fix(plugin-system): unload/update race, failed-load cleanup, limits validation, schema lookup, install rollback (#653)

* fix(plugin-system): unload/update race, failed-load module cleanup, limits validation, schema lookup, install rollback, op-queue dedupe

- unload_plugin takes the per-plugin lock (5s bounded) before cleanup(),
  and an update() that finishes after its plugin was unloaded no longer
  sets the state back to ENABLED.
- A load that fails after import drops plugin_<id> and its submodules
  and forgets its manager fonts, so a fixed plugin reloads new code.
- Resource limits are validated as non-negative numbers: 400 at
  POST /plugins/limits, bad cached records ignored with one warning.
  Route docstrings note health/metrics reset and limits only change the
  web process's view.
- SchemaManager.get_schema_path resolves each search dir via
  resolve_plugin_dir (manifest id, ledmatrix-<id>) before the literal
  paths; plugins/ still before plugin-repos/. Misses cached 30s and
  logged once at DEBUG.
- install_from_url sets an existing copy aside and restores it if the
  move fails, under the per-plugin reinstall lock.
- Operation queue refuses a second pending op for a plugin and trims
  _operations with history.
- get_vegas_render_width reads display_manager.width first.
- get_logger in store/schema/health/resource/saved_repositories;
  UTF-8 reads in store_manager and state_manager.
- Docs: update_interval precedence (manifest over config) stated where
  users are told to set it in config.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* fix(web): build the limits 400 message from the field name, not an exception

CodeQL flagged str(e) flowing into the response. invalid_limit_field()
returns the offending field without raising, and limits_from_dict uses it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Chuck
2026-09-28 10:41:40 -04:00
committed by GitHub
co-authored by Claude Opus 5.5
parent 0e9e2cabba
commit c00bf5e8e6
24 changed files with 869 additions and 49 deletions
@@ -0,0 +1,75 @@
"""A load that fails after the plugin module was imported must not leave
that module behind.
PluginLoader.load_module() reuses ``plugin_<id>`` from sys.modules. When
instantiation or validate_config() failed, the half-loaded module stayed
there (and in the loader's ``_loaded_modules``), so after the user fixed the
plugin, the next load kept running the old, broken code until a restart.
Font registrations the failed instance made stayed listed too.
"""
import json
import sys
from unittest.mock import MagicMock
import pytest
from src.plugin_system.plugin_manager import PluginManager
from src.plugin_system.plugin_state import PluginState
PLUGIN_ID = "failed-load-demo"
MODULE_NAME = "plugin_failed_load_demo"
_BROKEN_INIT = '''
class Demo:
def __init__(self, plugin_id, config, display_manager, cache_manager, plugin_manager):
raise RuntimeError("broken constructor")
'''
_BAD_CONFIG = '''
class Demo:
VERSION = "bad-config"
def __init__(self, plugin_id, config, display_manager, cache_manager, plugin_manager):
pass
def validate_config(self):
return False
'''
_FIXED = '''
class Demo:
VERSION = "fixed"
def __init__(self, plugin_id, config, display_manager, cache_manager, plugin_manager):
self.enabled = True
'''
@pytest.fixture
def plugin_env(tmp_path):
plugins_dir = tmp_path / "plugins"
plugin_dir = plugins_dir / PLUGIN_ID
plugin_dir.mkdir(parents=True)
manifest = {"id": PLUGIN_ID, "name": "Demo", "class_name": "Demo",
"entry_point": "manager.py"}
(plugin_dir / "manifest.json").write_text(json.dumps(manifest), encoding="utf-8")
manager = PluginManager(plugins_dir=str(plugins_dir))
manager.font_manager = MagicMock()
manager.plugin_manifests[PLUGIN_ID] = manifest
yield manager, plugin_dir
sys.modules.pop(MODULE_NAME, None)
@pytest.mark.parametrize("first_source", [_BROKEN_INIT, _BAD_CONFIG],
ids=["instantiate-fails", "validate-config-fails"])
def test_fixed_plugin_loads_new_code_after_failed_load(plugin_env, first_source):
pm, plugin_dir = plugin_env
(plugin_dir / "manager.py").write_text(first_source, encoding="utf-8")
assert pm.load_plugin(PLUGIN_ID) is False
assert pm.state_manager.get_state(PLUGIN_ID) == PluginState.ERROR
assert MODULE_NAME not in sys.modules
assert PLUGIN_ID not in pm.plugin_loader._loaded_modules
pm.font_manager.forget_manager_fonts.assert_called_with(PLUGIN_ID)
(plugin_dir / "manager.py").write_text(_FIXED, encoding="utf-8")
assert pm.load_plugin(PLUGIN_ID) is True
assert pm.plugins[PLUGIN_ID].VERSION == "fixed"