Repository navigation
[NO-TICKET] Stop map --upload crashing the build on a map with an undefined field - #355
Merged
Merged
Conversation
…efined field The input-map identity refused any property whose value is undefined, while the upload's JSON.stringify simply omits it. The identity now omits it too, so the digest names the document the server receives. An identity failure no longer fails the build: the map uploads unbound, as detect-only. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
/review |
|
Properly handles undefined map fields and avoids build crashes. 🎯 Quality: 100% Elite · 📦 Size: Small 📈 This month: Your 174th PR — above team average · Averaging Excellent |
daniloradovic
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changed
patchstack-connect map --uploadno longer crashes the build when the attack-surface map contains a property set toundefined. Before, a prebuild hook likepatchstack-connect scan && patchstack-connect map --upload && vite buildstopped withNonCanonicalInputMap: the input map contains a value with no JSON form (undefined), so the bundler never ran.Why it crashed
In a prebuild hook,
map --uploadhashes the map to get the build identity it writes into the rules file. The hashing code accepted only values that have a JSON form, and threw onundefined. The upload itself sends the map throughJSON.stringify, which leavesundefinedproperties out. So the hash refused a map that the upload would have sent without any problem.Fix
src/input-map-id.ts: an object property whose value isundefinedis left out of the canonical form, just as it is left out of the uploaded body. The digest still names exactly the document the server receives. Anundefinedarray element is still refused, because the upload would turn it intonulland the two forms would no longer match.src/map-command.ts: if the identity still can't be computed, the build carries on. It logs "could not bind this map to the runtime guard", and the map uploads with no build id, so rules made from it detect only and don't block. The rest ofmap --uploadalready handles Patchstack problems this way (it never fails the user's build), and an identity failure now gets the same treatment.tests/input-map-id.test.ts: covers a map withundefinedproperties hashing the same as its JSON round-trip, and anundefinedarray element still being refused. The pinned digest test is unchanged, so existing identities don't move.Verified
npm test(4281 passed, 7 skipped) andnpm run typecheckboth pass.Out of scope, worth a follow-up
This PR doesn't track down which analyser field ends up
undefined. The identity is now correct whatever the answer, but the producer could also normalise optional fields to absent-or-null so the map document stays tidy.Docs: not needed. No flag, output format or documented step changes. The only new output is the existing "could not bind" line, now also reached from an identity failure.
Field test: none outstanding.
AGENT-INSTALL.md, theguidechecklist and the install prompt are untouched.🤖 Generated with Claude Code