fix: make Service Worker cache and removal outcomes truthful

SW-URL-01: canonicalize each generated root-relative manifest URL against the
registration scope once, re-check same-origin, and share that absolute identity
across install cache keys, fetch classification and cache lookup or delete.
Previously every verified asset fell through to the network.

SW-01: serve verified static requests only from the current release cache. A
CacheStorage-wide match could return a previous release's response for the same
URL while the delete targeted a cache that was never read. The worker scope
facade no longer exposes a wide match at all.

SW-02: cache reset deletes only names that parse as owned, so a foreign cache
sharing the ca-static-v1- prefix survives.

SW-03: unregister() resolving to false is a FAILED unregister, not UNREGISTERED.

SW-04: staged removal reports what happened - ABSENT, UNREGISTERED and PURGED
map to DISABLED, OWNERSHIP_MISMATCH to INCOMPATIBLE and FAILED to FAILED - so a
later release cannot delete the worker while a registration or owned cache is
still present.

SW-05: add the runtime-neutral service-worker-static-manifest codec that owns
exact row keys, the extension and content-type allowlist, the root-relative URL
rule and the length-prefixed canonical bytes. The generator and the build gate
hash those same bytes, and the build gate now decodes and recomputes the set
digest instead of type-casting the manifest.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
DongHyeonka
2026-08-14 00:25:11 +09:00
co-authored by Claude Opus 5
parent cc4e875c2d
commit 58efe6ddbd
10 changed files with 722 additions and 55 deletions
+247
View File
@@ -118,6 +118,253 @@ function workerScope() {
return { scope, clients, deleted };
}
describe("service worker static cache authority", () => {
const setDigest = `sha256:${"c".repeat(64)}` as const;
const currentCacheName = `${STATIC_CACHE_PREFIX}${setDigest.slice(
"sha256:".length,
"sha256:".length + 16,
)}`;
function staticRuntime(
caches: Readonly<{
open: (name: string) => Promise<unknown>;
keys: () => Promise<readonly string[]>;
delete: (name: string) => Promise<boolean>;
}>,
) {
return createServiceWorkerRuntime(
{
caches,
clients: { matchAll: vi.fn(async () => []) },
registrationScope: `${ORIGIN}/app/`,
skipWaiting: vi.fn(async () => {}),
fetcher: vi.fn(),
digest: vi.fn(),
} as never,
{
identity: { ...identity, staticAssetSetDigest: setDigest },
handlers: ["PWA_STATIC_ASSETS"],
manifest: {
schemaVersion: 1,
buildId: identity.buildId,
releaseId: identity.releaseId,
setDigest,
// SW-URL-01. Generator output is root-relative.
assets: [
{
url: "/assets/app.0123456789abcdef.js",
sha256: `sha256:${"d".repeat(64)}`,
bytes: 10,
contentType: "text/javascript",
},
],
},
runtimeConfigUrl: "/runtime-config.json",
releaseManifestUrl: "/release-manifest.json",
},
);
}
it("classifies a generated root-relative asset against an absolute Request URL", async () => {
const currentResponse = new Response("current", { status: 200 });
const opened: string[] = [];
const runtime = staticRuntime({
open: vi.fn(async (name: string) => {
opened.push(name);
return {
match: async () => currentResponse.clone(),
delete: async () => true,
};
}),
keys: vi.fn(async () => [currentCacheName]),
delete: vi.fn(async () => true),
});
const served = await runtime.onFetch({
method: "GET",
url: `${ORIGIN}/assets/app.0123456789abcdef.js`,
});
expect(served).not.toBeNull();
expect(opened).toEqual([currentCacheName]);
});
it("matches static responses only in the current release cache", async () => {
const previousCacheName = `${STATIC_CACHE_PREFIX}${"e".repeat(16)}`;
const previousMatch = vi.fn(
async () => new Response("previous", { status: 200 }),
);
const runtime = staticRuntime({
open: vi.fn(
async (
name: string,
): Promise<Readonly<{ match: unknown; delete: unknown }>> =>
name === previousCacheName
? {
match: previousMatch,
delete: async (): Promise<boolean> => true,
}
: {
match: async (): Promise<Response | undefined> => undefined,
delete: async (): Promise<boolean> => true,
},
),
keys: vi.fn(async () => [currentCacheName, previousCacheName]),
delete: vi.fn(async () => true),
});
// Only the previous cache holds the entry, so the request falls through to
// the network rather than serving a stale release.
await expect(
runtime.onFetch({
method: "GET",
url: `${ORIGIN}/assets/app.0123456789abcdef.js`,
}),
).resolves.toBeNull();
expect(previousMatch).not.toHaveBeenCalled();
});
it("deletes an invalid hit only from the current release cache", async () => {
const deletes: string[] = [];
const runtime = staticRuntime({
open: vi.fn(async (name: string) => ({
match: async () => new Response("bad", { status: 500 }),
delete: async (url: string): Promise<boolean> => {
deletes.push(`${name}:${url}`);
return true;
},
})),
keys: vi.fn(async () => [currentCacheName]),
delete: vi.fn(async () => true),
});
await expect(
runtime.onFetch({
method: "GET",
url: `${ORIGIN}/assets/app.0123456789abcdef.js`,
}),
).resolves.toBeNull();
expect(deletes).toEqual([
`${currentCacheName}:${ORIGIN}/assets/app.0123456789abcdef.js`,
]);
});
});
describe("service worker exact ownership and truthful removal", () => {
it("deletes only exact owned static cache names", async () => {
const fixture = workerScope();
fixture.scope.caches.keys = vi.fn(async () => [
`${STATIC_CACHE_PREFIX}${"a".repeat(16)}`,
`${STATIC_CACHE_PREFIX}${"b".repeat(16)}`,
// SW-02. Same prefix, not owned.
`${STATIC_CACHE_PREFIX}not-owned`,
`${STATIC_CACHE_PREFIX}${"c".repeat(17)}`,
`${STATIC_CACHE_PREFIX}${"A".repeat(16)}`,
"foreign-cache",
]);
const runtime = createServiceWorkerRuntime(fixture.scope as never, {
identity,
handlers: [],
manifest: null,
runtimeConfigUrl: "/runtime-config.json",
releaseManifestUrl: "/release-manifest.json",
});
const request = createServiceWorkerMessage({
kind: "CACHE_RESET_REQUEST",
sourceBuildId: "page-build",
targetBuildId: identity.buildId,
nonce: "nonce-reset-0001",
});
await runtime.onCacheResetRequest(request, fixture.clients[0] as never);
expect(fixture.deleted).toEqual([
`${STATIC_CACHE_PREFIX}${"a".repeat(16)}`,
`${STATIC_CACHE_PREFIX}${"b".repeat(16)}`,
]);
});
it.each([
{
label: "unregister false",
unregister: async () => false,
expected: { kind: "FAILED" },
},
{
label: "unregister rejects",
unregister: async () => {
throw new TypeError("unregister exploded");
},
expected: { kind: "FAILED" },
},
{
label: "unregister true",
unregister: async () => true,
expected: { kind: "DISABLED" },
},
])(
"does not hide $label behind DISABLED",
async ({ unregister, expected }) => {
const registration = {
scope: `${ORIGIN}/`,
installing: null,
waiting: null,
active: { scriptURL: SCRIPT_URL },
unregister: vi.fn(unregister),
update: vi.fn(async () => {}),
} as unknown as ServiceWorkerRegistration;
const controller = createServiceWorkerPageController({
container: {
controller: null,
register: vi.fn(),
getRegistration: vi.fn(async () => registration),
addEventListener: vi.fn(),
removeEventListener: vi.fn(),
} as never,
routerBasePath: "/",
origin: ORIGIN,
selection: {
mode: "REMOVE_REGISTRATION",
scriptPath: "service-worker.js",
handlers: [],
},
} as never);
await expect(controller.start()).resolves.toMatchObject(expected);
},
);
it("reports an ownership mismatch as INCOMPATIBLE rather than DISABLED", async () => {
const foreign = {
scope: `${ORIGIN}/`,
installing: null,
waiting: null,
active: { scriptURL: `${ORIGIN}/someone-else.js` },
unregister: vi.fn(async () => true),
update: vi.fn(async () => {}),
} as unknown as ServiceWorkerRegistration;
const controller = createServiceWorkerPageController({
container: {
controller: null,
register: vi.fn(),
getRegistration: vi.fn(async () => foreign),
addEventListener: vi.fn(),
removeEventListener: vi.fn(),
} as never,
routerBasePath: "/",
origin: ORIGIN,
selection: {
mode: "REMOVE_REGISTRATION",
scriptPath: "service-worker.js",
handlers: [],
},
} as never);
await expect(controller.start()).resolves.toMatchObject({
kind: "INCOMPATIBLE",
});
expect(foreign.unregister).not.toHaveBeenCalled();
});
});
describe("service worker page protocol", () => {
it("does not attach late listeners when stopped during registration", async () => {
const browser = pageContainer();