Skip to content

fix(plugin): resolve local package manifest entrypoints - #53796

Draft
caniko wants to merge 1 commit into
anomalyco:v2from
caniko:plugin-manifest-v2
Draft

caniko wants to merge 1 commit into
anomalyco:v2from
caniko:plugin-manifest-v2

Conversation

@caniko

@caniko caniko commented Oct 7, 2026 •

Copy link
Copy Markdown

Issue for this PR

Addresses #52300 (local package-directory manifest entrypoint discovery). Direct file-path configuration is unchanged; that separate part of the issue is not claimed fixed.

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

Resolve local plugin directories through their package manifest before asking the runtime to resolve the resulting entrypoint. Packages using main: dist/index.js or conditional exports then load when configured by their directory.

Use [email protected] for conditional maps. Respect deliberately unexported server/TUI/RPC files, reread manifests during reload, and retain the configuration layer's real-path containment checks. No API contract changes or generated client edits.

How did you verify your code works?

Prior verification for candidate 5e7a5194045ed39589779bd8a7160dadb18cb071, baseline 5183ea45c39aaabf14236d0ce8ae0b086d9c31e8:

  • bun run check: all 36 tasks passed in a bounded 10 GiB scope.
  • Plugin package tests: 14 passed.
  • Focused core supervisor reload/containment tests passed through the package's isolated test runner.
  • Built the single-platform CLI with --skip-install --skip-web-ui. Independently packed/installed Claude and Jev plugins loaded directly from their package directories and passed direct/routed shared-backend streaming, concurrent-project reload and real read-tool continuation fixtures.

These are the original candidate's offline receipts, not current-live-target hosted acceptance. Current full-candidate Codex review and required application CI remain outstanding. Actual subscription inference is outside the offline tests. No local tests or builds were run during this maintenance pass.

Screenshots / recordings

Not applicable: package loading change with no UI changes.

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Thanks for your contribution!

This PR doesn't have a linked issue. All PRs must reference an existing issue.

Please:

  1. Open an issue describing the bug/feature (if one doesn't exist)
  2. Add Fixes #<number> or Closes #<number> to this PR description

See CONTRIBUTING.md for details.

@github-actions github-actions Bot added the needs:compliance This means the issue will auto-close after 2 hours. label Oct 7, 2026
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

The following comment was made by an LLM, it may be inaccurate:

@caniko

caniko commented Oct 8, 2026

Copy link
Copy Markdown
Author

@codex review

Please review the complete PR candidate at head 5e7a5194045ed39589779bd8a7160dadb18cb071 against current v2 93afa91904022f3f6849ada78918407fe90e795d, including all still-actionable historical findings. This is a full-candidate code review request, not a security-only review.

@github-actions github-actions Bot removed the needs:compliance This means the issue will auto-close after 2 hours. label Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Thanks for updating your PR! It now meets our contributing guidelines. 👍

@caniko

caniko commented Oct 8, 2026

Copy link
Copy Markdown
Author

@codex review

Please review the complete candidate 5e7a5194045ed39589779bd8a7160dadb18cb071 against current v2 434f7b2a3670dd932794688bee5e34029e546630, including historical findings. This is full-candidate code review, not security-only. Both candidates apply without conflicts to this live target; required application CI and maintainer approval remain separate gates.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant