Repository navigation
fix(plugin-devkit): reject package-relative theme assets at check time - #944
Merged
vastsa merged 1 commit intoSep 23, 2026
Merged
Conversation
ADR 0255 made theme assets absolute filesystem paths and the host-core installer enforces it, but validateManifest in the SDK still accepts the package-relative spelling, so a theme plugin can pass pi-plugin check and be published while no user can install it: PLUGIN_INVALID: theme <id> asset themes/assets/wallpaper-dark.webp must be an absolute image or font path Fail the check with a actionable message that points at the migration path (ship bytes in pi.plugin.getDataPath() and reference them by absolute path, or register them at runtime with pi.themes.upsert). The shared SDK normalizer and the runtime loader keep accepting package-relative references for already-installed plugins; whether the loader should enforce ADR 0255 as well is left to the linked issue.
vastsa
added a commit
that referenced
this pull request
Sep 23, 2026
- ADR 0255: mention devkit author-time check (#944) - 08-component-spec: cross-reference SVG file-only classification (#969) - e2e-test-plan: register E2E-ATTACHMENTS-svg-file-fallback scenario (#969) - zh-CN 08-component-spec: mirror SVG exclusion rule (#969) - zh-CN 09-interaction-patterns: add §3.4 queued send with promoted-row cancel semantics (#965)
This was referenced Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
pi-plugin checknow failscontributes.themes[].assetsentries that the host-core installer rejects, with a message that names the migration path. Fixes #943 (direction A, author-time half).Problem
ADR 0255 made theme assets absolute filesystem paths and the host-core installer enforces it. The SDK validator (
isThemeAssetPath), the SDK doc comments ("may be package-relative or absolute"), and thePluginThemeContrib.assetsdoc still accept the package-relative spelling, so a theme plugin can passpi-plugin check, publish to a catalog, and then fail installation for every user with an error that reads like a plugin bug:An absolute spelling is not an escape hatch for a distributed package either: the installer requires the referenced file to already exist on the installing machine (
asset missing), so package-shipped bytes have no installable manifest spelling at all (see #943 for the full matrix).Impact
local.miku-theme1.0.0 in AIUO-Net/pi-desktop-plugins, review-approved,pi-plugin check-clean).Change
packages/plugin-devkit/src/check.tsgains one check aftervalidateManifest: for everycontributes.themes[].assetsentry whose normalized form is valid but not external (normalizeThemeAssetPath+isExternalThemeAssetPath, both already exported by the SDK), it reportstheme.asset-package-relativewith the ADR 0255 rule and the two migration routes (bytes inpi.plugin.getDataPath()referenced by absolute path, or runtime registration viapi.themes.upsert).Deliberately scoped:
Affected ADRs / specs
docs/adr/0255-theme-assets-by-absolute-path.md), which already states thatnormalizeThemeAssetPath(SDK) rejects package-relative references.Validation
New test
fails theme assets the installer rejects: package-relative paths (ADR 0255)covers: package-relative asset → error quoting the asset, the absolute-path rule, andpi.themes.upsert; absolute spelling → check stays green.E2E: NOT RUN — this change is confined to the devkit CLI's static checks (
pi-plugin check) and has no runtime surface in the desktop app; unit coverage exercises both outcomes directly. Remaining risk is limited to the wording of the new diagnostic.Compatibility / migration
pi-plugin checkbefore publishing; the message states where the bytes must live. That is the intended ADR 0255 behavior arriving at author time instead of at users' install time.