Skip to content

Audit host contracts and bound peer frames by bytes - #892

Merged
nedtwigg merged 13 commits into
spec-cleanup-terminal-activityfrom
spec-cleanup-host-contracts
Oct 2, 2026
Merged

nedtwigg merged 13 commits into
spec-cleanup-terminal-activityfrom
spec-cleanup-host-contracts

Conversation

@nedtwigg

@nedtwigg nedtwigg commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Audit the transport and VS Code specs against the adapters, persistence, and peer-routing code. Replace duplicated capability and snapshot inventories with their canonical types, retain cross-boundary invariants, and shorten the compatible-agent contributor instructions.

Peer framing enforces its cap on UTF-8 bytes before parsing, with incremental accounting for buffered fragments. Disposed or replaced webviews reject pending recovery replies; native-shell discovery stays scoped to its platform.

Validation: current platform CI and bot reviews pass. The generated public-guide assertion is updated for both withheld contributor links. Stacked on #891.

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Deploying mouseterm with  Cloudflare Pages  Cloudflare Pages

Latest commit: f231bb0
Status: ✅  Deploy successful!
Preview URL: https://cdfdf54e.mouseterm.pages.dev
Branch Preview URL: https://spec-cleanup-host-contracts.mouseterm.pages.dev

View logs

@dormouse-bot dormouse-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Three concerns on the recovery-privacy path, inline below.

Comment thread lib/src/host/recovery-store.ts Outdated
Comment thread lib/src/host/private-path.ts Outdated
Comment thread vscode-ext/src/extension.ts Outdated

@dormouse-bot dormouse-bot left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The earlier three threads are addressed. One new point, inline below.

Comment thread lib/src/host/private-path.ts Outdated
nedtwigg and others added 4 commits October 1, 2026 22:42
# Conflicts:
#	scripts/spec-word-budgets.json
Standalone already locks its recovery directory in Rust before the
sidecar starts, and the VS Code record lives under extension storage that
inherits a user-only profile ACL. The PowerShell-backed private-path
helper cost ~300 ms at every Windows start, silently disabled recovery on
failure, and ran in no CI job. Restore the synchronous recovery store, its
synchronous take, and the original specs, audit prompt, and known-gap row.

Keep the pre-existing race fix in DormouseViewProvider: dispose is
registered before the shell-discovery await, so a view disposed or
replaced while it is pending is never served and cannot release its
successor's router; its tests now drive the delay through shell discovery.

Also restore the reconnection steps' message names (`dormouse:init`,
`pty:list`, `pty:replay`, `alert:state`) in transport.md, and move the
dual-runtime tsconfig paragraph into vscode.rationale.md.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
FrameDecoder re-measured the whole pending buffer with Buffer.byteLength
on every push, quadratic in a frame that arrives in many chunks. Measure
each newline-delimited piece once as it arrives and carry the pending
frame's byte count, keeping the cap on complete frames and partial tails
and preserving adjacent valid frames.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The original PR bundled unrelated test-portability work into a host
security change: path.win32 fixtures for enroll-offer, pty-core, and
mirrored-constants, the named-pipe peer-link tests, and the Unix peer
socket parent setup. None of it changes shipped behaviour, and none of
the Windows-only cases run in CI, so it obscured the reviewable part of
the diff. It now lives on its own PR (#899, based on main), leaving this
PR as the spec cleanup plus the peer-frame byte cap.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@nedtwigg nedtwigg changed the title Audit host contracts and enforce recovery privacy and peer byte bounds Audit host contracts and bound peer frames by bytes Oct 2, 2026
…contracts

# Conflicts:
#	scripts/spec-word-budgets.json
@nedtwigg
nedtwigg merged commit 5ce9132 into main Oct 2, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants