|
| 1 | +// Copyright (c) 2026 ObjectStack. Licensed under the Apache-2.0 license. |
| 2 | + |
| 3 | +/** |
| 4 | + * #21243 — a package write the store refused is never answered as success. |
| 5 | + * |
| 6 | + * ## The defect |
| 7 | + * |
| 8 | + * `installPackage` and `updatePackage` write two stores: the in-memory |
| 9 | + * registry, then `sys_packages` through the `package` service. Both caught the |
| 10 | + * second write's failure — returned `{ success: false }` or thrown — logged it |
| 11 | + * with `console.warn`, and answered success over the registry row. On MySQL, |
| 12 | + * where `sys_packages` was never created, every `POST /api/v1/packages` |
| 13 | + * answered 201 and every `PATCH /api/v1/packages/:id` answered 200, and after |
| 14 | + * the next restart `GET /api/v1/packages/:id` answered 404. |
| 15 | + * |
| 16 | + * ## The contract pinned here (triage's ruling: both halves, not one) |
| 17 | + * |
| 18 | + * 1. The failure is ANSWERED — a thrown error with the status and code the |
| 19 | + * dispatcher door reads (`resolveThrownHttpError`, the one rule every |
| 20 | + * door applies), never a success body. |
| 21 | + * 2. The registry write is UNDONE — after the throw the process holds no |
| 22 | + * package the store does not: a fresh install leaves nothing, a |
| 23 | + * re-install leaves the prior row, an edit leaves the prior manifest. |
| 24 | + * |
| 25 | + * Both failure channels of `publish` are driven, because the service has two: |
| 26 | + * RETURNED `{ success: false, driverFault }` (an undeclared driver fault the |
| 27 | + * service swallowed) and THROWN (a failure that declared its own answer — |
| 28 | + * what a live SQL driver's refused raw statement is, `500 DATABASE_ERROR`). |
| 29 | + * |
| 30 | + * ## The registry double |
| 31 | + * |
| 32 | + * This package cannot depend on `@objectstack/objectql` (it is the other way |
| 33 | + * round), so the registry is a double. It mirrors the real `SchemaRegistry` |
| 34 | + * verbs BY NAME and by the behaviour this contract leans on |
| 35 | + * (`packages/objectql/src/registry.ts`): `installPackage` builds a NEW row |
| 36 | + * object, keeps an existing row's lifecycle fields and registers the |
| 37 | + * namespace; `updatePackageManifest` edits the row and its manifest IN PLACE; |
| 38 | + * `enablePackage` / `disablePackage` move the lifecycle fields; |
| 39 | + * `unregisterItem('package', id)` withdraws the row; the namespace verbs keep |
| 40 | + * a set of owners per namespace. |
| 41 | + */ |
| 42 | + |
| 43 | +import { describe, it, expect, vi } from 'vitest'; |
| 44 | +import { resolveThrownHttpError } from '@objectstack/types'; |
| 45 | +import { ObjectStackProtocolImplementation } from './index.js'; |
| 46 | + |
| 47 | +interface Row { |
| 48 | + manifest: Record<string, unknown>; |
| 49 | + status: string; |
| 50 | + enabled: boolean; |
| 51 | + installedAt: string; |
| 52 | + updatedAt: string; |
| 53 | + settings?: unknown; |
| 54 | +} |
| 55 | + |
| 56 | +function makeRegistry() { |
| 57 | + const rows = new Map<string, Row>(); |
| 58 | + const namespaces = new Map<string, Set<string>>(); |
| 59 | + let tick = 0; |
| 60 | + const stamp = () => `2026-10-01T00:00:${String(tick++).padStart(2, '0')}.000Z`; |
| 61 | + return { |
| 62 | + rows, |
| 63 | + namespaces, |
| 64 | + installPackage(manifest: any, settings?: unknown): Row { |
| 65 | + const existing = rows.get(manifest.id); |
| 66 | + const row: Row = { |
| 67 | + manifest: { ...manifest }, |
| 68 | + status: existing?.status ?? 'installed', |
| 69 | + enabled: existing?.enabled ?? true, |
| 70 | + installedAt: stamp(), |
| 71 | + updatedAt: stamp(), |
| 72 | + settings, |
| 73 | + }; |
| 74 | + if (manifest.namespace) this.registerNamespace(manifest.namespace, manifest.id); |
| 75 | + rows.set(manifest.id, row); |
| 76 | + return row; |
| 77 | + }, |
| 78 | + getPackage: (id: string) => rows.get(id), |
| 79 | + getAllPackages: () => [...rows.values()], |
| 80 | + updatePackageManifest(id: string, patch: Record<string, unknown>) { |
| 81 | + const row = rows.get(id); |
| 82 | + if (!row) return undefined; |
| 83 | + for (const [k, v] of Object.entries(patch)) if (v !== undefined) row.manifest[k] = v; |
| 84 | + row.updatedAt = stamp(); |
| 85 | + return row; |
| 86 | + }, |
| 87 | + enablePackage(id: string) { |
| 88 | + const row = rows.get(id); |
| 89 | + if (row) Object.assign(row, { enabled: true, status: 'installed', updatedAt: stamp() }); |
| 90 | + return row; |
| 91 | + }, |
| 92 | + disablePackage(id: string) { |
| 93 | + const row = rows.get(id); |
| 94 | + if (row) Object.assign(row, { enabled: false, status: 'disabled', updatedAt: stamp() }); |
| 95 | + return row; |
| 96 | + }, |
| 97 | + unregisterItem(type: string, name: string) { |
| 98 | + if (type === 'package') rows.delete(name); |
| 99 | + }, |
| 100 | + registerNamespace(ns: string, id: string) { |
| 101 | + const owners = namespaces.get(ns) ?? new Set<string>(); |
| 102 | + owners.add(id); |
| 103 | + namespaces.set(ns, owners); |
| 104 | + }, |
| 105 | + unregisterNamespace(ns: string, id: string) { |
| 106 | + const owners = namespaces.get(ns); |
| 107 | + owners?.delete(id); |
| 108 | + if (owners?.size === 0) namespaces.delete(ns); |
| 109 | + }, |
| 110 | + getNamespaceOwners: (ns: string) => [...(namespaces.get(ns) ?? [])], |
| 111 | + }; |
| 112 | +} |
| 113 | + |
| 114 | +function makeImpl(publish: (d: { manifest: any; metadata: unknown }) => Promise<unknown>) { |
| 115 | + const registry = makeRegistry(); |
| 116 | + const publishSpy = vi.fn(publish); |
| 117 | + const services = new Map<string, unknown>([['package', { publish: publishSpy, delete: async () => ({ success: true }) }]]); |
| 118 | + const impl = new ObjectStackProtocolImplementation({ registry, find: async () => [] } as any, () => services as any); |
| 119 | + return { impl: impl as any, registry, publish: publishSpy }; |
| 120 | +} |
| 121 | + |
| 122 | +/** The service's RETURNED channel: the INSERT broke, nothing declared (`PackagePublishResult`). */ |
| 123 | +const returnedDriverFault = async () => ({ |
| 124 | + success: false, |
| 125 | + driverFault: { message: 'The package registry could not store this package.' }, |
| 126 | +}); |
| 127 | + |
| 128 | +/** The THROWN channel, shaped as a live SQL driver's refused raw statement (`rawStatementFaultError`). */ |
| 129 | +const DRIVER_LINE = "Table 'os.sys_packages' doesn't exist"; |
| 130 | +const thrownDatabaseError = async () => { |
| 131 | + throw Object.assign(new Error('The database refused to run a raw statement.'), { |
| 132 | + code: 'DATABASE_ERROR', |
| 133 | + status: 500, |
| 134 | + cause: new Error(DRIVER_LINE), |
| 135 | + }); |
| 136 | +}; |
| 137 | + |
| 138 | +/** What the dispatcher door answers for a thrown value (`errorFromThrown` → `resolveThrownHttpError`). */ |
| 139 | +const door = (e: unknown) => { |
| 140 | + const r = resolveThrownHttpError(e, 500); |
| 141 | + return { status: r.status, code: r.code, message: r.message }; |
| 142 | +}; |
| 143 | + |
| 144 | +async function rejectionOf(p: Promise<unknown>): Promise<unknown> { |
| 145 | + try { |
| 146 | + await p; |
| 147 | + } catch (e) { |
| 148 | + return e; |
| 149 | + } |
| 150 | + throw new Error('expected the call to reject, and it resolved'); |
| 151 | +} |
| 152 | + |
| 153 | +describe('#21243 installPackage — a refused sys_packages write fails the install and registers nothing', () => { |
| 154 | + it.each([ |
| 155 | + ['returned driverFault', 'INTERNAL_ERROR', returnedDriverFault], |
| 156 | + ['thrown DATABASE_ERROR', 'DATABASE_ERROR', thrownDatabaseError], |
| 157 | + ] as const)('fresh id, %s → 500 %s, no row, no namespace', async (_label, code, publish) => { |
| 158 | + const { impl, registry } = makeImpl(publish); |
| 159 | + |
| 160 | + const err = await rejectionOf(impl.installPackage({ manifest: { id: 'com.example.leave', name: 'Leave' } })); |
| 161 | + |
| 162 | + expect(door(err)).toMatchObject({ status: 500, code }); |
| 163 | + // The driver's words stay on `cause` for the operator, never in the caller's sentence. |
| 164 | + expect(door(err).message).not.toContain(DRIVER_LINE); |
| 165 | + expect((err as { cause?: unknown }).cause).toBeDefined(); |
| 166 | + // The undo half: nothing in this process claims the package. |
| 167 | + expect(registry.getPackage('com.example.leave')).toBeUndefined(); |
| 168 | + // The namespace this install derived (`leave`) is released with it. |
| 169 | + expect(registry.getNamespaceOwners('leave')).toEqual([]); |
| 170 | + }); |
| 171 | + |
| 172 | + it('a re-install over an existing row puts the PRIOR row back, lifecycle included', async () => { |
| 173 | + const { impl, registry } = makeImpl(returnedDriverFault); |
| 174 | + const prior = registry.installPackage({ id: 'com.example.leave', name: 'Leave v1', version: '1.0.0', namespace: 'leave' }); |
| 175 | + registry.disablePackage('com.example.leave'); |
| 176 | + const priorContent = JSON.parse(JSON.stringify(registry.getPackage('com.example.leave'))); |
| 177 | + |
| 178 | + const err = await rejectionOf(impl.installPackage({ |
| 179 | + manifest: { id: 'com.example.leave', name: 'Leave v2', version: '2.0.0', namespace: 'leave' }, |
| 180 | + enableOnInstall: true, |
| 181 | + })); |
| 182 | + |
| 183 | + expect(door(err)).toMatchObject({ status: 500, code: 'INTERNAL_ERROR' }); |
| 184 | + // Content, not identity: the registry keeps the row object it now holds. |
| 185 | + expect(JSON.parse(JSON.stringify(registry.getPackage('com.example.leave')))).toEqual(priorContent); |
| 186 | + expect(registry.getPackage('com.example.leave')?.manifest.name).toBe('Leave v1'); |
| 187 | + expect(registry.getPackage('com.example.leave')?.enabled).toBe(false); |
| 188 | + // The namespace the id already owned stays owned. |
| 189 | + expect(registry.getNamespaceOwners('leave')).toEqual(['com.example.leave']); |
| 190 | + expect(prior.manifest.name).toBe('Leave v1'); |
| 191 | + }); |
| 192 | + |
| 193 | + it('a declared 4xx refusal from the store leaves as the producer answered it, and is still undone', async () => { |
| 194 | + const refusal = Object.assign(new Error('Refused by the platform.'), { code: 'DESTRUCTIVE_CHANGE', status: 409 }); |
| 195 | + const { impl, registry } = makeImpl(async () => { |
| 196 | + throw refusal; |
| 197 | + }); |
| 198 | + |
| 199 | + const err = await rejectionOf(impl.installPackage({ manifest: { id: 'com.example.leave' } })); |
| 200 | + |
| 201 | + expect(err).toBe(refusal); |
| 202 | + expect(door(err)).toMatchObject({ status: 409, code: 'DESTRUCTIVE_CHANGE' }); |
| 203 | + expect(registry.getPackage('com.example.leave')).toBeUndefined(); |
| 204 | + }); |
| 205 | + |
| 206 | + it('CONTROL — a landed write answers the installed row, exactly as before', async () => { |
| 207 | + const { impl, registry, publish } = makeImpl(async () => ({ success: true })); |
| 208 | + |
| 209 | + const res = await impl.installPackage({ manifest: { id: 'com.example.leave', name: 'Leave' } }); |
| 210 | + |
| 211 | + expect(res.package.manifest.id).toBe('com.example.leave'); |
| 212 | + expect(registry.getPackage('com.example.leave')).toBe(res.package); |
| 213 | + expect(registry.getNamespaceOwners('leave')).toEqual(['com.example.leave']); |
| 214 | + expect(publish).toHaveBeenCalledTimes(1); |
| 215 | + }); |
| 216 | +}); |
| 217 | + |
| 218 | +describe('#21243 updatePackage — a refused sys_packages write fails the edit and restores the manifest', () => { |
| 219 | + it.each([ |
| 220 | + ['returned driverFault', 'INTERNAL_ERROR', returnedDriverFault], |
| 221 | + ['thrown DATABASE_ERROR', 'DATABASE_ERROR', thrownDatabaseError], |
| 222 | + ] as const)('%s → 500 %s, the prior manifest back in place', async (_label, code, publish) => { |
| 223 | + const { impl, registry } = makeImpl(publish); |
| 224 | + const row = registry.installPackage({ id: 'com.example.leave', name: 'Leave', version: '1.0.0' }); |
| 225 | + const manifestObject = row.manifest; |
| 226 | + const priorContent = JSON.parse(JSON.stringify(row)); |
| 227 | + |
| 228 | + const err = await rejectionOf(impl.updatePackage({ |
| 229 | + packageId: 'com.example.leave', |
| 230 | + patch: { name: 'Leave (renamed)', description: 'patched' }, |
| 231 | + })); |
| 232 | + |
| 233 | + expect(door(err)).toMatchObject({ status: 500, code }); |
| 234 | + expect(door(err).message).not.toContain(DRIVER_LINE); |
| 235 | + const now = registry.getPackage('com.example.leave')!; |
| 236 | + expect(JSON.parse(JSON.stringify(now))).toEqual(priorContent); |
| 237 | + // `description` was ABSENT before the edit and is absent again — not `undefined`, absent. |
| 238 | + expect('description' in now.manifest).toBe(false); |
| 239 | + // Restored in place: the row and its manifest are the objects the registry already held. |
| 240 | + expect(now).toBe(row); |
| 241 | + expect(now.manifest).toBe(manifestObject); |
| 242 | + }); |
| 243 | + |
| 244 | + it('CONTROL — a landed write answers the edited row', async () => { |
| 245 | + const { impl, registry } = makeImpl(async () => ({ success: true })); |
| 246 | + registry.installPackage({ id: 'com.example.leave', name: 'Leave', version: '1.0.0' }); |
| 247 | + |
| 248 | + const res = await impl.updatePackage({ packageId: 'com.example.leave', patch: { description: 'patched' } }); |
| 249 | + |
| 250 | + expect(res.package.manifest.description).toBe('patched'); |
| 251 | + expect(registry.getPackage('com.example.leave')?.manifest.description).toBe('patched'); |
| 252 | + }); |
| 253 | +}); |
0 commit comments