Repository navigation
chore(deps): bump vendor/tinymcp to ship the 401-parking fix (#6412) - #6463
Conversation
The MCP reconnect supervisor retried a server whose credential was rejected forever — backoff grew to 300 s and stayed there, with no needs-auth state anywhere in the UI (tinyhumansai#6412). The fix landed upstream in tinymcp#20 (10786a472) on 2026-09-22, but vendor/tinymcp was still pinned at fe34f5b8c (2026-09-19), two commits behind it, so no build carried the fix. A merged submodule PR is not delivery; the gitlink has to move. tinymcp 10786a472 adds `|| error.is_unauthorized()` to the terminal-error guard in registry/supervisor/types.rs, so a 401 parks the server the way a missing runtime already did, instead of riding the backoff curve. Also refreshes the tinymcp module-pin exemption. `expect` pins one exact drift by design, so moving the pin widens it and fails the gate until the new describe is recorded — v0.3.2-13-gfe34f5b8 becomes v0.3.2-15-g10786a47. The exemption's compile-only rationale is unchanged: the registry still retains the published v0.3.2 artifact, and tinymcp is registry-entered but not wired, so nothing downloads or loads it. Closes tinyhumansai#6412
Tiny Sweeper reviewTiny Sweeper reviewed this change across 6 lane(s) and found 0 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below. State: Ready for maintainer review Review snapshot
Completeness: Complete What changedThe review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below. FeaturesNone identified with supported citations. TestsNo supported feature-to-test mapping was produced. Test execution is not inferred. FindingsNo active actionable findings. Before mergeNone. Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughThe tinymcp submodule reference advances to Changestinymcp pin update
Priority: ➖ Normal Estimated code review effort: 1 (Trivial) | ~3 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested reviewers: Merge Risk: ⚪ Minimal · up to The available evidence supports the intended 401 retry stop, and no concrete merge-blocking issue is established for this scoped pin update. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Linked Issues checkExplanation For
A rabbit checks the pin, Comment ✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
|
There was a problem hiding this comment.
tinysweeper found nothing blocking. Approving.
$0.0011 · 34,780 in / 2,700 out · 1,536 cached (4%) · ladder/vectors, gpt-5.6-luna, deepseek-v4-flash · 143 embedded
critique: $0.0004 · 13,132 in / 87 out · 0 cached (0%) · gpt-5.6-luna
security: $0.0005 · 12,888 in / 236 out · 0 cached (0%) · gpt-5.6-luna
description: $0.0002 · 7,059 in / 1,566 out · 1,536 cached (22%) · deepseek-v4-flash
Summary
vendor/tinymcpgitlink fromfe34f5b8cto10786a472, delivering the fix for MCP server returning 401 is retried forever (18+ failures, every 300 s) with no needs-auth state in the UI #6412.tinymcpentry inscripts/ci/module-pin-exemptions.json, whoseexpectpins one exact drift and therefore has to move with the pin.Problem
An MCP server whose credential was rejected (HTTP 401) was retried forever: backoff grew to 300 s and stayed there, 18+ failures in one session, with no
needs_authstate anywhere in the UI (#6412).The fix landed upstream in tinyhumansai/tinymcp#20, merged 2026-09-22 as
10786a472. Butvendor/tinymcpwas still pinned atfe34f5b8c, whose tinymcp-side commit is dated 2026-09-19 — two commits behind the fix:So the issue read as fixed while every build still shipped the old retry loop. A merged submodule PR is not delivery — the gitlink has to move.
Solution
The pin.
vendor/tinymcp→10786a472. The upstream change adds|| error.is_unauthorized()to the terminal-error guard incrates/tinymcp/src/registry/supervisor/types.rs, so a 401 parks the server the way a missing runtime already did, instead of riding the backoff curve. Its own comment cites openhuman#6412.The exemption.
expectaccepts one specific drift by design, so moving the pin widens it and failscheck-module-pins.mjsuntil the new describe is recorded.v0.3.2-13-gfe34f5b8→v0.3.2-15-g10786a47. The compile-only rationale is unchanged and still true: the registry retains the published v0.3.2 artifact, and tinymcp is registry-entered but not wired, so no build downloads or loads it. Thereasontext now also names the fix the drift carries.What was verified, and how
Forward movement — checked two independent ways so a shallow clone could not fake it.
gh api .../compare/fe34f5b8c...10786a472→status: "ahead",ahead_by: 2,behind_by: 0. Locally,merge-base --is-ancestorconfirms the same on a submodule verified non-shallow (rev-parse --is-shallow-repository→false).Both gates, before and after:
check-module-pins.mjscheck-submodule-monotonic.mjs"tinymcp" drift has CHANGED ... is at v0.3.2-15-g10786a47, exemption pins v0.3.2-13-gfe34f5b8~ tinymcp: v0.3.2-15-g10786a471 submodule pin(s) moved forward: vendor/tinymcpThe exemption edit was made only after the gate demanded it, not pre-emptively.
Two notes for anyone re-running these locally. Both gates need submodules checked out — the pin gate fails closed with
"vendor/tinydocs is not a checked-out submodule"rather than skipping. And the monotonic gate reads committed gitlinks (ls-treeof base..HEAD), so run before committing it reportsnone movedand exit 0 — a false green indistinguishable from a real pass. It also defaults toorigin/main, which on a fork is stale; the runs above passupstream/mainexplicitly.Cargo.lockdoes not move — verified rather than assumed, two ways:git status --porcelain Cargo.lockis empty, and the upstream diff touches zero Cargo manifests.Contract compile.
cargo check -p openhuman --libpasses on this branch — exit 0, zero errors, 307 dependency crates includingtinymcp v0.3.2andtinymcp-bus v0.3.2at the new pin. To be sure the host lib itself was exercised and not just its dependencies, I forced it to rebuild (touch crates/openhuman-core/src/lib.rs) and confirmedChecking openhuman v0.63.31 ... Finished in 11.27swith no errors. The 8 warnings are pre-existing dead-code warnings in vendoredtinyjuice, unrelated to this change.Note the package is
openhuman, notopenhuman-core— the directory name differs from the crate name. Reaching a compile also required all 16 top-level submodules plusvendor/tinyagents' nestedtinyinference/tinytools/wiki; two earlierexit 101s were dependency resolution failures, not compilation.Submission Checklist
N/A: submodule pin bump; the behaviour change and its tests live in tinymcp#20, which adds 70 lines of supervisor tests. No openhuman source changes to test.N/A: no executable lines changed in this repo. The diff is one gitlink and one JSON metadata field.N/A: behaviour-only change, delivered from a submodule; no feature rows added, removed or renamed.## Related—N/A: no matrix rows affected.N/A: no release-cut surface changed. tinymcp is registry-entered but not wired, so no build downloads or loads the artifact.Closes #NNNin the## Relatedsection — see below.Impact
Desktop runtime. An MCP server that returns 401 now stops being retried instead of issuing a request every 300 s for the life of the session, which removes the log and Sentry noise reported in #6412 and stops the pointless traffic against a third-party endpoint.
Scope is bounded: the change is internal to tinymcp's reconnect supervisor, adds no public signature change to
Supervisor::tickorTickReport, and this repo's sources are untouched.Not covered by this PR: the
needs_authstate in the MCP Servers page and the "Set token" action, which are the UI half of #6412's acceptance criteria. Those remain open — this delivers the retry-halting half.Related
10786a472)needs_authUI state + "Set token" action for the MCP Servers page. Also mcp_setup_request_secret never renders a prompt — times out 120 s ×3, agent asks for the bearer token in plain chat #6411 and MCP registry search hangs 15 s against registry.modelcontextprotocol.io and fails with no error shown #6415, which are tinymcp-side and gated on the same pin.AI Authored PR Metadata (required for Codex/Linear PRs)
Linear Issue
Commit & Branch
fix/bump-tinymcp-64120fa8353950c732921e26c6ca391416744405c66fValidation Run
pnpm --filter openhuman-app format:check—N/A: no app/ files changed.pnpm typecheck—N/A: no TypeScript changed.node scripts/ci/check-module-pins.mjsandnode scripts/ci/check-submodule-monotonic.mjs upstream/main HEAD— both exit 0 post-commit; outputs in the table above.cargo check -p openhuman --lib→ exit 0, zero errors (forced-rebuild confirmation of the host lib included above).N/Afor fmt: no Rust sources changed in this repo.N/A: no Tauri sources changed.Validation Blocked
command:none blocked.error:n/aimpact:n/a — the two pin gates and the contract compile all ran and passed. Not attempted: the full test suite and clippy, neither of which this diff can affect (no Rust, TypeScript or workflow sources changed).Behavior Changes
reconnecting failed: mcp unauthorized ... retry_in_seconds=300warnings stop. The MCP Servers page still shows noneeds_authindicator — that half of MCP server returning 401 is retried forever (18+ failures, every 300 s) with no needs-auth state in the UI #6412 is not addressed here.Parity Contract
is_missing_runtime()already took this exact path, and the new condition is OR'd onto it.check-module-pins.mjsandcheck-submodule-monotonic.mjsboth pass post-commit againstupstream/main.Duplicate / Superseded PR Handling
vendor/tinymcp.Summary by CodeRabbit