fix(npm-resolve): 按仓库名猜名反查,低热度包不再误判为「无 npm 包」 - #64
Closed
Fishquito7 wants to merge 1 commit into
Closed
Fishquito7 wants to merge 1 commit into
Fishquito7 wants to merge 1 commit into
Conversation
npm search 接口没有 `repository:` 限定符:它被当作普通词元参与全文检索, 结果按下载量/质量分排序。只发这一条查询时,size=10 的第一页全是热门包, 「包名就等于仓库名但下载量低」的插件根本排不进去,反查因此得出 「该仓库没有 npm 包」的错误结论并把它缓存下来,安装回落到 git 通道 —— 而 git 通道正是缺构建产物、需要认证或用户网络受限时最容易失败的一条路。 改成按「仓库名 → 作者名 → repository: 兼容写法」顺序猜名,命中即返回; 每条结果仍然要过原有的铁证校验(包元数据必须指回该仓库),所以放宽检索词 不会误命中。只要有任何一条查询没能给出答案(网络/超时/解析),就返回 undefined 而不返回 null,避免把一次不确切的结论缓存成「确认无包」。 同时把 repo 段数校验收紧到恰好两段(`a/b/c` 直接返回 null,不再发无谓请求)。
Owner
|
感谢 PR,根因抓得准 —— 只发 合并前想确认两处:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
问题
目录没有下发
npmPackage时,服务端会用 npm registry 的 search 接口按 repository 地址反查官方包名(resolveNpmPackage)。但 npm search 并没有repository:限定符 —— 它被当作普通词元参与全文检索,结果按热度排序。于是只发
repository:owner/name这一条查询时,「包名就等于仓库名、但下载量低」的插件根本进不了size=10的第一页,反查得出「该仓库没有 npm 包」的错误结论并把它缓存下来,安装永远回落到 git 通道 —— 而 git 通道恰恰是缺构建产物 / 需要认证 / 用户网络受限时最容易失败的那一条。实例:
fishquito7/dsh-skill-mcp-panel(包名与仓库名一致,热度很低)反查不到,只能走 git。改动
src/server/services/install/npm-resolve.tsnpmResolveQueries(owner, name):按 仓库名 → 作者名 →repository:owner/name的顺序猜名,命中即返回。repository:写法降级为最后一条,只为兼容真把它当限定符实现的镜像源。size从 10 提到 25,让铁证校验能看见热度排名靠后的候选。undefined而不是null—— 避免把一次不确切的结论缓存成「确认无包」,那会让整个会话都退回 git 通道。repo段数校验收紧到恰好两段(a/b/c直接返回null,不再发无谓请求)。测试
tests/npm-resolve.test.tsresolveNpmPackage('fishquito7/dsh-skill-mcp-panel') === 'dsh-skill-mcp-panel'。npm run typecheck:server通过;npm test→ 86 tests / 84 pass / 0 fail / 2 skipped。一个相关观察(未在本 PR 中改动)
反查修好后,「低热度包」会开始走 npm 通道,而 npm 通道传的是裸包名(
dsh plugin add <pkg>)。DSH profile 目录里有pnpm-workspace.yaml,pnpm 的发布年龄门会让刚发布不久的版本被跳过 —— 本机 pnpm 11.7.0 实测:pnpm add dsh-skill-mcp-panel解析到的版本pnpm-workspace.yaml,无该键)2.1.0minimumReleaseAge: 02.1.2(registry latest)minimumReleaseAge: 12.1.2也就是说:发版后的 24 小时内,npm 通道会装到上一个版本。对
dsh-skill-mcp-panel来说这曾经是致命的(2.1.0在 DSH 0.1.7 上技能页白屏),其他插件也可能踩同样的坑。可选做法(属于安装通道的设计取舍,交给维护者定夺,我故意没有塞进本 PR):把 npm 通道的 target 带上目录里的版本号(
pkg@x.y.z),或在文档里把 npm 通道明确成「装 registry latest、可能滞后一个版本」。不过反查本身仍是纯收益:它修掉的是「明明有 npm 包却被判成没有」这个错误结论。