Skip to content

chore(deps): bump vendor/tinymcp to ship the 401-parking fix (#6412) - #6463

Merged
senamakel merged 1 commit into
tinyhumansai:mainfrom
M3gA-Mind:fix/bump-tinymcp-6412
Sep 23, 2026
Merged

senamakel merged 1 commit into
tinyhumansai:mainfrom
M3gA-Mind:fix/bump-tinymcp-6412

Conversation

@M3gA-Mind

@M3gA-Mind M3gA-Mind commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Problem

An MCP server whose credential was rejected (HTTP 401) was retried forever: backoff grew to 300 s and stayed there, 18+ failures in one session, with no needs_auth state anywhere in the UI (#6412).

The fix landed upstream in tinyhumansai/tinymcp#20, merged 2026-09-22 as 10786a472. But vendor/tinymcp was still pinned at fe34f5b8c, whose tinymcp-side commit is dated 2026-09-19 — two commits behind the fix:

$ git ls-tree upstream/main vendor/tinymcp
160000 commit fe34f5b8c89a49e6f7ca05c2da791bb34550f85f	vendor/tinymcp

$ gh api repos/tinyhumansai/tinymcp/compare/10786a472...fe34f5b8c --jq '{status,behind_by}'
{"status":"behind","behind_by":2}

So the issue read as fixed while every build still shipped the old retry loop. A merged submodule PR is not delivery — the gitlink has to move.

Solution

The pin. vendor/tinymcp → 10786a472. The upstream change adds || error.is_unauthorized() to the terminal-error guard in crates/tinymcp/src/registry/supervisor/types.rs, so a 401 parks the server the way a missing runtime already did, instead of riding the backoff curve. Its own comment cites openhuman#6412.

The exemption. expect accepts one specific drift by design, so moving the pin widens it and fails check-module-pins.mjs until the new describe is recorded. v0.3.2-13-gfe34f5b8 → v0.3.2-15-g10786a47. The compile-only rationale is unchanged and still true: the registry retains the published v0.3.2 artifact, and tinymcp is registry-entered but not wired, so no build downloads or loads it. The reason text now also names the fix the drift carries.

What was verified, and how

Forward movement — checked two independent ways so a shallow clone could not fake it. gh api .../compare/fe34f5b8c...10786a472 → status: "ahead", ahead_by: 2, behind_by: 0. Locally, merge-base --is-ancestor confirms the same on a submodule verified non-shallow (rev-parse --is-shallow-repository → false).

Both gates, before and after:

check-module-pins.mjs check-submodule-monotonic.mjs
clean tree OK (exit 0) OK (exit 0)
pin bumped, exemption not yet updated FAILED — "tinymcp" drift has CHANGED ... is at v0.3.2-15-g10786a47, exemption pins v0.3.2-13-gfe34f5b8 —
both changes, committed OK (exit 0), ~ tinymcp: v0.3.2-15-g10786a47 OK (exit 0), 1 submodule pin(s) moved forward: vendor/tinymcp

The exemption edit was made only after the gate demanded it, not pre-emptively.

Two notes for anyone re-running these locally. Both gates need submodules checked out — the pin gate fails closed with "vendor/tinydocs is not a checked-out submodule" rather than skipping. And the monotonic gate reads committed gitlinks (ls-tree of base..HEAD), so run before committing it reports none moved and exit 0 — a false green indistinguishable from a real pass. It also defaults to origin/main, which on a fork is stale; the runs above pass upstream/main explicitly.

Cargo.lock does not move — verified rather than assumed, two ways: git status --porcelain Cargo.lock is empty, and the upstream diff touches zero Cargo manifests.

Contract compile. cargo check -p openhuman --lib passes on this branch — exit 0, zero errors, 307 dependency crates including tinymcp v0.3.2 and tinymcp-bus v0.3.2 at the new pin. To be sure the host lib itself was exercised and not just its dependencies, I forced it to rebuild (touch crates/openhuman-core/src/lib.rs) and confirmed Checking openhuman v0.63.31 ... Finished in 11.27s with no errors. The 8 warnings are pre-existing dead-code warnings in vendored tinyjuice, unrelated to this change.

Note the package is openhuman, not openhuman-core — the directory name differs from the crate name. Reaching a compile also required all 16 top-level submodules plus vendor/tinyagents' nested tinyinference / tinytools / wiki; two earlier exit 101s were dependency resolution failures, not compilation.

Submission Checklist

  • Tests added or updated — N/A: submodule pin bump; the behaviour change and its tests live in tinymcp#20, which adds 70 lines of supervisor tests. No openhuman source changes to test.
  • Diff coverage ≥ 80% — N/A: no executable lines changed in this repo. The diff is one gitlink and one JSON metadata field.
  • Coverage matrix updated — N/A: behaviour-only change, delivered from a submodule; no feature rows added, removed or renamed.
  • All affected feature IDs from the matrix are listed under ## Related — N/A: no matrix rows affected.
  • No new external network dependencies introduced — no new dependency; an existing vendored submodule moves forward two commits.
  • Manual smoke checklist updated if this touches release-cut surfaces — N/A: no release-cut surface changed. tinymcp is registry-entered but not wired, so no build downloads or loads the artifact.
  • Linked issue closed via Closes #NNN in the ## Related section — see below.

Impact

Desktop runtime. An MCP server that returns 401 now stops being retried instead of issuing a request every 300 s for the life of the session, which removes the log and Sentry noise reported in #6412 and stops the pointless traffic against a third-party endpoint.

Scope is bounded: the change is internal to tinymcp's reconnect supervisor, adds no public signature change to Supervisor::tick or TickReport, and this repo's sources are untouched.

Not covered by this PR: the needs_auth state in the MCP Servers page and the "Set token" action, which are the UI half of #6412's acceptance criteria. Those remain open — this delivers the retry-halting half.

Related


AI Authored PR Metadata (required for Codex/Linear PRs)

Linear Issue

  • Key: N/A
  • URL: N/A

Commit & Branch

  • Branch: fix/bump-tinymcp-6412
  • Commit SHA: 0fa8353950c732921e26c6ca391416744405c66f

Validation Run

  • pnpm --filter openhuman-app format:check — N/A: no app/ files changed.
  • pnpm typecheck — N/A: no TypeScript changed.
  • Focused tests: node scripts/ci/check-module-pins.mjs and node scripts/ci/check-submodule-monotonic.mjs upstream/main HEAD — both exit 0 post-commit; outputs in the table above.
  • Rust fmt/check (if changed): cargo check -p openhuman --lib → exit 0, zero errors (forced-rebuild confirmation of the host lib included above). N/A for fmt: no Rust sources changed in this repo.
  • Tauri fmt/check (if changed): N/A: no Tauri sources changed.

Validation Blocked

  • command: none blocked.
  • error: n/a
  • impact: n/a — the two pin gates and the contract compile all ran and passed. Not attempted: the full test suite and clippy, neither of which this diff can affect (no Rust, TypeScript or workflow sources changed).

Behavior Changes

Parity Contract

  • Legacy behavior preserved: yes for every other error class. Only the unauthorized case changes branch; is_missing_runtime() already took this exact path, and the new condition is OR'd onto it.
  • Guard/fallback/dispatch parity checks: check-module-pins.mjs and check-submodule-monotonic.mjs both pass post-commit against upstream/main.

Duplicate / Superseded PR Handling

  • Duplicate PR(s): none — no open PR on this repo touches vendor/tinymcp.
  • Canonical PR: this one.
  • Resolution: N/A

Summary by CodeRabbit

  • Bug Fixes
    • Servers whose credentials are rejected are now parked instead of retrying indefinitely, preventing repeated connection attempts. Restart or update the server’s credentials to resume connections.

The MCP reconnect supervisor retried a server whose credential was
rejected forever — backoff grew to 300 s and stayed there, with no
needs-auth state anywhere in the UI (tinyhumansai#6412).

The fix landed upstream in tinymcp#20 (10786a472) on 2026-09-22, but
vendor/tinymcp was still pinned at fe34f5b8c (2026-09-19), two commits
behind it, so no build carried the fix. A merged submodule PR is not
delivery; the gitlink has to move.

tinymcp 10786a472 adds `|| error.is_unauthorized()` to the terminal-error
guard in registry/supervisor/types.rs, so a 401 parks the server the way
a missing runtime already did, instead of riding the backoff curve.

Also refreshes the tinymcp module-pin exemption. `expect` pins one exact
drift by design, so moving the pin widens it and fails the gate until the
new describe is recorded — v0.3.2-13-gfe34f5b8 becomes v0.3.2-15-g10786a47.
The exemption's compile-only rationale is unchanged: the registry still
retains the published v0.3.2 artifact, and tinymcp is registry-entered but
not wired, so nothing downloads or loads it.

Closes tinyhumansai#6412
@M3gA-Mind
M3gA-Mind requested a review from a team September 22, 2026 22:23
@tinysweeper

tinysweeper Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper reviewed this change across 6 lane(s) and found 0 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below.

State: Ready for maintainer review
Priority: none
Reviewed head: 0fa8353950c7
Updated: 1790115935 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 0 Active findings 0
Tests 0 Noted findings 0
Documentation 0 Resolved findings 0
Configuration 1 Pending checks/questions 0

Completeness: Complete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

The review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below.

Features

None identified with supported citations.

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

Findings

No active actionable findings.

Before merge

None.

Agent review details

critique

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The exemption updates the expected tinymcp submodule revision and documents the reconnect-supervisor fix. The change is limited to CI metadata and looks safe to merge based on the supplied diff. _The code index is behind this pull request (indexed at `656c80e58f06`), so retrieved context may be out of date._ _5 memory call(s) failed (model: cortex: v1/recall: timed out after 10s), so this review saw part of what the engine holds._

security

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: The exemption updates the expected tinymcp submodule revision and documents the reconnect-supervisor fix. The change looks safe to merge. _The code index is behind this pull request (indexed at `656c80e58f06`), so retrieved context may be out of date._ _5 memory call(s) failed (model: cortex: v1/recall: timed out after 10s), so this review saw part of what the engine holds._

tests

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: No behavioural change: nothing outside documentation, configuration and tests.

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: This pull request updates the `vendor/tinymcp` submodule pin to include a fix that parks MCP servers on HTTP 401 instead of retrying forever, and updates the corresponding exemption metadata. No source files in this repository are changed; the diff consists of two lines in `scripts/ci/module-pin-exemptions.json` and the submodule gitlink. The change is well-documented, verified through both CI gates and a contract compile, and does not introduce any rule violations. It is safe to merge. _The code index is behind this pull request (indexed at `656c80e58f06`), so retrieved context may be out of date._ _5 memory call(s) failed (model: cortex: v1/recall: timed out after 10s), so this review saw part of what the engine holds._

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: No behavioural change: nothing outside documentation, configuration and tests.
Evidence and run details
  • Models: ladder/vectors, gpt-5.6-luna, deepseek-v4-flash
  • Spend: $0.001126
  • Tokens: 34780 input · 2700 output · 1536 cached · 143 embedding
Head State Pass summary
0fa8353950c7 ready for maintainer review 0 active finding(s), 0 resolved finding(s) (at 1790115935)

tinysweeper 0.1.0

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 369ad7d9-7182-4896-93da-dfcf8836b975

📥 Commits

Reviewing files that changed from the base of the PR and between 0f1ecc9 and 0fa8353.

📒 Files selected for processing (2)
  • scripts/ci/module-pin-exemptions.json
  • vendor/tinymcp

Included review availability: Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The tinymcp submodule reference advances to 10786a4. The CI module-pin exemption updates its expected version and expands the reason to cite the reconnect-supervisor fix for rejected credentials.

Changes

tinymcp pin update

Layer / File(s) Summary
Update and document the tinymcp pin
vendor/tinymcp, scripts/ci/module-pin-exemptions.json
The submodule reference and CI exemption advance to v0.3.2-15-g10786a47. The exemption reason now cites the reconnect-supervisor fix.

Priority: ➖ Normal

Estimated code review effort: 1 (Trivial) | ~3 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: senamakel

Merge Risk: ⚪ Minimal · up to 0fa83

The available evidence supports the intended 401 retry stop, and no concrete merge-blocking issue is established for this scoped pin update.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning For #6412, the vendor/tinymcp pin advances to deliver the upstream 401 retry-parking fix. This addresses the retry-halting part of the issue. The PR does not implement the required needs_auth stat… Implement and test the remaining #6412 acceptance criteria: show needs_auth, provide a “Set token” action that resumes connection, handle 401/403 as required, and limit 401 warnings to one per server per session.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the tinymcp vendor update and its purpose: delivering the 401-parking fix.
Out of Scope Changes check ✅ Passed Both changes support delivery of the #6412 fix. The vendor/tinymcp pin delivers the upstream retry-parking change, and the exemption update matches that pin so the module-pin gate accepts the delibe…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Full details: Linked Issues check

Explanation

For #6412, the vendor/tinymcp pin advances to deliver the upstream 401 retry-parking fix. This addresses the retry-halting part of the issue. The PR does not implement the required needs_auth state or “Set token” action. The available evidence also does not establish 403 handling or limiting warnings to one per server per session.

  • Fix all pre-merge checks with AI

A rabbit checks the pin,
Then hops along the trail.
Rejected keys now pause,
While retries lose their trail.
The version moves ahead,
And CI notes the change.

Comment @coderabbitai help to get the list of available commands.

✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking. Approving.

             $0.0011 · 34,780 in / 2,700 out · 1,536 cached (4%)  · ladder/vectors, gpt-5.6-luna, deepseek-v4-flash · 143 embedded
critique:    $0.0004 · 13,132 in / 87 out    · 0 cached (0%)      · gpt-5.6-luna
security:    $0.0005 · 12,888 in / 236 out   · 0 cached (0%)      · gpt-5.6-luna
description: $0.0002 · 7,059 in  / 1,566 out · 1,536 cached (22%) · deepseek-v4-flash

@tinysweeper tinysweeper Bot added the priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect. label Sep 22, 2026
@senamakel
senamakel merged commit 33e54ea into tinyhumansai:main Sep 23, 2026
30 of 35 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p3 Whenever. Cosmetic, a nicety, or a cleanup with no user visible effect.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

MCP server returning 401 is retried forever (18+ failures, every 300 s) with no needs-auth state in the UI

2 participants