Audit host contracts and bound peer frames by bytes - #892
Merged
nedtwigg merged 13 commits intoOct 2, 2026
Merged
Conversation
Deploying mouseterm with
|
| Latest commit: |
f231bb0
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://cdfdf54e.mouseterm.pages.dev |
| Branch Preview URL: | https://spec-cleanup-host-contracts.mouseterm.pages.dev |
nedtwigg
requested a deployment
to
hosted-preview
October 2, 2026 02:44 — with
GitHub Actions
Waiting
dormouse-bot
reviewed
Oct 2, 2026
dormouse-bot
left a comment
Collaborator
There was a problem hiding this comment.
Three concerns on the recovery-privacy path, inline below.
dormouse-bot
reviewed
Oct 2, 2026
dormouse-bot
left a comment
Collaborator
There was a problem hiding this comment.
The earlier three threads are addressed. One new point, inline below.
dormouse-bot
approved these changes
Oct 2, 2026
dormouse-bot
approved these changes
Oct 2, 2026
nedtwigg
added this pull request to stack #896
October 2, 2026 05:05
# Conflicts: # scripts/spec-word-budgets.json
Standalone already locks its recovery directory in Rust before the sidecar starts, and the VS Code record lives under extension storage that inherits a user-only profile ACL. The PowerShell-backed private-path helper cost ~300 ms at every Windows start, silently disabled recovery on failure, and ran in no CI job. Restore the synchronous recovery store, its synchronous take, and the original specs, audit prompt, and known-gap row. Keep the pre-existing race fix in DormouseViewProvider: dispose is registered before the shell-discovery await, so a view disposed or replaced while it is pending is never served and cannot release its successor's router; its tests now drive the delay through shell discovery. Also restore the reconnection steps' message names (`dormouse:init`, `pty:list`, `pty:replay`, `alert:state`) in transport.md, and move the dual-runtime tsconfig paragraph into vscode.rationale.md. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
FrameDecoder re-measured the whole pending buffer with Buffer.byteLength on every push, quadratic in a frame that arrives in many chunks. Measure each newline-delimited piece once as it arrives and carry the pending frame's byte count, keeping the cap on complete frames and partial tails and preserving adjacent valid frames. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The original PR bundled unrelated test-portability work into a host security change: path.win32 fixtures for enroll-offer, pty-core, and mirrored-constants, the named-pipe peer-link tests, and the Unix peer socket parent setup. None of it changes shipped behaviour, and none of the Windows-only cases run in CI, so it obscured the reviewable part of the diff. It now lives on its own PR (#899, based on main), leaving this PR as the spec cleanup plus the peer-frame byte cap. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…contracts # Conflicts: # scripts/spec-word-budgets.json
dormouse-bot
approved these changes
Oct 2, 2026
…o spec-cleanup-host-contracts # Conflicts: # scripts/spec-word-budgets.json
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Audit the transport and VS Code specs against the adapters, persistence, and peer-routing code. Replace duplicated capability and snapshot inventories with their canonical types, retain cross-boundary invariants, and shorten the compatible-agent contributor instructions.
Peer framing enforces its cap on UTF-8 bytes before parsing, with incremental accounting for buffered fragments. Disposed or replaced webviews reject pending recovery replies; native-shell discovery stays scoped to its platform.
Validation: current platform CI and bot reviews pass. The generated public-guide assertion is updated for both withheld contributor links. Stacked on #891.