Stage 2 of the web plugin catalog, after #688.
- The display publishes a plugin runtime snapshot (plugin_runtime.py) to
the shared cache: per plugin loaded, lifecycle state, a short redacted
error summary, the version it loaded and when, plus published_at /
stale_after / running. Written on change (throttled to 10 s; the
RUNNING/ENABLED flip of an ordinary update is not a change) and once a
minute otherwise; cleanup() publishes running: false.
- The web reads it back and restores loaded / state / error_info in
/api/v3/plugins/installed (plus loaded_version, loaded_at and
data.runtime). Only a live snapshot counts; stale, stopped or missing
answers null and says which.
- data/plugin_state.json is retired: every reader and writer moved to
config + disk (desired) or the snapshot (observed). Nothing in it was
non-derivable, so nothing is migrated and an existing file is left
unread. The web-side PluginStateManager (state_manager.py) is removed;
the display's plugin_state.PluginStateManager is the only state machine.
- StateReconciliation compares config + disk with the snapshot, reporting
enabled-but-not-loaded and older-version-loaded as no_action findings.
- Backups list installed manifests with enabled from config.json.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(plugin-system): unload/update race, failed-load module cleanup, limits validation, schema lookup, install rollback, op-queue dedupe
- unload_plugin takes the per-plugin lock (5s bounded) before cleanup(),
and an update() that finishes after its plugin was unloaded no longer
sets the state back to ENABLED.
- A load that fails after import drops plugin_<id> and its submodules
and forgets its manager fonts, so a fixed plugin reloads new code.
- Resource limits are validated as non-negative numbers: 400 at
POST /plugins/limits, bad cached records ignored with one warning.
Route docstrings note health/metrics reset and limits only change the
web process's view.
- SchemaManager.get_schema_path resolves each search dir via
resolve_plugin_dir (manifest id, ledmatrix-<id>) before the literal
paths; plugins/ still before plugin-repos/. Misses cached 30s and
logged once at DEBUG.
- install_from_url sets an existing copy aside and restores it if the
move fails, under the per-plugin reinstall lock.
- Operation queue refuses a second pending op for a plugin and trims
_operations with history.
- get_vegas_render_width reads display_manager.width first.
- get_logger in store/schema/health/resource/saved_repositories;
UTF-8 reads in store_manager and state_manager.
- Docs: update_interval precedence (manifest over config) stated where
users are told to set it in config.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(web): build the limits 400 message from the field name, not an exception
CodeQL flagged str(e) flowing into the response. invalid_limit_field()
returns the offending field without raising, and limits_from_dict uses it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>