Skip to content

fix(web3): pin tinywallet v0.7.0 (x402 budget/allowlist/replay/session, BTC fee, chain_status probe, Solana cluster) - #6792

Merged
senamakel merged 7 commits into
tinyhumansai:mainfrom
senamakel:tinywallet-43
Sep 30, 2026
Merged

senamakel merged 7 commits into
tinyhumansai:mainfrom
senamakel:tinywallet-43

Conversation

@senamakel

@senamakel senamakel commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Summary

Problem

Seven bugs moved into tinywallet with #6784, and they were already present in the code OpenHuman had before the move:

  • concurrent x402 payments could overspend the daily or monthly cap;
  • any solana:* or eip155:* network and any asset was payable;
  • a streaming request body was paid for and then re-sent with no body;
  • tool payments carried an empty session_id, so session totals missed them;
  • BTC fees were sized for 1 input and 2 outputs no matter how many UTXOs were spent;
  • chain_status reported Ready without contacting the endpoint;
  • Solana explorer links and network defaults ignored a configured devnet cluster.

Solution

tinywallet v0.7.0 (#44):

  • Budget. The spend is reserved atomically under the ledger lock before signing.
  • Allowlist. Only USDC on known networks is accepted.
  • Streaming bodies. A body that cannot be replayed is refused before anything is paid.
  • Session. session_id is always the ledger session, and a new thread_id field is added (serde(default), so existing ledgers still load).
  • BTC fees. Sized from the actual input and output count, with dust change folded into the fee.
  • chain_status. Probes each endpoint and reports failures with an error field.
  • Solana devnet. Explorer links and network defaults follow the configured cluster.

Host changes:

  • web3/x402/seams.rs: TaskLocalThread reads APPROVAL_CHAT_CONTEXT.thread_id and is wired into request_tool().
  • web3/x402/records.rs: a new pending_record() builds the fallback payment record. tools/impl/network/http_request.rs now uses it instead of writing an empty session_id.
  • web3/wallet/test_support.rs: new UnreachableRpcGuard and a shared RPC env lock, so the seam test and the wallet E2E never reach real RPC endpoints now that chain_status probes. Before this, Polygon answered 401 in the E2E. The mock in tests/json_rpc_e2e.rs now answers every chain's probe.

Submission Checklist

  • Tests added or updated. New host tests:

    • the_thread_scope_reads_the_approval_chat_context_task_local
    • a_fallback_payment_counts_in_the_session_total_and_names_its_thread
    • a_payment_outside_a_chat_turn_has_no_thread_but_the_same_session
    • the updated chain_status seam test

    The crate fixes carry their own red-first tests in tinywallet#44.

  • Diff coverage ≥ 80%. The changed host lines are covered by the tests above.

  • Coverage matrix: N/A. These are behaviour fixes; no feature rows change.

  • Feature IDs: N/A.

  • No new external network dependencies. The wallet tests are now more hermetic than before.

  • Manual smoke checklist: N/A.

  • Linked issue: Follow-ups from #42 review: pre-existing x402 and wallet behaviors tinywallet#43 was closed by tinywallet#44.

Impact

  • Wallet, chain_status: it now performs one cheap RPC per configured endpoint.
    • An unreachable provider shows as missing with an error, instead of ready.
    • ChainStatus.error and explorerTxUrlSuffix are additive, and are omitted when empty.
    • On devnet, the Solana network label reads solana-devnet.
  • x402:
    • Payments on unsupported networks or with non-USDC assets are refused with UnsupportedNetwork or UnsupportedAsset.
    • A streaming body behind a 402 is refused with NonReplayableBody.
    • The spending caps now hold under concurrency.
  • BTC: transactions that spend several UTXOs now pay a fee sized for all of them.

Related


AI Authored PR Metadata (required for Codex/Linear PRs)

Linear Issue

  • Key: N/A
  • URL: N/A

Commit & Branch

  • Branch: tinywallet-43
  • Commit SHA: see the PR head

Validation Run

  • pnpm format:check: passes.
  • pnpm typecheck: passes. app/ is unchanged, and the pre-push hook passed.
  • Focused tests:
    • cargo test -p openhuman --features web3 --lib web3::: 61 passed.
    • --lib http_request: 30 passed.
    • Wallet JSON-RPC E2E: 4 passed. The 5 module-driven --ignored round-trips against v0.7.0 also passed.
    • Every openhuman-cli test target builds with --no-run.
  • Rust fmt and check:
    • cargo fmt --check and pnpm rust:clippy pass.
    • cargo check -p openhuman passes with --features web3 and with --no-default-features.
    • Gated-test allowlist, kernel floor and feature forwarding all pass.
    • check-module-pins passes. check-submodule-monotonic upstream/main passes, with only tinywallet moving forward.
  • Tauri fmt and check: N/A. The shell is unchanged.

Validation Blocked

  • command: pnpm rust:layout
  • error: crates/openhuman-core/src/inference/provider/openhuman_backend_model_tests.rs: 761 lines (limit 750)
  • impact: The file is identical on upstream main, and this PR does not touch inference/.

Behavior Changes

  • Intended behaviour change: the seven bug fixes listed above.
  • User-visible effect:
    • More accurate provider status.
    • Correct BTC fees.
    • x402 caps are enforced.
    • Unsupported x402 assets are refused.
    • Devnet explorer links are correct.

Parity Contract

  • Legacy behavior preserved: RPC namespaces, tool names, and the error strings of unchanged paths. The 1-in/2-out BTC fee vector is unchanged.
  • Guard, fallback and dispatch parity checks: the wallet E2E round-trips and the http_request x402 tests.

Duplicate / Superseded PR Handling

  • Duplicate PR(s): none
  • Canonical PR: this one

Summary by CodeRabbit

  • New Features
    • Wallet chain status now checks each configured network endpoint and reports unavailable connections with an error, while keeping the network listed.
    • Pending x402 payments are tracked with payment details and can be associated with the active chat. In-flight amounts are included in budget totals.
    • Updated the bundled TinyWallet release to v0.7.0.
  • Documentation
    • Clarified wallet connection-status behavior and payment tracking and budget totals.

senamakel and others added 7 commits September 30, 2026 09:02
… seam

Co-authored-by: Medulla <medulla@tinyhumans.ai>
chain_status now contacts each configured chain's endpoint, so the seam test
points every wallet endpoint at a closed loopback port and the JSON-RPC e2e
mocks every chain and covers an unreachable one.

Co-authored-by: Medulla <medulla@tinyhumans.ai>
…llback with the ledger session

Co-authored-by: Medulla <medulla@tinyhumans.ai>
Updated the module record for the tinywallet dependency from version 0.6.0 to 0.7.0, including the corresponding release URL and all platform-specific asset archives with their new SHA-256 checksums.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Update the version of all five tinywallet workspace crates in Cargo.lock to 0.7.0, reflecting the new release of the project.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
Bump the versions of tinywallet-bus, tinywallet-crypto, tinywallet-web3, and tinywallet-x402 to 0.7.0 in the lockfile to reflect the updated dependency specifications.

Auto-committed-on: dragonfly
Co-authored-by: Medulla <medulla@tinyhumans.ai>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 1a031706-0447-40d6-a514-d2b2cbf2d0c1

📥 Commits

Reviewing files that changed from the base of the PR and between eadf6e0 and f0f3ad5.

⛔ Files ignored due to path filters (2)
  • Cargo.lock is excluded by !**/*.lock
  • crates/openhuman-app/Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (15)
  • crates/openhuman-core/src/modules/registry/records_docs_wallet.rs
  • crates/openhuman-core/src/tools/impl/network/http_request.rs
  • crates/openhuman-core/src/web3/seams_tests.rs
  • crates/openhuman-core/src/web3/wallet/README.md
  • crates/openhuman-core/src/web3/wallet/endpoints_tests.rs
  • crates/openhuman-core/src/web3/wallet/schemas.rs
  • crates/openhuman-core/src/web3/wallet/test_support.rs
  • crates/openhuman-core/src/web3/x402/README.md
  • crates/openhuman-core/src/web3/x402/mod.rs
  • crates/openhuman-core/src/web3/x402/records.rs
  • crates/openhuman-core/src/web3/x402/records_tests.rs
  • crates/openhuman-core/src/web3/x402/seams.rs
  • crates/openhuman-core/src/web3/x402/seams_tests.rs
  • tests/json_rpc_e2e.rs
  • vendor/tinywallet

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The changes centralize x402 pending-record creation with ledger-session and optional chat-thread attribution, add wallet RPC endpoint-probe test coverage and supporting test isolation, and update Tinywallet release metadata to v0.7.0.

Changes

X402 Pending Records

Layer / File(s) Summary
Resolve chat thread context
crates/openhuman-core/src/web3/x402/seams.rs, crates/openhuman-core/src/web3/x402/seams_tests.rs
TaskLocalThread reads the thread ID from APPROVAL_CHAT_CONTEXT and is attached to the x402 request tool. Tests cover missing context and nested scopes.
Create and use pending records
crates/openhuman-core/src/web3/x402/records.rs, crates/openhuman-core/src/web3/x402/mod.rs, crates/openhuman-core/src/tools/impl/network/http_request.rs, crates/openhuman-core/src/web3/x402/records_tests.rs, crates/openhuman-core/src/web3/x402/README.md
pending_record creates records with payment details, a ledger session ID, and an optional chat thread ID. The HTTP request tool uses it. Tests cover record fields and ledger summaries; the README describes record attribution and ledger totals.

Wallet Endpoint Probe Tests

Layer / File(s) Summary
Isolate RPC endpoint test settings
crates/openhuman-core/src/web3/wallet/test_support.rs, crates/openhuman-core/src/web3/wallet/endpoints_tests.rs, crates/openhuman-core/src/web3/seams_tests.rs
Shared test support serializes endpoint overrides and restores prior environment variables. Wallet tests use the shared lock and can point all configured endpoints at unreachable loopback addresses.
Document and test chain probe results
crates/openhuman-core/src/web3/wallet/schemas.rs, crates/openhuman-core/src/web3/wallet/README.md, tests/json_rpc_e2e.rs
The schema and README describe chain-tip probes and their result fields. The end-to-end mock supplies probe responses and checks ready and missing statuses.

Tinywallet Release Metadata

Layer / File(s) Summary
Update Tinywallet release references
crates/openhuman-core/src/modules/registry/records_docs_wallet.rs, vendor/tinywallet
The registry entries now reference Tinywallet v0.7.0 archives and digests. The vendored subproject reference points to a new commit.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant HttpRequestTool
  participant pending_record
  participant TaskLocalThread
  participant APPROVAL_CHAT_CONTEXT
  HttpRequestTool->>pending_record: payment_result
  pending_record->>TaskLocalThread: request current thread
  TaskLocalThread->>APPROVAL_CHAT_CONTEXT: read scoped thread ID
  APPROVAL_CHAT_CONTEXT-->>TaskLocalThread: thread ID or no context
  TaskLocalThread-->>pending_record: optional thread ID
Loading

Suggested reviewers: m3ga-mind

Merge Risk: ⚪ Minimal · up to f0f3a

The changes improve payment attribution and wallet probe coverage while updating Tinywallet to v0.7.0. No actionable merge-blocking issue remains; merge after normal checks.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to f0f3a

Payment attribution improves without an observed expansion of payment authority. However, the updated wallet’s budget, cancellation, recovery and ledger-compatibility guarantees, and its published release checksums, could not be independently confirmed.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — An allowed remote destination can supply payment requirements through an HTTP 402 response and engage the configured wallet signing path when web3 is enabled. The relevant exposure includes wallet funds and ledger accounting. The available host changes do not establish broader tenant or environment authority; vendor-side limits on payable requirements remain unverified.

Trust Boundaries and Controls

  • observed — The HTTP entrypoint checks action permission, rate limits and LocalOnly policy before outbound execution, and delegates URL validation to the allowed-domain and DNS-checking helper. Requests disable redirects and replay an owned string body. The new thread attribution reads existing task-local context rather than accepting a payment-supplied session identity; it does not itself grant signing authority.

Resilience and Maintainability Implications

  • observed — The existing fallback ignores ledger-write errors, returns before updating status when the retry encounters a transport error, and searches only the latest 100 payments for its final update. These host paths are outside the attribution replacement and are not established as newly introduced concerns. Whether they interact safely with the new reservation lifecycle, cancellation and recovery remains unresolved without vendor source.

Hardening Proposals

  • proposed — Before relying on the new payment guarantees, verify the pinned implementation’s reservation completion, interrupted-payment recovery and old-ledger compatibility, and reconcile the 11 configured digests with trusted published release bytes. This is a validation proposal, not an observed vulnerability.
🚥 Pre-merge checks | ✅ 4 | ❓ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ❓ Inconclusive Docstring coverage is 47.62% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 21 functions across 11 files. (4 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the primary change, pinning tinywallet to v0.7.0, and accurately lists the related web3 and x402 fixes. It is detailed but remains specific and relevant.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 47.62% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 21 functions across 11 files. (4 skipped: 3 unsupported, 1 too large.)


A rabbit checks the ledger light,
And threads a chat ID just right.
The wallet probes each chain anew,
While Tinywallet’s release grew.
Three carrots hop beside the code,
Then back to burrow down the road.

Comment @coderabbitai help to get the list of available commands.

@senamakel
senamakel merged commit cf5e7c2 into tinyhumansai:main Sep 30, 2026
31 of 33 checks passed
@tinysweeper

tinysweeper Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper reviewed this change across 6 lane(s) and found 3 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below.

State: Incomplete
Priority: medium
Reviewed head: f0f3ad54fe47
Updated: 1790753405 (Unix time)

Review snapshot

Change surface Files Review signal Count
Production 6 Active findings 3
Tests 6 Noted findings 0
Documentation 2 Resolved findings 0
Configuration 0 Pending checks/questions 30

Completeness: Incomplete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

What changed

The review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below.

Features

None identified with supported citations.

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

Findings

  • medium · tests · Exercise the pinned TinyWallet release end to end — The registry record for tinywallet was bumped from 0.6.0 to 0.7.0, changing every platform archive name and SHA-256 digest. No test in this change downloads, verifies, loads, or ex (crates/openhuman\-core/src/modules/registry/records\_docs\_wallet\.rs:111)
  • medium · description · Exercise the pinned TinyWallet v0.7.0 release end to end — This changes the runtime-downloaded TinyWallet release, archive names, and every platform checksum, but no test loads the registry-selected `0.7.0` artifact and exercises its contr (\(pull request description\))
  • medium · e2e · End-to-end job `Rust Feature-Gate Smoke (gates off)` will not run on this change — `Rust Feature-Gate Smoke (gates off)` in `.github/workflows/ci-lite.yml` will not run for this pull request: the forge reports it as skipped, so a job condition was false for this (\.github/workflows/ci\-lite\.yml)

Pending checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)

Could not review: crates/openhuman-core/src/modules/registry/records_docs_wallet.rs, crates/openhuman-core/src/tools/impl/network/http_request.rs, crates/openhuman-core/src/web3/seams_tests.rs, crates/openhuman-core/src/web3/wallet/README.md, crates/openhuman-core/src/web3/wallet/endpoints_tests.rs, crates/openhuman-core/src/web3/wallet/schemas.rs, crates/openhuman-core/src/web3/wallet/test_support.rs, crates/openhuman-core/src/web3/x402/README.md, crates/openhuman-core/src/web3/x402/mod.rs, crates/openhuman-core/src/web3/x402/records.rs, crates/openhuman-core/src/web3/x402/records_tests.rs, crates/openhuman-core/src/web3/x402/seams.rs, crates/openhuman-core/src/web3/x402/seams_tests.rs, tests/json_rpc_e2e.rs

Before merge

  • Complete the critique review for crates/openhuman-core/src/modules/registry/records_docs_wallet.rs, crates/openhuman-core/src/tools/impl/network/http_request.rs, crates/openhuman-core/src/web3/seams_tests.rs, crates/openhuman-core/src/web3/wallet/README.md, crates/openhuman-core/src/web3/wallet/endpoints_tests.rs, crates/openhuman-core/src/web3/wallet/schemas.rs, crates/openhuman-core/src/web3/wallet/test_support.rs, crates/openhuman-core/src/web3/x402/README.md, crates/openhuman-core/src/web3/x402/mod.rs, crates/openhuman-core/src/web3/x402/records.rs, crates/openhuman-core/src/web3/x402/records_tests.rs, crates/openhuman-core/src/web3/x402/seams.rs, crates/openhuman-core/src/web3/x402/seams_tests.rs, tests/json_rpc_e2e.rs.
  • Complete the security review for crates/openhuman-core/src/web3/x402/records.rs, crates/openhuman-core/src/web3/x402/records_tests.rs, crates/openhuman-core/src/modules/registry/records_docs_wallet.rs, crates/openhuman-core/src/tools/impl/network/http_request.rs, crates/openhuman-core/src/web3/seams_tests.rs, crates/openhuman-core/src/web3/wallet/endpoints_tests.rs, crates/openhuman-core/src/web3/wallet/schemas.rs, crates/openhuman-core/src/web3/x402/mod.rs, crates/openhuman-core/src/web3/x402/seams.rs, crates/openhuman-core/src/web3/x402/seams_tests.rs, crates/openhuman-core/src/web3/wallet/test_support.rs, tests/json_rpc_e2e.rs.
  • Wait for Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS).

How this fits together

flowchart LR
  n0["WorkspaceEnvGuard<br/>changed"]:::changed
  n1["setup_wallet_in"]:::impacted
  n2["setup"]:::impacted
  n3["set_workspace_env_for_test"]:::impacted
  n1 -->|uses| n0
  n1 -->|calls| n2
  n1 -->|tests| n2
  n1 -->|calls| n3
  n3 -->|uses| n0
  classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
  classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
  classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
  classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Loading
Agent review details

critique

  • Conclusion: Neutral
  • Scope reviewed: incomplete; unanswered: crates/openhuman-core/src/modules/registry/records_docs_wallet.rs, crates/openhuman-core/src/tools/impl/network/http_request.rs, crates/openhuman-core/src/web3/seams_tests.rs, crates/openhuman-core/src/web3/wallet/README.md, crates/openhuman-core/src/web3/wallet/endpoints_tests.rs, crates/openhuman-core/src/web3/wallet/schemas.rs, crates/openhuman-core/src/web3/wallet/test_support.rs, crates/openhuman-core/src/web3/x402/README.md, crates/openhuman-core/src/web3/x402/mod.rs, crates/openhuman-core/src/web3/x402/records.rs, crates/openhuman-core/src/web3/x402/records_tests.rs, crates/openhuman-core/src/web3/x402/seams.rs, crates/openhuman-core/src/web3/x402/seams_tests.rs, tests/json_rpc_e2e.rs
  • Lane summary: Reviewed 0 files; 0 findings. 14 files could not be reviewed: crates/openhuman-core/src/modules/registry/records_docs_wallet.rs, crates/openhuman-core/src/tools/impl/network/http_request.rs, crates/openhuman-core/src/web3/seams_tests.rs, crates/openhuman-core/src/web3/wallet/README.md, crates/openhuman-core/src/web3/wallet/endpoints_tests.rs, crates/openhuman-core/src/web3/wallet/schemas.rs, crates/openhuman-core/src/web3/wallet/test_support.rs, crates/openhuman-core/src/web3/x402/README.md, crates/openhuman-core/src/web3/x402/mod.rs, crates/openhuman-core/src/web3/x402/records.rs, crates/openhuman-core/src/web3/x402/records_tests.rs, crates/openhuman-core/src/web3/x402/seams.rs, crates/openhuman-core/src/web3/x402/seams_tests.rs, tests/json_rpc_e2e.rs.

security

  • Conclusion: Neutral
  • Scope reviewed: incomplete; unanswered: crates/openhuman-core/src/web3/x402/records.rs, crates/openhuman-core/src/web3/x402/records_tests.rs, crates/openhuman-core/src/modules/registry/records_docs_wallet.rs, crates/openhuman-core/src/tools/impl/network/http_request.rs, crates/openhuman-core/src/web3/seams_tests.rs, crates/openhuman-core/src/web3/wallet/endpoints_tests.rs, crates/openhuman-core/src/web3/wallet/schemas.rs, crates/openhuman-core/src/web3/x402/mod.rs, crates/openhuman-core/src/web3/x402/seams.rs, crates/openhuman-core/src/web3/x402/seams_tests.rs, crates/openhuman-core/src/web3/wallet/test_support.rs, tests/json_rpc_e2e.rs
  • Lane summary: Reviewed 0 files; 0 findings. 12 files could not be reviewed: crates/openhuman-core/src/web3/x402/records.rs, crates/openhuman-core/src/web3/x402/records_tests.rs, crates/openhuman-core/src/modules/registry/records_docs_wallet.rs, crates/openhuman-core/src/tools/impl/network/http_request.rs, crates/openhuman-core/src/web3/seams_tests.rs, crates/openhuman-core/src/web3/wallet/endpoints_tests.rs, crates/openhuman-core/src/web3/wallet/schemas.rs, crates/openhuman-core/src/web3/x402/mod.rs, crates/openhuman-core/src/web3/x402/seams.rs, crates/openhuman-core/src/web3/x402/seams_tests.rs, crates/openhuman-core/src/web3/wallet/test_support.rs, tests/json_rpc_e2e.rs. 2 files were not security-reviewed: crates/openhuman-core/src/web3/wallet/README.md (prose or tabular data), crates/openhuman-core/src/web3/x402/README.md (prose or tabular data).

tests

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: Updates the tinywallet module to v0.7.0, centralizes payment record creation for the HTTP tool fallback, adds chain-status probe assertions to the e2e test, and adds thread-attribution for x402 payments. The tests added for the new records function and the thread scope are sound and pin the new behaviour. However, the module version bump has no integration test that exercises the new release, which has been flagged repeatedly in earlier reviews. _The code index is behind this pull request (indexed at `a65c48a3ec18`), so retrieved context may be out of date._ _4 memory call(s) failed (model: cortex: v1/recall: timed out after 10s), so this review saw part of what the engine holds._
  • Evidence: crates/openhuman\-core/src/modules/registry/records\_docs\_wallet\.rs — Exercise the pinned TinyWallet release end to end

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Success
  • Scope reviewed: all assigned evidence
  • Lane summary: This pull request pins tinywallet to v0.7.0 and adds host-side fixes for x402 budget, allowlist, replay, session tracking, BTC fees, chain_status probing, and Solana devnet support. The diff looks correct in structure, but it repeats a known gap: no test resolves the registry record, downloads the v0.7.0 artifact, loads it, and exercises the module contract. This was flagged in multiple earlier cycles for the same module and remains unaddressed. _The code index is behind this pull request (indexed at `a65c48a3ec18`), so retrieved context may be out of date._ _4 memory call(s) failed (model: cortex: v1/recall: timed out after 10s), so this review saw part of what the engine holds._
  • Evidence: \(pull request description\) — Exercise the pinned TinyWallet v0.7.0 release end to end

e2e

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: This change bumps the tinywallet module to v0.7.0, adds a `chain_status` probe that distinguishes reachable from unreachable endpoints, and stamps x402 payments with the ledger's session and chat thread. The end-to-end test in `tests/json_rpc_e2e.rs` exercises the `chain_status` probe (ready and unreachable paths), the updated wallet endpoints, and a Solana `getHealth` mock. The TinyWallet registry bump is not exercised end to end — no test downloads, loads, or calls the pinned artifact — which is a pattern that has been flagged on earlier revisions. (1 finding discarded for not matching a changed line) Waiting on end-to-end jobs: `Rust E2E (mock backend)`, `Build Playwright E2E Artifact`, `E2E (Playwright / web lane)`, `Desktop E2E (full suite, 3 OS)`.
  • Unresolved questions/checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS)
  • Evidence: \.github/workflows/ci\-lite\.yml — End-to-end job `Rust Feature-Gate Smoke (gates off)` will not run on this change
Evidence and run details
  • Models: flash, ladder/vectors, deepseek/deepseek-v4-flash
  • Spend: $0.010576
  • Tokens: 101269 input · 13455 output · 9984 cached · 1305 embedding
Head State Pass summary
f0f3ad54fe47 incomplete 3 active finding(s), 0 resolved finding(s) (at 1790753405)

tinysweeper 0.1.0

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking, but could not review everything, so this is not an approval: crates/openhuman-core/src/modules/registry/records_docs_wallet.rs, crates/openhuman-core/src/tools/impl/network/http_request.rs, crates/openhuman-core/src/web3/seams_tests.rs, crates/openhuman-core/src/web3/wallet/README.md, crates/openhuman-core/src/web3/wallet/endpoints_tests.rs, crates/openhuman-core/src/web3/wallet/schemas.rs, crates/openhuman-core/src/web3/wallet/test_support.rs, crates/openhuman-core/src/web3/x402/README.md and 6 more.

             $0.0106 · 101,269 in / 13,455 out · 9,984 cached (10%) · flash, ladder/vectors, deepseek/deepseek-v4-flash · 1,305 embedded
tests:       $0.0030 · 26,573 in  / 3,331 out  · 0 cached (0%)      · deepseek/deepseek-v4-flash
description: $0.0024 · 18,793 in  / 3,967 out  · 0 cached (0%)      · deepseek/deepseek-v4-flash
e2e:         $0.0026 · 30,684 in  / 371 out    · 0 cached (0%)      · deepseek/deepseek-v4-flash

object_path: "/ai/tinyhumans/tinywallet/Wallet",
version: "0.6.0",
release_url: "https://github.com/tinyhumansai/tinywallet/releases/tag/v0.6.0",
version: "0.7.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority medium tests confident

Exercise the pinned TinyWallet release end to end

The registry record for tinywallet was bumped from 0.6.0 to 0.7.0, changing every platform archive name and SHA-256 digest. No test in this change downloads, verifies, loads, or exercises the new module artifact. A wrong release asset, checksum, or ABI will therefore remain undetected until wallet functionality is used. Add a regression or E2E test that resolves this record, downloads and verifies the selected asset, loads it, and performs a representative wallet call without exposing real credentials.

[RULE] missing-release-integration-test ·

@tinysweeper tinysweeper Bot added the priority: p2 Soon. Real but survivable — a rough edge, a gap, a thing that will bite later. label Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

priority: p2 Soon. Real but survivable — a rough edge, a gap, a thing that will bite later.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant