Hmbown/CodeWhale · error

First-party catalog drift: run python3…

Error message

First-party catalog drift: run python3 scripts/sync-marketplace.py, review, and rebuild.

What it means

sync-marketplace.py regenerates crates/tui/assets/first-party-marketplace.json from marketplace.json plus the pinned git revision. With --check (CI mode), it compares the rendered snapshot to the committed file and exits with this drift message if the file is absent or differs, instructing the developer to regenerate, review, and rebuild.

Solutions

  1. Run `python3 scripts/sync-marketplace.py` to regenerate the asset.
  2. Review the diff of crates/tui/assets/first-party-marketplace.json.
  3. Rebuild/re-run tests that embed the asset.
  4. Commit both marketplace.json and the regenerated asset together, then re-run with --check.

Example fix

// before (hand-edited asset or stale)
crates/tui/assets/first-party-marketplace.json (revision abc123)
// after
$ python3 scripts/sync-marketplace.py  # regenerates asset at current HEAD revision
Defensive patterns

Strategy: validation

Validate before calling

subprocess.run(['python3','scripts/sync-marketplace.py','--check'], check=True)

Try / catch

import subprocess
try:
    subprocess.run(['python3','scripts/sync-marketplace.py','--check'], check=True)
except subprocess.CalledProcessError:
    subprocess.run(['python3','scripts/sync-marketplace.py'], check=True)  # regenerate, then review diff

Prevention

When it happens

Trigger: Committing a marketplace.json change without re-running the script; editing first-party-marketplace.json by hand; a CI check running after someone bumped marketplace.json but not the asset.

Common situations: Forgetting the sync step during a plugin release; manual tweaks to the generated asset; rebase that took marketplace.json from one side and the asset from another.

Understand the failure class

Background: Checksum mismatch errors: "checksum verification failed", "digest mismatch", "expected vs actual checksum" — what they mean and how to fix them — this error's family across 41 libraries.

Related errors


AI-assisted analysis of Hmbown/CodeWhale@433685b202 (2026-09-15). Data as JSON: /api/errors/2796a6fc908a82fc. Report an issue: GitHub.

Appendix: source

Thrown at scripts/sync-marketplace.py:40

for candidate in catalog["plugins"]:
    spec = candidate["source"]
    if not spec.startswith("path:"):
        raise SystemExit(f"unexpected first-party source: {spec}")
    relative = spec[5:]
    if any(part in ("", ".", "..") or not all(c.isascii() and (c.isalnum() or c in "-_.") for c in part) for part in relative.split("/")):
        raise SystemExit(f"unsafe bundle path: {relative}")
    # Pin every install source to the reviewed marketplace revision so the
    # bytes a user installs are the bytes this snapshot describes. Freshness
    # comes from bumping the pin (the marketplace-sync workflow reports drift
    # against `main` weekly); `/plugin update` re-downloads the same archive
    # and reports no change until the pin moves.
    candidate["source"] = f"https://codeload.github.com/Hmbown/codewhale-plugin-marketplace/tar.gz/{revision}#path={relative}"
snapshot = {"repository": REPOSITORY, "revision": revision, "catalog": catalog}
rendered = json.dumps(snapshot, indent=2, ensure_ascii=False) + "\n"
output = ROOT / "crates/tui/assets/first-party-marketplace.json"
if args.check:
    if not output.exists() or output.read_text() != rendered:
        raise SystemExit("First-party catalog drift: run python3 scripts/sync-marketplace.py, review, and rebuild.")
    print(f"First-party catalog matches marketplace {revision}")
else:
    output.write_text(rendered)
    print(f"Updated {output} from marketplace {revision}")

View on GitHub (pinned to 433685b202)