Share VSIX extraction and pinned downloads between the Desktop build and remote hosts - #950
Merged
Conversation
thesiti92
force-pushed
the
remote/9-source-windows
branch
from
October 5, 2026 23:09
b55e244 to
5516292
Compare
thesiti92
force-pushed
the
remote/10-share-vsix-install
branch
from
October 5, 2026 23:11
538ed59 to
589073a
Compare
thesiti92
force-pushed
the
remote/10-share-vsix-install
branch
from
October 5, 2026 23:20
589073a to
6fff173
Compare
thesiti92
force-pushed
the
remote/9-source-windows
branch
3 times, most recently
from
October 6, 2026 02:46
6a50048 to
4c2c1ae
Compare
thesiti92
force-pushed
the
remote/10-share-vsix-install
branch
from
October 6, 2026 03:46
6fff173 to
1214041
Compare
thesiti92
force-pushed
the
remote/9-source-windows
branch
from
October 6, 2026 03:46
4c2c1ae to
1214041
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Stacked on #942 (
remote/9-source-windows). Review commit by commit:addActivationEventsfrom the remote extension catalog: removes dead code, no behaviour change.vsix.ts, used by the build script and remote hosts.pinned-download.ts: a pure move, no behaviour change.curated-extensions.mjs(Desktop build) andwhiteboard remote extensions ensure(#937) each had their own yauzl extractor and manifest sanitizer. Both now usepackages/review/src/vsix.ts, which the build script imports directly with Node 24's type stripping (the same waywindows-cli.test.mjsalready imports package source). The build no longer reaches into code-oss'snode_modulesfor yauzl.The extractor combines both checks: the remote's unpack-size cap (the build passes none) and the build's
.and:path checks plus the win32 chmod skip.The sanitizer parses the manifest with zod and checks the declared ID. It returns
engines.vscodefor the build's stamp.Removes
addActivationEventsfrom the remote catalog. Start rust-analyzer in every review window and keep it after the last peek closes #854 removed the manifest's last entry (onLanguage:rust) and now rewrites rust-analyzer's activation events in the renderer (ImplicitActivationEvents.setRewrite) for every install path, so the field was always[].Downloads:
packages/review/src/pinned-download.tsholds the remote installer's streaming download (sha256, optional size cap, timeout and abort).curated-extensions.mjsandstage-vscode-server.mjsnow use it in place of their own copies, which buffered whole downloads in memory. A cached file with the wrong hash is refetched rather than failing the run.--print-hashesuses the same download without a pin.ensureVsix'sallowDownloadwas always true when reached, so it is gone.Fixes the
pack-review-clitest fixture, which already failed 4/4 on Open Source windows for remote reviews #942: it destructureddependenciesout of the manifest and then readmanifest.dependencies. Its tarballs are now served over HTTP becausefetchhas nofile:support.The Desktop's runtime installer (
reviewOptionalExtensionInstaller.ts) keeps its own download because it has to use Electronnetso proxy and certificate settings apply.Test plan
pnpm --filter @dev.fast/whiteboard test src/remote-extensions.test.ts: 10/10 pass.node --test apps/review-desktop/scripts/curated-extensions.test.mjs: 8/8 (needs code-ossnode_modulesfor yazl).node apps/review-desktop/scripts/curated-extensions.mjs, then--check: real pinned VSIXes materialize and verify.--only=rust,go:rust-analyzer --versionruns from the extracted payload.node --test scripts/pack-review-cli.test.mjs: 4/4 (0/4 on the base).--checkpasses and no.partfiles are left.pnpm lint,pnpm format, packagetsc --noEmitandpnpm --filter @dev.fast/whiteboard build: clean.