Compare commits
622
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
159704dc6f | ||
|
|
6492f10f42 | ||
|
|
a525ba4d01 | ||
|
|
c261aea021 | ||
|
|
8d4fee231b | ||
|
|
307d38453f | ||
|
|
d2a8a79ac6 | ||
|
|
6c8998878d | ||
|
|
41283c8dd9 | ||
|
|
fa29cc2c95 | ||
|
|
7a4fd97526 | ||
|
|
103077dfae | ||
|
|
cd2006305e | ||
|
|
a453c6e2da | ||
|
|
16247ce7c5 | ||
|
|
b9e786e106 | ||
|
|
ccd4d83d43 | ||
|
|
3a9ac1b1b7 | ||
|
|
f2c51ffe39 | ||
|
|
ef17955369 | ||
|
|
62e467c035 | ||
|
|
4950749c5d | ||
|
|
dc2f8b409d | ||
|
|
d2aa92a729 | ||
|
|
86017a5abc | ||
|
|
799998639a | ||
|
|
755d460f0d | ||
|
|
07f9793bc6 | ||
|
|
89a40db79e | ||
|
|
84a8423611 | ||
|
|
8e79c1dc96 | ||
|
|
000afbbe19 | ||
|
|
db1a2f567b | ||
|
|
bdd05dce4d | ||
|
|
4e138b7e36 | ||
|
|
1839acb3d0 | ||
|
|
f26c7e0d09 | ||
|
|
437ef5b56b | ||
|
|
7d64b443f2 | ||
|
|
449745ee24 | ||
|
|
e66efc746f | ||
|
|
436bcc812d | ||
|
|
6086099fe4 | ||
|
|
390f468471 | ||
|
|
ef1d8d9af2 | ||
|
|
ceb7b95096 | ||
|
|
237c985f2c | ||
|
|
66c5be16f8 | ||
|
|
bedbb670e4 | ||
|
|
0591fd528c | ||
|
|
19ff3724ed | ||
|
|
741d71327a | ||
|
|
27117f3246 | ||
|
|
1b5a39dbc9 | ||
|
|
f65f0e3b8f | ||
|
|
e2df9f9493 | ||
|
|
959b497135 | ||
|
|
ef08b873ce | ||
|
|
2f975808bb | ||
|
|
273f10e954 | ||
|
|
f349738257 | ||
|
|
577bf75051 | ||
|
|
79df31ccf6 | ||
|
|
72812878c0 | ||
|
|
cea115ecd9 | ||
|
|
4c3b15d8d6 | ||
|
|
45d21ac032 | ||
|
|
4e713fce19 | ||
|
|
428b7d0fef | ||
|
|
5ddc8dceac | ||
|
|
f901b9bee3 | ||
|
|
2f9604a12f | ||
|
|
893122781d | ||
|
|
f367d73231 | ||
|
|
5fa480904d | ||
|
|
0618de21eb | ||
|
|
d5012d3e16 | ||
|
|
28d53aadf2 | ||
|
|
4fb75ec324 | ||
|
|
091ee764a4 | ||
|
|
439f967cb8 | ||
|
|
80d6861aba | ||
|
|
d2ec533585 | ||
|
|
b52b7c963c | ||
|
|
89910a1a29 | ||
|
|
7ee2b78bbb | ||
|
|
0b2ce6ca1f | ||
|
|
bca8ba6ed9 | ||
|
|
5c9331e848 | ||
|
|
bb6bc9f6a1 | ||
|
|
845817d3bf | ||
|
|
1d98921a45 | ||
|
|
7ede927d5a | ||
|
|
6081448a7e | ||
|
|
70162d5001 | ||
|
|
b975812c18 | ||
|
|
1251c0ca70 | ||
|
|
dd40c41f45 | ||
|
|
428d255b27 | ||
|
|
38d25582b2 | ||
|
|
cdc0a5da33 | ||
|
|
c96cc49d0a | ||
|
|
9bd1550715 | ||
|
|
81fa035a1c | ||
|
|
371fd7c6e5 | ||
|
|
d231f41300 | ||
|
|
97555bb5a1 | ||
|
|
d62ab6e1de | ||
|
|
217a4828d7 | ||
|
|
bc2b8513f7 | ||
|
|
73122c10fd | ||
|
|
b84db7fac7 | ||
|
|
911df3df77 | ||
|
|
acf1f5fb53 | ||
|
|
1044b39c3f | ||
|
|
a729d68600 | ||
|
|
b83886554f | ||
|
|
5a8bcebdf4 | ||
|
|
a479d3e32d | ||
|
|
f399d7383c | ||
|
|
e8e019eb76 | ||
|
|
3c2fd5d760 | ||
|
|
1ca5663298 | ||
|
|
b28d64c3c6 | ||
|
|
76c800542c | ||
|
|
cca073f8aa | ||
|
|
c0f4c184ca | ||
|
|
8c8fb01426 | ||
|
|
052408392d | ||
|
|
cfb215ab0c | ||
|
|
3501e0dffe | ||
|
|
af683af2d2 | ||
|
|
90b1a1fccb | ||
|
|
5954021cc5 | ||
|
|
108088d811 | ||
|
|
ca2ad18ded | ||
|
|
d2e6a2a1a7 | ||
|
|
e275a80f4c | ||
|
|
2745f3d516 | ||
|
|
8f7b87a29e | ||
|
|
2a7b659be4 | ||
|
|
3dd680683c | ||
|
|
49c9e19074 | ||
|
|
ddd2f86e26 | ||
|
|
fac79dc962 | ||
|
|
71a39002fb | ||
|
|
58904c441a | ||
|
|
1e812b793b | ||
|
|
ff8aa6bcbf | ||
|
|
2b213a8add | ||
|
|
021aca8d5e | ||
|
|
21b14ba440 | ||
|
|
5c242d9620 | ||
|
|
31565c9b9e | ||
|
|
99f31e0055 | ||
|
|
4cda83b748 | ||
|
|
13e76d3544 | ||
|
|
85b6d9f027 | ||
|
|
8daf9eacb7 | ||
|
|
48672e4317 | ||
|
|
eb998f0ad4 | ||
|
|
9cbb5b9b71 | ||
|
|
108666664a | ||
|
|
5abf16f9e6 | ||
|
|
78c98a34d1 | ||
|
|
68f1ddbd5a | ||
|
|
71284cdc92 | ||
|
|
03ad525fcc | ||
|
|
af9e940873 | ||
|
|
b547203fde | ||
|
|
9728b533b4 | ||
|
|
9c4d1559fd | ||
|
|
e0ec8ce78a | ||
|
|
9de04f7266 | ||
|
|
eea26f9174 | ||
|
|
0b1e9fdc5b | ||
|
|
277af3dec3 | ||
|
|
3bfd1ca07d | ||
|
|
0e635ba6b4 | ||
|
|
017ac70876 | ||
|
|
5428837605 | ||
|
|
87482df956 | ||
|
|
a13fb6933b | ||
|
|
d775e09688 | ||
|
|
f1ab40bf01 | ||
|
|
c92bc447cc | ||
|
|
6f68bb8d95 | ||
|
|
f39127b752 | ||
|
|
a6f9019edd | ||
|
|
2865abb65a | ||
|
|
f6eb11e567 | ||
|
|
ee750363d2 | ||
|
|
d8f467e30f | ||
|
|
746c51c701 | ||
|
|
f9ca777afe | ||
|
|
4189b80004 | ||
|
|
6013048f68 | ||
|
|
1d626cdea6 | ||
|
|
615c02501a | ||
|
|
7a7891d467 | ||
|
|
38bd122dd0 | ||
|
|
9c0c7badcf | ||
|
|
c3798559d2 | ||
|
|
d89ace5b9c | ||
|
|
1994d2d668 | ||
|
|
1c3ec71361 | ||
|
|
e7333f2e4d | ||
|
|
5149ab703f | ||
|
|
1e0f2158ba | ||
|
|
f17a458a04 | ||
|
|
5f06af81cb | ||
|
|
8407ce22b4 | ||
|
|
c6ddff159f | ||
|
|
b7c890d3f6 | ||
|
|
4b1f1e593d | ||
|
|
7ee702b162 | ||
|
|
680b2a4160 | ||
|
|
076c504640 | ||
|
|
2c76675110 | ||
|
|
ceb1ee3b56 | ||
|
|
de43209643 | ||
|
|
0f7e78c164 | ||
|
|
eb2e5907ea | ||
|
|
c29eba0c70 | ||
|
|
613f412659 | ||
|
|
5d55e47e9b | ||
|
|
8066f71b51 | ||
|
|
5ad588f059 | ||
|
|
4ab696b434 | ||
|
|
d3b8bdfddc | ||
|
|
a607a1f20d | ||
|
|
520209f38c | ||
|
|
ae2d80ba5a | ||
|
|
8652041855 | ||
|
|
04f15623f2 | ||
|
|
a4ed5fb082 | ||
|
|
c884d51702 | ||
|
|
ea47e54399 | ||
|
|
d953049d7d | ||
|
|
2c7ef24a29 | ||
|
|
48c09fd709 | ||
|
|
6ebe4f7752 | ||
|
|
d4de8e26ce | ||
|
|
42c9e9144c | ||
|
|
06a9f2f5fd | ||
|
|
58143ead83 | ||
|
|
b193e3e088 | ||
|
|
e1f02ffca3 | ||
|
|
bd5f2b75c3 | ||
|
|
2bad74046e | ||
|
|
dfbfd6ed82 | ||
|
|
de1a20c007 | ||
|
|
7abc3c7751 | ||
|
|
e8103477a4 | ||
|
|
354f1e1081 | ||
|
|
8a5b341e5e | ||
|
|
2232149be0 | ||
|
|
a766048f29 | ||
|
|
168951b668 | ||
|
|
519730e7d3 | ||
|
|
27f6b3366c | ||
|
|
07782704d4 | ||
|
|
e58355e7e3 | ||
|
|
ce62d23502 | ||
|
|
4c1b8c3d0a | ||
|
|
8578bc1c29 | ||
|
|
77b5276fd3 | ||
|
|
b21638f56c | ||
|
|
08edc767b5 | ||
|
|
4cd4ae9cb5 | ||
|
|
061136d798 | ||
|
|
ecdc52fce9 | ||
|
|
406c057025 | ||
|
|
3eac7f8eae | ||
|
|
79a0e45dbc | ||
|
|
2e2fdae8ef | ||
|
|
d802778104 | ||
|
|
de5f3ba49e | ||
|
|
74aca6f6c5 | ||
|
|
2a23b8d770 | ||
|
|
54d325aeb4 | ||
|
|
6dc78e3f2a | ||
|
|
108b6dc787 | ||
|
|
395de19639 | ||
|
|
cc25201c4f | ||
|
|
66f04e0424 | ||
|
|
5f9797fdd6 | ||
|
|
b4d2b3a442 | ||
|
|
155e039e66 | ||
|
|
b4786b407a | ||
|
|
a59d935bd3 | ||
|
|
6e95e497f7 | ||
|
|
ef12c6b185 | ||
|
|
e6f68496b4 | ||
|
|
be517417ff | ||
|
|
3fc0dd0bde | ||
|
|
89eb59505b | ||
|
|
2601bfa9f0 | ||
|
|
8a15cca567 | ||
|
|
ece35c391c | ||
|
|
6c3ac08c54 | ||
|
|
0e14e7c14e | ||
|
|
2704b8c4bd | ||
|
|
d5338f9244 | ||
|
|
e447f177e0 | ||
|
|
962b769989 | ||
|
|
52a786c780 | ||
|
|
f33415c7e2 | ||
|
|
3e03e53627 | ||
|
|
794e43a534 | ||
|
|
9f721ba437 | ||
|
|
4a5e28067e | ||
|
|
ab7658c1f2 | ||
|
|
6cc0065d15 | ||
|
|
4cd4a06e98 | ||
|
|
f164483e62 | ||
|
|
faf9bb0a82 | ||
|
|
df150647c4 | ||
|
|
6434df13aa | ||
|
|
9f664c751a | ||
|
|
1d27f6c90a | ||
|
|
98c85a1d9e | ||
|
|
1f198ccb43 | ||
|
|
5fb8c393c5 | ||
|
|
7c424e7d38 | ||
|
|
5fa0846dcf | ||
|
|
19c3ec45eb | ||
|
|
bdc11c771d | ||
|
|
35fba2b6fb | ||
|
|
bf4bf4da09 | ||
|
|
d25ca6ff3c | ||
|
|
79ee5c4388 | ||
|
|
2081fd5bda | ||
|
|
8fcfa6e016 | ||
|
|
c14083a45a | ||
|
|
861c351a96 | ||
|
|
50b261e7e2 | ||
|
|
54245e3292 | ||
|
|
a63b40f460 | ||
|
|
8684344e92 | ||
|
|
5f52c72b45 | ||
|
|
839783b2e6 | ||
|
|
717ff8db01 | ||
|
|
249b55ec3f | ||
|
|
5885850726 | ||
|
|
bc484338df | ||
|
|
43c9216ef8 | ||
|
|
ec3a1c621d | ||
|
|
2edffafc2b | ||
|
|
627c8f36ff | ||
|
|
01ba4c157a | ||
|
|
6f790faed9 | ||
|
|
79ca0f7f81 | ||
|
|
8fd75228e4 | ||
|
|
dcbd04aacd | ||
|
|
870bcc76a5 | ||
|
|
c383178f7f | ||
|
|
97df2c8a28 | ||
|
|
6eda265bf2 | ||
|
|
147a600577 | ||
|
|
0dd5be8e7a | ||
|
|
8c42729e5b | ||
|
|
5e0b023a7b | ||
|
|
09f0ec5ebf | ||
|
|
c326c45d70 | ||
|
|
ebf6beaaf1 | ||
|
|
c91f5fc9b8 | ||
|
|
673c739909 | ||
|
|
3bc0de1762 | ||
|
|
9af2ad7cd9 | ||
|
|
12d7e69f07 | ||
|
|
142fdffb00 | ||
|
|
c4687b6816 | ||
|
|
9b161d251e | ||
|
|
a8f058c792 | ||
|
|
5ec8bae983 | ||
|
|
7f06e6567a | ||
|
|
3257cf799a | ||
|
|
70b8ed628d | ||
|
|
aadc0329d2 | ||
|
|
120044af80 | ||
|
|
dfc5263eec | ||
|
|
2646dfae7e | ||
|
|
7d087afbf6 | ||
|
|
59c59a6a70 | ||
|
|
97edfe8ae7 | ||
|
|
daf3ae68c3 | ||
|
|
df5d65dc2d | ||
|
|
4887aa33d9 | ||
|
|
b1af95ad20 | ||
|
|
865a11c628 | ||
|
|
7c2c5319f4 | ||
|
|
f62ed4db8a | ||
|
|
556fc353a8 | ||
|
|
8fd3cb855f | ||
|
|
448a24a975 | ||
|
|
d547198361 | ||
|
|
1143ae1c5a | ||
|
|
69c55a21a4 | ||
|
|
22c631cf88 | ||
|
|
a13868818c | ||
|
|
203160db4f | ||
|
|
61ae37a752 | ||
|
|
e752a7206a | ||
|
|
36b9ed450f | ||
|
|
75215bb143 | ||
|
|
8e625344e6 | ||
|
|
3ecd86dbc2 | ||
|
|
d95e044913 | ||
|
|
0717aae341 | ||
|
|
054d44f737 | ||
|
|
c04c8796f5 | ||
|
|
72e9f2f14e | ||
|
|
9e7c84a430 | ||
|
|
a04fe0a9dd | ||
|
|
9fbe9e7aea | ||
|
|
93bdad4c42 | ||
|
|
21008249ea | ||
|
|
ae5f3e425b | ||
|
|
fccef54cd6 | ||
|
|
d67f4023e1 | ||
|
|
4caafe99d3 | ||
|
|
e33dee192c | ||
|
|
02cd596139 | ||
|
|
d31b89072d | ||
|
|
b11f83c8b3 | ||
|
|
dbdae3c63f | ||
|
|
4a4590f86b | ||
|
|
25e0ae7f0d | ||
|
|
baefa90df9 | ||
|
|
c4f3c42957 | ||
|
|
3a22360a78 | ||
|
|
e4be4944d8 | ||
|
|
b2b4764f36 | ||
|
|
6ac916c785 | ||
|
|
831c8dc64e | ||
|
|
23ec2bbd7e | ||
|
|
945a61c0ed | ||
|
|
883badc1d8 | ||
|
|
135343a2e7 | ||
|
|
ff3b779fa9 | ||
|
|
24c8297df1 | ||
|
|
656b0220c4 | ||
|
|
399a9d43d3 | ||
|
|
ee16a4debc | ||
|
|
454d67d0a2 | ||
|
|
bf44d8124d | ||
|
|
5415a9478d | ||
|
|
62dd661395 | ||
|
|
e6b2144f74 | ||
|
|
9a2454037f | ||
|
|
2fc20adc23 | ||
|
|
ae5528b62f | ||
|
|
92432ad750 | ||
|
|
381db88e33 | ||
|
|
7abe13f23d | ||
|
|
a1f904b84d | ||
|
|
3d147c9e01 | ||
|
|
db23435337 | ||
|
|
7e35721a81 | ||
|
|
8ce4fcdeba | ||
|
|
0080c5b3d4 | ||
|
|
865c3f01ba | ||
|
|
37d0105319 | ||
|
|
c5cd587780 | ||
|
|
e881c47abf | ||
|
|
952020c8a5 | ||
|
|
db1f6fb6d1 | ||
|
|
66fa9d55a1 | ||
|
|
50224326aa | ||
|
|
a59e5c1ed3 | ||
|
|
5df7580a1e | ||
|
|
96223148c0 | ||
|
|
68a8fc97d2 | ||
|
|
ca28c927b2 | ||
|
|
9cf5344fc5 | ||
|
|
e5510620cc | ||
|
|
8e6b440f9a | ||
|
|
f396e1a253 | ||
|
|
39b55fb6e8 | ||
|
|
c91ed5600f | ||
|
|
35e6533986 | ||
|
|
a114fa9d0a | ||
|
|
017c4471ed | ||
|
|
c0e760d73e | ||
|
|
8f5eef94e4 | ||
|
|
c4a7eb7a2e | ||
|
|
9b7c4e279d | ||
|
|
c6fa0b2d95 | ||
|
|
a0cd3dd0e9 | ||
|
|
e578d888e3 | ||
|
|
e0680ccee0 | ||
|
|
6cc8551a6c | ||
|
|
b0225e48b8 | ||
|
|
a5df9e3728 | ||
|
|
ead96654be | ||
|
|
0430ed982d | ||
|
|
52e40b2fdc | ||
|
|
93265ae65c | ||
|
|
699db538b6 | ||
|
|
9ac540f7cf | ||
|
|
8206b5912d | ||
|
|
59d0a58e3a | ||
|
|
945ecdf64d | ||
|
|
e37a360d07 | ||
|
|
9881a061fe | ||
|
|
76729c3377 | ||
|
|
f880007639 | ||
|
|
eee2ce00e2 | ||
|
|
a729282cc1 | ||
|
|
061322d425 | ||
|
|
191e7999c0 | ||
|
|
c0239684ed | ||
|
|
d1095f854a | ||
|
|
902b383de7 | ||
|
|
ab7ab69f20 | ||
|
|
edc53a6bc9 | ||
|
|
1f0766c1d7 | ||
|
|
01f2e926b0 | ||
|
|
0a9e585c1d | ||
|
|
75e8103cdd | ||
|
|
356d06ef58 | ||
|
|
730bc73975 | ||
|
|
b4cb9fbc41 | ||
|
|
2c78428d9d | ||
|
|
88f4c7e104 | ||
|
|
3fb3368272 | ||
|
|
af435fa9bc | ||
|
|
06287aca40 | ||
|
|
6c04cb9a0b | ||
|
|
b5e623e5a1 | ||
|
|
5f7f81bdde | ||
|
|
9ca2f85b08 | ||
|
|
8b42e319e2 | ||
|
|
c8877b49a4 | ||
|
|
54a91f1b7e | ||
|
|
63d7ad788d | ||
|
|
e6619bc6c9 | ||
|
|
ac58bfdd63 | ||
|
|
a705bb3bf2 | ||
|
|
30e49d806a | ||
|
|
5f00329d44 | ||
|
|
ed33a0b00f | ||
|
|
57bbf14e1a | ||
|
|
02006fee2e | ||
|
|
466e2bf927 | ||
|
|
878517dcd2 | ||
|
|
b0ea9513e3 | ||
|
|
817c335f30 | ||
|
|
f8a1e9452e | ||
|
|
1097f35ed8 | ||
|
|
3dac71d0a5 | ||
|
|
993e407df2 | ||
|
|
c94e157b76 | ||
|
|
ca988ffc3a | ||
|
|
93bd6bdf01 | ||
|
|
ec600c8806 | ||
|
|
717c0999a5 | ||
|
|
c4d7ad8d0d | ||
|
|
6711bcf300 | ||
|
|
838b273d9c | ||
|
|
f64570ee84 | ||
|
|
94cb37075a | ||
|
|
6beb8625bf | ||
|
|
998225eb4e | ||
|
|
8de6b447ee | ||
|
|
85683f17c3 | ||
|
|
ffa8e2f25a | ||
|
|
faadebc67a | ||
|
|
748074ba9f | ||
|
|
884accd976 | ||
|
|
7377527f7c | ||
|
|
e44827823a | ||
|
|
1fdef32a4d | ||
|
|
da2dbfb108 | ||
|
|
f8230f9f59 | ||
|
|
71ca05c899 | ||
|
|
509ca60959 | ||
|
|
be91977725 | ||
|
|
22be375f1b | ||
|
|
0142ef1d3f | ||
|
|
6e4c49df61 | ||
|
|
4bf6b1bf0f | ||
|
|
d2ee3bf379 | ||
|
|
f1c182072b | ||
|
|
877ec94fc9 | ||
|
|
a5709d8bfc | ||
|
|
a5f3b0b554 | ||
|
|
3a0fd1c219 | ||
|
|
8e600311d0 | ||
|
|
ea6355a73d | ||
|
|
3cfb3a647e | ||
|
|
22af7fd342 | ||
|
|
c0f70d1a88 | ||
|
|
8b135cf47a | ||
|
|
e5126321ad | ||
|
|
982a1b75ed | ||
|
|
86c87ded89 | ||
|
|
66821b30a7 | ||
|
|
ecd3f124be | ||
|
|
41db5a9bf9 | ||
|
|
dfa966dbfc | ||
|
|
00a2459a86 | ||
|
|
d5b718b380 | ||
|
|
9e08291579 | ||
|
|
075cdfc810 | ||
|
|
b5f10ab7dc | ||
|
|
71f4c11fea | ||
|
|
8a623394da | ||
|
|
349a55fa33 | ||
|
|
83699e2011 | ||
|
|
462de32a5a | ||
|
|
630548644d | ||
|
|
d51b610f97 | ||
|
|
aea2a8a45d | ||
|
|
3b026b2f5f | ||
|
|
ecb23a1651 | ||
|
|
d7f0a718c3 | ||
|
|
f1876321c5 | ||
|
|
8940262618 | ||
|
|
69ab9f7c22 | ||
|
|
caf18dbaab |
@@ -1,2 +1,3 @@
|
||||
/memory/
|
||||
tickets/.ticket-backend.lock
|
||||
/workspace.db*
|
||||
|
||||
@@ -1,66 +1,97 @@
|
||||
---
|
||||
title: 'MCP local stdio integration architecture'
|
||||
title: 'MCP local stdio integration roadmap'
|
||||
state: 'active'
|
||||
created_at: '2026-06-10T07:48:45Z'
|
||||
updated_at: '2026-06-13T15:30:22Z'
|
||||
updated_at: '2026-06-20T05:34:00Z'
|
||||
linked_tickets: ['00001KTR81P9X', '00001KV0SP0TY', '00001KVHR3WRF', '00001KVHR3WRY', '00001KVHR3WS6', '00001KVHR3WSD', '00001KVHR3WSN', '00001KVHR3WSW']
|
||||
---
|
||||
|
||||
## Objective
|
||||
## Goal
|
||||
|
||||
Add MCP local stdio integration to Yoi without weakening Worker history, prompt-context, scoped tool permission, or Plugin/Feature layering invariants.
|
||||
|
||||
MCP should be implemented as a protocol-backed integration layer on top of `pod::feature`. `pod::feature` supplies the contribution/lifecycle API substrate; MCP owns its own enablement, local server trust model, command/env/secret policy, and MCP-specific permissions. MCP is not the Plugin model, and Plugin permission policy is not implemented by feature-layer authority grants.
|
||||
MCP is a protocol-backed integration layer on top of `pod::feature`. `pod::feature` supplies contribution/lifecycle/runtime-discovered registration substrate; MCP owns its own enablement, local server trust model, command/env/secret policy, and MCP-specific permission decisions. MCP is not the Plugin model, and Plugin permission policy is not implemented by feature-layer authority grants.
|
||||
|
||||
## Strategic direction
|
||||
## Motivation / background
|
||||
|
||||
- Baseline the implementation on MCP specification `2025-11-25`.
|
||||
Yoi needs to integrate with external capability providers without turning them into hidden context sources or bypassing ordinary Tool/Worker safety rules. MCP is useful because it can expose tools, resources, and prompts from local protocol servers, but those server-provided declarations and results are untrusted and must be normalized through Yoi's existing authority boundaries.
|
||||
|
||||
The first MCP slice should focus on local stdio servers because they are concrete enough to implement and debug while keeping remote auth, OAuth, Streamable HTTP, registry distribution, sampling, and elicitation out of the initial trust boundary.
|
||||
|
||||
A configured local MCP server runs as a local executable. Yoi feature authority does not sandbox that executable's OS-level side effects, so command/env/secret handling and explicit local trust policy are MCP-layer responsibilities rather than generic `pod::feature` grants.
|
||||
|
||||
## Strategy / design direction
|
||||
|
||||
- Baseline the initial implementation on MCP specification `2025-11-25`.
|
||||
- Start with local stdio MCP servers only.
|
||||
- Treat MCP server metadata, tools, resources, prompts, and results as untrusted content.
|
||||
- Do not allow MCP resources/prompts to be hidden context injection.
|
||||
- Do not allow MCP resources/prompts to become hidden context injection.
|
||||
- They must be explicit tool operations with history records.
|
||||
- Use the normal Yoi tool registry, PreToolCall permission, history, and bounded result paths.
|
||||
- Use the normal Yoi ToolRegistry, PreToolCall permission, history, and bounded result paths.
|
||||
- Do not add private MCP-only bypasses around Worker/tool invariants.
|
||||
- Keep sampling and elicitation fail-closed initially.
|
||||
- Keep Streamable HTTP, remote auth, OAuth, and MCP Registry/distribution out of the first slice.
|
||||
- Treat local stdio server execution as an explicit MCP config/trust decision, not as a `pod::feature` authority grant.
|
||||
- Document clearly that a configured local MCP server runs as a local executable; Yoi feature authority does not sandbox its OS-level side effects.
|
||||
|
||||
## Layering decisions
|
||||
### Layering decisions
|
||||
|
||||
- `pod::feature` is an API/contribution substrate.
|
||||
- It owns contribution declarations, provider/service lifecycle hooks, diagnostics, dynamic registration plumbing, and integration with normal Worker/ToolRegistry paths.
|
||||
- It owns contribution declarations, provider/service lifecycle hooks, diagnostics, runtime-discovered registration plumbing, and integration with normal Worker/ToolRegistry paths.
|
||||
- It does not own Plugin permission policy or MCP server trust policy.
|
||||
- Plugin is a user-facing package/config/runtime layer over `pod::feature`.
|
||||
- Plugin permissions are Plugin-layer policy.
|
||||
- Plugin package discovery/enablement must not be conflated with MCP local server execution.
|
||||
- MCP is a separate feature-backed integration layer.
|
||||
- MCP enablement, command/env/secret handling, server trust, and MCP-specific permission decisions live in MCP config/implementation.
|
||||
- MCP dynamic tools/resources/prompts are exposed through the feature API and ordinary Yoi tool paths.
|
||||
- MCP provider-discovered tools/resources/prompts are exposed through the feature API and ordinary Yoi tool paths.
|
||||
|
||||
## Work breakdown
|
||||
### Concrete implementation tickets
|
||||
|
||||
1. `00001KTR81P9X` — Extend `pod::feature` API for protocol-backed external providers.
|
||||
- provider/service lifecycle
|
||||
- startup discovery and dynamic contribution registration
|
||||
- bounded refresh semantics
|
||||
- metadata/result normalization
|
||||
- no feature-layer authority model for MCP/Plugin permissions
|
||||
2. `00001KTR82RB7` — Implement MCP `2025-11-25` local stdio server bridge.
|
||||
- explicit MCP config and trust model
|
||||
- initialize/capability negotiation
|
||||
- tools/resources/prompts list/call/read/get
|
||||
- bounded result serialization
|
||||
- list-changed diagnostics/refresh behavior
|
||||
3. `00001KV0SP0TY` — Remove feature-layer HostAuthority model.
|
||||
- remove authority/grant terminology from `pod::feature`
|
||||
- keep real permission/trust policy in owning Plugin/MCP/manifest/tool layers
|
||||
4. Later follow-ups, if needed.
|
||||
- richer MCP tasks / task-support integration
|
||||
- remote/HTTP transports
|
||||
- OAuth / registry / package distribution
|
||||
- Plugin package/runtime alignment, if an explicit MCP/plugin bridge is later approved
|
||||
Completed prerequisites:
|
||||
|
||||
## Success criteria
|
||||
- `00001KTR81P9X` — Extend `pod::feature` API for external protocol-backed capability providers.
|
||||
- `00001KV0SP0TY` — Remove feature-layer HostAuthority model.
|
||||
|
||||
Concrete MCP implementation sequence:
|
||||
|
||||
1. `00001KVHR3WRF` — MCP local stdio server config and trust policy.
|
||||
- explicit config, command/env/secret redaction, local executable trust boundary, no auto-start.
|
||||
2. `00001KVHR3WRY` — MCP stdio JSON-RPC lifecycle client.
|
||||
- subprocess lifecycle, initialize/capability negotiation, diagnostics, shutdown.
|
||||
3. `00001KVHR3WS6` — MCP tools/list registration into ToolRegistry.
|
||||
- provider-discovered tools, stable namespacing, schema validation, untrusted metadata normalization, no tools/call yet.
|
||||
4. `00001KVHR3WSD` — MCP tools/call execution through ordinary Tool path.
|
||||
- PreToolCall gate before server call, bounded result serialization, history path.
|
||||
5. `00001KVHR3WSN` — MCP resources/prompts as explicit tool operations.
|
||||
- resources/list/read and prompts/list/get without hidden context injection.
|
||||
6. `00001KVHR3WSW` — MCP list_changed notification handling.
|
||||
- deterministic safe refresh/diagnostic behavior without breaking tool schema or prompt-cache invariants.
|
||||
|
||||
The old broad implementation Ticket `00001KTR82RB7` is superseded by this sequence and should not be used as an implementation work item.
|
||||
|
||||
### Terminology
|
||||
|
||||
Use `runtime-discovered` or `provider-discovered` for MCP tools/resources/prompts discovered from `tools/list`, `resources/list`, or `prompts/list`. Avoid `dynamic tools` / `dynamic registry` in new MCP design prose because those phrases imply that model-visible tool schemas may change during an active LLM run.
|
||||
|
||||
The intended invariant is:
|
||||
|
||||
```text
|
||||
provider-discovered at startup / provider initialization;
|
||||
registered into the ordinary ToolRegistry before model exposure;
|
||||
run-stable for the duration of a model request/run;
|
||||
refreshed only at a safe boundary or reported as a diagnostic.
|
||||
```
|
||||
|
||||
### Later follow-ups
|
||||
|
||||
- Richer MCP task/task-support integration if ordinary tool-call fallback is insufficient.
|
||||
- Streamable HTTP transport.
|
||||
- OAuth / remote auth.
|
||||
- Registry/package distribution.
|
||||
- Explicit MCP/Plugin bridge only if separately approved; do not conflate Plugin packages with MCP local server execution.
|
||||
|
||||
## Success criteria / exit conditions
|
||||
|
||||
- A local mock MCP server can be configured explicitly and initialized.
|
||||
- Discovered MCP tools appear as ordinary Yoi tools with stable namespacing.
|
||||
@@ -70,3 +101,11 @@ MCP should be implemented as a protocol-backed integration layer on top of `pod:
|
||||
- Secret values, command/env details, and server diagnostics are redacted where required.
|
||||
- Local server trust boundary is documented: Yoi does not sandbox the configured executable through feature authority.
|
||||
- Feature, Plugin, and MCP permission/trust responsibilities are documented as separate layers.
|
||||
|
||||
## Decision context
|
||||
|
||||
- MCP is not the Plugin model; it is a protocol-backed integration layer using `pod::feature` substrate.
|
||||
- `pod::feature` should provide contribution/lifecycle/runtime-discovered registration plumbing, not MCP server trust policy or Plugin package permission policy.
|
||||
- MCP resources and prompts must never be hidden context injection. They are explicit operations recorded through ordinary history/tool paths.
|
||||
- Provider-discovered tools are discovered at startup/provider initialization and registered before model exposure; model-visible schemas remain run-stable during a request/run.
|
||||
- Local stdio server execution is a user/config trust decision. Yoi does not sandbox the local executable merely because it is configured through MCP.
|
||||
|
||||
@@ -0,0 +1,101 @@
|
||||
---
|
||||
title: "Plugin platform roadmap"
|
||||
state: "active"
|
||||
created_at: "2026-06-19T13:18:58Z"
|
||||
updated_at: "2026-06-24T19:55:00Z"
|
||||
linked_tickets: ["00001KV5R5V2S", "00001KV5W3PHA", "00001KV5W3PHW", "00001KV5W3PJ3", "00001KVFD3YSV", "00001KVFDX9AF", "00001KVFDX9AY", "00001KVG0HR96", "00001KVXHVCR5", "00001KVXK0WD3", "00001KVXK0WDH", "00001KVXK0WDQ", "00001KVXK0WDX", "00001KVXK0WE4", "00001KVXK0WEA"]
|
||||
---
|
||||
|
||||
## Goal
|
||||
|
||||
Build Yoi's Plugin platform as a coherent extension system: packages are discovered and inspected safely, enabled explicitly, registered through typed Plugin surfaces, executed in a sandboxed runtime, constrained by Plugin-layer grants, and authored through SDK/templates rather than raw runtime ABI details.
|
||||
|
||||
The long-term platform goal is not merely to run Wasm. It is to make Plugin packages a durable, inspectable, permissioned, and authorable extension layer for Tools first, then host APIs (`https`, `fs`), and later Service / Ingress surfaces when concrete needs justify them.
|
||||
|
||||
## Motivation / background
|
||||
|
||||
The current Plugin foundation is already substantial:
|
||||
|
||||
- package discovery and explicit enablement resolver;
|
||||
- Tool surface registration through the ordinary ToolRegistry/model-visible schema path;
|
||||
- minimal sandboxed WASM Tool execution;
|
||||
- Plugin permission grant enforcement;
|
||||
- follow-up Tickets for read-only inspection CLI, `https`, `fs`, and Component Model migration.
|
||||
|
||||
The remaining work must be kept as one roadmap because the pieces constrain each other:
|
||||
|
||||
- Plugin authoring needs an SDK/PDK and examples, not raw pointer/length Wasm ABI hand-coding.
|
||||
- `https` and `fs` host APIs must be grant-gated and shaped so they can move cleanly to typed Component Model interfaces.
|
||||
- Diagnostics (`yoi plugin list/show`) are needed before the system becomes harder to debug.
|
||||
- Component Model adoption should guide new host API design before a custom raw ABI becomes entrenched.
|
||||
- Service / Ingress are useful for bridge-style integrations, but should come after Tool runtime, diagnostics, and host API policy are stable.
|
||||
|
||||
Research of common Wasm extension systems points to the same pattern: mature systems combine a package manifest, explicit capabilities, a sandbox runtime, host-provided capability APIs, language SDK/PDK bindings, templates/examples, inspection/check tooling, and versioned interfaces.
|
||||
|
||||
## Strategy / design direction
|
||||
|
||||
- Keep Plugin as a user-facing package/config/runtime layer above lower-level `pod::feature` substrate.
|
||||
- `pod::feature` provides contribution/registration substrate.
|
||||
- Plugin owns package discovery, enablement, grant policy, runtime selection, authoring UX, and user-facing diagnostics.
|
||||
- Preserve authority boundaries.
|
||||
- Package discovery is read-only inventory.
|
||||
- Package presence never registers a Tool/Hook, executes Wasm, starts a Service, reads files, opens network, or injects context.
|
||||
- Explicit enablement and Plugin grants are required before registration/execution/host API use.
|
||||
- Tool calls/results continue through ordinary ToolRegistry and Worker history paths.
|
||||
- Treat Component Model as the active Plugin runtime shape before public release.
|
||||
- New typed Plugin host APIs should be designed in WIT-compatible terms.
|
||||
- `runtime.kind = "wasm-component"` is the current Plugin runtime authority for new work.
|
||||
- The earlier `yoi-plugin-wasm-1` raw core-Wasm compatibility bridge is retired from the active roadmap because Plugin has not been publicly released and compatibility would preserve the wrong boundary.
|
||||
- Sequence the platform in usable layers:
|
||||
1. Package discovery / explicit enablement / digest-pinned restore. Completed foundation.
|
||||
2. Tool surface registration. Completed foundation.
|
||||
3. Minimal WASM Tool execution. Completed foundation.
|
||||
4. Permission grants. Completed foundation.
|
||||
5. Read-only Plugin CLI inspection (`yoi plugin list/show`) for debugging discovery/enablement/grants/runtime metadata.
|
||||
6. `https` and `fs` host APIs for Tool Plugins, grant-gated and WIT-compatible.
|
||||
7. Remove the raw core-Wasm compatibility bridge and reject legacy runtime manifests.
|
||||
8. Component Model runtime and authoring model become the only active Plugin runtime path.
|
||||
9. Guest SDK/PDK, examples, `check`/`pack`/`new` authoring tooling target Component Model only.
|
||||
10. Service / Ingress runtime is developed as host-managed lifecycle, event queue, output command, and diagnostics slices.
|
||||
11. WebSocket support for long-lived integrations is host-owned connection driver + ingress event delivery + output command, not Plugin-owned polling with `recv(timeout)`.
|
||||
- Keep Discord-style bridge goals split into two stages.
|
||||
- Outbound Discord/webhook Tool is possible after `https`.
|
||||
- Bidirectional Discord bridge requires Service + Ingress + WebSocket or inbound HTTP and host routing policy.
|
||||
|
||||
## Current implementation split
|
||||
|
||||
The broad Plugin runtime redesign is tracked by `00001KVXHVCR5` as context only; implementation should proceed through concrete Tickets instead of routing that umbrella as a single coding task.
|
||||
|
||||
1. `00001KVXK0WD3` Remove legacy raw WASM Plugin runtime.
|
||||
- Deletes the active `LegacyToolAdapter` / raw-Wasm execution path.
|
||||
2. `00001KVXK0WDH` Reject legacy Plugin runtime in manifest and CLI diagnostics.
|
||||
- Makes `plugin.toml`, `yoi plugin check/list/show`, docs, and fixtures reflect Component Model only runtime authority.
|
||||
3. `00001KVXK0WDQ` Define Plugin Service lifecycle and ingress queue runtime.
|
||||
- Adds host-managed lifecycle, bounded queue, serial dispatch, backpressure, timeout, and diagnostics.
|
||||
4. `00001KVXK0WDX` Add Plugin service output command model.
|
||||
- Lets service handlers request side effects as grant-checked commands rather than ambient authority.
|
||||
5. `00001KVXK0WE4` Add host-owned WebSocket driver for Plugin services.
|
||||
- Converts incoming WS frames into ingress events and sends outbound frames through output commands.
|
||||
6. `00001KVXK0WEA` Update Plugin WIT PDK templates for service event runtime.
|
||||
- Aligns authoring API, WIT, PDK, templates, and docs with the new event/command execution model.
|
||||
|
||||
## Success criteria / exit conditions
|
||||
|
||||
- Users can inspect Plugin discovery/enablement/grant/runtime state through a read-only CLI without executing Plugin code.
|
||||
- Plugin authors can build a Tool Plugin without writing raw memory/pointer ABI plumbing.
|
||||
- Tool Plugins can safely call grant-gated `https` and `fs` host APIs.
|
||||
- Component Model is the only active Plugin runtime path, with WIT-compatible host API types and measured packaging/runtime impact.
|
||||
- Plugin grants remain authoritative over registration, execution, and host API calls.
|
||||
- Plugin diagnostics explain missing package, invalid manifest, digest/version mismatch, missing grant, rejected schema, runtime mismatch, legacy runtime rejection, and unsupported host API cases safely.
|
||||
- Raw core-Wasm Plugin compatibility is removed before public release; tests and docs no longer treat it as a current runtime.
|
||||
- Documentation covers package format, Component Model runtime, host API authority, authoring SDK/templates, Service/Ingress event runtime, and operational debugging.
|
||||
- Service/Ingress work is host-managed: services have lifecycle/status, ingress uses bounded queues, side effects are output commands, and WebSocket integrations use host-owned connection drivers.
|
||||
|
||||
## Decision context
|
||||
|
||||
- This Objective is roadmap context, not Ticket authority. Implementation still requires reading concrete Ticket bodies, threads, artifacts, and relations.
|
||||
- Component Model direction supersedes Yoi's custom raw ABI as both long-term and current active Plugin runtime authority before public release.
|
||||
- `https` / `fs` work should avoid choices that conflict with later WIT typed interfaces.
|
||||
- Guest SDK work targets Component Model directly; raw ABI wrappers are not a supported transitional authoring path.
|
||||
- Plugin and MCP remain separate. Component Model adoption for Plugin does not imply MCP server execution, MCP prompt/resource injection, or MCP trust policy changes.
|
||||
- Plugin surfaces remain Tool / Hook / Service / Ingress; outbound side effects are Tool metadata and host API grants, not a separate surface.
|
||||
@@ -0,0 +1,249 @@
|
||||
---
|
||||
title: "Team workspace control plane and runner architecture"
|
||||
state: "active"
|
||||
created_at: "2026-06-20T14:26:29Z"
|
||||
updated_at: "2026-06-21T18:10:00Z"
|
||||
linked_tickets: ["00001KVMFFYVX"]
|
||||
---
|
||||
|
||||
## Goal
|
||||
|
||||
Yoi を、単一のローカル開発ディレクトリで動くエージェント実行ツールから、チームで作業・判断・実行結果を管理できるワークスペース基盤へ発展させる。
|
||||
|
||||
この Objective の中心は、Web から扱える管理システムを作り、その管理システムにローカル実行環境・リモート実行環境・将来のクラウド実行環境を接続できるようにすることである。管理システムは Ticket、Objective、Memory、Knowledge、Run、Artifact、Runner の正本を持つ。実行環境はその管理システムから仕事を受け取り、コード取得、作業用ディレクトリ作成、エージェント実行、検証、結果報告を行う。
|
||||
|
||||
この Objective は Git ホスティングサービスを作るものではない。Git は重要な Repository provider として扱うが、Yoi の Workspace は Git Repository root と同じものにしない。Yoi が作るべきものは、コード・ドキュメント・データ・成果物などの Repository と実行環境を接続しながら、人間とエージェントの作業、Ticket lifecycle、Memory/Knowledge、検証証跡、実行環境配置を管理するチームワークスペースである。
|
||||
|
||||
## Glossary
|
||||
|
||||
この Objective では、以下の語をこの意味で使う。
|
||||
|
||||
- Workspace: チームまたはプロジェクトの管理単位。Ticket、Objective、Memory、Knowledge、Run、Artifact、Policy、Actor、Repository を持つ。Git Repository root ではない。
|
||||
- Control plane: Workspace の正本を持ち、Web UI / API / CLI から操作される管理システム。
|
||||
- Runner: Control plane から仕事を受け取り、実際にエージェントやツールを動かす実行環境。最初はローカルマシン上の runner、後でリモート runner やクラウド runner を追加する。
|
||||
- Repository: Workspace に接続される source/storage。コード、ドキュメント、local directory、object storage、artifact store、dataset などを含む。Git Repository も Repository の一種であり、基本的には filesystem path ではなく URI / URL で識別する。
|
||||
- Repository provider: Repository の種類ごとの実装。Git、local filesystem、object store、artifact store、将来の non-Git VCS など。
|
||||
- RepositoryPoint: Repository 内の特定地点。Git commit/ref/path、object store version/prefix、file snapshot/path など、provider ごとの revision/ref/snapshot/path を表す。
|
||||
- Execution Workspace: Runner が Run のために作る作業用ディレクトリや container filesystem。1 つ以上の RepositoryPoint から materialize される。Git worktree、clone、sparse checkout などはこれを作る手段である。
|
||||
- Ticket: チームで扱う作業単位。目的、要件、判断、議論、完了条件、関係、証跡を持つ。
|
||||
- Objective: 複数の Ticket を束ねる長期目標や設計方針。
|
||||
- Run: Ticket や Objective に対して行われた具体的な実行試行。どの Runner が、どの Execution Workspace で、何を実行し、どんな結果になったかを持つ。
|
||||
- Artifact: Run や Ticket に紐づく成果物や証跡。diff、log、validation result、review result、report など。
|
||||
- Memory: エージェントやユーザーが再利用するための要約された文脈。Ticket や Run の正本ではない。
|
||||
- Knowledge: 保守された知識や設計判断。Memory より人間が維持する資料に近い。
|
||||
- Actor: 人間、エージェント、システム、外部サービスなど、Workspace 上で操作や発言を行う主体。
|
||||
|
||||
## Motivation / background
|
||||
|
||||
現在の Yoi は、ローカルの `.yoi` ディレクトリ、ローカルプロセス、Ticket ファイル、ワークツリー運用によって、自分自身の開発に使えるエージェント実行環境になっている。しかし、チーム利用、Web UI、リモート実行、クラウド実行、最終的な SaaS 提供を考えると、次の前提を変える必要がある。
|
||||
|
||||
- Workspace を Git Repository root と同一視しない。
|
||||
- ローカル filesystem 上の `.yoi` を、長期的なチーム用正本 store にしない。
|
||||
- Ticket をローカル作業メモではなく、チームの作業調整 record にする。
|
||||
- Ticket と実行試行を分ける。実行試行は Run として記録する。
|
||||
- 管理システムと実行環境を分ける。
|
||||
- まず Web から Ticket、Objective、Memory、Knowledge、Run、Artifact、Runner state を見られるようにする。
|
||||
- 最初はローカルマシンを Runner として使い、後でリモート Runner、クラウド Runner、runner pool、resource allocation、quota、billing、sandboxing に拡張する。
|
||||
- Git ホスティング機能を取り込むのではなく、Git Repository / worktree / clone は Repository provider と Execution Workspace materialization の手段として扱う。
|
||||
|
||||
OSS として Control plane、Runner、Web frontend、protocol を公開しつつ、managed service では hosted control plane、runner fleet、リソース柔軟性、team auth、backup、audit、availability、multi-tenant operations で価値を出す。
|
||||
|
||||
## Strategy / design direction
|
||||
|
||||
### 1. Control plane を先に作る
|
||||
|
||||
Team Workspace の正本は server-side control plane に置く。`.yoi` は local backend、single-user/self-hosted compatibility、offline/export/import、runner-local projection、migration bridge として残せるが、multi-user SaaS の正本とはみなさない。
|
||||
|
||||
Control plane は Ticket、Objective、Memory、Knowledge、Run、Artifact、Actor、Permission、Audit、Runner state を管理する。Web UI、CLI、TUI、将来の desktop client は、この Control plane を操作する client であり、別の正本 store を持たない。
|
||||
|
||||
### 2. Workspace と Repository を同一視しない
|
||||
|
||||
Workspace はチームまたはプロジェクトの作業管理単位である。Repository は Workspace に接続される source/storage である。Git Repository は Repository の一種にすぎない。
|
||||
|
||||
1 つの Workspace は複数の Repository を持てる。Repository は filesystem path ではなく URI / URL で識別する。例として `git+https://...`、`file://...`、`s3://...`、`artifact://...`、将来の VCS provider URI などを扱えるようにする。
|
||||
|
||||
Ticket と Objective は Repository 配下に置かず、Workspace 配下に平たく持つ。Ticket は必要に応じて対象 Repository、ref selector、path、必要 capability を持つ。Objective は複数 Ticket にまたがる target default / scope hint を持てるが、Repository の所有物にはしない。
|
||||
|
||||
Run は Ticket の target selector を具体的な RepositoryPoint に解決し、その RepositoryPoint から Execution Workspace を materialize する。Git worktree 相当の機能は、この Execution Workspace を作るための実装戦略として扱う。
|
||||
|
||||
短期的には Git を主な Repository provider とする。ただし Yoi の authority model を Git object、Git branch、Git Repository root、worktree path に固定しない。Orchestration は Git そのものではなく、`resolve_ref`、`materialize`、`diff`、`patch`、`commit`、`merge` などの Repository capability に依存する。
|
||||
|
||||
### 3. Ticket を team coordination record にする
|
||||
|
||||
Ticket は実行そのものではない。Ticket は「何を、なぜ、どの条件で完了とみなすか」を持つ。Ticket は Workspace に平たく所属し、Repository には所属しない。コードやドキュメントを対象にする Ticket は、対象 Repository / ref selector / path / intent を target として持つ。
|
||||
|
||||
Ticket target は intent/selector であり、実行再現性のための immutable point ではない。Run が target selector を concrete RepositoryPoint に解決し、実際にどの revision/snapshot を materialize したかを記録する。
|
||||
|
||||
```text
|
||||
Ticket
|
||||
-> target selectors: Repository + ref selector + path + intent
|
||||
-> Run / Attempt
|
||||
-> resolved RepositoryPoint
|
||||
-> Execution Workspace
|
||||
-> Artifact / Evidence
|
||||
-> Review / Decision
|
||||
-> Audit / Notification
|
||||
```
|
||||
|
||||
Target 例:
|
||||
|
||||
```text
|
||||
Ticket targets:
|
||||
- repository: main-code
|
||||
role: primary
|
||||
ref: develop
|
||||
paths: ["crates/pod/"]
|
||||
intent: change
|
||||
- repository: docs
|
||||
role: related
|
||||
ref: main
|
||||
paths: ["docs/development/"]
|
||||
intent: read
|
||||
|
||||
Run inputs:
|
||||
- repository: main-code
|
||||
requested_ref: develop
|
||||
resolved_point: git commit abc123
|
||||
mount: /workspace/main-code
|
||||
```
|
||||
|
||||
Ticket には次の概念が必要になる。
|
||||
|
||||
- Actor identity: human / agent / system / service account.
|
||||
- Assignment / owner / reviewer / watcher.
|
||||
- Typed thread events: comment, decision, plan, review, implementation report, state transition.
|
||||
- Linked Objective / Artifact / Run / Repository / RepositoryPoint / Execution Workspace.
|
||||
- Permission / visibility.
|
||||
- Audit trail.
|
||||
- Notification / mention.
|
||||
- Board / queue / planning / review / done / archived views.
|
||||
- Conflict handling and concurrent editing policy.
|
||||
|
||||
### 4. Memory / Knowledge の本格再設計は後回しにする
|
||||
|
||||
Memory / Knowledge は Ticket / Run / Artifact のコピーではない。再利用可能な文脈、方針、学習された制約、保守された知識として扱う。ただし、Memory の意味論・抽出・承認・検索・staleness 処理を今この Objective で先に作り込まない。
|
||||
|
||||
理由は、Memory の正しい設計が Workspace control plane の record model、Actor / visibility / permission、Ticket と Run の分離、Artifact / evidence、RepositoryPoint、Runner に渡す context の監査方法に依存するためである。これらが固まる前に Memory schema だけを作ると、local `.yoi` 前提や現行 agent runtime 前提に引っ張られ、後で再設計が必要になる。
|
||||
|
||||
この Objective では、Memory / Knowledge について以下の platform contract だけを維持する。
|
||||
|
||||
- Memory / Knowledge は Control plane が扱う record だが、Ticket / Run / Artifact の authority を置き換えない。
|
||||
- 将来、Memory / Knowledge の canonical storage は Workspace control plane 側に置く。
|
||||
- local `.yoi` memory は compatibility、offline/export/import、runner-local projection、migration bridge として扱う。
|
||||
- Personal Memory、Workspace Memory、Run Summary、Maintained Knowledge は分離が必要である。
|
||||
- Generated Memory には provenance、visibility、approval、audit が必要である。
|
||||
- Runner / agent に渡した Memory/Knowledge context は、将来 ContextPack などとして Run に記録できる必要がある。
|
||||
|
||||
本格的な Memory 再設計は、Memory の保存先を Workspace backend / control plane record に移すタイミングで回収する。それまでは低リスクな観察、問題例の収集、既存 local memory の互換維持に留める。
|
||||
|
||||
### 5. 管理システムと実行環境を弱結合にする
|
||||
|
||||
Control plane は正本と調整を持つ。Runner は実行を担当する。
|
||||
|
||||
初期形:
|
||||
|
||||
```text
|
||||
Web UI / Control Plane
|
||||
-> Runner connection
|
||||
-> Local machine runner
|
||||
-> Existing Yoi runtime, tools, working copy, build/test commands
|
||||
```
|
||||
|
||||
この段階では、現在ローカル管理画面が行っている Ticket 選択、エージェント起動、レビュー起動、作業用 checkout 作成、検証実行、結果表示を、Web/control plane から local runner に対して実行できるようにする。
|
||||
|
||||
その後で、remote runner、self-hosted runner、hosted cloud runner、runner pool、resource allocation、quota、billing、sandbox、network policy、secret distribution を追加する。
|
||||
|
||||
```text
|
||||
Phase 1: Web control plane + local runner
|
||||
Phase 2: Remote/self-hosted runner
|
||||
Phase 3: Hosted cloud runner fleet
|
||||
Phase 4: Resource allocation / scheduling / quotas / billing / isolation
|
||||
```
|
||||
|
||||
### 6. Web frontend を先に作る
|
||||
|
||||
Desktop app は対応コストが高いので、まず Web frontend を primary UI とする。
|
||||
|
||||
- Web: チームで使う主要 UI。
|
||||
- CLI: automation、scripting、local operations。
|
||||
- TUI/local panel: local runner cockpit、fallback、dogfooding surface。
|
||||
- Future desktop: Web/control-plane model が安定した後に検討する optional client。
|
||||
|
||||
Web UI は Ticket、Objective、Memory、Knowledge、Run、Runner、Artifact を扱う。UI の都合で正本を二重化しない。
|
||||
|
||||
### 7. 多重起動コストと runtime placement を見直す
|
||||
|
||||
Cloud/remote execution を成立させるには、多数のエージェント実行を安く管理できる必要がある。logical agent session と runtime process/resource placement を分ける。
|
||||
|
||||
初期 Workspace DB では、Worker を canonical table として永続化しない。Host / Worker 一覧は backend-local runtime inspection や将来の Host protocol から逐次取得する live view とし、Ticket に関わった Worker は Ticket thread events と WorkerRef snapshot / TicketWorkerLink として記録する。
|
||||
|
||||
Worker の一元管理、データ永続化、アーカイブは将来的には必要になる。これは Host protocol、remote/self-hosted/hosted worker lifecycle、worker identity、retention policy、audit requirements が固まった後に、dedicated Worker registry / archive model として追加する。v0 で Pod metadata の代替として Worker table を作らない。
|
||||
|
||||
検討対象:
|
||||
|
||||
- Agent identity と process/runtime placement の分離。
|
||||
- Provider client、tool registry、resource cache の共有可能性。
|
||||
- Prompt/resource/profile resolution cache。
|
||||
- Model call multiplexing and scheduling。
|
||||
- Tool execution sandbox reuse。
|
||||
- Plugin instance / Service runtime との統合。
|
||||
- Session/event stream と runtime lifecycle の分離。
|
||||
- Runner-local cache、checkout reuse、build cache、dependency cache。
|
||||
|
||||
## Initial phases / candidate tickets
|
||||
|
||||
1. **Vocabulary / architecture record**
|
||||
- Workspace / Repository / RepositoryPoint / Execution Workspace / Runner / Control Plane / Run / Ticket / Memory / Knowledge の用語と境界を固める。
|
||||
2. **Team-space canonical data model**
|
||||
- Ticket / Objective / Target / Run / Artifact / Actor / Permission / Audit / Memory / Knowledge の entity/event model を設計する。
|
||||
3. **Ticket and Run separation**
|
||||
- Ticket lifecycle と execution attempt / orchestration run / validation run を分離し、Ticket thread と Run evidence の責務を明確化する。
|
||||
4. **Memory storage migration boundary**
|
||||
- Memory / Knowledge の本格再設計は後回しにし、まずは Workspace backend に移す時の platform contract、compatibility/cache/export 方針、将来の provenance / visibility / approval 要件だけを固定する。
|
||||
5. **Control plane backend architecture**
|
||||
- local `.yoi` backend と server-side canonical backend の境界、migration/export/import、compatibility mode を設計する。
|
||||
6. **Web control plane MVP design**
|
||||
- read-only Ticket / Objective / Memory / Knowledge / Runner state UI/API の範囲を決める。
|
||||
7. **Local runner protocol design**
|
||||
- Web/control plane から local runner に安全な操作を送る protocol と authority boundary を設計する。
|
||||
8. **Repository and Execution Workspace materialization model**
|
||||
- Repository URI、Repository provider capability、RepositoryPoint resolution、Git worktree / clone / sparse checkout / future source backend を runner-side strategy として抽象化する。
|
||||
9. **Remote/hosted runner foundation**
|
||||
- runner registration, heartbeat, capability advertisement, job assignment, logs/events, secrets, sandbox/resource policy を設計する。
|
||||
|
||||
## Non-goals
|
||||
|
||||
- Git hosting service を作ること。
|
||||
- `.yoi` filesystem をそのまま SaaS canonical store にすること。
|
||||
- 最初から full hosted cloud execution を作ること。
|
||||
- local execution / CLI / TUI / local panel を捨てること。
|
||||
- Ticket を単なる issue tracker clone にすること。
|
||||
- Memory を Ticket/Run audit log の代替にすること。
|
||||
- Web UI のために core authority を二重化すること。
|
||||
- hidden server state を LLM context に直接注入すること。
|
||||
- multi-tenant auth/billing/secret/security を shortcut して実装すること。
|
||||
|
||||
## Success criteria / exit conditions
|
||||
|
||||
- Workspace / Repository / RepositoryPoint / Execution Workspace / Runner / Control Plane / Run / Ticket / Memory / Knowledge の境界が文書化されている。
|
||||
- Ticket が team coordination record として、target selector / Run / Artifact / Actor / Permission / Audit と分離された model を持つ。
|
||||
- `.yoi` local backend は compatibility/local backend として整理され、server-side canonical backend の設計を阻害しない。
|
||||
- Web UI/API が Ticket / Objective / Runner state を中心とした read-only view を提供できる設計または MVP を持つ。Memory / Knowledge は既存 record の表示または将来 placeholder に留め、本格再設計をこの段階の必須条件にしない。
|
||||
- Control plane から local runner に対して、現在のローカル管理画面相当の安全な操作を実行できる design/protocol がある。
|
||||
- Git Repository root に依存しない Workspace model があり、Git Repository は Repository provider の一種として扱われている。
|
||||
- Ticket と Objective は Workspace 配下に平たく存在し、Repository への所属ではなく target selector / scope hint で対象を表現する。
|
||||
- Git worktree 相当は Execution Workspace materialization strategy として扱われ、Run が immutable な RepositoryPoint を記録する。
|
||||
- Memory / Knowledge は Ticket / Run / Artifact の authority を置き換えない record として platform contract だけを持つ。本格的な意味論・抽出・承認・検索・staleness 処理は、Memory の保存先を Workspace backend / control plane record に移すタイミングで回収する。
|
||||
- Hosted runner / resource allocation / SaaS offering に進むための後続 Ticket が切れる状態になっている。
|
||||
- 既存 local dogfooding runtime を壊さず、local use と remote-capable architecture が両立している。
|
||||
|
||||
## Decision context
|
||||
|
||||
- Yoi は hosted Git tool ではなく、team workspace control plane + execution environment として設計する。
|
||||
- Team-space の長期 canonical authority は server-side control plane に置く。local `.yoi` は互換/local/offline/export/import surface だが、multi-user SaaS の正本ではない。
|
||||
- 実行環境と管理システムは弱結合にする。まず管理システムを独立させ、local runner を実行環境として接続する。その後に remote/self-hosted/hosted runner fleet へ進む。
|
||||
- Web frontend を最初の primary team UI とする。Desktop app は web/control-plane model が安定した後に検討する。
|
||||
- Git は重要な Repository provider / materialization backend として使うが、Workspace identity と authority を Git Repository root に固定しない。
|
||||
- Ticket と Objective は Workspace 配下に平たく持つ。対象コードベースや ref は Repository target selector として表現し、Run が concrete RepositoryPoint に解決する。
|
||||
- Memory の本格再設計は後回しにする。先に Workspace / Ticket / Repository / Host/Worker live view / Control plane の基盤を固め、Memory の保存先を Workspace backend に移すタイミングで、意味論・抽出・承認・検索・staleness 処理をまとめて回収する。
|
||||
- Worker の一元管理・データ永続化・アーカイブも後続設計に回す。初期 DB では Worker を Pod metadata の代替として永続化せず、live view と Ticket-linked WorkerRef 記録に留める。
|
||||
@@ -0,0 +1,268 @@
|
||||
---
|
||||
title: "効果的な Memory システム設計・検証"
|
||||
state: "active"
|
||||
created_at: "2026-06-20T15:16:00Z"
|
||||
updated_at: "2026-06-20T15:16:00Z"
|
||||
linked_tickets: ["00001KSKBPHRG", "00001KT02TCCG", "00001KTGCAFXG", "00001KSKBPTHR"]
|
||||
---
|
||||
|
||||
## Goal
|
||||
|
||||
Yoi の Memory / Knowledge / generated memory / resident context / retrieval / usage metrics を、実際の開発・設計・レビュー・オーケストレーションに効く sensemaking substrate として再設計・検証する。
|
||||
|
||||
この Objective でいう「効果的な Memory システム」は、単に多く保存する仕組みではなく、作業中の問いに対して relevant material を集め、根拠を検証可能にし、再表現・仮説形成・反証探索・意思決定・成果物への反映を低コストにする仕組みである。
|
||||
|
||||
暫定的な定義:
|
||||
|
||||
- foraging cost を下げる: Ticket / Objective / current question に対して、関連する memory / docs / tickets / session evidence / code references を探しやすい。
|
||||
- evidence を失わない: Memory が authority そのものにならず、Ticket / docs / git history / session logs / user instruction への検証可能な入口になる。
|
||||
- schema 化を支援する: raw summary ではなく、subsystem、invariant、risk、authority boundary、open question、rejected alternative、hypothesis など推論しやすい形へ再表現できる。
|
||||
- hypothesis loop を支援する: 支持証拠だけでなく、代替仮説・棄却理由・反証 evidence・stale assumption を扱える。
|
||||
- product に戻る: Memory に保存して終わりではなく、Ticket、review、docs、implementation、decision、report に影響を戻せる。
|
||||
- stale / contradiction を扱う: 古い前提、矛盾、適用範囲外の memory を検出・降格・更新できる。
|
||||
- usage を成果基準で測る: resident exposure や read count ではなく、判断・レビュー・実装・docs に効いたかを観測できる。
|
||||
|
||||
## Motivation / background
|
||||
|
||||
現在の Memory システムは「墓場化」している。保存された情報はあるが、後続の作業で自然に使われにくく、使われたとしても根拠・適用範囲・鮮度・反証可能性が弱い。結果として Memory は、作業場ではなく古い結論の倉庫になりやすい。
|
||||
|
||||
Pirolli & Card 2005 の sensemaking model では、分析作業は単なる保存ではなく、次の変換として捉えられる。
|
||||
|
||||
```text
|
||||
external data sources
|
||||
-> shoebox
|
||||
-> evidence file
|
||||
-> schema / representation
|
||||
-> hypotheses
|
||||
-> presentation / product
|
||||
```
|
||||
|
||||
Yoi の現行 Memory は、この流れのうち「保存」と「一部の検索」には対応しているが、少なくとも以下が弱い。
|
||||
|
||||
- Ticket / task / question ごとの shoebox がない。
|
||||
- shoebox から evidence snippets を切り出し、source / provenance / applicability / confidence と共に扱う evidence file がない。
|
||||
- `summary`, `decision`, `request`, `knowledge` は storage taxonomy であり、sensemaking 用 schema としては粗い。
|
||||
- decision は残るが、hypothesis space、alternative、rejected reason、disconfirming evidence が残りにくい。
|
||||
- reviewer / orchestrator が confirmation bias を避けるための反証探索導線が弱い。
|
||||
- resident exposure と explicit retrieval は観測できても、Memory が product に効いたかは測りにくい。
|
||||
|
||||
この Objective は、Memory 関連の設計・検証・検討・考察を一元化し、個別 Ticket がばらばらに storage、prompt、retrieval、metrics を改善して再び墓場を増やすことを防ぐための判断背景である。
|
||||
|
||||
## Strategy / design direction
|
||||
|
||||
Memory を「長期保存領域」ではなく、Yoi の multi-agent 開発における sensemaking loop の支援機構として設計する。
|
||||
|
||||
### 1. Pirolli & Card の stage に合わせて責務を分ける
|
||||
|
||||
- external data sources: Tickets、docs、git history、session logs、reports、code、user instructions。
|
||||
- shoebox: 特定 Ticket / Objective / design question に対して関連しそうな材料を集めた task-bound working set。
|
||||
- evidence file: shoebox から抜き出した根拠 snippet。source anchor、支持/反証、適用範囲、confidence、staleness を持つ。
|
||||
- schema / representation: subsystem、invariant、risk、authority boundary、open question、hypothesis、alternative、contradiction など、推論しやすい再表現。
|
||||
- hypotheses: 採用前の設計仮説、代替案、棄却条件、反証 evidence。
|
||||
- product: Ticket、review、docs、implementation、decision、report、orchestration plan などの成果物。
|
||||
|
||||
### 2. 最初の重点は task-bound shoebox と evidence file
|
||||
|
||||
Memory 墓場化の最初の原因は、保存情報が現在の問いに集まらないことである。まずは Orchestrator / Intake / Reviewer が Ticket を扱う時に、関連 memory / docs / tickets / reports / prior decisions を shoebox として束ねる導線を作る。
|
||||
|
||||
この段階では大きな永続 schema 追加に飛びつかず、report / Ticket artifact / bounded generated context として検証してよい。
|
||||
|
||||
### 3. Memory を authority にしない
|
||||
|
||||
Memory は Ticket、docs、git history、session logs、user instruction の代替ではない。Memory は authority record への evidence index / schema / reasoning aid として扱う。
|
||||
|
||||
したがって、改善案は次の性質を持つべきである。
|
||||
|
||||
- source / provenance を辿れる。
|
||||
- stale / superseded / contradicted を扱える。
|
||||
- Memory の断定をそのまま authority として使わない。
|
||||
- Ticket body/thread/artifacts を読まずに Objective や Memory だけで実装判断できる状態を作らない。
|
||||
|
||||
### 4. 反証探索を first-class にする
|
||||
|
||||
より効果的な Memory は、過去方針を思い出すだけでなく、現在案を疑うために使える必要がある。
|
||||
|
||||
Reviewer / Orchestrator / Intake の導線では、次を探せるようにする。
|
||||
|
||||
- supporting evidence
|
||||
- contradicting evidence
|
||||
- stale decisions
|
||||
- rejected alternatives
|
||||
- unresolved questions
|
||||
- authority boundary risks
|
||||
- prior failures / reports
|
||||
|
||||
### 5. Metrics は exposure から product impact へ寄せる
|
||||
|
||||
Memory が prompt に入った、または query されたことは成功ではない。評価は次を区別する。
|
||||
|
||||
- resident exposure
|
||||
- explicit retrieval
|
||||
- cited in response
|
||||
- cited in Ticket / review / report
|
||||
- changed requirement
|
||||
- changed implementation
|
||||
- contradicted / invalidated
|
||||
- led to docs or decision update
|
||||
|
||||
### 6. 後続 Ticket は concrete slice に分割する
|
||||
|
||||
この Objective は中期的な設計・検証の一元化 record であり、umbrella Ticket ではない。実装や調査は、単独で実装・レビュー・close できる concrete Ticket に分割する。
|
||||
|
||||
候補 slice:
|
||||
|
||||
- Memory sensemaking 分析 report を `docs/report/` に作る。
|
||||
- Ticket routing 用 Memory shoebox artifact を試作する。
|
||||
- evidence snippet schema / source resolver を設計する。
|
||||
- hypothesis / rejected alternative / disconfirming evidence の表現を追加する。
|
||||
- Reviewer workflow に反証探索を入れる。
|
||||
- Memory usage metrics を product impact oriented に拡張する。
|
||||
- stale / contradiction / renewal の検出・表示を設計する。
|
||||
|
||||
## Success criteria / exit conditions
|
||||
|
||||
- Memory システムの目的が「保存」ではなく「sensemaking loop 支援」として project records / docs / prompts / workflows で一貫して説明されている。
|
||||
- Pirolli & Card の `shoebox -> evidence file -> schema -> hypotheses -> product` に対応する Yoi 内の責務と非責務が整理されている。
|
||||
- Ticket / Objective / docs / session logs / Memory / Knowledge の authority boundary が明確で、Memory が authority を僭称しない。
|
||||
- 少なくとも一つの実作業 routing / review / design analysis で、task-bound shoebox または evidence file が生成・利用され、作業品質にどう効いたかが確認されている。
|
||||
- Memory records または関連 artifacts が source / provenance / applicability / staleness / supports-or-refutes のいずれかを扱えるようになっている。
|
||||
- Reviewer / Orchestrator が supporting evidence だけでなく、contradicting evidence / stale assumptions / rejected alternatives を探す導線を持っている。
|
||||
- Memory usage metrics が resident exposure と product impact を区別している。
|
||||
- 古い Memory が放置されるのではなく、stale / superseded / contradicted / needs-review として扱える方針がある。
|
||||
- 後続の実装 Ticket が concrete slice として分割され、Objective が Ticket dependency や進捗 container として使われていない。
|
||||
|
||||
この Objective は、Memory が少なくとも一つの中規模設計・実装・レビュー作業で「関連情報を見つける」「根拠を確認する」「代替案/反証を検討する」「成果物へ反映する」流れを実証し、その設計方針が docs / workflows / metrics に反映された時点で `done` を検討できる。
|
||||
|
||||
## Decision context
|
||||
|
||||
- ユーザー指摘: 「Memoryシステムが完全に墓場化している」。これは保存量不足ではなく、保存情報が現在の問い・根拠・仮説・成果物に接続されない問題として扱う。
|
||||
- ユーザー指示: Memory システムの設計・検証・検討・考察を Objective にまとめ、より効果的な Memory システムを作成する目標のもとで情報を一元化する。
|
||||
- 「効果的」の定義は未確定だが、当面は Pirolli & Card の sensemaking process に沿って、foraging cost、evidence quality、schema usefulness、hypothesis/disconfirmation support、product impact、staleness handling を評価軸にする。
|
||||
- Memory は durable project authority ではない。Ticket、docs、git history、session logs、明示 user instruction の代替として使わない。
|
||||
- Objective context は判断背景であり、個別実装の authority は各 Ticket body/thread/artifacts と明示的な Ticket relations / OrchestrationPlan records にある。
|
||||
- `history` に残らない context-only injection を改善案にしない。新しい context input は history に commit する原則を守る。
|
||||
- Knowledge は単なる長期保存ではなく、再利用可能な schema / model / procedure / invariant として再検討する余地がある。
|
||||
- Generated memory / curated Knowledge / Ticket / docs / report の境界を再定義する場合は、authority boundary と migration/staleness を明示する。
|
||||
- 関連する既存 Ticket:
|
||||
- `00001KSKBPHRG` — Prompt / Workflow 評価メトリクスと改善 Offer
|
||||
- `00001KT02TCCG` — Memory prompt: conditional guidance and proactive lookup
|
||||
- `00001KTGCAFXG` — Use .yoi/memory marker for repo-local memory root
|
||||
- `00001KSKBPTHR` — ワークスペースのメモリーをLintするヘッドレスCLI
|
||||
|
||||
## Historical references / prior design sources
|
||||
|
||||
現在の Memory システムの初期設計時には、Codex Memories / Chronicle と HermesAgent を明示的な参考事例として調査していた。関連する調査・設計記録は、現在は主に以下に退避されている。
|
||||
|
||||
- `docs/.local/old-docs/ref/memory-systems.md`
|
||||
- `docs/.local/old-docs/plan/memory.md`
|
||||
- 初期設計 commit: `ca5a3d11` — `2026-04-21 メモリシステムの設計`
|
||||
- 関連 commit:
|
||||
- `0c1276b7` — `Memoryシステムの整理・Promptカタログチケット`
|
||||
- `3d04f793` — `memoryを抽出する仕組みの実装`
|
||||
- `f1b7af62` — `docs: memoryシステムの仕様変更と、動的Tool・VCSの話`
|
||||
- `a2aecbf0` — `update: memoryシステムの"Phase"表記を撤廃`
|
||||
|
||||
### Codex Memories / Chronicle から得た設計要素
|
||||
|
||||
旧設計では、Codex Memories / Chronicle を `extract -> staging -> consolidation -> durable Markdown memory` の非同期パイプラインとして捉えていた。
|
||||
|
||||
主な参照点:
|
||||
|
||||
- extract と consolidation の 2 段構成。
|
||||
- extract は JSON schema / structured output で分類ブレを抑える。
|
||||
- consolidation は reasoning model / agentic rewrite によって、既存 memory と staging entries を統合・整理する。
|
||||
- staging と durable memory を分ける。
|
||||
- `MEMORY.md` は retrieval-oriented handbook として扱う。
|
||||
- `memory_summary.md` は prompt-loaded high-signal context として扱う。
|
||||
- `raw_memories.md` は routing layer / task inventory 的な中間層として扱う。
|
||||
- workspace diff や usage 情報を使い、stale / deleted evidence / noisy entries を整理する。
|
||||
- consolidation は append だけでなく、rewrite / merge / split / trim / drop / cleanup を担う。
|
||||
|
||||
Yoi 初期設計では、これを参考に以下を意図していた。
|
||||
|
||||
- activity token 閾値で extract を発火する。
|
||||
- compact より前に session log range を抽出する。
|
||||
- extract は `decisions`, `discussions`, `attempts`, `requests` などの候補を staging に保存する。
|
||||
- 抽出時点では Knowledge 化せず、純粋な「起きたこと」に寄せる。
|
||||
- consolidation が summary / decisions / requests / knowledge candidates を整理する。
|
||||
- consolidation 入力に linter warnings / usage metrics / Knowledge 化候補を含める。
|
||||
- stale / superseded / unused / noisy な情報を整理する。
|
||||
|
||||
この Objective での再解釈:
|
||||
|
||||
- Codex の `raw_memories.md` は、Pirolli & Card の sensemaking model では `shoebox` または `evidence file` に近い。
|
||||
- Yoi は extract / consolidation という pipeline だけを継承しても不十分であり、task-bound shoebox / evidence file / hypothesis loop / product feedback がなければ Memory は再び墓場化する。
|
||||
- 特に、staging を consolidation の一時入力としてだけ扱うと、後続 Ticket / Objective / review が使う探索入口にならない。
|
||||
- Yoi では `raw memories` 相当の中間層を、現在の問いに紐づく working set / evidence index として再設計する必要がある。
|
||||
|
||||
### HermesAgent から得た設計要素
|
||||
|
||||
旧設計では、Nous Research HermesAgent を 3 層の memory system として整理していた。
|
||||
|
||||
- Persistent Memory:
|
||||
- `MEMORY.md` / `USER.md`
|
||||
- Markdown + SQLite / FTS5 session search
|
||||
- 起動時 system prompt snapshot
|
||||
- bounded character limits
|
||||
- Skill Library:
|
||||
- procedural memory
|
||||
- `~/.hermes/skills/<name>/SKILL.md`
|
||||
- `skill_manage` tool による agentic CRUD
|
||||
- User Model / Honcho:
|
||||
- dialectic user modeling
|
||||
- 外部 service 連携
|
||||
|
||||
HermesAgent で特に重要だった点:
|
||||
|
||||
- memory / skill review は一定 turn / tool iteration ごとに background agent として起動する。
|
||||
- 保存すべきものがなければ `Nothing to save.` で NOP として終了する。
|
||||
- Yoi extract の「空配列許容」はこの設計からも影響を受けている。
|
||||
- memory は session start 時の frozen snapshot として system prompt に入り、mid-session write で prompt cache を壊さない。
|
||||
- persistent memory は bounded で、limit 超過時は deterministic eviction ではなく、agent に replace / remove を促す。
|
||||
- procedural memory / skills は一般 memory から分離されている。
|
||||
- SQLite FTS5 + LLM summarization による cross-session recall がある。
|
||||
|
||||
この Objective での再解釈:
|
||||
|
||||
- HermesAgent の `MEMORY.md` / `USER.md` / `skills` の分離は、Yoi の Knowledge / Workflow / prompt resource / docs / Ticket decision / generated memory の責務再整理に使える。
|
||||
- reusable procedure, reviewer focus, orchestration tactic, project preference, user preference, design invariant を同じ Memory bucket に入れると墓場化しやすい。
|
||||
- `Nothing to save.` / empty extraction allowed は重要だが、保存抑制だけでは効果的な Memory にはならない。保存されたものが task-bound shoebox / evidence / schema / hypothesis / product に接続される必要がある。
|
||||
- frozen snapshot / prompt cache 配慮は Yoi の history/context 加工原則と整合するが、それだけでは retrieval / resurfacing / disconfirmation は解決しない。
|
||||
|
||||
### Lessons for the next design iteration
|
||||
|
||||
Codex と HermesAgent の調査から、Yoi が継承すべきものと、継承するだけでは足りないものを分ける。
|
||||
|
||||
継承すべきもの:
|
||||
|
||||
- structured extract と agentic consolidation の分離。
|
||||
- staging / raw memories / durable memory の分離。
|
||||
- 保存対象がなければ NOP にする発火設計。
|
||||
- prompt-loaded summary と durable retrieval-oriented memory の分離。
|
||||
- stale / noisy / unused entries の cleanup。
|
||||
- procedural memory と declarative memory の分離。
|
||||
- session search / usage metrics / linter feedback を consolidation に入れる設計。
|
||||
|
||||
足りないもの:
|
||||
|
||||
- Pirolli & Card の sensemaking stage における各 record の役割定義。
|
||||
- Ticket / Objective / current question に紐づく task-bound shoebox。
|
||||
- authority record へ戻れる evidence file / provenance / source anchor。
|
||||
- hypothesis, alternative hypothesis, rejected reason, disconfirming evidence の first-class 表現。
|
||||
- reviewer / orchestrator が confirmation bias を避けるための反証探索導線。
|
||||
- resident exposure や read count ではなく product impact を測る metrics。
|
||||
- stale / contradiction / renewal を作業中に resurfacing する導線。
|
||||
|
||||
したがって、次の Memory 設計は Codex / HermesAgent の単純なコピーではなく、以下を満たす必要がある。
|
||||
|
||||
```text
|
||||
external data / sessions / tickets / docs / code
|
||||
-> task-bound shoebox
|
||||
-> evidence file with provenance
|
||||
-> schema / representation
|
||||
-> hypotheses and disconfirmation
|
||||
-> Ticket / review / docs / implementation / decision product
|
||||
-> product impact and stale-feedback metrics
|
||||
```
|
||||
|
||||
この Objective では、以後の Memory 関連 Ticket / report / implementation をこの historical reference と sensemaking model の両方に照らして判断する。
|
||||
@@ -1,8 +1,8 @@
|
||||
---
|
||||
title: "Pod: 任意ターンからの Fork(複数ターン巻き戻し)"
|
||||
state: "planning"
|
||||
state: 'closed'
|
||||
created_at: "2026-05-27T00:00:09Z"
|
||||
updated_at: "2026-05-27T00:00:09Z"
|
||||
updated_at: '2026-06-20T16:31:29Z'
|
||||
---
|
||||
|
||||
## Migration reference
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
Closed as no longer needed. Arbitrary-turn Pod/session fork and multi-turn rewind are not part of the current desired workflow; current restore/rewind/fork behavior is sufficient for active use, and future history editing should be reopened as a narrower current-runtime design if needed.
|
||||
@@ -4,4 +4,22 @@
|
||||
|
||||
Migrated from tickets/pod-session-fork.md. No legacy review file was present at migration time.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-20T16:31:28Z from: planning to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-20T16:31:29Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Closed as no longer needed. Arbitrary-turn Pod/session fork and multi-turn rewind are not part of the current desired workflow; current restore/rewind/fork behavior is sufficient for active use, and future history editing should be reopened as a narrower current-runtime design if needed.
|
||||
|
||||
|
||||
---
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
---
|
||||
title: "Prompt / Workflow 評価メトリクスと改善 Offer"
|
||||
state: "planning"
|
||||
state: 'closed'
|
||||
created_at: "2026-05-27T00:00:10Z"
|
||||
updated_at: "2026-05-27T00:00:10Z"
|
||||
updated_at: '2026-06-20T16:31:29Z'
|
||||
---
|
||||
|
||||
## Migration reference
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
Closed as superseded/no longer needed. Workflow evaluation metrics and improvement planning have moved under the newer Memory redesign / team-workspace memory objectives, so this old prompt/workflow metrics ticket should not remain as a standalone planning item.
|
||||
@@ -4,4 +4,22 @@
|
||||
|
||||
Migrated from tickets/prompt-eval-metrics.md. No legacy review file was present at migration time.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-20T16:31:29Z from: planning to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-20T16:31:29Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Closed as superseded/no longer needed. Workflow evaluation metrics and improvement planning have moved under the newer Memory redesign / team-workspace memory objectives, so this old prompt/workflow metrics ticket should not remain as a standalone planning item.
|
||||
|
||||
|
||||
---
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
---
|
||||
title: "TUI: navigation mode / block focus の設計"
|
||||
state: "planning"
|
||||
state: 'closed'
|
||||
created_at: "2026-05-27T00:00:15Z"
|
||||
updated_at: "2026-05-27T00:00:15Z"
|
||||
updated_at: '2026-06-20T16:31:29Z'
|
||||
---
|
||||
|
||||
## Migration reference
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
Closed as no longer needed. The current TUI navigation/block-focus behavior is satisfactory, so the older navigation-mode design ticket is obsolete.
|
||||
@@ -4,4 +4,22 @@
|
||||
|
||||
Migrated from tickets/tui-navigation-mode-design.md. No legacy review file was present at migration time.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-20T16:31:29Z from: planning to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-20T16:31:29Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Closed as no longer needed. The current TUI navigation/block-focus behavior is satisfactory, so the older navigation-mode design ticket is obsolete.
|
||||
|
||||
|
||||
---
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
---
|
||||
title: "Audit crate responsibility boundaries"
|
||||
state: "planning"
|
||||
state: 'closed'
|
||||
created_at: "2026-05-28T13:13:17Z"
|
||||
updated_at: "2026-05-28T13:13:17Z"
|
||||
updated_at: '2026-06-20T16:45:54Z'
|
||||
---
|
||||
|
||||
## Background
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
Closed as completed. The crate responsibility boundary audit was already performed and recorded in artifacts/audit.md with concrete findings; any implementation cleanup should be handled by narrower follow-up tickets.
|
||||
@@ -4,4 +4,22 @@
|
||||
|
||||
Created by tickets.sh create.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-20T16:45:54Z from: planning to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-20T16:45:54Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Closed as completed. The crate responsibility boundary audit was already performed and recorded in artifacts/audit.md with concrete findings; any implementation cleanup should be handled by narrower follow-up tickets.
|
||||
|
||||
|
||||
---
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
---
|
||||
title: 'Plugin: define runtime, surface, and minimal host API model'
|
||||
state: 'planning'
|
||||
state: 'closed'
|
||||
created_at: '2026-05-31T01:00:05Z'
|
||||
updated_at: '2026-06-14T17:22:23Z'
|
||||
updated_at: '2026-06-19T13:29:26Z'
|
||||
assignee: null
|
||||
---
|
||||
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
Closed as superseded by durable Objective and design documentation.
|
||||
|
||||
This Ticket was a broad Plugin runtime/surface/host API design record rather than a concrete implementation task. The useful design decisions have been moved into durable roadmap/design context:
|
||||
- Objective `00001KVG0HR9M` (`Plugin platform roadmap`) now owns the overall Plugin roadmap and sequencing context.
|
||||
- `docs/design/plugin-component-model.md` records Component Model research and migration direction.
|
||||
- `docs/design/plugin-packages.md` records package/runtime metadata direction.
|
||||
|
||||
Concrete implementation work remains tracked by implementation Tickets such as package discovery, Tool registration, WASM runtime, permission grants, CLI inspection, `https`, `fs`, and Component Model runtime migration. Future Plugin work should be filed as concrete implementation Tickets, not broad design umbrella Tickets.
|
||||
@@ -99,4 +99,29 @@ This preserves the desired detachable shape: feature state remains in the featur
|
||||
- General-purpose host API は引き続き `https` と `fs` に絞る。`ingress.submit` と `diagnostics` は surface-intrinsic host calls として扱い、広い ambient capability にはしない。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-19T13:29:26Z from: planning to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-19T13:29:26Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Closed as superseded by durable Objective and design documentation.
|
||||
|
||||
This Ticket was a broad Plugin runtime/surface/host API design record rather than a concrete implementation task. The useful design decisions have been moved into durable roadmap/design context:
|
||||
- Objective `00001KVG0HR9M` (`Plugin platform roadmap`) now owns the overall Plugin roadmap and sequencing context.
|
||||
- `docs/design/plugin-component-model.md` records Component Model research and migration direction.
|
||||
- `docs/design/plugin-packages.md` records package/runtime metadata direction.
|
||||
|
||||
Concrete implementation work remains tracked by implementation Tickets such as package discovery, Tool registration, WASM runtime, permission grants, CLI inspection, `https`, `fs`, and Component Model runtime migration. Future Plugin work should be filed as concrete implementation Tickets, not broad design umbrella Tickets.
|
||||
|
||||
|
||||
---
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
---
|
||||
title: "Audit external dependencies and license posture"
|
||||
state: "planning"
|
||||
state: 'closed'
|
||||
created_at: "2026-06-01T12:36:41Z"
|
||||
updated_at: "2026-06-01T13:08:45Z"
|
||||
updated_at: '2026-06-20T16:45:54Z'
|
||||
---
|
||||
|
||||
## Background
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
Closed as completed. The dependency/license audit was already performed and recorded in artifacts/audit-report.md with implementation report evidence; any dependency cleanup or third-party notice work should be tracked by narrower follow-up tickets.
|
||||
@@ -418,4 +418,22 @@ Interpretation:
|
||||
- Acceptance: compare current `html5ever`/`RcDom` extractor with viable maintained alternatives; preserve bounded, safe, link-aware extraction behavior; only proceed if measurable binary/build-time benefit exists.
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-20T16:45:54Z from: planning to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-20T16:45:54Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Closed as completed. The dependency/license audit was already performed and recorded in artifacts/audit-report.md with implementation report evidence; any dependency cleanup or third-party notice work should be tracked by narrower follow-up tickets.
|
||||
|
||||
|
||||
---
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
---
|
||||
title: "Improve Pod notification injection guidance"
|
||||
state: "planning"
|
||||
state: 'closed'
|
||||
created_at: "2026-06-07T07:33:13Z"
|
||||
updated_at: "2026-06-07T07:33:13Z"
|
||||
updated_at: '2026-06-20T16:23:37Z'
|
||||
---
|
||||
|
||||
## Background
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
Closed as stale/currently not needed. Orchestrator role/profile/workflow notification guidance has since improved, and the broad planning issue is not currently reproducing. If similar notification-as-user-turn confusion recurs in default profiles or generic notification wrappers, create a narrower ticket against the current prompt/profile state.
|
||||
@@ -4,4 +4,39 @@
|
||||
|
||||
Created by LocalTicketBackend create.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: decision author: intake at: 2026-06-20T16:20:17Z -->
|
||||
|
||||
## Decision
|
||||
|
||||
ユーザー判断により、この Ticket は一旦 close 推奨とする。
|
||||
|
||||
理由:
|
||||
- Ticket 作成後に Orchestrator profile / role prompt / workflow guidance の改善が複数回入っている。
|
||||
- 現在の明示的な Orchestrator role では、通知を user request と誤認しているケースを最近見かけていない。
|
||||
- default profile では同種の誤認がまだ起き得る可能性はあるが、現時点でこの broad な planning Ticket を残しておくほどの実害・優先度は確認されていない。
|
||||
|
||||
判断:
|
||||
- この Ticket は stale / currently not needed として close してよい。
|
||||
- 将来 default profile や generic notify_wrapper で同じ問題が再発した場合は、現在の prompt/profile 状態を前提に、より狭い concrete Ticket として切り直す。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-20T16:23:37Z from: planning to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-20T16:23:37Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Closed as stale/currently not needed. Orchestrator role/profile/workflow notification guidance has since improved, and the broad planning issue is not currently reproducing. If similar notification-as-user-turn confusion recurs in default profiles or generic notification wrappers, create a narrower ticket against the current prompt/profile state.
|
||||
|
||||
|
||||
---
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
---
|
||||
title: 'Implement MCP 2025-11-25 local stdio server-feature bridge'
|
||||
state: 'planning'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-10T07:48:49Z'
|
||||
updated_at: '2026-06-13T15:29:21Z'
|
||||
updated_at: '2026-06-20T05:33:15Z'
|
||||
assignee: null
|
||||
readiness: 'blocked'
|
||||
risk_flags: ['mcp', 'prompt-context', 'permission-scope', 'secrets', 'process-exec', 'feature-api', 'trust-boundary']
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
Closed as superseded by concrete MCP implementation Tickets.
|
||||
|
||||
This Ticket bundled config/trust policy, stdio lifecycle, tools/list registration, tools/call execution, resources/prompts operations, result serialization, and list_changed handling into one broad implementation item. That is too coarse for the current Ticket policy: Tickets should be concrete implementation tasks.
|
||||
|
||||
The MCP roadmap now lives in Objective `00001KTR80WMN` (`MCP local stdio integration roadmap`). Concrete follow-up Tickets are:
|
||||
- `00001KVHR3WRF` — local stdio server config and trust policy;
|
||||
- `00001KVHR3WRY` — stdio JSON-RPC lifecycle client;
|
||||
- `00001KVHR3WS6` — server tools registration into ToolRegistry;
|
||||
- `00001KVHR3WSD` — tools/call execution through ordinary Tool path;
|
||||
- `00001KVHR3WSN` — resources/prompts as explicit tool operations;
|
||||
- `00001KVHR3WSW` — list_changed notification handling.
|
||||
|
||||
Future MCP work should use those concrete Tickets or similarly scoped follow-ups, not this broad umbrella Ticket.
|
||||
@@ -22,4 +22,34 @@ LocalTicketBackend によって作成されました。
|
||||
- `00001KSXRQ4G8` と `00001KT0Z4BK8` は Plugin permission を Plugin layer として扱い、MCP を初期 Plugin packaging/runtime から分離する。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-20T05:33:15Z from: planning to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-20T05:33:15Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Closed as superseded by concrete MCP implementation Tickets.
|
||||
|
||||
This Ticket bundled config/trust policy, stdio lifecycle, tools/list registration, tools/call execution, resources/prompts operations, result serialization, and list_changed handling into one broad implementation item. That is too coarse for the current Ticket policy: Tickets should be concrete implementation tasks.
|
||||
|
||||
The MCP roadmap now lives in Objective `00001KTR80WMN` (`MCP local stdio integration roadmap`). Concrete follow-up Tickets are:
|
||||
- `00001KVHR3WRF` — local stdio server config and trust policy;
|
||||
- `00001KVHR3WRY` — stdio JSON-RPC lifecycle client;
|
||||
- `00001KVHR3WS6` — server tools registration into ToolRegistry;
|
||||
- `00001KVHR3WSD` — tools/call execution through ordinary Tool path;
|
||||
- `00001KVHR3WSN` — resources/prompts as explicit tool operations;
|
||||
- `00001KVHR3WSW` — list_changed notification handling.
|
||||
|
||||
Future MCP work should use those concrete Tickets or similarly scoped follow-ups, not this broad umbrella Ticket.
|
||||
|
||||
|
||||
---
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
---
|
||||
title: 'Panel 起動遅延の待ち要因を E2E 計測で特定し改善する'
|
||||
state: 'done'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-15T12:40:33Z'
|
||||
updated_at: '2026-06-15T14:31:28Z'
|
||||
updated_at: '2026-06-19T05:44:09Z'
|
||||
assignee: null
|
||||
readiness: 'implementation_ready'
|
||||
risk_flags: ['panel', 'tui', 'e2e', 'latency', 'runtime-observation']
|
||||
|
||||
@@ -0,0 +1,9 @@
|
||||
Closed as completed by the subsequent Panel startup E2E and latency-improvement sequence.
|
||||
|
||||
The initial work separated first visible frame readiness from background reload, but later review showed that user-visible startup latency must be measured at dashboard content-ready, not first frame or single-row readiness. The later Tickets added dashboard snapshot readiness, shell-enter launch-path coverage, live workspace measurements, and the actual startup fix for duplicate Pod probes/session-log scans.
|
||||
|
||||
Relevant follow-ups:
|
||||
- 00001KV62PF32: corrected readiness away from first frame / weak row count;
|
||||
- 00001KVDETSN6: dashboard content-ready snapshot metric;
|
||||
- 00001KVDQH839: shell-enter launch-path measurement;
|
||||
- 00001KVF0ZJM5: fixed live startup by reusing initial Pod list presence and avoiding session-log reads before first rows.
|
||||
@@ -215,4 +215,30 @@ Cleanup planned:
|
||||
|
||||
Reviewer approved, implementation/evidence branch merged into the orchestration branch, and E2E-focused validation passed in the Orchestrator worktree. Marking Ticket done in the orchestration branch.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-19T05:44:09Z from: done to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-19T05:44:09Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Closed as completed by the subsequent Panel startup E2E and latency-improvement sequence.
|
||||
|
||||
The initial work separated first visible frame readiness from background reload, but later review showed that user-visible startup latency must be measured at dashboard content-ready, not first frame or single-row readiness. The later Tickets added dashboard snapshot readiness, shell-enter launch-path coverage, live workspace measurements, and the actual startup fix for duplicate Pod probes/session-log scans.
|
||||
|
||||
Relevant follow-ups:
|
||||
- 00001KV62PF32: corrected readiness away from first frame / weak row count;
|
||||
- 00001KVDETSN6: dashboard content-ready snapshot metric;
|
||||
- 00001KVDQH839: shell-enter launch-path measurement;
|
||||
- 00001KVF0ZJM5: fixed live startup by reusing initial Pod list presence and avoiding session-log reads before first rows.
|
||||
|
||||
|
||||
---
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
---
|
||||
title: 'Panel startup latency E2E を一覧データ描画完了基準に修正する'
|
||||
state: 'done'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-15T16:44:06Z'
|
||||
updated_at: '2026-06-18T13:30:51Z'
|
||||
updated_at: '2026-06-19T05:44:09Z'
|
||||
assignee: null
|
||||
readiness: 'implementation_ready'
|
||||
risk_flags: ['panel', 'e2e', 'startup-latency', 'readiness-metric', 'ticket-list-rendering']
|
||||
|
||||
@@ -0,0 +1,8 @@
|
||||
Closed as superseded/completed by the later dashboard content-ready and live startup latency work.
|
||||
|
||||
This Ticket corrected the mistaken premise that first frame readiness represented usable Panel startup readiness, but its single fixture-row rows-ready metric was later judged insufficient for the user-visible delay. Follow-up work strengthened the metric to dashboard content-ready snapshot validation and then used live-path measurements to identify and fix the Pod status probe/session-log startup bottleneck.
|
||||
|
||||
Relevant follow-ups:
|
||||
- 00001KVDETSN6: user-visible dashboard content-ready metric and snapshot validation;
|
||||
- 00001KVDQH839: shell-enter launch-path readiness measurement;
|
||||
- 00001KVF0ZJM5: live startup latency fix by removing duplicate Pod probes and session-log reads from the initial list path.
|
||||
@@ -294,4 +294,29 @@ The current result still does not answer the user-facing latency problem. The pr
|
||||
Do not treat fixture first-frame or single-row readiness numbers as evidence that no improvement is needed. The acceptance criterion must be strengthened to a user-visible dashboard-content-ready point and paired with slow-source attribution/improvement for the live-like Panel startup path.
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-19T05:44:09Z from: done to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-19T05:44:09Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Closed as superseded/completed by the later dashboard content-ready and live startup latency work.
|
||||
|
||||
This Ticket corrected the mistaken premise that first frame readiness represented usable Panel startup readiness, but its single fixture-row rows-ready metric was later judged insufficient for the user-visible delay. Follow-up work strengthened the metric to dashboard content-ready snapshot validation and then used live-path measurements to identify and fix the Pod status probe/session-log startup bottleneck.
|
||||
|
||||
Relevant follow-ups:
|
||||
- 00001KVDETSN6: user-visible dashboard content-ready metric and snapshot validation;
|
||||
- 00001KVDQH839: shell-enter launch-path readiness measurement;
|
||||
- 00001KVF0ZJM5: live startup latency fix by removing duplicate Pod probes and session-log reads from the initial list path.
|
||||
|
||||
|
||||
---
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
---
|
||||
title: 'Orchestrator Ticket event Companion notify の peer registration / diagnostics を修正する'
|
||||
state: 'done'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-18T14:33:09Z'
|
||||
updated_at: '2026-06-18T14:33:50Z'
|
||||
updated_at: '2026-06-19T07:52:14Z'
|
||||
assignee: null
|
||||
readiness: 'implementation_ready'
|
||||
risk_flags: ['orchestrator', 'companion', 'peer-notify', 'ticket-event', 'auto-run-false', 'diagnostics']
|
||||
|
||||
@@ -0,0 +1,3 @@
|
||||
Ticket `00001KVDJCVWZ` (`Orchestrator Ticket event Companion notify の peer registration / diagnostics を修正する`) はすでに `state: done` に到達していたため、workspace Panel から close しました。
|
||||
|
||||
この Close action によって、実装作業、state 変更、Orchestrator/Companion launch、worker invocation は開始されていません。
|
||||
@@ -4,4 +4,24 @@
|
||||
|
||||
LocalTicketBackend によって作成されました。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-19T07:52:14Z from: done to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-19T07:52:14Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Ticket `00001KVDJCVWZ` (`Orchestrator Ticket event Companion notify の peer registration / diagnostics を修正する`) はすでに `state: done` に到達していたため、workspace Panel から close しました。
|
||||
|
||||
この Close action によって、実装作業、state 変更、Orchestrator/Companion launch、worker invocation は開始されていません。
|
||||
|
||||
|
||||
---
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
{
|
||||
"version": 1,
|
||||
"relations": [
|
||||
{
|
||||
"ticket_id": "00001KVDQH839",
|
||||
"kind": "related",
|
||||
"target": "00001KVDETSN6",
|
||||
"note": "Adds shell-enter launch-path coverage on top of dashboard content-ready metric.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-18T16:03:59Z"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,57 @@
|
||||
---
|
||||
title: 'Panel E2E に shell Enter 起動経路の dashboard readiness 計測を追加する'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-18T16:02:56Z'
|
||||
updated_at: '2026-06-19T05:44:09Z'
|
||||
assignee: null
|
||||
readiness: 'implementation_ready'
|
||||
risk_flags: ['panel', 'e2e', 'startup-latency', 'shell-launch', 'dashboard-content-ready']
|
||||
---
|
||||
|
||||
## Background
|
||||
|
||||
既存の Panel dashboard readiness E2E は direct `Command::spawn(yoi panel ...)` から dashboard content ready までを測っていた。ユーザー目線の「Enter した瞬間から実コンテンツが表示されるまで」に近づけるため、isolated fixture は維持しつつ、shell 上で command line を投入して Enter された起動経路を部分的に模した E2E を追加する。
|
||||
|
||||
この Ticket は live workspace の遅延改善そのものではなく、E2E の起動経路を実利用に近づける追加計測である。
|
||||
|
||||
## Requirements
|
||||
|
||||
- PTY 上で `/bin/sh` を起動し、`exec <yoi> panel ...` を command line として送って Enter 相当から測定する。
|
||||
- 測定開始点は command line を PTY に送る直前とする。
|
||||
- dashboard readiness は既存の `dashboard_content_ready` snapshot matcher を使う。
|
||||
- first frame だけ、単一 row だけでは通さない。
|
||||
- Isolated fixture / isolated HOME / XDG dirs / runtime dirs は維持する。
|
||||
- `YOI_POD_RUNTIME_COMMAND` は tested binary を明示して渡す。
|
||||
- Direct spawn E2E は残し、shell-enter path は追加 coverage とする。
|
||||
|
||||
## Implementation summary
|
||||
|
||||
- `PanelHarness::spawn_via_shell_enter` を追加した。
|
||||
- `/bin/sh` を PTY 上で起動。
|
||||
- `exec '<binary>' '<args>'...` を送信。
|
||||
- command line送信直前の `Instant` を返す。
|
||||
- artifacts `run.json` に `launch_mode: shell_enter_exec` を記録。
|
||||
- shell quote helper を追加した。
|
||||
- `panel_dashboard_content_ready_from_shell_enter_path` E2E を追加した。
|
||||
- Enter相当から first frame / dashboard content ready を測定。
|
||||
- expected dashboard snapshot / source breakdown を検証。
|
||||
|
||||
## Validation
|
||||
|
||||
- `cargo test -p yoi-e2e --features e2e --test panel panel_dashboard_content_ready_from_shell_enter_path -- --nocapture`
|
||||
- observed: dashboard content ready 約 `220ms`, first frame 約 `20ms` in isolated fixture。
|
||||
- `cargo test -p yoi-e2e --features e2e --test panel`
|
||||
- `cargo check -p yoi-e2e -p yoi -p tui --features tui/e2e-test`
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check`
|
||||
|
||||
## Non-goals
|
||||
|
||||
- Live workspace startup latency の改善。
|
||||
- Interactive shell の command lookup / user typing latency の完全再現。
|
||||
- User's actual shell rc/profile を読むこと。
|
||||
- Panel architecture / lifecycle の変更。
|
||||
|
||||
## Related work
|
||||
|
||||
- `00001KVDETSN6` — Panel startup latency をユーザー目線の dashboard content ready 基準で計測・改善する。
|
||||
@@ -0,0 +1,10 @@
|
||||
Closed as completed.
|
||||
|
||||
Added E2E coverage for a Panel shell-enter launch path:
|
||||
- PTY starts `/bin/sh` and sends `exec <yoi> panel ...` as the command line;
|
||||
- measurement starts immediately before sending the command line / Enter-equivalent input;
|
||||
- the test waits for the existing dashboard content-ready snapshot rather than first frame or a single row;
|
||||
- isolated HOME/XDG/runtime fixture remains in place and `YOI_POD_RUNTIME_COMMAND` is pinned to the tested binary;
|
||||
- direct-spawn Panel readiness tests remain as separate coverage.
|
||||
|
||||
Validation was recorded during implementation, including the focused shell-enter test, the full Panel E2E test set, relevant cargo check, formatting, diff check, ticket doctor, and Nix build.
|
||||
@@ -0,0 +1,34 @@
|
||||
<!-- event: create author: "yoi ticket" at: 2026-06-18T16:02:56Z -->
|
||||
|
||||
## 作成
|
||||
|
||||
LocalTicketBackend によって作成されました。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-19T05:44:09Z from: done to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-19T05:44:09Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Closed as completed.
|
||||
|
||||
Added E2E coverage for a Panel shell-enter launch path:
|
||||
- PTY starts `/bin/sh` and sends `exec <yoi> panel ...` as the command line;
|
||||
- measurement starts immediately before sending the command line / Enter-equivalent input;
|
||||
- the test waits for the existing dashboard content-ready snapshot rather than first frame or a single row;
|
||||
- isolated HOME/XDG/runtime fixture remains in place and `YOI_POD_RUNTIME_COMMAND` is pinned to the tested binary;
|
||||
- direct-spawn Panel readiness tests remain as separate coverage.
|
||||
|
||||
Validation was recorded during implementation, including the focused shell-enter test, the full Panel E2E test set, relevant cargo check, formatting, diff check, ticket doctor, and Nix build.
|
||||
|
||||
|
||||
---
|
||||
@@ -0,0 +1,21 @@
|
||||
{
|
||||
"version": 1,
|
||||
"relations": [
|
||||
{
|
||||
"ticket_id": "00001KVF0ZJM5",
|
||||
"kind": "related",
|
||||
"target": "00001KVDETSN6",
|
||||
"note": "Implements live startup latency improvement after dashboard content-ready measurement exposed Pod probe bottleneck.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T04:19:09Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVF0ZJM5",
|
||||
"kind": "related",
|
||||
"target": "00001KVDQH839",
|
||||
"note": "Uses shell/live startup measurements added by the E2E launch-path work.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T04:19:09Z"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,43 @@
|
||||
---
|
||||
title: 'Panel startup で Pod status probe を重複実行せず初回一覧表示を高速化する'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-19T04:07:17Z'
|
||||
updated_at: '2026-06-19T04:19:09Z'
|
||||
assignee: null
|
||||
readiness: 'implementation_ready'
|
||||
risk_flags: ['panel', 'startup-latency', 'pod-status-probe', 'live-path', 'performance']
|
||||
---
|
||||
|
||||
## Background
|
||||
|
||||
Live workspace で `yoi panel` を起動すると、first frame は約 50ms で出る一方、実際の Ticket / Pod rows が表示されるまで約 8 秒かかっている。実測 breakdown では `pod_metadata_status_probe.initial`、`companion.presence`、`orchestrator.presence` がそれぞれ約 2.5 秒かかり、同じ Pod metadata / live status scan が初回 dashboard render 前に直列で重複実行されている。
|
||||
|
||||
この Ticket では初回一覧表示前の重複 Pod status probe をなくし、live Pod summary の重い session log scan を避け、ユーザー目線の「一覧が表示されるまで」を短縮する。
|
||||
|
||||
## Requirements
|
||||
|
||||
- `load_multi_pod_snapshot` で初回 `load_pod_list` の結果を Companion / Orchestrator presence 判定に再利用する。
|
||||
- 初回 render 前に `load_exact_companion_pod_presence` / `load_exact_pod_presence` 相当の追加 full probe を直列実行しない。
|
||||
- Live status probe は session log 全読みの preview/summary 作成を初回 path で行わない。
|
||||
- stored metadata summary を優先して使う。
|
||||
- live-only row は minimal live summary でよい。
|
||||
- Companion / Orchestrator spawn/restore が必要な場合の reload は維持する。
|
||||
- Existing Panel behavior を壊さない。
|
||||
- Companion / Orchestrator live status 表示
|
||||
- Queue action
|
||||
- Pod rows open/attach
|
||||
- E2E dashboard readiness
|
||||
- Live workspace に近い例外的計測で、rows 表示までの時間が改善していることを確認する。
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Panel startup source breakdown で `companion.presence` / `orchestrator.presence` が追加 full Pod probe として秒単位で出ない。
|
||||
- Live workspace 計測で first non-empty rows 表示が従来約 8 秒から明確に短縮する。
|
||||
- `cargo test -p yoi-e2e --features e2e --test panel` が通る。
|
||||
- `cargo check -p yoi-e2e -p yoi -p tui --features tui/e2e-test` が通る。
|
||||
- `cargo fmt --check` / `git diff --check` / `target/debug/yoi ticket doctor` が通る。
|
||||
|
||||
## Related work
|
||||
|
||||
- `00001KVDETSN6` — Panel startup latency をユーザー目線の dashboard content ready 基準で計測・改善する。
|
||||
- `00001KVDQH839` — Panel E2E に shell Enter 起動経路の dashboard readiness 計測を追加する。
|
||||
@@ -0,0 +1,22 @@
|
||||
Implemented and validated.
|
||||
|
||||
Changes:
|
||||
- Reused the initial `load_pod_list` result for Companion and Orchestrator presence in `load_multi_pod_snapshot`, removing two duplicate full Pod status probes before the first dashboard rows render.
|
||||
- Renamed the E2E source timings to `companion.presence.from_initial_list` and `orchestrator.presence.from_initial_list` so regressions show whether the initial list is reused.
|
||||
- Changed Pod list startup summarization to avoid reading active session logs while building initial Pod rows. Stored metadata now uses a cheap active-segment marker and live-only rows keep existing minimal live/pending summaries.
|
||||
- Preserved spawn/restore behavior after Companion/Orchestrator lifecycle changes; if lifecycle changes require reload, the existing reload path remains.
|
||||
|
||||
Live-path measurement in the current workspace:
|
||||
- Before this fix: first non-empty Panel rows appeared at about 7967ms; `pod_metadata_status_probe.initial`, `companion.presence`, and `orchestrator.presence` were each about 2.5s.
|
||||
- After removing duplicate probes only: first non-empty rows appeared at about 2964ms; duplicate presence probes dropped to 0ms but initial Pod metadata/status probe was still about 2386ms.
|
||||
- After also removing session-log reads from the startup Pod summary path: first non-empty rows appeared at about 754ms; `pod_metadata_status_probe.initial` was about 138ms; total dashboard source breakdown was about 649ms.
|
||||
|
||||
Validation:
|
||||
- cargo test -p tui pod_list --lib
|
||||
- cargo test -p yoi-e2e --features e2e --test panel
|
||||
- cargo check -p yoi-e2e -p yoi -p tui --features tui/e2e-test
|
||||
- cargo build -p yoi
|
||||
- cargo fmt --check
|
||||
- git diff --check
|
||||
- target/debug/yoi ticket doctor
|
||||
- nix build .#yoi --no-link
|
||||
@@ -0,0 +1,46 @@
|
||||
<!-- event: create author: "yoi ticket" at: 2026-06-19T04:07:17Z -->
|
||||
|
||||
## 作成
|
||||
|
||||
LocalTicketBackend によって作成されました。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-19T04:19:09Z from: inprogress to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-19T04:19:09Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Implemented and validated.
|
||||
|
||||
Changes:
|
||||
- Reused the initial `load_pod_list` result for Companion and Orchestrator presence in `load_multi_pod_snapshot`, removing two duplicate full Pod status probes before the first dashboard rows render.
|
||||
- Renamed the E2E source timings to `companion.presence.from_initial_list` and `orchestrator.presence.from_initial_list` so regressions show whether the initial list is reused.
|
||||
- Changed Pod list startup summarization to avoid reading active session logs while building initial Pod rows. Stored metadata now uses a cheap active-segment marker and live-only rows keep existing minimal live/pending summaries.
|
||||
- Preserved spawn/restore behavior after Companion/Orchestrator lifecycle changes; if lifecycle changes require reload, the existing reload path remains.
|
||||
|
||||
Live-path measurement in the current workspace:
|
||||
- Before this fix: first non-empty Panel rows appeared at about 7967ms; `pod_metadata_status_probe.initial`, `companion.presence`, and `orchestrator.presence` were each about 2.5s.
|
||||
- After removing duplicate probes only: first non-empty rows appeared at about 2964ms; duplicate presence probes dropped to 0ms but initial Pod metadata/status probe was still about 2386ms.
|
||||
- After also removing session-log reads from the startup Pod summary path: first non-empty rows appeared at about 754ms; `pod_metadata_status_probe.initial` was about 138ms; total dashboard source breakdown was about 649ms.
|
||||
|
||||
Validation:
|
||||
- cargo test -p tui pod_list --lib
|
||||
- cargo test -p yoi-e2e --features e2e --test panel
|
||||
- cargo check -p yoi-e2e -p yoi -p tui --features tui/e2e-test
|
||||
- cargo build -p yoi
|
||||
- cargo fmt --check
|
||||
- git diff --check
|
||||
- target/debug/yoi ticket doctor
|
||||
- nix build .#yoi --no-link
|
||||
|
||||
|
||||
---
|
||||
@@ -0,0 +1 @@
|
||||
{"id":"orch-plan-20260619-102132-1","ticket_id":"00001KVFD3YSV","kind":"accepted_plan","accepted_plan":{"summary":"`yoi plugin list` / `yoi plugin show <ref>` を product CLI に追加し、Plugin package discovery / enablement resolution / grant diagnostics / static Tool/runtime eligibility を read-only typed inspection reportとして表示する。Plugin code / WASM / Tool execution / mutation は行わない。","branch":"impl/00001KVFD3YSV-plugin-cli-inspection","worktree":"/home/hare/Projects/yoi/.worktree/00001KVFD3YSV-plugin-cli-inspection","role_plan":"Orchestrator は専用 implementation worktree を作成し、Coder をその worktree への narrow write scope で起動する。Reviewer は実装報告後に read-only で確認する。Host API implementation Tickets は関連するが、CLI inspection は read-only diagnostic surface として先行実装し、host API実装による追加表示は後続差分として扱える。"},"author":"yoi-orchestrator","at":"2026-06-19T10:21:32Z"}
|
||||
@@ -0,0 +1,45 @@
|
||||
{
|
||||
"version": 1,
|
||||
"relations": [
|
||||
{
|
||||
"ticket_id": "00001KVFD3YSV",
|
||||
"kind": "depends_on",
|
||||
"target": "00001KV5R5V2S",
|
||||
"note": "CLI inspection consumes Plugin package discovery and enablement resolver output.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T07:40:41Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVFD3YSV",
|
||||
"kind": "depends_on",
|
||||
"target": "00001KV5W3PJ3",
|
||||
"note": "CLI inspection should expose permission/grant diagnostics from the implemented grant model.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T07:40:41Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVFD3YSV",
|
||||
"kind": "related",
|
||||
"target": "00001KSXRQ4G8",
|
||||
"note": "Uses established Plugin runtime/surface/host API terminology.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T07:40:41Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVFD3YSV",
|
||||
"kind": "related",
|
||||
"target": "00001KV5W3PHA",
|
||||
"note": "Tool surface registration status should be visible in inspection output.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T07:40:41Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVFD3YSV",
|
||||
"kind": "related",
|
||||
"target": "00001KV5W3PHW",
|
||||
"note": "Runtime config/status should be shown without executing Plugin code.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T07:40:41Z"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,186 @@
|
||||
---
|
||||
title: 'Plugin: add read-only CLI inspection list/show'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-19T07:39:23Z'
|
||||
updated_at: '2026-06-19T14:22:41Z'
|
||||
assignee: null
|
||||
readiness: 'implementation_ready'
|
||||
risk_flags: ['plugin', 'cli', 'diagnostics', 'read-only', 'json-output', 'no-execution']
|
||||
queued_by: 'workspace-panel'
|
||||
queued_at: '2026-06-19T10:19:28Z'
|
||||
---
|
||||
|
||||
## Background
|
||||
|
||||
Plugin package discovery / explicit enablement / Tool registration / WASM Tool runtime / permission grants まで実装されたため、次に必要なのは「なぜ Plugin が見えない / 有効化されない / 実行できないのか」を headless に確認できる read-only inspection surface である。
|
||||
|
||||
Panel や TUI diagnostic に出す前に、CLI で deterministic に確認できる `yoi plugin list` / `yoi plugin show <ref>` を追加する。この CLI は Plugin code を実行せず、package discovery、manifest parse、enablement resolution、grant validation、static diagnostics を表示するだけにする。
|
||||
|
||||
目的は、Plugin の多段 failure point を human / JSON の両方で確認できるようにすること。
|
||||
|
||||
```text
|
||||
package discovered?
|
||||
manifest valid?
|
||||
api version compatible?
|
||||
explicitly enabled?
|
||||
digest/version/source match?
|
||||
requested permission granted?
|
||||
tool schema valid?
|
||||
runtime config present?
|
||||
```
|
||||
|
||||
## Requirements
|
||||
|
||||
- Top-level product CLI に read-only Plugin inspection command を追加する。
|
||||
- `yoi plugin list`
|
||||
- `yoi plugin show <ref>`
|
||||
- `--json` output を最初から提供する。
|
||||
- `yoi plugin list --json`
|
||||
- `yoi plugin show <ref> --json`
|
||||
- Human-readable output は JSON 用 typed report の thin formatting にする。
|
||||
- Workspace / Profile resolution は通常起動に近い意味にする。
|
||||
- default は current workspace。
|
||||
- 既存 CLI 方針に合わせて `--workspace <path>` を扱う。
|
||||
- Profile 指定が必要なら既存 Profile selector と整合する option を使う。
|
||||
- Plugin code を実行しない。
|
||||
- WASM module を実行しない。
|
||||
- Tool call を発生させない。
|
||||
- Hook / Service / Ingress を起動しない。
|
||||
- Read-only とする。
|
||||
- install / update / enable / disable / trust / sign / run は non-goal。
|
||||
- Plugin package / config / Ticket / memory / Pod state を変更しない。
|
||||
- Inspection report は typed data として実装する。
|
||||
- future Panel diagnostic / tests / agent-readable output で再利用できる形にする。
|
||||
- `list` は package/ref 単位の overview を出す。
|
||||
- ref
|
||||
- source
|
||||
- package path (human output では必要に応じて短縮)
|
||||
- version
|
||||
- api version
|
||||
- digest
|
||||
- status
|
||||
- enabled surfaces
|
||||
- diagnostic count / summary
|
||||
- `show <ref>` は詳細を出す。
|
||||
- manifest metadata
|
||||
- source-qualified identity
|
||||
- package path
|
||||
- digest
|
||||
- version / api version
|
||||
- runtime kind/config summary
|
||||
- enabled surfaces
|
||||
- Tool definitions and registration eligibility
|
||||
- requested permissions
|
||||
- granted permissions
|
||||
- effective grants / denied grants
|
||||
- diagnostics
|
||||
- Status vocabulary を明確にする。
|
||||
- `active`: enabled and statically valid for at least one surface/tool.
|
||||
- `disabled`: discovered but not explicitly enabled.
|
||||
- `missing`: enablement refers to a package that is not discovered.
|
||||
- `rejected`: invalid manifest / incompatible api / digest mismatch / grant mismatch / invalid schema etc.
|
||||
- `partial`: package is usable but some surfaces/tools are rejected.
|
||||
- Diagnostics は bounded / safe にする。
|
||||
- secret-like values / auth / file contents を出さない。
|
||||
- path は必要最小限。JSON では absolute path が必要なら workspace/user store source と一緒に出す。
|
||||
- denial / parse / digest / grant mismatch reasons を区別できる。
|
||||
- Ambiguous unqualified ref は fail closed し、`show` で diagnostic を返す。
|
||||
- JSON schema は stable typed structure として test で固定する。
|
||||
|
||||
## Example human output
|
||||
|
||||
`yoi plugin list`:
|
||||
|
||||
```text
|
||||
REF SOURCE VERSION STATUS SURFACES DIGEST
|
||||
project:example.echo project 0.1.0 active tool sha256:...
|
||||
project:broken project - rejected - -
|
||||
user:fetch user 0.2.1 disabled tool sha256:...
|
||||
```
|
||||
|
||||
`yoi plugin show project:example.echo`:
|
||||
|
||||
```text
|
||||
Plugin: project:example.echo
|
||||
Source: project
|
||||
Package: .yoi/plugins/example.echo.yoi-plugin
|
||||
Version: 0.1.0
|
||||
API: yoi-plugin-1
|
||||
Digest: sha256:...
|
||||
Status: active
|
||||
|
||||
Enabled surfaces:
|
||||
- tool
|
||||
|
||||
Tools:
|
||||
- example_echo
|
||||
status: registered
|
||||
schema: valid
|
||||
external_write: false
|
||||
|
||||
Permissions:
|
||||
Requested:
|
||||
- surfaces.tool
|
||||
- tool:example_echo
|
||||
|
||||
Granted:
|
||||
- surfaces.tool
|
||||
- tool:example_echo
|
||||
|
||||
Diagnostics:
|
||||
- none
|
||||
```
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- `yoi plugin list` prints a bounded human-readable overview without executing Plugin code.
|
||||
- `yoi plugin show <ref>` prints detailed static inspection for a Plugin ref without executing Plugin code.
|
||||
- `--json` output is available for both commands and uses a stable typed structure.
|
||||
- Valid enabled Plugin appears as `active`.
|
||||
- Discovered but not enabled Plugin appears as `disabled`.
|
||||
- Enabled but missing package appears as `missing`.
|
||||
- Invalid manifest / incompatible api version appears as `rejected` with diagnostic.
|
||||
- Digest / version / source mismatch appears as diagnostic.
|
||||
- Grant denial / missing requested permission appears as diagnostic.
|
||||
- Partial tool/surface rejection can be represented without marking the whole package as fully active.
|
||||
- Ambiguous unqualified id fails closed with diagnostic.
|
||||
- Plugin code / WASM / Tool execution is not triggered by list/show.
|
||||
- Tests cover:
|
||||
- list human output for active / disabled / rejected / missing packages
|
||||
- show human output for active package with Tool surface and grants
|
||||
- JSON list structure
|
||||
- JSON show structure
|
||||
- invalid manifest diagnostic
|
||||
- digest mismatch diagnostic
|
||||
- missing grant diagnostic
|
||||
- ambiguous ref diagnostic
|
||||
- no runtime execution from inspection path
|
||||
- Validation: focused CLI/plugin inspection tests, relevant `cargo check` / `cargo test`, `cargo fmt --check`, `git diff --check`, and `nix build .#yoi` because product CLI / packaging surface changes.
|
||||
|
||||
## Non-goals
|
||||
|
||||
- Plugin install / update / remove.
|
||||
- Enable / disable mutation.
|
||||
- Trust / signature / registry implementation.
|
||||
- Plugin code execution.
|
||||
- WASM validation beyond static runtime config/manifest inspection.
|
||||
- `https` host API implementation.
|
||||
- `fs` host API implementation.
|
||||
- Service / Ingress startup.
|
||||
- Panel/TUI Plugin diagnostics UI.
|
||||
|
||||
## Implementation notes
|
||||
|
||||
- Product CLI ownership stays in the `yoi` crate.
|
||||
- Avoid embedding resolver logic directly in display formatting; build a typed inspection report first.
|
||||
- Reuse existing Plugin resolver / diagnostics where possible.
|
||||
- Keep CLI output deterministic and suitable for tests.
|
||||
- Do not introduce user-facing terminology `contribution category`; use Plugin runtime / surface / host API / grants.
|
||||
|
||||
## Related work
|
||||
|
||||
- `00001KV5R5V2S` — Plugin package discovery and explicit enablement resolver.
|
||||
- `00001KV5W3PHA` — Plugin Tool surface registration.
|
||||
- `00001KV5W3PHW` — Plugin Tool execution with minimal WASM runtime.
|
||||
- `00001KV5W3PJ3` — Plugin permission grant enforcement.
|
||||
- `00001KSXRQ4G8` — Plugin runtime / surface / minimal host API model design.
|
||||
@@ -0,0 +1,44 @@
|
||||
Ticket `00001KVFD3YSV` is complete.
|
||||
|
||||
Completed implementation:
|
||||
- Added read-only Plugin inspection CLI commands:
|
||||
- `yoi plugin list`
|
||||
- `yoi plugin show <ref>`
|
||||
- JSON output support.
|
||||
- Added typed Plugin inspection report used by both JSON and human output.
|
||||
- Inspection reports package path/location, schema/API version, source/ref/digest/version, requested permissions, grants/denials, diagnostics, Tool/static eligibility, and future host API eligibility structure.
|
||||
- Status vocabulary is limited to `active`, `disabled`, `missing`, `rejected`, `partial`.
|
||||
- Implemented static Tool definition inspection for invalid/duplicate Tool names and invalid `input_schema`.
|
||||
- Distinguished truly absent configured package refs (`missing`) from present-but-invalid packages (`rejected`), including `Missing` diagnostics for missing root `plugin.toml` or missing referenced runtime/package entries.
|
||||
- Preserved read-only/no-execution behavior: inspection does not execute Plugin WASM or Tool code.
|
||||
- Kept diagnostics bounded and structured.
|
||||
|
||||
Reviewed / merged:
|
||||
- Implementation commits:
|
||||
- `462de32a` (`plugin: add cli inspection`)
|
||||
- `b5f10ab7` (`plugin: align inspection statuses`)
|
||||
- `dfa966db` (`plugin: report inspection package metadata`)
|
||||
- `982a1b75` (`plugin: validate inspected tool schemas`)
|
||||
- `a5f3b0b5` (`plugin: reject configured invalid packages`)
|
||||
- `0142ef1d` (`plugin: distinguish present invalid packages`)
|
||||
- Multiple review rounds requested and verified fixes for status vocabulary, package metadata fields, Tool schema/name validation, configured invalid package status, and present-but-invalid `Missing` diagnostics.
|
||||
- Final review `yoi-reviewer-00001KVFD3YSV-r6` approved with no blockers.
|
||||
- Orchestrator merge commit: `71ca05c8` (`merge: plugin cli inspection`)
|
||||
|
||||
Validation in Orchestrator worktree:
|
||||
- `cargo fmt --check` — passed
|
||||
- `cargo check -p yoi -p pod -p manifest` — passed
|
||||
- `cargo test -p yoi plugin -- --nocapture` — passed; 11 passed, 0 failed
|
||||
- `cargo test -p pod static_inspection -- --nocapture` — passed; 4 passed, 0 failed
|
||||
- `cargo test -p pod plugin -- --nocapture` — passed; 31 passed, 0 failed
|
||||
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||
- `git diff --check` — passed
|
||||
- `nix build .#yoi --no-link` — passed
|
||||
|
||||
Cleanup:
|
||||
- Stopped Coder Pod `yoi-coder-00001KVFD3YSV`.
|
||||
- Stopped Reviewer Pod `yoi-reviewer-00001KVFD3YSV-r6`.
|
||||
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KVFD3YSV-plugin-cli-inspection`.
|
||||
- Deleted merged branch `impl/00001KVFD3YSV-plugin-cli-inspection`.
|
||||
|
||||
Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction. The completed work is integrated on the Orchestrator branch.
|
||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,3 @@
|
||||
{"id":"orch-plan-20260619-102132-1","ticket_id":"00001KVFDX9AF","kind":"waiting_capacity_note","note":"明示 queue review で確認済み。依存 Ticket `00001KV5W3PHW` / `00001KV5W3PJ3` は closed で blocker ではないが、同時 queued の `00001KVFD3YSV` CLI inspection と `00001KVFDX9AY` fs host API はいずれも Plugin manifest/grant/runtime/diagnostic 周辺を触る。まず read-only CLI inspection を開始し、host API implementation は conflict / reviewer-coder bottleneck を避けるため queued のまま待機する。次の routing pass で再確認する。","author":"yoi-orchestrator","at":"2026-06-19T10:21:32Z"}
|
||||
{"id":"orch-plan-20260619-102132-2","ticket_id":"00001KVFDX9AF","kind":"do_not_parallelize","related_ticket":"00001KVFDX9AY","note":"`https` と `fs` host API はどちらも WASM Plugin Tool runtime host import boundary、Plugin grant model、diagnostics/tests/package behavior に触れるため、同時実装は conflict risk が高い。片方の merged/validated 後にもう片方を再 routing する。","author":"yoi-orchestrator","at":"2026-06-19T10:21:32Z"}
|
||||
{"id":"orch-plan-20260619-142431-3","ticket_id":"00001KVFDX9AF","kind":"accepted_plan","accepted_plan":{"summary":"WASM Plugin Tool runtime に明示 grant された HTTPS outbound host API を追加する。HTTPS-only、private/local target rejection、method/host/path allowlist、bounded request/response/timeout/redirect/diagnostics、secret redaction、ordinary Tool result path、no ambient env/network authority を満たす。","branch":"impl/00001KVFDX9AF-plugin-https-host-api","worktree":"/home/hare/Projects/yoi/.worktree/00001KVFDX9AF-plugin-https-host-api","role_plan":"Orchestrator は専用 implementation worktree を作成し、Coder をその worktree への narrow write scope で起動する。Reviewer は実装報告後に read-only で確認する。`fs` host API と Component Model migration は重複する Plugin runtime/grant surface のため queued hold を維持する。"},"author":"yoi-orchestrator","at":"2026-06-19T14:24:31Z"}
|
||||
@@ -0,0 +1,37 @@
|
||||
{
|
||||
"version": 1,
|
||||
"relations": [
|
||||
{
|
||||
"ticket_id": "00001KVFDX9AF",
|
||||
"kind": "depends_on",
|
||||
"target": "00001KV5W3PHW",
|
||||
"note": "https host API is implemented inside the WASM Plugin Tool runtime.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T07:54:32Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVFDX9AF",
|
||||
"kind": "depends_on",
|
||||
"target": "00001KV5W3PJ3",
|
||||
"note": "https host API must be guarded by Plugin permission grants.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T07:54:32Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVFDX9AF",
|
||||
"kind": "related",
|
||||
"target": "00001KSXRQ4G8",
|
||||
"note": "Uses established Plugin host API terminology.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T07:54:32Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVFDX9AF",
|
||||
"kind": "related",
|
||||
"target": "00001KVFD3YSV",
|
||||
"note": "Inspection CLI should expose https host API grants/diagnostics.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T07:54:32Z"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,98 @@
|
||||
---
|
||||
title: 'Plugin: implement https host API for Tool runtime'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-19T07:53:13Z'
|
||||
updated_at: '2026-06-19T15:35:46Z'
|
||||
assignee: null
|
||||
readiness: 'implementation_ready'
|
||||
risk_flags: ['plugin', 'https', 'host-api', 'network', 'sandbox', 'secrets', 'permission-grants']
|
||||
queued_by: 'workspace-panel'
|
||||
queued_at: '2026-06-19T10:19:53Z'
|
||||
---
|
||||
|
||||
## Background
|
||||
|
||||
Plugin Tool runtime は minimal WASM execution と permission grants まで実装済みだが、外部 HTTPS API を呼ぶ host API はまだ未実装である。
|
||||
|
||||
この Ticket では、WASM Plugin Tool から明示 grant された outbound HTTPS request だけを実行できる `https` host API を追加する。これは Discord webhook / REST API など outbound integration の前提になる。ただし Service / Ingress / WebSocket / inbound HTTP はこの Ticket の対象外。
|
||||
|
||||
用語は `web` ではなく `https` とする。
|
||||
|
||||
## Requirements
|
||||
|
||||
- WASM Plugin Tool runtime に `https` host API import を追加する。
|
||||
- API 名・ABI は既存 `yoi-plugin-wasm-1` / host import 設計と整合させる。
|
||||
- Plugin は ambient network access を持たず、host API 経由のみで HTTPS request できる。
|
||||
- HTTPS only とする。
|
||||
- `http://` は reject。
|
||||
- localhost / private / link-local / unix socket / file URL 等は reject。
|
||||
- Permission grants と統合する。
|
||||
- manifest requested permissions の `host_api.https` を読む。
|
||||
- config granted permissions と照合する。
|
||||
- grant がない場合は fail closed。
|
||||
- host / method / optional path prefix などの allowlist を表現できるようにする。
|
||||
- Request を bounded にする。
|
||||
- method allowlist。
|
||||
- request body size bound。
|
||||
- header count / size bound。
|
||||
- response body size bound。
|
||||
- timeout。
|
||||
- redirect policy。
|
||||
- Credentials は ambient env から読まない。
|
||||
- header / auth は explicit config / secret ref 経由だけにする。
|
||||
- diagnostics に secret-like header / token / body content を漏らさない。
|
||||
- Response は Tool result に安全に戻せる bounded structure にする。
|
||||
- status code
|
||||
- bounded headers if needed
|
||||
- bounded body text / bytes policy
|
||||
- truncated flag
|
||||
- Failure は structured Tool error にする。
|
||||
- grant denied
|
||||
- URL rejected
|
||||
- private/local host rejected
|
||||
- timeout
|
||||
- response too large
|
||||
- network error
|
||||
- unsupported method
|
||||
- Plugin code / history / model context に hidden context injection しない。
|
||||
- HTTPS response は Tool result として通常の tool history 経路に残す。
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Granted Plugin Tool can perform an allowed HTTPS request through host API.
|
||||
- Request without `host_api.https` grant fails closed before network access.
|
||||
- Disallowed host / method / URL scheme fails closed.
|
||||
- `http://`, localhost, private IP, link-local, and local/private host targets are rejected.
|
||||
- Timeout and response size bounds are enforced.
|
||||
- Request / response diagnostics are bounded and redact secret-like values.
|
||||
- No ambient env credentials or ambient network APIs are exposed to WASM.
|
||||
- Tool result path remains ordinary Tool result/history path.
|
||||
- Tests cover:
|
||||
- allowed HTTPS request with grant
|
||||
- missing grant denied
|
||||
- disallowed host denied
|
||||
- method denied
|
||||
- http scheme denied
|
||||
- private/local host denied
|
||||
- timeout
|
||||
- response truncation / size bound
|
||||
- secret header redaction
|
||||
- no network access without host API import/grant
|
||||
- Validation: focused plugin https tests, relevant cargo check/test, `cargo fmt --check`, `git diff --check`, and `nix build .#yoi` because dependency/package/network code may change.
|
||||
|
||||
## Non-goals
|
||||
|
||||
- `fs` host API implementation.
|
||||
- WebSocket / SSE / timer host APIs.
|
||||
- Service surface lifecycle.
|
||||
- Ingress surface.
|
||||
- Discord Gateway bridge.
|
||||
- Inbound HTTP server.
|
||||
- Plugin package manager / install/update.
|
||||
|
||||
## Related work
|
||||
|
||||
- `00001KV5W3PHW` — Plugin Tool execution with minimal WASM runtime.
|
||||
- `00001KV5W3PJ3` — Plugin permission grant enforcement.
|
||||
- `00001KVFD3YSV` — Plugin read-only CLI inspection list/show.
|
||||
- `00001KSXRQ4G8` — Plugin runtime / surface / minimal host API model design.
|
||||
@@ -0,0 +1,37 @@
|
||||
Ticket `00001KVFDX9AF` is complete.
|
||||
|
||||
Completed implementation:
|
||||
- Added granted outbound HTTPS host API for WASM Plugin Tools.
|
||||
- Added typed `host_api.https` grant scope with host, method, optional path prefix, and bounded request/response options.
|
||||
- Implemented `yoi:https` WASM host import handling.
|
||||
- Enforced grant/allowlist checks before network access.
|
||||
- Enforced HTTPS-only behavior and rejected `http://`, embedded credentials, localhost/private/link-local/local targets, IPv4-mapped/compatible IPv6 private/local forms, and unsafe DNS results.
|
||||
- Bound DNS validation to the actual reqwest connection path by pinning validated public socket addresses with `resolve_to_addrs`.
|
||||
- Added request/response bounds, timeout, no redirects, `no_proxy()`, response truncation, and secret-like diagnostics redaction.
|
||||
- Preserved ordinary Tool result/history path and avoided hidden context injection.
|
||||
- Updated Plugin CLI inspection and manifest/permission model to expose HTTPS host API grant/diagnostic details.
|
||||
|
||||
Reviewed / merged:
|
||||
- Implementation commits:
|
||||
- `7377527f` (`plugin: implement https host api`)
|
||||
- `85683f17` (`plugin: harden https target validation`)
|
||||
- First review requested changes for IPv4-mapped IPv6 bypass and DNS validation TOCTOU.
|
||||
- Re-review approved with no remaining blockers.
|
||||
- Orchestrator merge commit: `6beb8625` (`merge: plugin https host api`)
|
||||
|
||||
Validation in Orchestrator worktree:
|
||||
- `cargo fmt --check` — passed
|
||||
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||
- `cargo test -p pod feature::plugin::tests -- --nocapture` — passed; 39 passed, 0 failed
|
||||
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||
- `git diff --check` — passed
|
||||
- `nix build .#yoi --no-link` — passed
|
||||
|
||||
Cleanup:
|
||||
- Stopped Coder Pod `yoi-coder-00001KVFDX9AF`.
|
||||
- Stopped Reviewer Pod `yoi-reviewer-00001KVFDX9AF-r2`.
|
||||
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KVFDX9AF-plugin-https-host-api`.
|
||||
- Deleted merged branch `impl/00001KVFDX9AF-plugin-https-host-api`.
|
||||
|
||||
Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction. The completed work is integrated on the Orchestrator branch.
|
||||
@@ -0,0 +1,766 @@
|
||||
<!-- event: create author: "yoi ticket" at: 2026-06-19T07:53:13Z -->
|
||||
|
||||
## 作成
|
||||
|
||||
LocalTicketBackend によって作成されました。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: workspace-panel at: 2026-06-19T10:19:53Z from: ready to: queued reason: queued field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を `workspace-panel` が queued にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: plan author: yoi-orchestrator at: 2026-06-19T10:22:26Z -->
|
||||
|
||||
## Plan
|
||||
|
||||
Routing hold / waiting-capacity note:
|
||||
|
||||
明示 queue review で Ticket body / relations / orchestration plan / workspace state を確認した。
|
||||
|
||||
Current decision:
|
||||
- この Ticket は `queued` のまま待機。
|
||||
- 依存 Ticket `00001KV5W3PHW` / `00001KV5W3PJ3` は closed で dependency blocker ではない。
|
||||
- ただし同時 queued の `00001KVFD3YSV` CLI inspection を先に受理した。CLI inspection は Plugin discovery / enablement / grants / diagnostics の read-only public surface を作る作業で、host API implementation と同じ Plugin manifest/grant/runtime/diagnostic 周辺に触れる。
|
||||
- `00001KVFDX9AY` fs host API とは WASM Plugin Tool runtime host import boundary、Plugin grant model、diagnostics/tests/package behavior の変更面が重なるため `do_not_parallelize` plan record を残した。
|
||||
|
||||
Bounded reason for idle queued:
|
||||
- conflict / reviewer-coder bottleneck。
|
||||
|
||||
Next action:
|
||||
- `00001KVFD3YSV` の implementation/review/merge outcome を確認後、queued のまま再 routing する。
|
||||
- その時点で `fs` host API Ticket との ordering / conflict も再確認する。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: decision author: yoi-orchestrator at: 2026-06-19T14:25:13Z -->
|
||||
|
||||
## Decision
|
||||
|
||||
Routing decision: implementation_ready
|
||||
|
||||
Reason:
|
||||
- Panel Queue により、この Ticket は Orchestrator routing 対象として明示許可された。
|
||||
- Ticket body には、HTTPS host API intent、binding invariants、acceptance criteria、non-goals、validation、escalation-worthy risk domain が実装可能な粒度で揃っている。
|
||||
- 依存 relation の `00001KV5W3PHW` minimal WASM runtime、`00001KV5W3PJ3` permission grants、関連 `00001KVFD3YSV` CLI inspection は closed で blocker ではない。
|
||||
- Risk domain は network / secrets / host API / permission grants だが、Ticket は HTTPS-only、private/local target rejection、grant allowlist、bounded request/response/timeout/diagnostics、no ambient env/network、ordinary Tool result path を binding invariants として明示している。bounded context check 後も implementation 前に必要な追加 human decision は見つからなかった。
|
||||
- 同時 queued の `00001KVFDX9AY` fs host API と `00001KVG0HR96` Component Model migration は Plugin runtime/grant/diagnostic/packaging surface が重なるため、waiting/conflict notes を更新し queued のまま待機する。
|
||||
|
||||
Evidence checked:
|
||||
- Ticket `00001KVFDX9AF` body / thread / artifacts。
|
||||
- `TicketRelationQuery(00001KVFDX9AF)`: depends_on は closed。related Ticket は context であり acceptance blocker ではない。
|
||||
- `TicketOrchestrationPlanQuery(00001KVFDX9AF)`: 既存 waiting/do_not_parallelize records を確認。今回 `accepted_plan` を記録済み。
|
||||
- Related completed Tickets:
|
||||
- `00001KV5W3PHW` — minimal WASM Tool runtime closed。
|
||||
- `00001KV5W3PJ3` — Plugin permission grants closed。
|
||||
- `00001KVFD3YSV` — Plugin read-only CLI inspection closed。
|
||||
- Current queued Tickets:
|
||||
- `00001KVFDX9AY` fs host API: do_not_parallelize / waiting reason を維持。
|
||||
- `00001KVG0HR96` Component Model migration: migration boundary / conflict waiting note を更新。
|
||||
- Orchestrator worktree `/home/hare/Projects/yoi/.worktree/orchestration`: clean。
|
||||
- Existing branch/worktree: matching `00001KVFDX9AF` branch/worktree はなし。
|
||||
- Visible Pods: self / peer / intake only; spawned child capacity is free。
|
||||
- Current code map:
|
||||
- `crates/pod/src/feature/plugin.rs`: Plugin resolver, permission grants, static inspection, WASM tool feature。
|
||||
- `crates/pod/src/pod.rs`: WASM Tool runtime / `run_plugin_wasm_tool` / host import validation。
|
||||
- `crates/manifest/src/plugin.rs`: Plugin manifest and permission model。
|
||||
- `crates/yoi/src/plugin_cli.rs`: read-only inspection output should remain compatible with host API diagnostics。
|
||||
|
||||
IntentPacket:
|
||||
|
||||
Intent:
|
||||
- WASM Plugin Tool runtime に、明示 grant された outbound HTTPS request だけを実行できる `https` host API を追加する。
|
||||
- Plugin は ambient network access を持たず、host API import + requested permission + config grant + allowlist を満たす場合だけ bounded HTTPS request を実行できる。
|
||||
|
||||
Binding decisions / invariants:
|
||||
- Host API name/domain は `https`。`web` ではない。
|
||||
- HTTPS-only。`http://`、localhost、private IP、link-local、unix socket、file URL、local/private host targets は reject。
|
||||
- Grant がない場合、network access 前に fail closed。
|
||||
- host / method / optional path prefix などの allowlist を表現し、grant と request を照合する。
|
||||
- Request/response は bounded。
|
||||
- method allowlist
|
||||
- request body size bound
|
||||
- header count/size bound
|
||||
- response body size bound
|
||||
- timeout
|
||||
- redirect policy
|
||||
- Credentials は ambient env から読まない。header/auth は explicit config / secret ref 経由だけ。
|
||||
- Diagnostics に secret-like header/token/body content を漏らさない。
|
||||
- HTTPS response は hidden context injection ではなく ordinary Tool result/history path に残す。
|
||||
- `fs` host API、WebSocket/SSE/timers、Service/Ingress lifecycle、Plugin package manager は non-goals。
|
||||
|
||||
Requirements / acceptance criteria:
|
||||
- Granted Plugin Tool can perform an allowed HTTPS request through host API。
|
||||
- Missing `host_api.https` grant denies before network access。
|
||||
- Disallowed host / method / URL scheme denies。
|
||||
- `http://`, localhost, private IP, link-local, local/private host targets reject。
|
||||
- Timeout and response-size bounds are enforced。
|
||||
- Request/response diagnostics are bounded and redact secret-like values。
|
||||
- No ambient env credentials or ambient network APIs are exposed to WASM。
|
||||
- Tool result path remains ordinary Tool result/history path。
|
||||
- Tests cover allowed HTTPS, missing grant, disallowed host/method/scheme/private target, timeout, response truncation, secret redaction, no network without host API import/grant。
|
||||
|
||||
Implementation latitude:
|
||||
- Choose exact ABI/import shape consistent with existing `yoi-plugin-wasm-1` host import design。
|
||||
- Choose narrow grant config representation for host/method/path allowlist consistent with current Plugin permission grant model。
|
||||
- Use local deterministic test server/mock if needed for allowed HTTPS/timeout/response bound tests, but keep network-safety tests deterministic。
|
||||
- Choose bounded response header/body representation that fits existing Tool result error/result types。
|
||||
|
||||
Escalate if:
|
||||
- Implementing HTTPS requires broad runtime executor redesign or Component Model migration first。
|
||||
- Secure host/method/path grant model cannot be represented without breaking existing permission grant schema。
|
||||
- SecretRef handling requires new secret-store public API beyond explicit config references。
|
||||
- Safe private/local-host rejection cannot be implemented deterministically enough for tests。
|
||||
- Host API result/error shape requires product-visible Tool result schema decision beyond this Ticket。
|
||||
|
||||
Validation:
|
||||
- Focused plugin HTTPS host API tests。
|
||||
- Relevant `cargo test` / `cargo check` for `pod`, `manifest`, `yoi` as changed。
|
||||
- `cargo fmt --check`。
|
||||
- `git diff --check`。
|
||||
- `nix build .#yoi` because dependency/package/network code may change。
|
||||
|
||||
Critical risks / reviewer focus:
|
||||
- Network access before grant/allowlist checks。
|
||||
- Private/local/localhost bypass through DNS, redirects, IPv6, encoded URLs, or scheme confusion。
|
||||
- Secret leakage in diagnostics or Tool result/history。
|
||||
- Ambient env credential usage。
|
||||
- Unbounded request/response bodies or headers。
|
||||
- Hidden context injection by bypassing normal Tool result path。
|
||||
- Breaking existing Plugin permission grant enforcement or CLI inspection semantics。
|
||||
|
||||
Next action:
|
||||
- `queued -> inprogress` を記録し、Ticket records を Orchestrator worktree に commit してから、専用 implementation worktree を作成し Coder Pod を narrow write scope で起動する。root/original workspace は操作しない。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-19T14:25:28Z from: queued to: inprogress reason: orchestrator_acceptance_plugin_https_host_api field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket body/thread, relation metadata, orchestration plan records, related completed Tickets, Orchestrator worktree, visible Pods, existing branch/worktree, and bounded Plugin host API code context were checked. Depends-on blockers are closed, prior CLI inspection related work is closed, and no dirty-state blocker or missing planning decision was found. `fs` host API and Component Model migration remain queued with conflict/migration waiting records. Accepting this queued Ticket for implementation before worktree/Pod side effects.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T14:26:32Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Implementation start note:
|
||||
|
||||
`queued -> inprogress` acceptance、accepted plan、routing decision / IntentPacket、fs host API / Component Model migration の waiting records を記録し、Orchestrator worktree で commit した後に、専用 implementation worktree と Coder Pod を起動した。
|
||||
|
||||
Worktree:
|
||||
- `/home/hare/Projects/yoi/.worktree/00001KVFDX9AF-plugin-https-host-api`
|
||||
- branch: `impl/00001KVFDX9AF-plugin-https-host-api`
|
||||
|
||||
Coder Pod:
|
||||
- `yoi-coder-00001KVFDX9AF`
|
||||
|
||||
Scope / boundaries:
|
||||
- child runtime workspace root は read scope。
|
||||
- implementation worktree は write scope。
|
||||
- root/original workspace と Orchestrator worktree へは書き込まないよう指示済み。
|
||||
- `.yoi/memory`、runtime/log/lock/local/secret-like `.yoi` paths は編集しないよう指示済み。
|
||||
|
||||
Related queued Tickets:
|
||||
- `00001KVFDX9AY` fs host API remains queued due existing do_not_parallelize / conflict with HTTPS host API.
|
||||
- `00001KVG0HR96` Component Model migration remains queued due migration boundary / conflict with active host API work.
|
||||
|
||||
Next:
|
||||
- Coder は granted HTTPS host API implementation、focused tests、validation、implementation commit を行い、実装報告を返す予定。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T15:04:07Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Coder implementation report received / Orchestrator validation:
|
||||
|
||||
Implementation commit:
|
||||
- `73775275` — `plugin: implement https host api`
|
||||
|
||||
Summary:
|
||||
- Added typed HTTPS host API grant scope to Plugin permission model:
|
||||
- hosts
|
||||
- methods
|
||||
- optional path prefixes
|
||||
- bounded request/response options
|
||||
- Implemented `yoi:https` WASM host import handling in the Plugin Tool runtime。
|
||||
- Added deterministic local TLS / HTTPS test harness for runtime tests。
|
||||
- Added URL validation / network safety checks:
|
||||
- HTTPS-only;
|
||||
- reject `http://`;
|
||||
- reject localhost/private/link-local/local targets;
|
||||
- reject disallowed hosts/methods/schemes before network access。
|
||||
- Added request/response bounds and diagnostics:
|
||||
- body/header limits;
|
||||
- response truncation;
|
||||
- timeout;
|
||||
- bounded/redacted error messages。
|
||||
- Preserved no ambient env credentials and ordinary Tool result/history path semantics。
|
||||
- Updated read-only Plugin CLI inspection so HTTPS host API grant details / diagnostics remain inspectable。
|
||||
- Updated `package.nix` cargo hash for new dependency/build closure.
|
||||
|
||||
Files changed:
|
||||
- `Cargo.lock`
|
||||
- `crates/manifest/src/plugin.rs`
|
||||
- `crates/pod/Cargo.toml`
|
||||
- `crates/pod/src/feature/plugin.rs`
|
||||
- `crates/pod/src/pod.rs`
|
||||
- `crates/yoi/src/plugin_cli.rs`
|
||||
- `package.nix`
|
||||
|
||||
Coder reported validation:
|
||||
- `cargo fmt --check` — passed
|
||||
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||
- `cargo test -p pod feature::plugin::tests -- --nocapture` — passed; 36 passed
|
||||
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed
|
||||
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed
|
||||
- `git diff --check` — passed
|
||||
- `nix build .#yoi --no-link` — passed
|
||||
|
||||
Orchestrator evidence checked:
|
||||
- Pod output を確認。
|
||||
- implementation worktree は clean。
|
||||
- branch `impl/00001KVFDX9AF-plugin-https-host-api` HEAD は `73775275`。
|
||||
- diff stat from accepted base `1fdef32a..73775275`: 7 files changed, 1799 insertions, 97 deletions。
|
||||
|
||||
Validation re-run by Orchestrator in implementation worktree:
|
||||
- `cargo fmt --check` — passed
|
||||
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||
- `cargo test -p pod feature::plugin::tests -- --nocapture` — passed; 36 passed, 0 failed
|
||||
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||
- `git diff --check` — passed
|
||||
- `nix build .#yoi --no-link` — passed
|
||||
|
||||
Routing classification: review_needed
|
||||
|
||||
Next action:
|
||||
- recorded intent / invariants / acceptance criteria に照らして、read-only Reviewer Pod で外部レビューする。
|
||||
- 特に grant-before-network、private/local rejection、redirect/DNS bypass、bounds/timeouts、secret redaction、ordinary Tool result path、no ambient env credentials、CLI inspection compatibility、dependency/package.nix correctness を確認する。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: plan author: yoi-orchestrator at: 2026-06-19T15:04:59Z -->
|
||||
|
||||
## Plan
|
||||
|
||||
Review dispatch:
|
||||
|
||||
Reviewer Pod `yoi-reviewer-00001KVFDX9AF` を read-only scope で起動した。
|
||||
|
||||
Review target:
|
||||
- worktree: `/home/hare/Projects/yoi/.worktree/00001KVFDX9AF-plugin-https-host-api`
|
||||
- branch: `impl/00001KVFDX9AF-plugin-https-host-api`
|
||||
- commit: `73775275`
|
||||
|
||||
Reviewer focus:
|
||||
- recorded intent / invariants / acceptance criteria に対する適合性。
|
||||
- network access が grant/allowlist checks の前に発生しないこと。
|
||||
- private/local/localhost/link-local target rejection が DNS / IPv6 / redirect / scheme edge cases を含め妥当であること。
|
||||
- timeout / request-response size / header bounds が enforce されること。
|
||||
- secret-like values が errors / diagnostics / Tool results に漏れないこと。
|
||||
- ambient env credential / ambient network access path が WASM に exposed されていないこと。
|
||||
- HTTPS response が ordinary Tool result/history path だけに戻ること。
|
||||
- allowed HTTPS / missing grant / disallowed host-method-scheme-private target / timeout / truncation / redaction / no network without grant/import tests が意味を持つこと。
|
||||
- manifest/permission grant schema changes が existing grants / CLI inspection と整合していること。
|
||||
- `Cargo.lock` / `package.nix` update が妥当で、`nix build .#yoi --no-link` validation と整合していること。
|
||||
- `fs` host API と Component Model migration が non-goals として保たれていること。
|
||||
|
||||
Next:
|
||||
- Reviewer output を確認し、approve なら Orchestrator worktree への merge/validation/cleanup/close-ready 処理へ進む。request_changes なら blocker を記録して Coder に戻す。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVFDX9AF at: 2026-06-19T15:10:37Z status: request_changes -->
|
||||
|
||||
## Review: request changes
|
||||
|
||||
Review result: request_changes
|
||||
|
||||
対象:
|
||||
- Ticket: `00001KVFDX9AF`
|
||||
- branch: `impl/00001KVFDX9AF-plugin-https-host-api`
|
||||
- commit: `7377527f` (`plugin: implement https host api`)
|
||||
|
||||
Blockers:
|
||||
|
||||
1. Private/local target rejection is bypassable with IPv4-mapped IPv6 literals.
|
||||
- `validate_static_https_target` parses the URL host as `IpAddr` and delegates IPv6 literals to `is_forbidden_ipv6` (`crates/pod/src/feature/plugin.rs:622-631`, `665-669`).
|
||||
- `is_forbidden_ipv6` rejects loopback/unspecified/ULA/link-local/multicast (`699-705`) but does not check `Ipv6Addr::to_ipv4_mapped()` / IPv4-compatible forms.
|
||||
- Rust confirms `::ffff:127.0.0.1` is not `is_loopback()` as IPv6, while `to_ipv4_mapped()` is `Some(127.0.0.1)`.
|
||||
- A granted request to `https://[::ffff:127.0.0.1]/...` would therefore pass the current private/local filter if the grant host matches, violating localhost/private IP rejection and the IPv6 edge-case reviewer focus.
|
||||
|
||||
2. DNS private-address validation is TOCTOU and does not bind the checked address set to the actual connection.
|
||||
- `ReqwestPluginHttpsClient::execute` calls `validate_dns_target(url)` before constructing/sending the request (`crates/pod/src/feature/plugin.rs:365-405`).
|
||||
- `validate_dns_target` resolves with `ToSocketAddrs` and rejects private/local addresses in that returned set (`641-655`), but `reqwest` performs its own DNS resolution later during `builder.send()` (`405`).
|
||||
- DNS rebinding / split answers between the preflight lookup and reqwest’s lookup can pass validation on a public address then connect to a private/local address.
|
||||
- Ticket critical risks explicitly include DNS/private/local bypasses before network access.
|
||||
|
||||
Requested changes:
|
||||
- Reject IPv4-mapped IPv6 addresses by applying the existing IPv4 forbidden checks to mapped IPv4 addresses; add tests for mapped loopback/private/link-local examples.
|
||||
- Bind DNS validation to the actual connection path. Either pin validated public `SocketAddr`s into the reqwest client/request resolver path, or otherwise ensure the actual connected remote address is validated / not private.
|
||||
- Add deterministic test coverage around the real validation edge cases where feasible.
|
||||
|
||||
Supporting positive findings:
|
||||
- Grant checks happen before request parsing/DNS/network dispatch in `execute_plugin_https_request`, and WASM import validation denies `yoi:https` imports without requested/configured `host_api.https` grant before instantiation.
|
||||
- Scheme, embedded credentials, method allowlist, request descriptor/body/header count/size, response body/header bounds, timeout, no redirects, and `no_proxy()` are present.
|
||||
- WASM imports are narrow (`yoi:tool`, `yoi:https` only), WASI/ambient imports are rejected, and `yoi:fs` remains explicitly unimplemented.
|
||||
- Response path remains ordinary plugin Tool output/history path.
|
||||
- Manifest/CLI schema additions are mostly compatible: new `PluginPermission::HostApi`, `PluginHttpsGrant`, defaulted `grants.https`, and CLI display of configured HTTPS grants.
|
||||
|
||||
Test gap:
|
||||
- Current HTTPS-focused tests use `MockHttpsClient` for allowed/denied/timeout/truncation behavior. That is useful for grant ordering, but it does not exercise the real `ReqwestPluginHttpsClient` DNS filtering, redirect policy, TLS/HTTPS path, or actual timeout/read-limit behavior. Given the security-sensitive DNS/IP requirements, add coverage for the real validation edge cases above.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: plan author: yoi-orchestrator at: 2026-06-19T15:12:19Z -->
|
||||
|
||||
## Plan
|
||||
|
||||
Review follow-up dispatch:
|
||||
|
||||
Reviewer `yoi-reviewer-00001KVFDX9AF` は `request_changes` を返したため、Ticket review として記録し、既存 Coder Pod `yoi-coder-00001KVFDX9AF` に修正依頼を送った。
|
||||
|
||||
Blockers:
|
||||
1. IPv4-mapped IPv6 literals が private/local target rejection を bypass し得る。
|
||||
- `::ffff:127.0.0.1` などを IPv6 として見るだけでは loopback/private 判定に漏れる。
|
||||
- `Ipv6Addr::to_ipv4_mapped()` 等で mapped IPv4 を取り出し、既存 IPv4 forbidden checks を適用する必要がある。
|
||||
|
||||
2. DNS private-address validation が TOCTOU で actual connection path に bind されていない。
|
||||
- preflight `ToSocketAddrs` validation 後に `reqwest` が別途 DNS resolution するため、DNS rebinding / split answers で public answer validation 後に private/local address へ接続し得る。
|
||||
- validated public `SocketAddr`s を reqwest client/request resolver path に pin する、または actual connected remote address を検証する必要がある。
|
||||
|
||||
Required fixes sent to Coder:
|
||||
- IPv4-mapped IPv6 addresses を mapped IPv4 として private/local/link-local/loopback checks に通す。
|
||||
- mapped loopback/private/link-local の tests を追加する。
|
||||
- DNS validation を actual connection path に bind する設計へ修正する。
|
||||
- DNS / actual connection edge の deterministic test coverage を追加する。
|
||||
- Prior positives を維持する: grant-before-network、WASM import grant validation、HTTPS-only、embedded credentials rejection、method allowlist、bounds、timeout、no redirects、`no_proxy()`、ordinary Tool result path、manifest/CLI schema compatibility。
|
||||
|
||||
Next:
|
||||
- Coder の修正 commit / validation report を待つ。
|
||||
- 修正後、network-safety edge cases と grant-before-network invariants を中心に再レビューする。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T15:22:56Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Coder review-fix implementation report received / Orchestrator validation:
|
||||
|
||||
Incremental fix commit:
|
||||
- `85683f17` — `plugin: harden https target validation`
|
||||
|
||||
Summary:
|
||||
- Hardened IPv6 target validation:
|
||||
- IPv4-mapped IPv6 addresses now apply existing IPv4 private/local/link-local checks.
|
||||
- IPv4-compatible embedded forms are also checked through IPv4 rules.
|
||||
- Host canonicalization strips IPv6 brackets before IP parsing.
|
||||
- Removed DNS validation TOCTOU gap:
|
||||
- DNS resolution now produces validated public `SocketAddr`s.
|
||||
- Those exact validated addresses are pinned into the `reqwest` client via `resolve_to_addrs`, so `reqwest` does not perform a separate unvalidated DNS lookup for hostname requests.
|
||||
- Private DNS answers are rejected before client build / network dispatch.
|
||||
- Added deterministic tests for:
|
||||
- IPv4-mapped loopback/private/link-local rejection;
|
||||
- IPv4-compatible private rejection;
|
||||
- DNS resolution pinning to validated public socket addresses;
|
||||
- private DNS answer rejection before client build.
|
||||
|
||||
Files changed in incremental fix:
|
||||
- `crates/pod/src/feature/plugin.rs`
|
||||
|
||||
Coder reported validation:
|
||||
- `cargo test -p pod feature::plugin::tests` — passed; 39 tests
|
||||
- `cargo test -p manifest plugin` — passed; 17 tests
|
||||
- `cargo test -p yoi plugin_cli` — passed; 10 tests
|
||||
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||
- `cargo fmt --check` — passed
|
||||
- `git diff --check` — passed
|
||||
- `nix build .#yoi --no-link` — passed
|
||||
|
||||
Orchestrator evidence checked:
|
||||
- Pod output を確認。
|
||||
- implementation worktree は clean。
|
||||
- branch `impl/00001KVFDX9AF-plugin-https-host-api` HEAD は `85683f17`。
|
||||
- incremental diff stat from previous review target `7377527f..85683f17`: 1 file changed, 170 insertions, 21 deletions。
|
||||
|
||||
Validation re-run by Orchestrator in implementation worktree:
|
||||
- `cargo fmt --check` — passed
|
||||
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||
- `cargo test -p pod feature::plugin::tests -- --nocapture` — passed; 39 passed, 0 failed
|
||||
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||
- `git diff --check` — passed
|
||||
- `nix build .#yoi --no-link` — passed
|
||||
|
||||
Routing classification: review_needed
|
||||
|
||||
Next action:
|
||||
- previous `request_changes` blockers が解消されたか、read-only Reviewer Pod で再レビューする。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: plan author: yoi-orchestrator at: 2026-06-19T15:23:58Z -->
|
||||
|
||||
## Plan
|
||||
|
||||
Review re-dispatch:
|
||||
|
||||
Reviewer Pod `yoi-reviewer-00001KVFDX9AF-r2` を read-only scope で起動した。
|
||||
|
||||
Review target:
|
||||
- worktree: `/home/hare/Projects/yoi/.worktree/00001KVFDX9AF-plugin-https-host-api`
|
||||
- branch: `impl/00001KVFDX9AF-plugin-https-host-api`
|
||||
- commits:
|
||||
- `7377527f` — initial HTTPS host API implementation
|
||||
- `85683f17` — target validation hardening fix
|
||||
|
||||
Reviewer focus:
|
||||
- previous IPv4-mapped/compatible IPv6 private/local bypass blocker が解消されているか。
|
||||
- DNS validation が validated address pinning により actual reqwest connection path に bind され、unvalidated resolution path が残っていないか。
|
||||
- mapped IPv6 / DNS pinning / private DNS answer rejection tests が deterministic で意味を持つか。
|
||||
- prior positives: grant-before-network、WASM import grant validation、HTTPS-only、embedded credentials rejection、method allowlist、bounds、timeout、no redirects、`no_proxy()`、ordinary Tool result path、manifest/CLI schema compatibility が維持されているか。
|
||||
- `resolve_to_addrs` usage や host canonicalization に新しい security regression がないか。
|
||||
|
||||
Next:
|
||||
- Reviewer output を確認し、approve なら Orchestrator worktree への merge/validation/cleanup/close-ready 処理へ進む。request_changes なら blocker を記録して Coder に戻す。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVFDX9AF-r2 at: 2026-06-19T15:29:22Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Review result: approve
|
||||
|
||||
対象:
|
||||
- Ticket: `00001KVFDX9AF`
|
||||
- branch: `impl/00001KVFDX9AF-plugin-https-host-api`
|
||||
- commits:
|
||||
- `7377527f` — `plugin: implement https host api`
|
||||
- `85683f17` — `plugin: harden https target validation`
|
||||
|
||||
No remaining blockers found.
|
||||
|
||||
Evidence reviewed:
|
||||
- IPv4-mapped / compatible IPv6 bypass is closed.
|
||||
- Host canonicalization strips IPv6 brackets before IP parsing via `normalize_host_literal` / `canonical_host`.
|
||||
- `validate_static_https_target` parses canonical hosts as `IpAddr` and applies `validate_public_ip`.
|
||||
- `is_forbidden_ipv6` delegates mapped/compatible embedded IPv4 addresses through `ipv6_embedded_ipv4`, then applies existing IPv4 private/loopback/link-local/broadcast/special checks.
|
||||
- `ipv4_mapped_ipv6_targets_deny_before_network` covers `::ffff:127.0.0.1`, `::ffff:10.0.0.1`, `::ffff:169.254.169.254`, and compatible `::10.0.0.1`, with mock network call count asserted as zero.
|
||||
- DNS validation is bound to the reqwest connection path.
|
||||
- `ReqwestPluginHttpsClient::execute` calls `resolve_https_target_for_client` before building the client.
|
||||
- Hostname URLs resolve to `SocketAddr`s, reject empty/private/local answers, and return those exact validated addresses.
|
||||
- reqwest builder pins each validated domain using `resolve_to_addrs(domain, &pinned_resolution.addrs)`, with no remaining separate unvalidated DNS lookup path visible in this implementation.
|
||||
- IP-literal URLs skip DNS pinning only after static IP validation.
|
||||
- DNS tests are deterministic and meaningful at the unit boundary.
|
||||
- `FakeHttpsResolver` avoids live DNS/network.
|
||||
- `dns_resolution_is_pinned_to_validated_public_socket_addresses` verifies resolver input, returned pinned domains/addrs, and reqwest builder acceptance of `resolve_to_addrs`.
|
||||
- `dns_resolution_rejects_private_addresses_before_client_build` verifies private DNS answers fail before client build/network dispatch.
|
||||
- Prior positives remain preserved.
|
||||
- Grant checks happen before request validation/client dispatch in `execute_plugin_https_request`.
|
||||
- WASM import validation checks `yoi:https` authorization before allowing the import.
|
||||
- HTTPS-only, embedded-credential rejection, host/method/path allowlist, request/header/body bounds, response truncation, timeout, no redirects, `no_proxy()`, sensitive-header rejection/redaction, and ordinary Tool result flow remain present.
|
||||
- Existing tests cover missing grant before network, disallowed host/method/scheme/private targets before network, timeout/redaction, response truncation, no network without HTTPS import, and ordinary Tool result path.
|
||||
|
||||
Reviewer validation:
|
||||
- Static diff/code review and worktree status inspection.
|
||||
- Orchestrator-reported successful runs were reviewed:
|
||||
- `cargo fmt --check`
|
||||
- `cargo check -p pod -p manifest -p yoi`
|
||||
- focused pod/manifest/yoi plugin tests
|
||||
- `git diff --check`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Conclusion:
|
||||
- Previous request_changes blockers are resolved.
|
||||
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVFDX9AF-r2 at: 2026-06-19T15:29:45Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Review result: approve
|
||||
|
||||
対象:
|
||||
- Ticket: `00001KVFDX9AF`
|
||||
- branch: `impl/00001KVFDX9AF-plugin-https-host-api`
|
||||
- commits:
|
||||
- `7377527f` — `plugin: implement https host api`
|
||||
- `85683f17` — `plugin: harden https target validation`
|
||||
|
||||
No remaining blockers found.
|
||||
|
||||
Evidence reviewed:
|
||||
- IPv4-mapped / compatible IPv6 bypass is closed.
|
||||
- Host canonicalization strips IPv6 brackets before IP parsing via `normalize_host_literal` / `canonical_host`.
|
||||
- `validate_static_https_target` parses canonical hosts as `IpAddr` and applies `validate_public_ip`.
|
||||
- `is_forbidden_ipv6` delegates mapped/compatible embedded IPv4 addresses through `ipv6_embedded_ipv4`, then applies existing IPv4 private/loopback/link-local/broadcast/special checks.
|
||||
- `ipv4_mapped_ipv6_targets_deny_before_network` covers `::ffff:127.0.0.1`, `::ffff:10.0.0.1`, `::ffff:169.254.169.254`, and compatible `::10.0.0.1`, with mock network call count asserted as zero.
|
||||
- DNS validation is bound to the reqwest connection path.
|
||||
- `ReqwestPluginHttpsClient::execute` calls `resolve_https_target_for_client` before building the client.
|
||||
- Hostname URLs resolve to `SocketAddr`s, reject empty/private/local answers, and return those exact validated addresses.
|
||||
- reqwest builder pins each validated domain using `resolve_to_addrs(domain, &pinned_resolution.addrs)`, with no remaining separate unvalidated DNS lookup path visible in this implementation.
|
||||
- IP-literal URLs skip DNS pinning only after static IP validation.
|
||||
- DNS tests are deterministic and meaningful at the unit boundary.
|
||||
- `FakeHttpsResolver` avoids live DNS/network.
|
||||
- `dns_resolution_is_pinned_to_validated_public_socket_addresses` verifies resolver input, returned pinned domains/addrs, and reqwest builder acceptance of `resolve_to_addrs`.
|
||||
- `dns_resolution_rejects_private_addresses_before_client_build` verifies private DNS answers fail before client build/network dispatch.
|
||||
- Prior positives remain preserved.
|
||||
- Grant checks happen before request validation/client dispatch in `execute_plugin_https_request`.
|
||||
- WASM import validation checks `yoi:https` authorization before allowing the import.
|
||||
- HTTPS-only, embedded-credential rejection, host/method/path allowlist, request/header/body bounds, response truncation, timeout, no redirects, `no_proxy()`, sensitive-header rejection/redaction, and ordinary Tool result flow remain present.
|
||||
- Existing tests cover missing grant before network, disallowed host/method/scheme/private targets before network, timeout/redaction, response truncation, no network without HTTPS import, and ordinary Tool result path.
|
||||
|
||||
Reviewer validation:
|
||||
- Static diff/code review and worktree status inspection.
|
||||
- Orchestrator-reported successful runs were reviewed:
|
||||
- `cargo fmt --check`
|
||||
- `cargo check -p pod -p manifest -p yoi`
|
||||
- focused pod/manifest/yoi plugin tests
|
||||
- `git diff --check`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Conclusion:
|
||||
- Previous request_changes blockers are resolved.
|
||||
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVFDX9AF-r2 at: 2026-06-19T15:32:15Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Review result: approve
|
||||
|
||||
対象:
|
||||
- Ticket: `00001KVFDX9AF`
|
||||
- branch: `impl/00001KVFDX9AF-plugin-https-host-api`
|
||||
- commits:
|
||||
- `7377527f` — `plugin: implement https host api`
|
||||
- `85683f17` — `plugin: harden https target validation`
|
||||
|
||||
No remaining blockers found.
|
||||
|
||||
Evidence reviewed:
|
||||
- IPv4-mapped / compatible IPv6 bypass is closed.
|
||||
- Host canonicalization strips IPv6 brackets before IP parsing via `normalize_host_literal` / `canonical_host`.
|
||||
- `validate_static_https_target` parses canonical hosts as `IpAddr` and applies `validate_public_ip`.
|
||||
- `is_forbidden_ipv6` delegates mapped/compatible embedded IPv4 addresses through `ipv6_embedded_ipv4`, then applies existing IPv4 private/loopback/link-local/broadcast/special checks.
|
||||
- `ipv4_mapped_ipv6_targets_deny_before_network` covers `::ffff:127.0.0.1`, `::ffff:10.0.0.1`, `::ffff:169.254.169.254`, and compatible `::10.0.0.1`, with mock network call count asserted as zero.
|
||||
- DNS validation is bound to the reqwest connection path.
|
||||
- `ReqwestPluginHttpsClient::execute` calls `resolve_https_target_for_client` before building the client.
|
||||
- Hostname URLs resolve to `SocketAddr`s, reject empty/private/local answers, and return those exact validated addresses.
|
||||
- reqwest builder pins each validated domain using `resolve_to_addrs(domain, &pinned_resolution.addrs)`, with no remaining separate unvalidated DNS lookup path visible in this implementation.
|
||||
- IP-literal URLs skip DNS pinning only after static IP validation.
|
||||
- DNS tests are deterministic and meaningful at the unit boundary.
|
||||
- `FakeHttpsResolver` avoids live DNS/network.
|
||||
- `dns_resolution_is_pinned_to_validated_public_socket_addresses` verifies resolver input, returned pinned domains/addrs, and reqwest builder acceptance of `resolve_to_addrs`.
|
||||
- `dns_resolution_rejects_private_addresses_before_client_build` verifies private DNS answers fail before client build/network dispatch.
|
||||
- Prior positives remain preserved.
|
||||
- Grant checks happen before request validation/client dispatch in `execute_plugin_https_request`.
|
||||
- WASM import validation checks `yoi:https` authorization before allowing the import.
|
||||
- HTTPS-only, embedded-credential rejection, host/method/path allowlist, request/header/body bounds, response truncation, timeout, no redirects, `no_proxy()`, sensitive-header rejection/redaction, and ordinary Tool result flow remain present.
|
||||
- Existing tests cover missing grant before network, disallowed host/method/scheme/private targets before network, timeout/redaction, response truncation, no network without HTTPS import, and ordinary Tool result path.
|
||||
|
||||
Reviewer validation:
|
||||
- Static diff/code review and worktree status inspection.
|
||||
- Orchestrator-reported successful runs were reviewed:
|
||||
- `cargo fmt --check`
|
||||
- `cargo check -p pod -p manifest -p yoi`
|
||||
- focused pod/manifest/yoi plugin tests
|
||||
- `git diff --check`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Conclusion:
|
||||
- Previous request_changes blockers are resolved.
|
||||
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T15:32:56Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Merge / validation report:
|
||||
|
||||
Implementation branch `impl/00001KVFDX9AF-plugin-https-host-api` は Orchestrator worktree の `orchestration` branch に merge 済み。
|
||||
|
||||
Merge:
|
||||
- merge commit: `6beb8625` — `merge: plugin https host api`
|
||||
- implementation commits:
|
||||
- `7377527f` — `plugin: implement https host api`
|
||||
- `85683f17` — `plugin: harden https target validation`
|
||||
- changed files:
|
||||
- `Cargo.lock`
|
||||
- `crates/manifest/src/plugin.rs`
|
||||
- `crates/pod/Cargo.toml`
|
||||
- `crates/pod/src/feature/plugin.rs`
|
||||
- `crates/yoi/src/plugin_cli.rs`
|
||||
- `package.nix`
|
||||
|
||||
Validation in Orchestrator worktree after merge:
|
||||
- `cargo fmt --check` — passed
|
||||
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||
- `cargo test -p pod feature::plugin::tests -- --nocapture` — passed; 39 passed, 0 failed
|
||||
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||
- `git diff --check` — passed
|
||||
- `nix build .#yoi --no-link` — passed
|
||||
|
||||
Review:
|
||||
- First review requested changes for IPv4-mapped IPv6 private/local bypass and DNS validation TOCTOU.
|
||||
- Coder fixed target validation by applying IPv4 checks to mapped/compatible IPv6 forms and binding DNS validation to reqwest via validated address pinning.
|
||||
- Re-review `yoi-reviewer-00001KVFDX9AF-r2` returned `approve` with no remaining blockers.
|
||||
|
||||
Outcome:
|
||||
- Granted HTTPS host API is implemented for WASM Plugin Tools.
|
||||
- Missing grant denies before network access.
|
||||
- Host/method/path allowlist and HTTPS-only/private-local target restrictions are represented and tested.
|
||||
- DNS validation is pinned to the actual reqwest connection path.
|
||||
- Request/response bounds, timeout, no redirects, `no_proxy()`, secret redaction, ordinary Tool result path, and CLI inspection compatibility are present.
|
||||
- `fs` host API and Component Model migration remain non-goals for this Ticket.
|
||||
- Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T15:33:57Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Merge / validation report:
|
||||
|
||||
Implementation branch `impl/00001KVFDX9AF-plugin-https-host-api` は Orchestrator worktree の `orchestration` branch に merge 済み。
|
||||
|
||||
Merge:
|
||||
- merge commit: `6beb8625` — `merge: plugin https host api`
|
||||
- implementation commits:
|
||||
- `7377527f` — `plugin: implement https host api`
|
||||
- `85683f17` — `plugin: harden https target validation`
|
||||
- changed files:
|
||||
- `Cargo.lock`
|
||||
- `crates/manifest/src/plugin.rs`
|
||||
- `crates/pod/Cargo.toml`
|
||||
- `crates/pod/src/feature/plugin.rs`
|
||||
- `crates/yoi/src/plugin_cli.rs`
|
||||
- `package.nix`
|
||||
|
||||
Validation in Orchestrator worktree after merge:
|
||||
- `cargo fmt --check` — passed
|
||||
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||
- `cargo test -p pod feature::plugin::tests -- --nocapture` — passed; 39 passed, 0 failed
|
||||
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||
- `git diff --check` — passed
|
||||
- `nix build .#yoi --no-link` — passed
|
||||
|
||||
Review:
|
||||
- First review requested changes for IPv4-mapped IPv6 private/local bypass and DNS validation TOCTOU.
|
||||
- Coder fixed target validation by applying IPv4 checks to mapped/compatible IPv6 forms and binding DNS validation to reqwest via validated address pinning.
|
||||
- Re-review `yoi-reviewer-00001KVFDX9AF-r2` returned `approve` with no remaining blockers.
|
||||
|
||||
Outcome:
|
||||
- Granted HTTPS host API is implemented for WASM Plugin Tools.
|
||||
- Missing grant denies before network access.
|
||||
- Host/method/path allowlist and HTTPS-only/private-local target restrictions are represented and tested.
|
||||
- DNS validation is pinned to the actual reqwest connection path.
|
||||
- Request/response bounds, timeout, no redirects, `no_proxy()`, secret redaction, ordinary Tool result path, and CLI inspection compatibility are present.
|
||||
- `fs` host API and Component Model migration remain non-goals for this Ticket.
|
||||
- Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T15:35:11Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Cleanup report:
|
||||
|
||||
Plugin HTTPS host API Ticket の implementation/review Pods と child worktree を cleanup 済み。
|
||||
|
||||
Stopped Pods:
|
||||
- `yoi-coder-00001KVFDX9AF`
|
||||
- `yoi-reviewer-00001KVFDX9AF-r2`
|
||||
|
||||
Removed child implementation worktree:
|
||||
- `/home/hare/Projects/yoi/.worktree/00001KVFDX9AF-plugin-https-host-api`
|
||||
|
||||
Deleted merged implementation branch:
|
||||
- `impl/00001KVFDX9AF-plugin-https-host-api` at `85683f17`
|
||||
|
||||
Orchestrator branch remains the integration authority for this completed work. Root/original workspace was not touched for this Ticket, per Panel Queue instruction.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-19T15:35:22Z from: inprogress to: done reason: merged_validated_review_approved field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Implementation commits `7377527f` and `85683f17` were reviewed after blocker resolution, approved, merged into the Orchestrator branch as `6beb8625`, validated in the Orchestrator worktree, and child implementation resources were cleaned up. Requirements and acceptance criteria are satisfied for this Ticket. Root/original workspace was not operated on for this Ticket per Panel Queue instruction.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-19T15:35:45Z from: done to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-19T15:35:46Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Ticket `00001KVFDX9AF` is complete.
|
||||
|
||||
Completed implementation:
|
||||
- Added granted outbound HTTPS host API for WASM Plugin Tools.
|
||||
- Added typed `host_api.https` grant scope with host, method, optional path prefix, and bounded request/response options.
|
||||
- Implemented `yoi:https` WASM host import handling.
|
||||
- Enforced grant/allowlist checks before network access.
|
||||
- Enforced HTTPS-only behavior and rejected `http://`, embedded credentials, localhost/private/link-local/local targets, IPv4-mapped/compatible IPv6 private/local forms, and unsafe DNS results.
|
||||
- Bound DNS validation to the actual reqwest connection path by pinning validated public socket addresses with `resolve_to_addrs`.
|
||||
- Added request/response bounds, timeout, no redirects, `no_proxy()`, response truncation, and secret-like diagnostics redaction.
|
||||
- Preserved ordinary Tool result/history path and avoided hidden context injection.
|
||||
- Updated Plugin CLI inspection and manifest/permission model to expose HTTPS host API grant/diagnostic details.
|
||||
|
||||
Reviewed / merged:
|
||||
- Implementation commits:
|
||||
- `7377527f` (`plugin: implement https host api`)
|
||||
- `85683f17` (`plugin: harden https target validation`)
|
||||
- First review requested changes for IPv4-mapped IPv6 bypass and DNS validation TOCTOU.
|
||||
- Re-review approved with no remaining blockers.
|
||||
- Orchestrator merge commit: `6beb8625` (`merge: plugin https host api`)
|
||||
|
||||
Validation in Orchestrator worktree:
|
||||
- `cargo fmt --check` — passed
|
||||
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||
- `cargo test -p pod feature::plugin::tests -- --nocapture` — passed; 39 passed, 0 failed
|
||||
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||
- `git diff --check` — passed
|
||||
- `nix build .#yoi --no-link` — passed
|
||||
|
||||
Cleanup:
|
||||
- Stopped Coder Pod `yoi-coder-00001KVFDX9AF`.
|
||||
- Stopped Reviewer Pod `yoi-reviewer-00001KVFDX9AF-r2`.
|
||||
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KVFDX9AF-plugin-https-host-api`.
|
||||
- Deleted merged branch `impl/00001KVFDX9AF-plugin-https-host-api`.
|
||||
|
||||
Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction. The completed work is integrated on the Orchestrator branch.
|
||||
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
{"id":"orch-plan-20260619-102132-1","ticket_id":"00001KVFDX9AY","kind":"waiting_capacity_note","note":"明示 queue review で確認済み。依存 Ticket `00001KV5W3PHW` / `00001KV5W3PJ3` は closed で blocker ではないが、同時 queued の `00001KVFD3YSV` CLI inspection と `00001KVFDX9AF` https host API はいずれも Plugin manifest/grant/runtime/diagnostic 周辺を触る。まず read-only CLI inspection を開始し、host API implementation は conflict / reviewer-coder bottleneck を避けるため queued のまま待機する。次の routing pass で再確認する。","author":"yoi-orchestrator","at":"2026-06-19T10:21:32Z"}
|
||||
{"id":"orch-plan-20260619-102132-2","ticket_id":"00001KVFDX9AY","kind":"do_not_parallelize","related_ticket":"00001KVFDX9AF","note":"`fs` と `https` host API はどちらも WASM Plugin Tool runtime host import boundary、Plugin grant model、diagnostics/tests/package behavior に触れるため、同時実装は conflict risk が高い。片方の merged/validated 後にもう片方を再 routing する。","author":"yoi-orchestrator","at":"2026-06-19T10:21:32Z"}
|
||||
{"id":"orch-plan-20260619-142431-3","ticket_id":"00001KVFDX9AY","kind":"waiting_capacity_note","note":"`00001KVFD3YSV` Plugin CLI inspection は closed になったため再 routing した。`https` host API Ticket `00001KVFDX9AF` を先に受理する。`fs` host API は既存 do_not_parallelize record の通り WASM Plugin Tool runtime host import boundary、Plugin grant model、diagnostics/tests/package behavior が重なるため、`https` の merge/validation outcome まで queued のまま待機する。Bounded reason: conflict / reviewer-coder bottleneck。","author":"yoi-orchestrator","at":"2026-06-19T14:24:31Z"}
|
||||
{"id":"orch-plan-20260619-153644-4","ticket_id":"00001KVFDX9AY","kind":"accepted_plan","accepted_plan":{"summary":"WASM Plugin Tool runtime に明示 grant された scoped filesystem `fs` host API を追加する。read/list/write initial subset、path normalization、traversal/symlink/root escape rejection、bounds、safe diagnostics、file mutation safety、no ambient workspace filesystem inheritance を満たす。","branch":"impl/00001KVFDX9AY-plugin-fs-host-api","worktree":"/home/hare/Projects/yoi/.worktree/00001KVFDX9AY-plugin-fs-host-api","role_plan":"Orchestrator は専用 implementation worktree を作成し、Coder をその worktree への narrow write scope で起動する。Reviewer は実装報告後に read-only で確認する。Component Model migration は Plugin runtime/host API/WIT migration boundary として queued hold を維持する。"},"author":"yoi-orchestrator","at":"2026-06-19T15:36:44Z"}
|
||||
@@ -0,0 +1,37 @@
|
||||
{
|
||||
"version": 1,
|
||||
"relations": [
|
||||
{
|
||||
"ticket_id": "00001KVFDX9AY",
|
||||
"kind": "depends_on",
|
||||
"target": "00001KV5W3PHW",
|
||||
"note": "fs host API is implemented inside the WASM Plugin Tool runtime.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T07:54:32Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVFDX9AY",
|
||||
"kind": "depends_on",
|
||||
"target": "00001KV5W3PJ3",
|
||||
"note": "fs host API must be guarded by Plugin permission grants.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T07:54:32Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVFDX9AY",
|
||||
"kind": "related",
|
||||
"target": "00001KSXRQ4G8",
|
||||
"note": "Uses established Plugin host API terminology.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T07:54:32Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVFDX9AY",
|
||||
"kind": "related",
|
||||
"target": "00001KVFD3YSV",
|
||||
"note": "Inspection CLI should expose fs host API grants/diagnostics.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T07:54:32Z"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,90 @@
|
||||
---
|
||||
title: 'Plugin: implement fs host API for Tool runtime'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-19T07:53:13Z'
|
||||
updated_at: '2026-06-19T16:17:51Z'
|
||||
assignee: null
|
||||
readiness: 'implementation_ready'
|
||||
risk_flags: ['plugin', 'fs', 'host-api', 'sandbox', 'path-safety', 'permission-grants', 'file-mutation']
|
||||
queued_by: 'workspace-panel'
|
||||
queued_at: '2026-06-19T10:19:52Z'
|
||||
---
|
||||
|
||||
## Background
|
||||
|
||||
Plugin Tool runtime は minimal WASM execution と permission grants まで実装済みだが、Plugin-layer scoped filesystem access はまだ未実装である。
|
||||
|
||||
この Ticket では、WASM Plugin Tool から明示 grant された scoped paths のみを read/list/write できる `fs` host API を追加する。Plugin は Pod / workspace の filesystem authority を自動継承しない。Plugin-specific grant だけが有効な authority になる。
|
||||
|
||||
## Requirements
|
||||
|
||||
- WASM Plugin Tool runtime に `fs` host API import を追加する。
|
||||
- API 名・ABI は既存 `yoi-plugin-wasm-1` / host import 設計と整合させる。
|
||||
- Plugin は ambient filesystem access を持たず、host API 経由のみで fs operation できる。
|
||||
- Plugin-layer scoped paths を grant で表現する。
|
||||
- read
|
||||
- list
|
||||
- write の初期 subset
|
||||
- optional path root / glob / prefix policy は implementation-time に最小安全形を選ぶ。
|
||||
- Workspace filesystem scope を自動継承しない。
|
||||
- Pod が workspace write authority を持っていても Plugin は grant なしでは読めない/書けない。
|
||||
- Path safety を徹底する。
|
||||
- normalization
|
||||
- `..` traversal reject
|
||||
- symlink/root escape reject
|
||||
- absolute/relative path policy を明確化
|
||||
- allowed root 外は fail closed
|
||||
- Bounds を設ける。
|
||||
- read size bound
|
||||
- write size bound
|
||||
- directory entry count bound
|
||||
- path length bound
|
||||
- diagnostic size bound
|
||||
- Writes は既存 file mutation safety と整合させる。
|
||||
- normalized target file ごとの serialization / atomic-ish behavior を検討する。
|
||||
- broad Worker scheduler は追加しない。
|
||||
- Diagnostics は safe にする。
|
||||
- file content を error/log に漏らさない。
|
||||
- rejected path は必要最小限にする。
|
||||
- Tool result path は通常 Tool result/history 経路を使う。
|
||||
- hidden context injection しない。
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Granted Plugin Tool can read an allowed file through `fs` host API.
|
||||
- Granted Plugin Tool can list an allowed directory within bounds.
|
||||
- Granted Plugin Tool can write an allowed file within bounds.
|
||||
- Plugin without matching `host_api.fs` grant cannot read/list/write.
|
||||
- Workspace write authority is not inherited by Plugin without Plugin grant.
|
||||
- `../` traversal, symlink escape, and allowed-root escape are rejected.
|
||||
- Oversize read/write/list results fail closed or truncate according to explicit policy.
|
||||
- File mutation safety does not race unsafely with existing Write/Edit semantics.
|
||||
- Diagnostics do not include file content or secret-like data.
|
||||
- Tests cover:
|
||||
- allowed read
|
||||
- allowed list
|
||||
- allowed write
|
||||
- missing grant denied
|
||||
- workspace authority not inherited
|
||||
- path traversal rejected
|
||||
- symlink/root escape rejected
|
||||
- read/write/list bounds
|
||||
- diagnostics redaction
|
||||
- write serialization or safe conflict behavior
|
||||
- Validation: focused plugin fs tests, relevant cargo check/test, `cargo fmt --check`, `git diff --check`, and `nix build .#yoi` because host API / packaging behavior may change.
|
||||
|
||||
## Non-goals
|
||||
|
||||
- `https` host API implementation.
|
||||
- General workspace Read/Write tool delegation.
|
||||
- Service / Ingress surface.
|
||||
- File watcher / background sync.
|
||||
- Broad WASI filesystem exposure.
|
||||
- Plugin package manager / install/update.
|
||||
|
||||
## Related work
|
||||
|
||||
- `00001KV5W3PHW` — Plugin Tool execution with minimal WASM runtime.
|
||||
- `00001KV5W3PJ3` — Plugin permission grant enforcement.
|
||||
- `00001KVFD3YSV` — Plugin read-only CLI inspection list/show.
|
||||
- `00001KSXRQ4G8` — Plugin runtime / surface / minimal host API model design.
|
||||
@@ -0,0 +1,33 @@
|
||||
Ticket `00001KVFDX9AY` is complete.
|
||||
|
||||
Completed implementation:
|
||||
- Added granted scoped filesystem `fs` host API for WASM Plugin Tools.
|
||||
- Added `PluginFsGrant { root, operations }` and `PluginFsOperation::{read,list,write}` to the Plugin grant model.
|
||||
- Implemented `yoi:fs` WASM host imports for read/list/write with response buffer handling.
|
||||
- Enforced Plugin-specific grants before filesystem access; Plugin Tools do not inherit Pod/workspace filesystem authority.
|
||||
- Added path safety for relative-only requests, traversal rejection, symlink/root escape rejection, canonical root checks, and Unix `O_NOFOLLOW` for writes.
|
||||
- Added read/list/write bounds, explicit truncation/fail-closed behavior, write serialization by normalized/canonical target, and bounded/redacted diagnostics.
|
||||
- Updated Plugin CLI inspection to show configured fs grants.
|
||||
|
||||
Reviewed / merged:
|
||||
- Implementation commit: `717c0999` (`plugin: implement fs host api`)
|
||||
- Reviewer result: approve, no blockers.
|
||||
- Reviewer noted a non-blocking future hardening context: the current implementation is path/canonicalization based and does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is accepted within the feasible scope of the initial subset.
|
||||
- Orchestrator merge commit: `c94e157b` (`merge: plugin fs host api`)
|
||||
|
||||
Validation in Orchestrator worktree:
|
||||
- `cargo fmt --check` — passed
|
||||
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||
- `cargo test -p pod feature::plugin -- --nocapture` — passed; 48 passed, 0 failed
|
||||
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||
- `git diff --check` — passed
|
||||
- `nix build .#yoi --no-link` — passed
|
||||
|
||||
Cleanup:
|
||||
- Stopped Coder Pod `yoi-coder-00001KVFDX9AY`.
|
||||
- Stopped Reviewer Pod `yoi-reviewer-00001KVFDX9AY`.
|
||||
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KVFDX9AY-plugin-fs-host-api`.
|
||||
- Deleted merged branch `impl/00001KVFDX9AY-plugin-fs-host-api`.
|
||||
|
||||
Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction. The completed work is integrated on the Orchestrator branch.
|
||||
@@ -0,0 +1,870 @@
|
||||
<!-- event: create author: "yoi ticket" at: 2026-06-19T07:53:13Z -->
|
||||
|
||||
## 作成
|
||||
|
||||
LocalTicketBackend によって作成されました。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: workspace-panel at: 2026-06-19T10:19:52Z from: ready to: queued reason: queued field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を `workspace-panel` が queued にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: plan author: yoi-orchestrator at: 2026-06-19T10:22:26Z -->
|
||||
|
||||
## Plan
|
||||
|
||||
Routing hold / waiting-capacity note:
|
||||
|
||||
明示 queue review で Ticket body / relations / orchestration plan / workspace state を確認した。
|
||||
|
||||
Current decision:
|
||||
- この Ticket は `queued` のまま待機。
|
||||
- 依存 Ticket `00001KV5W3PHW` / `00001KV5W3PJ3` は closed で dependency blocker ではない。
|
||||
- ただし同時 queued の `00001KVFD3YSV` CLI inspection を先に受理した。CLI inspection は Plugin discovery / enablement / grants / diagnostics の read-only public surface を作る作業で、host API implementation と同じ Plugin manifest/grant/runtime/diagnostic 周辺に触れる。
|
||||
- `00001KVFDX9AF` https host API とは WASM Plugin Tool runtime host import boundary、Plugin grant model、diagnostics/tests/package behavior の変更面が重なるため `do_not_parallelize` plan record を残した。
|
||||
|
||||
Bounded reason for idle queued:
|
||||
- conflict / reviewer-coder bottleneck。
|
||||
|
||||
Next action:
|
||||
- `00001KVFD3YSV` の implementation/review/merge outcome を確認後、queued のまま再 routing する。
|
||||
- その時点で `https` host API Ticket との ordering / conflict も再確認する。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: decision author: yoi-orchestrator at: 2026-06-19T15:37:24Z -->
|
||||
|
||||
## Decision
|
||||
|
||||
Routing decision: implementation_ready
|
||||
|
||||
Reason:
|
||||
- Panel Queue により、この Ticket は Orchestrator routing 対象として明示許可された。
|
||||
- Ticket body には、`fs` host API intent、binding invariants、acceptance criteria、non-goals、validation、escalation-worthy risk domain が実装可能な粒度で揃っている。
|
||||
- 依存 relation の `00001KV5W3PHW` minimal WASM runtime、`00001KV5W3PJ3` permission grants、関連 `00001KVFD3YSV` CLI inspection、`00001KVFDX9AF` HTTPS host API は closed で blocker ではない。
|
||||
- Risk domain は filesystem / path safety / file mutation / permission grants だが、Ticket は Plugin-specific grants、no workspace authority inheritance、path normalization、traversal/symlink/root escape rejection、bounds、safe diagnostics、ordinary Tool result path を binding invariants として明示している。bounded context check 後も implementation 前に必要な追加 human decision は見つからなかった。
|
||||
- `00001KVG0HR96` Component Model migration は Plugin runtime / WIT / host API shape / grants / inspection / packaging に広く触れる migration boundary で、active `fs` host API と衝突しやすいため waiting note を更新し queued のまま待機する。
|
||||
|
||||
Evidence checked:
|
||||
- Ticket `00001KVFDX9AY` body / thread / artifacts。
|
||||
- `TicketRelationQuery(00001KVFDX9AY)`: depends_on は closed。related Ticket は context であり acceptance blocker ではない。
|
||||
- `TicketOrchestrationPlanQuery(00001KVFDX9AY)`: prior waiting/do_not_parallelize records を確認。HTTPS host API は closed になったため今回 `accepted_plan` を記録済み。
|
||||
- Related completed Tickets:
|
||||
- `00001KV5W3PHW` — minimal WASM Tool runtime closed。
|
||||
- `00001KV5W3PJ3` — Plugin permission grants closed。
|
||||
- `00001KVFD3YSV` — Plugin read-only CLI inspection closed。
|
||||
- `00001KVFDX9AF` — Plugin HTTPS host API closed。
|
||||
- Current queued Ticket `00001KVG0HR96` Component Model migration: migration boundary / conflict waiting note を更新。
|
||||
- Orchestrator worktree `/home/hare/Projects/yoi/.worktree/orchestration`: clean。
|
||||
- Existing branch/worktree: matching `00001KVFDX9AY` branch/worktree はなし。
|
||||
- Visible Pods: self / peers only; spawned child capacity is free。
|
||||
- Current code map:
|
||||
- `crates/pod/src/feature/plugin.rs`: Plugin resolver, permission grants, static inspection, host API eligibility, HTTPS implementation pattern。
|
||||
- `crates/pod/src/pod.rs`: WASM Tool runtime / host import validation / Tool execution path。
|
||||
- `crates/manifest/src/plugin.rs`: Plugin manifest and permission model。
|
||||
- `crates/yoi/src/plugin_cli.rs`: read-only inspection output should remain compatible with fs host API diagnostics。
|
||||
|
||||
IntentPacket:
|
||||
|
||||
Intent:
|
||||
- WASM Plugin Tool runtime に、明示 grant された scoped path のみ read/list/write できる `fs` host API を追加する。
|
||||
- Plugin は Pod/workspace filesystem authority を自動継承せず、Plugin-specific `host_api.fs` grants だけが filesystem authority になる。
|
||||
|
||||
Binding decisions / invariants:
|
||||
- Host API name/domain は `fs`。
|
||||
- Broad WASI filesystem exposure は禁止。Plugin は ambient filesystem access を持たない。
|
||||
- Workspace read/write authority は Plugin に自動継承しない。
|
||||
- Grant がない read/list/write は fail closed。
|
||||
- Grants は operation kind (`read`, `list`, `write`) と scoped root/prefix/glob 等の最小安全形を持つ。
|
||||
- Path normalization、`..` traversal rejection、symlink/root escape rejection、allowed root outside rejection は binding。
|
||||
- Absolute/relative path policy は明確にし、safe default を選ぶ。
|
||||
- Bounds: path length、read size、write size、directory entry count、diagnostic size。
|
||||
- Writes は existing file mutation safety と整合し、normalized target file ごとに unsafe race を避ける。
|
||||
- Diagnostics に file content / secret-like data を漏らさない。
|
||||
- Tool result path は ordinary Tool result/history path。hidden context injection しない。
|
||||
- `https` host API、Service/Ingress/File watcher/package manager は non-goals。
|
||||
|
||||
Requirements / acceptance criteria:
|
||||
- Granted Plugin Tool can read an allowed file。
|
||||
- Granted Plugin Tool can list an allowed directory within bounds。
|
||||
- Granted Plugin Tool can write an allowed file within bounds。
|
||||
- Plugin without matching `host_api.fs` grant cannot read/list/write。
|
||||
- Workspace authority is not inherited by Plugin without Plugin grant。
|
||||
- `../` traversal、symlink escape、allowed-root escape reject。
|
||||
- Oversize read/write/list fail closed or truncate according to explicit policy。
|
||||
- File mutation safety avoids unsafe race with existing Write/Edit semantics。
|
||||
- Diagnostics do not include file content or secret-like data。
|
||||
- Tests cover allowed read/list/write, missing grant denied, workspace authority not inherited, traversal/symlink/root escape, bounds, diagnostics redaction, safe write conflict behavior。
|
||||
|
||||
Implementation latitude:
|
||||
- Choose exact ABI/import shape consistent with existing `yoi-plugin-wasm-1` host import design and current HTTPS host API pattern。
|
||||
- Choose narrow grant config representation for root/prefix/glob/operation allowlist consistent with current Plugin permission grant model。
|
||||
- Use tempdir/local fixture files for deterministic tests。
|
||||
- Choose read/list/write response shape consistent with existing Tool result/error types and CLI inspection structure。
|
||||
- If write serialization requires reusing existing file mutation primitives, keep it narrow and avoid broad Worker scheduler changes。
|
||||
|
||||
Escalate if:
|
||||
- Safe path/symlink/root escape handling cannot be represented without broad filesystem authority redesign。
|
||||
- write serialization requires broad Worker scheduler or global mutation system redesign。
|
||||
- Existing Plugin grant schema cannot safely represent fs scopes without breaking HTTPS grants/CLI inspection。
|
||||
- Broad WASI filesystem exposure appears necessary。
|
||||
- Product decision is needed for truncate-vs-fail policy beyond Ticket’s bounded latitude。
|
||||
|
||||
Validation:
|
||||
- Focused plugin fs host API tests。
|
||||
- Relevant `cargo test` / `cargo check` for `pod`, `manifest`, `yoi` as changed。
|
||||
- `cargo fmt --check`。
|
||||
- `git diff --check`。
|
||||
- `nix build .#yoi --no-link` / `nix build .#yoi` if dependency/package-source-filter changes occur。
|
||||
|
||||
Critical risks / reviewer focus:
|
||||
- Workspace authority leaking into Plugin without Plugin grant。
|
||||
- Path traversal / symlink / root escape bypass。
|
||||
- Write race / unsafe mutation behavior。
|
||||
- File content or secret leakage in diagnostics。
|
||||
- Unbounded read/list/write outputs。
|
||||
- Hidden context injection by bypassing normal Tool result path。
|
||||
- Breaking existing HTTPS host API, permission grants, or CLI inspection semantics。
|
||||
|
||||
Next action:
|
||||
- `queued -> inprogress` を記録し、Ticket records を Orchestrator worktree に commit してから、専用 implementation worktree を作成し Coder Pod を narrow write scope で起動する。root/original workspace は操作しない。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-19T15:37:38Z from: queued to: inprogress reason: orchestrator_acceptance_plugin_fs_host_api field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket body/thread, relation metadata, orchestration plan records, related completed Tickets, Orchestrator worktree, visible Pods, existing branch/worktree, and bounded Plugin fs host API code context were checked. Depends-on blockers are closed, HTTPS host API and CLI inspection related work are closed, and no dirty-state blocker or missing planning decision was found. Component Model migration remains queued with migration/conflict waiting record. Accepting this queued Ticket for implementation before worktree/Pod side effects.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T15:39:09Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Implementation start note:
|
||||
|
||||
`queued -> inprogress` acceptance、accepted plan、routing decision / IntentPacket、Component Model migration の waiting record を記録し、Orchestrator worktree で commit した後に、専用 implementation worktree と Coder Pod を起動した。
|
||||
|
||||
Worktree:
|
||||
- `/home/hare/Projects/yoi/.worktree/00001KVFDX9AY-plugin-fs-host-api`
|
||||
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||
|
||||
Coder Pod:
|
||||
- `yoi-coder-00001KVFDX9AY`
|
||||
|
||||
Scope / boundaries:
|
||||
- child runtime workspace root は read scope。
|
||||
- implementation worktree は write scope。
|
||||
- root/original workspace と Orchestrator worktree へは書き込まないよう指示済み。
|
||||
- `.yoi/memory`、runtime/log/lock/local/secret-like `.yoi` paths は編集しないよう指示済み。
|
||||
|
||||
Related queued Ticket:
|
||||
- `00001KVG0HR96` Component Model migration remains queued due migration boundary / conflict with active fs host API work.
|
||||
|
||||
Next:
|
||||
- Coder は scoped `fs` host API implementation、focused tests、validation、implementation commit を行い、実装報告を返す予定。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T16:01:41Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Coder implementation report received / Orchestrator validation:
|
||||
|
||||
Implementation commit:
|
||||
- `717c0999` — `plugin: implement fs host api`
|
||||
|
||||
Summary:
|
||||
- Added manifest/config support for `host_api.fs` grants:
|
||||
- `PluginFsGrant { root, operations }`
|
||||
- `PluginFsOperation::{read,list,write}`
|
||||
- Implemented WASM host import module `yoi:fs` with:
|
||||
- `read`
|
||||
- `list`
|
||||
- `write`
|
||||
- `response_len`
|
||||
- `response_read`
|
||||
- Enforced plugin-specific grant checks; Pod/workspace fs authority is not inherited.
|
||||
- Added path safety:
|
||||
- relative-only request paths;
|
||||
- `..` traversal rejection;
|
||||
- configured root must be absolute/non-symlink directory;
|
||||
- symlink component/target rejection;
|
||||
- canonical allowed-root escape checks.
|
||||
- Added bounds:
|
||||
- request descriptor size;
|
||||
- path length;
|
||||
- read size with explicit truncation flag;
|
||||
- write size fail-closed;
|
||||
- directory entry count with explicit truncation flag.
|
||||
- Added write serialization by normalized target plus `O_NOFOLLOW` on Unix.
|
||||
- Kept fs errors/diagnostics bounded and redacted.
|
||||
- Extended Plugin CLI inspection to show configured fs grants.
|
||||
|
||||
Files changed:
|
||||
- `crates/manifest/src/plugin.rs`
|
||||
- `crates/pod/src/feature/plugin.rs`
|
||||
- `crates/yoi/src/plugin_cli.rs`
|
||||
|
||||
Coder reported validation:
|
||||
- `cargo fmt --check` — passed
|
||||
- `cargo test -p pod feature::plugin` — passed
|
||||
- `cargo test -p manifest plugin` — passed
|
||||
- `cargo test -p yoi plugin_cli` — passed
|
||||
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||
- `git diff --check` — passed
|
||||
- `nix build` not run by Coder because no dependency/package-source-filter changes.
|
||||
|
||||
Orchestrator evidence checked:
|
||||
- Pod output を確認。
|
||||
- implementation worktree は clean。
|
||||
- branch `impl/00001KVFDX9AY-plugin-fs-host-api` HEAD は `717c0999`。
|
||||
- diff stat from accepted base `6711bcf3..717c0999`: 3 files changed, 1068 insertions, 17 deletions。
|
||||
|
||||
Validation re-run by Orchestrator in implementation worktree:
|
||||
- `cargo fmt --check` — passed
|
||||
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||
- `cargo test -p pod feature::plugin -- --nocapture` — passed; 48 passed, 0 failed
|
||||
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||
- `git diff --check` — passed
|
||||
- `nix build .#yoi --no-link` — passed
|
||||
|
||||
Routing classification: review_needed
|
||||
|
||||
Next action:
|
||||
- recorded intent / invariants / acceptance criteria に照らして、read-only Reviewer Pod で外部レビューする。
|
||||
- 特に no ambient workspace fs authority、grant-before-filesystem access、path traversal/symlink/root escape、bounds/truncation/fail-closed policy、write serialization/O_NOFOLLOW、diagnostic redaction、ordinary Tool result path、HTTPS/CLI compatibility を確認する。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: plan author: yoi-orchestrator at: 2026-06-19T16:02:39Z -->
|
||||
|
||||
## Plan
|
||||
|
||||
Review dispatch:
|
||||
|
||||
Reviewer Pod `yoi-reviewer-00001KVFDX9AY` を read-only scope で起動した。
|
||||
|
||||
Review target:
|
||||
- worktree: `/home/hare/Projects/yoi/.worktree/00001KVFDX9AY-plugin-fs-host-api`
|
||||
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||
- commit: `717c0999`
|
||||
|
||||
Reviewer focus:
|
||||
- recorded intent / invariants / acceptance criteria に対する適合性。
|
||||
- filesystem access が grant checks の前に発生しないこと。
|
||||
- Workspace/POD filesystem authority が Plugin に自動継承されていないこと。
|
||||
- traversal / symlink / root escape protections が canonicalization races を含め妥当であること。
|
||||
- read/list/write bounds と truncate-vs-fail-closed policy が明確で enforce されること。
|
||||
- write serialization by normalized target と `O_NOFOLLOW` が既存 file mutation safety と整合すること。portability issue がないこと。
|
||||
- diagnostics に file content / secret-like data が漏れないこと。
|
||||
- ordinary Tool result/history path だけに戻ること。
|
||||
- tests が allowed read/list/write、missing grant、no workspace inheritance、traversal、symlink/root escape、bounds、redaction、write safety を十分に覆うこと。
|
||||
- manifest/permission grant schema と CLI inspection changes が既存 HTTPS grants / Plugin inspection behavior と互換であること。
|
||||
- HTTPS host API と Component Model migration が non-goals として保たれていること。
|
||||
|
||||
Next:
|
||||
- Reviewer output を確認し、approve なら Orchestrator worktree への merge/validation/cleanup/close-ready 処理へ進む。request_changes なら blocker を記録して Coder に戻す。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:08:53Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Review result: approve
|
||||
|
||||
対象:
|
||||
- Ticket: `00001KVFDX9AY`
|
||||
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||
|
||||
No blockers found.
|
||||
|
||||
Evidence reviewed:
|
||||
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||
- Permission/grant binding is layered correctly:
|
||||
- requested `host_api.fs` permission required;
|
||||
- configured grant permission required;
|
||||
- usable FS scope required;
|
||||
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||
- Path safety is materially addressed:
|
||||
- absolute paths, NULs, and `..` traversal rejected;
|
||||
- grant root must be absolute, existing, directory, and not final symlink;
|
||||
- request path components are symlink-checked;
|
||||
- canonicalized targets must remain under the canonical grant root;
|
||||
- write target symlinks/dirs rejected;
|
||||
- Unix writes add `O_NOFOLLOW`.
|
||||
- Bounds are explicit:
|
||||
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||
- read/list truncation is explicit via `truncated`;
|
||||
- oversize write fails closed.
|
||||
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||
|
||||
Reviewer validation:
|
||||
- Static review of changed files and relevant tests.
|
||||
- Confirmed worktree branch/head.
|
||||
- `git diff --check 717c0999^..717c0999` — passed.
|
||||
- Orchestrator-reported validation was reviewed:
|
||||
- `cargo fmt --check`
|
||||
- `cargo check -p pod -p manifest -p yoi`
|
||||
- `cargo test -p pod feature::plugin`
|
||||
- `cargo test -p manifest plugin`
|
||||
- `cargo test -p yoi plugin_cli`
|
||||
- `git diff --check`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Non-blocking risk noted:
|
||||
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the “feasible scope” of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||
|
||||
Conclusion:
|
||||
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:09:17Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Review result: approve
|
||||
|
||||
対象:
|
||||
- Ticket: `00001KVFDX9AY`
|
||||
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||
|
||||
No blockers found.
|
||||
|
||||
Evidence reviewed:
|
||||
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||
- Permission/grant binding is layered correctly:
|
||||
- requested `host_api.fs` permission required;
|
||||
- configured grant permission required;
|
||||
- usable FS scope required;
|
||||
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||
- Path safety is materially addressed:
|
||||
- absolute paths, NULs, and `..` traversal rejected;
|
||||
- grant root must be absolute, existing, directory, and not final symlink;
|
||||
- request path components are symlink-checked;
|
||||
- canonicalized targets must remain under the canonical grant root;
|
||||
- write target symlinks/dirs rejected;
|
||||
- Unix writes add `O_NOFOLLOW`.
|
||||
- Bounds are explicit:
|
||||
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||
- read/list truncation is explicit via `truncated`;
|
||||
- oversize write fails closed.
|
||||
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||
|
||||
Reviewer validation:
|
||||
- Static review of changed files and relevant tests.
|
||||
- Confirmed worktree branch/head.
|
||||
- `git diff --check 717c0999^..717c0999` — passed.
|
||||
- Orchestrator-reported validation was reviewed:
|
||||
- `cargo fmt --check`
|
||||
- `cargo check -p pod -p manifest -p yoi`
|
||||
- `cargo test -p pod feature::plugin`
|
||||
- `cargo test -p manifest plugin`
|
||||
- `cargo test -p yoi plugin_cli`
|
||||
- `git diff --check`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Non-blocking risk noted:
|
||||
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the feasible scope of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||
|
||||
Conclusion:
|
||||
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:09:50Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Review result: approve
|
||||
|
||||
対象:
|
||||
- Ticket: `00001KVFDX9AY`
|
||||
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||
|
||||
No blockers found.
|
||||
|
||||
Evidence reviewed:
|
||||
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||
- Permission/grant binding is layered correctly:
|
||||
- requested `host_api.fs` permission required;
|
||||
- configured grant permission required;
|
||||
- usable FS scope required;
|
||||
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||
- Path safety is materially addressed:
|
||||
- absolute paths, NULs, and `..` traversal rejected;
|
||||
- grant root must be absolute, existing, directory, and not final symlink;
|
||||
- request path components are symlink-checked;
|
||||
- canonicalized targets must remain under the canonical grant root;
|
||||
- write target symlinks/dirs rejected;
|
||||
- Unix writes add `O_NOFOLLOW`.
|
||||
- Bounds are explicit:
|
||||
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||
- read/list truncation is explicit via `truncated`;
|
||||
- oversize write fails closed.
|
||||
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||
|
||||
Reviewer validation:
|
||||
- Static review of changed files and relevant tests.
|
||||
- Confirmed worktree branch/head.
|
||||
- `git diff --check 717c0999^..717c0999` — passed.
|
||||
- Orchestrator-reported validation was reviewed:
|
||||
- `cargo fmt --check`
|
||||
- `cargo check -p pod -p manifest -p yoi`
|
||||
- `cargo test -p pod feature::plugin`
|
||||
- `cargo test -p manifest plugin`
|
||||
- `cargo test -p yoi plugin_cli`
|
||||
- `git diff --check`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Non-blocking risk noted:
|
||||
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the feasible scope of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||
|
||||
Conclusion:
|
||||
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:10:26Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Review result: approve
|
||||
|
||||
対象:
|
||||
- Ticket: `00001KVFDX9AY`
|
||||
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||
|
||||
No blockers found.
|
||||
|
||||
Evidence reviewed:
|
||||
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||
- Permission/grant binding is layered correctly:
|
||||
- requested `host_api.fs` permission required;
|
||||
- configured grant permission required;
|
||||
- usable FS scope required;
|
||||
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||
- Path safety is materially addressed:
|
||||
- absolute paths, NULs, and `..` traversal rejected;
|
||||
- grant root must be absolute, existing, directory, and not final symlink;
|
||||
- request path components are symlink-checked;
|
||||
- canonicalized targets must remain under the canonical grant root;
|
||||
- write target symlinks/dirs rejected;
|
||||
- Unix writes add `O_NOFOLLOW`.
|
||||
- Bounds are explicit:
|
||||
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||
- read/list truncation is explicit via `truncated`;
|
||||
- oversize write fails closed.
|
||||
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||
|
||||
Reviewer validation:
|
||||
- Static review of changed files and relevant tests.
|
||||
- Confirmed worktree branch/head.
|
||||
- `git diff --check 717c0999^..717c0999` — passed.
|
||||
- Orchestrator-reported validation was reviewed:
|
||||
- `cargo fmt --check`
|
||||
- `cargo check -p pod -p manifest -p yoi`
|
||||
- `cargo test -p pod feature::plugin`
|
||||
- `cargo test -p manifest plugin`
|
||||
- `cargo test -p yoi plugin_cli`
|
||||
- `git diff --check`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Non-blocking risk noted:
|
||||
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the feasible scope of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||
|
||||
Conclusion:
|
||||
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:11:01Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Review result: approve
|
||||
|
||||
対象:
|
||||
- Ticket: `00001KVFDX9AY`
|
||||
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||
|
||||
No blockers found.
|
||||
|
||||
Evidence reviewed:
|
||||
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||
- Permission/grant binding is layered correctly:
|
||||
- requested `host_api.fs` permission required;
|
||||
- configured grant permission required;
|
||||
- usable FS scope required;
|
||||
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||
- Path safety is materially addressed:
|
||||
- absolute paths, NULs, and `..` traversal rejected;
|
||||
- grant root must be absolute, existing, directory, and not final symlink;
|
||||
- request path components are symlink-checked;
|
||||
- canonicalized targets must remain under the canonical grant root;
|
||||
- write target symlinks/dirs rejected;
|
||||
- Unix writes add `O_NOFOLLOW`.
|
||||
- Bounds are explicit:
|
||||
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||
- read/list truncation is explicit via `truncated`;
|
||||
- oversize write fails closed.
|
||||
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||
|
||||
Reviewer validation:
|
||||
- Static review of changed files and relevant tests.
|
||||
- Confirmed worktree branch/head.
|
||||
- `git diff --check 717c0999^..717c0999` — passed.
|
||||
- Orchestrator-reported validation was reviewed:
|
||||
- `cargo fmt --check`
|
||||
- `cargo check -p pod -p manifest -p yoi`
|
||||
- `cargo test -p pod feature::plugin`
|
||||
- `cargo test -p manifest plugin`
|
||||
- `cargo test -p yoi plugin_cli`
|
||||
- `git diff --check`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Non-blocking risk noted:
|
||||
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the feasible scope of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||
|
||||
Conclusion:
|
||||
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:11:47Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Review result: approve
|
||||
|
||||
対象:
|
||||
- Ticket: `00001KVFDX9AY`
|
||||
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||
|
||||
No blockers found.
|
||||
|
||||
Evidence reviewed:
|
||||
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||
- Permission/grant binding is layered correctly:
|
||||
- requested `host_api.fs` permission required;
|
||||
- configured grant permission required;
|
||||
- usable FS scope required;
|
||||
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||
- Path safety is materially addressed:
|
||||
- absolute paths, NULs, and `..` traversal rejected;
|
||||
- grant root must be absolute, existing, directory, and not final symlink;
|
||||
- request path components are symlink-checked;
|
||||
- canonicalized targets must remain under the canonical grant root;
|
||||
- write target symlinks/dirs rejected;
|
||||
- Unix writes add `O_NOFOLLOW`.
|
||||
- Bounds are explicit:
|
||||
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||
- read/list truncation is explicit via `truncated`;
|
||||
- oversize write fails closed.
|
||||
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||
|
||||
Reviewer validation:
|
||||
- Static review of changed files and relevant tests.
|
||||
- Confirmed worktree branch/head.
|
||||
- `git diff --check 717c0999^..717c0999` — passed.
|
||||
- Orchestrator-reported validation was reviewed:
|
||||
- `cargo fmt --check`
|
||||
- `cargo check -p pod -p manifest -p yoi`
|
||||
- `cargo test -p pod feature::plugin`
|
||||
- `cargo test -p manifest plugin`
|
||||
- `cargo test -p yoi plugin_cli`
|
||||
- `git diff --check`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Non-blocking risk noted:
|
||||
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the feasible scope of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||
|
||||
Conclusion:
|
||||
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:12:41Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Review result: approve
|
||||
|
||||
対象:
|
||||
- Ticket: `00001KVFDX9AY`
|
||||
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||
|
||||
No blockers found.
|
||||
|
||||
Evidence reviewed:
|
||||
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||
- Permission/grant binding is layered correctly:
|
||||
- requested `host_api.fs` permission required;
|
||||
- configured grant permission required;
|
||||
- usable FS scope required;
|
||||
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||
- Path safety is materially addressed:
|
||||
- absolute paths, NULs, and `..` traversal rejected;
|
||||
- grant root must be absolute, existing, directory, and not final symlink;
|
||||
- request path components are symlink-checked;
|
||||
- canonicalized targets must remain under the canonical grant root;
|
||||
- write target symlinks/dirs rejected;
|
||||
- Unix writes add `O_NOFOLLOW`.
|
||||
- Bounds are explicit:
|
||||
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||
- read/list truncation is explicit via `truncated`;
|
||||
- oversize write fails closed.
|
||||
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||
|
||||
Reviewer validation:
|
||||
- Static review of changed files and relevant tests.
|
||||
- Confirmed worktree branch/head.
|
||||
- `git diff --check 717c0999^..717c0999` — passed.
|
||||
- Orchestrator-reported validation was reviewed:
|
||||
- `cargo fmt --check`
|
||||
- `cargo check -p pod -p manifest -p yoi`
|
||||
- `cargo test -p pod feature::plugin`
|
||||
- `cargo test -p manifest plugin`
|
||||
- `cargo test -p yoi plugin_cli`
|
||||
- `git diff --check`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Non-blocking risk noted:
|
||||
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the feasible scope of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||
|
||||
Conclusion:
|
||||
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T16:14:42Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Merge / validation report:
|
||||
|
||||
Implementation branch `impl/00001KVFDX9AY-plugin-fs-host-api` を Orchestrator worktree の `orchestration` branch に merge 済み。
|
||||
|
||||
Merge:
|
||||
- merge commit: `c94e157b` — `merge: plugin fs host api`
|
||||
- implementation commit:
|
||||
- `717c0999` — `plugin: implement fs host api`
|
||||
- changed files:
|
||||
- `crates/manifest/src/plugin.rs`
|
||||
- `crates/pod/src/feature/plugin.rs`
|
||||
- `crates/yoi/src/plugin_cli.rs`
|
||||
|
||||
Validation in Orchestrator worktree after merge:
|
||||
- `cargo fmt --check` — passed
|
||||
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||
- `cargo test -p pod feature::plugin -- --nocapture` — passed; 48 passed, 0 failed
|
||||
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||
- `git diff --check` — passed
|
||||
- `nix build .#yoi --no-link` — passed
|
||||
|
||||
Review:
|
||||
- Reviewer `yoi-reviewer-00001KVFDX9AY` returned `approve` with no blockers.
|
||||
- Reviewer noted a non-blocking future hardening context: this implementation is path/canonicalization based and does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is accepted within the feasible scope of the initial subset.
|
||||
|
||||
Outcome:
|
||||
- Granted scoped filesystem `fs` host API is implemented for WASM Plugin Tools.
|
||||
- Missing `host_api.fs` grant denies before filesystem access.
|
||||
- Workspace/POD filesystem authority is not inherited by Plugin without Plugin grant.
|
||||
- Path traversal / symlink / root escape protections, read/list/write bounds, write serialization, diagnostics redaction, ordinary Tool result path, and CLI inspection compatibility are present.
|
||||
- HTTPS host API and Component Model migration remain non-goals for this Ticket.
|
||||
- Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVFDX9AY at: 2026-06-19T16:15:17Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Review result: approve
|
||||
|
||||
対象:
|
||||
- Ticket: `00001KVFDX9AY`
|
||||
- branch: `impl/00001KVFDX9AY-plugin-fs-host-api`
|
||||
- commit: `717c0999` (`plugin: implement fs host api`)
|
||||
|
||||
No blockers found.
|
||||
|
||||
Evidence reviewed:
|
||||
- FS grant schema is explicit and additive: `PluginGrantConfig.fs`, `PluginFsGrant { root, operations }`, and `PluginFsOperation::{read,list,write}` in `crates/manifest/src/plugin.rs`. Existing HTTPS grant shape remains separate.
|
||||
- Runtime dispatch checks `host_api.fs` before request parsing reaches any filesystem operation: `execute_plugin_fs_request` bounds descriptor size, then calls `authorize_plugin_host_api(record, PluginHostApi::Fs)` before read/list/write dispatch.
|
||||
- Permission/grant binding is layered correctly:
|
||||
- requested `host_api.fs` permission required;
|
||||
- configured grant permission required;
|
||||
- usable FS scope required;
|
||||
- per-operation grants checked in `authorize_fs_path` / `authorize_fs_write_path`.
|
||||
- No ambient WASI/workspace filesystem authority is exposed. WASM import validation only allows `yoi:tool`, `yoi:https`, and `yoi:fs`; WASI remains rejected. Runtime FS is only through `yoi:fs` imports.
|
||||
- Path safety is materially addressed:
|
||||
- absolute paths, NULs, and `..` traversal rejected;
|
||||
- grant root must be absolute, existing, directory, and not final symlink;
|
||||
- request path components are symlink-checked;
|
||||
- canonicalized targets must remain under the canonical grant root;
|
||||
- write target symlinks/dirs rejected;
|
||||
- Unix writes add `O_NOFOLLOW`.
|
||||
- Bounds are explicit:
|
||||
- request descriptor, path, read bytes, write bytes, list entry count, and diagnostics are bounded/redacted;
|
||||
- read/list truncation is explicit via `truncated`;
|
||||
- oversize write fails closed.
|
||||
- Writes serialize by normalized/canonical target with a shared lock map and use truncate/create with `sync_all`.
|
||||
- Diagnostics use `PluginFsError::new` with `bounded_message(redact_secret_like(...))`; tests verify secret-like path redaction and no file-content leakage on denial.
|
||||
- FS responses flow through WASM host response buffers and then ordinary plugin Tool output/error handling; no hidden context/history injection path found.
|
||||
- CLI inspection reports `configured_fs_grants` alongside existing permission/HTTPS grant inspection without changing HTTPS semantics.
|
||||
|
||||
Reviewer validation:
|
||||
- Static review of changed files and relevant tests.
|
||||
- Confirmed worktree branch/head.
|
||||
- `git diff --check 717c0999^..717c0999` — passed.
|
||||
- Orchestrator-reported validation was reviewed:
|
||||
- `cargo fmt --check`
|
||||
- `cargo check -p pod -p manifest -p yoi`
|
||||
- `cargo test -p pod feature::plugin`
|
||||
- `cargo test -p manifest plugin`
|
||||
- `cargo test -p yoi plugin_cli`
|
||||
- `git diff --check`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Non-blocking risk noted:
|
||||
- The implementation is still fundamentally path/canonicalization based. It rejects static symlink/root escapes and uses Unix `O_NOFOLLOW` for final write target, but it does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is judged within the feasible scope of the initial subset and not a blocker for this Ticket, but should be preserved as future hardening context if the threat model expands.
|
||||
|
||||
Conclusion:
|
||||
- Implementation satisfies the recorded Ticket acceptance criteria and is ready for merge/validation in the Orchestrator worktree.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T16:16:56Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Cleanup report:
|
||||
|
||||
Plugin FS host API Ticket の implementation/review Pods と child worktree を cleanup した。
|
||||
|
||||
Stopped Pods:
|
||||
- `yoi-coder-00001KVFDX9AY`
|
||||
- `yoi-reviewer-00001KVFDX9AY`
|
||||
|
||||
Removed child implementation worktree:
|
||||
- `/home/hare/Projects/yoi/.worktree/00001KVFDX9AY-plugin-fs-host-api`
|
||||
|
||||
Deleted merged implementation branch:
|
||||
- `impl/00001KVFDX9AY-plugin-fs-host-api` at `717c0999`
|
||||
|
||||
Orchestrator branch remains the integration authority for this completed work. Root/original workspace was not touched for this Ticket, per Panel Queue instruction.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-19T16:17:29Z from: inprogress to: done reason: merged_validated_review_approved field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Implementation commit `717c0999` was reviewed and approved, merged into the Orchestrator branch as `c94e157b`, validated in the Orchestrator worktree, and child implementation resources were cleaned up. Requirements and acceptance criteria are satisfied for this Ticket. Root/original workspace was not operated on for this Ticket per Panel Queue instruction.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-19T16:17:51Z from: done to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-19T16:17:51Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Ticket `00001KVFDX9AY` is complete.
|
||||
|
||||
Completed implementation:
|
||||
- Added granted scoped filesystem `fs` host API for WASM Plugin Tools.
|
||||
- Added `PluginFsGrant { root, operations }` and `PluginFsOperation::{read,list,write}` to the Plugin grant model.
|
||||
- Implemented `yoi:fs` WASM host imports for read/list/write with response buffer handling.
|
||||
- Enforced Plugin-specific grants before filesystem access; Plugin Tools do not inherit Pod/workspace filesystem authority.
|
||||
- Added path safety for relative-only requests, traversal rejection, symlink/root escape rejection, canonical root checks, and Unix `O_NOFOLLOW` for writes.
|
||||
- Added read/list/write bounds, explicit truncation/fail-closed behavior, write serialization by normalized/canonical target, and bounded/redacted diagnostics.
|
||||
- Updated Plugin CLI inspection to show configured fs grants.
|
||||
|
||||
Reviewed / merged:
|
||||
- Implementation commit: `717c0999` (`plugin: implement fs host api`)
|
||||
- Reviewer result: approve, no blockers.
|
||||
- Reviewer noted a non-blocking future hardening context: the current implementation is path/canonicalization based and does not fully eliminate adversarial external TOCTOU races where another local process mutates granted-root directories between checks and open/read/list/write. This is accepted within the feasible scope of the initial subset.
|
||||
- Orchestrator merge commit: `c94e157b` (`merge: plugin fs host api`)
|
||||
|
||||
Validation in Orchestrator worktree:
|
||||
- `cargo fmt --check` — passed
|
||||
- `cargo check -p pod -p manifest -p yoi` — passed
|
||||
- `cargo test -p pod feature::plugin -- --nocapture` — passed; 48 passed, 0 failed
|
||||
- `cargo test -p manifest plugin -- --nocapture` — passed; 17 passed, 0 failed
|
||||
- `cargo test -p yoi plugin_cli -- --nocapture` — passed; 10 passed, 0 failed
|
||||
- `git diff --check` — passed
|
||||
- `nix build .#yoi --no-link` — passed
|
||||
|
||||
Cleanup:
|
||||
- Stopped Coder Pod `yoi-coder-00001KVFDX9AY`.
|
||||
- Stopped Reviewer Pod `yoi-reviewer-00001KVFDX9AY`.
|
||||
- Removed child worktree `/home/hare/Projects/yoi/.worktree/00001KVFDX9AY-plugin-fs-host-api`.
|
||||
- Deleted merged branch `impl/00001KVFDX9AY-plugin-fs-host-api`.
|
||||
|
||||
Root/original workspace was not read/written/merged/validated for this Ticket, per Panel Queue instruction. The completed work is integrated on the Orchestrator branch.
|
||||
|
||||
---
|
||||
@@ -0,0 +1,4 @@
|
||||
{"id":"orch-plan-20260619-133549-1","ticket_id":"00001KVG0HR96","kind":"waiting_capacity_note","note":"明示 queue review で Ticket body / relations / orchestration plan / workspace state を確認した。依存 Ticket `00001KV5W3PHW` / `00001KV5W3PJ3` は closed で blocker ではないが、現在 `00001KVFD3YSV` Plugin CLI inspection が inprogress/review-needed で、さらに `00001KVFDX9AF` / `00001KVFDX9AY` host API Tickets も queued hold 中。Component Model runtime migration は Plugin runtime backend / manifest runtime metadata / WIT / grants / inspection / packaging に広く触れる migration boundary で、current CLI inspection outcome と host API ordering に強く依存・競合するため、現時点では queued のまま待機する。`00001KVFD3YSV` の merge/close 後に再 routing する。","author":"yoi-orchestrator","at":"2026-06-19T13:35:49Z"}
|
||||
{"id":"orch-plan-20260619-142431-2","ticket_id":"00001KVG0HR96","kind":"waiting_capacity_note","note":"`00001KVFD3YSV` Plugin CLI inspection は closed になったため再 routing した。Component Model runtime migration は Plugin runtime backend / WIT / host API shape / grants / inspection / packaging に広く触れる migration boundary で、queued host API Tickets と衝突しやすい。まず `00001KVFDX9AF` https host API を受理し、`fs` host API と Component Model migration はその outcome 後に再 routing する。Bounded reason: migration boundary / conflict。","author":"yoi-orchestrator","at":"2026-06-19T14:24:31Z"}
|
||||
{"id":"orch-plan-20260619-153644-3","ticket_id":"00001KVG0HR96","kind":"waiting_capacity_note","note":"`00001KVFDX9AF` HTTPS host API は closed になったため再 routing した。次は `00001KVFDX9AY` fs host API を受理する。Component Model runtime migration は Plugin runtime backend / WIT / host API shape / grants / inspection / packaging に広く触れる migration boundary で、active fs host API と衝突しやすいため queued のまま待機する。Bounded reason: migration boundary / conflict。","author":"yoi-orchestrator","at":"2026-06-19T15:36:44Z"}
|
||||
{"id":"orch-plan-20260619-162050-4","ticket_id":"00001KVG0HR96","kind":"accepted_plan","accepted_plan":{"summary":"WASM Plugin Tool runtime を現行 core-module host imports (`yoi-plugin-wasm-1`) から WebAssembly Component Model / WIT-first runtime へ移行する。Typed host API surface、permission/grant enforcement、ordinary Tool result path、HTTPS/FS安全性、CLI inspection、tests/package validation を保つ。","branch":"impl/00001KVG0HR96-plugin-component-model-runtime","worktree":"/home/hare/Projects/yoi/.worktree/00001KVG0HR96-plugin-component-model-runtime","role_plan":"Orchestrator は専用 implementation worktree を作成し、Coder をその worktree への narrow write scope で起動する。Reviewer は実装報告後に read-only で確認する。Plugin CLI / HTTPS / FS host API は closed になったため、Component Model migration を単独で受理する。"},"author":"yoi-orchestrator","at":"2026-06-19T16:20:50Z"}
|
||||
@@ -0,0 +1,53 @@
|
||||
{
|
||||
"version": 1,
|
||||
"relations": [
|
||||
{
|
||||
"ticket_id": "00001KVG0HR96",
|
||||
"kind": "depends_on",
|
||||
"target": "00001KV5W3PHW",
|
||||
"note": "Component Model runtime migrates the existing raw WASM Tool runtime.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T13:21:01Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVG0HR96",
|
||||
"kind": "depends_on",
|
||||
"target": "00001KV5W3PJ3",
|
||||
"note": "Component runtime must preserve Plugin permission grant enforcement.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T13:21:01Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVG0HR96",
|
||||
"kind": "related",
|
||||
"target": "00001KSXRQ4G8",
|
||||
"note": "Updates Plugin runtime/surface/host API design direction toward Component Model.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T13:21:01Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVG0HR96",
|
||||
"kind": "related",
|
||||
"target": "00001KVFD3YSV",
|
||||
"note": "Inspection CLI should report component runtime metadata without execution.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T13:21:01Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVG0HR96",
|
||||
"kind": "related",
|
||||
"target": "00001KVFDX9AF",
|
||||
"note": "https host API should be designed in WIT-compatible typed terms.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T13:21:01Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVG0HR96",
|
||||
"kind": "related",
|
||||
"target": "00001KVFDX9AY",
|
||||
"note": "fs host API should be designed in WIT-compatible typed terms.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-19T13:21:01Z"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,115 @@
|
||||
---
|
||||
title: 'Plugin: migrate WASM Tool runtime to WebAssembly Component Model'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-19T13:18:58Z'
|
||||
updated_at: '2026-06-19T17:23:31Z'
|
||||
assignee: null
|
||||
readiness: 'implementation_ready'
|
||||
risk_flags: ['plugin', 'wasm', 'component-model', 'wit', 'runtime-backend', 'sandbox', 'packaging', 'sdk']
|
||||
queued_by: 'workspace-panel'
|
||||
queued_at: '2026-06-19T13:34:43Z'
|
||||
---
|
||||
|
||||
## Background
|
||||
|
||||
Yoi's current Plugin Tool runtime uses a raw core-Wasm ABI (`yoi-plugin-wasm-1`) with `yoi_tool_call`, exported `memory`, and host imports for input/output pointer-length plumbing. That was a good MVP for a small sandboxed runtime, but it should not become the long-term authoring interface.
|
||||
|
||||
Common Wasm extension systems usually provide a typed SDK/PDK, manifest, capability grants, templates, and inspection tooling. The WebAssembly Component Model provides a standard way to describe typed imports/exports via WIT and canonical ABI. Adopting it early prevents `https`, `fs`, SDK, and future Service/Ingress APIs from entrenching a Yoi-specific raw ABI.
|
||||
|
||||
This Ticket implements an explicit Component Model runtime path for Plugin Tool packages while preserving the existing package discovery, enablement, digest pinning, ToolRegistry, ordinary Tool history, and Plugin grant enforcement boundaries.
|
||||
|
||||
Research and direction are persisted in:
|
||||
|
||||
- `.yoi/objectives/00001KVG0HR9M/item.md` — Plugin Component Model migration Objective.
|
||||
- `docs/design/plugin-component-model.md` — design research and policy.
|
||||
- `docs/design/plugin-packages.md` — package runtime metadata direction.
|
||||
|
||||
## Requirements
|
||||
|
||||
- Add an explicit Component Model runtime kind for Plugin packages.
|
||||
- Example manifest shape:
|
||||
|
||||
```toml
|
||||
[runtime]
|
||||
kind = "wasm-component"
|
||||
component = "plugin.component.wasm"
|
||||
world = "yoi:plugin/tool@1.0.0"
|
||||
```
|
||||
|
||||
- Do not silently reinterpret existing raw core-Wasm packages.
|
||||
- Current raw runtime remains explicit, e.g. `kind = "wasm"`, `abi = "yoi-plugin-wasm-1"`.
|
||||
- Component runtime selection is driven by package manifest/runtime metadata.
|
||||
- Define WIT package/worlds for the Plugin Tool runtime.
|
||||
- Tool request / response / structured error types.
|
||||
- Tool name and JSON input/output representation, or a better typed equivalent if decided during implementation.
|
||||
- Initial host API interfaces should be WIT-compatible even if some APIs remain unimplemented.
|
||||
- Add a host runtime backend capable of loading and invoking Component Model Plugin Tools.
|
||||
- Evaluate whether this uses `wasmtime::component`, adapter tooling, or another backend.
|
||||
- Keep runtime selected per package; discovery/inspection must not execute Plugin code.
|
||||
- Preserve existing Plugin authority boundaries.
|
||||
- Package discovery is read-only.
|
||||
- Explicit enablement is required.
|
||||
- Plugin grants are checked before Tool registration/execution and before host API calls.
|
||||
- WIT imports are not authority by themselves.
|
||||
- No ambient WASI filesystem/network/env is exposed.
|
||||
- Preserve ordinary Tool behavior.
|
||||
- Component Tool registration goes through existing ToolRegistry/model-visible schema path.
|
||||
- Tool calls/results use ordinary Worker/Tool history path.
|
||||
- No hidden context injection.
|
||||
- Provide at least one sample Component Model Tool Plugin.
|
||||
- Prefer Rust authoring path if feasible.
|
||||
- Plugin author source should not contain raw pointer/length ABI plumbing.
|
||||
- Add or update tests for both positive and negative paths.
|
||||
- Component package discovery and manifest parsing.
|
||||
- Component Tool registration.
|
||||
- Component Tool execution.
|
||||
- Grant denial before execution / host API access.
|
||||
- Wrong world / missing export / incompatible component rejected.
|
||||
- Existing raw core-Wasm Plugin runtime either still passes or has a recorded compatibility decision.
|
||||
- Measure packaging/runtime impact.
|
||||
- Binary size/build time impact if adding Wasmtime/component tooling.
|
||||
- Nix packaging changes and `cargoHash` if dependencies change.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- A package with `runtime.kind = "wasm-component"` and the expected WIT world can be discovered, enabled, registered as a Tool, and executed.
|
||||
- A sample Component Model Tool Plugin returns a normal Tool result through the ordinary Tool path.
|
||||
- Plugin author code for the sample uses generated/SDK bindings rather than raw pointer/length imports/exports.
|
||||
- Component Tool execution is denied without matching Plugin grants.
|
||||
- Component host imports cannot bypass Yoi's Plugin grant model.
|
||||
- Unsupported / wrong WIT world or missing required export fails closed with bounded diagnostic.
|
||||
- Existing raw core-Wasm runtime remains explicitly supported or a migration/deprecation decision is recorded and tests are updated accordingly.
|
||||
- `yoi plugin list/show` inspection path, if available, reports Component runtime metadata without executing the component.
|
||||
- Documentation is updated with authoring/runtime instructions and migration notes.
|
||||
- Validation includes relevant focused tests, `cargo fmt --check`, `git diff --check`, `cargo check` / `cargo test`, and `nix build .#yoi`.
|
||||
|
||||
## Non-goals
|
||||
|
||||
- Service surface implementation.
|
||||
- Ingress surface implementation.
|
||||
- WebSocket / Discord Gateway bridge.
|
||||
- Inbound HTTP server.
|
||||
- Replacing Plugin grants with WIT imports.
|
||||
- Exposing WASI filesystem/network/env as ambient authority.
|
||||
- MCP integration or MCP trust policy changes.
|
||||
- A full public package registry or signature/trust-chain system.
|
||||
|
||||
## Implementation notes
|
||||
|
||||
- Keep raw core-Wasm ABI compatibility separate from Component Model support.
|
||||
- Prefer WIT names that can version cleanly, such as `yoi:plugin/tool@1.0.0` and `yoi:host/https@1.0.0`.
|
||||
- If Wasmtime is introduced, update Nix packaging and record dependency/build-size impact.
|
||||
- If a staged approach is necessary, first land WIT definitions and manifest parsing, then runtime execution in a follow-up. Do not pretend manifest parsing alone completes this Ticket.
|
||||
- `https` and `fs` host API work should avoid long-term raw ABI coupling; component-compatible request/response/path/error records are preferred.
|
||||
|
||||
## Related work
|
||||
|
||||
- `00001KVG0HR9M` — Objective: Plugin Component Model migration.
|
||||
- `docs/design/plugin-component-model.md` — design research and migration direction.
|
||||
- `docs/design/plugin-packages.md` — package runtime metadata direction.
|
||||
- `00001KV5W3PHW` — Plugin Tool execution with minimal WASM runtime.
|
||||
- `00001KV5W3PJ3` — Plugin permission grant enforcement.
|
||||
- `00001KVFDX9AF` — Plugin https host API.
|
||||
- `00001KVFDX9AY` — Plugin fs host API.
|
||||
- `00001KVFD3YSV` — Plugin read-only CLI inspection list/show.
|
||||
- `00001KSXRQ4G8` — Plugin runtime / surface / minimal host API model design.
|
||||
@@ -0,0 +1,42 @@
|
||||
## Resolution
|
||||
|
||||
`00001KVG0HR96` を完了しました。
|
||||
|
||||
実装内容:
|
||||
- Plugin manifest/runtime metadata に明示的な Component Model runtime (`kind = "wasm-component"`) を追加しました。
|
||||
- 既存 raw core-Wasm runtime (`kind = "wasm"`, `abi = "yoi-plugin-wasm-1"`) は明示的に維持しました。
|
||||
- `wasmtime::component` による Component Tool execution path を追加しました。
|
||||
- Component Tool は既存 ToolRegistry / Worker Tool path を通って実行され、hidden context injection はありません。
|
||||
- WIT host imports は権限そのものではなく、Plugin grants が Tool execution / host API use の authority boundary のままです。
|
||||
- Component runtime に raw runtime 相当の Wasmtime resource limits を追加し、memory/table/instance/output bound の negative tests を追加しました。
|
||||
- WASI fs/network/env は expose していません。
|
||||
- `yoi plugin list/show` static inspection は Component runtime metadata を報告し、component artifact を実行しません。
|
||||
- WIT files、Component sample authoring sketch、docs/design updates、package/Nix updates を追加しました。
|
||||
- JSON-string WIT v1 request/response shape は migration bridge として docs に記録し、structured records は follow-up に deferred としました。
|
||||
|
||||
主な commit:
|
||||
- `57bbf14e plugin: implement component model runtime`
|
||||
- `a705bb3b plugin: bound component model runtime resources`
|
||||
- `63d7ad78 merge: plugin component model runtime`
|
||||
|
||||
Review:
|
||||
- r1 は Component runtime resource limit 不足で `request_changes`。
|
||||
- Coder が resource limiter / negative tests / docs note を追加。
|
||||
- r2 は `approve`。
|
||||
|
||||
最終 validation:
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check HEAD^1..HEAD`
|
||||
- `cargo check`
|
||||
- `cargo test -p pod feature::plugin::tests -- --nocapture`
|
||||
- `cargo test -p manifest plugin -- --nocapture`
|
||||
- `cargo test -p yoi plugin -- --nocapture`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Package impact:
|
||||
- `nix path-info -S .#yoi`: `112156120`
|
||||
- `bin/yoi`: `54605944`
|
||||
- output dir: `53M`
|
||||
|
||||
Validation log:
|
||||
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-rZDseu.log`
|
||||
@@ -0,0 +1,464 @@
|
||||
<!-- event: create author: "yoi ticket" at: 2026-06-19T13:18:58Z -->
|
||||
|
||||
## 作成
|
||||
|
||||
LocalTicketBackend によって作成されました。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: workspace-panel at: 2026-06-19T13:34:43Z from: ready to: queued reason: queued field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を `workspace-panel` が queued にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: decision author: yoi-orchestrator at: 2026-06-19T16:21:31Z -->
|
||||
|
||||
## Decision
|
||||
|
||||
Routing decision: implementation_ready
|
||||
|
||||
Reason:
|
||||
- Panel Queue により、この Ticket は Orchestrator routing 対象として明示許可された。
|
||||
- Ticket body には、Component Model runtime path の intent、requirements、acceptance criteria、non-goals、implementation notes、validation が実装可能な粒度で揃っている。
|
||||
- depends_on の `00001KV5W3PHW` minimal WASM runtime と `00001KV5W3PJ3` permission grant enforcement は closed。
|
||||
- Related/context work はすべて完了または non-blocking context として確認した。
|
||||
- `00001KVFD3YSV` Plugin CLI inspection: closed。
|
||||
- `00001KVFDX9AF` HTTPS host API: closed。
|
||||
- `00001KVFDX9AY` FS host API: closed。
|
||||
- `00001KSXRQ4G8` is planning design context, not blocking relation authority。
|
||||
- Prior waiting-capacity notes の blocker は解消した。現在 inprogress Ticket は 0 件、child implementation Pod はなし、matching branch/worktree はなし、Orchestrator worktree は clean。
|
||||
- Risk domain は component-model / WIT / runtime-backend / sandbox / packaging / SDK だが、Ticket は existing raw core-Wasm packages を silently reinterpret しない、grants before Tool registration/execution/host API access、no ambient WASI fs/network/env、ordinary Tool history path、runtime kind selected by manifest metadata などの invariants を明示している。bounded context check 後も implementation 前に必要な追加 human decision は見つからなかった。
|
||||
|
||||
Evidence checked:
|
||||
- Ticket `00001KVG0HR96` body / thread / artifacts。
|
||||
- `TicketRelationQuery(00001KVG0HR96)`: depends_on blockers は closed。related records は context link。
|
||||
- `TicketOrchestrationPlanQuery(00001KVG0HR96)`: previous waiting notes were based on active CLI/HTTPS/FS work; all are now closed. 今回 `accepted_plan` を記録済み。
|
||||
- Current workspace state:
|
||||
- Orchestrator worktree clean。
|
||||
- queued: this Ticket only。
|
||||
- inprogress: 0。
|
||||
- visible Pods: self + peers only; spawned children 0。
|
||||
- Code/docs context:
|
||||
- `crates/manifest/src/plugin.rs`: current runtime metadata and `yoi-plugin-wasm-1` validation。
|
||||
- `crates/pod/src/feature/plugin.rs`: current core-Wasm Plugin runtime, Tool registration/static inspection, HTTPS/FS host APIs, import validation。
|
||||
- `crates/yoi/src/plugin_cli.rs`: inspection output should report Component runtime metadata without execution。
|
||||
- Ticket body references `docs/design/plugin-component-model.md`, `docs/design/plugin-packages.md`, and Objective `00001KVG0HR9M` as design context.
|
||||
|
||||
IntentPacket:
|
||||
|
||||
Intent:
|
||||
- Add explicit WebAssembly Component Model runtime support for Plugin Tool packages while preserving existing Plugin discovery, enablement, digest pinning, ToolRegistry integration, ordinary Tool history, and Plugin grant enforcement.
|
||||
- Move Plugin authoring/runtime path toward WIT/canonical ABI so future `https`, `fs`, SDK, Service/Ingress APIs do not entrench the raw pointer/length core-Wasm ABI.
|
||||
|
||||
Binding decisions / invariants:
|
||||
- Existing raw core-Wasm packages must not be silently reinterpreted as components。
|
||||
- Runtime selection is manifest-driven. Component packages use explicit runtime metadata such as `kind = "wasm-component"`, component artifact path, and expected world。
|
||||
- Existing raw runtime remains explicit (`kind = "wasm"`, `abi = "yoi-plugin-wasm-1"`) unless a migration/deprecation decision is recorded in this Ticket with tests updated accordingly。
|
||||
- Package discovery and inspection remain read-only and must not execute components。
|
||||
- Explicit enablement and digest/version/source pinning remain authoritative。
|
||||
- Plugin grants are checked before Tool registration/execution and before host API calls。
|
||||
- WIT imports are not authority by themselves。
|
||||
- No ambient WASI filesystem/network/env is exposed。
|
||||
- Component Tool registration still goes through existing ToolRegistry / model-visible schema path。
|
||||
- Tool calls/results use ordinary Worker/Tool history path; no hidden context injection。
|
||||
- HTTPS/FS host API security boundaries already implemented must be preserved。
|
||||
|
||||
Requirements / acceptance criteria:
|
||||
- A package with `runtime.kind = "wasm-component"` and expected WIT world can be discovered, enabled, registered as a Tool, and executed。
|
||||
- Sample Component Model Tool Plugin returns a normal Tool result through ordinary Tool path。
|
||||
- Sample Plugin author source uses generated/SDK bindings rather than raw pointer/length imports/exports。
|
||||
- Component Tool execution is denied without matching Plugin grants。
|
||||
- Component host imports cannot bypass Plugin grant model。
|
||||
- Wrong world / missing export / incompatible component fails closed with bounded diagnostic。
|
||||
- Existing raw core-Wasm runtime remains explicitly supported, or a migration/deprecation decision is recorded and tests updated。
|
||||
- `yoi plugin list/show` reports Component runtime metadata without executing components。
|
||||
- Documentation is updated with authoring/runtime instructions and migration notes。
|
||||
- Build/package impact is measured and Nix packaging/cargo hash updated if dependencies change。
|
||||
|
||||
Implementation latitude:
|
||||
- Use `wasmtime::component` / WIT tooling or another narrow backend consistent with the codebase。
|
||||
- Choose WIT names that version cleanly, e.g. `yoi:plugin/tool@1.0.0` and `yoi:host/https@1.0.0` / `yoi:host/fs@1.0.0`。
|
||||
- If a staged approach is unavoidable, escalate before narrowing completion. Do not land manifest parsing alone as if it completes this Ticket。
|
||||
- Keep compatibility layer and Component runtime dispatch cleanly separated。
|
||||
- Use focused sample fixtures/tests rather than broad E2E process spawning。
|
||||
|
||||
Escalate if:
|
||||
- Component runtime execution cannot be implemented without a broad architecture redesign。
|
||||
- Dependency/build-size impact is large enough to need product decision。
|
||||
- WIT/tool request-response typing requires a product/API decision beyond Ticket latitude。
|
||||
- Preserving both raw core-Wasm and Component runtime would substantially distort implementation。
|
||||
- SDK/sample generation requires external toolchain not feasible in repository validation。
|
||||
|
||||
Validation:
|
||||
- Focused Component Plugin manifest/discovery/static inspection tests。
|
||||
- Component Tool registration and execution tests。
|
||||
- Grant denial before Component Tool execution / host API access。
|
||||
- Wrong world / missing export / incompatible component fail-closed tests。
|
||||
- Existing raw core-Wasm Plugin runtime tests remain passing or migration decision/tests updated。
|
||||
- `cargo fmt --check`。
|
||||
- `git diff --check`。
|
||||
- relevant `cargo check` / `cargo test`。
|
||||
- `nix build .#yoi` because component runtime dependencies / packaging are likely to change。
|
||||
|
||||
Critical risks / reviewer focus:
|
||||
- WIT imports becoming implicit authority。
|
||||
- Component runtime bypassing existing Plugin grant enforcement。
|
||||
- Ambient WASI fs/network/env exposure。
|
||||
- Component execution bypassing ordinary Tool result/history path。
|
||||
- Breaking existing raw core-Wasm package behavior without explicit decision/tests。
|
||||
- Inspection accidentally executing components。
|
||||
- Unbounded or secret-leaking diagnostics。
|
||||
- Packaging/Nix/Cargo dependency correctness and binary/build-time impact。
|
||||
|
||||
Next action:
|
||||
- `queued -> inprogress` を記録し、Ticket records を Orchestrator worktree に commit してから、専用 implementation worktree を作成し Coder Pod を narrow write scope で起動する。root/original workspace は操作しない。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-19T16:21:50Z from: queued to: inprogress reason: orchestrator_acceptance_plugin_component_model_runtime field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket body/thread, relation metadata, orchestration plan records, related completed Tickets, Orchestrator worktree, visible Pods, existing branch/worktree, and bounded Component Model runtime code context were checked. Depends-on blockers are closed, Plugin CLI / HTTPS / FS related work are closed, and no dirty-state blocker or missing planning decision was found. Accepting this queued Ticket for implementation before worktree/Pod side effects.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T16:25:23Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Implementation orchestration start:
|
||||
- Acceptance records were committed on Orchestrator branch: `878517dc ticket: accept plugin component model runtime`.
|
||||
- Created implementation worktree `/home/hare/Projects/yoi/.worktree/00001KVG0HR96-plugin-component-model-runtime` on branch `impl/00001KVG0HR96-plugin-component-model-runtime` at `878517dc`.
|
||||
- Initial `SpawnPod` attempt with only the implementation worktree as readable scope failed because the spawned runtime workspace identity is `/home/hare/Projects/yoi` and that root was not readable under the child scope. No child Pod remained registered.
|
||||
- Retried with read-only scope for `/home/hare/Projects/yoi` plus write scope limited to the implementation worktree. Coder Pod `yoi-coder-00001KVG0HR96` started successfully. The task explicitly instructs the Coder to edit/build/commit only in the implementation worktree and not to operate in the root/original workspace.
|
||||
|
||||
Next action:
|
||||
- Wait for Coder implementation report, then inspect branch diff/validation evidence and route to Reviewer.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T17:00:21Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Coder implementation report received from `yoi-coder-00001KVG0HR96`.
|
||||
|
||||
Implementation commit:
|
||||
- `57bbf14e plugin: implement component model runtime`
|
||||
|
||||
Changed areas reported:
|
||||
- Manifest/runtime metadata: added explicit `kind = "wasm-component"` support with `component` artifact path and `world = "yoi:plugin/tool@1.0.0"`; preserved raw core-Wasm as `kind = "wasm"` + `abi = "yoi-plugin-wasm-1"`; reject mixed raw/component runtime metadata.
|
||||
- Plugin runtime: added `wasmtime::component` path; Component Tools execute through existing ToolRegistry / Worker Tool path; component imports are fail-closed; grants are checked before instantiation/import use and on host API calls; no WASI fs/network/env exposed.
|
||||
- Static inspection: reports `wasm-component/yoi:plugin/tool@1.0.0` without reading/executing the artifact.
|
||||
- Tests: component discovery/registration/execution, host-import grant denial, wrong-world, missing-export, raw-core-Wasm-not-component fail-closed, and existing raw runtime coverage.
|
||||
- Docs / authoring: updated design/package docs, added WIT files under `resources/plugin/wit/`, and sample author source under `docs/examples/plugin-component-tool/lib.rs`.
|
||||
- Packaging: added `wasmtime = 45.0.2` with narrow non-default features; updated `Cargo.lock` and `package.nix` `cargoHash`.
|
||||
|
||||
Coder validation reported as passing:
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check`
|
||||
- `cargo check`
|
||||
- `cargo test -p pod feature::plugin::tests -- --nocapture` (`55 passed`)
|
||||
- `cargo test -p manifest plugin -- --nocapture` (`17 passed`)
|
||||
- `cargo test -p yoi plugin -- --nocapture` (`11 passed`)
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Orchestrator evidence checked before review dispatch:
|
||||
- Implementation worktree is clean on `impl/00001KVG0HR96-plugin-component-model-runtime`.
|
||||
- Merge-base with `orchestration` is `878517dc`; Orchestrator branch head is `02006fee`.
|
||||
- Diff from acceptance is one implementation commit, `57bbf14e`, touching 10 files: `Cargo.lock`, manifest Plugin parser, pod Plugin runtime, `crates/pod/Cargo.toml`, docs, `package.nix`, and WIT/sample files.
|
||||
- `git diff --check 878517dc..HEAD` produced no diagnostics.
|
||||
- Diff size is material: about 1568 insertions / 68 deletions; dependency impact note is reviewer focus.
|
||||
|
||||
Next action:
|
||||
- Dispatch Reviewer for r1 review against Ticket requirements, with focus on Component Model authority boundaries, grant enforcement, no ambient WASI, raw runtime compatibility, inspection not executing code, diagnostics, tests, and packaging/Nix impact.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: plan author: yoi-orchestrator at: 2026-06-19T17:00:57Z -->
|
||||
|
||||
## Plan
|
||||
|
||||
Review dispatch:
|
||||
- Spawned Reviewer Pod `yoi-reviewer-00001KVG0HR96-r1` against implementation branch `impl/00001KVG0HR96-plugin-component-model-runtime`.
|
||||
- Review target commit: `57bbf14e plugin: implement component model runtime`.
|
||||
- Review baseline: `878517dc`.
|
||||
- Reviewer task focuses on Component/WIT authority boundaries, Plugin grant enforcement, no ambient WASI, raw runtime compatibility, inspection read-only behavior, fail-closed diagnostics, HTTPS/FS invariant preservation, dependency/package impact, and validation evidence.
|
||||
- Reviewer is instructed not to edit source, commit, merge, close the Ticket, or use TicketReview directly; it will report verdict/evidence back to Orchestrator.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVG0HR96-r1 at: 2026-06-19T17:08:18Z status: request_changes -->
|
||||
|
||||
## Review: request changes
|
||||
|
||||
Verdict: `request_changes`
|
||||
|
||||
確認範囲:
|
||||
- Ticket contract: `.yoi/tickets/00001KVG0HR96/item.md`, `.yoi/tickets/00001KVG0HR96/thread.md`
|
||||
- Diff: `878517dc..57bbf14e`
|
||||
- 主な対象: `crates/manifest/src/plugin.rs`, `crates/pod/src/feature/plugin.rs`, `crates/pod/Cargo.toml`, `Cargo.lock`, `package.nix`, `resources/plugin/wit/*`, docs/sample, existing `crates/yoi/src/plugin_cli.rs` static inspection path。
|
||||
|
||||
良い点:
|
||||
- 明示的な `wasm-component` metadata、raw `wasm` ABI との分離、artifact を実行しない static inspection、ToolRegistry 経由の registration/execution、Tool execution/host API 前の grant check、WASI imports を link しない方針は概ね Ticket intent に沿っている。
|
||||
|
||||
Blocking issue:
|
||||
1. Component runtime が既存 WASM sandbox/resource boundary を保持していない。
|
||||
- Raw core-Wasm path は `StoreLimitsBuilder` / `memory_size(PLUGIN_WASM_MEMORY_BYTES)` / table/instance/memory limits / `store.limiter(...)` を使っている。
|
||||
- 新しい Component Model path (`crates/pod/src/feature/plugin.rs:1965-2006`) は `consume_fuel(true)` と `max_wasm_stack(...)` は設定しているが、component execution store に同等の `Store::limiter(...)` / resource limit がない。
|
||||
- また component result は `String` として host 側に lift された後で `decode_plugin_wasm_output(output.as_bytes())` による output cap を適用しており、untrusted component が output cap 前に host allocation を強制できる。
|
||||
- これは Ticket/design の「Component Model support must preserve existing Plugin authority/sandbox boundaries」に反する。component memory/table/instance/output bounds のテストも不足している。
|
||||
|
||||
Required fix:
|
||||
- Component execution store に raw runtime と同等の Wasmtime resource limiter / memory/table/instance limits を入れる。
|
||||
- Component output/string lifting が unbounded host allocation にならないよう、少なくとも component memory/resource limit により bounded で fail-closed になることを実装・コメント・テストで示す。
|
||||
- Component memory/resource/output bound の negative tests を追加する。
|
||||
|
||||
Non-blocking concerns / follow-ups:
|
||||
- WIT は現在 `call(tool-name: string, input-json: string) -> string`。Ticket の “Tool request / response / structured error types” は完全には表現していない。今回 v1 の narrow ABI として意図的に deferred なら decision/follow-up として記録すること。
|
||||
- Rust sample は `wit_bindgen` authoring sketch であり、build/package された sample plugin を test しているわけではない。follow-up として packaged sample があるとよい。
|
||||
- `nix build` / `cargoHash` は検証されているが、binary size/build-time impact measurement がまだ明示記録されていない。最終 closure 前に capture すること。
|
||||
|
||||
Reviewer validation:
|
||||
- `git diff --check 878517dc..57bbf14e`: passed
|
||||
- `cargo fmt --check`: passed
|
||||
- `cargo test -p manifest plugin -- --nocapture`: 17 passed
|
||||
- `cargo test -p pod feature::plugin::tests -- --nocapture`: 55 passed
|
||||
- `cargo test -p yoi plugin -- --nocapture`: 11 passed
|
||||
- `cargo check`: passed
|
||||
- `nix build .#yoi --no-link`: passed
|
||||
- `nix path-info .#yoi`: `/nix/store/m5gsv05lfs7s9bh8dfy4ady6sda925fv-yoi-0.1.0`
|
||||
|
||||
Worktree status at review end: clean。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T17:17:08Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Coder r1-fix report received from `yoi-coder-00001KVG0HR96`.
|
||||
|
||||
New fix commit:
|
||||
- `a705bb3b plugin: bound component model runtime resources`
|
||||
|
||||
Branch commits now:
|
||||
- `a705bb3b plugin: bound component model runtime resources`
|
||||
- `57bbf14e plugin: implement component model runtime`
|
||||
|
||||
Fix summary:
|
||||
- Added `wasmtime::StoreLimits` to Component Model host state.
|
||||
- Applied raw-runtime-equivalent limits to component execution store:
|
||||
- `memory_size(PLUGIN_WASM_MEMORY_BYTES)`
|
||||
- `table_elements(PLUGIN_WASM_TABLE_ELEMENTS)`
|
||||
- `instances(1)`
|
||||
- `tables(1)`
|
||||
- `memories(1)`
|
||||
- `trap_on_grow_failure(true)`
|
||||
- Added inline comment near WIT string lift explaining that host allocation before `decode_plugin_wasm_output` is bounded by component memory/table/instance limits.
|
||||
- Added negative tests:
|
||||
- component oversized memory fails closed before string lift
|
||||
- component oversized table fails closed
|
||||
- component output cap still fails closed after bounded lift
|
||||
- Added docs note that JSON-string WIT v1 request/response is deliberate migration bridge and structured WIT records are deferred.
|
||||
|
||||
Coder validation reported as passing:
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check`
|
||||
- `cargo check`
|
||||
- `cargo test -p pod feature::plugin::tests -- --nocapture` (`58 passed`)
|
||||
- `cargo test -p manifest plugin -- --nocapture` (`17 passed`)
|
||||
- `cargo test -p yoi plugin -- --nocapture` (`11 passed`)
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Package / binary impact measurement reported:
|
||||
- `nix path-info -S .#yoi`: `/nix/store/g9nhx3g2xsn7r3rw6n61scdkha5s7m8s-yoi-0.1.0 112156120`
|
||||
- `stat -c '%s %n' "$out/bin/yoi"`: `54605944 .../bin/yoi`
|
||||
- `du -sh "$out"`: `53M`
|
||||
|
||||
Orchestrator evidence checked before re-review:
|
||||
- Implementation worktree is clean.
|
||||
- HEAD is `a705bb3b`.
|
||||
- Fix diff from `57bbf14e..HEAD` touches `crates/pod/src/feature/plugin.rs` and `docs/design/plugin-component-model.md`, 108 insertions.
|
||||
- Overall `git diff --check 878517dc..HEAD` produced no diagnostics.
|
||||
|
||||
Next action:
|
||||
- Route back to Reviewer for r2 verification of the resource-boundary blocker and final acceptance criteria.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVG0HR96-r1 at: 2026-06-19T17:19:55Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Verdict: `approve`
|
||||
|
||||
確認範囲:
|
||||
- Ticket contract: `.yoi/tickets/00001KVG0HR96/item.md`, `.yoi/tickets/00001KVG0HR96/thread.md`
|
||||
- r1 blocker fix diff: `57bbf14e..a705bb3b`
|
||||
- 全体実装: `878517dc..a705bb3b`
|
||||
- 主な対象: Plugin runtime / manifest / WIT / docs / tests / Cargo/Nix/package impact paths。
|
||||
|
||||
Previous blocker verification:
|
||||
- Component runtime now has raw-runtime-equivalent Wasmtime store limits:
|
||||
- `crates/pod/src/feature/plugin.rs:1514-1523`
|
||||
- `memory_size(PLUGIN_WASM_MEMORY_BYTES)`
|
||||
- `table_elements(PLUGIN_WASM_TABLE_ELEMENTS)`
|
||||
- `instances(1)`
|
||||
- `tables(1)`
|
||||
- `memories(1)`
|
||||
- `trap_on_grow_failure(true)`
|
||||
- Component host state carries those limits:
|
||||
- `crates/pod/src/feature/plugin.rs:1926-1930`
|
||||
- Component store installs the limiter before instantiation/execution:
|
||||
- `crates/pod/src/feature/plugin.rs:1991-2001`
|
||||
- Code documents why WIT string lifting remains bounded before ToolOutput JSON cap enforcement:
|
||||
- `crates/pod/src/feature/plugin.rs:2017-2026`
|
||||
- Focused negative tests were added and passed:
|
||||
- component memory limit fails closed before string lift
|
||||
- component table limit fails closed
|
||||
- component output cap still fails closed after bounded lift
|
||||
|
||||
Overall Ticket satisfaction:
|
||||
- Runtime kind is explicit and manifest-driven: raw `kind = "wasm"` + `abi = "yoi-plugin-wasm-1"`; component `kind = "wasm-component"` + `component` + expected `world`。
|
||||
- Component execution stays on existing Plugin Tool / ToolRegistry path。
|
||||
- Plugin grants remain authority boundary before Tool execution and host API use。
|
||||
- Component imports are validated; unsupported imports fail closed。
|
||||
- No WASI fs/network/env is linked。
|
||||
- Static inspection reports runtime metadata without executing component artifacts。
|
||||
- Existing raw runtime tests continue passing。
|
||||
- Docs record JSON-string WIT v1 as deliberate migration bridge and defer structured WIT records:
|
||||
- `docs/design/plugin-component-model.md:169-177`
|
||||
|
||||
Blocking issues: none。
|
||||
|
||||
Non-blocking follow-ups:
|
||||
- Structured WIT request/response/error records are intentionally deferred。
|
||||
- Sample remains an authoring sketch rather than fully built packaged sample, but runtime behavior is covered by focused component fixtures/tests。
|
||||
|
||||
Reviewer validation:
|
||||
- `git diff --check 878517dc..a705bb3b`: passed
|
||||
- `cargo fmt --check`: passed
|
||||
- `cargo test -p pod feature::plugin::tests -- --nocapture`: 58 passed
|
||||
- `cargo test -p manifest plugin -- --nocapture`: 17 passed
|
||||
- `cargo test -p yoi plugin -- --nocapture`: 11 passed
|
||||
- `cargo check`: passed
|
||||
- `nix build .#yoi --no-link`: passed
|
||||
- `nix path-info -S .#yoi`: `/nix/store/g9nhx3g2xsn7r3rw6n61scdkha5s7m8s-yoi-0.1.0 112156120`
|
||||
- `stat -c '%s %n' "$out/bin/yoi"`: `54605944 .../bin/yoi`
|
||||
- `du -sh "$out"`: `53M`
|
||||
|
||||
Worktree status at review end: clean。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-19T17:23:09Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Merge and final validation report:
|
||||
|
||||
Merged implementation branch into Orchestrator branch:
|
||||
- Merge commit: `63d7ad78 merge: plugin component model runtime`
|
||||
- Implementation commits included:
|
||||
- `57bbf14e plugin: implement component model runtime`
|
||||
- `a705bb3b plugin: bound component model runtime resources`
|
||||
|
||||
Reviewer outcome:
|
||||
- r1 requested changes for missing Component Model resource limiter.
|
||||
- Coder added raw-runtime-equivalent Wasmtime `StoreLimits` for Component execution and negative tests.
|
||||
- r2 approved with no blocking issues.
|
||||
|
||||
Orchestrator validation after merge passed:
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check HEAD^1..HEAD`
|
||||
- `cargo check`
|
||||
- `cargo test -p pod feature::plugin::tests -- --nocapture`
|
||||
- `cargo test -p manifest plugin -- --nocapture`
|
||||
- `cargo test -p yoi plugin -- --nocapture`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Validation log:
|
||||
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-rZDseu.log`
|
||||
|
||||
Package impact recorded by Coder/Reviewer:
|
||||
- `nix path-info -S .#yoi`: `112156120`
|
||||
- `bin/yoi` size: `54605944`
|
||||
- output dir: `53M`
|
||||
|
||||
Final state:
|
||||
- Orchestrator worktree clean at `63d7ad78` after validation.
|
||||
- Implementation worktree remains available for cleanup after Ticket completion records are committed.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-19T17:23:13Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Implementation was merged into Orchestrator branch at `63d7ad78`, r2 review approved, and final Orchestrator validation passed: `cargo fmt --check`, `git diff --check HEAD^1..HEAD`, `cargo check`, focused Plugin tests for `pod`/`manifest`/`yoi`, and `nix build .#yoi --no-link`.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-19T17:23:31Z from: done to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-19T17:23:31Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
## Resolution
|
||||
|
||||
`00001KVG0HR96` を完了しました。
|
||||
|
||||
実装内容:
|
||||
- Plugin manifest/runtime metadata に明示的な Component Model runtime (`kind = "wasm-component"`) を追加しました。
|
||||
- 既存 raw core-Wasm runtime (`kind = "wasm"`, `abi = "yoi-plugin-wasm-1"`) は明示的に維持しました。
|
||||
- `wasmtime::component` による Component Tool execution path を追加しました。
|
||||
- Component Tool は既存 ToolRegistry / Worker Tool path を通って実行され、hidden context injection はありません。
|
||||
- WIT host imports は権限そのものではなく、Plugin grants が Tool execution / host API use の authority boundary のままです。
|
||||
- Component runtime に raw runtime 相当の Wasmtime resource limits を追加し、memory/table/instance/output bound の negative tests を追加しました。
|
||||
- WASI fs/network/env は expose していません。
|
||||
- `yoi plugin list/show` static inspection は Component runtime metadata を報告し、component artifact を実行しません。
|
||||
- WIT files、Component sample authoring sketch、docs/design updates、package/Nix updates を追加しました。
|
||||
- JSON-string WIT v1 request/response shape は migration bridge として docs に記録し、structured records は follow-up に deferred としました。
|
||||
|
||||
主な commit:
|
||||
- `57bbf14e plugin: implement component model runtime`
|
||||
- `a705bb3b plugin: bound component model runtime resources`
|
||||
- `63d7ad78 merge: plugin component model runtime`
|
||||
|
||||
Review:
|
||||
- r1 は Component runtime resource limit 不足で `request_changes`。
|
||||
- Coder が resource limiter / negative tests / docs note を追加。
|
||||
- r2 は `approve`。
|
||||
|
||||
最終 validation:
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check HEAD^1..HEAD`
|
||||
- `cargo check`
|
||||
- `cargo test -p pod feature::plugin::tests -- --nocapture`
|
||||
- `cargo test -p manifest plugin -- --nocapture`
|
||||
- `cargo test -p yoi plugin -- --nocapture`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Package impact:
|
||||
- `nix path-info -S .#yoi`: `112156120`
|
||||
- `bin/yoi`: `54605944`
|
||||
- output dir: `53M`
|
||||
|
||||
Validation log:
|
||||
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-rZDseu.log`
|
||||
|
||||
---
|
||||
@@ -0,0 +1 @@
|
||||
{"id":"orch-plan-20260620-045332-1","ticket_id":"00001KVHKWNQA","kind":"accepted_plan","accepted_plan":{"summary":"Component Model Tool authoring用の first-party Rust PDK crate と embedded `rust-component-tool` template を追加する。PDK は guest-side only とし、raw pointer/length ABI を隠し、typed JSON helper / ToolError / ToolContext / WIT binding glue を提供する。crates.io 公開・remote template fetch・authoring CLI implementation は含めない。","branch":"impl/00001KVHKWNQA-plugin-rust-pdk-templates","worktree":"/home/hare/Projects/yoi/.worktree/00001KVHKWNQA-plugin-rust-pdk-templates","role_plan":"Orchestrator は queued acceptance を記録・commit 後、専用 implementation worktree を `.worktree/00001KVHKWNQA-plugin-rust-pdk-templates` に作成し、Coder をその child worktree への narrow write scope で起動する。Coder 実装後、Reviewer が PDK guest-only boundary、Component Model runtime compatibility、template/resource packaging、docs/tests/Nix impact を確認する。"},"author":"yoi-orchestrator","at":"2026-06-20T04:53:32Z"}
|
||||
@@ -0,0 +1,37 @@
|
||||
{
|
||||
"version": 1,
|
||||
"relations": [
|
||||
{
|
||||
"ticket_id": "00001KVHKWNQA",
|
||||
"kind": "depends_on",
|
||||
"target": "00001KVG0HR96",
|
||||
"note": "PDK targets the Component Model Tool runtime.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-20T04:17:24Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVHKWNQA",
|
||||
"kind": "related",
|
||||
"target": "00001KVFD3YSV",
|
||||
"note": "PDK authoring flow should pair with read-only plugin inspection.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-20T04:17:24Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVHKWNQA",
|
||||
"kind": "related",
|
||||
"target": "00001KVFDX9AF",
|
||||
"note": "PDK should later wrap https host API ergonomically.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-20T04:17:24Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVHKWNQA",
|
||||
"kind": "related",
|
||||
"target": "00001KVFDX9AY",
|
||||
"note": "PDK should later wrap fs host API ergonomically.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-20T04:17:24Z"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,90 @@
|
||||
---
|
||||
title: 'Plugin: add Rust PDK and embedded authoring templates for Component Model Tools'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-20T04:16:14Z'
|
||||
updated_at: '2026-06-20T05:53:20Z'
|
||||
assignee: null
|
||||
readiness: 'implementation_ready'
|
||||
risk_flags: ['plugin', 'pdk', 'component-model', 'authoring', 'templates', 'sdk', 'no-crates-io']
|
||||
queued_by: 'workspace-panel'
|
||||
queued_at: '2026-06-20T04:52:58Z'
|
||||
---
|
||||
|
||||
## Background
|
||||
|
||||
Yoi can now discover Plugin packages, register Tool surfaces, execute sandboxed WASM/Component Model Tool Plugins, enforce Plugin grants, expose `https` / `fs` host APIs, and inspect Plugin state through CLI. The next gap is authoring: independent Plugin developers should not need to write raw WIT/ABI glue or copy ad-hoc examples by hand.
|
||||
|
||||
This Ticket adds a first-party Rust PDK for Component Model Tool Plugins and embeds a starter template into Yoi resources. It deliberately does not publish to crates.io yet and does not fetch remote templates. The PDK/API and WIT world are still young, so out-of-tree authors should initially use a git rev or generated local path dependency rather than depending on a public semver crate.
|
||||
|
||||
## Requirements
|
||||
|
||||
- Add a Rust PDK crate inside the Yoi workspace.
|
||||
- Suggested package name: `yoi-plugin-pdk`.
|
||||
- Suggested path: `crates/plugin-pdk`.
|
||||
- Target Component Model Tool Plugins, not raw core-Wasm as the primary authoring path.
|
||||
- PDK must be guest-side only.
|
||||
- Do not depend on host runtime crates such as `pod`, `llm-worker`, `tui`, or `client`.
|
||||
- Keep dependencies minimal, e.g. `serde`, `serde_json`, and WIT binding support.
|
||||
- Do not expose ambient fs/network/env authority.
|
||||
- Provide ergonomic Tool helpers.
|
||||
- Typed JSON input parsing.
|
||||
- Typed JSON output serialization.
|
||||
- Structured `ToolError` / error-code helpers.
|
||||
- `ToolContext` containing at least the tool name.
|
||||
- Helper equivalent to `run_json_tool` that returns the ToolOutput JSON expected by the Yoi runtime.
|
||||
- Provide Component Model binding glue.
|
||||
- Re-export or wrap generated WIT bindings enough that an author does not need to hand-write raw pointer/length ABI code.
|
||||
- Prefer a minimal `Guest` impl helper first; add a macro only if it is simpler and testable.
|
||||
- Include embedded authoring templates under runtime resources.
|
||||
- Suggested path: `resources/plugin/templates/rust-component-tool/`.
|
||||
- Template includes `Cargo.toml`, `src/lib.rs`, `plugin.toml`, and a short README.
|
||||
- Template should be usable by a future `yoi plugin new` command without network access.
|
||||
- Template dependency policy:
|
||||
- In checkout/dev mode, template may use a local path dependency to `crates/plugin-pdk`.
|
||||
- For out-of-tree authors, docs/template comments should show a git `rev` dependency pattern.
|
||||
- Do not publish or require crates.io for this Ticket.
|
||||
- Do not use `curl | sh` or remote template fetch.
|
||||
- Include at least one example or fixture Plugin using the PDK.
|
||||
- Echo-style Component Model Tool is enough.
|
||||
- It should compile to a component artifact through the documented toolchain or, if full component build automation is not yet available, be covered by a clear fixture/test boundary.
|
||||
- Update Plugin development docs.
|
||||
- Explain that Component Model + PDK is the preferred authoring path.
|
||||
- Explain that raw core-Wasm ABI is compatibility/transitional.
|
||||
- Explain why crates.io publication and remote templates are intentionally deferred.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Workspace contains a guest-side `yoi-plugin-pdk` crate.
|
||||
- A Rust Component Model Tool Plugin can use the PDK to implement a JSON Tool without raw pointer/length ABI code.
|
||||
- PDK-produced Tool success output is accepted by the existing Yoi Plugin Tool runtime.
|
||||
- PDK-produced Tool errors are bounded and represented as ordinary Tool result/error content.
|
||||
- PDK does not grant or imply authority; host-side Plugin grants still decide `https` / `fs` / Tool execution access.
|
||||
- Embedded `rust-component-tool` template exists in runtime resources and is suitable for future `yoi plugin new` expansion.
|
||||
- No crates.io publication is required or performed.
|
||||
- No remote template fetch is implemented.
|
||||
- Tests cover:
|
||||
- PDK JSON input/output happy path;
|
||||
- PDK error output path;
|
||||
- PDK sample/template compiles or fixture is validated;
|
||||
- sample Plugin can be executed by Yoi component runtime if feasible in current test infrastructure;
|
||||
- PDK has no host-runtime crate dependency.
|
||||
- Validation: focused PDK/plugin tests, `cargo fmt --check`, relevant `cargo check` / `cargo test`, `git diff --check`, and `nix build .#yoi` because workspace/package/resources may change.
|
||||
|
||||
## Non-goals
|
||||
|
||||
- Publishing `yoi-plugin-pdk` to crates.io.
|
||||
- Remote template fetch or `curl | sh` setup.
|
||||
- `yoi plugin new/check/pack` CLI implementation.
|
||||
- Multi-language PDKs.
|
||||
- Service / Ingress authoring.
|
||||
- WebSocket / inbound HTTP bridge support.
|
||||
- Replacing Plugin grants with PDK-side checks.
|
||||
|
||||
## Related work
|
||||
|
||||
- `00001KVG0HR9M` — Objective: Plugin platform roadmap.
|
||||
- `00001KVG0HR96` — Plugin Component Model runtime.
|
||||
- `00001KVFD3YSV` — Plugin read-only CLI inspection.
|
||||
- `00001KVFDX9AF` — Plugin https host API.
|
||||
- `00001KVFDX9AY` — Plugin fs host API.
|
||||
- `docs/development/plugin-development.md` — current Plugin development guide.
|
||||
@@ -0,0 +1,43 @@
|
||||
## Resolution
|
||||
|
||||
`00001KVHKWNQA` を完了しました。
|
||||
|
||||
実装内容:
|
||||
- Guest-side Rust PDK crate `yoi-plugin-pdk` を追加しました。
|
||||
- PDK は typed JSON input/output helper、bounded `ToolError`、`ToolContext`、`run_json_tool` 系 helper、`wit_bindgen` re-export、`export_component_tool!` macro を提供します。
|
||||
- PDK は host/runtime Yoi crates に依存せず、authority を付与しません。Host-side Plugin manifest grants が Tool execution / host API use の authority boundary のままです。
|
||||
- Embedded Rust Component Tool template を `resources/plugin/templates/rust-component-tool/` に追加しました。
|
||||
- Template は local checkout/dev path dependency を使い、future out-of-tree git `rev` pattern を docs に記録しています。
|
||||
- `resources/plugin/wit` を `wit-bindgen` が parse できる package layout に修正し、host WIT dependency を `resources/plugin/wit/deps/yoi-host/yoi-host-v1.wit` に移動しました。
|
||||
- WIT keyword `list` は `%list` escape にし、import name semantics を保持しました。
|
||||
- Embedded template は empty `[workspace]` により in-tree standalone package として check できます。
|
||||
- `wit_bindgen::generate!` を実際に `resources/plugin/wit` に対して実行する probe と、embedded template の `wasm32-unknown-unknown` cargo-check probe を追加しました。
|
||||
- Plugin development docs / design docs / package docs / example source を更新しました。
|
||||
- `yoi plugin new/check/pack`、remote template fetch、crates.io publication、full packaged component execution はこの Ticket の non-goals / follow-up として残しました。
|
||||
|
||||
主な commit:
|
||||
- `06287aca plugin: add rust pdk template`
|
||||
- `0a9e585c plugin: fix rust pdk wit template probes`
|
||||
- `edc53a6b merge: plugin rust pdk templates`
|
||||
|
||||
Review:
|
||||
- r1 は WIT parse failure と embedded template Cargo workspace issue で `request_changes`。
|
||||
- Coder が WIT layout / `%list` / template `[workspace]` / actual probes を追加。
|
||||
- r2 は `approve`。
|
||||
|
||||
最終 validation:
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check HEAD^1..HEAD`
|
||||
- `cargo test -p yoi-plugin-pdk`
|
||||
- `cargo test -p manifest embedded_rust_component_tool_template_is_valid_package_shape`
|
||||
- `cargo test -p pod pdk_tool_output_shape_is_accepted_by_wasm_decoder`
|
||||
- `cargo check`
|
||||
- `cargo tree -p yoi-plugin-pdk --edges normal`
|
||||
- `cargo check --manifest-path resources/plugin/templates/rust-component-tool/Cargo.toml --target wasm32-unknown-unknown`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Package impact:
|
||||
- `nix path-info -S .#yoi`: `112156384`
|
||||
|
||||
Validation log:
|
||||
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-o9gvGb.log`
|
||||
@@ -0,0 +1,439 @@
|
||||
<!-- event: create author: "yoi ticket" at: 2026-06-20T04:16:14Z -->
|
||||
|
||||
## 作成
|
||||
|
||||
LocalTicketBackend によって作成されました。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: workspace-panel at: 2026-06-20T04:52:58Z from: ready to: queued reason: queued field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を `workspace-panel` が queued にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: decision author: yoi-orchestrator at: 2026-06-20T04:53:59Z -->
|
||||
|
||||
## Decision
|
||||
|
||||
Routing decision: implementation_ready
|
||||
|
||||
Reason:
|
||||
- Panel Queue により、この Ticket は Orchestrator routing 対象として明示許可された。
|
||||
- Ticket body は Rust PDK crate、guest-side only boundary、ergonomic Tool helpers、Component Model binding glue、embedded `rust-component-tool` template、docs/tests/validation/non-goals を実装可能な粒度で定義している。
|
||||
- Blocking dependency `00001KVG0HR96` Component Model runtime は closed。Component runtime は explicit `wasm-component` metadata、ToolRegistry path、grant enforcement、no ambient WASI、resource limits、WIT files を含めて完了済み。
|
||||
- Incoming dependency from `00001KVHKWNQS` は、この Ticket が将来の authoring CLI Ticket を unblock する関係であり、本 Ticket の blocker ではない。
|
||||
- Related Plugin CLI / HTTPS / FS Tickets は closed または non-blocking context。
|
||||
- 現在 queued はこの Ticket のみ、inprogress は 0 件、child implementation Pods はなし、matching branch/worktree はなし、Orchestrator worktree は clean。
|
||||
- Risk domain は plugin / pdk / component-model / authoring / templates / sdk / no-crates-io だが、Ticket は no crates.io publication、no remote template fetch、guest-side only、no ambient authority、host-side grants remain authority などの invariants を明示している。bounded context check 後も implementation 前に必要な追加 human decision は見つからなかった。
|
||||
|
||||
Evidence checked:
|
||||
- Ticket `00001KVHKWNQA` body / thread / relations / artifacts。
|
||||
- `TicketRelationQuery(00001KVHKWNQA)`: outgoing `depends_on` target `00001KVG0HR96` is closed。incoming `00001KVHKWNQS depends_on this` is not a blocker。
|
||||
- `TicketOrchestrationPlanQuery(00001KVHKWNQA)`: no previous plan records; accepted plan was recorded now。
|
||||
- Workspace state:
|
||||
- Orchestrator worktree clean at `9ca2f85b`。
|
||||
- queued: this Ticket only。
|
||||
- inprogress: 0。
|
||||
- visible Pods: self + peers only; spawned children 0。
|
||||
- no matching implementation branch/worktree。
|
||||
- Code/resource context:
|
||||
- `resources/plugin/wit/yoi-plugin-tool-v1.wit` and `resources/plugin/wit/yoi-host-v1.wit` exist from the Component runtime work。
|
||||
- `docs/development/plugin-development.md` is the current Plugin development guide target。
|
||||
- Cargo workspace has no existing `crates/plugin-pdk` crate。
|
||||
|
||||
IntentPacket:
|
||||
|
||||
Intent:
|
||||
- Add a first-party Rust PDK for Component Model Tool Plugins and an embedded starter template so authors can implement Yoi Plugin Tools without raw pointer/length ABI plumbing or remote template fetches。
|
||||
- Position Component Model + PDK as preferred authoring path while keeping raw core-Wasm ABI as compatibility/transitional runtime support。
|
||||
|
||||
Binding decisions / invariants:
|
||||
- PDK is guest-side only。It must not depend on host runtime crates such as `pod`, `llm-worker`, `tui`, or `client`。
|
||||
- PDK must not grant or imply authority。Host-side Plugin manifest grants remain the authority boundary for Tool execution / HTTPS / FS host APIs。
|
||||
- No ambient fs/network/env authority is introduced。
|
||||
- Do not publish to crates.io and do not implement remote template fetch。
|
||||
- Do not implement `yoi plugin new/check/pack` in this Ticket; embedded resources should be suitable for that future Ticket。
|
||||
- Template dependency policy must support checkout/dev local path dependency and document a future out-of-tree git `rev` pattern。
|
||||
- PDK should target the current Component Model Tool world (`yoi:plugin/tool@1.0.0`) and runtime ToolOutput JSON bridge。
|
||||
- Prefer minimal, testable helper APIs over broad macro magic。
|
||||
|
||||
Requirements / acceptance criteria:
|
||||
- Add workspace crate `yoi-plugin-pdk` under `crates/plugin-pdk` or a justified equivalent。
|
||||
- Provide typed JSON input parsing, output serialization, structured/bounded `ToolError`, `ToolContext` with at least tool name, and helper equivalent to `run_json_tool` producing ToolOutput JSON accepted by the current runtime。
|
||||
- Provide WIT binding glue/re-export/wrapper enough that authors do not hand-write raw pointer/length ABI code。
|
||||
- Add embedded template under `resources/plugin/templates/rust-component-tool/` with `Cargo.toml`, `src/lib.rs`, `plugin.toml`, and README/next steps。
|
||||
- Include example or fixture Plugin using the PDK。
|
||||
- Update Plugin development docs and explain publication/template-fetch deferrals。
|
||||
- Tests cover PDK happy/error paths, template/sample fixture validation, runtime acceptance if feasible, and no host-runtime crate dependency。
|
||||
- Validation includes focused PDK/plugin tests, `cargo fmt --check`, relevant `cargo check`/`cargo test`, `git diff --check`, and `nix build .#yoi` because workspace/package/resources may change。
|
||||
|
||||
Escalate if:
|
||||
- Current WIT/runtime shape cannot support a guest-side helper without changing the Component runtime contract。
|
||||
- A full sample component build requires external tooling that cannot be kept deterministic in this repo。
|
||||
- Keeping the PDK guest-only would require undesirable dependencies on host crates。
|
||||
- Template/resource packaging needs a broader CLI/resource architecture decision。
|
||||
|
||||
Next action:
|
||||
- Record `queued -> inprogress` and commit Ticket records before creating the implementation worktree and spawning Coder。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-20T04:54:04Z from: queued to: inprogress reason: orchestrator_acceptance_plugin_rust_pdk_templates field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket body/thread, relation metadata, Component Model runtime dependency state, related completed Tickets, Orchestrator worktree state, visible Pods, existing branch/worktree, and bounded resource/code context were checked. Dependency `00001KVG0HR96` is closed, no inprogress/capacity blocker exists, and no missing planning decision was found. Accepting this queued Ticket for implementation before worktree/Pod side effects.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-20T04:54:51Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Implementation orchestration start:
|
||||
- Acceptance records were committed on Orchestrator branch: `5f7f81bd ticket: accept plugin rust pdk templates`.
|
||||
- Created implementation worktree `/home/hare/Projects/yoi/.worktree/00001KVHKWNQA-plugin-rust-pdk-templates` on branch `impl/00001KVHKWNQA-plugin-rust-pdk-templates` at `5f7f81bd`.
|
||||
- Spawned Coder Pod `yoi-coder-00001KVHKWNQA` with write scope limited to the implementation worktree and read-only root scope only for runtime workspace identity.
|
||||
- Coder task explicitly forbids root/original workspace implementation, merge, Ticket close, and cleanup.
|
||||
|
||||
Next action:
|
||||
- Wait for Coder implementation report, then inspect branch diff/validation evidence and route to Reviewer.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-20T05:16:16Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Coder implementation report received from `yoi-coder-00001KVHKWNQA`.
|
||||
|
||||
Implementation commit:
|
||||
- `06287aca plugin: add rust pdk template`
|
||||
|
||||
Changed areas reported:
|
||||
- Added workspace crate `crates/plugin-pdk` / `yoi-plugin-pdk`:
|
||||
- guest-side PDK helpers;
|
||||
- typed JSON input parsing via `parse_json_input` / `run_json_tool`;
|
||||
- typed JSON output via `ToolOutput::json`;
|
||||
- bounded structured `ToolError` and error-code helpers;
|
||||
- `ToolContext` with selected tool name;
|
||||
- `wit_bindgen` re-export and `export_component_tool!` macro to avoid raw pointer/length ABI plumbing;
|
||||
- tests for happy path, error path, oversized output, template validation, and host-runtime dependency exclusion。
|
||||
- Added embedded starter template under `resources/plugin/templates/rust-component-tool/` with `Cargo.toml`, `src/lib.rs`, `plugin.toml`, and `README.md`。
|
||||
- Added embedded template constants in `crates/manifest/src/plugin.rs` for future authoring CLI use without remote fetching。
|
||||
- Updated Component Model example to use the PDK。
|
||||
- Added runtime decoder test confirming PDK-produced ToolOutput JSON shape is accepted。
|
||||
- Updated Plugin development/design/package docs。
|
||||
- Updated workspace/package metadata: root `Cargo.toml`, `Cargo.lock`, `package.nix` cargo hash。
|
||||
|
||||
Coder validation reported as passing:
|
||||
- `cargo test -p yoi-plugin-pdk`
|
||||
- `cargo test -p manifest embedded_rust_component_tool_template_is_valid_package_shape`
|
||||
- `cargo test -p pod pdk_tool_output_shape_is_accepted_by_wasm_decoder`
|
||||
- `cargo check`
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check`
|
||||
- `git diff --check --cached`
|
||||
- `cargo tree -p yoi-plugin-pdk --edges normal`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Known deferrals reported:
|
||||
- No `yoi plugin new/check/pack`, remote template fetch, or crates.io publication。
|
||||
- Full deterministic sample component build/pack execution remains deferred to future authoring CLI/tooling; current sample/template are fixture-validated and use current WIT/PDK shape。
|
||||
- Raw core-Wasm ABI remains compatibility/transitional runtime support。
|
||||
|
||||
Orchestrator evidence checked before review dispatch:
|
||||
- Implementation worktree is clean on `impl/00001KVHKWNQA-plugin-rust-pdk-templates`。
|
||||
- HEAD is `06287aca`。
|
||||
- Diff from acceptance `5f7f81bd..HEAD` is one implementation commit touching 17 files, about 857 insertions / 35 deletions。
|
||||
- `git diff --check 5f7f81bd..HEAD` produced no diagnostics。
|
||||
|
||||
Next action:
|
||||
- Dispatch Reviewer for r1 review against Ticket requirements, with focus on guest-only PDK boundary, no host-runtime deps, authority/grant wording, template/resource packaging, sample/test boundary honesty, docs, and Nix/workspace changes。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: plan author: yoi-orchestrator at: 2026-06-20T05:16:53Z -->
|
||||
|
||||
## Plan
|
||||
|
||||
Review dispatch:
|
||||
- Spawned Reviewer Pod `yoi-reviewer-00001KVHKWNQA-r1` against implementation branch `impl/00001KVHKWNQA-plugin-rust-pdk-templates`。
|
||||
- Review target commit: `06287aca plugin: add rust pdk template`。
|
||||
- Review baseline: `5f7f81bd`。
|
||||
- Reviewer task focuses on guest-only PDK boundary, absence of host-runtime deps, authority/grant wording, no ambient fs/network/env, template/resource packaging, current WIT/runtime compatibility, sample/test honesty, docs, and Nix/workspace changes。
|
||||
- Reviewer is instructed not to edit source, commit, merge, close the Ticket, or use TicketReview directly; it will report verdict/evidence back to Orchestrator。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVHKWNQA-r1 at: 2026-06-20T05:21:50Z status: request_changes -->
|
||||
|
||||
## Review: request changes
|
||||
|
||||
Verdict: `request_changes`
|
||||
|
||||
確認範囲:
|
||||
- Ticket body/thread / Orchestrator IntentPacket
|
||||
- Diff: `5f7f81bd..06287aca`
|
||||
- 主な対象: `crates/plugin-pdk/*`, embedded template `resources/plugin/templates/rust-component-tool/*`, `resources/plugin/wit/*`, `crates/manifest/src/plugin.rs`, `crates/pod/src/feature/plugin.rs`, workspace/package docs/Nix/Cargo paths。
|
||||
|
||||
良い点:
|
||||
- PDK は guest-side only として提示され、Yoi host/runtime crates への normal dependency は見当たらない。
|
||||
- docs/templates は host-side Plugin grants が authority boundary であること、crates.io publication / remote template fetch を要求しないことを概ね維持している。
|
||||
- `ToolError` / `ToolOutput` bounds と runtime decoder test は現在の ToolOutput JSON bridge と整合している。
|
||||
|
||||
Blocking issues:
|
||||
1. PDK/template authoring path が現在の WIT で実際に compile/parse できない。
|
||||
- Template/example/docs は次の generated binding path を示している。
|
||||
- `resources/plugin/templates/rust-component-tool/src/lib.rs`
|
||||
- `docs/examples/plugin-component-tool/lib.rs`
|
||||
- `crates/plugin-pdk/src/lib.rs`
|
||||
- しかし `resources/plugin/wit/yoi-host-v1.wit` の interface `fs` が `list: func(...)` を使っており、`wit-bindgen` probe で `list` が keyword として扱われ parse error になった。
|
||||
- これは “author does not need to hand-write raw pointer/length ABI code” と “template/sample compile or honest validated fixture boundary” の Ticket contract に反する。
|
||||
|
||||
2. Embedded template を source tree 内で Cargo package として check できない。
|
||||
- `cargo check --manifest-path resources/plugin/templates/rust-component-tool/Cargo.toml --target wasm32-unknown-unknown` が root workspace 配下の non-member package として失敗した。
|
||||
- Template を workspace member にするか、workspace exclude / embedded template 側の empty `[workspace]` 等で standalone fixture として check 可能にする必要がある。
|
||||
- 現在の shape tests は `wit_bindgen::generate!` や WIT parse を実行していないため、この問題を捕捉できていない。
|
||||
|
||||
Required fix:
|
||||
- Current WIT を `wit-bindgen` が parse できるよう修正する。`list` は WIT keyword なので `%list` escape など、runtime import name semantics を壊さない形を優先すること。
|
||||
- Embedded template を in-place または controlled fixture copy で Cargo check できるようにする。
|
||||
- `wit_bindgen::generate!` against `resources/plugin/wit` を実際に通す test/probe を追加する。string-shape assertion だけでは不可。
|
||||
- Template/example/PDK docs が full build boundary と deferral を正直に表現していることを確認する。
|
||||
|
||||
Reviewer validation:
|
||||
- Passed:
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check 5f7f81bd..HEAD`
|
||||
- `cargo test -p yoi-plugin-pdk`
|
||||
- `cargo test -p manifest embedded_rust_component_tool_template_is_valid_package_shape`
|
||||
- `cargo test -p pod pdk_tool_output_shape_is_accepted_by_wasm_decoder`
|
||||
- `cargo check`
|
||||
- `cargo tree -p yoi-plugin-pdk --edges normal`
|
||||
- `nix build .#yoi --no-link`
|
||||
- Failed reviewer probes:
|
||||
- `cargo check --manifest-path resources/plugin/templates/rust-component-tool/Cargo.toml --target wasm32-unknown-unknown`: workspace membership/standalone failure。
|
||||
- copied template probe with adjusted relative paths and empty `[workspace]`: WIT parse failure at `resources/plugin/wit/yoi-host-v1.wit` because `list` is keyword。
|
||||
|
||||
Worktree status at review end: source tree clean; ignored artifacts under `target/` only。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-20T05:40:15Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Coder r1-fix report received from `yoi-coder-00001KVHKWNQA`.
|
||||
|
||||
New fix commit:
|
||||
- `0a9e585c plugin: fix rust pdk wit template probes`
|
||||
|
||||
Branch commits now:
|
||||
- `0a9e585c plugin: fix rust pdk wit template probes`
|
||||
- `06287aca plugin: add rust pdk template`
|
||||
|
||||
Fix summary:
|
||||
- Moved host WIT to dependency package path `resources/plugin/wit/deps/yoi-host/yoi-host-v1.wit` so `resources/plugin/wit` is a valid WIT package directory with `yoi:host` resolved as dependency。
|
||||
- Escaped WIT keyword function as `%list` while preserving import name semantics。
|
||||
- Added empty `[workspace]` to embedded template `Cargo.toml` so it can be checked in-place without becoming an undeclared member of Yoi root workspace。
|
||||
- Updated template/example/docs/PDK snippets to the compile-tested binding pattern with PDK `wit_bindgen` re-export, `generate_all`, and `runtime_path: "yoi_plugin_pdk::wit_bindgen::rt"`。
|
||||
- Added compile-time probe `crates/plugin-pdk/tests/wit_bindgen_probe.rs` that runs `wit_bindgen::generate!` against `resources/plugin/wit`。
|
||||
- Added embedded template cargo-check probe for `wasm32-unknown-unknown` in `crates/plugin-pdk/tests/template.rs`。
|
||||
- Added `%list` WIT assertion and updated host WIT include path。
|
||||
- Updated `Cargo.lock` and `package.nix` for new dev dependency edge / cargo hash。
|
||||
|
||||
Coder validation reported as passing:
|
||||
- `cargo test -p yoi-plugin-pdk` including PDK tests, WIT constants, actual `wit_bindgen::generate!` probe, and embedded template wasm32 check probe。
|
||||
- `cargo test -p manifest embedded_rust_component_tool_template_is_valid_package_shape`
|
||||
- `cargo test -p pod pdk_tool_output_shape_is_accepted_by_wasm_decoder`
|
||||
- `cargo check`
|
||||
- `cargo tree -p yoi-plugin-pdk --edges normal`
|
||||
- `cargo check --manifest-path resources/plugin/templates/rust-component-tool/Cargo.toml --target wasm32-unknown-unknown`
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check 5f7f81bd..HEAD`
|
||||
- `git diff --check`
|
||||
- `git diff --check --cached`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Operational note:
|
||||
- `nix build .#yoi --no-link` initially hit disk exhaustion after accepting the updated vendor hash; Coder removed local implementation worktree `target/` cache and reran successfully。
|
||||
|
||||
Remaining deferrals:
|
||||
- No `yoi plugin new/check/pack`。
|
||||
- No crates.io publication or remote template fetching。
|
||||
- Full packaged component execution remains deferred; the current WIT parses with `wit-bindgen` and embedded Rust template compiles to the wasm target boundary。
|
||||
|
||||
Orchestrator evidence checked before r2 review:
|
||||
- Implementation worktree is clean。
|
||||
- HEAD is `0a9e585c`。
|
||||
- Fix diff from `06287aca..HEAD` touches 12 files, about 105 insertions / 13 deletions。
|
||||
- Overall `git diff --check 5f7f81bd..HEAD` produced no diagnostics。
|
||||
|
||||
Next action:
|
||||
- Route back to Reviewer for r2 verification of the WIT parse/template compile blockers and final acceptance criteria。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVHKWNQA-r1 at: 2026-06-20T05:47:13Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Verdict: `approve`
|
||||
|
||||
確認範囲:
|
||||
- Ticket body/thread / Orchestrator IntentPacket
|
||||
- r2 fix diff: `06287aca..0a9e585c`
|
||||
- 全体実装 diff: `5f7f81bd..0a9e585c`
|
||||
- 主な対象: `resources/plugin/wit/deps/yoi-host/yoi-host-v1.wit`, `resources/plugin/wit/yoi-plugin-tool-v1.wit`, embedded template, `crates/plugin-pdk/*`, `crates/manifest/src/plugin.rs`, `crates/pod/src/feature/plugin.rs`, docs, `package.nix`。
|
||||
|
||||
Previous blockers verification:
|
||||
- Host WIT は `resources/plugin/wit/deps/yoi-host/yoi-host-v1.wit` に配置され、`resources/plugin/wit` は current package directory として `wit-bindgen` が parse できる形になった。
|
||||
- Keyword function は `%list` として escape され、import name semantics を保持している。
|
||||
- Embedded template の `Cargo.toml` には empty `[workspace]` があり、root workspace 配下の non-member package として拒否されない。
|
||||
- `crates/plugin-pdk/tests/wit_bindgen_probe.rs` は実際に `wit_bindgen::generate!` を `resources/plugin/wit` に対して実行している。
|
||||
- Embedded template は `wasm32-unknown-unknown` target で cargo-check できる。
|
||||
|
||||
Overall Ticket fit:
|
||||
- PDK は guest-side に留まり、host/runtime Yoi crates への dependency は見当たらない。
|
||||
- PDK / template は authority を付与せず、host-side Plugin manifest grants が authority boundary であることを維持している。
|
||||
- Ambient fs/network/env authority は露出していない。
|
||||
- crates.io publication / remote template fetch / `yoi plugin new/check/pack` は実装していない。
|
||||
- Docs は full build/pack boundary と deferral を概ね正直に記述している。
|
||||
|
||||
Blocking issues: none。
|
||||
|
||||
Non-blocking concerns / follow-ups:
|
||||
- `cargo check --manifest-path resources/plugin/templates/rust-component-tool/Cargo.toml --target wasm32-unknown-unknown` を直接実行すると template-local `Cargo.lock` と `target/` ができる。Reviewer は検証後に untracked artifacts を削除した。テスト自体は temporary target dir を使い template lockfile を消すため blocking ではないが、将来 docs/CI では explicit `--target-dir` を推奨するとよい。
|
||||
- Reviewer r2 の `nix build .#yoi --no-link` は final artifact copy 中に `No space left on device` で environment-fail。cargo hash/source-filter/code diagnostic ではない。Coder 側では同コマンド成功済み。Orchestrator final validation で再確認する。
|
||||
|
||||
Reviewer validation:
|
||||
- `cargo test -p yoi-plugin-pdk`: passed
|
||||
- `cargo test -p manifest embedded_rust_component_tool_template_is_valid_package_shape`: passed
|
||||
- `cargo test -p pod pdk_tool_output_shape_is_accepted_by_wasm_decoder`: passed
|
||||
- `cargo check --manifest-path resources/plugin/templates/rust-component-tool/Cargo.toml --target wasm32-unknown-unknown`: passed
|
||||
- `cargo tree -p yoi-plugin-pdk --edges normal`: passed; host/runtime Yoi crate dependencyなし
|
||||
- `cargo fmt --check`: passed
|
||||
- `git diff --check 5f7f81bd..HEAD`: passed
|
||||
- `git diff --check`: passed
|
||||
- `git diff --check --cached`: passed
|
||||
- `cargo check`: passed
|
||||
- `nix build .#yoi --no-link`: attempted, environment failed with `No space left on device` during final artifact copying
|
||||
|
||||
Worktree status at review end: source tree clean; ignored artifacts under normal `target/` only。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-20T05:51:33Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Merge and final validation report:
|
||||
|
||||
Merged implementation branch into Orchestrator branch:
|
||||
- Merge commit: `edc53a6b merge: plugin rust pdk templates`
|
||||
- Implementation commits included:
|
||||
- `06287aca plugin: add rust pdk template`
|
||||
- `0a9e585c plugin: fix rust pdk wit template probes`
|
||||
|
||||
Reviewer outcome:
|
||||
- r1 requested changes for WIT parse failure (`list` keyword) and embedded template Cargo workspace check failure。
|
||||
- Coder fixed WIT package layout / `%list` escaping, added actual `wit_bindgen::generate!` probe, and made the embedded template standalone-checkable。
|
||||
- r2 approved with no blocking issues。
|
||||
|
||||
Orchestrator validation after merge passed:
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check HEAD^1..HEAD`
|
||||
- `cargo test -p yoi-plugin-pdk`
|
||||
- `cargo test -p manifest embedded_rust_component_tool_template_is_valid_package_shape`
|
||||
- `cargo test -p pod pdk_tool_output_shape_is_accepted_by_wasm_decoder`
|
||||
- `cargo check`
|
||||
- `cargo tree -p yoi-plugin-pdk --edges normal`
|
||||
- `cargo check --manifest-path resources/plugin/templates/rust-component-tool/Cargo.toml --target wasm32-unknown-unknown`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Validation log:
|
||||
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-o9gvGb.log`
|
||||
|
||||
Package impact:
|
||||
- `nix path-info -S .#yoi`: `112156384`
|
||||
|
||||
Cleanup note:
|
||||
- Direct template cargo-check creates local `resources/plugin/templates/rust-component-tool/Cargo.lock` and `target/`; Orchestrator removed those untracked artifacts after validation. Worktree is clean。
|
||||
|
||||
Final state:
|
||||
- Orchestrator worktree clean at `edc53a6b` after validation。
|
||||
- Implementation worktree remains available for cleanup after Ticket completion records are committed。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-20T05:51:42Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Implementation was merged into Orchestrator branch at `edc53a6b`, r2 review approved, and final Orchestrator validation passed: `cargo fmt --check`, `git diff --check HEAD^1..HEAD`, focused PDK/manifest/pod tests, `cargo check`, PDK dependency tree check, embedded template wasm32 check, and `nix build .#yoi --no-link`.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-20T05:53:20Z from: done to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-20T05:53:20Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
## Resolution
|
||||
|
||||
`00001KVHKWNQA` を完了しました。
|
||||
|
||||
実装内容:
|
||||
- Guest-side Rust PDK crate `yoi-plugin-pdk` を追加しました。
|
||||
- PDK は typed JSON input/output helper、bounded `ToolError`、`ToolContext`、`run_json_tool` 系 helper、`wit_bindgen` re-export、`export_component_tool!` macro を提供します。
|
||||
- PDK は host/runtime Yoi crates に依存せず、authority を付与しません。Host-side Plugin manifest grants が Tool execution / host API use の authority boundary のままです。
|
||||
- Embedded Rust Component Tool template を `resources/plugin/templates/rust-component-tool/` に追加しました。
|
||||
- Template は local checkout/dev path dependency を使い、future out-of-tree git `rev` pattern を docs に記録しています。
|
||||
- `resources/plugin/wit` を `wit-bindgen` が parse できる package layout に修正し、host WIT dependency を `resources/plugin/wit/deps/yoi-host/yoi-host-v1.wit` に移動しました。
|
||||
- WIT keyword `list` は `%list` escape にし、import name semantics を保持しました。
|
||||
- Embedded template は empty `[workspace]` により in-tree standalone package として check できます。
|
||||
- `wit_bindgen::generate!` を実際に `resources/plugin/wit` に対して実行する probe と、embedded template の `wasm32-unknown-unknown` cargo-check probe を追加しました。
|
||||
- Plugin development docs / design docs / package docs / example source を更新しました。
|
||||
- `yoi plugin new/check/pack`、remote template fetch、crates.io publication、full packaged component execution はこの Ticket の non-goals / follow-up として残しました。
|
||||
|
||||
主な commit:
|
||||
- `06287aca plugin: add rust pdk template`
|
||||
- `0a9e585c plugin: fix rust pdk wit template probes`
|
||||
- `edc53a6b merge: plugin rust pdk templates`
|
||||
|
||||
Review:
|
||||
- r1 は WIT parse failure と embedded template Cargo workspace issue で `request_changes`。
|
||||
- Coder が WIT layout / `%list` / template `[workspace]` / actual probes を追加。
|
||||
- r2 は `approve`。
|
||||
|
||||
最終 validation:
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check HEAD^1..HEAD`
|
||||
- `cargo test -p yoi-plugin-pdk`
|
||||
- `cargo test -p manifest embedded_rust_component_tool_template_is_valid_package_shape`
|
||||
- `cargo test -p pod pdk_tool_output_shape_is_accepted_by_wasm_decoder`
|
||||
- `cargo check`
|
||||
- `cargo tree -p yoi-plugin-pdk --edges normal`
|
||||
- `cargo check --manifest-path resources/plugin/templates/rust-component-tool/Cargo.toml --target wasm32-unknown-unknown`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Package impact:
|
||||
- `nix path-info -S .#yoi`: `112156384`
|
||||
|
||||
Validation log:
|
||||
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-o9gvGb.log`
|
||||
|
||||
---
|
||||
@@ -0,0 +1,2 @@
|
||||
{"id":"orch-plan-20260620-052336-1","ticket_id":"00001KVHKWNQS","kind":"blocked_by","related_ticket":"00001KVHKWNQA","note":"Panel Queue was accepted for routing review, but implementation cannot start yet because `00001KVHKWNQS` depends on `00001KVHKWNQA` Rust PDK/templates, which is currently `inprogress` and in a reviewer-requested-changes loop. Leave `00001KVHKWNQS` queued until `00001KVHKWNQA` is closed, then reroute.","author":"yoi-orchestrator","at":"2026-06-20T05:23:36Z"}
|
||||
{"id":"orch-plan-20260620-055356-2","ticket_id":"00001KVHKWNQS","kind":"accepted_plan","accepted_plan":{"summary":"`yoi plugin new rust-component-tool`, `yoi plugin check`, `yoi plugin pack` を追加する。new は embedded template only、check/pack は Plugin code を実行せず、directory/package safety、manifest/runtime/schema/permission diagnostics、deterministic digest/package output、JSON reports、enablement guidance を提供する。","branch":"impl/00001KVHKWNQS-plugin-authoring-cli","worktree":"/home/hare/Projects/yoi/.worktree/00001KVHKWNQS-plugin-authoring-cli","role_plan":"Orchestrator は acceptance records を commit 後、専用 implementation worktree `.worktree/00001KVHKWNQS-plugin-authoring-cli` を作成し、Coder をその child worktree への narrow write scope で起動する。Coder 実装後、Reviewer が non-execution checks、archive safety、deterministic pack/digest、JSON report stability、template use、workspace/config non-mutation、Nix/resource packaging を確認する。"},"author":"yoi-orchestrator","at":"2026-06-20T05:53:56Z"}
|
||||
@@ -0,0 +1,29 @@
|
||||
{
|
||||
"version": 1,
|
||||
"relations": [
|
||||
{
|
||||
"ticket_id": "00001KVHKWNQS",
|
||||
"kind": "depends_on",
|
||||
"target": "00001KVHKWNQA",
|
||||
"note": "Authoring new/check/pack uses the Rust PDK and embedded templates.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-20T04:17:24Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVHKWNQS",
|
||||
"kind": "related",
|
||||
"target": "00001KVFD3YSV",
|
||||
"note": "Authoring check/pack diagnostics should align with plugin list/show inspection.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-20T04:17:24Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVHKWNQS",
|
||||
"kind": "related",
|
||||
"target": "00001KVG0HR96",
|
||||
"note": "Authoring CLI validates Component Model Tool package metadata.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-20T04:17:24Z"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,93 @@
|
||||
---
|
||||
title: 'Plugin: add authoring CLI new/check/pack'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-20T04:16:14Z'
|
||||
updated_at: '2026-06-20T06:55:06Z'
|
||||
assignee: null
|
||||
readiness: 'implementation_ready'
|
||||
risk_flags: ['plugin', 'cli', 'authoring', 'templates', 'package-validation', 'packaging', 'read-only-check']
|
||||
queued_by: 'workspace-panel'
|
||||
queued_at: '2026-06-20T05:23:14Z'
|
||||
---
|
||||
|
||||
## Background
|
||||
|
||||
After the Rust PDK and embedded templates exist, independent Plugin developers need first-party CLI tooling to scaffold, validate, and package Plugins without relying on remote shell scripts or hand-written ZIP commands.
|
||||
|
||||
This Ticket adds authoring commands for local Plugin development. It complements read-only operational inspection (`yoi plugin list/show`) but serves a different audience: Plugin authors preparing a package before enabling it in Yoi.
|
||||
|
||||
## Requirements
|
||||
|
||||
- Add Plugin authoring subcommands to the product CLI.
|
||||
- `yoi plugin new rust-component-tool <path-or-name>`
|
||||
- `yoi plugin check <path-or-package>`
|
||||
- `yoi plugin pack <path> [--output <file>]`
|
||||
- `new` uses embedded templates only.
|
||||
- No remote template fetch.
|
||||
- No `curl | sh` flow.
|
||||
- Generated files should include `Cargo.toml`, `src/lib.rs`, `plugin.toml`, and README/next-steps.
|
||||
- Generated dependency should be appropriate for the current checkout/release mode: local path in checkout mode, or documented git rev/tag pattern if out-of-tree.
|
||||
- `check` validates a Plugin directory or `.yoi-plugin` package without executing Plugin code.
|
||||
- Parse `plugin.toml`.
|
||||
- Validate package id/version/source-compatible shape.
|
||||
- Validate runtime kind and referenced artifact presence.
|
||||
- Validate Component Model world metadata where possible.
|
||||
- Validate Tool schema shape.
|
||||
- Validate requested permissions / host API declarations.
|
||||
- Validate archive safety for packages: path traversal, root escape, unsupported compression, bounded file count/size.
|
||||
- Calculate and print deterministic digest.
|
||||
- Produce actionable diagnostics and a suggested enablement/grant snippet.
|
||||
- `pack` creates a deterministic `.yoi-plugin` package.
|
||||
- Include required manifest/runtime files.
|
||||
- Use currently supported archive format, including stored entries if compression is not supported.
|
||||
- Reject unsafe paths / root escapes.
|
||||
- Print output path and digest.
|
||||
- Do not modify workspace enablement config.
|
||||
- Provide JSON output for automation where useful.
|
||||
- At minimum `check --json` and `pack --json`.
|
||||
- Keep commands safe.
|
||||
- `check` and `pack` do not execute Plugin code.
|
||||
- `new` only writes into the requested destination and refuses to overwrite non-empty directories unless an explicit safe option is added.
|
||||
- No secrets are generated or embedded.
|
||||
- Integrate with existing inspection language.
|
||||
- Diagnostics/statuses should align with `yoi plugin list/show` where possible.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- `yoi plugin new rust-component-tool ./my-plugin` creates a usable template without network access.
|
||||
- `yoi plugin check ./my-plugin` validates the generated template and reports next steps/digest/enablement guidance.
|
||||
- `yoi plugin pack ./my-plugin` creates a `.yoi-plugin` package that Yoi discovery can read.
|
||||
- `check` can validate an existing `.yoi-plugin` archive.
|
||||
- `check --json` returns a stable typed report suitable for tests/agents.
|
||||
- `pack --json` returns output path and digest.
|
||||
- Unsafe package paths / traversal / unsupported compression / missing manifest / missing runtime artifact are rejected with clear diagnostics.
|
||||
- Commands do not execute Plugin code or mutate enablement config.
|
||||
- Tests cover:
|
||||
- `new` generated file set;
|
||||
- refusal to overwrite non-empty destination;
|
||||
- `check` valid directory;
|
||||
- `check` invalid manifest;
|
||||
- `check` missing runtime artifact;
|
||||
- `check` unsafe package archive;
|
||||
- `pack` deterministic digest;
|
||||
- `pack` package is discoverable by existing Plugin discovery;
|
||||
- JSON report shape.
|
||||
- Validation: focused CLI/plugin authoring tests, relevant `cargo check` / `cargo test`, `cargo fmt --check`, `git diff --check`, and `nix build .#yoi` because product CLI/resources/packaging behavior changes.
|
||||
|
||||
## Non-goals
|
||||
|
||||
- Remote template fetching.
|
||||
- Publishing or installing from a registry.
|
||||
- Enabling/disabling Plugins in workspace config.
|
||||
- Executing Plugin code during `check`.
|
||||
- crates.io publication of PDK.
|
||||
- Service / Ingress scaffolding.
|
||||
- Multi-language templates beyond Rust Component Model Tool.
|
||||
|
||||
## Related work
|
||||
|
||||
- `00001KVG0HR9M` — Objective: Plugin platform roadmap.
|
||||
- `00001KVHKWNQA` — Rust PDK and embedded authoring templates.
|
||||
- `00001KVFD3YSV` — Plugin read-only CLI inspection list/show.
|
||||
- `00001KVG0HR96` — Plugin Component Model runtime.
|
||||
- `docs/development/plugin-development.md` — current Plugin development guide.
|
||||
@@ -0,0 +1,41 @@
|
||||
## Resolution
|
||||
|
||||
`00001KVHKWNQS` を完了しました。
|
||||
|
||||
実装内容:
|
||||
- `yoi plugin new rust-component-tool <path-or-name>` を追加しました。
|
||||
- `yoi plugin check <path-or-package> [--json]` を追加しました。
|
||||
- `yoi plugin pack <path> [--output <file>] [--json]` を追加しました。
|
||||
- Safe directory/package reading、deterministic digesting、deterministic `.yoi-plugin` writing、symlink/root-escape rejection を含む materialized package helpers を追加しました。
|
||||
- `check` / `pack` は Plugin code を実行せず、既存 static Plugin inspection を再利用して manifest/runtime/schema/permission/host API declarations を検査します。
|
||||
- Embedded Rust Component Tool template を `new` で利用し、generated template を check/pack できるよう placeholder `plugin.component.wasm` を追加しました。
|
||||
- Placeholder artifact は `check` で検出され、generated template / packed archive は `partial` と bounded diagnostic を返します。placeholder が残る間は enablement-ready guidance を出しません。
|
||||
- `plugin new` は existing destination symlink を拒否し、write-through を防ぎます。
|
||||
- JSON report shape、human output、CLI help/docs を更新しました。
|
||||
- Focused tests と CLI smoke coverage を追加しました。
|
||||
|
||||
主な commit:
|
||||
- `945ecdf6 plugin: add authoring cli`
|
||||
- `699db538 plugin: harden authoring checks`
|
||||
- `87704ad4 merge: plugin authoring cli`
|
||||
|
||||
Review:
|
||||
- r1 は destination symlink write-through と placeholder artifact の enablement-ready 表示で `request_changes`。
|
||||
- Coder が symlink refusal、placeholder detection、`partial` status/diagnostics、tests/docs を追加。
|
||||
- r2 は `approve`。
|
||||
|
||||
最終 validation:
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check HEAD^1..HEAD`
|
||||
- `cargo check -p yoi`
|
||||
- `cargo test -p yoi plugin_cli`
|
||||
- `cargo test -p yoi-plugin-pdk template`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
補足:
|
||||
- 初回 `nix build .#yoi --no-link` は `aws-lc-sys` build 中に `No space left on device` で environment failure。
|
||||
- Orchestrator worktree の Cargo build artifacts を `cargo clean` で削除してから再実行し、Nix build は成功しました。
|
||||
- `nix path-info -S .#yoi`: `112260512`
|
||||
|
||||
Validation log:
|
||||
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-Q0KE3A.log`
|
||||
@@ -0,0 +1,427 @@
|
||||
<!-- event: create author: "yoi ticket" at: 2026-06-20T04:16:14Z -->
|
||||
|
||||
## 作成
|
||||
|
||||
LocalTicketBackend によって作成されました。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: workspace-panel at: 2026-06-20T05:23:14Z from: ready to: queued reason: queued field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を `workspace-panel` が queued にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: decision author: yoi-orchestrator at: 2026-06-20T05:23:44Z -->
|
||||
|
||||
## Decision
|
||||
|
||||
Routing decision: blocked_pending_dependency
|
||||
|
||||
Panel Queue により、この Ticket は Orchestrator routing 対象として明示許可されたが、実装開始はまだ行わない。
|
||||
|
||||
Reason:
|
||||
- `00001KVHKWNQS` は `00001KVHKWNQA` に `depends_on` している。
|
||||
- `00001KVHKWNQA` は現在 `inprogress` で、Rust PDK / embedded template 実装が r1 review の `request_changes` 修正ループ中。
|
||||
- この Ticket の `new/check/pack` は PDK crate / embedded template を使うため、PDK/template が closed になるまで authoring CLI implementation の worktree/Pod side effects は開始しない。
|
||||
- Orchestrator workspace は clean、queued はこの Ticket のみ、inprogress は `00001KVHKWNQA` のみ、matching branch/worktree は存在しない。
|
||||
|
||||
Action:
|
||||
- `00001KVHKWNQS` は `queued` のまま保持する。
|
||||
- `00001KVHKWNQA` が closed になった後、改めて body/thread/relations/workspace state を確認して routing する。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: decision author: yoi-orchestrator at: 2026-06-20T05:54:38Z -->
|
||||
|
||||
## Decision
|
||||
|
||||
Routing decision: implementation_ready
|
||||
|
||||
Reason:
|
||||
- Panel Queue により、この Ticket は Orchestrator routing 対象として明示許可された。
|
||||
- 前回は `00001KVHKWNQA` Rust PDK/templates が inprogress だったため blocked/queued hold としたが、現在 `00001KVHKWNQA` は closed。
|
||||
- Ticket body は `new` / `check` / `pack` の CLI surface、non-execution safety、archive safety、deterministic digest/package、JSON reports、diagnostics、tests、validation、non-goals を実装可能な粒度で定義している。
|
||||
- Related Plugin CLI inspection (`00001KVFD3YSV`) と Component runtime (`00001KVG0HR96`) は closed。
|
||||
- 現在 queued はこの Ticket のみ、inprogress は 0 件、child implementation Pods はなし、matching branch/worktree はなし、Orchestrator worktree は clean。
|
||||
- Risk domain は plugin / CLI / authoring / templates / package-validation / packaging / read-only-check だが、Ticket は check/pack が Plugin code を実行しない、new は embedded templates only、enablement config を mutate しない、safe overwrite refusal、archive traversal/root-escape rejection などの invariants を明示している。bounded context check 後も implementation 前に必要な追加 human decision は見つからなかった。
|
||||
|
||||
Evidence checked:
|
||||
- Ticket `00001KVHKWNQS` body / thread / relations / artifacts。
|
||||
- `TicketRelationQuery(00001KVHKWNQS)`: outgoing `depends_on 00001KVHKWNQA` is now closed。Related records are closed context。
|
||||
- `TicketOrchestrationPlanQuery(00001KVHKWNQS)`: previous `blocked_by` plan is resolved by `00001KVHKWNQA` closure; accepted plan recorded now。
|
||||
- Workspace state:
|
||||
- Orchestrator worktree clean at `902b383d`。
|
||||
- queued: this Ticket only。
|
||||
- inprogress: 0。
|
||||
- visible Pods: self + peers only; spawned children 0。
|
||||
- no matching implementation branch/worktree。
|
||||
- Code/resource context:
|
||||
- Rust PDK/template resources are now merged from `00001KVHKWNQA`。
|
||||
- Component Model runtime and Plugin CLI inspection work are closed and available as implementation context。
|
||||
|
||||
IntentPacket:
|
||||
|
||||
Intent:
|
||||
- Add first-party local Plugin authoring CLI commands: `yoi plugin new rust-component-tool <path-or-name>`, `yoi plugin check <path-or-package>`, and `yoi plugin pack <path> [--output <file>]`。
|
||||
- Make local authoring safe and deterministic without remote scripts, without executing Plugin code during validation, and without mutating workspace enablement config。
|
||||
|
||||
Binding decisions / invariants:
|
||||
- `new` uses embedded templates only; no network, no remote template fetch, no `curl | sh` flow。
|
||||
- `new` writes only to the requested destination and refuses non-empty destinations unless a narrow explicit safe option is intentionally added。
|
||||
- Generated Rust Component Tool template should use the current PDK/template resources and current checkout/release dependency policy。
|
||||
- `check` and `pack` must not execute Plugin code or instantiate components。
|
||||
- `check` validates directory and `.yoi-plugin` package inputs with bounded diagnostics and stable JSON report shape for `--json`。
|
||||
- `pack` creates deterministic `.yoi-plugin` output and prints digest/path; `pack --json` returns stable typed output。
|
||||
- `check` validates manifest/runtime/schema/permission/host API declarations, referenced artifact presence, archive safety, and deterministic digest where applicable。
|
||||
- `pack` rejects unsafe paths/root escapes and unsupported package shapes; use currently supported archive format/constraints。
|
||||
- Commands do not mutate enablement/workspace config and do not generate/embed secrets。
|
||||
- Diagnostics/status language should align with existing `yoi plugin list/show` where possible。
|
||||
- Do not implement registry publish/install, enabling/disabling config, Plugin execution, Service/Ingress scaffolding, or extra language templates。
|
||||
|
||||
Requirements / acceptance criteria:
|
||||
- `yoi plugin new rust-component-tool ./my-plugin` creates the expected file set from embedded template without network access。
|
||||
- `yoi plugin check ./my-plugin` validates the generated template and reports next steps/digest/enablement guidance。
|
||||
- `yoi plugin pack ./my-plugin` creates a `.yoi-plugin` package discoverable by existing Plugin discovery。
|
||||
- `check` validates existing `.yoi-plugin` archive inputs and rejects unsafe archives。
|
||||
- `check --json` and `pack --json` provide stable typed reports for tests/agents。
|
||||
- Tests cover generated file set, overwrite refusal, valid/invalid check paths, missing runtime artifact, unsafe package archive, deterministic pack digest, discoverability by existing Plugin discovery, and JSON report shape。
|
||||
- Validation includes focused CLI/plugin authoring tests, relevant `cargo check` / `cargo test`, `cargo fmt --check`, `git diff --check`, and `nix build .#yoi` because CLI/resources/package behavior changes。
|
||||
|
||||
Escalate if:
|
||||
- Current package/archive format lacks enough existing helpers and needs a broader package-format decision。
|
||||
- `check` cannot validate Component world metadata without executing code and needs explicit scope narrowing。
|
||||
- Deterministic packaging conflicts with current discovery/package reader behavior。
|
||||
- Embedded template resource packaging/source filtering needs broader product decision。
|
||||
|
||||
Next action:
|
||||
- Record `queued -> inprogress` and commit Ticket records before creating the implementation worktree and spawning Coder。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-20T05:54:45Z from: queued to: inprogress reason: orchestrator_acceptance_plugin_authoring_cli field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket body/thread, relation metadata, resolved Rust PDK dependency, related closed Tickets, Orchestrator worktree state, visible Pods, existing branch/worktree, and bounded CLI/resource/package context were checked. Dependency `00001KVHKWNQA` is closed, no inprogress/capacity blocker exists, and no missing planning decision was found. Accepting this queued Ticket for implementation before worktree/Pod side effects.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-20T05:55:31Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Implementation orchestration start:
|
||||
- Acceptance records were committed on Orchestrator branch: `d1095f85 ticket: accept plugin authoring cli`。
|
||||
- Created implementation worktree `/home/hare/Projects/yoi/.worktree/00001KVHKWNQS-plugin-authoring-cli` on branch `impl/00001KVHKWNQS-plugin-authoring-cli` at `d1095f85`。
|
||||
- Spawned Coder Pod `yoi-coder-00001KVHKWNQS` with write scope limited to the implementation worktree and read-only root scope only for runtime workspace identity。
|
||||
- Coder task explicitly forbids root/original workspace implementation, merge, Ticket close, and cleanup。
|
||||
|
||||
Next action:
|
||||
- Wait for Coder implementation report, then inspect branch diff/validation evidence and route to Reviewer。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-20T06:25:39Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Coder implementation report received from `yoi-coder-00001KVHKWNQS`.
|
||||
|
||||
Implementation commit:
|
||||
- `945ecdf6 plugin: add authoring cli`
|
||||
|
||||
Changed areas reported:
|
||||
- Added `yoi plugin new rust-component-tool <path-or-name>`。
|
||||
- Added `yoi plugin check <path-or-package> [--json]`。
|
||||
- Added `yoi plugin pack <path> [--output <file>] [--json]`。
|
||||
- Added manifest-level materialized package helpers for safe directory/package reading, deterministic digesting, deterministic stored `.yoi-plugin` writing, and symlink/root-escape rejection。
|
||||
- Reused existing static Plugin inspection for Tool schema / permission / host API declaration checks without Plugin execution。
|
||||
- Added embedded `plugin.component.wasm` placeholder to Rust component Tool template so generated templates can be checked/packed immediately; docs instruct replacing it before enabling/execution。
|
||||
- Updated CLI parsing/help and Plugin development docs。
|
||||
- Added focused tests for generated file set, overwrite refusal, valid directory check, invalid manifest, missing runtime artifact, unsafe package archive, deterministic pack digest, package discoverability, and JSON report shape。
|
||||
|
||||
Coder validation reported:
|
||||
- `cargo fmt`
|
||||
- `cargo fmt --check`
|
||||
- `cargo check -p yoi`
|
||||
- `cargo test -p yoi plugin_cli`
|
||||
- `cargo test -p yoi-plugin-pdk template`
|
||||
- `git diff --check`
|
||||
- CLI smoke:
|
||||
- `cargo run -q -p yoi -- plugin new rust-component-tool ... --json`
|
||||
- `cargo run -q -p yoi -- plugin check ... --json`
|
||||
- `cargo run -q -p yoi -- plugin pack ... --output ... --json`
|
||||
- invalid check reports `"status": "rejected"` and exits non-zero。
|
||||
- `nix build .#yoi --no-link` was attempted but failed due environment/storage: `No space left on device`。
|
||||
- No Cargo dependency or `Cargo.lock` changes were introduced。
|
||||
|
||||
Known risks / deferrals reported:
|
||||
- Component validation remains metadata/static only; no component instantiation/execution is performed by design。
|
||||
- Template includes a placeholder artifact solely for deterministic authoring check/pack; docs instruct replacing it before enabling/execution。
|
||||
|
||||
Orchestrator evidence checked before review dispatch:
|
||||
- Implementation worktree is clean on `impl/00001KVHKWNQS-plugin-authoring-cli`。
|
||||
- HEAD is `945ecdf6`。
|
||||
- Diff from acceptance `d1095f85..HEAD` is one implementation commit touching 6 files, about 1274 insertions / 24 deletions。
|
||||
- `git diff --check d1095f85..HEAD` produced no diagnostics。
|
||||
|
||||
Next action:
|
||||
- Dispatch Reviewer for r1 review against Ticket requirements, with focus on non-execution safety, archive/path traversal safety, deterministic pack/digest behavior, placeholder artifact policy, JSON report stability, discoverability, workspace/config non-mutation, CLI UX, tests, and Nix/package validation feasibility。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: plan author: yoi-orchestrator at: 2026-06-20T06:26:24Z -->
|
||||
|
||||
## Plan
|
||||
|
||||
Review dispatch:
|
||||
- Spawned Reviewer Pod `yoi-reviewer-00001KVHKWNQS-r1` against implementation branch `impl/00001KVHKWNQS-plugin-authoring-cli`。
|
||||
- Review target commit: `945ecdf6 plugin: add authoring cli`。
|
||||
- Review baseline: `d1095f85`。
|
||||
- Reviewer task focuses on non-execution safety, archive/path traversal safety, deterministic pack/digest behavior, placeholder artifact policy, JSON report stability, discoverability, workspace/config non-mutation, CLI UX, tests, and Nix/package validation feasibility。
|
||||
- Reviewer is instructed not to edit source, commit, merge, close the Ticket, or use TicketReview directly; it will report verdict/evidence back to Orchestrator。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVHKWNQS-r1 at: 2026-06-20T06:36:52Z status: request_changes -->
|
||||
|
||||
## Review: request changes
|
||||
|
||||
Verdict: `request_changes`
|
||||
|
||||
確認範囲:
|
||||
- Ticket body/thread / Orchestrator IntentPacket
|
||||
- Implementation diff: `d1095f85..945ecdf6`
|
||||
- 主な対象: `crates/yoi/src/plugin_cli.rs`, `crates/yoi/src/main.rs`, `crates/manifest/src/plugin.rs`, `resources/plugin/templates/rust-component-tool/*`, `docs/development/plugin-development.md`, `package.nix`。
|
||||
|
||||
Blocking issues:
|
||||
1. `yoi plugin new` が symlink destination を辿り、物理的な requested destination 外へ書き込める。
|
||||
- `materialize_template` は `fs::metadata(destination)` / `fs::read_dir(destination)` を使い、destination symlink を拒否せず `destination.join(relative)` に書く。
|
||||
- Reviewer smoke: `linkdest -> target` に対して `plugin new rust-component-tool "$tmp/linkdest"` を実行すると、`target/plugin.toml` が作られた。
|
||||
- Ticket invariant: `new` は requested destination にだけ書き、non-empty destination を拒否する。symlink destination はこの境界を破る。
|
||||
|
||||
2. Generated placeholder component が `check` で enablement-ready に見える。
|
||||
- Template は text placeholder `resources/plugin/templates/rust-component-tool/plugin.component.wasm` を含む。
|
||||
- `new` output は next steps で一度 warning するが、fresh generated template に対する `check --json` は `status=active diagnostics=0` になり、generic enablement guidance を出す。
|
||||
- Reviewer smoke: generated template check output に placeholder/non-executable warning がなく、`To enable after review...` guidance が出る。
|
||||
- Ticket/reviewer contract: check/pack may pass, but output must not imply executable component is ready for enablement if placeholder is not executable。
|
||||
|
||||
Required fixes:
|
||||
- `plugin new` destination symlink を `symlink_metadata` 等で拒否し、symlink write-through を防ぐ。関連する overwrite/destination tests を追加する。
|
||||
- Generated placeholder artifact を `check` が検出し、bounded diagnostic / next step を出す。Status は `partial` など enablement-ready でない表現にすることを優先する。少なくとも `active diagnostics=0` と enablement guidance の組み合わせは避ける。
|
||||
- `check --json` and human output tests should cover generated template placeholder warning/status。
|
||||
|
||||
Non-blocking concerns:
|
||||
- `nix build .#yoi --no-link` は environment storage (`No space left on device`) で失敗。source-filter/resource-packaging issue は見えていないが、最終 Orchestrator validation で再試行する。
|
||||
- `pack --json` digest is nested under `package.digest`, not top-level. Acceptable if documented/stable, but consider documenting shape。
|
||||
|
||||
Reviewer validation:
|
||||
- `cargo fmt --check`: passed
|
||||
- `git diff --check d1095f85..HEAD`: passed
|
||||
- `cargo check -p yoi`: passed
|
||||
- `cargo test -p yoi plugin_cli`: passed (`15 tests`)
|
||||
- `cargo test -p yoi-plugin-pdk template`: passed
|
||||
- CLI smoke for `new`, `check --json`, `pack --json`, packed package check/list discovery, invalid check rejected: passed except blocker findings above。
|
||||
- `nix build .#yoi --no-link`: failed due `No space left on device`。
|
||||
|
||||
Worktree status at review end: clean。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-20T06:46:09Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Coder r1-fix report received from `yoi-coder-00001KVHKWNQS`.
|
||||
|
||||
New fix commit:
|
||||
- `699db538 plugin: harden authoring checks`
|
||||
|
||||
Branch commits now:
|
||||
- `699db538 plugin: harden authoring checks`
|
||||
- `945ecdf6 plugin: add authoring cli`
|
||||
|
||||
Fix summary:
|
||||
- `plugin new` rejects an existing destination symlink via `symlink_metadata` before writes。
|
||||
- Added regression test ensuring symlink destination is refused and target is not written。
|
||||
- `plugin check` detects embedded generated placeholder `plugin.component.wasm`。
|
||||
- Fresh generated templates report `status: "partial"` instead of `active`。
|
||||
- JSON/human diagnostics include bounded placeholder warning。
|
||||
- Enablement guidance no longer says a package is ready to enable while placeholder artifact remains。
|
||||
- `partial` checks exit successfully; `rejected` checks remain non-zero。
|
||||
- Docs updated for symlink refusal and placeholder/partial behavior。
|
||||
|
||||
Coder validation reported as passing:
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check d1095f85..HEAD`
|
||||
- `cargo check -p yoi`
|
||||
- `cargo test -p yoi plugin_cli`
|
||||
- `cargo test -p yoi-plugin-pdk template`
|
||||
- CLI smoke:
|
||||
- `plugin new ... --json`
|
||||
- `plugin check <generated> --json` => `partial` with placeholder diagnostic。
|
||||
- `plugin pack ... --json` => `packed`。
|
||||
- `plugin check <packed .yoi-plugin> --json` => `partial`。
|
||||
- copied packed archive into `.yoi/plugins` and confirmed `plugin list --workspace ... --json` discovers it。
|
||||
- invalid check after removing runtime artifact => `rejected` and non-zero。
|
||||
- Freed only child-worktree Cargo build artifacts with `cargo clean` and reran `nix build .#yoi --no-link`; it completed successfully。
|
||||
|
||||
Orchestrator evidence checked before r2 review:
|
||||
- Implementation worktree is clean。
|
||||
- HEAD is `699db538`。
|
||||
- Fix diff from `945ecdf6..HEAD` touches `crates/yoi/src/plugin_cli.rs` and `docs/development/plugin-development.md`, about 124 insertions / 34 deletions。
|
||||
- Overall `git diff --check d1095f85..HEAD` produced no diagnostics。
|
||||
|
||||
Next action:
|
||||
- Route back to Reviewer for r2 verification of symlink destination refusal, placeholder partial/check behavior, and final acceptance criteria。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVHKWNQS-r1 at: 2026-06-20T06:50:40Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Verdict: `approve`
|
||||
|
||||
確認範囲:
|
||||
- Ticket body/thread / Orchestrator IntentPacket
|
||||
- r2 fix diff: `945ecdf6..699db538`
|
||||
- 全体実装 diff: `d1095f85..699db538`
|
||||
- 主な対象: `crates/yoi/src/plugin_cli.rs`, `docs/development/plugin-development.md`, and prior `new` / `check` / `pack` implementation surface。
|
||||
|
||||
Previous blocker verification:
|
||||
1. `plugin new` symlink destination write-through
|
||||
- `materialize_template` now uses `fs::symlink_metadata` and rejects destination symlink before writing。
|
||||
- Regression test `plugin_new_refuses_symlink_destination_without_following_it` verifies refusal and no write-through。
|
||||
- CLI smoke confirmed symlink destination is rejected and target directory does not receive `plugin.toml`。
|
||||
|
||||
2. Placeholder component reported as enablement-ready
|
||||
- `check` now compares runtime component bytes against embedded template placeholder and adds bounded `placeholder` diagnostic。
|
||||
- Generated template now reports `status=partial` when static validation is otherwise clean but placeholder remains。
|
||||
- Enablement guidance is suppressed for `partial` and says the package is not ready to enable。
|
||||
- CLI smoke confirmed generated directory and packed `.yoi-plugin` both report `partial` with placeholder diagnostic; `partial` exits successfully, while invalid/missing paths remain non-zero rejected。
|
||||
|
||||
Blocking issues: none。
|
||||
|
||||
Non-blocking concerns / follow-ups:
|
||||
- None required for this Ticket. The hardening keeps status vocabulary aligned with existing Plugin inspection (`active` / `partial` / `rejected`)。
|
||||
|
||||
Reviewer validation:
|
||||
- `cargo fmt --check`: passed
|
||||
- `git diff --check d1095f85..HEAD`: passed
|
||||
- `cargo check -p yoi`: passed
|
||||
- `cargo test -p yoi plugin_cli`: passed (`16 tests`)
|
||||
- `cargo test -p yoi-plugin-pdk template`: passed (`2 template tests`)
|
||||
- CLI smoke after `cargo build -p yoi`: passed for `new`, generated `check --json partial`, human `[partial]`, `pack --json`, packed package `check --json partial`, invalid check rejected/non-zero, symlink destination refusal, and `plugin list --workspace ... --json` discoverability as `disabled`。
|
||||
- `nix build .#yoi --no-link`: passed
|
||||
|
||||
Worktree status at review end: source tree clean。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-20T06:54:35Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Merge and final validation report:
|
||||
|
||||
Merged implementation branch into Orchestrator branch:
|
||||
- Merge commit: `87704ad4 merge: plugin authoring cli`
|
||||
- Implementation commits included:
|
||||
- `945ecdf6 plugin: add authoring cli`
|
||||
- `699db538 plugin: harden authoring checks`
|
||||
|
||||
Reviewer outcome:
|
||||
- r1 requested changes for symlink destination write-through and placeholder component being reported as enablement-ready。
|
||||
- Coder added symlink destination refusal, placeholder detection, `partial` status / diagnostics, and tests。
|
||||
- r2 approved with no blocking issues。
|
||||
|
||||
Orchestrator validation after merge:
|
||||
- Passed before Nix:
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check HEAD^1..HEAD`
|
||||
- `cargo check -p yoi`
|
||||
- `cargo test -p yoi plugin_cli`
|
||||
- `cargo test -p yoi-plugin-pdk template`
|
||||
- Initial `nix build .#yoi --no-link` failed with environment storage exhaustion while building `aws-lc-sys` (`No space left on device`), not a source/package diagnostic。
|
||||
- Orchestrator freed only Orchestrator-worktree Cargo build artifacts with `cargo clean` (`43.3GiB`) and reran:
|
||||
- `nix build .#yoi --no-link`: passed。
|
||||
- `nix path-info -S .#yoi`: `112260512`。
|
||||
|
||||
Validation log for first grouped run:
|
||||
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-Q0KE3A.log`
|
||||
|
||||
Final state:
|
||||
- Orchestrator worktree clean at `87704ad4` after successful Nix validation。
|
||||
- Implementation worktree remains available for cleanup after Ticket completion records are committed。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-20T06:54:45Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Implementation was merged into Orchestrator branch at `87704ad4`, r2 review approved, and final Orchestrator validation passed: `cargo fmt --check`, `git diff --check HEAD^1..HEAD`, `cargo check -p yoi`, focused `yoi plugin_cli` / `yoi-plugin-pdk template` tests, and `nix build .#yoi --no-link` after freeing Orchestrator worktree build artifacts.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-20T06:55:06Z from: done to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-20T06:55:06Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
## Resolution
|
||||
|
||||
`00001KVHKWNQS` を完了しました。
|
||||
|
||||
実装内容:
|
||||
- `yoi plugin new rust-component-tool <path-or-name>` を追加しました。
|
||||
- `yoi plugin check <path-or-package> [--json]` を追加しました。
|
||||
- `yoi plugin pack <path> [--output <file>] [--json]` を追加しました。
|
||||
- Safe directory/package reading、deterministic digesting、deterministic `.yoi-plugin` writing、symlink/root-escape rejection を含む materialized package helpers を追加しました。
|
||||
- `check` / `pack` は Plugin code を実行せず、既存 static Plugin inspection を再利用して manifest/runtime/schema/permission/host API declarations を検査します。
|
||||
- Embedded Rust Component Tool template を `new` で利用し、generated template を check/pack できるよう placeholder `plugin.component.wasm` を追加しました。
|
||||
- Placeholder artifact は `check` で検出され、generated template / packed archive は `partial` と bounded diagnostic を返します。placeholder が残る間は enablement-ready guidance を出しません。
|
||||
- `plugin new` は existing destination symlink を拒否し、write-through を防ぎます。
|
||||
- JSON report shape、human output、CLI help/docs を更新しました。
|
||||
- Focused tests と CLI smoke coverage を追加しました。
|
||||
|
||||
主な commit:
|
||||
- `945ecdf6 plugin: add authoring cli`
|
||||
- `699db538 plugin: harden authoring checks`
|
||||
- `87704ad4 merge: plugin authoring cli`
|
||||
|
||||
Review:
|
||||
- r1 は destination symlink write-through と placeholder artifact の enablement-ready 表示で `request_changes`。
|
||||
- Coder が symlink refusal、placeholder detection、`partial` status/diagnostics、tests/docs を追加。
|
||||
- r2 は `approve`。
|
||||
|
||||
最終 validation:
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check HEAD^1..HEAD`
|
||||
- `cargo check -p yoi`
|
||||
- `cargo test -p yoi plugin_cli`
|
||||
- `cargo test -p yoi-plugin-pdk template`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
補足:
|
||||
- 初回 `nix build .#yoi --no-link` は `aws-lc-sys` build 中に `No space left on device` で environment failure。
|
||||
- Orchestrator worktree の Cargo build artifacts を `cargo clean` で削除してから再実行し、Nix build は成功しました。
|
||||
- `nix path-info -S .#yoi`: `112260512`
|
||||
|
||||
Validation log:
|
||||
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-Q0KE3A.log`
|
||||
|
||||
---
|
||||
@@ -0,0 +1,21 @@
|
||||
{
|
||||
"version": 1,
|
||||
"relations": [
|
||||
{
|
||||
"ticket_id": "00001KVHQDS6B",
|
||||
"kind": "related",
|
||||
"target": "00001KVHKWNQA",
|
||||
"note": "Observed prerequisite Ticket already queued/in progress should allow dependent queueing.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-20T05:19:32Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVHQDS6B",
|
||||
"kind": "related",
|
||||
"target": "00001KVHKWNQS",
|
||||
"note": "Dependent Ticket hit backend conflict despite Panel queue UI allowing it.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-20T05:19:32Z"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,55 @@
|
||||
---
|
||||
title: 'Panel Queue action should allow ready Tickets whose blockers are already queued or in progress'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-20T05:18:00Z'
|
||||
updated_at: '2026-06-20T12:27:08Z'
|
||||
assignee: null
|
||||
readiness: 'implementation_ready'
|
||||
risk_flags: ['ticket', 'panel', 'queue', 'dependency', 'blocker', 'orchestrator']
|
||||
---
|
||||
|
||||
## Background
|
||||
|
||||
Panel ViewModel already treats a ready Ticket as queueable when all blocking relations point at Tickets that are already `queued` or `inprogress`. That matches the intended workflow: once prerequisite work is queued/accepted by Orchestrator, dependent ready Tickets should also be queueable so the human does not need to return after every prerequisite completes.
|
||||
|
||||
However, pressing Enter in Panel still calls the backend `queue_ready` gate, and that backend rejected any unresolved relation blocker regardless of blocker state. This caused a `ticket conflict` even though the UI correctly showed Queue as available.
|
||||
|
||||
Concrete example:
|
||||
|
||||
- `00001KVHKWNQS` depends on `00001KVHKWNQA`.
|
||||
- `00001KVHKWNQA` is already `inprogress`.
|
||||
- Panel shows `00001KVHKWNQS` as queueable.
|
||||
- Enter/Queue fails with backend ticket conflict.
|
||||
|
||||
## Requirements
|
||||
|
||||
- Backend `queue_ready` must match the Panel gating rule.
|
||||
- A ready Ticket may transition `ready -> queued` when every relation blocker is already `queued` or `inprogress`.
|
||||
- A ready Ticket must still be blocked when any relation blocker is `planning` or `ready`.
|
||||
- This change applies to queueing only.
|
||||
- `queued -> inprogress` acceptance remains blocked while unresolved dependency/blocker relations exist; Orchestrator must preserve execution order after queueing.
|
||||
- Existing Panel display behavior should remain aligned with backend behavior.
|
||||
|
||||
## Implementation summary
|
||||
|
||||
- Added backend helper `relation_blocker_allows_queue`.
|
||||
- Updated `LocalTicketBackend::queue_ready` to filter relation blockers by that helper before rejecting.
|
||||
- Kept `queued -> inprogress` relation blocker validation unchanged.
|
||||
- Added backend test coverage for ready Tickets with queued/inprogress blockers.
|
||||
- Re-ran existing Panel ViewModel test that already asserted ready+queued dependency appears queueable.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- `ready` Ticket with `depends_on` target in `queued` state can be queued.
|
||||
- `ready` Ticket with incoming `blocks` blocker in `inprogress` state can be queued.
|
||||
- `ready` Ticket with dependency/blocker still in `planning` remains rejected.
|
||||
- Panel and backend queue behavior are consistent.
|
||||
- Orchestrator acceptance ordering remains guarded by existing `queued -> inprogress` relation check.
|
||||
|
||||
## Validation
|
||||
|
||||
- `cargo test -p ticket queue_gate --lib`
|
||||
- `cargo test -p tui workspace_panel_allows_ready_ticket_when_relation_prerequisite_is_queued --lib`
|
||||
- `cargo check -p ticket -p tui`
|
||||
- `cargo fmt`
|
||||
- `git diff --check`
|
||||
@@ -0,0 +1,3 @@
|
||||
Ticket `00001KVHQDS6B` (`Panel Queue action should allow ready Tickets whose blockers are already queued or in progress`) はすでに `state: done` に到達していたため、workspace Panel から close しました。
|
||||
|
||||
この Close action によって、実装作業、state 変更、Orchestrator/Companion launch、worker invocation は開始されていません。
|
||||
@@ -0,0 +1,27 @@
|
||||
<!-- event: create author: "yoi ticket" at: 2026-06-20T05:18:00Z -->
|
||||
|
||||
## 作成
|
||||
|
||||
LocalTicketBackend によって作成されました。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-20T12:27:08Z from: done to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-20T12:27:08Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
Ticket `00001KVHQDS6B` (`Panel Queue action should allow ready Tickets whose blockers are already queued or in progress`) はすでに `state: done` に到達していたため、workspace Panel から close しました。
|
||||
|
||||
この Close action によって、実装作業、state 変更、Orchestrator/Companion launch、worker invocation は開始されていません。
|
||||
|
||||
|
||||
---
|
||||
@@ -0,0 +1,2 @@
|
||||
{"id":"orch-plan-20260620-060022-1","ticket_id":"00001KVHR3WRF","kind":"waiting_capacity_note","note":"Panel Queue was accepted for routing review, but implementation is held because `00001KVHKWNQS` is currently inprogress with active Coder work. Leave this MCP foundation Ticket queued; reroute when current implementation capacity is free.","author":"yoi-orchestrator","at":"2026-06-20T06:00:22Z"}
|
||||
{"id":"orch-plan-20260620-065554-2","ticket_id":"00001KVHR3WRF","kind":"accepted_plan","accepted_plan":{"summary":"Named local stdio MCP server configuration and trust policy metadataを追加する。This Ticket only parses/validates config and diagnostics; it must not spawn subprocesses or implement JSON-RPC lifecycle. Command/env/secret fields must fail closed, redact sensitive values, and document that local MCP executables run with user OS permissions outside Yoi feature sandbox authority.","branch":"impl/00001KVHR3WRF-mcp-stdio-config-trust","worktree":"/home/hare/Projects/yoi/.worktree/00001KVHR3WRF-mcp-stdio-config-trust","role_plan":"Orchestrator は acceptance records を commit 後、専用 implementation worktree `.worktree/00001KVHR3WRF-mcp-stdio-config-trust` を作成し、Coder をその child worktree への narrow write scope で起動する。Coder 実装後、Reviewer が config schema、trust boundary docs、secret redaction、fail-closed validation、no auto-start/no process execution、Profile/config layering separation を確認する。"},"author":"yoi-orchestrator","at":"2026-06-20T06:55:54Z"}
|
||||
@@ -0,0 +1,13 @@
|
||||
{
|
||||
"version": 1,
|
||||
"relations": [
|
||||
{
|
||||
"ticket_id": "00001KVHR3WRF",
|
||||
"kind": "related",
|
||||
"target": "00001KTR81P9X",
|
||||
"note": "MCP implementation builds on the protocol-backed provider feature substrate.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-20T05:33:03Z"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,49 @@
|
||||
---
|
||||
title: 'MCP: add local stdio server config and trust policy'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-20T05:30:04Z'
|
||||
updated_at: '2026-06-20T07:28:55Z'
|
||||
assignee: null
|
||||
readiness: 'implementation_ready'
|
||||
risk_flags: ['mcp', 'config', 'trust-boundary', 'secrets', 'process-exec']
|
||||
queued_by: 'workspace-panel'
|
||||
queued_at: '2026-06-20T05:58:46Z'
|
||||
---
|
||||
|
||||
## Background
|
||||
|
||||
MCP integration starts with explicit local stdio server configuration and trust policy. Yoi must not auto-start MCP servers from workspace presence, package discovery, or Plugin packages. A configured MCP local stdio server is a local executable running with the user's OS permissions; Yoi feature authority does not sandbox its OS-level side effects.
|
||||
|
||||
This Ticket only defines/parses/validates config and diagnostics. It does not spawn MCP processes or implement JSON-RPC lifecycle.
|
||||
|
||||
## Requirements
|
||||
|
||||
- Add typed Profile/config support for named local stdio MCP servers.
|
||||
- Config fields must cover command, args, cwd policy, env policy, and explicit secret/env references as needed.
|
||||
- No package/workspace presence auto-start.
|
||||
- Validate command/env/secret config fail-closed.
|
||||
- Define diagnostic surfaces for config parse/validation errors.
|
||||
- Redact command/env/secret values where needed; do not write plaintext secrets to logs/model context.
|
||||
- Document local executable trust boundary.
|
||||
- Keep MCP config/trust separate from Plugin permissions and `pod::feature` authority.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- A Profile/config can declare a named local stdio MCP server.
|
||||
- Invalid command/env/secret config is rejected with bounded diagnostic.
|
||||
- Secrets are not emitted in plaintext diagnostics/log/model context.
|
||||
- Config alone does not spawn a process.
|
||||
- Docs explain that configured local MCP servers are not OS-sandboxed by Yoi feature authority.
|
||||
- Tests cover valid config, invalid config, secret redaction, and no auto-start.
|
||||
|
||||
## Non-goals
|
||||
|
||||
- Spawning stdio subprocesses.
|
||||
- MCP initialize/capability negotiation.
|
||||
- Tool/resource/prompt registration.
|
||||
- Streamable HTTP/OAuth/remote MCP.
|
||||
|
||||
## Related work
|
||||
|
||||
- Objective: `00001KTR80WMN`.
|
||||
- Supersedes part of broad MCP Ticket `00001KTR82RB7`.
|
||||
@@ -0,0 +1,37 @@
|
||||
## Resolution
|
||||
|
||||
`00001KVHR3WRF` を完了しました。
|
||||
|
||||
実装内容:
|
||||
- Typed MCP config schema を `crates/manifest` に追加しました。
|
||||
- Profile/config で named local stdio MCP server を宣言できるようにしました。
|
||||
- Config fields は `name`, `command`, `args`, `cwd`, `env.inherit`, `env.set` を含みます。
|
||||
- Env value は `literal`, `secret_ref`, `env_ref` をサポートします。
|
||||
- Validation は duplicate names、empty/NUL command/args、cwd policy/path、env var name、secret ref、NUL literal env values などを fail-closed で検査します。
|
||||
- Diagnostics / `Debug` は secret/env/literal values を plaintext で出さないよう redaction します。
|
||||
- Profile resolution / child manifest inheritance に MCP config を通しましたが、subprocess spawning / initialize / JSON-RPC lifecycle / tool/resource/prompt registration は実装していません。
|
||||
- Docs に local stdio MCP server の trust boundary を記録しました。Configured stdio server は user OS permissions で動く local executable であり、Yoi feature authority / Plugin permissions / MCP config validation は OS sandbox ではありません。
|
||||
|
||||
主な commit:
|
||||
- `e0680cce mcp: add stdio server config`
|
||||
- `9b7c4e27 merge: mcp stdio config trust`
|
||||
|
||||
Review:
|
||||
- r1 は `approve`。
|
||||
- Reviewer は config-only boundary、no process spawning/no auto-start、secret redaction、Profile/config integration、docs trust boundary を確認しました。
|
||||
|
||||
最終 validation:
|
||||
- `cargo fmt --all --check`
|
||||
- `git diff --check HEAD^1..HEAD`
|
||||
- `cargo test -p manifest mcp --lib`
|
||||
- `cargo check`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Package impact:
|
||||
- `nix path-info -S .#yoi`: `112615056`
|
||||
|
||||
Known unrelated note:
|
||||
- Full `cargo test -p manifest --lib` は、branch 外の既存 Plugin template-shape mismatch で失敗するため最終 gate にしませんでした。Reviewer はこの failure が `b0225e48..HEAD` の diff に起因しないことを確認済みです。
|
||||
|
||||
Validation log:
|
||||
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-uxMpR3.log`
|
||||
@@ -0,0 +1,307 @@
|
||||
<!-- event: create author: "yoi ticket" at: 2026-06-20T05:30:04Z -->
|
||||
|
||||
## 作成
|
||||
|
||||
LocalTicketBackend によって作成されました。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: workspace-panel at: 2026-06-20T05:58:46Z from: ready to: queued reason: queued field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を `workspace-panel` が queued にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: decision author: yoi-orchestrator at: 2026-06-20T06:00:44Z -->
|
||||
|
||||
## Decision
|
||||
|
||||
Routing decision: waiting_capacity
|
||||
|
||||
Panel Queue により routing 対象として確認したが、現在 `00001KVHKWNQS` が `inprogress` で Coder 作業中のため、この MCP foundation Ticket は実装開始せず queued のまま保持する。
|
||||
|
||||
Evidence:
|
||||
- Ticket body / relations を確認。
|
||||
- Orchestrator worktree は clean。
|
||||
- queued は MCP chain とこの Ticket 群、inprogress は `00001KVHKWNQS` のみ。
|
||||
- matching branch/worktree は存在しない。
|
||||
|
||||
Next:
|
||||
- `00001KVHKWNQS` が完了して実装 capacity が空いた後、改めて reroute する。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: decision author: yoi-orchestrator at: 2026-06-20T06:56:16Z -->
|
||||
|
||||
## Decision
|
||||
|
||||
Routing decision: implementation_ready
|
||||
|
||||
Reason:
|
||||
- Panel Queue により、この Ticket は Orchestrator routing 対象として明示許可された。
|
||||
- Ticket body は local stdio MCP server configuration / trust policy の範囲を、spawning/lifecycle を含まない config parse/validation/diagnostics Ticket として明確に定義している。
|
||||
- 前回の waiting_capacity note は `00001KVHKWNQS` が inprogress だったためだが、現在 `00001KVHKWNQS` は closed で capacity blocker は解消済み。
|
||||
- `00001KVHR3WRF` 自身には未解決 blocking relation はない。Incoming `00001KVHR3WRY depends_on this` は後続 Ticket であり blocker ではない。
|
||||
- 現在 inprogress は 0 件、child implementation Pods はなし、matching branch/worktree はなし、Orchestrator worktree は clean。
|
||||
- Risk domain は mcp / config / trust-boundary / secrets / process-exec だが、Ticket は no process spawning、no auto-start、secret redaction、local executable trust boundary、Plugin permissions / `pod::feature` authority separation などの invariants を明示している。bounded context check 後も implementation 前に必要な追加 human decision は見つからなかった。
|
||||
|
||||
Evidence checked:
|
||||
- Ticket `00001KVHR3WRF` body / thread / relations / artifacts。
|
||||
- `TicketRelationQuery(00001KVHR3WRF)`: no outgoing blocking dependency; incoming lifecycle Ticket depends on this。
|
||||
- `TicketOrchestrationPlanQuery(00001KVHR3WRF)`: previous waiting capacity note resolved by `00001KVHKWNQS` closure; accepted plan recorded now。
|
||||
- Workspace state:
|
||||
- Orchestrator worktree clean at `a5df9e37`。
|
||||
- queued: MCP chain remains queued。
|
||||
- inprogress: 0。
|
||||
- visible Pods: self + peers only; spawned children 0。
|
||||
- no matching MCP implementation branch/worktree。
|
||||
|
||||
IntentPacket:
|
||||
|
||||
Intent:
|
||||
- Add typed Profile/config support for named local stdio MCP servers and the trust-policy diagnostics around that config。
|
||||
- This Ticket is intentionally config-only: parse, validate, redact, and document; do not spawn processes or implement JSON-RPC lifecycle。
|
||||
|
||||
Binding decisions / invariants:
|
||||
- No package/workspace presence auto-start。Config alone must not spawn an MCP process。
|
||||
- Local stdio MCP servers are local executables running with user OS permissions; Yoi feature authority does not sandbox OS-level side effects。
|
||||
- Keep MCP config/trust policy separate from Plugin permissions and `pod::feature` authority。
|
||||
- Config must be explicit and named; no implicit discovery or auto-enablement。
|
||||
- Command/args/cwd/env/secret-related configuration must validate fail-closed with bounded diagnostics。
|
||||
- Secret/env values must be redacted in diagnostics/log/model-facing surfaces; do not persist plaintext secrets through errors/debug output。
|
||||
- This Ticket must not implement initialize/capability negotiation, tool/resource/prompt registration, streamable HTTP/OAuth/remote MCP, or subprocess spawning。
|
||||
|
||||
Requirements / acceptance criteria:
|
||||
- A Profile/config can declare a named local stdio MCP server。
|
||||
- Invalid command/env/secret config is rejected with bounded diagnostic。
|
||||
- Secrets are not emitted in plaintext diagnostics/log/model context。
|
||||
- Config alone does not spawn a process。
|
||||
- Docs explain that configured local MCP servers are not OS-sandboxed by Yoi feature authority。
|
||||
- Tests cover valid config, invalid config, secret redaction, and no auto-start。
|
||||
|
||||
Escalate if:
|
||||
- Existing Profile/config model cannot represent MCP server declarations without a broader config/profile schema decision。
|
||||
- Secret reference representation would require changing the local secret-store policy rather than referencing existing secret/env abstractions。
|
||||
- Tests require actual process spawning; that belongs to a later Ticket, not this one。
|
||||
|
||||
Next action:
|
||||
- Record `queued -> inprogress` and commit Ticket records before creating the implementation worktree and spawning Coder。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-20T06:56:23Z from: queued to: inprogress reason: orchestrator_acceptance_mcp_stdio_config_trust field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket body/thread, relation metadata, resolved capacity blocker, Orchestrator worktree state, visible Pods, existing branch/worktree, and bounded MCP config/trust context were checked. There is no unresolved blocking dependency, no inprogress/capacity blocker, and no missing planning decision. Accepting this queued Ticket for implementation before worktree/Pod side effects.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-20T06:57:08Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Implementation orchestration start:
|
||||
- Acceptance records were committed on Orchestrator branch: `b0225e48 ticket: accept mcp stdio config trust`。
|
||||
- Created implementation worktree `/home/hare/Projects/yoi/.worktree/00001KVHR3WRF-mcp-stdio-config-trust` on branch `impl/00001KVHR3WRF-mcp-stdio-config-trust` at `b0225e48`。
|
||||
- Spawned Coder Pod `yoi-coder-00001KVHR3WRF` with write scope limited to the implementation worktree and read-only root scope only for runtime workspace identity。
|
||||
- Coder task explicitly forbids root/original workspace implementation, process spawning for this Ticket, merge, Ticket close, and cleanup。
|
||||
|
||||
Next action:
|
||||
- Wait for Coder implementation report, then inspect branch diff/validation evidence and route to Reviewer。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-20T07:18:35Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Coder implementation report received from `yoi-coder-00001KVHR3WRF`.
|
||||
|
||||
Implementation commit:
|
||||
- `e0680cce mcp: add stdio server config`
|
||||
|
||||
Changed areas reported:
|
||||
- Added typed MCP config schema in `crates/manifest`:
|
||||
- `mcp.stdio_server` list with explicit `name`, `command`, `args`, `cwd`, and `env`。
|
||||
- explicit env policy with `inherit` and `set`。
|
||||
- env values support `literal`, `secret_ref`, and `env_ref`。
|
||||
- literal env values are redacted in `Debug`。
|
||||
- Added validation for duplicate names, empty/NUL command and args, cwd policy/path, env variable names, secret refs, and bounded diagnostics without secret/env value leakage。
|
||||
- Integrated MCP config through Profile resolution and child manifest inheritance without adding process spawning。
|
||||
- Added focused tests for valid config, invalid command/duplicate names, invalid secret refs/redaction, nonexistent command accepted as no auto-start proof, and Lua Profile MCP config resolution。
|
||||
- Updated docs in `docs/design/profiles-manifests-prompts.md` with local stdio MCP config and trust boundary。
|
||||
- Updated Nix cargo hash due manifest dependency graph change。
|
||||
|
||||
Coder validation reported:
|
||||
- `cargo test -p manifest mcp --lib`: passed。
|
||||
- `cargo check`: passed。
|
||||
- `cargo fmt --all --check`: passed。
|
||||
- `git diff --check`: passed。
|
||||
- `nix build .#yoi --no-link`: passed。
|
||||
- `cargo test -p manifest --lib`: failed on pre-existing/unrelated `plugin::tests::template_includes_current_pdk_version`, reportedly due `resources/plugin-templates/rust/Cargo.toml` PDK version `0.2.0` vs `CARGO_PKG_VERSION` `0.1.0`。
|
||||
|
||||
Known deferrals:
|
||||
- No MCP subprocess spawning, initialize/capability negotiation, tool/resource/prompt registration, HTTP/OAuth, or JSON-RPC lifecycle added。
|
||||
- Command executability intentionally not checked at config-parse time; only structural validation is performed。
|
||||
|
||||
Orchestrator evidence checked before review dispatch:
|
||||
- Implementation worktree is clean。
|
||||
- HEAD is `e0680cce`。
|
||||
- Diff from acceptance `b0225e48..HEAD` is one implementation commit touching 8 files, about 515 insertions / 10 deletions。
|
||||
- `git diff --check b0225e48..HEAD` produced no diagnostics。
|
||||
|
||||
Next action:
|
||||
- Dispatch Reviewer for r1 review against Ticket requirements, with focus on config schema fit, validation/redaction boundaries, no process spawning/no auto-start, Profile/config layering, docs trust boundary, and whether the reported `manifest --lib` failure is unrelated or must be fixed。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: plan author: yoi-orchestrator at: 2026-06-20T07:19:20Z -->
|
||||
|
||||
## Plan
|
||||
|
||||
Review dispatch:
|
||||
- Spawned Reviewer Pod `yoi-reviewer-00001KVHR3WRF-r1` against implementation branch `impl/00001KVHR3WRF-mcp-stdio-config-trust`。
|
||||
- Review target commit: `e0680cce mcp: add stdio server config`。
|
||||
- Review baseline: `b0225e48`。
|
||||
- Reviewer task focuses on config-only boundary, no process spawning/no auto-start, secret/env redaction, fail-closed validation, Profile/config layering, trust-boundary docs, MCP vs Plugin/feature authority separation, and the reported `cargo test -p manifest --lib` failure。
|
||||
- Reviewer is instructed not to edit source, commit, merge, close the Ticket, or use TicketReview directly; it will report verdict/evidence back to Orchestrator。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: review author: yoi-reviewer-00001KVHR3WRF-r1 at: 2026-06-20T07:27:01Z status: approve -->
|
||||
|
||||
## Review: approve
|
||||
|
||||
Verdict: `approve`
|
||||
|
||||
確認範囲:
|
||||
- Ticket contract / Orchestrator IntentPacket。
|
||||
- Diff: `b0225e48..e0680cce`。
|
||||
- 主な対象: `crates/manifest/src/lib.rs`, `crates/manifest/src/config.rs`, `crates/manifest/src/profile.rs`, `crates/manifest/Cargo.toml`, `crates/pod/src/spawn/tool.rs`, `docs/design/profiles-manifests-prompts.md`, `Cargo.lock`, `package.nix`。
|
||||
- Diff 内で `Command::new`, `tokio::process`, `std::process`, spawn, initialize/capability negotiation, JSON-RPC/tool registration などの process/lifecycle implementation 追加を確認。
|
||||
|
||||
Blocking issues: none。
|
||||
|
||||
Critical risk checks:
|
||||
- Config-only boundary は維持されている。MCP subprocess spawning、MCP initialize/capability negotiation、JSON-RPC lifecycle、tool/resource/prompt registration は追加されていない。
|
||||
- `crates/manifest/src/lib.rs` は typed `McpConfig`、named `stdio_server` entries、`command` / `args` / `cwd` / explicit `env.inherit` / `env.set`、`literal` / `secret_ref` / `env_ref` を追加している。
|
||||
- `McpEnvValue::Debug` は literal env values を redact する。validation errors は literal/env/secret values を echo しない。
|
||||
- `crates/manifest/src/config.rs` は duplicate server names、empty/NUL names/commands/args、cwd absolute-after-resolution policy、env var names、secret ref IDs、NUL literal env values を bounded diagnostics で検証している。
|
||||
- Profile integration は通常の Profile resolution / path-resolution flow 経由。Reusable Profiles は absolute MCP cwd paths を拒否する。
|
||||
- `crates/pod/src/spawn/tool.rs` は `manifest.mcp.clone()` を inherited child manifest config に載せるだけで、child/grandchild MCP execution は追加しない。
|
||||
- Docs は stdio config 宣言だけでは subprocess / tool/resource/prompt registration が起きないこと、local stdio MCP server は user OS permissions の通常 executable として動くこと、Yoi feature flags / Plugin permissions / MCP config validation は OS sandbox ではないことを明記している。
|
||||
|
||||
Non-blocking concerns / follow-ups:
|
||||
- `cargo test -p manifest --lib` は `plugin::tests::embedded_rust_component_tool_template_is_valid_package_shape` で失敗するが、この branch の diff は `crates/manifest/src/plugin.rs` や template files を変更していない。Reviewer は `b0225e48` 時点で既に同じ template resource/test mismatch があるため unrelated/pre-existing と判断した。
|
||||
|
||||
Reviewer validation:
|
||||
- `cargo fmt --all --check`: passed。
|
||||
- `git diff --check b0225e48..HEAD`: passed。
|
||||
- `cargo test -p manifest mcp --lib`: 5 MCP-focused tests passed。
|
||||
- `cargo check`: passed。
|
||||
- `nix build .#yoi --no-link`: passed。
|
||||
- `cargo test -p manifest --lib`: unrelated pre-existing plugin template-shape failure only。
|
||||
|
||||
Worktree status at review end: clean。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: implementation_report author: yoi-orchestrator at: 2026-06-20T07:28:20Z -->
|
||||
|
||||
## Implementation report
|
||||
|
||||
Merge and final validation report:
|
||||
|
||||
Merged implementation branch into Orchestrator branch:
|
||||
- Merge commit: `9b7c4e27 merge: mcp stdio config trust`
|
||||
- Implementation commit included:
|
||||
- `e0680cce mcp: add stdio server config`
|
||||
|
||||
Reviewer outcome:
|
||||
- r1 approved with no blocking issues。
|
||||
- Reviewer confirmed config-only boundary, no subprocess/MCP lifecycle implementation, redaction behavior, Profile/config integration, docs trust boundary, and that `cargo test -p manifest --lib` failure is unrelated/pre-existing plugin template test mismatch。
|
||||
|
||||
Orchestrator validation after merge passed:
|
||||
- `cargo fmt --all --check`
|
||||
- `git diff --check HEAD^1..HEAD`
|
||||
- `cargo test -p manifest mcp --lib`
|
||||
- `cargo check`
|
||||
- `nix build .#yoi --no-link`
|
||||
- `nix path-info -S .#yoi`: `112615056`
|
||||
|
||||
Validation log:
|
||||
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-uxMpR3.log`
|
||||
|
||||
Known unrelated validation note:
|
||||
- Full `cargo test -p manifest --lib` was not used as a final gate because Reviewer confirmed an unrelated/pre-existing plugin template-shape failure outside this branch's diff。
|
||||
|
||||
Final state:
|
||||
- Orchestrator worktree clean at `9b7c4e27` after validation。
|
||||
- Implementation worktree remains available for cleanup after Ticket completion records are committed。
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: yoi-orchestrator at: 2026-06-20T07:28:26Z from: inprogress to: done reason: merged_reviewed_validated field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Implementation was merged into Orchestrator branch at `9b7c4e27`, review approved, and final Orchestrator validation passed: `cargo fmt --all --check`, `git diff --check HEAD^1..HEAD`, `cargo test -p manifest mcp --lib`, `cargo check`, and `nix build .#yoi --no-link`.
|
||||
|
||||
---
|
||||
|
||||
<!-- event: state_changed author: hare at: 2026-06-20T07:28:55Z from: done to: closed reason: closed field: state -->
|
||||
|
||||
## State changed
|
||||
|
||||
Ticket を closed にしました。
|
||||
|
||||
|
||||
---
|
||||
|
||||
<!-- event: close author: hare at: 2026-06-20T07:28:55Z status: closed -->
|
||||
|
||||
## 完了
|
||||
|
||||
## Resolution
|
||||
|
||||
`00001KVHR3WRF` を完了しました。
|
||||
|
||||
実装内容:
|
||||
- Typed MCP config schema を `crates/manifest` に追加しました。
|
||||
- Profile/config で named local stdio MCP server を宣言できるようにしました。
|
||||
- Config fields は `name`, `command`, `args`, `cwd`, `env.inherit`, `env.set` を含みます。
|
||||
- Env value は `literal`, `secret_ref`, `env_ref` をサポートします。
|
||||
- Validation は duplicate names、empty/NUL command/args、cwd policy/path、env var name、secret ref、NUL literal env values などを fail-closed で検査します。
|
||||
- Diagnostics / `Debug` は secret/env/literal values を plaintext で出さないよう redaction します。
|
||||
- Profile resolution / child manifest inheritance に MCP config を通しましたが、subprocess spawning / initialize / JSON-RPC lifecycle / tool/resource/prompt registration は実装していません。
|
||||
- Docs に local stdio MCP server の trust boundary を記録しました。Configured stdio server は user OS permissions で動く local executable であり、Yoi feature authority / Plugin permissions / MCP config validation は OS sandbox ではありません。
|
||||
|
||||
主な commit:
|
||||
- `e0680cce mcp: add stdio server config`
|
||||
- `9b7c4e27 merge: mcp stdio config trust`
|
||||
|
||||
Review:
|
||||
- r1 は `approve`。
|
||||
- Reviewer は config-only boundary、no process spawning/no auto-start、secret redaction、Profile/config integration、docs trust boundary を確認しました。
|
||||
|
||||
最終 validation:
|
||||
- `cargo fmt --all --check`
|
||||
- `git diff --check HEAD^1..HEAD`
|
||||
- `cargo test -p manifest mcp --lib`
|
||||
- `cargo check`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Package impact:
|
||||
- `nix path-info -S .#yoi`: `112615056`
|
||||
|
||||
Known unrelated note:
|
||||
- Full `cargo test -p manifest --lib` は、branch 外の既存 Plugin template-shape mismatch で失敗するため最終 gate にしませんでした。Reviewer はこの failure が `b0225e48..HEAD` の diff に起因しないことを確認済みです。
|
||||
|
||||
Validation log:
|
||||
- `/run/user/1000/yoi/yoi-orchestrator/bash-output/bash-uxMpR3.log`
|
||||
|
||||
---
|
||||
@@ -0,0 +1,2 @@
|
||||
{"id":"orch-plan-20260620-060022-1","ticket_id":"00001KVHR3WRY","kind":"blocked_by","related_ticket":"00001KVHR3WRF","note":"Lifecycle client requires explicit local stdio MCP config/trust policy. `00001KVHR3WRF` is queued and not yet implemented; leave this Ticket queued until that dependency is closed.","author":"yoi-orchestrator","at":"2026-06-20T06:00:22Z"}
|
||||
{"id":"orch-plan-20260620-072936-2","ticket_id":"00001KVHR3WRY","kind":"accepted_plan","accepted_plan":{"summary":"Configured local stdio MCP serverを明示 config から起動し、newline-delimited JSON-RPC over stdioで initialize/capability negotiation/initialized notification/shutdownを行う lifecycle client foundation を実装する。Tools/resources/prompts registration/executionは後続 Ticket のため含めない。","branch":"impl/00001KVHR3WRY-mcp-stdio-lifecycle-client","worktree":"/home/hare/Projects/yoi/.worktree/00001KVHR3WRY-mcp-stdio-lifecycle-client","role_plan":"Orchestrator は acceptance records を commit 後、専用 implementation worktree `.worktree/00001KVHR3WRY-mcp-stdio-lifecycle-client` を作成し、Coder をその child worktree への narrow write scope で起動する。Coder 実装後、Reviewer が process lifecycle safety、JSON-RPC framing、initialize/capability negotiation、stderr bounds/redaction、shutdown/kill fallback、no ToolRegistry/resources/prompts exposure を確認する。"},"author":"yoi-orchestrator","at":"2026-06-20T07:29:36Z"}
|
||||
@@ -0,0 +1,21 @@
|
||||
{
|
||||
"version": 1,
|
||||
"relations": [
|
||||
{
|
||||
"ticket_id": "00001KVHR3WRY",
|
||||
"kind": "depends_on",
|
||||
"target": "00001KVHR3WRF",
|
||||
"note": "Lifecycle client requires explicit local stdio MCP config/trust policy.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-20T05:33:03Z"
|
||||
},
|
||||
{
|
||||
"ticket_id": "00001KVHR3WRY",
|
||||
"kind": "related",
|
||||
"target": "00001KTR81P9X",
|
||||
"note": "MCP lifecycle uses the protocol-backed provider feature substrate.",
|
||||
"author": "yoi ticket",
|
||||
"at": "2026-06-20T05:33:03Z"
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,51 @@
|
||||
---
|
||||
title: 'MCP: implement stdio JSON-RPC lifecycle client'
|
||||
state: 'closed'
|
||||
created_at: '2026-06-20T05:30:04Z'
|
||||
updated_at: '2026-06-20T07:59:30Z'
|
||||
assignee: null
|
||||
readiness: 'implementation_ready'
|
||||
risk_flags: ['mcp', 'stdio', 'json-rpc', 'process-lifecycle', 'diagnostics']
|
||||
queued_by: 'workspace-panel'
|
||||
queued_at: '2026-06-20T05:58:54Z'
|
||||
---
|
||||
|
||||
## Background
|
||||
|
||||
After MCP local stdio server config exists, Yoi needs a lifecycle client that can start a configured server, speak newline-delimited JSON-RPC over stdio, perform MCP initialize/capability negotiation, and shut down safely.
|
||||
|
||||
This Ticket creates the protocol/lifecycle foundation only. It does not expose MCP tools/resources/prompts to the model-visible ToolRegistry.
|
||||
|
||||
## Requirements
|
||||
|
||||
- Spawn configured local stdio MCP servers from explicit config only.
|
||||
- Use stdin/stdout newline-delimited JSON-RPC.
|
||||
- Treat stdout as protocol messages.
|
||||
- Treat stderr as bounded diagnostics/logging, not automatic protocol failure.
|
||||
- Implement initialize, capability negotiation, and notifications/initialized.
|
||||
- Track server name and startup phase in diagnostics.
|
||||
- Implement graceful shutdown, terminate, and kill fallback.
|
||||
- Handle process exit/disconnect/startup failure with bounded diagnostics.
|
||||
- Do not declare sampling or elicitation client capabilities initially.
|
||||
- Add local mock MCP server tests.
|
||||
|
||||
## Acceptance criteria
|
||||
|
||||
- Mock local stdio MCP server initializes successfully.
|
||||
- Initialize failure reports server name and phase.
|
||||
- stderr is bounded and redacted where needed.
|
||||
- Shutdown is safe and deterministic.
|
||||
- Sampling/elicitation are not advertised and fail closed if requested.
|
||||
- No tools/resources/prompts are registered by this Ticket.
|
||||
|
||||
## Non-goals
|
||||
|
||||
- tools/list ToolRegistry registration.
|
||||
- tools/call execution.
|
||||
- resources/prompts operations.
|
||||
- Streamable HTTP/OAuth/remote MCP.
|
||||
|
||||
## Related work
|
||||
|
||||
- Depends on `00001KVHR3WRF`.
|
||||
- Objective: `00001KTR80WMN`.
|
||||
@@ -0,0 +1,37 @@
|
||||
## Resolution
|
||||
|
||||
`00001KVHR3WRY` を完了しました。
|
||||
|
||||
実装内容:
|
||||
- New internal crate `mcp` を追加しました。
|
||||
- Explicit MCP stdio server config から resolved stdio server spec を作成する bridge を追加しました。
|
||||
- Tokio child process による local stdio MCP server lifecycle foundation を実装しました。
|
||||
- stdin/stdout/stderr handling、newline-delimited JSON-RPC request/response handling、initialize/capability negotiation、`notifications/initialized` を実装しました。
|
||||
- stdout/stderr/protocol payloads は bounded に扱います。
|
||||
- stderr は bounded diagnostics/logging として扱い、protocol failure とは別扱いです。
|
||||
- server name / phase-aware errors を追加しました。
|
||||
- shutdown は stdin close / wait / terminate / kill fallback で deterministic に行います。
|
||||
- Server-to-client requests は fail-closed し、sampling/elicitation は advertise せず、unknown request は JSON-RPC error で返します。
|
||||
- `McpStdioServerSpec` の `Debug` は custom redacted 実装にし、resolved env/secret-derived values を出さない regression test を追加しました。
|
||||
- ToolRegistry / tools/resources/prompts registration、remote MCP / Streamable HTTP / OAuth は実装していません。
|
||||
|
||||
主な commit:
|
||||
- `a114fa9d mcp: implement stdio lifecycle client`
|
||||
- `f396e1a2 mcp: redact stdio server spec debug`
|
||||
- `9cf5344f merge: mcp stdio lifecycle client`
|
||||
|
||||
Review:
|
||||
- r1 は resolved spec `Debug` による env/secret leak で `request_changes`。
|
||||
- Coder が custom redacted `Debug` と regression test を追加。
|
||||
- r2 は `approve`。
|
||||
|
||||
最終 validation:
|
||||
- `cargo fmt --check`
|
||||
- `git diff --check HEAD^1..HEAD`
|
||||
- `cargo test -p mcp`
|
||||
- `cargo check`
|
||||
- `cargo tree -p mcp --depth 1`
|
||||
- `nix build .#yoi --no-link`
|
||||
|
||||
Package impact:
|
||||
- `nix path-info -S .#yoi`: `112615056`
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user