Skip to content

feat(workspaces): bake cast plugin and allow wp-admin plugin updates - #8

Merged
pcfreak30 merged 4 commits into
developfrom
feat/cast-plugin-bake
Sep 21, 2026
Merged

pcfreak30 merged 4 commits into
developfrom
feat/cast-plugin-bake

Conversation

@pcfreak30

@pcfreak30 pcfreak30 commented Sep 21, 2026 •

Copy link
Copy Markdown
Member

Bakes the latest LumeWeb/cast develop snapshot (Composer deps vendored at build) into the WordPress image, seeded to fresh plugin volumes and force-kept active by an image-owned MU guard that also works around WP 7.1's plugins-before-pluggable load order.

Drops DISALLOW_FILE_MODS so wp-admin can install and update plugins; the plugin/theme editor and out-of-band auto-updates stay disabled.

Bootstrap runs wp plugin activate cast on every boot, and the verify matrix now covers the new lockdown contract and Cast's presence/activation. Existing workspaces pick Cast up on their next image redeploy.


Summary

This PR makes the Cast plugin a platform-managed, force-active part of the WordPress workspace image, while re-enabling wp-admin plugin install/update (removing the old DISALLOW_FILE_MODS lockdown).

What changed

Bake Cast into the WordPress image

  • A new cast-builder Docker stage pulls the latest develop tree snapshot of LumeWeb/cast from GitHub, runs composer install --no-dev to vendor runtime dependencies at build time, and copies the result into /usr/src/wordpress/wp-content/plugins/cast.
  • The snapshot is deliberately not checksum-pinned yet; only the Composer builder base image is pinned (composer:2.10.3 by digest).
  • The Composer base/digest are added to versions.env, passed through docker-bake.hcl, and validated by verify-pins.sh.

Force Cast to stay active (Cast Guard MU plugin)

  • A new image-owned MU plugin, mu-plugins/cast-guard.php, is copied into the ephemeral wp-content/mu-plugins on every boot.
  • On every read of active_plugins, it re-adds cast/cast.php so the plugin cannot be deactivated via wp-admin, WP-CLI, or REST writes.
  • It also covers multisite (active_sitewide_plugins) and removes the admin Deactivate action.
  • Includes a WP 7.1 load-order compatibility shim for wp_salt() used by Cast at boot.

Startup convergence for existing sites

  • wp-init.sh now runs wp plugin activate cast on every boot after the DB is available (fresh installs and existing sites), performing the real one-time activation transition (schema install, rewrite flush).
  • Already-seeded plugin volumes are not overwritten — Cast is delivered to fresh volumes only; reconciling existing volumes is noted as a planned future step.

Allow wp-admin plugin updates

  • The generated wp-config.php no longer defines DISALLOW_FILE_MODS, so plugin installs and updates through wp-admin work.
  • Plugin/theme file editing remains blocked (DISALLOW_FILE_EDIT) and automatic/out-of-band updates remain disabled.

Verification updates

  • verify-wordpress.sh now asserts Cast is present on fresh volumes, active, and survives container recreation.
  • Confirms cast-guard.php exists.
  • Confirms DISALLOW_FILE_MODS is absent from the generated config while the other lockdown constants remain.

Review note

The automated review flagged one high severity issue: cast-guard.php filters option_active_plugins unconditionally, so on an already-seeded plugins volume where Cast files are missing, the plugin is reported as active even though it does not exist — masking the missing state and defeating the deferred-delivery design. This should be addressed before merge.

Bakes the latest LumeWeb/cast develop snapshot (Composer deps vendored at
build) into the WordPress image, seeded to fresh plugin volumes and
force-kept active by an image-owned MU guard that also works around WP
7.1's plugins-before-pluggable load order (core #62244).

Drops DISALLOW_FILE_MODS so wp-admin can install and update plugins; the
plugin/theme editor and out-of-band auto-updates stay disabled.

Bootstrap runs 'wp plugin activate cast' on every boot, the composer:2
builder base is digest-pinned in versions.env and drift-checked by
scripts/verify-pins.sh, and the verify matrix covers the new lockdown
contract plus Cast's presence and activation.
@kody-ai

This comment has been minimized.

@pcfreak30
pcfreak30 marked this pull request as ready for review September 21, 2026 13:25
Comment thread images/wordpress/mu-plugins/cast-guard.php
A volume seeded before Cast shipped never receives the plugin (one-time
seeding), so an unconditional active_plugins filter forced a phantom
entry that validate_active_plugins kept removing while the filter kept
re-adding. Both force-on filters now apply only while the managed plugin
files exist; the verify matrix gains a regression boot asserting the
guard stays neutral on a pre-cast volume.
@kody-ai

This comment has been minimized.

Comment thread scripts/verify-wordpress.sh Outdated
The pre-cast-volume regression check used 'wp plugin is-active cast',
which failed with a not-found error instead of proving the guard keeps
the force-on off while the plugin files are missing. Write the persisted
active_plugins entry out (deactivate) before the recreate and assert the
guard does not re-add Cast on the next option read.
@kody-ai

This comment has been minimized.

Comment thread scripts/verify-wordpress.sh Outdated
One-time seeding left pre-Cast volumes without cast forever and froze
seeded copies at their first-seed version, contradicting delivery-by-image.
Adds reconcile_cast(): a flock-serialized, content-compared convergence of
only plugins/cast to the image bake each boot, archiving the replaced copy
as .cast.bak-<epoch> (dot-prefixed, invisible to get_plugins()). All other
plugins stay volume-authoritative. The MU guard keeps its files-presence
gate so transient absence never churns a phantom active entry. Regression
coverage: guard neutral while files missing, reconcile restores cast, and a
drifted cast copy converges back; deactivation ordering fixed so wp plugin
deactivate runs before the files are removed (WP-CLI resolves operands via
a filesystem scan and errors without rewriting the option).
@kody-ai

kody-ai Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the @kody start-review command at the root of your PR.

  • Validate Business Logic: Ask Kody to validate your code against business rules by adding a comment with the @kody -v business-logic command.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

​

Comment thread images/wordpress/wp-init.sh
@pcfreak30
pcfreak30 merged commit f621c30 into develop Sep 21, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant