Skip to content

Declare runtime plugin service dependencies - #165

Merged
ldsenow merged 2 commits into
mainfrom
codex/plugin-service-dependencies
Sep 29, 2026
Merged

ldsenow merged 2 commits into
mainfrom
codex/plugin-service-dependencies

Conversation

@ldsenow

@ldsenow ldsenow commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Scope

Third Cordis-inspired increment: a trusted built-in Webhook plugin can declare requires: { http: "api" } and use the named HTTP plugin's client with a relative webhook URL. The registry validates the provider and service, activates providers first in ConnectAllAsync, exposes active dependencies in composition, blocks provider disconnect/replacement while in use, and tears down dependents first on Host shutdown. Dependency denials are recorded as no-effect management failures.

HTTP and Webhook URLs now reject non-HTTP schemes; a dependent Webhook URL cannot move the initial request to another origin. Rejected dependent URLs finalize admitted management operations as Failed; a provider replacement blocked by an active dependent returns HTTP 409.

Verification

  • Python unittest discovery: 111 tests, 1 skipped.
  • Solution restore and locked restore: passed.
  • Release solution build: 0 warnings, 0 errors.
  • Full Release solution test on commit 19cf6fa: 2993 total, 2979 passed, 14 skipped, 0 failed.
  • Format verification for changed C# files: passed.
  • Both review regressions failed before the fix and passed afterward. The Host endpoint test uses a local test HTTP handler; no external Webhook request is needed.

The skipped tests need Docker's npipe endpoint, Windows symlink privileges, or a configured live Echo HTTP endpoint.

Boundary

This is process-local composition among trusted Host connectors. It does not create a persistent service grant, credential broker, Tenant isolation, external plugin sandbox, or automatic dependency reconciliation after restart. HTTP redirects and egress still follow Host deployment policy. See docs/implementation/2026-09-29-plugin-service-dependencies.md.

@ldsenow
ldsenow marked this pull request as ready for review September 29, 2026 14:58
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-29T15:04:01.691709Z e4fdfc1 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Comment thread tests/Weave.Silo.Tests/PluginEndpointHappyPathTests.cs
Comment thread tests/Weave.Silo.Tests/Plugins/PluginRegistryActivationTests.cs

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e4fdfc13fc

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread hosts/Weave.Host/Api/PluginEndpoints.cs
Comment thread hosts/Weave.Host/Api/PluginEndpoints.cs Outdated
@ldsenow
ldsenow merged commit e9ff50e into main Sep 29, 2026
23 checks passed
@ldsenow
ldsenow deleted the codex/plugin-service-dependencies branch September 29, 2026 22:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant