refactor(web): read plugins through a PluginCatalog; only the display runs them (#688)

The web process built its own PluginManager and loaded plugins into itself:
store installs and updates loaded or reloaded a web-side copy, and config
saves and enable/disable called on_config_change, on_enable and on_disable
on it. None of that reached the panel, and /plugins/installed reported
runtime state from those copies.

- Add PluginCatalog (src/plugin_system/plugin_catalog.py): manifests,
  directories, display modes, installed version, schema and config reads,
  with no way to run a plugin. app.py and both blueprints use it; the
  plugin_manager blueprint attribute is gone.
- Remove every lifecycle call from the web routes. Config changes already
  reach the display through ConfigService (on_config_change) and the
  enabled-set reconcile.
- Health and metrics readers move to api_v3.health_tracker /
  resource_monitor. /plugins/installed reports loaded/state/error_info as
  null (the display does not publish them) and enabled by the display's
  rule.
- Store install, update and uninstall answer restart_required when the
  running display will not pick the change up by itself
  (display_restart_required). The restart banner follows the flag via
  window.noteRestartRequired instead of the /config/main URL heuristic;
  /config/main now sends restart_required: true.
- The one remaining in-process import of plugin code (Starlark helper
  modules, oauth_flow action scripts) goes through
  _import_plugin_code_in_web_process() until a web-entry contract.
- /plugins/installed reports vegas_participation (from #682) from the
  user's setting or the manifest, with vegas_participation_source; when
  only the plugin's code decides it, null with source 'runtime', since the
  web process no longer has plugin instances to ask.
- Check & Update All keeps its restart flags when the final list refresh
  fails, and asks for a restart when an enabled plugin's first request got
  no answer and the re-sent one found it up to date.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Chuck
2026-09-30 10:39:44 -04:00
committed by GitHub
co-authored by Claude Opus 5.5
parent ba6eccb489
commit 7ab6fb1aff
74 changed files with 1759 additions and 676 deletions
@@ -69,10 +69,20 @@ const PluginInstallManager = {
if (onProgress) onProgress(i + 1, plugins.length, plugin.id);
// Each plugin gets its own pass over the backoff schedule.
const pendingDelays = retryDelays.slice();
let lostAnswer = false;
for (;;) {
try {
const result = await window.PluginAPI.updatePlugin(plugin.id);
results.push({ pluginId: plugin.id, success: true, result });
const entry = { pluginId: plugin.id, success: true, result };
if (lostAnswer) {
// An earlier attempt got no answer, so it may have
// updated the plugin before the connection dropped,
// and this answer then says up_to_date. restartRequest()
// reads these two.
entry.afterLostAnswer = true;
entry.enabled = plugin.enabled === true;
}
results.push(entry);
break;
} catch (error) {
// No HTTP answer at all (connection refused/reset, e.g. the
@@ -81,6 +91,7 @@ const PluginInstallManager = {
// back rather than skipping it. An HTTP error response is
// the server's answer and is not retried.
if (error && error.error_code === 'NETWORK_ERROR' && pendingDelays.length > 0) {
lostAnswer = true;
await sleep(pendingDelays.shift());
continue;
}
@@ -90,9 +101,14 @@ const PluginInstallManager = {
}
}
// Reload plugin list once at the end
// Reload plugin list once at the end. A failed refresh must not
// lose the results: they carry the restart flags.
if (window.PluginStateManager) {
await window.PluginStateManager.loadInstalledPlugins();
try {
await window.PluginStateManager.loadInstalledPlugins();
} catch (error) {
console.warn('Could not refresh the installed plugin list after updating:', error);
}
}
return results;
@@ -148,6 +164,42 @@ const PluginInstallManager = {
text: parts.join(', '),
type
};
},
/**
* The first update answer that says the display needs a restart, or null.
*
* The display keeps running the code it loaded until it restarts, so an
* update of a plugin it runs answers `restart_required: true` (with the
* banner's wording in `restart_message`). One restart covers every
* plugin in the run, so one answer is enough; pass it to
* window.noteRestartRequired.
*
* Failing that, an enabled plugin whose first request got no answer and
* whose re-sent one says up_to_date may have been updated by the lost
* request, which nothing reported: that asks for a restart too, since a
* needless restart is cheaper than the display running old code.
*
* @param {Array} results - updateAll()'s results
* @returns {Object|null}
*/
restartRequest(results) {
const entries = Array.isArray(results) ? results : [];
for (const entry of entries) {
const body = entry && entry.success ? entry.result : null;
if (body && body.restart_required === true) return body;
}
for (const entry of entries) {
if (entry && entry.success && entry.afterLostAnswer && entry.enabled
&& this.updateOutcome(entry) === 'up_to_date') {
return {
restart_required: true,
restart_message: `Plugin ${entry.pluginId} may have been updated before the `
+ 'connection dropped — restart the display to be sure it runs the new version',
};
}
}
return null;
}
};