044 provider runtime completion (pre-staged workstream): capacity/operator stores, provider ops/protocol/reconciler/dispatch revalidation, exploration sandbox runtime, alembic 0014-0016, live canary evidence (browser provider 6/6 against the live stand). 050 Phases 0-2: RBAC FastMCP server with a 45-tool explicit catalog, OAuth/DCR transport guards with bounded bodies, per-call provenance (McpToolInvocationRecord), durable ActionApprovalGate + CAS decide + leased/fenced poller, authoring workspace ops, bounded-response discipline, hidden-vs-gated matrices. Parity domains (T012-T014): gated git/deploy/migration/backup/llm tools with reviewed dispatch adapters in explicit poll chains; Superset reads/writes with a dedicated plugin:superset_sql risk class (terminal PROD denial via the canonical execution-policy criterion, hardened danger-SQL guard covering INTO/CALL/SET/REFRESH/file primitives/multi-statement); baseline 037 tools over the shared REST-surface services. Evidence (T016/T023/T028): REST-vs-MCP field parity on shared 037 fixtures; vertical E2E from tools/list through registry revision activation with real scenario:EDIT RBAC; sandbox-to-revision promotion E2E with unsafe-payload and caller-digest rejection; dispatcher soak (three poll cycles, exactly-once). Orthogonal QA+security audit hardening: enforced response_limit fail-closed envelope, poisoned-exploration fail-closed (EXPLORATION_TARGET_UNRESOLVED), sha256 exploration evidence digests, actor-UUID task ownership, is_active guard on baseline consume, 038 resolver description=None selector fix. Phase 3/4 decommission: HandoffSurface behind the MCP_DECOMMISSION flag, then unconditional removal — agent/ service tree, chat components/models/ stores/types, gradio proxies (vite + nginx), agent service in run.sh, docker-compose profiles, build.sh bundles; /agent renders the handoff only. Docs: AGENTS.md/INSTALL.md two-service rewrite; 036-047 drift amendments marked done; WORKSTATE checkpoints with all evidence. Suites: backend 11199 passed / 240 skipped / 1 xpassed; frontend 3454 passed (197 files), lint 0 errors, build OK; browser E2E login+handoff 6/6 twice on the isolated compose stack (no 7860); ruff/compileall clean. Misc: gitignore hardening (tmp/, tool model cache); E2E selector repairs (nav strict-mode, invalid-credentials passthrough detail).
37 lines
2.0 KiB
Markdown
37 lines
2.0 KiB
Markdown
## @{ Doc.Adr.ADR0016 [C:1] [TYPE ADR]
|
|
# @STATUS ACCEPTED
|
|
# @BRIEF Define the implemented plugin discovery and execution boundary.
|
|
# @RELATION BINDS_TO -> [backend/src/core/plugin_loader.py]
|
|
# @RELATION BINDS_TO -> [backend/src/core/plugin_base.py]
|
|
# @RATIONALE The repository already contains first-party plugins that share the application runtime, configuration, database access patterns, and async Task Manager. The executable contract is `PluginBase`, not an unimplemented manifest or subprocess protocol.
|
|
# @REJECTED `plugin.toml` manifests and a mandatory subprocess executor — rejected as the current architecture because neither is the runtime contract implemented by the repository.
|
|
# @REJECTED Treating dynamic discovery as a sandbox — rejected because imported plugin code runs in the backend process and has the same process privileges.
|
|
|
|
## Decision
|
|
|
|
First-party plugins live in `backend/src/plugins/`. `PluginLoader` discovers Python
|
|
modules and package `__init__.py` files in that directory, imports them under the
|
|
`src.plugins` package, instantiates subclasses of `PluginBase`, and exposes their
|
|
validated `PluginConfig` metadata.
|
|
|
|
Every discoverable plugin must implement the abstract `PluginBase` contract:
|
|
|
|
- stable `id`, `name`, `description`, and `version` properties;
|
|
- `get_schema()` returning an input schema;
|
|
- asynchronous `execute(params)`;
|
|
- optional `ui_route` and a permission derived from `required_permission`.
|
|
|
|
Plugins are trusted, versioned source in this repository. They are not third-party
|
|
sandboxed extensions. A future marketplace or untrusted-plugin feature requires a
|
|
new ADR that specifies its isolation, permission, resource, and failure model.
|
|
|
|
## Consequences
|
|
|
|
- Plugin failures during discovery are logged and do not stop discovery of other
|
|
modules, but execution remains subject to normal backend failure handling.
|
|
- Plugin dependencies must be compatible with the backend runtime.
|
|
- Adding a plugin requires tests for discovery and its public execution contract;
|
|
it does not require a `plugin.toml` manifest.
|
|
|
|
## @} Doc.Adr.ADR0016
|