Skip to content

PLC9: close Plugin management, isolation, package security, and cleanup #509

Description

@zhnt

Objective

After PLC8 is complete and its three-view review findings are fixed, close Plugin management projections, package supply-chain security, isolated Worker execution, retained-version GC, repair, and destructive-data lifecycle.

Hard prerequisite

Ordered scope

  1. Unify CLI/RPC/UI/SDK projections over the durable Plugin management service and repair workflow.
  2. Make Package lifecycle the sole bounded acquisition/quarantine/extraction/dependency-verification/publication owner; allow verified wheels only unless a separately contained build service is accepted.
  3. Add versioned local_worker declarations and a supervised, required-containment Worker envelope over authorized Process Host.
  4. Remove peer manifest.enabled/source.enabled runtime-selection vetoes after migration.
  5. Implement retained-version and orphaned-generation GC, separately confirmed private-data deletion, backup retention, and partial-retirement repair.
  6. Remove superseded compatibility adapters. Evaluate remote_service only as a later separately accepted topology.

Exit gate

  • every management surface calls one service;
  • install/inspect/validate/activate cannot execute untrusted source builds or escape quarantine;
  • containment is non-downgradable and same-user child process is never called a Sandbox;
  • remove, retirement, GC, and data deletion remain distinct and diagnosable;
  • incomplete termination is never reported as disabled or removed;
  • three independent review views pass and every blocking finding is fixed/re-reviewed;
  • full cross-platform, non-live, architecture, Ruff, and mypy gates pass.

Canonical plan: docs/internals/architecture/harness/plugin/plugin-lifecycle-coding-pluginization-plan.md.

This issue is Product/Harness work only. It does not authorize MCP expansion, marketplace work, remote-service shortcuts, or a second Plugin/Graph/Resource authority.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions