Skip to content

fix(marketplace): harden git plugin install and cleanup - #14492

Merged
marius-kilocode merged 2 commits into
mainfrom
fix/marketplace-git-plugin-hardening
Sep 23, 2026
Merged

marius-kilocode merged 2 commits into
mainfrom
fix/marketplace-git-plugin-hardening

Conversation

@marius-kilocode

@marius-kilocode marius-kilocode commented Sep 23, 2026 •

Copy link
Copy Markdown
Collaborator

What Problem This Solves

Follow-up fixes for git-hosted Marketplace plugins (#14485):

  • A ~/ repository spec passed validation but was cloned as https://~/..., so it always failed.
  • A failed clone left a .tmp-* staging directory in the plugin cache.
  • Identity normalization rewrote backslashes on POSIX and could change a legal filename.
  • The install dialog described every plugin as an "npm plugin", which is wrong for git-sourced plugins.

Why This Change Was Made

  • cloneUrl now expands ~/ to the home directory before it falls through to the shorthand https:// branch.
  • cloneInto wraps the clone and checkout in a try/catch that removes the staging directory and rethrows.
  • normalizeRepo converts backslashes only for Windows-style paths (drive letter or UNC). POSIX paths are left unchanged.
  • The plugin modal text no longer names npm as the source, across en and all 19 locales.
  • The marketplace and plugins docs document plugin install and git-source publishing, which were missing.

A shared-clone cache deletion on uninstall was drafted and dropped: the cache lives under a shared global cache keyed by identity and ref, so it is shared across projects and worktrees. Checking only the caller's directory tree could delete a clone another worktree still installs. The clone cache is intentionally left in place on uninstall.

User Impact

  • ~/ git plugins now install.
  • Failed clones no longer accumulate staging directories.
  • POSIX repository paths that contain a backslash keep a stable identity.
  • The install dialog is accurate for git plugins.

Evidence

  • packages/opencode: bun test ./test/kilocode/plugin-git-source.test.ts plus the marketplace suite (marketplace-plugin, marketplace-installer, marketplace-api, marketplace-plugin-http) -> 43 pass, 281 assertions. New cases cover ~/ expansion, staging cleanup on a failed clone, POSIX backslash identity, Windows and file URL identity, and git vs npm/local identity collision.
  • bun run typecheck in packages/opencode -> pass. packages/kilo-i18n typecheck and the i18n keys guard -> pass.
  • script/check-md-table-padding.ts -> pass. Scoped oxlint on the changed files -> 0 errors.

Expand `~/` repository paths in cloneUrl instead of turning them into an
https URL. Remove the staging directory when a clone fails so no `.tmp-*`
folder is left in the cache.

Keep backslashes in POSIX paths during identity normalization and convert
them only for Windows-style paths, so a legal POSIX filename is not
rewritten.

Delete the cloned plugin cache on uninstall when no remaining scope still
installs the plugin, and keep it when another scope still uses it.

Stop describing every plugin as an npm plugin in the install dialog, and
document plugin install and git-source publishing in the marketplace and
plugins docs.
Comment thread packages/opencode/src/kilocode/marketplace/installer.ts Outdated
Comment thread packages/opencode/src/kilocode/plugin/git-source.ts Outdated
@kilo-code-bot

kilo-code-bot Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Code Review Summary

Status: No Issues Found | Recommendation: Merge

The follow-up commit removes the shared-clone cache cleanup on uninstall, resolving both prior findings, and simplifies stripPluginFromFile to return a plain status string. No new issues in the changed code.

Files Reviewed (4 files)
  • .changeset/marketplace-git-plugin-hardening.md
  • packages/opencode/src/kilocode/marketplace/installer.ts
  • packages/opencode/src/kilocode/plugin/git-source.ts
  • packages/opencode/test/kilocode/plugin-git-source.test.ts
Previous Review Summary (commit 43f5d55)

Current summary above is authoritative. Previous snapshots are kept for context only.

Previous review (commit 43f5d55)

Status: 2 Issues Found | Recommendation: Address before merge

Overview

Severity Count
CRITICAL 0
WARNING 1
SUGGESTION 1

The git-source hardening looks correct overall: ~/ expansion, staging cleanup on failed clone, Windows-only backslash normalization, and the flock-guarded cache removal are all sound, and the new tests exercise the real implementation. Two gaps are noted in the new cache-removal path.

Fix these issues in Kilo Cloud

Issue Details (click to expand)

WARNING

File Line Issue
packages/opencode/src/kilocode/marketplace/installer.ts 380 removeUnusedPluginCache only checks the caller's project directory via detect, so a removal in one worktree can delete the shared clone another worktree's project config still installs

SUGGESTION

File Line Issue
packages/opencode/src/kilocode/plugin/git-source.ts 220 removeGitPluginCache deletes only the removed spec's ref cache entry; clones for other refs of the same identity linger
Files Reviewed (26 files)
  • .changeset/marketplace-git-plugin-hardening.md - no issues
  • packages/kilo-docs/pages/automate/extending/plugins.md - no issues
  • packages/kilo-docs/pages/customize/marketplace.md - no issues
  • packages/kilo-i18n/src/{ar,br,bs,da,de,en,es,fr,it,ja,ko,nl,no,pl,ru,th,tr,uk,zh,zht}.ts - no issues (all 20 locales updated consistently)
  • packages/opencode/src/kilocode/marketplace/installer.ts - 1 warning
  • packages/opencode/src/kilocode/plugin/git-source.ts - 1 suggestion
  • packages/opencode/test/kilocode/plugin-git-source.test.ts - no issues

Reviewed by deepseek-v4.1-flash · Input: 0 · Output: 0 · Cached: 0

Review guidance: REVIEW.md from base branch main

The clone cache is keyed by identity and ref under a shared global cache,
so it is shared across projects and worktrees. The removal-time check only
inspected the caller's directory tree, so removing a plugin in one worktree
could delete a clone another worktree still installs, forcing a re-clone or
failing offline.

Drop the cache deletion and the specs it needed. Uninstall leaves the
shared clone in place.
@marius-kilocode
marius-kilocode merged commit 95b45e5 into main Sep 23, 2026
35 checks passed
@marius-kilocode
marius-kilocode deleted the fix/marketplace-git-plugin-hardening branch September 23, 2026 10:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants