siyuan-note/siyuan · error
marketplace package name mismatch: expected
Error message
marketplace package name mismatch: expected [%s], got [%s]
What it means
As a path-traversal / supply-chain safeguard (GHSA-rpx2-p6hp-x5gj), installPackage compares the `name` declared in the downloaded package's own manifest against the package name requested for installation. Any mismatch aborts the install so one package's contents can never be written into another package's directory.
Solutions
- Fix the package manifest `name` to match the marketplace-published package name and re-release
- Refresh the marketplace index / clear caches so the URL matches the package name
- If installing locally, pass the correct package name that the manifest declares
Example fix
// before: plugin.json name "old-name", installed as "new-name" // after: set plugin.json name to "new-name" and republish
Defensive patterns
Strategy: validation
Validate before calling
pkg, err := bazaar.ParsePackageJSON("plugin.json")
if err != nil || pkg.Name != expectedName {
return fmt.Errorf("archive name %q does not match requested %q", pkg.Name, expectedName)
} Prevention
- Keep the manifest `name` in sync with the marketplace package name on every rename
- Fetch package URLs only from a trusted, current index
- Never install from ad-hoc URLs outside the marketplace flow (the name check is a supply-chain guard)
When it happens
Trigger: Downloading package A but its manifest declares name B — e.g. the index URL for pkgName points at a different package's archive, or the author renamed the package without updating the manifest.
Common situations: Tampered or misconfigured marketplace index entries; author forgot to bump `name` in plugin.json after a rename; malicious archives crafted to overwrite arbitrary install dirs; stale caches pairing names with wrong URLs.
Understand the failure class
Background: "invalid id" errors: invalid identifier format — why libraries reject IDs before lookup, and how to fix them — this error's family across 37 libraries.
Related errors
- invalid marketplace package manifest
- marketplace package manifest not found or invalid
- multiple marketplace package manifests found
- 199
- Argon2id Iterations too low (minimum 3)
AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19).
Data as JSON: /api/errors/9bcc967426ea3f66.
Report an issue: GitHub.
Appendix: source
Thrown at kernel/bazaar/install.go:182
}
srcPath := unzipPath
if 1 == len(dirs) && dirs[0].IsDir() {
srcPath = filepath.Join(unzipPath, dirs[0].Name())
}
// 校验下载包自身声明的名称与请求安装的包名一致,防止把其他包的内容写入指定目录
// https://github.com/siyuan-note/siyuan/security/advisories/GHSA-rpx2-p6hp-x5gj
jsonFileName, ok := packageManifestNames[pkgType]
if !ok {
return errors.New("invalid marketplace package type")
}
pkg, parseErr := ParsePackageJSON(filepath.Join(srcPath, jsonFileName))
if parseErr != nil || nil == pkg {
return errors.New("marketplace package manifest not found or invalid")
}
if packageName != pkg.Name {
return fmt.Errorf("marketplace package name mismatch: expected [%s], got [%s]", packageName, pkg.Name)
}
if err = replacePackageDirectory(srcPath, installPath, update); err != nil {
return
}
return
}
// replacePackageDirectory 将 sourcePath 整目录替换到 installPath。
// 先拷到安装目录同级的 staging,更新时再把旧目录 rename 成 backup,最后把 staging rename 成目标路径。
// 这样新包已删除的文件不会残留,失败时也可以把 backup rename 回去。
func replacePackageDirectory(sourcePath, installPath string, update bool) (err error) {
packageInstallLock.Lock()
defer packageInstallLock.Unlock()
if err = os.MkdirAll(filepath.Dir(installPath), 0755); err != nil {
return
}View on GitHub (pinned to 9f775e8a12)