Skip to content

feat(runtime)!: add explicit remote updates and SSR revisions - #5074

Merged
2heal1 merged 1 commit into
feat/mf-ssr-clear-cachefrom
feat/ssr-update-remotes
Sep 14, 2026
Merged

2heal1 merged 1 commit into
feat/mf-ssr-clear-cachefrom
feat/ssr-update-remotes

Conversation

@2heal1

@2heal1 2heal1 commented Sep 14, 2026

Copy link
Copy Markdown
Member

Description

Replace forced remote registration with await updateRemotes(remotes). Identical registration is a no-op; conflicting registration and force: true now throw. Batch updates validate before cleanup, serialize per instance, retain unspecified remotes, and refresh all live bundler mappings.

The Modern SSR owner adds batch publication and application-wide integer revisions. Pending/successful duplicate messages reuse their result; stale or conflicting revisions reject. Applied revisions advance only after publication. Failed mutations remain unavailable, and explicit whole-application recovery includes retained targets from previous failed batches. Results and errors expose operation metadata. Existing selective-entry proofs, shared identity retention and same-process rebuilding remain in place.

Migrates affected examples and runtime API docs. This is a breaking API migration with major changesets; the fixed release group expands the release plan to 3.0.0. Private example/site packages intentionally have no release entries.

Validation: 20 build tasks; runtime-core 147, runtime 94, bundler 128 and Modern 35 tests; strict native artifacts 23; Node E2E 1, runtime browser E2E 26, Modern SSR cache E2E 2. Real Modern HTTP artifacts pass ordinary, numeric/minified and concatenated variants, plus production MF (1) and HTTP (3) tests. Full Prettier, whitespace, commitlint and Changesets parsing/scope checks pass. Existing non-fatal Modern publint and nested-remote DTS warnings remain.

Exact commands and skipped matrices are in tools/ssr-cache/VALIDATION.md. Worktree validation uses Turbo/package scripts. Unrelated package/framework/builder matrices and sustained load/heap/hydration acceptance remain R6; this PR does not claim final production sign-off. No package publication or deployment.

Related Issue

R5 of the MF/Modern SSR cache RFC, following #5072. Target: feat/mf-ssr-clear-cache.

Types of changes

  • Docs change / refactoring / dependency upgrade
  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)

The API migration itself is breaking, as explained above and in the changeset.

Checklist

  • I have added tests to cover my changes.
  • All new and existing tests passed.
  • I have updated the documentation.

@changeset-bot

changeset-bot Bot commented Sep 14, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e6ddc59

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 48 packages
Name Type
@module-federation/runtime-core Major
@module-federation/runtime Major
@module-federation/webpack-bundler-runtime Major
@module-federation/modern-js-v3 Major
@module-federation/nextjs-mf Patch
@module-federation/bridge-react Major
@module-federation/devtools Major
@module-federation/dts-plugin Major
@module-federation/esbuild Patch
@module-federation/metro Major
@module-federation/modern-js Major
@module-federation/node Patch
@module-federation/observability-plugin Patch
@module-federation/playground Patch
@module-federation/retry-plugin Major
@module-federation/runtime-tools Major
@module-federation/bridge-vue3 Major
website-new Patch
@module-federation/enhanced Major
shared-tree-shaking-with-server-host Patch
shared-tree-shaking-with-server-provider Patch
@module-federation/metro-plugin-rnc-cli Major
@module-federation/metro-plugin-rnef Major
@module-federation/metro-plugin-rock Major
@module-federation/rsbuild-plugin Major
@module-federation/rstest Major
node-dynamic-remote-new-version Patch
node-dynamic-remote Patch
@module-federation/rspack Major
@module-federation/inject-external-runtime-core-plugin Major
@module-federation/rspress-plugin Major
@module-federation/storybook-addon Patch
shared-tree-shaking-no-server-host Patch
shared-tree-shaking-no-server-provider Patch
remote5 Patch
remote6 Patch
@module-federation/cli Major
create-module-federation Major
@module-federation/error-codes Major
@module-federation/managers Major
@module-federation/manifest Major
@module-federation/sdk Major
@module-federation/third-party-dts-extractor Major
@module-federation/treeshake-frontend Major
@module-federation/treeshake-server Major
@module-federation/bridge-react-webpack-plugin Major
@module-federation/bridge-shared Major
@module-federation/utilities Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-14T03:21:48.426501Z e6ddc59 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@pkg-pr-new

pkg-pr-new Bot commented Sep 14, 2026

Copy link
Copy Markdown

Open in StackBlitz

@module-federation/devtools

pnpm add https://pkg.pr.new/@module-federation/devtools@e6ddc59

@module-federation/cli

pnpm add https://pkg.pr.new/@module-federation/cli@e6ddc59

create-module-federation

pnpm add https://pkg.pr.new/create-module-federation@e6ddc59

@module-federation/dts-plugin

pnpm add https://pkg.pr.new/@module-federation/dts-plugin@e6ddc59

@module-federation/enhanced

pnpm add https://pkg.pr.new/@module-federation/enhanced@e6ddc59

@module-federation/error-codes

pnpm add https://pkg.pr.new/@module-federation/error-codes@e6ddc59

@module-federation/esbuild

pnpm add https://pkg.pr.new/@module-federation/esbuild@e6ddc59

@module-federation/managers

pnpm add https://pkg.pr.new/@module-federation/managers@e6ddc59

@module-federation/manifest

pnpm add https://pkg.pr.new/@module-federation/manifest@e6ddc59

@module-federation/metro

pnpm add https://pkg.pr.new/@module-federation/metro@e6ddc59

@module-federation/metro-plugin-rnc-cli

pnpm add https://pkg.pr.new/@module-federation/metro-plugin-rnc-cli@e6ddc59

@module-federation/metro-plugin-rnef

pnpm add https://pkg.pr.new/@module-federation/metro-plugin-rnef@e6ddc59

@module-federation/metro-plugin-rock

pnpm add https://pkg.pr.new/@module-federation/metro-plugin-rock@e6ddc59

@module-federation/modern-js

pnpm add https://pkg.pr.new/@module-federation/modern-js@e6ddc59

@module-federation/modern-js-v3

pnpm add https://pkg.pr.new/@module-federation/modern-js-v3@e6ddc59

@module-federation/native-federation-tests

pnpm add https://pkg.pr.new/@module-federation/native-federation-tests@e6ddc59

@module-federation/native-federation-typescript

pnpm add https://pkg.pr.new/@module-federation/native-federation-typescript@e6ddc59

@module-federation/nextjs-mf

pnpm add https://pkg.pr.new/@module-federation/nextjs-mf@e6ddc59

@module-federation/node

pnpm add https://pkg.pr.new/@module-federation/node@e6ddc59

@module-federation/observability-plugin

pnpm add https://pkg.pr.new/@module-federation/observability-plugin@e6ddc59

@module-federation/playground

pnpm add https://pkg.pr.new/@module-federation/playground@e6ddc59

@module-federation/retry-plugin

pnpm add https://pkg.pr.new/@module-federation/retry-plugin@e6ddc59

@module-federation/rsbuild-plugin

pnpm add https://pkg.pr.new/@module-federation/rsbuild-plugin@e6ddc59

@module-federation/rspack

pnpm add https://pkg.pr.new/@module-federation/rspack@e6ddc59

@module-federation/rspress-plugin

pnpm add https://pkg.pr.new/@module-federation/rspress-plugin@e6ddc59

@module-federation/rstest

pnpm add https://pkg.pr.new/@module-federation/rstest@e6ddc59

@module-federation/runtime

pnpm add https://pkg.pr.new/@module-federation/runtime@e6ddc59

@module-federation/runtime-core

pnpm add https://pkg.pr.new/@module-federation/runtime-core@e6ddc59

@module-federation/runtime-tools

pnpm add https://pkg.pr.new/@module-federation/runtime-tools@e6ddc59

@module-federation/sdk

pnpm add https://pkg.pr.new/@module-federation/sdk@e6ddc59

@module-federation/storybook-addon

pnpm add https://pkg.pr.new/@module-federation/storybook-addon@e6ddc59

@module-federation/third-party-dts-extractor

pnpm add https://pkg.pr.new/@module-federation/third-party-dts-extractor@e6ddc59

@module-federation/treeshake-frontend

pnpm add https://pkg.pr.new/@module-federation/treeshake-frontend@e6ddc59

@module-federation/treeshake-server

pnpm add https://pkg.pr.new/@module-federation/treeshake-server@e6ddc59

@module-federation/typescript

pnpm add https://pkg.pr.new/@module-federation/typescript@e6ddc59

@module-federation/utilities

pnpm add https://pkg.pr.new/@module-federation/utilities@e6ddc59

@module-federation/webpack-bundler-runtime

pnpm add https://pkg.pr.new/@module-federation/webpack-bundler-runtime@e6ddc59

@module-federation/bridge-react

pnpm add https://pkg.pr.new/@module-federation/bridge-react@e6ddc59

@module-federation/bridge-react-webpack-plugin

pnpm add https://pkg.pr.new/@module-federation/bridge-react-webpack-plugin@e6ddc59

@module-federation/bridge-shared

pnpm add https://pkg.pr.new/@module-federation/bridge-shared@e6ddc59

@module-federation/bridge-vue3

pnpm add https://pkg.pr.new/@module-federation/bridge-vue3@e6ddc59

@module-federation/inject-external-runtime-core-plugin

pnpm add https://pkg.pr.new/@module-federation/inject-external-runtime-core-plugin@e6ddc59

commit: e6ddc59

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e6ddc59918

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +27 to +29
updateRemotes(): never {
throw new Error(REMOTE_DISABLED_MESSAGE);
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Return a rejected promise when remotes are disabled

When experiments.optimization.disableRemote is enabled, this implementation throws synchronously even though the new public updateRemotes() API is declared to return Promise<void>. Consequently, callers using the documented promise contract—for example, mf.updateRemotes(remotes).catch(...)—cannot handle the failure through the returned promise. Make the disabled path return Promise.reject(...) or make the public wrapper async, as is already done for loadRemote and preloadRemote.

Useful? React with 👍 / 👎.

Comment on lines +668 to +670
// Capture caller-owned values immediately; validate again when the queue runs.
captured = this.prepareRemotes(remotes, true);
} catch (error) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Defer state-dependent validation until the queued update runs

When an earlier queued update changes or frees an alias, a later update that reuses that alias is rejected here against the pre-update registrations even though it would be valid when its serialized turn begins. For example, with a aliased as old and b aliased as other, queueing an update that changes a to new followed immediately by one that changes b to old rejects the second call before the first completes. Capture and validate caller-owned field shapes immediately, but perform alias checks that depend on host.options.remotes only inside the queued operation.

Useful? React with 👍 / 👎.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e6ddc59918

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +167 to +168
const previous = registered ||
remembered.get(name) || { name };

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Resolve retained registrations by canonical identity

When a replacement addressed by an alias fails after removing the registration, remembered is keyed only by that alias. If the recovery message addresses the same remote by its canonical name, this lookup misses and fabricates { name }; the recovery de-duplication then selects that stripped target, losing the original alias, type, entryGlobalName, and other options while marking the application serving again. Index or search retained registrations by both canonical name and alias.

Useful? React with 👍 / 👎.

Comment on lines +27 to +28
updateRemotes(): never {
throw new Error(REMOTE_DISABLED_MESSAGE);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Return a rejected promise when remotes are disabled

With experiments.optimization.disableRemote, this implementation throws synchronously even though the public updateRemotes signature promises Promise<void> and the enabled implementation converts validation failures into rejected promises. Code using updateRemotes(...).catch(...) therefore cannot handle this configuration and may crash its callback before a promise exists; return Promise.reject(...) or make the public wrapper async.

Useful? React with 👍 / 👎.

Comment on lines +42 to +43
const update = instance.updateRemotes;
host.updateRemotes = function (...args: Parameters<typeof update>) {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Include updateRemotes in the static-consumption scan

This adds updateRemotes as another out-of-owner mutation that invalidates Modern's static SSR proof, but SSRDependencyPlugin.ts:50 still scans application source only for loadRemote, registerRemotes, importRemote, and eval. An entry containing the new API can consequently be classified as statically safe until that path executes, unlike the equivalent legacy registration call, allowing the adapter to choose selective invalidation despite a known dynamic mutation path. Add updateRemotes to that conservative source scan.

Useful? React with 👍 / 👎.

@2heal1
2heal1 merged commit 656f7d0 into feat/mf-ssr-clear-cache Sep 14, 2026
20 checks passed
@2heal1
2heal1 deleted the feat/ssr-update-remotes branch September 14, 2026 06:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant