siyuan-note/siyuan · error
invalid package name
Error message
invalid package name: %s
What it means
parseBazaarRatingRegion unmarshals the region file into a map of package name -> raw rating distribution and validates each key with IsValidPackageName, which enforces a safe cross-platform directory name (1-255 printable UTF-8 bytes, no leading dot/space, no trailing dot/space, no '..', no <>&'":/\|?*, not a Windows reserved name). A key that fails this check aborts the whole region file parse with this error. This guards against corrupt or malicious CDN data being used as install directory names.
Solutions
- Log the offending package name from the error and fix the entry at the source (the ratings generation pipeline or the CDN file)
- If the file is an old schema (repo-URL keys), regenerate the region files with plain package names as keys
- Validate the ratings JSON with the same rules as IsValidPackageName before publishing it to the CDN
- If serving cached data, clear the stale bucket so the corrected file is fetched
Example fix
// before (in ratings source data)
{"siyuan-note/sample-plugin-md": [1,2,3,4,5]} // slash makes it invalid
// after
{"sample-plugin-md": [1,2,3,4,5]} Defensive patterns
Strategy: validation
Validate before calling
for name := range rawRatings {
if !bazaar.IsValidPackageName(name) {
return fmt.Errorf("region file has invalid package name: %q", name)
}
} Try / catch
dist, err := parseBazaarRatingRegion(data)
if err != nil && strings.HasPrefix(err.Error(), "invalid package name") {
log.Warnf("skipping malformed ratings region file: %v", err)
return map[string]bazaarRatingDistribution{}
} Prevention
- Publish ratings files keyed by plain package names, never repo slugs or paths
- Run the same IsValidPackageName rules in the ratings generation pipeline before upload
- Never hand-edit CDN rating JSON; regenerate from source data
- Pin/validate the region file schema version
When it happens
Trigger: Calling fetchBazaarRatingRegion / parseBazaarRatingRegion on a region JSON whose top-level object contains a key like "", ".hidden", "a/b", "CON", "pkg ", or a >255-byte name — typically from a tampered, hand-edited, or wrongly generated ratings file, or an old-format file where keys were repo URLs like "user/repo@version" instead of package names.
Common situations: The rating stat pipeline was changed to emit repo slugs or IDs instead of package names; someone hand-edited the CDN JSON; a stale ratings file from a previous schema is cached and served; the region files were regenerated from a source containing invalid placeholder names.
Understand the failure class
Background: "invalid id" errors: invalid identifier format — why libraries reject IDs before lookup, and how to fix them — this error's family across 37 libraries.
Related errors
- invalid rating distribution length for package
- Field [ ] must not be empty
- invalid bazaar index packages
- invalid marketplace package manifest
- invalid null bazaar index
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/439a8c87fb997f67.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/bazaar/rating.go:435
return nil, err
}
if 200 != resp.StatusCode {
return nil, fmt.Errorf("unexpected status code: %d", resp.StatusCode)
}
ret, err = parseBazaarRatingRegion(buf.Bytes())
return
}
func parseBazaarRatingRegion(data []byte) (ret map[string]bazaarRatingDistribution, err error) {
raw := map[string]json.RawMessage{}
if err = json.Unmarshal(data, &raw); nil != err {
return nil, err
}
ret = make(map[string]bazaarRatingDistribution, len(raw))
for packageName, rawDistribution := range raw {
if !IsValidPackageName(packageName) {
return nil, fmt.Errorf("invalid package name: %s", packageName)
}
var values []int64
if err = json.Unmarshal(rawDistribution, &values); nil != err {
return nil, err
}
if 5 != len(values) {
return nil, fmt.Errorf("invalid rating distribution length for package: %s", packageName)
}
distribution := bazaarRatingDistribution(values)
if !validBazaarRatingDistribution(distribution) {
return nil, fmt.Errorf("invalid rating distribution for package: %s", packageName)
}
ret[packageName] = distribution
}
return
}
func mergeBazaarRatingRegions(regions [bazaarRatingRegionCount]bazaarRatingRegionResult) map[string]*PackageRating {View on GitHub (pinned to 9f775e8a12)