Repository navigation
fix(skills): key ownership tracking on owner/repo, not the leaf directory name #2052
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Daniel Meppiel (danielmeppiel)
merged 4 commits into
microsoft:main
from
nadav-y:fix/skill-ownership-identity-collision
Jul 10, 2026
Merged
Changes from 1 commit
Commits
Show all changes
4 commits
Select commit
Hold shift + click to select a range
a212abf
fix(skills): key ownership tracking on owner/repo, not the leaf direc…
nadav-y edcd4df
chore: spec-conformance waiver for skill-ownership-identity-collision…
nadav-y cdabb2c
docs: add PR reference to skill-ownership-collision CHANGELOG entry
nadav-y 7f27447
Merge branch 'main' into fix/skill-ownership-identity-collision
danielmeppiel File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
119 changes: 119 additions & 0 deletions
119
tests/unit/install/phases/test_lockfile_cross_package_reconcile.py
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,119 @@ | ||
| """Regression traps for cross-package deployed-file ownership reconciliation. | ||
|
|
||
| ``ctx.package_deployed_files`` is populated once per dep_key, independently, | ||
| by that dep's own integration call (see ``install/template.py``). When two | ||
| different packages' primitives resolve to the same on-disk path -- a name | ||
| collision, e.g. two repos both shipping a skill called ``shared-topic`` -- | ||
| each package's own integration call correctly and independently reports "I | ||
| wrote this path" at the moment it ran. Without reconciliation, BOTH entries | ||
| end up claiming ``deployed_files`` for a path only one of them actually | ||
| owns on disk -- a lockfile integrity bug: a future ``apm uninstall`` or | ||
| ``apm audit`` on the "losing" package would act on a file it does not | ||
| control. See ``LockfileBuilder._reconcile_cross_package_deployed_files``. | ||
| """ | ||
|
|
||
| from __future__ import annotations | ||
|
|
||
| from types import SimpleNamespace | ||
|
|
||
| from apm_cli.deps.lockfile import LockedDependency, LockFile | ||
| from apm_cli.install.phases.lockfile import LockfileBuilder | ||
|
|
||
|
|
||
| def _target(name, root_dir=".claude"): | ||
| return SimpleNamespace(name=name, root_dir=root_dir, primitives={}) | ||
|
|
||
|
|
||
| def _ctx(*, package_deployed_files, existing_lockfile=None, targets=None, project_root): | ||
| return SimpleNamespace( | ||
| package_deployed_files=package_deployed_files, | ||
| existing_lockfile=existing_lockfile, | ||
| targets=targets or [_target("claude")], | ||
| project_root=project_root, | ||
| ) | ||
|
|
||
|
|
||
| class TestReconcileCrossPackageDeployedFiles: | ||
| def test_colliding_path_kept_only_on_last_writer(self, tmp_path) -> None: | ||
| """Two dep_keys both report the same path; only the last (the actual | ||
| on-disk owner, under sequential integration order) keeps it.""" | ||
| package_deployed_files = { | ||
| "orga/shared-skill": [".claude/skills/shared-topic/SKILL.md"], | ||
| "orgb/shared-skill": [".claude/skills/shared-topic/SKILL.md"], | ||
| } | ||
| ctx = _ctx(package_deployed_files=package_deployed_files, project_root=tmp_path) | ||
|
|
||
| LockfileBuilder(ctx)._reconcile_cross_package_deployed_files() | ||
|
|
||
| assert package_deployed_files["orga/shared-skill"] == [] | ||
| assert package_deployed_files["orgb/shared-skill"] == [ | ||
| ".claude/skills/shared-topic/SKILL.md" | ||
| ] | ||
|
|
||
| def test_non_colliding_paths_are_untouched(self, tmp_path) -> None: | ||
| """Normal case: no two dep_keys share a path -- nothing is stripped.""" | ||
| package_deployed_files = { | ||
| "orga/repo-a": [".claude/skills/topic-a/SKILL.md"], | ||
| "orgb/repo-b": [".claude/skills/topic-b/SKILL.md"], | ||
| } | ||
| ctx = _ctx(package_deployed_files=package_deployed_files, project_root=tmp_path) | ||
|
|
||
| LockfileBuilder(ctx)._reconcile_cross_package_deployed_files() | ||
|
|
||
| assert package_deployed_files["orga/repo-a"] == [".claude/skills/topic-a/SKILL.md"] | ||
| assert package_deployed_files["orgb/repo-b"] == [".claude/skills/topic-b/SKILL.md"] | ||
|
|
||
| def test_partial_collision_only_strips_the_shared_path(self, tmp_path) -> None: | ||
| """A dep_key with multiple deployed files only loses the ONE path | ||
| another dep_key also claims -- its other files are untouched.""" | ||
| package_deployed_files = { | ||
| "orga/shared-skill": [ | ||
| ".claude/skills/shared-topic/SKILL.md", | ||
| ".claude/skills/unique-to-a/SKILL.md", | ||
| ], | ||
| "orgb/shared-skill": [".claude/skills/shared-topic/SKILL.md"], | ||
| } | ||
| ctx = _ctx(package_deployed_files=package_deployed_files, project_root=tmp_path) | ||
|
|
||
| LockfileBuilder(ctx)._reconcile_cross_package_deployed_files() | ||
|
|
||
| assert package_deployed_files["orga/shared-skill"] == [ | ||
| ".claude/skills/unique-to-a/SKILL.md" | ||
| ] | ||
| assert package_deployed_files["orgb/shared-skill"] == [ | ||
| ".claude/skills/shared-topic/SKILL.md" | ||
| ] | ||
|
|
||
| def test_attach_deployed_files_end_to_end_only_winner_recorded(self, tmp_path) -> None: | ||
| """End-to-end through _attach_deployed_files: the lockfile entry for | ||
| the losing package must not claim deployed_files for the collided | ||
| path, and must not resurrect it from a prior lockfile either.""" | ||
| key_a = "orga/shared-skill" | ||
| key_b = "orgb/shared-skill" | ||
| collided_path = ".claude/skills/shared-topic/SKILL.md" | ||
|
|
||
| prior = LockFile() | ||
| prior.add_dependency( | ||
| LockedDependency( | ||
| repo_url=key_a, | ||
| deployed_files=[collided_path], | ||
| deployed_file_hashes={collided_path: "sha256:aaa"}, | ||
| ) | ||
| ) | ||
|
|
||
| new = LockFile() | ||
| new.add_dependency(LockedDependency(repo_url=key_a)) | ||
| new.add_dependency(LockedDependency(repo_url=key_b)) | ||
|
|
||
| ctx = _ctx( | ||
| package_deployed_files={key_a: [collided_path], key_b: [collided_path]}, | ||
| existing_lockfile=prior, | ||
| targets=[_target("claude")], | ||
| project_root=tmp_path, | ||
| ) | ||
| LockfileBuilder(ctx)._attach_deployed_files(new) | ||
|
|
||
| dep_a = new.get_dependency(key_a) | ||
| dep_b = new.get_dependency(key_b) | ||
| assert collided_path not in (dep_a.deployed_files or []) | ||
| assert collided_path in dep_b.deployed_files |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.