Supervise extension hosts and add a tested authoring workflow - #6735
Merged
Merged
Conversation
Checkpoint the original uncommitted isolated-engine regression before recovering the 23-file phase-1 implementation from /private/tmp/cw-lanes/tsx-fixes-work.patch. Original agent ac38eaf89e9209cb2 saved the implementation and restored this test for a fail-without-fix run before quota interruption. The retained red-check log ends during compilation, so this checkpoint claims no completed validation. No new implementation in this commit. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014ZwqatxgVFxHvovngywnks Signed-off-by: Hunter B <hmbown@gmail.com>
Recover the interrupted Phase 1 implementation from the preserved 23-file patch after checkpointing its isolated-engine regression. Give each engine its own attachment to the process-wide host, reconcile the reviewed union, and install only that engine's tools. Publish a completed scan only when the entire attachment set still matches, so a workspace change cannot activate or publish stale owners. Bind extension approval and session-grant keys to the plugin identity and reviewed content receipt. Cover approval-gated code-mode execution and preserve the ungated refusal. Share the regular .mjs/.js entry rule between discovery and activation, report invalid entries in review, and correct extension-host/skill authoring guidance while retaining the previous bundled skill generation. Validation on the final source tree: - Focused Rust host/engine/approval/plugin/skill tests: 532 passed, 0 failed, 1 ignored subprocess entry point (exercised by process tests), 13297 filtered. CODEWHALE_EXT_HOST_TESTS=1 required real Node fixtures; no provider calls. - npm test: 636 passed, 0 failed (68 wrapper, 16 SDK, 50 host, 502 web). - npm run check:web: exit 0; facts, docs, tokens, lint, types and production build passed. Existing canonical Git objects supplied the partial clone's missing history without changing generated dates. - cargo fmt --all -- --check and git diff --check passed. The earlier interrupted red-check never completed and is not claimed as evidence. Phase 2 supervision/restart work is not included; existing experimental platform sandbox limitations remain documented. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014ZwqatxgVFxHvovngywnks Signed-off-by: Hunter B <hmbown@gmail.com>
Production uses background reconciliation; the synchronous attachment helper is used only by host tests. Hosted MSRV and OpenHarmony checks caught its dead-code error in the non-test build. Existing focused tests remain applicable; non-test compilation is pending before this follow-up is pushed.
Monitor the shared extension host with generation-bound pings, report delayed responses, and kill a hung process tree. Recover unexpected post-handshake exits through the existing reconciliation path with backoff and a shared three-crash/five-minute limit. Opening another engine cannot reset that limit; explicit plugin mutation retries deliberately, while launch failures permit attachment retry only after cooldown. Replay only currently attached, still-authorized plugin receipts with fresh owner tokens and tool handles. Preserve failed/faulted receipts, attribute activation crashes to the activating owner, reject stale callbacks and superseded launches, and never replay pending tool calls. Refresh same-byte authority after an explicit plugin mutation. The experimental feature remains disabled by default with its existing approval and sandbox boundaries. Validation: - Production codewhale-tui library check passed with locked dependencies and warnings denied. - Focused Rust host/engine/approval tests: 48 passed, 0 failed, 0 ignored, 13792 filtered; real Node host fixtures required with CODEWHALE_EXT_HOST_TESTS=1, no provider calls. - Extension-host build and typecheck passed; host/protocol tests: 53 passed, 0 failed, 0 skipped. - npm test: 639 passed, 0 failed (68 wrapper, 16 SDK, 53 host, 502 web). - npm run check:web: exit 0; facts, docs, tokens, lint, types and production build passed. Existing canonical Git objects supplied missing partial-clone history without changing source facts. - cargo fmt --all -- --check and git diff --check passed. The initial production check caught a shutdown-only registry helper after its production caller was replaced; the helper is now test-only and the corrected production check passed. This is the bounded supervision/restart slice of Phase 2a. Owner diagnostics, dirty teardown recovery, author workflow additions and laptop-suspend behavior remain outside this proof. Local fixture success does not claim hosted CI, provider, deployment or release qualification. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014ZwqatxgVFxHvovngywnks Signed-off-by: Hunter B <hmbown@gmail.com>
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Count incomplete, leaking, malformed and timed-out teardown results on both revocation and failed-activation cleanup. Two events within ten minutes request one planned restart through the existing generation-bound monitor and reconciliation path. Wait for reconciliation and non-heartbeat requests to become idle, then seal new admission under the pending-map lock before retiring the process tree. Treat the sealed process as retiring before its exit callback, so a new reconcile cannot falsely fail a valid owner's activation. Bind planned maintenance to the exact generation and exit reason; preserve the unexpected-crash budget, failed receipts and normal replay validation. Ignore stale teardown outcomes from the retired host and never replay calls. Validation: - Production codewhale-tui library check passed with locked dependencies and warnings denied. - Focused Rust host/engine/approval tests: 52 passed, 0 failed, 0 ignored, 13792 filtered; real Node fixtures required, including dirty disposal, failed-activation cleanup, atomic admission, live-call completion and fresh-owner replay. - npm test: 639 passed, 0 failed (68 wrapper, 16 SDK, 53 host, 502 web). - npm run check:web: exit 0; facts, docs, tokens, lint, types and production build passed with the canonical local Git object store supplying partial-clone history. - Formatting and diff checks passed. Real-Node fixture smoke verified disposal reports false after its deadline while heartbeat stays responsive. The existing large-unwind linker warning is separate from source diagnostics. This completes Phase 2a dirty-teardown recovery; the scoped owner report, cwd/mts and author guide/example/skill work follow. No hosted CI, provider or release qualification is claimed. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014ZwqatxgVFxHvovngywnks Signed-off-by: Hunter B <hmbown@gmail.com>
Expose bounded plugin-attributed diagnostics and typed owner state through the existing plugin show surface. Escape plugin-controlled text and translate the report and state labels in all 15 complete locale packs. Preserve the single shared diagnostic ring and existing approval and authority checks. Accept regular .mts entries through the existing staged-byte and receipt validation path, suggest safe plugin-specific tool names, and document the actual experimental host contract. Exercise the exact typed hello example through the host and reviewed installation path. Ship plugin-creator generation 17 while preserving generation 16 and customized installed bodies. The agent stops after install/validate/show; a person reviews/trusts/enables. The execution context does not expose the calling workspace path. Validation on the final source: - Production TUI library check passed with locked dependencies (53.33s). - Focused Rust: 56 passed, 0 failed, 0 ignored; real Node fixtures required. - Focused localization: 3 passed, 0 failed; all 15 locale packs pass parity. - Host build/typecheck passed; host/protocol tests: 54 passed, 0 failed. - npm test: 640 passed, 0 failed (68 wrapper, 16 SDK, 54 host, 502 web). - npm run check:web passed; local Git object store supplied missing history. - Formatting/diff checks passed; exact previous generation body preserved. These are local results; hosted CI and release qualification remain separate. Depends on the Phase 1 attachment/approval fixes in PR #6734. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014ZwqatxgVFxHvovngywnks Signed-off-by: Hunter B <hmbown@gmail.com>
Hmbown
changed the base branch from
fix/ts-extension-host-phase1-fixes
to
main
September 29, 2026 10:54
Use SessionUpdated as the acknowledgement for SyncSession so a generic background status cannot replace the host resume confirmation. Extend the existing silent-config regression to verify restored state and keep the original launch-card PTY assertion unchanged. Validation: focused Engine test 1 passed / 0 failed; original PTY test 1 passed / 0 failed across five terminal sizes; npm test 636 passed / 0 failed; check:web passed. No live provider calls. Signed-off-by: Hunter B <hmbown@gmail.com>
Publish exit under the pending-call lock before draining requests, and repeat the admission check under that lock. A failed-call notification can no longer admit an orphaned request during process teardown. Validation: production TUI check passed;38 focused Rust tests passed, 0 failed/0 ignored with real Node fixtures required, including the deterministic exit-waker regression. npm640passed/0failed; check:web passed. Existing retirement, ownership and recovery checks remain intact. Signed-off-by: Hunter B <hmbown@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Recover a reviewed extension after a host crash without replaying interrupted calls or losing the shared crash budget. The existing manager now supervises heartbeats, retires a persistently hung process, and replays only still-authorized owners with fresh tokens and handles. Three crashes within five minutes stop automatic recovery; opening another engine cannot reset that budget. Explicit plugin changes retry deliberately, and launch failures also permit a new attachment to retry after cooldown.
Two dirty teardowns within ten minutes request maintenance after active calls finish. Admission closes atomically before retirement; maintenance preserves the crash budget, and failed-activation cleanup shares the same accounting. Ordinary process exit also closes admission under the pending-call lock before failed calls are notified; a reentrant request is rejected immediately. Stale callbacks cannot mutate new owners, and failed/faulted receipts remain suppressed until explicit retry or changed authority.
The authoring path now accepts reviewed regular
.mtsentries through the existing staged-byte and receipt checks./plugin showdisplays typed owner state, live tools and up to 20 retained plugin-attributed diagnostics from the existing bounded 64-entry shared ring. Plugin-controlled text is escaped, and report labels and states are translated in all 15 complete locale packs. Name refusals suggest a plugin-specific prefix without relaxing restrictions. The guide and executablehello.mtsexample use the real host; plugin-creator generation 17 preserves the exact previous generation and custom installed bodies. The agent stops after install, validate and show; a person reviews, trusts and enables.The experimental feature remains off by default. Approval, receipt and sandbox boundaries remain in place.
Validation
npm test: 640 passed, 0 failed (68 wrapper, 16 SDK, 54 host, 502 web).npm run check:web, formatting and diff checks passed. The existing local Git object store supplied history missing from the partial checkout; no generated facts were changed.These are local results. Full hosted CI remains required before merge; local checks do not establish provider, deploy or release qualification.
Scope and dependency
Depends on #6734; do not merge this PR before Phase 1 lands. The base is
mainso full hosted CI can run in parallel. Attachment ownership and receipt-bound approval still come from #6734; changing the base does not remove that landing dependency.The execution context exposes
signal,callIdandargs; it does not expose the calling workspace path. Plugins share a process, and the existing platform sandbox limitations remain documented. Laptop suspend/resume, provider behavior, deploy and release qualification are not established by these local checks.No-Issue: continuation of the existing TypeScript extension-host implementation; tracked in the Core execution plan and Linear SHA-6705 (not GitHub issue #6705).