Skip to content

fix(compose): guard non-mapping service field in extension manifests - #5953

Closed
vaibhavsrv wants to merge 1 commit into
Osmantic:public-betafrom
vaibhavsrv:fix/resolve-compose-manifest-service-mapping
Closed

vaibhavsrv wants to merge 1 commit into
Osmantic:public-betafrom
vaibhavsrv:fix/resolve-compose-manifest-service-mapping

Conversation

@vaibhavsrv

Copy link
Copy Markdown
Contributor

Fixes #5712

Why this matters

In ods/scripts/resolve-compose-stack.sh, both built-in extension discovery and user extension (data/user-extensions/) discovery evaluate extension manifests for GPU backend compatibility and compose fragment paths. In both loops, service is retrieved via manifest.get("service", {}) followed immediately by service.get("gpu_backends", ...).

If an extension manifest contains a scalar or list value for service: (such as service: "oops" or hand-edited / corrupted backup restoration), manifest.get("service") returns the non-dict object. When service.get(...) is evaluated, Python raises an uncaught AttributeError: 'str' object has no attribute 'get'. Because the --skip-broken handler only classifies YAML/JSON syntax errors, KeyError, and TypeError as recoverable, AttributeError propagates unhandled and causes the resolver to crash on every CLI invocation, bricking commands like ods status, ods start, etc.

This change explicitly guards service to verify isinstance(service, dict) before dereferencing child properties in both loops. When service is not a mapping, a warning is printed to stderr and the invalid extension is skipped without crashing the stack resolver.

Validation

  • Baseline reproduction: Creating a test extension with service: "oops" caused resolve-compose-stack.sh to crash with AttributeError: 'str' object has no attribute 'get' with exit code 1 even when --skip-broken was specified.
  • Post-fix verification: Running ods/tests/test_resolve_compose_service_mapping.py verifies that both scalar strings and list structures for service: emit a non-fatal warning to stderr and allow stack resolution to complete successfully with exit code 0.
  • Telemetry: Resolver test suites pass: test_resolve_compose_service_mapping.py and test-resolve-compose-resilient.sh pass cleanly. Wired into Linux CI workflow under the compose resolution test step.

Overlap check

Risk / AI disclosure

AI-assisted investigation, implementation, and test regressions. This strengthens defensive schema validation on parsed extension manifests to prevent unhandled Python exceptions. Independent human review and platform/runtime qualification remain gates. No running configuration, deployment or upstream merge changed.

Follow-up integration evidence

Composed with #5871, #5951, and #5952 at HEAD without conflicts. Production and test diffs passed together; resolver and compose contracts remain intact.
Backlog composition was local-only (production/test diffs, excluding workflow/Makefile wiring); it is not an upstream merge or independent human approval. Declared live-review gates remain open.

@Lightheartdevs

Copy link
Copy Markdown
Collaborator

Thanks for this contribution. public-beta was promoted into main on 2026-09-24 and no longer receives changes, so we're closing pull requests that target it. This isn't a judgment on the change itself. If it's still needed, please rebase onto main and open a focused PR. See #7253 for details and the contribution policy.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants