • Cargo.lock is excluded by !**/*.lock
  • crates/openhuman-app/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (15)
  • crates/openhuman-core/src/channels/context_tests.rs
  • crates/openhuman-core/src/channels/routes_tests.rs
  • crates/openhuman-core/src/channels/runtime/dispatch_tests.rs
  • crates/openhuman-core/src/channels/runtime/test_support.rs
  • crates/openhuman-core/src/channels/tests/discord_integration.rs
  • crates/openhuman-core/src/channels/tests/runtime_dispatch.rs
  • crates/openhuman-core/src/channels/tests/runtime_tool_calls.rs
  • crates/openhuman-core/src/channels/tests/telegram_integration.rs
  • crates/openhuman-core/src/modules/registry/records_extra.rs
  • crates/openhuman-core/src/threads/store/bus.rs
  • crates/openhuman-core/src/threads/store/bus_tests.rs
  • scripts/ci/module-pin-exemptions.json
  • tests/raw_coverage/channels_round24_raw_coverage_e2e.rs
  • vendor/tinychannels
  • vendor/tinymemory
💤 Files with no reviewable changes (1)
  • scripts/ci/module-pin-exemptions.json

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 5 remain after this review.


📝 Walkthrough

Walkthrough

Channel message fixtures and a thread-ID derivation message now initialize sender_name to None. The TinyChannels registry data and vendor reference now point to version 0.1.11, its pin-drift exemption is removed, and the TinyMemory submodule reference is updated.

Changes

Channel message fixtures

Layer / File(s) Summary
Initialize sender_name in message fixtures
crates/openhuman-core/src/channels/*, crates/openhuman-core/src/threads/store/*, tests/raw_coverage/*
Test fixtures and the message used for persisted thread-ID derivation now explicitly set sender_name to None. Existing test behavior and assertions are unchanged.

TinyChannels release update

Layer / File(s) Summary
Update TinyChannels release pin
crates/openhuman-core/src/modules/registry/records_extra.rs, scripts/ci/module-pin-exemptions.json, vendor/tinychannels
The registry entry and all 11 platform asset filenames and checksums now reference version 0.1.11. The vendor pointer changes to commit bb54fd4114733b85828bd15aa86ff12ab9a100cc, and the pin-drift exemption is removed.

TinyMemory reference update

Layer / File(s) Summary
Update TinyMemory submodule reference
vendor/tinymemory
The submodule pointer changes to commit f2b55881b9d3a3510fc2e8633dc9a2116af8c752.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Suggested reviewers: senamakel

Merge Risk: ⚪ Minimal · up to d51b8

No confirmed issue blocks merging. The selected TinyChannels revision still needs normal CI build validation.

Security Architecture Review

Security architecture risk: 🔵 Low · up to d51b8

No introduced security issue was established. The release update retains the existing host selection and download configuration, but the exact selected dependency code and published binaries were unavailable for inspection. Their identity-handling and integrity guarantees therefore remain partly unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The security-relevant release exposure is deployments that load the new TinyChannels executable for an existing supported host target. The host describes this path as downloading, hashing, extracting, and dynamically loading a module. Impact beyond that application authority, including credential inheritance or tenant isolation, cannot be bounded from the unavailable selected dependency implementation.

Trust Boundaries and Controls

  • observed — The registry contains fixed upstream release metadata and per-asset SHA-256 values. Existing tests assert host/archive alignment, archive/version alignment, and a versioned upstream GitHub release URL. These are metadata consistency checks, not independent attestation of the published binaries or proof that the exact selected loader enforces every admission control.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately and concisely describes the main changes: updating tinymemory to v1.23.9 and tinychannels to v0.1.11.
Docstring Coverage ✅ Passed Docstring coverage is 85.71% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 35 functions across 12 files. (2 skipped: 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

A rabbit checks each message field,
And finds a name left blank and still.
New pins point where releases land,
Checksums line up, neat and planned.
Then hops away with carrots in hand.

Comment @coderabbitai help to get the list of available commands.

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking. Approving.

             $0.0262 · 285,257 in / 11,444 out · 27,020 cached (9%)  · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0140 · 129,510 in / 3,646 out  · 14,307 cached (11%) · gpt-5.6-luna
security:    $0.0118 · 114,338 in / 3,351 out  · 12,713 cached (11%) · gpt-5.6-luna
tests:       $0.0001 · 9,852 in   / 226 out    · 0 cached (0%)       · glm-5.3-flash
description: $0.0001 · 11,337 in  / 122 out    · 0 cached (0%)       · glm-5.3-flash
e2e:         $0.0001 · 10,731 in  / 826 out    · 0 cached (0%)       · glm-5.3-flash

@tinysweeper tinysweeper Bot added the priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect. label Oct 8, 2026
@M3gA-Mind
M3gA-Mind merged commit 4eff297 into tinyhumansai:main Oct 8, 2026
32 of 34 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant