Skip to content

refactor(plugins): share API provider specs - #4062

Merged
steipete merged 3 commits into
mainfrom
triage/20260921-plugin-glue-b4
Sep 28, 2026
Merged

steipete merged 3 commits into
mainfrom
triage/20260921-plugin-glue-b4

Conversation

@steipete

Copy link
Copy Markdown
Owner

Six bundled providers now share PluginProviderSpec registration: Hugging Face, Nous, Fireworks, xAI, Venice, and Zed. Hugging Face and xAI also share the API-key settings implementation. This removes 255 production lines and raises the declarative count from 31 to 37, with the 87-provider registry unchanged.

Native boundaries remain provider-owned: Hugging Face keeps its CLI-token reader and serialized retained runtime; Nous keeps Hermes credential validation and diagnostics; Fireworks keeps slug projection and allowlisted persistence; Venice and Zed keep their native source routing, cookie policy, bindings, and visibility. Bundled scripts are unchanged. Every migrated color uses ProviderColor(hex:).

The new typed options carry existing status-page, token-cost, settings-section, and plugin-result-policy contracts. Each is needed by at least two candidates, including deferred providers: status pages by Hugging Face/OpenAI; token costs by xAI/OpenRouter/OpenAI; settings sections by Fireworks/Moonshot/z.ai/OpenRouter; result policies by Fireworks/OpenAI. Shared code contains no provider switch.

Equivalence and validation

The separate pre/post capture is byte-identical: 53,692 bytes, SHA-256:

18e4f2007980d5a6cc990a51e0f9f60f19b791c225c8b04e035f40ce20e96798

It covers all ten candidates: registry and implementation order, full CLI help, metadata/branding/widget flags, settings text/actions/pickers, cookie-mode snapshots, credential projections, token-account metadata, and availability. The committed golden remains derived-only and adds the token-cost capability. New coverage checks native file-token discovery and reuse of the retained Hugging Face strategy.

All Swift tests used source Scripts/test_environment.sh. No live probes, cookie imports, app relaunches, release builds, or full sharded suite were run.

swift test --jobs 4 --filter 'PluginProviderSpecTests|PluginCookieProviderSpecTests|ProviderArchitectureGatekeeperTests|ProviderSettingsDescriptorTests|ProviderSettingsIntegrationTests|ProviderPlugin.*ParityTests|CLIEntryTests|CLICommonOptionsTests|CLIArgumentParsingTests|CLIProviderSelectionTests|ProviderSelectionFixtureTests|CLIUnificationGoldenTests|TokenAccount.*Tests|ProviderTokenAccountData|FileTokenAccountStore|ProviderCredentialCharacterizationTests|ProviderConfigEnvironmentTests|ProviderTokenResolverTests|ProviderLabelMetadataCharacterizationTests|ProviderPresentationPolicyCharacterizationTests|ProviderRegistryTests|ProviderWidgetAvailabilityTests|WidgetProviderChoiceTests|ProviderIconResourcesTests|ProviderAccentColorTests|ConfigurationDocsProviderIDTests|ProviderEndpointOverrideSecurity.*Tests|HuggingFace|NousPluginTests|NousSettingsReaderTests|XAIProviderTests|XAICostUsageMappingTests|Fireworks|Venice|Zed|HostResultProviderTests|ProviderPluginResultTests'
✔ Test run with 565 tests in 60 suites passed after 27.534 seconds.
✔ Test run with 56 tests in 5 suites passed after 4.176 seconds.
✔ Test run with 18 tests in 2 suites passed after 0.041 seconds.

565 app/core tests, 56 plugin tests, and 18 Linux-target tests passed. XCTest executed 65 tests with two opt-in renderers skipped and zero failures. Linux-target tests ran on macOS.

CODEXBAR_PLUGIN_ENGINE=jsc swift test --skip-build --filter 'PluginProviderSpecTests|ProviderPluginParityTests|ProviderPluginDetailsParityTests|HuggingFacePluginTests|HuggingFaceWalletPluginTests|NousPluginTests|XAIProviderTests|FireworksUsageFetcherTests|VeniceUsageFetcherTests|VeniceWebUsageFetcherTests|VeniceClerkSessionTests|ZedPluginTests|ZedStatusProbeTests|HostResultProviderTests'
make check
✔ Test run with 117 tests in 11 suites passed after 2.071 seconds.
✔ Test run with 39 tests in 3 suites passed after 4.225 seconds.
Done linting! Found 0 violations, 0 serious in 2660 files.

JSC: 117 app/core and 39 plugin tests passed. make check: exit 0, zero violations in 2,660 Swift files. All three pre-commit independent reviews finished without actionable P0–P2 findings.

The initial build caught a test naming the removed xAI implementation. A temporary capture hook also reused the golden's fixture name and contaminated synthetic account availability; the hook was removed and the focused run passed without changing the frozen expected values. One argument-layout lint violation was fixed in a separate commit. No pre-existing bug fix or regression red→green claim is made; this is a behavior-preserving refactor. No changelog entry is needed.

Deferred candidates

  • Moonshot: provider-specific config normalization (Sources/CodexBarCore/Providers/Moonshot/MoonshotProviderDescriptor.swift:88) and shared Kimi branding remain outside the spec.
  • z.ai: custom monthly-MCP pacing (Sources/CodexBarCore/Providers/Zai/ZaiProviderDescriptor.swift:95) is not expressible by the spec; it is the only candidate needing that option.
  • OpenRouter: its credit capability (Sources/CodexBarCore/Providers/OpenRouter/OpenRouterProviderDescriptor.swift:59) is unique among these spec candidates; widget selectability also must be retained.
  • OpenAI API: the exact (0.06, 0.51, 0.43) color (Sources/CodexBarCore/Providers/OpenAI/OpenAIAPIProviderDescriptor.swift:45) cannot be represented by six-digit hex without changing the capture; its custom icon and cost-menu configuration also remain outside the current spec. No color was changed.

Abacus, Muse, LongCat, Replicate, and TypeSafe are untouched as requested.

Production delta

Group Insertions Deletions Net
API registration/settings 139 351 -212
Venice/Zed registration 81 124 -43
Whole branch 220 475 -255

The branch changes 12 production files. Scripts/regenerate-provider-manifests.sh regenerated the manifests; only the two app implementation entries changed. No gatekeeper anchors needed changes. Tests add 156 lines and remove four relative to the pinned base bf34fc9f424f.

Refs #4043
Refs #4049
Refs #4058

@clawsweeper

clawsweeper Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

🦞👀
ClawSweeper picked this up.

Pull request received. I will update this pull request when review starts.

ClawSweeper review blocked

Automated review did not run, so no review verdict was produced.

Reason: The input-safety check rejected material in this revision. No detected value, path, or scanner output is reproduced here.

Automatic review is on hold, including after source changes. Request a fresh re-review after resolving the failure; maintainers can also release the hold through an intentional scanner-policy update.

Next step: If this is a genuine credential, remove and rotate it. If it is an intentional test fixture, a maintainer must review and qualify it.

View the workflow run.

@steipete
steipete force-pushed the triage/20260921-plugin-glue-b4 branch from 3a46313 to d59562f Compare September 28, 2026 01:49
@steipete
steipete merged commit 579f684 into main Sep 28, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant