Skip to content

feat(memory)!: remove Composio→memory sync - #7146

Merged
senamakel merged 91 commits into
tinyhumansai:mainfrom
senamakel:remove-composio-memory-sync
Oct 8, 2026
Merged

senamakel merged 91 commits into
tinyhumansai:mainfrom
senamakel:remove-composio-memory-sync

Conversation

@senamakel

@senamakel senamakel commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Removes Composio→memory syncing. Connected accounts (Gmail, Slack, Notion, GitHub, Linear, ClickUp) are no longer pulled into memory on a schedule or when a connection is created.
  • openhuman.composio_sync is gone. composio.delete_connection drops clear_memory and returns only {deleted}.
  • Memory sources keep folder, file, link, github and rss. memory_sources_add rejects composio.
  • The UI drops the Composio source kind, the "clear memory on disconnect" checkbox and the unused syncConnection client call. Every Memory tab stays.
  • Gitlinks bump vendor/tinyconnectors (sync engine removed, contract 1.12) and vendor/tinymemory (Composio source kind removed).

Problem

  • The Composio sync was expensive (paged pulls, per-connection passes, version and root bookkeeping) and added little to memory.

Solution

  • Core: deleted memory/sources/{composio,versions,roots}, integrations/composio/ops/{sync,pass_failure}, contract/runs, the composio_sync controller, module_client::call_slow and the composio_integration_sync plan flag.
    • The connection-created subscriber still waits for the connection to go active, warms the cache and fetches the profile; it just no longer starts a sync.
  • Config: a stale composio entry in [[memory.sources]] or the legacy [[memory_sources]] is dropped with a warn!, so old configs still load. connector_items.json and connection_roots.json are deleted at memory startup.
  • Merge with main: files.rs no longer records connection roots. The memory-scenarios D-connectors scenario and its mock Composio are removed along with the sync they exercised.
  • Frontend: removes the composio kind from the memory source types, labels and i18n in all locales. Also removes the clearMemory plumbing from deleteConnection and the modal, plus the composio_sync e2e cases and the matching mock backend route.

Submission Checklist

  • Tests added or updated. memory_v2_e2e: composio is rejected while folder, file, link, github and rss are accepted; composio_sync is an unknown method; a stale config loads. Unit tests cover config dropping a stale composio entry, apply_add rejecting composio, orphaned-file cleanup, and the add-source dialog not offering Composio.
  • Diff coverage ≥ 80%: not measured locally; this is mostly deletions. CI will report it.
  • Coverage matrix updated where rows referenced the removed sync.
  • Affected feature IDs: N/A (removal, no new feature rows).
  • No new external network dependencies.
  • Manual smoke checklist: N/A (no release-cut surface added).
  • Linked issue: N/A.

Impact

  • Merge order: satisfied. tinyconnectors#42 and tinymemory#245 are merged and released as v0.13.0 and v1.25.0. Both gitlinks sit on those tags, and the tinyconnectors module is repinned to v0.13.0. Its checksums are copied verbatim from the release's checksum.toml, for the same 11 host platforms as before.
  • Compatibility: existing configs with a Composio memory source load and drop it. Items already stored from Composio stay in memory; tinymemory decodes their kind as import.
  • Runtime: no more background connector passes, fewer backend and Composio calls, and less disk state.

Related


AI Authored PR Metadata (required for Codex/Linear PRs)

Linear Issue

  • Key: N/A
  • URL: N/A

Commit & Branch

  • Branch: remove-composio-memory-sync
  • Commit SHA: see the PR head

Validation Run

  • pnpm --filter openhuman-app format:check: Prettier clean on the changed files
  • pnpm typecheck: tsc --noEmit clean
  • Focused tests: vitest 911/911 (memory, composio, api, i18n, Memory page). cargo test -p openhuman --lib modules/memory/config/composio: 1457 passed against the release tags. in_process_all: 107 passed. memory_v2_e2e: 22 passed.
  • Rust fmt/check: cargo clippy -p openhuman --all-targets -D warnings clean, product-feature cargo check --tests, check-openhuman-rust-layout, check-feature-forwarding
  • Tauri fmt/check: cargo check --manifest-path crates/openhuman-app/Cargo.toml

Validation Blocked

  • command: Playwright and WDIO e2e suites
  • error: not run locally
  • impact: the edited connector and memory specs only type-check here; CI runs them

Behavior Changes

  • Intended behavior change: Composio accounts no longer feed memory.
  • User-visible effect: no Composio option when adding a memory source, and no "clear memory" checkbox when disconnecting an app.

senamakel and others added 30 commits October 8, 2026 23:19
Advance the vendored tinyagents and tinybox submodules to their latest
commits. Both checkouts carry local modifications, so the recorded
revisions are marked dirty.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Vendors the tinycomputer package so it can be used without relying on an
external fetch.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Introduce shared facet label helpers and wire them through the memory
tabs, dialogs, and previews so facet names render consistently. Update
the accompanying tests and vendor the tinydocs dependency.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Vendors the tinyhumans SDK so the project can depend on it without
pulling it from an external source at build time.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Vendors the tinyjuice library so it can be used without relying on an external package source.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add a service module for memory-related API calls so the app has a
dedicated place to fetch and mutate memory data.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Refresh the vendored tinyagents, tinybox, tinycomputer, tinymemory, and
tinyskills packages to their current revisions. Also drop the now-unused
rpcMethods service file.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add shared label maps for memory lifecycle states and memory sources so
the memory UI can render consistent human-readable names instead of
duplicating strings across components.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Remove memory RPC method constants that no longer have handlers and delete an accidentally committed editor backup of rpcMethods.ts. The lifecycle label test now asserts the pdf source instead of web to match the current source list.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add a memory chips component for displaying memory entries in the UI. The
vendor/tinydocs submodule was also updated to a newer revision.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Introduce a settingsRouteElements module that maps settings routes to their
components so the settings area can be composed from a single source. The
vendor submodules were bumped alongside to pick up the matching SDK and
styling changes.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Introduce a MemoryBrainTab component that renders the memory view for the
memory section. This gives users a dedicated tab to inspect memory data
alongside the existing memory views.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add a MemoryBrainTab component and wire it into the Memory page so the
brain view is reachable alongside the existing memory tabs. The
tinymemory vendor submodule is updated to the revision the new tab
depends on.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Introduces a dialog component for adding a source to a memory entry, giving users a dedicated flow to attach source material instead of relying on inline input.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Adds functions to execute Composio tools and to fetch a user's connected
accounts, along with the types describing tool execution results and
connection state. These give the app a way to run tools and check which
integrations a user has already authorised.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Extract the connect flow logic from the modal into a dedicated hook so the
modal component stays focused on presentation. Add tests covering the API
interactions used by the flow.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add tests for the Composio API client to lock in request handling and
response parsing.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Adds a modal component that lets users connect a Composio integration and
covers the underlying API calls with tests. This gives the UI a dedicated
flow for authorising integrations instead of relying on ad hoc handling.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add tests for the Composio connect modal covering its rendering and
user interactions, so the component's behaviour is verified and
regressions are caught.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add tests for the brain redirect component and the settings route
elements so their routing behaviour is verified.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add tests for the memory chips component and the memory page, exercising
chip selection and page rendering so the memory UI has regression
coverage.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add tests for the memory brain tab, synced sources, and helper utilities, and update the tinyconnectors and tinymemory vendored dependencies to support them.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Introduce a MemoryBrainTab component that renders the memory view for the
memory section. This gives users a dedicated tab to inspect memory data
alongside the existing memory views.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Refresh the vendored tinyconnectors and tinymemory dependencies to their
current revisions.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Added the new translation strings to every supported locale file so the
recently introduced UI text is localized instead of falling back to
English.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Refresh the vendored tinyconnectors and tinymemory dependencies to their
current revisions.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The memory page's brain tab and header now read "Files" and describe the
tab as files synced from this device plus documents added by hand, rather
than documents shared by every agent. Updated across all locales.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Refresh the vendored tinyconnectors and tinymemory dependencies to their
current revisions.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
senamakel and others added 14 commits October 8, 2026 23:43
Add the tinymemory package to the vendor directory so it can be used
without fetching it at build time.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
… Composio

Memory sources can once again be web pages, GitHub repositories, RSS feeds and
Composio toolkits, alongside local folders and files. Targets are normalized per
kind, legacy v1 entries of these kinds migrate instead of being dropped, and
synced items are filed under the connector they came from so removing a source
erases exactly its documents.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Introduce a migration step that upgrades persisted memory configuration to the current schema, so older configs load without manual edits.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Introduce a memory sources module with sync logic so the brain can pull
content from external sources, and cover the new paths with tests.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The end-to-end source tests now exercise link and github sources alongside
folder and file, and the stale-config case keeps an rss entry instead of a
file one. The composio rejection test was narrowed to composio alone so the
remaining kinds are asserted as accepted rather than rejected.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Composio is no longer a memory source kind, so the docs and spec no
longer list it among synced sources and the integration page no longer
claims connections sync into memory. The personal assistant guide now
points at folders, files and links instead.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
…gence catalog

Adds a README describing the Composio integration bus and its event flow, and
extends the about-app catalog with a conversation intelligence entry. The
documentation and catalog entry were added to make the integration easier to
discover and understand.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Document the Composio integration's purpose and usage so the module's
behaviour and entry points are discoverable without reading the source.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The README claimed profile fetch, action execution, and sync all route through the loaded tinyconnectors module, but sync no longer does, so the sentence now names only profile fetch and action execution.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The sync schema and its test were removed, so the test asserting its
required connection_id and optional reason fields no longer applies. The
known-schema key list is updated to drop the sync entry.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The lockfile no longer lists chrono and tracing as dependencies of tinyconnectors-sync, reflecting that the crate stopped using them.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The delete connection request no longer sets clear_memory, since the field was removed from the request struct and is no longer accepted by the API.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Update the vendored tinyconnectors submodule to the latest commit.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Resolves the memory module split on main: roots.rs and versions.rs stay
deleted (connector-only state), files.rs no longer records connection
roots, and the memory-scenarios Composio connector scenario and its mock
are removed with the sync they exercised.

Co-authored-by: Medulla <medulla@tinyhumans.ai>
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 200d4cd2-7721-49cb-bd06-4a6bdd2d20a5
📥 Commits

Reviewing files that changed from the base of the PR and between b0aa9e0 and cad7abd.

⛔ Files ignored due to path filters (2)
  • Cargo.lock is excluded by !**/*.lock
  • crates/openhuman-app/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (104)
  • app/src/components/composio/ComposioConnectModal.test.tsx
  • app/src/components/composio/ComposioConnectModal.tsx
  • app/src/components/composio/useComposioConnectFlow.ts
  • app/src/components/memory/MemoryAddSourceDialog.tsx
  • app/src/components/memory/MemorySyncedSources.test.tsx
  • app/src/components/memory/MemorySyncedSources.tsx
  • app/src/components/memory/memorySourceLabels.ts
  • app/src/lib/composio/composioApi.test.ts
  • app/src/lib/composio/composioApi.ts
  • app/src/lib/composio/types.ts
  • app/src/lib/i18n/ar.ts
  • app/src/lib/i18n/bn.ts
  • app/src/lib/i18n/de.ts
  • app/src/lib/i18n/en.ts
  • app/src/lib/i18n/es.ts
  • app/src/lib/i18n/fr.ts
  • app/src/lib/i18n/hi.ts
  • app/src/lib/i18n/id.ts
  • app/src/lib/i18n/it.ts
  • app/src/lib/i18n/ja.ts
  • app/src/lib/i18n/ko.ts
  • app/src/lib/i18n/pl.ts
  • app/src/lib/i18n/pt.ts
  • app/src/lib/i18n/ru.ts
  • app/src/lib/i18n/tr.ts
  • app/src/lib/i18n/zh-CN.ts
  • app/src/services/api/memoryApi.ts
  • app/test/e2e/helpers/composio-helpers.ts
  • app/test/e2e/helpers/connector-contract.ts
  • app/test/e2e/specs/connector-discord-composio.spec.ts
  • app/test/e2e/specs/connector-github.spec.ts
  • app/test/e2e/specs/connector-gmail-composio.spec.ts
  • app/test/e2e/specs/connector-jira.spec.ts
  • app/test/e2e/specs/connector-session-guard.spec.ts
  • app/test/playwright/specs/connector-gmail-composio.spec.ts
  • crates/openhuman-core/src/config/schema/load/migrate.rs
  • crates/openhuman-core/src/config/schema/memory.rs
  • crates/openhuman-core/src/config/schema/memory_tests.rs
  • crates/openhuman-core/src/core/runtime/services.rs
  • crates/openhuman-core/src/core/runtime/services_tests.rs
  • crates/openhuman-core/src/flows/tinyflows/memory_adapter_tests.rs
  • crates/openhuman-core/src/integrations/composio/README.md
  • crates/openhuman-core/src/integrations/composio/bus.rs
  • crates/openhuman-core/src/integrations/composio/bus/connection_created_subscriber.rs
  • crates/openhuman-core/src/integrations/composio/contract/catalogs/mod.rs
  • crates/openhuman-core/src/integrations/composio/contract/mod.rs
  • crates/openhuman-core/src/integrations/composio/contract/runs.rs
  • crates/openhuman-core/src/integrations/composio/contract/runs_tests.rs
  • crates/openhuman-core/src/integrations/composio/mod.rs
  • crates/openhuman-core/src/integrations/composio/module_client.rs
  • crates/openhuman-core/src/integrations/composio/ops/connections.rs
  • crates/openhuman-core/src/integrations/composio/ops/error_utils.rs
  • crates/openhuman-core/src/integrations/composio/ops/mod.rs
  • crates/openhuman-core/src/integrations/composio/ops/pass_failure.rs
  • crates/openhuman-core/src/integrations/composio/ops/pass_failure_tests.rs
  • crates/openhuman-core/src/integrations/composio/ops/sync.rs
  • crates/openhuman-core/src/integrations/composio/ops_fetch_integrations_and_triggers_tests.rs
  • crates/openhuman-core/src/integrations/composio/ops_no_session_and_cache_tests.rs
  • crates/openhuman-core/src/integrations/composio/providers/mod.rs
  • crates/openhuman-core/src/integrations/composio/schemas.rs
  • crates/openhuman-core/src/integrations/composio/schemas/definitions.rs
  • crates/openhuman-core/src/integrations/composio/schemas/handlers_connections.rs
  • crates/openhuman-core/src/integrations/composio/schemas/handlers_identity.rs
  • crates/openhuman-core/src/integrations/composio/schemas/registry.rs
  • crates/openhuman-core/src/integrations/composio/schemas_tests.rs
  • crates/openhuman-core/src/integrations/composio/tools.rs
  • crates/openhuman-core/src/memory/README.md
  • crates/openhuman-core/src/memory/brain.rs
  • crates/openhuman-core/src/memory/brain_tests.rs
  • crates/openhuman-core/src/memory/deletion.rs
  • crates/openhuman-core/src/memory/deletion_tests.rs
  • crates/openhuman-core/src/memory/files.rs
  • crates/openhuman-core/src/memory/files_tests.rs
  • crates/openhuman-core/src/memory/layout_migration/copy_tests.rs
  • crates/openhuman-core/src/memory/layout_migration/map_tests.rs
  • crates/openhuman-core/src/memory/sources/composio.rs
  • crates/openhuman-core/src/memory/sources/composio_tests.rs
  • crates/openhuman-core/src/memory/sources/mod.rs
  • crates/openhuman-core/src/memory/sources/mod_tests.rs
  • crates/openhuman-core/src/memory/sources/roots.rs
  • crates/openhuman-core/src/memory/sources/roots_tests.rs
  • crates/openhuman-core/src/memory/sources/state.rs
  • crates/openhuman-core/src/memory/sources/sync.rs
  • crates/openhuman-core/src/memory/sources/sync_tests.rs
  • crates/openhuman-core/src/memory/sources/versions.rs
  • crates/openhuman-core/src/memory/sources/versions_tests.rs
  • crates/openhuman-core/src/modules/connectors.rs
  • crates/openhuman-core/src/modules/connectors_tests.rs
  • crates/openhuman-core/src/modules/registry/records_mcp_connectors.rs
  • crates/openhuman-core/src/platform/about_app/catalog_conversation_intelligence.rs
  • docs/TEST-COVERAGE-MATRIX.md
  • docs/specs/memory-v2.md
  • gitbooks/features/integrations/README.md
  • gitbooks/features/memory.md
  • gitbooks/guides/personal-assistant.md
  • scripts/memory-scenarios/README.md
  • scripts/memory-scenarios/connectors.mjs
  • scripts/memory-scenarios/mock-composio.mjs
  • scripts/memory-scenarios/run.mjs
  • scripts/mock-api/routes/integrations.mjs
  • tests/in_process/worker_c_modules_e2e.rs
  • tests/memory_v2_e2e.rs
  • vendor/tinyconnectors
  • vendor/tinymemory
 ____________________________________________
< 99 little bugs in the code... I filed 100. >
 --------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

senamakel and others added 3 commits October 9, 2026 00:52
Update the vendored tinyconnectors submodule to the latest upstream commit.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Update the tinyconnectors module record to version 0.13.0 with refreshed
archive names and checksums for every supported platform, and advance the
tinyconnectors and tinymemory vendored submodules to their matching
revisions.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Update the lockfiles to reflect the new versions of the tinyconnectors and tinymemory crates.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@senamakel
senamakel marked this pull request as ready for review October 8, 2026 19:33
@tinysweeper

tinysweeper Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper reviewed this change across 6 lane(s) and found 7 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below.

State: Changes requested
Priority: critical
Reviewed head: b93990ece245
Updated: 1791489137 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 62 Active findings 19
Tests 32 Noted findings 0
Documentation 8 Resolved findings 46
Configuration 0 Pending checks/questions 4

Completeness: Complete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

The review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below.

Features

None identified with supported citations.

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

Findings

  • critical · critique · Use a declared SourceKind variant — The previous registration also included the connector scenario, but this now registers only `migration`. That makes the connector path—and therefore its SourceKind validation—unrea (scripts/memory\-scenarios/run\.mjs:39)
  • high · critique · Restore memory cleanup after deleting a connection — Because the connector scenario is no longer registered, the delete-connection flow that checks memory cleanup is no longer executed by this script. This removes coverage for a prev (scripts/memory\-scenarios/run\.mjs:39)
  • medium · critique · Retain the memory-ingest capability assertion — The predicate now accepts Gmail whenever `native_provider` is true, so a capability entry with `memory_ingest == false` will pass this regression test. The previous assertion cover (crates/openhuman\-core/src/integrations/composio/ops\_no\_session\_and\_cache\_tests\.rs:33)
  • medium · critique · Migrate persisted connection deletions before removing the variant — Users upgrading from a version that queued a disconnected connection can still have entries such as `{ "kind": "connection", "connection_id": "c", "toolkit": "gmail" }` in `pending (crates/openhuman\-core/src/memory/deletion\.rs:34)
  • medium · critique · Restore the sync regression tests — This change removes the direct tests for sessionless sync and invalid sync reasons, including the check that invalid input is rejected before the client is touched. With them gone, (crates/openhuman\-core/src/integrations/composio/ops\_no\_session\_and\_cache\_tests\.rs:160)
  • medium · critique · Retain the integration-to-memory setup step — Only `migration` is registered now; the previously registered connector scenario is omitted. As a result, the integration-to-memory setup step is no longer performed or validated b (scripts/memory\-scenarios/run\.mjs:39)
  • medium · critique · Restore the sync session-preservation regression test — The connector scenario is no longer passed to `registerLocalOnly`, so its sync session-preservation regression test cannot run. Restore that scenario or move the check into a scena (scripts/memory\-scenarios/run\.mjs:39)
  • medium · critique · Keep the source-roots permission check covered — The connector scenario is no longer registered, so the source-roots permission check is absent from this run. Replacing the registration with migration-only coverage leaves that ex (scripts/memory\-scenarios/run\.mjs:39)
  • medium · critique · Drive the revised delete_connection RPC end to end — The connector scenario that drives the revised `delete_connection` RPC is no longer registered. This change therefore drops end-to-end coverage for the revised RPC instead of valid (scripts/memory\-scenarios/run\.mjs:39)
  • medium · critique · Drive the revised delete_connection RPC end to end — The connector scenario that drives the revised `delete_connection` RPC is no longer registered. This change therefore drops end-to-end coverage for the revised RPC instead of valid (scripts/memory\-scenarios/run\.mjs:39)
  • medium · critique · Run orphan cleanup independently of memory job startup — Unregistering the connector scenario removes the path that exercises orphan cleanup independently of memory job startup. This hides the regression instead of ensuring cleanup still (scripts/memory\-scenarios/run\.mjs:39)
  • medium · security · Retain the integration-to-memory capability assertion — The previous assertion required the Gmail capability to advertise `memory_ingest`, but this change removes that requirement. That drops coverage for the integration-to-memory setup (crates/openhuman\-core/src/integrations/composio/ops\_no\_session\_and\_cache\_tests\.rs:33)
  • medium · security · Retain the integration-to-memory scenario — This registration change removes the `connectors` scenario from the local run, leaving only the migration scenario registered from this file. As a result, the suite no longer exerc (scripts/memory\-scenarios/run\.mjs:39)
  • medium · tests · Run orphan cleanup independently of memory job startup — Still stands from the previous review, unchanged. `remove_orphaned_connector_files` runs inside `if plan.memory_jobs`, so a workspace whose `ServiceSet` has memory sync disabled ne (crates/openhuman\-core/src/core/runtime/services\.rs:262)
  • medium · tests · Provide a cleanup path for memory items synced before this change — The clear-memory path is removed along with the whole sync feature. Users who previously synced Composio data (emails, Notion pages) into memory now have no automatic removal on di (crates/openhuman\-core/src/integrations/composio/ops/connections\.rs:169)
  • medium · description · Restore the Turkish chat.sidebar translations — This PR is about removing Composio→memory sync, but the Turkish locale file also deletes thirteen unrelated `chat.sidebar.*` keys (`searchPlaceholder` through `chat.sidebar.working (\(pull request description\))
  • medium · description · Run orphan cleanup independently of memory job startup — Still standing from the earlier review. `remove_orphaned_connector_files` deletes `connector_items.` and `connection_roots.`, files the removed sync left behind, but it only runs i (\(pull request description\))
  • high · e2e · Keep forgetting a disconnected connection's memory items — Still outstanding from the earlier review, and the removal is now the PR's stated purpose rather than an oversight, but the consequence stands and must be recorded: `composio_delet (crates/openhuman\-core/src/integrations/composio/ops/connections\.rs:167)
  • medium · e2e · Run orphan connector-file cleanup independently of memory job startup — Still outstanding from the earlier review: `remove_orphaned_connector_files` sits inside the `if plan.memory_jobs` block, so it runs only when memory background jobs are enabled. T (crates/openhuman\-core/src/core/runtime/services\.rs:263)

Resolved this pass

  • critical — Use a declared SourceKind variant
  • Restore memory cleanup after deleting a connection
  • Drive the revised delete_connection RPC end to end
  • Use a declared SourceKind variant
  • Restore memory cleanup after deleting a connection
  • Restore the sync session-preservation regression test
  • Retain the integration-to-memory setup step
  • Run orphan cleanup independently of memory job startup
  • Keep the source-roots permission check covered
  • Drive the revised delete_connection RPC end to end
  • Use a declared SourceKind variant
  • Restore memory cleanup after deleting a connection
  • Restore the sync session-preservation regression test
  • Retain the integration-to-memory setup step
  • Run orphan cleanup independently of memory job startup
  • Keep the source-roots permission check covered
  • Drive the revised delete_connection RPC end to end
  • Drive the revised delete_connection RPC end to end
  • critical — Use a declared SourceKind variant
  • high — Restore memory cleanup after deleting a connection
  • medium — Drive the revised delete_connection RPC end to end
  • medium — Drive the revised delete_connection RPC end to end
  • critical — Use a declared SourceKind variant
  • critical — Use a declared SourceKind variant
  • medium — Retain the integration-to-memory setup step
  • medium — Keep the source-roots permission check covered
  • medium — Drive the revised delete_connection RPC end to end
  • medium — Drive the revised delete_connection RPC end to end
  • critical — Use a declared SourceKind variant
  • Use a declared SourceKind variant
  • Restore the sync session-preservation regression test
  • Retain the integration-to-memory setup step
  • Keep the source-roots permission check covered
  • Drive the revised delete\_connection RPC end to end
  • Use a declared SourceKind variant
  • Restore memory cleanup after deleting a connection
  • Restore the sync session-preservation regression test
  • Retain the integration-to-memory setup step
  • Keep the source-roots permission check covered
  • Drive the revised delete_connection RPC end to end
  • Drive the revised delete\_connection RPC end to end
  • Use a declared SourceKind variant
  • Restore the sync session-preservation regression test
  • Retain the integration-to-memory setup step
  • Keep the source-roots permission check covered
  • Drive the revised delete_connection RPC end to end

Pending checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)

Before merge

  • Address Use a declared SourceKind variant (scripts/memory\-scenarios/run\.mjs).
  • Address Restore memory cleanup after deleting a connection (scripts/memory\-scenarios/run\.mjs).
  • Address Keep forgetting a disconnected connection's memory items (crates/openhuman\-core/src/integrations/composio/ops/connections\.rs).
  • Wait for Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS).

How this fits together

flowchart LR
  n0["ComposioConnectModal<br/>changed"]:::changed
  n1["useComposioConnectFlow<br/>changed"]:::changed
  n0 -->|calls| n1
  classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
  classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
  classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
  classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Loading
Agent review details

critique

  • Conclusion: Failure
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 9 files; 11 findings. (1 earlier finding(s) still open) (7 observation(s) grouped into shared inline comments) _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: scripts/memory\-scenarios/run\.mjs — Use a declared SourceKind variant
  • Evidence: scripts/memory\-scenarios/run\.mjs — Restore memory cleanup after deleting a connection
  • Evidence: crates/openhuman\-core/src/integrations/composio/ops\_no\_session\_and\_cache\_tests\.rs — Retain the memory-ingest capability assertion
  • Evidence: crates/openhuman\-core/src/memory/deletion\.rs — Migrate persisted connection deletions before removing the variant
  • Evidence: crates/openhuman\-core/src/integrations/composio/ops\_no\_session\_and\_cache\_tests\.rs — Restore the sync regression tests
  • Evidence: scripts/memory\-scenarios/run\.mjs — Retain the integration-to-memory setup step
  • Evidence: scripts/memory\-scenarios/run\.mjs — Restore the sync session-preservation regression test
  • Evidence: scripts/memory\-scenarios/run\.mjs — Keep the source-roots permission check covered
  • Evidence: scripts/memory\-scenarios/run\.mjs — Drive the revised delete_connection RPC end to end
  • Evidence: scripts/memory\-scenarios/run\.mjs — Drive the revised delete_connection RPC end to end
  • Evidence: scripts/memory\-scenarios/run\.mjs — Run orphan cleanup independently of memory job startup

security

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 6 files; 2 findings. 3 files were not security-reviewed: crates/openhuman-core/src/memory/README.md (prose or tabular data), docs/TEST-COVERAGE-MATRIX.md (prose or tabular data), scripts/memory-scenarios/README.md (prose or tabular data). (8 earlier finding(s) still open) (2 observation(s) grouped into shared inline comments) _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: crates/openhuman\-core/src/integrations/composio/ops\_no\_session\_and\_cache\_tests\.rs — Retain the integration-to-memory capability assertion
  • Evidence: scripts/memory\-scenarios/run\.mjs — Retain the integration-to-memory scenario

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The sync-into-memory feature is removed end to end, with new tests pinning the removal (composio source kind rejected, composio_sync an unknown method, stale configs dropping composio sources, orphaned connector files cleaned). Two earlier findings remain: the automatic cleanup of previously synced Composio memory is gone with the feature, and the orphan-file cleanup still runs only when memory jobs start. (2 earlier finding(s) still open) _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: crates/openhuman\-core/src/core/runtime/services\.rs — Run orphan cleanup independently of memory job startup
  • Evidence: crates/openhuman\-core/src/integrations/composio/ops/connections\.rs — Provide a cleanup path for memory items synced before this change

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: This revision adds the i18n cleanups and tests the earlier review asked for: the stale-composio config drop, apply_add rejection, orphan-file cleanup and the revised delete_connection RPC are now covered, and the deleted SourceKind usage is gone. Prior findings on memory cleanup, the session test and the setup step are moot — the PR now explicitly removes Composio→memory sync as its stated purpose. One prior finding stands (orphan cleanup still only runs under the memory_jobs flag), and the Turkish locale file drops an unrelated block of chat.sidebar translations. _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: \(pull request description\) — Restore the Turkish chat.sidebar translations
  • Evidence: \(pull request description\) — Run orphan cleanup independently of memory job startup

e2e

  • Conclusion: Failure
  • Scope reviewed: all assigned evidence
  • Lane summary: This revision removes Composio-to-memory sync end to end: the composio_sync RPC, the composio memory source kind, clear_memory on delete, and the sync e2e tests all go, with a stale-config migration, orphan-file cleanup, and new in-process e2e tests asserting the removed method and dropped source kind. The revised delete_connection RPC is still driven by the connector session-guard e2e suite, and the source-kind tests now use a declared variant. One prior concern remains: disconnecting a connection no longer forgets the memory it synced, and the orphan-file cleanup still only runs when memory background jobs are enabled. Waiting on end-to-end jobs: `Rust E2E (mock backend)`, `Build Playwright E2E Artifact`, `E2E (Playwright / web lane)`, `Desktop E2E (full suite, 3 OS)`. (3 earlier finding(s) still open) _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Unresolved questions/checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)
  • Evidence: crates/openhuman\-core/src/integrations/composio/ops/connections\.rs — Keep forgetting a disconnected connection's memory items
  • Evidence: crates/openhuman\-core/src/core/runtime/services\.rs — Run orphan connector-file cleanup independently of memory job startup
Evidence and run details
  • Models: gpt-5.6-luna, glm-5.3-flash
  • Spend: $0.038068
  • Tokens: 600645 input · 34995 output · 96353 cached · 0 embedding
  • Continuity: summary cache chain restarted at the storage ceiling.
Head State Pass summary
4fe15f9b7c88 changes requested 7 active finding(s), 0 resolved finding(s) (at 1791488456)
b93990ece245 changes requested 19 active finding(s), 46 resolved finding(s) (at 1791489137)

tinysweeper 0.1.0

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 1 lane(s) blocking, worst finding is critical.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0627 · 1,354,865 in / 47,933 out · 121,856 cached (9%) · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0330 · 623,205 in   / 29,424 out · 74,521 cached (12%) · gpt-5.6-luna, glm-5.3-flash
security:    $0.0214 · 419,542 in   / 14,085 out · 47,335 cached (11%) · gpt-5.6-luna
tests:       $0.0007 · 74,438 in    / 101 out    · 0 cached (0%)       · glm-5.3-flash
description: $0.0007 · 74,376 in    / 200 out    · 0 cached (0%)       · glm-5.3-flash
e2e:         $0.0007 · 78,031 in    / 553 out    · 0 cached (0%)       · glm-5.3-flash

assert!(is_untrusted(&crate::flows::flow_meta("f", &[])));
assert!(is_untrusted(&MemoryMeta::from_source(
SourceKind::Composio,
SourceKind::Import,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority critical critique confident

Use a declared SourceKind variant

SourceKind declares Jsonl, JsonlLegacyDir, and Markdown, but no Import variant. This change therefore causes the test code to fail compilation; use one of the declared variants or update the enum contract if a new variant is intended.

[RULE] invalid-enum-variant ·

// the synced memory and the identity facets — is this host's own
// bookkeeping about a connection it no longer has.
let mut resp = connectors::call::<_, ComposioDeleteResponse>(
// Only the Composio-side removal crosses the bus. The identity facets

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high critique confident

Restore memory cleanup after deleting a connection

When a connection has synchronized memory, this operation now deletes it from Composio and removes identity facets but never calls crate::memory::sources::composio::forget_connection. The previous implementation performed that cleanup when clear_memory was requested, so a deletion with memory cleanup enabled now leaves connection-scoped records behind. Restore the cleanup behavior or provide an equivalent deletion path before removing this call.

[RULE] incomplete-cleanup ·

await assertSessionNotNuked();
});

it('composio_execute routes a basic task', async function () {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Restore the sync session-preservation regression test

Removing this test means the Gmail suite no longer invokes openhuman.composio_sync or verifies that a sync failure leaves the user session intact. A regression specific to the sync route could therefore log the user out or break navigation without failing this suite; retain the test even if the request URL assertion is omitted.

[RULE] missing-regression-test ·


- Open **Settings** and connect an integration (Gmail is the common starting point). Each connection is a one-click OAuth approval.
- Once connected, add the integration as a source under **Connections → Memory → Brain** (kind `composio`); it syncs into [Memory](../features/memory.md) on a schedule.
- Add folders, files or links as sources under **Connections → Memory** so they sync into [Memory](../features/memory.md) on a schedule.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Retain the integration-to-memory setup step

The preceding text still tells users to connect an integration such as Gmail, but this replacement removes the instruction to add that connected integration as a Memory source. A user following the documented Gmail path can complete OAuth without Gmail ever syncing into Memory. Keep the integration-specific step alongside the new folders/files/links guidance.

[RULE] incomplete-user-guidance ·

// jobs (idempotent) and mark sources a killed process left `syncing` idle.
if plan.memory_jobs {
crate::memory::sources::state::reset_interrupted(&config.workspace_dir);
crate::memory::sources::state::remove_orphaned_connector_files(&config.workspace_dir);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Run orphan cleanup independently of memory job startup

This cleanup only runs inside the plan.memory_jobs branch. A valid configuration can enable integrations while disabling memory_sync—the adjacent tests exercise that combination—so existing connector_items.json and connection_roots.json files remain indefinitely for those workspaces. Since these files are obsolete regardless of whether memory cron jobs are enabled, invoke the cleanup outside the memory_jobs condition.

[RULE] conditional-cleanup ·

seen += 1;
}
assert!(seen >= 5, "every state file was written: {seen}");
assert!(seen >= 4, "every state file was written: {seen}");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium security confident

Keep the source-roots permission check covered

Removing the source-roots fixture and lowering the minimum count means this test can pass without ever creating or checking the source-roots state file. That weakens regression coverage for the owner-only file-permission contract this test is intended to enforce. Keep the source-roots write in the fixture and retain the corresponding count.

[RULE] missing-security-test-coverage ·

pub deleted: bool,
}

pub async fn composio_delete_connection(

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium e2e uncertain

Drive the revised delete_connection RPC end to end

This changes the openhuman.composio_delete_connection RPC contract: the handler no longer takes clear_memory, the reply type changes from ComposioDeleteResponse to ComposioDeleteResult ({deleted: true} without memory_chunks_deleted), and the memory-forgetting side effect is gone. The frontend disconnect flow (ComposioConnectModal / useComposioConnectFlow / composioApi.deleteConnection) was updated to match, but only via rewritten unit tests that mock the RPC. No end-to-end test drives the new contract: tests/memory_v2_e2e.rs exercises memory_sources_add and composio_sync removal but never calls openhuman.composio_delete_connection, and the connector e2e specs only cover list_connections/composio_execute. An e2e test would need to connect a connector via the mock backend, call the disconnect flow (or the RPC with a single connection_id), and assert the connection disappears and the UI returns to the idle state with the new reply shape. Until that exists, the changed reply shape and the frontend's consumption of it are unverified beyond mocked units; if the reply shape drifts (e.g. unwrapCliEnvelope's handling of the new type), the disconnect button would break in the shipped app without CI noticing.

[RULE] e2e-uncovered ·

@tinysweeper tinysweeper Bot added the priority: p0 Drop what you are doing. Data loss, a live break, or an exploitable hole. label Oct 8, 2026
senamakel and others added 3 commits October 9, 2026 01:12
Main modified memory/sources/composio.rs (hard erasure of a connection's
items) and added a pending-deletion queue whose Connection variant called
forget_connection. Composio items are no longer synced into memory, so
composio.rs stays deleted and the Connection variant is dropped; the
queue keeps its Thread and Source deletions. The queue has not shipped in
any release, so no persisted queue holds a Connection entry.

Co-authored-by: Medulla <medulla@tinyhumans.ai>
Added Turkish locale strings to the i18n module so the app can
display Turkish text.

Auto-committed-on: macbook
Co-authored-by: Medulla <medulla@tinyhumans.ai>
A merge on main left ten chat.sidebar keys defined twice in tr.ts
(TS1117) and three search keys no other locale or component uses,
which failed typecheck and the i18n coverage test.

Co-authored-by: Medulla <medulla@tinyhumans.ai>
@senamakel
senamakel merged commit f3ff1fe into tinyhumansai:main Oct 8, 2026
16 of 19 checks passed

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 2 lane(s) blocking, worst finding is critical.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0381 · 600,645 in / 34,995 out · 96,353 cached (16%) · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0161 · 145,598 in / 15,899 out · 61,707 cached (42%) · gpt-5.6-luna, glm-5.3-flash
security:    $0.0193 · 126,320 in / 10,637 out · 31,574 cached (25%) · gpt-5.6-luna
tests:       $0.0006 · 78,451 in  / 1,882 out  · 1,536 cached (2%)   · glm-5.3-flash
description: $0.0006 · 78,358 in  / 1,395 out  · 1,408 cached (2%)   · glm-5.3-flash
e2e:         $0.0007 · 81,992 in  / 2,094 out  · 0 cached (0%)       · glm-5.3-flash

import { migration } from "./migration.mjs";

registerLocalOnly(connectors, migration);
registerLocalOnly(migration);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority critical critique uncertain

Use a declared SourceKind variant

The previous registration also included the connector scenario, but this now registers only migration. That makes the connector path—and therefore its SourceKind validation—unreachable from this runner rather than fixing the invalid variant. Keep the scenario registered while correcting the variant it exercises.


Additional security observation

priority medium confident

Retain the integration-to-memory scenario

[RULE] missing-integration-coverage

This registration change removes the connectors scenario from the local run, leaving only the migration scenario registered from this file. As a result, the suite no longer exercises the integration-to-memory setup and related connector flows that were previously part of the local memory scenarios. Keep the connector scenario registered, or replace it with equivalent coverage before removing the mock setup.


Additional critique observation

priority medium likely

Run orphan cleanup independently of memory job startup

[RULE] test-coverage-regression

Unregistering the connector scenario removes the path that exercises orphan cleanup independently of memory job startup. This hides the regression instead of ensuring cleanup still runs when the memory job does not start.


Additional critique observation

priority medium likely

Drive the revised delete_connection RPC end to end

[RULE] test-coverage-regression

The connector scenario that drives the revised delete_connection RPC is no longer registered. This change therefore drops end-to-end coverage for the revised RPC instead of validating its caller behavior.


Additional critique observation

priority medium likely

Drive the revised delete_connection RPC end to end

[RULE] test-coverage-regression

The connector scenario that drives the revised delete_connection RPC is no longer registered. This change therefore drops end-to-end coverage for the revised RPC instead of validating its caller behavior.


Additional critique observation

priority medium likely

Keep the source-roots permission check covered

[RULE] test-coverage-regression

The connector scenario is no longer registered, so the source-roots permission check is absent from this run. Replacing the registration with migration-only coverage leaves that existing contract untested.


Additional critique observation

priority medium likely

Restore the sync session-preservation regression test

[RULE] test-coverage-regression

The connector scenario is no longer passed to registerLocalOnly, so its sync session-preservation regression test cannot run. Restore that scenario or move the check into a scenario that remains registered.


Additional critique observation

priority medium confident

Retain the integration-to-memory setup step

[RULE] test-coverage-regression

Only migration is registered now; the previously registered connector scenario is omitted. As a result, the integration-to-memory setup step is no longer performed or validated by this runner.


Additional critique observation

priority high likely

Restore memory cleanup after deleting a connection

[RULE] test-coverage-regression

Because the connector scenario is no longer registered, the delete-connection flow that checks memory cleanup is no longer executed by this script. This removes coverage for a previously identified high-impact regression; unregistering the scenario is not a fix for the cleanup behavior.

[RULE] test-coverage-regression ·

.capabilities
.iter()
.any(|entry| { entry.toolkit == "gmail" && entry.native_provider && entry.memory_ingest }));
.any(|entry| { entry.toolkit == "gmail" && entry.native_provider }));

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Retain the memory-ingest capability assertion

The predicate now accepts Gmail whenever native_provider is true, so a capability entry with memory_ingest == false will pass this regression test. The previous assertion covered the integration-to-memory setup contract; keep checking that field so a connector can’t silently lose memory ingestion while this suite remains green.


Additional security observation

priority medium confident

Retain the integration-to-memory capability assertion

[RULE] regression-coverage

The previous assertion required the Gmail capability to advertise memory_ingest, but this change removes that requirement. That drops coverage for the integration-to-memory setup contract and can allow the capability matrix to lose memory ingestion support unnoticed. Keep the memory_ingest predicate unless the contract itself is intentionally being removed and covered elsewhere.

Suggested change for this observation (reference only)

.any(|entry| { entry.toolkit == "gmail" && entry.native_provider && entry.memory_ingest }));

Suggested change for the opening observation

Suggested change
.any(|entry| { entry.toolkit == "gmail" && entry.native_provider }));
.any(|entry| { entry.toolkit == "gmail" && entry.native_provider && entry.memory_ingest }));

[RULE] regression-coverage ·

#[serde(default, skip_serializing_if = "Option::is_none")]
toolkit: Option<String>,
},
/// Every item a removed memory source stored.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Migrate persisted connection deletions before removing the variant

Users upgrading from a version that queued a disconnected connection can still have entries such as { "kind": "connection", "connection_id": "c", "toolkit": "gmail" } in pending_deletions.json. Removing the enum variant makes serde_json::from_str fail for that file; read then renames the whole file to .corrupt and returns an empty queue, so unrelated pending thread/source deletions are silently abandoned as well. Keep a compatibility deserialization path or explicitly migrate/drop only the retired connection entries while preserving the rest of the queue.

[RULE] backward-compatible-deserialization ·

assert!(err.contains("unrecognized sync reason"));
}

#[tokio::test]

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Restore the sync regression tests

This change removes the direct tests for sessionless sync and invalid sync reasons, including the check that invalid input is rejected before the client is touched. With them gone, regressions in sync’s session handling and reason validation can pass CI unnoticed. Restore these tests (and the sync session-preservation regression they previously accompanied) rather than deleting the coverage.

[RULE] regression-coverage ·


// Memory: seed the `memory_context_refresh` / `memory_sources_sync` cron
// jobs (idempotent) and mark sources a killed process left `syncing` idle.
if plan.memory_jobs {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium tests likely

Run orphan cleanup independently of memory job startup

Still stands from the previous review, unchanged. remove_orphaned_connector_files runs inside if plan.memory_jobs, so a workspace whose ServiceSet has memory sync disabled never removes the dead connector_items. / connection_roots. files this PR obsoleted. Cleanup is a one-shot filesystem removal, not memory work; hoist it out of the gate (or run it from config load, where the composio sources are already being dropped).

[RULE] gated-cleanup ·

let mut resp = connectors::call::<_, ComposioDeleteResponse>(
// Only the Composio-side removal crosses the bus. The identity facets
// are this host's own bookkeeping about a connection it no longer has.
let resp = connectors::call::<_, ComposioDeleteResponse>(

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium tests uncertain

Provide a cleanup path for memory items synced before this change

The clear-memory path is removed along with the whole sync feature. Users who previously synced Composio data (emails, Notion pages) into memory now have no automatic removal on disconnect: forget_connection is gone, the composio source kind is dropped at config load so memory_sources_remove cannot target it, and remove_orphaned_connector_files deletes only the state JSON files, not the stored items. The items survive under their brain sources (e.g. source:notion); a user's only recourse is a manual whole-source brain forget, which is not discoverable as 'disconnecting this app'. Level moved from high to medium because the feature removal is deliberate, the items are user-visible and manually forgettable via brain forget, and no new items can be created. Consider a one-time migration that forgets items still tagged connection:<id> (the tag filter machinery the deletion queue already had), or at least documenting the manual path in the release notes.

[RULE] orphaned-legacy-data ·

// the synced memory and the identity facets — is this host's own
// bookkeeping about a connection it no longer has.
let mut resp = connectors::call::<_, ComposioDeleteResponse>(
// Only the Composio-side removal crosses the bus. The identity facets

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high e2e likely

Keep forgetting a disconnected connection's memory items

Still outstanding from the earlier review, and the removal is now the PR's stated purpose rather than an oversight, but the consequence stands and must be recorded: composio_delete_connection no longer forgets the memory items the connection synced. Previously synced records carry a connection:<id> tag and were forgotten on disconnect (immediately, or queued via PendingDeletion::Connection when memory was off); that path is deleted entirely. A user who disconnects Gmail keeps every email's content in their memory store with no UI or RPC to remove it, and legacy_connector_slug in brain.rs goes out of its way to keep those documents filed under their nodes across migration — so the stale items are retained, not cleaned up incidentally. If the removal is deliberate, the deletion pipeline (deletion.rs PendingDeletion::Connection) should at minimum still be driven for already-queued deletions, or the retained items documented and surfaced; as reviewed, nothing in the product removes them.

[RULE] data-lifecycle ·

// Memory: seed the `memory_context_refresh` / `memory_sources_sync` cron
// jobs (idempotent) and mark sources a killed process left `syncing` idle.
if plan.memory_jobs {
crate::memory::sources::state::reset_interrupted(&config.workspace_dir);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium e2e likely

Run orphan connector-file cleanup independently of memory job startup

Still outstanding from the earlier review: remove_orphaned_connector_files sits inside the if plan.memory_jobs block, so it runs only when memory background jobs are enabled. The cleanup is a one-time removal of files nothing reads any more and has no dependency on the memory job machinery; a user whose ServiceSet disables memory_sync (or a preset that gates it off) keeps connector_items.json and connection_roots.json in their workspace indefinitely. Nothing about the code changed since the finding was raised, so the level is unchanged. The call belongs outside the gate, next to the other unconditional boot work.

[RULE] cleanup-gated ·

sanil-23 pushed a commit that referenced this pull request Oct 8, 2026
…ations

#7146 removed the composio `sync` controller but the raw-coverage suite
still listed it in the schema catalog and called it in the bad-params
check, so `rust-core-coverage` has failed on main and on every PR
rebased since. The two expectations are removed; the remaining 22
functions are unchanged.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p0 Drop what you are doing. Data loss, a live break, or an exploitable hole.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant