Skip to content

feat: vendor direct TinyHumans dependencies - #176

Merged
senamakel merged 3 commits into
mainfrom
git-deps-main-sync
Oct 1, 2026
Merged

senamakel merged 3 commits into
mainfrom
git-deps-main-sync

Conversation

@senamakel

@senamakel senamakel commented Sep 19, 2026 •

Copy link
Copy Markdown
Member

Replaces parent-level TinyHumans Git dependencies with paths into vendored submodules pinned to current upstream main.\n\nVerification:\n- TinyHivemind: cargo test --workspace --all-targets\n- TinyCortex: cargo check --workspace --all-targets, focused API/contract tests (full suite has one pre-existing source-weight assertion failure unrelated to this change).

Summary by CodeRabbit

  • Build and Dependency Updates
    • Added version-pinned inference and memory components to the project, and configured dependencies to use these included versions.
    • Updated the build configuration to include the components in the workspace while keeping the app and API as default build targets.
    • Updated component revisions for reproducible builds.
    • No user-facing functionality or public interfaces changed.

senamakel and others added 2 commits September 19, 2026 21:55
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@tinysweeper

tinysweeper Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper reviewed this change across 6 lane(s) and found 4 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below.

State: Incomplete
Priority: none
Reviewed head: 239a360f28b2
Updated: 1790879270 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 1 Active findings 4
Tests 0 Noted findings 0
Documentation 0 Resolved findings 0
Configuration 2 Pending checks/questions 5

Completeness: Incomplete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

The review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below.

Features

None identified with supported citations.

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

  • Unreviewed: tinysweeper/tests

Findings

Previously reported and still active

  • Do not merge crates from nested workspaces into this workspace
  • Avoid requiring an uninitialized submodule to build
  • Use Rust 2021 edition per repository convention
  • Fix workspace.package repository URL to point to the correct project

Could not review: Cargo.toml, tinysweeper/description, tinysweeper/e2e, tinysweeper/tests

Before merge

  • Address carried finding Do not merge crates from nested workspaces into this workspace.
  • Address carried finding Avoid requiring an uninitialized submodule to build.
  • Address carried finding Use Rust 2021 edition per repository convention.
  • Address carried finding Fix workspace.package repository URL to point to the correct project.
  • Complete the critique review for Cargo.toml.
  • Complete the security review for Cargo.toml.
  • Complete the tests review for tinysweeper/tests.
  • Complete the description review for tinysweeper/description.
  • Complete the e2e review for tinysweeper/e2e.
Agent review details

critique

  • Conclusion: Neutral
  • Scope reviewed: incomplete; unanswered: Cargo.toml
  • Lane summary: Reviewed 0 files; 0 findings. 1 file could not be reviewed: Cargo.toml.

security

  • Conclusion: Neutral
  • Scope reviewed: incomplete; unanswered: Cargo.toml
  • Lane summary: Reviewed 0 files; 0 findings. 1 file could not be reviewed: Cargo.toml.

tests

  • Conclusion: Neutral
  • Scope reviewed: incomplete; unanswered: tinysweeper/tests
  • Lane summary: No reviewer could be consulted.

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Neutral
  • Scope reviewed: incomplete; unanswered: tinysweeper/description
  • Lane summary: No reviewer could be consulted.

e2e

  • Conclusion: Success
  • Scope reviewed: incomplete; unanswered: tinysweeper/e2e
  • Lane summary: No reviewer could be consulted; only the job states below are reported. (4 earlier finding(s) still open) _The code index is behind this pull request (indexed at `d27a8c14f768`), so retrieved context may be out of date._ _3 memory call(s) failed (model: cortex: v1/answer answered 502 Bad Gateway), so this review saw part of what the engine holds._
Evidence and run details
  • Models: ladder/vectors
  • Spend: $0.000004
  • Tokens: 0 input · 0 output · 0 cached · 396 embedding
Head State Pass summary
8386fd7f10d1 changes requested 4 active finding(s), 0 resolved finding(s) (at 1789844675)
239a360f28b2 incomplete 0 active finding(s), 0 resolved finding(s) (at 1790879270)

tinysweeper 0.1.0

@coderabbitai

coderabbitai Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 3db30b82-e58e-4167-b37f-52cad4ff0387

📥 Commits

Reviewing files that changed from the base of the PR and between 8386fd7 and 239a360.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (1)
  • Cargo.toml
 _____________________________
< ░R░e░v░i░e░w░ ░i░n░ ░b░i░o░ >
 -----------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: aa09f19b-8e66-4a90-bb4e-db83db51a512

📥 Commits

Reviewing files that changed from the base of the PR and between 518c855 and 8386fd7.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (5)
  • .gitmodules
  • Cargo.toml
  • api/Cargo.toml
  • vendor/tinyinference
  • vendor/tinymemory

Included review availability: Your plan provides up to 2 included reviews per hour; 1 remains after this review.


📝 Walkthrough

Walkthrough

The repository adds pinned tinyinference and tinymemory submodules, includes their crates in the Rust workspace, centralizes workspace metadata and dependencies, and changes application dependencies from Git revisions to local vendored paths.

Changes

Vendored workspace integration

Layer / File(s) Summary
Workspace and submodule setup
.gitmodules, Cargo.toml, vendor/tinyinference, vendor/tinymemory
The repository registers and pins both submodules. The workspace includes their crates and adds shared package metadata, dependencies, and lint settings.
Local dependency resolution
Cargo.toml, api/Cargo.toml
tinyinference-embeddings, tinyinference-llm, and tinymemory-api now use local paths instead of Git dependencies and revision pins.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: vendoring the direct TinyHumans dependencies.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

A rabbit hops through crates so neat
Vendored paths make builds complete
Two pinned friends join the Rusty den
Shared lints guide them now and then
Local links replace the distant trail

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T18:30:29.559930Z 239a360 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8386fd7f10

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread Cargo.toml
Comment on lines +10 to +13
"vendor/tinyinference/crates/tinyinference-core",
"vendor/tinyinference/crates/tinyinference-embeddings",
"vendor/tinyinference/crates/tinyinference-llm",
"vendor/tinymemory/crates/tinymemory-api",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Initialize submodules in the documented clone workflow

When a new contributor follows gitbooks/getting-started.md:147-154, the documented plain git clone leaves these newly required submodule directories uninitialized, so the first cargo check fails while loading the missing vendored manifests. Although scripts/setup.sh initializes them, this workflow never invokes that script; update it to clone with --recurse-submodules or run git submodule update --init --recursive before Cargo.

Useful? React with 👍 / 👎.

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 2 lane(s) blocking, worst finding is high.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0152 · 304,927 in / 18,286 out · 21,186 cached (7%) · ladder/vectors, gpt-5.6-luna, deepseek-v4-flash · 396 embedded
critique:    $0.0074 · 137,361 in / 5,706 out  · 10,112 cached (7%) · gpt-5.6-luna, deepseek-v4-flash
security:    $0.0067 · 123,409 in / 3,140 out  · 9,026 cached (7%)  · gpt-5.6-luna
tests:       $0.0003 · 16,101 in  / 1,866 out  · 1,024 cached (6%)  · deepseek-v4-flash
description: $0.0003 · 7,714 in   / 4,237 out  · 1,024 cached (13%) · deepseek-v4-flash
e2e:         $0.0003 · 16,867 in  / 379 out    · 0 cached (0%)      · deepseek-v4-flash

Comment thread Cargo.toml
members = [
".",
"api",
"vendor/tinyinference/crates/tinyinference-core",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority high critique likely

Do not merge crates from nested workspaces into this workspace

These crates are described as inheriting metadata from the TinyInference upstream workspace, but listing them as members of this root workspace makes them members of this workspace instead. Cargo does not support nested workspaces, and any workspace = true fields in their manifests will resolve against this root's metadata (edition = 2024, rust-version = 1.88, and the TinyInference repository) rather than their upstream workspace. That can make cargo metadata/cargo check fail or silently change the vendored crates' package configuration. Keep the submodule workspace separate and use path dependencies, or remove its own workspace root and explicitly verify every inherited field after making it a member.

[RULE] workspace-membership ·

Comment thread api/Cargo.toml
tinymemory-api = { git = "https://github.com/tinyhumansai/tinymemory", rev = "4549cda222de3891b95e2fa58e2565bb2c194328" }
# Vendored as a submodule so this re-export and any local TinyMemory consumer
# resolve exactly one set of contract types, without a direct Git dependency.
tinymemory-api = { path = "../vendor/tinymemory/crates/tinymemory-api" }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium critique confident

Avoid requiring an uninitialized submodule to build

This path dependency only works when vendor/tinymemory has been populated. A normal git clone does not initialize submodules, and Cargo also does not populate nested submodules when resolving a repository used as a git dependency, so cargo check fails with a missing manifest before tinycortex-api can build. The CI checkout explicitly enables submodules, but that does not protect contributors following the repository's normal clone instructions or downstream users consuming the crate from Git. Keep the dependency self-contained for ordinary checkouts, or add and enforce a documented/bootstrap mechanism that makes every supported source-consumption path initialize the submodule.

[RULE] uninitialized-submodule ·

@tinysweeper tinysweeper Bot added the priority: p1 Next. Wrong behaviour a user will hit, or a security weakness behind a condition. label Sep 19, 2026
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@senamakel
senamakel merged commit 2ffca27 into main Oct 1, 2026
1 of 8 checks passed

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking, but could not review everything, so this is not an approval: Cargo.toml, tinysweeper/description, tinysweeper/e2e, tinysweeper/tests.

$0.0000 · 0 in / 0 out · 396 embedded · ladder/vectors

@tinysweeper tinysweeper Bot added priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect. and removed priority: p1 Next. Wrong behaviour a user will hit, or a security weakness behind a condition. labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant