siyuan-note/siyuan · error

invalid package name

Error message

invalid package name: %s

What it means

parseBazaarRatingRegion unmarshals the region file into a map of package name -> raw rating distribution and validates each key with IsValidPackageName, which enforces a safe cross-platform directory name (1-255 printable UTF-8 bytes, no leading dot/space, no trailing dot/space, no '..', no <>&'":/\|?*, not a Windows reserved name). A key that fails this check aborts the whole region file parse with this error. This guards against corrupt or malicious CDN data being used as install directory names.

Solutions

  1. Log the offending package name from the error and fix the entry at the source (the ratings generation pipeline or the CDN file)
  2. If the file is an old schema (repo-URL keys), regenerate the region files with plain package names as keys
  3. Validate the ratings JSON with the same rules as IsValidPackageName before publishing it to the CDN
  4. If serving cached data, clear the stale bucket so the corrected file is fetched

Example fix

// before (in ratings source data)
{"siyuan-note/sample-plugin-md": [1,2,3,4,5]}  // slash makes it invalid
// after
{"sample-plugin-md": [1,2,3,4,5]}
Defensive patterns

Strategy: validation

Validate before calling

for name := range rawRatings {
    if !bazaar.IsValidPackageName(name) {
        return fmt.Errorf("region file has invalid package name: %q", name)
    }
}

Try / catch

dist, err := parseBazaarRatingRegion(data)
if err != nil && strings.HasPrefix(err.Error(), "invalid package name") {
    log.Warnf("skipping malformed ratings region file: %v", err)
    return map[string]bazaarRatingDistribution{}
}

Prevention

When it happens

Trigger: Calling fetchBazaarRatingRegion / parseBazaarRatingRegion on a region JSON whose top-level object contains a key like "", ".hidden", "a/b", "CON", "pkg ", or a >255-byte name — typically from a tampered, hand-edited, or wrongly generated ratings file, or an old-format file where keys were repo URLs like "user/repo@version" instead of package names.

Common situations: The rating stat pipeline was changed to emit repo slugs or IDs instead of package names; someone hand-edited the CDN JSON; a stale ratings file from a previous schema is cached and served; the region files were regenerated from a source containing invalid placeholder names.

Understand the failure class

Background: "invalid id" errors: invalid identifier format — why libraries reject IDs before lookup, and how to fix them — this error's family across 37 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/439a8c87fb997f67. Report an issue: GitHub.

Appendix: source

Thrown at kernel/bazaar/rating.go:435

		return nil, err
	}
	if 200 != resp.StatusCode {
		return nil, fmt.Errorf("unexpected status code: %d", resp.StatusCode)
	}

	ret, err = parseBazaarRatingRegion(buf.Bytes())
	return
}

func parseBazaarRatingRegion(data []byte) (ret map[string]bazaarRatingDistribution, err error) {
	raw := map[string]json.RawMessage{}
	if err = json.Unmarshal(data, &raw); nil != err {
		return nil, err
	}
	ret = make(map[string]bazaarRatingDistribution, len(raw))
	for packageName, rawDistribution := range raw {
		if !IsValidPackageName(packageName) {
			return nil, fmt.Errorf("invalid package name: %s", packageName)
		}
		var values []int64
		if err = json.Unmarshal(rawDistribution, &values); nil != err {
			return nil, err
		}
		if 5 != len(values) {
			return nil, fmt.Errorf("invalid rating distribution length for package: %s", packageName)
		}
		distribution := bazaarRatingDistribution(values)
		if !validBazaarRatingDistribution(distribution) {
			return nil, fmt.Errorf("invalid rating distribution for package: %s", packageName)
		}
		ret[packageName] = distribution
	}
	return
}

func mergeBazaarRatingRegions(regions [bazaarRatingRegionCount]bazaarRatingRegionResult) map[string]*PackageRating {

View on GitHub (pinned to 9f775e8a12)