The web process built its own PluginManager and loaded plugins into itself:
store installs and updates loaded or reloaded a web-side copy, and config
saves and enable/disable called on_config_change, on_enable and on_disable
on it. None of that reached the panel, and /plugins/installed reported
runtime state from those copies.
- Add PluginCatalog (src/plugin_system/plugin_catalog.py): manifests,
directories, display modes, installed version, schema and config reads,
with no way to run a plugin. app.py and both blueprints use it; the
plugin_manager blueprint attribute is gone.
- Remove every lifecycle call from the web routes. Config changes already
reach the display through ConfigService (on_config_change) and the
enabled-set reconcile.
- Health and metrics readers move to api_v3.health_tracker /
resource_monitor. /plugins/installed reports loaded/state/error_info as
null (the display does not publish them) and enabled by the display's
rule.
- Store install, update and uninstall answer restart_required when the
running display will not pick the change up by itself
(display_restart_required). The restart banner follows the flag via
window.noteRestartRequired instead of the /config/main URL heuristic;
/config/main now sends restart_required: true.
- The one remaining in-process import of plugin code (Starlark helper
modules, oauth_flow action scripts) goes through
_import_plugin_code_in_web_process() until a web-entry contract.
- /plugins/installed reports vegas_participation (from #682) from the
user's setting or the manifest, with vegas_participation_source; when
only the plugin's code decides it, null with source 'runtime', since the
web process no longer has plugin instances to ask.
- Check & Update All keeps its restart flags when the final list refresh
fails, and asks for a restart when an enabled plugin's first request got
no answer and the re-sent one found it up to date.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(plugin-system): unload/update race, failed-load module cleanup, limits validation, schema lookup, install rollback, op-queue dedupe
- unload_plugin takes the per-plugin lock (5s bounded) before cleanup(),
and an update() that finishes after its plugin was unloaded no longer
sets the state back to ENABLED.
- A load that fails after import drops plugin_<id> and its submodules
and forgets its manager fonts, so a fixed plugin reloads new code.
- Resource limits are validated as non-negative numbers: 400 at
POST /plugins/limits, bad cached records ignored with one warning.
Route docstrings note health/metrics reset and limits only change the
web process's view.
- SchemaManager.get_schema_path resolves each search dir via
resolve_plugin_dir (manifest id, ledmatrix-<id>) before the literal
paths; plugins/ still before plugin-repos/. Misses cached 30s and
logged once at DEBUG.
- install_from_url sets an existing copy aside and restores it if the
move fails, under the per-plugin reinstall lock.
- Operation queue refuses a second pending op for a plugin and trims
_operations with history.
- get_vegas_render_width reads display_manager.width first.
- get_logger in store/schema/health/resource/saved_repositories;
UTF-8 reads in store_manager and state_manager.
- Docs: update_interval precedence (manifest over config) stated where
users are told to set it in config.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(web): build the limits 400 message from the field name, not an exception
CodeQL flagged str(e) flowing into the response. invalid_limit_field()
returns the offending field without raising, and limits_from_dict uses it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>