Skip to content

feat(extensions): complete MCP, Plugin and LSP onboarding - #284

Merged
Qiyuanqiii merged 5 commits into
mainfrom
codex/issue-276-extension-onboarding
Oct 7, 2026
Merged

Qiyuanqiii merged 5 commits into
mainfrom
codex/issue-276-extension-onboarding

Conversation

@Qiyuanqiii

@Qiyuanqiii Qiyuanqiii commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Summary

Settings can now complete first-time MCP, Plugin and LSP setup through the shared Go control plane. Users can select a Workspace before a Run exists, register a manual MCP descriptor, upload a pinned Plugin ZIP, or stage an installed language server. Forms retain input after failure, show source/scope/review metadata and provide the next available action. Web/Desktop use the same backend-advertised onboarding capabilities and generated API contract.

Registration stays inert. MCP retains separate discovery and capability reviews; actual calls use the ordinary task/Approval/Gateway path and settings reads their durable audit result. Plugin import retains the existing 4 MiB plugin.v1 validator and explicit package/capability reviews. LSP review persists the existing operator configuration format; a separate bounded symbol-query test returns real server/query/document provenance. A stable manager connects new configurations to model tools, rejects stale queries and owns process cleanup. OS advisory locking and digest checks prevent concurrent configuration overwrites. Explicit CLI/environment LSP files remain authoritative and read-only in settings.

Plugin upload preflight uses bounded decoding and canonical re-encoding so supported 3.5–4 MiB payloads do not overflow the browser regex stack. Both encoded-length and decoded-byte limits remain enforced, and malformed or noncanonical input is rejected before the request.

The application preview copy now describes the available service/log view separately from browser availability.

The existing real Edge CI job uses lowercase nul for its empty Git configuration, accommodating the Git for Windows 2.56/UCRT regression (upstream #6449). Source-binding failures now retain Git stderr without mixing it into the source metadata.

Closes #276.

Validation

  • Full CI run 37566854056 is running on merge commit 0955d7fc0aab7539cdb0fbb0b8930582ae9c7c92, synchronized with main 7aac2773451daff1e372647a5733c937c00d2cc7. GitHub reports the PR as mergeable.
  • Complete frontend suite: 174 files / 1,639 tests pass, including task search, execution labels, onboarding and all 14 Plugin Base64 boundary regressions. Production build and npm run check:api pass.
  • Complete HTTP package (197.68s) and domain package (0.16s) pass. Existing Store title-search and execution-fact regressions pass (2.76s).
  • HTTP coverage includes inert MCP registration and separate review, normal task/approval/Gateway invocation and replay, Plugin import/review/Hook receipts, real LSP setup/query/restart, concurrent configuration owners and rejected scope/hash/authentication changes. The shared MCP product test also passes with task-list approval and cancellation projections.
  • Go OpenAPI and TypeScript snapshots were regenerated and exactly match the merged contracts. Protocol and Surface registry checks pass against main 7aac2773451daff1e372647a5733c937c00d2cc7.
  • go vet for HTTP, application and Store packages, and git diff --check, pass.
  • Earlier browser evidence for the unchanged Base64 helper: Chromium 154.0.8037.98 reproduced the grouped-regex stack overflow and passed all 14 cases after the fix on 395d7bfc. This is a browser-side preflight probe, not a complete import/install test of a large ZIP. The supported 3.5 MiB, 4 MiB minus one byte and exactly 4 MiB client requests are covered again by the current full frontend suite.
  • This change uses the existing applicable CI and introduces no new workflow or duplicate full-suite gate.

Surface governance

  • No Surface is added, promoted, downgraded, deprecated, or removed.
  • Registry declarations: N/A — no Surface change. Existing optional extension integrations remain behind Go-owned control authentication, review, policy and scope. Existing CLI flows remain available.

Audit

  • No credentials or local runtime data are included.
  • Policy, workspace, process ownership and persistence boundaries were reviewed. Public inventories exclude LSP launch arguments, executable paths, private roots and raw output. The explicit operator LSP probe starts only a reviewed selected server; it does not widen model authority or bypass the ordinary MCP call path.
  • Usage, code-intelligence documentation, architecture and project memory are updated; ADR 0168 records lifecycle, review, compatibility and rollback behavior. No SQLite migration is added.

@Qiyuanqiii
Qiyuanqiii merged commit 6509627 into main Oct 7, 2026
22 checks passed
@Qiyuanqiii
Qiyuanqiii deleted the codex/issue-276-extension-onboarding branch October 7, 2026 08:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[P3] feat(extensions): 完成 MCP、插件与 LSP 首次接入

1 participant