Skip to content

Configure OpenHuman runtimes, profiles, seats and multi-hive deployments - #123

Open
senamakel wants to merge 7 commits into
mainfrom
openhuman-hive-config
Open

senamakel wants to merge 7 commits into
mainfrom
openhuman-hive-config

Conversation

@senamakel

@senamakel senamakel commented Oct 10, 2026 •

Copy link
Copy Markdown
Member

Summary

Replace hand-built OpenHuman seats with a validated manifest and a deployment that constructs one runtime, reusable profiles, continuing seats, and multiple hives. Refresh the vendored embed pin to bc59324d, migrate the three existing examples, and add an offline multi-hive proof where one seat writes in hive A and is refused in hive B without changing its session.

Related issue

Closes #113. Closes #114. Closes #115. Closes #116. Closes #117. Closes #118.

API or behavior changes

  • Add typed JSON/Markdown configuration, strict parsing, referenced secrets, authority narrowing, and deployment/factory/approval/scheduler host ports.
  • Persist per-hive policy and roles; bound turns by hive policy and runtime concurrency. Carry authenticated scheduled origin through direct, private, queued, and recovered turns.
  • Correlate approval release with the exact parked invocation; refuse early or stale release. Concurrent scheduled invocations receive unique message IDs.
  • Add turn_id and optional scheduled origin fields to public turn/storage types. Persisted additions use serde defaults; Rust struct literals must be updated. Add the provided TurnHooks::turn_timeout method and await native cancellation cleanup.
  • The manifest factory accepts its typed manifest schema; portable hive-language seat envelopes and separate memory bindings require a host factory and fail closed here.
  • Native seat cron uses isolated sessions. Unsupported native settings fail before construction. Scheduled effects remain refused; approval answers do not replay effects or create grants. Semantic-routing policy remains a pure view with deterministic fallback when no router is installed.

Validation

Commands actually run, with their outcome:

  • cargo fmt --all -- --check — passed

  • cargo clippy --all-targets --all-features -- -D warnings — passed

  • cargo build --all-targets --all-features — passed

  • cargo test --all-features — passed

  • .github/scripts/assert-pure.sh and .github/scripts/assert-openhuman-pin.sh — passed

  • RUSTDOCFLAGS="-D warnings" cargo doc --no-deps --all-features — passed

  • cargo fmt --manifest-path examples/openhuman/Cargo.toml --all -- --check — passed

  • cargo clippy --manifest-path examples/openhuman/Cargo.toml --all-targets -- -D warnings — passed

  • cargo build --manifest-path examples/openhuman/Cargo.toml --all-targets — passed

  • cargo test --manifest-path examples/openhuman/Cargo.toml — passed: 73 tests, no failures or ignored tests

  • cargo run --manifest-path examples/openhuman/Cargo.toml --bin basic_hive and --bin multi_hive — both offline runs passed

  • cargo llvm-cov --workspace --all-features --json --output-path target/workspace-coverage-final.json — passed; all 28 changed executable library source files exceed 90% line coverage (minimum 92.1%). Standalone executable source coverage was not measured.

These checks ran after merging the latest upstream main, including its hive-language changes.

CI follow-up

The initial CI run found two supply-chain findings and two coverage-short test files. The latest commit adds a package-scoped MIT-0 exception for borrow-or-share 0.2.4, skips only the manifest-level wildcard finding for the revision-pinned tinyflows-sqlite 0.1.0, and changes fixture tests to propagate setup errors. cargo deny check all, strict Clippy, and focused OpenHuman coverage pass locally; both affected test files now exceed 95% coverage. The branch also includes upstream #121, merged during review, with both README topics retained. CI is rerunning on the updated head.

Tests

Regression tests cover strict manifests, independent blind/revealed widths, README exclusion, layered permissions, authenticated MCP/delegate/management effects, continuing sessions, native subprocess cleanup, premature/stale approval release, and overlapping workflow invocation identities. Tests for the four checked-in manifests inspect native lowering as well as metadata. Offline basic and multi-hive runs exercise the actual deployment.

Live provider, real Docker, and operator credential integrations are optional and were not run. Automated pin-refresh scheduling remains the explicit open question; this change refreshes the pin on demand.

Documentation

Accepted behavior and native limits: docs/specs/openhuman-hive-config.md; implementation record: docs/plans/2026-10-10-openhuman-hive-config.md. Update adapter/module documentation, checked-in example manifest documentation, ROADMAP, and the wiki host-integration page. The wiki commit is pushed to its canonical repository on the matching branch and included through the gitlink.

Checklist

  • The change is focused on one logical change
  • No new #[allow(...)], #[ignore], or relaxed lints
  • No secrets, tokens, or .env contents in the diff or the description

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@tinysweeper

tinysweeper Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Tiny Sweeper review

Tiny Sweeper reviewed this change across 5 lane(s) and found 0 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below.

State: Incomplete
Priority: critical
Reviewed head: 93f67468e229
Updated: 2026-10-11T03:33:31Z

Review snapshot

Change surface Files Review signal Count
Production 43 Active findings 1
Tests 48 Noted findings 0
Documentation 61 Resolved findings 0
Configuration 8 Pending checks/questions 7

Completeness: Incomplete
Test assessment: No supported feature-to-test mapping was available; this does not mean tests are absent or passed.

Features

None identified with supported citations.

Tests

No supported feature-to-test mapping was produced. Test execution is not inferred.

  • Unreviewed: tinysweeper/tests

Findings

  • critical · security · Add the referenced full configuration fixture — This `include_str!` requires `crates/tinyhivemind-openhuman/src/config/test/fixtures/full.json`, but that file is absent at this revision. The test module therefore fails to compil (crates/tinyhivemind\-openhuman/src/config/test/mod\.rs:78)

Could not review: crates/tinyhivemind-openhuman/Cargo.toml, crates/tinyhivemind-openhuman/examples/live_language/test.rs, crates/tinyhivemind-openhuman/src/config/test/mod.rs, deny.toml, tinysweeper/description, tinysweeper/tests

Before merge

  • Complete the critique review for crates/tinyhivemind-openhuman/Cargo.toml, crates/tinyhivemind-openhuman/src/config/test/mod.rs, deny.toml.
  • Address Add the referenced full configuration fixture (crates/tinyhivemind\-openhuman/src/config/test/mod\.rs).
  • Complete the security review for crates/tinyhivemind-openhuman/Cargo.toml, crates/tinyhivemind-openhuman/examples/live_language/test.rs.
  • Complete the tests review for tinysweeper/tests.
  • Complete the description review for tinysweeper/description.

How this fits together

flowchart LR
  n0["run_with_mcp_executable"]:::impacted
  n1["run_with_mcp_executable_and_timeout"]:::impacted
  n2["Task"]:::impacted
  n0 -->|calls| n1
  n0 -->|tests| n1
  n0 -->|uses| n2
  n1 -->|uses| n2
  classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
  classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
  classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
  classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Loading
Agent review details

critique

  • Conclusion: Success
  • Scope reviewed: incomplete; unanswered: crates/tinyhivemind-openhuman/Cargo.toml, crates/tinyhivemind-openhuman/src/config/test/mod.rs, deny.toml
  • Lane summary: Reviewed 3 files; 0 findings. 3 files could not be reviewed: crates/tinyhivemind-openhuman/Cargo.toml, crates/tinyhivemind-openhuman/src/config/test/mod.rs, deny.toml. _The code index for this repository is cold, so this review saw the diff alone._ _3 memory call(s) failed (model: cortex: v1/answer: timed out after 20s), so this review saw part of what the engine holds._

security

  • Conclusion: Failure
  • Scope reviewed: incomplete; unanswered: crates/tinyhivemind-openhuman/Cargo.toml, crates/tinyhivemind-openhuman/examples/live_language/test.rs
  • Lane summary: Reviewed 3 files; 1 finding. 2 files could not be reviewed: crates/tinyhivemind-openhuman/Cargo.toml, crates/tinyhivemind-openhuman/examples/live_language/test.rs. 1 file was not security-reviewed: crates/tinyhivemind-openhuman/README.md (prose or tabular data). _The code index for this repository is cold, so this review saw the diff alone._ _3 memory call(s) failed (model: cortex: v1/answer: timed out after 20s), so this review saw part of what the engine holds._
  • Evidence: crates/tinyhivemind\-openhuman/src/config/test/mod\.rs — Add the referenced full configuration fixture

tests

  • Conclusion: Neutral
  • Scope reviewed: incomplete; unanswered: tinysweeper/tests
  • Lane summary: No reviewer could be consulted.

commits

  • Conclusion: Neutral
  • Scope reviewed: all assigned evidence
  • Lane summary: Nothing sensitive found in what this pull request commits.

description

  • Conclusion: Neutral
  • Scope reviewed: incomplete; unanswered: tinysweeper/description
  • Lane summary: No reviewer could be consulted.
Evidence and run details
  • Models: openai/gpt-5.6-luna, , deep, deepseek/deepseek-v4-flash
  • Spend: $0.075947
  • Tokens: 578752 input · 17567 output · 184742 cached · 0 embedding
  • Continuity: summary cache chain restarted at the storage ceiling.
Head State Pass summary
4f4f946405f9 incomplete 0 active finding(s), 0 resolved finding(s) (at 2026-10-10T22:02:59Z)
93f67468e229 incomplete 1 active finding(s), 0 resolved finding(s) (at 2026-10-11T03:33:31Z)

tinysweeper 0.1.0

@coderabbitai

coderabbitai Bot commented Oct 10, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

  • Run on-demand review

This review includes 161 billable files and costs up to $40.25.

View limit details

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 077a838f-c159-4467-9a76-e54b750b6f6f

📥 Commits

Reviewing files that changed from the base of the PR and between bc31f4d and 93f6746.


⛔ Files ignored due to path filters (2)
  • Cargo.lock is excluded by !**/*.lock
  • examples/openhuman/Cargo.lock is excluded by !**/*.lock

📒 Files selected for processing (161)
  • Cargo.toml
  • ROADMAP.md
  • crates/tinyhivemind-core/src/driver/conduct/test/wire.rs
  • crates/tinyhivemind-core/src/driver/conduct/types.rs
  • crates/tinyhivemind-core/src/hive/division/test.rs
  • crates/tinyhivemind-core/src/hive/division/types.rs
  • crates/tinyhivemind-hives/src/README.md
  • crates/tinyhivemind-hives/src/coordinator/README.md
  • crates/tinyhivemind-hives/src/coordinator/conduct.rs
  • crates/tinyhivemind-hives/src/coordinator/conduct/README.md
  • crates/tinyhivemind-hives/src/coordinator/conduct/test.rs
  • crates/tinyhivemind-hives/src/coordinator/messaging.rs
  • crates/tinyhivemind-hives/src/coordinator/mod.rs
  • crates/tinyhivemind-hives/src/coordinator/scheduler.rs
  • crates/tinyhivemind-hives/src/coordinator/settings.rs
  • crates/tinyhivemind-hives/src/coordinator/test/README.md
  • crates/tinyhivemind-hives/src/coordinator/test/mod.rs
  • crates/tinyhivemind-hives/src/coordinator/test/registration.rs
  • crates/tinyhivemind-hives/src/coordinator/test/release.rs
  • crates/tinyhivemind-hives/src/coordinator/test/settings.rs
  • crates/tinyhivemind-hives/src/coordinator/types.rs
  • crates/tinyhivemind-hives/src/storage/README.md
  • crates/tinyhivemind-hives/src/storage/mod.rs
  • crates/tinyhivemind-hives/src/storage/test.rs
  • crates/tinyhivemind-hives/src/storage/types.rs
  • crates/tinyhivemind-openhuman/Cargo.toml
  • crates/tinyhivemind-openhuman/README.md
  • crates/tinyhivemind-openhuman/examples/live_language/test.rs
  • crates/tinyhivemind-openhuman/src/README.md
  • crates/tinyhivemind-openhuman/src/config/README.md
  • crates/tinyhivemind-openhuman/src/config/mod.rs
  • crates/tinyhivemind-openhuman/src/config/parse.rs
  • crates/tinyhivemind-openhuman/src/config/test/README.md
  • crates/tinyhivemind-openhuman/src/config/test/directory.rs
  • crates/tinyhivemind-openhuman/src/config/test/fixtures/README.md
  • crates/tinyhivemind-openhuman/src/config/test/fixtures/full.json
  • crates/tinyhivemind-openhuman/src/config/test/mod.rs
  • crates/tinyhivemind-openhuman/src/config/test/validation.rs
  • crates/tinyhivemind-openhuman/src/config/types.rs
  • crates/tinyhivemind-openhuman/src/config/validate.rs
  • crates/tinyhivemind-openhuman/src/deploy/README.md
  • crates/tinyhivemind-openhuman/src/deploy/compatibility.rs
  • crates/tinyhivemind-openhuman/src/deploy/factory.rs
  • crates/tinyhivemind-openhuman/src/deploy/hooks.rs
  • crates/tinyhivemind-openhuman/src/deploy/memory_root.rs
  • crates/tinyhivemind-openhuman/src/deploy/mod.rs
  • crates/tinyhivemind-openhuman/src/deploy/permission.rs
  • crates/tinyhivemind-openhuman/src/deploy/profile.rs
  • crates/tinyhivemind-openhuman/src/deploy/rules.rs
  • crates/tinyhivemind-openhuman/src/deploy/runtime.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/README.md
  • crates/tinyhivemind-openhuman/src/deploy/test/cancellation.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/construction.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/delegation.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/factory.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/mcp.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/mod.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/permission.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/preflight.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/profile.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/runtime.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/sends.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/support.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/timeout.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/turns.rs
  • crates/tinyhivemind-openhuman/src/deploy/test/workflow.rs
  • crates/tinyhivemind-openhuman/src/deploy/types.rs
  • crates/tinyhivemind-openhuman/src/deploy/workflow.rs
  • crates/tinyhivemind-openhuman/src/error.rs
  • crates/tinyhivemind-openhuman/src/host/README.md
  • crates/tinyhivemind-openhuman/src/host/hooks_test.rs
  • crates/tinyhivemind-openhuman/src/host/memory_test.rs
  • crates/tinyhivemind-openhuman/src/host/mod.rs
  • crates/tinyhivemind-openhuman/src/host/replace_test.rs
  • crates/tinyhivemind-openhuman/src/host/runner.rs
  • crates/tinyhivemind-openhuman/src/host/runner_test.rs
  • crates/tinyhivemind-openhuman/src/host/test.rs
  • crates/tinyhivemind-openhuman/src/host/types.rs
  • crates/tinyhivemind-openhuman/src/host/types_test.rs
  • crates/tinyhivemind-openhuman/src/lib.rs
  • crates/tinyhivemind-openhuman/src/memory/store_test.rs
  • crates/tinyhivemind-openhuman/src/tools/direct_test.rs
  • crates/tinyhivemind-openhuman/src/tools/mod.rs
  • crates/tinyhivemind-openhuman/src/tools/policy_test.rs
  • crates/tinyhivemind-openhuman/src/tools/test.rs
  • deny.toml
  • docs/plans/2026-10-10-openhuman-hive-config.md
  • docs/plans/README.md
  • docs/specs/README.md
  • docs/specs/openhuman-hive-config.md
  • examples/openhuman/Cargo.toml
  • examples/openhuman/README.md
  • examples/openhuman/hives/README.md
  • examples/openhuman/hives/basic_hive/README.md
  • examples/openhuman/hives/basic_hive/context/README.md
  • examples/openhuman/hives/basic_hive/context/release.md
  • examples/openhuman/hives/basic_hive/hive.json
  • examples/openhuman/hives/basic_hive/profiles/README.md
  • examples/openhuman/hives/basic_hive/profiles/alice.md
  • examples/openhuman/hives/basic_hive/profiles/bob.md
  • examples/openhuman/hives/deepswe_hive/README.md
  • examples/openhuman/hives/deepswe_hive/context/README.md
  • examples/openhuman/hives/deepswe_hive/context/protocol.md
  • examples/openhuman/hives/deepswe_hive/hive.json
  • examples/openhuman/hives/deepswe_hive/profiles/README.md
  • examples/openhuman/hives/deepswe_hive/profiles/implementer.md
  • examples/openhuman/hives/deepswe_hive/profiles/lead.md
  • examples/openhuman/hives/deepswe_hive/profiles/reviewer.md
  • examples/openhuman/hives/deepswe_hive/profiles/tester.md
  • examples/openhuman/hives/multi_hive/README.md
  • examples/openhuman/hives/multi_hive/context/README.md
  • examples/openhuman/hives/multi_hive/context/review.md
  • examples/openhuman/hives/multi_hive/hive.json
  • examples/openhuman/hives/multi_hive/profiles/README.md
  • examples/openhuman/hives/multi_hive/profiles/planner.md
  • examples/openhuman/hives/multi_hive/profiles/reviewer.md
  • examples/openhuman/hives/multi_hive/profiles/worker.md
  • examples/openhuman/hives/pe1006_hive/README.md
  • examples/openhuman/hives/pe1006_hive/context/README.md
  • examples/openhuman/hives/pe1006_hive/context/agents.md
  • examples/openhuman/hives/pe1006_hive/context/memory.md
  • examples/openhuman/hives/pe1006_hive/context/research.md
  • examples/openhuman/hives/pe1006_hive/context/sealed.md
  • examples/openhuman/hives/pe1006_hive/context/task.md
  • examples/openhuman/hives/pe1006_hive/hive.json
  • examples/openhuman/hives/pe1006_hive/profiles/README.md
  • examples/openhuman/hives/pe1006_hive/profiles/checker.md
  • examples/openhuman/hives/pe1006_hive/profiles/lead.md
  • examples/openhuman/hives/pe1006_hive/profiles/researcher.md
  • examples/openhuman/hives/pe1006_hive/profiles/solver.md
  • examples/openhuman/hives/pe1006_hive/profiles/theory.md
  • examples/openhuman/src/README.md
  • examples/openhuman/src/bin/README.md
  • examples/openhuman/src/bin/basic_hive.rs
  • examples/openhuman/src/bin/deepswe_hive.rs
  • examples/openhuman/src/bin/deepswe_hive/sandbox.rs
  • examples/openhuman/src/bin/deepswe_hive/test.rs
  • examples/openhuman/src/bin/deepswe_hive/test/README.md
  • examples/openhuman/src/bin/deepswe_hive/test/deadline.rs
  • examples/openhuman/src/bin/deepswe_hive/test/docker.rs
  • examples/openhuman/src/bin/deepswe_hive/test/retry.rs
  • examples/openhuman/src/bin/deepswe_hive/test/retry/README.md
  • examples/openhuman/src/bin/deepswe_hive/test/retry/fail_closed.rs
  • examples/openhuman/src/bin/multi_hive.rs
  • examples/openhuman/src/bin/pe1006_hive.rs
  • examples/openhuman/src/bin/pe1006_hive/README.md
  • examples/openhuman/src/bin/pe1006_hive/round.rs
  • examples/openhuman/src/bin/pe1006_hive/test.rs
  • examples/openhuman/src/bin/pe1006_hive/typesafe.rs
  • examples/openhuman/src/bin/pe1006_hive/workspace.rs
  • examples/openhuman/src/bin/pe1006_hive/workspace_test.rs
  • examples/openhuman/src/lib.rs
  • examples/openhuman/src/proof/README.md
  • examples/openhuman/src/proof/dynamic.rs
  • examples/openhuman/src/proof/fixture.rs
  • examples/openhuman/src/proof/topology.rs
  • examples/openhuman/src/test.rs
  • examples/openhuman/tests/README.md
  • examples/openhuman/tests/manifests.rs
  • vendor/openhuman
  • wiki

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking, but could not review everything, so this is not an approval: Cargo.toml, ROADMAP.md, crates/tinyhivemind-core/src/driver/conduct/test/wire.rs, crates/tinyhivemind-core/src/driver/conduct/types.rs, crates/tinyhivemind-core/src/hive/division/test.rs, crates/tinyhivemind-core/src/hive/division/types.rs, crates/tinyhivemind-hives/src/README.md, crates/tinyhivemind-hives/src/coordinator/README.md and 150 more.

$0.0016 · 194,394 in / 3,946 out · 128 cached (0%) · glm-5.3-flash

senamakel and others added 3 commits October 11, 2026 06:05
Co-authored-by: Medulla <medulla@tinyhumans.ai>
# Conflicts:
#	crates/tinyhivemind-openhuman/README.md
Co-authored-by: Medulla <medulla@tinyhumans.ai>

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

tinysweeper found nothing blocking, but could not review everything, so this is not an approval: crates/tinyhivemind-openhuman/src/config/test/directory.rs, deny.toml, tinysweeper/description, tinysweeper/tests.

          $0.1092 · 893,465 in / 26,137 out · 404,801 cached (45%) · flash, openai/gpt-5.6-luna, deep, , z-ai/glm-5.3-flash
critique: $0.0505 · 192,081 in / 6,778 out  · 19,566 cached (10%)  · openai/gpt-5.6-luna, deep
security: $0.0346 · 135,843 in / 3,897 out  · 13,389 cached (10%)  · openai/gpt-5.6-luna, , deep

tinysweeper[bot]
tinysweeper Bot previously requested changes Oct 11, 2026

@tinysweeper tinysweeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requesting changes: 1 lane(s) blocking, worst finding is critical.

Fix or reply to the findings below and push. The next review clears this automatically once they are gone — you should not need to dismiss anything by hand.

          $0.0759 · 578,752 in / 17,567 out · 184,742 cached (32%) · openai/gpt-5.6-luna, , deep, deepseek/deepseek-v4-flash
critique: $0.0272 · 99,593 in  / 4,420 out  · 9,846 cached (10%)   · openai/gpt-5.6-luna, , deep
security: $0.0281 · 105,961 in / 4,040 out  · 11,078 cached (10%)  · openai/gpt-5.6-luna, , deep

Comment thread crates/tinyhivemind-openhuman/src/config/test/mod.rs
@senamakel
senamakel dismissed tinysweeper[bot]’s stale review October 11, 2026 03:46

The sole finding is a false positive: crates/tinyhivemind-openhuman/src/config/test/fixtures/full.json is committed at the reviewed head and the relative include_str path resolves to it. I replied to the inline thread with git evidence; no code fix is applicable. A re-request was attempted, but GitHub could not resolve the tinysweeper reviewer login. Dismissing only this review after verifying the finding is incorrect.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

1 participant