Compare commits
675
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
159704dc6f | ||
|
|
6492f10f42 | ||
|
|
a525ba4d01 | ||
|
|
c261aea021 | ||
|
|
8d4fee231b | ||
|
|
307d38453f | ||
|
|
d2a8a79ac6 | ||
|
|
6c8998878d | ||
|
|
41283c8dd9 | ||
|
|
fa29cc2c95 | ||
|
|
7a4fd97526 | ||
|
|
103077dfae | ||
|
|
cd2006305e | ||
|
|
a453c6e2da | ||
|
|
16247ce7c5 | ||
|
|
b9e786e106 | ||
|
|
ccd4d83d43 | ||
|
|
3a9ac1b1b7 | ||
|
|
f2c51ffe39 | ||
|
|
ef17955369 | ||
|
|
62e467c035 | ||
|
|
4950749c5d | ||
|
|
dc2f8b409d | ||
|
|
d2aa92a729 | ||
|
|
86017a5abc | ||
|
|
799998639a | ||
|
|
755d460f0d | ||
|
|
07f9793bc6 | ||
|
|
89a40db79e | ||
|
|
84a8423611 | ||
|
|
8e79c1dc96 | ||
|
|
000afbbe19 | ||
|
|
db1a2f567b | ||
|
|
bdd05dce4d | ||
|
|
4e138b7e36 | ||
|
|
1839acb3d0 | ||
|
|
f26c7e0d09 | ||
|
|
437ef5b56b | ||
|
|
7d64b443f2 | ||
|
|
449745ee24 | ||
|
|
e66efc746f | ||
|
|
436bcc812d | ||
|
|
6086099fe4 | ||
|
|
390f468471 | ||
|
|
ef1d8d9af2 | ||
|
|
ceb7b95096 | ||
|
|
237c985f2c | ||
|
|
66c5be16f8 | ||
|
|
bedbb670e4 | ||
|
|
0591fd528c | ||
|
|
19ff3724ed | ||
|
|
741d71327a | ||
|
|
27117f3246 | ||
|
|
1b5a39dbc9 | ||
|
|
f65f0e3b8f | ||
|
|
e2df9f9493 | ||
|
|
959b497135 | ||
|
|
ef08b873ce | ||
|
|
2f975808bb | ||
|
|
273f10e954 | ||
|
|
f349738257 | ||
|
|
577bf75051 | ||
|
|
79df31ccf6 | ||
|
|
72812878c0 | ||
|
|
cea115ecd9 | ||
|
|
4c3b15d8d6 | ||
|
|
45d21ac032 | ||
|
|
4e713fce19 | ||
|
|
428b7d0fef | ||
|
|
5ddc8dceac | ||
|
|
f901b9bee3 | ||
|
|
2f9604a12f | ||
|
|
893122781d | ||
|
|
f367d73231 | ||
|
|
5fa480904d | ||
|
|
0618de21eb | ||
|
|
d5012d3e16 | ||
|
|
28d53aadf2 | ||
|
|
4fb75ec324 | ||
|
|
091ee764a4 | ||
|
|
439f967cb8 | ||
|
|
80d6861aba | ||
|
|
d2ec533585 | ||
|
|
b52b7c963c | ||
|
|
89910a1a29 | ||
|
|
7ee2b78bbb | ||
|
|
0b2ce6ca1f | ||
|
|
bca8ba6ed9 | ||
|
|
5c9331e848 | ||
|
|
bb6bc9f6a1 | ||
|
|
845817d3bf | ||
|
|
1d98921a45 | ||
|
|
7ede927d5a | ||
|
|
6081448a7e | ||
|
|
70162d5001 | ||
|
|
b975812c18 | ||
|
|
1251c0ca70 | ||
|
|
dd40c41f45 | ||
|
|
428d255b27 | ||
|
|
38d25582b2 | ||
|
|
cdc0a5da33 | ||
|
|
c96cc49d0a | ||
|
|
9bd1550715 | ||
|
|
81fa035a1c | ||
|
|
371fd7c6e5 | ||
|
|
d231f41300 | ||
|
|
97555bb5a1 | ||
|
|
d62ab6e1de | ||
|
|
217a4828d7 | ||
|
|
bc2b8513f7 | ||
|
|
73122c10fd | ||
|
|
b84db7fac7 | ||
|
|
911df3df77 | ||
|
|
acf1f5fb53 | ||
|
|
1044b39c3f | ||
|
|
a729d68600 | ||
|
|
b83886554f | ||
|
|
5a8bcebdf4 | ||
|
|
a479d3e32d | ||
|
|
f399d7383c | ||
|
|
e8e019eb76 | ||
|
|
3c2fd5d760 | ||
|
|
1ca5663298 | ||
|
|
b28d64c3c6 | ||
|
|
76c800542c | ||
|
|
cca073f8aa | ||
|
|
c0f4c184ca | ||
|
|
8c8fb01426 | ||
|
|
052408392d | ||
|
|
cfb215ab0c | ||
|
|
3501e0dffe | ||
|
|
af683af2d2 | ||
|
|
90b1a1fccb | ||
|
|
5954021cc5 | ||
|
|
108088d811 | ||
|
|
ca2ad18ded | ||
|
|
d2e6a2a1a7 | ||
|
|
e275a80f4c | ||
|
|
2745f3d516 | ||
|
|
8f7b87a29e | ||
|
|
2a7b659be4 | ||
|
|
3dd680683c | ||
|
|
49c9e19074 | ||
|
|
ddd2f86e26 | ||
|
|
fac79dc962 | ||
|
|
71a39002fb | ||
|
|
58904c441a | ||
|
|
1e812b793b | ||
|
|
ff8aa6bcbf | ||
|
|
2b213a8add | ||
|
|
021aca8d5e | ||
|
|
21b14ba440 | ||
|
|
5c242d9620 | ||
|
|
31565c9b9e | ||
|
|
99f31e0055 | ||
|
|
4cda83b748 | ||
|
|
13e76d3544 | ||
|
|
85b6d9f027 | ||
|
|
8daf9eacb7 | ||
|
|
48672e4317 | ||
|
|
eb998f0ad4 | ||
|
|
9cbb5b9b71 | ||
|
|
108666664a | ||
|
|
5abf16f9e6 | ||
|
|
78c98a34d1 | ||
|
|
68f1ddbd5a | ||
|
|
71284cdc92 | ||
|
|
03ad525fcc | ||
|
|
af9e940873 | ||
|
|
b547203fde | ||
|
|
9728b533b4 | ||
|
|
9c4d1559fd | ||
|
|
e0ec8ce78a | ||
|
|
9de04f7266 | ||
|
|
eea26f9174 | ||
|
|
0b1e9fdc5b | ||
|
|
277af3dec3 | ||
|
|
3bfd1ca07d | ||
|
|
0e635ba6b4 | ||
|
|
017ac70876 | ||
|
|
5428837605 | ||
|
|
87482df956 | ||
|
|
a13fb6933b | ||
|
|
d775e09688 | ||
|
|
f1ab40bf01 | ||
|
|
c92bc447cc | ||
|
|
6f68bb8d95 | ||
|
|
f39127b752 | ||
|
|
a6f9019edd | ||
|
|
2865abb65a | ||
|
|
f6eb11e567 | ||
|
|
ee750363d2 | ||
|
|
d8f467e30f | ||
|
|
746c51c701 | ||
|
|
f9ca777afe | ||
|
|
4189b80004 | ||
|
|
6013048f68 | ||
|
|
1d626cdea6 | ||
|
|
615c02501a | ||
|
|
7a7891d467 | ||
|
|
38bd122dd0 | ||
|
|
9c0c7badcf | ||
|
|
c3798559d2 | ||
|
|
d89ace5b9c | ||
|
|
1994d2d668 | ||
|
|
1c3ec71361 | ||
|
|
e7333f2e4d | ||
|
|
5149ab703f | ||
|
|
1e0f2158ba | ||
|
|
f17a458a04 | ||
|
|
5f06af81cb | ||
|
|
8407ce22b4 | ||
|
|
c6ddff159f | ||
|
|
b7c890d3f6 | ||
|
|
4b1f1e593d | ||
|
|
7ee702b162 | ||
|
|
680b2a4160 | ||
|
|
076c504640 | ||
|
|
2c76675110 | ||
|
|
ceb1ee3b56 | ||
|
|
de43209643 | ||
|
|
0f7e78c164 | ||
|
|
eb2e5907ea | ||
|
|
c29eba0c70 | ||
|
|
613f412659 | ||
|
|
5d55e47e9b | ||
|
|
8066f71b51 | ||
|
|
5ad588f059 | ||
|
|
4ab696b434 | ||
|
|
d3b8bdfddc | ||
|
|
a607a1f20d | ||
|
|
520209f38c | ||
|
|
ae2d80ba5a | ||
|
|
8652041855 | ||
|
|
04f15623f2 | ||
|
|
a4ed5fb082 | ||
|
|
c884d51702 | ||
|
|
ea47e54399 | ||
|
|
d953049d7d | ||
|
|
2c7ef24a29 | ||
|
|
48c09fd709 | ||
|
|
6ebe4f7752 | ||
|
|
d4de8e26ce | ||
|
|
42c9e9144c | ||
|
|
06a9f2f5fd | ||
|
|
58143ead83 | ||
|
|
b193e3e088 | ||
|
|
e1f02ffca3 | ||
|
|
bd5f2b75c3 | ||
|
|
2bad74046e | ||
|
|
dfbfd6ed82 | ||
|
|
de1a20c007 | ||
|
|
7abc3c7751 | ||
|
|
e8103477a4 | ||
|
|
354f1e1081 | ||
|
|
8a5b341e5e | ||
|
|
2232149be0 | ||
|
|
a766048f29 | ||
|
|
168951b668 | ||
|
|
519730e7d3 | ||
|
|
27f6b3366c | ||
|
|
07782704d4 | ||
|
|
e58355e7e3 | ||
|
|
ce62d23502 | ||
|
|
4c1b8c3d0a | ||
|
|
8578bc1c29 | ||
|
|
77b5276fd3 | ||
|
|
b21638f56c | ||
|
|
08edc767b5 | ||
|
|
4cd4ae9cb5 | ||
|
|
061136d798 | ||
|
|
ecdc52fce9 | ||
|
|
406c057025 | ||
|
|
3eac7f8eae | ||
|
|
79a0e45dbc | ||
|
|
2e2fdae8ef | ||
|
|
d802778104 | ||
|
|
de5f3ba49e | ||
|
|
74aca6f6c5 | ||
|
|
2a23b8d770 | ||
|
|
54d325aeb4 | ||
|
|
6dc78e3f2a | ||
|
|
108b6dc787 | ||
|
|
395de19639 | ||
|
|
cc25201c4f | ||
|
|
66f04e0424 | ||
|
|
5f9797fdd6 | ||
|
|
b4d2b3a442 | ||
|
|
155e039e66 | ||
|
|
b4786b407a | ||
|
|
a59d935bd3 | ||
|
|
6e95e497f7 | ||
|
|
ef12c6b185 | ||
|
|
e6f68496b4 | ||
|
|
be517417ff | ||
|
|
3fc0dd0bde | ||
|
|
89eb59505b | ||
|
|
2601bfa9f0 | ||
|
|
8a15cca567 | ||
|
|
ece35c391c | ||
|
|
6c3ac08c54 | ||
|
|
0e14e7c14e | ||
|
|
2704b8c4bd | ||
|
|
d5338f9244 | ||
|
|
e447f177e0 | ||
|
|
962b769989 | ||
|
|
52a786c780 | ||
|
|
f33415c7e2 | ||
|
|
3e03e53627 | ||
|
|
794e43a534 | ||
|
|
9f721ba437 | ||
|
|
4a5e28067e | ||
|
|
ab7658c1f2 | ||
|
|
6cc0065d15 | ||
|
|
4cd4a06e98 | ||
|
|
f164483e62 | ||
|
|
faf9bb0a82 | ||
|
|
df150647c4 | ||
|
|
6434df13aa | ||
|
|
9f664c751a | ||
|
|
1d27f6c90a | ||
|
|
98c85a1d9e | ||
|
|
1f198ccb43 | ||
|
|
5fb8c393c5 | ||
|
|
7c424e7d38 | ||
|
|
5fa0846dcf | ||
|
|
19c3ec45eb | ||
|
|
bdc11c771d | ||
|
|
35fba2b6fb | ||
|
|
bf4bf4da09 | ||
|
|
d25ca6ff3c | ||
|
|
79ee5c4388 | ||
|
|
2081fd5bda | ||
|
|
8fcfa6e016 | ||
|
|
c14083a45a | ||
|
|
861c351a96 | ||
|
|
50b261e7e2 | ||
|
|
54245e3292 | ||
|
|
a63b40f460 | ||
|
|
8684344e92 | ||
|
|
5f52c72b45 | ||
|
|
839783b2e6 | ||
|
|
717ff8db01 | ||
|
|
249b55ec3f | ||
|
|
5885850726 | ||
|
|
bc484338df | ||
|
|
43c9216ef8 | ||
|
|
ec3a1c621d | ||
|
|
2edffafc2b | ||
|
|
627c8f36ff | ||
|
|
01ba4c157a | ||
|
|
6f790faed9 | ||
|
|
79ca0f7f81 | ||
|
|
8fd75228e4 | ||
|
|
dcbd04aacd | ||
|
|
870bcc76a5 | ||
|
|
c383178f7f | ||
|
|
97df2c8a28 | ||
|
|
6eda265bf2 | ||
|
|
147a600577 | ||
|
|
0dd5be8e7a | ||
|
|
8c42729e5b | ||
|
|
5e0b023a7b | ||
|
|
09f0ec5ebf | ||
|
|
c326c45d70 | ||
|
|
ebf6beaaf1 | ||
|
|
c91f5fc9b8 | ||
|
|
673c739909 | ||
|
|
3bc0de1762 | ||
|
|
9af2ad7cd9 | ||
|
|
12d7e69f07 | ||
|
|
142fdffb00 | ||
|
|
c4687b6816 | ||
|
|
9b161d251e | ||
|
|
a8f058c792 | ||
|
|
5ec8bae983 | ||
|
|
7f06e6567a | ||
|
|
3257cf799a | ||
|
|
70b8ed628d | ||
|
|
aadc0329d2 | ||
|
|
120044af80 | ||
|
|
dfc5263eec | ||
|
|
2646dfae7e | ||
|
|
7d087afbf6 | ||
|
|
59c59a6a70 | ||
|
|
97edfe8ae7 | ||
|
|
daf3ae68c3 | ||
|
|
df5d65dc2d | ||
|
|
4887aa33d9 | ||
|
|
b1af95ad20 | ||
|
|
865a11c628 | ||
|
|
7c2c5319f4 | ||
|
|
f62ed4db8a | ||
|
|
556fc353a8 | ||
|
|
8fd3cb855f | ||
|
|
448a24a975 | ||
|
|
d547198361 | ||
|
|
1143ae1c5a | ||
|
|
69c55a21a4 | ||
|
|
22c631cf88 | ||
|
|
a13868818c | ||
|
|
203160db4f | ||
|
|
61ae37a752 | ||
|
|
e752a7206a | ||
|
|
36b9ed450f | ||
|
|
75215bb143 | ||
|
|
8e625344e6 | ||
|
|
3ecd86dbc2 | ||
|
|
d95e044913 | ||
|
|
0717aae341 | ||
|
|
054d44f737 | ||
|
|
c04c8796f5 | ||
|
|
72e9f2f14e | ||
|
|
9e7c84a430 | ||
|
|
a04fe0a9dd | ||
|
|
9fbe9e7aea | ||
|
|
93bdad4c42 | ||
|
|
21008249ea | ||
|
|
ae5f3e425b | ||
|
|
fccef54cd6 | ||
|
|
d67f4023e1 | ||
|
|
4caafe99d3 | ||
|
|
e33dee192c | ||
|
|
02cd596139 | ||
|
|
d31b89072d | ||
|
|
b11f83c8b3 | ||
|
|
dbdae3c63f | ||
|
|
4a4590f86b | ||
|
|
25e0ae7f0d | ||
|
|
baefa90df9 | ||
|
|
c4f3c42957 | ||
|
|
3a22360a78 | ||
|
|
e4be4944d8 | ||
|
|
b2b4764f36 | ||
|
|
6ac916c785 | ||
|
|
831c8dc64e | ||
|
|
23ec2bbd7e | ||
|
|
945a61c0ed | ||
|
|
883badc1d8 | ||
|
|
135343a2e7 | ||
|
|
ff3b779fa9 | ||
|
|
24c8297df1 | ||
|
|
656b0220c4 | ||
|
|
399a9d43d3 | ||
|
|
ee16a4debc | ||
|
|
454d67d0a2 | ||
|
|
bf44d8124d | ||
|
|
5415a9478d | ||
|
|
62dd661395 | ||
|
|
e6b2144f74 | ||
|
|
9a2454037f | ||
|
|
2fc20adc23 | ||
|
|
ae5528b62f | ||
|
|
92432ad750 | ||
|
|
381db88e33 | ||
|
|
7abe13f23d | ||
|
|
a1f904b84d | ||
|
|
3d147c9e01 | ||
|
|
db23435337 | ||
|
|
7e35721a81 | ||
|
|
8ce4fcdeba | ||
|
|
0080c5b3d4 | ||
|
|
865c3f01ba | ||
|
|
37d0105319 | ||
|
|
c5cd587780 | ||
|
|
e881c47abf | ||
|
|
952020c8a5 | ||
|
|
db1f6fb6d1 | ||
|
|
66fa9d55a1 | ||
|
|
50224326aa | ||
|
|
a59e5c1ed3 | ||
|
|
5df7580a1e | ||
|
|
96223148c0 | ||
|
|
68a8fc97d2 | ||
|
|
ca28c927b2 | ||
|
|
9cf5344fc5 | ||
|
|
e5510620cc | ||
|
|
8e6b440f9a | ||
|
|
f396e1a253 | ||
|
|
39b55fb6e8 | ||
|
|
c91ed5600f | ||
|
|
35e6533986 | ||
|
|
a114fa9d0a | ||
|
|
017c4471ed | ||
|
|
c0e760d73e | ||
|
|
8f5eef94e4 | ||
|
|
c4a7eb7a2e | ||
|
|
9b7c4e279d | ||
|
|
c6fa0b2d95 | ||
|
|
a0cd3dd0e9 | ||
|
|
e578d888e3 | ||
|
|
e0680ccee0 | ||
|
|
6cc8551a6c | ||
|
|
b0225e48b8 | ||
|
|
a5df9e3728 | ||
|
|
ead96654be | ||
|
|
0430ed982d | ||
|
|
52e40b2fdc | ||
|
|
93265ae65c | ||
|
|
699db538b6 | ||
|
|
9ac540f7cf | ||
|
|
8206b5912d | ||
|
|
59d0a58e3a | ||
|
|
945ecdf64d | ||
|
|
e37a360d07 | ||
|
|
9881a061fe | ||
|
|
76729c3377 | ||
|
|
f880007639 | ||
|
|
eee2ce00e2 | ||
|
|
a729282cc1 | ||
|
|
061322d425 | ||
|
|
191e7999c0 | ||
|
|
c0239684ed | ||
|
|
d1095f854a | ||
|
|
902b383de7 | ||
|
|
ab7ab69f20 | ||
|
|
edc53a6bc9 | ||
|
|
1f0766c1d7 | ||
|
|
01f2e926b0 | ||
|
|
0a9e585c1d | ||
|
|
75e8103cdd | ||
|
|
356d06ef58 | ||
|
|
730bc73975 | ||
|
|
b4cb9fbc41 | ||
|
|
2c78428d9d | ||
|
|
88f4c7e104 | ||
|
|
3fb3368272 | ||
|
|
af435fa9bc | ||
|
|
06287aca40 | ||
|
|
6c04cb9a0b | ||
|
|
b5e623e5a1 | ||
|
|
5f7f81bdde | ||
|
|
9ca2f85b08 | ||
|
|
8b42e319e2 | ||
|
|
c8877b49a4 | ||
|
|
54a91f1b7e | ||
|
|
63d7ad788d | ||
|
|
e6619bc6c9 | ||
|
|
ac58bfdd63 | ||
|
|
a705bb3bf2 | ||
|
|
30e49d806a | ||
|
|
5f00329d44 | ||
|
|
ed33a0b00f | ||
|
|
57bbf14e1a | ||
|
|
02006fee2e | ||
|
|
466e2bf927 | ||
|
|
878517dcd2 | ||
|
|
b0ea9513e3 | ||
|
|
817c335f30 | ||
|
|
f8a1e9452e | ||
|
|
1097f35ed8 | ||
|
|
3dac71d0a5 | ||
|
|
993e407df2 | ||
|
|
c94e157b76 | ||
|
|
ca988ffc3a | ||
|
|
93bd6bdf01 | ||
|
|
ec600c8806 | ||
|
|
717c0999a5 | ||
|
|
c4d7ad8d0d | ||
|
|
6711bcf300 | ||
|
|
838b273d9c | ||
|
|
f64570ee84 | ||
|
|
94cb37075a | ||
|
|
6beb8625bf | ||
|
|
998225eb4e | ||
|
|
8de6b447ee | ||
|
|
85683f17c3 | ||
|
|
ffa8e2f25a | ||
|
|
faadebc67a | ||
|
|
748074ba9f | ||
|
|
884accd976 | ||
|
|
7377527f7c | ||
|
|
e44827823a | ||
|
|
1fdef32a4d | ||
|
|
da2dbfb108 | ||
|
|
f8230f9f59 | ||
|
|
71ca05c899 | ||
|
|
509ca60959 | ||
|
|
be91977725 | ||
|
|
22be375f1b | ||
|
|
0142ef1d3f | ||
|
|
6e4c49df61 | ||
|
|
4bf6b1bf0f | ||
|
|
d2ee3bf379 | ||
|
|
f1c182072b | ||
|
|
877ec94fc9 | ||
|
|
a5709d8bfc | ||
|
|
a5f3b0b554 | ||
|
|
3a0fd1c219 | ||
|
|
8e600311d0 | ||
|
|
ea6355a73d | ||
|
|
3cfb3a647e | ||
|
|
22af7fd342 | ||
|
|
c0f70d1a88 | ||
|
|
8b135cf47a | ||
|
|
e5126321ad | ||
|
|
982a1b75ed | ||
|
|
86c87ded89 | ||
|
|
66821b30a7 | ||
|
|
ecd3f124be | ||
|
|
41db5a9bf9 | ||
|
|
dfa966dbfc | ||
|
|
00a2459a86 | ||
|
|
d5b718b380 | ||
|
|
9e08291579 | ||
|
|
075cdfc810 | ||
|
|
b5f10ab7dc | ||
|
|
71f4c11fea | ||
|
|
8a623394da | ||
|
|
349a55fa33 | ||
|
|
83699e2011 | ||
|
|
462de32a5a | ||
|
|
630548644d | ||
|
|
d51b610f97 | ||
|
|
aea2a8a45d | ||
|
|
3b026b2f5f | ||
|
|
ecb23a1651 | ||
|
|
d7f0a718c3 | ||
|
|
f1876321c5 | ||
|
|
8940262618 | ||
|
|
69ab9f7c22 | ||
|
|
caf18dbaab | ||
|
|
7593202492 | ||
|
|
63449a8c26 | ||
|
|
0ef36b4e02 | ||
|
|
8e8d95eba4 | ||
|
|
49cc0f2e80 | ||
|
|
f7179f7a99 | ||
|
|
160c96ad1e | ||
|
|
86ce56b941 | ||
|
|
6952b265b5 | ||
|
|
38cc57e7fb | ||
|
|
7b975aaf93 | ||
|
|
3b634d66ca | ||
|
|
6fe2dcdf8e | ||
|
|
e2e76d3beb | ||
|
|
6cd2af7b72 | ||
|
|
6d289a583a | ||
|
|
667873bdbf | ||
|
|
2d4d11e476 | ||
|
|
a92dff05f8 | ||
|
|
cd07a9d846 | ||
|
|
cd86cc533c | ||
|
|
656f3fb249 | ||
|
|
5870251bdf | ||
|
|
ef0c22eae9 | ||
|
|
94aa3c1d3b | ||
|
|
a172d46c90 | ||
|
|
486ee5f41e | ||
|
|
d98872af4c | ||
|
|
20cc77573b | ||
|
|
7ae725c95d | ||
|
|
b1ba15995f | ||
|
|
fc1ee5bb55 | ||
|
|
6c52e5dddf | ||
|
|
3b4879446f | ||
|
|
b5f0081566 | ||
|
|
dcbfb6314e | ||
|
|
d2833ffded | ||
|
|
8cbade818f | ||
|
|
9ca89250b4 | ||
|
|
a984f5809f | ||
|
|
b6685af3ae | ||
|
|
63d864e1f0 | ||
|
|
6641bf4860 | ||
|
|
05cd788c13 | ||
|
|
c05bfaa9c4 | ||
|
|
f2d4194f37 | ||
|
|
10d12148dd | ||
|
|
ca29cd3b89 | ||
|
|
226eca7a9d | ||
|
|
49db85c09a | ||
|
|
7de73dbd33 | ||
|
|
fffdfd2721 | ||
|
|
54cc87132e |
@@ -1,2 +1,3 @@
|
|||||||
/memory/
|
/memory/
|
||||||
tickets/.ticket-backend.lock
|
tickets/.ticket-backend.lock
|
||||||
|
/workspace.db*
|
||||||
|
|||||||
@@ -1,66 +1,97 @@
|
|||||||
---
|
---
|
||||||
title: 'MCP local stdio integration architecture'
|
title: 'MCP local stdio integration roadmap'
|
||||||
state: 'active'
|
state: 'active'
|
||||||
created_at: '2026-06-10T07:48:45Z'
|
created_at: '2026-06-10T07:48:45Z'
|
||||||
updated_at: '2026-06-13T15:30:22Z'
|
updated_at: '2026-06-20T05:34:00Z'
|
||||||
|
linked_tickets: ['00001KTR81P9X', '00001KV0SP0TY', '00001KVHR3WRF', '00001KVHR3WRY', '00001KVHR3WS6', '00001KVHR3WSD', '00001KVHR3WSN', '00001KVHR3WSW']
|
||||||
---
|
---
|
||||||
|
|
||||||
## Objective
|
## Goal
|
||||||
|
|
||||||
Add MCP local stdio integration to Yoi without weakening Worker history, prompt-context, scoped tool permission, or Plugin/Feature layering invariants.
|
Add MCP local stdio integration to Yoi without weakening Worker history, prompt-context, scoped tool permission, or Plugin/Feature layering invariants.
|
||||||
|
|
||||||
MCP should be implemented as a protocol-backed integration layer on top of `pod::feature`. `pod::feature` supplies the contribution/lifecycle API substrate; MCP owns its own enablement, local server trust model, command/env/secret policy, and MCP-specific permissions. MCP is not the Plugin model, and Plugin permission policy is not implemented by feature-layer authority grants.
|
MCP is a protocol-backed integration layer on top of `pod::feature`. `pod::feature` supplies contribution/lifecycle/runtime-discovered registration substrate; MCP owns its own enablement, local server trust model, command/env/secret policy, and MCP-specific permission decisions. MCP is not the Plugin model, and Plugin permission policy is not implemented by feature-layer authority grants.
|
||||||
|
|
||||||
## Strategic direction
|
## Motivation / background
|
||||||
|
|
||||||
- Baseline the implementation on MCP specification `2025-11-25`.
|
Yoi needs to integrate with external capability providers without turning them into hidden context sources or bypassing ordinary Tool/Worker safety rules. MCP is useful because it can expose tools, resources, and prompts from local protocol servers, but those server-provided declarations and results are untrusted and must be normalized through Yoi's existing authority boundaries.
|
||||||
|
|
||||||
|
The first MCP slice should focus on local stdio servers because they are concrete enough to implement and debug while keeping remote auth, OAuth, Streamable HTTP, registry distribution, sampling, and elicitation out of the initial trust boundary.
|
||||||
|
|
||||||
|
A configured local MCP server runs as a local executable. Yoi feature authority does not sandbox that executable's OS-level side effects, so command/env/secret handling and explicit local trust policy are MCP-layer responsibilities rather than generic `pod::feature` grants.
|
||||||
|
|
||||||
|
## Strategy / design direction
|
||||||
|
|
||||||
|
- Baseline the initial implementation on MCP specification `2025-11-25`.
|
||||||
- Start with local stdio MCP servers only.
|
- Start with local stdio MCP servers only.
|
||||||
- Treat MCP server metadata, tools, resources, prompts, and results as untrusted content.
|
- Treat MCP server metadata, tools, resources, prompts, and results as untrusted content.
|
||||||
- Do not allow MCP resources/prompts to be hidden context injection.
|
- Do not allow MCP resources/prompts to become hidden context injection.
|
||||||
- They must be explicit tool operations with history records.
|
- They must be explicit tool operations with history records.
|
||||||
- Use the normal Yoi tool registry, PreToolCall permission, history, and bounded result paths.
|
- Use the normal Yoi ToolRegistry, PreToolCall permission, history, and bounded result paths.
|
||||||
- Do not add private MCP-only bypasses around Worker/tool invariants.
|
- Do not add private MCP-only bypasses around Worker/tool invariants.
|
||||||
- Keep sampling and elicitation fail-closed initially.
|
- Keep sampling and elicitation fail-closed initially.
|
||||||
- Keep Streamable HTTP, remote auth, OAuth, and MCP Registry/distribution out of the first slice.
|
- Keep Streamable HTTP, remote auth, OAuth, and MCP Registry/distribution out of the first slice.
|
||||||
- Treat local stdio server execution as an explicit MCP config/trust decision, not as a `pod::feature` authority grant.
|
- Treat local stdio server execution as an explicit MCP config/trust decision, not as a `pod::feature` authority grant.
|
||||||
- Document clearly that a configured local MCP server runs as a local executable; Yoi feature authority does not sandbox its OS-level side effects.
|
- Document clearly that a configured local MCP server runs as a local executable; Yoi feature authority does not sandbox its OS-level side effects.
|
||||||
|
|
||||||
## Layering decisions
|
### Layering decisions
|
||||||
|
|
||||||
- `pod::feature` is an API/contribution substrate.
|
- `pod::feature` is an API/contribution substrate.
|
||||||
- It owns contribution declarations, provider/service lifecycle hooks, diagnostics, dynamic registration plumbing, and integration with normal Worker/ToolRegistry paths.
|
- It owns contribution declarations, provider/service lifecycle hooks, diagnostics, runtime-discovered registration plumbing, and integration with normal Worker/ToolRegistry paths.
|
||||||
- It does not own Plugin permission policy or MCP server trust policy.
|
- It does not own Plugin permission policy or MCP server trust policy.
|
||||||
- Plugin is a user-facing package/config/runtime layer over `pod::feature`.
|
- Plugin is a user-facing package/config/runtime layer over `pod::feature`.
|
||||||
- Plugin permissions are Plugin-layer policy.
|
- Plugin permissions are Plugin-layer policy.
|
||||||
- Plugin package discovery/enablement must not be conflated with MCP local server execution.
|
- Plugin package discovery/enablement must not be conflated with MCP local server execution.
|
||||||
- MCP is a separate feature-backed integration layer.
|
- MCP is a separate feature-backed integration layer.
|
||||||
- MCP enablement, command/env/secret handling, server trust, and MCP-specific permission decisions live in MCP config/implementation.
|
- MCP enablement, command/env/secret handling, server trust, and MCP-specific permission decisions live in MCP config/implementation.
|
||||||
- MCP dynamic tools/resources/prompts are exposed through the feature API and ordinary Yoi tool paths.
|
- MCP provider-discovered tools/resources/prompts are exposed through the feature API and ordinary Yoi tool paths.
|
||||||
|
|
||||||
## Work breakdown
|
### Concrete implementation tickets
|
||||||
|
|
||||||
1. `00001KTR81P9X` — Extend `pod::feature` API for protocol-backed external providers.
|
Completed prerequisites:
|
||||||
- provider/service lifecycle
|
|
||||||
- startup discovery and dynamic contribution registration
|
|
||||||
- bounded refresh semantics
|
|
||||||
- metadata/result normalization
|
|
||||||
- no feature-layer authority model for MCP/Plugin permissions
|
|
||||||
2. `00001KTR82RB7` — Implement MCP `2025-11-25` local stdio server bridge.
|
|
||||||
- explicit MCP config and trust model
|
|
||||||
- initialize/capability negotiation
|
|
||||||
- tools/resources/prompts list/call/read/get
|
|
||||||
- bounded result serialization
|
|
||||||
- list-changed diagnostics/refresh behavior
|
|
||||||
3. `00001KV0SP0TY` — Remove feature-layer HostAuthority model.
|
|
||||||
- remove authority/grant terminology from `pod::feature`
|
|
||||||
- keep real permission/trust policy in owning Plugin/MCP/manifest/tool layers
|
|
||||||
4. Later follow-ups, if needed.
|
|
||||||
- richer MCP tasks / task-support integration
|
|
||||||
- remote/HTTP transports
|
|
||||||
- OAuth / registry / package distribution
|
|
||||||
- Plugin package/runtime alignment, if an explicit MCP/plugin bridge is later approved
|
|
||||||
|
|
||||||
## Success criteria
|
- `00001KTR81P9X` — Extend `pod::feature` API for external protocol-backed capability providers.
|
||||||
|
- `00001KV0SP0TY` — Remove feature-layer HostAuthority model.
|
||||||
|
|
||||||
|
Concrete MCP implementation sequence:
|
||||||
|
|
||||||
|
1. `00001KVHR3WRF` — MCP local stdio server config and trust policy.
|
||||||
|
- explicit config, command/env/secret redaction, local executable trust boundary, no auto-start.
|
||||||
|
2. `00001KVHR3WRY` — MCP stdio JSON-RPC lifecycle client.
|
||||||
|
- subprocess lifecycle, initialize/capability negotiation, diagnostics, shutdown.
|
||||||
|
3. `00001KVHR3WS6` — MCP tools/list registration into ToolRegistry.
|
||||||
|
- provider-discovered tools, stable namespacing, schema validation, untrusted metadata normalization, no tools/call yet.
|
||||||
|
4. `00001KVHR3WSD` — MCP tools/call execution through ordinary Tool path.
|
||||||
|
- PreToolCall gate before server call, bounded result serialization, history path.
|
||||||
|
5. `00001KVHR3WSN` — MCP resources/prompts as explicit tool operations.
|
||||||
|
- resources/list/read and prompts/list/get without hidden context injection.
|
||||||
|
6. `00001KVHR3WSW` — MCP list_changed notification handling.
|
||||||
|
- deterministic safe refresh/diagnostic behavior without breaking tool schema or prompt-cache invariants.
|
||||||
|
|
||||||
|
The old broad implementation Ticket `00001KTR82RB7` is superseded by this sequence and should not be used as an implementation work item.
|
||||||
|
|
||||||
|
### Terminology
|
||||||
|
|
||||||
|
Use `runtime-discovered` or `provider-discovered` for MCP tools/resources/prompts discovered from `tools/list`, `resources/list`, or `prompts/list`. Avoid `dynamic tools` / `dynamic registry` in new MCP design prose because those phrases imply that model-visible tool schemas may change during an active LLM run.
|
||||||
|
|
||||||
|
The intended invariant is:
|
||||||
|
|
||||||
|
```text
|
||||||
|
provider-discovered at startup / provider initialization;
|
||||||
|
registered into the ordinary ToolRegistry before model exposure;
|
||||||
|
run-stable for the duration of a model request/run;
|
||||||
|
refreshed only at a safe boundary or reported as a diagnostic.
|
||||||
|
```
|
||||||
|
|
||||||
|
### Later follow-ups
|
||||||
|
|
||||||
|
- Richer MCP task/task-support integration if ordinary tool-call fallback is insufficient.
|
||||||
|
- Streamable HTTP transport.
|
||||||
|
- OAuth / remote auth.
|
||||||
|
- Registry/package distribution.
|
||||||
|
- Explicit MCP/Plugin bridge only if separately approved; do not conflate Plugin packages with MCP local server execution.
|
||||||
|
|
||||||
|
## Success criteria / exit conditions
|
||||||
|
|
||||||
- A local mock MCP server can be configured explicitly and initialized.
|
- A local mock MCP server can be configured explicitly and initialized.
|
||||||
- Discovered MCP tools appear as ordinary Yoi tools with stable namespacing.
|
- Discovered MCP tools appear as ordinary Yoi tools with stable namespacing.
|
||||||
@@ -70,3 +101,11 @@ MCP should be implemented as a protocol-backed integration layer on top of `pod:
|
|||||||
- Secret values, command/env details, and server diagnostics are redacted where required.
|
- Secret values, command/env details, and server diagnostics are redacted where required.
|
||||||
- Local server trust boundary is documented: Yoi does not sandbox the configured executable through feature authority.
|
- Local server trust boundary is documented: Yoi does not sandbox the configured executable through feature authority.
|
||||||
- Feature, Plugin, and MCP permission/trust responsibilities are documented as separate layers.
|
- Feature, Plugin, and MCP permission/trust responsibilities are documented as separate layers.
|
||||||
|
|
||||||
|
## Decision context
|
||||||
|
|
||||||
|
- MCP is not the Plugin model; it is a protocol-backed integration layer using `pod::feature` substrate.
|
||||||
|
- `pod::feature` should provide contribution/lifecycle/runtime-discovered registration plumbing, not MCP server trust policy or Plugin package permission policy.
|
||||||
|
- MCP resources and prompts must never be hidden context injection. They are explicit operations recorded through ordinary history/tool paths.
|
||||||
|
- Provider-discovered tools are discovered at startup/provider initialization and registered before model exposure; model-visible schemas remain run-stable during a request/run.
|
||||||
|
- Local stdio server execution is a user/config trust decision. Yoi does not sandbox the local executable merely because it is configured through MCP.
|
||||||
|
|||||||
@@ -0,0 +1,101 @@
|
|||||||
|
---
|
||||||
|
title: "Plugin platform roadmap"
|
||||||
|
state: "active"
|
||||||
|
created_at: "2026-06-19T13:18:58Z"
|
||||||
|
updated_at: "2026-06-24T19:55:00Z"
|
||||||
|
linked_tickets: ["00001KV5R5V2S", "00001KV5W3PHA", "00001KV5W3PHW", "00001KV5W3PJ3", "00001KVFD3YSV", "00001KVFDX9AF", "00001KVFDX9AY", "00001KVG0HR96", "00001KVXHVCR5", "00001KVXK0WD3", "00001KVXK0WDH", "00001KVXK0WDQ", "00001KVXK0WDX", "00001KVXK0WE4", "00001KVXK0WEA"]
|
||||||
|
---
|
||||||
|
|
||||||
|
## Goal
|
||||||
|
|
||||||
|
Build Yoi's Plugin platform as a coherent extension system: packages are discovered and inspected safely, enabled explicitly, registered through typed Plugin surfaces, executed in a sandboxed runtime, constrained by Plugin-layer grants, and authored through SDK/templates rather than raw runtime ABI details.
|
||||||
|
|
||||||
|
The long-term platform goal is not merely to run Wasm. It is to make Plugin packages a durable, inspectable, permissioned, and authorable extension layer for Tools first, then host APIs (`https`, `fs`), and later Service / Ingress surfaces when concrete needs justify them.
|
||||||
|
|
||||||
|
## Motivation / background
|
||||||
|
|
||||||
|
The current Plugin foundation is already substantial:
|
||||||
|
|
||||||
|
- package discovery and explicit enablement resolver;
|
||||||
|
- Tool surface registration through the ordinary ToolRegistry/model-visible schema path;
|
||||||
|
- minimal sandboxed WASM Tool execution;
|
||||||
|
- Plugin permission grant enforcement;
|
||||||
|
- follow-up Tickets for read-only inspection CLI, `https`, `fs`, and Component Model migration.
|
||||||
|
|
||||||
|
The remaining work must be kept as one roadmap because the pieces constrain each other:
|
||||||
|
|
||||||
|
- Plugin authoring needs an SDK/PDK and examples, not raw pointer/length Wasm ABI hand-coding.
|
||||||
|
- `https` and `fs` host APIs must be grant-gated and shaped so they can move cleanly to typed Component Model interfaces.
|
||||||
|
- Diagnostics (`yoi plugin list/show`) are needed before the system becomes harder to debug.
|
||||||
|
- Component Model adoption should guide new host API design before a custom raw ABI becomes entrenched.
|
||||||
|
- Service / Ingress are useful for bridge-style integrations, but should come after Tool runtime, diagnostics, and host API policy are stable.
|
||||||
|
|
||||||
|
Research of common Wasm extension systems points to the same pattern: mature systems combine a package manifest, explicit capabilities, a sandbox runtime, host-provided capability APIs, language SDK/PDK bindings, templates/examples, inspection/check tooling, and versioned interfaces.
|
||||||
|
|
||||||
|
## Strategy / design direction
|
||||||
|
|
||||||
|
- Keep Plugin as a user-facing package/config/runtime layer above lower-level `pod::feature` substrate.
|
||||||
|
- `pod::feature` provides contribution/registration substrate.
|
||||||
|
- Plugin owns package discovery, enablement, grant policy, runtime selection, authoring UX, and user-facing diagnostics.
|
||||||
|
- Preserve authority boundaries.
|
||||||
|
- Package discovery is read-only inventory.
|
||||||
|
- Package presence never registers a Tool/Hook, executes Wasm, starts a Service, reads files, opens network, or injects context.
|
||||||
|
- Explicit enablement and Plugin grants are required before registration/execution/host API use.
|
||||||
|
- Tool calls/results continue through ordinary ToolRegistry and Worker history paths.
|
||||||
|
- Treat Component Model as the active Plugin runtime shape before public release.
|
||||||
|
- New typed Plugin host APIs should be designed in WIT-compatible terms.
|
||||||
|
- `runtime.kind = "wasm-component"` is the current Plugin runtime authority for new work.
|
||||||
|
- The earlier `yoi-plugin-wasm-1` raw core-Wasm compatibility bridge is retired from the active roadmap because Plugin has not been publicly released and compatibility would preserve the wrong boundary.
|
||||||
|
- Sequence the platform in usable layers:
|
||||||
|
1. Package discovery / explicit enablement / digest-pinned restore. Completed foundation.
|
||||||
|
2. Tool surface registration. Completed foundation.
|
||||||
|
3. Minimal WASM Tool execution. Completed foundation.
|
||||||
|
4. Permission grants. Completed foundation.
|
||||||
|
5. Read-only Plugin CLI inspection (`yoi plugin list/show`) for debugging discovery/enablement/grants/runtime metadata.
|
||||||
|
6. `https` and `fs` host APIs for Tool Plugins, grant-gated and WIT-compatible.
|
||||||
|
7. Remove the raw core-Wasm compatibility bridge and reject legacy runtime manifests.
|
||||||
|
8. Component Model runtime and authoring model become the only active Plugin runtime path.
|
||||||
|
9. Guest SDK/PDK, examples, `check`/`pack`/`new` authoring tooling target Component Model only.
|
||||||
|
10. Service / Ingress runtime is developed as host-managed lifecycle, event queue, output command, and diagnostics slices.
|
||||||
|
11. WebSocket support for long-lived integrations is host-owned connection driver + ingress event delivery + output command, not Plugin-owned polling with `recv(timeout)`.
|
||||||
|
- Keep Discord-style bridge goals split into two stages.
|
||||||
|
- Outbound Discord/webhook Tool is possible after `https`.
|
||||||
|
- Bidirectional Discord bridge requires Service + Ingress + WebSocket or inbound HTTP and host routing policy.
|
||||||
|
|
||||||
|
## Current implementation split
|
||||||
|
|
||||||
|
The broad Plugin runtime redesign is tracked by `00001KVXHVCR5` as context only; implementation should proceed through concrete Tickets instead of routing that umbrella as a single coding task.
|
||||||
|
|
||||||
|
1. `00001KVXK0WD3` Remove legacy raw WASM Plugin runtime.
|
||||||
|
- Deletes the active `LegacyToolAdapter` / raw-Wasm execution path.
|
||||||
|
2. `00001KVXK0WDH` Reject legacy Plugin runtime in manifest and CLI diagnostics.
|
||||||
|
- Makes `plugin.toml`, `yoi plugin check/list/show`, docs, and fixtures reflect Component Model only runtime authority.
|
||||||
|
3. `00001KVXK0WDQ` Define Plugin Service lifecycle and ingress queue runtime.
|
||||||
|
- Adds host-managed lifecycle, bounded queue, serial dispatch, backpressure, timeout, and diagnostics.
|
||||||
|
4. `00001KVXK0WDX` Add Plugin service output command model.
|
||||||
|
- Lets service handlers request side effects as grant-checked commands rather than ambient authority.
|
||||||
|
5. `00001KVXK0WE4` Add host-owned WebSocket driver for Plugin services.
|
||||||
|
- Converts incoming WS frames into ingress events and sends outbound frames through output commands.
|
||||||
|
6. `00001KVXK0WEA` Update Plugin WIT PDK templates for service event runtime.
|
||||||
|
- Aligns authoring API, WIT, PDK, templates, and docs with the new event/command execution model.
|
||||||
|
|
||||||
|
## Success criteria / exit conditions
|
||||||
|
|
||||||
|
- Users can inspect Plugin discovery/enablement/grant/runtime state through a read-only CLI without executing Plugin code.
|
||||||
|
- Plugin authors can build a Tool Plugin without writing raw memory/pointer ABI plumbing.
|
||||||
|
- Tool Plugins can safely call grant-gated `https` and `fs` host APIs.
|
||||||
|
- Component Model is the only active Plugin runtime path, with WIT-compatible host API types and measured packaging/runtime impact.
|
||||||
|
- Plugin grants remain authoritative over registration, execution, and host API calls.
|
||||||
|
- Plugin diagnostics explain missing package, invalid manifest, digest/version mismatch, missing grant, rejected schema, runtime mismatch, legacy runtime rejection, and unsupported host API cases safely.
|
||||||
|
- Raw core-Wasm Plugin compatibility is removed before public release; tests and docs no longer treat it as a current runtime.
|
||||||
|
- Documentation covers package format, Component Model runtime, host API authority, authoring SDK/templates, Service/Ingress event runtime, and operational debugging.
|
||||||
|
- Service/Ingress work is host-managed: services have lifecycle/status, ingress uses bounded queues, side effects are output commands, and WebSocket integrations use host-owned connection drivers.
|
||||||
|
|
||||||
|
## Decision context
|
||||||
|
|
||||||
|
- This Objective is roadmap context, not Ticket authority. Implementation still requires reading concrete Ticket bodies, threads, artifacts, and relations.
|
||||||
|
- Component Model direction supersedes Yoi's custom raw ABI as both long-term and current active Plugin runtime authority before public release.
|
||||||
|
- `https` / `fs` work should avoid choices that conflict with later WIT typed interfaces.
|
||||||
|
- Guest SDK work targets Component Model directly; raw ABI wrappers are not a supported transitional authoring path.
|
||||||
|
- Plugin and MCP remain separate. Component Model adoption for Plugin does not imply MCP server execution, MCP prompt/resource injection, or MCP trust policy changes.
|
||||||
|
- Plugin surfaces remain Tool / Hook / Service / Ingress; outbound side effects are Tool metadata and host API grants, not a separate surface.
|
||||||
@@ -0,0 +1,249 @@
|
|||||||
|
---
|
||||||
|
title: "Team workspace control plane and runner architecture"
|
||||||
|
state: "active"
|
||||||
|
created_at: "2026-06-20T14:26:29Z"
|
||||||
|
updated_at: "2026-06-21T18:10:00Z"
|
||||||
|
linked_tickets: ["00001KVMFFYVX"]
|
||||||
|
---
|
||||||
|
|
||||||
|
## Goal
|
||||||
|
|
||||||
|
Yoi を、単一のローカル開発ディレクトリで動くエージェント実行ツールから、チームで作業・判断・実行結果を管理できるワークスペース基盤へ発展させる。
|
||||||
|
|
||||||
|
この Objective の中心は、Web から扱える管理システムを作り、その管理システムにローカル実行環境・リモート実行環境・将来のクラウド実行環境を接続できるようにすることである。管理システムは Ticket、Objective、Memory、Knowledge、Run、Artifact、Runner の正本を持つ。実行環境はその管理システムから仕事を受け取り、コード取得、作業用ディレクトリ作成、エージェント実行、検証、結果報告を行う。
|
||||||
|
|
||||||
|
この Objective は Git ホスティングサービスを作るものではない。Git は重要な Repository provider として扱うが、Yoi の Workspace は Git Repository root と同じものにしない。Yoi が作るべきものは、コード・ドキュメント・データ・成果物などの Repository と実行環境を接続しながら、人間とエージェントの作業、Ticket lifecycle、Memory/Knowledge、検証証跡、実行環境配置を管理するチームワークスペースである。
|
||||||
|
|
||||||
|
## Glossary
|
||||||
|
|
||||||
|
この Objective では、以下の語をこの意味で使う。
|
||||||
|
|
||||||
|
- Workspace: チームまたはプロジェクトの管理単位。Ticket、Objective、Memory、Knowledge、Run、Artifact、Policy、Actor、Repository を持つ。Git Repository root ではない。
|
||||||
|
- Control plane: Workspace の正本を持ち、Web UI / API / CLI から操作される管理システム。
|
||||||
|
- Runner: Control plane から仕事を受け取り、実際にエージェントやツールを動かす実行環境。最初はローカルマシン上の runner、後でリモート runner やクラウド runner を追加する。
|
||||||
|
- Repository: Workspace に接続される source/storage。コード、ドキュメント、local directory、object storage、artifact store、dataset などを含む。Git Repository も Repository の一種であり、基本的には filesystem path ではなく URI / URL で識別する。
|
||||||
|
- Repository provider: Repository の種類ごとの実装。Git、local filesystem、object store、artifact store、将来の non-Git VCS など。
|
||||||
|
- RepositoryPoint: Repository 内の特定地点。Git commit/ref/path、object store version/prefix、file snapshot/path など、provider ごとの revision/ref/snapshot/path を表す。
|
||||||
|
- Execution Workspace: Runner が Run のために作る作業用ディレクトリや container filesystem。1 つ以上の RepositoryPoint から materialize される。Git worktree、clone、sparse checkout などはこれを作る手段である。
|
||||||
|
- Ticket: チームで扱う作業単位。目的、要件、判断、議論、完了条件、関係、証跡を持つ。
|
||||||
|
- Objective: 複数の Ticket を束ねる長期目標や設計方針。
|
||||||
|
- Run: Ticket や Objective に対して行われた具体的な実行試行。どの Runner が、どの Execution Workspace で、何を実行し、どんな結果になったかを持つ。
|
||||||
|
- Artifact: Run や Ticket に紐づく成果物や証跡。diff、log、validation result、review result、report など。
|
||||||
|
- Memory: エージェントやユーザーが再利用するための要約された文脈。Ticket や Run の正本ではない。
|
||||||
|
- Knowledge: 保守された知識や設計判断。Memory より人間が維持する資料に近い。
|
||||||
|
- Actor: 人間、エージェント、システム、外部サービスなど、Workspace 上で操作や発言を行う主体。
|
||||||
|
|
||||||
|
## Motivation / background
|
||||||
|
|
||||||
|
現在の Yoi は、ローカルの `.yoi` ディレクトリ、ローカルプロセス、Ticket ファイル、ワークツリー運用によって、自分自身の開発に使えるエージェント実行環境になっている。しかし、チーム利用、Web UI、リモート実行、クラウド実行、最終的な SaaS 提供を考えると、次の前提を変える必要がある。
|
||||||
|
|
||||||
|
- Workspace を Git Repository root と同一視しない。
|
||||||
|
- ローカル filesystem 上の `.yoi` を、長期的なチーム用正本 store にしない。
|
||||||
|
- Ticket をローカル作業メモではなく、チームの作業調整 record にする。
|
||||||
|
- Ticket と実行試行を分ける。実行試行は Run として記録する。
|
||||||
|
- 管理システムと実行環境を分ける。
|
||||||
|
- まず Web から Ticket、Objective、Memory、Knowledge、Run、Artifact、Runner state を見られるようにする。
|
||||||
|
- 最初はローカルマシンを Runner として使い、後でリモート Runner、クラウド Runner、runner pool、resource allocation、quota、billing、sandboxing に拡張する。
|
||||||
|
- Git ホスティング機能を取り込むのではなく、Git Repository / worktree / clone は Repository provider と Execution Workspace materialization の手段として扱う。
|
||||||
|
|
||||||
|
OSS として Control plane、Runner、Web frontend、protocol を公開しつつ、managed service では hosted control plane、runner fleet、リソース柔軟性、team auth、backup、audit、availability、multi-tenant operations で価値を出す。
|
||||||
|
|
||||||
|
## Strategy / design direction
|
||||||
|
|
||||||
|
### 1. Control plane を先に作る
|
||||||
|
|
||||||
|
Team Workspace の正本は server-side control plane に置く。`.yoi` は local backend、single-user/self-hosted compatibility、offline/export/import、runner-local projection、migration bridge として残せるが、multi-user SaaS の正本とはみなさない。
|
||||||
|
|
||||||
|
Control plane は Ticket、Objective、Memory、Knowledge、Run、Artifact、Actor、Permission、Audit、Runner state を管理する。Web UI、CLI、TUI、将来の desktop client は、この Control plane を操作する client であり、別の正本 store を持たない。
|
||||||
|
|
||||||
|
### 2. Workspace と Repository を同一視しない
|
||||||
|
|
||||||
|
Workspace はチームまたはプロジェクトの作業管理単位である。Repository は Workspace に接続される source/storage である。Git Repository は Repository の一種にすぎない。
|
||||||
|
|
||||||
|
1 つの Workspace は複数の Repository を持てる。Repository は filesystem path ではなく URI / URL で識別する。例として `git+https://...`、`file://...`、`s3://...`、`artifact://...`、将来の VCS provider URI などを扱えるようにする。
|
||||||
|
|
||||||
|
Ticket と Objective は Repository 配下に置かず、Workspace 配下に平たく持つ。Ticket は必要に応じて対象 Repository、ref selector、path、必要 capability を持つ。Objective は複数 Ticket にまたがる target default / scope hint を持てるが、Repository の所有物にはしない。
|
||||||
|
|
||||||
|
Run は Ticket の target selector を具体的な RepositoryPoint に解決し、その RepositoryPoint から Execution Workspace を materialize する。Git worktree 相当の機能は、この Execution Workspace を作るための実装戦略として扱う。
|
||||||
|
|
||||||
|
短期的には Git を主な Repository provider とする。ただし Yoi の authority model を Git object、Git branch、Git Repository root、worktree path に固定しない。Orchestration は Git そのものではなく、`resolve_ref`、`materialize`、`diff`、`patch`、`commit`、`merge` などの Repository capability に依存する。
|
||||||
|
|
||||||
|
### 3. Ticket を team coordination record にする
|
||||||
|
|
||||||
|
Ticket は実行そのものではない。Ticket は「何を、なぜ、どの条件で完了とみなすか」を持つ。Ticket は Workspace に平たく所属し、Repository には所属しない。コードやドキュメントを対象にする Ticket は、対象 Repository / ref selector / path / intent を target として持つ。
|
||||||
|
|
||||||
|
Ticket target は intent/selector であり、実行再現性のための immutable point ではない。Run が target selector を concrete RepositoryPoint に解決し、実際にどの revision/snapshot を materialize したかを記録する。
|
||||||
|
|
||||||
|
```text
|
||||||
|
Ticket
|
||||||
|
-> target selectors: Repository + ref selector + path + intent
|
||||||
|
-> Run / Attempt
|
||||||
|
-> resolved RepositoryPoint
|
||||||
|
-> Execution Workspace
|
||||||
|
-> Artifact / Evidence
|
||||||
|
-> Review / Decision
|
||||||
|
-> Audit / Notification
|
||||||
|
```
|
||||||
|
|
||||||
|
Target 例:
|
||||||
|
|
||||||
|
```text
|
||||||
|
Ticket targets:
|
||||||
|
- repository: main-code
|
||||||
|
role: primary
|
||||||
|
ref: develop
|
||||||
|
paths: ["crates/pod/"]
|
||||||
|
intent: change
|
||||||
|
- repository: docs
|
||||||
|
role: related
|
||||||
|
ref: main
|
||||||
|
paths: ["docs/development/"]
|
||||||
|
intent: read
|
||||||
|
|
||||||
|
Run inputs:
|
||||||
|
- repository: main-code
|
||||||
|
requested_ref: develop
|
||||||
|
resolved_point: git commit abc123
|
||||||
|
mount: /workspace/main-code
|
||||||
|
```
|
||||||
|
|
||||||
|
Ticket には次の概念が必要になる。
|
||||||
|
|
||||||
|
- Actor identity: human / agent / system / service account.
|
||||||
|
- Assignment / owner / reviewer / watcher.
|
||||||
|
- Typed thread events: comment, decision, plan, review, implementation report, state transition.
|
||||||
|
- Linked Objective / Artifact / Run / Repository / RepositoryPoint / Execution Workspace.
|
||||||
|
- Permission / visibility.
|
||||||
|
- Audit trail.
|
||||||
|
- Notification / mention.
|
||||||
|
- Board / queue / planning / review / done / archived views.
|
||||||
|
- Conflict handling and concurrent editing policy.
|
||||||
|
|
||||||
|
### 4. Memory / Knowledge の本格再設計は後回しにする
|
||||||
|
|
||||||
|
Memory / Knowledge は Ticket / Run / Artifact のコピーではない。再利用可能な文脈、方針、学習された制約、保守された知識として扱う。ただし、Memory の意味論・抽出・承認・検索・staleness 処理を今この Objective で先に作り込まない。
|
||||||
|
|
||||||
|
理由は、Memory の正しい設計が Workspace control plane の record model、Actor / visibility / permission、Ticket と Run の分離、Artifact / evidence、RepositoryPoint、Runner に渡す context の監査方法に依存するためである。これらが固まる前に Memory schema だけを作ると、local `.yoi` 前提や現行 agent runtime 前提に引っ張られ、後で再設計が必要になる。
|
||||||
|
|
||||||
|
この Objective では、Memory / Knowledge について以下の platform contract だけを維持する。
|
||||||
|
|
||||||
|
- Memory / Knowledge は Control plane が扱う record だが、Ticket / Run / Artifact の authority を置き換えない。
|
||||||
|
- 将来、Memory / Knowledge の canonical storage は Workspace control plane 側に置く。
|
||||||
|
- local `.yoi` memory は compatibility、offline/export/import、runner-local projection、migration bridge として扱う。
|
||||||
|
- Personal Memory、Workspace Memory、Run Summary、Maintained Knowledge は分離が必要である。
|
||||||
|
- Generated Memory には provenance、visibility、approval、audit が必要である。
|
||||||
|
- Runner / agent に渡した Memory/Knowledge context は、将来 ContextPack などとして Run に記録できる必要がある。
|
||||||
|
|
||||||
|
本格的な Memory 再設計は、Memory の保存先を Workspace backend / control plane record に移すタイミングで回収する。それまでは低リスクな観察、問題例の収集、既存 local memory の互換維持に留める。
|
||||||
|
|
||||||
|
### 5. 管理システムと実行環境を弱結合にする
|
||||||
|
|
||||||
|
Control plane は正本と調整を持つ。Runner は実行を担当する。
|
||||||
|
|
||||||
|
初期形:
|
||||||
|
|
||||||
|
```text
|
||||||
|
Web UI / Control Plane
|
||||||
|
-> Runner connection
|
||||||
|
-> Local machine runner
|
||||||
|
-> Existing Yoi runtime, tools, working copy, build/test commands
|
||||||
|
```
|
||||||
|
|
||||||
|
この段階では、現在ローカル管理画面が行っている Ticket 選択、エージェント起動、レビュー起動、作業用 checkout 作成、検証実行、結果表示を、Web/control plane から local runner に対して実行できるようにする。
|
||||||
|
|
||||||
|
その後で、remote runner、self-hosted runner、hosted cloud runner、runner pool、resource allocation、quota、billing、sandbox、network policy、secret distribution を追加する。
|
||||||
|
|
||||||
|
```text
|
||||||
|
Phase 1: Web control plane + local runner
|
||||||
|
Phase 2: Remote/self-hosted runner
|
||||||
|
Phase 3: Hosted cloud runner fleet
|
||||||
|
Phase 4: Resource allocation / scheduling / quotas / billing / isolation
|
||||||
|
```
|
||||||
|
|
||||||
|
### 6. Web frontend を先に作る
|
||||||
|
|
||||||
|
Desktop app は対応コストが高いので、まず Web frontend を primary UI とする。
|
||||||
|
|
||||||
|
- Web: チームで使う主要 UI。
|
||||||
|
- CLI: automation、scripting、local operations。
|
||||||
|
- TUI/local panel: local runner cockpit、fallback、dogfooding surface。
|
||||||
|
- Future desktop: Web/control-plane model が安定した後に検討する optional client。
|
||||||
|
|
||||||
|
Web UI は Ticket、Objective、Memory、Knowledge、Run、Runner、Artifact を扱う。UI の都合で正本を二重化しない。
|
||||||
|
|
||||||
|
### 7. 多重起動コストと runtime placement を見直す
|
||||||
|
|
||||||
|
Cloud/remote execution を成立させるには、多数のエージェント実行を安く管理できる必要がある。logical agent session と runtime process/resource placement を分ける。
|
||||||
|
|
||||||
|
初期 Workspace DB では、Worker を canonical table として永続化しない。Host / Worker 一覧は backend-local runtime inspection や将来の Host protocol から逐次取得する live view とし、Ticket に関わった Worker は Ticket thread events と WorkerRef snapshot / TicketWorkerLink として記録する。
|
||||||
|
|
||||||
|
Worker の一元管理、データ永続化、アーカイブは将来的には必要になる。これは Host protocol、remote/self-hosted/hosted worker lifecycle、worker identity、retention policy、audit requirements が固まった後に、dedicated Worker registry / archive model として追加する。v0 で Pod metadata の代替として Worker table を作らない。
|
||||||
|
|
||||||
|
検討対象:
|
||||||
|
|
||||||
|
- Agent identity と process/runtime placement の分離。
|
||||||
|
- Provider client、tool registry、resource cache の共有可能性。
|
||||||
|
- Prompt/resource/profile resolution cache。
|
||||||
|
- Model call multiplexing and scheduling。
|
||||||
|
- Tool execution sandbox reuse。
|
||||||
|
- Plugin instance / Service runtime との統合。
|
||||||
|
- Session/event stream と runtime lifecycle の分離。
|
||||||
|
- Runner-local cache、checkout reuse、build cache、dependency cache。
|
||||||
|
|
||||||
|
## Initial phases / candidate tickets
|
||||||
|
|
||||||
|
1. **Vocabulary / architecture record**
|
||||||
|
- Workspace / Repository / RepositoryPoint / Execution Workspace / Runner / Control Plane / Run / Ticket / Memory / Knowledge の用語と境界を固める。
|
||||||
|
2. **Team-space canonical data model**
|
||||||
|
- Ticket / Objective / Target / Run / Artifact / Actor / Permission / Audit / Memory / Knowledge の entity/event model を設計する。
|
||||||
|
3. **Ticket and Run separation**
|
||||||
|
- Ticket lifecycle と execution attempt / orchestration run / validation run を分離し、Ticket thread と Run evidence の責務を明確化する。
|
||||||
|
4. **Memory storage migration boundary**
|
||||||
|
- Memory / Knowledge の本格再設計は後回しにし、まずは Workspace backend に移す時の platform contract、compatibility/cache/export 方針、将来の provenance / visibility / approval 要件だけを固定する。
|
||||||
|
5. **Control plane backend architecture**
|
||||||
|
- local `.yoi` backend と server-side canonical backend の境界、migration/export/import、compatibility mode を設計する。
|
||||||
|
6. **Web control plane MVP design**
|
||||||
|
- read-only Ticket / Objective / Memory / Knowledge / Runner state UI/API の範囲を決める。
|
||||||
|
7. **Local runner protocol design**
|
||||||
|
- Web/control plane から local runner に安全な操作を送る protocol と authority boundary を設計する。
|
||||||
|
8. **Repository and Execution Workspace materialization model**
|
||||||
|
- Repository URI、Repository provider capability、RepositoryPoint resolution、Git worktree / clone / sparse checkout / future source backend を runner-side strategy として抽象化する。
|
||||||
|
9. **Remote/hosted runner foundation**
|
||||||
|
- runner registration, heartbeat, capability advertisement, job assignment, logs/events, secrets, sandbox/resource policy を設計する。
|
||||||
|
|
||||||
|
## Non-goals
|
||||||
|
|
||||||
|
- Git hosting service を作ること。
|
||||||
|
- `.yoi` filesystem をそのまま SaaS canonical store にすること。
|
||||||
|
- 最初から full hosted cloud execution を作ること。
|
||||||
|
- local execution / CLI / TUI / local panel を捨てること。
|
||||||
|
- Ticket を単なる issue tracker clone にすること。
|
||||||
|
- Memory を Ticket/Run audit log の代替にすること。
|
||||||
|
- Web UI のために core authority を二重化すること。
|
||||||
|
- hidden server state を LLM context に直接注入すること。
|
||||||
|
- multi-tenant auth/billing/secret/security を shortcut して実装すること。
|
||||||
|
|
||||||
|
## Success criteria / exit conditions
|
||||||
|
|
||||||
|
- Workspace / Repository / RepositoryPoint / Execution Workspace / Runner / Control Plane / Run / Ticket / Memory / Knowledge の境界が文書化されている。
|
||||||
|
- Ticket が team coordination record として、target selector / Run / Artifact / Actor / Permission / Audit と分離された model を持つ。
|
||||||
|
- `.yoi` local backend は compatibility/local backend として整理され、server-side canonical backend の設計を阻害しない。
|
||||||
|
- Web UI/API が Ticket / Objective / Runner state を中心とした read-only view を提供できる設計または MVP を持つ。Memory / Knowledge は既存 record の表示または将来 placeholder に留め、本格再設計をこの段階の必須条件にしない。
|
||||||
|
- Control plane から local runner に対して、現在のローカル管理画面相当の安全な操作を実行できる design/protocol がある。
|
||||||
|
- Git Repository root に依存しない Workspace model があり、Git Repository は Repository provider の一種として扱われている。
|
||||||
|
- Ticket と Objective は Workspace 配下に平たく存在し、Repository への所属ではなく target selector / scope hint で対象を表現する。
|
||||||
|
- Git worktree 相当は Execution Workspace materialization strategy として扱われ、Run が immutable な RepositoryPoint を記録する。
|
||||||
|
- Memory / Knowledge は Ticket / Run / Artifact の authority を置き換えない record として platform contract だけを持つ。本格的な意味論・抽出・承認・検索・staleness 処理は、Memory の保存先を Workspace backend / control plane record に移すタイミングで回収する。
|
||||||
|
- Hosted runner / resource allocation / SaaS offering に進むための後続 Ticket が切れる状態になっている。
|
||||||
|
- 既存 local dogfooding runtime を壊さず、local use と remote-capable architecture が両立している。
|
||||||
|
|
||||||
|
## Decision context
|
||||||
|
|
||||||
|
- Yoi は hosted Git tool ではなく、team workspace control plane + execution environment として設計する。
|
||||||
|
- Team-space の長期 canonical authority は server-side control plane に置く。local `.yoi` は互換/local/offline/export/import surface だが、multi-user SaaS の正本ではない。
|
||||||
|
- 実行環境と管理システムは弱結合にする。まず管理システムを独立させ、local runner を実行環境として接続する。その後に remote/self-hosted/hosted runner fleet へ進む。
|
||||||
|
- Web frontend を最初の primary team UI とする。Desktop app は web/control-plane model が安定した後に検討する。
|
||||||
|
- Git は重要な Repository provider / materialization backend として使うが、Workspace identity と authority を Git Repository root に固定しない。
|
||||||
|
- Ticket と Objective は Workspace 配下に平たく持つ。対象コードベースや ref は Repository target selector として表現し、Run が concrete RepositoryPoint に解決する。
|
||||||
|
- Memory の本格再設計は後回しにする。先に Workspace / Ticket / Repository / Host/Worker live view / Control plane の基盤を固め、Memory の保存先を Workspace backend に移すタイミングで、意味論・抽出・承認・検索・staleness 処理をまとめて回収する。
|
||||||
|
- Worker の一元管理・データ永続化・アーカイブも後続設計に回す。初期 DB では Worker を Pod metadata の代替として永続化せず、live view と Ticket-linked WorkerRef 記録に留める。
|
||||||
@@ -0,0 +1,268 @@
|
|||||||
|
---
|
||||||
|
title: "効果的な Memory システム設計・検証"
|
||||||
|
state: "active"
|
||||||
|
created_at: "2026-06-20T15:16:00Z"
|
||||||
|
updated_at: "2026-06-20T15:16:00Z"
|
||||||
|
linked_tickets: ["00001KSKBPHRG", "00001KT02TCCG", "00001KTGCAFXG", "00001KSKBPTHR"]
|
||||||
|
---
|
||||||
|
|
||||||
|
## Goal
|
||||||
|
|
||||||
|
Yoi の Memory / Knowledge / generated memory / resident context / retrieval / usage metrics を、実際の開発・設計・レビュー・オーケストレーションに効く sensemaking substrate として再設計・検証する。
|
||||||
|
|
||||||
|
この Objective でいう「効果的な Memory システム」は、単に多く保存する仕組みではなく、作業中の問いに対して relevant material を集め、根拠を検証可能にし、再表現・仮説形成・反証探索・意思決定・成果物への反映を低コストにする仕組みである。
|
||||||
|
|
||||||
|
暫定的な定義:
|
||||||
|
|
||||||
|
- foraging cost を下げる: Ticket / Objective / current question に対して、関連する memory / docs / tickets / session evidence / code references を探しやすい。
|
||||||
|
- evidence を失わない: Memory が authority そのものにならず、Ticket / docs / git history / session logs / user instruction への検証可能な入口になる。
|
||||||
|
- schema 化を支援する: raw summary ではなく、subsystem、invariant、risk、authority boundary、open question、rejected alternative、hypothesis など推論しやすい形へ再表現できる。
|
||||||
|
- hypothesis loop を支援する: 支持証拠だけでなく、代替仮説・棄却理由・反証 evidence・stale assumption を扱える。
|
||||||
|
- product に戻る: Memory に保存して終わりではなく、Ticket、review、docs、implementation、decision、report に影響を戻せる。
|
||||||
|
- stale / contradiction を扱う: 古い前提、矛盾、適用範囲外の memory を検出・降格・更新できる。
|
||||||
|
- usage を成果基準で測る: resident exposure や read count ではなく、判断・レビュー・実装・docs に効いたかを観測できる。
|
||||||
|
|
||||||
|
## Motivation / background
|
||||||
|
|
||||||
|
現在の Memory システムは「墓場化」している。保存された情報はあるが、後続の作業で自然に使われにくく、使われたとしても根拠・適用範囲・鮮度・反証可能性が弱い。結果として Memory は、作業場ではなく古い結論の倉庫になりやすい。
|
||||||
|
|
||||||
|
Pirolli & Card 2005 の sensemaking model では、分析作業は単なる保存ではなく、次の変換として捉えられる。
|
||||||
|
|
||||||
|
```text
|
||||||
|
external data sources
|
||||||
|
-> shoebox
|
||||||
|
-> evidence file
|
||||||
|
-> schema / representation
|
||||||
|
-> hypotheses
|
||||||
|
-> presentation / product
|
||||||
|
```
|
||||||
|
|
||||||
|
Yoi の現行 Memory は、この流れのうち「保存」と「一部の検索」には対応しているが、少なくとも以下が弱い。
|
||||||
|
|
||||||
|
- Ticket / task / question ごとの shoebox がない。
|
||||||
|
- shoebox から evidence snippets を切り出し、source / provenance / applicability / confidence と共に扱う evidence file がない。
|
||||||
|
- `summary`, `decision`, `request`, `knowledge` は storage taxonomy であり、sensemaking 用 schema としては粗い。
|
||||||
|
- decision は残るが、hypothesis space、alternative、rejected reason、disconfirming evidence が残りにくい。
|
||||||
|
- reviewer / orchestrator が confirmation bias を避けるための反証探索導線が弱い。
|
||||||
|
- resident exposure と explicit retrieval は観測できても、Memory が product に効いたかは測りにくい。
|
||||||
|
|
||||||
|
この Objective は、Memory 関連の設計・検証・検討・考察を一元化し、個別 Ticket がばらばらに storage、prompt、retrieval、metrics を改善して再び墓場を増やすことを防ぐための判断背景である。
|
||||||
|
|
||||||
|
## Strategy / design direction
|
||||||
|
|
||||||
|
Memory を「長期保存領域」ではなく、Yoi の multi-agent 開発における sensemaking loop の支援機構として設計する。
|
||||||
|
|
||||||
|
### 1. Pirolli & Card の stage に合わせて責務を分ける
|
||||||
|
|
||||||
|
- external data sources: Tickets、docs、git history、session logs、reports、code、user instructions。
|
||||||
|
- shoebox: 特定 Ticket / Objective / design question に対して関連しそうな材料を集めた task-bound working set。
|
||||||
|
- evidence file: shoebox から抜き出した根拠 snippet。source anchor、支持/反証、適用範囲、confidence、staleness を持つ。
|
||||||
|
- schema / representation: subsystem、invariant、risk、authority boundary、open question、hypothesis、alternative、contradiction など、推論しやすい再表現。
|
||||||
|
- hypotheses: 採用前の設計仮説、代替案、棄却条件、反証 evidence。
|
||||||
|
- product: Ticket、review、docs、implementation、decision、report、orchestration plan などの成果物。
|
||||||
|
|
||||||
|
### 2. 最初の重点は task-bound shoebox と evidence file
|
||||||
|
|
||||||
|
Memory 墓場化の最初の原因は、保存情報が現在の問いに集まらないことである。まずは Orchestrator / Intake / Reviewer が Ticket を扱う時に、関連 memory / docs / tickets / reports / prior decisions を shoebox として束ねる導線を作る。
|
||||||
|
|
||||||
|
この段階では大きな永続 schema 追加に飛びつかず、report / Ticket artifact / bounded generated context として検証してよい。
|
||||||
|
|
||||||
|
### 3. Memory を authority にしない
|
||||||
|
|
||||||
|
Memory は Ticket、docs、git history、session logs、user instruction の代替ではない。Memory は authority record への evidence index / schema / reasoning aid として扱う。
|
||||||
|
|
||||||
|
したがって、改善案は次の性質を持つべきである。
|
||||||
|
|
||||||
|
- source / provenance を辿れる。
|
||||||
|
- stale / superseded / contradicted を扱える。
|
||||||
|
- Memory の断定をそのまま authority として使わない。
|
||||||
|
- Ticket body/thread/artifacts を読まずに Objective や Memory だけで実装判断できる状態を作らない。
|
||||||
|
|
||||||
|
### 4. 反証探索を first-class にする
|
||||||
|
|
||||||
|
より効果的な Memory は、過去方針を思い出すだけでなく、現在案を疑うために使える必要がある。
|
||||||
|
|
||||||
|
Reviewer / Orchestrator / Intake の導線では、次を探せるようにする。
|
||||||
|
|
||||||
|
- supporting evidence
|
||||||
|
- contradicting evidence
|
||||||
|
- stale decisions
|
||||||
|
- rejected alternatives
|
||||||
|
- unresolved questions
|
||||||
|
- authority boundary risks
|
||||||
|
- prior failures / reports
|
||||||
|
|
||||||
|
### 5. Metrics は exposure から product impact へ寄せる
|
||||||
|
|
||||||
|
Memory が prompt に入った、または query されたことは成功ではない。評価は次を区別する。
|
||||||
|
|
||||||
|
- resident exposure
|
||||||
|
- explicit retrieval
|
||||||
|
- cited in response
|
||||||
|
- cited in Ticket / review / report
|
||||||
|
- changed requirement
|
||||||
|
- changed implementation
|
||||||
|
- contradicted / invalidated
|
||||||
|
- led to docs or decision update
|
||||||
|
|
||||||
|
### 6. 後続 Ticket は concrete slice に分割する
|
||||||
|
|
||||||
|
この Objective は中期的な設計・検証の一元化 record であり、umbrella Ticket ではない。実装や調査は、単独で実装・レビュー・close できる concrete Ticket に分割する。
|
||||||
|
|
||||||
|
候補 slice:
|
||||||
|
|
||||||
|
- Memory sensemaking 分析 report を `docs/report/` に作る。
|
||||||
|
- Ticket routing 用 Memory shoebox artifact を試作する。
|
||||||
|
- evidence snippet schema / source resolver を設計する。
|
||||||
|
- hypothesis / rejected alternative / disconfirming evidence の表現を追加する。
|
||||||
|
- Reviewer workflow に反証探索を入れる。
|
||||||
|
- Memory usage metrics を product impact oriented に拡張する。
|
||||||
|
- stale / contradiction / renewal の検出・表示を設計する。
|
||||||
|
|
||||||
|
## Success criteria / exit conditions
|
||||||
|
|
||||||
|
- Memory システムの目的が「保存」ではなく「sensemaking loop 支援」として project records / docs / prompts / workflows で一貫して説明されている。
|
||||||
|
- Pirolli & Card の `shoebox -> evidence file -> schema -> hypotheses -> product` に対応する Yoi 内の責務と非責務が整理されている。
|
||||||
|
- Ticket / Objective / docs / session logs / Memory / Knowledge の authority boundary が明確で、Memory が authority を僭称しない。
|
||||||
|
- 少なくとも一つの実作業 routing / review / design analysis で、task-bound shoebox または evidence file が生成・利用され、作業品質にどう効いたかが確認されている。
|
||||||
|
- Memory records または関連 artifacts が source / provenance / applicability / staleness / supports-or-refutes のいずれかを扱えるようになっている。
|
||||||
|
- Reviewer / Orchestrator が supporting evidence だけでなく、contradicting evidence / stale assumptions / rejected alternatives を探す導線を持っている。
|
||||||
|
- Memory usage metrics が resident exposure と product impact を区別している。
|
||||||
|
- 古い Memory が放置されるのではなく、stale / superseded / contradicted / needs-review として扱える方針がある。
|
||||||
|
- 後続の実装 Ticket が concrete slice として分割され、Objective が Ticket dependency や進捗 container として使われていない。
|
||||||
|
|
||||||
|
この Objective は、Memory が少なくとも一つの中規模設計・実装・レビュー作業で「関連情報を見つける」「根拠を確認する」「代替案/反証を検討する」「成果物へ反映する」流れを実証し、その設計方針が docs / workflows / metrics に反映された時点で `done` を検討できる。
|
||||||
|
|
||||||
|
## Decision context
|
||||||
|
|
||||||
|
- ユーザー指摘: 「Memoryシステムが完全に墓場化している」。これは保存量不足ではなく、保存情報が現在の問い・根拠・仮説・成果物に接続されない問題として扱う。
|
||||||
|
- ユーザー指示: Memory システムの設計・検証・検討・考察を Objective にまとめ、より効果的な Memory システムを作成する目標のもとで情報を一元化する。
|
||||||
|
- 「効果的」の定義は未確定だが、当面は Pirolli & Card の sensemaking process に沿って、foraging cost、evidence quality、schema usefulness、hypothesis/disconfirmation support、product impact、staleness handling を評価軸にする。
|
||||||
|
- Memory は durable project authority ではない。Ticket、docs、git history、session logs、明示 user instruction の代替として使わない。
|
||||||
|
- Objective context は判断背景であり、個別実装の authority は各 Ticket body/thread/artifacts と明示的な Ticket relations / OrchestrationPlan records にある。
|
||||||
|
- `history` に残らない context-only injection を改善案にしない。新しい context input は history に commit する原則を守る。
|
||||||
|
- Knowledge は単なる長期保存ではなく、再利用可能な schema / model / procedure / invariant として再検討する余地がある。
|
||||||
|
- Generated memory / curated Knowledge / Ticket / docs / report の境界を再定義する場合は、authority boundary と migration/staleness を明示する。
|
||||||
|
- 関連する既存 Ticket:
|
||||||
|
- `00001KSKBPHRG` — Prompt / Workflow 評価メトリクスと改善 Offer
|
||||||
|
- `00001KT02TCCG` — Memory prompt: conditional guidance and proactive lookup
|
||||||
|
- `00001KTGCAFXG` — Use .yoi/memory marker for repo-local memory root
|
||||||
|
- `00001KSKBPTHR` — ワークスペースのメモリーをLintするヘッドレスCLI
|
||||||
|
|
||||||
|
## Historical references / prior design sources
|
||||||
|
|
||||||
|
現在の Memory システムの初期設計時には、Codex Memories / Chronicle と HermesAgent を明示的な参考事例として調査していた。関連する調査・設計記録は、現在は主に以下に退避されている。
|
||||||
|
|
||||||
|
- `docs/.local/old-docs/ref/memory-systems.md`
|
||||||
|
- `docs/.local/old-docs/plan/memory.md`
|
||||||
|
- 初期設計 commit: `ca5a3d11` — `2026-04-21 メモリシステムの設計`
|
||||||
|
- 関連 commit:
|
||||||
|
- `0c1276b7` — `Memoryシステムの整理・Promptカタログチケット`
|
||||||
|
- `3d04f793` — `memoryを抽出する仕組みの実装`
|
||||||
|
- `f1b7af62` — `docs: memoryシステムの仕様変更と、動的Tool・VCSの話`
|
||||||
|
- `a2aecbf0` — `update: memoryシステムの"Phase"表記を撤廃`
|
||||||
|
|
||||||
|
### Codex Memories / Chronicle から得た設計要素
|
||||||
|
|
||||||
|
旧設計では、Codex Memories / Chronicle を `extract -> staging -> consolidation -> durable Markdown memory` の非同期パイプラインとして捉えていた。
|
||||||
|
|
||||||
|
主な参照点:
|
||||||
|
|
||||||
|
- extract と consolidation の 2 段構成。
|
||||||
|
- extract は JSON schema / structured output で分類ブレを抑える。
|
||||||
|
- consolidation は reasoning model / agentic rewrite によって、既存 memory と staging entries を統合・整理する。
|
||||||
|
- staging と durable memory を分ける。
|
||||||
|
- `MEMORY.md` は retrieval-oriented handbook として扱う。
|
||||||
|
- `memory_summary.md` は prompt-loaded high-signal context として扱う。
|
||||||
|
- `raw_memories.md` は routing layer / task inventory 的な中間層として扱う。
|
||||||
|
- workspace diff や usage 情報を使い、stale / deleted evidence / noisy entries を整理する。
|
||||||
|
- consolidation は append だけでなく、rewrite / merge / split / trim / drop / cleanup を担う。
|
||||||
|
|
||||||
|
Yoi 初期設計では、これを参考に以下を意図していた。
|
||||||
|
|
||||||
|
- activity token 閾値で extract を発火する。
|
||||||
|
- compact より前に session log range を抽出する。
|
||||||
|
- extract は `decisions`, `discussions`, `attempts`, `requests` などの候補を staging に保存する。
|
||||||
|
- 抽出時点では Knowledge 化せず、純粋な「起きたこと」に寄せる。
|
||||||
|
- consolidation が summary / decisions / requests / knowledge candidates を整理する。
|
||||||
|
- consolidation 入力に linter warnings / usage metrics / Knowledge 化候補を含める。
|
||||||
|
- stale / superseded / unused / noisy な情報を整理する。
|
||||||
|
|
||||||
|
この Objective での再解釈:
|
||||||
|
|
||||||
|
- Codex の `raw_memories.md` は、Pirolli & Card の sensemaking model では `shoebox` または `evidence file` に近い。
|
||||||
|
- Yoi は extract / consolidation という pipeline だけを継承しても不十分であり、task-bound shoebox / evidence file / hypothesis loop / product feedback がなければ Memory は再び墓場化する。
|
||||||
|
- 特に、staging を consolidation の一時入力としてだけ扱うと、後続 Ticket / Objective / review が使う探索入口にならない。
|
||||||
|
- Yoi では `raw memories` 相当の中間層を、現在の問いに紐づく working set / evidence index として再設計する必要がある。
|
||||||
|
|
||||||
|
### HermesAgent から得た設計要素
|
||||||
|
|
||||||
|
旧設計では、Nous Research HermesAgent を 3 層の memory system として整理していた。
|
||||||
|
|
||||||
|
- Persistent Memory:
|
||||||
|
- `MEMORY.md` / `USER.md`
|
||||||
|
- Markdown + SQLite / FTS5 session search
|
||||||
|
- 起動時 system prompt snapshot
|
||||||
|
- bounded character limits
|
||||||
|
- Skill Library:
|
||||||
|
- procedural memory
|
||||||
|
- `~/.hermes/skills/<name>/SKILL.md`
|
||||||
|
- `skill_manage` tool による agentic CRUD
|
||||||
|
- User Model / Honcho:
|
||||||
|
- dialectic user modeling
|
||||||
|
- 外部 service 連携
|
||||||
|
|
||||||
|
HermesAgent で特に重要だった点:
|
||||||
|
|
||||||
|
- memory / skill review は一定 turn / tool iteration ごとに background agent として起動する。
|
||||||
|
- 保存すべきものがなければ `Nothing to save.` で NOP として終了する。
|
||||||
|
- Yoi extract の「空配列許容」はこの設計からも影響を受けている。
|
||||||
|
- memory は session start 時の frozen snapshot として system prompt に入り、mid-session write で prompt cache を壊さない。
|
||||||
|
- persistent memory は bounded で、limit 超過時は deterministic eviction ではなく、agent に replace / remove を促す。
|
||||||
|
- procedural memory / skills は一般 memory から分離されている。
|
||||||
|
- SQLite FTS5 + LLM summarization による cross-session recall がある。
|
||||||
|
|
||||||
|
この Objective での再解釈:
|
||||||
|
|
||||||
|
- HermesAgent の `MEMORY.md` / `USER.md` / `skills` の分離は、Yoi の Knowledge / Workflow / prompt resource / docs / Ticket decision / generated memory の責務再整理に使える。
|
||||||
|
- reusable procedure, reviewer focus, orchestration tactic, project preference, user preference, design invariant を同じ Memory bucket に入れると墓場化しやすい。
|
||||||
|
- `Nothing to save.` / empty extraction allowed は重要だが、保存抑制だけでは効果的な Memory にはならない。保存されたものが task-bound shoebox / evidence / schema / hypothesis / product に接続される必要がある。
|
||||||
|
- frozen snapshot / prompt cache 配慮は Yoi の history/context 加工原則と整合するが、それだけでは retrieval / resurfacing / disconfirmation は解決しない。
|
||||||
|
|
||||||
|
### Lessons for the next design iteration
|
||||||
|
|
||||||
|
Codex と HermesAgent の調査から、Yoi が継承すべきものと、継承するだけでは足りないものを分ける。
|
||||||
|
|
||||||
|
継承すべきもの:
|
||||||
|
|
||||||
|
- structured extract と agentic consolidation の分離。
|
||||||
|
- staging / raw memories / durable memory の分離。
|
||||||
|
- 保存対象がなければ NOP にする発火設計。
|
||||||
|
- prompt-loaded summary と durable retrieval-oriented memory の分離。
|
||||||
|
- stale / noisy / unused entries の cleanup。
|
||||||
|
- procedural memory と declarative memory の分離。
|
||||||
|
- session search / usage metrics / linter feedback を consolidation に入れる設計。
|
||||||
|
|
||||||
|
足りないもの:
|
||||||
|
|
||||||
|
- Pirolli & Card の sensemaking stage における各 record の役割定義。
|
||||||
|
- Ticket / Objective / current question に紐づく task-bound shoebox。
|
||||||
|
- authority record へ戻れる evidence file / provenance / source anchor。
|
||||||
|
- hypothesis, alternative hypothesis, rejected reason, disconfirming evidence の first-class 表現。
|
||||||
|
- reviewer / orchestrator が confirmation bias を避けるための反証探索導線。
|
||||||
|
- resident exposure や read count ではなく product impact を測る metrics。
|
||||||
|
- stale / contradiction / renewal を作業中に resurfacing する導線。
|
||||||
|
|
||||||
|
したがって、次の Memory 設計は Codex / HermesAgent の単純なコピーではなく、以下を満たす必要がある。
|
||||||
|
|
||||||
|
```text
|
||||||
|
external data / sessions / tickets / docs / code
|
||||||
|
-> task-bound shoebox
|
||||||
|
-> evidence file with provenance
|
||||||
|
-> schema / representation
|
||||||
|
-> hypotheses and disconfirmation
|
||||||
|
-> Ticket / review / docs / implementation / decision product
|
||||||
|
-> product impact and stale-feedback metrics
|
||||||
|
```
|
||||||
|
|
||||||
|
この Objective では、以後の Memory 関連 Ticket / report / implementation をこの historical reference と sensemaking model の両方に照らして判断する。
|
||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: "Pod: 任意ターンからの Fork(複数ターン巻き戻し)"
|
title: "Pod: 任意ターンからの Fork(複数ターン巻き戻し)"
|
||||||
state: "planning"
|
state: 'closed'
|
||||||
created_at: "2026-05-27T00:00:09Z"
|
created_at: "2026-05-27T00:00:09Z"
|
||||||
updated_at: "2026-05-27T00:00:09Z"
|
updated_at: '2026-06-20T16:31:29Z'
|
||||||
---
|
---
|
||||||
|
|
||||||
## Migration reference
|
## Migration reference
|
||||||
|
|||||||
@@ -0,0 +1 @@
|
|||||||
|
Closed as no longer needed. Arbitrary-turn Pod/session fork and multi-turn rewind are not part of the current desired workflow; current restore/rewind/fork behavior is sufficient for active use, and future history editing should be reopened as a narrower current-runtime design if needed.
|
||||||
@@ -4,4 +4,22 @@
|
|||||||
|
|
||||||
Migrated from tickets/pod-session-fork.md. No legacy review file was present at migration time.
|
Migrated from tickets/pod-session-fork.md. No legacy review file was present at migration time.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-20T16:31:28Z from: planning to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-20T16:31:29Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Closed as no longer needed. Arbitrary-turn Pod/session fork and multi-turn rewind are not part of the current desired workflow; current restore/rewind/fork behavior is sufficient for active use, and future history editing should be reopened as a narrower current-runtime design if needed.
|
||||||
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: "Prompt / Workflow 評価メトリクスと改善 Offer"
|
title: "Prompt / Workflow 評価メトリクスと改善 Offer"
|
||||||
state: "planning"
|
state: 'closed'
|
||||||
created_at: "2026-05-27T00:00:10Z"
|
created_at: "2026-05-27T00:00:10Z"
|
||||||
updated_at: "2026-05-27T00:00:10Z"
|
updated_at: '2026-06-20T16:31:29Z'
|
||||||
---
|
---
|
||||||
|
|
||||||
## Migration reference
|
## Migration reference
|
||||||
|
|||||||
@@ -0,0 +1 @@
|
|||||||
|
Closed as superseded/no longer needed. Workflow evaluation metrics and improvement planning have moved under the newer Memory redesign / team-workspace memory objectives, so this old prompt/workflow metrics ticket should not remain as a standalone planning item.
|
||||||
@@ -4,4 +4,22 @@
|
|||||||
|
|
||||||
Migrated from tickets/prompt-eval-metrics.md. No legacy review file was present at migration time.
|
Migrated from tickets/prompt-eval-metrics.md. No legacy review file was present at migration time.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-20T16:31:29Z from: planning to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-20T16:31:29Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Closed as superseded/no longer needed. Workflow evaluation metrics and improvement planning have moved under the newer Memory redesign / team-workspace memory objectives, so this old prompt/workflow metrics ticket should not remain as a standalone planning item.
|
||||||
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: "TUI: navigation mode / block focus の設計"
|
title: "TUI: navigation mode / block focus の設計"
|
||||||
state: "planning"
|
state: 'closed'
|
||||||
created_at: "2026-05-27T00:00:15Z"
|
created_at: "2026-05-27T00:00:15Z"
|
||||||
updated_at: "2026-05-27T00:00:15Z"
|
updated_at: '2026-06-20T16:31:29Z'
|
||||||
---
|
---
|
||||||
|
|
||||||
## Migration reference
|
## Migration reference
|
||||||
|
|||||||
@@ -0,0 +1 @@
|
|||||||
|
Closed as no longer needed. The current TUI navigation/block-focus behavior is satisfactory, so the older navigation-mode design ticket is obsolete.
|
||||||
@@ -4,4 +4,22 @@
|
|||||||
|
|
||||||
Migrated from tickets/tui-navigation-mode-design.md. No legacy review file was present at migration time.
|
Migrated from tickets/tui-navigation-mode-design.md. No legacy review file was present at migration time.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-20T16:31:29Z from: planning to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-20T16:31:29Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Closed as no longer needed. The current TUI navigation/block-focus behavior is satisfactory, so the older navigation-mode design ticket is obsolete.
|
||||||
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: "Audit crate responsibility boundaries"
|
title: "Audit crate responsibility boundaries"
|
||||||
state: "planning"
|
state: 'closed'
|
||||||
created_at: "2026-05-28T13:13:17Z"
|
created_at: "2026-05-28T13:13:17Z"
|
||||||
updated_at: "2026-05-28T13:13:17Z"
|
updated_at: '2026-06-20T16:45:54Z'
|
||||||
---
|
---
|
||||||
|
|
||||||
## Background
|
## Background
|
||||||
|
|||||||
@@ -0,0 +1 @@
|
|||||||
|
Closed as completed. The crate responsibility boundary audit was already performed and recorded in artifacts/audit.md with concrete findings; any implementation cleanup should be handled by narrower follow-up tickets.
|
||||||
@@ -4,4 +4,22 @@
|
|||||||
|
|
||||||
Created by tickets.sh create.
|
Created by tickets.sh create.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-20T16:45:54Z from: planning to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-20T16:45:54Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Closed as completed. The crate responsibility boundary audit was already performed and recorded in artifacts/audit.md with concrete findings; any implementation cleanup should be handled by narrower follow-up tickets.
|
||||||
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: 'Plugin: define runtime, surface, and minimal host API model'
|
title: 'Plugin: define runtime, surface, and minimal host API model'
|
||||||
state: 'planning'
|
state: 'closed'
|
||||||
created_at: '2026-05-31T01:00:05Z'
|
created_at: '2026-05-31T01:00:05Z'
|
||||||
updated_at: '2026-06-14T17:22:23Z'
|
updated_at: '2026-06-19T13:29:26Z'
|
||||||
assignee: null
|
assignee: null
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
Closed as superseded by durable Objective and design documentation.
|
||||||
|
|
||||||
|
This Ticket was a broad Plugin runtime/surface/host API design record rather than a concrete implementation task. The useful design decisions have been moved into durable roadmap/design context:
|
||||||
|
- Objective `00001KVG0HR9M` (`Plugin platform roadmap`) now owns the overall Plugin roadmap and sequencing context.
|
||||||
|
- `docs/design/plugin-component-model.md` records Component Model research and migration direction.
|
||||||
|
- `docs/design/plugin-packages.md` records package/runtime metadata direction.
|
||||||
|
|
||||||
|
Concrete implementation work remains tracked by implementation Tickets such as package discovery, Tool registration, WASM runtime, permission grants, CLI inspection, `https`, `fs`, and Component Model runtime migration. Future Plugin work should be filed as concrete implementation Tickets, not broad design umbrella Tickets.
|
||||||
@@ -99,4 +99,29 @@ This preserves the desired detachable shape: feature state remains in the featur
|
|||||||
- General-purpose host API は引き続き `https` と `fs` に絞る。`ingress.submit` と `diagnostics` は surface-intrinsic host calls として扱い、広い ambient capability にはしない。
|
- General-purpose host API は引き続き `https` と `fs` に絞る。`ingress.submit` と `diagnostics` は surface-intrinsic host calls として扱い、広い ambient capability にはしない。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-19T13:29:26Z from: planning to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-19T13:29:26Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Closed as superseded by durable Objective and design documentation.
|
||||||
|
|
||||||
|
This Ticket was a broad Plugin runtime/surface/host API design record rather than a concrete implementation task. The useful design decisions have been moved into durable roadmap/design context:
|
||||||
|
- Objective `00001KVG0HR9M` (`Plugin platform roadmap`) now owns the overall Plugin roadmap and sequencing context.
|
||||||
|
- `docs/design/plugin-component-model.md` records Component Model research and migration direction.
|
||||||
|
- `docs/design/plugin-packages.md` records package/runtime metadata direction.
|
||||||
|
|
||||||
|
Concrete implementation work remains tracked by implementation Tickets such as package discovery, Tool registration, WASM runtime, permission grants, CLI inspection, `https`, `fs`, and Component Model runtime migration. Future Plugin work should be filed as concrete implementation Tickets, not broad design umbrella Tickets.
|
||||||
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: "Audit external dependencies and license posture"
|
title: "Audit external dependencies and license posture"
|
||||||
state: "planning"
|
state: 'closed'
|
||||||
created_at: "2026-06-01T12:36:41Z"
|
created_at: "2026-06-01T12:36:41Z"
|
||||||
updated_at: "2026-06-01T13:08:45Z"
|
updated_at: '2026-06-20T16:45:54Z'
|
||||||
---
|
---
|
||||||
|
|
||||||
## Background
|
## Background
|
||||||
|
|||||||
@@ -0,0 +1 @@
|
|||||||
|
Closed as completed. The dependency/license audit was already performed and recorded in artifacts/audit-report.md with implementation report evidence; any dependency cleanup or third-party notice work should be tracked by narrower follow-up tickets.
|
||||||
@@ -418,4 +418,22 @@ Interpretation:
|
|||||||
- Acceptance: compare current `html5ever`/`RcDom` extractor with viable maintained alternatives; preserve bounded, safe, link-aware extraction behavior; only proceed if measurable binary/build-time benefit exists.
|
- Acceptance: compare current `html5ever`/`RcDom` extractor with viable maintained alternatives; preserve bounded, safe, link-aware extraction behavior; only proceed if measurable binary/build-time benefit exists.
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-20T16:45:54Z from: planning to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-20T16:45:54Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Closed as completed. The dependency/license audit was already performed and recorded in artifacts/audit-report.md with implementation report evidence; any dependency cleanup or third-party notice work should be tracked by narrower follow-up tickets.
|
||||||
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: "Workspace panel Companion interface"
|
title: "Workspace panel Companion interface"
|
||||||
state: "planning"
|
state: 'closed'
|
||||||
created_at: "2026-06-07T00:16:51Z"
|
created_at: "2026-06-07T00:16:51Z"
|
||||||
updated_at: "2026-06-07T03:13:01Z"
|
updated_at: '2026-06-18T13:06:31Z'
|
||||||
---
|
---
|
||||||
|
|
||||||
## Background
|
## Background
|
||||||
|
|||||||
@@ -0,0 +1,10 @@
|
|||||||
|
Closed as completed by child Tickets.
|
||||||
|
|
||||||
|
The original Workspace Panel Companion interface plan has been implemented through more specific work:
|
||||||
|
- direct selected-Pod send was removed from the Panel composer path;
|
||||||
|
- Panel composer routing now targets the workspace Companion and Ticket Intake explicitly;
|
||||||
|
- workspace Companion Pod lifecycle restore/spawn/observe behavior is implemented;
|
||||||
|
- local role/session registry and Ticket claim handling were added for Panel-launched role sessions;
|
||||||
|
- project role Profile feature defaults limit Companion authority and keep Ticket orchestration / Pods / Task disabled for Companion by default.
|
||||||
|
|
||||||
|
The remaining work in this area should be tracked as targeted follow-up Tickets rather than keeping this umbrella planning Ticket open.
|
||||||
@@ -74,4 +74,31 @@ Companion work is useful but not required for near-term panel operation. The pan
|
|||||||
|
|
||||||
Decision: downgrade Companion-related follow-up priority to P2 so near-term focus can stay on Ticket role config strictness/init, Orchestrator queue automation, and workflow/compaction reliability.
|
Decision: downgrade Companion-related follow-up priority to P2 so near-term focus can stay on Ticket role config strictness/init, Orchestrator queue automation, and workflow/compaction reliability.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-18T13:06:31Z from: planning to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-18T13:06:31Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Closed as completed by child Tickets.
|
||||||
|
|
||||||
|
The original Workspace Panel Companion interface plan has been implemented through more specific work:
|
||||||
|
- direct selected-Pod send was removed from the Panel composer path;
|
||||||
|
- Panel composer routing now targets the workspace Companion and Ticket Intake explicitly;
|
||||||
|
- workspace Companion Pod lifecycle restore/spawn/observe behavior is implemented;
|
||||||
|
- local role/session registry and Ticket claim handling were added for Panel-launched role sessions;
|
||||||
|
- project role Profile feature defaults limit Companion authority and keep Ticket orchestration / Pods / Task disabled for Companion by default.
|
||||||
|
|
||||||
|
The remaining work in this area should be tracked as targeted follow-up Tickets rather than keeping this umbrella planning Ticket open.
|
||||||
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: "Improve Pod notification injection guidance"
|
title: "Improve Pod notification injection guidance"
|
||||||
state: "planning"
|
state: 'closed'
|
||||||
created_at: "2026-06-07T07:33:13Z"
|
created_at: "2026-06-07T07:33:13Z"
|
||||||
updated_at: "2026-06-07T07:33:13Z"
|
updated_at: '2026-06-20T16:23:37Z'
|
||||||
---
|
---
|
||||||
|
|
||||||
## Background
|
## Background
|
||||||
|
|||||||
@@ -0,0 +1 @@
|
|||||||
|
Closed as stale/currently not needed. Orchestrator role/profile/workflow notification guidance has since improved, and the broad planning issue is not currently reproducing. If similar notification-as-user-turn confusion recurs in default profiles or generic notification wrappers, create a narrower ticket against the current prompt/profile state.
|
||||||
@@ -4,4 +4,39 @@
|
|||||||
|
|
||||||
Created by LocalTicketBackend create.
|
Created by LocalTicketBackend create.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: decision author: intake at: 2026-06-20T16:20:17Z -->
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
ユーザー判断により、この Ticket は一旦 close 推奨とする。
|
||||||
|
|
||||||
|
理由:
|
||||||
|
- Ticket 作成後に Orchestrator profile / role prompt / workflow guidance の改善が複数回入っている。
|
||||||
|
- 現在の明示的な Orchestrator role では、通知を user request と誤認しているケースを最近見かけていない。
|
||||||
|
- default profile では同種の誤認がまだ起き得る可能性はあるが、現時点でこの broad な planning Ticket を残しておくほどの実害・優先度は確認されていない。
|
||||||
|
|
||||||
|
判断:
|
||||||
|
- この Ticket は stale / currently not needed として close してよい。
|
||||||
|
- 将来 default profile や generic notify_wrapper で同じ問題が再発した場合は、現在の prompt/profile 状態を前提に、より狭い concrete Ticket として切り直す。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-20T16:23:37Z from: planning to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-20T16:23:37Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Closed as stale/currently not needed. Orchestrator role/profile/workflow notification guidance has since improved, and the broad planning issue is not currently reproducing. If similar notification-as-user-turn confusion recurs in default profiles or generic notification wrappers, create a narrower ticket against the current prompt/profile state.
|
||||||
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: 'Implement MCP 2025-11-25 local stdio server-feature bridge'
|
title: 'Implement MCP 2025-11-25 local stdio server-feature bridge'
|
||||||
state: 'planning'
|
state: 'closed'
|
||||||
created_at: '2026-06-10T07:48:49Z'
|
created_at: '2026-06-10T07:48:49Z'
|
||||||
updated_at: '2026-06-13T15:29:21Z'
|
updated_at: '2026-06-20T05:33:15Z'
|
||||||
assignee: null
|
assignee: null
|
||||||
readiness: 'blocked'
|
readiness: 'blocked'
|
||||||
risk_flags: ['mcp', 'prompt-context', 'permission-scope', 'secrets', 'process-exec', 'feature-api', 'trust-boundary']
|
risk_flags: ['mcp', 'prompt-context', 'permission-scope', 'secrets', 'process-exec', 'feature-api', 'trust-boundary']
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
Closed as superseded by concrete MCP implementation Tickets.
|
||||||
|
|
||||||
|
This Ticket bundled config/trust policy, stdio lifecycle, tools/list registration, tools/call execution, resources/prompts operations, result serialization, and list_changed handling into one broad implementation item. That is too coarse for the current Ticket policy: Tickets should be concrete implementation tasks.
|
||||||
|
|
||||||
|
The MCP roadmap now lives in Objective `00001KTR80WMN` (`MCP local stdio integration roadmap`). Concrete follow-up Tickets are:
|
||||||
|
- `00001KVHR3WRF` — local stdio server config and trust policy;
|
||||||
|
- `00001KVHR3WRY` — stdio JSON-RPC lifecycle client;
|
||||||
|
- `00001KVHR3WS6` — server tools registration into ToolRegistry;
|
||||||
|
- `00001KVHR3WSD` — tools/call execution through ordinary Tool path;
|
||||||
|
- `00001KVHR3WSN` — resources/prompts as explicit tool operations;
|
||||||
|
- `00001KVHR3WSW` — list_changed notification handling.
|
||||||
|
|
||||||
|
Future MCP work should use those concrete Tickets or similarly scoped follow-ups, not this broad umbrella Ticket.
|
||||||
@@ -22,4 +22,34 @@ LocalTicketBackend によって作成されました。
|
|||||||
- `00001KSXRQ4G8` と `00001KT0Z4BK8` は Plugin permission を Plugin layer として扱い、MCP を初期 Plugin packaging/runtime から分離する。
|
- `00001KSXRQ4G8` と `00001KT0Z4BK8` は Plugin permission を Plugin layer として扱い、MCP を初期 Plugin packaging/runtime から分離する。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-20T05:33:15Z from: planning to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-20T05:33:15Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Closed as superseded by concrete MCP implementation Tickets.
|
||||||
|
|
||||||
|
This Ticket bundled config/trust policy, stdio lifecycle, tools/list registration, tools/call execution, resources/prompts operations, result serialization, and list_changed handling into one broad implementation item. That is too coarse for the current Ticket policy: Tickets should be concrete implementation tasks.
|
||||||
|
|
||||||
|
The MCP roadmap now lives in Objective `00001KTR80WMN` (`MCP local stdio integration roadmap`). Concrete follow-up Tickets are:
|
||||||
|
- `00001KVHR3WRF` — local stdio server config and trust policy;
|
||||||
|
- `00001KVHR3WRY` — stdio JSON-RPC lifecycle client;
|
||||||
|
- `00001KVHR3WS6` — server tools registration into ToolRegistry;
|
||||||
|
- `00001KVHR3WSD` — tools/call execution through ordinary Tool path;
|
||||||
|
- `00001KVHR3WSN` — resources/prompts as explicit tool operations;
|
||||||
|
- `00001KVHR3WSW` — list_changed notification handling.
|
||||||
|
|
||||||
|
Future MCP work should use those concrete Tickets or similarly scoped follow-ups, not this broad umbrella Ticket.
|
||||||
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: 'Panel 起動遅延の待ち要因を E2E 計測で特定し改善する'
|
title: 'Panel 起動遅延の待ち要因を E2E 計測で特定し改善する'
|
||||||
state: 'done'
|
state: 'closed'
|
||||||
created_at: '2026-06-15T12:40:33Z'
|
created_at: '2026-06-15T12:40:33Z'
|
||||||
updated_at: '2026-06-15T14:31:28Z'
|
updated_at: '2026-06-19T05:44:09Z'
|
||||||
assignee: null
|
assignee: null
|
||||||
readiness: 'implementation_ready'
|
readiness: 'implementation_ready'
|
||||||
risk_flags: ['panel', 'tui', 'e2e', 'latency', 'runtime-observation']
|
risk_flags: ['panel', 'tui', 'e2e', 'latency', 'runtime-observation']
|
||||||
|
|||||||
@@ -0,0 +1,9 @@
|
|||||||
|
Closed as completed by the subsequent Panel startup E2E and latency-improvement sequence.
|
||||||
|
|
||||||
|
The initial work separated first visible frame readiness from background reload, but later review showed that user-visible startup latency must be measured at dashboard content-ready, not first frame or single-row readiness. The later Tickets added dashboard snapshot readiness, shell-enter launch-path coverage, live workspace measurements, and the actual startup fix for duplicate Pod probes/session-log scans.
|
||||||
|
|
||||||
|
Relevant follow-ups:
|
||||||
|
- 00001KV62PF32: corrected readiness away from first frame / weak row count;
|
||||||
|
- 00001KVDETSN6: dashboard content-ready snapshot metric;
|
||||||
|
- 00001KVDQH839: shell-enter launch-path measurement;
|
||||||
|
- 00001KVF0ZJM5: fixed live startup by reusing initial Pod list presence and avoiding session-log reads before first rows.
|
||||||
@@ -215,4 +215,30 @@ Cleanup planned:
|
|||||||
|
|
||||||
Reviewer approved, implementation/evidence branch merged into the orchestration branch, and E2E-focused validation passed in the Orchestrator worktree. Marking Ticket done in the orchestration branch.
|
Reviewer approved, implementation/evidence branch merged into the orchestration branch, and E2E-focused validation passed in the Orchestrator worktree. Marking Ticket done in the orchestration branch.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-19T05:44:09Z from: done to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-19T05:44:09Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Closed as completed by the subsequent Panel startup E2E and latency-improvement sequence.
|
||||||
|
|
||||||
|
The initial work separated first visible frame readiness from background reload, but later review showed that user-visible startup latency must be measured at dashboard content-ready, not first frame or single-row readiness. The later Tickets added dashboard snapshot readiness, shell-enter launch-path coverage, live workspace measurements, and the actual startup fix for duplicate Pod probes/session-log scans.
|
||||||
|
|
||||||
|
Relevant follow-ups:
|
||||||
|
- 00001KV62PF32: corrected readiness away from first frame / weak row count;
|
||||||
|
- 00001KVDETSN6: dashboard content-ready snapshot metric;
|
||||||
|
- 00001KVDQH839: shell-enter launch-path measurement;
|
||||||
|
- 00001KVF0ZJM5: fixed live startup by reusing initial Pod list presence and avoiding session-log reads before first rows.
|
||||||
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: 'Plugin: package discovery and explicit enablement resolver'
|
title: 'Plugin: package discovery and explicit enablement resolver'
|
||||||
state: 'done'
|
state: 'closed'
|
||||||
created_at: '2026-06-15T13:40:15Z'
|
created_at: '2026-06-15T13:40:15Z'
|
||||||
updated_at: '2026-06-15T15:30:00Z'
|
updated_at: '2026-06-18T12:22:04Z'
|
||||||
assignee: null
|
assignee: null
|
||||||
readiness: 'implementation_ready'
|
readiness: 'implementation_ready'
|
||||||
risk_flags: ['plugin', 'package-loading', 'discovery', 'enablement', 'capability-boundary', 'startup-restore']
|
risk_flags: ['plugin', 'package-loading', 'discovery', 'enablement', 'capability-boundary', 'startup-restore']
|
||||||
|
|||||||
@@ -0,0 +1,3 @@
|
|||||||
|
Ticket `00001KV5R5V2S` (`Plugin: package discovery and explicit enablement resolver`) はすでに `state: done` に到達していたため、workspace Panel から close しました。
|
||||||
|
|
||||||
|
この Close action によって、実装作業、state 変更、Orchestrator/Companion launch、worker invocation は開始されていません。
|
||||||
@@ -524,4 +524,24 @@ Cleanup planned:
|
|||||||
|
|
||||||
Reviewer approved after requested fixes, implementation branch merged into the orchestration branch, and focused plus packaging validation passed in the Orchestrator worktree. Marking Ticket done in the orchestration branch.
|
Reviewer approved after requested fixes, implementation branch merged into the orchestration branch, and focused plus packaging validation passed in the Orchestrator worktree. Marking Ticket done in the orchestration branch.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-18T12:22:04Z from: done to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-18T12:22:04Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Ticket `00001KV5R5V2S` (`Plugin: package discovery and explicit enablement resolver`) はすでに `state: done` に到達していたため、workspace Panel から close しました。
|
||||||
|
|
||||||
|
この Close action によって、実装作業、state 変更、Orchestrator/Companion launch、worker invocation は開始されていません。
|
||||||
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: 'Plugin: execute Plugin Tool with minimal WASM runtime'
|
title: 'Plugin: execute Plugin Tool with minimal WASM runtime'
|
||||||
state: 'inprogress'
|
state: 'closed'
|
||||||
created_at: '2026-06-15T14:48:59Z'
|
created_at: '2026-06-15T14:48:59Z'
|
||||||
updated_at: '2026-06-17T09:50:53Z'
|
updated_at: '2026-06-18T13:55:12Z'
|
||||||
assignee: null
|
assignee: null
|
||||||
readiness: 'implementation_ready'
|
readiness: 'implementation_ready'
|
||||||
risk_flags: ['plugin', 'wasm', 'tool-runtime', 'sandbox', 'capability-boundary', 'cancellation']
|
risk_flags: ['plugin', 'wasm', 'tool-runtime', 'sandbox', 'capability-boundary', 'cancellation']
|
||||||
|
|||||||
@@ -0,0 +1,3 @@
|
|||||||
|
Ticket `00001KV5W3PHW` (`Plugin: execute Plugin Tool with minimal WASM runtime`) はすでに `state: done` に到達していたため、workspace Panel から close しました。
|
||||||
|
|
||||||
|
この Close action によって、実装作業、state 変更、Orchestrator/Companion launch、worker invocation は開始されていません。
|
||||||
@@ -127,4 +127,206 @@ Recovery needed:
|
|||||||
State handling:
|
State handling:
|
||||||
- Ticket remains `inprogress` because acceptance and worktree side effects already happened; it is not silently returned to `queued`.
|
- Ticket remains `inprogress` because acceptance and worktree side effects already happened; it is not silently returned to `queued`.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T12:05:59Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Implementation resumed:
|
||||||
|
|
||||||
|
Previous `SpawnPod` failure was recovered after Orchestrator runtime refresh. Reused existing clean child worktree and successfully spawned Coder Pod.
|
||||||
|
|
||||||
|
Worktree:
|
||||||
|
- `/home/hare/Projects/yoi/.worktree/00001KV5W3PHW-plugin-wasm-tool-runtime`
|
||||||
|
- branch: `impl/00001KV5W3PHW-plugin-wasm-tool-runtime`
|
||||||
|
|
||||||
|
Coder Pod:
|
||||||
|
- `yoi-coder-00001KV5W3PHW`
|
||||||
|
|
||||||
|
No duplicate `queued -> inprogress` transition was performed; this resumes the already accepted in-progress work.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-coder-00001KV5W3PHW at: 2026-06-18T12:31:01Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Implementation report from Coder Pod `yoi-coder-00001KV5W3PHW`:
|
||||||
|
|
||||||
|
Commit:
|
||||||
|
- `10d12148 feat: run plugin tools through wasm runtime`
|
||||||
|
|
||||||
|
Changed files:
|
||||||
|
- `Cargo.lock`
|
||||||
|
- `crates/manifest/src/plugin.rs`
|
||||||
|
- `crates/pod/Cargo.toml`
|
||||||
|
- `crates/pod/src/feature/plugin.rs`
|
||||||
|
- `package.nix`
|
||||||
|
|
||||||
|
Implemented behavior:
|
||||||
|
- Added minimal sandboxed Plugin Tool WASM runtime using `wasmi`.
|
||||||
|
- Enabled registered Plugin Tool calls now execute through normal `Tool::execute` / `ToolOutput` / `ToolResult` paths.
|
||||||
|
- Added manifest-side helper to load resolved runtime module from pinned package:
|
||||||
|
- validates runtime kind/ABI;
|
||||||
|
- re-reads package from resolved path;
|
||||||
|
- verifies deterministic package digest before selecting runtime entry;
|
||||||
|
- bounds package/module size and reports safe diagnostics.
|
||||||
|
- Added `yoi-plugin-wasm-1` host ABI:
|
||||||
|
- required export: `yoi_tool_call()`;
|
||||||
|
- required guest export: `memory`;
|
||||||
|
- host imports under `yoi:tool` only:
|
||||||
|
- `tool_name_len() -> i32`
|
||||||
|
- `tool_name_read(ptr, len) -> i32`
|
||||||
|
- `input_len() -> i32`
|
||||||
|
- `input_read(ptr, len) -> i32`
|
||||||
|
- `output_write(ptr, len) -> i32`
|
||||||
|
- No WASI, filesystem, network, environment, or arbitrary host imports are provided; unsupported imports fail closed.
|
||||||
|
|
||||||
|
Bounds / failure behavior:
|
||||||
|
- Input JSON bound: `64 KiB`.
|
||||||
|
- Output JSON bound: `64 KiB`.
|
||||||
|
- Output summary bound: `1 KiB`.
|
||||||
|
- Linear memory bound: `2 MiB`.
|
||||||
|
- Table bound: `256`.
|
||||||
|
- Fuel bound: `5_000_000`.
|
||||||
|
- Wall timeout: `1s`.
|
||||||
|
- Diagnostics/errors are bounded and sanitized before surfacing as ordinary Tool errors.
|
||||||
|
- Malformed input JSON, malformed output JSON, output schema mismatch, oversized output, missing runtime/package/module, unsupported imports, load failure, and non-terminating execution fail closed.
|
||||||
|
|
||||||
|
Tests added/updated cover:
|
||||||
|
- Sample Plugin package Tool executes through WASM runtime.
|
||||||
|
- Tool input JSON reaches the module.
|
||||||
|
- Output JSON returns through ordinary Tool result path.
|
||||||
|
- Malformed input JSON.
|
||||||
|
- Malformed output JSON.
|
||||||
|
- Output schema mismatch.
|
||||||
|
- Oversize output.
|
||||||
|
- Non-terminating/high-fuel execution fail closed.
|
||||||
|
- Missing runtime/package/module diagnostic is safe and bounded.
|
||||||
|
- No ambient WASI/fs/network/env import access.
|
||||||
|
- Existing Plugin Tool registration behavior.
|
||||||
|
|
||||||
|
Validation reported by coder:
|
||||||
|
- Passed: `cargo fmt --check`
|
||||||
|
- Passed: `cargo check -p pod`
|
||||||
|
- Passed: `cargo test -p manifest plugin::`
|
||||||
|
- Passed: `cargo test -p pod feature::plugin`
|
||||||
|
- Passed: `git diff --check`
|
||||||
|
- Passed: `nix build .#yoi`
|
||||||
|
- Passed: `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Residual risks / notes:
|
||||||
|
- ABI is intentionally minimal and not a general Plugin capability model.
|
||||||
|
- Permission grants, richer host APIs, WASI-like APIs, per-plugin runtime configuration knobs, and schema-driven rich output contracts remain follow-up work.
|
||||||
|
- Cancellation has no explicit `ToolExecutionContext` cancellation token today; this implementation provides safe timeout/fuel-bounded execution and maps timeout/join failure into ordinary Tool errors.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KV5W3PHW at: 2026-06-18T12:37:14Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
Evidence checked:
|
||||||
|
- Child worktree のみ確認。
|
||||||
|
- `/home/hare/Projects/yoi/.worktree/00001KV5W3PHW-plugin-wasm-tool-runtime`
|
||||||
|
- implementation commit: `10d12148`
|
||||||
|
- base: `d32fb3bc`
|
||||||
|
- 変更箇所を確認。
|
||||||
|
- `crates/pod/src/feature/plugin.rs`
|
||||||
|
- `crates/manifest/src/plugin.rs`
|
||||||
|
- `crates/pod/Cargo.toml`
|
||||||
|
- `Cargo.lock`
|
||||||
|
- `package.nix`
|
||||||
|
- Read-only validation:
|
||||||
|
- Passed: `git diff --check d32fb3bc..10d12148`
|
||||||
|
|
||||||
|
Acceptance review:
|
||||||
|
- WASM runtime は `wasmi` を使い、WASI setup はなく、host import surface は `yoi_plugin_tool_v1` の最小 input/output 関数だけに限定されている。
|
||||||
|
- `wasi_snapshot_preview1.fd_write` や `env.getenv` など ambient-style imports は拒否される。
|
||||||
|
- Plugin Tools は ordinary `Feature` tool contribution / `ToolExecutor` path で `ToolOutput` / `ToolError` を返し、hidden context injection path は見当たらない。
|
||||||
|
- module/input/output/summary/error/memory/table/stack/fuel などの bounds が実装されている。
|
||||||
|
- malformed output、invalid UTF-8、schema mismatch、oversize output は `ToolError` として fail closed する。
|
||||||
|
- runtime module selection は resolved plugin record、resolved package path、recorded digest、runtime kind/ABI、entry path に基づき、archive digest を再検証してから module bytes を使用している。
|
||||||
|
- non-termination は fuel exhaustion と runtime timeout wrapper で fail closed する。現行 `ToolExecutionContext` に cancellation token がないため、明示的 cancellation-token integration がない点は、この Ticket の範囲では blocker ではないと判断した。
|
||||||
|
- `wasmi` は `default-features = false` で `std` / `extra-checks` のみ、`wat` は dev-only。WASI/network/process capability library の追加は見当たらない。
|
||||||
|
|
||||||
|
Validation not run by reviewer:
|
||||||
|
- `cargo test` / `cargo check` / `nix build` は read-only review scope では build artifacts を書くため未実行。Coder reported validation を evidence とした。
|
||||||
|
|
||||||
|
Risk assessment:
|
||||||
|
- residual risk は低〜中程度。
|
||||||
|
- sandbox boundary は Ticket scope に対して妥当。No WASI / no fs / no network / no env imports、bounded IO、bounded diagnostics、deterministic digest check がある。
|
||||||
|
- `tokio::time::timeout` は `spawn_blocking` の実行中 task を強制 abort しないが、fuel により guest execution は有限化される。より強い cooperative cancellation semantics は Tool execution API/runtime cancellation model の follow-up として扱うべき。
|
||||||
|
- Permission grants / richer host API authority は正しく未実装の follow-up に残っている。
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Approved. No blocker remains.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T12:39:30Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Integration report:
|
||||||
|
|
||||||
|
Merged implementation branch into orchestration branch:
|
||||||
|
- branch: `impl/00001KV5W3PHW-plugin-wasm-tool-runtime`
|
||||||
|
- implementation commit: `10d12148 feat: run plugin tools through wasm runtime`
|
||||||
|
- merge commit: `05cd788c merge: plugin wasm tool runtime`
|
||||||
|
|
||||||
|
Reviewer result:
|
||||||
|
- `approve` recorded from `yoi-reviewer-00001KV5W3PHW`.
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree `/home/hare/Projects/yoi/.worktree/orchestration`:
|
||||||
|
- Passed: `cargo fmt --check`
|
||||||
|
- Passed: `cargo check -p pod`
|
||||||
|
- Passed: `cargo test -p manifest plugin::`
|
||||||
|
- Passed: `cargo test -p pod feature::plugin`
|
||||||
|
- 21 passed
|
||||||
|
- Passed: `git diff --check`
|
||||||
|
- Passed: `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Outcome:
|
||||||
|
- Enabled Plugin Tool calls now execute through minimal `wasmi` runtime with no WASI/fs/network/env host imports.
|
||||||
|
- Runtime module selection is deterministic from resolved package path/digest/runtime config and rechecks package digest.
|
||||||
|
- Tool input/output/errors are bounded and returned through ordinary Tool result/error path.
|
||||||
|
- Missing/malformed/oversize/schema-mismatch/non-terminating execution fails closed with safe Tool errors.
|
||||||
|
- Permission grants, richer host APIs, WASI-like APIs, and stronger cancellation-token integration remain follow-up scope.
|
||||||
|
|
||||||
|
Cleanup planned:
|
||||||
|
- Stop related coder/reviewer Pods.
|
||||||
|
- Remove only child implementation worktree/branch for this Ticket.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-18T12:39:30Z from: inprogress to: done reason: merged_validated field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Reviewer approved, implementation branch merged into the orchestration branch, and focused plus packaging validation passed in the Orchestrator worktree. Marking Ticket done in the orchestration branch.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-18T13:55:12Z from: done to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-18T13:55:12Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Ticket `00001KV5W3PHW` (`Plugin: execute Plugin Tool with minimal WASM runtime`) はすでに `state: done` に到達していたため、workspace Panel から close しました。
|
||||||
|
|
||||||
|
この Close action によって、実装作業、state 変更、Orchestrator/Companion launch、worker invocation は開始されていません。
|
||||||
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -0,0 +1 @@
|
|||||||
|
{"id":"orch-plan-20260618-131145-1","ticket_id":"00001KV5W3PJ3","kind":"accepted_plan","accepted_plan":{"summary":"Accept Plugin permission grant enforcement work. Implement typed requested/granted permission matching for Plugin Tool registration/execution and future host API denial diagnostics, fail-closed without implementing fs/https APIs.","branch":"impl/00001KV5W3PJ3-plugin-permission-grants","worktree":"/home/hare/Projects/yoi/.worktree/00001KV5W3PJ3-plugin-permission-grants","role_plan":"Orchestrator creates dedicated implementation worktree and spawns Coder with write scope limited to that worktree. Reviewer will run read-only after implementation report. Dependency `00001KV5W3PHW` is done and workspace is clean."},"author":"yoi-orchestrator","at":"2026-06-18T13:11:45Z"}
|
||||||
@@ -1,11 +1,13 @@
|
|||||||
---
|
---
|
||||||
title: 'Plugin: enforce Plugin permission grants'
|
title: 'Plugin: enforce Plugin permission grants'
|
||||||
state: 'ready'
|
state: 'closed'
|
||||||
created_at: '2026-06-15T14:48:59Z'
|
created_at: '2026-06-15T14:48:59Z'
|
||||||
updated_at: '2026-06-15T14:50:28Z'
|
updated_at: '2026-06-18T14:24:42Z'
|
||||||
assignee: null
|
assignee: null
|
||||||
readiness: 'implementation_ready'
|
readiness: 'implementation_ready'
|
||||||
risk_flags: ['plugin', 'permission', 'grant-enforcement', 'capability-boundary', 'tool-execution']
|
risk_flags: ['plugin', 'permission', 'grant-enforcement', 'capability-boundary', 'tool-execution']
|
||||||
|
queued_by: 'workspace-panel'
|
||||||
|
queued_at: '2026-06-18T13:11:00Z'
|
||||||
---
|
---
|
||||||
|
|
||||||
## Background
|
## Background
|
||||||
|
|||||||
@@ -0,0 +1,30 @@
|
|||||||
|
Ticket `00001KV5W3PJ3` is complete.
|
||||||
|
|
||||||
|
Completed implementation:
|
||||||
|
- Added typed Plugin permission declarations/grants for tool surfaces, tool names/namespaces, `external_write`, and future `host_api.https` / `host_api.fs` boundaries.
|
||||||
|
- Bound grants to source-qualified package identity, deterministic digest, and exact package version.
|
||||||
|
- Added fail-closed registration gating in `PluginToolFeature::install`.
|
||||||
|
- Added independent runtime execution gating in `run_plugin_wasm_tool` before WASM load/execute.
|
||||||
|
- Added future host API permission boundary checks without implementing actual `https` / `fs` host APIs.
|
||||||
|
- Added bounded/sanitized denial diagnostics.
|
||||||
|
- Preserved the existing PreToolCall / Tool permission path; plugin grants are an additional fail-closed gate, not an ambient authority grant.
|
||||||
|
|
||||||
|
Reviewed / merged:
|
||||||
|
- Implementation commit: `b1ba1599` (`plugin: enforce permission grants`)
|
||||||
|
- Reviewer result: approve, no blockers.
|
||||||
|
- Orchestrator merge commit: `94aa3c1d` (`merge: plugin permission grants`)
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p manifest -p pod` — passed
|
||||||
|
- `cargo test -p pod plugin -- --nocapture` — passed; 27 passed, 0 failed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
|
||||||
|
Cleanup:
|
||||||
|
- Stopped Coder Pod `yoi-coder-00001KV5W3PJ3`.
|
||||||
|
- Stopped Reviewer Pod `yoi-reviewer-00001KV5W3PJ3`.
|
||||||
|
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KV5W3PJ3-plugin-permission-grants`.
|
||||||
|
- Deleted merged branch `impl/00001KV5W3PJ3-plugin-permission-grants`.
|
||||||
|
|
||||||
|
Root/original workspace promotion was not performed in this step; the completed work is integrated on the Orchestrator branch.
|
||||||
@@ -5,3 +5,385 @@
|
|||||||
LocalTicketBackend によって作成されました。
|
LocalTicketBackend によって作成されました。
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: workspace-panel at: 2026-06-18T13:11:00Z from: ready to: queued reason: queued field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を `workspace-panel` が queued にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: decision author: yoi-orchestrator at: 2026-06-18T13:11:45Z -->
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
Routing decision: implementation_ready
|
||||||
|
|
||||||
|
Reason:
|
||||||
|
- Panel Queue により routing が明示的に許可され、Ticket は `queued`。
|
||||||
|
- Ticket body / thread / relations / OrchestrationPlan / Orchestrator workspace state を確認した。
|
||||||
|
- `depends_on 00001KV5W3PHW` は done/closed 済みで、Plugin Tool execution path が存在するため typed relation blocker は解消済み。
|
||||||
|
- 本 Ticket は Plugin manifest の requested permissions と Profile/config grants を照合し、enablement / Tool registration / Tool execution / future host API dispatch の enforcement points を明確にする実装であり、`https` / `fs` host API 実装や broad policy UI は non-goal として明確。
|
||||||
|
- permission / grant-enforcement / capability-boundary / tool-execution risk は高いが、fail-closed conditions、diagnostics、PreToolCall alignment、external_write handling が Ticket に具体化されているため implementation-ready と判断する。
|
||||||
|
|
||||||
|
Evidence checked:
|
||||||
|
- Ticket body/thread: requirements、initial grant model、acceptance criteria、non-goals、related work を確認。
|
||||||
|
- Ticket relations: outgoing `depends_on 00001KV5W3PHW` は done/closed。related design `00001KSXRQ4G8` は blocker ではない。
|
||||||
|
- OrchestrationPlan: 既存 record なし。
|
||||||
|
- Orchestrator workspace: `/home/hare/Projects/yoi/.worktree/orchestration` は clean、`b6685af3` 上。
|
||||||
|
- Visible Pods/worktrees: active implementation child なし。
|
||||||
|
|
||||||
|
IntentPacket:
|
||||||
|
|
||||||
|
Intent:
|
||||||
|
- Plugin requested permissions と explicit grants を typed model で照合し、Plugin Tool registration/execution と future host API dispatch が grant なしでは fail closed になる boundary を実装する。
|
||||||
|
|
||||||
|
Binding decisions / invariants:
|
||||||
|
- Package presence / discovery / Tool registration だけで execution authority を得ない。
|
||||||
|
- Requested but not granted は fail closed。
|
||||||
|
- Unknown permission kind / unsupported grant / overly broad ambiguous grant は fail closed または explicit diagnostic。
|
||||||
|
- Grant は package ref / source-qualified identity / digest / version と結びつけ、mismatch grant は使わない。
|
||||||
|
- Permission declarations/grants を ambient workspace FS/network authority として扱わない。
|
||||||
|
- `https` / `fs` host API の実行実装は non-goal。ただし requested/granted 型と denial diagnostics は扱う。
|
||||||
|
- Tool effect / external_write metadata は existing permission / PreToolCall path と矛盾させない。
|
||||||
|
- Denial diagnostics は bounded/safe で、hidden model context injection しない。
|
||||||
|
|
||||||
|
Requirements / acceptance criteria:
|
||||||
|
- Grant なしの Plugin Tool は登録または実行されず safe diagnostic になる。
|
||||||
|
- Granted Tool だけが登録または実行可能になる。
|
||||||
|
- Requested surface missing、requested tool missing、external_write missing、host API missing、digest/version/source mismatch、unknown permission kind は fail closed。
|
||||||
|
- Denied reason が diagnostic / trace で確認できる。
|
||||||
|
- Existing PreToolCall / Tool permission path と矛盾しない。
|
||||||
|
- Tests cover no grant denies Plugin Tool execution, grant allows specific Plugin Tool, unrelated package grant does not apply, digest mismatch denies, requested surface missing denies, external_write missing denies, unknown permission kind fails closed, bounded safe denial reason。
|
||||||
|
|
||||||
|
Implementation latitude:
|
||||||
|
- Initial grant model は `surfaces.tool`, tool names/namespaces, external_write flag, `host_api.https`, `host_api.fs` を狭く始める。
|
||||||
|
- Enforcement point のうち Tool registration と Tool execution のどちらで落とすかは実装判断。ただし model-visible schema gating と runtime execution gating の境界を実装報告に明記する。
|
||||||
|
- Existing Plugin resolver / Tool surface / WASM runtime code に合わせて typed structs / diagnostics を配置してよい。
|
||||||
|
|
||||||
|
Escalate if:
|
||||||
|
- PreToolCall / Tool metadata public API の broad redesign が必要。
|
||||||
|
- Grants を安全に package digest/version/source と結合できない。
|
||||||
|
- Future host API dispatch boundary を追加するには runtime executor redesign が必要。
|
||||||
|
- Permission UI/policy semantics を product decision として固定する必要が出る。
|
||||||
|
|
||||||
|
Validation:
|
||||||
|
- focused plugin permission/grant tests。
|
||||||
|
- relevant `cargo test` / `cargo check`。
|
||||||
|
- `cargo fmt --check`。
|
||||||
|
- `git diff --check`。
|
||||||
|
- `nix build .#yoi` if dependencies/Cargo.lock/package changes occur。
|
||||||
|
|
||||||
|
Critical risks / reviewer focus:
|
||||||
|
- fail-closed grant enforcement at registration and execution。
|
||||||
|
- source/digest/version binding。
|
||||||
|
- no ambient authority accidentally granted。
|
||||||
|
- external_write/effect metadata and PreToolCall consistency。
|
||||||
|
- bounded safe diagnostics。
|
||||||
|
- Plugin Tool execution path from `00001KV5W3PHW` is gated by grants。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-18T13:11:51Z from: queued to: inprogress reason: orchestrator_acceptance_dependency_done field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Routing decision と accepted implementation plan を記録済み。dependency `00001KV5W3PHW` は done/closed で relation blocker は解消済み。Orchestrator workspace は clean。implementation side effects の前に `queued -> inprogress` acceptance を記録する。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T13:12:47Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Implementation start failure / recovery note:
|
||||||
|
|
||||||
|
`queued -> inprogress` acceptance と worktree 作成は完了したが、Coder Pod spawn に失敗した。
|
||||||
|
|
||||||
|
Created worktree:
|
||||||
|
- `/home/hare/Projects/yoi/.worktree/00001KV5W3PJ3-plugin-permission-grants`
|
||||||
|
- branch: `impl/00001KV5W3PJ3-plugin-permission-grants`
|
||||||
|
|
||||||
|
Failure:
|
||||||
|
- `SpawnPod` failed before child Pod creation.
|
||||||
|
- Error: `failed to spawn /home/hare/Projects/yoi/target/debug/yoi (deleted) pod: No such file or directory (os error 2)`
|
||||||
|
|
||||||
|
Interpretation:
|
||||||
|
- Runtime binary path for this long-lived Orchestrator process again points at a deleted executable. This is an operational/runtime issue, not a Ticket requirement issue.
|
||||||
|
- No Coder Pod was started and no implementation commit exists in the child worktree yet.
|
||||||
|
|
||||||
|
Recovery needed:
|
||||||
|
- Refresh/restart the Orchestrator runtime or provide a valid Pod runtime command so `SpawnPod` can launch children again.
|
||||||
|
- After recovery, reuse the existing clean child worktree/branch and resume Coder spawn for this in-progress Ticket.
|
||||||
|
|
||||||
|
State handling:
|
||||||
|
- Ticket remains `inprogress` because acceptance and worktree side effects already happened; it is not silently returned to `queued`.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T13:56:44Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Implementation resume note:
|
||||||
|
|
||||||
|
Coder Pod の再開を試み、最初の `SpawnPod` は child scope に runtime workspace root `/home/hare/Projects/yoi` の read scope が含まれていなかったため失敗した。
|
||||||
|
|
||||||
|
Recovery:
|
||||||
|
- 既存 implementation worktree `/home/hare/Projects/yoi/.worktree/00001KV5W3PJ3-plugin-permission-grants` を再利用。
|
||||||
|
- child scope を workspace root read + implementation worktree write に狭く設定して再試行。
|
||||||
|
- Coder Pod `yoi-coder-00001KV5W3PJ3` の起動に成功。
|
||||||
|
|
||||||
|
Current status:
|
||||||
|
- Ticket は `inprogress` のまま。
|
||||||
|
- Coder は Plugin permission grants 実装、focused validation、commit、実装報告を行う予定。
|
||||||
|
- root/original workspace は触らず、implementation worktree 上で作業するよう指示済み。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T14:15:12Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Coder implementation report received:
|
||||||
|
|
||||||
|
Commit:
|
||||||
|
- `b1ba1599` — `plugin: enforce permission grants`
|
||||||
|
|
||||||
|
Summary:
|
||||||
|
- typed plugin permission declarations/grants を追加。
|
||||||
|
- `surfaces.tool`
|
||||||
|
- specific tool names
|
||||||
|
- tool namespaces
|
||||||
|
- `external_write`
|
||||||
|
- future `host_api.https` / `host_api.fs`
|
||||||
|
- grant binding を source-qualified package id / deterministic digest / exact package version に結合。
|
||||||
|
- registration gating を `PluginToolFeature::install` に実装。
|
||||||
|
- ungranted / unrequested plugin tools は登録されない。
|
||||||
|
- partial grant では authorized tools のみ登録し、skipped tools は bounded diagnostics。
|
||||||
|
- runtime execution gating を `run_plugin_wasm_tool` に実装。
|
||||||
|
- WASM 読み込み/実行前に binding と requested/granted tool authority を再確認。
|
||||||
|
- future host API boundary として `validate_wasm_imports` が `yoi:https` / `yoi:fs` imports を認識し、non-implemented boundary error の前に permission check。
|
||||||
|
- actual `https` / `fs` host API は実装していない。
|
||||||
|
- `external_write` を plugin tool manifest metadata に追加し、requested+granted の場合のみ許可。
|
||||||
|
- Existing PreToolCall/tool permission path は変更せず、plugin grant checks を追加の fail-closed gate とした。
|
||||||
|
|
||||||
|
Files changed:
|
||||||
|
- `crates/manifest/src/plugin.rs`
|
||||||
|
- `crates/pod/src/feature/plugin.rs`
|
||||||
|
- `crates/pod/src/pod.rs`
|
||||||
|
|
||||||
|
Validation reported by Coder:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `cargo check -p manifest -p pod`
|
||||||
|
- `cargo test -p pod plugin -- --nocapture` — 27 passed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — 17 passed
|
||||||
|
- `git diff --check`
|
||||||
|
|
||||||
|
Orchestrator evidence checked:
|
||||||
|
- Pod output を確認。
|
||||||
|
- implementation worktree は clean。
|
||||||
|
- commit `b1ba1599` が branch `impl/00001KV5W3PJ3-plugin-permission-grants` の HEAD。
|
||||||
|
- diff stat: `crates/manifest/src/plugin.rs`, `crates/pod/src/feature/plugin.rs`, `crates/pod/src/pod.rs` に 575 insertions / 19 deletions。
|
||||||
|
|
||||||
|
Routing classification: review_needed
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- recorded intent / invariants / acceptance criteria に照らして、read-only Reviewer Pod で外部レビューする。
|
||||||
|
- 特に fail-closed grant enforcement、source/digest/version binding、no ambient authority、external_write/effect metadata、bounded diagnostics、existing PreToolCall path との整合性を確認する。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: plan author: yoi-orchestrator at: 2026-06-18T14:16:18Z -->
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
Review dispatch:
|
||||||
|
|
||||||
|
Reviewer Pod `yoi-reviewer-00001KV5W3PJ3` を read-only scope で起動した。
|
||||||
|
|
||||||
|
Review target:
|
||||||
|
- worktree: `/home/hare/Projects/yoi/.worktree/00001KV5W3PJ3-plugin-permission-grants`
|
||||||
|
- branch: `impl/00001KV5W3PJ3-plugin-permission-grants`
|
||||||
|
- commit: `b1ba1599`
|
||||||
|
|
||||||
|
Reviewer focus:
|
||||||
|
- recorded intent / invariants / acceptance criteria に対する適合性。
|
||||||
|
- registration / execution の fail-closed grant enforcement。
|
||||||
|
- source-qualified identity / digest / version binding。
|
||||||
|
- unrelated grant / digest mismatch / missing surface/tool/external_write / unknown kind の拒否。
|
||||||
|
- `external_write` と Tool effect / PreToolCall path の整合性。
|
||||||
|
- future `https` / `fs` host API permission boundary が ambient authority を作っていないこと。
|
||||||
|
- bounded safe diagnostics。
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Reviewer output を確認し、approve なら Ticket review に記録して merge-ready 判断へ進む。request_changes なら Coder に修正依頼する。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KV5W3PJ3 at: 2026-06-18T14:22:32Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KV5W3PJ3`
|
||||||
|
- branch: `impl/00001KV5W3PJ3-plugin-permission-grants`
|
||||||
|
- commit: `b1ba1599` (`plugin: enforce permission grants`)
|
||||||
|
|
||||||
|
No blockers found.
|
||||||
|
|
||||||
|
Review / validation performed:
|
||||||
|
- review target branch/head が `impl/00001KV5W3PJ3-plugin-permission-grants` at `b1ba1599` であることを確認。
|
||||||
|
- merge-base `a984f580` との差分を確認。
|
||||||
|
- changed files は以下に限定:
|
||||||
|
- `crates/manifest/src/plugin.rs`
|
||||||
|
- `crates/pod/src/feature/plugin.rs`
|
||||||
|
- `crates/pod/src/pod.rs`
|
||||||
|
- `git diff --check` against merge-base を実行し、whitespace/check failure なし。
|
||||||
|
- Review boundary が read-only/static review のため cargo validation は再実行せず、Coder reported validation を確認。
|
||||||
|
|
||||||
|
Evidence:
|
||||||
|
- typed permission/grant model が追加されている。
|
||||||
|
- `PluginGrantConfig` は non-empty grants を source-qualified id、digest、exact version に binding し、missing/mismatched binding では fail する。
|
||||||
|
- permission variants は `surfaces.*`、tool names/namespaces、`external_write`、future `host_api.https/fs` を含む。
|
||||||
|
- `PluginToolManifest.external_write` は explicit metadata として追加され、matching request+grant を要求する設計。
|
||||||
|
- grant binding は resolution 時に enforcement され、mismatch では `Grant` diagnostic と no resolved record になる。
|
||||||
|
- registration は fail-closed。
|
||||||
|
- `PluginToolFeature::install` が tool 登録前に `authorize_plugin_tool` を呼び、denied tool は bounded diagnostic として skip する。
|
||||||
|
- `authorize_plugin_tool` は requested+granted `surfaces.tool`、tool permission/name/namespace、必要時 `external_write` を要求する。
|
||||||
|
- execution も独立して fail-closed。
|
||||||
|
- `run_plugin_wasm_tool` が WASM read/load/execute 前に manifest tool を再確認し、`authorize_plugin_tool` を再実行する。
|
||||||
|
- future host API は実装せずに permission boundary を model 化。
|
||||||
|
- `authorize_plugin_host_api` は requested+granted host API permission を要求してから `host_api.* is not implemented` を返す。
|
||||||
|
- `validate_wasm_imports` は `yoi:https` / `yoi:fs` imports を authorization path に通してから unsupported module を reject する。
|
||||||
|
- denial diagnostics は bounded/sanitized。
|
||||||
|
- `bounded_message` が 512 bytes に truncation し、newline/tab 以外の control characters を除去する。
|
||||||
|
- Existing Tool / PreToolCall path と矛盾していない。
|
||||||
|
- granted plugin tools は normal `ToolRegistry` / `PreToolCall` policy path に入る。
|
||||||
|
|
||||||
|
Test coverage evidence in diff:
|
||||||
|
- no grant denies registration and runtime execution。
|
||||||
|
- specific grant registers only intended tool。
|
||||||
|
- unrelated package/digest/version grants do not authorize。
|
||||||
|
- requested surface/tool/external_write missing denies。
|
||||||
|
- future host API permissions checked before unimplemented boundary。
|
||||||
|
- exact package identity/digest/version binding and mismatch cases。
|
||||||
|
- unknown permission kind fails at manifest parse boundary。
|
||||||
|
|
||||||
|
Residual note:
|
||||||
|
- `external_write` effect metadata は broader `ToolMeta` public API effect field ではなく plugin manifest/tool metadata level で表現されている。Ticket の escalation condition が broad PreToolCall/Tool metadata redesign を要求していたため、この slice では implemented permission gate として許容可能。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T14:23:59Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Merge / validation report:
|
||||||
|
|
||||||
|
Implementation branch `impl/00001KV5W3PJ3-plugin-permission-grants` を Orchestrator worktree の `orchestration` branch に merge した。
|
||||||
|
|
||||||
|
Merge:
|
||||||
|
- merge commit: `94aa3c1d` — `merge: plugin permission grants`
|
||||||
|
- implementation commit: `b1ba1599` — `plugin: enforce permission grants`
|
||||||
|
- changed files:
|
||||||
|
- `crates/manifest/src/plugin.rs`
|
||||||
|
- `crates/pod/src/feature/plugin.rs`
|
||||||
|
- `crates/pod/src/pod.rs`
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p manifest -p pod` — passed
|
||||||
|
- `cargo test -p pod plugin -- --nocapture` — passed; 27 passed, 0 failed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
|
||||||
|
Review:
|
||||||
|
- Reviewer `yoi-reviewer-00001KV5W3PJ3` returned `approve` with no blockers.
|
||||||
|
|
||||||
|
Outcome:
|
||||||
|
- Recorded requirements are satisfied.
|
||||||
|
- Implementation is merged into the Orchestrator branch and validated.
|
||||||
|
- Ticket is ready for done/close processing under standing merge/close completion authority. Root/original workspace promotion is not performed in this step.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T14:24:23Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Cleanup report:
|
||||||
|
|
||||||
|
Plugin permission grants Ticket の implementation/review Pods と child worktree を cleanup した。
|
||||||
|
|
||||||
|
Stopped Pods:
|
||||||
|
- `yoi-coder-00001KV5W3PJ3`
|
||||||
|
- `yoi-reviewer-00001KV5W3PJ3`
|
||||||
|
|
||||||
|
Removed child implementation worktree:
|
||||||
|
- `/home/hare/Projects/yoi/.worktree/00001KV5W3PJ3-plugin-permission-grants`
|
||||||
|
|
||||||
|
Deleted merged implementation branch:
|
||||||
|
- `impl/00001KV5W3PJ3-plugin-permission-grants` at `b1ba1599`
|
||||||
|
|
||||||
|
Orchestrator branch remains the integration authority for this completed work. Root/original workspace promotion was not performed in this step.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-18T14:24:29Z from: inprogress to: done reason: merged_validated_review_approved field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Implementation commit `b1ba1599` was reviewed and approved, merged into the Orchestrator branch as `94aa3c1d`, validated in the Orchestrator worktree, and child implementation resources were cleaned up. Requirements and acceptance criteria are satisfied for this Ticket.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-18T14:24:42Z from: done to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-18T14:24:42Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Ticket `00001KV5W3PJ3` is complete.
|
||||||
|
|
||||||
|
Completed implementation:
|
||||||
|
- Added typed Plugin permission declarations/grants for tool surfaces, tool names/namespaces, `external_write`, and future `host_api.https` / `host_api.fs` boundaries.
|
||||||
|
- Bound grants to source-qualified package identity, deterministic digest, and exact package version.
|
||||||
|
- Added fail-closed registration gating in `PluginToolFeature::install`.
|
||||||
|
- Added independent runtime execution gating in `run_plugin_wasm_tool` before WASM load/execute.
|
||||||
|
- Added future host API permission boundary checks without implementing actual `https` / `fs` host APIs.
|
||||||
|
- Added bounded/sanitized denial diagnostics.
|
||||||
|
- Preserved the existing PreToolCall / Tool permission path; plugin grants are an additional fail-closed gate, not an ambient authority grant.
|
||||||
|
|
||||||
|
Reviewed / merged:
|
||||||
|
- Implementation commit: `b1ba1599` (`plugin: enforce permission grants`)
|
||||||
|
- Reviewer result: approve, no blockers.
|
||||||
|
- Orchestrator merge commit: `94aa3c1d` (`merge: plugin permission grants`)
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p manifest -p pod` — passed
|
||||||
|
- `cargo test -p pod plugin -- --nocapture` — passed; 27 passed, 0 failed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
|
||||||
|
Cleanup:
|
||||||
|
- Stopped Coder Pod `yoi-coder-00001KV5W3PJ3`.
|
||||||
|
- Stopped Reviewer Pod `yoi-reviewer-00001KV5W3PJ3`.
|
||||||
|
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KV5W3PJ3-plugin-permission-grants`.
|
||||||
|
- Deleted merged branch `impl/00001KV5W3PJ3-plugin-permission-grants`.
|
||||||
|
|
||||||
|
Root/original workspace promotion was not performed in this step; the completed work is integrated on the Orchestrator branch.
|
||||||
|
|
||||||
|
---
|
||||||
|
|||||||
@@ -1,8 +1,8 @@
|
|||||||
---
|
---
|
||||||
title: 'Panel startup latency E2E を一覧データ描画完了基準に修正する'
|
title: 'Panel startup latency E2E を一覧データ描画完了基準に修正する'
|
||||||
state: 'inprogress'
|
state: 'closed'
|
||||||
created_at: '2026-06-15T16:44:06Z'
|
created_at: '2026-06-15T16:44:06Z'
|
||||||
updated_at: '2026-06-17T09:50:53Z'
|
updated_at: '2026-06-19T05:44:09Z'
|
||||||
assignee: null
|
assignee: null
|
||||||
readiness: 'implementation_ready'
|
readiness: 'implementation_ready'
|
||||||
risk_flags: ['panel', 'e2e', 'startup-latency', 'readiness-metric', 'ticket-list-rendering']
|
risk_flags: ['panel', 'e2e', 'startup-latency', 'readiness-metric', 'ticket-list-rendering']
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
Closed as superseded/completed by the later dashboard content-ready and live startup latency work.
|
||||||
|
|
||||||
|
This Ticket corrected the mistaken premise that first frame readiness represented usable Panel startup readiness, but its single fixture-row rows-ready metric was later judged insufficient for the user-visible delay. Follow-up work strengthened the metric to dashboard content-ready snapshot validation and then used live-path measurements to identify and fix the Pod status probe/session-log startup bottleneck.
|
||||||
|
|
||||||
|
Relevant follow-ups:
|
||||||
|
- 00001KVDETSN6: user-visible dashboard content-ready metric and snapshot validation;
|
||||||
|
- 00001KVDQH839: shell-enter launch-path readiness measurement;
|
||||||
|
- 00001KVF0ZJM5: live startup latency fix by removing duplicate Pod probes and session-log reads from the initial list path.
|
||||||
@@ -123,4 +123,200 @@ Recovery needed:
|
|||||||
State handling:
|
State handling:
|
||||||
- Ticket remains `inprogress` because acceptance and worktree side effects already happened; it is not silently returned to `queued`.
|
- Ticket remains `inprogress` because acceptance and worktree side effects already happened; it is not silently returned to `queued`.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T12:05:59Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Implementation resumed:
|
||||||
|
|
||||||
|
Previous `SpawnPod` failure was recovered after Orchestrator runtime refresh. Reused existing clean child worktree and successfully spawned Coder Pod.
|
||||||
|
|
||||||
|
Worktree:
|
||||||
|
- `/home/hare/Projects/yoi/.worktree/00001KV62PF32-panel-rows-ready-e2e`
|
||||||
|
- branch: `impl/00001KV62PF32-panel-rows-ready-e2e`
|
||||||
|
|
||||||
|
Coder Pod:
|
||||||
|
- `yoi-coder-00001KV62PF32`
|
||||||
|
|
||||||
|
No duplicate `queued -> inprogress` transition was performed; this resumes the already accepted in-progress work.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-coder-00001KV62PF32 at: 2026-06-18T12:19:45Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Implementation report from Coder Pod `yoi-coder-00001KV62PF32`:
|
||||||
|
|
||||||
|
Commit:
|
||||||
|
- `fffdfd27 test: assert panel rows-ready fixture data`
|
||||||
|
|
||||||
|
Changed files:
|
||||||
|
- `tests/e2e/src/lib.rs`
|
||||||
|
- Added concrete `ExpectedPanelTicketRow` matcher.
|
||||||
|
- Exposed fixture ready/planning Ticket ids/titles/states.
|
||||||
|
- Added `wait_for_first_visible_frame`, `wait_for_fixture_ticket_rows_ready`, and delayed-row negative assertion helpers.
|
||||||
|
- `tests/e2e/tests/panel.rs`
|
||||||
|
- Replaced main startup readiness assertion from `rows.len() >= 2` / “full ready” to concrete ready fixture Ticket row readiness.
|
||||||
|
- Added matcher regression test proving absent/wrong fixture data is rejected.
|
||||||
|
- Added delayed reload assertion that first frame can arrive while fixture rows are still not rendered.
|
||||||
|
- `crates/tui/src/multi_pod.rs`
|
||||||
|
- Added comments clarifying `panel_ready` is first-visible-frame only, while `rows_rendered` snapshots are the data-backed readiness surface.
|
||||||
|
|
||||||
|
Behavior / evidence:
|
||||||
|
- Main startup readiness now distinguishes:
|
||||||
|
- first frame: legacy `panel_ready`, can be loading/empty;
|
||||||
|
- rows ready: concrete `rows_rendered` containing expected fixture Ticket id/title/state/kind;
|
||||||
|
- full/background completion: still observable via background task events, but no longer the startup readiness proxy.
|
||||||
|
- Startup readiness assertion is no longer satisfied by first frame alone or by weak `rows.len() >= N` checks.
|
||||||
|
- Delayed reload test asserts first visible frame can arrive while expected fixture Ticket row remains absent for the delayed window.
|
||||||
|
|
||||||
|
Validation reported by coder:
|
||||||
|
- Passed: `cargo test -p yoi-e2e --features e2e --no-run`
|
||||||
|
- Passed: `cargo test -p yoi-e2e --features e2e panel -- --nocapture`
|
||||||
|
- Passed: `cargo check -p yoi-e2e -p yoi -p tui`
|
||||||
|
- Passed: `cargo fmt --check`
|
||||||
|
- Passed: `git diff --check`
|
||||||
|
- Not run: `nix build .#yoi` — no runtime/package/dependency changes.
|
||||||
|
|
||||||
|
Measured values from focused post-commit reruns:
|
||||||
|
- `panel_fixture_ticket_row_ready_has_startup_budget`
|
||||||
|
- first visible frame: `20.403589ms` / budget `1.5s`
|
||||||
|
- fixture rows ready: `120.605891ms` / budget `5s`
|
||||||
|
- `panel_first_visible_render_arrives_before_background_reload`
|
||||||
|
- first visible frame: `20.311085ms` / budget `1.5s`
|
||||||
|
- reload held; test asserts ready fixture Ticket row remains absent for delayed window before exit.
|
||||||
|
|
||||||
|
Repository status:
|
||||||
|
- Child implementation worktree clean at `fffdfd27`.
|
||||||
|
|
||||||
|
Residual gaps:
|
||||||
|
- None known.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KV62PF32 at: 2026-06-18T12:24:00Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
Evidence checked:
|
||||||
|
- 対象 worktree / branch / commit が期待通りで clean であることを確認。
|
||||||
|
- branch: `impl/00001KV62PF32-panel-rows-ready-e2e`
|
||||||
|
- HEAD: `fffdfd2721fed5171d4dd9780f893b9bb323ab8a`
|
||||||
|
- base: `d32fb3bc3c82f1cb7e4a29d4fdf6e908ba495c7f`
|
||||||
|
- Diff scope は以下3ファイルに限定されていることを確認。
|
||||||
|
- `crates/tui/src/multi_pod.rs`
|
||||||
|
- `tests/e2e/src/lib.rs`
|
||||||
|
- `tests/e2e/tests/panel.rs`
|
||||||
|
|
||||||
|
Acceptance / intent review:
|
||||||
|
- Main startup readiness は `panel_fixture_ticket_row_ready_has_startup_budget` で concrete fixture Ticket row readiness を待つ形になっている。
|
||||||
|
- `rows.len() >= N` ではなく、fixture Ticket row の kind / id / title / status-state を matcher で確認している。
|
||||||
|
- `panel_ready` / `wait_for_first_visible_frame` は first-visible-frame only としてコメント・helper 名で区別されている。
|
||||||
|
- `wait_for_fixture_ticket_rows_ready` が startup rows-ready signal として定義されている。
|
||||||
|
- `panel_fixture_ticket_row_matcher_rejects_absent_fixture_data` により absent/wrong fixture data を reject する挙動が確認されている。
|
||||||
|
- delayed reload test は first frame が先に出る一方、held reload 中は expected fixture Ticket row が描画されないことを確認している。
|
||||||
|
- 既存 Panel mouse / row selection E2E は残っており、action dispatch なし・mouse capture behavior の coverage は維持されている。
|
||||||
|
- fixture isolation / no-provider / no-network 前提は維持されている。
|
||||||
|
|
||||||
|
Validation performed by reviewer:
|
||||||
|
- Passed: `cargo fmt --check`
|
||||||
|
- Passed: `git diff --check d32fb3bc..HEAD`
|
||||||
|
|
||||||
|
Validation not run by reviewer:
|
||||||
|
- `cargo test` / `cargo check` は read-only review scope では build/artifact 書き込みを伴うため未実行。Coder reported validation を evidence として確認した。
|
||||||
|
|
||||||
|
Risk assessment:
|
||||||
|
- residual risk は低い。変更は test/harness focused で Ticket boundary に沿っている。
|
||||||
|
- timing test は環境依存性が残るが、readiness predicate は first frame/loading paint ではなく concrete fixture row rendering を測るよう修正されている。
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Approved. No blocker remains.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T12:25:14Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Integration report:
|
||||||
|
|
||||||
|
Merged implementation branch into orchestration branch:
|
||||||
|
- branch: `impl/00001KV62PF32-panel-rows-ready-e2e`
|
||||||
|
- implementation commit: `fffdfd27 test: assert panel rows-ready fixture data`
|
||||||
|
- merge commit: `226eca7a merge: panel rows-ready e2e`
|
||||||
|
|
||||||
|
Reviewer result:
|
||||||
|
- `approve` recorded from `yoi-reviewer-00001KV62PF32`.
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree `/home/hare/Projects/yoi/.worktree/orchestration`:
|
||||||
|
- Passed: `cargo test -p yoi-e2e --features e2e --no-run`
|
||||||
|
- Passed: `cargo test -p yoi-e2e --features e2e panel -- --nocapture`
|
||||||
|
- panel E2E: 6 passed
|
||||||
|
- first visible frame examples: ~20.34ms / budget 1.5s
|
||||||
|
- fixture rows ready example: ~120.54ms / budget 5s
|
||||||
|
- Passed: `cargo check -p yoi-e2e -p yoi -p tui`
|
||||||
|
- Passed: `cargo fmt --check`
|
||||||
|
- Passed: `git diff --check`
|
||||||
|
|
||||||
|
Outcome:
|
||||||
|
- Startup readiness E2E now uses concrete fixture Ticket row render readiness instead of first visible/loading frame or weak row-count checks.
|
||||||
|
- `panel_ready` remains first-visible-frame only; `rows_rendered` fixture row matching is the data-backed readiness surface.
|
||||||
|
- Delayed reload coverage verifies first frame can arrive before rows-ready and expected fixture Ticket row remains absent while reload is held.
|
||||||
|
- Existing Panel mouse/row selection E2E remains covered.
|
||||||
|
|
||||||
|
Cleanup planned:
|
||||||
|
- Stop related coder/reviewer Pods.
|
||||||
|
- Remove only child implementation worktree/branch for this Ticket.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-18T12:25:14Z from: inprogress to: done reason: merged_validated field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Reviewer approved, implementation branch merged into the orchestration branch, and E2E-focused validation passed in the Orchestrator worktree. Marking Ticket done in the orchestration branch.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: hare at: 2026-06-18T13:30:51Z status: request_changes -->
|
||||||
|
|
||||||
|
## Review: request changes
|
||||||
|
|
||||||
|
Request changes.
|
||||||
|
|
||||||
|
The current result still does not answer the user-facing latency problem. The problematic latency is the time from launching `yoi panel` / pressing Enter to seeing the actual workspace dashboard content. The current E2E measures a direct subprocess spawn to one concrete fixture Ticket row appearing in `rows_rendered`; it does not require the dashboard content to be complete from the user's perspective, and it does not reproduce or attribute the clearly long live-workspace delay.
|
||||||
|
|
||||||
|
Do not treat fixture first-frame or single-row readiness numbers as evidence that no improvement is needed. The acceptance criterion must be strengthened to a user-visible dashboard-content-ready point and paired with slow-source attribution/improvement for the live-like Panel startup path.
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-19T05:44:09Z from: done to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-19T05:44:09Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Closed as superseded/completed by the later dashboard content-ready and live startup latency work.
|
||||||
|
|
||||||
|
This Ticket corrected the mistaken premise that first frame readiness represented usable Panel startup readiness, but its single fixture-row rows-ready metric was later judged insufficient for the user-visible delay. Follow-up work strengthened the metric to dashboard content-ready snapshot validation and then used live-path measurements to identify and fix the Pod status probe/session-log startup bottleneck.
|
||||||
|
|
||||||
|
Relevant follow-ups:
|
||||||
|
- 00001KVDETSN6: user-visible dashboard content-ready metric and snapshot validation;
|
||||||
|
- 00001KVDQH839: shell-enter launch-path readiness measurement;
|
||||||
|
- 00001KVF0ZJM5: live startup latency fix by removing duplicate Pod probes and session-log reads from the initial list path.
|
||||||
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|||||||
@@ -0,0 +1 @@
|
|||||||
|
{"id":"orch-plan-20260618-135757-1","ticket_id":"00001KVDETSN6","kind":"accepted_plan","accepted_plan":{"summary":"Panel startup latency の主 metric を user-visible dashboard content ready に置き直し、live-like fixture / expected dashboard snapshot / slow-source breakdown を追加し、必要な latency 改善を行う。first frame や単一 Ticket row readiness を主 evidence として扱わない。","branch":"impl/00001KVDETSN6-panel-dashboard-content-ready","worktree":"/home/hare/Projects/yoi/.worktree/00001KVDETSN6-panel-dashboard-content-ready","role_plan":"Orchestrator は専用 implementation worktree を作成し、Coder をその worktree への narrow write scope で起動する。既存 Plugin permission grants Coder とは主対象が異なり、Panel/E2E/TUI harness 側の変更として並行可能。Reviewer は実装報告後に read-only で確認する。"},"author":"yoi-orchestrator","at":"2026-06-18T13:57:57Z"}
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
{
|
||||||
|
"version": 1,
|
||||||
|
"relations": [
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVDETSN6",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KV5D7MG5",
|
||||||
|
"note": "Dashboard content-ready fixture should include orchestration overlay state.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-18T13:31:43Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVDETSN6",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KV5MRH6D",
|
||||||
|
"note": "Follows up Panel startup latency E2E work.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-18T13:31:43Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVDETSN6",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KV62PF32",
|
||||||
|
"note": "Supersedes the insufficient single-row rows-ready E2E with user-visible dashboard content-ready measurement.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-18T13:31:43Z"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,105 @@
|
|||||||
|
---
|
||||||
|
title: 'Panel startup latency をユーザー目線の dashboard content ready 基準で計測・改善する'
|
||||||
|
state: 'closed'
|
||||||
|
created_at: '2026-06-18T13:30:51Z'
|
||||||
|
updated_at: '2026-06-18T14:48:44Z'
|
||||||
|
assignee: null
|
||||||
|
readiness: 'implementation_ready'
|
||||||
|
risk_flags: ['panel', 'e2e', 'startup-latency', 'user-visible-readiness', 'dashboard-content', 'profiling']
|
||||||
|
queued_by: 'workspace-panel'
|
||||||
|
queued_at: '2026-06-18T13:55:08Z'
|
||||||
|
---
|
||||||
|
|
||||||
|
## Background
|
||||||
|
|
||||||
|
ユーザーが問題にしている `yoi panel` startup latency は、first frame や fixture の単一 Ticket row が `rows_rendered` に出るまでではなく、**ユーザーが `yoi panel` を起動してから、workspace dashboard として実際に使えるコンテンツが画面に揃って見えるまで**の時間である。
|
||||||
|
|
||||||
|
既存の `00001KV62PF32` は `panel_ready` / first frame と単一 fixture Ticket row readiness の混同を修正したが、まだ以下の点で不十分だった。
|
||||||
|
|
||||||
|
- direct subprocess spawn から単一 fixture Ticket row の `rows_rendered` までを測っているだけで、workspace dashboard 全体の content ready ではない。
|
||||||
|
- live workspace でユーザーが体感している明らかに長い遅延を再現・属性分解していない。
|
||||||
|
- fixture 上の約 120ms rows-ready をもって「追加改善不要」と判断してしまうと、ユーザー視点の問題を取り逃がす。
|
||||||
|
|
||||||
|
この Ticket では、Panel startup latency の主基準を user-visible dashboard content ready に置き直し、遅延源を計測・改善する。
|
||||||
|
|
||||||
|
## Definitions
|
||||||
|
|
||||||
|
- `panel_first_frame`: 初回 visible draw。loading / empty frame でもよい補助 metric。
|
||||||
|
- `fixture_single_row_ready`: 具体的な fixture Ticket row が `rows_rendered` に現れる補助 metric。
|
||||||
|
- `dashboard_content_ready`: ユーザーが workspace dashboard として必要な主要コンテンツが揃い、実際に画面へ描画された状態。この Ticket の主 metric。
|
||||||
|
|
||||||
|
`dashboard_content_ready` は少なくとも以下を含む。
|
||||||
|
|
||||||
|
- Ticket rows が fixture / live-like workspace の期待データと一致している。
|
||||||
|
- id
|
||||||
|
- title
|
||||||
|
- state/status
|
||||||
|
- row kind
|
||||||
|
- primary action / disabled reason where relevant
|
||||||
|
- Pod / Companion / Orchestrator 関連 row または status が、fixture / live-like workspace の期待状態と一致している。
|
||||||
|
- orchestration overlay を含む fixture では、local / orchestration state が表示上も期待通り反映されている。
|
||||||
|
- loading / empty / partial single-row render だけでは ready とみなさない。
|
||||||
|
|
||||||
|
## Requirements
|
||||||
|
|
||||||
|
- E2E / harness の readiness event または helper を追加・修正し、`dashboard_content_ready` を測れるようにする。
|
||||||
|
- first frame / single-row readiness とは別 metric にする。
|
||||||
|
- event 名・test 名・log 出力から意味が誤解されないようにする。
|
||||||
|
- 測定開始点は、ユーザーの `yoi panel` 起動に十分近いものにする。
|
||||||
|
- 基本は `Command::spawn` 直前からでよい。
|
||||||
|
- interactive shell 入力まで含めない場合は、その範囲を test/report に明記する。
|
||||||
|
- Fixture を live-like に強化する。
|
||||||
|
- 複数 Ticket state を含める。
|
||||||
|
- Pod metadata / Companion / Orchestrator 表示を含める。
|
||||||
|
- orchestration overlay を含める。
|
||||||
|
- 必要に応じて stale socket / slow observation / many Ticket records など、実遅延の候補を再現する fixture を追加する。
|
||||||
|
- `dashboard_content_ready` は単なる `rows.len() >= N` や単一 Ticket row match だけで通さない。
|
||||||
|
- expected dashboard snapshot / expected row set として比較する。
|
||||||
|
- 欠落 row、wrong status、wrong action、overlay 未反映を fail にする。
|
||||||
|
- Live workspace 相当の遅延源を属性分解する。
|
||||||
|
- Ticket scan / parsing
|
||||||
|
- orchestration overlay worktree validation / read
|
||||||
|
- Pod metadata scan
|
||||||
|
- socket/status probing
|
||||||
|
- Companion / Orchestrator lifecycle observation
|
||||||
|
- role session / local claim scan
|
||||||
|
- git worktree / branch checks
|
||||||
|
- 明らかに長い遅延がある場合は改善する。
|
||||||
|
- UI 初期化を content-ready 待ちで止めないだけでは不十分。
|
||||||
|
- 実コンテンツが揃うまでの経路自体を短くする。
|
||||||
|
- slow source を lazy / bounded / parallel / cached / timeout-shortened にできる場合は実装する。
|
||||||
|
- Before / after の実測値を implementation report に記録する。
|
||||||
|
- first frame
|
||||||
|
- dashboard content ready
|
||||||
|
- slow-source breakdown
|
||||||
|
- fixture 条件 / live-like 条件
|
||||||
|
- 測定で改善不要と判断する場合でも、ユーザーが見ている長い live latency がなぜ再現しないか、またはどの範囲外かを明示する。
|
||||||
|
|
||||||
|
## Acceptance criteria
|
||||||
|
|
||||||
|
- E2E が `dashboard_content_ready` を主 startup latency metric として測る。
|
||||||
|
- `panel_first_frame` または単一 Ticket row readiness だけでは、この Ticket の主 E2E は通らない。
|
||||||
|
- Expected dashboard snapshot に含まれる Ticket / Pod / Companion / Orchestrator / overlay 要素が揃って描画された時点を ready として扱う。
|
||||||
|
- Missing row / wrong state / missing overlay / missing action label の fixture では ready 判定が fail する。
|
||||||
|
- User-visible dashboard content ready の before / after 実測値が記録される。
|
||||||
|
- 遅延源の breakdown が記録され、主要 slow source に対して具体的な改善または明示的な non-action rationale がある。
|
||||||
|
- Live-like fixture または current workspace に近い条件で、ユーザー体感の長い遅延を取り逃がさない。
|
||||||
|
- Existing Panel behavior に regression がない。
|
||||||
|
- row selection
|
||||||
|
- composer target
|
||||||
|
- Queue action
|
||||||
|
- orchestration overlay display
|
||||||
|
- Validation: relevant `cargo test -p yoi-e2e --features e2e panel`, `cargo check`, `cargo fmt --check`, `git diff --check`, and `nix build .#yoi` if code/package/runtime behavior changes.
|
||||||
|
|
||||||
|
## Non-goals
|
||||||
|
|
||||||
|
- Interactive shell の command lookup / prompt rendering まで含めた OS/shell latency の厳密測定。
|
||||||
|
- すべての background observation が完全 settle するまで UI を出さないこと。
|
||||||
|
- Panel architecture の全面刷新。
|
||||||
|
- Ticket lifecycle semantics の変更。
|
||||||
|
|
||||||
|
## Related work
|
||||||
|
|
||||||
|
- `00001KV62PF32` — Panel startup latency E2E を一覧データ描画完了基準に修正する。単一 fixture row readiness までで不十分だったため request-changes 済み。
|
||||||
|
- `00001KV5MRH6D` — Panel startup latency E2E / first visible frame separation work。
|
||||||
|
- `00001KV5D7MG5` — Panel orchestration worktree Ticket state overlay。
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
Ticket `00001KVDETSN6` is complete.
|
||||||
|
|
||||||
|
Completed implementation:
|
||||||
|
- Added a user-visible `dashboard_content_ready` metric that carries and validates a rendered dashboard snapshot rather than treating first frame or a single row as ready.
|
||||||
|
- Added expected dashboard content coverage for Ticket rows, Pod rows, Companion status, Orchestrator status, orchestration overlay state, action labels, disabled reasons, local Ticket state, and overlay Ticket state.
|
||||||
|
- Added a real git/orchestration overlay fixture for the local-ready / overlay-inprogress case and validated the visible `ready→prog` / `Wait` row.
|
||||||
|
- Added negative coverage for missing expected row, wrong state, missing overlay state, and missing action label.
|
||||||
|
- Added bounded startup source breakdown including pod metadata/status probing, ticket config probe/parse, overlay validation/read/git checks, ticket scan/parse, local claim scan, pod row materialization, and total workspace panel build.
|
||||||
|
|
||||||
|
Reviewed / merged:
|
||||||
|
- Initial implementation: `fc1ee5bb` (`tui: measure panel dashboard readiness`)
|
||||||
|
- Review-fix implementation: `5870251b` (`tui: tighten panel dashboard readiness`)
|
||||||
|
- First review requested changes; blockers were fixed.
|
||||||
|
- Re-review approved with no remaining blockers.
|
||||||
|
- Orchestrator merge commit: `2d4d11e4` (`merge: panel dashboard readiness metric`)
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p tui --features e2e-test` — passed
|
||||||
|
- `cargo test -p yoi-e2e --features e2e --test panel` — passed; 7 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
|
||||||
|
Cleanup:
|
||||||
|
- Stopped Coder Pod `yoi-coder-00001KVDETSN6`.
|
||||||
|
- Stopped Reviewer Pod `yoi-reviewer-00001KVDETSN6-r2`.
|
||||||
|
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KVDETSN6-panel-dashboard-content-ready`.
|
||||||
|
- Deleted merged branch `impl/00001KVDETSN6-panel-dashboard-content-ready`.
|
||||||
|
|
||||||
|
Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction. The completed work is integrated on the Orchestrator branch.
|
||||||
@@ -0,0 +1,540 @@
|
|||||||
|
<!-- event: create author: "yoi ticket" at: 2026-06-18T13:30:51Z -->
|
||||||
|
|
||||||
|
## 作成
|
||||||
|
|
||||||
|
LocalTicketBackend によって作成されました。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: workspace-panel at: 2026-06-18T13:55:08Z from: ready to: queued reason: queued field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を `workspace-panel` が queued にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: decision author: yoi-orchestrator at: 2026-06-18T13:58:25Z -->
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
Routing decision: implementation_ready
|
||||||
|
|
||||||
|
Reason:
|
||||||
|
- Panel Queue により、この Ticket は Orchestrator routing 対象として明示許可された。
|
||||||
|
- 主目的は Panel startup latency の測定基準を、first frame / 単一 Ticket row readiness ではなく、ユーザー目線の dashboard content ready に揃えること。
|
||||||
|
- 要件、非目標、validation、escalation 条件が実装可能な粒度で揃っており、残る不確実性は Panel/E2E/TUI harness 近傍の bounded implementation investigation に閉じる。
|
||||||
|
- `depends_on` / incoming `blocks` の未解決 blocker は見当たらない。関連 Ticket は完了済みまたは context link として扱える。
|
||||||
|
- 既存 in-progress Ticket `00001KV5W3PJ3` は Plugin permission grants 領域で、今回の主作業面は Panel startup/E2E/TUI harness 側のため、別 worktree での並行実装は conflict risk が低い。
|
||||||
|
|
||||||
|
Evidence checked:
|
||||||
|
- Ticket `00001KVDETSN6` body/thread/artifacts via `TicketShow`。
|
||||||
|
- `TicketRelationQuery(00001KVDETSN6)` の relation metadata: blocking acceptance blocker はなし。
|
||||||
|
- `TicketOrchestrationPlanQuery(00001KVDETSN6)`: 既存 plan record はなし。今回 `accepted_plan` を記録済み。
|
||||||
|
- 関連 Ticket `00001KV62PF32`, `00001KV5MRH6D`, `00001KV5D7MG5` の状態: done/closed context として確認。
|
||||||
|
- Orchestrator worktree `/home/hare/Projects/yoi/.worktree/orchestration` の git state と既存 worktree/branch: matching implementation branch/worktree はなし。
|
||||||
|
- Code map: `panel_ready`, `rows_rendered`, startup latency / fixture readiness 周辺の既存実装・テスト候補を grep で確認。
|
||||||
|
- Visible Pods: 既存 Coder `yoi-coder-00001KV5W3PJ3` は別 Ticket 用。今回の worktree / branch / scope を分離できる。
|
||||||
|
|
||||||
|
IntentPacket:
|
||||||
|
|
||||||
|
Intent:
|
||||||
|
- Panel startup latency の主な evidence を、ユーザーが dashboard として意味ある内容を見られる状態へ合わせる。
|
||||||
|
- live-like fixture と expected dashboard content snapshot を使い、Ticket/Pod/claim など代表 dashboard data が描画・利用可能になるまでを測定できるようにする。
|
||||||
|
- 測定結果から遅延源を分解し、必要な範囲で startup/readiness 改善を行う。
|
||||||
|
|
||||||
|
Binding decisions / invariants:
|
||||||
|
- `panel_ready` や first frame は主 UX metric にしない。必要なら補助 metric として残す。
|
||||||
|
- `rows_rendered`/単一 Ticket row readiness だけで dashboard content ready と見なさない。
|
||||||
|
- E2E/fixture はユーザーに見える dashboard content を代表すること。空画面や trivial row だけの readiness は不可。
|
||||||
|
- Panel は scheduler/backend ではなく local-file-first view である、という既存設計を変えない。
|
||||||
|
- Mouse/input semantics や Panel queue/close/review workflow semantics をこの Ticket で広げない。
|
||||||
|
- root/original workspace は操作せず、Orchestrator worktree から作成した child implementation worktree だけで実装する。
|
||||||
|
|
||||||
|
Requirements / acceptance criteria:
|
||||||
|
- Dashboard content ready を測る fixture/test harness または equivalent な計測 surface が追加される。
|
||||||
|
- Expected dashboard content snapshot / assertion があり、ユーザーに意味のある複数種の dashboard rows/data が ready 条件に含まれる。
|
||||||
|
- Startup latency 出力に first frame と dashboard content ready の違い、または slow-source breakdown が分かる evidence がある。
|
||||||
|
- 既存 Panel startup regression test / benchmark 相当が新しい基準に合わせて更新される。
|
||||||
|
- 改善実装を入れる場合は、semantic shortcut ではなく実際の readiness path の遅延削減であること。
|
||||||
|
|
||||||
|
Implementation latitude:
|
||||||
|
- 既存 Panel test/fixture structure を調査し、最小の fixture/harness 拡張で dashboard content ready を表現してよい。
|
||||||
|
- Metric 名、structured output field 名、test helper の分割は既存コードに合わせてよい。
|
||||||
|
- 遅延改善は、測定で見えた局所的な loading/readiness bottleneck に限定してよい。
|
||||||
|
|
||||||
|
Escalate if:
|
||||||
|
- Panel architecture を scheduler/backend 化する必要が出る。
|
||||||
|
- Dashboard ready の定義に product/UX 判断が必要な未記録の分岐がある。
|
||||||
|
- Terminal/PTY 実 E2E の新規大規模設計が必要になる。
|
||||||
|
- Existing Ticket lifecycle / queue semantics を変更しないと達成できない。
|
||||||
|
|
||||||
|
Validation:
|
||||||
|
- Focused Panel startup / fixture / snapshot tests。
|
||||||
|
- Relevant `cargo test` / `cargo check`。
|
||||||
|
- `cargo fmt --check`。
|
||||||
|
- `git diff --check`。
|
||||||
|
- `nix build .#yoi` は dependency/Cargo.lock/package-source-filter 変更時のみ。
|
||||||
|
|
||||||
|
Current code map:
|
||||||
|
- Panel startup metric / rows readiness / test fixtures around matches for `panel_ready`, `rows_rendered`, `startup latency`, dashboard fixture readiness.
|
||||||
|
- Likely crates: `crates/tui` and related integration/E2E harness files.
|
||||||
|
- Avoid unrelated Plugin permission grant worktree and root/original workspace.
|
||||||
|
|
||||||
|
Critical risks / reviewer focus:
|
||||||
|
- Metric rename/additionが実際の UX readiness を測らず名前だけ変えていないか。
|
||||||
|
- Fixture が live-like で、Ticket/Pod/claim など dashboard content を代表しているか。
|
||||||
|
- Slow-source breakdown が regression triage に使える bounded output か。
|
||||||
|
- Startup performance 改善が semantics を壊す shortcut ではないか。
|
||||||
|
- Existing Panel behavior / queue semantics / row selection semantics を accidental に変更していないか。
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- `queued -> inprogress` を記録し、Orchestrator worktree の tracked Ticket records を commit してから、専用 implementation worktree を作成し Coder Pod を narrow write scope で起動する。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-18T13:58:33Z from: queued to: inprogress reason: orchestrator_acceptance_dashboard_content_ready field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Routing decision と accepted implementation plan を記録済み。Ticket body/thread、relations、OrchestrationPlan、関連 Ticket、Orchestrator worktree、visible Pods、既存 branch/worktree を確認し、blocking relation / conflict / missing planning decision は見つからなかった。Panel startup dashboard-content-ready work は既存 Plugin permission grants work と主対象が異なり、別 worktree/branch/scope で並行可能なため、implementation side effects の前に acceptance を記録する。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T13:59:23Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Implementation start note:
|
||||||
|
|
||||||
|
`queued -> inprogress` acceptance、accepted plan の記録、Orchestrator worktree での Ticket record commit 後に、専用 implementation worktree と Coder Pod を起動した。
|
||||||
|
|
||||||
|
Worktree:
|
||||||
|
- `/home/hare/Projects/yoi/.worktree/00001KVDETSN6-panel-dashboard-content-ready`
|
||||||
|
- branch: `impl/00001KVDETSN6-panel-dashboard-content-ready`
|
||||||
|
- base: Orchestrator branch commit `3b487944`
|
||||||
|
|
||||||
|
Coder Pod:
|
||||||
|
- `yoi-coder-00001KVDETSN6`
|
||||||
|
|
||||||
|
Scope / boundaries:
|
||||||
|
- child runtime workspace root は read scope。
|
||||||
|
- implementation worktree は write scope。
|
||||||
|
- root/original workspace と Orchestrator worktree へは書き込まないよう指示済み。
|
||||||
|
- `.yoi/memory`、runtime/log/lock/local/secret-like `.yoi` paths は編集しないよう指示済み。
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Coder は dashboard content ready metric / live-like fixture / slow-source breakdown / focused validation を実装し、commit と実装報告を返す予定。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T14:15:27Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Coder implementation report received:
|
||||||
|
|
||||||
|
Commit:
|
||||||
|
- `fc1ee5bb` — `tui: measure panel dashboard readiness`
|
||||||
|
|
||||||
|
Summary:
|
||||||
|
- Panel startup E2E に dashboard-content-ready metric を追加。
|
||||||
|
- fixture に複数 Ticket、Pod metadata、Companion claim、orchestration overlay を追加。
|
||||||
|
- Expected dashboard content snapshot / assertions を導入し、loading/partial/single-row では ready 判定しないようにした。
|
||||||
|
- stdout JSON に `dashboard_content_ready`, `startup_readiness_checks`, `startup_sources` を追加。
|
||||||
|
- source breakdown と render-source summary を追加。
|
||||||
|
- startup regression test を first frame / single-row ではなく dashboard content ready basis に更新。
|
||||||
|
- semantic shortcut ではなく expected dashboard row set と overlay/action/status を検証する readiness path として実装。
|
||||||
|
|
||||||
|
Files changed:
|
||||||
|
- `crates/tui/tests/e2e/panel.rs`
|
||||||
|
|
||||||
|
Validation reported by Coder:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `cargo test -p tui --test panel --features e2e -- --nocapture panel_startup_latency_e2e_reports_content_ready_after_rows`
|
||||||
|
- `cargo test -p tui --test panel --features e2e -- --nocapture panel_startup_latency_e2e_fails_if_expected_dashboard_content_is_missing`
|
||||||
|
- `cargo test -p tui --test panel --features e2e -- --nocapture panel_startup_latency_e2e_fails_if_orchestration_overlay_is_missing`
|
||||||
|
- `cargo check -p tui`
|
||||||
|
- `git diff --check`
|
||||||
|
|
||||||
|
Measured evidence reported by Coder:
|
||||||
|
- passing content-ready run:
|
||||||
|
- `panel_ready_ms`: 39
|
||||||
|
- `row_ready_ms`: 140
|
||||||
|
- `dashboard_content_ready_ms`: 140
|
||||||
|
- negative fixtures fail as expected for missing expected dashboard content / missing orchestration overlay。
|
||||||
|
|
||||||
|
Orchestrator evidence checked:
|
||||||
|
- Pod output を確認。
|
||||||
|
- implementation worktree は clean。
|
||||||
|
- commit `fc1ee5bb` が branch `impl/00001KVDETSN6-panel-dashboard-content-ready` の HEAD。
|
||||||
|
- diff stat: `crates/tui/tests/e2e/panel.rs` に 385 insertions / 34 deletions。
|
||||||
|
|
||||||
|
Routing classification: review_needed
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- recorded intent / invariants / acceptance criteria に照らして、read-only Reviewer Pod で外部レビューする。
|
||||||
|
- 特に dashboard content ready が名前だけの metric ではないこと、fixture が live-like な representative dashboard content を検証していること、single-row readiness だけでは通らないこと、negative fixtures が有効であること、Panel semantics を accidental に変更していないことを確認する。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: plan author: yoi-orchestrator at: 2026-06-18T14:16:26Z -->
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
Review dispatch:
|
||||||
|
|
||||||
|
Reviewer Pod `yoi-reviewer-00001KVDETSN6` を read-only scope で起動した。
|
||||||
|
|
||||||
|
Review target:
|
||||||
|
- worktree: `/home/hare/Projects/yoi/.worktree/00001KVDETSN6-panel-dashboard-content-ready`
|
||||||
|
- branch: `impl/00001KVDETSN6-panel-dashboard-content-ready`
|
||||||
|
- commit: `fc1ee5bb`
|
||||||
|
|
||||||
|
Reviewer focus:
|
||||||
|
- recorded intent / invariants / acceptance criteria に対する適合性。
|
||||||
|
- `dashboard_content_ready` が名前だけの metric ではなく、代表 dashboard content の expected row/content set に基づくこと。
|
||||||
|
- first frame / single-row readiness だけでは主 E2E が通らないこと。
|
||||||
|
- missing dashboard content / missing orchestration overlay の negative fixtures が意味を持つこと。
|
||||||
|
- startup source breakdown が bounded で regression triage に使えること。
|
||||||
|
- Existing Panel behavior / workflow semantics を accidental に変更していないこと。
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Reviewer output を確認し、approve なら Ticket review に記録して merge-ready 判断へ進む。request_changes なら Coder に修正依頼する。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVDETSN6 at: 2026-06-18T14:20:21Z status: request_changes -->
|
||||||
|
|
||||||
|
## Review: request changes
|
||||||
|
|
||||||
|
Review result: request_changes
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVDETSN6`
|
||||||
|
- branch: `impl/00001KVDETSN6-panel-dashboard-content-ready`
|
||||||
|
- commit: `fc1ee5bb` (`tui: measure panel dashboard readiness`)
|
||||||
|
|
||||||
|
Blockers:
|
||||||
|
|
||||||
|
1. Dashboard content readiness が required Companion / Orchestrator / orchestration overlay content を含んでいない。
|
||||||
|
- fixture は 2 件の Ticket と `workspace` / `workspace-orchestrator` の Pod metadata だけを作っている。
|
||||||
|
- expected dashboard content は ready Ticket、planning Ticket、Pod name `workspace` のみ。
|
||||||
|
- orchestration worktree/overlay fixture setup、expected overlay state、Companion/Orchestrator status assertion が `dashboard_content_ready` に含まれていない。
|
||||||
|
- Ticket acceptance criteria の Ticket / Pod / Companion / Orchestrator / overlay elements を代表する expected dashboard snapshot に不足がある。
|
||||||
|
|
||||||
|
2. Wrong / missing action labels が readiness を通過できる。
|
||||||
|
- `ExpectedPanelTicketRow::matches` は row kind、id、title、status のみを確認している。
|
||||||
|
- `ExpectedDashboardContent` は `tickets` と `pod_names` のみ。
|
||||||
|
- main E2E は ready/planning/pod categories を確認するが、`actionable_rows > 0` や specific action labels を確認していない。
|
||||||
|
- acceptance では missing action label / wrong action が失敗することを求めている。
|
||||||
|
|
||||||
|
3. Missing overlay / missing action / wrong state の committed negative fixtures がない。
|
||||||
|
- 既存 negative test は単一 ticket matcher の wrong title / wrong kind に限られる。
|
||||||
|
- missing row、wrong state、missing overlay、missing action label が dashboard readiness を失敗させることを示す test/fixture が必要。
|
||||||
|
|
||||||
|
4. emitted `dashboard_content_ready` event が broad category gate のまま。
|
||||||
|
- runtime readiness predicate は `ticket_configured && ready_ticket_rows > 0 && planning_ticket_rows > 0 && pod_rows > 0` 程度。
|
||||||
|
- harness 側 expected filter により現在の test では first-frame/single-ticket passing を防いでいるが、event 名自体は overlay/action/header content を検証せず emit され得る。
|
||||||
|
- main/exported metric として誤用されやすく、Ticket の expected dashboard snapshot 定義より弱い。
|
||||||
|
|
||||||
|
5. Slow-source breakdown が requested attribution には粗い。
|
||||||
|
- 追加 source は pod list、companion presence/lifecycle、ticket config、orchestrator presence/lifecycle、`workspace_panel.build` など。
|
||||||
|
- Ticket は Ticket scan/parsing、orchestration overlay validation/read、Pod metadata scan、socket/status probing、role claim scan、git worktree/branch checks の attribution を求めている。
|
||||||
|
- overlay/role/ticket parsing/git checks が `workspace_panel.build` に lump されており、live-latency source の診断には不足。
|
||||||
|
|
||||||
|
Positive evidence:
|
||||||
|
- main startup test は `dashboard_content_ready` を待つ形に変更され、`panel_ready` や単一 ready Ticket row だけではない。
|
||||||
|
- current main E2E は expected fixture Tickets と expected Pod name を要求するため、first frame / single Ticket row だけでは通らない。
|
||||||
|
- diff は E2E instrumentation / harness/tests に閉じており、queue/close/review workflow semantic changes は見当たらない。
|
||||||
|
- Reviewer は `git diff --check fc1ee5bb^..fc1ee5bb` を実行し、成功を確認した。
|
||||||
|
|
||||||
|
Requested changes:
|
||||||
|
- expected dashboard content に action labels / disabled reasons を追加する。
|
||||||
|
- Companion / Orchestrator status と orchestration overlay state の fixture support と assertions を追加する。
|
||||||
|
- missing row、wrong state、missing overlay、missing action label の negative tests/fixtures を追加する。
|
||||||
|
- `dashboard_content_ready` event 自体が complete snapshot semantics を carry/validate する、または exported/main metric が broad category gate と誤解されない形にする。
|
||||||
|
- source breakdown を、少なくとも ticket scan/parsing、overlay validation/read/git checks、pod metadata/status probing、local claim scan が見える程度に分割する。省略する場合は明確な non-action rationale を記録する。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: plan author: yoi-orchestrator at: 2026-06-18T14:20:54Z -->
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
Review follow-up dispatch:
|
||||||
|
|
||||||
|
Reviewer `yoi-reviewer-00001KVDETSN6` は `request_changes` を返したため、Ticket review として記録し、既存 Coder Pod `yoi-coder-00001KVDETSN6` に修正依頼を送った。
|
||||||
|
|
||||||
|
Coder に依頼した主な修正:
|
||||||
|
- dashboard content readiness に Companion / Orchestrator / orchestration overlay state を含める。
|
||||||
|
- expected dashboard content に action labels / disabled reasons 相当を含め、wrong/missing action が readiness を通らないようにする。
|
||||||
|
- missing row、wrong state、missing overlay、missing action label の negative tests/fixtures を追加する。
|
||||||
|
- `dashboard_content_ready` event / exported main metric が broad category gate と誤解されないよう、complete snapshot semantics を carry/validate するか内部 gate と分離する。
|
||||||
|
- slow-source breakdown を ticket scan/parsing、overlay validation/read/git checks、pod metadata/status probing、local claim scan などに分割する。広い設計変更なしに観測できない source は明確な non-action rationale として報告する。
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Coder の修正 commit / validation report を待つ。
|
||||||
|
- 修正後、必要に応じて同じ review focus で再レビューする。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T14:41:45Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Coder review-fix implementation report received:
|
||||||
|
|
||||||
|
Incremental fix commit:
|
||||||
|
- `5870251b` — `tui: tighten panel dashboard readiness`
|
||||||
|
|
||||||
|
Summary:
|
||||||
|
- `dashboard_content_ready` を broad category gate から、full dashboard snapshot を carry/validate する readiness に強化。
|
||||||
|
- Snapshot/header assertions を追加。
|
||||||
|
- Companion status
|
||||||
|
- Orchestrator status
|
||||||
|
- orchestration overlay state
|
||||||
|
- Ticket action labels
|
||||||
|
- disabled reasons
|
||||||
|
- local / overlay Ticket states
|
||||||
|
- E2E fixture を real git/orchestration worktree overlay を作る形に更新。
|
||||||
|
- local ready Ticket は `ready` のまま。
|
||||||
|
- orchestration overlay 側で同 Ticket を `inprogress` に進める。
|
||||||
|
- visible `ready→prog` row と `Wait` action を期待する。
|
||||||
|
- negative coverage を追加。
|
||||||
|
- missing expected row
|
||||||
|
- wrong state
|
||||||
|
- missing overlay
|
||||||
|
- missing action label
|
||||||
|
- source breakdown attribution を拡張。
|
||||||
|
- `pod_metadata_status_probe.initial`
|
||||||
|
- `ticket_config_probe`
|
||||||
|
- `ticket_config_parse`
|
||||||
|
- `orchestration_overlay_validation_read_git`
|
||||||
|
- `ticket_scan_parse`
|
||||||
|
- `local_claim_scan`
|
||||||
|
- `pod_row_materialization`
|
||||||
|
- `workspace_panel.build.total`
|
||||||
|
|
||||||
|
Files changed in incremental fix:
|
||||||
|
- `crates/tui/src/multi_pod.rs`
|
||||||
|
- `crates/tui/src/workspace_panel.rs`
|
||||||
|
- `tests/e2e/src/lib.rs`
|
||||||
|
- `tests/e2e/tests/panel.rs`
|
||||||
|
|
||||||
|
Coder reported no blockers/escalations.
|
||||||
|
|
||||||
|
Orchestrator evidence checked:
|
||||||
|
- Pod output を確認。
|
||||||
|
- implementation worktree は clean。
|
||||||
|
- branch `impl/00001KVDETSN6-panel-dashboard-content-ready` HEAD は `5870251b`。
|
||||||
|
- incremental diff stat from `fc1ee5bb..5870251b`: 4 files changed, 709 insertions, 65 deletions。
|
||||||
|
- `git diff --check fc1ee5bb..HEAD` passed。
|
||||||
|
|
||||||
|
Validation re-run by Orchestrator in implementation worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p tui --features e2e-test` — passed
|
||||||
|
- `cargo test -p yoi-e2e --features e2e --test panel` — passed; 7 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
|
||||||
|
Routing classification: review_needed
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- previous `request_changes` blockers が解消されたか、read-only Reviewer Pod で再レビューする。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: plan author: yoi-orchestrator at: 2026-06-18T14:42:24Z -->
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
Review re-dispatch:
|
||||||
|
|
||||||
|
Reviewer Pod `yoi-reviewer-00001KVDETSN6-r2` を read-only scope で起動した。
|
||||||
|
|
||||||
|
Review target:
|
||||||
|
- worktree: `/home/hare/Projects/yoi/.worktree/00001KVDETSN6-panel-dashboard-content-ready`
|
||||||
|
- branch: `impl/00001KVDETSN6-panel-dashboard-content-ready`
|
||||||
|
- commits:
|
||||||
|
- `fc1ee5bb` — initial implementation
|
||||||
|
- `5870251b` — review-fix implementation
|
||||||
|
|
||||||
|
Reviewer focus:
|
||||||
|
- previous `request_changes` blockers が解消されているか。
|
||||||
|
- final `dashboard_content_ready` が Ticket / Pod / Companion / Orchestrator / overlay elements を含む expected dashboard snapshot semantics を持つか。
|
||||||
|
- first-frame / single-row readiness だけで main metric が通らないか。
|
||||||
|
- missing row / wrong state / missing overlay / missing action label の negative tests が意味を持つか。
|
||||||
|
- slow-source breakdown が bounded かつ診断可能か。
|
||||||
|
- Panel workflow semantics を accidental に変更していないか。
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Reviewer output を確認し、approve なら merge/validation/close-ready 処理へ進む。request_changes なら blocker を記録して Coder に戻す。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVDETSN6-r2 at: 2026-06-18T14:46:51Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVDETSN6`
|
||||||
|
- branch: `impl/00001KVDETSN6-panel-dashboard-content-ready`
|
||||||
|
- commits:
|
||||||
|
- `fc1ee5bb` — `tui: measure panel dashboard readiness`
|
||||||
|
- `5870251b` — `tui: tighten panel dashboard readiness`
|
||||||
|
|
||||||
|
No remaining blockers found.
|
||||||
|
|
||||||
|
Evidence reviewed:
|
||||||
|
- `dashboard_content_ready` は broad readiness timestamp ではなく、rendered dashboard snapshot を carry するようになっている。
|
||||||
|
- `crates/tui/src/multi_pod.rs` の `PanelE2eDashboardContentReady` が `header`, `rows`, `source_breakdown` を持つ。
|
||||||
|
- rendered Ticket rows は `action`, `disabled_reason`, `local_state`, `orchestration_overlay_state` を含み、Ticket / Pod / Companion / Orchestrator / overlay-visible content の validation basis になっている。
|
||||||
|
- main E2E readiness wait は first-frame / single-row readiness では通らない。
|
||||||
|
- `panel_e2e_dashboard_content_is_ready` が header content、ready/planning/pod categories、action/disabled/overlay fields を含む Ticket rows を要求する。
|
||||||
|
- test harness は emitted snapshot を `ExpectedDashboardContent` と照合するため、wrong visible content は metric を満たさない。
|
||||||
|
- Companion / Orchestrator / overlay content が coverage に含まれている。
|
||||||
|
- `tests/e2e/tests/panel.rs` が `companion_status`, `orchestrator_status`, overlay state, local state, action label, disabled reason を assert する。
|
||||||
|
- `tests/e2e/src/lib.rs` が real orchestration worktree overlay を作成し、local state は `ready` のまま overlay state を `inprogress` に進め、visible `ready→prog` / `Wait` row を期待している。
|
||||||
|
- Negative coverage は meaningful。
|
||||||
|
- missing expected row、wrong state、missing overlay state、missing action label が `snapshot_for_expected` を失敗させる。
|
||||||
|
- wrong action labels は `ExpectedPanelTicketRow::matches` が `action` equality を見るため reject される。
|
||||||
|
- Slow-source breakdown は改善され、bounded。
|
||||||
|
- initial pod metadata/status probing、ticket config probe/parse、orchestration overlay validation/read/git checks、ticket scan/parse、local claim scan、pod row materialization、total workspace panel build が区別されている。
|
||||||
|
- `workspace_panel.build.total` は additive component ではなく enclosing total であることが naming から分かる。
|
||||||
|
- Panel semantics は preserved と判断。
|
||||||
|
- local-ready / overlay-inprogress の場合に disabled `Wait` action になり、stale local state から queue しない。
|
||||||
|
- planning rows は expected disabled reason 付き `Clarify` を維持。
|
||||||
|
- 新しい assertions は intended user-visible dashboard content/action labels に結びついており、incidental layout/terminal formatting には依存していない。
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- final branch と `fc1ee5bb..5870251b` focus areas の static review。
|
||||||
|
- read-only git/worktree inspection。
|
||||||
|
- `git diff --check` over reviewed commits — passed。
|
||||||
|
|
||||||
|
Orchestrator validation already confirmed:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p tui --features e2e-test` — passed
|
||||||
|
- `cargo test -p yoi-e2e --features e2e --test panel` — passed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Previous request_changes blockers are resolved.
|
||||||
|
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T14:47:55Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Merge / validation report:
|
||||||
|
|
||||||
|
Implementation branch `impl/00001KVDETSN6-panel-dashboard-content-ready` を Orchestrator worktree の `orchestration` branch に merge した。
|
||||||
|
|
||||||
|
Merge:
|
||||||
|
- merge commit: `2d4d11e4` — `merge: panel dashboard readiness metric`
|
||||||
|
- implementation commits:
|
||||||
|
- `fc1ee5bb` — `tui: measure panel dashboard readiness`
|
||||||
|
- `5870251b` — `tui: tighten panel dashboard readiness`
|
||||||
|
- changed files:
|
||||||
|
- `crates/tui/src/multi_pod.rs`
|
||||||
|
- `crates/tui/src/workspace_panel.rs`
|
||||||
|
- `tests/e2e/src/lib.rs`
|
||||||
|
- `tests/e2e/tests/panel.rs`
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p tui --features e2e-test` — passed
|
||||||
|
- `cargo test -p yoi-e2e --features e2e --test panel` — passed; 7 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
|
||||||
|
Review:
|
||||||
|
- First review returned `request_changes` and blockers were sent back to Coder.
|
||||||
|
- Re-review `yoi-reviewer-00001KVDETSN6-r2` returned `approve` with no remaining blockers.
|
||||||
|
|
||||||
|
Outcome:
|
||||||
|
- `dashboard_content_ready` now validates expected dashboard snapshot content including Ticket / Pod / Companion / Orchestrator / overlay-visible state and action/disabled fields.
|
||||||
|
- first-frame / single-row readiness no longer satisfies the main metric.
|
||||||
|
- negative coverage covers missing row, wrong state, missing overlay, and missing action label.
|
||||||
|
- slow-source breakdown is bounded and more diagnostic.
|
||||||
|
- Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T14:48:21Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Cleanup report:
|
||||||
|
|
||||||
|
Panel dashboard readiness Ticket の implementation/review Pods と child worktree を cleanup した。
|
||||||
|
|
||||||
|
Stopped Pods:
|
||||||
|
- `yoi-coder-00001KVDETSN6`
|
||||||
|
- `yoi-reviewer-00001KVDETSN6-r2`
|
||||||
|
|
||||||
|
Removed child implementation worktree:
|
||||||
|
- `/home/hare/Projects/yoi/.worktree/00001KVDETSN6-panel-dashboard-content-ready`
|
||||||
|
|
||||||
|
Deleted merged implementation branch:
|
||||||
|
- `impl/00001KVDETSN6-panel-dashboard-content-ready` at `5870251b`
|
||||||
|
|
||||||
|
Orchestrator branch remains the integration authority for this completed work. Root/original workspace was not touched for this Ticket, per Panel Queue instruction.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-18T14:48:30Z from: inprogress to: done reason: merged_validated_review_approved field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Implementation commits `fc1ee5bb` and `5870251b` were reviewed after blocker resolution, approved, merged into the Orchestrator branch as `2d4d11e4`, validated in the Orchestrator worktree, and child implementation resources were cleaned up. Requirements and acceptance criteria are satisfied for this Ticket. Root/original workspace was not operated on for this Ticket per Panel Queue instruction.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-18T14:48:44Z from: done to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-18T14:48:44Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Ticket `00001KVDETSN6` is complete.
|
||||||
|
|
||||||
|
Completed implementation:
|
||||||
|
- Added a user-visible `dashboard_content_ready` metric that carries and validates a rendered dashboard snapshot rather than treating first frame or a single row as ready.
|
||||||
|
- Added expected dashboard content coverage for Ticket rows, Pod rows, Companion status, Orchestrator status, orchestration overlay state, action labels, disabled reasons, local Ticket state, and overlay Ticket state.
|
||||||
|
- Added a real git/orchestration overlay fixture for the local-ready / overlay-inprogress case and validated the visible `ready→prog` / `Wait` row.
|
||||||
|
- Added negative coverage for missing expected row, wrong state, missing overlay state, and missing action label.
|
||||||
|
- Added bounded startup source breakdown including pod metadata/status probing, ticket config probe/parse, overlay validation/read/git checks, ticket scan/parse, local claim scan, pod row materialization, and total workspace panel build.
|
||||||
|
|
||||||
|
Reviewed / merged:
|
||||||
|
- Initial implementation: `fc1ee5bb` (`tui: measure panel dashboard readiness`)
|
||||||
|
- Review-fix implementation: `5870251b` (`tui: tighten panel dashboard readiness`)
|
||||||
|
- First review requested changes; blockers were fixed.
|
||||||
|
- Re-review approved with no remaining blockers.
|
||||||
|
- Orchestrator merge commit: `2d4d11e4` (`merge: panel dashboard readiness metric`)
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p tui --features e2e-test` — passed
|
||||||
|
- `cargo test -p yoi-e2e --features e2e --test panel` — passed; 7 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
|
||||||
|
Cleanup:
|
||||||
|
- Stopped Coder Pod `yoi-coder-00001KVDETSN6`.
|
||||||
|
- Stopped Reviewer Pod `yoi-reviewer-00001KVDETSN6-r2`.
|
||||||
|
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KVDETSN6-panel-dashboard-content-ready`.
|
||||||
|
- Deleted merged branch `impl/00001KVDETSN6-panel-dashboard-content-ready`.
|
||||||
|
|
||||||
|
Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction. The completed work is integrated on the Orchestrator branch.
|
||||||
|
|
||||||
|
---
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
{"id":"orch-plan-20260618-144957-1","ticket_id":"00001KVDH2E06","kind":"accepted_plan","accepted_plan":{"summary":"`yoi panel` の通常 Pod rows/action target を、persisted Pod metadata / resolved runtime workspace root に基づき現在 workspace 所属の Pod に限定する。別 workspace / 判定不能 / corrupt metadata は通常一覧に混ぜず、current workspace の Companion/Orchestrator/role Pod と worktree cwd の Pod は残す。","branch":"impl/00001KVDH2E06-panel-current-workspace-pods","worktree":"/home/hare/Projects/yoi/.worktree/00001KVDH2E06-panel-current-workspace-pods","role_plan":"Orchestrator は専用 implementation worktree を作成し、Coder をその worktree への narrow write scope で起動する。Reviewer は実装報告後に read-only で確認する。現在 inprogress Ticket はなく、Panel/TUI/Pod metadata 近傍の単独実装として受理する。"},"author":"yoi-orchestrator","at":"2026-06-18T14:49:57Z"}
|
||||||
@@ -0,0 +1,96 @@
|
|||||||
|
---
|
||||||
|
title: 'Panel 表示を現在 workspace の Pod に限定する'
|
||||||
|
state: 'closed'
|
||||||
|
created_at: '2026-06-18T14:09:59Z'
|
||||||
|
updated_at: '2026-06-18T15:40:38Z'
|
||||||
|
assignee: null
|
||||||
|
readiness: 'ready'
|
||||||
|
risk_flags: ['panel', 'pod-metadata', 'workspace-boundary', 'runtime-observation']
|
||||||
|
queued_by: 'workspace-panel'
|
||||||
|
queued_at: '2026-06-18T14:47:10Z'
|
||||||
|
---
|
||||||
|
|
||||||
|
## Background
|
||||||
|
|
||||||
|
`yoi panel` は workspace の状況確認・Ticket queue・Orchestrator 操作の入口になっているため、別 workspace の Pod が一覧に混ざると、現在 workspace の状態として誤認しやすい。
|
||||||
|
|
||||||
|
Yoi では runtime workspace root、Pod identity、Profile、cwd、Ticket backend checkout が別概念として整理されている。したがって Panel の表示対象も、Pod 名や cwd の heuristic ではなく、Pod metadata に記録された runtime workspace identity を基準に workspace-scoped にする必要がある。
|
||||||
|
|
||||||
|
Request snapshot:
|
||||||
|
|
||||||
|
- `yoi panel` の Pod 表示で、現在の workspace に属さない Pod が表示されないようにしたい。
|
||||||
|
- Panel handoff context:
|
||||||
|
- workspace: `yoi`
|
||||||
|
- workspace_orchestrator_pod: `yoi-orchestrator`
|
||||||
|
|
||||||
|
## Requirements
|
||||||
|
|
||||||
|
- `yoi panel` の通常 Pod 表示は、現在の runtime workspace root に属する Pod のみに限定する。
|
||||||
|
- 別 workspace の Pod は Panel の通常一覧・通常 action target に表示しない。
|
||||||
|
- workspace Orchestrator Pod、Companion Pod、Ticket role Pod など、現在 workspace に属する role Pod は表示対象に残す。
|
||||||
|
- dedicated orchestration worktree や implementation worktree を cwd にしている Pod でも、runtime workspace が現在 workspace なら表示対象に残す。
|
||||||
|
- Pod 名 prefix や cwd だけで workspace 所属を推測しない。可能な限り persisted Pod metadata / resolved runtime workspace root を authority とする。
|
||||||
|
- metadata が壊れている、または workspace 判定不能な Pod は、通常一覧に混ぜず、必要なら bounded diagnostic として扱う。
|
||||||
|
- no-Ticket workspace / Pod-centric fallback でも、現在 workspace の Pod discovery と attach/open は維持する。
|
||||||
|
- Ticket rows / queue actions / Panel Orchestrator lifecycle は維持する。
|
||||||
|
|
||||||
|
## Acceptance criteria
|
||||||
|
|
||||||
|
- `yoi panel` を workspace `A` で開いたとき、workspace `B` の Pod が通常 Pod list に表示されない。
|
||||||
|
- 現在 workspace の `workspace_orchestrator_pod`、Companion、Ticket role Pod は引き続き表示・操作できる。
|
||||||
|
- cwd が `.worktree/...` 配下でも、runtime workspace が現在 workspace なら隠されない。
|
||||||
|
- workspace 判定不能な legacy/corrupt Pod metadata が、現在 workspace の通常 row として誤表示されない。
|
||||||
|
- Panel の attach/open は、表示されている現在 workspace Pod に対して従来通り機能する。
|
||||||
|
- Focused unit tests または E2E/fixture tests で、複数 workspace の Pod metadata が存在する場合に Panel が現在 workspace の Pod だけを表示することを確認する。
|
||||||
|
|
||||||
|
## Binding decisions / invariants
|
||||||
|
|
||||||
|
- Panel 表示スコープの authority は、runtime workspace root / Pod metadata に基づく。Pod name prefix や process cwd のみでは判定しない。
|
||||||
|
- `role_workspace_root` / `original_workspace_root` / `implementation_worktree_root` / `merge_target_workspace_root` は混同しない。
|
||||||
|
- dedicated orchestration worktree を使う Orchestrator は、cwd が workspace 外に見えても、runtime workspace が元 workspace なら表示対象に残す。
|
||||||
|
- ワークスペース外 Pod を通常一覧に出してから UI 上で注意表示するのではなく、通常一覧から除外する。
|
||||||
|
- 別 workspace の Pod に対する attach/open/action path を Panel から提供しない。
|
||||||
|
- 既存 Pod metadata の破壊的 migration はこの Ticket の範囲外。必要なら escalation する。
|
||||||
|
- ユーザー承認により、metadata が古く workspace 判定不能な Pod は通常 Panel 表示から隠し、必要なら diagnostic にだけ出す。
|
||||||
|
|
||||||
|
## Implementation latitude
|
||||||
|
|
||||||
|
- workspace root の canonicalization / path comparison の具体実装は Coder が調査して選んでよい。
|
||||||
|
- 判定不能 Pod の diagnostic 表示方法は、既存 Panel diagnostic pattern に合わせてよい。
|
||||||
|
- 既存 ViewModel / Pod listing abstraction のどこで filter するかは実装調査に任せてよい。
|
||||||
|
- E2E が重すぎる場合、まず unit/fixture test で複数 workspace Pod metadata を作る focused coverage でもよい。ただし user-visible Panel 挙動の確認手段は残す。
|
||||||
|
|
||||||
|
## Readiness
|
||||||
|
|
||||||
|
- readiness: implementation_ready
|
||||||
|
- risk_flags: [panel, pod-metadata, workspace-boundary, runtime-observation]
|
||||||
|
- open_questions: none
|
||||||
|
|
||||||
|
## Escalation conditions
|
||||||
|
|
||||||
|
- 既存 metadata に runtime workspace root が十分に保存されておらず、正しい workspace 判定に schema/storage 変更が必要な場合。
|
||||||
|
- legacy Pod を隠すことで既存の復元/attach 導線が実用上失われる場合。
|
||||||
|
- workspace root canonicalization で symlink / moved checkout / worktree の扱いに人間判断が必要な場合。
|
||||||
|
- Panel の no-Ticket fallback が「全 Pod dashboard」であるべきか「current workspace Pod dashboard」であるべきか、既存設計と衝突する場合。
|
||||||
|
- 別 workspace Pod を診断用に見せる必要が出た場合。その場合も通常 action row とは分離する。
|
||||||
|
|
||||||
|
## Validation
|
||||||
|
|
||||||
|
- Focused tests for Panel ViewModel / Pod list filtering:
|
||||||
|
- current workspace Pod is visible;
|
||||||
|
- other workspace Pod is hidden;
|
||||||
|
- workspace Orchestrator / role Pod for current workspace is visible;
|
||||||
|
- cwd/worktree difference alone does not hide current workspace Pod;
|
||||||
|
- unknown/corrupt workspace metadata is not treated as current workspace.
|
||||||
|
- Existing Panel/TUI tests continue to pass.
|
||||||
|
- If practical: Panel E2E fixture with multiple workspace Pod metadata records.
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `git diff --check`
|
||||||
|
- relevant `cargo test` / `cargo check`
|
||||||
|
|
||||||
|
## Related work
|
||||||
|
|
||||||
|
- `00001KTFQ109S`: Workspace panel Companion interface。
|
||||||
|
- `00001KTFQ109V`: Remove workspace panel direct Pod send。
|
||||||
|
- `00001KV0YK5S0`: E2E harness を完全な tmp runtime/data/workspace 隔離と cleanup に対応させる。
|
||||||
|
- Runtime workspace / Pod identity decisions in existing memory and related closed runtime-workspace Tickets。
|
||||||
@@ -0,0 +1,40 @@
|
|||||||
|
Ticket `00001KVDH2E06` is complete.
|
||||||
|
|
||||||
|
Completed implementation:
|
||||||
|
- Normal `yoi panel` Pod rows and Pod action targets are filtered to the current runtime workspace using persisted Pod metadata / runtime workspace ownership.
|
||||||
|
- Added optional persisted `workspace_root` to `PodMetadata` and ensured normal metadata write-through persists it.
|
||||||
|
- Added `PodMetadataStore::set_active_with_workspace_root(...)` while keeping compatibility `set_active(...)` preserving existing workspace ownership.
|
||||||
|
- Workspace-external Pods are excluded from normal Panel rows/action targets.
|
||||||
|
- Unknown/corrupt/live-only metadata fail closed and are not treated as current workspace Pods.
|
||||||
|
- Current-workspace role-like Pods remain visible when persisted runtime workspace matches, independent of cwd/worktree differences.
|
||||||
|
|
||||||
|
Reviewed / merged:
|
||||||
|
- Initial implementation: `3b634d66` (`tui: filter panel pods by workspace`)
|
||||||
|
- Persistence-boundary fix: `160c96ad` (`pod: persist metadata workspace root`)
|
||||||
|
- First review requested changes for missing persistence of `workspace_root` through the normal store writer path.
|
||||||
|
- Re-review approved with no remaining blockers.
|
||||||
|
- Orchestrator merge commit: `0ef36b4e` (`merge: panel workspace pod filter`)
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p tui -p pod -p pod-store` — passed
|
||||||
|
- `cargo test -p pod metadata_writer_persists_workspace_root_through_store_update -- --nocapture` — passed
|
||||||
|
- `cargo test -p pod pod_metadata -- --nocapture` — passed
|
||||||
|
- `cargo test -p pod-store` — passed; 6 passed, 0 failed
|
||||||
|
- `cargo test -p tui workspace_panel -- --nocapture` — passed; 23 passed, 0 failed
|
||||||
|
- `cargo test -p tui pod_list -- --nocapture` — passed; 19 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
|
||||||
|
Known validation debt:
|
||||||
|
- Full `cargo test -p tui` still has three pre-existing/unrelated failures reproduced on the Orchestrator branch before this implementation was merged:
|
||||||
|
- `multi_pod::tests::orchestrator_launch_context_uses_orchestration_root_for_runtime_workspace`
|
||||||
|
- `spawn::tests::profile_choices_use_project_registry_default`
|
||||||
|
- `spawn::tests::profile_choices_include_builtin_and_project_default_marker`
|
||||||
|
|
||||||
|
Cleanup:
|
||||||
|
- Stopped Coder Pod `yoi-coder-00001KVDH2E06`.
|
||||||
|
- Stopped Reviewer Pod `yoi-reviewer-00001KVDH2E06-r2`.
|
||||||
|
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KVDH2E06-panel-current-workspace-pods`.
|
||||||
|
- Deleted merged branch `impl/00001KVDH2E06-panel-current-workspace-pods`.
|
||||||
|
|
||||||
|
Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction. The completed work is integrated on the Orchestrator branch.
|
||||||
@@ -0,0 +1,569 @@
|
|||||||
|
<!-- event: create author: ticket-intake at: 2026-06-18T14:09:59Z -->
|
||||||
|
|
||||||
|
## 作成
|
||||||
|
|
||||||
|
LocalTicketBackend によって作成されました。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: intake_summary author: ticket-intake at: 2026-06-18T14:10:12Z -->
|
||||||
|
|
||||||
|
## Intake summary
|
||||||
|
|
||||||
|
ユーザー承認済み。`yoi panel` の通常 Pod 表示を現在の runtime workspace に属する Pod だけに限定する concrete work item。workspace 外 Pod は通常一覧/action target から除外し、workspace 判定不能な legacy/corrupt metadata は通常表示せず bounded diagnostic のみ許容する。受け入れ条件・binding invariants・validation は Ticket body に記録済み。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: ticket-intake at: 2026-06-18T14:10:12Z from: planning to: ready reason: user_approved_intake_ready field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket intake が完了しました。実装起動は Orchestrator routing / queue flow に委ねます。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: workspace-panel at: 2026-06-18T14:47:10Z from: ready to: queued reason: queued field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を `workspace-panel` が queued にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: decision author: yoi-orchestrator at: 2026-06-18T14:50:44Z -->
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
Routing decision: implementation_ready
|
||||||
|
|
||||||
|
Reason:
|
||||||
|
- Panel Queue により、この Ticket は Orchestrator routing 対象として明示許可された。
|
||||||
|
- Ticket body には、workspace-scoped Pod visibility の intent、binding invariants、acceptance criteria、implementation latitude、validation、escalation conditions が揃っている。
|
||||||
|
- Risk domain は Panel / Pod metadata / workspace boundary / runtime observation だが、Ticket では authority を runtime workspace root / persisted Pod metadata に固定しており、Pod name prefix / cwd heuristic を禁止している。bounded context check 後も implementation 前に必要な追加の human decision は見つからなかった。
|
||||||
|
- `depends_on` / incoming `blocks` の blocker はない。OrchestrationPlan には既存 blocker/conflict record はなく、今回 accepted plan を記録済み。
|
||||||
|
- 現在 inprogress Ticket は 0 件で、visible child Pod もない。Orchestrator worktree は clean、同名 branch/worktree は存在しない。
|
||||||
|
|
||||||
|
Evidence checked:
|
||||||
|
- Ticket `00001KVDH2E06` body / thread / artifacts。
|
||||||
|
- `TicketRelationQuery(00001KVDH2E06)`: relation 0 件、blocking acceptance blocker なし。
|
||||||
|
- `TicketOrchestrationPlanQuery(00001KVDH2E06)`: 既存 record なし。今回 `accepted_plan` を記録済み。
|
||||||
|
- `TicketList`: queued は本 Ticket 1 件、inprogress は 0 件。
|
||||||
|
- Orchestrator worktree `/home/hare/Projects/yoi/.worktree/orchestration`: clean。
|
||||||
|
- Existing worktree/branch: `00001KVDH2E06` / panel-current-workspace-pods matching branch/worktree なし。
|
||||||
|
- Visible Pods: self `yoi-orchestrator` のみ。
|
||||||
|
- Current code map:
|
||||||
|
- `crates/tui/src/pod_list.rs`: stored/live Pod metadata を `PodListEntry` に merge して action/diagnostics を作る。
|
||||||
|
- `crates/tui/src/workspace_panel.rs`: `build_workspace_panel*` と `pod_rows(pods)` が Pod rows を Panel に入れている。
|
||||||
|
- `crates/pod-store/src/lib.rs`: durable `PodMetadata` は `resolved_manifest_snapshot` を持ち、runtime workspace 判定の authority candidate になる。
|
||||||
|
- Current `pod_rows` は `pods.entries.iter().map(pod_row)` で、workspace filter が見当たらない。
|
||||||
|
|
||||||
|
IntentPacket:
|
||||||
|
|
||||||
|
Intent:
|
||||||
|
- `yoi panel` の通常 Pod 表示と Pod action target を、現在の runtime workspace に属する Pod に限定する。
|
||||||
|
- 別 workspace の Pod、workspace 判定不能な legacy/corrupt metadata を通常 Pod rows に混ぜない。
|
||||||
|
- Current workspace の Companion / Orchestrator / Ticket role Pod は、cwd が dedicated orchestration worktree や implementation worktree でも、runtime workspace が現在 workspace なら表示対象に残す。
|
||||||
|
|
||||||
|
Binding decisions / invariants:
|
||||||
|
- Authority は runtime workspace root / persisted Pod metadata / resolved runtime workspace identity。Pod name prefix や process cwd だけで判定しない。
|
||||||
|
- `role_workspace_root` / `original_workspace_root` / `implementation_worktree_root` / `merge_target_workspace_root` を混同しない。
|
||||||
|
- Workspace 外 Pod は通常一覧に出して warning するのではなく通常一覧から除外する。
|
||||||
|
- 別 workspace Pod に対する attach/open/action path を Panel から提供しない。
|
||||||
|
- Corrupt / unknown workspace metadata は current workspace とみなさない。必要なら bounded diagnostic に留める。
|
||||||
|
- 既存 Pod metadata の破壊的 migration はこの Ticket の範囲外。
|
||||||
|
- Panel Ticket rows / queue actions / Orchestrator lifecycle semantics は維持する。
|
||||||
|
|
||||||
|
Requirements / acceptance criteria:
|
||||||
|
- workspace A で `yoi panel` を開いたとき workspace B の Pod が通常 Pod list に表示されない。
|
||||||
|
- Current workspace の workspace Orchestrator / Companion / Ticket role Pod は表示・操作できる。
|
||||||
|
- cwd が `.worktree/...` 配下でも runtime workspace が current workspace なら隠されない。
|
||||||
|
- Unknown/corrupt workspace metadata は通常 current-workspace Pod row として誤表示されない。
|
||||||
|
- Attach/open は表示されている current workspace Pod に対して従来通り機能する。
|
||||||
|
- Focused tests または E2E/fixture tests で multiple workspace Pod metadata の filter を確認する。
|
||||||
|
|
||||||
|
Implementation latitude:
|
||||||
|
- workspace root canonicalization / path comparison の具体実装は Coder が既存 pattern に合わせて選んでよい。
|
||||||
|
- Filtering location は `PodList` 側または `WorkspacePanelViewModel` construction 側のどちらでもよいが、normal Panel rows/action target に外部 workspace Pod が混ざらないこと。
|
||||||
|
- 判定不能 Pod の diagnostic 表示は既存 Panel diagnostics pattern に合わせてよい。
|
||||||
|
- E2E が重すぎる場合は unit/fixture coverage を優先してよい。ただし user-visible Panel behavior の確認手段は残す。
|
||||||
|
|
||||||
|
Escalate if:
|
||||||
|
- Existing metadata / resolved manifest snapshot に runtime workspace root が十分に保存されておらず、schema/storage 追加や destructive migration が必要。
|
||||||
|
- Legacy Pod を隠すことで restore/attach 導線を維持できない。
|
||||||
|
- canonicalization で symlink / moved checkout / worktree treatment の product decision が必要。
|
||||||
|
- no-Ticket fallback が all-Pod dashboard であるべきか current-workspace dashboard であるべきか、既存設計と衝突する。
|
||||||
|
- 別 workspace Pod を診断用に通常 action row とは別に見せる必要が出る。
|
||||||
|
|
||||||
|
Validation:
|
||||||
|
- Focused tests for Panel ViewModel / Pod list filtering:
|
||||||
|
- current workspace Pod visible;
|
||||||
|
- other workspace Pod hidden;
|
||||||
|
- current workspace Orchestrator/role Pod visible;
|
||||||
|
- cwd/worktree difference alone does not hide current workspace Pod;
|
||||||
|
- unknown/corrupt workspace metadata is not treated as current workspace。
|
||||||
|
- Existing Panel/TUI tests continue to pass。
|
||||||
|
- If practical: Panel E2E fixture with multiple workspace Pod metadata records。
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `git diff --check`
|
||||||
|
- relevant `cargo test` / `cargo check`
|
||||||
|
|
||||||
|
Critical risks / reviewer focus:
|
||||||
|
- workspace filter が cwd/name heuristic になっていないか。
|
||||||
|
- metadata 判定不能 Pod を current workspace と誤認していないか。
|
||||||
|
- dedicated orchestration / implementation worktree cwd の current workspace Pod を誤って隠していないか。
|
||||||
|
- attach/open/action target が hidden external Pod に残っていないか。
|
||||||
|
- no-Ticket fallback と Ticket-enabled Panel の両方で current workspace Pod discovery が維持されているか。
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- `queued -> inprogress` を記録し、Ticket records を Orchestrator worktree に commit してから、専用 implementation worktree を作成し Coder Pod を narrow write scope で起動する。root/original workspace は操作しない。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-18T14:50:54Z from: queued to: inprogress reason: orchestrator_acceptance_current_workspace_pod_filter field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket body/thread, relation metadata, orchestration plan records, Orchestrator worktree, visible Pods, existing branch/worktree, and bounded code context were checked. No blocking relation, conflict, dirty-state blocker, or missing planning decision was found. Risk flags are captured as invariants/reviewer focus rather than stop gates. Accepting this queued Ticket for implementation before worktree/Pod side effects.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T14:51:50Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Implementation start note:
|
||||||
|
|
||||||
|
`queued -> inprogress` acceptance、accepted plan、routing decision / IntentPacket を記録し、Orchestrator worktree で commit した後に、専用 implementation worktree と Coder Pod を起動した。
|
||||||
|
|
||||||
|
Worktree:
|
||||||
|
- `/home/hare/Projects/yoi/.worktree/00001KVDH2E06-panel-current-workspace-pods`
|
||||||
|
- branch: `impl/00001KVDH2E06-panel-current-workspace-pods`
|
||||||
|
|
||||||
|
Coder Pod:
|
||||||
|
- `yoi-coder-00001KVDH2E06`
|
||||||
|
|
||||||
|
Scope / boundaries:
|
||||||
|
- child runtime workspace root は read scope。
|
||||||
|
- implementation worktree は write scope。
|
||||||
|
- root/original workspace と Orchestrator worktree へは書き込まないよう指示済み。
|
||||||
|
- `.yoi/memory`、runtime/log/lock/local/secret-like `.yoi` paths は編集しないよう指示済み。
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Coder は current-workspace Pod filtering、focused tests、validation、implementation commit を行い、実装報告を返す予定。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T15:15:57Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Coder implementation report received:
|
||||||
|
|
||||||
|
Commit:
|
||||||
|
- `3b634d66` — `tui: filter panel pods by workspace`
|
||||||
|
|
||||||
|
Summary:
|
||||||
|
- `PodMetadata` に optional persisted `workspace_root` を追加し、新規 metadata write 時に Pod runtime workspace を保存するようにした。
|
||||||
|
- persisted metadata に基づく workspace-aware Pod list construction/filtering を追加。Pod name prefix や cwd heuristic では判定しない。
|
||||||
|
- `yoi panel` の normal Pod rows / action targets を current runtime workspace metadata で filter するようにした。
|
||||||
|
- legacy / unknown / corrupt workspace metadata は normal Panel Pod rows では fail-closed にした。
|
||||||
|
- current-workspace Companion / Orchestrator / Ticket role Pod は、stored runtime workspace が current workspace と一致すれば worktree/cwd 差分に関係なく表示対象に残る。
|
||||||
|
|
||||||
|
Files changed:
|
||||||
|
- `crates/pod-store/src/lib.rs`
|
||||||
|
- `crates/pod/src/pod.rs`
|
||||||
|
- `crates/pod/src/discovery.rs`
|
||||||
|
- `crates/pod/src/ticket_event_notify.rs`
|
||||||
|
- `crates/tui/src/multi_pod.rs`
|
||||||
|
- `crates/tui/src/pod_list.rs`
|
||||||
|
- `crates/tui/src/workspace_panel.rs`
|
||||||
|
|
||||||
|
Focused validation reported by Coder:
|
||||||
|
- `cargo test -p tui workspace_panel -- --nocapture` — passed; 23 tests
|
||||||
|
- `cargo test -p tui pod_list -- --nocapture` — passed; 19 tests
|
||||||
|
- `cargo test -p pod-store` — passed; 6 tests
|
||||||
|
- `cargo test -p pod pod_metadata -- --nocapture` — passed targeted Pod metadata tests and filtered integration tests
|
||||||
|
- `cargo check -p tui -p pod -p pod-store` — passed
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
|
||||||
|
Full-suite note:
|
||||||
|
- Coder also attempted `cargo test -p tui`; it failed with 3 tests outside the focused scope:
|
||||||
|
- `multi_pod::tests::orchestrator_launch_context_uses_orchestration_root_for_runtime_workspace`
|
||||||
|
- `spawn::tests::profile_choices_include_builtin_and_project_default_marker`
|
||||||
|
- `spawn::tests::profile_choices_use_project_registry_default`
|
||||||
|
- Orchestrator re-ran these failing tests in both the implementation worktree and the current Orchestrator worktree before this implementation was merged. The same failures reproduce on the Orchestrator branch, so they are currently treated as pre-existing validation debt rather than blockers for this Ticket, unless review finds the implementation worsens their semantics.
|
||||||
|
|
||||||
|
Orchestrator evidence checked:
|
||||||
|
- Pod output を確認。
|
||||||
|
- implementation worktree は clean。
|
||||||
|
- branch `impl/00001KVDH2E06-panel-current-workspace-pods` HEAD は `3b634d66`。
|
||||||
|
- diff stat from accepted base `e2e76d3b..3b634d66`: 7 files changed, 292 insertions, 14 deletions。
|
||||||
|
- Focused failing-test comparison:
|
||||||
|
- `cargo test -p tui multi_pod::tests::orchestrator_launch_context_uses_orchestration_root_for_runtime_workspace -- --nocapture` fails identically on implementation worktree and Orchestrator worktree.
|
||||||
|
- `cargo test -p tui spawn::tests::profile_choices -- --nocapture` fails identically on implementation worktree and Orchestrator worktree.
|
||||||
|
|
||||||
|
Routing classification: review_needed
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- recorded intent / invariants / acceptance criteria に照らして、read-only Reviewer Pod で外部レビューする。
|
||||||
|
- 特に workspace authority が runtime workspace metadata であり cwd/name heuristic ではないこと、unknown/corrupt metadata の fail-closed、current workspace role Pod visibility、hidden external Pod に action target が残らないこと、optional `workspace_root` metadata の compatibility を確認する。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: plan author: yoi-orchestrator at: 2026-06-18T15:16:45Z -->
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
Review dispatch:
|
||||||
|
|
||||||
|
Reviewer Pod `yoi-reviewer-00001KVDH2E06` を read-only scope で起動した。
|
||||||
|
|
||||||
|
Review target:
|
||||||
|
- worktree: `/home/hare/Projects/yoi/.worktree/00001KVDH2E06-panel-current-workspace-pods`
|
||||||
|
- branch: `impl/00001KVDH2E06-panel-current-workspace-pods`
|
||||||
|
- commit: `3b634d66`
|
||||||
|
|
||||||
|
Reviewer focus:
|
||||||
|
- recorded intent / invariants / acceptance criteria に対する適合性。
|
||||||
|
- workspace ownership authority が persisted runtime workspace metadata / resolved identity に基づき、Pod name prefix / cwd heuristic ではないこと。
|
||||||
|
- external workspace Pod が normal rows と normal action targets から除外されること。
|
||||||
|
- current workspace Companion / Orchestrator / Ticket role Pod が cwd/worktree difference によって誤って隠されないこと。
|
||||||
|
- unknown/corrupt/legacy metadata が fail-closed で current workspace と誤認されないこと。
|
||||||
|
- optional `workspace_root` metadata が non-destructive / compatible であること。
|
||||||
|
- focused tests が current visible / external hidden / role visible / worktree cwd difference / live-only legacy corrupt hidden / Panel row-action filtering を十分に覆っていること。
|
||||||
|
- `cargo test -p tui` の 3 failure は Orchestrator branch でも同様に再現するため pre-existing debt と見てよいか、それともこの branch が semantic に悪化させているか。
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Reviewer output を確認し、approve なら Orchestrator worktree へ merge/validation/cleanup/close-ready 処理へ進む。request_changes なら blocker を記録して Coder に戻す。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVDH2E06 at: 2026-06-18T15:24:39Z status: request_changes -->
|
||||||
|
|
||||||
|
## Review: request changes
|
||||||
|
|
||||||
|
Review result: request_changes
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVDH2E06`
|
||||||
|
- branch: `impl/00001KVDH2E06-panel-current-workspace-pods`
|
||||||
|
- commit: `3b634d66` (`tui: filter panel pods by workspace`)
|
||||||
|
|
||||||
|
Blocker:
|
||||||
|
- runtime metadata 用の `workspace_root` は計算されているが、normal metadata write-through path で永続化される前に捨てられている。
|
||||||
|
|
||||||
|
Evidence:
|
||||||
|
- `crates/pod/src/pod.rs:4320-4327` では `PodMetadata::new(...).with_workspace_root(workspace_root.to_path_buf())` を構築している。
|
||||||
|
- しかし `pod_metadata_writer_for_store` (`crates/pod/src/pod.rs:68-80`) は `store.set_active(&metadata.pod_name, metadata.active, metadata.resolved_manifest_snapshot)` だけを呼び、`metadata.workspace_root` を渡していない。
|
||||||
|
- `PodMetadataStore::set_active` / `update_by_name` (`crates/pod-store/src/lib.rs:154-178`) は absent record を `PodMetadata::new(pod_name, None)` で作り、`active` / `resolved_manifest_snapshot` だけを更新する。そのため、新規 metadata file は `workspace_root: None` のままになる。
|
||||||
|
- constructors/write-through paths、例: `write_pod_metadata_pending` はこの writer を使うため、normal runtime path では新しい workspace ownership field が永続化されないように見える。
|
||||||
|
|
||||||
|
Why this breaks acceptance:
|
||||||
|
- `crates/tui/src/pod_list.rs:68-95` は fail-closed 設計で、stored Pods は `info.workspace_root.is_some_and(...)` の場合だけ含め、live Pods も stored current-workspace record と name が一致した場合だけ含める。
|
||||||
|
- normal write path が current-workspace Pods を `workspace_root: None` のままにすると、新規 current-workspace Pods が unknown/legacy として扱われ、normal Panel rows/action targets から隠れる。
|
||||||
|
- これは current-workspace Companion / Orchestrator / Ticket role Pods を表示するという acceptance criteria を直接壊す。
|
||||||
|
|
||||||
|
Positive findings:
|
||||||
|
- filter logic の方向性は正しい。persisted `workspace_root` を使っており、Pod name / live cwd heuristic ではない。
|
||||||
|
- `workspace_root: Option<PathBuf>` に serde default / skip-serializing-if を付ける設計は old metadata に対して non-destructive に見える。
|
||||||
|
- tests は pure Panel/PodList filtering fixtures を覆っているが、runtime metadata with `workspace_root` が normal Pod runtime path で実際に永続化される persistence boundary を見逃している。
|
||||||
|
|
||||||
|
Requested changes:
|
||||||
|
- write-through path で `metadata.workspace_root` を永続化すること。
|
||||||
|
- 例: `set_active` を拡張する、または active/snapshot/workspace ownership を同時に更新する store method を追加する。
|
||||||
|
- unrelated fields は保持すること。
|
||||||
|
- normal Pod metadata write-through を構築/実行し、stored metadata に runtime workspace root が残ることを確認する targeted test を追加する。
|
||||||
|
- Filtering fixture だけではなく、`PodMetadata::with_workspace_root` が存在するだけでもなく、normal runtime/store boundary の永続化を検証すること。
|
||||||
|
|
||||||
|
Validation note:
|
||||||
|
- Reviewer は read-only inspection を実施。Coder の focused validation は確認した。
|
||||||
|
- `cargo test -p tui` の既知 3 failures について、この branch が原因/悪化とは見ていない。ただし上記 persistence blocker は独立して修正が必要。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: plan author: yoi-orchestrator at: 2026-06-18T15:25:21Z -->
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
Review follow-up dispatch:
|
||||||
|
|
||||||
|
Reviewer `yoi-reviewer-00001KVDH2E06` は `request_changes` を返したため、Ticket review として記録し、既存 Coder Pod `yoi-coder-00001KVDH2E06` に修正依頼を送った。
|
||||||
|
|
||||||
|
Coder に依頼した blocker:
|
||||||
|
- `workspace_root` は runtime metadata 構築時に計算されるが、normal metadata write-through path で `PodMetadataStore::set_active` / `update_by_name` に渡されず、永続化されていない。
|
||||||
|
- その結果、新規 current-workspace Pod metadata が `workspace_root: None` になり、fail-closed filter により current-workspace Companion / Orchestrator / Ticket role Pod まで normal Panel rows/action targets から隠れる可能性がある。
|
||||||
|
|
||||||
|
Required fixes:
|
||||||
|
- `metadata.workspace_root` を write-through path で永続化する。
|
||||||
|
- active/snapshot/workspace ownership を同時に更新する API 追加または既存 API 拡張で、unrelated fields は保持する。
|
||||||
|
- normal Pod metadata write-through/store boundary を通して、stored metadata に runtime workspace root が残る targeted test を追加する。
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Coder の修正 commit / validation report を待つ。
|
||||||
|
- 修正後、同じ persistence boundary と filtering semantics を中心に再レビューする。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T15:29:08Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Coder review-fix implementation report received:
|
||||||
|
|
||||||
|
Incremental fix commit:
|
||||||
|
- `160c96ad` — `pod: persist metadata workspace root`
|
||||||
|
|
||||||
|
Summary:
|
||||||
|
- metadata write-through path を更新し、`PodMetadata.workspace_root` が永続化されるようにした。
|
||||||
|
- `PodMetadataStore::set_active_with_workspace_root(...)` を追加。
|
||||||
|
- 既存 `set_active(...)` は compatibility wrapper として残し、既存 workspace ownership を保持する挙動にした。
|
||||||
|
- `pod_metadata_writer_for_store(...)` が `metadata.workspace_root` を store に渡すようにした。
|
||||||
|
- persistence-boundary targeted test を追加。
|
||||||
|
- `metadata_writer_persists_workspace_root_through_store_update`
|
||||||
|
- `pod_metadata_writer_for_store` + `FsPodStore` を通し、stored metadata に runtime workspace root が残ることを検証。
|
||||||
|
|
||||||
|
Files changed in incremental fix:
|
||||||
|
- `crates/pod-store/src/lib.rs`
|
||||||
|
- `crates/pod/src/pod.rs`
|
||||||
|
|
||||||
|
Validation reported by Coder:
|
||||||
|
- `cargo test -p pod metadata_writer_persists_workspace_root_through_store_update -- --nocapture` — passed
|
||||||
|
- `cargo test -p pod pod_metadata -- --nocapture` — passed
|
||||||
|
- `cargo test -p pod-store` — passed
|
||||||
|
- `cargo test -p tui workspace_panel -- --nocapture` — passed
|
||||||
|
- `cargo test -p tui pod_list -- --nocapture` — passed
|
||||||
|
- `cargo check -p tui -p pod -p pod-store` — passed
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
|
||||||
|
Orchestrator evidence checked:
|
||||||
|
- Pod output を確認。
|
||||||
|
- implementation worktree は clean。
|
||||||
|
- branch `impl/00001KVDH2E06-panel-current-workspace-pods` HEAD は `160c96ad`。
|
||||||
|
- incremental diff stat from previous review target `3b634d66..160c96ad`: 2 files changed, 35 insertions, 2 deletions。
|
||||||
|
|
||||||
|
Routing classification: review_needed
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- previous `request_changes` blocker が解消されたか、read-only Reviewer Pod で再レビューする。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: plan author: yoi-orchestrator at: 2026-06-18T15:29:46Z -->
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
Review re-dispatch:
|
||||||
|
|
||||||
|
Reviewer Pod `yoi-reviewer-00001KVDH2E06-r2` を read-only scope で起動した。
|
||||||
|
|
||||||
|
Review target:
|
||||||
|
- worktree: `/home/hare/Projects/yoi/.worktree/00001KVDH2E06-panel-current-workspace-pods`
|
||||||
|
- branch: `impl/00001KVDH2E06-panel-current-workspace-pods`
|
||||||
|
- commits:
|
||||||
|
- `3b634d66` — initial implementation
|
||||||
|
- `160c96ad` — persistence-boundary fix
|
||||||
|
|
||||||
|
Reviewer focus:
|
||||||
|
- previous blocker が normal runtime/store write-through path で解消されているか。
|
||||||
|
- `set_active_with_workspace_root` が unrelated metadata fields を破壊せず、workspace ownership を永続化するか。
|
||||||
|
- compatibility `set_active` が existing workspace ownership を保持しているか。
|
||||||
|
- 新 test `metadata_writer_persists_workspace_root_through_store_update` が constructor ではなく `pod_metadata_writer_for_store` + `FsPodStore` boundary を実際に検証しているか。
|
||||||
|
- final branch が current workspace visible / external hidden / role visible / unknown corrupt fail-closed / hidden external action target なし、という Ticket acceptance criteria を満たすか。
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Reviewer output を確認し、approve なら Orchestrator worktree への merge/validation/cleanup/close-ready 処理へ進む。request_changes なら blocker を記録して Coder に戻す。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVDH2E06-r2 at: 2026-06-18T15:37:52Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVDH2E06`
|
||||||
|
- branch: `impl/00001KVDH2E06-panel-current-workspace-pods`
|
||||||
|
- commits:
|
||||||
|
- `3b634d66` — `tui: filter panel pods by workspace`
|
||||||
|
- `160c96ad` — `pod: persist metadata workspace root`
|
||||||
|
|
||||||
|
No blockers found.
|
||||||
|
|
||||||
|
Evidence reviewed:
|
||||||
|
- Previous blocker is fixed in the normal write-through path.
|
||||||
|
- `crates/pod/src/pod.rs:68-82` の `pod_metadata_writer_for_store(...)` が `store.set_active_with_workspace_root(...)` を呼び、`metadata.workspace_root` を渡している。
|
||||||
|
- `pod_metadata_for_manifest(...)` は引き続き `.with_workspace_root(workspace_root.to_path_buf())` で runtime metadata を構築しており、computed runtime workspace root が writer から `PodMetadataStore` へ流れる。
|
||||||
|
- `set_active_with_workspace_root` は unrelated metadata を保持している。
|
||||||
|
- `crates/pod-store/src/lib.rs:178-192` は `active`、`resolved_manifest_snapshot`、および `workspace_root` が `Some` の場合のみ `workspace_root` を更新する。
|
||||||
|
- `update_by_name` を使うため、`spawned_children`、`reclaimed_children`、`peers` などは保持される。
|
||||||
|
- compatibility `set_active` は existing workspace ownership を保持している。
|
||||||
|
- `crates/pod-store/src/lib.rs:168-176` は `workspace_root: None` で delegate する。
|
||||||
|
- delegated implementation は `if let Some(...)` の中でだけ `metadata.workspace_root` を書くため、legacy callers は既存 workspace ownership を clear しない。
|
||||||
|
- 新 test は constructor ではなく persistence boundary を検証している。
|
||||||
|
- `metadata_writer_persists_workspace_root_through_store_update` は real `FsPodStore` を作り、production `pod_metadata_writer_for_store` を取得し、writer を実行した後、stored metadata を読み戻して `workspace_root` が残ることを assert している。
|
||||||
|
- Final branch still satisfies Ticket behavior。
|
||||||
|
- `PodList::from_workspace_sources` は persisted `workspace_root` で stored Pods を filter し、live probes は stored current-workspace names に限定するため、live-only / legacy / unknown Pods は fail-closed。
|
||||||
|
- `WorkspacePanelViewModel` construction も `pods.filter_for_workspace(workspace_root)` を通すため、external workspace rows は normal Panel rows/action targets にならない。
|
||||||
|
- focused tests は current workspace visible、external/legacy/corrupt/live-only hidden、role-like current workspace Pods visible、normal open action only for visible rows を覆っている。
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- `git diff --check 3b634d66..160c96ad` — passed
|
||||||
|
- `git diff --check e2e76d3b..HEAD` — passed
|
||||||
|
- `cargo test -p pod metadata_writer_persists_workspace_root_through_store_update -- --nocapture` — passed
|
||||||
|
- `cargo test -p pod-store active_updates_preserve_children_and_manifest_snapshot -- --nocapture` — passed
|
||||||
|
- `cargo test -p tui pod_list -- --nocapture` — passed
|
||||||
|
- `cargo test -p tui workspace_panel_filters_pod_rows_to_current_workspace_metadata -- --nocapture` — passed
|
||||||
|
|
||||||
|
Known validation debt:
|
||||||
|
- Full `cargo test -p tui -- --nocapture` still fails in three tests, but these appear pre-existing/unrelated to this branch:
|
||||||
|
- `multi_pod::tests::orchestrator_launch_context_uses_orchestration_root_for_runtime_workspace`
|
||||||
|
- `spawn::tests::profile_choices_use_project_registry_default`
|
||||||
|
- `spawn::tests::profile_choices_include_builtin_and_project_default_marker`
|
||||||
|
- The failing orchestrator assertion/code is already identical on `develop`, and the spawn failures are in unrelated profile-choice tests.
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Previous request_changes blocker is resolved.
|
||||||
|
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T15:39:28Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Merge / validation report:
|
||||||
|
|
||||||
|
Implementation branch `impl/00001KVDH2E06-panel-current-workspace-pods` を Orchestrator worktree の `orchestration` branch に merge した。
|
||||||
|
|
||||||
|
Merge:
|
||||||
|
- merge commit: `0ef36b4e` — `merge: panel workspace pod filter`
|
||||||
|
- implementation commits:
|
||||||
|
- `3b634d66` — `tui: filter panel pods by workspace`
|
||||||
|
- `160c96ad` — `pod: persist metadata workspace root`
|
||||||
|
- changed files:
|
||||||
|
- `crates/pod-store/src/lib.rs`
|
||||||
|
- `crates/pod/src/discovery.rs`
|
||||||
|
- `crates/pod/src/pod.rs`
|
||||||
|
- `crates/pod/src/ticket_event_notify.rs`
|
||||||
|
- `crates/tui/src/multi_pod.rs`
|
||||||
|
- `crates/tui/src/pod_list.rs`
|
||||||
|
- `crates/tui/src/workspace_panel.rs`
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p tui -p pod -p pod-store` — passed
|
||||||
|
- `cargo test -p pod metadata_writer_persists_workspace_root_through_store_update -- --nocapture` — passed
|
||||||
|
- `cargo test -p pod pod_metadata -- --nocapture` — passed
|
||||||
|
- `cargo test -p pod-store` — passed; 6 passed, 0 failed
|
||||||
|
- `cargo test -p tui workspace_panel -- --nocapture` — passed; 23 passed, 0 failed
|
||||||
|
- `cargo test -p tui pod_list -- --nocapture` — passed; 19 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
|
||||||
|
Review:
|
||||||
|
- First review returned `request_changes` for missing persistence of `workspace_root` in the normal metadata write-through path.
|
||||||
|
- Coder fixed the persistence boundary and added a targeted `pod_metadata_writer_for_store` + `FsPodStore` test.
|
||||||
|
- Re-review `yoi-reviewer-00001KVDH2E06-r2` returned `approve` with no blockers.
|
||||||
|
|
||||||
|
Known validation debt:
|
||||||
|
- Full `cargo test -p tui` has three failures that were reproduced on the Orchestrator branch before this branch was merged and are treated as pre-existing/unrelated for this Ticket:
|
||||||
|
- `multi_pod::tests::orchestrator_launch_context_uses_orchestration_root_for_runtime_workspace`
|
||||||
|
- `spawn::tests::profile_choices_use_project_registry_default`
|
||||||
|
- `spawn::tests::profile_choices_include_builtin_and_project_default_marker`
|
||||||
|
|
||||||
|
Outcome:
|
||||||
|
- Normal Panel Pod rows/action targets are filtered to current workspace Pods using persisted runtime workspace metadata.
|
||||||
|
- External workspace Pods and unknown/corrupt/live-only metadata fail closed for normal rows.
|
||||||
|
- Current workspace role-like Pods remain visible when persisted runtime workspace matches, independent of cwd/worktree differences.
|
||||||
|
- Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-18T15:40:02Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Cleanup report:
|
||||||
|
|
||||||
|
Panel current-workspace Pod filter Ticket の implementation/review Pods と child worktree を cleanup した。
|
||||||
|
|
||||||
|
Stopped Pods:
|
||||||
|
- `yoi-coder-00001KVDH2E06`
|
||||||
|
- `yoi-reviewer-00001KVDH2E06-r2`
|
||||||
|
|
||||||
|
Removed child implementation worktree:
|
||||||
|
- `/home/hare/Projects/yoi/.worktree/00001KVDH2E06-panel-current-workspace-pods`
|
||||||
|
|
||||||
|
Deleted merged implementation branch:
|
||||||
|
- `impl/00001KVDH2E06-panel-current-workspace-pods` at `160c96ad`
|
||||||
|
|
||||||
|
Orchestrator branch remains the integration authority for this completed work. Root/original workspace was not touched for this Ticket, per Panel Queue instruction.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-18T15:40:11Z from: inprogress to: done reason: merged_validated_review_approved field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Implementation commits `3b634d66` and `160c96ad` were reviewed after blocker resolution, approved, merged into the Orchestrator branch as `0ef36b4e`, validated in the Orchestrator worktree, and child implementation resources were cleaned up. Requirements and acceptance criteria are satisfied for this Ticket. Root/original workspace was not operated on for this Ticket per Panel Queue instruction.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-18T15:40:38Z from: done to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-18T15:40:38Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Ticket `00001KVDH2E06` is complete.
|
||||||
|
|
||||||
|
Completed implementation:
|
||||||
|
- Normal `yoi panel` Pod rows and Pod action targets are filtered to the current runtime workspace using persisted Pod metadata / runtime workspace ownership.
|
||||||
|
- Added optional persisted `workspace_root` to `PodMetadata` and ensured normal metadata write-through persists it.
|
||||||
|
- Added `PodMetadataStore::set_active_with_workspace_root(...)` while keeping compatibility `set_active(...)` preserving existing workspace ownership.
|
||||||
|
- Workspace-external Pods are excluded from normal Panel rows/action targets.
|
||||||
|
- Unknown/corrupt/live-only metadata fail closed and are not treated as current workspace Pods.
|
||||||
|
- Current-workspace role-like Pods remain visible when persisted runtime workspace matches, independent of cwd/worktree differences.
|
||||||
|
|
||||||
|
Reviewed / merged:
|
||||||
|
- Initial implementation: `3b634d66` (`tui: filter panel pods by workspace`)
|
||||||
|
- Persistence-boundary fix: `160c96ad` (`pod: persist metadata workspace root`)
|
||||||
|
- First review requested changes for missing persistence of `workspace_root` through the normal store writer path.
|
||||||
|
- Re-review approved with no remaining blockers.
|
||||||
|
- Orchestrator merge commit: `0ef36b4e` (`merge: panel workspace pod filter`)
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p tui -p pod -p pod-store` — passed
|
||||||
|
- `cargo test -p pod metadata_writer_persists_workspace_root_through_store_update -- --nocapture` — passed
|
||||||
|
- `cargo test -p pod pod_metadata -- --nocapture` — passed
|
||||||
|
- `cargo test -p pod-store` — passed; 6 passed, 0 failed
|
||||||
|
- `cargo test -p tui workspace_panel -- --nocapture` — passed; 23 passed, 0 failed
|
||||||
|
- `cargo test -p tui pod_list -- --nocapture` — passed; 19 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
|
||||||
|
Known validation debt:
|
||||||
|
- Full `cargo test -p tui` still has three pre-existing/unrelated failures reproduced on the Orchestrator branch before this implementation was merged:
|
||||||
|
- `multi_pod::tests::orchestrator_launch_context_uses_orchestration_root_for_runtime_workspace`
|
||||||
|
- `spawn::tests::profile_choices_use_project_registry_default`
|
||||||
|
- `spawn::tests::profile_choices_include_builtin_and_project_default_marker`
|
||||||
|
|
||||||
|
Cleanup:
|
||||||
|
- Stopped Coder Pod `yoi-coder-00001KVDH2E06`.
|
||||||
|
- Stopped Reviewer Pod `yoi-reviewer-00001KVDH2E06-r2`.
|
||||||
|
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KVDH2E06-panel-current-workspace-pods`.
|
||||||
|
- Deleted merged branch `impl/00001KVDH2E06-panel-current-workspace-pods`.
|
||||||
|
|
||||||
|
Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction. The completed work is integrated on the Orchestrator branch.
|
||||||
|
|
||||||
|
---
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
{
|
||||||
|
"version": 1,
|
||||||
|
"relations": [
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVDJCVWZ",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KTTW04W2",
|
||||||
|
"note": "Fixes live delivery gap for auto_run:false Orchestrator Ticket event Companion notifications.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-18T14:33:50Z"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,70 @@
|
|||||||
|
---
|
||||||
|
title: 'Orchestrator Ticket event Companion notify の peer registration / diagnostics を修正する'
|
||||||
|
state: 'closed'
|
||||||
|
created_at: '2026-06-18T14:33:09Z'
|
||||||
|
updated_at: '2026-06-19T07:52:14Z'
|
||||||
|
assignee: null
|
||||||
|
readiness: 'implementation_ready'
|
||||||
|
risk_flags: ['orchestrator', 'companion', 'peer-notify', 'ticket-event', 'auto-run-false', 'diagnostics']
|
||||||
|
---
|
||||||
|
|
||||||
|
## Background
|
||||||
|
|
||||||
|
`00001KTTW04W2` で Orchestrator role の明示 Ticket lifecycle event を workspace Companion に `Notify { auto_run: false }` で送る hook は実装済みだった。しかし live 状態では Orchestrator metadata 側に workspace Companion peer が無いと、`send_weak_notify_to_live_peer` が silent no-op になり、Companion に通知が届かない。
|
||||||
|
|
||||||
|
現在の運用では workspace Companion `yoi` と `yoi-orchestrator` が同じ workspace の role Pod として存在していても、peer metadata が片方向または欠落することがある。この場合、通知 hook は実行されても delivery 前提を満たせず、ユーザーには何も見えない。
|
||||||
|
|
||||||
|
この Ticket では peer 境界を緩めず、workspace Companion / Orchestrator の reciprocal peer relationship を通知前に保証し、delivery skip reason を bounded diagnostic として残す。
|
||||||
|
|
||||||
|
## Requirements
|
||||||
|
|
||||||
|
- Orchestrator Ticket event Companion notify は `auto_run: false` を維持する。
|
||||||
|
- Companion missing / stopped / unreachable では spawn / restore しない。
|
||||||
|
- Peer visibility check は維持する。
|
||||||
|
- arbitrary Pod name へ notify できるようにはしない。
|
||||||
|
- Orchestrator startup / hook install 時に、既存 workspace Companion metadata があれば reciprocal peer を ensure する。
|
||||||
|
- Ticket event hook 実行時にも、既存 workspace Companion metadata があれば reciprocal peer を ensure する。
|
||||||
|
- 既存 running state で片方向 peer / missing peer があっても回復できるようにする。
|
||||||
|
- `send_weak_notify_to_live_peer` は bool ではなく delivery reason を返す。
|
||||||
|
- delivered
|
||||||
|
- missing metadata
|
||||||
|
- not visible
|
||||||
|
- visible but not peer
|
||||||
|
- not live / unreachable
|
||||||
|
- send failed
|
||||||
|
- Delivery skip / failure reason は bounded tracing diagnostic として確認できる。
|
||||||
|
- Missing Companion は debug/no-op に留める。
|
||||||
|
- Ticket event hook は passive Ticket read/list/show では発火しない既存条件を維持する。
|
||||||
|
|
||||||
|
## Implementation summary
|
||||||
|
|
||||||
|
- `PodDiscovery::ensure_existing_peer` を追加し、peer metadata が存在する場合だけ reciprocal peer registration を行う。
|
||||||
|
- `register_peer` は `ensure_existing_peer` を使う形に整理し、missing peer は従来どおり `MissingPod` error を返す。
|
||||||
|
- `WeakNotifyDelivery` を追加し、weak notify delivery result を reason 付きで返すようにした。
|
||||||
|
- Orchestrator Ticket event hook install 時に existing Companion peer を ensure する。
|
||||||
|
- Ticket event hook call 時にも existing Companion peer を ensure してから weak notify する。
|
||||||
|
- Delivery skipped / send failed を `warn!`、missing Companion / ensured peer を `debug!` で記録する。
|
||||||
|
- Tests を追加・更新し、peer が事前登録されていない既存 Companion metadata でも hook が reciprocal peer を作り、`Notify { auto_run: false }` を届けることを確認した。
|
||||||
|
|
||||||
|
## Acceptance criteria
|
||||||
|
|
||||||
|
- Existing workspace Companion metadata がある場合、Orchestrator Ticket event notify 前に reciprocal peer が ensure される。
|
||||||
|
- Orchestrator Ticket event hook は peer 未登録の既存 Companion に `Notify { auto_run: false }` を届けられる。
|
||||||
|
- `send_weak_notify_to_live_peer` は delivered / skipped reason を区別して返す。
|
||||||
|
- Spawned-child visibility など peer ではない Pod には weak notify しない。
|
||||||
|
- Missing Companion では spawn / restore せず no-op diagnostic に留める。
|
||||||
|
- Passive Ticket tool call では通知しない既存挙動を維持する。
|
||||||
|
|
||||||
|
## Validation
|
||||||
|
|
||||||
|
- `cargo test -p pod discovery::tests::register_peer_persists_reciprocal_metadata --no-default-features`
|
||||||
|
- `cargo test -p pod weak_notify --no-default-features`
|
||||||
|
- `cargo test -p pod ticket_event_notify --no-default-features`
|
||||||
|
- `cargo check -p pod -p tui --all-targets`
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `git diff --check`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
## Related work
|
||||||
|
|
||||||
|
- `00001KTTW04W2` — Orchestrator進捗をAutoKickなしでCompanionへ通知する。
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
Ticket `00001KVDJCVWZ` (`Orchestrator Ticket event Companion notify の peer registration / diagnostics を修正する`) はすでに `state: done` に到達していたため、workspace Panel から close しました。
|
||||||
|
|
||||||
|
この Close action によって、実装作業、state 変更、Orchestrator/Companion launch、worker invocation は開始されていません。
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
<!-- event: create author: "yoi ticket" at: 2026-06-18T14:33:09Z -->
|
||||||
|
|
||||||
|
## 作成
|
||||||
|
|
||||||
|
LocalTicketBackend によって作成されました。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-19T07:52:14Z from: done to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-19T07:52:14Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Ticket `00001KVDJCVWZ` (`Orchestrator Ticket event Companion notify の peer registration / diagnostics を修正する`) はすでに `state: done` に到達していたため、workspace Panel から close しました。
|
||||||
|
|
||||||
|
この Close action によって、実装作業、state 変更、Orchestrator/Companion launch、worker invocation は開始されていません。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
@@ -0,0 +1,13 @@
|
|||||||
|
{
|
||||||
|
"version": 1,
|
||||||
|
"relations": [
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVDQH839",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KVDETSN6",
|
||||||
|
"note": "Adds shell-enter launch-path coverage on top of dashboard content-ready metric.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-18T16:03:59Z"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,57 @@
|
|||||||
|
---
|
||||||
|
title: 'Panel E2E に shell Enter 起動経路の dashboard readiness 計測を追加する'
|
||||||
|
state: 'closed'
|
||||||
|
created_at: '2026-06-18T16:02:56Z'
|
||||||
|
updated_at: '2026-06-19T05:44:09Z'
|
||||||
|
assignee: null
|
||||||
|
readiness: 'implementation_ready'
|
||||||
|
risk_flags: ['panel', 'e2e', 'startup-latency', 'shell-launch', 'dashboard-content-ready']
|
||||||
|
---
|
||||||
|
|
||||||
|
## Background
|
||||||
|
|
||||||
|
既存の Panel dashboard readiness E2E は direct `Command::spawn(yoi panel ...)` から dashboard content ready までを測っていた。ユーザー目線の「Enter した瞬間から実コンテンツが表示されるまで」に近づけるため、isolated fixture は維持しつつ、shell 上で command line を投入して Enter された起動経路を部分的に模した E2E を追加する。
|
||||||
|
|
||||||
|
この Ticket は live workspace の遅延改善そのものではなく、E2E の起動経路を実利用に近づける追加計測である。
|
||||||
|
|
||||||
|
## Requirements
|
||||||
|
|
||||||
|
- PTY 上で `/bin/sh` を起動し、`exec <yoi> panel ...` を command line として送って Enter 相当から測定する。
|
||||||
|
- 測定開始点は command line を PTY に送る直前とする。
|
||||||
|
- dashboard readiness は既存の `dashboard_content_ready` snapshot matcher を使う。
|
||||||
|
- first frame だけ、単一 row だけでは通さない。
|
||||||
|
- Isolated fixture / isolated HOME / XDG dirs / runtime dirs は維持する。
|
||||||
|
- `YOI_POD_RUNTIME_COMMAND` は tested binary を明示して渡す。
|
||||||
|
- Direct spawn E2E は残し、shell-enter path は追加 coverage とする。
|
||||||
|
|
||||||
|
## Implementation summary
|
||||||
|
|
||||||
|
- `PanelHarness::spawn_via_shell_enter` を追加した。
|
||||||
|
- `/bin/sh` を PTY 上で起動。
|
||||||
|
- `exec '<binary>' '<args>'...` を送信。
|
||||||
|
- command line送信直前の `Instant` を返す。
|
||||||
|
- artifacts `run.json` に `launch_mode: shell_enter_exec` を記録。
|
||||||
|
- shell quote helper を追加した。
|
||||||
|
- `panel_dashboard_content_ready_from_shell_enter_path` E2E を追加した。
|
||||||
|
- Enter相当から first frame / dashboard content ready を測定。
|
||||||
|
- expected dashboard snapshot / source breakdown を検証。
|
||||||
|
|
||||||
|
## Validation
|
||||||
|
|
||||||
|
- `cargo test -p yoi-e2e --features e2e --test panel panel_dashboard_content_ready_from_shell_enter_path -- --nocapture`
|
||||||
|
- observed: dashboard content ready 約 `220ms`, first frame 約 `20ms` in isolated fixture。
|
||||||
|
- `cargo test -p yoi-e2e --features e2e --test panel`
|
||||||
|
- `cargo check -p yoi-e2e -p yoi -p tui --features tui/e2e-test`
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `git diff --check`
|
||||||
|
|
||||||
|
## Non-goals
|
||||||
|
|
||||||
|
- Live workspace startup latency の改善。
|
||||||
|
- Interactive shell の command lookup / user typing latency の完全再現。
|
||||||
|
- User's actual shell rc/profile を読むこと。
|
||||||
|
- Panel architecture / lifecycle の変更。
|
||||||
|
|
||||||
|
## Related work
|
||||||
|
|
||||||
|
- `00001KVDETSN6` — Panel startup latency をユーザー目線の dashboard content ready 基準で計測・改善する。
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
Closed as completed.
|
||||||
|
|
||||||
|
Added E2E coverage for a Panel shell-enter launch path:
|
||||||
|
- PTY starts `/bin/sh` and sends `exec <yoi> panel ...` as the command line;
|
||||||
|
- measurement starts immediately before sending the command line / Enter-equivalent input;
|
||||||
|
- the test waits for the existing dashboard content-ready snapshot rather than first frame or a single row;
|
||||||
|
- isolated HOME/XDG/runtime fixture remains in place and `YOI_POD_RUNTIME_COMMAND` is pinned to the tested binary;
|
||||||
|
- direct-spawn Panel readiness tests remain as separate coverage.
|
||||||
|
|
||||||
|
Validation was recorded during implementation, including the focused shell-enter test, the full Panel E2E test set, relevant cargo check, formatting, diff check, ticket doctor, and Nix build.
|
||||||
@@ -0,0 +1,34 @@
|
|||||||
|
<!-- event: create author: "yoi ticket" at: 2026-06-18T16:02:56Z -->
|
||||||
|
|
||||||
|
## 作成
|
||||||
|
|
||||||
|
LocalTicketBackend によって作成されました。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-19T05:44:09Z from: done to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-19T05:44:09Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Closed as completed.
|
||||||
|
|
||||||
|
Added E2E coverage for a Panel shell-enter launch path:
|
||||||
|
- PTY starts `/bin/sh` and sends `exec <yoi> panel ...` as the command line;
|
||||||
|
- measurement starts immediately before sending the command line / Enter-equivalent input;
|
||||||
|
- the test waits for the existing dashboard content-ready snapshot rather than first frame or a single row;
|
||||||
|
- isolated HOME/XDG/runtime fixture remains in place and `YOI_POD_RUNTIME_COMMAND` is pinned to the tested binary;
|
||||||
|
- direct-spawn Panel readiness tests remain as separate coverage.
|
||||||
|
|
||||||
|
Validation was recorded during implementation, including the focused shell-enter test, the full Panel E2E test set, relevant cargo check, formatting, diff check, ticket doctor, and Nix build.
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
@@ -0,0 +1,21 @@
|
|||||||
|
{
|
||||||
|
"version": 1,
|
||||||
|
"relations": [
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVF0ZJM5",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KVDETSN6",
|
||||||
|
"note": "Implements live startup latency improvement after dashboard content-ready measurement exposed Pod probe bottleneck.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T04:19:09Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVF0ZJM5",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KVDQH839",
|
||||||
|
"note": "Uses shell/live startup measurements added by the E2E launch-path work.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T04:19:09Z"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,43 @@
|
|||||||
|
---
|
||||||
|
title: 'Panel startup で Pod status probe を重複実行せず初回一覧表示を高速化する'
|
||||||
|
state: 'closed'
|
||||||
|
created_at: '2026-06-19T04:07:17Z'
|
||||||
|
updated_at: '2026-06-19T04:19:09Z'
|
||||||
|
assignee: null
|
||||||
|
readiness: 'implementation_ready'
|
||||||
|
risk_flags: ['panel', 'startup-latency', 'pod-status-probe', 'live-path', 'performance']
|
||||||
|
---
|
||||||
|
|
||||||
|
## Background
|
||||||
|
|
||||||
|
Live workspace で `yoi panel` を起動すると、first frame は約 50ms で出る一方、実際の Ticket / Pod rows が表示されるまで約 8 秒かかっている。実測 breakdown では `pod_metadata_status_probe.initial`、`companion.presence`、`orchestrator.presence` がそれぞれ約 2.5 秒かかり、同じ Pod metadata / live status scan が初回 dashboard render 前に直列で重複実行されている。
|
||||||
|
|
||||||
|
この Ticket では初回一覧表示前の重複 Pod status probe をなくし、live Pod summary の重い session log scan を避け、ユーザー目線の「一覧が表示されるまで」を短縮する。
|
||||||
|
|
||||||
|
## Requirements
|
||||||
|
|
||||||
|
- `load_multi_pod_snapshot` で初回 `load_pod_list` の結果を Companion / Orchestrator presence 判定に再利用する。
|
||||||
|
- 初回 render 前に `load_exact_companion_pod_presence` / `load_exact_pod_presence` 相当の追加 full probe を直列実行しない。
|
||||||
|
- Live status probe は session log 全読みの preview/summary 作成を初回 path で行わない。
|
||||||
|
- stored metadata summary を優先して使う。
|
||||||
|
- live-only row は minimal live summary でよい。
|
||||||
|
- Companion / Orchestrator spawn/restore が必要な場合の reload は維持する。
|
||||||
|
- Existing Panel behavior を壊さない。
|
||||||
|
- Companion / Orchestrator live status 表示
|
||||||
|
- Queue action
|
||||||
|
- Pod rows open/attach
|
||||||
|
- E2E dashboard readiness
|
||||||
|
- Live workspace に近い例外的計測で、rows 表示までの時間が改善していることを確認する。
|
||||||
|
|
||||||
|
## Acceptance criteria
|
||||||
|
|
||||||
|
- Panel startup source breakdown で `companion.presence` / `orchestrator.presence` が追加 full Pod probe として秒単位で出ない。
|
||||||
|
- Live workspace 計測で first non-empty rows 表示が従来約 8 秒から明確に短縮する。
|
||||||
|
- `cargo test -p yoi-e2e --features e2e --test panel` が通る。
|
||||||
|
- `cargo check -p yoi-e2e -p yoi -p tui --features tui/e2e-test` が通る。
|
||||||
|
- `cargo fmt --check` / `git diff --check` / `target/debug/yoi ticket doctor` が通る。
|
||||||
|
|
||||||
|
## Related work
|
||||||
|
|
||||||
|
- `00001KVDETSN6` — Panel startup latency をユーザー目線の dashboard content ready 基準で計測・改善する。
|
||||||
|
- `00001KVDQH839` — Panel E2E に shell Enter 起動経路の dashboard readiness 計測を追加する。
|
||||||
@@ -0,0 +1,22 @@
|
|||||||
|
Implemented and validated.
|
||||||
|
|
||||||
|
Changes:
|
||||||
|
- Reused the initial `load_pod_list` result for Companion and Orchestrator presence in `load_multi_pod_snapshot`, removing two duplicate full Pod status probes before the first dashboard rows render.
|
||||||
|
- Renamed the E2E source timings to `companion.presence.from_initial_list` and `orchestrator.presence.from_initial_list` so regressions show whether the initial list is reused.
|
||||||
|
- Changed Pod list startup summarization to avoid reading active session logs while building initial Pod rows. Stored metadata now uses a cheap active-segment marker and live-only rows keep existing minimal live/pending summaries.
|
||||||
|
- Preserved spawn/restore behavior after Companion/Orchestrator lifecycle changes; if lifecycle changes require reload, the existing reload path remains.
|
||||||
|
|
||||||
|
Live-path measurement in the current workspace:
|
||||||
|
- Before this fix: first non-empty Panel rows appeared at about 7967ms; `pod_metadata_status_probe.initial`, `companion.presence`, and `orchestrator.presence` were each about 2.5s.
|
||||||
|
- After removing duplicate probes only: first non-empty rows appeared at about 2964ms; duplicate presence probes dropped to 0ms but initial Pod metadata/status probe was still about 2386ms.
|
||||||
|
- After also removing session-log reads from the startup Pod summary path: first non-empty rows appeared at about 754ms; `pod_metadata_status_probe.initial` was about 138ms; total dashboard source breakdown was about 649ms.
|
||||||
|
|
||||||
|
Validation:
|
||||||
|
- cargo test -p tui pod_list --lib
|
||||||
|
- cargo test -p yoi-e2e --features e2e --test panel
|
||||||
|
- cargo check -p yoi-e2e -p yoi -p tui --features tui/e2e-test
|
||||||
|
- cargo build -p yoi
|
||||||
|
- cargo fmt --check
|
||||||
|
- git diff --check
|
||||||
|
- target/debug/yoi ticket doctor
|
||||||
|
- nix build .#yoi --no-link
|
||||||
@@ -0,0 +1,46 @@
|
|||||||
|
<!-- event: create author: "yoi ticket" at: 2026-06-19T04:07:17Z -->
|
||||||
|
|
||||||
|
## 作成
|
||||||
|
|
||||||
|
LocalTicketBackend によって作成されました。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-19T04:19:09Z from: inprogress to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-19T04:19:09Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Implemented and validated.
|
||||||
|
|
||||||
|
Changes:
|
||||||
|
- Reused the initial `load_pod_list` result for Companion and Orchestrator presence in `load_multi_pod_snapshot`, removing two duplicate full Pod status probes before the first dashboard rows render.
|
||||||
|
- Renamed the E2E source timings to `companion.presence.from_initial_list` and `orchestrator.presence.from_initial_list` so regressions show whether the initial list is reused.
|
||||||
|
- Changed Pod list startup summarization to avoid reading active session logs while building initial Pod rows. Stored metadata now uses a cheap active-segment marker and live-only rows keep existing minimal live/pending summaries.
|
||||||
|
- Preserved spawn/restore behavior after Companion/Orchestrator lifecycle changes; if lifecycle changes require reload, the existing reload path remains.
|
||||||
|
|
||||||
|
Live-path measurement in the current workspace:
|
||||||
|
- Before this fix: first non-empty Panel rows appeared at about 7967ms; `pod_metadata_status_probe.initial`, `companion.presence`, and `orchestrator.presence` were each about 2.5s.
|
||||||
|
- After removing duplicate probes only: first non-empty rows appeared at about 2964ms; duplicate presence probes dropped to 0ms but initial Pod metadata/status probe was still about 2386ms.
|
||||||
|
- After also removing session-log reads from the startup Pod summary path: first non-empty rows appeared at about 754ms; `pod_metadata_status_probe.initial` was about 138ms; total dashboard source breakdown was about 649ms.
|
||||||
|
|
||||||
|
Validation:
|
||||||
|
- cargo test -p tui pod_list --lib
|
||||||
|
- cargo test -p yoi-e2e --features e2e --test panel
|
||||||
|
- cargo check -p yoi-e2e -p yoi -p tui --features tui/e2e-test
|
||||||
|
- cargo build -p yoi
|
||||||
|
- cargo fmt --check
|
||||||
|
- git diff --check
|
||||||
|
- target/debug/yoi ticket doctor
|
||||||
|
- nix build .#yoi --no-link
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
{"id":"orch-plan-20260619-102132-1","ticket_id":"00001KVFD3YSV","kind":"accepted_plan","accepted_plan":{"summary":"`yoi plugin list` / `yoi plugin show <ref>` を product CLI に追加し、Plugin package discovery / enablement resolution / grant diagnostics / static Tool/runtime eligibility を read-only typed inspection reportとして表示する。Plugin code / WASM / Tool execution / mutation は行わない。","branch":"impl/00001KVFD3YSV-plugin-cli-inspection","worktree":"/home/hare/Projects/yoi/.worktree/00001KVFD3YSV-plugin-cli-inspection","role_plan":"Orchestrator は専用 implementation worktree を作成し、Coder をその worktree への narrow write scope で起動する。Reviewer は実装報告後に read-only で確認する。Host API implementation Tickets は関連するが、CLI inspection は read-only diagnostic surface として先行実装し、host API実装による追加表示は後続差分として扱える。"},"author":"yoi-orchestrator","at":"2026-06-19T10:21:32Z"}
|
||||||
@@ -0,0 +1,45 @@
|
|||||||
|
{
|
||||||
|
"version": 1,
|
||||||
|
"relations": [
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVFD3YSV",
|
||||||
|
"kind": "depends_on",
|
||||||
|
"target": "00001KV5R5V2S",
|
||||||
|
"note": "CLI inspection consumes Plugin package discovery and enablement resolver output.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T07:40:41Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVFD3YSV",
|
||||||
|
"kind": "depends_on",
|
||||||
|
"target": "00001KV5W3PJ3",
|
||||||
|
"note": "CLI inspection should expose permission/grant diagnostics from the implemented grant model.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T07:40:41Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVFD3YSV",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KSXRQ4G8",
|
||||||
|
"note": "Uses established Plugin runtime/surface/host API terminology.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T07:40:41Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVFD3YSV",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KV5W3PHA",
|
||||||
|
"note": "Tool surface registration status should be visible in inspection output.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T07:40:41Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVFD3YSV",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KV5W3PHW",
|
||||||
|
"note": "Runtime config/status should be shown without executing Plugin code.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T07:40:41Z"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,186 @@
|
|||||||
|
---
|
||||||
|
title: 'Plugin: add read-only CLI inspection list/show'
|
||||||
|
state: 'closed'
|
||||||
|
created_at: '2026-06-19T07:39:23Z'
|
||||||
|
updated_at: '2026-06-19T14:22:41Z'
|
||||||
|
assignee: null
|
||||||
|
readiness: 'implementation_ready'
|
||||||
|
risk_flags: ['plugin', 'cli', 'diagnostics', 'read-only', 'json-output', 'no-execution']
|
||||||
|
queued_by: 'workspace-panel'
|
||||||
|
queued_at: '2026-06-19T10:19:28Z'
|
||||||
|
---
|
||||||
|
|
||||||
|
## Background
|
||||||
|
|
||||||
|
Plugin package discovery / explicit enablement / Tool registration / WASM Tool runtime / permission grants まで実装されたため、次に必要なのは「なぜ Plugin が見えない / 有効化されない / 実行できないのか」を headless に確認できる read-only inspection surface である。
|
||||||
|
|
||||||
|
Panel や TUI diagnostic に出す前に、CLI で deterministic に確認できる `yoi plugin list` / `yoi plugin show <ref>` を追加する。この CLI は Plugin code を実行せず、package discovery、manifest parse、enablement resolution、grant validation、static diagnostics を表示するだけにする。
|
||||||
|
|
||||||
|
目的は、Plugin の多段 failure point を human / JSON の両方で確認できるようにすること。
|
||||||
|
|
||||||
|
```text
|
||||||
|
package discovered?
|
||||||
|
manifest valid?
|
||||||
|
api version compatible?
|
||||||
|
explicitly enabled?
|
||||||
|
digest/version/source match?
|
||||||
|
requested permission granted?
|
||||||
|
tool schema valid?
|
||||||
|
runtime config present?
|
||||||
|
```
|
||||||
|
|
||||||
|
## Requirements
|
||||||
|
|
||||||
|
- Top-level product CLI に read-only Plugin inspection command を追加する。
|
||||||
|
- `yoi plugin list`
|
||||||
|
- `yoi plugin show <ref>`
|
||||||
|
- `--json` output を最初から提供する。
|
||||||
|
- `yoi plugin list --json`
|
||||||
|
- `yoi plugin show <ref> --json`
|
||||||
|
- Human-readable output は JSON 用 typed report の thin formatting にする。
|
||||||
|
- Workspace / Profile resolution は通常起動に近い意味にする。
|
||||||
|
- default は current workspace。
|
||||||
|
- 既存 CLI 方針に合わせて `--workspace <path>` を扱う。
|
||||||
|
- Profile 指定が必要なら既存 Profile selector と整合する option を使う。
|
||||||
|
- Plugin code を実行しない。
|
||||||
|
- WASM module を実行しない。
|
||||||
|
- Tool call を発生させない。
|
||||||
|
- Hook / Service / Ingress を起動しない。
|
||||||
|
- Read-only とする。
|
||||||
|
- install / update / enable / disable / trust / sign / run は non-goal。
|
||||||
|
- Plugin package / config / Ticket / memory / Pod state を変更しない。
|
||||||
|
- Inspection report は typed data として実装する。
|
||||||
|
- future Panel diagnostic / tests / agent-readable output で再利用できる形にする。
|
||||||
|
- `list` は package/ref 単位の overview を出す。
|
||||||
|
- ref
|
||||||
|
- source
|
||||||
|
- package path (human output では必要に応じて短縮)
|
||||||
|
- version
|
||||||
|
- api version
|
||||||
|
- digest
|
||||||
|
- status
|
||||||
|
- enabled surfaces
|
||||||
|
- diagnostic count / summary
|
||||||
|
- `show <ref>` は詳細を出す。
|
||||||
|
- manifest metadata
|
||||||
|
- source-qualified identity
|
||||||
|
- package path
|
||||||
|
- digest
|
||||||
|
- version / api version
|
||||||
|
- runtime kind/config summary
|
||||||
|
- enabled surfaces
|
||||||
|
- Tool definitions and registration eligibility
|
||||||
|
- requested permissions
|
||||||
|
- granted permissions
|
||||||
|
- effective grants / denied grants
|
||||||
|
- diagnostics
|
||||||
|
- Status vocabulary を明確にする。
|
||||||
|
- `active`: enabled and statically valid for at least one surface/tool.
|
||||||
|
- `disabled`: discovered but not explicitly enabled.
|
||||||
|
- `missing`: enablement refers to a package that is not discovered.
|
||||||
|
- `rejected`: invalid manifest / incompatible api / digest mismatch / grant mismatch / invalid schema etc.
|
||||||
|
- `partial`: package is usable but some surfaces/tools are rejected.
|
||||||
|
- Diagnostics は bounded / safe にする。
|
||||||
|
- secret-like values / auth / file contents を出さない。
|
||||||
|
- path は必要最小限。JSON では absolute path が必要なら workspace/user store source と一緒に出す。
|
||||||
|
- denial / parse / digest / grant mismatch reasons を区別できる。
|
||||||
|
- Ambiguous unqualified ref は fail closed し、`show` で diagnostic を返す。
|
||||||
|
- JSON schema は stable typed structure として test で固定する。
|
||||||
|
|
||||||
|
## Example human output
|
||||||
|
|
||||||
|
`yoi plugin list`:
|
||||||
|
|
||||||
|
```text
|
||||||
|
REF SOURCE VERSION STATUS SURFACES DIGEST
|
||||||
|
project:example.echo project 0.1.0 active tool sha256:...
|
||||||
|
project:broken project - rejected - -
|
||||||
|
user:fetch user 0.2.1 disabled tool sha256:...
|
||||||
|
```
|
||||||
|
|
||||||
|
`yoi plugin show project:example.echo`:
|
||||||
|
|
||||||
|
```text
|
||||||
|
Plugin: project:example.echo
|
||||||
|
Source: project
|
||||||
|
Package: .yoi/plugins/example.echo.yoi-plugin
|
||||||
|
Version: 0.1.0
|
||||||
|
API: yoi-plugin-1
|
||||||
|
Digest: sha256:...
|
||||||
|
Status: active
|
||||||
|
|
||||||
|
Enabled surfaces:
|
||||||
|
- tool
|
||||||
|
|
||||||
|
Tools:
|
||||||
|
- example_echo
|
||||||
|
status: registered
|
||||||
|
schema: valid
|
||||||
|
external_write: false
|
||||||
|
|
||||||
|
Permissions:
|
||||||
|
Requested:
|
||||||
|
- surfaces.tool
|
||||||
|
- tool:example_echo
|
||||||
|
|
||||||
|
Granted:
|
||||||
|
- surfaces.tool
|
||||||
|
- tool:example_echo
|
||||||
|
|
||||||
|
Diagnostics:
|
||||||
|
- none
|
||||||
|
```
|
||||||
|
|
||||||
|
## Acceptance criteria
|
||||||
|
|
||||||
|
- `yoi plugin list` prints a bounded human-readable overview without executing Plugin code.
|
||||||
|
- `yoi plugin show <ref>` prints detailed static inspection for a Plugin ref without executing Plugin code.
|
||||||
|
- `--json` output is available for both commands and uses a stable typed structure.
|
||||||
|
- Valid enabled Plugin appears as `active`.
|
||||||
|
- Discovered but not enabled Plugin appears as `disabled`.
|
||||||
|
- Enabled but missing package appears as `missing`.
|
||||||
|
- Invalid manifest / incompatible api version appears as `rejected` with diagnostic.
|
||||||
|
- Digest / version / source mismatch appears as diagnostic.
|
||||||
|
- Grant denial / missing requested permission appears as diagnostic.
|
||||||
|
- Partial tool/surface rejection can be represented without marking the whole package as fully active.
|
||||||
|
- Ambiguous unqualified id fails closed with diagnostic.
|
||||||
|
- Plugin code / WASM / Tool execution is not triggered by list/show.
|
||||||
|
- Tests cover:
|
||||||
|
- list human output for active / disabled / rejected / missing packages
|
||||||
|
- show human output for active package with Tool surface and grants
|
||||||
|
- JSON list structure
|
||||||
|
- JSON show structure
|
||||||
|
- invalid manifest diagnostic
|
||||||
|
- digest mismatch diagnostic
|
||||||
|
- missing grant diagnostic
|
||||||
|
- ambiguous ref diagnostic
|
||||||
|
- no runtime execution from inspection path
|
||||||
|
- Validation: focused CLI/plugin inspection tests, relevant `cargo check` / `cargo test`, `cargo fmt --check`, `git diff --check`, and `nix build .#yoi` because product CLI / packaging surface changes.
|
||||||
|
|
||||||
|
## Non-goals
|
||||||
|
|
||||||
|
- Plugin install / update / remove.
|
||||||
|
- Enable / disable mutation.
|
||||||
|
- Trust / signature / registry implementation.
|
||||||
|
- Plugin code execution.
|
||||||
|
- WASM validation beyond static runtime config/manifest inspection.
|
||||||
|
- `https` host API implementation.
|
||||||
|
- `fs` host API implementation.
|
||||||
|
- Service / Ingress startup.
|
||||||
|
- Panel/TUI Plugin diagnostics UI.
|
||||||
|
|
||||||
|
## Implementation notes
|
||||||
|
|
||||||
|
- Product CLI ownership stays in the `yoi` crate.
|
||||||
|
- Avoid embedding resolver logic directly in display formatting; build a typed inspection report first.
|
||||||
|
- Reuse existing Plugin resolver / diagnostics where possible.
|
||||||
|
- Keep CLI output deterministic and suitable for tests.
|
||||||
|
- Do not introduce user-facing terminology `contribution category`; use Plugin runtime / surface / host API / grants.
|
||||||
|
|
||||||
|
## Related work
|
||||||
|
|
||||||
|
- `00001KV5R5V2S` — Plugin package discovery and explicit enablement resolver.
|
||||||
|
- `00001KV5W3PHA` — Plugin Tool surface registration.
|
||||||
|
- `00001KV5W3PHW` — Plugin Tool execution with minimal WASM runtime.
|
||||||
|
- `00001KV5W3PJ3` — Plugin permission grant enforcement.
|
||||||
|
- `00001KSXRQ4G8` — Plugin runtime / surface / minimal host API model design.
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
Ticket `00001KVFD3YSV` is complete.
|
||||||
|
|
||||||
|
Completed implementation:
|
||||||
|
- Added read-only Plugin inspection CLI commands:
|
||||||
|
- `yoi plugin list`
|
||||||
|
- `yoi plugin show <ref>`
|
||||||
|
- JSON output support.
|
||||||
|
- Added typed Plugin inspection report used by both JSON and human output.
|
||||||
|
- Inspection reports package path/location, schema/API version, source/ref/digest/version, requested permissions, grants/denials, diagnostics, Tool/static eligibility, and future host API eligibility structure.
|
||||||
|
- Status vocabulary is limited to `active`, `disabled`, `missing`, `rejected`, `partial`.
|
||||||
|
- Implemented static Tool definition inspection for invalid/duplicate Tool names and invalid `input_schema`.
|
||||||
|
- Distinguished truly absent configured package refs (`missing`) from present-but-invalid packages (`rejected`), including `Missing` diagnostics for missing root `plugin.toml` or missing referenced runtime/package entries.
|
||||||
|
- Preserved read-only/no-execution behavior: inspection does not execute Plugin WASM or Tool code.
|
||||||
|
- Kept diagnostics bounded and structured.
|
||||||
|
|
||||||
|
Reviewed / merged:
|
||||||
|
- Implementation commits:
|
||||||
|
- `462de32a` (`plugin: add cli inspection`)
|
||||||
|
- `b5f10ab7` (`plugin: align inspection statuses`)
|
||||||
|
- `dfa966db` (`plugin: report inspection package metadata`)
|
||||||
|
- `982a1b75` (`plugin: validate inspected tool schemas`)
|
||||||
|
- `a5f3b0b5` (`plugin: reject configured invalid packages`)
|
||||||
|
- `0142ef1d` (`plugin: distinguish present invalid packages`)
|
||||||
|
- Multiple review rounds requested and verified fixes for status vocabulary, package metadata fields, Tool schema/name validation, configured invalid package status, and present-but-invalid `Missing` diagnostics.
|
||||||
|
- Final review `yoi-reviewer-00001KVFD3YSV-r6` approved with no blockers.
|
||||||
|
- Orchestrator merge commit: `71ca05c8` (`merge: plugin cli inspection`)
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p yoi -p pod -p manifest` — passed
|
||||||
|
- `cargo test -p yoi plugin -- --nocapture` — passed; 11 passed, 0 failed
|
||||||
|
- `cargo test -p pod static_inspection -- --nocapture` — passed; 4 passed, 0 failed
|
||||||
|
- `cargo test -p pod plugin -- --nocapture` — passed; 31 passed, 0 failed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
- `nix build .#yoi --no-link` — passed
|
||||||
|
|
||||||
|
Cleanup:
|
||||||
|
- Stopped Coder Pod `yoi-coder-00001KVFD3YSV`.
|
||||||
|
- Stopped Reviewer Pod `yoi-reviewer-00001KVFD3YSV-r6`.
|
||||||
|
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KVFD3YSV-plugin-cli-inspection`.
|
||||||
|
- Deleted merged branch `impl/00001KVFD3YSV-plugin-cli-inspection`.
|
||||||
|
|
||||||
|
Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction. The completed work is integrated on the Orchestrator branch.
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,3 @@
|
|||||||
|
{"id":"orch-plan-20260619-102132-1","ticket_id":"00001KVFDX9AF","kind":"waiting_capacity_note","note":"明示 queue review で確認済み。依存 Ticket `00001KV5W3PHW` / `00001KV5W3PJ3` は closed で blocker ではないが、同時 queued の `00001KVFD3YSV` CLI inspection と `00001KVFDX9AY` fs host API はいずれも Plugin manifest/grant/runtime/diagnostic 周辺を触る。まず read-only CLI inspection を開始し、host API implementation は conflict / reviewer-coder bottleneck を避けるため queued のまま待機する。次の routing pass で再確認する。","author":"yoi-orchestrator","at":"2026-06-19T10:21:32Z"}
|
||||||
|
{"id":"orch-plan-20260619-102132-2","ticket_id":"00001KVFDX9AF","kind":"do_not_parallelize","related_ticket":"00001KVFDX9AY","note":"`https` と `fs` host API はどちらも WASM Plugin Tool runtime host import boundary、Plugin grant model、diagnostics/tests/package behavior に触れるため、同時実装は conflict risk が高い。片方の merged/validated 後にもう片方を再 routing する。","author":"yoi-orchestrator","at":"2026-06-19T10:21:32Z"}
|
||||||
|
{"id":"orch-plan-20260619-142431-3","ticket_id":"00001KVFDX9AF","kind":"accepted_plan","accepted_plan":{"summary":"WASM Plugin Tool runtime に明示 grant された HTTPS outbound host API を追加する。HTTPS-only、private/local target rejection、method/host/path allowlist、bounded request/response/timeout/redirect/diagnostics、secret redaction、ordinary Tool result path、no ambient env/network authority を満たす。","branch":"impl/00001KVFDX9AF-plugin-https-host-api","worktree":"/home/hare/Projects/yoi/.worktree/00001KVFDX9AF-plugin-https-host-api","role_plan":"Orchestrator は専用 implementation worktree を作成し、Coder をその worktree への narrow write scope で起動する。Reviewer は実装報告後に read-only で確認する。`fs` host API と Component Model migration は重複する Plugin runtime/grant surface のため queued hold を維持する。"},"author":"yoi-orchestrator","at":"2026-06-19T14:24:31Z"}
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
{
|
||||||
|
"version": 1,
|
||||||
|
"relations": [
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVFDX9AF",
|
||||||
|
"kind": "depends_on",
|
||||||
|
"target": "00001KV5W3PHW",
|
||||||
|
"note": "https host API is implemented inside the WASM Plugin Tool runtime.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T07:54:32Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVFDX9AF",
|
||||||
|
"kind": "depends_on",
|
||||||
|
"target": "00001KV5W3PJ3",
|
||||||
|
"note": "https host API must be guarded by Plugin permission grants.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T07:54:32Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVFDX9AF",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KSXRQ4G8",
|
||||||
|
"note": "Uses established Plugin host API terminology.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T07:54:32Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVFDX9AF",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KVFD3YSV",
|
||||||
|
"note": "Inspection CLI should expose https host API grants/diagnostics.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T07:54:32Z"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,98 @@
|
|||||||
|
---
|
||||||
|
title: 'Plugin: implement https host API for Tool runtime'
|
||||||
|
state: 'closed'
|
||||||
|
created_at: '2026-06-19T07:53:13Z'
|
||||||
|
updated_at: '2026-06-19T15:35:46Z'
|
||||||
|
assignee: null
|
||||||
|
readiness: 'implementation_ready'
|
||||||
|
risk_flags: ['plugin', 'https', 'host-api', 'network', 'sandbox', 'secrets', 'permission-grants']
|
||||||
|
queued_by: 'workspace-panel'
|
||||||
|
queued_at: '2026-06-19T10:19:53Z'
|
||||||
|
---
|
||||||
|
|
||||||
|
## Background
|
||||||
|
|
||||||
|
Plugin Tool runtime は minimal WASM execution と permission grants まで実装済みだが、外部 HTTPS API を呼ぶ host API はまだ未実装である。
|
||||||
|
|
||||||
|
この Ticket では、WASM Plugin Tool から明示 grant された outbound HTTPS request だけを実行できる `https` host API を追加する。これは Discord webhook / REST API など outbound integration の前提になる。ただし Service / Ingress / WebSocket / inbound HTTP はこの Ticket の対象外。
|
||||||
|
|
||||||
|
用語は `web` ではなく `https` とする。
|
||||||
|
|
||||||
|
## Requirements
|
||||||
|
|
||||||
|
- WASM Plugin Tool runtime に `https` host API import を追加する。
|
||||||
|
- API 名・ABI は既存 `yoi-plugin-wasm-1` / host import 設計と整合させる。
|
||||||
|
- Plugin は ambient network access を持たず、host API 経由のみで HTTPS request できる。
|
||||||
|
- HTTPS only とする。
|
||||||
|
- `http://` は reject。
|
||||||
|
- localhost / private / link-local / unix socket / file URL 等は reject。
|
||||||
|
- Permission grants と統合する。
|
||||||
|
- manifest requested permissions の `host_api.https` を読む。
|
||||||
|
- config granted permissions と照合する。
|
||||||
|
- grant がない場合は fail closed。
|
||||||
|
- host / method / optional path prefix などの allowlist を表現できるようにする。
|
||||||
|
- Request を bounded にする。
|
||||||
|
- method allowlist。
|
||||||
|
- request body size bound。
|
||||||
|
- header count / size bound。
|
||||||
|
- response body size bound。
|
||||||
|
- timeout。
|
||||||
|
- redirect policy。
|
||||||
|
- Credentials は ambient env から読まない。
|
||||||
|
- header / auth は explicit config / secret ref 経由だけにする。
|
||||||
|
- diagnostics に secret-like header / token / body content を漏らさない。
|
||||||
|
- Response は Tool result に安全に戻せる bounded structure にする。
|
||||||
|
- status code
|
||||||
|
- bounded headers if needed
|
||||||
|
- bounded body text / bytes policy
|
||||||
|
- truncated flag
|
||||||
|
- Failure は structured Tool error にする。
|
||||||
|
- grant denied
|
||||||
|
- URL rejected
|
||||||
|
- private/local host rejected
|
||||||
|
- timeout
|
||||||
|
- response too large
|
||||||
|
- network error
|
||||||
|
- unsupported method
|
||||||
|
- Plugin code / history / model context に hidden context injection しない。
|
||||||
|
- HTTPS response は Tool result として通常の tool history 経路に残す。
|
||||||
|
|
||||||
|
## Acceptance criteria
|
||||||
|
|
||||||
|
- Granted Plugin Tool can perform an allowed HTTPS request through host API.
|
||||||
|
- Request without `host_api.https` grant fails closed before network access.
|
||||||
|
- Disallowed host / method / URL scheme fails closed.
|
||||||
|
- `http://`, localhost, private IP, link-local, and local/private host targets are rejected.
|
||||||
|
- Timeout and response size bounds are enforced.
|
||||||
|
- Request / response diagnostics are bounded and redact secret-like values.
|
||||||
|
- No ambient env credentials or ambient network APIs are exposed to WASM.
|
||||||
|
- Tool result path remains ordinary Tool result/history path.
|
||||||
|
- Tests cover:
|
||||||
|
- allowed HTTPS request with grant
|
||||||
|
- missing grant denied
|
||||||
|
- disallowed host denied
|
||||||
|
- method denied
|
||||||
|
- http scheme denied
|
||||||
|
- private/local host denied
|
||||||
|
- timeout
|
||||||
|
- response truncation / size bound
|
||||||
|
- secret header redaction
|
||||||
|
- no network access without host API import/grant
|
||||||
|
- Validation: focused plugin https tests, relevant cargo check/test, `cargo fmt --check`, `git diff --check`, and `nix build .#yoi` because dependency/package/network code may change.
|
||||||
|
|
||||||
|
## Non-goals
|
||||||
|
|
||||||
|
- `fs` host API implementation.
|
||||||
|
- WebSocket / SSE / timer host APIs.
|
||||||
|
- Service surface lifecycle.
|
||||||
|
- Ingress surface.
|
||||||
|
- Discord Gateway bridge.
|
||||||
|
- Inbound HTTP server.
|
||||||
|
- Plugin package manager / install/update.
|
||||||
|
|
||||||
|
## Related work
|
||||||
|
|
||||||
|
- `00001KV5W3PHW` — Plugin Tool execution with minimal WASM runtime.
|
||||||
|
- `00001KV5W3PJ3` — Plugin permission grant enforcement.
|
||||||
|
- `00001KVFD3YSV` — Plugin read-only CLI inspection list/show.
|
||||||
|
- `00001KSXRQ4G8` — Plugin runtime / surface / minimal host API model design.
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
Ticket `00001KVFDX9AF` is complete.
|
||||||
|
|
||||||
|
Completed implementation:
|
||||||
|
- Added granted outbound HTTPS host API for WASM Plugin Tools.
|
||||||
|
- Added typed `host_api.https` grant scope with host, method, optional path prefix, and bounded request/response options.
|
||||||
|
- Implemented `yoi:https` WASM host import handling.
|
||||||
|
- Enforced grant/allowlist checks before network access.
|
||||||
|
- Enforced HTTPS-only behavior and rejected `http://`, embedded credentials, localhost/private/link-local/local targets, IPv4-mapped/compatible IPv6 private/local forms, and unsafe DNS results.
|
||||||
|
- Bound DNS validation to the actual reqwest connection path by pinning validated public socket addresses with `resolve_to_addrs`.
|
||||||
|
- Added request/response bounds, timeout, no redirects, `no_proxy()`, response truncation, and secret-like diagnostics redaction.
|
||||||
|
- Preserved ordinary Tool result/history path and avoided hidden context injection.
|
||||||
|
- Updated Plugin CLI inspection and manifest/permission model to expose HTTPS host API grant/diagnostic details.
|
||||||
|
|
||||||
|
Reviewed / merged:
|
||||||
|
- Implementation commits:
|
||||||
|
- `7377527f` (`plugin: implement https host api`)
|
||||||
|
- `85683f17` (`plugin: harden https target validation`)
|
||||||
|
- First review requested changes for IPv4-mapped IPv6 bypass and DNS validation TOCTOU.
|
||||||
|
- Re-review approved with no remaining blockers.
|
||||||
|
- Orchestrator merge commit: `6beb8625` (`merge: plugin https host api`)
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||||
|
- `cargo test -p pod feature::plugin::tests -- --nocapture` — passed; 39 passed, 0 failed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||||
|
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
- `nix build .#yoi --no-link` — passed
|
||||||
|
|
||||||
|
Cleanup:
|
||||||
|
- Stopped Coder Pod `yoi-coder-00001KVFDX9AF`.
|
||||||
|
- Stopped Reviewer Pod `yoi-reviewer-00001KVFDX9AF-r2`.
|
||||||
|
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KVFDX9AF-plugin-https-host-api`.
|
||||||
|
- Deleted merged branch `impl/00001KVFDX9AF-plugin-https-host-api`.
|
||||||
|
|
||||||
|
Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction. The completed work is integrated on the Orchestrator branch.
|
||||||
@@ -0,0 +1,766 @@
|
|||||||
|
<!-- event: create author: "yoi ticket" at: 2026-06-19T07:53:13Z -->
|
||||||
|
|
||||||
|
## 作成
|
||||||
|
|
||||||
|
LocalTicketBackend によって作成されました。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: workspace-panel at: 2026-06-19T10:19:53Z from: ready to: queued reason: queued field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を `workspace-panel` が queued にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: plan author: yoi-orchestrator at: 2026-06-19T10:22:26Z -->
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
Routing hold / waiting-capacity note:
|
||||||
|
|
||||||
|
明示 queue review で Ticket body / relations / orchestration plan / workspace state を確認した。
|
||||||
|
|
||||||
|
Current decision:
|
||||||
|
- この Ticket は `queued` のまま待機。
|
||||||
|
- 依存 Ticket `00001KV5W3PHW` / `00001KV5W3PJ3` は closed で dependency blocker ではない。
|
||||||
|
- ただし同時 queued の `00001KVFD3YSV` CLI inspection を先に受理した。CLI inspection は Plugin discovery / enablement / grants / diagnostics の read-only public surface を作る作業で、host API implementation と同じ Plugin manifest/grant/runtime/diagnostic 周辺に触れる。
|
||||||
|
- `00001KVFDX9AY` fs host API とは WASM Plugin Tool runtime host import boundary、Plugin grant model、diagnostics/tests/package behavior の変更面が重なるため `do_not_parallelize` plan record を残した。
|
||||||
|
|
||||||
|
Bounded reason for idle queued:
|
||||||
|
- conflict / reviewer-coder bottleneck。
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- `00001KVFD3YSV` の implementation/review/merge outcome を確認後、queued のまま再 routing する。
|
||||||
|
- その時点で `fs` host API Ticket との ordering / conflict も再確認する。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: decision author: yoi-orchestrator at: 2026-06-19T14:25:13Z -->
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
Routing decision: implementation_ready
|
||||||
|
|
||||||
|
Reason:
|
||||||
|
- Panel Queue により、この Ticket は Orchestrator routing 対象として明示許可された。
|
||||||
|
- Ticket body には、HTTPS host API intent、binding invariants、acceptance criteria、non-goals、validation、escalation-worthy risk domain が実装可能な粒度で揃っている。
|
||||||
|
- 依存 relation の `00001KV5W3PHW` minimal WASM runtime、`00001KV5W3PJ3` permission grants、関連 `00001KVFD3YSV` CLI inspection は closed で blocker ではない。
|
||||||
|
- Risk domain は network / secrets / host API / permission grants だが、Ticket は HTTPS-only、private/local target rejection、grant allowlist、bounded request/response/timeout/diagnostics、no ambient env/network、ordinary Tool result path を binding invariants として明示している。bounded context check 後も implementation 前に必要な追加 human decision は見つからなかった。
|
||||||
|
- 同時 queued の `00001KVFDX9AY` fs host API と `00001KVG0HR96` Component Model migration は Plugin runtime/grant/diagnostic/packaging surface が重なるため、waiting/conflict notes を更新し queued のまま待機する。
|
||||||
|
|
||||||
|
Evidence checked:
|
||||||
|
- Ticket `00001KVFDX9AF` body / thread / artifacts。
|
||||||
|
- `TicketRelationQuery(00001KVFDX9AF)`: depends_on は closed。related Ticket は context であり acceptance blocker ではない。
|
||||||
|
- `TicketOrchestrationPlanQuery(00001KVFDX9AF)`: 既存 waiting/do_not_parallelize records を確認。今回 `accepted_plan` を記録済み。
|
||||||
|
- Related completed Tickets:
|
||||||
|
- `00001KV5W3PHW` — minimal WASM Tool runtime closed。
|
||||||
|
- `00001KV5W3PJ3` — Plugin permission grants closed。
|
||||||
|
- `00001KVFD3YSV` — Plugin read-only CLI inspection closed。
|
||||||
|
- Current queued Tickets:
|
||||||
|
- `00001KVFDX9AY` fs host API: do_not_parallelize / waiting reason を維持。
|
||||||
|
- `00001KVG0HR96` Component Model migration: migration boundary / conflict waiting note を更新。
|
||||||
|
- Orchestrator worktree `/home/hare/Projects/yoi/.worktree/orchestration`: clean。
|
||||||
|
- Existing branch/worktree: matching `00001KVFDX9AF` branch/worktree はなし。
|
||||||
|
- Visible Pods: self / peer / intake only; spawned child capacity is free。
|
||||||
|
- Current code map:
|
||||||
|
- `crates/pod/src/feature/plugin.rs`: Plugin resolver, permission grants, static inspection, WASM tool feature。
|
||||||
|
- `crates/pod/src/pod.rs`: WASM Tool runtime / `run_plugin_wasm_tool` / host import validation。
|
||||||
|
- `crates/manifest/src/plugin.rs`: Plugin manifest and permission model。
|
||||||
|
- `crates/yoi/src/plugin_cli.rs`: read-only inspection output should remain compatible with host API diagnostics。
|
||||||
|
|
||||||
|
IntentPacket:
|
||||||
|
|
||||||
|
Intent:
|
||||||
|
- WASM Plugin Tool runtime に、明示 grant された outbound HTTPS request だけを実行できる `https` host API を追加する。
|
||||||
|
- Plugin は ambient network access を持たず、host API import + requested permission + config grant + allowlist を満たす場合だけ bounded HTTPS request を実行できる。
|
||||||
|
|
||||||
|
Binding decisions / invariants:
|
||||||
|
- Host API name/domain は `https`。`web` ではない。
|
||||||
|
- HTTPS-only。`http://`、localhost、private IP、link-local、unix socket、file URL、local/private host targets は reject。
|
||||||
|
- Grant がない場合、network access 前に fail closed。
|
||||||
|
- host / method / optional path prefix などの allowlist を表現し、grant と request を照合する。
|
||||||
|
- Request/response は bounded。
|
||||||
|
- method allowlist
|
||||||
|
- request body size bound
|
||||||
|
- header count/size bound
|
||||||
|
- response body size bound
|
||||||
|
- timeout
|
||||||
|
- redirect policy
|
||||||
|
- Credentials は ambient env から読まない。header/auth は explicit config / secret ref 経由だけ。
|
||||||
|
- Diagnostics に secret-like header/token/body content を漏らさない。
|
||||||
|
- HTTPS response は hidden context injection ではなく ordinary Tool result/history path に残す。
|
||||||
|
- `fs` host API、WebSocket/SSE/timers、Service/Ingress lifecycle、Plugin package manager は non-goals。
|
||||||
|
|
||||||
|
Requirements / acceptance criteria:
|
||||||
|
- Granted Plugin Tool can perform an allowed HTTPS request through host API。
|
||||||
|
- Missing `host_api.https` grant denies before network access。
|
||||||
|
- Disallowed host / method / URL scheme denies。
|
||||||
|
- `http://`, localhost, private IP, link-local, local/private host targets reject。
|
||||||
|
- Timeout and response-size bounds are enforced。
|
||||||
|
- Request/response diagnostics are bounded and redact secret-like values。
|
||||||
|
- No ambient env credentials or ambient network APIs are exposed to WASM。
|
||||||
|
- Tool result path remains ordinary Tool result/history path。
|
||||||
|
- Tests cover allowed HTTPS, missing grant, disallowed host/method/scheme/private target, timeout, response truncation, secret redaction, no network without host API import/grant。
|
||||||
|
|
||||||
|
Implementation latitude:
|
||||||
|
- Choose exact ABI/import shape consistent with existing `yoi-plugin-wasm-1` host import design。
|
||||||
|
- Choose narrow grant config representation for host/method/path allowlist consistent with current Plugin permission grant model。
|
||||||
|
- Use local deterministic test server/mock if needed for allowed HTTPS/timeout/response bound tests, but keep network-safety tests deterministic。
|
||||||
|
- Choose bounded response header/body representation that fits existing Tool result error/result types。
|
||||||
|
|
||||||
|
Escalate if:
|
||||||
|
- Implementing HTTPS requires broad runtime executor redesign or Component Model migration first。
|
||||||
|
- Secure host/method/path grant model cannot be represented without breaking existing permission grant schema。
|
||||||
|
- SecretRef handling requires new secret-store public API beyond explicit config references。
|
||||||
|
- Safe private/local-host rejection cannot be implemented deterministically enough for tests。
|
||||||
|
- Host API result/error shape requires product-visible Tool result schema decision beyond this Ticket。
|
||||||
|
|
||||||
|
Validation:
|
||||||
|
- Focused plugin HTTPS host API tests。
|
||||||
|
- Relevant `cargo test` / `cargo check` for `pod`, `manifest`, `yoi` as changed。
|
||||||
|
- `cargo fmt --check`。
|
||||||
|
- `git diff --check`。
|
||||||
|
- `nix build .#yoi` because dependency/package/network code may change。
|
||||||
|
|
||||||
|
Critical risks / reviewer focus:
|
||||||
|
- Network access before grant/allowlist checks。
|
||||||
|
- Private/local/localhost bypass through DNS, redirects, IPv6, encoded URLs, or scheme confusion。
|
||||||
|
- Secret leakage in diagnostics or Tool result/history。
|
||||||
|
- Ambient env credential usage。
|
||||||
|
- Unbounded request/response bodies or headers。
|
||||||
|
- Hidden context injection by bypassing normal Tool result path。
|
||||||
|
- Breaking existing Plugin permission grant enforcement or CLI inspection semantics。
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- `queued -> inprogress` を記録し、Ticket records を Orchestrator worktree に commit してから、専用 implementation worktree を作成し Coder Pod を narrow write scope で起動する。root/original workspace は操作しない。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-19T14:25:28Z from: queued to: inprogress reason: orchestrator_acceptance_plugin_https_host_api field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket body/thread, relation metadata, orchestration plan records, related completed Tickets, Orchestrator worktree, visible Pods, existing branch/worktree, and bounded Plugin host API code context were checked. Depends-on blockers are closed, prior CLI inspection related work is closed, and no dirty-state blocker or missing planning decision was found. `fs` host API and Component Model migration remain queued with conflict/migration waiting records. Accepting this queued Ticket for implementation before worktree/Pod side effects.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T14:26:32Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Implementation start note:
|
||||||
|
|
||||||
|
`queued -> inprogress` acceptance、accepted plan、routing decision / IntentPacket、fs host API / Component Model migration の waiting records を記録し、Orchestrator worktree で commit した後に、専用 implementation worktree と Coder Pod を起動した。
|
||||||
|
|
||||||
|
Worktree:
|
||||||
|
- `/home/hare/Projects/yoi/.worktree/00001KVFDX9AF-plugin-https-host-api`
|
||||||
|
- branch: `impl/00001KVFDX9AF-plugin-https-host-api`
|
||||||
|
|
||||||
|
Coder Pod:
|
||||||
|
- `yoi-coder-00001KVFDX9AF`
|
||||||
|
|
||||||
|
Scope / boundaries:
|
||||||
|
- child runtime workspace root は read scope。
|
||||||
|
- implementation worktree は write scope。
|
||||||
|
- root/original workspace と Orchestrator worktree へは書き込まないよう指示済み。
|
||||||
|
- `.yoi/memory`、runtime/log/lock/local/secret-like `.yoi` paths は編集しないよう指示済み。
|
||||||
|
|
||||||
|
Related queued Tickets:
|
||||||
|
- `00001KVFDX9AY` fs host API remains queued due existing do_not_parallelize / conflict with HTTPS host API.
|
||||||
|
- `00001KVG0HR96` Component Model migration remains queued due migration boundary / conflict with active host API work.
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Coder は granted HTTPS host API implementation、focused tests、validation、implementation commit を行い、実装報告を返す予定。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T15:04:07Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Coder implementation report received / Orchestrator validation:
|
||||||
|
|
||||||
|
Implementation commit:
|
||||||
|
- `73775275` — `plugin: implement https host api`
|
||||||
|
|
||||||
|
Summary:
|
||||||
|
- Added typed HTTPS host API grant scope to Plugin permission model:
|
||||||
|
- hosts
|
||||||
|
- methods
|
||||||
|
- optional path prefixes
|
||||||
|
- bounded request/response options
|
||||||
|
- Implemented `yoi:https` WASM host import handling in the Plugin Tool runtime。
|
||||||
|
- Added deterministic local TLS / HTTPS test harness for runtime tests。
|
||||||
|
- Added URL validation / network safety checks:
|
||||||
|
- HTTPS-only;
|
||||||
|
- reject `http://`;
|
||||||
|
- reject localhost/private/link-local/local targets;
|
||||||
|
- reject disallowed hosts/methods/schemes before network access。
|
||||||
|
- Added request/response bounds and diagnostics:
|
||||||
|
- body/header limits;
|
||||||
|
- response truncation;
|
||||||
|
- timeout;
|
||||||
|
- bounded/redacted error messages。
|
||||||
|
- Preserved no ambient env credentials and ordinary Tool result/history path semantics。
|
||||||
|
- Updated read-only Plugin CLI inspection so HTTPS host API grant details / diagnostics remain inspectable。
|
||||||
|
- Updated `package.nix` cargo hash for new dependency/build closure.
|
||||||
|
|
||||||
|
Files changed:
|
||||||
|
- `Cargo.lock`
|
||||||
|
- `crates/manifest/src/plugin.rs`
|
||||||
|
- `crates/pod/Cargo.toml`
|
||||||
|
- `crates/pod/src/feature/plugin.rs`
|
||||||
|
- `crates/pod/src/pod.rs`
|
||||||
|
- `crates/yoi/src/plugin_cli.rs`
|
||||||
|
- `package.nix`
|
||||||
|
|
||||||
|
Coder reported validation:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||||
|
- `cargo test -p pod feature::plugin::tests -- --nocapture` — passed; 36 passed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed
|
||||||
|
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
- `nix build .#yoi --no-link` — passed
|
||||||
|
|
||||||
|
Orchestrator evidence checked:
|
||||||
|
- Pod output を確認。
|
||||||
|
- implementation worktree は clean。
|
||||||
|
- branch `impl/00001KVFDX9AF-plugin-https-host-api` HEAD は `73775275`。
|
||||||
|
- diff stat from accepted base `1fdef32a..73775275`: 7 files changed, 1799 insertions, 97 deletions。
|
||||||
|
|
||||||
|
Validation re-run by Orchestrator in implementation worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||||
|
- `cargo test -p pod feature::plugin::tests -- --nocapture` — passed; 36 passed, 0 failed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||||
|
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
- `nix build .#yoi --no-link` — passed
|
||||||
|
|
||||||
|
Routing classification: review_needed
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- recorded intent / invariants / acceptance criteria に照らして、read-only Reviewer Pod で外部レビューする。
|
||||||
|
- 特に grant-before-network、private/local rejection、redirect/DNS bypass、bounds/timeouts、secret redaction、ordinary Tool result path、no ambient env credentials、CLI inspection compatibility、dependency/package.nix correctness を確認する。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: plan author: yoi-orchestrator at: 2026-06-19T15:04:59Z -->
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
Review dispatch:
|
||||||
|
|
||||||
|
Reviewer Pod `yoi-reviewer-00001KVFDX9AF` を read-only scope で起動した。
|
||||||
|
|
||||||
|
Review target:
|
||||||
|
- worktree: `/home/hare/Projects/yoi/.worktree/00001KVFDX9AF-plugin-https-host-api`
|
||||||
|
- branch: `impl/00001KVFDX9AF-plugin-https-host-api`
|
||||||
|
- commit: `73775275`
|
||||||
|
|
||||||
|
Reviewer focus:
|
||||||
|
- recorded intent / invariants / acceptance criteria に対する適合性。
|
||||||
|
- network access が grant/allowlist checks の前に発生しないこと。
|
||||||
|
- private/local/localhost/link-local target rejection が DNS / IPv6 / redirect / scheme edge cases を含め妥当であること。
|
||||||
|
- timeout / request-response size / header bounds が enforce されること。
|
||||||
|
- secret-like values が errors / diagnostics / Tool results に漏れないこと。
|
||||||
|
- ambient env credential / ambient network access path が WASM に exposed されていないこと。
|
||||||
|
- HTTPS response が ordinary Tool result/history path だけに戻ること。
|
||||||
|
- allowed HTTPS / missing grant / disallowed host-method-scheme-private target / timeout / truncation / redaction / no network without grant/import tests が意味を持つこと。
|
||||||
|
- manifest/permission grant schema changes が existing grants / CLI inspection と整合していること。
|
||||||
|
- `Cargo.lock` / `package.nix` update が妥当で、`nix build .#yoi --no-link` validation と整合していること。
|
||||||
|
- `fs` host API と Component Model migration が non-goals として保たれていること。
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Reviewer output を確認し、approve なら Orchestrator worktree への merge/validation/cleanup/close-ready 処理へ進む。request_changes なら blocker を記録して Coder に戻す。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVFDX9AF at: 2026-06-19T15:10:37Z status: request_changes -->
|
||||||
|
|
||||||
|
## Review: request changes
|
||||||
|
|
||||||
|
Review result: request_changes
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVFDX9AF`
|
||||||
|
- branch: `impl/00001KVFDX9AF-plugin-https-host-api`
|
||||||
|
- commit: `7377527f` (`plugin: implement https host api`)
|
||||||
|
|
||||||
|
Blockers:
|
||||||
|
|
||||||
|
1. Private/local target rejection is bypassable with IPv4-mapped IPv6 literals.
|
||||||
|
- `validate_static_https_target` parses the URL host as `IpAddr` and delegates IPv6 literals to `is_forbidden_ipv6` (`crates/pod/src/feature/plugin.rs:622-631`, `665-669`).
|
||||||
|
- `is_forbidden_ipv6` rejects loopback/unspecified/ULA/link-local/multicast (`699-705`) but does not check `Ipv6Addr::to_ipv4_mapped()` / IPv4-compatible forms.
|
||||||
|
- Rust confirms `::ffff:127.0.0.1` is not `is_loopback()` as IPv6, while `to_ipv4_mapped()` is `Some(127.0.0.1)`.
|
||||||
|
- A granted request to `https://[::ffff:127.0.0.1]/...` would therefore pass the current private/local filter if the grant host matches, violating localhost/private IP rejection and the IPv6 edge-case reviewer focus.
|
||||||
|
|
||||||
|
2. DNS private-address validation is TOCTOU and does not bind the checked address set to the actual connection.
|
||||||
|
- `ReqwestPluginHttpsClient::execute` calls `validate_dns_target(url)` before constructing/sending the request (`crates/pod/src/feature/plugin.rs:365-405`).
|
||||||
|
- `validate_dns_target` resolves with `ToSocketAddrs` and rejects private/local addresses in that returned set (`641-655`), but `reqwest` performs its own DNS resolution later during `builder.send()` (`405`).
|
||||||
|
- DNS rebinding / split answers between the preflight lookup and reqwest’s lookup can pass validation on a public address then connect to a private/local address.
|
||||||
|
- Ticket critical risks explicitly include DNS/private/local bypasses before network access.
|
||||||
|
|
||||||
|
Requested changes:
|
||||||
|
- Reject IPv4-mapped IPv6 addresses by applying the existing IPv4 forbidden checks to mapped IPv4 addresses; add tests for mapped loopback/private/link-local examples.
|
||||||
|
- Bind DNS validation to the actual connection path. Either pin validated public `SocketAddr`s into the reqwest client/request resolver path, or otherwise ensure the actual connected remote address is validated / not private.
|
||||||
|
- Add deterministic test coverage around the real validation edge cases where feasible.
|
||||||
|
|
||||||
|
Supporting positive findings:
|
||||||
|
- Grant checks happen before request parsing/DNS/network dispatch in `execute_plugin_https_request`, and WASM import validation denies `yoi:https` imports without requested/configured `host_api.https` grant before instantiation.
|
||||||
|
- Scheme, embedded credentials, method allowlist, request descriptor/body/header count/size, response body/header bounds, timeout, no redirects, and `no_proxy()` are present.
|
||||||
|
- WASM imports are narrow (`yoi:tool`, `yoi:https` only), WASI/ambient imports are rejected, and `yoi:fs` remains explicitly unimplemented.
|
||||||
|
- Response path remains ordinary plugin Tool output/history path.
|
||||||
|
- Manifest/CLI schema additions are mostly compatible: new `PluginPermission::HostApi`, `PluginHttpsGrant`, defaulted `grants.https`, and CLI display of configured HTTPS grants.
|
||||||
|
|
||||||
|
Test gap:
|
||||||
|
- Current HTTPS-focused tests use `MockHttpsClient` for allowed/denied/timeout/truncation behavior. That is useful for grant ordering, but it does not exercise the real `ReqwestPluginHttpsClient` DNS filtering, redirect policy, TLS/HTTPS path, or actual timeout/read-limit behavior. Given the security-sensitive DNS/IP requirements, add coverage for the real validation edge cases above.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: plan author: yoi-orchestrator at: 2026-06-19T15:12:19Z -->
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
Review follow-up dispatch:
|
||||||
|
|
||||||
|
Reviewer `yoi-reviewer-00001KVFDX9AF` は `request_changes` を返したため、Ticket review として記録し、既存 Coder Pod `yoi-coder-00001KVFDX9AF` に修正依頼を送った。
|
||||||
|
|
||||||
|
Blockers:
|
||||||
|
1. IPv4-mapped IPv6 literals が private/local target rejection を bypass し得る。
|
||||||
|
- `::ffff:127.0.0.1` などを IPv6 として見るだけでは loopback/private 判定に漏れる。
|
||||||
|
- `Ipv6Addr::to_ipv4_mapped()` 等で mapped IPv4 を取り出し、既存 IPv4 forbidden checks を適用する必要がある。
|
||||||
|
|
||||||
|
2. DNS private-address validation が TOCTOU で actual connection path に bind されていない。
|
||||||
|
- preflight `ToSocketAddrs` validation 後に `reqwest` が別途 DNS resolution するため、DNS rebinding / split answers で public answer validation 後に private/local address へ接続し得る。
|
||||||
|
- validated public `SocketAddr`s を reqwest client/request resolver path に pin する、または actual connected remote address を検証する必要がある。
|
||||||
|
|
||||||
|
Required fixes sent to Coder:
|
||||||
|
- IPv4-mapped IPv6 addresses を mapped IPv4 として private/local/link-local/loopback checks に通す。
|
||||||
|
- mapped loopback/private/link-local の tests を追加する。
|
||||||
|
- DNS validation を actual connection path に bind する設計へ修正する。
|
||||||
|
- DNS / actual connection edge の deterministic test coverage を追加する。
|
||||||
|
- Prior positives を維持する: grant-before-network、WASM import grant validation、HTTPS-only、embedded credentials rejection、method allowlist、bounds、timeout、no redirects、`no_proxy()`、ordinary Tool result path、manifest/CLI schema compatibility。
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Coder の修正 commit / validation report を待つ。
|
||||||
|
- 修正後、network-safety edge cases と grant-before-network invariants を中心に再レビューする。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T15:22:56Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Coder review-fix implementation report received / Orchestrator validation:
|
||||||
|
|
||||||
|
Incremental fix commit:
|
||||||
|
- `85683f17` — `plugin: harden https target validation`
|
||||||
|
|
||||||
|
Summary:
|
||||||
|
- Hardened IPv6 target validation:
|
||||||
|
- IPv4-mapped IPv6 addresses now apply existing IPv4 private/local/link-local checks.
|
||||||
|
- IPv4-compatible embedded forms are also checked through IPv4 rules.
|
||||||
|
- Host canonicalization strips IPv6 brackets before IP parsing.
|
||||||
|
- Removed DNS validation TOCTOU gap:
|
||||||
|
- DNS resolution now produces validated public `SocketAddr`s.
|
||||||
|
- Those exact validated addresses are pinned into the `reqwest` client via `resolve_to_addrs`, so `reqwest` does not perform a separate unvalidated DNS lookup for hostname requests.
|
||||||
|
- Private DNS answers are rejected before client build / network dispatch.
|
||||||
|
- Added deterministic tests for:
|
||||||
|
- IPv4-mapped loopback/private/link-local rejection;
|
||||||
|
- IPv4-compatible private rejection;
|
||||||
|
- DNS resolution pinning to validated public socket addresses;
|
||||||
|
- private DNS answer rejection before client build.
|
||||||
|
|
||||||
|
Files changed in incremental fix:
|
||||||
|
- `crates/pod/src/feature/plugin.rs`
|
||||||
|
|
||||||
|
Coder reported validation:
|
||||||
|
- `cargo test -p pod feature::plugin::tests` — passed; 39 tests
|
||||||
|
- `cargo test -p manifest plugin` — passed; 17 tests
|
||||||
|
- `cargo test -p yoi plugin_cli` — passed; 10 tests
|
||||||
|
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
- `nix build .#yoi --no-link` — passed
|
||||||
|
|
||||||
|
Orchestrator evidence checked:
|
||||||
|
- Pod output を確認。
|
||||||
|
- implementation worktree は clean。
|
||||||
|
- branch `impl/00001KVFDX9AF-plugin-https-host-api` HEAD は `85683f17`。
|
||||||
|
- incremental diff stat from previous review target `7377527f..85683f17`: 1 file changed, 170 insertions, 21 deletions。
|
||||||
|
|
||||||
|
Validation re-run by Orchestrator in implementation worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||||
|
- `cargo test -p pod feature::plugin::tests -- --nocapture` — passed; 39 passed, 0 failed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||||
|
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
- `nix build .#yoi --no-link` — passed
|
||||||
|
|
||||||
|
Routing classification: review_needed
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- previous `request_changes` blockers が解消されたか、read-only Reviewer Pod で再レビューする。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: plan author: yoi-orchestrator at: 2026-06-19T15:23:58Z -->
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
Review re-dispatch:
|
||||||
|
|
||||||
|
Reviewer Pod `yoi-reviewer-00001KVFDX9AF-r2` を read-only scope で起動した。
|
||||||
|
|
||||||
|
Review target:
|
||||||
|
- worktree: `/home/hare/Projects/yoi/.worktree/00001KVFDX9AF-plugin-https-host-api`
|
||||||
|
- branch: `impl/00001KVFDX9AF-plugin-https-host-api`
|
||||||
|
- commits:
|
||||||
|
- `7377527f` — initial HTTPS host API implementation
|
||||||
|
- `85683f17` — target validation hardening fix
|
||||||
|
|
||||||
|
Reviewer focus:
|
||||||
|
- previous IPv4-mapped/compatible IPv6 private/local bypass blocker が解消されているか。
|
||||||
|
- DNS validation が validated address pinning により actual reqwest connection path に bind され、unvalidated resolution path が残っていないか。
|
||||||
|
- mapped IPv6 / DNS pinning / private DNS answer rejection tests が deterministic で意味を持つか。
|
||||||
|
- prior positives: grant-before-network、WASM import grant validation、HTTPS-only、embedded credentials rejection、method allowlist、bounds、timeout、no redirects、`no_proxy()`、ordinary Tool result path、manifest/CLI schema compatibility が維持されているか。
|
||||||
|
- `resolve_to_addrs` usage や host canonicalization に新しい security regression がないか。
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Reviewer output を確認し、approve なら Orchestrator worktree への merge/validation/cleanup/close-ready 処理へ進む。request_changes なら blocker を記録して Coder に戻す。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVFDX9AF-r2 at: 2026-06-19T15:29:22Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVFDX9AF`
|
||||||
|
- branch: `impl/00001KVFDX9AF-plugin-https-host-api`
|
||||||
|
- commits:
|
||||||
|
- `7377527f` — `plugin: implement https host api`
|
||||||
|
- `85683f17` — `plugin: harden https target validation`
|
||||||
|
|
||||||
|
No remaining blockers found.
|
||||||
|
|
||||||
|
Evidence reviewed:
|
||||||
|
- IPv4-mapped / compatible IPv6 bypass is closed.
|
||||||
|
- Host canonicalization strips IPv6 brackets before IP parsing via `normalize_host_literal` / `canonical_host`.
|
||||||
|
- `validate_static_https_target` parses canonical hosts as `IpAddr` and applies `validate_public_ip`.
|
||||||
|
- `is_forbidden_ipv6` delegates mapped/compatible embedded IPv4 addresses through `ipv6_embedded_ipv4`, then applies existing IPv4 private/loopback/link-local/broadcast/special checks.
|
||||||
|
- `ipv4_mapped_ipv6_targets_deny_before_network` covers `::ffff:127.0.0.1`, `::ffff:10.0.0.1`, `::ffff:169.254.169.254`, and compatible `::10.0.0.1`, with mock network call count asserted as zero.
|
||||||
|
- DNS validation is bound to the reqwest connection path.
|
||||||
|
- `ReqwestPluginHttpsClient::execute` calls `resolve_https_target_for_client` before building the client.
|
||||||
|
- Hostname URLs resolve to `SocketAddr`s, reject empty/private/local answers, and return those exact validated addresses.
|
||||||
|
- reqwest builder pins each validated domain using `resolve_to_addrs(domain, &pinned_resolution.addrs)`, with no remaining separate unvalidated DNS lookup path visible in this implementation.
|
||||||
|
- IP-literal URLs skip DNS pinning only after static IP validation.
|
||||||
|
- DNS tests are deterministic and meaningful at the unit boundary.
|
||||||
|
- `FakeHttpsResolver` avoids live DNS/network.
|
||||||
|
- `dns_resolution_is_pinned_to_validated_public_socket_addresses` verifies resolver input, returned pinned domains/addrs, and reqwest builder acceptance of `resolve_to_addrs`.
|
||||||
|
- `dns_resolution_rejects_private_addresses_before_client_build` verifies private DNS answers fail before client build/network dispatch.
|
||||||
|
- Prior positives remain preserved.
|
||||||
|
- Grant checks happen before request validation/client dispatch in `execute_plugin_https_request`.
|
||||||
|
- WASM import validation checks `yoi:https` authorization before allowing the import.
|
||||||
|
- HTTPS-only, embedded-credential rejection, host/method/path allowlist, request/header/body bounds, response truncation, timeout, no redirects, `no_proxy()`, sensitive-header rejection/redaction, and ordinary Tool result flow remain present.
|
||||||
|
- Existing tests cover missing grant before network, disallowed host/method/scheme/private targets before network, timeout/redaction, response truncation, no network without HTTPS import, and ordinary Tool result path.
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- Static diff/code review and worktree status inspection.
|
||||||
|
- Orchestrator-reported successful runs were reviewed:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `cargo check -p pod -p manifest -p yoi`
|
||||||
|
- focused pod/manifest/yoi plugin tests
|
||||||
|
- `git diff --check`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Previous request_changes blockers are resolved.
|
||||||
|
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVFDX9AF-r2 at: 2026-06-19T15:29:45Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVFDX9AF`
|
||||||
|
- branch: `impl/00001KVFDX9AF-plugin-https-host-api`
|
||||||
|
- commits:
|
||||||
|
- `7377527f` — `plugin: implement https host api`
|
||||||
|
- `85683f17` — `plugin: harden https target validation`
|
||||||
|
|
||||||
|
No remaining blockers found.
|
||||||
|
|
||||||
|
Evidence reviewed:
|
||||||
|
- IPv4-mapped / compatible IPv6 bypass is closed.
|
||||||
|
- Host canonicalization strips IPv6 brackets before IP parsing via `normalize_host_literal` / `canonical_host`.
|
||||||
|
- `validate_static_https_target` parses canonical hosts as `IpAddr` and applies `validate_public_ip`.
|
||||||
|
- `is_forbidden_ipv6` delegates mapped/compatible embedded IPv4 addresses through `ipv6_embedded_ipv4`, then applies existing IPv4 private/loopback/link-local/broadcast/special checks.
|
||||||
|
- `ipv4_mapped_ipv6_targets_deny_before_network` covers `::ffff:127.0.0.1`, `::ffff:10.0.0.1`, `::ffff:169.254.169.254`, and compatible `::10.0.0.1`, with mock network call count asserted as zero.
|
||||||
|
- DNS validation is bound to the reqwest connection path.
|
||||||
|
- `ReqwestPluginHttpsClient::execute` calls `resolve_https_target_for_client` before building the client.
|
||||||
|
- Hostname URLs resolve to `SocketAddr`s, reject empty/private/local answers, and return those exact validated addresses.
|
||||||
|
- reqwest builder pins each validated domain using `resolve_to_addrs(domain, &pinned_resolution.addrs)`, with no remaining separate unvalidated DNS lookup path visible in this implementation.
|
||||||
|
- IP-literal URLs skip DNS pinning only after static IP validation.
|
||||||
|
- DNS tests are deterministic and meaningful at the unit boundary.
|
||||||
|
- `FakeHttpsResolver` avoids live DNS/network.
|
||||||
|
- `dns_resolution_is_pinned_to_validated_public_socket_addresses` verifies resolver input, returned pinned domains/addrs, and reqwest builder acceptance of `resolve_to_addrs`.
|
||||||
|
- `dns_resolution_rejects_private_addresses_before_client_build` verifies private DNS answers fail before client build/network dispatch.
|
||||||
|
- Prior positives remain preserved.
|
||||||
|
- Grant checks happen before request validation/client dispatch in `execute_plugin_https_request`.
|
||||||
|
- WASM import validation checks `yoi:https` authorization before allowing the import.
|
||||||
|
- HTTPS-only, embedded-credential rejection, host/method/path allowlist, request/header/body bounds, response truncation, timeout, no redirects, `no_proxy()`, sensitive-header rejection/redaction, and ordinary Tool result flow remain present.
|
||||||
|
- Existing tests cover missing grant before network, disallowed host/method/scheme/private targets before network, timeout/redaction, response truncation, no network without HTTPS import, and ordinary Tool result path.
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- Static diff/code review and worktree status inspection.
|
||||||
|
- Orchestrator-reported successful runs were reviewed:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `cargo check -p pod -p manifest -p yoi`
|
||||||
|
- focused pod/manifest/yoi plugin tests
|
||||||
|
- `git diff --check`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Previous request_changes blockers are resolved.
|
||||||
|
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVFDX9AF-r2 at: 2026-06-19T15:32:15Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVFDX9AF`
|
||||||
|
- branch: `impl/00001KVFDX9AF-plugin-https-host-api`
|
||||||
|
- commits:
|
||||||
|
- `7377527f` — `plugin: implement https host api`
|
||||||
|
- `85683f17` — `plugin: harden https target validation`
|
||||||
|
|
||||||
|
No remaining blockers found.
|
||||||
|
|
||||||
|
Evidence reviewed:
|
||||||
|
- IPv4-mapped / compatible IPv6 bypass is closed.
|
||||||
|
- Host canonicalization strips IPv6 brackets before IP parsing via `normalize_host_literal` / `canonical_host`.
|
||||||
|
- `validate_static_https_target` parses canonical hosts as `IpAddr` and applies `validate_public_ip`.
|
||||||
|
- `is_forbidden_ipv6` delegates mapped/compatible embedded IPv4 addresses through `ipv6_embedded_ipv4`, then applies existing IPv4 private/loopback/link-local/broadcast/special checks.
|
||||||
|
- `ipv4_mapped_ipv6_targets_deny_before_network` covers `::ffff:127.0.0.1`, `::ffff:10.0.0.1`, `::ffff:169.254.169.254`, and compatible `::10.0.0.1`, with mock network call count asserted as zero.
|
||||||
|
- DNS validation is bound to the reqwest connection path.
|
||||||
|
- `ReqwestPluginHttpsClient::execute` calls `resolve_https_target_for_client` before building the client.
|
||||||
|
- Hostname URLs resolve to `SocketAddr`s, reject empty/private/local answers, and return those exact validated addresses.
|
||||||
|
- reqwest builder pins each validated domain using `resolve_to_addrs(domain, &pinned_resolution.addrs)`, with no remaining separate unvalidated DNS lookup path visible in this implementation.
|
||||||
|
- IP-literal URLs skip DNS pinning only after static IP validation.
|
||||||
|
- DNS tests are deterministic and meaningful at the unit boundary.
|
||||||
|
- `FakeHttpsResolver` avoids live DNS/network.
|
||||||
|
- `dns_resolution_is_pinned_to_validated_public_socket_addresses` verifies resolver input, returned pinned domains/addrs, and reqwest builder acceptance of `resolve_to_addrs`.
|
||||||
|
- `dns_resolution_rejects_private_addresses_before_client_build` verifies private DNS answers fail before client build/network dispatch.
|
||||||
|
- Prior positives remain preserved.
|
||||||
|
- Grant checks happen before request validation/client dispatch in `execute_plugin_https_request`.
|
||||||
|
- WASM import validation checks `yoi:https` authorization before allowing the import.
|
||||||
|
- HTTPS-only, embedded-credential rejection, host/method/path allowlist, request/header/body bounds, response truncation, timeout, no redirects, `no_proxy()`, sensitive-header rejection/redaction, and ordinary Tool result flow remain present.
|
||||||
|
- Existing tests cover missing grant before network, disallowed host/method/scheme/private targets before network, timeout/redaction, response truncation, no network without HTTPS import, and ordinary Tool result path.
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- Static diff/code review and worktree status inspection.
|
||||||
|
- Orchestrator-reported successful runs were reviewed:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `cargo check -p pod -p manifest -p yoi`
|
||||||
|
- focused pod/manifest/yoi plugin tests
|
||||||
|
- `git diff --check`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Previous request_changes blockers are resolved.
|
||||||
|
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T15:32:56Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Merge / validation report:
|
||||||
|
|
||||||
|
Implementation branch `impl/00001KVFDX9AF-plugin-https-host-api` は Orchestrator worktree の `orchestration` branch に merge 済み。
|
||||||
|
|
||||||
|
Merge:
|
||||||
|
- merge commit: `6beb8625` — `merge: plugin https host api`
|
||||||
|
- implementation commits:
|
||||||
|
- `7377527f` — `plugin: implement https host api`
|
||||||
|
- `85683f17` — `plugin: harden https target validation`
|
||||||
|
- changed files:
|
||||||
|
- `Cargo.lock`
|
||||||
|
- `crates/manifest/src/plugin.rs`
|
||||||
|
- `crates/pod/Cargo.toml`
|
||||||
|
- `crates/pod/src/feature/plugin.rs`
|
||||||
|
- `crates/yoi/src/plugin_cli.rs`
|
||||||
|
- `package.nix`
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree after merge:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||||
|
- `cargo test -p pod feature::plugin::tests -- --nocapture` — passed; 39 passed, 0 failed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||||
|
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
- `nix build .#yoi --no-link` — passed
|
||||||
|
|
||||||
|
Review:
|
||||||
|
- First review requested changes for IPv4-mapped IPv6 private/local bypass and DNS validation TOCTOU.
|
||||||
|
- Coder fixed target validation by applying IPv4 checks to mapped/compatible IPv6 forms and binding DNS validation to reqwest via validated address pinning.
|
||||||
|
- Re-review `yoi-reviewer-00001KVFDX9AF-r2` returned `approve` with no remaining blockers.
|
||||||
|
|
||||||
|
Outcome:
|
||||||
|
- Granted HTTPS host API is implemented for WASM Plugin Tools.
|
||||||
|
- Missing grant denies before network access.
|
||||||
|
- Host/method/path allowlist and HTTPS-only/private-local target restrictions are represented and tested.
|
||||||
|
- DNS validation is pinned to the actual reqwest connection path.
|
||||||
|
- Request/response bounds, timeout, no redirects, `no_proxy()`, secret redaction, ordinary Tool result path, and CLI inspection compatibility are present.
|
||||||
|
- `fs` host API and Component Model migration remain non-goals for this Ticket.
|
||||||
|
- Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T15:33:57Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Merge / validation report:
|
||||||
|
|
||||||
|
Implementation branch `impl/00001KVFDX9AF-plugin-https-host-api` は Orchestrator worktree の `orchestration` branch に merge 済み。
|
||||||
|
|
||||||
|
Merge:
|
||||||
|
- merge commit: `6beb8625` — `merge: plugin https host api`
|
||||||
|
- implementation commits:
|
||||||
|
- `7377527f` — `plugin: implement https host api`
|
||||||
|
- `85683f17` — `plugin: harden https target validation`
|
||||||
|
- changed files:
|
||||||
|
- `Cargo.lock`
|
||||||
|
- `crates/manifest/src/plugin.rs`
|
||||||
|
- `crates/pod/Cargo.toml`
|
||||||
|
- `crates/pod/src/feature/plugin.rs`
|
||||||
|
- `crates/yoi/src/plugin_cli.rs`
|
||||||
|
- `package.nix`
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree after merge:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||||
|
- `cargo test -p pod feature::plugin::tests -- --nocapture` — passed; 39 passed, 0 failed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||||
|
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
- `nix build .#yoi --no-link` — passed
|
||||||
|
|
||||||
|
Review:
|
||||||
|
- First review requested changes for IPv4-mapped IPv6 private/local bypass and DNS validation TOCTOU.
|
||||||
|
- Coder fixed target validation by applying IPv4 checks to mapped/compatible IPv6 forms and binding DNS validation to reqwest via validated address pinning.
|
||||||
|
- Re-review `yoi-reviewer-00001KVFDX9AF-r2` returned `approve` with no remaining blockers.
|
||||||
|
|
||||||
|
Outcome:
|
||||||
|
- Granted HTTPS host API is implemented for WASM Plugin Tools.
|
||||||
|
- Missing grant denies before network access.
|
||||||
|
- Host/method/path allowlist and HTTPS-only/private-local target restrictions are represented and tested.
|
||||||
|
- DNS validation is pinned to the actual reqwest connection path.
|
||||||
|
- Request/response bounds, timeout, no redirects, `no_proxy()`, secret redaction, ordinary Tool result path, and CLI inspection compatibility are present.
|
||||||
|
- `fs` host API and Component Model migration remain non-goals for this Ticket.
|
||||||
|
- Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T15:35:11Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Cleanup report:
|
||||||
|
|
||||||
|
Plugin HTTPS host API Ticket の implementation/review Pods と child worktree を cleanup 済み。
|
||||||
|
|
||||||
|
Stopped Pods:
|
||||||
|
- `yoi-coder-00001KVFDX9AF`
|
||||||
|
- `yoi-reviewer-00001KVFDX9AF-r2`
|
||||||
|
|
||||||
|
Removed child implementation worktree:
|
||||||
|
- `/home/hare/Projects/yoi/.worktree/00001KVFDX9AF-plugin-https-host-api`
|
||||||
|
|
||||||
|
Deleted merged implementation branch:
|
||||||
|
- `impl/00001KVFDX9AF-plugin-https-host-api` at `85683f17`
|
||||||
|
|
||||||
|
Orchestrator branch remains the integration authority for this completed work. Root/original workspace was not touched for this Ticket, per Panel Queue instruction.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-19T15:35:22Z from: inprogress to: done reason: merged_validated_review_approved field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Implementation commits `7377527f` and `85683f17` were reviewed after blocker resolution, approved, merged into the Orchestrator branch as `6beb8625`, validated in the Orchestrator worktree, and child implementation resources were cleaned up. Requirements and acceptance criteria are satisfied for this Ticket. Root/original workspace was not operated on for this Ticket per Panel Queue instruction.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-19T15:35:45Z from: done to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-19T15:35:46Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Ticket `00001KVFDX9AF` is complete.
|
||||||
|
|
||||||
|
Completed implementation:
|
||||||
|
- Added granted outbound HTTPS host API for WASM Plugin Tools.
|
||||||
|
- Added typed `host_api.https` grant scope with host, method, optional path prefix, and bounded request/response options.
|
||||||
|
- Implemented `yoi:https` WASM host import handling.
|
||||||
|
- Enforced grant/allowlist checks before network access.
|
||||||
|
- Enforced HTTPS-only behavior and rejected `http://`, embedded credentials, localhost/private/link-local/local targets, IPv4-mapped/compatible IPv6 private/local forms, and unsafe DNS results.
|
||||||
|
- Bound DNS validation to the actual reqwest connection path by pinning validated public socket addresses with `resolve_to_addrs`.
|
||||||
|
- Added request/response bounds, timeout, no redirects, `no_proxy()`, response truncation, and secret-like diagnostics redaction.
|
||||||
|
- Preserved ordinary Tool result/history path and avoided hidden context injection.
|
||||||
|
- Updated Plugin CLI inspection and manifest/permission model to expose HTTPS host API grant/diagnostic details.
|
||||||
|
|
||||||
|
Reviewed / merged:
|
||||||
|
- Implementation commits:
|
||||||
|
- `7377527f` (`plugin: implement https host api`)
|
||||||
|
- `85683f17` (`plugin: harden https target validation`)
|
||||||
|
- First review requested changes for IPv4-mapped IPv6 bypass and DNS validation TOCTOU.
|
||||||
|
- Re-review approved with no remaining blockers.
|
||||||
|
- Orchestrator merge commit: `6beb8625` (`merge: plugin https host api`)
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||||
|
- `cargo test -p pod feature::plugin::tests -- --nocapture` — passed; 39 passed, 0 failed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||||
|
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
- `nix build .#yoi --no-link` — passed
|
||||||
|
|
||||||
|
Cleanup:
|
||||||
|
- Stopped Coder Pod `yoi-coder-00001KVFDX9AF`.
|
||||||
|
- Stopped Reviewer Pod `yoi-reviewer-00001KVFDX9AF-r2`.
|
||||||
|
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KVFDX9AF-plugin-https-host-api`.
|
||||||
|
- Deleted merged branch `impl/00001KVFDX9AF-plugin-https-host-api`.
|
||||||
|
|
||||||
|
Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction. The completed work is integrated on the Orchestrator branch.
|
||||||
|
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
{"id":"orch-plan-20260619-102132-1","ticket_id":"00001KVFDX9AY","kind":"waiting_capacity_note","note":"明示 queue review で確認済み。依存 Ticket `00001KV5W3PHW` / `00001KV5W3PJ3` は closed で blocker ではないが、同時 queued の `00001KVFD3YSV` CLI inspection と `00001KVFDX9AF` https host API はいずれも Plugin manifest/grant/runtime/diagnostic 周辺を触る。まず read-only CLI inspection を開始し、host API implementation は conflict / reviewer-coder bottleneck を避けるため queued のまま待機する。次の routing pass で再確認する。","author":"yoi-orchestrator","at":"2026-06-19T10:21:32Z"}
|
||||||
|
{"id":"orch-plan-20260619-102132-2","ticket_id":"00001KVFDX9AY","kind":"do_not_parallelize","related_ticket":"00001KVFDX9AF","note":"`fs` と `https` host API はどちらも WASM Plugin Tool runtime host import boundary、Plugin grant model、diagnostics/tests/package behavior に触れるため、同時実装は conflict risk が高い。片方の merged/validated 後にもう片方を再 routing する。","author":"yoi-orchestrator","at":"2026-06-19T10:21:32Z"}
|
||||||
|
{"id":"orch-plan-20260619-142431-3","ticket_id":"00001KVFDX9AY","kind":"waiting_capacity_note","note":"`00001KVFD3YSV` Plugin CLI inspection は closed になったため再 routing した。`https` host API Ticket `00001KVFDX9AF` を先に受理する。`fs` host API は既存 do_not_parallelize record の通り WASM Plugin Tool runtime host import boundary、Plugin grant model、diagnostics/tests/package behavior が重なるため、`https` の merge/validation outcome まで queued のまま待機する。Bounded reason: conflict / reviewer-coder bottleneck。","author":"yoi-orchestrator","at":"2026-06-19T14:24:31Z"}
|
||||||
|
{"id":"orch-plan-20260619-153644-4","ticket_id":"00001KVFDX9AY","kind":"accepted_plan","accepted_plan":{"summary":"WASM Plugin Tool runtime に明示 grant された scoped filesystem `fs` host API を追加する。read/list/write initial subset、path normalization、traversal/symlink/root escape rejection、bounds、safe diagnostics、file mutation safety、no ambient workspace filesystem inheritance を満たす。","branch":"impl/00001KVFDX9AY-plugin-fs-host-api","worktree":"/home/hare/Projects/yoi/.worktree/00001KVFDX9AY-plugin-fs-host-api","role_plan":"Orchestrator は専用 implementation worktree を作成し、Coder をその worktree への narrow write scope で起動する。Reviewer は実装報告後に read-only で確認する。Component Model migration は Plugin runtime/host API/WIT migration boundary として queued hold を維持する。"},"author":"yoi-orchestrator","at":"2026-06-19T15:36:44Z"}
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
{
|
||||||
|
"version": 1,
|
||||||
|
"relations": [
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVFDX9AY",
|
||||||
|
"kind": "depends_on",
|
||||||
|
"target": "00001KV5W3PHW",
|
||||||
|
"note": "fs host API is implemented inside the WASM Plugin Tool runtime.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T07:54:32Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVFDX9AY",
|
||||||
|
"kind": "depends_on",
|
||||||
|
"target": "00001KV5W3PJ3",
|
||||||
|
"note": "fs host API must be guarded by Plugin permission grants.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T07:54:32Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVFDX9AY",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KSXRQ4G8",
|
||||||
|
"note": "Uses established Plugin host API terminology.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T07:54:32Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVFDX9AY",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KVFD3YSV",
|
||||||
|
"note": "Inspection CLI should expose fs host API grants/diagnostics.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T07:54:32Z"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,90 @@
|
|||||||
|
---
|
||||||
|
title: 'Plugin: implement fs host API for Tool runtime'
|
||||||
|
state: 'closed'
|
||||||
|
created_at: '2026-06-19T07:53:13Z'
|
||||||
|
updated_at: '2026-06-19T16:17:51Z'
|
||||||
|
assignee: null
|
||||||
|
readiness: 'implementation_ready'
|
||||||
|
risk_flags: ['plugin', 'fs', 'host-api', 'sandbox', 'path-safety', 'permission-grants', 'file-mutation']
|
||||||
|
queued_by: 'workspace-panel'
|
||||||
|
queued_at: '2026-06-19T10:19:52Z'
|
||||||
|
---
|
||||||
|
|
||||||
|
## Background
|
||||||
|
|
||||||
|
Plugin Tool runtime は minimal WASM execution と permission grants まで実装済みだが、Plugin-layer scoped filesystem access はまだ未実装である。
|
||||||
|
|
||||||
|
この Ticket では、WASM Plugin Tool から明示 grant された scoped paths のみを read/list/write できる `fs` host API を追加する。Plugin は Pod / workspace の filesystem authority を自動継承しない。Plugin-specific grant だけが有効な authority になる。
|
||||||
|
|
||||||
|
## Requirements
|
||||||
|
|
||||||
|
- WASM Plugin Tool runtime に `fs` host API import を追加する。
|
||||||
|
- API 名・ABI は既存 `yoi-plugin-wasm-1` / host import 設計と整合させる。
|
||||||
|
- Plugin は ambient filesystem access を持たず、host API 経由のみで fs operation できる。
|
||||||
|
- Plugin-layer scoped paths を grant で表現する。
|
||||||
|
- read
|
||||||
|
- list
|
||||||
|
- write の初期 subset
|
||||||
|
- optional path root / glob / prefix policy は implementation-time に最小安全形を選ぶ。
|
||||||
|
- Workspace filesystem scope を自動継承しない。
|
||||||
|
- Pod が workspace write authority を持っていても Plugin は grant なしでは読めない/書けない。
|
||||||
|
- Path safety を徹底する。
|
||||||
|
- normalization
|
||||||
|
- `..` traversal reject
|
||||||
|
- symlink/root escape reject
|
||||||
|
- absolute/relative path policy を明確化
|
||||||
|
- allowed root 外は fail closed
|
||||||
|
- Bounds を設ける。
|
||||||
|
- read size bound
|
||||||
|
- write size bound
|
||||||
|
- directory entry count bound
|
||||||
|
- path length bound
|
||||||
|
- diagnostic size bound
|
||||||
|
- Writes は既存 file mutation safety と整合させる。
|
||||||
|
- normalized target file ごとの serialization / atomic-ish behavior を検討する。
|
||||||
|
- broad Worker scheduler は追加しない。
|
||||||
|
- Diagnostics は safe にする。
|
||||||
|
- file content を error/log に漏らさない。
|
||||||
|
- rejected path は必要最小限にする。
|
||||||
|
- Tool result path は通常 Tool result/history 経路を使う。
|
||||||
|
- hidden context injection しない。
|
||||||
|
|
||||||
|
## Acceptance criteria
|
||||||
|
|
||||||
|
- Granted Plugin Tool can read an allowed file through `fs` host API.
|
||||||
|
- Granted Plugin Tool can list an allowed directory within bounds.
|
||||||
|
- Granted Plugin Tool can write an allowed file within bounds.
|
||||||
|
- Plugin without matching `host_api.fs` grant cannot read/list/write.
|
||||||
|
- Workspace write authority is not inherited by Plugin without Plugin grant.
|
||||||
|
- `../` traversal, symlink escape, and allowed-root escape are rejected.
|
||||||
|
- Oversize read/write/list results fail closed or truncate according to explicit policy.
|
||||||
|
- File mutation safety does not race unsafely with existing Write/Edit semantics.
|
||||||
|
- Diagnostics do not include file content or secret-like data.
|
||||||
|
- Tests cover:
|
||||||
|
- allowed read
|
||||||
|
- allowed list
|
||||||
|
- allowed write
|
||||||
|
- missing grant denied
|
||||||
|
- workspace authority not inherited
|
||||||
|
- path traversal rejected
|
||||||
|
- symlink/root escape rejected
|
||||||
|
- read/write/list bounds
|
||||||
|
- diagnostics redaction
|
||||||
|
- write serialization or safe conflict behavior
|
||||||
|
- Validation: focused plugin fs tests, relevant cargo check/test, `cargo fmt --check`, `git diff --check`, and `nix build .#yoi` because host API / packaging behavior may change.
|
||||||
|
|
||||||
|
## Non-goals
|
||||||
|
|
||||||
|
- `https` host API implementation.
|
||||||
|
- General workspace Read/Write tool delegation.
|
||||||
|
- Service / Ingress surface.
|
||||||
|
- File watcher / background sync.
|
||||||
|
- Broad WASI filesystem exposure.
|
||||||
|
- Plugin package manager / install/update.
|
||||||
|
|
||||||
|
## Related work
|
||||||
|
|
||||||
|
- `00001KV5W3PHW` — Plugin Tool execution with minimal WASM runtime.
|
||||||
|
- `00001KV5W3PJ3` — Plugin permission grant enforcement.
|
||||||
|
- `00001KVFD3YSV` — Plugin read-only CLI inspection list/show.
|
||||||
|
- `00001KSXRQ4G8` — Plugin runtime / surface / minimal host API model design.
|
||||||
@@ -0,0 +1,33 @@
|
|||||||
|
Ticket `00001KVFDX9AY` is complete.
|
||||||
|
|
||||||
|
Completed implementation:
|
||||||
|
- Added granted scoped filesystem `fs` host API for WASM Plugin Tools.
|
||||||
|
- Added `PluginFsGrant { root, operations }` and `PluginFsOperation::{read,list,write}` to the Plugin grant model.
|
||||||
|
- Implemented `yoi:fs` WASM host imports for read/list/write with response buffer handling.
|
||||||
|
- Enforced Plugin-specific grants before filesystem access; Plugin Tools do not inherit Pod/workspace filesystem authority.
|
||||||
|
- Added path safety for relative-only requests, traversal rejection, symlink/root escape rejection, canonical root checks, and Unix `O_NOFOLLOW` for writes.
|
||||||
|
- Added read/list/write bounds, explicit truncation/fail-closed behavior, write serialization by normalized/canonical target, and bounded/redacted diagnostics.
|
||||||
|
- Updated Plugin CLI inspection to show configured fs grants.
|
||||||
|
|
||||||
|
Reviewed / merged:
|
||||||
|
- Implementation commit: `717c0999` (`plugin: implement fs host api`)
|
||||||
|
- Reviewer result: approve, no blockers.
|
||||||
|
- Reviewer noted a non-blocking future hardening context: the current implementation is path/canonicalization based and does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is accepted within the feasible scope of the initial subset.
|
||||||
|
- Orchestrator merge commit: `c94e157b` (`merge: plugin fs host api`)
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||||
|
- `cargo test -p pod feature::plugin -- --nocapture` — passed; 48 passed, 0 failed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||||
|
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
- `nix build .#yoi --no-link` — passed
|
||||||
|
|
||||||
|
Cleanup:
|
||||||
|
- Stopped Coder Pod `yoi-coder-00001KVFDX9AY`.
|
||||||
|
- Stopped Reviewer Pod `yoi-reviewer-00001KVFDX9AY`.
|
||||||
|
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KVFDX9AY-plugin-fs-host-api`.
|
||||||
|
- Deleted merged branch `impl/00001KVFDX9AY-plugin-fs-host-api`.
|
||||||
|
|
||||||
|
Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction. The completed work is integrated on the Orchestrator branch.
|
||||||
@@ -0,0 +1,870 @@
|
|||||||
|
<!-- event: create author: "yoi ticket" at: 2026-06-19T07:53:13Z -->
|
||||||
|
|
||||||
|
## 作成
|
||||||
|
|
||||||
|
LocalTicketBackend によって作成されました。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: workspace-panel at: 2026-06-19T10:19:52Z from: ready to: queued reason: queued field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を `workspace-panel` が queued にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: plan author: yoi-orchestrator at: 2026-06-19T10:22:26Z -->
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
Routing hold / waiting-capacity note:
|
||||||
|
|
||||||
|
明示 queue review で Ticket body / relations / orchestration plan / workspace state を確認した。
|
||||||
|
|
||||||
|
Current decision:
|
||||||
|
- この Ticket は `queued` のまま待機。
|
||||||
|
- 依存 Ticket `00001KV5W3PHW` / `00001KV5W3PJ3` は closed で dependency blocker ではない。
|
||||||
|
- ただし同時 queued の `00001KVFD3YSV` CLI inspection を先に受理した。CLI inspection は Plugin discovery / enablement / grants / diagnostics の read-only public surface を作る作業で、host API implementation と同じ Plugin manifest/grant/runtime/diagnostic 周辺に触れる。
|
||||||
|
- `00001KVFDX9AF` https host API とは WASM Plugin Tool runtime host import boundary、Plugin grant model、diagnostics/tests/package behavior の変更面が重なるため `do_not_parallelize` plan record を残した。
|
||||||
|
|
||||||
|
Bounded reason for idle queued:
|
||||||
|
- conflict / reviewer-coder bottleneck。
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- `00001KVFD3YSV` の implementation/review/merge outcome を確認後、queued のまま再 routing する。
|
||||||
|
- その時点で `https` host API Ticket との ordering / conflict も再確認する。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: decision author: yoi-orchestrator at: 2026-06-19T15:37:24Z -->
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
Routing decision: implementation_ready
|
||||||
|
|
||||||
|
Reason:
|
||||||
|
- Panel Queue により、この Ticket は Orchestrator routing 対象として明示許可された。
|
||||||
|
- Ticket body には、`fs` host API intent、binding invariants、acceptance criteria、non-goals、validation、escalation-worthy risk domain が実装可能な粒度で揃っている。
|
||||||
|
- 依存 relation の `00001KV5W3PHW` minimal WASM runtime、`00001KV5W3PJ3` permission grants、関連 `00001KVFD3YSV` CLI inspection、`00001KVFDX9AF` HTTPS host API は closed で blocker ではない。
|
||||||
|
- Risk domain は filesystem / path safety / file mutation / permission grants だが、Ticket は Plugin-specific grants、no workspace authority inheritance、path normalization、traversal/symlink/root escape rejection、bounds、safe diagnostics、ordinary Tool result path を binding invariants として明示している。bounded context check 後も implementation 前に必要な追加 human decision は見つからなかった。
|
||||||
|
- `00001KVG0HR96` Component Model migration は Plugin runtime / WIT / host API shape / grants / inspection / packaging に広く触れる migration boundary で、active `fs` host API と衝突しやすいため waiting note を更新し queued のまま待機する。
|
||||||
|
|
||||||
|
Evidence checked:
|
||||||
|
- Ticket `00001KVFDX9AY` body / thread / artifacts。
|
||||||
|
- `TicketRelationQuery(00001KVFDX9AY)`: depends_on は closed。related Ticket は context であり acceptance blocker ではない。
|
||||||
|
- `TicketOrchestrationPlanQuery(00001KVFDX9AY)`: prior waiting/do_not_parallelize records を確認。HTTPS host API は closed になったため今回 `accepted_plan` を記録済み。
|
||||||
|
- Related completed Tickets:
|
||||||
|
- `00001KV5W3PHW` — minimal WASM Tool runtime closed。
|
||||||
|
- `00001KV5W3PJ3` — Plugin permission grants closed。
|
||||||
|
- `00001KVFD3YSV` — Plugin read-only CLI inspection closed。
|
||||||
|
- `00001KVFDX9AF` — Plugin HTTPS host API closed。
|
||||||
|
- Current queued Ticket `00001KVG0HR96` Component Model migration: migration boundary / conflict waiting note を更新。
|
||||||
|
- Orchestrator worktree `/home/hare/Projects/yoi/.worktree/orchestration`: clean。
|
||||||
|
- Existing branch/worktree: matching `00001KVFDX9AY` branch/worktree はなし。
|
||||||
|
- Visible Pods: self / peers only; spawned child capacity is free。
|
||||||
|
- Current code map:
|
||||||
|
- `crates/pod/src/feature/plugin.rs`: Plugin resolver, permission grants, static inspection, host API eligibility, HTTPS implementation pattern。
|
||||||
|
- `crates/pod/src/pod.rs`: WASM Tool runtime / host import validation / Tool execution path。
|
||||||
|
- `crates/manifest/src/plugin.rs`: Plugin manifest and permission model。
|
||||||
|
- `crates/yoi/src/plugin_cli.rs`: read-only inspection output should remain compatible with fs host API diagnostics。
|
||||||
|
|
||||||
|
IntentPacket:
|
||||||
|
|
||||||
|
Intent:
|
||||||
|
- WASM Plugin Tool runtime に、明示 grant された scoped path のみ read/list/write できる `fs` host API を追加する。
|
||||||
|
- Plugin は Pod/workspace filesystem authority を自動継承せず、Plugin-specific `host_api.fs` grants だけが filesystem authority になる。
|
||||||
|
|
||||||
|
Binding decisions / invariants:
|
||||||
|
- Host API name/domain は `fs`。
|
||||||
|
- Broad WASI filesystem exposure は禁止。Plugin は ambient filesystem access を持たない。
|
||||||
|
- Workspace read/write authority は Plugin に自動継承しない。
|
||||||
|
- Grant がない read/list/write は fail closed。
|
||||||
|
- Grants は operation kind (`read`, `list`, `write`) と scoped root/prefix/glob 等の最小安全形を持つ。
|
||||||
|
- Path normalization、`..` traversal rejection、symlink/root escape rejection、allowed root outside rejection は binding。
|
||||||
|
- Absolute/relative path policy は明確にし、safe default を選ぶ。
|
||||||
|
- Bounds: path length、read size、write size、directory entry count、diagnostic size。
|
||||||
|
- Writes は existing file mutation safety と整合し、normalized target file ごとに unsafe race を避ける。
|
||||||
|
- Diagnostics に file content / secret-like data を漏らさない。
|
||||||
|
- Tool result path は ordinary Tool result/history path。hidden context injection しない。
|
||||||
|
- `https` host API、Service/Ingress/File watcher/package manager は non-goals。
|
||||||
|
|
||||||
|
Requirements / acceptance criteria:
|
||||||
|
- Granted Plugin Tool can read an allowed file。
|
||||||
|
- Granted Plugin Tool can list an allowed directory within bounds。
|
||||||
|
- Granted Plugin Tool can write an allowed file within bounds。
|
||||||
|
- Plugin without matching `host_api.fs` grant cannot read/list/write。
|
||||||
|
- Workspace authority is not inherited by Plugin without Plugin grant。
|
||||||
|
- `../` traversal、symlink escape、allowed-root escape reject。
|
||||||
|
- Oversize read/write/list fail closed or truncate according to explicit policy。
|
||||||
|
- File mutation safety avoids unsafe race with existing Write/Edit semantics。
|
||||||
|
- Diagnostics do not include file content or secret-like data。
|
||||||
|
- Tests cover allowed read/list/write, missing grant denied, workspace authority not inherited, traversal/symlink/root escape, bounds, diagnostics redaction, safe write conflict behavior。
|
||||||
|
|
||||||
|
Implementation latitude:
|
||||||
|
- Choose exact ABI/import shape consistent with existing `yoi-plugin-wasm-1` host import design and current HTTPS host API pattern。
|
||||||
|
- Choose narrow grant config representation for root/prefix/glob/operation allowlist consistent with current Plugin permission grant model。
|
||||||
|
- Use tempdir/local fixture files for deterministic tests。
|
||||||
|
- Choose read/list/write response shape consistent with existing Tool result/error types and CLI inspection structure。
|
||||||
|
- If write serialization requires reusing existing file mutation primitives, keep it narrow and avoid broad Worker scheduler changes。
|
||||||
|
|
||||||
|
Escalate if:
|
||||||
|
- Safe path/symlink/root escape handling cannot be represented without broad filesystem authority redesign。
|
||||||
|
- write serialization requires broad Worker scheduler or global mutation system redesign。
|
||||||
|
- Existing Plugin grant schema cannot safely represent fs scopes without breaking HTTPS grants/CLI inspection。
|
||||||
|
- Broad WASI filesystem exposure appears necessary。
|
||||||
|
- Product decision is needed for truncate-vs-fail policy beyond Ticket’s bounded latitude。
|
||||||
|
|
||||||
|
Validation:
|
||||||
|
- Focused plugin fs host API tests。
|
||||||
|
- Relevant `cargo test` / `cargo check` for `pod`, `manifest`, `yoi` as changed。
|
||||||
|
- `cargo fmt --check`。
|
||||||
|
- `git diff --check`。
|
||||||
|
- `nix build .#yoi --no-link` / `nix build .#yoi` if dependency/package-source-filter changes occur。
|
||||||
|
|
||||||
|
Critical risks / reviewer focus:
|
||||||
|
- Workspace authority leaking into Plugin without Plugin grant。
|
||||||
|
- Path traversal / symlink / root escape bypass。
|
||||||
|
- Write race / unsafe mutation behavior。
|
||||||
|
- File content or secret leakage in diagnostics。
|
||||||
|
- Unbounded read/list/write outputs。
|
||||||
|
- Hidden context injection by bypassing normal Tool result path。
|
||||||
|
- Breaking existing HTTPS host API, permission grants, or CLI inspection semantics。
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- `queued -> inprogress` を記録し、Ticket records を Orchestrator worktree に commit してから、専用 implementation worktree を作成し Coder Pod を narrow write scope で起動する。root/original workspace は操作しない。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-19T15:37:38Z from: queued to: inprogress reason: orchestrator_acceptance_plugin_fs_host_api field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket body/thread, relation metadata, orchestration plan records, related completed Tickets, Orchestrator worktree, visible Pods, existing branch/worktree, and bounded Plugin fs host API code context were checked. Depends-on blockers are closed, HTTPS host API and CLI inspection related work are closed, and no dirty-state blocker or missing planning decision was found. Component Model migration remains queued with migration/conflict waiting record. Accepting this queued Ticket for implementation before worktree/Pod side effects.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T15:39:09Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Implementation start note:
|
||||||
|
|
||||||
|
`queued -> inprogress` acceptance、accepted plan、routing decision / IntentPacket、Component Model migration の waiting record を記録し、Orchestrator worktree で commit した後に、専用 implementation worktree と Coder Pod を起動した。
|
||||||
|
|
||||||
|
Worktree:
|
||||||
|
- `/home/hare/Projects/yoi/.worktree/00001KVFDX9AY-plugin-fs-host-api`
|
||||||
|
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||||
|
|
||||||
|
Coder Pod:
|
||||||
|
- `yoi-coder-00001KVFDX9AY`
|
||||||
|
|
||||||
|
Scope / boundaries:
|
||||||
|
- child runtime workspace root は read scope。
|
||||||
|
- implementation worktree は write scope。
|
||||||
|
- root/original workspace と Orchestrator worktree へは書き込まないよう指示済み。
|
||||||
|
- `.yoi/memory`、runtime/log/lock/local/secret-like `.yoi` paths は編集しないよう指示済み。
|
||||||
|
|
||||||
|
Related queued Ticket:
|
||||||
|
- `00001KVG0HR96` Component Model migration remains queued due migration boundary / conflict with active fs host API work.
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Coder は scoped `fs` host API implementation、focused tests、validation、implementation commit を行い、実装報告を返す予定。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T16:01:41Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Coder implementation report received / Orchestrator validation:
|
||||||
|
|
||||||
|
Implementation commit:
|
||||||
|
- `717c0999` — `plugin: implement fs host api`
|
||||||
|
|
||||||
|
Summary:
|
||||||
|
- Added manifest/config support for `host_api.fs` grants:
|
||||||
|
- `PluginFsGrant { root, operations }`
|
||||||
|
- `PluginFsOperation::{read,list,write}`
|
||||||
|
- Implemented WASM host import module `yoi:fs` with:
|
||||||
|
- `read`
|
||||||
|
- `list`
|
||||||
|
- `write`
|
||||||
|
- `response_len`
|
||||||
|
- `response_read`
|
||||||
|
- Enforced plugin-specific grant checks; Pod/workspace fs authority is not inherited.
|
||||||
|
- Added path safety:
|
||||||
|
- relative-only request paths;
|
||||||
|
- `..` traversal rejection;
|
||||||
|
- configured root must be absolute/non-symlink directory;
|
||||||
|
- symlink component/target rejection;
|
||||||
|
- canonical allowed-root escape checks.
|
||||||
|
- Added bounds:
|
||||||
|
- request descriptor size;
|
||||||
|
- path length;
|
||||||
|
- read size with explicit truncation flag;
|
||||||
|
- write size fail-closed;
|
||||||
|
- directory entry count with explicit truncation flag.
|
||||||
|
- Added write serialization by normalized target plus `O_NOFOLLOW` on Unix.
|
||||||
|
- Kept fs errors/diagnostics bounded and redacted.
|
||||||
|
- Extended Plugin CLI inspection to show configured fs grants.
|
||||||
|
|
||||||
|
Files changed:
|
||||||
|
- `crates/manifest/src/plugin.rs`
|
||||||
|
- `crates/pod/src/feature/plugin.rs`
|
||||||
|
- `crates/yoi/src/plugin_cli.rs`
|
||||||
|
|
||||||
|
Coder reported validation:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo test -p pod feature::plugin` — passed
|
||||||
|
- `cargo test -p manifest plugin` — passed
|
||||||
|
- `cargo test -p yoi plugin_cli` — passed
|
||||||
|
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
- `nix build` not run by Coder because no dependency/package-source-filter changes.
|
||||||
|
|
||||||
|
Orchestrator evidence checked:
|
||||||
|
- Pod output を確認。
|
||||||
|
- implementation worktree は clean。
|
||||||
|
- branch `impl/00001KVFDX9AY-plugin-fs-host-api` HEAD は `717c0999`。
|
||||||
|
- diff stat from accepted base `6711bcf3..717c0999`: 3 files changed, 1068 insertions, 17 deletions。
|
||||||
|
|
||||||
|
Validation re-run by Orchestrator in implementation worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||||
|
- `cargo test -p pod feature::plugin -- --nocapture` — passed; 48 passed, 0 failed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||||
|
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
- `nix build .#yoi --no-link` — passed
|
||||||
|
|
||||||
|
Routing classification: review_needed
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- recorded intent / invariants / acceptance criteria に照らして、read-only Reviewer Pod で外部レビューする。
|
||||||
|
- 特に no ambient workspace fs authority、grant-before-filesystem access、path traversal/symlink/root escape、bounds/truncation/fail-closed policy、write serialization/O_NOFOLLOW、diagnostic redaction、ordinary Tool result path、HTTPS/CLI compatibility を確認する。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: plan author: yoi-orchestrator at: 2026-06-19T16:02:39Z -->
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
Review dispatch:
|
||||||
|
|
||||||
|
Reviewer Pod `yoi-reviewer-00001KVFDX9AY` を read-only scope で起動した。
|
||||||
|
|
||||||
|
Review target:
|
||||||
|
- worktree: `/home/hare/Projects/yoi/.worktree/00001KVFDX9AY-plugin-fs-host-api`
|
||||||
|
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||||
|
- commit: `717c0999`
|
||||||
|
|
||||||
|
Reviewer focus:
|
||||||
|
- recorded intent / invariants / acceptance criteria に対する適合性。
|
||||||
|
- filesystem access が grant checks の前に発生しないこと。
|
||||||
|
- Workspace/POD filesystem authority が Plugin に自動継承されていないこと。
|
||||||
|
- traversal / symlink / root escape protections が canonicalization races を含め妥当であること。
|
||||||
|
- read/list/write bounds と truncate-vs-fail-closed policy が明確で enforce されること。
|
||||||
|
- write serialization by normalized target と `O_NOFOLLOW` が既存 file mutation safety と整合すること。portability issue がないこと。
|
||||||
|
- diagnostics に file content / secret-like data が漏れないこと。
|
||||||
|
- ordinary Tool result/history path だけに戻ること。
|
||||||
|
- tests が allowed read/list/write、missing grant、no workspace inheritance、traversal、symlink/root escape、bounds、redaction、write safety を十分に覆うこと。
|
||||||
|
- manifest/permission grant schema と CLI inspection changes が既存 HTTPS grants / Plugin inspection behavior と互換であること。
|
||||||
|
- HTTPS host API と Component Model migration が non-goals として保たれていること。
|
||||||
|
|
||||||
|
Next:
|
||||||
|
- Reviewer output を確認し、approve なら Orchestrator worktree への merge/validation/cleanup/close-ready 処理へ進む。request_changes なら blocker を記録して Coder に戻す。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:08:53Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVFDX9AY`
|
||||||
|
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||||
|
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||||
|
|
||||||
|
No blockers found.
|
||||||
|
|
||||||
|
Evidence reviewed:
|
||||||
|
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||||
|
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||||
|
- Permission/grant binding is layered correctly:
|
||||||
|
- requested `host_api.fs` permission required;
|
||||||
|
- configured grant permission required;
|
||||||
|
- usable FS scope required;
|
||||||
|
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||||
|
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||||
|
- Path safety is materially addressed:
|
||||||
|
- absolute paths, NULs, and `..` traversal rejected;
|
||||||
|
- grant root must be absolute, existing, directory, and not final symlink;
|
||||||
|
- request path components are symlink-checked;
|
||||||
|
- canonicalized targets must remain under the canonical grant root;
|
||||||
|
- write target symlinks/dirs rejected;
|
||||||
|
- Unix writes add `O_NOFOLLOW`.
|
||||||
|
- Bounds are explicit:
|
||||||
|
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||||
|
- read/list truncation is explicit via `truncated`;
|
||||||
|
- oversize write fails closed.
|
||||||
|
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||||
|
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||||
|
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||||
|
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- Static review of changed files and relevant tests.
|
||||||
|
- Confirmed worktree branch/head.
|
||||||
|
- `git diff --check 717c0999^..717c0999` — passed.
|
||||||
|
- Orchestrator-reported validation was reviewed:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `cargo check -p pod -p manifest -p yoi`
|
||||||
|
- `cargo test -p pod feature::plugin`
|
||||||
|
- `cargo test -p manifest plugin`
|
||||||
|
- `cargo test -p yoi plugin_cli`
|
||||||
|
- `git diff --check`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Non-blocking risk noted:
|
||||||
|
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the “feasible scope” of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:09:17Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVFDX9AY`
|
||||||
|
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||||
|
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||||
|
|
||||||
|
No blockers found.
|
||||||
|
|
||||||
|
Evidence reviewed:
|
||||||
|
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||||
|
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||||
|
- Permission/grant binding is layered correctly:
|
||||||
|
- requested `host_api.fs` permission required;
|
||||||
|
- configured grant permission required;
|
||||||
|
- usable FS scope required;
|
||||||
|
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||||
|
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||||
|
- Path safety is materially addressed:
|
||||||
|
- absolute paths, NULs, and `..` traversal rejected;
|
||||||
|
- grant root must be absolute, existing, directory, and not final symlink;
|
||||||
|
- request path components are symlink-checked;
|
||||||
|
- canonicalized targets must remain under the canonical grant root;
|
||||||
|
- write target symlinks/dirs rejected;
|
||||||
|
- Unix writes add `O_NOFOLLOW`.
|
||||||
|
- Bounds are explicit:
|
||||||
|
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||||
|
- read/list truncation is explicit via `truncated`;
|
||||||
|
- oversize write fails closed.
|
||||||
|
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||||
|
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||||
|
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||||
|
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- Static review of changed files and relevant tests.
|
||||||
|
- Confirmed worktree branch/head.
|
||||||
|
- `git diff --check 717c0999^..717c0999` — passed.
|
||||||
|
- Orchestrator-reported validation was reviewed:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `cargo check -p pod -p manifest -p yoi`
|
||||||
|
- `cargo test -p pod feature::plugin`
|
||||||
|
- `cargo test -p manifest plugin`
|
||||||
|
- `cargo test -p yoi plugin_cli`
|
||||||
|
- `git diff --check`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Non-blocking risk noted:
|
||||||
|
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the feasible scope of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:09:50Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVFDX9AY`
|
||||||
|
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||||
|
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||||
|
|
||||||
|
No blockers found.
|
||||||
|
|
||||||
|
Evidence reviewed:
|
||||||
|
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||||
|
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||||
|
- Permission/grant binding is layered correctly:
|
||||||
|
- requested `host_api.fs` permission required;
|
||||||
|
- configured grant permission required;
|
||||||
|
- usable FS scope required;
|
||||||
|
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||||
|
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||||
|
- Path safety is materially addressed:
|
||||||
|
- absolute paths, NULs, and `..` traversal rejected;
|
||||||
|
- grant root must be absolute, existing, directory, and not final symlink;
|
||||||
|
- request path components are symlink-checked;
|
||||||
|
- canonicalized targets must remain under the canonical grant root;
|
||||||
|
- write target symlinks/dirs rejected;
|
||||||
|
- Unix writes add `O_NOFOLLOW`.
|
||||||
|
- Bounds are explicit:
|
||||||
|
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||||
|
- read/list truncation is explicit via `truncated`;
|
||||||
|
- oversize write fails closed.
|
||||||
|
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||||
|
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||||
|
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||||
|
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- Static review of changed files and relevant tests.
|
||||||
|
- Confirmed worktree branch/head.
|
||||||
|
- `git diff --check 717c0999^..717c0999` — passed.
|
||||||
|
- Orchestrator-reported validation was reviewed:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `cargo check -p pod -p manifest -p yoi`
|
||||||
|
- `cargo test -p pod feature::plugin`
|
||||||
|
- `cargo test -p manifest plugin`
|
||||||
|
- `cargo test -p yoi plugin_cli`
|
||||||
|
- `git diff --check`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Non-blocking risk noted:
|
||||||
|
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the feasible scope of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:10:26Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVFDX9AY`
|
||||||
|
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||||
|
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||||
|
|
||||||
|
No blockers found.
|
||||||
|
|
||||||
|
Evidence reviewed:
|
||||||
|
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||||
|
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||||
|
- Permission/grant binding is layered correctly:
|
||||||
|
- requested `host_api.fs` permission required;
|
||||||
|
- configured grant permission required;
|
||||||
|
- usable FS scope required;
|
||||||
|
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||||
|
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||||
|
- Path safety is materially addressed:
|
||||||
|
- absolute paths, NULs, and `..` traversal rejected;
|
||||||
|
- grant root must be absolute, existing, directory, and not final symlink;
|
||||||
|
- request path components are symlink-checked;
|
||||||
|
- canonicalized targets must remain under the canonical grant root;
|
||||||
|
- write target symlinks/dirs rejected;
|
||||||
|
- Unix writes add `O_NOFOLLOW`.
|
||||||
|
- Bounds are explicit:
|
||||||
|
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||||
|
- read/list truncation is explicit via `truncated`;
|
||||||
|
- oversize write fails closed.
|
||||||
|
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||||
|
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||||
|
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||||
|
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- Static review of changed files and relevant tests.
|
||||||
|
- Confirmed worktree branch/head.
|
||||||
|
- `git diff --check 717c0999^..717c0999` — passed.
|
||||||
|
- Orchestrator-reported validation was reviewed:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `cargo check -p pod -p manifest -p yoi`
|
||||||
|
- `cargo test -p pod feature::plugin`
|
||||||
|
- `cargo test -p manifest plugin`
|
||||||
|
- `cargo test -p yoi plugin_cli`
|
||||||
|
- `git diff --check`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Non-blocking risk noted:
|
||||||
|
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the feasible scope of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:11:01Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVFDX9AY`
|
||||||
|
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||||
|
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||||
|
|
||||||
|
No blockers found.
|
||||||
|
|
||||||
|
Evidence reviewed:
|
||||||
|
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||||
|
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||||
|
- Permission/grant binding is layered correctly:
|
||||||
|
- requested `host_api.fs` permission required;
|
||||||
|
- configured grant permission required;
|
||||||
|
- usable FS scope required;
|
||||||
|
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||||
|
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||||
|
- Path safety is materially addressed:
|
||||||
|
- absolute paths, NULs, and `..` traversal rejected;
|
||||||
|
- grant root must be absolute, existing, directory, and not final symlink;
|
||||||
|
- request path components are symlink-checked;
|
||||||
|
- canonicalized targets must remain under the canonical grant root;
|
||||||
|
- write target symlinks/dirs rejected;
|
||||||
|
- Unix writes add `O_NOFOLLOW`.
|
||||||
|
- Bounds are explicit:
|
||||||
|
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||||
|
- read/list truncation is explicit via `truncated`;
|
||||||
|
- oversize write fails closed.
|
||||||
|
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||||
|
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||||
|
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||||
|
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- Static review of changed files and relevant tests.
|
||||||
|
- Confirmed worktree branch/head.
|
||||||
|
- `git diff --check 717c0999^..717c0999` — passed.
|
||||||
|
- Orchestrator-reported validation was reviewed:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `cargo check -p pod -p manifest -p yoi`
|
||||||
|
- `cargo test -p pod feature::plugin`
|
||||||
|
- `cargo test -p manifest plugin`
|
||||||
|
- `cargo test -p yoi plugin_cli`
|
||||||
|
- `git diff --check`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Non-blocking risk noted:
|
||||||
|
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the feasible scope of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:11:47Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVFDX9AY`
|
||||||
|
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||||
|
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||||
|
|
||||||
|
No blockers found.
|
||||||
|
|
||||||
|
Evidence reviewed:
|
||||||
|
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||||
|
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||||
|
- Permission/grant binding is layered correctly:
|
||||||
|
- requested `host_api.fs` permission required;
|
||||||
|
- configured grant permission required;
|
||||||
|
- usable FS scope required;
|
||||||
|
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||||
|
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||||
|
- Path safety is materially addressed:
|
||||||
|
- absolute paths, NULs, and `..` traversal rejected;
|
||||||
|
- grant root must be absolute, existing, directory, and not final symlink;
|
||||||
|
- request path components are symlink-checked;
|
||||||
|
- canonicalized targets must remain under the canonical grant root;
|
||||||
|
- write target symlinks/dirs rejected;
|
||||||
|
- Unix writes add `O_NOFOLLOW`.
|
||||||
|
- Bounds are explicit:
|
||||||
|
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||||
|
- read/list truncation is explicit via `truncated`;
|
||||||
|
- oversize write fails closed.
|
||||||
|
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||||
|
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||||
|
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||||
|
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- Static review of changed files and relevant tests.
|
||||||
|
- Confirmed worktree branch/head.
|
||||||
|
- `git diff --check 717c0999^..717c0999` — passed.
|
||||||
|
- Orchestrator-reported validation was reviewed:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `cargo check -p pod -p manifest -p yoi`
|
||||||
|
- `cargo test -p pod feature::plugin`
|
||||||
|
- `cargo test -p manifest plugin`
|
||||||
|
- `cargo test -p yoi plugin_cli`
|
||||||
|
- `git diff --check`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Non-blocking risk noted:
|
||||||
|
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the feasible scope of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:12:41Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVFDX9AY`
|
||||||
|
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||||
|
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||||
|
|
||||||
|
No blockers found.
|
||||||
|
|
||||||
|
Evidence reviewed:
|
||||||
|
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||||
|
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||||
|
- Permission/grant binding is layered correctly:
|
||||||
|
- requested `host_api.fs` permission required;
|
||||||
|
- configured grant permission required;
|
||||||
|
- usable FS scope required;
|
||||||
|
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||||
|
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||||
|
- Path safety is materially addressed:
|
||||||
|
- absolute paths, NULs, and `..` traversal rejected;
|
||||||
|
- grant root must be absolute, existing, directory, and not final symlink;
|
||||||
|
- request path components are symlink-checked;
|
||||||
|
- canonicalized targets must remain under the canonical grant root;
|
||||||
|
- write target symlinks/dirs rejected;
|
||||||
|
- Unix writes add `O_NOFOLLOW`.
|
||||||
|
- Bounds are explicit:
|
||||||
|
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||||
|
- read/list truncation is explicit via `truncated`;
|
||||||
|
- oversize write fails closed.
|
||||||
|
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||||
|
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||||
|
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||||
|
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- Static review of changed files and relevant tests.
|
||||||
|
- Confirmed worktree branch/head.
|
||||||
|
- `git diff --check 717c0999^..717c0999` — passed.
|
||||||
|
- Orchestrator-reported validation was reviewed:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `cargo check -p pod -p manifest -p yoi`
|
||||||
|
- `cargo test -p pod feature::plugin`
|
||||||
|
- `cargo test -p manifest plugin`
|
||||||
|
- `cargo test -p yoi plugin_cli`
|
||||||
|
- `git diff --check`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Non-blocking risk noted:
|
||||||
|
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the feasible scope of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T16:14:42Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Merge / validation report:
|
||||||
|
|
||||||
|
Implementation branch `impl/00001KVFDX9AY-plugin-fs-host-api` を Orchestrator worktree の `orchestration` branch に merge 済み。
|
||||||
|
|
||||||
|
Merge:
|
||||||
|
- merge commit: `c94e157b` — `merge: plugin fs host api`
|
||||||
|
- implementation commit:
|
||||||
|
- `717c0999` — `plugin: implement fs host api`
|
||||||
|
- changed files:
|
||||||
|
- `crates/manifest/src/plugin.rs`
|
||||||
|
- `crates/pod/src/feature/plugin.rs`
|
||||||
|
- `crates/yoi/src/plugin_cli.rs`
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree after merge:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||||
|
- `cargo test -p pod feature::plugin -- --nocapture` — passed; 48 passed, 0 failed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||||
|
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
- `nix build .#yoi --no-link` — passed
|
||||||
|
|
||||||
|
Review:
|
||||||
|
- Reviewer `yoi-reviewer-00001KVFDX9AY` returned `approve` with no blockers.
|
||||||
|
- Reviewer noted a non-blocking future hardening context: this implementation is path/canonicalization based and does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is accepted within the feasible scope of the initial subset.
|
||||||
|
|
||||||
|
Outcome:
|
||||||
|
- Granted scoped filesystem `fs` host API is implemented for WASM Plugin Tools.
|
||||||
|
- Missing `host_api.fs` grant denies before filesystem access.
|
||||||
|
- Workspace/POD filesystem authority is not inherited by Plugin without Plugin grant.
|
||||||
|
- Path traversal / symlink / root escape protections, read/list/write bounds, write serialization, diagnostics redaction, ordinary Tool result path, and CLI inspection compatibility are present.
|
||||||
|
- HTTPS host API and Component Model migration remain non-goals for this Ticket.
|
||||||
|
- Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:15:17Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Review result: approve
|
||||||
|
|
||||||
|
対象:
|
||||||
|
- Ticket: `00001KVFDX9AY`
|
||||||
|
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||||
|
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||||
|
|
||||||
|
No blockers found.
|
||||||
|
|
||||||
|
Evidence reviewed:
|
||||||
|
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||||
|
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||||
|
- Permission/grant binding is layered correctly:
|
||||||
|
- requested `host_api.fs` permission required;
|
||||||
|
- configured grant permission required;
|
||||||
|
- usable FS scope required;
|
||||||
|
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||||
|
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||||
|
- Path safety is materially addressed:
|
||||||
|
- absolute paths, NULs, and `..` traversal rejected;
|
||||||
|
- grant root must be absolute, existing, directory, and not final symlink;
|
||||||
|
- request path components are symlink-checked;
|
||||||
|
- canonicalized targets must remain under the canonical grant root;
|
||||||
|
- write target symlinks/dirs rejected;
|
||||||
|
- Unix writes add `O_NOFOLLOW`.
|
||||||
|
- Bounds are explicit:
|
||||||
|
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||||
|
- read/list truncation is explicit via `truncated`;
|
||||||
|
- oversize write fails closed.
|
||||||
|
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||||
|
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||||
|
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||||
|
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- Static review of changed files and relevant tests.
|
||||||
|
- Confirmed worktree branch/head.
|
||||||
|
- `git diff --check 717c0999^..717c0999` — passed.
|
||||||
|
- Orchestrator-reported validation was reviewed:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `cargo check -p pod -p manifest -p yoi`
|
||||||
|
- `cargo test -p pod feature::plugin`
|
||||||
|
- `cargo test -p manifest plugin`
|
||||||
|
- `cargo test -p yoi plugin_cli`
|
||||||
|
- `git diff --check`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Non-blocking risk noted:
|
||||||
|
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the feasible scope of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||||
|
|
||||||
|
Conclusion:
|
||||||
|
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T16:16:56Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Cleanup report:
|
||||||
|
|
||||||
|
Plugin FS host API Ticket の implementation/review Pods と child worktree を cleanup した。
|
||||||
|
|
||||||
|
Stopped Pods:
|
||||||
|
- `yoi-coder-00001KVFDX9AY`
|
||||||
|
- `yoi-reviewer-00001KVFDX9AY`
|
||||||
|
|
||||||
|
Removed child implementation worktree:
|
||||||
|
- `/home/hare/Projects/yoi/.worktree/00001KVFDX9AY-plugin-fs-host-api`
|
||||||
|
|
||||||
|
Deleted merged implementation branch:
|
||||||
|
- `impl/00001KVFDX9AY-plugin-fs-host-api` at `717c0999`
|
||||||
|
|
||||||
|
Orchestrator branch remains the integration authority for this completed work. Root/original workspace was not touched for this Ticket, per Panel Queue instruction.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-19T16:17:29Z from: inprogress to: done reason: merged_validated_review_approved field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Implementation commit `717c0999` was reviewed and approved, merged into the Orchestrator branch as `c94e157b`, validated in the Orchestrator worktree, and child implementation resources were cleaned up. Requirements and acceptance criteria are satisfied for this Ticket. Root/original workspace was not operated on for this Ticket per Panel Queue instruction.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-19T16:17:51Z from: done to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-19T16:17:51Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
Ticket `00001KVFDX9AY` is complete.
|
||||||
|
|
||||||
|
Completed implementation:
|
||||||
|
- Added granted scoped filesystem `fs` host API for WASM Plugin Tools.
|
||||||
|
- Added `PluginFsGrant { root, operations }` and `PluginFsOperation::{read,list,write}` to the Plugin grant model.
|
||||||
|
- Implemented `yoi:fs` WASM host imports for read/list/write with response buffer handling.
|
||||||
|
- Enforced Plugin-specific grants before filesystem access; Plugin Tools do not inherit Pod/workspace filesystem authority.
|
||||||
|
- Added path safety for relative-only requests, traversal rejection, symlink/root escape rejection, canonical root checks, and Unix `O_NOFOLLOW` for writes.
|
||||||
|
- Added read/list/write bounds, explicit truncation/fail-closed behavior, write serialization by normalized/canonical target, and bounded/redacted diagnostics.
|
||||||
|
- Updated Plugin CLI inspection to show configured fs grants.
|
||||||
|
|
||||||
|
Reviewed / merged:
|
||||||
|
- Implementation commit: `717c0999` (`plugin: implement fs host api`)
|
||||||
|
- Reviewer result: approve, no blockers.
|
||||||
|
- Reviewer noted a non-blocking future hardening context: the current implementation is path/canonicalization based and does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is accepted within the feasible scope of the initial subset.
|
||||||
|
- Orchestrator merge commit: `c94e157b` (`merge: plugin fs host api`)
|
||||||
|
|
||||||
|
Validation in Orchestrator worktree:
|
||||||
|
- `cargo fmt --check` — passed
|
||||||
|
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||||
|
- `cargo test -p pod feature::plugin -- --nocapture` — passed; 48 passed, 0 failed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||||
|
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||||
|
- `git diff --check` — passed
|
||||||
|
- `nix build .#yoi --no-link` — passed
|
||||||
|
|
||||||
|
Cleanup:
|
||||||
|
- Stopped Coder Pod `yoi-coder-00001KVFDX9AY`.
|
||||||
|
- Stopped Reviewer Pod `yoi-reviewer-00001KVFDX9AY`.
|
||||||
|
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KVFDX9AY-plugin-fs-host-api`.
|
||||||
|
- Deleted merged branch `impl/00001KVFDX9AY-plugin-fs-host-api`.
|
||||||
|
|
||||||
|
Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction. The completed work is integrated on the Orchestrator branch.
|
||||||
|
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
{"id":"orch-plan-20260619-133549-1","ticket_id":"00001KVG0HR96","kind":"waiting_capacity_note","note":"明示 queue review で Ticket body / relations / orchestration plan / workspace state を確認した。依存 Ticket `00001KV5W3PHW` / `00001KV5W3PJ3` は closed で blocker ではないが、現在 `00001KVFD3YSV` Plugin CLI inspection が inprogress/review-needed で、さらに `00001KVFDX9AF` / `00001KVFDX9AY` host API Tickets も queued hold 中。Component Model runtime migration は Plugin runtime backend / manifest runtime metadata / WIT / grants / inspection / packaging に広く触れる migration boundary で、current CLI inspection outcome と host API ordering に強く依存・競合するため、現時点では queued のまま待機する。`00001KVFD3YSV` の merge/close 後に再 routing する。","author":"yoi-orchestrator","at":"2026-06-19T13:35:49Z"}
|
||||||
|
{"id":"orch-plan-20260619-142431-2","ticket_id":"00001KVG0HR96","kind":"waiting_capacity_note","note":"`00001KVFD3YSV` Plugin CLI inspection は closed になったため再 routing した。Component Model runtime migration は Plugin runtime backend / WIT / host API shape / grants / inspection / packaging に広く触れる migration boundary で、queued host API Tickets と衝突しやすい。まず `00001KVFDX9AF` https host API を受理し、`fs` host API と Component Model migration はその outcome 後に再 routing する。Bounded reason: migration boundary / conflict。","author":"yoi-orchestrator","at":"2026-06-19T14:24:31Z"}
|
||||||
|
{"id":"orch-plan-20260619-153644-3","ticket_id":"00001KVG0HR96","kind":"waiting_capacity_note","note":"`00001KVFDX9AF` HTTPS host API は closed になったため再 routing した。次は `00001KVFDX9AY` fs host API を受理する。Component Model runtime migration は Plugin runtime backend / WIT / host API shape / grants / inspection / packaging に広く触れる migration boundary で、active fs host API と衝突しやすいため queued のまま待機する。Bounded reason: migration boundary / conflict。","author":"yoi-orchestrator","at":"2026-06-19T15:36:44Z"}
|
||||||
|
{"id":"orch-plan-20260619-162050-4","ticket_id":"00001KVG0HR96","kind":"accepted_plan","accepted_plan":{"summary":"WASM Plugin Tool runtime を現行 core-module host imports (`yoi-plugin-wasm-1`) から WebAssembly Component Model / WIT-first runtime へ移行する。Typed host API surface、permission/grant enforcement、ordinary Tool result path、HTTPS/FS安全性、CLI inspection、tests/package validation を保つ。","branch":"impl/00001KVG0HR96-plugin-component-model-runtime","worktree":"/home/hare/Projects/yoi/.worktree/00001KVG0HR96-plugin-component-model-runtime","role_plan":"Orchestrator は専用 implementation worktree を作成し、Coder をその worktree への narrow write scope で起動する。Reviewer は実装報告後に read-only で確認する。Plugin CLI / HTTPS / FS host API は closed になったため、Component Model migration を単独で受理する。"},"author":"yoi-orchestrator","at":"2026-06-19T16:20:50Z"}
|
||||||
@@ -0,0 +1,53 @@
|
|||||||
|
{
|
||||||
|
"version": 1,
|
||||||
|
"relations": [
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVG0HR96",
|
||||||
|
"kind": "depends_on",
|
||||||
|
"target": "00001KV5W3PHW",
|
||||||
|
"note": "Component Model runtime migrates the existing raw WASM Tool runtime.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T13:21:01Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVG0HR96",
|
||||||
|
"kind": "depends_on",
|
||||||
|
"target": "00001KV5W3PJ3",
|
||||||
|
"note": "Component runtime must preserve Plugin permission grant enforcement.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T13:21:01Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVG0HR96",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KSXRQ4G8",
|
||||||
|
"note": "Updates Plugin runtime/surface/host API design direction toward Component Model.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T13:21:01Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVG0HR96",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KVFD3YSV",
|
||||||
|
"note": "Inspection CLI should report component runtime metadata without execution.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T13:21:01Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVG0HR96",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KVFDX9AF",
|
||||||
|
"note": "https host API should be designed in WIT-compatible typed terms.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T13:21:01Z"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"ticket_id": "00001KVG0HR96",
|
||||||
|
"kind": "related",
|
||||||
|
"target": "00001KVFDX9AY",
|
||||||
|
"note": "fs host API should be designed in WIT-compatible typed terms.",
|
||||||
|
"author": "yoi ticket",
|
||||||
|
"at": "2026-06-19T13:21:01Z"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,115 @@
|
|||||||
|
---
|
||||||
|
title: 'Plugin: migrate WASM Tool runtime to WebAssembly Component Model'
|
||||||
|
state: 'closed'
|
||||||
|
created_at: '2026-06-19T13:18:58Z'
|
||||||
|
updated_at: '2026-06-19T17:23:31Z'
|
||||||
|
assignee: null
|
||||||
|
readiness: 'implementation_ready'
|
||||||
|
risk_flags: ['plugin', 'wasm', 'component-model', 'wit', 'runtime-backend', 'sandbox', 'packaging', 'sdk']
|
||||||
|
queued_by: 'workspace-panel'
|
||||||
|
queued_at: '2026-06-19T13:34:43Z'
|
||||||
|
---
|
||||||
|
|
||||||
|
## Background
|
||||||
|
|
||||||
|
Yoi's current Plugin Tool runtime uses a raw core-Wasm ABI (`yoi-plugin-wasm-1`) with `yoi_tool_call`, exported `memory`, and host imports for input/output pointer-length plumbing. That was a good MVP for a small sandboxed runtime, but it should not become the long-term authoring interface.
|
||||||
|
|
||||||
|
Common Wasm extension systems usually provide a typed SDK/PDK, manifest, capability grants, templates, and inspection tooling. The WebAssembly Component Model provides a standard way to describe typed imports/exports via WIT and canonical ABI. Adopting it early prevents `https`, `fs`, SDK, and future Service/Ingress APIs from entrenching a Yoi-specific raw ABI.
|
||||||
|
|
||||||
|
This Ticket implements an explicit Component Model runtime path for Plugin Tool packages while preserving the existing package discovery, enablement, digest pinning, ToolRegistry, ordinary Tool history, and Plugin grant enforcement boundaries.
|
||||||
|
|
||||||
|
Research and direction are persisted in:
|
||||||
|
|
||||||
|
- `.yoi/objectives/00001KVG0HR9M/item.md` — Plugin Component Model migration Objective.
|
||||||
|
- `docs/design/plugin-component-model.md` — design research and policy.
|
||||||
|
- `docs/design/plugin-packages.md` — package runtime metadata direction.
|
||||||
|
|
||||||
|
## Requirements
|
||||||
|
|
||||||
|
- Add an explicit Component Model runtime kind for Plugin packages.
|
||||||
|
- Example manifest shape:
|
||||||
|
|
||||||
|
```toml
|
||||||
|
[runtime]
|
||||||
|
kind = "wasm-component"
|
||||||
|
component = "plugin.component.wasm"
|
||||||
|
world = "yoi:plugin/tool@1.0.0"
|
||||||
|
```
|
||||||
|
|
||||||
|
- Do not silently reinterpret existing raw core-Wasm packages.
|
||||||
|
- Current raw runtime remains explicit, e.g. `kind = "wasm"`, `abi = "yoi-plugin-wasm-1"`.
|
||||||
|
- Component runtime selection is driven by package manifest/runtime metadata.
|
||||||
|
- Define WIT package/worlds for the Plugin Tool runtime.
|
||||||
|
- Tool request / response / structured error types.
|
||||||
|
- Tool name and JSON input/output representation, or a better typed equivalent if decided during implementation.
|
||||||
|
- Initial host API interfaces should be WIT-compatible even if some APIs remain unimplemented.
|
||||||
|
- Add a host runtime backend capable of loading and invoking Component Model Plugin Tools.
|
||||||
|
- Evaluate whether this uses `wasmtime::component`, adapter tooling, or another backend.
|
||||||
|
- Keep runtime selected per package; discovery/inspection must not execute Plugin code.
|
||||||
|
- Preserve existing Plugin authority boundaries.
|
||||||
|
- Package discovery is read-only.
|
||||||
|
- Explicit enablement is required.
|
||||||
|
- Plugin grants are checked before Tool registration/execution and before host API calls.
|
||||||
|
- WIT imports are not authority by themselves.
|
||||||
|
- No ambient WASI filesystem/network/env is exposed.
|
||||||
|
- Preserve ordinary Tool behavior.
|
||||||
|
- Component Tool registration goes through existing ToolRegistry/model-visible schema path.
|
||||||
|
- Tool calls/results use ordinary Worker/Tool history path.
|
||||||
|
- No hidden context injection.
|
||||||
|
- Provide at least one sample Component Model Tool Plugin.
|
||||||
|
- Prefer Rust authoring path if feasible.
|
||||||
|
- Plugin author source should not contain raw pointer/length ABI plumbing.
|
||||||
|
- Add or update tests for both positive and negative paths.
|
||||||
|
- Component package discovery and manifest parsing.
|
||||||
|
- Component Tool registration.
|
||||||
|
- Component Tool execution.
|
||||||
|
- Grant denial before execution / host API access.
|
||||||
|
- Wrong world / missing export / incompatible component rejected.
|
||||||
|
- Existing raw core-Wasm Plugin runtime either still passes or has a recorded compatibility decision.
|
||||||
|
- Measure packaging/runtime impact.
|
||||||
|
- Binary size/build time impact if adding Wasmtime/component tooling.
|
||||||
|
- Nix packaging changes and `cargoHash` if dependencies change.
|
||||||
|
|
||||||
|
## Acceptance criteria
|
||||||
|
|
||||||
|
- A package with `runtime.kind = "wasm-component"` and the expected WIT world can be discovered, enabled, registered as a Tool, and executed.
|
||||||
|
- A sample Component Model Tool Plugin returns a normal Tool result through the ordinary Tool path.
|
||||||
|
- Plugin author code for the sample uses generated/SDK bindings rather than raw pointer/length imports/exports.
|
||||||
|
- Component Tool execution is denied without matching Plugin grants.
|
||||||
|
- Component host imports cannot bypass Yoi's Plugin grant model.
|
||||||
|
- Unsupported / wrong WIT world or missing required export fails closed with bounded diagnostic.
|
||||||
|
- Existing raw core-Wasm runtime remains explicitly supported or a migration/deprecation decision is recorded and tests are updated accordingly.
|
||||||
|
- `yoi plugin list/show` inspection path, if available, reports Component runtime metadata without executing the component.
|
||||||
|
- Documentation is updated with authoring/runtime instructions and migration notes.
|
||||||
|
- Validation includes relevant focused tests, `cargo fmt --check`, `git diff --check`, `cargo check` / `cargo test`, and `nix build .#yoi`.
|
||||||
|
|
||||||
|
## Non-goals
|
||||||
|
|
||||||
|
- Service surface implementation.
|
||||||
|
- Ingress surface implementation.
|
||||||
|
- WebSocket / Discord Gateway bridge.
|
||||||
|
- Inbound HTTP server.
|
||||||
|
- Replacing Plugin grants with WIT imports.
|
||||||
|
- Exposing WASI filesystem/network/env as ambient authority.
|
||||||
|
- MCP integration or MCP trust policy changes.
|
||||||
|
- A full public package registry or signature/trust-chain system.
|
||||||
|
|
||||||
|
## Implementation notes
|
||||||
|
|
||||||
|
- Keep raw core-Wasm ABI compatibility separate from Component Model support.
|
||||||
|
- Prefer WIT names that can version cleanly, such as `yoi:plugin/tool@1.0.0` and `yoi:host/https@1.0.0`.
|
||||||
|
- If Wasmtime is introduced, update Nix packaging and record dependency/build-size impact.
|
||||||
|
- If a staged approach is necessary, first land WIT definitions and manifest parsing, then runtime execution in a follow-up. Do not pretend manifest parsing alone completes this Ticket.
|
||||||
|
- `https` and `fs` host API work should avoid long-term raw ABI coupling; component-compatible request/response/path/error records are preferred.
|
||||||
|
|
||||||
|
## Related work
|
||||||
|
|
||||||
|
- `00001KVG0HR9M` — Objective: Plugin Component Model migration.
|
||||||
|
- `docs/design/plugin-component-model.md` — design research and migration direction.
|
||||||
|
- `docs/design/plugin-packages.md` — package runtime metadata direction.
|
||||||
|
- `00001KV5W3PHW` — Plugin Tool execution with minimal WASM runtime.
|
||||||
|
- `00001KV5W3PJ3` — Plugin permission grant enforcement.
|
||||||
|
- `00001KVFDX9AF` — Plugin https host API.
|
||||||
|
- `00001KVFDX9AY` — Plugin fs host API.
|
||||||
|
- `00001KVFD3YSV` — Plugin read-only CLI inspection list/show.
|
||||||
|
- `00001KSXRQ4G8` — Plugin runtime / surface / minimal host API model design.
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
## Resolution
|
||||||
|
|
||||||
|
`00001KVG0HR96` を完了しました。
|
||||||
|
|
||||||
|
実装内容:
|
||||||
|
- Plugin manifest/runtime metadata に明示的な Component Model runtime (`kind = "wasm-component"`) を追加しました。
|
||||||
|
- 既存 raw core-Wasm runtime (`kind = "wasm"`, `abi = "yoi-plugin-wasm-1"`) は明示的に維持しました。
|
||||||
|
- `wasmtime::component` による Component Tool execution path を追加しました。
|
||||||
|
- Component Tool は既存 ToolRegistry / Worker Tool path を通って実行され、hidden context injection はありません。
|
||||||
|
- WIT host imports は権限そのものではなく、Plugin grants が Tool execution / host API use の authority boundary のままです。
|
||||||
|
- Component runtime に raw runtime 相当の Wasmtime resource limits を追加し、memory/table/instance/output bound の negative tests を追加しました。
|
||||||
|
- WASI fs/network/env は expose していません。
|
||||||
|
- `yoi plugin list/show` static inspection は Component runtime metadata を報告し、component artifact を実行しません。
|
||||||
|
- WIT files、Component sample authoring sketch、docs/design updates、package/Nix updates を追加しました。
|
||||||
|
- JSON-string WIT v1 request/response shape は migration bridge として docs に記録し、structured records は follow-up に deferred としました。
|
||||||
|
|
||||||
|
主な commit:
|
||||||
|
- `57bbf14e plugin: implement component model runtime`
|
||||||
|
- `a705bb3b plugin: bound component model runtime resources`
|
||||||
|
- `63d7ad78 merge: plugin component model runtime`
|
||||||
|
|
||||||
|
Review:
|
||||||
|
- r1 は Component runtime resource limit 不足で `request_changes`。
|
||||||
|
- Coder が resource limiter / negative tests / docs note を追加。
|
||||||
|
- r2 は `approve`。
|
||||||
|
|
||||||
|
最終 validation:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `git diff --check HEAD^1..HEAD`
|
||||||
|
- `cargo check`
|
||||||
|
- `cargo test -p pod feature::plugin::tests -- --nocapture`
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture`
|
||||||
|
- `cargo test -p yoi plugin -- --nocapture`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Package impact:
|
||||||
|
- `nix path-info -S .#yoi`: `112156120`
|
||||||
|
- `bin/yoi`: `54605944`
|
||||||
|
- output dir: `53M`
|
||||||
|
|
||||||
|
Validation log:
|
||||||
|
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-rZDseu.log`
|
||||||
@@ -0,0 +1,464 @@
|
|||||||
|
<!-- event: create author: "yoi ticket" at: 2026-06-19T13:18:58Z -->
|
||||||
|
|
||||||
|
## 作成
|
||||||
|
|
||||||
|
LocalTicketBackend によって作成されました。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: workspace-panel at: 2026-06-19T13:34:43Z from: ready to: queued reason: queued field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を `workspace-panel` が queued にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: decision author: yoi-orchestrator at: 2026-06-19T16:21:31Z -->
|
||||||
|
|
||||||
|
## Decision
|
||||||
|
|
||||||
|
Routing decision: implementation_ready
|
||||||
|
|
||||||
|
Reason:
|
||||||
|
- Panel Queue により、この Ticket は Orchestrator routing 対象として明示許可された。
|
||||||
|
- Ticket body には、Component Model runtime path の intent、requirements、acceptance criteria、non-goals、implementation notes、validation が実装可能な粒度で揃っている。
|
||||||
|
- depends_on の `00001KV5W3PHW` minimal WASM runtime と `00001KV5W3PJ3` permission grant enforcement は closed。
|
||||||
|
- Related/context work はすべて完了または non-blocking context として確認した。
|
||||||
|
- `00001KVFD3YSV` Plugin CLI inspection: closed。
|
||||||
|
- `00001KVFDX9AF` HTTPS host API: closed。
|
||||||
|
- `00001KVFDX9AY` FS host API: closed。
|
||||||
|
- `00001KSXRQ4G8` is planning design context, not blocking relation authority。
|
||||||
|
- Prior waiting-capacity notes の blocker は解消した。現在 inprogress Ticket は 0 件、child implementation Pod はなし、matching branch/worktree はなし、Orchestrator worktree は clean。
|
||||||
|
- Risk domain は component-model / WIT / runtime-backend / sandbox / packaging / SDK だが、Ticket は existing raw core-Wasm packages を silently reinterpret しない、grants before Tool registration/execution/host API access、no ambient WASI fs/network/env、ordinary Tool history path、runtime kind selected by manifest metadata などの invariants を明示している。bounded context check 後も implementation 前に必要な追加 human decision は見つからなかった。
|
||||||
|
|
||||||
|
Evidence checked:
|
||||||
|
- Ticket `00001KVG0HR96` body / thread / artifacts。
|
||||||
|
- `TicketRelationQuery(00001KVG0HR96)`: depends_on blockers は closed。related records は context link。
|
||||||
|
- `TicketOrchestrationPlanQuery(00001KVG0HR96)`: previous waiting notes were based on active CLI/HTTPS/FS work; all are now closed. 今回 `accepted_plan` を記録済み。
|
||||||
|
- Current workspace state:
|
||||||
|
- Orchestrator worktree clean。
|
||||||
|
- queued: this Ticket only。
|
||||||
|
- inprogress: 0。
|
||||||
|
- visible Pods: self + peers only; spawned children 0。
|
||||||
|
- Code/docs context:
|
||||||
|
- `crates/manifest/src/plugin.rs`: current runtime metadata and `yoi-plugin-wasm-1` validation。
|
||||||
|
- `crates/pod/src/feature/plugin.rs`: current core-Wasm Plugin runtime, Tool registration/static inspection, HTTPS/FS host APIs, import validation。
|
||||||
|
- `crates/yoi/src/plugin_cli.rs`: inspection output should report Component runtime metadata without execution。
|
||||||
|
- Ticket body references `docs/design/plugin-component-model.md`, `docs/design/plugin-packages.md`, and Objective `00001KVG0HR9M` as design context.
|
||||||
|
|
||||||
|
IntentPacket:
|
||||||
|
|
||||||
|
Intent:
|
||||||
|
- Add explicit WebAssembly Component Model runtime support for Plugin Tool packages while preserving existing Plugin discovery, enablement, digest pinning, ToolRegistry integration, ordinary Tool history, and Plugin grant enforcement.
|
||||||
|
- Move Plugin authoring/runtime path toward WIT/canonical ABI so future `https`, `fs`, SDK, Service/Ingress APIs do not entrench the raw pointer/length core-Wasm ABI.
|
||||||
|
|
||||||
|
Binding decisions / invariants:
|
||||||
|
- Existing raw core-Wasm packages must not be silently reinterpreted as components。
|
||||||
|
- Runtime selection is manifest-driven. Component packages use explicit runtime metadata such as `kind = "wasm-component"`, component artifact path, and expected world。
|
||||||
|
- Existing raw runtime remains explicit (`kind = "wasm"`, `abi = "yoi-plugin-wasm-1"`) unless a migration/deprecation decision is recorded in this Ticket with tests updated accordingly。
|
||||||
|
- Package discovery and inspection remain read-only and must not execute components。
|
||||||
|
- Explicit enablement and digest/version/source pinning remain authoritative。
|
||||||
|
- Plugin grants are checked before Tool registration/execution and before host API calls。
|
||||||
|
- WIT imports are not authority by themselves。
|
||||||
|
- No ambient WASI filesystem/network/env is exposed。
|
||||||
|
- Component Tool registration still goes through existing ToolRegistry / model-visible schema path。
|
||||||
|
- Tool calls/results use ordinary Worker/Tool history path; no hidden context injection。
|
||||||
|
- HTTPS/FS host API security boundaries already implemented must be preserved。
|
||||||
|
|
||||||
|
Requirements / acceptance criteria:
|
||||||
|
- A package with `runtime.kind = "wasm-component"` and expected WIT world can be discovered, enabled, registered as a Tool, and executed。
|
||||||
|
- Sample Component Model Tool Plugin returns a normal Tool result through ordinary Tool path。
|
||||||
|
- Sample Plugin author source uses generated/SDK bindings rather than raw pointer/length imports/exports。
|
||||||
|
- Component Tool execution is denied without matching Plugin grants。
|
||||||
|
- Component host imports cannot bypass Plugin grant model。
|
||||||
|
- Wrong world / missing export / incompatible component fails closed with bounded diagnostic。
|
||||||
|
- Existing raw core-Wasm runtime remains explicitly supported, or a migration/deprecation decision is recorded and tests updated。
|
||||||
|
- `yoi plugin list/show` reports Component runtime metadata without executing components。
|
||||||
|
- Documentation is updated with authoring/runtime instructions and migration notes。
|
||||||
|
- Build/package impact is measured and Nix packaging/cargo hash updated if dependencies change。
|
||||||
|
|
||||||
|
Implementation latitude:
|
||||||
|
- Use `wasmtime::component` / WIT tooling or another narrow backend consistent with the codebase。
|
||||||
|
- Choose WIT names that version cleanly, e.g. `yoi:plugin/tool@1.0.0` and `yoi:host/https@1.0.0` / `yoi:host/fs@1.0.0`。
|
||||||
|
- If a staged approach is unavoidable, escalate before narrowing completion. Do not land manifest parsing alone as if it completes this Ticket。
|
||||||
|
- Keep compatibility layer and Component runtime dispatch cleanly separated。
|
||||||
|
- Use focused sample fixtures/tests rather than broad E2E process spawning。
|
||||||
|
|
||||||
|
Escalate if:
|
||||||
|
- Component runtime execution cannot be implemented without a broad architecture redesign。
|
||||||
|
- Dependency/build-size impact is large enough to need product decision。
|
||||||
|
- WIT/tool request-response typing requires a product/API decision beyond Ticket latitude。
|
||||||
|
- Preserving both raw core-Wasm and Component runtime would substantially distort implementation。
|
||||||
|
- SDK/sample generation requires external toolchain not feasible in repository validation。
|
||||||
|
|
||||||
|
Validation:
|
||||||
|
- Focused Component Plugin manifest/discovery/static inspection tests。
|
||||||
|
- Component Tool registration and execution tests。
|
||||||
|
- Grant denial before Component Tool execution / host API access。
|
||||||
|
- Wrong world / missing export / incompatible component fail-closed tests。
|
||||||
|
- Existing raw core-Wasm Plugin runtime tests remain passing or migration decision/tests updated。
|
||||||
|
- `cargo fmt --check`。
|
||||||
|
- `git diff --check`。
|
||||||
|
- relevant `cargo check` / `cargo test`。
|
||||||
|
- `nix build .#yoi` because component runtime dependencies / packaging are likely to change。
|
||||||
|
|
||||||
|
Critical risks / reviewer focus:
|
||||||
|
- WIT imports becoming implicit authority。
|
||||||
|
- Component runtime bypassing existing Plugin grant enforcement。
|
||||||
|
- Ambient WASI fs/network/env exposure。
|
||||||
|
- Component execution bypassing ordinary Tool result/history path。
|
||||||
|
- Breaking existing raw core-Wasm package behavior without explicit decision/tests。
|
||||||
|
- Inspection accidentally executing components。
|
||||||
|
- Unbounded or secret-leaking diagnostics。
|
||||||
|
- Packaging/Nix/Cargo dependency correctness and binary/build-time impact。
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- `queued -> inprogress` を記録し、Ticket records を Orchestrator worktree に commit してから、専用 implementation worktree を作成し Coder Pod を narrow write scope で起動する。root/original workspace は操作しない。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-19T16:21:50Z from: queued to: inprogress reason: orchestrator_acceptance_plugin_component_model_runtime field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket body/thread, relation metadata, orchestration plan records, related completed Tickets, Orchestrator worktree, visible Pods, existing branch/worktree, and bounded Component Model runtime code context were checked. Depends-on blockers are closed, Plugin CLI / HTTPS / FS related work are closed, and no dirty-state blocker or missing planning decision was found. Accepting this queued Ticket for implementation before worktree/Pod side effects.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T16:25:23Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Implementation orchestration start:
|
||||||
|
- Acceptance records were committed on Orchestrator branch: `878517dc ticket: accept plugin component model runtime`.
|
||||||
|
- Created implementation worktree `/home/hare/Projects/yoi/.worktree/00001KVG0HR96-plugin-component-model-runtime` on branch `impl/00001KVG0HR96-plugin-component-model-runtime` at `878517dc`.
|
||||||
|
- Initial `SpawnPod` attempt with only the implementation worktree as readable scope failed because the spawned runtime workspace identity is `/home/hare/Projects/yoi` and that root was not readable under the child scope. No child Pod remained registered.
|
||||||
|
- Retried with read-only scope for `/home/hare/Projects/yoi` plus write scope limited to the implementation worktree. Coder Pod `yoi-coder-00001KVG0HR96` started successfully. The task explicitly instructs the Coder to edit/build/commit only in the implementation worktree and not to operate in the root/original workspace.
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- Wait for Coder implementation report, then inspect branch diff/validation evidence and route to Reviewer.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T17:00:21Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Coder implementation report received from `yoi-coder-00001KVG0HR96`.
|
||||||
|
|
||||||
|
Implementation commit:
|
||||||
|
- `57bbf14e plugin: implement component model runtime`
|
||||||
|
|
||||||
|
Changed areas reported:
|
||||||
|
- Manifest/runtime metadata: added explicit `kind = "wasm-component"` support with `component` artifact path and `world = "yoi:plugin/tool@1.0.0"`; preserved raw core-Wasm as `kind = "wasm"` + `abi = "yoi-plugin-wasm-1"`; reject mixed raw/component runtime metadata.
|
||||||
|
- Plugin runtime: added `wasmtime::component` path; Component Tools execute through existing ToolRegistry / Worker Tool path; component imports are fail-closed; grants are checked before instantiation/import use and on host API calls; no WASI fs/network/env exposed.
|
||||||
|
- Static inspection: reports `wasm-component/yoi:plugin/tool@1.0.0` without reading/executing the artifact.
|
||||||
|
- Tests: component discovery/registration/execution, host-import grant denial, wrong-world, missing-export, raw-core-Wasm-not-component fail-closed, and existing raw runtime coverage.
|
||||||
|
- Docs / authoring: updated design/package docs, added WIT files under `resources/plugin/wit/`, and sample author source under `docs/examples/plugin-component-tool/lib.rs`.
|
||||||
|
- Packaging: added `wasmtime = 45.0.2` with narrow non-default features; updated `Cargo.lock` and `package.nix` `cargoHash`.
|
||||||
|
|
||||||
|
Coder validation reported as passing:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `git diff --check`
|
||||||
|
- `cargo check`
|
||||||
|
- `cargo test -p pod feature::plugin::tests -- --nocapture` (`55 passed`)
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` (`17 passed`)
|
||||||
|
- `cargo test -p yoi plugin -- --nocapture` (`11 passed`)
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Orchestrator evidence checked before review dispatch:
|
||||||
|
- Implementation worktree is clean on `impl/00001KVG0HR96-plugin-component-model-runtime`.
|
||||||
|
- Merge-base with `orchestration` is `878517dc`; Orchestrator branch head is `02006fee`.
|
||||||
|
- Diff from acceptance is one implementation commit, `57bbf14e`, touching 10 files: `Cargo.lock`, manifest Plugin parser, pod Plugin runtime, `crates/pod/Cargo.toml`, docs, `package.nix`, and WIT/sample files.
|
||||||
|
- `git diff --check 878517dc..HEAD` produced no diagnostics.
|
||||||
|
- Diff size is material: about 1568 insertions / 68 deletions; dependency impact note is reviewer focus.
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- Dispatch Reviewer for r1 review against Ticket requirements, with focus on Component Model authority boundaries, grant enforcement, no ambient WASI, raw runtime compatibility, inspection not executing code, diagnostics, tests, and packaging/Nix impact.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: plan author: yoi-orchestrator at: 2026-06-19T17:00:57Z -->
|
||||||
|
|
||||||
|
## Plan
|
||||||
|
|
||||||
|
Review dispatch:
|
||||||
|
- Spawned Reviewer Pod `yoi-reviewer-00001KVG0HR96-r1` against implementation branch `impl/00001KVG0HR96-plugin-component-model-runtime`.
|
||||||
|
- Review target commit: `57bbf14e plugin: implement component model runtime`.
|
||||||
|
- Review baseline: `878517dc`.
|
||||||
|
- Reviewer task focuses on Component/WIT authority boundaries, Plugin grant enforcement, no ambient WASI, raw runtime compatibility, inspection read-only behavior, fail-closed diagnostics, HTTPS/FS invariant preservation, dependency/package impact, and validation evidence.
|
||||||
|
- Reviewer is instructed not to edit source, commit, merge, close the Ticket, or use TicketReview directly; it will report verdict/evidence back to Orchestrator.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVG0HR96-r1 at: 2026-06-19T17:08:18Z status: request_changes -->
|
||||||
|
|
||||||
|
## Review: request changes
|
||||||
|
|
||||||
|
Verdict: `request_changes`
|
||||||
|
|
||||||
|
確認範囲:
|
||||||
|
- Ticket contract: `.yoi/tickets/00001KVG0HR96/item.md`, `.yoi/tickets/00001KVG0HR96/thread.md`
|
||||||
|
- Diff: `878517dc..57bbf14e`
|
||||||
|
- 主な対象: `crates/manifest/src/plugin.rs`, `crates/pod/src/feature/plugin.rs`, `crates/pod/Cargo.toml`, `Cargo.lock`, `package.nix`, `resources/plugin/wit/*`, docs/sample, existing `crates/yoi/src/plugin_cli.rs` static inspection path。
|
||||||
|
|
||||||
|
良い点:
|
||||||
|
- 明示的な `wasm-component` metadata、raw `wasm` ABI との分離、artifact を実行しない static inspection、ToolRegistry 経由の registration/execution、Tool execution/host API 前の grant check、WASI imports を link しない方針は概ね Ticket intent に沿っている。
|
||||||
|
|
||||||
|
Blocking issue:
|
||||||
|
1. Component runtime が既存 WASM sandbox/resource boundary を保持していない。
|
||||||
|
- Raw core-Wasm path は `StoreLimitsBuilder` / `memory_size(PLUGIN_WASM_MEMORY_BYTES)` / table/instance/memory limits / `store.limiter(...)` を使っている。
|
||||||
|
- 新しい Component Model path (`crates/pod/src/feature/plugin.rs:1965-2006`) は `consume_fuel(true)` と `max_wasm_stack(...)` は設定しているが、component execution store に同等の `Store::limiter(...)` / resource limit がない。
|
||||||
|
- また component result は `String` として host 側に lift された後で `decode_plugin_wasm_output(output.as_bytes())` による output cap を適用しており、untrusted component が output cap 前に host allocation を強制できる。
|
||||||
|
- これは Ticket/design の「Component Model support must preserve existing Plugin authority/sandbox boundaries」に反する。component memory/table/instance/output bounds のテストも不足している。
|
||||||
|
|
||||||
|
Required fix:
|
||||||
|
- Component execution store に raw runtime と同等の Wasmtime resource limiter / memory/table/instance limits を入れる。
|
||||||
|
- Component output/string lifting が unbounded host allocation にならないよう、少なくとも component memory/resource limit により bounded で fail-closed になることを実装・コメント・テストで示す。
|
||||||
|
- Component memory/resource/output bound の negative tests を追加する。
|
||||||
|
|
||||||
|
Non-blocking concerns / follow-ups:
|
||||||
|
- WIT は現在 `call(tool-name: string, input-json: string) -> string`。Ticket の “Tool request / response / structured error types” は完全には表現していない。今回 v1 の narrow ABI として意図的に deferred なら decision/follow-up として記録すること。
|
||||||
|
- Rust sample は `wit_bindgen` authoring sketch であり、build/package された sample plugin を test しているわけではない。follow-up として packaged sample があるとよい。
|
||||||
|
- `nix build` / `cargoHash` は検証されているが、binary size/build-time impact measurement がまだ明示記録されていない。最終 closure 前に capture すること。
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- `git diff --check 878517dc..57bbf14e`: passed
|
||||||
|
- `cargo fmt --check`: passed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture`: 17 passed
|
||||||
|
- `cargo test -p pod feature::plugin::tests -- --nocapture`: 55 passed
|
||||||
|
- `cargo test -p yoi plugin -- --nocapture`: 11 passed
|
||||||
|
- `cargo check`: passed
|
||||||
|
- `nix build .#yoi --no-link`: passed
|
||||||
|
- `nix path-info .#yoi`: `/nix/store/m5gsv05lfs7s9bh8dfy4ady6sda925fv-yoi-0.1.0`
|
||||||
|
|
||||||
|
Worktree status at review end: clean。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T17:17:08Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Coder r1-fix report received from `yoi-coder-00001KVG0HR96`.
|
||||||
|
|
||||||
|
New fix commit:
|
||||||
|
- `a705bb3b plugin: bound component model runtime resources`
|
||||||
|
|
||||||
|
Branch commits now:
|
||||||
|
- `a705bb3b plugin: bound component model runtime resources`
|
||||||
|
- `57bbf14e plugin: implement component model runtime`
|
||||||
|
|
||||||
|
Fix summary:
|
||||||
|
- Added `wasmtime::StoreLimits` to Component Model host state.
|
||||||
|
- Applied raw-runtime-equivalent limits to component execution store:
|
||||||
|
- `memory_size(PLUGIN_WASM_MEMORY_BYTES)`
|
||||||
|
- `table_elements(PLUGIN_WASM_TABLE_ELEMENTS)`
|
||||||
|
- `instances(1)`
|
||||||
|
- `tables(1)`
|
||||||
|
- `memories(1)`
|
||||||
|
- `trap_on_grow_failure(true)`
|
||||||
|
- Added inline comment near WIT string lift explaining that host allocation before `decode_plugin_wasm_output` is bounded by component memory/table/instance limits.
|
||||||
|
- Added negative tests:
|
||||||
|
- component oversized memory fails closed before string lift
|
||||||
|
- component oversized table fails closed
|
||||||
|
- component output cap still fails closed after bounded lift
|
||||||
|
- Added docs note that JSON-string WIT v1 request/response is deliberate migration bridge and structured WIT records are deferred.
|
||||||
|
|
||||||
|
Coder validation reported as passing:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `git diff --check`
|
||||||
|
- `cargo check`
|
||||||
|
- `cargo test -p pod feature::plugin::tests -- --nocapture` (`58 passed`)
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture` (`17 passed`)
|
||||||
|
- `cargo test -p yoi plugin -- --nocapture` (`11 passed`)
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Package / binary impact measurement reported:
|
||||||
|
- `nix path-info -S .#yoi`: `/nix/store/g9nhx3g2xsn7r3rw6n61scdkha5s7m8s-yoi-0.1.0 112156120`
|
||||||
|
- `stat -c '%s %n' "$out/bin/yoi"`: `54605944 .../bin/yoi`
|
||||||
|
- `du -sh "$out"`: `53M`
|
||||||
|
|
||||||
|
Orchestrator evidence checked before re-review:
|
||||||
|
- Implementation worktree is clean.
|
||||||
|
- HEAD is `a705bb3b`.
|
||||||
|
- Fix diff from `57bbf14e..HEAD` touches `crates/pod/src/feature/plugin.rs` and `docs/design/plugin-component-model.md`, 108 insertions.
|
||||||
|
- Overall `git diff --check 878517dc..HEAD` produced no diagnostics.
|
||||||
|
|
||||||
|
Next action:
|
||||||
|
- Route back to Reviewer for r2 verification of the resource-boundary blocker and final acceptance criteria.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: review author: yoi-reviewer-00001KVG0HR96-r1 at: 2026-06-19T17:19:55Z status: approve -->
|
||||||
|
|
||||||
|
## Review: approve
|
||||||
|
|
||||||
|
Verdict: `approve`
|
||||||
|
|
||||||
|
確認範囲:
|
||||||
|
- Ticket contract: `.yoi/tickets/00001KVG0HR96/item.md`, `.yoi/tickets/00001KVG0HR96/thread.md`
|
||||||
|
- r1 blocker fix diff: `57bbf14e..a705bb3b`
|
||||||
|
- 全体実装: `878517dc..a705bb3b`
|
||||||
|
- 主な対象: Plugin runtime / manifest / WIT / docs / tests / Cargo/Nix/package impact paths。
|
||||||
|
|
||||||
|
Previous blocker verification:
|
||||||
|
- Component runtime now has raw-runtime-equivalent Wasmtime store limits:
|
||||||
|
- `crates/pod/src/feature/plugin.rs:1514-1523`
|
||||||
|
- `memory_size(PLUGIN_WASM_MEMORY_BYTES)`
|
||||||
|
- `table_elements(PLUGIN_WASM_TABLE_ELEMENTS)`
|
||||||
|
- `instances(1)`
|
||||||
|
- `tables(1)`
|
||||||
|
- `memories(1)`
|
||||||
|
- `trap_on_grow_failure(true)`
|
||||||
|
- Component host state carries those limits:
|
||||||
|
- `crates/pod/src/feature/plugin.rs:1926-1930`
|
||||||
|
- Component store installs the limiter before instantiation/execution:
|
||||||
|
- `crates/pod/src/feature/plugin.rs:1991-2001`
|
||||||
|
- Code documents why WIT string lifting remains bounded before ToolOutput JSON cap enforcement:
|
||||||
|
- `crates/pod/src/feature/plugin.rs:2017-2026`
|
||||||
|
- Focused negative tests were added and passed:
|
||||||
|
- component memory limit fails closed before string lift
|
||||||
|
- component table limit fails closed
|
||||||
|
- component output cap still fails closed after bounded lift
|
||||||
|
|
||||||
|
Overall Ticket satisfaction:
|
||||||
|
- Runtime kind is explicit and manifest-driven: raw `kind = "wasm"` + `abi = "yoi-plugin-wasm-1"`; component `kind = "wasm-component"` + `component` + expected `world`。
|
||||||
|
- Component execution stays on existing Plugin Tool / ToolRegistry path。
|
||||||
|
- Plugin grants remain authority boundary before Tool execution and host API use。
|
||||||
|
- Component imports are validated; unsupported imports fail closed。
|
||||||
|
- No WASI fs/network/env is linked。
|
||||||
|
- Static inspection reports runtime metadata without executing component artifacts。
|
||||||
|
- Existing raw runtime tests continue passing。
|
||||||
|
- Docs record JSON-string WIT v1 as deliberate migration bridge and defer structured WIT records:
|
||||||
|
- `docs/design/plugin-component-model.md:169-177`
|
||||||
|
|
||||||
|
Blocking issues: none。
|
||||||
|
|
||||||
|
Non-blocking follow-ups:
|
||||||
|
- Structured WIT request/response/error records are intentionally deferred。
|
||||||
|
- Sample remains an authoring sketch rather than fully built packaged sample, but runtime behavior is covered by focused component fixtures/tests。
|
||||||
|
|
||||||
|
Reviewer validation:
|
||||||
|
- `git diff --check 878517dc..a705bb3b`: passed
|
||||||
|
- `cargo fmt --check`: passed
|
||||||
|
- `cargo test -p pod feature::plugin::tests -- --nocapture`: 58 passed
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture`: 17 passed
|
||||||
|
- `cargo test -p yoi plugin -- --nocapture`: 11 passed
|
||||||
|
- `cargo check`: passed
|
||||||
|
- `nix build .#yoi --no-link`: passed
|
||||||
|
- `nix path-info -S .#yoi`: `/nix/store/g9nhx3g2xsn7r3rw6n61scdkha5s7m8s-yoi-0.1.0 112156120`
|
||||||
|
- `stat -c '%s %n' "$out/bin/yoi"`: `54605944 .../bin/yoi`
|
||||||
|
- `du -sh "$out"`: `53M`
|
||||||
|
|
||||||
|
Worktree status at review end: clean。
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T17:23:09Z -->
|
||||||
|
|
||||||
|
## Implementation report
|
||||||
|
|
||||||
|
Merge and final validation report:
|
||||||
|
|
||||||
|
Merged implementation branch into Orchestrator branch:
|
||||||
|
- Merge commit: `63d7ad78 merge: plugin component model runtime`
|
||||||
|
- Implementation commits included:
|
||||||
|
- `57bbf14e plugin: implement component model runtime`
|
||||||
|
- `a705bb3b plugin: bound component model runtime resources`
|
||||||
|
|
||||||
|
Reviewer outcome:
|
||||||
|
- r1 requested changes for missing Component Model resource limiter.
|
||||||
|
- Coder added raw-runtime-equivalent Wasmtime `StoreLimits` for Component execution and negative tests.
|
||||||
|
- r2 approved with no blocking issues.
|
||||||
|
|
||||||
|
Orchestrator validation after merge passed:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `git diff --check HEAD^1..HEAD`
|
||||||
|
- `cargo check`
|
||||||
|
- `cargo test -p pod feature::plugin::tests -- --nocapture`
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture`
|
||||||
|
- `cargo test -p yoi plugin -- --nocapture`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Validation log:
|
||||||
|
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-rZDseu.log`
|
||||||
|
|
||||||
|
Package impact recorded by Coder/Reviewer:
|
||||||
|
- `nix path-info -S .#yoi`: `112156120`
|
||||||
|
- `bin/yoi` size: `54605944`
|
||||||
|
- output dir: `53M`
|
||||||
|
|
||||||
|
Final state:
|
||||||
|
- Orchestrator worktree clean at `63d7ad78` after validation.
|
||||||
|
- Implementation worktree remains available for cleanup after Ticket completion records are committed.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-19T17:23:13Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Implementation was merged into Orchestrator branch at `63d7ad78`, r2 review approved, and final Orchestrator validation passed: `cargo fmt --check`, `git diff --check HEAD^1..HEAD`, `cargo check`, focused Plugin tests for `pod`/`manifest`/`yoi`, and `nix build .#yoi --no-link`.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: state_changed author: hare at: 2026-06-19T17:23:31Z from: done to: closed reason: closed field: state -->
|
||||||
|
|
||||||
|
## State changed
|
||||||
|
|
||||||
|
Ticket を closed にしました。
|
||||||
|
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
|
<!-- event: close author: hare at: 2026-06-19T17:23:31Z status: closed -->
|
||||||
|
|
||||||
|
## 完了
|
||||||
|
|
||||||
|
## Resolution
|
||||||
|
|
||||||
|
`00001KVG0HR96` を完了しました。
|
||||||
|
|
||||||
|
実装内容:
|
||||||
|
- Plugin manifest/runtime metadata に明示的な Component Model runtime (`kind = "wasm-component"`) を追加しました。
|
||||||
|
- 既存 raw core-Wasm runtime (`kind = "wasm"`, `abi = "yoi-plugin-wasm-1"`) は明示的に維持しました。
|
||||||
|
- `wasmtime::component` による Component Tool execution path を追加しました。
|
||||||
|
- Component Tool は既存 ToolRegistry / Worker Tool path を通って実行され、hidden context injection はありません。
|
||||||
|
- WIT host imports は権限そのものではなく、Plugin grants が Tool execution / host API use の authority boundary のままです。
|
||||||
|
- Component runtime に raw runtime 相当の Wasmtime resource limits を追加し、memory/table/instance/output bound の negative tests を追加しました。
|
||||||
|
- WASI fs/network/env は expose していません。
|
||||||
|
- `yoi plugin list/show` static inspection は Component runtime metadata を報告し、component artifact を実行しません。
|
||||||
|
- WIT files、Component sample authoring sketch、docs/design updates、package/Nix updates を追加しました。
|
||||||
|
- JSON-string WIT v1 request/response shape は migration bridge として docs に記録し、structured records は follow-up に deferred としました。
|
||||||
|
|
||||||
|
主な commit:
|
||||||
|
- `57bbf14e plugin: implement component model runtime`
|
||||||
|
- `a705bb3b plugin: bound component model runtime resources`
|
||||||
|
- `63d7ad78 merge: plugin component model runtime`
|
||||||
|
|
||||||
|
Review:
|
||||||
|
- r1 は Component runtime resource limit 不足で `request_changes`。
|
||||||
|
- Coder が resource limiter / negative tests / docs note を追加。
|
||||||
|
- r2 は `approve`。
|
||||||
|
|
||||||
|
最終 validation:
|
||||||
|
- `cargo fmt --check`
|
||||||
|
- `git diff --check HEAD^1..HEAD`
|
||||||
|
- `cargo check`
|
||||||
|
- `cargo test -p pod feature::plugin::tests -- --nocapture`
|
||||||
|
- `cargo test -p manifest plugin -- --nocapture`
|
||||||
|
- `cargo test -p yoi plugin -- --nocapture`
|
||||||
|
- `nix build .#yoi --no-link`
|
||||||
|
|
||||||
|
Package impact:
|
||||||
|
- `nix path-info -S .#yoi`: `112156120`
|
||||||
|
- `bin/yoi`: `54605944`
|
||||||
|
- output dir: `53M`
|
||||||
|
|
||||||
|
Validation log:
|
||||||
|
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-rZDseu.log`
|
||||||
|
|
||||||
|
---
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
{"id":"orch-plan-20260620-045332-1","ticket_id":"00001KVHKWNQA","kind":"accepted_plan","accepted_plan":{"summary":"Component Model Tool authoring用の first-party Rust PDK crate と embedded `rust-component-tool` template を追加する。PDK は guest-side only とし、raw pointer/length ABI を隠し、typed JSON helper / ToolError / ToolContext / WIT binding glue を提供する。crates.io 公開・remote template fetch・authoring CLI implementation は含めない。","branch":"impl/00001KVHKWNQA-plugin-rust-pdk-templates","worktree":"/home/hare/Projects/yoi/.worktree/00001KVHKWNQA-plugin-rust-pdk-templates","role_plan":"Orchestrator は queued acceptance を記録・commit 後、専用 implementation worktree を `.worktree/00001KVHKWNQA-plugin-rust-pdk-templates` に作成し、Coder をその child worktree への narrow write scope で起動する。Coder 実装後、Reviewer が PDK guest-only boundary、Component Model runtime compatibility、template/resource packaging、docs/tests/Nix impact を確認する。"},"author":"yoi-orchestrator","at":"2026-06-20T04:53:32Z"}
|
||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user