feat(plugin): install and run plugins with namespace identity - #5166
kelv1nq1an wants to merge 43 commits into
Conversation
|
|
本 PR 命中维护者确认门(product / pluginBase / arch 三类触发),自动流程在获得维护者确认前不会合并。 本次改动:客户端识别服务端 为何需确认:
确认方式:请维护者直接在本 PR 上 Approve;需要作者修改则 Request Changes 写明要求,改完后重新 Approve。 讨论 issue:#5168 |
|
@greptile-apps review |
|
@greptile-apps review |
662b89b to
2b67e75
Compare
|
@greptile-apps review |
|
基于最新 HEAD 已确认改善:原位安装在 receipt 盖章后能获得 Forge Broker;自由命名 Forge 的 OIDC 不再依赖旧前缀;新装 XD Mivo 能找到历史密钥;旧企业插件与同名 root 可以完成安装。下面是仍需处理的部分。 1. 搬迁遗漏媒体归属,导致新 root 继承旧企业插件的媒体访问权。
需要让媒体归属随安装实例保持一致,并纳入搬迁事务及恢复;也可以通过稳定的实例映射避免搬动数据身份。新 root 不能继承这些引用。 2. 目标数据冲突时,新安装失败会连带破坏旧插件可用性。 在源和目标存储位置分别预置不同 KV 数据后,安装同名 root:代码先搬走旧插件目录,再发现数据目标冲突。新安装返回 应在搬动前完成目标数据冲突检查,或在失败时完整恢复旧安装。保留 journal、防止覆盖数据是必要的,但不能把原本可用的旧插件永久留在隔离状态。 代码:GhostManager.ts。 3. 尚未完成 namespace 迁移的旧 Forge 仍会失去 Broker。 本轮已修复“receipt 已盖章”的情况,但对升级时已捕获为 需要保留已核实旧安装在迁移期间的原有资格,同时确保升级后新安装不能靠缺字段取得旧资格。不能依赖用户重新安装或重新确认权限。 代码:ghostFirstPartyFacts.ts、Forge 门槛。 4. 特殊权限仍未按已定设计限定可信来源。
当前名称限制挡住了部分入口,但这些边界在 S2 放开命名之前必须完成,因此目前还不能宣称已支持 S2 开启后的全部行为。 手工验证覆盖还不足。 现有记录覆盖了默认安装、缺字段保持旧协议、原位盖章、两份新插件同名共存、指令歧义和卸载隔离。这些是有效证据,但“两份新安装共存”不等于“旧企业实例迁移后与新 root 共存”;“重新同意后连接成功”也不能证明升级无需重新授权。 建议补齐以下验收,并注明实测构建 commit、环境、操作和结果:
“线上尚未开启 S2”不妨碍使用隔离环境/mock 验证自由命名、跨组织、update-all 等客户端行为,但测试结果应明确区分模拟验证和真实服务联调。最后两次搬迁修复尤其需要基于最新构建重新验收。 本轮在临时副本复跑相关现有单测 131 个,均通过;补充定向反例确认了上述问题。媒体复现使用真实文件系统和 SQLite,并执行 PR 中的数据搬迁函数;不涉及真实用户数据。以上属于代码与针对性测试结果,本轮未重新操作真实客户端,不把这些测试当作 E2E 已通过。 |
2b67e75 to
f6ec315
Compare
Signed-off-by: fattycat <fattycat.u@gmail.com>
Stamp namespace onto existing installs in place so XD plugins stay at their current directories and storage keys. Stop, uninstall, OAuth, media, and webview use the physical identity, not a derived _ns path. Author packages still cannot declare namespace. Signed-off-by: fattycat <fattycat.u@gmail.com>
… one Legacy installs were writing namespace: null into receipts. Keep the field omitted unless the caller explicitly passes namespace. Signed-off-by: fattycat <fattycat.u@gmail.com>
Namespaced Node workers were matching device/plugin authorization against manifest.id, so _ns instances could not open the auth card. Signed-off-by: fattycat <fattycat.u@gmail.com>
Install and update wrote pending markers under _ns/<namespace>/ but cleared them with the bare ghostId, leaving leftover journals after a successful namespaced install. Require organization namespace when currentOrganization.orgSlug is present. Signed-off-by: fattycat <fattycat.u@gmail.com>
$command and Host capability chips now inject the storage-part instance id. ghost_call was re-resolving with the catalog ghostId and dropping namespace, so a public twin made namespaced calls GHOST_AMBIGUOUS. Pin the instance after the first unique resolve for setup, grants, revalidation, and dispatch. Ledger, runtime, composer, and cards look up the same physical id instead of manifest.id. Signed-off-by: fattycat <fattycat.u@gmail.com>
GHOST_AMBIGUOUS was missing from setup target validation, census candidates were typed as readonly, and identity helpers narrowed valid ghost ids to never. Align the types with the physical instance id lookups. Signed-off-by: fattycat <fattycat.u@gmail.com>
Linux shard 1/2 failed on a 5s mobile Maestro dry-run timeout. This branch does not change apps/mobile; empty commit retriggers checks. Signed-off-by: fattycat <fattycat.u@gmail.com>
Update-all matched installed ghosts by manifest.id, so a root/org twin could donate the wrong approval token. Resolve by market namespace or physical root, and key batch versions/ignore-round by pluginId. Signed-off-by: fattycat <fattycat.u@gmail.com>
Library delete still validated isValidGhostId after IPC accepted instance ids, so org installs could not trash their library. Canonicalize to the storage part for overview, relocate, and delete. Signed-off-by: fattycat <fattycat.u@gmail.com>
Main now requires a consent context on market install. The namespaced drift case still called the old two-argument signature after rebase. Signed-off-by: fattycat <fattycat.u@gmail.com>
Signed-off-by: fattycat <fattycat.u@gmail.com>
Signed-off-by: fattycat <fattycat.u@gmail.com>
A tombstoned root row fell back to its same-name organization twin, while Connection only checked manifest identity. Require the trusted receipt namespace to match the market route so root copies cannot borrow organization OIDC access.
Physical namespace relocation previously moved plugin data but left per-project disables keyed by the old root ID, so the relocated plugin became usable and a new root plugin inherited its disable. Atomically remap those preferences at the end of relocation, preserve unreadable files for retry, and cover the repeated migration path.
The earlier workdir disable fix covered one physical-ID state store, but recommendations, recent use and live detached windows still used the old root ID. Move owner-scoped recommendation history on relocation, key the suggestion flow by physical instance, and rebuild the detached window before a new root plugin can claim it. Cover duplicate identities and interrupted relocation.
…ommendations Signed-off-by: fattycat <fattycat.u@gmail.com>
Legacy purge notices omitted namespace after organization installs gained namespaced ledger keys, so cleanup silently skipped them. Resolve only a unique matching organization record and refuse ambiguous notices. Keep namespace through mobile call grouping and projection, and resolve remote identity cards by the selected instance instead of a bare id. Regression tests cover the missed compatibility path and same-id root/org calls. Signed-off-by: fattycat <fattycat.u@gmail.com>
Namespace collisions recurred because renderer card matching and setup lifecycle snapshots still used bare ghost ids after namespaced installation keys were introduced. Use physical instance ids for card ownership and setup notifications, with red-green regressions for same-id root and enterprise plugins and in-place stamps.
Signed-off-by: fattycat <fattycat.u@gmail.com>
…ce migration Signed-off-by: fattycat <fattycat.u@gmail.com>
Signed-off-by: fattycat <fattycat.u@gmail.com>
Signed-off-by: fattycat <fattycat.u@gmail.com>
Signed-off-by: fattycat <fattycat.u@gmail.com>
Prevent legacy WebView sessions from surviving namespace commits, and use instance identity for model lookup, uninstall cleanup, offline market recovery, and home suggestions. Cover matching and mismatched identities with regression tests. Signed-off-by: fattycat <fattycat.u@gmail.com>
…nd cards Signed-off-by: fattycat <fattycat.u@gmail.com>
Signed-off-by: fattycat <fattycat.u@gmail.com>
Preserve S1 and S2-disabled publishing compatibility while supporting namespace-aware installs and verified organization identities. Pin requests and sessions to owner and approval identity; archive source-owned state and serialize recovery with mutations. Regression guards prevent stale guest requests, delayed Library creation, and superseded recovery jobs from reaching replacement installs. Validation: 60 Vitest files / 1977 tests passed; Desktop typecheck and development-doc contract checks passed. Existing lint diagnostics are unchanged. Signed-off-by: fattycat <fattycat.u@gmail.com>
Consolidate physical-instance lookup and relocatable state for S1 and both S2 rollout modes, preserving delivery namespace tri-state and trusted legacy provenance. Previous fixes still reselected plugins by bare name or retained physical-key-only authorization state after relocation. Bind revalidation, adapters and confirmation caches to the installed target, serialize recovery against owner/journal/receipt snapshots, and migrate durable staging metadata alongside user-data references. Add regression coverage for same-name coexistence, stale authorization and subscription callbacks, superseded recovery transactions, and replayable staging migration. Verified red-green regressions and the complete candidate in an independent worktree: 4871 desktop tests, 218 protocol/tools tests, typechecks and documentation checks. Signed-off-by: fattycat <fattycat.u@gmail.com>
Signed-off-by: fattycat <fattycat.u@gmail.com>
f6ec315 to
45362ca
Compare
这次改了什么
摘要
客户端现在识别服务端下发的
namespace,并以安装实例的物理身份隔离插件运行、凭证、用户数据和窗口。存量 XD 插件在原安装目录完成身份盖章,不会仅因升级搬入_ns;插件包也不能自行声明 namespace。未收到 namespace 的新安装会作为 root 安装,并在收据中明确写入
namespace: null。存量收据,或被旧客户端重写过的收据,可能缺少该字段;此时先保留“身份待确定”,不直接推断为 root。企业市场安装和 Forge 自测按经过核实的组织身份取得 Broker 资格,不靠插件名前缀授权。本 PR 从 #4910 重开;配套服务端 S1 已合入(xindong/cindy-server#760)。
变更类型
feat新功能fix缺陷修复refactor/perf重构或性能优化docs/test/chore文档、测试或工程维护范围
UI 变化
怎么验证的
自动验证
当前分支做过以下本地验证,不是全量 CI 或实机验收:
pnpm --filter desktop typecheck:通过。手工验证:历史记录
以下操作发生在隔离国内开发版
Cindy-dev2-plugin-namespace-client-2641db,没有使用--shared,也没有修改正式版数据目录。这些结果不是最新 HEADf6ec31502的实机验收。在当时的现网市场中,XD 默认插件可以安装且仍位于原目录;插件包不携带 namespace;卸载后可不重启直接重装。当时还观察到接口不下发 namespace 时收据会省略字段。当前代码已改为新装 root 显式写入
null,不能再用该次观察证明当前行为。在同一隔离客户端接入本地 mock 市场后,观察到存量 XD 插件在原目录盖章;root 与企业
twin可同名共存,显式指定 namespace 的命令指向对应实例,未指定时会提示歧义;卸掉其中一份不影响另一份。假xd-插件未取得企业特权,开启开发环境的前缀闸后安装被拒。飞书 OAuth 曾在重新同意后连接成功;这不能证明升级过程无需重新授权。尚待最新构建验收
xd-前缀限制。隔离环境或 mock 的 S2 测试须与真实服务联调分开记录。风险
风险分类
影响与回滚
提交前检查