Skip to content

fix(registry): verify index downloads against API SHA256 before persisting - #1217

Open
detail-app[bot] wants to merge 6 commits into
mainfrom
detail/bug-fix/fix-registry-verify-index-downloads-against-api-sh-451ec1
Open

detail-app[bot] wants to merge 6 commits into
mainfrom
detail/bug-fix/fix-registry-verify-index-downloads-against-api-sh-451ec1

Conversation

@detail-app

@detail-app detail-app Bot commented Sep 6, 2026 •

Copy link
Copy Markdown
Contributor

Verify compressed registry and KiCad index checksums before atomic cache replacement to match the server contract. Let KiCad search operations report completion once after download and database opening, so failures cannot leave search stuck downloading. Keep streaming progress and quiet cache reuse, remove duplicate reporting, and cover failure and success event sequences with a focused regression.


Note

Medium Risk
Changes local cache integrity and KiCad TUI download/error signaling for registry and KiCad indexes; incorrect hash handling could block updates, but it reduces risk of persisting corrupt indexes.

Overview
Index downloads now SHA-256-check the compressed zstd stream (matching API metadata) inside write_decoded_index before atomic replace; a mismatch aborts without overwriting an existing cache.

Registry and KiCad callers pass the API version_token as the expected hash. KiCad progress reporting is split: streaming byte updates only during download, with a single terminal DownloadProgress after download and SQLite open via report_kicad_result. Cached index opens stay silent on the download channel.

KiCad open failures surface through KicadSearchResults.error and TUI toasts instead of leaving search stuck in “downloading”. Regression tests cover hash verification, download event sequences, and error visibility across modes.

Reviewed by Cursor Bugbot for commit 49f6a9e. Bugbot is set up for automated code reviews on this repo. Configure here.

@detail-app
detail-app Bot requested a review from LK September 6, 2026 02:27
@detail-app detail-app Bot assigned LK Sep 6, 2026
@detail-app detail-app Bot added the detail label Sep 6, 2026
devin-ai-integration[bot]

This comment was marked as resolved.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Left a non-blocking comment and did not approve; reviewers were not assigned. Bugbot and Security Agent completed cleanly, but this is a functional change to registry and KiCad index download verification rather than a small fixup, so human review is still required.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@akhilles
akhilles force-pushed the detail/bug-fix/fix-registry-verify-index-downloads-against-api-sh-451ec1 branch from 0edfe20 to 0c95d70 Compare September 7, 2026 04:23

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Left a non-blocking comment and did not approve; reviewers were not assigned. Cursor Bugbot completed with no findings and Security Agent was not running on this update. This remains a functional change to registry and KiCad index download verification rather than a small fixup, so human review is still required.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@akhilles
akhilles force-pushed the detail/bug-fix/fix-registry-verify-index-downloads-against-api-sh-451ec1 branch from 0c95d70 to 2ba3054 Compare September 7, 2026 14:15

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Left a non-blocking comment and did not approve; reviewers were not assigned. Cursor Bugbot completed with no findings and Security Agent was not running on this update. This remains a functional change to registry/KiCad index verification and search progress rather than a small fixup, so human review is still required.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Left a non-blocking comment and did not approve; reviewers were not assigned. Cursor Bugbot completed with no findings and Security Agent was not running on this update. This remains a functional change to registry/KiCad index verification and search progress rather than a small fixup, so human review is still required.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@akhilles
akhilles force-pushed the detail/bug-fix/fix-registry-verify-index-downloads-against-api-sh-451ec1 branch from 31ffc32 to daff31e Compare September 7, 2026 14:43
cursor[bot]

This comment was marked as resolved.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Left a non-blocking comment and did not approve; reviewers were not assigned. Cursor Bugbot was present but completed as skipped, and Security Agent was not running on this update. This remains a functional change to registry/KiCad index verification and search progress rather than a small fixup, so human review is still required.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@akhilles
akhilles force-pushed the detail/bug-fix/fix-registry-verify-index-downloads-against-api-sh-451ec1 branch from daff31e to 0bb2ed2 Compare September 7, 2026 15:22

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Left a non-blocking comment and did not approve; reviewers were not assigned. Cursor Bugbot was present but completed as skipped, and Security Agent was not running on this update. This remains a functional change to registry/KiCad index verification and search progress rather than a small fixup, so human review is still required.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@akhilles
akhilles force-pushed the detail/bug-fix/fix-registry-verify-index-downloads-against-api-sh-451ec1 branch from 0bb2ed2 to 25fab31 Compare September 7, 2026 16:02
devin-ai-integration[bot]

This comment was marked as resolved.

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Left a non-blocking comment and did not approve; reviewers were not assigned. Cursor Bugbot completed with no current findings and Security Agent was not running on this update. This remains a functional change to registry/KiCad index verification and search progress rather than a small fixup, so human review is still required.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Left a non-blocking comment and did not approve; reviewers were not assigned. Cursor Bugbot completed with no current findings and Security Agent was not running on this update. This remains a functional change to registry/KiCad index verification and search progress rather than a small fixup, so human review is still required.

Open in Web View Automation 

Sent by Cursor Approval Agent: Pull Request Router and Approver

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants