iloveeyjafjalla opened a new issue, #6191: URL: https://github.com/apache/rocketmq-dashboard/issues/6191
# [Bug] CRLF checkout rejects verified toggle-selection license and aborts web build ### Before Creating the Bug Report - [x] I searched the repository issues and pull requests and believe this frontend build defect is not already tracked by a dedicated issue. - [x] This is a RocketMQ Studio defect in this repository. - [x] Reproduced on `rocketmq-studio` at the commit below. ### Studio Version Branch: `rocketmq-studio` Commit: `5e4c39b053c35a5598cc79ff331b8a54e649d7b1` Built from source; failure occurs before deployment. ### Runtime Environment Windows 11, version 10.0.26200; Git for Windows 2.49.0. The installed Git system configuration sets `core.autocrlf=true`. No database, browser interaction, or deployed Studio instance is needed to reproduce this build failure. ### Connected RocketMQ Cluster Not applicable: the frontend production build fails before connecting to a cluster. ### Build Toolchain Node.js 24.15.0, npm 11.12.1, locked frontend dependencies (Vite 6.4.3). The reproduction checkout used the dependencies installed with `npm ci` in an isolated sibling checkout through a local directory junction. ### Describe the Bug A Git CRLF working tree makes `npm run build` fail in `distribution-licenses`: ```text [distribution-licenses] toggle-selection code or upstream license text does not match the verified source ``` Git converts the tracked fallback `web/licenses/toggle-selection-1.0.6/LICENSE` to CRLF, but `collectLicenses` compares its raw bytes against the upstream LF SHA-256. The license text is otherwise unchanged. The same checkout also exposes two related portability failures in `npm run license:test`: the LF-only `Third-party source materials` delimiter does not strip the source-package attribution from the generated binary LICENSE, and the Vite fixture interpolates Windows paths into JavaScript string literals without escaping backslashes. ### Steps to Reproduce 1. On Windows with Git `core.autocrlf=true`, check out the `rocketmq-studio` commit above in a new directory. 2. In `web`, run `npm ci`. 3. Run `npm run build`. 4. Run `npm run license:test`. ### What Did You Expect to See? The production build and license tests should accept a normal Git checkout whose legal text differs only in LF/CRLF working-tree conversion, while still rejecting modified license text and build artifacts. ### What Did You See Instead? The production build exits 1 after transforming 8,098 modules, at the toggle-selection source-verification check. The existing license suite reports 5 tests, 2 passed, 3 failed: - `vendoredSvgAndRuntimeOnlyTest`: source-only model-logo attribution remains in the generated LICENSE. - `upstreamFallbacksKeepCompleteTextTest`: toggle-selection fallback verification rejects CRLF. - `vitePackagingAndTamperGateTest`: Rollup cannot resolve the fixture's escaped Windows import path. ### Additional Context I checked the actual file diffs of all 515 open PRs in the audit snapshot, and searched both open and closed issues/PRs for the license script, Windows, CRLF, and autocrlf. This build failure was already observed in PR #5882's validation notes. Its actual four-file diff only changes cluster API/service code and tests, so it does not fix the license rejection. I am reporting the independently reproduced, still-unfixed build blocker here, rather than claiming its first discovery. PR #5346 already notes the two Windows test failures as outside its scope; its actual diff only fixes final bundle checksums. That checksum fix is already present through merged PR #5019. Issue #5601 / PR #5602 address the separate Go CLI license generator; PR #5618 addresses Go catalog files. Issue #5085 concerns the backend Maven/JAR gate. None of those actual changes fixes the tracked frontend fallback's CRLF/hash mismatch. Proposed scope: fix the frontend build's rejection of the tracked fallback under Git CRLF conversion while preserving source/content verification. Add LF/CRLF and genuine text-tampering regression coverage; address the known test portability problems only as needed to verify the same frontend license pipeline. No dependency upgrade, deployment change, or UI change is proposed. AI assistance (OpenAI Codex) was used for investigation and automated reproduction on the Windows environment described above. The logs are actual executed checks; no deployment or cluster test is claimed. ### Are You Willing to Submit a Pull Request? - [x] Yes, I intend to submit one focused fix PR to `rocketmq-studio` and link this issue with `Fixes #<this issue>`. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
