Skip to content

Run one extension host per remote host - #938

Draft
thesiti92 wants to merge 1 commit into
remote/4-remote-vscode-serverfrom
remote/5-remote-extension-host-guard
Draft

thesiti92 wants to merge 1 commit into
remote/4-remote-vscode-serverfrom
remote/5-remote-extension-host-guard

Conversation

@thesiti92

@thesiti92 thesiti92 commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Stacked PR 5 of 9 for remote reviews (base: remote/4-remote-vscode-server; #934, the rename, is merged). Review in order; each PR builds and passes its suites on its own.

Manual test plan

Purpose. Each Desktop window runs one stock extension host per remote host, inside a small per-host scope that binds files, models, diagnostics, workspace roots, search, commands and language features to their host, so hover and go to definition in a remote review answer from that host, read-only. Remote extensions are trusted the way VS Code Remote trusts them. The host's extension host reconnects as soon as main has a new endpoint, and the Rust, Swift and C# groups install on remotes.

Setup. Worktree at origin/remote/5-remote-extension-host-guard. Build the remote runtime (PR 4). R up a; R up b; R install a; R install b; R ssh a -- whiteboard remote extensions ensure (and b). Create Remote-order on a and on b. Launch; add both hosts.

Steps.

  1. Each Settings row: online and Language features: available.
  2. a's review → Diff view → hover one in f.ts → function one(): number.
  3. Go to definition on one() → f.ts line 1, from the host; typing in it changes nothing.
  4. b's review hovers too; a laptop review's hovers still work.
  5. R pause b → a keeps answering; R resume b → b answers again without a reload.
  6. R ssh b -- pkill -f server-main.js → b's hover answers again after the reattach.
  7. Host extension commands: in the review window ⌘⇧P TypeScript lists no rows; it shows neither the laptop's nor a host's TypeScript commands. From PR 9 a Source window's palette lists the host's TypeScript commands (PR 9 step 8).
  8. Optional: turn on Swift (Settings → Tools → Extensions → Manage…), Retry a → its row lists Swift with swift was not found on the login shell's PATH.

Negative checks.

  • echo '{"commit":"0000000000000000000000000000000000000000"}' > apps/review-desktop/code-oss/product.overrides.json, restart Desktop → hosts stay online, reviews open, rows read Language features: unavailable — …, no hovers. Delete the file.
  • Routing, one test file each: --test 'code-oss/src/vs/review/services/remote/**/*.test.ts' (the file-event filter, the scoped vscode.executeHoverProvider, models, markers, workspace roots, resolver). Journeys remote-lsp, and by name remote-lsp-rust|swift|csharp (R up --toolchain).

Cleanup. Common cleanup; make sure product.overrides.json is gone.

Reviewer notes

  • Remote hosts are trusted the way VS Code Remote trusts them: a host's extension host gets what a local one gets. The per-host scope exists for routing only (upstream's URI transformer drops the authority, so files, models, diagnostics, workspace roots, search, commands and language features are bound to their host). Plan: docs/superpowers/plans/2026-10-05-adopt-vscode-trust-model.md, ruling T1.
  • Not a defect: a remote extension's showOpenDialog/showSaveDialog and modal messages reach the laptop as they do in VS Code Remote (ruling T1).
Common setup for all plans

Common setup (read once)

  • Test each PR in a worktree at its head branch: git -C <core> worktree add --detach ../review-prN origin/<head>, then pnpm install there. Run everything below from that worktree root.
  • Helpers (bash or zsh):
R() { node apps/review-desktop/scripts/e2e/remote/remote.mjs "$@"; }
export WB_TEST_RUN=manual-$$                  # before the first `R up`
S() { ssh -F /tmp/wbt.$WB_TEST_RUN/ssh_config "$@"; }   # host aliases are wb-test-<name>
H=/tmp/wb-home-$WB_TEST_RUN                   # isolated Desktop home
mkdir -p $H/review-desktop/state/user-data/User
echo '{"review.experimental.remoteHosts.enabled": true}' > $H/review-desktop/state/user-data/User/settings.json
awk '/createRemoteReview = String.raw`/{f=1;next} /^`;/{f=0} f' apps/review-desktop/scripts/e2e/journeys/remote-host.mjs > /tmp/wb-review.sh
sed -e 's/open\\":false/open\\":true/' -e 's/wbrepo/wbrepo2/g' /tmp/wb-review.sh > /tmp/wb-push.sh
edit() { printf '{"sessionId":"%s","edit":{"type":"insert","content":{"type":"markdown","markdown":"%s"}}}' "$2" "$3" | S "$1" 'whiteboard api session_edit -'; }
  • Launch (dev build only; a packaged build ignores both env vars): DEV_REVIEW_HOME=$H DEV_FAST_REVIEW_SSH_CONFIG=/tmp/wbt.$WB_TEST_RUN/ssh_config pnpm dev (prefix DEV_FAST_REVIEW_DESKTOP_BACKGROUND=1 to keep it from taking focus).
  • Desktop API: D=$(ls $H/review-desktop/instances/dev-*.json); URL=$(node -p "require('$D').url"); TOK=$(node -p "require('$D').token"); api() { curl -s -H "x-review-token: $TOK" "$URL$1"; }
  • A remote review: ID=$(S wb-test-a 'bash -s -- Remote-order' < /tmp/wb-review.sh | head -1) (repo ~/wbrepo, review "Remote-order" with a prose line and a code peek of f.ts). /tmp/wb-push.sh is the same with open: true in ~/wbrepo2.
  • Settings: ⌘, → region Remote hosts → type the alias in SSH alias → Add.
  • Fork unit tests: (cd apps/review-desktop && TSX_TSCONFIG_PATH=tsconfig.test.json node --import tsx --test --test-force-exit <files>). Package tests: pnpm --filter @dev.fast/whiteboard test <files>.
  • Journeys: stage a runtime per apps/review-desktop/scripts/e2e/TESTING.md ("Staging the runtime"), then node apps/review-desktop/scripts/e2e/run.mjs --runtime "$REVIEW_E2E_RUNTIME" --journey <name>.
  • The harness has pause/resume (there is no unpause).
  • Cleanup, every plan: quit Desktop first (its ssh masters count as leftovers), then R down --all; R verify-clean; rm -rf $H /tmp/wb-*.sh. Without an aws sso login session verify-clean also prints AWS could not be checked and exits 1; no other line may appear.

@thesiti92
thesiti92 force-pushed the remote/5-remote-extension-host-guard branch from 9209333 to bf6188a Compare October 5, 2026 19:37
@thesiti92
thesiti92 added this pull request to stack #943 October 5, 2026 19:37
@thesiti92
thesiti92 force-pushed the remote/5-remote-extension-host-guard branch from bf6188a to f5a401d Compare October 5, 2026 20:00
@thesiti92
thesiti92 force-pushed the remote/5-remote-extension-host-guard branch from f5a401d to a257609 Compare October 5, 2026 20:19
@thesiti92
thesiti92 force-pushed the remote/5-remote-extension-host-guard branch from a257609 to 7c04951 Compare October 5, 2026 20:33
@thesiti92
thesiti92 force-pushed the remote/5-remote-extension-host-guard branch 2 times, most recently from 2060c55 to 7c04951 Compare October 5, 2026 20:41
@thesiti92
thesiti92 force-pushed the remote/5-remote-extension-host-guard branch from 7c04951 to 033cc3e Compare October 5, 2026 21:24
@thesiti92
thesiti92 force-pushed the remote/5-remote-extension-host-guard branch from 033cc3e to ed959d1 Compare October 5, 2026 21:38
@thesiti92
thesiti92 force-pushed the remote/5-remote-extension-host-guard branch from ed959d1 to 8fe1e40 Compare October 5, 2026 21:47
@thesiti92
thesiti92 force-pushed the remote/5-remote-extension-host-guard branch 3 times, most recently from 10f7424 to d7e5026 Compare October 6, 2026 01:58
@thesiti92 thesiti92 changed the title Run a guarded extension host per remote host Run one extension host per remote host Oct 6, 2026
@thesiti92
thesiti92 force-pushed the remote/5-remote-extension-host-guard branch 2 times, most recently from a8e85a7 to ee86485 Compare October 6, 2026 03:46
@thesiti92
thesiti92 force-pushed the remote/5-remote-extension-host-guard branch from ee86485 to 9052c4f Compare October 6, 2026 15:57
@thesiti92
thesiti92 force-pushed the remote/5-remote-extension-host-guard branch from 9052c4f to 9e2dec5 Compare October 6, 2026 16:16
@thesiti92
thesiti92 force-pushed the remote/5-remote-extension-host-guard branch from 9e2dec5 to 172940e Compare October 6, 2026 17:10
@thesiti92
thesiti92 force-pushed the remote/5-remote-extension-host-guard branch from 172940e to b0687b4 Compare October 7, 2026 13:31

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant