Skip to content

feat(storage): cron and flows on the storage ports - #7187

Merged
senamakel merged 28 commits into
tinyhumansai:mainfrom
senamakel:storage-cron-flows
Oct 9, 2026
Merged

senamakel merged 28 commits into
tinyhumansai:mainfrom
senamakel:storage-cron-flows

Conversation

@senamakel

@senamakel senamakel commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Summary

Problem

Solution

  • cron/store.rs: each function asks documents(config)? first and, when a backend is installed, runs the matching CronDocuments method through storage::block_on_anyhow, with the same max_run_history / max_tasks limits.
  • flows/store.rs / draft_store.rs: the same dispatch over FlowCatalogDocuments. update_flow_graph keeps returning FlowUpdateError, and storage failures map to FlowUpdateError::Store.
  • flows/tinyflows/state.rs (new): FlowState is one type for a flow's flow:<id> namespace, either SqliteStateStore or FlowStateDocuments. It implements both the engine's StateStore and DedupKv, so what a run stores is exactly what bus::dedup_commit settles. When the scope can't be resolved (SaaS with no acting agent) every call fails instead of falling back to the file. build_capabilities and dedup_commit use it.
  • Checkpointers: open_flow_checkpointer and the delegation graph pick DriverCheckpointer over the scoped documents when a backend is installed. The delegation checkpointer uses the delegation_graph prefix.
  • storage::block_on_anyhow: block_on for stores whose errors are anyhow::Error, so downcastable typed errors pass through.

Submission Checklist

  • Tests added or updated:
    • flows/tinyflows/state_tests.rs: engine and dedup views share records on both stores; namespaces isolated; an unresolved scope fails every call; no backend means SQLite.
    • tests/storage_flows_e2e.rs (own binary, memory backend):
      • cron add/list/record_run/list_runs/remove;
      • flows_create / flows_list through the RPC ops;
      • flow state resolves to documents and round-trips through kv_get / kv_set;
      • no cron/jobs.db or flows/flows.db written, and SQLite back in use after storage::clear().
    • The existing cron, flows and orchestration suites pass unchanged: 1404 tests, together with the devices, notifications, task-source and storage suites.
  • Diff coverage ≥ 80%: covered by the storage e2e suites and unit tests; CI reports the measured figure.
  • Coverage matrix updated: N/A, no user-visible feature change (desktop path unchanged).
  • Affected feature IDs: N/A.
  • No new external network dependencies: tests use the memory driver.
  • Manual smoke checklist: N/A, default desktop behaviour unchanged.
  • Linked issue: N/A, part of the storage-drivers migration.

Impact

  • Desktop / CLI / TUI: no change without a storage URL.
  • Cloud / SaaS: cron jobs, flows, drafts, flow state and checkpoints persist in the configured backend, isolated per agent. Rescheduling and run-status transitions use compare-and-swap upstream, so replicas sharing one database don't double-apply them.
  • Dependencies: tinyflows-drivers (unpublished, in the vendored tinyflows) joins core: schedule always, catalog with flows. tinyagents-graph gains its storage-drivers feature. The app lockfile is updated.

Related


AI Authored PR Metadata (required for Codex/Linear PRs)

Linear Issue

  • Key: N/A
  • URL: N/A

Commit & Branch

  • Branch: storage-cron-flows
  • Commit SHA: see the PR head

Validation Run

  • pnpm --filter openhuman-app format:check: N/A, no frontend changes
  • pnpm typecheck: N/A, no frontend changes
  • Focused tests:
    • RUST_MIN_STACK=16777216 cargo test -p openhuman --lib -- flows:: cron:: storage:: agent::orchestration security::devices desktop::notifications integrations::task_sources (1404 passed)
    • cargo test -p openhuman-cli --test storage_flows_e2e --test storage_domains_e2e
  • Rust fmt/check (if changed): cargo fmt, cargo clippy -p openhuman --lib --tests -- -D warnings, pnpm rust:layout, cargo check -p openhuman --no-default-features, node scripts/ci/check-feature-forwarding.mjs
  • Tauri fmt/check (if changed): app lockfile updated

Validation Blocked

Behavior Changes

  • Intended behavior change: with a storage backend configured, cron and flows persist there, scoped per agent.
  • User-visible effect: none on the desktop.

Parity Contract

  • Legacy behavior preserved: every public store signature and return contract is unchanged; without a backend the SQLite paths are untouched.
  • Guard/fallback/dispatch parity checks: upstream ports mirror the SQLite semantics with their own suites. The host's dispatch is one documents(config)? check per function, and flow state fails closed when the scope does not resolve.

Duplicate / Superseded PR Handling

  • Duplicate PR(s): none
  • Canonical PR: this one
  • Resolution (closed/superseded/updated): N/A

Summary by CodeRabbit

  • New Features
    • Cron jobs, flow catalogs, drafts, flow state, and execution checkpoints can now use a configured storage backend. Without one, existing local storage remains available.
    • Delegated task checkpoints also use the configured storage backend when available.
  • Documentation
    • Added guidance on storage-backed cron jobs and flows, including behavior when an agent’s storage scope cannot be resolved.
  • Tests
    • Added end-to-end coverage for storage-backed cron and flow operations.

senamakel and others added 18 commits October 9, 2026 13:27
…kend

Flow and delegation graph checkpoints now use the configured storage backend
through the new tinyflows-drivers dependency, falling back to the existing
SQLite files when no backend is set. This keeps checkpoint state in the acting
agent's scope instead of local workspace databases.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Regenerate the lockfile to pick up the new tinyflows-drivers crate and the
sha2 and tinystoragedrivers-core dependencies it pulls into the app graph.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The tinyflows-drivers dependency now enables its schedule feature by default with default features off, so the cron half is always available like cron itself, while the catalog, flow state and checkpointer features ride the flows gate. The flows feature now activates tinyflows-drivers/catalog instead of the optional dependency.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Adds a block_on variant for futures that already return anyhow::Result, so
stores whose errors are anyhow-based (with typed errors callers may downcast)
can be driven without wrapping or unwrapping the result.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Every cron store function now checks for a configured storage backend and
delegates to CronDocuments in the acting agent's scope, falling back to the
SQLite upstream otherwise. This lets cron jobs persist through the document
store with the same run-history and task limits.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Update the vendored tinyflows submodule to a newer revision and refresh
Cargo.lock accordingly. The tinyflows-drivers crate now pulls in anyhow,
chrono, tinyflows-catalog, tinyflows-schedule, and uuid, and
tinyflows-catalog gains anyhow.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Renamed the owned copy of the job id so the original parameter stays
available for the confirmation message after the async block.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
When a storage backend is configured, flow and draft catalog calls now go
through FlowCatalogDocuments in the acting agent's scope instead of the
local SQLite directory, falling back to the existing directory-based path
otherwise.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
The flows directory now always resolves to the workspace path instead of
first checking the documents provider, removing a fallible lookup that
could not succeed in this context.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Flow state construction now goes through a FlowState helper that opens the
flows database or the configured storage backend, replacing direct
SqliteStateStore usage in the dedup commit subscriber and capability
builder. This centralises backend selection so state access is no longer
hard-wired to SQLite.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
…ites

Adds the tinyflows-drivers dev-dependency with test-fixtures so the flows
store can forward the document catalog's test fixtures in test builds.
The remaining changes are rustfmt reflowing of long call chains and import
ordering, with no behaviour change.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add a Cargo test target for the new storage flows end-to-end test so it runs
as a separate binary, since it installs a storage backend into the
process-wide slot and would otherwise interfere with other tests.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Flow state assertions now read and write through the catalog's KV
interface instead of the dedup trait, since the engine/dedup sharing is
covered by unit tests in core. Also reformats a few assertions to satisfy
rustfmt.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Add anyhow to tinyflows-catalog and extend tinyflows-drivers with anyhow, chrono, tinyflows-catalog, tinyflows-schedule, and uuid. The lockfile is regenerated to reflect the new dependency graph.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Update the vendored tinyflows submodule to the latest commit.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Update the vendored tinyagents submodule to the latest upstream commit.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Adds README sections describing how cron, flows and the storage layer
delegate to the document port when a storage backend is configured,
covering the drivers used, scope handling and the block_on_anyhow helper.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: f1ede853-e96d-45e1-8e4e-b1a407a0df22

📥 Commits

Reviewing files that changed from the base of the PR and between f40fb22 and 7df8d51.


⛔ Files ignored due to path filters (2)
  • Cargo.lock is excluded by !**/*.lock
  • crates/openhuman-app/Cargo.lock is excluded by !**/*.lock

📒 Files selected for processing (4)
  • crates/openhuman-cli/Cargo.toml
  • crates/openhuman-core/src/storage/README.md
  • crates/openhuman-core/src/storage/mod.rs
  • vendor/tinyflows

🚧 Files skipped from review as they are similar to previous changes (1)
  • crates/openhuman-core/src/storage/README.md

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 4 remain after this review.



📝 Walkthrough

Walkthrough

Cron and flow storage operations now use scoped document storage when configured, with SQLite fallbacks in the existing paths. Flow state and checkpointer selection also uses scoped storage. New tests exercise cron, catalog, and state operations with MemoryStorage.

Changes

Storage-backed cron and flows

Layer / File(s) Summary
Storage drivers and synchronous bridge
crates/openhuman-core/Cargo.toml, crates/openhuman-core/src/storage/*, vendor/tinyflows
The core crate enables storage drivers and adds block_on_anyhow for futures returning anyhow::Result. Storage consumer documentation and the vendored tinyflows reference are updated.
Cron document-store routing
crates/openhuman-core/src/cron/store.rs, crates/openhuman-core/src/cron/README.md
Cron operations use scoped CronDocuments when available and retain SQLite fallback behavior and configured limits.
Flow catalog and draft routing
crates/openhuman-core/src/flows/store.rs, crates/openhuman-core/src/flows/draft_store.rs
Flow catalog and draft operations use the scoped document catalog when configured and retain SQLite fallbacks.
Flow state and checkpoints
crates/openhuman-core/src/flows/tinyflows/*, crates/openhuman-core/src/flows/bus/dedup_commit.rs, crates/openhuman-core/src/agent/orchestration/delegation.rs, crates/openhuman-core/src/flows/README.md
Flow state and flow checkpointers use scoped storage when available. Delegation checkpoints use scoped documents when configured and otherwise retain the workspace SQLite checkpointer. State tests cover both storage paths and unavailable-scope errors.
Storage routing integration coverage
crates/openhuman-cli/Cargo.toml, tests/storage_flows_e2e.rs
A separate test binary exercises cron, flow catalog, and flow-state operations with MemoryStorage. It checks that the classic cron and flow database files are absent.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant StorageFlowsE2E
  participant MemoryStorage
  participant CronDocuments
  participant FlowCatalogDocuments
  participant FlowState
  StorageFlowsE2E->>MemoryStorage: install backend
  StorageFlowsE2E->>CronDocuments: create, list, record run, remove
  StorageFlowsE2E->>FlowCatalogDocuments: create and list flow
  StorageFlowsE2E->>FlowState: open state and round-trip KV value
  StorageFlowsE2E->>MemoryStorage: clear backend
Loading

Suggested reviewers: codeghost21


Merge Risk: 🔵 Low · up to 7df8d

The storage integration test covers cron, catalog, and flow-state behavior, but not delegation checkpoints; a regression in that persistence path could go undetected, so merge with bounded follow-up to add coverage.

Architecture Summary

Architecture risk: 🔵 Low · up to 7df8d

The change affects 2 systems.

Changed systems: crates, tests

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — crates (service) was modified; 15 changed files map to changed impact.
  • observed — tests (service) was modified; 1 changed file maps to changed impact.

Before / after behavior

  • observed — Modified behavior in crates/openhuman-core/Cargo.toml: Adds the tinyflows-drivers path dependency with default features disabled and schedule enabled; comments specify that schedule support is unconditional while catalog-related drivers follow the flows gate.
  • observed — Modified behavior in crates/openhuman-core/Cargo.toml: Enables storage-drivers on tinyagents-graph, alongside its existing sqlite feature.
  • observed — Modified behavior in crates/openhuman-core/Cargo.toml: Adds a test-only tinyflows-drivers dependency with default features disabled and schedule plus test-fixtures enabled.
  • observed — Modified behavior in crates/openhuman-core/Cargo.toml: Adds tinyflows-drivers/catalog forwarding to the flows feature, so catalog driver support is enabled with that feature.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage Warning Docstring coverage is 75.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 84 functions across 11 files. (3 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely describes the main change: routing cron and flow persistence through storage ports.

Full details: Docstring Coverage

Explanation

Docstring coverage is 75.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 84 functions across 11 files. (3 skipped: 3 unsupported.)



  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

A rabbit checks the flow of bytes,
Through document stores and scheduled nights.
Cron jobs hop from scope to scope,
State finds room to save its hope.
SQLite waits when storage’s away,
And tests keep watch along the way.

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ⚠️ Failed 2026-10-09T13:11:39.489713Z 7df8d51 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

senamakel and others added 2 commits October 9, 2026 14:59
Update the vendored submodule pointers for tinymcp, tinysearch and
tinyskills to their latest revisions.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@tinysweeper

tinysweeper Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper completed its review; deterministic results follow.

State: Changes requested
Priority: critical
Reviewed head: 7df8d512b795
Updated: 1791551041 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 9 Active findings 6
Tests 2 Noted findings 0
Documentation 3 Resolved findings 64
Configuration 2 Pending checks/questions 4

Completeness: Complete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

This pull request routes the cron store, the flow catalog, flow drafts, per-flow engine state, and both checkpointer call sites (delegation graphs and flow runs) onto the configured storage backend when one is present, falling back to the existing SQLite files otherwise. A new FlowState abstraction in the flows tinyflows module picks Sqlite, document-backed, or an explicitly Unavailable store per call, and a new block_on_anyhow helper bridges the synchronous host APIs to the async document stores. A dedicated end-to-end test binary (storage_flows_e2e) drives cron jobs, the flow catalog, flow state and the KV layer against an in-memory backend and asserts the workspace SQLite files are not written. The cron and flows READMEs document the storage-backed behavior, and the storage README lists the newly ported stores plus the block_on_anyhow helper.

Features

  • Added — Cron store served by the storage backend: With a storage backend configured, every cron store function is served by tinyflows_drivers::schedule::CronDocuments instead of cron/jobs.db, in the acting agent's storage scope, with the same run-history cap and due-job batch size; reschedule_after_run advances a job only when its stored schedule still matches, so two processes sharing one database do not double-advance it. Without a backend the SQLite path is unchanged. (crates/openhuman-core/src/cron/store.rs#fn opts(config: &Config) -> CronStoreOptions {, crates/openhuman-core/src/cron/store.rs#pub fn add_agent_job(, crates/openhuman-core/src/cron/store.rs#pub fn add_agent_job_with_definition(, crates/openhuman-core/src/cron/store.rs#pub fn add_flow_schedule_job(, crates/openhuman-core/src/cron/store.rs#pub fn add_shell_job(, crates/openhuman-core/src/cron/store.rs#pub fn record_last_run(, crates/openhuman-core/src/cron/store.rs#pub fn record_run(, crates/openhuman-core/src/cron/store.rs#pub fn record_run_with_delivery(, crates/openhuman-core/src/cron/store.rs#pub fn reschedule_after_run(, crates/openhuman-core/src/cron/README.md#missing row, reschedules a drifted one, and removes the retired)
  • Added — Flow catalog and drafts served by the storage backend: With a storage backend configured, every flow catalog and draft store function is served by tinyflows_drivers::catalog::FlowCatalogDocuments on the document port in the acting agent's scope instead of flows/flows.db and flows/drafts/; the SQLite file paths remain the fallback when no backend is configured. (crates/openhuman-core/src/flows/store.rs#pub fn create_flow(, crates/openhuman-core/src/flows/store.rs#pub fn update_flow_graph(, crates/openhuman-core/src/flows/store.rs#pub fn insert_flow_run(, crates/openhuman-core/src/flows/store.rs#pub fn finish_flow_run(, crates/openhuman-core/src/flows/store.rs#pub fn expire_parked_runs(, crates/openhuman-core/src/flows/store.rs#pub fn kv_set(, crates/openhuman-core/src/flows/store.rs#pub fn list_running_run_ids(, crates/openhuman-core/src/flows/store.rs#pub fn list_suggestions(, crates/openhuman-core/src/flows/store.rs#pub fn revision_by_id(, crates/openhuman-core/src/flows/store.rs#pub fn force_corrupt_graph_json_for_test(, crates/openhuman-core/src/flows/store.rs#pub fn force_run_status_for_test(, crates/openhuman-core/src/flows/store.rs#pub fn dir(config: &Config) -> PathBuf {, crates/openhuman-core/src/flows/store.rs#use tinyflows_catalog::{, crates/openhuman-core/src/flows/draft_store.rs#pub fn create_draft(, crates/openhuman-core/src/flows/draft_store.rs#pub fn update_draft()
  • Added — Per-flow engine state abstraction (FlowState): A new FlowState type picks the store for a flow's namespaced state: SqliteStateStore over flows/flows.db without a backend, FlowStateDocuments in the acting agent's scope with one, or an Unavailable variant that fails every call rather than falling back to the local file when the scope cannot be resolved (SaaS mode with no acting agent). It implements both the engine's StateStore and the dedup settlement's DedupKv, so a run's writes and the post-run dedup settlement read the same records. (crates/openhuman-core/src/flows/tinyflows/state.rs, crates/openhuman-core/src/flows/tinyflows/mod.rs#pub mod caps;, crates/openhuman-core/src/flows/bus/dedup_commit.rs#impl DedupCommitSubscriber {)
  • Modified — Dedup settlement shares FlowState with the engine: The dedup commit subscriber settles dedup nodes through FlowState instead of SqliteStateStore, so on a storage backend the settlement reads the same document-backed records the engine wrote during the run. (crates/openhuman-core/src/flows/bus/dedup_commit.rs#impl DedupCommitSubscriber {)
  • Modified — Delegation graph checkpoints on the storage backend: Subagent delegation graph checkpoints move from workspace graph_checkpoints.db to tinyagents-graph's DriverCheckpointer over the storage backend's document port (prefixed delegation_graph) in the acting agent's scope, in the acting agent's scope, when a backend is configured; the SQLite checkpointer remains the no-backend path. Reviewers flagged that this new branch currently has no test exercising it. (crates/openhuman-core/src/agent/orchestration/delegation.rs#pub(crate) async fn run_subagent_delegation_with_parent_context()
  • Modified — Flow-run checkpointer on the storage backend: The durable cross-process checkpointer a flows_run uses opens as tinyflows_drivers::DriverCheckpointer over the configured backend in the acting agent's scope instead of flows/checkpoints.db; the SQLite checkpointer under the workspace remains the fallback. (crates/openhuman-core/src/flows/tinyflows/caps/ops.rs#pub fn build_capabilities(config: Arc<Config>, state_namespace: impl Into<String, crates/openhuman-core/src/flows/tinyflows/caps/ops.rs#impl ToolInvoker for OpenHumanTools {)
  • Added — block_on_anyhow bridge for the new document stores: Adds a storage::block_on_anyhow helper so the synchronous host APIs can drive the async document stores, whose errors are anyhow::Error; typed errors such as FlowUpdateError pass through unchanged for downcasting by callers. (crates/openhuman-core/src/storage/mod.rs#where, crates/openhuman-core/src/storage/README.md#on `storage-mongodb`.)
  • Added — Dedicated storage-flows end-to-end test binary: A new storage_flows_e2e test target runs in its own binary because it installs a backend into the process-wide storage slot, which would reroute other suites' stores in a shared process. (crates/openhuman-cli/Cargo.toml#path = "../../tests/storage_approvals_e2e.rs")

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

Findings

  • critical · critique · Add the referenced storage-flows test source — The new explicit test target points to `../../tests/storage_flows_e2e.rs`, but repository search found no file at that path. Cargo will fail to load or build this package because t (crates/openhuman\-cli/Cargo\.toml:98)
  • medium · tests · Assert the SQLite fallback without the conditional skip — This test gates its only assertion on `installed().is_none()`. If some other test in the same binary (or the same process, since the storage slot is process-wide) installs a backen (crates/openhuman\-core/src/flows/tinyflows/state\_tests\.rs:68)
  • medium · description · Test the delegation checkpointer on a storage backend — Every other store rerouted by this PR is covered — cron, the flow catalog and flow state in `tests/storage_flows_e2e.rs`, and the `FlowState` variants in `state_tests.rs` — but the (\(pull request description\))
  • medium · e2e · Drive the storage-backed delegation checkpointer end to end — The delegation checkpointer now routes to tinyagents-graph's `DriverCheckpointer` when a storage backend is configured, but tests/storage_flows_e2e.rs — the only e2e harness that i (crates/openhuman\-core/src/agent/orchestration/delegation\.rs:91)

Previously reported and still active

  • Exercise the storage-backed delegation checkpointer
  • Exercise the delegation checkpointer on the document store

Resolved this pass

  • Register the storage flows E2E test target
  • Own the agent job name before moving it into the async call
  • Own the defined agent job name before moving it asynchronously
  • Own the job name before moving it into the future
  • Add the storage flows test source before declaring its target
  • Test the delegation checkpointer on a storage backend
  • Exercise the delegation checkpointer on the storage backend
  • Exercise delegation checkpointing on the document store
  • Own the shell job name before moving it into the async call
  • Exercise cron delegation on the storage backend
  • Register the storage flows E2E test target
  • Exercise delegation checkpointing in the storage-flow test
  • Drive the delegation checkpointer on a storage backend
  • Drive the fallback path after clearing the storage backend
  • Test the storage-backed delegation checkpointer
  • Assert the SQLite fallback without the conditional skip
  • Register the storage flows E2E test target
  • Own the agent job name before moving it into the async call
  • Own the defined agent job name before moving it asynchronously
  • Own the job name before moving it into the future
  • Add the storage flows test source before declaring its target
  • Test the delegation checkpointer on a storage backend
  • Exercise the delegation checkpointer on a storage backend
  • Exercise delegation checkpointing on the document store
  • Own the shell job name before moving it into the async call
  • Exercise cron delegation on the storage backend
  • Register the storage flows E2E test target
  • Exercise delegation checkpointing in the storage-flow test
  • Drive the fallback path after clearing the storage backend
  • Assert the SQLite fallback without the conditional skip
  • Own the agent job name before moving it into the async call
  • Own the defined agent job name before moving it asynchronously
  • Own the job name before moving it into the future
  • Own the agent job name before moving it into the future
  • Own the shell job name before moving it into the async call
  • Own the agent job name before moving it asynchronously
  • Own the shell job name before moving it asynchronously
  • Add the storage flows test source before declaring its target
  • Register the storage flows E2E test target
  • Drive the fallback path after clearing the storage backend
  • Own the agent job name before moving it into the async call
  • Own the defined agent job name before moving it asynchronously
  • Own the job name before moving it into the future
  • Own the agent job name before moving it into the future
  • Own the shell job name before moving it into the async call
  • Own the defined agent job name before moving it asynchronously
  • Own the shell job name before moving it asynchronously
  • Own the agent job name before moving it asynchronously
  • Add the storage flows test source before declaring its target
  • Register the storage flows E2E test target
  • Drive the fallback path after clearing the storage backend
  • Assert the SQLite fallback without the conditional skip
  • Drive the delegation checkpointer on a storage backend end to end
  • Own the agent job name before moving it into the async call
  • Own the defined agent job name before moving it asynchronously
  • Own the job name before moving it into the future
  • Own the shell job name before moving it into the async call
  • Own the agent job name before moving it into the future
  • Own the shell job name before moving it asynchronously
  • Own the agent job name before moving it asynchronously
  • Add the storage flows test source before declaring its target
  • Register the storage flows E2E test target
  • Exercise cron delegation on the storage backend
  • Drive the fallback path after clearing the storage backend

Pending checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)

Before merge

  • Address carried finding Exercise the storage-backed delegation checkpointer.
  • Address carried finding Exercise the delegation checkpointer on the document store.
  • Address Add the referenced storage-flows test source (crates/openhuman\-cli/Cargo\.toml).
  • Wait for Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS).

How this fits together

flowchart LR
  n0["flows_create"]:::impacted
  n1["..._expires_stale_runs_but_spares_fresh_ones"]:::impacted
  n2["flows_run"]:::impacted
  n3["flows_resume"]:::impacted
  n4["...t_with_an_incompatible_saved_child_failed"]:::impacted
  n5["structurally_valid_graph"]:::impacted
  n1 -->|calls| n0
  n1 -->|tests| n0
  n1 -->|calls| n2
  n1 -->|tests| n2
  n1 -->|calls| n3
  n1 -->|tests| n3
  n4 -->|calls| n0
  n4 -->|tests| n0
  n4 -->|calls| n2
  n4 -->|tests| n2
  n4 -->|calls| n3
  n4 -->|tests| n3
  n4 -->|calls| n5
  n4 -->|tests| n5
  classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
  classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
  classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
  classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Loading
Agent review details

critique

  • Conclusion: Failure
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 3 files; 1 finding. (9 earlier finding(s) still open) _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: crates/openhuman\-cli/Cargo\.toml — Add the referenced storage-flows test source

security

  • Conclusion: Failure
  • Scope reviewed: all assigned evidence
  • Lane summary: Reviewed 2 files; 1 finding. 1 file was not security-reviewed: crates/openhuman-core/src/storage/README.md (prose or tabular data). (1 already reported on an earlier push) (10 earlier finding(s) still open) _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: The previously missing storage-flows test target is now registered as its own test binary in the CLI crate and the earlier compile-level and test-target findings are resolved.
  • Positive: The storage-backend rerouting of cron, the flow catalog/drafts, flow state and draft stores is now driven end to end by tests/storage_flows_e2e.rs, and the fallback path is asserted after storage::clear().
  • Lane summary: The change routes cron, flow catalog, drafts, flow state and both checkpointers onto the configured storage backend, and this revision adds the previously missing test target and test source, owns every borrowed value before it moves into a future, and drives the SQLite fallback after clearing the backend. What remains untested is the delegation graph's new DriverCheckpointer branch — nothing in the diff exercises delegation on a storage backend — and the SQLite fallback test still skips itself conditionally. Otherwise the change looks sound and ready to merge. (1 already reported on an earlier push) (16 earlier finding(s) still open) _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: crates/openhuman\-core/src/flows/tinyflows/state\_tests\.rs — Assert the SQLite fallback without the conditional skip

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Positive: Borrowed values in the cron store are now owned before moving into the futures, fixing the stored-name move concerns; the new block_on_anyhow helper and its README note are judged sound.
  • Lane summary: The stored-name moves in the cron store are fixed (every `&str` is owned before entering the future), and `storage_flows_e2e` is now registered as its own test target in crates/openhuman-cli/Cargo.toml with the fallback asserted after `storage::clear()`. The new `block_on_anyhow` helper and its README note are sound. One concern remains: the delegation graph's new storage-backed checkpointer path still has no test exercising it, unlike the cron and flow paths covered end to end. (10 earlier finding(s) still open) _Code retrieval was unavailable (model: ladder embeddings returned 400 Bad Request: {"error":{"message":"unknown ladder vectors; known ladders are flash (also chat-v1, flash-v1), instant (also no-think, instant-v1), reasoning (also deepseek), max-reasoning (also max-reasoning-v1), deepseek-flash (also reasoning-v1, agentic-v1), deep (also luna), scribe, uncensored, vectors-oai3 (also embeddings-oai3-v1), vision (also vision-v1, multimodal-v1), image (also images-v1, image-v1), vi), so this review saw the diff alone._ _Memory was unavailable (model: cortex: v1/recall: error sending request for url (http://cortexdb:3141/v1/recall\)\), so this review ran without it._
  • Evidence: \(pull request description\) — Test the delegation checkpointer on a storage backend

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: The storage-backend rerouting of cron, the flow catalog/drafts, flow state and draft stores is now driven end to end by tests/storage_flows_e2e.rs, and the earlier compile-level and test-target findings are resolved. One behavioural change remains without any end-to-end driver: the delegation graph checkpointer's storage-backend branch. Safe to merge apart from that coverage gap. Waiting on end-to-end jobs: `Rust E2E (mock backend)`, `Build Playwright E2E Artifact`, `E2E (Playwright / web lane)`, `Desktop E2E (full suite, 3 OS)`. (15 earlier finding(s) still open)
  • Unresolved questions/checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)
  • Evidence: crates/openhuman\-core/src/agent/orchestration/delegation\.rs — Drive the storage-backed delegation checkpointer end to end
Evidence and run details
  • Models: gpt-5.6-luna, glm-5.3-flash
  • Spend: $0.003602
  • Tokens: 185827 input · 12795 output · 26050 cached · 0 embedding
Head State Pass summary
df4e9eed87f0 changes requested 6 active finding(s), 0 resolved finding(s) (at 1791547755)
bbcd917399fb changes requested 15 active finding(s), 102 resolved finding(s) (at 1791548611)
f40fb22c7acb changes requested 15 active finding(s), 182 resolved finding(s) (at 1791549327)
7df8d512b795 changes requested 4 active finding(s), 64 resolved finding(s) (at 1791551041)

tinysweeper 0.1.0

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 2 lane(s) blocking, worst finding is critical.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0084 · 702,330 in / 38,462 out · 64,440 cached (9%)  · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0042 · 333,856 in / 18,854 out · 35,619 cached (11%) · gpt-5.6-luna, glm-5.3-flash
security:    $0.0028 · 225,206 in / 11,206 out · 26,965 cached (12%) · gpt-5.6-luna
tests:       $0.0004 · 46,378 in  / 3,574 out  · 1,856 cached (4%)   · glm-5.3-flash
description: $0.0002 · 22,634 in  / 172 out    · 0 cached (0%)       · glm-5.3-flash
e2e:         $0.0005 · 51,757 in  / 697 out    · 0 cached (0%)       · glm-5.3-flash

Comment thread crates/openhuman-core/src/cron/store.rs
Comment thread crates/openhuman-core/src/cron/store.rs
Comment thread crates/openhuman-core/src/cron/store.rs
Comment thread crates/openhuman-cli/Cargo.toml
Comment thread crates/openhuman-core/src/agent/orchestration/delegation.rs
senamakel and others added 2 commits October 9, 2026 15:10
Update the vendored tinymcp and tinysearch submodule pointers to their
latest revisions.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
…eam main

The previous auto-commit recorded stale local submodule checkouts.

Co-authored-by: Medulla <medulla@tinyhumans.ai>
@tinysweeper tinysweeper Bot added the priority: p0 Drop what you are doing. Data loss, a live break, or an exploitable hole. label Oct 9, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 654eaf5307

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/openhuman-core/src/cron/store.rs
Comment thread crates/openhuman-core/src/cron/store.rs
Comment thread crates/openhuman-core/src/flows/store.rs
Comment thread crates/openhuman-core/src/flows/bus/dedup_commit.rs
Comment thread crates/openhuman-core/src/flows/store.rs
coderabbitai[bot]
coderabbitai Bot previously approved these changes Oct 9, 2026

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 2 lane(s) blocking, worst finding is critical.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0088 · 696,362 in / 52,270 out · 111,555 cached (16%) · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0046 · 344,787 in / 30,333 out · 62,993 cached (18%)  · gpt-5.6-luna, glm-5.3-flash
security:    $0.0033 · 257,564 in / 17,489 out · 46,706 cached (18%)  · gpt-5.6-luna
tests:       $0.0002 · 21,935 in  / 811 out    · 0 cached (0%)        · glm-5.3-flash
description: $0.0002 · 23,128 in  / 951 out    · 0 cached (0%)        · glm-5.3-flash
e2e:         $0.0002 · 25,722 in  / 1,150 out  · 1,728 cached (7%)    · glm-5.3-flash

Comment thread crates/openhuman-core/src/cron/store.rs
Comment thread crates/openhuman-cli/Cargo.toml
Comment thread tests/storage_flows_e2e.rs
Comment thread crates/openhuman-core/src/agent/orchestration/delegation.rs
Comment thread crates/openhuman-core/src/flows/store.rs
Comment thread crates/openhuman-core/src/cron/store.rs
Comment thread crates/openhuman-core/src/cron/store.rs
Comment thread crates/openhuman-core/src/cron/store.rs
Comment thread crates/openhuman-core/src/flows/tinyflows/state_tests.rs
Comment thread tests/storage_flows_e2e.rs
Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
coderabbitai[bot]
coderabbitai Bot previously approved these changes Oct 9, 2026

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 2 lane(s) blocking, worst finding is critical.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0373 · 791,175 in / 60,211 out · 103,799 cached (13%) · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0204 · 412,248 in / 29,418 out · 56,253 cached (14%)  · gpt-5.6-luna, glm-5.3-flash
security:    $0.0156 · 259,647 in / 25,886 out · 34,106 cached (13%)  · gpt-5.6-luna
tests:       $0.0004 · 47,046 in  / 802 out    · 13,440 cached (29%)  · glm-5.3-flash
description: $0.0002 · 23,232 in  / 762 out    · 0 cached (0%)        · glm-5.3-flash
e2e:         $0.0002 · 25,789 in  / 548 out    · 0 cached (0%)        · glm-5.3-flash

Comment thread crates/openhuman-core/src/cron/store.rs
Comment thread crates/openhuman-core/src/cron/store.rs
Comment thread crates/openhuman-core/src/cron/store.rs
Comment thread crates/openhuman-core/src/cron/store.rs
Comment thread crates/openhuman-core/src/agent/orchestration/delegation.rs
Comment thread crates/openhuman-cli/Cargo.toml
Comment thread tests/storage_flows_e2e.rs
Comment thread crates/openhuman-core/src/flows/tinyflows/caps/ops.rs
Comment thread crates/openhuman-core/src/flows/bus/dedup_commit.rs
Comment thread tests/storage_flows_e2e.rs

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f40fb22c7a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/openhuman-core/src/cron/store.rs
Comment thread crates/openhuman-core/src/flows/store.rs
Comment thread crates/openhuman-core/src/flows/bus/dedup_commit.rs
Comment thread crates/openhuman-core/src/flows/store.rs
senamakel and others added 4 commits October 9, 2026 16:00
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previously-blocking findings are resolved. Clearing the changes request.

             $0.0043 · 202,370 in / 15,234 out · 9,982 cached (5%)  · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0008 · 54,433 in  / 5,311 out  · 7,934 cached (15%) · gpt-5.6-luna
security:    $0.0024 · 27,087 in  / 2,330 out  · 0 cached (0%)      · gpt-5.6-luna
tests:       $0.0002 · 22,356 in  / 1,234 out  · 64 cached (0%)     · glm-5.3-flash
description: $0.0002 · 23,460 in  / 1,509 out  · 64 cached (0%)     · glm-5.3-flash
e2e:         $0.0005 · 52,290 in  / 2,905 out  · 1,792 cached (3%)  · glm-5.3-flash

Comment thread tests/storage_flows_e2e.rs
Comment thread crates/openhuman-core/src/flows/tinyflows/state_tests.rs
@tinysweeper tinysweeper Bot added priority: p2 Soon. Real but survivable — a rough edge, a gap, a thing that will bite later. and removed priority: p0 Drop what you are doing. Data loss, a live break, or an exploitable hole. labels Oct 9, 2026

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 2 lane(s) blocking, worst finding is critical.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0036 · 185,827 in / 12,795 out · 26,050 cached (14%) · gpt-5.6-luna, glm-5.3-flash
critique:    $0.0009 · 42,231 in  / 4,142 out  · 14,319 cached (34%) · gpt-5.6-luna, glm-5.3-flash
security:    $0.0016 · 22,362 in  / 1,713 out  · 6,995 cached (31%)  · gpt-5.6-luna
tests:       $0.0004 · 48,943 in  / 1,819 out  · 1,600 cached (3%)   · glm-5.3-flash
description: $0.0002 · 23,460 in  / 852 out    · 1,408 cached (6%)   · glm-5.3-flash
e2e:         $0.0002 · 26,072 in  / 1,152 out  · 1,728 cached (7%)   · glm-5.3-flash

Comment thread crates/openhuman-cli/Cargo.toml
Comment thread crates/openhuman-core/src/flows/tinyflows/state_tests.rs
Comment thread crates/openhuman-core/src/agent/orchestration/delegation.rs
@tinysweeper tinysweeper Bot added priority: p0 Drop what you are doing. Data loss, a live break, or an exploitable hole. and removed priority: p2 Soon. Real but survivable — a rough edge, a gap, a thing that will bite later. labels Oct 9, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7df8d512b7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/openhuman-core/src/flows/store.rs
Comment thread crates/openhuman-core/src/flows/store.rs
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p0 Drop what you are doing. Data loss, a live break, or an exploitable hole.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant