fix: DevKit 1.2.1 legacy manifest validation hotfix - #31
Conversation
Reviewer's GuideThis hotfix makes retained legacy manifest validation fail closed on any missing or unexpected field, adds coverage through source, CLI, and independently extracted artifact paths, and updates package metadata and documentation for version 1.2.1 without changing dependencies, runtime behavior, or execution authority. Flow diagram for closed legacy manifest validationflowchart LR
Inputs["Source package, CLI input, or extracted artifact"] --> Checker["check_compatibility.load"]
Checker --> Fields["Compare legacy manifest fields"]
Fields -->|"Exact set: IDENTITY, mcpServers, interface"| Accept["Compatibility check passes"]
Fields -->|"Missing or extra field"| Reject["Raise PackageError: legacy_manifest_fields_differ"]
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've found 1 issue
Prompt for AI Agents
Please address the comments from this code review:
## Individual Comments
### Comment 1
<location path="docs/compatibility/codex-2026-09.md" line_range="108-110" />
<code_context>
These links explain the migration decisions. They are not runtime authority or
permission receipts, and future availability must be checked again.
+
+## 1.2.1 retained-manifest hardening
+
+Both manifests have closed field sets in the compatibility preflight. Extra retained Codex keys (including `hooks`, `agents`, and `skills`) or missing expected keys make the diagnostic fail. This validates the reviewed package shape, not the safety of arbitrary modified code, a signature, host permission, or execution authority.
</code_context>
<issue_to_address>
**nitpick:** The compatibility document's new 1.2.1 section conflicts with its unchanged introduction, which still presents DevKit 1.2.0 as the current release; readers receive contradictory current-version guidance.
**Suggested fix:** Update the document's current-release references from 1.2.0 to 1.2.1 while retaining historical references where appropriate.
</issue_to_address>Sourcery assessment
Needs a human reviewer. If the closed-field check is wrong, it could reject a valid legacy manifest and prevent the compatibility preflight or package workflow from accepting it, or fail to enforce the reviewed runtime surface. Reverting the checker and versioned package changes restores the prior behavior, with no persisted data or irreversible side effect.
| ## 1.2.1 retained-manifest hardening | ||
|
|
||
| Both manifests have closed field sets in the compatibility preflight. Extra retained Codex keys (including `hooks`, `agents`, and `skills`) or missing expected keys make the diagnostic fail. This validates the reviewed package shape, not the safety of arbitrary modified code, a signature, host permission, or execution authority. |
There was a problem hiding this comment.
nitpick: The compatibility document's new 1.2.1 section conflicts with its unchanged introduction, which still presents DevKit 1.2.0 as the current release; readers receive contradictory current-version guidance.
Suggested fix: Update the document's current-release references from 1.2.0 to 1.2.1 while retaining historical references where appropriate.
Summary
Hotfix for the substantive Sourcery finding posted after #29 merged: #29 (comment)
.codex-plugin/plugin.json, rejecting missing fields and extra entries such ashooks,agents,skills,commands, or unknown metadata.This remains a read-only diagnostic. It does not prove arbitrary modified code is safe or grant any host/execution authority. No runtime tool, permission, transport or dependency upgrade is included.
Verification
git diff --checkpass.uv lock --checkpasses. Only the root project version changed in the lock; dependencies are unchanged.f27abf30e91b67277865ae5afb2aafe765732b50.No release/tag or marketplace publication has been performed.
Summary by Sourcery
Harden legacy manifest validation and release the package as version 1.2.1.
Bug Fixes:
Enhancements:
Build:
Documentation:
Tests: