You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix(runtime): refuse a non-array packages in resolveArtifactCollections (#19924)
Fixes#15293
Clause-②: no
<sub>Rewritten short by the `domain:spec#5` seat (2026-09-23T20:02Z).
The dev report is on #15293 (`5801982470`); the earlier long body is in
the edit history.</sub>
Ruling A (`5634034754`): a release artifact's `packages` that is present
but is not an array (`{}`, `0`, `'x'`) is malformed, not absent, and
every reader refuses it. `ObjectStackDefinitionSchema` already declares
`packages: z.array(ArtifactPackageSchema).optional()`, so this narrows
an accept set back to the declaration.
## What changed
- **runtime** (the behaviour change): `resolveArtifactCollections` used
to return the artifact for any non-array `packages`. It now treats only
`undefined` / `null` as absent. Anything else reaches
`resolveArtifactPackageOrder`, which refuses with
`INVALID_ARTIFACT_PACKAGES` (422).
- **spec**: the rule is stated once, beside
`AssembledPackageBodySchema`. The docblocks in core and the two plugin
readers point at it.
- **plugin-security**: its private guard is dropped. Dropping it is
behaviour-equal on the dev's 29-input differential.
- **plugin-dev**: its private guard is kept, and the reason is written
at the site. Dropping it turns an existing pin red.
- **Pins**: `{}`, `0` and `'x'` at all three call sites, with lit
controls. Reverting the runtime line turns the three runtime pins red.
- **changeset**: `@objectstack/runtime` patch.
## Not in this PR
- The `@objectstack/cli` readers still return nothing for a non-array
`packages`: #19925.
- `packages: null` is refused by the schema but read as absent by every
reader: #19926.
🤖 Generated with [Claude Code](https://claude.com/claude-code)
https://claude.ai/code/session_01Sfe5YjBLwB9J3y8fvm2xq1
---------
Co-authored-by: Claude <noreply@anthropic.com>
A release artifact whose `packages` is present but is not an array (`{}`, `0`, `'x'`) is now refused by the runtime's collection reader too, as `INVALID_ARTIFACT_PACKAGES` (ADR-0112, `status: 422`) (#15293).
6
+
7
+
Clause-②: no
8
+
9
+
`packages` is declared as an array of package entries (`ObjectStackDefinitionSchema.packages: z.array(ArtifactPackageSchema).optional()`), and the rule is now written down once, beside `AssembledPackageBodySchema` in `@objectstack/spec`: an absent `packages` means a single-package artifact, and any other non-array value is malformed and refused. `resolveArtifactPackageOrder` in `@objectstack/core` already refused it, and so did the i18n detector in `@objectstack/plugin-dev` and the default-permission-set reader in `@objectstack/plugin-security`.
10
+
11
+
-**What changes**: `AppPlugin` reads its collections in `start()`, and `start()` now raises the same refusal `init()` already raised through the kernel's `manifest` service. Under `os dev`, `DevPlugin`'s child-`start()` loop logs it on its `error` line, where before the app started on its top-level collections alone. `createStandaloneStack` now refuses such an artifact while it builds the stack. Before, the refusal came later, when the app registered with the `manifest` service. `loadArtifactBundle`'s runtime-module merge reports it through its existing `warn` line and skips the merge, as it already does for a malformed `packages[]` entry. `resolveProjectDatabaseUrl` no longer reads a default datasource out of such an artifact: it declines, as it already does for any artifact it cannot read, and moves on to the next rung (the unified default database). The boot that loads the artifact then refuses it.
12
+
-**What does not change**: an absent `packages`, and `packages: null`, still return the caller's own object by identity. A well-formed `packages[]` resolves exactly as before.
13
+
-**Fix**: remove the `packages` key for a single-package artifact, or make it an array of `{ manifest: … }` entries.
0 commit comments