Skip to content

Add static TinyBus module exports - #23

Merged
senamakel merged 5 commits into
tinyhumansai:mainfrom
senamakel:static-modules
Sep 25, 2026
Merged

senamakel merged 5 commits into
tinyhumansai:mainfrom
senamakel:static-modules

Conversation

@senamakel

@senamakel senamakel commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Pin TinyBus to merged PR fix(oauth): prefer RFC 8414 metadata and fill gaps from OIDC discovery #28 (11a7d0d), which provides linked module startup and Rust-addressable ABI entries.
  • Add opt-in static-link feature using one shared module declaration for static and dynamic exports.
  • Expose the descriptor, manifest, and init entries for a Rust host while preserving the default loadable module path.

Related issue

None.

API or behavior changes

Additive: with static-link, the crate exposes tinybus_module::{TINYBUS_MODULE_ABI_V1, tinybus_module_manifest_v1, tinybus_module_init_v1}. Default dynamic loading is unchanged.

Validation

  • cargo fmt --all -- --check
  • cargo clippy --all-targets --all-features -- -D warnings
  • cargo clippy --all-targets -- -D warnings
  • cargo build --all-targets --all-features
  • cargo test --all-features
  • cargo build -p tinymcp and cargo run -p tinymcp --example verify_module -- target/debug/libtinymcp.dylib

Tests

Added a static feature integration test for the descriptor, manifest, and init entry. The existing dynamic verifier passed against a freshly built artifact.

Documentation

Updated README with static-link usage.

Checklist

  • Focused change
  • No secrets or credentials in diff or description

Summary by CodeRabbit

  • New Features
    • Added a static-link option for loading TinyBus modules through static linking, with the required ABI entries available to Rust code.
  • Documentation
    • Added guidance on static linking, including how it differs from native loadable modules and which feature to use when packaging a dynamic library.

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: c67bfaa4-b4a1-4dae-a8e7-1928a50a90bb

📥 Commits

Reviewing files that changed from the base of the PR and between a79968d and 0eddf2d.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (8)
  • .github/workflows/ci.yml
  • README.md
  • crates/tinymcp/Cargo.toml
  • crates/tinymcp/src/lib.rs
  • crates/tinymcp/src/tinybus_module/mod.rs
  • crates/tinymcp/src/tinybus_module/service.rs
  • crates/tinymcp/tests/static_link.rs
  • vendor/tinybus

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The crate adds a static-link feature that exposes TinyBus ABI v1 entries as Rust-addressable symbols while retaining dynamic module exports by default. The PR also updates service method bodies, adds ABI checks, and documents the build paths.

Changes

Static-link ABI exposure

Layer / File(s) Summary
Feature and module visibility
crates/tinymcp/Cargo.toml, crates/tinymcp/src/lib.rs
The crate adds the static-link feature and module-gated examples. The tinybus_module module is public when static-link is enabled.
Static and dynamic ABI exports
crates/tinymcp/src/tinybus_module/mod.rs, vendor/tinybus
The export declaration selects static exports when static-link is enabled and retains dynamic exports otherwise. The TinyBus submodule reference changes.
Service async method implementations
crates/tinymcp/src/tinybus_module/service.rs
Six method bodies await immediately ready futures before running their existing logic. The interface comment describes the required async signatures.
Static-link verification and build documentation
crates/tinymcp/tests/static_link.rs, .github/workflows/ci.yml, README.md
A feature-gated test checks the ABI descriptor, manifest, and initialization function. CI verifies a default-features build, and the README describes the build paths.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature

Merge Risk: 🔵 Low · up to 0eddf

CI checks both linking modes, but the static-link test may miss regressions in the module manifest’s contents. This is a bounded follow-up risk; there is no evidence the current manifest is incorrect.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 0eddf

The linked entrypoints use the same declared service setup as the existing loadable module. No introduced security bypass was identified, but the linked initialization path and its caller permissions have not been verified at runtime.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — A host opting into the linked ABI can initialize the existing TinyBus service, whose methods reach its configured registry and audit store. The evidence does not establish additional tenant or network exposure.

Trust Boundaries and Controls

  • inferred — The repository-visible static and dynamic declarations select the same setup and methods, providing no observed alternate route around service construction. Generated initialization behavior and broker-level caller authorization remain unverified.

Hardening Proposals

  • proposed — Exercise linked init and a served method in a host integration test to verify startup and caller-boundary behavior beyond symbol availability.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the primary change: adding static TinyBus module exports.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 8 functions across 4 files. (4 skipped: 4 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

A rabbit checks the symbols bright,
Static paths and exports take flight.
Six methods pause, then hop along,
The tests confirm their ABI song.
The README marks each build-path right.
I tuck the notes beside the byte.

Comment @coderabbitai help to get the list of available commands.

@tinysweeper

tinysweeper Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper reviewed this change across 6 lane(s) and found 3 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below.

State: Ready for maintainer review
Priority: medium
Reviewed head: 0eddf2d41752
Updated: 1790368313 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 3 Active findings 6
Tests 1 Noted findings 0
Documentation 1 Resolved findings 3
Configuration 2 Pending checks/questions 0

Completeness: Complete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

The review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below.

Features

None identified with supported citations.

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

Findings

  • medium · description · Validate the manifest contents beyond length — The test only asserts that the manifest is non-empty. A malformed or incorrect manifest containing the wrong interface, object path, or methods would still pass. Parse the returned (\(pull request description\))

Previously reported and still active

  • Validate the manifest contents
  • Verify `module\_export\_static!` macro exists in `tinybus-module`
  • Build the verified module with all features
  • Validate the manifest contents
  • Verify the module with all features enabled

Resolved this pass

  • Assert the exact module name
  • Assert the exact module name
  • Assert the exact module name

Before merge

  • Address carried finding Validate the manifest contents.
  • Address carried finding Verify `module\_export\_static!` macro exists in `tinybus-module`.
  • Address carried finding Build the verified module with all features.
  • Address carried finding Validate the manifest contents.
  • Address carried finding Verify the module with all features enabled.

How this fits together

flowchart LR
  n0["McpService<br/>changed"]:::changed
  n1["failed"]:::impacted
  n2["Error"]:::impacted
  n3["parse_handles"]:::impacted
  n4["service"]:::impacted
  n1 -->|uses| n2
  n3 -->|uses| n2
  n4 -->|uses| n0
  classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
  classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
  classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
  classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Loading
Agent review details

critique

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: This documentation-only change accurately explains the static-link and dynamic-module build modes. It is safe to merge. (5 earlier finding(s) still open) _The code index is behind this pull request (indexed at `e8be469fc6e3`), so retrieved context may be out of date._ _3 memory call(s) failed (model: cortex: v1/answer answered 502 Bad Gateway), so this review saw part of what the engine holds._

security

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: No changed file has any attack surface. 1 file was not security-reviewed: README.md (prose or tabular data).

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Adds static-link support for Rust-linked TinyBus modules, with a test confirming the three ABI entry points are exported. The test does not parse the embedded manifest to verify the interface name, object path, or served members, so the earlier finding about incomplete manifest validation remains unresolved. (1 already reported on an earlier push) (3 earlier finding(s) still open) _The code index is behind this pull request (indexed at `e8be469fc6e3`), so retrieved context may be out of date._ _3 memory call(s) failed (model: cortex: v1/answer answered 502 Bad Gateway), so this review saw part of what the engine holds._

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Adds documentation for the static-link feature and explains the CI build trade-off. The manifest validation test remains shallow (only checks non-empty), which was flagged before and still unfixed, but this commit does not introduce a regression. (5 earlier finding(s) still open) _The code index is behind this pull request (indexed at `e8be469fc6e3`), so retrieved context may be out of date._ _3 memory call(s) failed (model: cortex: v1/answer answered 502 Bad Gateway), so this review saw part of what the engine holds._
  • Evidence: \(pull request description\) — Validate the manifest contents beyond length

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: No end-to-end harness in this repository: no e2e test files and no e2e workflow.
Evidence and run details
  • Models: ladder/vectors, gpt-5.6-luna, deepseek-v4-flash
  • Spend: $0.001279
  • Tokens: 48469 input · 8348 output · 2560 cached · 460 embedding
Head State Pass summary
e8be469fc6e3 ready for maintainer review 3 active finding(s), 0 resolved finding(s) (at 1790367486)
f0dc56a5e984 changes requested 4 active finding(s), 25 resolved finding(s) (at 1790368036)
0eddf2d41752 ready for maintainer review 1 active finding(s), 3 resolved finding(s) (at 1790368313)

tinysweeper 0.1.0

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking. Approving.

             $0.0069 · 263,537 in / 19,975 out · 28,479 cached (11%) · ladder/vectors, gpt-5.6-luna, deepseek-v4-flash · 372 embedded
critique:    $0.0041 · 153,604 in / 5,641 out  · 8,192 cached (5%)   · gpt-5.6-luna, deepseek-v4-flash
security:    $0.0019 · 74,526 in  / 2,205 out  · 5,439 cached (7%)   · gpt-5.6-luna
tests:       $0.0005 · 27,529 in  / 6,809 out  · 13,824 cached (50%) · deepseek-v4-flash
description: $0.0002 · 4,759 in   / 3,356 out  · 1,024 cached (22%)  · deepseek-v4-flash

Comment thread crates/tinymcp/tests/static_link.rs Outdated
Comment thread crates/tinymcp/tests/static_link.rs
Comment thread crates/tinymcp/src/tinybus_module/mod.rs

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 2 lane(s) blocking, worst finding is high.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

             $0.0062 · 214,396 in / 20,558 out · 11,880 cached (6%) · ladder/vectors, gpt-5.6-luna, deepseek-v4-flash · 445 embedded
critique:    $0.0030 · 93,036 in  / 9,039 out  · 4,648 cached (5%)  · gpt-5.6-luna, deepseek-v4-flash
security:    $0.0022 · 78,936 in  / 3,240 out  · 3,648 cached (5%)  · gpt-5.6-luna
tests:       $0.0007 · 32,191 in  / 4,410 out  · 2,560 cached (8%)  · deepseek-v4-flash
description: $0.0001 · 6,040 in   / 764 out    · 1,024 cached (17%) · deepseek-v4-flash

Comment thread .github/workflows/ci.yml
Comment thread crates/tinymcp/tests/static_link.rs

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The previously-blocking findings are resolved. Clearing the changes request.

             $0.0013 · 48,469 in / 8,348 out · 2,560 cached (5%)  · ladder/vectors, gpt-5.6-luna, deepseek-v4-flash · 460 embedded
critique:    $0.0004 · 15,457 in / 561 out   · 0 cached (0%)      · gpt-5.6-luna
tests:       $0.0003 · 17,934 in / 1,143 out · 1,536 cached (9%)  · deepseek-v4-flash
description: $0.0002 · 9,154 in  / 2,185 out · 1,024 cached (11%) · deepseek-v4-flash

@senamakel
senamakel merged commit 61565e2 into tinyhumansai:main Sep 25, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant