Conversation
Add ADR 0003 and the ABI v1 §File input contract. File input moves from the App v2 capabilities.fileInput manifest block to a runtime host_file_register call on the mediated-input lifecycle, with inline (8 MiB) and relaunch (128 MiB) delivery and host_file_info for the selected file's name, MIME type and size. The manifest keeps only an advisory top-level fileTypes hint. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Implement ABI v1 §File input on the mediated-input lifecycle. host_file_register validates the JSON descriptor (4 KiB, strict fields, integer maxBytes, id/label/extension/MIME/mount-path rules), shares the handle space and the eight-registration quota with host_input_register, and reports -2/-4 from the deliveries the Host declares. host_file_info describes a ready file. Hosts see registrations with file_registrations, receive guest-triggered picker requests as MediatedInputCommand::FileRequest, and deliver a selection with send_file_input, which rejects empty or over-bound files with status 6. A relaunch delivery stops the execution and returns a FileRelaunch that set_file_relaunch mounts over the asset of a fresh execution, where the re-registered handler reports status 3. host_input_cancel discards a ready result and every successful cancel leaves the registration idle. AppDescriptor parses the advisory fileTypes hint, and the wasm bridge exposes the same calls to the browser core. The file-input fixture is assembled from source in tests/file_input.rs. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
The translated backend parses descriptors with the native strictness and both backends exchange the same Host messages: file-registrations, file-input-request, file-input, and file-input-delivery, with the fileInput and fileRelaunch start options. A Host still receives the registrations of an execution that fails before it becomes ready. Shared descriptor vectors and the file-input fixture run against both backends. Browser assets are regenerated from the build. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
replghost
force-pushed
the
docs/runtime-file-handlers
branch
from
September 29, 2026 18:52
6fa4b77 to
c0b2825
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Implements ABI v1 §File input (#69) in the native runtime and both browser backends, with aligned bounds and failure behavior.
host_file_registerandhost_file_infoguest imports. Registrations share the mediated-input handle space and the quota of eight. Descriptors are strict JSON with no unknown fields, no duplicate keys, and integer-only numbers; they return-1/-2/-3/-4.host_input_canceldiscards a ready result.mountPathin a fresh execution, within the asset bounds. A handler re-registered with the sameidreports status 3, andhost_file_infodescribes the file.initfails.fileTypeshint is exposed onAppDescriptor.Host API
Native (
Runtime/ApplicationRuntime):set_file_input_support,file_registrations/take_file_registrationsMediatedInputCommand::FileRequestsend_file_inputreturnsReady,Rejected,Refused, orRelaunch(FileRelaunch)set_file_relaunchbeforeinitBrowser:
fileInputandfileRelaunchfile-registrations,file-input-request,file-input-deliveryfile-input, plus the existingmediated-input-resultfor statuses 4–6The UniFFI facade does not expose mediated input yet, so file input is not in it either.
Tests
tests/fixtures/file-descriptors.json) run through the guest on the native path and both browser paths.file-input.polkavmfixture is assembled from source intests/file_input.rsand checked byte for byte.Verification
cargo +nightly fmt --check: passed-D warnings: passedcargo test --workspace --all-features: passedcargo check: passednpm test: 94/94 passedverify-browser-assets.mjsand the exporter diff: passedNeeds CI: the embedded
polkavm-browser-runtime.wasmwas built on macOS and will not match the Linux reproducible build. Replace it with CI'sreproduced-browser-assetsartifact and update the digest inpolkavm-host-runtime-assets/src/lib.rs.🤖 Generated with Claude Code