Skip to content

[NO-TICKET] Stop map --upload crashing the build on a map with an undefined field - #355

Merged
mariojgt merged 1 commit into
mainfrom
fix/input-map-id-undefined
Oct 2, 2026
Merged

mariojgt merged 1 commit into
mainfrom
fix/input-map-id-undefined

Conversation

@mariojgt

@mariojgt mariojgt commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

What changed

patchstack-connect map --upload no longer crashes the build when the attack-surface map contains a property set to undefined. Before, a prebuild hook like patchstack-connect scan && patchstack-connect map --upload && vite build stopped with NonCanonicalInputMap: the input map contains a value with no JSON form (undefined), so the bundler never ran.

Why it crashed

In a prebuild hook, map --upload hashes the map to get the build identity it writes into the rules file. The hashing code accepted only values that have a JSON form, and threw on undefined. The upload itself sends the map through JSON.stringify, which leaves undefined properties out. So the hash refused a map that the upload would have sent without any problem.

Fix

  • src/input-map-id.ts: an object property whose value is undefined is left out of the canonical form, just as it is left out of the uploaded body. The digest still names exactly the document the server receives. An undefined array element is still refused, because the upload would turn it into null and the two forms would no longer match.
  • src/map-command.ts: if the identity still can't be computed, the build carries on. It logs "could not bind this map to the runtime guard", and the map uploads with no build id, so rules made from it detect only and don't block. The rest of map --upload already handles Patchstack problems this way (it never fails the user's build), and an identity failure now gets the same treatment.
  • tests/input-map-id.test.ts: covers a map with undefined properties hashing the same as its JSON round-trip, and an undefined array element still being refused. The pinned digest test is unchanged, so existing identities don't move.

Verified

npm test (4281 passed, 7 skipped) and npm run typecheck both pass.

Out of scope, worth a follow-up

This PR doesn't track down which analyser field ends up undefined. The identity is now correct whatever the answer, but the producer could also normalise optional fields to absent-or-null so the map document stays tidy.

Docs: not needed. No flag, output format or documented step changes. The only new output is the existing "could not bind" line, now also reached from an identity failure.

Field test: none outstanding. AGENT-INSTALL.md, the guide checklist and the install prompt are untouched.

🤖 Generated with Claude Code

…efined field

The input-map identity refused any property whose value is undefined, while
the upload's JSON.stringify simply omits it. The identity now omits it too, so
the digest names the document the server receives. An identity failure no
longer fails the build: the map uploads unbound, as detect-only.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@mariojgt

mariojgt commented Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

/review

@coderbuds

coderbuds Bot commented Oct 2, 2026

Copy link
Copy Markdown

Properly handles undefined map fields and avoids build crashes.

🎯 Quality: 100% Elite · 📦 Size: Small

📈 This month: Your 174th PR — above team average · Averaging Excellent

See how your team is trending →

@mariojgt
mariojgt merged commit 23fad72 into main Oct 2, 2026
23 checks passed
@mariojgt
mariojgt deleted the fix/input-map-id-undefined branch October 2, 2026 09:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants