fix(shared): 依存が循環していてもパッケージ一覧が落ちないようにする - #2445
Merged
Merged
Conversation
computePackagesStatus の isInstallable は依存を再帰で辿るだけで、
評価中の id を持っていない。dependencies はリモート由来
(dataURL の packages.json と {installationPath}/packages.json)なので、
A→B→A や A→A が書かれると無限再帰で RangeError になる。
getPackagesWithStatus に try/catch が無いため、この例外は tRPC の
クエリごと失敗させる。パッケージ 1 件の問題でタブが丸ごと表示できなくなり、
ユーザーには原因も分からない。
循環を検出したら false(導入できない)を返す。一覧そのものが出なくなるより、
その 1 件が導入不可と表示されるほうが先へ進めるため。
なお公式データ(apm-data v3、285 パッケージ)は最大依存深さ 2 で循環は無い。
到達経路は主に localRepoPath とサードパーティの dataURL。
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
症状
パッケージデータの依存に循環(
A → B → A、あるいは自己依存A → A)が 1 つでもあると、Plugins タブが丸ごと表示できなくなる。原因
computePackagesStatusのisInstallableは依存を再帰で辿るだけで、評価中の id を持っていない。dependenciesはリモート由来 — dataURL のpackages.jsonと{installationPath}/packages.json(localRepoPath)— なので循環が書かれうる。書かれるとRangeError: Maximum call stack size exceededになる。呼び出し元の
getPackagesWithStatus(src/main/services/packageList.ts)に try/catch が無いため、この例外は tRPC のクエリごと失敗する。パッケージ 1 件の記述ミスで一覧全体が死ぬうえ、ユーザーには原因が分からない。修正
評価中の id を
Setで持ち、循環を検出したらfalse(導入できない)を返す。falseに倒す理由: 一覧そのものが出なくなるより、その 1 件が「導入不可」と表示されるほうがユーザーは先へ進める。到達経路について
公式データ(apm-data v3、285 パッケージ)を実際に集計したところ 最大依存深さ 2・循環なしだった。したがって現時点で踏むのは主に次の 2 つ:
{installationPath}/packages.json(ローカルリポジトリ。自作パッケージの検証で手書きされる)「自作パッケージ・サードパーティデータの検証」は AGENTS.md が明示的に守ると決めているユースケースなので、そこで一覧が落ちるのは避けたい。
テスト
computePackagesStatusに 3 件追加した。修正前は 3 件ともMaximum call stack size exceededで落ち、修正後は通る。3 件目の「循環に巻き込まれていないパッケージの判定は変わらない」は、循環の巻き添えで無関係なパッケージまで導入不可にしていないことの確認。
調査と文面の作成に Claude Code を使用しています。