Skip to content

fix: reject duplicate bundle components - #4467

Open
marcelsafin wants to merge 2 commits into
github:mainfrom
marcelsafin:fix/bundle-duplicate-components
Open

fix: reject duplicate bundle components#4467
marcelsafin wants to merge 2 commits into
github:mainfrom
marcelsafin:fix/bundle-duplicate-components

Conversation

@marcelsafin

@marcelsafin marcelsafin commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Description

Reject duplicate component declarations within the same bundle component kind.

Previously, duplicate (kind, id) entries passed structural validation. During
installation, the first entry won and later declarations were silently skipped,
including conflicting version pins or preset options. Validation now reports
the duplicate before resolution or installation; identical IDs in different
component kinds remain valid.

Testing

  • Tested locally with uv run specify --help
  • Ran existing tests with uv sync && uv run pytest
  • Tested with a sample project (if applicable)

Targeted: tests/contract/test_manifest_schema.py (39 passed).

Full suite: 7,533 passed, 195 skipped. One existing PowerShell-launcher test
was omitted because pwsh is unavailable locally; it fails identically on the
unchanged upstream commit.

AI Disclosure

  • I did not use AI assistance for this contribution
  • I did use AI assistance (describe below)

GitHub Copilot (GPT-5.6 Sol) autonomously reproduced the bug, wrote the
regression test and implementation, and ran verification under
@marcelsafin's direction and review.

Assisted-by: GitHub Copilot (model: gpt-5.6-sol, autonomous)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings September 8, 2026 14:37
@marcelsafin
marcelsafin requested a review from mnriem as a code owner September 8, 2026 14:37

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃煛 Changes recommended

Cross-kind duplicate-ID allowance needs regression coverage before approval.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Adds bundle-manifest validation to reject duplicate component IDs within the same component kind.

Changes:

  • Tracks (kind, id) pairs during structural validation.
  • Adds regression coverage for duplicate extensions.
File summaries
File Description
src/specify_cli/bundler/models/manifest.py Rejects duplicate component declarations.
tests/contract/test_manifest_schema.py Tests same-kind duplicate rejection.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 1
  • Review effort level: Balanced

馃挕 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +130 to +141
def test_duplicate_component_in_same_kind_is_rejected():
data = valid_manifest_dict()
data["provides"]["extensions"].append(
{"id": "ext-a", "version": "9.9.9"}
)

errors = BundleManifest.from_dict(data).structural_errors()

assert any(
"duplicate extension 'ext-a'" in error.lower()
for error in errors
)

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed on 8376e332: added explicit regression coverage proving the same component ID remains valid across different kinds. Full runnable suite: 7,533 passed, 195 skipped; Ruff and CLI smoke are clean. Posted on behalf of @marcelsafin by GitHub Copilot (model: GPT-5.6 Sol).

Assisted-by: GitHub Copilot (model: gpt-5.6-sol, autonomous)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 8, 2026 14:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃煝 Approval recommended

The change is small, well-scoped, and backed by targeted tests that cover both the rejection behavior and the cross-kind allowance contract.

Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants