feat(plugin): Add versioned plugin storage and lockfile - #1937
Merged
Conversation
Phase 2 of WASM auth plugin support: installed plugins now live at <plugin_root>/<name>/<version>/<name>.wasm and are tracked in a JSON lockfile (plugins.lock) recording each entry's sha256, source, install time, and trust metadata, plus which version of each plugin name is active. Lockfile writes go through a tmp-file-then-rename atomic write so a process killed mid-install can never leave it corrupted. - PluginLockfile/PluginEntry/TrustInfo with load/save and atomic_write - registry::install/remove/verify/installed for the full lifecycle, loading only the active version and re-checking sha256 on every load - osc plugin remove/info/verify commands; install/list updated for the versioned, multi-version-aware layout Assisted-By: Claude Sonnet 5 <noreply@anthropic.com> Signed-off-by: Artem Goncharov <artem.goncharov@gmail.com>
Open
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Phase 2 of WASM auth plugin support: installed plugins now live at
<plugin_root>///.wasm and are tracked in a JSON
lockfile (plugins.lock) recording each entry's sha256, source, install
time, and trust metadata, plus which version of each plugin name is
active. Lockfile writes go through a tmp-file-then-rename atomic write
so a process killed mid-install can never leave it corrupted.
loading only the active version and re-checking sha256 on every load
versioned, multi-version-aware layout
Assisted-By: Claude Sonnet 5 noreply@anthropic.com
Signed-off-by: Artem Goncharov artem.goncharov@gmail.com