Skip to content

Share VSIX extraction and pinned downloads between the Desktop build and remote hosts - #950

Merged
thesiti92 merged 0 commit into
remote/9-source-windowsfrom
remote/10-share-vsix-install
Oct 6, 2026
Merged

thesiti92 merged 0 commit into
remote/9-source-windowsfrom
remote/10-share-vsix-install

Conversation

@thesiti92

@thesiti92 thesiti92 commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Stacked on #942 (remote/9-source-windows). Review commit by commit:

  1. Keep the manifest's dependencies in the pack-review-cli test fixture: a one-line fix for a test that already failed.
  2. Drop addActivationEvents from the remote extension catalog: removes dead code, no behaviour change.
  3. Share VSIX extraction: adds vsix.ts, used by the build script and remote hosts.
  4. Move the remote installer's pinned download into pinned-download.ts: a pure move, no behaviour change.
  5. Switch the build scripts to that download: the one behaviour change, a cached file with the wrong hash is refetched.

curated-extensions.mjs (Desktop build) and whiteboard remote extensions ensure (#937) each had their own yauzl extractor and manifest sanitizer. Both now use packages/review/src/vsix.ts, which the build script imports directly with Node 24's type stripping (the same way windows-cli.test.mjs already imports package source). The build no longer reaches into code-oss's node_modules for yauzl.

  • The extractor combines both checks: the remote's unpack-size cap (the build passes none) and the build's . and : path checks plus the win32 chmod skip.

  • The sanitizer parses the manifest with zod and checks the declared ID. It returns engines.vscode for the build's stamp.

  • Removes addActivationEvents from the remote catalog. Start rust-analyzer in every review window and keep it after the last peek closes #854 removed the manifest's last entry (onLanguage:rust) and now rewrites rust-analyzer's activation events in the renderer (ImplicitActivationEvents.setRewrite) for every install path, so the field was always [].

  • Downloads: packages/review/src/pinned-download.ts holds the remote installer's streaming download (sha256, optional size cap, timeout and abort). curated-extensions.mjs and stage-vscode-server.mjs now use it in place of their own copies, which buffered whole downloads in memory. A cached file with the wrong hash is refetched rather than failing the run. --print-hashes uses the same download without a pin. ensureVsix's allowDownload was always true when reached, so it is gone.

  • Fixes the pack-review-cli test fixture, which already failed 4/4 on Open Source windows for remote reviews #942: it destructured dependencies out of the manifest and then read manifest.dependencies. Its tarballs are now served over HTTP because fetch has no file: support.

The Desktop's runtime installer (reviewOptionalExtensionInstaller.ts) keeps its own download because it has to use Electron net so proxy and certificate settings apply.

Test plan

  • pnpm --filter @dev.fast/whiteboard test src/remote-extensions.test.ts: 10/10 pass.
  • node --test apps/review-desktop/scripts/curated-extensions.test.mjs: 8/8 (needs code-oss node_modules for yazl).
  • node apps/review-desktop/scripts/curated-extensions.mjs, then --check: real pinned VSIXes materialize and verify. --only=rust,go: rust-analyzer --version runs from the extracted payload.
  • node --test scripts/pack-review-cli.test.mjs: 4/4 (0/4 on the base).
  • A real run: a deleted cache entry downloads again from Open VSX, and a tampered one is refetched; --check passes and no .part files are left.
  • pnpm lint, pnpm format, package tsc --noEmit and pnpm --filter @dev.fast/whiteboard build: clean.

@thesiti92
thesiti92 force-pushed the remote/9-source-windows branch from b55e244 to 5516292 Compare October 5, 2026 23:09
@thesiti92
thesiti92 force-pushed the remote/10-share-vsix-install branch from 538ed59 to 589073a Compare October 5, 2026 23:11
@thesiti92 thesiti92 changed the title Share VSIX extraction between the Desktop build and remote hosts Share VSIX extraction and pinned downloads between the Desktop build and remote hosts Oct 5, 2026
@thesiti92
thesiti92 force-pushed the remote/10-share-vsix-install branch from 589073a to 6fff173 Compare October 5, 2026 23:20
@thesiti92
thesiti92 force-pushed the remote/9-source-windows branch 3 times, most recently from 6a50048 to 4c2c1ae Compare October 6, 2026 02:46
@thesiti92 thesiti92 closed this Oct 6, 2026
@thesiti92
thesiti92 force-pushed the remote/10-share-vsix-install branch from 6fff173 to 1214041 Compare October 6, 2026 03:46
@thesiti92
thesiti92 merged commit 1214041 into remote/9-source-windows Oct 6, 2026
@thesiti92
thesiti92 force-pushed the remote/9-source-windows branch from 4c2c1ae to 1214041 Compare October 6, 2026 03:46
@thesiti92
thesiti92 deleted the remote/10-share-vsix-install branch October 6, 2026 03:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant