Sitelet https://github.com/tangle-network/agent-integrations/pull/264
Skip to content

fix(connectors): load the native clients inside the execute path - #264

Merged
drewstone merged 1 commit into
mainfrom
fix/worker-safe-subpaths
Aug 9, 2026
Merged

drewstone merged 1 commit into
mainfrom
fix/worker-safe-subpaths

Conversation

@drewstone

Copy link
Copy Markdown
Contributor

Closes #263.

/catalog and /specs describe connectors. A Worker product reads them to render an integrations page or build a tool list, and never executes one — but both entries statically reached two native Node clients, so the bundle failed on a file the product never intended to run:

[UNLOADABLE_DEPENDENCY] … @duckdb+node-bindings-linux-x64/duckdb.node
[UNRESOLVED_IMPORT]     … cpu-features/build/Release/cpufeatures.node

The path is specs/registry → bundled-manifests → import * as bundledAdapters from './adapters/index.js', which re-exports every adapter so their static manifests can be read. duckdb.ts imported @duckdb/node-api and sftp.ts imported ssh2-sftp-client at module top level, so reading manifest data pulled both clients in.

The manifest is data; only execution needs a client. Both now load inside the execute path, and the types stay static — they erase.

Proof

The graph, walked before and after (from the built dist/catalog.js + dist/specs.js):

files reached native client
before 11 chunk-4JDM3HRZ.js -> @duckdb/node-api
after 11 none

A test that fails when it comes back. src/worker-safe-subpaths.test.ts walks the source graph from both entries, skipping import type (erases) and await import (the point). Restoring one static import turns it red and names the file:

+   "connectors/adapters/sftp.ts statically imports ssh2-sftp-client"
  Tests  2 failed | 1 passed (3)

Its third case points the same matcher at a known-bad line and asserts one hit, so the two green assertions cannot be vacuous.

Suite: 685 files / 5,158 tests passed. pnpm typecheck exit 0, pnpm build exit 0.

What it unblocks

legal-agent is pinned to ^0.52.0 today purely because of this — the only product off the latest integrations. It moves to latest as soon as this publishes.

A Worker product that imports only /catalog and /specs — to describe connectors,
never to execute one — could not bundle. specs/registry reaches
bundled-manifests, which re-exports every adapter so their static manifests can
be read, and two adapters imported a native client at module top level. Reading
manifest DATA therefore pulled @duckdb/node-api and ssh2-sftp-client's
cpu-features into the bundle, and a Worker cannot load a .node file at all.

Both clients now load when a query or a transfer runs. The types stay static and
erase. A source-graph test walks the two entries and fails on a native import
that returns, and asserts it can still see one so it cannot pass vacuously.

Closes #263

@tangletools tangletools left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Auto-approved drewstone PR — e5db016f

This PR was opened by the trusted drewstone account.
The full PR reviewer audit still runs separately and will publish findings if it detects issues.

tangletools · auto-approval · reason: drewstone_author · 2026-08-09T23:42:53Z

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Worker consumers cannot bundle /catalog or /specs: both statically reach native clients

2 participants