Skip to content

fix(extensions): reject non-callable VCS operation watch hooks - #1080

Open
edenbuilds wants to merge 1 commit into
modem-dev:mainfrom
edenbuilds:fix/reject-vcs-operation-watch-hooks
Open

fix(extensions): reject non-callable VCS operation watch hooks#1080
edenbuilds wants to merge 1 commit into
modem-dev:mainfrom
edenbuilds:fix/reject-vcs-operation-watch-hooks

Conversation

@edenbuilds

Copy link
Copy Markdown

Summary

registerVcsAdapter validates that an operation's load field is callable, but not the optional watchSignature / watchPlan hooks. An untyped extension can register:

{
  load: async () => result,
  watchSignature: "not a function",
}

Registration currently accepts this. The watchSignature && {...} spread guard in toInternalVcsOperation treats any truthy value as present, wraps it, and the resulting TypeError only surfaces once watch planning invokes the hook — well after registration.

Fix

toInternalVcsAdapter now requires watchSignature and watchPlan to be absent or callable before accepting an operation, matching the existing behavior for a non-callable load (the whole operation entry is dropped, so lookups report "not supported" instead of failing mid-review).

Test plan

  • Added an operation with a non-callable watch hook is dropped, not wrapped to publicApiRobustness.test.ts, mirroring the existing load coverage.
  • Confirmed the new test fails on current main (TypeError path) and passes with the fix.
  • bun test packages/hunk/src/extensions/runExtension.test.ts — 51 pass, 0 fail.
  • bun run typecheck, oxfmt --check, oxlint --deny-warnings all clean on the changed files.
  • Added a patch changeset.

Fixes #763

registerVcsAdapter validated that an operation's `load` field is
callable but let `watchSignature` and `watchPlan` through unchecked.
A truthy non-function value (e.g. a typo'd string) passed the
`watchSignature && {...}` spread guard in toInternalVcsOperation and
was wrapped, so calling it threw a TypeError only once watch planning
invoked it — well after registration.

Require both optional hooks to be absent or callable before an
operation is accepted, matching the existing drop-on-`load` behavior.

Fixes modem-dev#763

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 9, 2026

Copy link
Copy Markdown

@edenbuilds is attempting to deploy a commit to the Modem Team on Vercel.

A member of the Team first needs to authorize it.

@greptile-apps

greptile-apps Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

PR author is not in the allowed authors list.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Reject malformed optional VCS operation hooks during extension registration

1 participant