fix(registry): verify index downloads against API SHA256 before persisting - #1217
detail-app[bot] wants to merge 6 commits into
Conversation
There was a problem hiding this comment.
Stale comment
Left a non-blocking comment and did not approve; reviewers were not assigned. Bugbot and Security Agent completed cleanly, but this is a functional change to registry and KiCad index download verification rather than a small fixup, so human review is still required.
Sent by Cursor Approval Agent: Pull Request Router and Approver
0edfe20 to
0c95d70
Compare
There was a problem hiding this comment.
Stale comment
Left a non-blocking comment and did not approve; reviewers were not assigned. Cursor Bugbot completed with no findings and Security Agent was not running on this update. This remains a functional change to registry and KiCad index download verification rather than a small fixup, so human review is still required.
Sent by Cursor Approval Agent: Pull Request Router and Approver
0c95d70 to
2ba3054
Compare
There was a problem hiding this comment.
Stale comment
Left a non-blocking comment and did not approve; reviewers were not assigned. Cursor Bugbot completed with no findings and Security Agent was not running on this update. This remains a functional change to registry/KiCad index verification and search progress rather than a small fixup, so human review is still required.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Stale comment
Left a non-blocking comment and did not approve; reviewers were not assigned. Cursor Bugbot completed with no findings and Security Agent was not running on this update. This remains a functional change to registry/KiCad index verification and search progress rather than a small fixup, so human review is still required.
Sent by Cursor Approval Agent: Pull Request Router and Approver
31ffc32 to
daff31e
Compare
There was a problem hiding this comment.
Stale comment
Left a non-blocking comment and did not approve; reviewers were not assigned. Cursor Bugbot was present but completed as skipped, and Security Agent was not running on this update. This remains a functional change to registry/KiCad index verification and search progress rather than a small fixup, so human review is still required.
Sent by Cursor Approval Agent: Pull Request Router and Approver
daff31e to
0bb2ed2
Compare
There was a problem hiding this comment.
Stale comment
Left a non-blocking comment and did not approve; reviewers were not assigned. Cursor Bugbot was present but completed as skipped, and Security Agent was not running on this update. This remains a functional change to registry/KiCad index verification and search progress rather than a small fixup, so human review is still required.
Sent by Cursor Approval Agent: Pull Request Router and Approver
0bb2ed2 to
25fab31
Compare
There was a problem hiding this comment.
Stale comment
Left a non-blocking comment and did not approve; reviewers were not assigned. Cursor Bugbot completed with no current findings and Security Agent was not running on this update. This remains a functional change to registry/KiCad index verification and search progress rather than a small fixup, so human review is still required.
Sent by Cursor Approval Agent: Pull Request Router and Approver
There was a problem hiding this comment.
Left a non-blocking comment and did not approve; reviewers were not assigned. Cursor Bugbot completed with no current findings and Security Agent was not running on this update. This remains a functional change to registry/KiCad index verification and search progress rather than a small fixup, so human review is still required.
Sent by Cursor Approval Agent: Pull Request Router and Approver


Verify compressed registry and KiCad index checksums before atomic cache replacement to match the server contract. Let KiCad search operations report completion once after download and database opening, so failures cannot leave search stuck downloading. Keep streaming progress and quiet cache reuse, remove duplicate reporting, and cover failure and success event sequences with a focused regression.
Note
Medium Risk
Changes local cache integrity and KiCad TUI download/error signaling for registry and KiCad indexes; incorrect hash handling could block updates, but it reduces risk of persisting corrupt indexes.
Overview
Index downloads now SHA-256-check the compressed zstd stream (matching API metadata) inside
write_decoded_indexbefore atomic replace; a mismatch aborts without overwriting an existing cache.Registry and KiCad callers pass the API
version_tokenas the expected hash. KiCad progress reporting is split: streaming byte updates only during download, with a single terminalDownloadProgressafter download and SQLite open viareport_kicad_result. Cached index opens stay silent on the download channel.KiCad open failures surface through
KicadSearchResults.errorand TUI toasts instead of leaving search stuck in “downloading”. Regression tests cover hash verification, download event sequences, and error visibility across modes.Reviewed by Cursor Bugbot for commit 49f6a9e. Bugbot is set up for automated code reviews on this repo. Configure here.