{"record":{"id":"b47193b8d7ae18cb","repo":"siyuan-note/siyuan","slug":"invalid-marketplace-package-archive","errorCode":null,"errorMessage":"invalid marketplace package archive","messagePattern":"invalid marketplace package archive","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/bazaar/local.go","lineNumber":92,"sourceCode":"\t}\n\tif manifestPath == \"\" {\n\t\terr = errors.New(\"marketplace package manifest not found\")\n\t\tcleanup()\n\t\treturn\n\t}\n\n\tpkg, err = ParsePackageJSON(manifestPath)\n\tif err != nil || pkg == nil {\n\t\terr = errors.New(\"invalid marketplace package manifest\")\n\t\tcleanup()\n\t}\n\treturn\n}\n\nfunc extractLocalPackageArchive(archivePath, destination string) error {\n\treader, err := zip.OpenReader(archivePath)\n\tif err != nil {\n\t\treturn errors.New(\"invalid marketplace package archive\")\n\t}\n\tdefer reader.Close()\n\n\tif len(reader.File) == 0 {\n\t\treturn errors.New(\"marketplace package archive is empty\")\n\t}\n\tif len(reader.File) > maxLocalPackageFileCount {\n\t\treturn errors.New(\"marketplace package contains too many files\")\n\t}\n\n\tvar declaredTotal uint64\n\tfor _, item := range reader.File {\n\t\tif item.UncompressedSize64 > maxLocalPackageFileSize {\n\t\t\treturn errors.New(\"marketplace package contains a file that is too large\")\n\t\t}\n\t\tif ^uint64(0)-declaredTotal < item.UncompressedSize64 {\n\t\t\treturn errors.New(\"marketplace package is too large\")\n\t\t}","sourceCodeStart":74,"sourceCodeEnd":110,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/bazaar/local.go#L74-L110","documentation":"extractLocalPackageArchive calls zip.OpenReader on the uploaded archive path. If the file cannot be opened as a ZIP (missing file, truncated download, not a zip at all), the specific OS/zip error is replaced with this generic error to avoid leaking internals.","triggerScenarios":"Calling ExtractLocalPackage with a path to a nonexistent file, a .zip that is actually plain text or a tar.gz, or a partially downloaded/corrupted zip.","commonSituations":"User selects a .tar.gz instead of .zip; browser download interrupted; file renamed to .zip without converting; path points to a directory.","solutions":["Verify the file exists and is a real zip (unzip -t or file command)","Re-download/re-export the package archive","Ensure the package is built as a ZIP archive, not tar/gzip","Check the path passed to InstallLocalBazaarPackage points to the archive, not a directory"],"exampleFix":"// before: path = \"/downloads/my-plugin.tar.gz\"\n// after: rebuild as zip, path = \"/downloads/my-plugin.zip\"","handlingStrategy":"validation","validationCode":"if (!fs.existsSync(zipPath) || !fs.statSync(zipPath).isFile()) throw new Error(\"archive missing\");\nif (fs.readFileSync(zipPath).subarray(0, 2).toString() !== \"PK\") throw new Error(\"not a ZIP archive\");","typeGuard":null,"tryCatchPattern":"try { await installLocalPackage(zipPath); } catch (e) { if (String(e).includes(\"invalid marketplace package archive\")) { /* repack as zip and retry once */ } }","preventionTips":["Verify archive integrity with unzip -t before installing","Export as ZIP, not tar.gz","Ensure downloads complete (check file size)"],"tags":["bazaar","zip","archive","corrupt-file"],"backgroundTag":"file-open-failed","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}