siyuan-note/siyuan · error

marketplace package name mismatch: expected

Error message

marketplace package name mismatch: expected [%s], got [%s]

What it means

As a path-traversal / supply-chain safeguard (GHSA-rpx2-p6hp-x5gj), installPackage compares the `name` declared in the downloaded package's own manifest against the package name requested for installation. Any mismatch aborts the install so one package's contents can never be written into another package's directory.

Solutions

  1. Fix the package manifest `name` to match the marketplace-published package name and re-release
  2. Refresh the marketplace index / clear caches so the URL matches the package name
  3. If installing locally, pass the correct package name that the manifest declares

Example fix

// before: plugin.json name "old-name", installed as "new-name"
// after: set plugin.json name to "new-name" and republish
Defensive patterns

Strategy: validation

Validate before calling

pkg, err := bazaar.ParsePackageJSON("plugin.json")
if err != nil || pkg.Name != expectedName {
    return fmt.Errorf("archive name %q does not match requested %q", pkg.Name, expectedName)
}

Prevention

When it happens

Trigger: Downloading package A but its manifest declares name B — e.g. the index URL for pkgName points at a different package's archive, or the author renamed the package without updating the manifest.

Common situations: Tampered or misconfigured marketplace index entries; author forgot to bump `name` in plugin.json after a rename; malicious archives crafted to overwrite arbitrary install dirs; stale caches pairing names with wrong URLs.

Understand the failure class

Background: "invalid id" errors: invalid identifier format — why libraries reject IDs before lookup, and how to fix them — this error's family across 37 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/9bcc967426ea3f66. Report an issue: GitHub.

Appendix: source

Thrown at kernel/bazaar/install.go:182

	}

	srcPath := unzipPath
	if 1 == len(dirs) && dirs[0].IsDir() {
		srcPath = filepath.Join(unzipPath, dirs[0].Name())
	}

	// 校验下载包自身声明的名称与请求安装的包名一致,防止把其他包的内容写入指定目录
	// https://github.com/siyuan-note/siyuan/security/advisories/GHSA-rpx2-p6hp-x5gj
	jsonFileName, ok := packageManifestNames[pkgType]
	if !ok {
		return errors.New("invalid marketplace package type")
	}
	pkg, parseErr := ParsePackageJSON(filepath.Join(srcPath, jsonFileName))
	if parseErr != nil || nil == pkg {
		return errors.New("marketplace package manifest not found or invalid")
	}
	if packageName != pkg.Name {
		return fmt.Errorf("marketplace package name mismatch: expected [%s], got [%s]", packageName, pkg.Name)
	}

	if err = replacePackageDirectory(srcPath, installPath, update); err != nil {
		return
	}
	return
}

// replacePackageDirectory 将 sourcePath 整目录替换到 installPath。
// 先拷到安装目录同级的 staging,更新时再把旧目录 rename 成 backup,最后把 staging rename 成目标路径。
// 这样新包已删除的文件不会残留,失败时也可以把 backup rename 回去。
func replacePackageDirectory(sourcePath, installPath string, update bool) (err error) {
	packageInstallLock.Lock()
	defer packageInstallLock.Unlock()

	if err = os.MkdirAll(filepath.Dir(installPath), 0755); err != nil {
		return
	}

View on GitHub (pinned to 9f775e8a12)