From 84e88b4a8e44c33692e3561d3a94f2b2306daa8b Mon Sep 17 00:00:00 2001 From: Omarchybot <317366263+omarchybot@users.noreply.github.com> Date: Thu, 1 Oct 2026 04:49:25 +0200 Subject: [PATCH] Guard third-party manifests keeping __sourceDir No suite failed with the strip restored, so nothing kept the 4.0.3 regression from coming back. Co-Authored-By: Claude Opus 5.5 --- test/shell.d/plugins-test.sh | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/test/shell.d/plugins-test.sh b/test/shell.d/plugins-test.sh index 5d634dc9..c10509a7 100644 --- a/test/shell.d/plugins-test.sh +++ b/test/shell.d/plugins-test.sh @@ -210,5 +210,18 @@ check( '_syncServices still drops disabled or removed services' ) +const publicManifestMatch = shellSource.match(/function publicPluginManifest\(manifest\) \{[\s\S]*?\n \}/) +check(!!publicManifestMatch, 'publicPluginManifest is defined') +if (publicManifestMatch) { + const host = {} + require('vm').runInNewContext(`${publicManifestMatch[0]}\nthis.publicPluginManifest = publicPluginManifest`, host) + const raw = { id: 'acme.demo', __sourceDir: '/plugins/acme.demo', __isFirstParty: false, __hostCapabilities: ['authentication'] } + const copy = host.publicPluginManifest(raw) + check(copy.__sourceDir === '/plugins/acme.demo', 'third-party manifests keep their own source directory') + check(!('__isFirstParty' in copy) && !('__hostCapabilities' in copy), 'third-party manifests drop host trust markers') + copy.__sourceDir = '/elsewhere' + check(raw.__sourceDir === '/plugins/acme.demo', 'a plugin editing its manifest copy cannot move the registry entry') +} + assert(errors.length === 0, 'plugin manifests match shell registry contract', errors.join('\n')) JS