Implements the compile-in plugin system designed in spec 019:
- internal/plugin/ (~1,300 LOC):
* Tiny Plugin interface + 10 optional HasX capability sub-interfaces
* Host struct with Logger / DB / Messenger / Channels / Attachments /
Search / Secrets / Events / Config / DataDir / Tracer / Metrics /
DefaultOwner / BaseURL
* Registry with panic-on-duplicate, stability-level tracking, capability
indexing (MCP tools, actions, panels, channel types, routes, event
subscribers, CLI commands)
* Migrator: per-plugin SHA-256-checksum'd migration chain, namespaced
plugin_<name>_* table enforcement, idempotent re-apply
* Three-phase lifecycle (Migrate → Init → Start) with panic-safe
wrappers around every plugin call; failure per plugin isolated,
core continues
* YAML config loader that preserves unknown top-level keys on round-trip
* Status store exposing /api/plugins/status JSON
* Restart helpers (Noop + SignalRestarter); graceful reload is
in-process for the demo
- internal/plugin/plugintest/ (~345 LOC):
* NopHost(t) with in-memory modernc.org/sqlite
* Run(t, plugin) full-lifecycle smoke helper
* Assertions: HasTool, HasAction, HasPanel, HasChannelType,
HasMigration, PluginStarted, PluginFailed
* ScopedSecrets that returns ErrSecretNotFound for cross-plugin
reads (satisfies SC-006)
- internal/plugins/demo/ (canonical showcase):
* Plugin that exercises every HasX capability (migrations, actions,
HTTP routes, web panel, lifecycle, config schema, stability)
* Own SQL migration creating plugin_demo_notes
* Embedded HTML panel that fetches notes via JS
* 4 unit tests covering smoke, full capability registration, action
handlers, and config-driven max_notes limit
- cmd/plugindemo/ (~290 LOC):
* Demo HTTP server wiring registry to chi
* Mounts /api/plugins/status, /api/admin/plugins/{name}/{enable,disable},
/api/actions/{name}, /api/plugins/<name>/* (per-plugin REST),
/ui/plugins/<name>/ (per-plugin UI)
* SIGHUP-triggered config reload + registry rebuild + mux swap
* SIGTERM/SIGINT graceful shutdown
- test/integration/ (~357 LOC, build-tag "integration"):
* 6 end-to-end tests against a spawned plugindemo binary
* Enable/disable round-trip with data preservation
* SIGHUP reload timing (measured 41 ms — SC-008 target is 2 s)
* Action-404 on disabled plugin, panel-404 on disabled plugin
* REST endpoints + UI panel reachable
Contract deviation: admin toggle endpoints moved from
/api/plugins/{name}/{enable,disable} to /api/admin/plugins/{name}/{...}
to avoid URL collision with chi per-plugin route mounts. rest.md updated.
Scope deferred to next session (mechanical follow-ups):
- Port internal/wiki/ to internal/plugins/wiki/
- Squash 26 migrations to schema/000_initial.sql
- Backup scripts for live kubic instance
- Remaining 9 plugin extractions
- Boundary-lint static analyzer
- Wire into cmd/synapbus/main.go
All unit + integration tests green. Chrome UI smoke test passes.
autonomous_summary.md carries the full verification record.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
69 lines
1.9 KiB
Go
69 lines
1.9 KiB
Go
package plugintest
|
|
|
|
import (
|
|
"context"
|
|
"sync"
|
|
|
|
"github.com/synapbus/synapbus/internal/plugin"
|
|
)
|
|
|
|
// sharedStore is a process-wide map of (plugin, name) → value. Multiple
|
|
// ScopedSecrets instances created with different plugin names share this
|
|
// store, so a test that wants to verify cross-plugin isolation can do so
|
|
// by instantiating two ScopedSecrets from the same process.
|
|
var (
|
|
sharedStoreMu sync.Mutex
|
|
sharedStore = map[string]map[string][]byte{}
|
|
)
|
|
|
|
// ScopedSecrets is a plugin-scoped secret store backed by an in-memory map
|
|
// keyed by (plugin, name). Accessing a secret with a different plugin name
|
|
// returns plugin.ErrSecretNotFound — exactly like a missing secret. This
|
|
// lets tests verify the isolation guarantee from FR-007 / SC-006.
|
|
type ScopedSecrets struct {
|
|
pluginName string
|
|
}
|
|
|
|
func NewScopedSecrets(pluginName string) *ScopedSecrets {
|
|
return &ScopedSecrets{pluginName: pluginName}
|
|
}
|
|
|
|
func (s *ScopedSecrets) Get(ctx context.Context, name string) ([]byte, error) {
|
|
sharedStoreMu.Lock()
|
|
defer sharedStoreMu.Unlock()
|
|
ps, ok := sharedStore[s.pluginName]
|
|
if !ok {
|
|
return nil, plugin.ErrSecretNotFound
|
|
}
|
|
v, ok := ps[name]
|
|
if !ok {
|
|
return nil, plugin.ErrSecretNotFound
|
|
}
|
|
// Copy to avoid aliasing.
|
|
out := make([]byte, len(v))
|
|
copy(out, v)
|
|
return out, nil
|
|
}
|
|
|
|
func (s *ScopedSecrets) Set(ctx context.Context, name string, value []byte) error {
|
|
sharedStoreMu.Lock()
|
|
defer sharedStoreMu.Unlock()
|
|
ps, ok := sharedStore[s.pluginName]
|
|
if !ok {
|
|
ps = map[string][]byte{}
|
|
sharedStore[s.pluginName] = ps
|
|
}
|
|
cp := make([]byte, len(value))
|
|
copy(cp, value)
|
|
ps[name] = cp
|
|
return nil
|
|
}
|
|
|
|
// ResetScopedSecrets wipes the shared store. Call t.Cleanup(ResetScopedSecrets)
|
|
// if your test sets secrets and doesn't want them to leak across runs.
|
|
func ResetScopedSecrets() {
|
|
sharedStoreMu.Lock()
|
|
defer sharedStoreMu.Unlock()
|
|
sharedStore = map[string]map[string][]byte{}
|
|
}
|