Skip to content

feat(runtime): register file handlers at runtime - #70

Open
replghost wants to merge 6 commits into
docs/runtime-file-handlersfrom
feat/runtime-file-handlers
Open

replghost wants to merge 6 commits into
docs/runtime-file-handlersfrom
feat/runtime-file-handlers

Conversation

@replghost

Copy link
Copy Markdown
Collaborator

Summary

Implements ABI v1 §File input (#69) in the native runtime and both browser backends, with aligned bounds and failure behavior.

  • host_file_register and host_file_info guest imports. Registrations share the mediated-input handle space and the quota of eight. Descriptors are strict JSON with no unknown fields, no duplicate keys, and integer-only numbers; they return -1/-2/-3/-4.
  • Inline delivery goes through the existing status/read/cancel lifecycle. host_input_cancel discards a ready result.
  • Relaunch delivery: the selected file replaces the asset at mountPath in a fresh execution, within the asset bounds. A handler re-registered with the same id reports status 3, and host_file_info describes the file.
  • Registrations stay readable after an execution stops or init fails.
  • The parsed fileTypes hint is exposed on AppDescriptor.

Host API

Native (Runtime / ApplicationRuntime):

  • set_file_input_support, file_registrations / take_file_registrations
  • guest triggers arrive as MediatedInputCommand::FileRequest
  • send_file_input returns Ready, Rejected, Refused, or Relaunch(FileRelaunch)
  • set_file_relaunch before init

Browser:

  • start options fileInput and fileRelaunch
  • runtime → Host: file-registrations, file-input-request, file-input-delivery
  • Host → runtime: file-input, plus the existing mediated-input-result for statuses 4–6

The UniFFI facade does not expose mediated input yet, so file input is not in it either.

Tests

  • 76 shared descriptor vectors (tests/fixtures/file-descriptors.json) run through the guest on the native path and both browser paths.
  • The file-input.polkavm fixture is assembled from source in tests/file_input.rs and checked byte for byte.

Verification

  • cargo +nightly fmt --check: passed
  • workspace clippy with -D warnings: passed
  • cargo test --workspace --all-features: passed
  • wasm32 cargo check: passed
  • npm test: 94/94 passed
  • verify-browser-assets.mjs and the exporter diff: passed

Needs CI: the embedded polkavm-browser-runtime.wasm was built on macOS and will not match the Linux reproducible build. Replace it with CI's reproduced-browser-assets artifact and update the digest in polkavm-host-runtime-assets/src/lib.rs.

🤖 Generated with Claude Code

replghost and others added 6 commits September 29, 2026 12:19
Add ADR 0003 and the ABI v1 §File input contract. File input moves from the
App v2 capabilities.fileInput manifest block to a runtime host_file_register
call on the mediated-input lifecycle, with inline (8 MiB) and relaunch
(128 MiB) delivery and host_file_info for the selected file's name, MIME type
and size. The manifest keeps only an advisory top-level fileTypes hint.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Implement ABI v1 §File input on the mediated-input lifecycle.
host_file_register validates the JSON descriptor (4 KiB, strict fields,
integer maxBytes, id/label/extension/MIME/mount-path rules), shares the
handle space and the eight-registration quota with host_input_register,
and reports -2/-4 from the deliveries the Host declares.
host_file_info describes a ready file.

Hosts see registrations with file_registrations, receive guest-triggered
picker requests as MediatedInputCommand::FileRequest, and deliver a
selection with send_file_input, which rejects empty or over-bound files
with status 6. A relaunch delivery stops the execution and returns a
FileRelaunch that set_file_relaunch mounts over the asset of a fresh
execution, where the re-registered handler reports status 3.
host_input_cancel discards a ready result and every successful cancel
leaves the registration idle. AppDescriptor parses the advisory fileTypes
hint, and the wasm bridge exposes the same calls to the browser core.

The file-input fixture is assembled from source in tests/file_input.rs.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The translated backend parses descriptors with the native strictness and
both backends exchange the same Host messages: file-registrations,
file-input-request, file-input, and file-input-delivery, with the
fileInput and fileRelaunch start options. A Host still receives the
registrations of an execution that fails before it becomes ready.
Shared descriptor vectors and the file-input fixture run against both
backends. Browser assets are regenerated from the build.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@replghost
replghost force-pushed the docs/runtime-file-handlers branch from 6fa4b77 to c0b2825 Compare September 29, 2026 18:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant