Guard third-party manifests keeping __sourceDir

No suite failed with the strip restored, so nothing kept the 4.0.3 regression from coming back.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
OmarchybotandClaude Opus 5.5 committed 2026-10-01 04:49:25 +02:00
1 parent 146fe5d368
commit 84e88b4a8e
1 file changed
+13
+13
View File
@@ -210,5 +210,18 @@ check(
'_syncServices still drops disabled or removed services'
)
const publicManifestMatch = shellSource.match(/function publicPluginManifest\(manifest\) \{[\s\S]*?\n \}/)
check(!!publicManifestMatch, 'publicPluginManifest is defined')
if (publicManifestMatch) {
const host = {}
require('vm').runInNewContext(`${publicManifestMatch[0]}\nthis.publicPluginManifest = publicPluginManifest`, host)
const raw = { id: 'acme.demo', __sourceDir: '/plugins/acme.demo', __isFirstParty: false, __hostCapabilities: ['authentication'] }
const copy = host.publicPluginManifest(raw)
check(copy.__sourceDir === '/plugins/acme.demo', 'third-party manifests keep their own source directory')
check(!('__isFirstParty' in copy) && !('__hostCapabilities' in copy), 'third-party manifests drop host trust markers')
copy.__sourceDir = '/elsewhere'
check(raw.__sourceDir === '/plugins/acme.demo', 'a plugin editing its manifest copy cannot move the registry entry')
}
assert(errors.length === 0, 'plugin manifests match shell registry contract', errors.join('\n'))
JS