fix: reject duplicate bundle components - #4467
Conversation
Assisted-by: GitHub Copilot (model: gpt-5.6-sol, autonomous) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
馃煛 Changes recommended
Cross-kind duplicate-ID allowance needs regression coverage before approval.
Once you've addressed the issues Copilot identified, you can request another Copilot review.
Pull request overview
Adds bundle-manifest validation to reject duplicate component IDs within the same component kind.
Changes:
- Tracks
(kind, id)pairs during structural validation. - Adds regression coverage for duplicate extensions.
File summaries
| File | Description |
|---|---|
src/specify_cli/bundler/models/manifest.py |
Rejects duplicate component declarations. |
tests/contract/test_manifest_schema.py |
Tests same-kind duplicate rejection. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 1
- Review effort level: Balanced
馃挕 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| def test_duplicate_component_in_same_kind_is_rejected(): | ||
| data = valid_manifest_dict() | ||
| data["provides"]["extensions"].append( | ||
| {"id": "ext-a", "version": "9.9.9"} | ||
| ) | ||
|
|
||
| errors = BundleManifest.from_dict(data).structural_errors() | ||
|
|
||
| assert any( | ||
| "duplicate extension 'ext-a'" in error.lower() | ||
| for error in errors | ||
| ) |
There was a problem hiding this comment.
Addressed on 8376e332: added explicit regression coverage proving the same component ID remains valid across different kinds. Full runnable suite: 7,533 passed, 195 skipped; Ruff and CLI smoke are clean. Posted on behalf of @marcelsafin by GitHub Copilot (model: GPT-5.6 Sol).
Assisted-by: GitHub Copilot (model: gpt-5.6-sol, autonomous) Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
馃煝 Approval recommended
The change is small, well-scoped, and backed by targeted tests that cover both the rejection behavior and the cross-kind allowance contract.
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0 new
- Review effort level: Lite
Description
Reject duplicate component declarations within the same bundle component kind.
Previously, duplicate
(kind, id)entries passed structural validation. Duringinstallation, the first entry won and later declarations were silently skipped,
including conflicting version pins or preset options. Validation now reports
the duplicate before resolution or installation; identical IDs in different
component kinds remain valid.
Testing
uv run specify --helpuv sync && uv run pytestTargeted:
tests/contract/test_manifest_schema.py(39 passed).Full suite: 7,533 passed, 195 skipped. One existing PowerShell-launcher test
was omitted because
pwshis unavailable locally; it fails identically on theunchanged upstream commit.
AI Disclosure
GitHub Copilot (GPT-5.6 Sol) autonomously reproduced the bug, wrote the
regression test and implementation, and ran verification under
@marcelsafin's direction and review.