iloveeyjafjalla opened a new issue, #6191:
URL: https://github.com/apache/rocketmq-dashboard/issues/6191

   # [Bug] CRLF checkout rejects verified toggle-selection license and aborts 
web build
   
   ### Before Creating the Bug Report
   
   - [x] I searched the repository issues and pull requests and believe this 
frontend build defect is not already tracked by a dedicated issue.
   - [x] This is a RocketMQ Studio defect in this repository.
   - [x] Reproduced on `rocketmq-studio` at the commit below.
   
   ### Studio Version
   
   Branch: `rocketmq-studio`
   Commit: `5e4c39b053c35a5598cc79ff331b8a54e649d7b1`
   Built from source; failure occurs before deployment.
   
   ### Runtime Environment
   
   Windows 11, version 10.0.26200; Git for Windows 2.49.0.
   The installed Git system configuration sets `core.autocrlf=true`.
   No database, browser interaction, or deployed Studio instance is needed to 
reproduce this build failure.
   
   ### Connected RocketMQ Cluster
   
   Not applicable: the frontend production build fails before connecting to a 
cluster.
   
   ### Build Toolchain
   
   Node.js 24.15.0, npm 11.12.1, locked frontend dependencies (Vite 6.4.3).
   The reproduction checkout used the dependencies installed with `npm ci` in 
an isolated sibling checkout through a local directory junction.
   
   ### Describe the Bug
   
   A Git CRLF working tree makes `npm run build` fail in 
`distribution-licenses`:
   
   ```text
   [distribution-licenses] toggle-selection code or upstream license text does 
not match the verified source
   ```
   
   Git converts the tracked fallback 
`web/licenses/toggle-selection-1.0.6/LICENSE` to CRLF, but `collectLicenses` 
compares its raw bytes against the upstream LF SHA-256. The license text is 
otherwise unchanged.
   
   The same checkout also exposes two related portability failures in `npm run 
license:test`: the LF-only `Third-party source materials` delimiter does not 
strip the source-package attribution from the generated binary LICENSE, and the 
Vite fixture interpolates Windows paths into JavaScript string literals without 
escaping backslashes.
   
   ### Steps to Reproduce
   
   1. On Windows with Git `core.autocrlf=true`, check out the `rocketmq-studio` 
commit above in a new directory.
   2. In `web`, run `npm ci`.
   3. Run `npm run build`.
   4. Run `npm run license:test`.
   
   ### What Did You Expect to See?
   
   The production build and license tests should accept a normal Git checkout 
whose legal text differs only in LF/CRLF working-tree conversion, while still 
rejecting modified license text and build artifacts.
   
   ### What Did You See Instead?
   
   The production build exits 1 after transforming 8,098 modules, at the 
toggle-selection source-verification check.
   The existing license suite reports 5 tests, 2 passed, 3 failed:
   
   - `vendoredSvgAndRuntimeOnlyTest`: source-only model-logo attribution 
remains in the generated LICENSE.
   - `upstreamFallbacksKeepCompleteTextTest`: toggle-selection fallback 
verification rejects CRLF.
   - `vitePackagingAndTamperGateTest`: Rollup cannot resolve the fixture's 
escaped Windows import path.
   
   ### Additional Context
   
   I checked the actual file diffs of all 515 open PRs in the audit snapshot, 
and searched both open and closed issues/PRs for the license script, Windows, 
CRLF, and autocrlf.
   
   This build failure was already observed in PR #5882's validation notes. Its 
actual four-file diff only changes cluster API/service code and tests, so it 
does not fix the license rejection. I am reporting the independently 
reproduced, still-unfixed build blocker here, rather than claiming its first 
discovery.
   
   PR #5346 already notes the two Windows test failures as outside its scope; 
its actual diff only fixes final bundle checksums. That checksum fix is already 
present through merged PR #5019. Issue #5601 / PR #5602 address the separate Go 
CLI license generator; PR #5618 addresses Go catalog files. Issue #5085 
concerns the backend Maven/JAR gate. None of those actual changes fixes the 
tracked frontend fallback's CRLF/hash mismatch.
   
   Proposed scope: fix the frontend build's rejection of the tracked fallback 
under Git CRLF conversion while preserving source/content verification. Add 
LF/CRLF and genuine text-tampering regression coverage; address the known test 
portability problems only as needed to verify the same frontend license 
pipeline. No dependency upgrade, deployment change, or UI change is proposed.
   
   AI assistance (OpenAI Codex) was used for investigation and automated 
reproduction on the Windows environment described above. The logs are actual 
executed checks; no deployment or cluster test is claimed.
   
   ### Are You Willing to Submit a Pull Request?
   
   - [x] Yes, I intend to submit one focused fix PR to `rocketmq-studio` and 
link this issue with `Fixes #<this issue>`.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to