Skip to main content

ServerPluginInstaller

Struct ServerPluginInstaller 

Source
pub struct ServerPluginInstaller { /* private fields */ }
Expand description

AppState-backed PluginInstaller. See the module docs for the full design rationale (borrowing, path derivation, atomicity).

Implementations§

Source§

impl ServerPluginInstaller

Source

pub fn new(state: Data<AppState>) -> Self

Source

pub async fn stop_services_for_upgrade(&self, plugin_id: &str) -> Vec<String>

Same-id upgrade ordering (issue #479 “Install-flow deltas” / “Same-id upgrade ordering bug risk”): plugin_source::stage_plugin_source swaps plugin_dir’s ENTIRE contents (old bundle moved to a .backup-* dir, staged bundle renamed into place) BEFORE install() — and therefore Self::register_services — ever runs. A still-running old service process holding the old binary open during that swap is at best running stale code post-swap and at worst (Windows) blocks the rename outright. The minimal seam that fixes the ordering without restructuring stage_plugin_source/ install(): the HTTP update_plugin handler calls this BEFORE stage_plugin_source, using the URL path’s target id (known up front for an upgrade, unlike a fresh install) to look up the CURRENTLY-installed row’s registered.service_ids and stop each one. Net effect: stop (old binary) → swap (new binary) → start (new binary, via register_services inside install()), exactly the sequencing the issue calls for.

Best-effort: returns exactly the ids that were actually running and got stopped (not e.g. an already-stopped or unknown id), so a subsequently-failed upgrade can restart precisely those — see Self::restart_services_after_failed_upgrade. A plugin with no prior install (or no services) returns an empty vec and stops nothing.

Source

pub async fn restart_services_after_failed_upgrade( &self, plugin_id: &str, stopped: &[String], )

Counterpart to Self::stop_services_for_upgrade: called after a FAILED upgrade whose StagedPlugin::rollback() already restored plugin_dir to the pre-upgrade bundle’s bytes — re-reads that (now-restored) OLD plugin.json and restarts exactly the services in stopped that it still declares as enabled. Best-effort/ log-and-continue: a failure here leaves the affected service stopped (a degraded-but-safe outcome — never silently double-runs an old and a new instance) rather than panicking the request.

Trait Implementations§

Source§

impl PluginInstaller for ServerPluginInstaller

Source§

fn install<'life0, 'life1, 'life2, 'async_trait>( &'life0 self, manifest: &'life1 PluginManifest, plugin_dir: &'life2 Path, source: PluginSource, disposition: InstallDisposition, installed_at: DateTime<Utc>, ) -> Pin<Box<dyn Future<Output = PluginResult<InstalledPlugin>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait, 'life2: 'async_trait,

Install (or, with InstallDisposition::Upgrade, upgrade) a plugin already unpacked at plugin_dir (source handling — copying a local dir, unpacking a .tar.gz, fetching+verifying a URL + selecting the per-platform artifact — happens BEFORE this is called; by the time install runs, plugin_dir already contains plugin.json plus the skills//prompts//workflows//bin/ layout the manifest declares). Read more
Source§

fn uninstall<'life0, 'life1, 'async_trait>( &'life0 self, id: &'life1 str, ) -> Pin<Box<dyn Future<Output = PluginResult<()>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Reverse everything install registered for id (stop + remove MCP servers, remove prompt presets, remove workflow files), then remove the provenance entry and delete plugin_dir from disk. Safe by construction: the provenance registered set only ever names plugin-created entries (invariant 1 in the module docs).
Source§

fn list<'life0, 'async_trait>( &'life0 self, ) -> Pin<Box<dyn Future<Output = PluginResult<Vec<InstalledPlugin>>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait,

All currently-installed plugins (a thin read of installed.json).

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more