refactor(web): read plugins through a PluginCatalog; only the display runs them (#688)

The web process built its own PluginManager and loaded plugins into itself:
store installs and updates loaded or reloaded a web-side copy, and config
saves and enable/disable called on_config_change, on_enable and on_disable
on it. None of that reached the panel, and /plugins/installed reported
runtime state from those copies.

- Add PluginCatalog (src/plugin_system/plugin_catalog.py): manifests,
  directories, display modes, installed version, schema and config reads,
  with no way to run a plugin. app.py and both blueprints use it; the
  plugin_manager blueprint attribute is gone.
- Remove every lifecycle call from the web routes. Config changes already
  reach the display through ConfigService (on_config_change) and the
  enabled-set reconcile.
- Health and metrics readers move to api_v3.health_tracker /
  resource_monitor. /plugins/installed reports loaded/state/error_info as
  null (the display does not publish them) and enabled by the display's
  rule.
- Store install, update and uninstall answer restart_required when the
  running display will not pick the change up by itself
  (display_restart_required). The restart banner follows the flag via
  window.noteRestartRequired instead of the /config/main URL heuristic;
  /config/main now sends restart_required: true.
- The one remaining in-process import of plugin code (Starlark helper
  modules, oauth_flow action scripts) goes through
  _import_plugin_code_in_web_process() until a web-entry contract.
- /plugins/installed reports vegas_participation (from #682) from the
  user's setting or the manifest, with vegas_participation_source; when
  only the plugin's code decides it, null with source 'runtime', since the
  web process no longer has plugin instances to ask.
- Check & Update All keeps its restart flags when the final list refresh
  fails, and asks for a restart when an enabled plugin's first request got
  no answer and the re-sent one found it up to date.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Chuck
2026-09-30 10:39:44 -04:00
committed by GitHub
co-authored by Claude Opus 5.5
parent ba6eccb489
commit 7ab6fb1aff
74 changed files with 1759 additions and 676 deletions
@@ -93,13 +93,12 @@ def env(tmp_path, api_v3_module):
api = api_v3_module.api_v3
api.config_manager = config_manager
api.schema_manager = SchemaManager(plugins_dir=plugins_dir, project_root=tmp_path)
api.plugin_manager.plugin_manifests = {PLUGIN_ID: {"id": PLUGIN_ID},
api.plugin_catalog.plugin_manifests = {PLUGIN_ID: {"id": PLUGIN_ID},
NEWS_ID: {"id": NEWS_ID}}
api.plugin_manager.get_plugin.return_value = None
class Env:
client = build_app(api).test_client()
plugin_manager = api.plugin_manager
plugin_catalog = api.plugin_catalog
@staticmethod
def stored(plugin_id=PLUGIN_ID):
@@ -183,19 +182,18 @@ class TestReset:
assert calls == [True]
assert env.stored()["stock_symbols"] == ["AAPL"]
def test_reset_notifies_the_plugin_with_its_prepared_config(self, env):
plugin = MagicMock()
env.plugin_manager.get_plugin.return_value = plugin
env.plugin_manager.prepare_plugin_config.side_effect = (
lambda _pid, raw: {**raw, "prepared": True})
def test_reset_runs_no_plugin_code_in_the_web_process(self, env):
# The running plugin gets the reset config from the display's config
# watcher (on_config_change there, with the prepared section). The
# catalog has no get_plugin, so a route that still reached for a
# plugin instance here would fail this request.
assert not hasattr(env.plugin_catalog, "get_plugin")
response = env.client.post("/api/v3/plugins/config/reset",
json={"plugin_id": PLUGIN_ID})
assert response.status_code == 200, response.get_json()
handed_over = plugin.on_config_change.call_args.args[0]
assert handed_over["prepared"] is True
assert handed_over["stock_symbols"] == ["AAPL"]
assert env.stored()["stock_symbols"] == ["AAPL"]
def test_a_failed_save_is_reported(self, env, monkeypatch):
failed = MagicMock(message="disk full")