fix(web3): pin tinywallet v0.7.0 (x402 budget/allowlist/replay/session, BTC fee, chain_status probe, Solana cluster) - #6792
Conversation
… seam Co-authored-by: Medulla <medulla@tinyhumans.ai>
chain_status now contacts each configured chain's endpoint, so the seam test points every wallet endpoint at a closed loopback port and the JSON-RPC e2e mocks every chain and covers an unreachable one. Co-authored-by: Medulla <medulla@tinyhumans.ai>
…llback with the ledger session Co-authored-by: Medulla <medulla@tinyhumans.ai>
Updated the module record for the tinywallet dependency from version 0.6.0 to 0.7.0, including the corresponding release URL and all platform-specific asset archives with their new SHA-256 checksums. Auto-committed-on: dragonfly Co-authored-by: Medulla <medulla@tinyhumans.ai>
Update the version of all five tinywallet workspace crates in Cargo.lock to 0.7.0, reflecting the new release of the project. Auto-committed-on: dragonfly Co-authored-by: Medulla <medulla@tinyhumans.ai>
Bump the versions of tinywallet-bus, tinywallet-crypto, tinywallet-web3, and tinywallet-x402 to 0.7.0 in the lockfile to reflect the updated dependency specifications. Auto-committed-on: dragonfly Co-authored-by: Medulla <medulla@tinyhumans.ai>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (15)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review. 📝 WalkthroughWalkthroughThe changes centralize x402 pending-record creation with ledger-session and optional chat-thread attribution, add wallet RPC endpoint-probe test coverage and supporting test isolation, and update Tinywallet release metadata to v0.7.0. ChangesX402 Pending Records
Wallet Endpoint Probe Tests
Tinywallet Release Metadata
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant HttpRequestTool
participant pending_record
participant TaskLocalThread
participant APPROVAL_CHAT_CONTEXT
HttpRequestTool->>pending_record: payment_result
pending_record->>TaskLocalThread: request current thread
TaskLocalThread->>APPROVAL_CHAT_CONTEXT: read scoped thread ID
APPROVAL_CHAT_CONTEXT-->>TaskLocalThread: thread ID or no context
TaskLocalThread-->>pending_record: optional thread ID
Suggested reviewers: Merge Risk: ⚪ Minimal · up to The changes improve payment attribution and wallet probe coverage while updating Tinywallet to v0.7.0. No actionable merge-blocking issue remains; merge after normal checks. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Payment attribution improves without an observed expansion of payment authority. However, the updated wallet’s budget, cancellation, recovery and ledger-compatibility guarantees, and its published release checksums, could not be independently confirmed. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❓ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 47.62% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 21 functions across 11 files. (4 skipped: 3 unsupported, 1 too large.) A rabbit checks the ledger light, Comment |
Tiny Sweeper reviewTiny Sweeper reviewed this change across 6 lane(s) and found 3 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below. State: Incomplete Review snapshot
Completeness: Incomplete What changedThe review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below. FeaturesNone identified with supported citations. TestsNo supported feature-to-test mapping was produced. Test execution is not inferred. Findings
Pending checks: Rust E2E (mock backend), Build Playwright E2E Artifact, E2E (Playwright / web lane), Desktop E2E (full suite, 3 OS) Could not review: crates/openhuman-core/src/modules/registry/records_docs_wallet.rs, crates/openhuman-core/src/tools/impl/network/http_request.rs, crates/openhuman-core/src/web3/seams_tests.rs, crates/openhuman-core/src/web3/wallet/README.md, crates/openhuman-core/src/web3/wallet/endpoints_tests.rs, crates/openhuman-core/src/web3/wallet/schemas.rs, crates/openhuman-core/src/web3/wallet/test_support.rs, crates/openhuman-core/src/web3/x402/README.md, crates/openhuman-core/src/web3/x402/mod.rs, crates/openhuman-core/src/web3/x402/records.rs, crates/openhuman-core/src/web3/x402/records_tests.rs, crates/openhuman-core/src/web3/x402/seams.rs, crates/openhuman-core/src/web3/x402/seams_tests.rs, tests/json_rpc_e2e.rs Before merge
How this fits togetherflowchart LR
n0["WorkspaceEnvGuard<br/>changed"]:::changed
n1["setup_wallet_in"]:::impacted
n2["setup"]:::impacted
n3["set_workspace_env_for_test"]:::impacted
n1 -->|uses| n0
n1 -->|calls| n2
n1 -->|tests| n2
n1 -->|calls| n3
n3 -->|uses| n0
classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
There was a problem hiding this comment.
tinysweeper found nothing blocking, but could not review everything, so this is not an approval: crates/openhuman-core/src/modules/registry/records_docs_wallet.rs, crates/openhuman-core/src/tools/impl/network/http_request.rs, crates/openhuman-core/src/web3/seams_tests.rs, crates/openhuman-core/src/web3/wallet/README.md, crates/openhuman-core/src/web3/wallet/endpoints_tests.rs, crates/openhuman-core/src/web3/wallet/schemas.rs, crates/openhuman-core/src/web3/wallet/test_support.rs, crates/openhuman-core/src/web3/x402/README.md and 6 more.
$0.0106 · 101,269 in / 13,455 out · 9,984 cached (10%) · flash, ladder/vectors, deepseek/deepseek-v4-flash · 1,305 embedded
tests: $0.0030 · 26,573 in / 3,331 out · 0 cached (0%) · deepseek/deepseek-v4-flash
description: $0.0024 · 18,793 in / 3,967 out · 0 cached (0%) · deepseek/deepseek-v4-flash
e2e: $0.0026 · 30,684 in / 371 out · 0 cached (0%) · deepseek/deepseek-v4-flash
| object_path: "/ai/tinyhumans/tinywallet/Wallet", | ||
| version: "0.6.0", | ||
| release_url: "https://github.com/tinyhumansai/tinywallet/releases/tag/v0.6.0", | ||
| version: "0.7.0", |
There was a problem hiding this comment.
Exercise the pinned TinyWallet release end to end
The registry record for tinywallet was bumped from 0.6.0 to 0.7.0, changing every platform archive name and SHA-256 digest. No test in this change downloads, verifies, loads, or exercises the new module artifact. A wrong release asset, checksum, or ABI will therefore remain undetected until wallet functionality is used. Add a regression or E2E test that resolves this record, downloads and verifies the selected asset, loads it, and performs a representative wallet call without exposing real credentials.
[RULE] missing-release-integration-test ·
Summary
vendor/tinywalletto v0.7.0 and re-pins thetinywalletregistry record: the version, the release URL, and all 11 archive digests, copied verbatim from the release'schecksum.toml.ThreadScopeimplementation that attributes x402 payments to the chat thread, correct session stamping in thehttp_requestx402 fallback, and hermetic tests for the newchain_statusendpoint probe.Problem
Seven bugs moved into tinywallet with #6784, and they were already present in the code OpenHuman had before the move:
solana:*oreip155:*network and any asset was payable;session_id, so session totals missed them;chain_statusreported Ready without contacting the endpoint;Solution
tinywallet v0.7.0 (#44):
session_idis always the ledger session, and a newthread_idfield is added (serde(default), so existing ledgers still load).chain_status. Probes each endpoint and reports failures with anerrorfield.Host changes:
web3/x402/seams.rs:TaskLocalThreadreadsAPPROVAL_CHAT_CONTEXT.thread_idand is wired intorequest_tool().web3/x402/records.rs: a newpending_record()builds the fallback payment record.tools/impl/network/http_request.rsnow uses it instead of writing an emptysession_id.web3/wallet/test_support.rs: newUnreachableRpcGuardand a shared RPC env lock, so the seam test and the wallet E2E never reach real RPC endpoints now thatchain_statusprobes. Before this, Polygon answered 401 in the E2E. The mock intests/json_rpc_e2e.rsnow answers every chain's probe.Submission Checklist
Tests added or updated. New host tests:
the_thread_scope_reads_the_approval_chat_context_task_locala_fallback_payment_counts_in_the_session_total_and_names_its_threada_payment_outside_a_chat_turn_has_no_thread_but_the_same_sessionchain_statusseam testThe crate fixes carry their own red-first tests in tinywallet#44.
Diff coverage ≥ 80%. The changed host lines are covered by the tests above.
Coverage matrix: N/A. These are behaviour fixes; no feature rows change.
Feature IDs: N/A.
No new external network dependencies. The wallet tests are now more hermetic than before.
Manual smoke checklist: N/A.
Linked issue: Follow-ups from #42 review: pre-existing x402 and wallet behaviors tinywallet#43 was closed by tinywallet#44.
Impact
chain_status: it now performs one cheap RPC per configured endpoint.missingwith anerror, instead ofready.ChainStatus.errorandexplorerTxUrlSuffixare additive, and are omitted when empty.solana-devnet.UnsupportedNetworkorUnsupportedAsset.NonReplayableBody.Related
AI Authored PR Metadata (required for Codex/Linear PRs)
Linear Issue
Commit & Branch
tinywallet-43Validation Run
pnpm format:check: passes.pnpm typecheck: passes.app/is unchanged, and the pre-push hook passed.cargo test -p openhuman --features web3 --lib web3::: 61 passed.--lib http_request: 30 passed.--ignoredround-trips against v0.7.0 also passed.openhuman-clitest target builds with--no-run.cargo fmt --checkandpnpm rust:clippypass.cargo check -p openhumanpasses with--features web3and with--no-default-features.check-module-pinspasses.check-submodule-monotonic upstream/mainpasses, with onlytinywalletmoving forward.Validation Blocked
command:pnpm rust:layouterror:crates/openhuman-core/src/inference/provider/openhuman_backend_model_tests.rs: 761 lines (limit 750)impact:The file is identical on upstreammain, and this PR does not touchinference/.Behavior Changes
Parity Contract
http_requestx402 tests.Duplicate / Superseded PR Handling
Summary by CodeRabbit