Skip to content

Implement File System Access pickers and handles over AppScene native panels #248

Description

@wieslawsoltes

Active implementation checkpoint — 20 September 2026

Exact merged heads are WebScene ca4b6b4ba2a6699970ee78b2b8acc795dc968e77, AppScene 724bf58bd56951e5c102db256ccb220964fa90ae, and unchanged Code OSS 645f29cc3176500b4b5762ba887cf2a7f0ffdf2c. Local vscode-demo is c8ce793d, intentionally unpushed, with Actions disabled. One-agent mode remains active.

Linux workspace stack merged

The dependent GitHub stack is complete and merged bottom-to-top:

  1. AppScene Intercept parser and nested-frame resources through Service Workers #312 / PR Batch mutable stylesheet publication #315 → merge 1321ecc1: complete linked WebScene v2 panel/grant ABI with one fail-closed family capability.
  2. AppScene Generate shared CSS property identity metadata #313 / PR Generate native CSS property identity #316 → merge 4295d7da: bounded Linux opaque grant authority for same-entry, ancestry, ranged reads, atomic writes, paged directory operations, create/remove, durable partition/origin-bound locators, and release.
  3. AppScene Restore CSS property metadata generator #314 / PR Generate native CSS grammar families #317 → merge 724bf58b: XDG Desktop Portal open-file/open-folder/save-file integration, filters/options/initial location, capability grants, queue wakeup, profile storage, cancellation, and teardown.

This reusable SDK implementation requires no Code OSS source change and adds no Electron, Chromium, CEF, WebView, GTK, shell, or helper-process dependency. Source, ABI, package, lifecycle, adversarial-path, bounded-memory, latency, idle-CPU, and unchanged-product gates are committed and documented. They were intentionally not executed under the fast implementation instruction. PR checks reported failures before the admin merges; no pass is claimed. Obsolete PR jobs were canceled. The newest AppScene main Linux SDK run 35498051568 also completed with failure, and no CI jobs remain queued. AppScene #318 is the native sub-issue for focused CI repair.

Consolidation status

Focused implementations are on their main branches. Consolidations remain open and unmerged: WebScene PR #76 at 3ed3a70cddb216ecf89dbefdbf59ab447fafdb9a, AppScene PR #65 refreshed at 3a92b02, and vscode-demo PR #1. The local demo submodule points to AppScene 724bf58b, WebScene ca4b6b4b, and unchanged Code OSS 645f29cc; local commit c8ce793d is not pushed.

Remaining order

  1. AppScene Audit CSS property metadata completeness #318: repair the recorded project-policy and Linux SDK CI failures at one exact main head. Then AppScene Implement effective CSS property cascade semantics #305 and WebScene Publish installed full-V8 Runtime components for Linux and Windows #809 execute the retained installed-package, portal/grant, Ubuntu VM, visual, lifecycle, memory, performance, idle-frame, and unchanged Code OSS workspace/Explorer/open-edit-save-restart gates.
  2. AppScene Make retained inset parsing portable on macOS #306: publish the installed Win32/D3D12/Graphite Runtime host and desktop services.
  3. AppScene Split IndexedDB bootstrap below the MSVC literal limit #307: publish multi-RID Runtime components through .asproj and doctor/build/run/publish, including relocatability, dependency, disk-size, and fail-closed gates.
  4. vscode-demo Implement Windows DirectWrite font positioning #12: build Release packages and qualify workspace/Explorer, terminal latency, Markdown/webviews, visual geometry, accessibility, input, CSS/product performance, memory, lifecycle, package size, and recursive no-browser evidence.
  5. Keep CSS [Epic] CSS features, compatibility, validation, and performance #235, file API Implement File System Access pickers and handles over AppScene native panels #248, Runtime package [Epic] Restore full V8 Linux and Windows package portability #687/Publish installed full-V8 Runtime components for Linux and Windows #809, and all coordination epics synchronized as new evidence or reduced defects appear.

Cross-repository parent epic: SceneTech/AppScene#122
Native host capability: SceneTech/AppScene#123
Related broad platform scope: SceneTech/AppScene#32

Problem

Unchanged VS Code browser and extension consumers use showOpenFilePicker, showDirectoryPicker, showSaveFilePicker, FileSystemFileHandle, and FileSystemDirectoryHandle when operating on local file: resources. WebScene does not expose the complete File System Access contract and AppScene currently has no typed native panel request, so local open/save and extension dialog calls cannot complete without an application patch.

The remote SimpleFileDialog path is tracked separately and remains the first VS Code workspace path. This issue owns the reusable browser API layer over the native capability from AppScene#123.

Proposed implementation

  • Implement the three picker entry points with secure-context/user-activation checks, options validation, cancellation, and DOMException-compatible errors.
  • Add file and directory handles with stable identity, kind/name, getFile, writable streams, directory iteration, relative resolution, permission query/request, and explicit release semantics required by audited consumers.
  • Map only typed bounded data to AppScene#123; never expose Cocoa objects or Electron-shaped APIs to JavaScript.
  • Stream file reads/writes with backpressure and atomic save/replace behavior. Avoid whole-file and whole-directory copies when not required by the web contract.
  • Define persisted grants/bookmarks by origin/profile and reject stale or cross-origin handles.
  • Add WPT-derived contracts plus native mock-host integration and packaged unchanged-consumer tests.

Acceptance

  • Web-compatible open-file, open-directory, save-file, cancel, denial, and malformed-option behavior passes in main window, iframe, and extension-host consumer contexts where applicable.
  • Handles support the exact VS Code/extension calls discovered by the audit and remain stable across allowed persistence/reopen.
  • Text/binary files, Unicode names, empty files, large streamed files, nested directories, multi-select, overwrite, and failures preserve bytes and error classes.
  • User activation cannot be replayed and one request completes exactly once.
  • WPT/native/browser contracts pass with bounded memory, copied bytes, handles, requests, and latency.
  • Packaged acceptance proves extension showOpenDialog/showSaveDialog plus local open/save without Electron or browser processes.

Schedule

Agree the typed schema with AppScene#123 after the remote picker baseline is captured. Implement AppScene request/response and WebScene API as a two-PR dependent stack; validate the cumulative top, then merge the focused stack before consolidated product gates.

Activity

  1. wieslawsoltes commented on Sep 17, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Hierarchy audit keeps this issue as the browser-facing half of SceneTech/AppScene#123 and avoids folding in remote workspace behavior from #247/#252.

    The File System Access contract should explicitly cover option/accept-type validation, transient user activation, cancel as AbortError, denied/stale grants, queryPermission/requestPermission, same-entry identity, isSameEntry, file snapshots, directory iteration/order, nested handle lookup/create/remove/resolve, writable keepExistingData, seek/truncate/close/abort, atomic replacement, concurrent writers, disconnect, and explicit handle release. Persisted handles must remain origin/profile scoped and must not serialize an ambient raw path.

    Qualify main and admitted nested realms, extension showOpenDialog/showSaveDialog consumers, local Save As from #269, and transfer flows owned by AppScene#32. Include Unicode/normalization, packages/symlinks, empty/binary/large streamed files, long names, multi-select, overwrite/errors, navigation/restart, and revoked/moved targets. Link shared WPT ledger #263, visual #259, accessibility #262, mutation/RSS #258, broad workbench #260, and Release #130 rather than duplicating those harnesses.

  2. wieslawsoltes commented on Sep 17, 2026

    @wieslawsoltes
    CollaboratorAuthor

    The first #248 stack entry is open as PR #291 from rebased commit 5c85bbb1 on current main 4040058e.

    This entry is intentionally the transport/broker foundation only: additive v2 open-file/open-directory/save-file request/result structs, bounded validation, opaque initial/grant identifiers, exact-ID and exactly-once completion, reentrancy, and document/runtime retirement. The v1 byte service is unchanged.

    Focused evidence passes: full V8 dylib build, C11 header compile, Node export audit plus actual dylib symbols, five direct contract runs, ASan/UBSan, and 10,000 lifecycle cycles in 6.47 ms with zero retained broker bytes at every checkpoint.

    The dependent child branch is now implementing browser File System Access producers and opaque handles. AppScene #123 retains native panel, grant, bookmark, and filesystem authority ownership.

  3. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    AppScene dependency update: SceneTech/AppScene#153 merged through SceneTech/AppScene#154 as AppScene main 2a3f9e0d1482e33440f7293627a787193764ccce.

    The native Cocoa authority now provides a versioned, main-thread is_same_entry query over two live opaque grants. It compares a private cross-volume filesystem identity captured at grant creation, returns only a boolean, performs no lookup I/O, and fails closed for malformed, foreign, released, identity-unavailable, off-main, or retired grants. Repeated selections, Unicode/hard-link entries, and directory-derived child grants are covered.

    This removes the AppScene authority gap for #248's FileSystemHandle.isSameEntry() wiring. WebScene still owns the browser-facing operation/transport and should consume the new installed SDK contract without comparing random grant bytes or exposing paths/bookmarks.

  4. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Native-parent status: SceneTech/AppScene#123 is complete and closed after its final audit. AppScene main 2a3f9e0d1482e33440f7293627a787193764ccce now contains the complete typed panel/opaque-grant authority: presentation lifecycle, security-scoped issuance/release, reads, paged directory and derived grants, atomic writers, and same-entry identity.

    This does not close #248. Browser-facing handles, origin/profile persistence, permission behavior, and restart/reopen semantics remain here. If that design proves it needs an additional native restoration primitive, it should be split from this issue's concrete browser contract rather than inferred or duplicated in the completed AppScene panel surface.

  5. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Merged focused identity slice via PR #353 as bdf9e8791650e95e5ade19a75357396f19060060 from exact head e33f95524950ec335d3bd0cbe04d8c5800f98bf3, rebased on cc18b9337374ea6aadc570280d503547f3621497.

    The reproduced defect was token equality in FileSystemHandle.isSameEntry(): repeated selections of one native entry receive different random grants and incorrectly compared false. The merged bridge sends two bounded closure-private tokens to the native authority and receives only admitted/same booleans. Denial, malformed completion, navigation, and teardown fail closed; paths, bookmarks, filesystem identifiers, and platform objects never enter JavaScript.

    Retained evidence:

    • exact-head Linux X64 and macOS ARM64 build/test: PASS;
    • Chrome 153 WPT-derived identical/repeated/different/file-vs-directory oracle: 4/4;
    • native picker/identity lifecycle: 100 cycles in 0.509 s, V8 heap +751,468 B, external +0, RSS +1,327,104 B, queues drained;
    • portable broker: 10,000 cycles in 1.50 ms, RSS +98,304 B, FD delta 0, retained bytes 0;
    • ASan/UBSan, C11 public header, Objective-C++ adapter against AppScene 2a3f9e0d, ABI architecture 9/9, dylib exports, and portable ABI surface audit: PASS.

    #248 remains open for content/directory/writer operations, persistence, and packaged unchanged-consumer acceptance.

  6. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Remaining browser-operation audit on WebScene bdf9e8791650e95e5ade19a75357396f19060060 against AppScene 2a3f9e0d1482e33440f7293627a787193764ccce:

    • FileSystemHandle: kind/name, capability-derived permission queries, and native-authority isSameEntry() are present. Structured-clone/IndexedDB persistence, authority restart restoration, revocation/re-prompt, and explicit grant release remain.
    • FileSystemFileHandle: getFile() and createWritable() are stubs. AppScene already exposes bounded offset reads with byte count/modification time and atomic writer transactions for existing grants.
    • FileSystemDirectoryHandle: async iteration, child lookup, removal, and resolve() are stubs. AppScene paging can supply deterministic existing-child iteration/derived grants. Native create/delete and durable ancestry/restoration contracts are not present and must not be inferred from capability bits.
    • Picker presentation/opaque handle issuance is merged; packaged persistence/reopen remains separate acceptance.

    The smallest high-value next slice is FileSystemFileHandle.getFile(). Unchanged VS Code 1.137 calls it for stat, full reads, read streams, rename/copy, and local-search content. The implementation will use sequential bounded native offset reads, validate stable metadata across chunks, resolve a snapshot File with name/size/lastModified/content, map cancellation/denial/not-found/I/O to DOMException classes, and retire pending work on navigation/teardown. It will not expose a path or infer filesystem authority in JavaScript.

    Oracle/contract sources are pinned WPT fs/script-tests/FileSystemFileHandle-getFile.js at 2c705104a295c48053eeddf7fe0170d790a4e853 plus a direct Chrome 153 OPFS run. Native tests will cover empty/binary/Unicode/chunked files, metadata mutation, offset/eof/status validation, malformed/oversized completion, exact-once/stale completion, 100 lifecycle cycles, 10,000 broker operations, FD/RSS/heap/queue bounds, sanitizer, C11/ABI/export, and an Objective-C++ adapter compile against the installed AppScene surface.

    #248 already names getFile and streaming reads, so no duplicate child issue is needed. Active #237/#312/#348 paths are disjoint. PR #350 currently owns central runtime/ABI files; this slice will integrate only after that clean PR lands or otherwise no longer overlaps.

  7. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Merged the focused FileSystemFileHandle.getFile() slice through PR #360 as 379a72dd3b8c9faa487b20ce44f6baad84ebb013 from exact head 71e601c3ec5e351ba46daa9eea025b36058bbb98, rebased on 69d929f6.

    The browser layer now reads AppScene-compatible opaque grants through a bounded v2 range ABI and returns lazy snapshot File objects with metadata, binary/text reads, exact slices, and 64 KiB backpressured streams. Every chunk revalidates exact nanosecond metadata; mutation maps to NotReadableError. Cancellation, denial, missing files, and I/O map to the browser DOMException classes. Write-only grants fail before native dispatch, and navigation/teardown retires requests exactly once.

    Retained evidence:

    • exact-head Linux X64, macOS ARM64, native Linux document, and portable V8 runners: PASS;
    • Chrome 153 WPT-derived oracle: 4/4 subtests in 120 ms, result SHA-256 e7bc1f0803a46138a5351cff497cf17085cf8a5a4181f0298bba6f11045835ab;
    • native File System Access profile: 4/4; 100 picker/read cycles in 0.79 s, +756,880 B V8 heap, +540,672 B peak RSS, queues drained;
    • broker: 10,000 reads in 7.4 ms Release / 11.8 ms ASan+UBSan, zero FD growth, zero retained bytes;
    • C11 header, actual dylib exports, portable ABI allowlist, and Objective-C++ adapter against AppScene 2a3f9e0d: PASS.

    #248 remains open. The remaining independently reviewable work is createWritable(), existing-child directory iteration/lookup/resolve, explicit grant release, origin/profile persistence and restart restoration, then packaged unchanged-consumer acceptance. Native create/delete/restoration must stay separate unless AppScene adds those authority contracts.

  8. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    createWritable() bounded-slice audit on WebScene main 379a72dd3b8c9faa487b20ce44f6baad84ebb013 against AppScene main 2a3f9e0d1482e33440f7293627a787193764ccce:

    • Native authority is sufficient: AppScene's installed v2 contract already owns opaque BEGIN/CHUNK/COMMIT transactions plus explicit abort. It creates a private sibling, accepts bounded offset chunks, truncates to the committed length, fsyncs, revalidates target identity, atomically replaces, directory-syncs, and drains on cancellation/release/retirement. No path, bookmark, descriptor, or platform object needs to enter WebScene or JavaScript.
    • This slice will add only the product-neutral WebScene write request/completion ABI and broker, runtime FileSystemWritableFileStream, createWritable({keepExistingData}), ordered write/seek/truncate/close/abort, chunking, native status-to-DOMException mapping, and navigation/teardown retirement. keepExistingData will snapshot through the already-merged bounded read bridge before opening/writing the native transaction.
    • The browser contract will follow the pinned WPT FileSystemWritableFileStream*.js behavior and a direct Chrome oracle: atomic visibility on close, zero-fill gaps, cursor/truncate behavior, supported byte/string/Blob/command inputs, queued operations, one terminal close, and abort preserving the original. This slice does not claim mode: "exclusive" locking because AppScene's contract intentionally permits concurrent atomic writers; unsupported mode values will reject instead of inventing a lock authority.
    • Gates: direct broker contracts including malformed/stale/exactly-once cases and 10,000 operations; native runtime correctness/lifecycle/heap/RSS/FD/queue drain; WPT-derived Chrome oracle; ASan/UBSan; strict C11 header; exported-symbol and portable ABI audits; Objective-C++ layout/adapter compile against AppScene 2a3f9e0d.

    Current open PR collision audit is clear for focused implementation paths: #361 is CSSOM-only and #354 is ServiceWorker/parser-test-only. Draft consolidation #76 remains untouched. This branch will not change AppScene, CSS, ServiceWorker/parser paths, vscode-demo docs/PR #1, directory operations, persistence/restart authority, or packaged Code OSS acceptance.

  9. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Merged the focused FileSystemFileHandle.createWritable() slice through PR #363 as WebScene b6dfb66051e417fecb328da6639d7dfce7f251ee from exact head 4ab5f1e30e3fefdb7ed3cf61c0fbc7c691d27215, based on 15d55a4c.

    The browser runtime now exposes FileSystemWritableFileStream over a bounded opaque write ABI: begin, 1 MiB offset chunks, 1 GiB transaction limit, atomic commit, and explicit abort. It implements ordered string/Blob/BufferSource/command writes, seek(), truncate(), keepExistingData, zero-filled gaps, one terminal close, concurrent siloed writers, DOMException status mapping, and navigation/teardown retirement. mode: "exclusive" fails explicitly because AppScene provides atomic concurrent transactions but no lock authority. Paths, bookmarks, descriptors, temporary names, and platform objects remain native-only.

    Retained evidence:

    • exact-head Linux X64, macOS ARM64, portable real-V8, and native Linux document/independent SDK checks: PASS;
    • Chrome 153 WPT-derived IDL/writer oracle: 2/2 documents, 9/9 subtests; result SHA-256 6e276e73749716aa3f4beb89edae4ef179aeafd27c0c27678feba0130ff3ec5a;
    • release broker: 10,000 operations in 0.0125 s, RSS +114,688 bytes, FD delta 0, retained bytes 0;
    • ASan/UBSan, strict C11 layout, portable ABI allowlist, actual dylib exports, and Objective-C++ adapter/layout compile against AppScene 2a3f9e0d: PASS;
    • native runtime contract includes functional write/seek/truncate/abort/keepExistingData/error cases, 100 read/write lifecycle cycles, queue drain, navigation retirement, and heap/external/RSS budgets.

    Redundant pre-rebase, pre-final-head, post-merge, NuGet, and unrelated NativeAOT tail runs were canceled after the four directly related exact-head checks passed.

    #248 remains open. Independently reviewable remaining work is existing-child directory iteration/lookup/resolve, explicit grant release, origin/profile persistence and restart restoration, then packaged unchanged-consumer acceptance. Native create/delete/restoration and exclusive-lock authority remain out of scope unless AppScene adds those contracts.

  10. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Next bounded #248 slice starts from exact WebScene b6dfb66051e417fecb328da6639d7dfce7f251ee and consumes exact AppScene 2a3f9e0d1482e33440f7293627a787193764ccce.

    The native audit confirms #138/#139 already provides the required authority for deterministic, bounded directory pages: at most 32 entries/page, 10,000 entries and 1 MiB names/snapshot, no-follow validation, mutation detection, explicit operation cancellation/cursor release, narrowed capabilities, and a fresh opaque child grant per verified regular file/directory. WebScene can therefore add a generic directory-page ABI/broker and expose FileSystemDirectoryHandle[Symbol.asyncIterator], entries(), keys(), values(), getFileHandle(name, {create:false}), and getDirectoryHandle(name, {create:false}). Each iterator owns one snapshot/cursor, fetches lazily, releases on early return, and converts only native metadata plus derived grants into canonical browser handles. Lookup validates a single component, scans bounded pages, releases promptly on match/exhaustion, and maps missing/wrong-kind/native status to browser-compatible NotFoundError, TypeMismatchError, NotAllowedError, InvalidStateError, or AbortError.

    Native create/delete authority is absent. {create:true} and removeEntry() remain explicitly unavailable and dispatch no filesystem mutation. resolve() also remains unavailable: AppScene grant records do not preserve an authority-bound ancestry relation after enumeration, so JavaScript traversal history cannot correctly resolve independently selected/restored descendants. The focused native gap is tracked in SceneTech/AppScene#156 rather than inferring paths or ancestry in WebScene.

    Evidence will include WPT-derived iteration/lookup contracts and a Chrome oracle; native functional, malformed/cross-scope/stale/mutation/cancellation/early-return/retirement coverage; 10,000 broker operations, maximum 10,000-entry paging, 100 lifecycle cycles, RSS/FD/retained-state bounds; ASan/UBSan; strict C11 layout; portable ABI allowlist and actual exports; and an Objective-C++ adapter compile against AppScene 2a3f9e0d.

    Collision audit: active #365 owns only CSSOM files and draft #76 owns only docs/code-oss-compatibility.md. This slice will not modify AppScene, CSS, #266 resource/ServiceWorker/parser paths, consolidation #76, vscode-demo files/docs/PR #1, persistence/restart restoration, packaged Code OSS acceptance, or create/delete/path authority.

  11. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Merged the focused existing-child directory slice through PR #367 as WebScene d521dd05f217eb1a43604b357346197d60b5b294, from exact head 2aa91643d0016660281b5dd87a302c6a1f9e9f96 on exact base c4c4ac915918d44919d573539e89e7ace551aa5c.

    The browser runtime now exposes lazy FileSystemDirectoryHandle async iteration (@@asyncIterator, entries, keys, and values) plus getFileHandle/getDirectoryHandle for existing children. A generic bounded v2 ABI/broker transports AppScene's deterministic 32-entry pages, accepts at most 10,000 entries per snapshot, creates canonical browser handles only from fresh opaque derived grants, maps native failures to browser errors, and explicitly releases unfinished native cursors after successful lookup or early iterator return. Navigation and teardown cancel pending promises and drain broker state.

    Native create/delete authority is still absent, so {create:true} and removeEntry() remain unavailable. resolve() also remains unavailable because AppScene does not retain authority-bound ancestry for independently selected/restored grants; the missing native contract is tracked as SceneTech/AppScene#156, nested under AppScene#123.

    Retained evidence:

    • exact-head Linux X64, macOS ARM64, portable real-V8, and native Linux document/independent SDK checks: PASS;
    • Chrome 153 WPT-derived IDL/iteration/lookup oracle: 2/2 documents, 9/9 subtests; result SHA-256 824276c8ba1d6376a274cbd45a5762a6d2b0b5c488785b5dfc562bf482366832;
    • release broker: 10,000 operations in 0.0011 s, RSS +114,688 bytes, FD delta 0, retained input bytes 0; 100 retirement cycles drain;
    • ASan/UBSan broker: PASS, 10,000 operations in 0.0079 s, RSS +4,636,672 bytes, FD delta 0, retained input bytes 0;
    • strict C11 ABI layout, actual dylib exports, portable ABI allowlist, and Objective-C++ adapter/layout compile against AppScene 2a3f9e0d: PASS;
    • native real-V8 contract covers two-page and 10,000-entry iteration, existing/missing/wrong-kind lookup, invalid/create/resolve authority boundaries, explicit early/match cursor release, six native status mappings, 100 lifecycle cycles, and navigation retirement.

    #248 remains open for native create/delete/resolve authority, explicit grant release, origin/profile persistence and restart restoration, and packaged unchanged-consumer acceptance. Redundant superseded-head, NuGet, NativeAOT tail, and post-merge runs were canceled after the four directly related exact-head checks passed.

  12. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Starting the next bounded slice in child #370 from exact d521dd05f217eb1a43604b357346197d60b5b294.

    Audit result:

    • FileSystemHandle.release() is not a browser API (Chrome 153 reports undefined), so this slice will not add one.
    • WebScene currently retains every wrapper in a strong Map and never invokes AppScene's existing appscene_file_panel_cocoa_release_grant_v2 contract.
    • V8 currently clones handles as empty plain objects because only MessagePort is registered as a clone host object.
    • Chrome/WPT require a distinct branded same-entry handle after structured clone, with deserialization limited to the same storage origin.
    • IndexedDB persistence requires an origin/profile-bound durable locator. Raw live grant tokens are process-local and must not be persisted. Missing native authority is now isolated in AppScene#157, attached under AppScene#123.

    Collision-free implementation scope: weak V8 handle bindings; a shared grant owner retained by live wrappers and in-flight clone packets; same-origin transient structured clone; deterministic realm/navigation retirement; and one bounded native release request when the final owner disappears. This includes the public ABI, generic broker, exports, AppScene release-adapter compile gate, Chrome/WPT/security/lifecycle tests, 10k broker coverage, 100 realm cycles, and memory/FD gates.

    Excluded: IndexedDB durable persistence pending AppScene#157, explicit JS release, path exposure, creation/deletion/resolve authority, AppScene source, resources (#364), CSS (#366), #156 ancestry, consolidation #76, and vscode-demo files.

    Oracle: Chrome 153.0.8010.50 produced distinct [object FileSystemFileHandle] clones with isSameEntry() === true, no enumerable own keys, and no release; the CDP probe source hash is 88b4607a849d1122f475e90f08a94fee15d36ea443dc100fefe75d9fab81ea6c.

  13. 8 remaining items

  14. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    PR #390 merged at 2ffb0dc (exact reviewed head ca784cc). FileSystemHandle values now persist through IndexedDB via partition/origin-bound opaque locators, restore as fresh realm-bound grants after engine restart, and revoke on replacement/deletion. Retired navigation generations reject stale completions.

    Direct exact-head checks passed: Linux X64, macOS ARM64, portable V8, and native Linux document contracts. Chrome 153 WPT-derived oracle, real-V8 restart lifecycle, exact AppScene aadf606d adapter, strict C11 ABI/exports, 10,000-cycle memory/FD gate, and ASan/UBSan also passed. Child #382 is complete.

  15. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    #394 is attached as the next bounded File System Access child from exact main 2ffb0dc and AppScene aadf606ddf7a1cc1c4e3bbe8aefd46219cbbfbfd.

    Audit result: getFile/createWritable, existing-child directory operations, resolve, weak ownership, and durable IndexedDB restoration are merged. Entry create/delete/remove/move remains blocked because AppScene exposes capability bits but no typed mutation operation; this slice will not infer one. The smallest unblocked defect is permission overclaim: readwrite currently succeeds from any write-like bit without also requiring read authority.

    #394 owns only capability-exact queryPermission/requestPermission states, WebIDL-shaped descriptor/receiver behavior, clone and durable-restore parity, and focused browser/native lifecycle evidence. AppScene grants remain terminal granted/denied decisions; no prompt/elevation authority is invented. Active #392 History, #391/#388 resources, CSS work, #76, AppScene, and vscode-demo are disjoint and excluded.

  16. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Permission leaf #394 is complete via PR #395, merged at 7438a60 (head 6301d6c). Exact grant capabilities now control queryPermission/requestPermission across live, cloned, and durable-restored handles; unsupported descriptor modes reject and terminal decisions never invent native elevation. Linux, macOS, portable V8, NativeAOT 11/12, native-document, Chrome 153 (2/2), ABI/C11, durable restore, and bounded lifecycle/performance gates are green. The remaining save-picker READ authority is isolated in SceneTech/AppScene#160 under AppScene #123.

  17. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Native save-picker authority prerequisite SceneTech/AppScene#160 is complete via AppScene PR #161 at 07e980f30872b7eb5f59df6fff616af1eb51b1ac. Successful save grants now carry READ | WRITE | CREATE, matching WebScene permission semantics merged in #395. Existing targets are readable, new targets report not-found, and opaque lifecycle/security/performance/ABI gates are green.

  18. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Next bounded slice: file child creation

    Audit baseline: WebScene 9378075872bf1a5ebf66a1b1a194bd5cbc5e0614, AppScene 07e980f30872b7eb5f59df6fff616af1eb51b1ac, pinned WPT 2c705104a295c48053eeddf7fe0170d790a4e853.

    The first missing typed authority is an atomic opaque-directory get or create file child operation. Current WebScene already supports existing-child lookup but rejects every {create:true} call; AppScene exposes CREATE as a capability but has no operation that may exercise it. VS Code's browser filesystem provider calls parent.getFileHandle(name, {create:true}) before createWritable() for new files, and browser download export uses the same path.

    WPT requires a missing child to become an empty file, an existing file to retain its contents, and a directory collision to reject with TypeMismatchError. The native operation therefore must decide lookup/create atomically beneath the parent grant; JavaScript will not synthesize path or mutation authority.

    Tracked stack:

    The slice excludes directory creation, removal, recursive deletion, move/rename, and #131/#252 package work. Gates cover WPT/Chrome semantics, C11/export/adapter parity, origin/profile/partition isolation, cancel/stale/retire behavior, 10k bounded operations, and 100 lifecycle cycles with heap/RSS/FD bounds.

  19. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    File-child creation slice #400 is complete: PR #406 merged as ad33c45305f4cabbb87d378686539d39efb606c5, consuming AppScene#162/#163 (d63d6b4bc6105ee34e9845c1017125e9382d48c3). FileSystemDirectoryHandle.getFileHandle(name,{create:true}) now uses typed opaque parent authority, returns a derived browser handle without exposing paths/bookmarks/native objects, preserves existing contents, maps native failures, cancels on navigation, and releases the derived grant exactly once. Exact-head Linux, macOS, portable V8, native-document, and AOT 11/12 passed; Chrome 153 oracle passed 3/3; local 10k broker and 100-cycle RSS/heap/FD gates passed.

  20. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Next dependency-ordered directory mutation audit\n\nBaseline: WebScene ad33c45305f4cabbb87d378686539d39efb606c5, AppScene cac13616eb4f291f7cef44c5b8480b4a7a37ce3, pinned WPT 2c705104a295c48053eeddf7fe0170d790a4e853. Open PR paths are disjoint (#408 CSS only; #76 docs only).\n\nThe smallest complete remaining capability is FileSystemDirectoryHandle.getDirectoryHandle(name,{create:true}). It directly unlocks unchanged VS Code htmlFileSystemProvider.mkdir() and recursive browser folder export in fileImportExport.ts; removeEntry would unlock delete and file rename later, while handle move/rename does not serve the provider path. WPT requires missing-directory creation, existing-content preservation, file collision as TypeMismatchError, and invalid component names as TypeError. Chrome 153.0.8010.50 passes the focused reduction 3/3 in 128 ms; result SHA-256 837bedb8a5065b5b3bf10a6a287f6c4b19203f33965a5f2cb1d47975c4900c70.\n\nThe native authority audit found a hard dependency: AppScene exposes paged read-only enumeration and get-or-create file child operations only. It has no typed directory create, remove, or move operation. Capability bits alone cannot authorize filesystem mutation, and WebScene cannot safely synthesize paths or creation in JavaScript.\n\nTracked stack: SceneTech/AppScene#168 (attached directly under open AppScene#122) and WebScene #409 (attached here). #409 is intentionally blocked until #168 supplies the opaque atomic authority; no WebScene runtime branch will invent native mutation authority. This respects the requested AppScene code-path exclusion while preserving dependency order.

  21. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Merged directory-child creation slice via #415 at fbc1f99cc74d83160dc18abd7e9833b54a104cf7 (dependent AppScene authority: SceneTech/AppScene#169, merge d4a738883464077767efff69e9848a99fe47c768). FileSystemDirectoryHandle.getDirectoryHandle(name, { create: true }) now uses the typed bounded broker and returns a derived opaque directory grant, with browser error mapping and stale-navigation retirement. Exact-head Linux, macOS, NativeAOT 11/12, and portable-V8 gates passed; local C11/ABI/export/runtime, 10k broker, 100-cycle lifecycle, heap/RSS/FD, and Chrome 153 3/3 oracle gates passed. #409 closed.

  22. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Resync against WebScene fc71e92f and AppScene d4a73888 found one remaining generic File System Access operation exercised by unchanged VS Code: FileSystemDirectoryHandle.removeEntry(). The browser filesystem provider uses it for ordinary delete and for the removal half of copy/delete rename. This work stays outside MessagePort #288, webviews/resources #266, consolidation PRs #65/#76, packaging, and vscode-demo.

    The native prerequisite is complete: AppScene #170 / PR SceneTech/AppScene#171 merged as eef005596716174594e9ec74966b89a0aba99a10. Focused WebScene PR #435 now consumes that exact typed authority.

    Current cumulative evidence:

    • strict request layout/status/cap parity against the merged AppScene header;
    • native C11 ABI, exported-symbol and binary interop checks;
    • V8 runtime/native-engine translation-unit compilation plus portable library build;
    • permission/status mapping, malformed and duplicate rejection, exact-once completion, navigation/teardown cancellation;
    • 10,000 optimized operations: 0.0012 s, RSS +65,536 bytes, FD delta 0;
    • 10,000 ASan/UBSan operations: 0.0085 s, RSS +3,719,168 bytes, FD delta 0;
    • 100 broker lifecycle cycles return to zero queued/pending/retained state;
    • direct Chrome 153 oracle passes all 4/4 focused cases.

    The browser oracle is pinned to WPT FileSystemDirectoryHandle-removeEntry.js at 2c705104a295c48053eeddf7fe0170d790a4e853. The March 2026 WHATWG living text now treats a missing entry as success, while that WPT revision and Chrome 153 return NotFoundError; #429 and PR #435 preserve the pinned Chromium behavior used for this compatibility slice.

  23. wieslawsoltes commented on Sep 18, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Completed: focused PR #435 merged as 6e27f2b9305bcbe8202c3c451a31172661025fc2 from exact reviewed head a28754298c29fd4159a10f14ebf36951056f795d after the directly affected hosted macOS ARM64 gate passed. The broad queued/tail CI, package, Linux-document, and portable-V8 runs were cancelled after merge under the fast-merge policy; cumulative local V8/portable/ABI/sanitizer/performance/lifecycle evidence remains recorded above and on the PR.

    Together with AppScene eef005596716174594e9ec74966b89a0aba99a10, unchanged VS Code now has the generic removeEntry() delete primitive and copy/delete rename removal path. #429 closed with the merge.

  24. wieslawsoltes commented on Sep 19, 2026

    @wieslawsoltes
    CollaboratorAuthor

    Implementation-first re-audit at WebScene 59d143e1 confirms every generic picker/handle operation used by unchanged Code OSS is already merged, including removeEntry (#435) and FileSystemObserver (#438). Remaining work is packaged unchanged-consumer/local-save acceptance coordinated with #269/#260; no additional transport or authority mutation is justified. No code or validation was run.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    vscode-oss/plannedPlanned for the AppScene/WebScene VS Code OSS integration

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions