refactor(plugins): the display publishes plugin runtime state; retire plugin_state.json (#690)

Stage 2 of the web plugin catalog, after #688.

- The display publishes a plugin runtime snapshot (plugin_runtime.py) to
  the shared cache: per plugin loaded, lifecycle state, a short redacted
  error summary, the version it loaded and when, plus published_at /
  stale_after / running. Written on change (throttled to 10 s; the
  RUNNING/ENABLED flip of an ordinary update is not a change) and once a
  minute otherwise; cleanup() publishes running: false.
- The web reads it back and restores loaded / state / error_info in
  /api/v3/plugins/installed (plus loaded_version, loaded_at and
  data.runtime). Only a live snapshot counts; stale, stopped or missing
  answers null and says which.
- data/plugin_state.json is retired: every reader and writer moved to
  config + disk (desired) or the snapshot (observed). Nothing in it was
  non-derivable, so nothing is migrated and an existing file is left
  unread. The web-side PluginStateManager (state_manager.py) is removed;
  the display's plugin_state.PluginStateManager is the only state machine.
- StateReconciliation compares config + disk with the snapshot, reporting
  enabled-but-not-loaded and older-version-loaded as no_action findings.
- Backups list installed manifests with enabled from config.json.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Chuck
2026-09-30 10:48:14 -04:00
committed by GitHub
co-authored by Claude Opus 5.5
parent 7ab6fb1aff
commit b09434a418
38 changed files with 1893 additions and 940 deletions
+35
View File
@@ -175,6 +175,41 @@ read any of them:
process still imports plugin code -- the Starlark helper modules and an
`oauth_flow` action script -- is `_import_plugin_code_in_web_process()`,
until a plugin web-entry contract replaces it.
- The display publishes its plugin runtime state, and the web interface
reads it (web plugin catalog, stage 2). A new snapshot in the shared cache
(`plugin_runtime_snapshot`, `src/plugin_system/plugin_runtime.py`) lists,
per plugin, whether the display has it loaded, its lifecycle state, a
short redacted summary of its last error, the version it loaded and when.
It is written when something changes (at most every 10 s; an ordinary
plugin update is not a change) and otherwise once a minute, carries its
publish time, and says `running: false` when the display stops.
- `/api/v3/plugins/installed` fills `loaded`, `state` and `error_info`
again, from that snapshot, and adds `loaded_version` and `loaded_at`.
Only a live snapshot counts: when the display is stopped, has not
published, or has not refreshed for 3 minutes, those fields are `null`
and the new `data.runtime.status` says `stopped`, `unknown` or `stale`.
- `data/plugin_state.json` is retired: nothing reads or writes it. It held
copies of config.json's enabled flags and the manifests' versions, plus
install timestamps only `GET /api/v3/plugins/state` returned, so nothing
in it is migrated; an existing file is left in place and can be deleted.
The web-side `PluginStateManager` (`src/plugin_system/state_manager.py`)
that wrote it is removed; the display's state machine in
`plugin_state.py` is now the only `PluginStateManager`.
- `GET /api/v3/plugins/state` is built per request from config.json, the
plugins on disk and the display's snapshot (`installed`, `in_config`,
`enabled`, `version`, `status`, the runtime fields, and `installed_at` /
`last_updated` from the operation history), with a top-level `runtime`.
It no longer returns `config_version` or `metadata`.
- State reconciliation compares desired state (config.json plus disk) with
the display's snapshot. New findings -- enabled but not loaded (with the
load error), and loaded at an older version than is installed -- are
reported with `fix_action: no_action`; the unresolved-issues banner is
unchanged. `StateReconciliation` takes `config_manager`, `plugins_dir`,
`store_manager` and `runtime_source` as keywords.
- Backups list the installed plugins from disk, with `enabled` from
config.json, instead of merging in `plugin_state.json`. A plugin that
only that file still named (not installed, not configured) is no longer
listed. Restores are unchanged.
### Fixes