Repository navigation
Conversation
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Tiny Sweeper reviewThis pull request lays the foundation for enforcing module dependency boundaries and adds a pre-core module access client. It introduces a machine-checkable boundary gate (scripts/ci/check-module-boundaries.mjs with a policy JSON and inventory docs), CI lane wiring, and a new ModuleClient with sanitized, deduplicated terminal failure reporting. Review lanes reported four findings across critique and security, none blocking; the tests lane found the behavioral tests sound and earned. State: Reviewing pending checks Review snapshot
Completeness: Complete What changedNo supported behavioral explanation was produced. Features
Tests
Findings
Resolved this pass
Pending checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS), Storage e2e on MongoDB Before merge
How this fits togetherflowchart LR
n0["ensure_loaded_within<br/>changed"]:::changed
n1["start_resolution<br/>changed"]:::changed
n2["...d_downloads_off_fails_rather_than_loading"]:::impacted
n3["resolve"]:::impacted
n4["LoadError"]:::impacted
n5["ModuleRecord"]:::impacted
n6["load_cached"]:::impacted
n7["offline_config"]:::impacted
n0 -->|calls| n1
n0 -->|uses| n4
n1 -->|calls| n3
n1 -->|uses| n5
n2 -->|calls| n0
n2 -->|tests| n0
n2 -->|uses| n4
n2 -->|calls| n7
n2 -->|tests| n7
n3 -->|uses| n5
n3 -->|calls| n6
n6 -->|uses| n5
classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueNote Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info
📝 Walkthrough
|
Loadable-module implementations still enter shipped hosts directly and through contract crates. This PR adds dependency-boundary enforcement and a curated pre-core module client so each subsystem can migrate through its minimal bus contract. The migration is incomplete: 34 exceptions and two pending contracts remain. No implementation dependency, submodule gitlink or released artifact pin changes here.
The checker resolves host normal/build dependency graphs, including platform edges and the excluded desktop workspace, and independently validates contract crates with default and all features. It rejects unlisted implementation packages, unexpected contract dependencies, alternate contract sources and stale exceptions.
--require-completealso rejects the temporary exceptions and pending contracts.openhuman_rpc::embed::modules::ModuleClientuses explicit configuration and the shared process-wide lazy loader before core startup. Loader-disabled builds return unavailable errors. Confidential calls retain attestation. The facade respects the existing library chain. AGENTS.md, architecture docs and the owning-repository inventory document the boundary and track independently reviewed upstream PRs.Validation: enabled-loader module fixtures and loader-disabled facade tests pass; boundary/lane script tests, crate-chain and feature-forwarding checks pass; minimal RPC compilation passes. The transitional dependency audit has zero unlisted violations and stale exceptions; strict completion correctly fails on the remaining migration work. The dependency floor/simulator measure one additional pure contract package, with no native-build increase; no build-time or binary-size improvement is claimed.
Existing unrelated baseline failures remain: seven oversized Rust files fail layout checks, and minimal core unit tests contain unguarded desktop/search imports. Product/platform matrices, frozen-tool restoration and host lifecycle integration remain follow-up verification.
The latest inventory records verified Voice hotkey/capture work and the other owning module PRs. Channels relay/durable delivery and additional sandbox backends, wallet services, document image parsing and large hosting inputs remain active work. TinyRuntime is excluded from this migration at the user's request because its removal is handled separately. Previously published Runtime source remains documented; its frozen Python-provider change is not published or integrated.
The terminal-failure Sentry correction is implemented and independently verified in OpenHuman #7342, which depends on this foundation. Host caller switches and dependency cuts still require compatible published module artifacts with verified digests.