## Evidence and method

This edition is grounded in the supplied&#32;**2026\-08\-29 source snapshot**\,&#32;complete public example files and a recorded completed verification report\.

Repository citations throughout refer to that snapshot\.&#32;They are not links to an assumed upstream commit\.&#32;The installed custom host can differ from a published npm package or upstream source with a similar version string\.

### Recorded completed checks

The supplied report records\:

- **312 passing contract tests**
- **22 test files**
- **1\,039 assertions**
- **0 failed tests**
- Bun&#32;**1\.3\.14**
- Host reported as&#32;**`omp/18.0.7`**
- Strict typecheck of all supplied public example TypeScript files
- **44 passing isolated example scenarios**
- Two resolved review findings

The two recorded corrections were\:

1. **Permission revocation\:**&#32;an in\-flight Review Desk dialog now gets aborted and generation\-invalidated\;&#32;a late positive RPC response cannot recreate the grant\.
2. **Binding lifetime\:**&#32;Field Notes is accurately described as factory\-local\.&#32;`newSession()`&#32;and&#32;`switchSession()`&#32;reuse its closures\;&#32;a new binding starts fresh\.

### Exact contract\-test command recorded

The following is the completed command from the supplied report\.&#32;It is also a reproduction recipe for a matching installed source checkout—not a command available inside the example ZIP alone\.

**Terminal shell—recorded repository\-root test command\:**

~~~sh
bun test \
  packages/coding-agent/test/extensions-runner.test.ts \
  packages/coding-agent/test/extensions-discovery.test.ts \
  packages/coding-agent/test/extension-delivery.test.ts \
  packages/coding-agent/test/extension-delivery-lifecycle.test.ts \
  packages/coding-agent/test/extension-provider-registration-rollback.test.ts \
  packages/coding-agent/test/extension-prepared-rebind.test.ts \
  packages/coding-agent/test/extension-flag-dispatch.test.ts \
  packages/coding-agent/test/extension-flag-initial-message.test.ts \
  packages/coding-agent/test/cli-explicit-extension-isolation.test.ts \
  packages/coding-agent/test/plugin-extensions-discovery.test.ts \
  packages/coding-agent/test/rpc-extension-ui.test.ts \
  packages/coding-agent/test/sdk-file-write-fallback-extension.test.ts \
  packages/coding-agent/test/sdk-extensions-per-session-binding.test.ts \
  packages/coding-agent/test/sdk-preloaded-extensions-isolation.test.ts \
  packages/coding-agent/test/sdk-restricted-extension-provider.test.ts \
  packages/coding-agent/test/extension-context-project-trust.test.ts \
  packages/coding-agent/test/extension-workspace-package-resolution.test.ts \
  packages/coding-agent/test/issue-4919-extension-autocomplete-provider.test.ts \
  packages/coding-agent/test/extensibility/ext-model-query.test.ts \
  packages/coding-agent/test/discovery/disabled-extensions.test.ts \
  packages/coding-agent/test/acp-agent.test.ts \
  packages/coding-agent/test/status-text-sanitization.test.ts
~~~

The strict public\-example typecheck used&#32;`tsgo`&#32;through a separate validation workspace’s&#32;`bun check`&#32;command\.&#32;The downloadable Package Lab manifest does not declare a&#32;`check`&#32;script\.&#32;Do not assume running&#32;`bun check`&#32;in an arbitrary extracted directory reproduces that validation configuration\.

### What the observations establish

The example scenarios used actual production components where named\:

- discovery and module loading\;
- factory binding and prepared rebinding\;
- runner dispatch and tool adapters\;
- real JSONL session storage\;
- real SDK construction\;
- real RPC request\/response streams\;
- real TUI controller\,&#32;focus dispatch and a terminal emulator\;
- real renderer width\/sanitization behavior\.

Seed Desk’s confirmation responses were simulated at the UI seam\.&#32;Review Desk’s native check used a surrounding mode fixture\.&#32;Some existing lifecycle contract tests used mock models to test scheduling and consumption\.

These distinctions matter\.&#32;A test can exercise a real coordinator while deliberately replacing the provider\.

### What is not claimed

The supplied proof does not establish\:

- live provider inference or OAuth against a real account\;
- actual package installation\,&#32;registry publication or marketplace deployment\;
- a real elevated file broker\;
- physical\-terminal visual correctness across terminals\;
- full Seed Desk autocomplete\/Enter smoke\;
- arbitrary remote\-client accessibility\;
- browser\/UI publication verification for this workbook\;
- complete\-repository test coverage\;
- cross\-process reservation or delivery coordination\.

The newly authored exercises in this manuscript are source\-backed teaching code\,&#32;not additions to the supplied completed\-check totals\.&#32;No new execution is claimed during manuscript authoring\.

### Material prerequisites and missing context

Some outcomes necessarily require evidence outside this bundle\:

- A real provider needs its actual endpoint\,&#32;auth flow and transport behavior\.
- A privileged file fallback needs a real host broker and filesystem policy\.
- A remote UI needs a client that implements the negotiated dialogs and cancellation behavior\.
- Declarative theme creation needs the matching host’s theme\-file schema\.
- Standalone shell\/script\-tool protocols should be checked in their own loader implementation rather than inferred from discovery metadata\.
- Exact hot\-reload behavior depends on the frontend path that performs reload\,&#32;not only on the module loader’s import support\.

Where public types or older prose disagree with current code\,&#32;this workbook uses the narrower implementation\-backed behavior\:&#32;RPC can have semantic UI\,&#32;command handlers do not automatically inherit event timeouts\,&#32;`ctx.reload()`&#32;is not promised to rebind factories\,&#32;and metadata discovery is not execution\.

### Source families used

The principal reference locations are\:

- `packages/coding-agent/src/extensibility/extensions/types.ts`
- `packages/coding-agent/src/extensibility/extensions/loader.ts`
- `packages/coding-agent/src/extensibility/extensions/runner.ts`
- `packages/coding-agent/src/extensibility/extensions/wrapper.ts`
- `packages/coding-agent/src/extensibility/extensions/model-api.ts`
- `packages/coding-agent/src/extensibility/extensions/managed-timers.ts`
- `packages/coding-agent/src/session/agent-session.ts`
- `packages/coding-agent/src/session/session-manager.ts`
- `packages/coding-agent/src/session/extension-delivery.ts`
- `packages/coding-agent/src/sdk.ts`
- `packages/coding-agent/src/main.ts`
- `packages/coding-agent/src/discovery/builtin.ts`
- `packages/coding-agent/src/discovery/helpers.ts`
- `packages/coding-agent/src/discovery/gemini.ts`
- `packages/coding-agent/src/extensibility/plugins/loader.ts`
- `packages/coding-agent/src/extensibility/plugins/manager.ts`
- `packages/coding-agent/src/config/model-registry.ts`
- `packages/coding-agent/src/modes/controllers/extension-ui-controller.ts`
- `packages/coding-agent/src/modes/rpc/rpc-mode.ts`
- `packages/coding-agent/src/modes/acp/acp-agent.ts`
- `packages/coding-agent/src/tools/file-write-fallback.ts`
- `packages/tui/src/components/composer/types.ts`

The public examples are available through&#32;[the complete ZIP](<https://present-sketch-tp94.here.now/downloads/extensions-examples.zip>)&#32;and the individual file links in their chapters\.&#32;Private runners\,&#32;private state\,&#32;credentials and local proof artifacts are not part of those downloads\.

The process to carry forward is simple\:

> Choose the smallest appropriate surface\.&#32;Give humans and models explicit contracts\.&#32;Make state lifetimes visible\.&#32;Test the real boundary that matters\.&#32;Distribute only what another reader can inspect\,&#32;operate and verify\.
