2.2 KiB
Mission Core Plugin SDK
This directory owns the versioned host/plugin contract. The v1alpha frontend contract, validated registry, generic runtime envelope, and backend read-only catalog are implemented in-tree, but this is not yet a separately published SDK package.
The v1alpha1 contract currently validates one model per plugin, one reviewed
transitional-in-process backend entrypoint, a required safe state.read
action, and declared UI/action metadata. It establishes:
- plugin manifest, version compatibility, firmware profiles, and declarative permissions;
- discovery candidates and opaque device references;
- provisioning requests using secret references;
- device-session lifecycle and health;
- EvidenceStore handles and raw-artifact lineage;
- canonical PointCloud, Pose, DeviceStatus, and metrics envelopes;
- SceneSink and event interfaces;
- capability-driven UI contribution data without plugin-owned layout.
The XGRIDS K1 extraction is the first real-device acceptance path. Synthetic multi-plugin composition tests verify that backend routing has no K1 identity or protocol assumption; static boundary tests enforce the same rule in the frontend.
Current implementation references:
apps/control-station/src/core/device-plugins/— TypeScript manifest and UI contribution contracts;apps/control-station/src/core/runtime/— normalized runtime envelope;src/k1link/web/plugin_catalog.py— strict backend manifest validation;src/k1link/web/plugin_runtime.py— host-owned allowlisted action dispatcher;src/k1link/web/device_plugin_composition.py— manifest factory loader and startup parity check between catalog and executable adapters;docs/adr/0003-device-plugin-ui-and-runtime-boundary.md— accepted boundary and extraction sequence.
The v1alpha lifecycle is fail-closed: inactive provider shells must perform no
I/O, events are scoped by plugin ID, and selection cannot change until the
active plugin confirms teardown. Process isolation and independent device
session IDs remain the next SDK milestone. permissions, mutating, and
secretFields are contract metadata only in v1alpha1; host authorization and
secret-vault enforcement are not implemented yet.