Repository navigation
Implement File System Access pickers and handles over AppScene native panels #248
Description
Activity
- addedvscode-oss/plannedPlanned for the AppScene/WebScene VS Code OSS integrationPlanned for the AppScene/WebScene VS Code OSS integration
on Sep 17, 2026 Hierarchy audit keeps this issue as the browser-facing half of SceneTech/AppScene#123 and avoids folding in remote workspace behavior from #247/#252.
The File System Access contract should explicitly cover option/accept-type validation, transient user activation, cancel as
AbortError, denied/stale grants,queryPermission/requestPermission, same-entry identity,isSameEntry, file snapshots, directory iteration/order, nested handle lookup/create/remove/resolve, writablekeepExistingData, seek/truncate/close/abort, atomic replacement, concurrent writers, disconnect, and explicit handle release. Persisted handles must remain origin/profile scoped and must not serialize an ambient raw path.Qualify main and admitted nested realms, extension
showOpenDialog/showSaveDialogconsumers, local Save As from #269, and transfer flows owned by AppScene#32. Include Unicode/normalization, packages/symlinks, empty/binary/large streamed files, long names, multi-select, overwrite/errors, navigation/restart, and revoked/moved targets. Link shared WPT ledger #263, visual #259, accessibility #262, mutation/RSS #258, broad workbench #260, and Release #130 rather than duplicating those harnesses.The first #248 stack entry is open as PR #291 from rebased commit
5c85bbb1on currentmain4040058e.This entry is intentionally the transport/broker foundation only: additive v2 open-file/open-directory/save-file request/result structs, bounded validation, opaque initial/grant identifiers, exact-ID and exactly-once completion, reentrancy, and document/runtime retirement. The v1 byte service is unchanged.
Focused evidence passes: full V8 dylib build, C11 header compile, Node export audit plus actual dylib symbols, five direct contract runs, ASan/UBSan, and 10,000 lifecycle cycles in 6.47 ms with zero retained broker bytes at every checkpoint.
The dependent child branch is now implementing browser File System Access producers and opaque handles. AppScene #123 retains native panel, grant, bookmark, and filesystem authority ownership.
AppScene dependency update: SceneTech/AppScene#153 merged through SceneTech/AppScene#154 as AppScene main
2a3f9e0d1482e33440f7293627a787193764ccce.The native Cocoa authority now provides a versioned, main-thread
is_same_entryquery over two live opaque grants. It compares a private cross-volume filesystem identity captured at grant creation, returns only a boolean, performs no lookup I/O, and fails closed for malformed, foreign, released, identity-unavailable, off-main, or retired grants. Repeated selections, Unicode/hard-link entries, and directory-derived child grants are covered.This removes the AppScene authority gap for #248's
FileSystemHandle.isSameEntry()wiring. WebScene still owns the browser-facing operation/transport and should consume the new installed SDK contract without comparing random grant bytes or exposing paths/bookmarks.Native-parent status: SceneTech/AppScene#123 is complete and closed after its final audit. AppScene main
2a3f9e0d1482e33440f7293627a787193764cccenow contains the complete typed panel/opaque-grant authority: presentation lifecycle, security-scoped issuance/release, reads, paged directory and derived grants, atomic writers, and same-entry identity.This does not close #248. Browser-facing handles, origin/profile persistence, permission behavior, and restart/reopen semantics remain here. If that design proves it needs an additional native restoration primitive, it should be split from this issue's concrete browser contract rather than inferred or duplicated in the completed AppScene panel surface.
Merged focused identity slice via PR #353 as
bdf9e8791650e95e5ade19a75357396f19060060from exact heade33f95524950ec335d3bd0cbe04d8c5800f98bf3, rebased oncc18b9337374ea6aadc570280d503547f3621497.The reproduced defect was token equality in
FileSystemHandle.isSameEntry(): repeated selections of one native entry receive different random grants and incorrectly compared false. The merged bridge sends two bounded closure-private tokens to the native authority and receives only admitted/same booleans. Denial, malformed completion, navigation, and teardown fail closed; paths, bookmarks, filesystem identifiers, and platform objects never enter JavaScript.Retained evidence:
- exact-head Linux X64 and macOS ARM64 build/test: PASS;
- Chrome 153 WPT-derived identical/repeated/different/file-vs-directory oracle: 4/4;
- native picker/identity lifecycle: 100 cycles in 0.509 s, V8 heap +751,468 B, external +0, RSS +1,327,104 B, queues drained;
- portable broker: 10,000 cycles in 1.50 ms, RSS +98,304 B, FD delta 0, retained bytes 0;
- ASan/UBSan, C11 public header, Objective-C++ adapter against AppScene
2a3f9e0d, ABI architecture 9/9, dylib exports, and portable ABI surface audit: PASS.
#248 remains open for content/directory/writer operations, persistence, and packaged unchanged-consumer acceptance.
Remaining browser-operation audit on WebScene
bdf9e8791650e95e5ade19a75357396f19060060against AppScene2a3f9e0d1482e33440f7293627a787193764ccce:FileSystemHandle:kind/name, capability-derived permission queries, and native-authorityisSameEntry()are present. Structured-clone/IndexedDB persistence, authority restart restoration, revocation/re-prompt, and explicit grant release remain.FileSystemFileHandle:getFile()andcreateWritable()are stubs. AppScene already exposes bounded offset reads with byte count/modification time and atomic writer transactions for existing grants.FileSystemDirectoryHandle: async iteration, child lookup, removal, andresolve()are stubs. AppScene paging can supply deterministic existing-child iteration/derived grants. Native create/delete and durable ancestry/restoration contracts are not present and must not be inferred from capability bits.- Picker presentation/opaque handle issuance is merged; packaged persistence/reopen remains separate acceptance.
The smallest high-value next slice is
FileSystemFileHandle.getFile(). Unchanged VS Code 1.137 calls it for stat, full reads, read streams, rename/copy, and local-search content. The implementation will use sequential bounded native offset reads, validate stable metadata across chunks, resolve a snapshotFilewith name/size/lastModified/content, map cancellation/denial/not-found/I/O to DOMException classes, and retire pending work on navigation/teardown. It will not expose a path or infer filesystem authority in JavaScript.Oracle/contract sources are pinned WPT
fs/script-tests/FileSystemFileHandle-getFile.jsat2c705104a295c48053eeddf7fe0170d790a4e853plus a direct Chrome 153 OPFS run. Native tests will cover empty/binary/Unicode/chunked files, metadata mutation, offset/eof/status validation, malformed/oversized completion, exact-once/stale completion, 100 lifecycle cycles, 10,000 broker operations, FD/RSS/heap/queue bounds, sanitizer, C11/ABI/export, and an Objective-C++ adapter compile against the installed AppScene surface.#248 already names
getFileand streaming reads, so no duplicate child issue is needed. Active #237/#312/#348 paths are disjoint. PR #350 currently owns central runtime/ABI files; this slice will integrate only after that clean PR lands or otherwise no longer overlaps.Merged the focused
FileSystemFileHandle.getFile()slice through PR #360 as379a72dd3b8c9faa487b20ce44f6baad84ebb013from exact head71e601c3ec5e351ba46daa9eea025b36058bbb98, rebased on69d929f6.The browser layer now reads AppScene-compatible opaque grants through a bounded v2 range ABI and returns lazy snapshot
Fileobjects with metadata, binary/text reads, exact slices, and 64 KiB backpressured streams. Every chunk revalidates exact nanosecond metadata; mutation maps toNotReadableError. Cancellation, denial, missing files, and I/O map to the browser DOMException classes. Write-only grants fail before native dispatch, and navigation/teardown retires requests exactly once.Retained evidence:
- exact-head Linux X64, macOS ARM64, native Linux document, and portable V8 runners: PASS;
- Chrome 153 WPT-derived oracle: 4/4 subtests in 120 ms, result SHA-256
e7bc1f0803a46138a5351cff497cf17085cf8a5a4181f0298bba6f11045835ab; - native File System Access profile: 4/4; 100 picker/read cycles in 0.79 s, +756,880 B V8 heap, +540,672 B peak RSS, queues drained;
- broker: 10,000 reads in 7.4 ms Release / 11.8 ms ASan+UBSan, zero FD growth, zero retained bytes;
- C11 header, actual dylib exports, portable ABI allowlist, and Objective-C++ adapter against AppScene
2a3f9e0d: PASS.
#248 remains open. The remaining independently reviewable work is
createWritable(), existing-child directory iteration/lookup/resolve, explicit grant release, origin/profile persistence and restart restoration, then packaged unchanged-consumer acceptance. Native create/delete/restoration must stay separate unless AppScene adds those authority contracts.createWritable()bounded-slice audit on WebScene main379a72dd3b8c9faa487b20ce44f6baad84ebb013against AppScene main2a3f9e0d1482e33440f7293627a787193764ccce:- Native authority is sufficient: AppScene's installed v2 contract already owns opaque
BEGIN/CHUNK/COMMITtransactions plus explicit abort. It creates a private sibling, accepts bounded offset chunks, truncates to the committed length, fsyncs, revalidates target identity, atomically replaces, directory-syncs, and drains on cancellation/release/retirement. No path, bookmark, descriptor, or platform object needs to enter WebScene or JavaScript. - This slice will add only the product-neutral WebScene write request/completion ABI and broker, runtime
FileSystemWritableFileStream,createWritable({keepExistingData}), orderedwrite/seek/truncate/close/abort, chunking, native status-to-DOMException mapping, and navigation/teardown retirement.keepExistingDatawill snapshot through the already-merged bounded read bridge before opening/writing the native transaction. - The browser contract will follow the pinned WPT
FileSystemWritableFileStream*.jsbehavior and a direct Chrome oracle: atomic visibility on close, zero-fill gaps, cursor/truncate behavior, supported byte/string/Blob/command inputs, queued operations, one terminal close, and abort preserving the original. This slice does not claimmode: "exclusive"locking because AppScene's contract intentionally permits concurrent atomic writers; unsupported mode values will reject instead of inventing a lock authority. - Gates: direct broker contracts including malformed/stale/exactly-once cases and 10,000 operations; native runtime correctness/lifecycle/heap/RSS/FD/queue drain; WPT-derived Chrome oracle; ASan/UBSan; strict C11 header; exported-symbol and portable ABI audits; Objective-C++ layout/adapter compile against AppScene
2a3f9e0d.
Current open PR collision audit is clear for focused implementation paths: #361 is CSSOM-only and #354 is ServiceWorker/parser-test-only. Draft consolidation #76 remains untouched. This branch will not change AppScene, CSS, ServiceWorker/parser paths, vscode-demo docs/PR #1, directory operations, persistence/restart authority, or packaged Code OSS acceptance.
- Native authority is sufficient: AppScene's installed v2 contract already owns opaque
Merged the focused
FileSystemFileHandle.createWritable()slice through PR #363 as WebSceneb6dfb66051e417fecb328da6639d7dfce7f251eefrom exact head4ab5f1e30e3fefdb7ed3cf61c0fbc7c691d27215, based on15d55a4c.The browser runtime now exposes
FileSystemWritableFileStreamover a bounded opaque write ABI: begin, 1 MiB offset chunks, 1 GiB transaction limit, atomic commit, and explicit abort. It implements ordered string/Blob/BufferSource/command writes,seek(),truncate(),keepExistingData, zero-filled gaps, one terminal close, concurrent siloed writers, DOMException status mapping, and navigation/teardown retirement.mode: "exclusive"fails explicitly because AppScene provides atomic concurrent transactions but no lock authority. Paths, bookmarks, descriptors, temporary names, and platform objects remain native-only.Retained evidence:
- exact-head Linux X64, macOS ARM64, portable real-V8, and native Linux document/independent SDK checks: PASS;
- Chrome 153 WPT-derived IDL/writer oracle: 2/2 documents, 9/9 subtests; result SHA-256
6e276e73749716aa3f4beb89edae4ef179aeafd27c0c27678feba0130ff3ec5a; - release broker: 10,000 operations in 0.0125 s, RSS +114,688 bytes, FD delta 0, retained bytes 0;
- ASan/UBSan, strict C11 layout, portable ABI allowlist, actual dylib exports, and Objective-C++ adapter/layout compile against AppScene
2a3f9e0d: PASS; - native runtime contract includes functional write/seek/truncate/abort/keepExistingData/error cases, 100 read/write lifecycle cycles, queue drain, navigation retirement, and heap/external/RSS budgets.
Redundant pre-rebase, pre-final-head, post-merge, NuGet, and unrelated NativeAOT tail runs were canceled after the four directly related exact-head checks passed.
#248 remains open. Independently reviewable remaining work is existing-child directory iteration/lookup/resolve, explicit grant release, origin/profile persistence and restart restoration, then packaged unchanged-consumer acceptance. Native create/delete/restoration and exclusive-lock authority remain out of scope unless AppScene adds those contracts.
Next bounded #248 slice starts from exact WebScene
b6dfb66051e417fecb328da6639d7dfce7f251eeand consumes exact AppScene2a3f9e0d1482e33440f7293627a787193764ccce.The native audit confirms #138/#139 already provides the required authority for deterministic, bounded directory pages: at most 32 entries/page, 10,000 entries and 1 MiB names/snapshot, no-follow validation, mutation detection, explicit operation cancellation/cursor release, narrowed capabilities, and a fresh opaque child grant per verified regular file/directory. WebScene can therefore add a generic directory-page ABI/broker and expose
FileSystemDirectoryHandle[Symbol.asyncIterator],entries(),keys(),values(),getFileHandle(name, {create:false}), andgetDirectoryHandle(name, {create:false}). Each iterator owns one snapshot/cursor, fetches lazily, releases on early return, and converts only native metadata plus derived grants into canonical browser handles. Lookup validates a single component, scans bounded pages, releases promptly on match/exhaustion, and maps missing/wrong-kind/native status to browser-compatibleNotFoundError,TypeMismatchError,NotAllowedError,InvalidStateError, orAbortError.Native create/delete authority is absent.
{create:true}andremoveEntry()remain explicitly unavailable and dispatch no filesystem mutation.resolve()also remains unavailable: AppScene grant records do not preserve an authority-bound ancestry relation after enumeration, so JavaScript traversal history cannot correctly resolve independently selected/restored descendants. The focused native gap is tracked in SceneTech/AppScene#156 rather than inferring paths or ancestry in WebScene.Evidence will include WPT-derived iteration/lookup contracts and a Chrome oracle; native functional, malformed/cross-scope/stale/mutation/cancellation/early-return/retirement coverage; 10,000 broker operations, maximum 10,000-entry paging, 100 lifecycle cycles, RSS/FD/retained-state bounds; ASan/UBSan; strict C11 layout; portable ABI allowlist and actual exports; and an Objective-C++ adapter compile against AppScene
2a3f9e0d.Collision audit: active #365 owns only CSSOM files and draft #76 owns only
docs/code-oss-compatibility.md. This slice will not modify AppScene, CSS, #266 resource/ServiceWorker/parser paths, consolidation #76, vscode-demo files/docs/PR #1, persistence/restart restoration, packaged Code OSS acceptance, or create/delete/path authority.Merged the focused existing-child directory slice through PR #367 as WebScene
d521dd05f217eb1a43604b357346197d60b5b294, from exact head2aa91643d0016660281b5dd87a302c6a1f9e9f96on exact basec4c4ac915918d44919d573539e89e7ace551aa5c.The browser runtime now exposes lazy
FileSystemDirectoryHandleasync iteration (@@asyncIterator,entries,keys, andvalues) plusgetFileHandle/getDirectoryHandlefor existing children. A generic bounded v2 ABI/broker transports AppScene's deterministic 32-entry pages, accepts at most 10,000 entries per snapshot, creates canonical browser handles only from fresh opaque derived grants, maps native failures to browser errors, and explicitly releases unfinished native cursors after successful lookup or early iterator return. Navigation and teardown cancel pending promises and drain broker state.Native create/delete authority is still absent, so
{create:true}andremoveEntry()remain unavailable.resolve()also remains unavailable because AppScene does not retain authority-bound ancestry for independently selected/restored grants; the missing native contract is tracked as SceneTech/AppScene#156, nested under AppScene#123.Retained evidence:
- exact-head Linux X64, macOS ARM64, portable real-V8, and native Linux document/independent SDK checks: PASS;
- Chrome 153 WPT-derived IDL/iteration/lookup oracle: 2/2 documents, 9/9 subtests; result SHA-256
824276c8ba1d6376a274cbd45a5762a6d2b0b5c488785b5dfc562bf482366832; - release broker: 10,000 operations in 0.0011 s, RSS +114,688 bytes, FD delta 0, retained input bytes 0; 100 retirement cycles drain;
- ASan/UBSan broker: PASS, 10,000 operations in 0.0079 s, RSS +4,636,672 bytes, FD delta 0, retained input bytes 0;
- strict C11 ABI layout, actual dylib exports, portable ABI allowlist, and Objective-C++ adapter/layout compile against AppScene
2a3f9e0d: PASS; - native real-V8 contract covers two-page and 10,000-entry iteration, existing/missing/wrong-kind lookup, invalid/create/resolve authority boundaries, explicit early/match cursor release, six native status mappings, 100 lifecycle cycles, and navigation retirement.
#248 remains open for native create/delete/resolve authority, explicit grant release, origin/profile persistence and restart restoration, and packaged unchanged-consumer acceptance. Redundant superseded-head, NuGet, NativeAOT tail, and post-merge runs were canceled after the four directly related exact-head checks passed.
Starting the next bounded slice in child #370 from exact
d521dd05f217eb1a43604b357346197d60b5b294.Audit result:
FileSystemHandle.release()is not a browser API (Chrome 153 reportsundefined), so this slice will not add one.- WebScene currently retains every wrapper in a strong
Mapand never invokes AppScene's existingappscene_file_panel_cocoa_release_grant_v2contract. - V8 currently clones handles as empty plain objects because only
MessagePortis registered as a clone host object. - Chrome/WPT require a distinct branded same-entry handle after structured clone, with deserialization limited to the same storage origin.
- IndexedDB persistence requires an origin/profile-bound durable locator. Raw live grant tokens are process-local and must not be persisted. Missing native authority is now isolated in AppScene#157, attached under AppScene#123.
Collision-free implementation scope: weak V8 handle bindings; a shared grant owner retained by live wrappers and in-flight clone packets; same-origin transient structured clone; deterministic realm/navigation retirement; and one bounded native release request when the final owner disappears. This includes the public ABI, generic broker, exports, AppScene release-adapter compile gate, Chrome/WPT/security/lifecycle tests, 10k broker coverage, 100 realm cycles, and memory/FD gates.
Excluded: IndexedDB durable persistence pending AppScene#157, explicit JS release, path exposure, creation/deletion/resolve authority, AppScene source, resources (#364), CSS (#366), #156 ancestry, consolidation #76, and vscode-demo files.
Oracle: Chrome
153.0.8010.50produced distinct[object FileSystemFileHandle]clones withisSameEntry() === true, no enumerable own keys, and norelease; the CDP probe source hash is88b4607a849d1122f475e90f08a94fee15d36ea443dc100fefe75d9fab81ea6c.8 remaining items
PR #390 merged at 2ffb0dc (exact reviewed head ca784cc). FileSystemHandle values now persist through IndexedDB via partition/origin-bound opaque locators, restore as fresh realm-bound grants after engine restart, and revoke on replacement/deletion. Retired navigation generations reject stale completions.
Direct exact-head checks passed: Linux X64, macOS ARM64, portable V8, and native Linux document contracts. Chrome 153 WPT-derived oracle, real-V8 restart lifecycle, exact AppScene aadf606d adapter, strict C11 ABI/exports, 10,000-cycle memory/FD gate, and ASan/UBSan also passed. Child #382 is complete.
#394 is attached as the next bounded File System Access child from exact main 2ffb0dc and AppScene aadf606ddf7a1cc1c4e3bbe8aefd46219cbbfbfd.
Audit result: getFile/createWritable, existing-child directory operations, resolve, weak ownership, and durable IndexedDB restoration are merged. Entry create/delete/remove/move remains blocked because AppScene exposes capability bits but no typed mutation operation; this slice will not infer one. The smallest unblocked defect is permission overclaim: readwrite currently succeeds from any write-like bit without also requiring read authority.
#394 owns only capability-exact queryPermission/requestPermission states, WebIDL-shaped descriptor/receiver behavior, clone and durable-restore parity, and focused browser/native lifecycle evidence. AppScene grants remain terminal granted/denied decisions; no prompt/elevation authority is invented. Active #392 History, #391/#388 resources, CSS work, #76, AppScene, and vscode-demo are disjoint and excluded.
Permission leaf #394 is complete via PR #395, merged at 7438a60 (head 6301d6c). Exact grant capabilities now control queryPermission/requestPermission across live, cloned, and durable-restored handles; unsupported descriptor modes reject and terminal decisions never invent native elevation. Linux, macOS, portable V8, NativeAOT 11/12, native-document, Chrome 153 (2/2), ABI/C11, durable restore, and bounded lifecycle/performance gates are green. The remaining save-picker READ authority is isolated in SceneTech/AppScene#160 under AppScene #123.
Native save-picker authority prerequisite SceneTech/AppScene#160 is complete via AppScene PR #161 at 07e980f30872b7eb5f59df6fff616af1eb51b1ac. Successful save grants now carry READ | WRITE | CREATE, matching WebScene permission semantics merged in #395. Existing targets are readable, new targets report not-found, and opaque lifecycle/security/performance/ABI gates are green.
Next bounded slice: file child creation
Audit baseline: WebScene
9378075872bf1a5ebf66a1b1a194bd5cbc5e0614, AppScene07e980f30872b7eb5f59df6fff616af1eb51b1ac, pinned WPT2c705104a295c48053eeddf7fe0170d790a4e853.The first missing typed authority is an atomic opaque-directory
get or create file childoperation. Current WebScene already supports existing-child lookup but rejects every{create:true}call; AppScene exposesCREATEas a capability but has no operation that may exercise it. VS Code's browser filesystem provider callsparent.getFileHandle(name, {create:true})beforecreateWritable()for new files, and browser download export uses the same path.WPT requires a missing child to become an empty file, an existing file to retain its contents, and a directory collision to reject with
TypeMismatchError. The native operation therefore must decide lookup/create atomically beneath the parent grant; JavaScript will not synthesize path or mutation authority.Tracked stack:
- SceneTech/AppScene#162: typed bounded get-or-create file-child ABI and Cocoa authority.
- Create file children through opaque directory grants #400: runtime/broker/adapter/browser surface, attached here.
The slice excludes directory creation, removal, recursive deletion, move/rename, and #131/#252 package work. Gates cover WPT/Chrome semantics, C11/export/adapter parity, origin/profile/partition isolation, cancel/stale/retire behavior, 10k bounded operations, and 100 lifecycle cycles with heap/RSS/FD bounds.
File-child creation slice #400 is complete: PR #406 merged as
ad33c45305f4cabbb87d378686539d39efb606c5, consuming AppScene#162/#163 (d63d6b4bc6105ee34e9845c1017125e9382d48c3).FileSystemDirectoryHandle.getFileHandle(name,{create:true})now uses typed opaque parent authority, returns a derived browser handle without exposing paths/bookmarks/native objects, preserves existing contents, maps native failures, cancels on navigation, and releases the derived grant exactly once. Exact-head Linux, macOS, portable V8, native-document, and AOT 11/12 passed; Chrome 153 oracle passed 3/3; local 10k broker and 100-cycle RSS/heap/FD gates passed.Next dependency-ordered directory mutation audit\n\nBaseline: WebScene
ad33c45305f4cabbb87d378686539d39efb606c5, AppScenecac13616eb4f291f7cef44c5b8480b4a7a37ce3, pinned WPT2c705104a295c48053eeddf7fe0170d790a4e853. Open PR paths are disjoint (#408 CSS only; #76 docs only).\n\nThe smallest complete remaining capability isFileSystemDirectoryHandle.getDirectoryHandle(name,{create:true}). It directly unlocks unchanged VS CodehtmlFileSystemProvider.mkdir()and recursive browser folder export infileImportExport.ts; removeEntry would unlock delete and file rename later, while handle move/rename does not serve the provider path. WPT requires missing-directory creation, existing-content preservation, file collision asTypeMismatchError, and invalid component names asTypeError. Chrome 153.0.8010.50 passes the focused reduction 3/3 in 128 ms; result SHA-256837bedb8a5065b5b3bf10a6a287f6c4b19203f33965a5f2cb1d47975c4900c70.\n\nThe native authority audit found a hard dependency: AppScene exposes paged read-only enumeration and get-or-create file child operations only. It has no typed directory create, remove, or move operation. Capability bits alone cannot authorize filesystem mutation, and WebScene cannot safely synthesize paths or creation in JavaScript.\n\nTracked stack: SceneTech/AppScene#168 (attached directly under open AppScene#122) and WebScene #409 (attached here). #409 is intentionally blocked until #168 supplies the opaque atomic authority; no WebScene runtime branch will invent native mutation authority. This respects the requested AppScene code-path exclusion while preserving dependency order.Merged directory-child creation slice via #415 at
fbc1f99cc74d83160dc18abd7e9833b54a104cf7(dependent AppScene authority: SceneTech/AppScene#169, merged4a738883464077767efff69e9848a99fe47c768).FileSystemDirectoryHandle.getDirectoryHandle(name, { create: true })now uses the typed bounded broker and returns a derived opaque directory grant, with browser error mapping and stale-navigation retirement. Exact-head Linux, macOS, NativeAOT 11/12, and portable-V8 gates passed; local C11/ABI/export/runtime, 10k broker, 100-cycle lifecycle, heap/RSS/FD, and Chrome 153 3/3 oracle gates passed. #409 closed.Resync against WebScene
fc71e92fand AppScened4a73888found one remaining generic File System Access operation exercised by unchanged VS Code:FileSystemDirectoryHandle.removeEntry(). The browser filesystem provider uses it for ordinary delete and for the removal half of copy/delete rename. This work stays outside MessagePort #288, webviews/resources #266, consolidation PRs #65/#76, packaging, andvscode-demo.The native prerequisite is complete: AppScene #170 / PR SceneTech/AppScene#171 merged as
eef005596716174594e9ec74966b89a0aba99a10. Focused WebScene PR #435 now consumes that exact typed authority.Current cumulative evidence:
- strict request layout/status/cap parity against the merged AppScene header;
- native C11 ABI, exported-symbol and binary interop checks;
- V8 runtime/native-engine translation-unit compilation plus portable library build;
- permission/status mapping, malformed and duplicate rejection, exact-once completion, navigation/teardown cancellation;
- 10,000 optimized operations: 0.0012 s, RSS +65,536 bytes, FD delta 0;
- 10,000 ASan/UBSan operations: 0.0085 s, RSS +3,719,168 bytes, FD delta 0;
- 100 broker lifecycle cycles return to zero queued/pending/retained state;
- direct Chrome 153 oracle passes all 4/4 focused cases.
The browser oracle is pinned to WPT
FileSystemDirectoryHandle-removeEntry.jsat2c705104a295c48053eeddf7fe0170d790a4e853. The March 2026 WHATWG living text now treats a missing entry as success, while that WPT revision and Chrome 153 returnNotFoundError; #429 and PR #435 preserve the pinned Chromium behavior used for this compatibility slice.Completed: focused PR #435 merged as
6e27f2b9305bcbe8202c3c451a31172661025fc2from exact reviewed heada28754298c29fd4159a10f14ebf36951056f795dafter the directly affected hosted macOS ARM64 gate passed. The broad queued/tail CI, package, Linux-document, and portable-V8 runs were cancelled after merge under the fast-merge policy; cumulative local V8/portable/ABI/sanitizer/performance/lifecycle evidence remains recorded above and on the PR.Together with AppScene
eef005596716174594e9ec74966b89a0aba99a10, unchanged VS Code now has the genericremoveEntry()delete primitive and copy/delete rename removal path. #429 closed with the merge.Implementation-first re-audit at WebScene
59d143e1confirms every generic picker/handle operation used by unchanged Code OSS is already merged, including removeEntry (#435) and FileSystemObserver (#438). Remaining work is packaged unchanged-consumer/local-save acceptance coordinated with #269/#260; no additional transport or authority mutation is justified. No code or validation was run.
Active implementation checkpoint — 20 September 2026
Exact merged heads are WebScene
ca4b6b4ba2a6699970ee78b2b8acc795dc968e77, AppScene724bf58bd56951e5c102db256ccb220964fa90ae, and unchanged Code OSS645f29cc3176500b4b5762ba887cf2a7f0ffdf2c. Local vscode-demo isc8ce793d, intentionally unpushed, with Actions disabled. One-agent mode remains active.Linux workspace stack merged
The dependent GitHub stack is complete and merged bottom-to-top:
1321ecc1: complete linked WebScene v2 panel/grant ABI with one fail-closed family capability.4295d7da: bounded Linux opaque grant authority for same-entry, ancestry, ranged reads, atomic writes, paged directory operations, create/remove, durable partition/origin-bound locators, and release.724bf58b: XDG Desktop Portal open-file/open-folder/save-file integration, filters/options/initial location, capability grants, queue wakeup, profile storage, cancellation, and teardown.This reusable SDK implementation requires no Code OSS source change and adds no Electron, Chromium, CEF, WebView, GTK, shell, or helper-process dependency. Source, ABI, package, lifecycle, adversarial-path, bounded-memory, latency, idle-CPU, and unchanged-product gates are committed and documented. They were intentionally not executed under the fast implementation instruction. PR checks reported failures before the admin merges; no pass is claimed. Obsolete PR jobs were canceled. The newest AppScene
mainLinux SDK run35498051568also completed with failure, and no CI jobs remain queued. AppScene #318 is the native sub-issue for focused CI repair.Consolidation status
Focused implementations are on their main branches. Consolidations remain open and unmerged: WebScene PR #76 at
3ed3a70cddb216ecf89dbefdbf59ab447fafdb9a, AppScene PR #65 refreshed at3a92b02, and vscode-demo PR #1. The local demo submodule points to AppScene724bf58b, WebSceneca4b6b4b, and unchanged Code OSS645f29cc; local commitc8ce793dis not pushed.Remaining order
.asprojanddoctor/build/run/publish, including relocatability, dependency, disk-size, and fail-closed gates.Cross-repository parent epic: SceneTech/AppScene#122
Native host capability: SceneTech/AppScene#123
Related broad platform scope: SceneTech/AppScene#32
Problem
Unchanged VS Code browser and extension consumers use
showOpenFilePicker,showDirectoryPicker,showSaveFilePicker,FileSystemFileHandle, andFileSystemDirectoryHandlewhen operating on localfile:resources. WebScene does not expose the complete File System Access contract and AppScene currently has no typed native panel request, so local open/save and extension dialog calls cannot complete without an application patch.The remote
SimpleFileDialogpath is tracked separately and remains the first VS Code workspace path. This issue owns the reusable browser API layer over the native capability from AppScene#123.Proposed implementation
kind/name,getFile, writable streams, directory iteration, relative resolution, permission query/request, and explicit release semantics required by audited consumers.Acceptance
showOpenDialog/showSaveDialogplus local open/save without Electron or browser processes.Schedule
Agree the typed schema with AppScene#123 after the remote picker baseline is captured. Implement AppScene request/response and WebScene API as a two-PR dependent stack; validate the cumulative top, then merge the focused stack before consolidated product gates.