Repository navigation
refactor(safety): delegate store::safety to the shared tinymemory-safety crate - #178
Conversation
…ety crate The scrubbers moved to tinymemory-safety (tinymemory w4-memory-rest), which the OpenHuman host and tinymemory-core share. store::safety keeps its public paths and pins the engine policy (corroborated bare-card gate, unchanged behaviour). Co-authored-by: Medulla <medulla@tinyhumans.ai>
Tiny Sweeper reviewTiny Sweeper reviewed this change across 6 lane(s) and found 0 active actionable finding(s). Detailed lane evidence and any incomplete work are listed below. State: Incomplete Review snapshot
Completeness: Incomplete What changedThe review could not produce a supported behavioral summary; inspect the cited changed surface and lane details below. FeaturesNone identified with supported citations. TestsNo supported feature-to-test mapping was produced. Test execution is not inferred.
FindingsNo active actionable findings. Could not review: src/memory/store/safety/mod.rs, src/memory/store/safety/safety_tests.rs, tinysweeper/description, tinysweeper/e2e, tinysweeper/tests Before merge
How this fits togetherflowchart LR
n0["sanitize_text"]:::impacted
n1["has_goal_pii"]:::impacted
n2["set_global"]:::impacted
n3["set_namespace"]:::impacted
n4["pii"]:::impacted
n5["redact_pii"]:::impacted
n1 -->|calls| n0
n2 -->|uses| n4
n2 -->|calls| n5
n3 -->|uses| n4
n3 -->|calls| n5
n5 -->|uses| n4
classDef changed fill:#0d4429,stroke:#238636,color:#e6edf3
classDef impacted fill:#161b22,stroke:#6e7681,color:#c9d1d9
classDef flagged fill:#5a1e02,stroke:#d93f0b,color:#ffffff
classDef blocking fill:#67060c,stroke:#f85149,color:#ffffff
Agent review detailscritique
security
tests
commits
description
e2e
Evidence and run details
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughThe engine adds the pinned ChangesShared safety integration
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Refactor Merge Risk: ⚪ Minimal · up to No actionable merge-blocking defect was identified. The shared safety integration appears mergeable subject to normal checks, though dependency behavior was not independently verified. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The wrappers retain a fixed policy and sanitize before storage or evidence construction. No introduced security regression was established, but the shared library’s exact behavior could not be independently compared with the replaced implementation. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
A rabbit checks the digits in a row, Comment |
There was a problem hiding this comment.
tinysweeper found nothing blocking, but could not review everything, so this is not an approval: Cargo.toml, src/memory/store/safety/mod.rs, src/memory/store/safety/safety_tests.rs, tinysweeper/description, tinysweeper/e2e, tinysweeper/tests.
$0.0000 · 0 in / 0 out · 1,184 embedded · ladder/vectors
The documentation comment for the write-rejection boundary now uses the full module path `pii::has_likely_pii` instead of the bare function name, making the cross-reference unambiguous when the module is not imported at the call site. Auto-committed-on: dragonfly
The doc comment for the safety module now links to `has_likely_pii` using its full module path instead of a relative reference, ensuring the link resolves correctly in generated documentation. Auto-committed-on: dragonfly
There was a problem hiding this comment.
tinysweeper found nothing blocking, but could not review everything, so this is not an approval: src/memory/store/safety/mod.rs, src/memory/store/safety/safety_tests.rs, tinysweeper/description, tinysweeper/e2e, tinysweeper/tests.
$0.0000 · 0 in / 0 out · 1,184 embedded · ladder/vectors
Summary
memory::store::safety(secret and PII scrubbing, ~1.5k lines with tests) moves to the new sharedtinymemory-safetycrate intinyhumansai/tinymemory(tinyhumansai/tinymemory#174, branchw4-memory-rest). TinyCortex keeps its publicsafety::*paths and pins its one policy choice.safety::{has_likely_pii, has_likely_secret, has_likely_email, SanitizationReport, Sanitized}are re-exports.sanitize_text,sanitize_jsonandpii::redact_piiare thin wrappers that passPolicy::corroborated(), so behaviour is unchanged: a bare Luhn-valid digit run is only redacted as a card when it has a real network IIN or a nearby card keyword (opencompany#1201).tinymemory-safety, by git rev liketinymemory-api([patch."https://github.com/tinyhumansai/tinymemory"]in a host that vendors it).Order
Stacks on tinymemory#174 (
w4-memory-rest): the git rev inCargo.tomlnames a commit that adds the crate. Merge the tinymemory PR first, then re-point the rev at the merged commit if the squash changes it.Testing
cargo fmt --all -- --check,cargo clippy --all-targets -- -D warnings,cargo test: 1203 lib tests pass (3 new pin the engine policy and the re-exports).Summary by CodeRabbit