Skip to content

Add plugin lock-file upgrade - #6317

Merged
samuv merged 6 commits into
mainfrom
plugins-lock/05-upgrade
Aug 20, 2026
Merged

Add plugin lock-file upgrade#6317
samuv merged 6 commits into
mainfrom
plugins-lock/05-upgrade

Conversation

@samuv

@samuv samuv commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Why: Sync restores a pin; teams also need a reviewed path to advance that pin when a mutable source has newer content.
  • What:
    • thv ai-plugin upgrade and POST /plugins/upgrade re-resolve each plugins: lock entry's source and install newer content when the digest moved (--preview / --allow-ref-change / --fail-on-changes).
    • Immutable sources (OCI digest or full git commit hash) are reported not-upgradable. Source is never rewritten.
    • A repository move is blocked unless --allow-ref-change is passed. Signer-change guarding is Stack 2 / PR9 — --allow-signer-change is not exposed yet.
    • Preview and --fail-on-changes still fetch OCI artifacts to compare digests (RFC: preview is not side-effect-free) but do not write the lock or install.
    • Gated by TOOLHIVE_PLUGINS_LOCK_ENABLED (403 when off).

Part of #6300. Stack 5/5 — schema → lock-service → install-hooks → sync → upgrade.

Type of change

  • New feature

Test plan

  • Unit tests (./pkg/plugins/pluginsvc upgrade tests and ./pkg/api/v1 upgrade endpoint tests, with the Taskfile race/ldflags flags)
  • Linting (task lint-fix)

Does this introduce a user-facing change?

No by default — the feature is inert unless TOOLHIVE_PLUGINS_LOCK_ENABLED=true. With the gate on, thv ai-plugin upgrade re-resolves plugins: lock entries.

Special notes for reviewers

  • No signer-change guard in this PR (PR9). The options type already aliases AllowSignerChange from skills; this PR does not enforce it and does not add the CLI flag.
  • resolveLatestState mirrors Install's dispatch (git → OCI → registry name) but stops short of extraction / DB / lock writes.
  • Git resolve clones to read HEAD; there is no lighter digest-only primitive, matching skills' "preview is not side-effect-free" note for OCI.

@github-actions github-actions Bot added the size/XL Extra large PR: 1000+ lines changed label Aug 13, 2026
@samuv samuv self-assigned this Aug 13, 2026
@github-actions github-actions Bot added size/XL Extra large PR: 1000+ lines changed and removed size/XL Extra large PR: 1000+ lines changed labels Aug 13, 2026
@codecov

codecov Bot commented Aug 13, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 66.66667% with 101 lines in your changes missing coverage. Please review.
✅ Project coverage is 77.68%. Comparing base (39a85c8) to head (00551eb).

Files with missing lines Patch % Lines
pkg/plugins/pluginsvc/upgrade.go 68.59% 65 Missing ⚠️
pkg/plugins/pluginsvc/sync.go 55.76% 23 Missing ⚠️
pkg/plugins/client/client.go 0.00% 11 Missing ⚠️
pkg/api/v1/plugins.go 95.23% 1 Missing ⚠️
pkg/plugins/pluginsvc/install.go 66.66% 1 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main    #6317      +/-   ##
==========================================
- Coverage   77.72%   77.68%   -0.05%     
==========================================
  Files         748      749       +1     
  Lines       71826    72126     +300     
==========================================
+ Hits        55827    56029     +202     
- Misses      15994    16092      +98     
  Partials        5        5              

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@JAORMX JAORMX left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Panel review found inconsistent plain-name resolution, ambiguous preview API status, and missing required CLI coverage/completion. Please address the inline findings before merge. The transaction fixes requested on the earlier stack PRs also apply to this upgrade path.

Comment thread pkg/plugins/pluginsvc/upgrade.go Outdated
Comment thread pkg/plugins/pluginsvc/upgrade.go
Comment thread cmd/thv/app/ai_plugin_upgrade.go
Comment thread cmd/thv/app/ai_plugin_upgrade.go
@samuv
samuv force-pushed the plugins-lock/05-upgrade branch from 9459007 to eb5e5b4 Compare August 14, 2026 08:16
@github-actions github-actions Bot added size/XL Extra large PR: 1000+ lines changed and removed size/XL Extra large PR: 1000+ lines changed labels Aug 14, 2026
@samuv
samuv force-pushed the plugins-lock/05-upgrade branch from eb5e5b4 to d071d5a Compare August 14, 2026 08:46
@github-actions github-actions Bot added size/XL Extra large PR: 1000+ lines changed and removed size/XL Extra large PR: 1000+ lines changed labels Aug 14, 2026
@samuv
samuv force-pushed the plugins-lock/05-upgrade branch from d071d5a to f51bf78 Compare August 14, 2026 08:57
@github-actions github-actions Bot added size/XL Extra large PR: 1000+ lines changed and removed size/XL Extra large PR: 1000+ lines changed labels Aug 14, 2026

@JAORMX JAORMX left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Local-store resolution, E2E coverage, and completion were addressed. The local apply path still drops the artifact/reference needed by persisted state and later sync.

Comment thread pkg/plugins/pluginsvc/upgrade.go
@samuv
samuv force-pushed the plugins-lock/05-upgrade branch from f51bf78 to f5b5f83 Compare August 14, 2026 12:52
@github-actions github-actions Bot removed the size/XL Extra large PR: 1000+ lines changed label Aug 14, 2026
@github-actions github-actions Bot added size/XL Extra large PR: 1000+ lines changed and removed size/XL Extra large PR: 1000+ lines changed labels Aug 19, 2026
@samuv
samuv force-pushed the plugins-lock/05-upgrade branch from 796523b to 4868efd Compare August 19, 2026 15:20
JAORMX
JAORMX previously approved these changes Aug 19, 2026
@github-actions github-actions Bot added size/XL Extra large PR: 1000+ lines changed and removed size/XL Extra large PR: 1000+ lines changed labels Aug 19, 2026
@samuv
samuv force-pushed the plugins-lock/05-upgrade branch from 4868efd to a18127f Compare August 19, 2026 15:46
@github-actions github-actions Bot added size/XL Extra large PR: 1000+ lines changed and removed size/XL Extra large PR: 1000+ lines changed labels Aug 19, 2026
Base automatically changed from plugins-lock/04-sync to main August 19, 2026 17:40
@samuv
samuv force-pushed the plugins-lock/05-upgrade branch from a18127f to e46c13e Compare August 19, 2026 17:40
@github-actions github-actions Bot added size/XL Extra large PR: 1000+ lines changed and removed size/XL Extra large PR: 1000+ lines changed labels Aug 19, 2026
@samuv
samuv force-pushed the plugins-lock/05-upgrade branch from e46c13e to e3dd9ba Compare August 20, 2026 08:09
samuv added 6 commits August 20, 2026 10:51
Re-resolve plugins: lock entries and install newer content via
thv ai-plugin upgrade and POST /plugins/upgrade.

Signed-off-by: Samuele Verzi <samu@stacklok.com>
Plain-name lock entries now resolve the same way Install does, so a
local rebuild is visible to upgrade. Also complete upgrade args from
lock entries and cover fail-on-changes in the plugin CLI e2e.

Signed-off-by: Samuele Verzi <samu@stacklok.com>
A bare local-store tag must not be rewritten as a Docker Hub
digest reference; apply the resolved layer bytes instead.

Signed-off-by: Samuele Verzi <samu@stacklok.com>
The DB should keep the local tag while the lock file keeps
the previous restorable pin instead of a Docker Hub rewrite.

Signed-off-by: Samuele Verzi <samu@stacklok.com>
A stale plan must not resurrect an uninstall or overwrite a
newer install of the same plugin.

Signed-off-by: Samuele Verzi <samu@stacklok.com>
Sync loads plain-source empty-reference pins by digest, and local
upgrades no longer keep a stale remote resolved reference.

Signed-off-by: Samuele Verzi <samu@stacklok.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size/XL Extra large PR: 1000+ lines changed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants