Commit Graph
145 Commits
Author SHA1 Message Date
can1357 3e1808e2b5 fix(agent): handle installed legacy dependency reloads 2026-07-05 12:44:17 +02:00
roboomp 45deb2098d fix(agent): reloaded legacy bare dependency children
Included ESM extension-local bare dependency entries in the legacy extension graph so their relative children receive the same mtime cache-bust rewrite as extension source modules.

Skipped CommonJS dependency entries to preserve native Bun CJS default import behavior.

Added a regression test for a local node_modules ESM dependency whose unchanged entry re-exports an edited helper.

Fixes #4565
2026-07-05 02:53:28 +00:00
roboomp 65cd063d90 fix(agent): refreshed legacy pi graph hooks
Collected the current extension graph on every load and registered supplemental Bun hooks for modules added after the first import.

Preserved exact-path filters by tracking covered realpaths per entry instead of widening hooks to unrelated files.

Added a regression test for an entry-only extension that later adds helper and leaf modules, then reloads an edited leaf.

Fixes #4565
2026-07-04 20:56:38 +00:00
roboomp 2049c72b94 fix(agent): propagated mtime through legacy extension graph
Threaded the current load's mtime tag through rewriteExtensionPackageImports, rewriteExtensionBareImports, and a new relative-graph pass so ./helper.ts, #alias/*, and extension-local bare deps all rekey per reload.

Added a toGraphImportSpecifier helper that emits bare POSIX paths with ?mtime on POSIX and keeps file:// URLs on Windows/bundled targets, matching the entry loader.

Added a regression test covering same-process relative-helper reload freshness through the public loader.

Fixes #4565
2026-07-04 20:44:56 +00:00
roboomp d510851593 fix(agent): reloaded edited legacy pi modules
Loaded legacy Pi extension entries through raw POSIX filesystem specifiers so Bun keys the cache-busting mtime query.

Allowed the extension graph onLoad hook to match and normalize the mtime query before rewriting source.

Added a regression test covering same-process reload freshness and clean fileURLToPath-derived paths.

Fixes #4565
2026-07-04 20:26:27 +00:00
can1357 eb47ce1063 Merge remote-tracking branch 'origin/farm/a23a6b23/drain-plugin-install-pipes' 2026-07-02 23:43:11 +02:00
can1357 1c0e35f73e Merge remote-tracking branch 'origin/farm/813601d2/install-npm-pi-packages' 2026-07-02 23:43:08 +02:00
roboomp 805b994211 fix(cli): accepted npm protocol plugin installs
Allowed npm:<package> install specs to validate against the resolved package name while still forwarding the original spec to Bun.

Added regression coverage for installing npm:pi-figma-remote-auth through PluginManager.

Fixes #4310
2026-07-02 12:08:01 +00:00
roboomp d2be57a8f7 fix(plugins): drain subprocess pipes concurrently with proc.exited
PluginManager.install (bun install + bun update), PluginManager.uninstall,
PluginManager.#fixMissingPlugin, the legacy installer.ts install/uninstall
helpers, and generate-legacy-pi-bundled-registry.ts's formatInPlace all
called Bun.spawn with stdout/stderr piped and awaited proc.exited before
touching either stream. Once a child's output exceeded the ~64 KiB OS
pipe buffer, the child would block on write(2) while the parent blocked
on exit — a classic pipe-buffer deadlock. Even where Bun's current runtime
happens to buffer eagerly, the pattern silently leaked unbounded bytes.

Each site now starts new Response(proc.stdout).text() and stderr readers
immediately after Bun.spawn and awaits them alongside proc.exited via
Promise.all. Existing error semantics are preserved: install throws with
stderr, uninstall keeps its generic error, and formatInPlace still includes
Biome's stderr in the failure message.

Adds a regression test (plugin-install-git.test.ts) that models the
OS-pipe deadlock by holding proc.exited until both mock streams are
drained — install must read them before awaiting exit, else the test hits
its 2s Promise.race timeout.

Fixes #4230
2026-07-02 08:33:32 +00:00
can1357 4e12e5bf76 fix(extensibility): read lazy graph modules from disk at import time
The consume-once source map kept entries for graph modules the initial
import never loaded (modules only reached via lazy dynamic imports).
Their first import - possibly long after load, and after an on-disk
edit - was served the boot-time snapshot instead of current file
content, and the unconsumed sources stayed in the plugin closure for
the process lifetime.

Clear the map once the entry import settles: everything Bun loaded at
startup was already consumed (keeping the read-once win), and anything
left must be read at its actual import time, matching pre-dedup
behavior for lazy modules. The new regression test passes on the
pre-dedup baseline and fails on the unfixed dedup.
2026-07-02 10:29:57 +02:00
can1357 64e4bd89d1 merge PR #4205: perf(extensibility): read extension source graph once per load (@metaphorics) 2026-07-02 10:29:57 +02:00
roboomp 15c4835e99 fix(coding-agent): cached plugin extension resolution
- Added shared plugin cache invalidators wired through clearClaudePluginRootsCache.\n- Memoized enabled plugin discovery and legacy bare dependency fallback resolution.\n- Added regression coverage for cache reuse and invalidation.\n\nFixes #4197
2026-07-02 04:54:10 +00:00
metaphorics 621e3f3a82 perf(extensibility): read extension source graph once per load
collectExtensionModules already reads every own-source module's text to scan imports; the onLoad rewrite hook then re-read each file. Return a Map<path,source> from the collector and serve it consume-once in onLoad (delete on first hit, disk fallback on miss), so transitive modules are read once and the entry still re-reads on its ?mtime re-import. Adds a regression test asserting exactly one read per graph module.

Closes #4196
2026-07-02 13:42:13 +09:00
roboomp 777b609e63 fix(cli): preserved windows extension paths
Rejoined split Windows extension module paths before launch parsing finishes and stripped extended-length Win32 prefixes before Bun import and worker spawn APIs see them.

Fixes #3804
2026-06-29 11:50:36 +00:00
roboomp 500c39aa2e fix(extensions): isolate codex hook scripts so process.exit cannot kill OMP startup
Codex discovery surfaced every `~/.codex/hooks/*.{ts,js}` file as an OMP
hook (silently defaulting untyped names to `pre:<basename>`), and
`discoverExtensionPaths` then handed those paths to `loadExtension` for
dynamic import. A standalone Codex hook script with a top-level
`process.exit(0)` terminated the host CLI cleanly — `try/catch` around
`await import()` cannot intercept a synchronous exit, so OMP died at the
`loadExtensions:start` startup marker with no error surface.

Two-layer fix:

- `packages/coding-agent/src/extensibility/utils.ts`: new
  `withExitGuard` helper patches `process.exit` for the duration of a
  guarded callback so an exit raises `ExtensionExitError` instead of
  terminating the process; nested and concurrent guards restore correctly
  via depth counter.
- `extensibility/extensions/loader.ts`, `extensibility/hooks/loader.ts`,
  and `extensibility/plugins/manager.ts` wrap their dynamic-import sites
  in `withExitGuard` so the existing per-module `try/catch` records the
  intercepted exit as a load error and OMP keeps starting.
- `discovery/codex.ts:loadHooks` no longer treats arbitrary files as
  OMP hooks: only `pre-<tool>.{ts,js}` and `post-<tool>.{ts,js}` are
  registered. Files like `memory-bank-reminder.ts` are silently skipped
  rather than imported as extension factories.

Adds regression coverage:

- `test/extension-loader-process-exit.test.ts` — `loadExtensions` /
  `loadHooks` return errors and leave `process.exit` restored when a
  module exits at import time; sibling modules still load.
- `test/discovery/codex-hooks-discovery.test.ts` — codex provider
  registers `pre-*` / `post-*` files and drops everything else.

Fixes #3680
2026-06-27 20:38:53 +00:00
can1357 96a838ee90 chore(extensibility): updated legacy registry modules with utility helpers
- Added block-symbols and settings-stream-fn utility modules.
- Removed the deprecated strip utility module from the bundle.
2026-06-27 12:26:11 +02:00
can1357 c3f7e849e5 refactor: centralized AI error handling into a dedicated module
- Migrated 288 lines of scattered error classification logic from `utils/error-id.ts` into a cohesive `packages/ai/src/error/` module with 13 specialized submodules covering flags, classes, OAuth, providers, rate-limiting, and finalization.
- Replaced 100+ generic `Error` throws across 60+ provider and registry files with semantic `AIError.*` classes (e.g., `AIError.MissingApiKeyError`, `AIError.OAuthError`, `AIError.ProviderResponseError`), improving error diagnostics and retry logic.
- Consolidated error utility imports from `pi-utils` and scattered classification functions into a single `AIError` namespace, reducing coupling and simplifying error handling across all packages.
2026-06-27 10:44:13 +02:00
roboomp e3fb8956a2 fix(coding-agent): treated legacy scope-less marketplace entries as user
Coerced missing scope on installed_plugins.json entries to user before suppressing them, matching listClaudePluginRoots semantics, so users carrying registries written before the scope field still see marketplace plugins hidden from plugin list and doctor.

Fixes #3628
2026-06-27 05:19:03 +00:00
roboomp cf3425cc61 fix(coding-agent): suppressed package-less marketplace plugins
Derived marketplace runtime package names from plugin IDs when package.json is absent, preserving suppression for config-only marketplace installs. Added regression coverage for package-less LSP plugin installs in plugin list and doctor.

Fixes #3628
2026-06-27 05:16:54 +00:00
roboomp a4256d6507 fix(coding-agent): preserved same-name plugin links
Compared marketplace runtime entries by realpath before suppressing link-only plugin-manager entries. Added a regression where a local runtime link reuses a marketplace package name but points at a different path.

Fixes #3628
2026-06-27 05:12:57 +00:00
roboomp e36172c32c fix(coding-agent): hid marketplace plugins from npm lists
Filtered marketplace-managed runtime symlinks out of the npm plugin listing and OMP extension-package status provider while keeping marketplace installs available to the runtime loader. Added regressions for both duplicate surfaces.

Fixes #3628
2026-06-27 05:04:28 +00:00
can1357 775ff2d171 Merge PR #3572: feat: add xai/ddg/firecrawl/tinyfish web_search providers (@zekdevs) 2026-06-27 02:04:51 +02:00
can1357 a19be87823 Merge PR #3025: feat(debug): load user DAP adapter configs (@danzaio) 2026-06-27 01:38:50 +02:00
can1357 ae1650d689 refactor: renamed search and find tools to grep and glob
- Renamed the `find` and `search` tools to `glob` and `grep` respectively across the codebase to improve command clarity.
- Implemented full-stack support for the renamed tools, including CLI arguments, system prompts, SDK exports, and tool registration.
- Added automated migration logic in `settings` to transform legacy `find` and `search` configuration keys to their new equivalents.
- Updated the `collab-web` renderer registry to ensure backwards compatibility with legacy tool outputs.
2026-06-27 00:57:55 +02:00
can1357 eb4a02433c refactor: consolidated json parsing and stream utilities
- Centralized JSON parsing and stream processing logic by moving utilities from `packages/ai` to the shared `@oh-my-pi/pi-utils` package.
- Standardized import paths for JSON parsing and streaming across the agent, ai, and coding-agent packages.
- Refactored SSE stream handling to use consolidated `parseStreamingJson` logic and introduced robust error recovery for malformed container-shaped tail events.
- Cleaned up legacy bundled registry references and updated related module exports and tests to reflect the new utility structure.
2026-06-27 00:11:42 +02:00
zekdevs 656a8e5c40 add provider subpaths to legacy pi bundle 2026-06-26 10:31:50 -06:00
Dr Kennedy Umege 8da76c80fc fix: address gc review feedback 2026-06-26 09:07:02 +01:00
roboomp 006470a111 fix(plugins): resolved string export deps
Handled package root export sugar when legacy extension bare dependency resolution falls back from Bun.resolveSync in compiled binaries.

Fixes #3508
2026-06-26 00:13:30 +00:00
roboomp b7706f1a44 fix(plugins): loaded legacy extensions safely
Restored the pi-ai OAuth device-code helper expected by legacy provider packages and rewrote extension-owned bare dependencies to file URLs during validation so compiled binaries do not rely on Bun's runtime bare resolver.

Excluded worker entry modules from the compiled legacy bundled registry so validation does not import worker-only code on the main thread.

Fixes #3508
2026-06-26 00:06:25 +00:00
roboomp c7d9abbcfd fix(plugins): bundle wildcard-exported pi-* subpaths
The first pass only enumerated non-wildcard `exports` entries, so
patterns like pi-ai's `./oauth/*` left every concrete target
(`@oh-my-pi/pi-ai/oauth/anthropic` and friends) outside the
bundled registry. Compiled-mode resolution then fell back through
`Bun.resolveSync` → original peer specifier → missing peer dep,
reproducing the original `Cannot find module` failure for any
plugin that imports a wildcard-only subpath (e.g.
`@mariozechner/pi-ai/utils/oauth/anthropic`, remapped via
PI_SUBPATH_REMAPS).

The generator now runs a second pass over wildcard exports,
parses each single-asterisk pattern into prefix/suffix halves,
globs the matching source directory, and emits a registry entry
per concrete `.ts` file. Root catch-all wildcards (`./*` /
`./*.js`) are skipped on purpose — they'd static-import top-level
files like the coding-agent's own `cli.ts` and explode the bundle
through the binary entry's transitive graph. Test, `.d`,
`.generated`, `.bench` files and `index` basenames are filtered
out so the registry stays focused on importable surfaces.

A new test case in
test/extensibility/legacy-pi-bundled-subpath-overrides.test.ts
asserts the reviewer's cited `@oh-my-pi/pi-ai/oauth/anthropic`
key now routes through the virtual namespace and that root
catch-all wildcards remain unbundled.

Fixes #3442
2026-06-25 06:13:38 +00:00
roboomp aa29b79642 fix(plugins): route bundled pi-* subpath imports through the virtual registry
Compiled-binary extension validation rewrote @(scope)/pi-ai/oauth →
@oh-my-pi/pi-ai/oauth, but LEGACY_PI_PACKAGE_ROOT_OVERRIDES only
covered bare package roots. resolveCanonicalPiSpecifier therefore
fell through to Bun.resolveSync, which fails inside bunfs on Bun
1.3.14+, then the rewriteLegacyPiImports catch left the original
specifier alone. Bun's native resolver then failed because most
plugins (e.g. @charmland/pi-hyper-provider) declare @(scope)/pi-ai
as a peerDependency only and never materialize a real install.

A new scripts/generate-legacy-pi-bundled-registry.ts reads every
bundled pi-* package's non-wildcard exports field and emits both
the heavy legacy-pi-bundled-registry.ts (static imports + map) and
a light legacy-pi-bundled-keys.ts. legacy-pi-compat.ts statically
imports the keys file to seed the override map without paying the
legacy-pi-coding-agent-shim → ../index → export/html/... cascade,
so subpath imports now route to the same omp-legacy-pi-bundled:
virtual namespace that already serves the roots.
scripts/build-binary.ts runs the generator before bun build
--compile so new pi-* subpaths added under packages/*/package.json
ship without manual regeneration; --check verifies the committed
output stays in sync.

Fixes #3442
2026-06-25 05:52:38 +00:00
can1357 fb43fbe9a7 refactor(coding-agent): drop dead legacy-pi bundled test seams
Remove `__getLegacyPiBundledRegistry` and `__synthesizeLegacyPiBundledSource`:
both reject outside compiled-binary mode, so no unit test can call them — they
were untested test seams. Real coverage runs through the pure
`__synthesizeLegacyPiBundledSourceWithRegistry` + `__getLegacyPiBundledRegistryGlobal`.

Also document why the synthesized virtual module must bridge back to the host
registry through `globalThis` (separate ES module, no shared closure scope,
live non-serializable exports) so the indirection isn't mistaken for cruft.
2026-06-25 05:12:14 +02:00
can1357 0cd852053e Merge branch 'farm/6a62fa2b/fix-bunfs-override-validation-fallback'
Serve bundled pi-* and TypeBox through an in-process virtual namespace
on Bun 1.3.14+ where `--compile` extras are unreachable via any
filesystem API (issue #3423).

Merge resolution:
- Reconciled `TYPEBOX_SHIM_PATH` with main's #3414 fall-through:
  `__resolveTypeBoxShimPath(isCompiled, sourcePath, exists)` returns the
  `omp-legacy-pi-bundled:` virtual specifier in compiled mode (no FS
  probe) and the on-disk source path otherwise, dropping to null when
  the shim file is missing so bare typebox imports fall through to native
  resolution.
- Removed the now-dead `--compile` extras path: dropped
  `LEGACY_COMPAT_BUILD_ENTRYPOINTS` usage from both build-binary.ts and
  ci-release-build-binaries.ts and deleted scripts/binary-entrypoints.ts;
  the bundler reaches every surface via legacy-pi-bundled-registry.ts.
- Deleted obsolete tests for the removed bunfs machinery
  (legacy-pi-compat-entrypoints, legacy-pi-typebox-shim-validation) and
  added regression coverage for __resolveTypeBoxShimPath.
- Dropped the binary-compiling smoke driver per maintainer request.

Verified: bun check clean; 77 extensibility tests pass; instrumented
compiled-binary run confirmed onLoad fires for all bundled specifiers.
2026-06-25 05:08:36 +02:00
roboomp 294d41bd3b fix(coding-agent): served bundled pi-* through virtual ns on bun 1.3.14
Bun 1.3.14 stopped exposing `--compile` extras through every filesystem-style API: `fs.existsSync`, `Bun.file().exists()`, `Bun.resolveSync`, and `await import()` on `/$bunfs/...` or `file:///$bunfs/...` all fail; only `/$bunfs/root/<binary-name>` itself answers. The pre-existing legacy-pi rewrite emitted `file:///$bunfs/...` URLs that Bun then could not load, so every legacy extension that imported `@oh-my-pi/pi-*` or `@sinclair/typebox` failed on the `omp-darwin-arm64` release binary.

`legacy-pi-compat.ts` now keeps a JS-heap reference to every bundled pi-* surface in a lazy-loaded sibling `legacy-pi-bundled-registry.ts` and serves them through an `omp-legacy-pi-bundled:` virtual namespace whose `Bun.plugin().onLoad` synthesizes a re-export module — no bunfs path ever leaves the module in compiled mode. Dev / source-link / installed-package modes keep the historical `file://` rewrite (source files exist on disk). The matching `--compile` extras in `scripts/build-binary.ts` are gone; `BUNFS_PACKAGE_ROOT`, `bunfsPath`, `__computeBunfsPackageRoot`, and `__joinBunfsPath` are deleted as dead code. `scripts/smoke-3423.ts` compiles a tiny binary that loads a fixture extension end-to-end through the new path.

Fixes #3423
2026-06-25 02:35:50 +00:00
roboomp 08977b226d fix(release): restored legacy pi-compat --compile entrypoints in release builds
- Extracted the legacy `--compile` entrypoint list to `scripts/binary-entrypoints.ts` and consumed it from both the release CI script and the local dev `build-binary.ts`, so the two cannot drift apart.
- `scripts/ci-release-build-binaries.ts` no longer ships release binaries without the typebox shim, legacy pi shims, and `@oh-my-pi/{agent,natives,tui,utils}` package barrels in bunfs. Commit dc5c93462f removed worker entrypoints and false-comment-claimed the legacy entrypoints were "still" listed, so every published `omp-<platform>-<arch>` since shipped without them and the resolver emitted bunfs URLs to missing files.
- Validated TYPEBOX_SHIM_PATH at module init via __resolveTypeBoxShimPath, mirroring __validateLegacyPiPackageRootOverrides (#2168). When the shim is absent the rewriter leaves bare typebox / @sinclair/typebox imports alone so Bun falls through to native node_modules resolution.
- Pinned both halves of the contract with tests: release+dev scripts must source from the shared constant, every shim path computed in legacy-pi-compat.ts must appear in it, and __resolveTypeBoxShimPath drops missing candidates.

Fixes #3414
2026-06-25 00:14:41 +00:00
can1357 df8c773fae Merge PR #3245: fix(cli): register marketplace plugin installs (@roboomp) 2026-06-24 18:23:47 +02:00
roboomp 57b4ee1eaf style: bun run fix 2026-06-23 16:04:50 +00:00
roboomp 03dae3814f fix(coding-agent): preserved bunfs double-slash in shim paths
`__computeBunfsPackageRoot` now returns `//root/packages` for the Bun 1.3.14
`//root/<binary>` import.meta.dir shape, but production immediately joined that
root with shim and package segments through `path.join`, which collapses the
POSIX double-slash bunfs mount back to `/root`. That still made override
validation miss the embedded shim files.

Added a bunfs join helper that preserves the `//root` mount prefix after joining
production descendants, wired `bunfsPath` through it, and extended the #3329
regression test to assert the full typebox shim path stays under
`//root/packages/...`.

Fixes #3329
2026-06-23 16:04:43 +00:00
roboomp f278ea6a9c docs(coding-agent): corrected #3329 wording — release asset, not Homebrew
The reporter clarified that the failing binary is the pre-built
`omp-darwin-arm64` release asset from GitHub Releases; Homebrew is only a
local-tap wrapper that downloads that asset. The fix already covers every
cross-compiled `<bunfs-root>/<binary>` shape, but the source/test docstrings
and changelog blurb framed it as a Homebrew-build-specific bug. Updated those
three call sites to name the release asset and note the Homebrew tap as a
downstream consumer of the same binary; no code change.
2026-06-23 16:00:15 +00:00
roboomp 5766952c20 style: bun run fix 2026-06-23 15:57:01 +00:00
roboomp aa393099a3 fix(coding-agent): handled <bunfs-root>/<binary> in __computeBunfsPackageRoot
Bun 1.3.14 reports `import.meta.dir` as `<bunfs-mount>/<binary-basename>` for
the compiled entry on some hosts — e.g. the Homebrew darwin-arm64 build sees
`//root/omp-darwin-arm64` instead of the bunfs root alone. The pre-fix path
joined `metaDir` with `"packages"` and baked the binary basename into every
bunfs path, so the typebox / legacy-pi shim overrides failed `existsSync`
validation, `resolveCanonicalPiSpecifier` fell through to a bunfs
`Bun.resolveSync` that also could not find the module, and every third-party
`@oh-my-pi/pi-*` extension was silently dropped.

`__computeBunfsPackageRoot` now detects the trailing binary-basename segment
(`path.basename(path.dirname(metaDir)) === "root"`) and strips it off the
original `metaDir` via string slicing rather than `path.join`, so Bun's
bunfs-native `//root` and `B:\~BUN\root` prefixes survive verbatim
(`path.posix.join` would collapse `//root` to `/root`). The single-segment
`<bunfs-root>` and deep `<bunfs>/packages/coding-agent/src/extensibility/plugins`
paths keep their existing branches.

Regression test added in `legacy-pi-bunfs-root.test.ts` for the POSIX
`//root/<bin>`, POSIX `/$bunfs/root/<bin>`, and Win32 `<drive>:\~BUN\root\<bin>.exe`
shapes.

Fixes #3329
2026-06-23 15:56:52 +00:00
roboomp dc74d09a8a style: bun run fix 2026-06-22 08:59:29 +00:00
roboomp bcfb5b5d8b fix(marketplace): preserved plugin root scope
Carried user/project root scope through enabled plugin enumeration so project marketplace installs keep project-level discovery metadata.
2026-06-22 08:59:24 +00:00
roboomp 661b3e1672 style: bun run fix 2026-06-22 08:51:41 +00:00
roboomp 77dd83de82 fix(marketplace): validated runtime package names
Rejected malformed marketplace package.json names before runtime link creation and guarded node_modules link paths lexically.
2026-06-22 08:51:30 +00:00
roboomp 1d500ce4f8 fix(cli): enumerated project-scope plugin root in loader
Made getEnabledPlugins walk both the user plugins root and the active project plugins root, with project entries shadowing same-named user entries. This makes `omp plugin install --scope project name@marketplace` discoverable to slash commands and the extension loader, matching the existing user-scope path. Added regression coverage that exercises the project-scope install through the runtime loader.\n\nFollow-up to #3244 review.
2026-06-22 08:46:37 +00:00
roboomp dc9be7c9de fix(cli): registered marketplace plugin installs
Added runtime symlink and lockfile bookkeeping for marketplace installs and removals so installed plugins are visible to the plugin loader. Updated manager coverage for install, uninstall, enablement, and loader discovery.\n\nFixes #3244
2026-06-22 08:35:24 +00:00
DanZAIO 90b7c395f9 fix(debug): preserve dap config file extensions 2026-06-20 00:01:25 -03:00
DanZAIO 9682186ff7 fix(debug): embed marketplace dap metadata on install 2026-06-20 00:01:25 -03:00
roboomp a63da8a3a3 fix(coding-agent): made plugin install transaction atomic on validation failure
The #3063 fix introduced a second mutating step — `bun update <name>` —
that rewrites bun.lock before extension validation runs. Three failure
paths could still leave the rejected commit pinned in the lockfile or
active tree:

- Extension validation throwing after `bun update` had refreshed
  bun.lock — rollback restored package.json and node_modules/<name>
  but never touched bun.lock.
- Feature validation (`omp plugin install pkg[ghost]`) throwing
  outside the rollback block entirely.
- Runtime-config save failing after a successful install with no
  rollback path.

Snapshot bun.lock alongside package.json before `bun install` runs and
route every post-install step (resolution, update, package.json read,
feature validation, extension validation, runtime-config save) through
one outer catch that restores all three (package.json + bun.lock +
node_modules/<name> from snapshot). `#rollbackFailedInstall` now
tolerates an unresolved `actualName` for failures that throw before
the dep key is known.

Three regression tests in plugin-install-validation.test.ts pin the
new contract: bun.lock restoration after a git reinstall fails
validation, bun.lock removal when it didn't exist pre-install, and
rollback on an unknown feature request.

Addresses review feedback on #3069.
2026-06-19 18:33:33 +00:00