{"record":{"id":"4a359c657c6c14e5","repo":"siyuan-note/siyuan","slug":"invalid-marketplace-package-type","errorCode":null,"errorMessage":"invalid marketplace package type","messagePattern":"invalid marketplace package type","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/bazaar/install.go","lineNumber":175,"sourceCode":"\t\tlogging.LogErrorf(\"write file [%s] failed: %s\", installPath, err)\n\t\treturn\n\t}\n\n\tdirs, err := os.ReadDir(unzipPath)\n\tif err != nil {\n\t\treturn\n\t}\n\n\tsrcPath := unzipPath\n\tif 1 == len(dirs) && dirs[0].IsDir() {\n\t\tsrcPath = filepath.Join(unzipPath, dirs[0].Name())\n\t}\n\n\t// 校验下载包自身声明的名称与请求安装的包名一致，防止把其他包的内容写入指定目录\n\t// https://github.com/siyuan-note/siyuan/security/advisories/GHSA-rpx2-p6hp-x5gj\n\tjsonFileName, ok := packageManifestNames[pkgType]\n\tif !ok {\n\t\treturn errors.New(\"invalid marketplace package type\")\n\t}\n\tpkg, parseErr := ParsePackageJSON(filepath.Join(srcPath, jsonFileName))\n\tif parseErr != nil || nil == pkg {\n\t\treturn errors.New(\"marketplace package manifest not found or invalid\")\n\t}\n\tif packageName != pkg.Name {\n\t\treturn fmt.Errorf(\"marketplace package name mismatch: expected [%s], got [%s]\", packageName, pkg.Name)\n\t}\n\n\tif err = replacePackageDirectory(srcPath, installPath, update); err != nil {\n\t\treturn\n\t}\n\treturn\n}\n\n// replacePackageDirectory 将 sourcePath 整目录替换到 installPath。\n// 先拷到安装目录同级的 staging，更新时再把旧目录 rename 成 backup，最后把 staging rename 成目标路径。\n// 这样新包已删除的文件不会残留，失败时也可以把 backup rename 回去。","sourceCodeStart":157,"sourceCodeEnd":193,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/bazaar/install.go#L157-L193","documentation":"installPackage maps the requested package type (plugin/theme/icon/template/widget) to its manifest filename via packageManifestNames. An unknown package type has no manifest name, so the install is rejected before any files are extracted.","triggerScenarios":"Calling InstallPackage with a pkgType string that is not one of the recognized marketplace package types.","commonSituations":"API callers passing a plugin-provided type string verbatim, typos like \"plugisn\", forward-compatibility issues when a new package kind exists client-side but not in the kernel.","solutions":["Use a supported package type: plugin, theme, icon, template, widget","Normalize the type string (case, whitespace) before calling","Upgrade the kernel if a new package type was introduced in a newer frontend"],"exampleFix":"// before\n// installPackage(u, \"my-pkg\", \"Plugin\", installPath, false)\n// after\n// installPackage(u, \"my-pkg\", \"plugin\", installPath, false)","handlingStrategy":"validation","validationCode":"var validTypes = map[string]bool{\"plugin\":true,\"theme\":true,\"icon\":true,\"template\":true,\"widget\":true}\nif !validTypes[pkgType] {\n    return fmt.Errorf(\"unsupported package type: %s\", pkgType)\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Keep a canonical allowlist of package types shared between frontend and kernel","Normalize/trim package type strings from API callers","When adding a new package kind, update kernel and frontend together"],"tags":["bazaar","validation","enum","install"],"backgroundTag":"invalid-enum-value","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}