Repository navigation
fix(release-service): compare declared access in canonical form - #3958
Conversation
|
There was a problem hiding this comment.
This is the right fix for the reported regression. The release service now validates the manifest’s declaredAccess against the lexicon schema and compares it in canonical form, matching the same semantic-equality check that core uses at install time. The regression test covers the exact failure mode (non-canonical key/host order), and the malformed-manifest case confirms schema validation is enforced. I checked evaluate.ts, plugin-types/src/declared-access.ts, the generated PackageReleaseExtension.declaredAccessSchema, and verifyPackageReleaseRecords; the record side is already canonical, so canonicalizing the manifest before comparison is correct and safe. No changeset is needed because @emdash-cms/release-service is a private app. No blocking issues.
What does this PR do?
Delegated releases fail with
ARTIFACT_RECORD_MISMATCHwhen the plugin's declared access is not already in canonical order. The release service compares the record'sdeclaredAccess, whichverifyPackageReleaseRecordsreturns in canonical form (sorted keys and host lists), with the rawdeclaredAccessfrom the bundle manifest, usingJSON.stringifyequality.The manifest side is built in a fixed key order, so
schemacomes beforenetwork, andallowedHostskeeps the order the publisher wrote. A plugin that declares bothschema:readandnetwork:request, or lists hosts unsorted, cannot pass this check even though the record and the bundle declare the same access.linguadash@0.2.0hit this after its provenance started verifying.The manifest value is now validated against the lexicon
declaredAccessschema and compared in canonical form, the same way core compares verified access at install time. A manifest whose access differs from the record, or that does not match the schema, is still rejected.@emdash-cms/release-serviceis private, so there is no changeset. The release service needs a redeploy for delegated releases to pick this up.Type of change
Checklist
pnpm typecheckpassespnpm lintpassespnpm testpasses (or targeted tests for my change)pnpm formathas been runmessages.pochanges except in translation PRs — a workflow extracts catalogs on merge tomain.AI-generated code disclosure
Screenshots / test output
Not applicable (no UI change).
apps/release-service: 491 tests pass. The new test (same unsorted access in the record and the manifest) fails on the previousevaluate.tswithARTIFACT_RECORD_MISMATCH. Checked against the reallinguadash@0.2.0bundle: its raw and canonical declared access differ only in order.