Skip to content

Supervise extension hosts and add a tested authoring workflow - #6735

Merged
Hmbown merged 9 commits into
mainfrom
fix/ts-extension-host-phase2a
Sep 29, 2026
Merged

Hmbown merged 9 commits into
mainfrom
fix/ts-extension-host-phase2a

Conversation

@Hmbown

@Hmbown Hmbown commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Summary

Recover a reviewed extension after a host crash without replaying interrupted calls or losing the shared crash budget. The existing manager now supervises heartbeats, retires a persistently hung process, and replays only still-authorized owners with fresh tokens and handles. Three crashes within five minutes stop automatic recovery; opening another engine cannot reset that budget. Explicit plugin changes retry deliberately, and launch failures also permit a new attachment to retry after cooldown.

Two dirty teardowns within ten minutes request maintenance after active calls finish. Admission closes atomically before retirement; maintenance preserves the crash budget, and failed-activation cleanup shares the same accounting. Ordinary process exit also closes admission under the pending-call lock before failed calls are notified; a reentrant request is rejected immediately. Stale callbacks cannot mutate new owners, and failed/faulted receipts remain suppressed until explicit retry or changed authority.

The authoring path now accepts reviewed regular .mts entries through the existing staged-byte and receipt checks. /plugin show displays typed owner state, live tools and up to 20 retained plugin-attributed diagnostics from the existing bounded 64-entry shared ring. Plugin-controlled text is escaped, and report labels and states are translated in all 15 complete locale packs. Name refusals suggest a plugin-specific prefix without relaxing restrictions. The guide and executable hello.mts example use the real host; plugin-creator generation 17 preserves the exact previous generation and custom installed bodies. The agent stops after install, validate and show; a person reviews, trusts and enables.

The experimental feature remains off by default. Approval, receipt and sandbox boundaries remain in place.

Validation

  • Production TUI library check passed with locked dependencies and warnings denied.
  • Authoring checkpoint668c90: 56 focused Rust tests passed, 0 failed, 0 ignored. Real Node fixtures were required and ran, including crash/hang recovery, dirty retirement, pending-call behavior, receipt/approval boundaries, attributed diagnostics, the reviewed typed author example, and skill migration.
  • Final exit/admission follow-up: 38 focused Rust tests passed, 0 failed, 0 ignored, with actual Node required. This includes the deterministic failed-call-waker regression and existing host recovery, retirement, replay and ownership coverage. A fresh production check, npm640 and check:web also passed.
  • Forward-merged Phase1 resume-receipt repair: its Engine1/0 and originalPTY1/0 across five terminal sizes passed before the merge; the Engine regression also passes in the final38-test follow-up.
  • Focused localization: 3 passed, 0 failed; parity passed across all 15 complete packs.
  • Host build/typecheck passed; host/protocol tests: 54 passed, 0 failed, 0 skipped, including the exact docs example.
  • npm test: 640 passed, 0 failed (68 wrapper, 16 SDK, 54 host, 502 web).
  • npm run check:web, formatting and diff checks passed. The existing local Git object store supplied history missing from the partial checkout; no generated facts were changed.

These are local results. Full hosted CI remains required before merge; local checks do not establish provider, deploy or release qualification.

Scope and dependency

Depends on #6734; do not merge this PR before Phase 1 lands. The base is main so full hosted CI can run in parallel. Attachment ownership and receipt-bound approval still come from #6734; changing the base does not remove that landing dependency.

The execution context exposes signal, callId and args; it does not expose the calling workspace path. Plugins share a process, and the existing platform sandbox limitations remain documented. Laptop suspend/resume, provider behavior, deploy and release qualification are not established by these local checks.

No-Issue: continuation of the existing TypeScript extension-host implementation; tracked in the Core execution plan and Linear SHA-6705 (not GitHub issue #6705).

Hmbown and others added 4 commits September 29, 2026 01:56
Checkpoint the original uncommitted isolated-engine regression before recovering the 23-file phase-1 implementation from /private/tmp/cw-lanes/tsx-fixes-work.patch. Original agent ac38eaf89e9209cb2 saved the implementation and restored this test for a fail-without-fix run before quota interruption. The retained red-check log ends during compilation, so this checkpoint claims no completed validation. No new implementation in this commit.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014ZwqatxgVFxHvovngywnks
Signed-off-by: Hunter B <hmbown@gmail.com>
Recover the interrupted Phase 1 implementation from the preserved 23-file patch after checkpointing its isolated-engine regression. Give each engine its own attachment to the process-wide host, reconcile the reviewed union, and install only that engine's tools. Publish a completed scan only when the entire attachment set still matches, so a workspace change cannot activate or publish stale owners.

Bind extension approval and session-grant keys to the plugin identity and reviewed content receipt. Cover approval-gated code-mode execution and preserve the ungated refusal. Share the regular .mjs/.js entry rule between discovery and activation, report invalid entries in review, and correct extension-host/skill authoring guidance while retaining the previous bundled skill generation.

Validation on the final source tree:
- Focused Rust host/engine/approval/plugin/skill tests: 532 passed, 0 failed, 1 ignored subprocess entry point (exercised by process tests), 13297 filtered. CODEWHALE_EXT_HOST_TESTS=1 required real Node fixtures; no provider calls.
- npm test: 636 passed, 0 failed (68 wrapper, 16 SDK, 50 host, 502 web).
- npm run check:web: exit 0; facts, docs, tokens, lint, types and production build passed. Existing canonical Git objects supplied the partial clone's missing history without changing generated dates.
- cargo fmt --all -- --check and git diff --check passed.

The earlier interrupted red-check never completed and is not claimed as evidence. Phase 2 supervision/restart work is not included; existing experimental platform sandbox limitations remain documented.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014ZwqatxgVFxHvovngywnks
Signed-off-by: Hunter B <hmbown@gmail.com>
Production uses background reconciliation; the synchronous attachment helper is used only by host tests. Hosted MSRV and OpenHarmony checks caught its dead-code error in the non-test build. Existing focused tests remain applicable; non-test compilation is pending before this follow-up is pushed.
Monitor the shared extension host with generation-bound pings, report delayed responses, and kill a hung process tree. Recover unexpected post-handshake exits through the existing reconciliation path with backoff and a shared three-crash/five-minute limit. Opening another engine cannot reset that limit; explicit plugin mutation retries deliberately, while launch failures permit attachment retry only after cooldown.

Replay only currently attached, still-authorized plugin receipts with fresh owner tokens and tool handles. Preserve failed/faulted receipts, attribute activation crashes to the activating owner, reject stale callbacks and superseded launches, and never replay pending tool calls. Refresh same-byte authority after an explicit plugin mutation. The experimental feature remains disabled by default with its existing approval and sandbox boundaries.

Validation:
- Production codewhale-tui library check passed with locked dependencies and warnings denied.
- Focused Rust host/engine/approval tests: 48 passed, 0 failed, 0 ignored, 13792 filtered; real Node host fixtures required with CODEWHALE_EXT_HOST_TESTS=1, no provider calls.
- Extension-host build and typecheck passed; host/protocol tests: 53 passed, 0 failed, 0 skipped.
- npm test: 639 passed, 0 failed (68 wrapper, 16 SDK, 53 host, 502 web).
- npm run check:web: exit 0; facts, docs, tokens, lint, types and production build passed. Existing canonical Git objects supplied missing partial-clone history without changing source facts.
- cargo fmt --all -- --check and git diff --check passed.

The initial production check caught a shutdown-only registry helper after its production caller was replaced; the helper is now test-only and the corrected production check passed. This is the bounded supervision/restart slice of Phase 2a. Owner diagnostics, dirty teardown recovery, author workflow additions and laptop-suspend behavior remain outside this proof. Local fixture success does not claim hosted CI, provider, deployment or release qualification.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014ZwqatxgVFxHvovngywnks
Signed-off-by: Hunter B <hmbown@gmail.com>
Copilot AI balanced review requested due to automatic review settings September 29, 2026 10:04
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Count incomplete, leaking, malformed and timed-out teardown results on both revocation and failed-activation cleanup. Two events within ten minutes request one planned restart through the existing generation-bound monitor and reconciliation path. Wait for reconciliation and non-heartbeat requests to become idle, then seal new admission under the pending-map lock before retiring the process tree.

Treat the sealed process as retiring before its exit callback, so a new reconcile cannot falsely fail a valid owner's activation. Bind planned maintenance to the exact generation and exit reason; preserve the unexpected-crash budget, failed receipts and normal replay validation. Ignore stale teardown outcomes from the retired host and never replay calls.

Validation:
- Production codewhale-tui library check passed with locked dependencies and warnings denied.
- Focused Rust host/engine/approval tests: 52 passed, 0 failed, 0 ignored, 13792 filtered; real Node fixtures required, including dirty disposal, failed-activation cleanup, atomic admission, live-call completion and fresh-owner replay.
- npm test: 639 passed, 0 failed (68 wrapper, 16 SDK, 53 host, 502 web).
- npm run check:web: exit 0; facts, docs, tokens, lint, types and production build passed with the canonical local Git object store supplying partial-clone history.
- Formatting and diff checks passed. Real-Node fixture smoke verified disposal reports false after its deadline while heartbeat stays responsive.

The existing large-unwind linker warning is separate from source diagnostics. This completes Phase 2a dirty-teardown recovery; the scoped owner report, cwd/mts and author guide/example/skill work follow. No hosted CI, provider or release qualification is claimed.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014ZwqatxgVFxHvovngywnks
Signed-off-by: Hunter B <hmbown@gmail.com>
Expose bounded plugin-attributed diagnostics and typed owner state through
the existing plugin show surface. Escape plugin-controlled text and translate
the report and state labels in all 15 complete locale packs. Preserve the
single shared diagnostic ring and existing approval and authority checks.

Accept regular .mts entries through the existing staged-byte and receipt
validation path, suggest safe plugin-specific tool names, and document the
actual experimental host contract. Exercise the exact typed hello example
through the host and reviewed installation path. Ship plugin-creator
generation 17 while preserving generation 16 and customized installed bodies.
The agent stops after install/validate/show; a person reviews/trusts/enables.
The execution context does not expose the calling workspace path.

Validation on the final source:
- Production TUI library check passed with locked dependencies (53.33s).
- Focused Rust: 56 passed, 0 failed, 0 ignored; real Node fixtures required.
- Focused localization: 3 passed, 0 failed; all 15 locale packs pass parity.
- Host build/typecheck passed; host/protocol tests: 54 passed, 0 failed.
- npm test: 640 passed, 0 failed (68 wrapper, 16 SDK, 54 host, 502 web).
- npm run check:web passed; local Git object store supplied missing history.
- Formatting/diff checks passed; exact previous generation body preserved.

These are local results; hosted CI and release qualification remain separate.
Depends on the Phase 1 attachment/approval fixes in PR #6734.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014ZwqatxgVFxHvovngywnks
Signed-off-by: Hunter B <hmbown@gmail.com>
@Hmbown Hmbown changed the title feat(extensions): supervise host recovery with bounded replay Supervise extension hosts and add a tested authoring workflow Sep 29, 2026
@Hmbown
Hmbown changed the base branch from fix/ts-extension-host-phase1-fixes to main September 29, 2026 10:54
Use SessionUpdated as the acknowledgement for SyncSession so a generic
background status cannot replace the host resume confirmation. Extend
the existing silent-config regression to verify restored state and keep
the original launch-card PTY assertion unchanged.

Validation: focused Engine test 1 passed / 0 failed; original PTY test
1 passed / 0 failed across five terminal sizes; npm test 636 passed /
0 failed; check:web passed. No live provider calls.

Signed-off-by: Hunter B <hmbown@gmail.com>
Publish exit under the pending-call lock before draining requests, and
repeat the admission check under that lock. A failed-call notification
can no longer admit an orphaned request during process teardown.

Validation: production TUI check passed;38 focused Rust tests passed,
0 failed/0 ignored with real Node fixtures required, including the
deterministic exit-waker regression. npm640passed/0failed; check:web
passed. Existing retirement, ownership and recovery checks remain intact.

Signed-off-by: Hunter B <hmbown@gmail.com>
@Hmbown
Hmbown merged commit b254c1c into main Sep 29, 2026
35 checks passed
@Hmbown
Hmbown deleted the fix/ts-extension-host-phase2a branch September 29, 2026 21:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants