Skip to content

Ignore uniqueItems when set to false while importing JSON Schema documents - #6924

Merged
gcanti merged 2 commits into
mainfrom
audit/repro-core-schemarepresentation-uniqueitems-false
Aug 3, 2026
Merged

Ignore uniqueItems when set to false while importing JSON Schema documents#6924
gcanti merged 2 commits into
mainfrom
audit/repro-core-schemarepresentation-uniqueitems-false

Conversation

@fubhy

@fubhy fubhy commented Aug 3, 2026

Copy link
Copy Markdown
Member

Summary

Importing a JSON Schema array with uniqueItems set to false rejects duplicate elements.

Important

This PR starts with focused failing reproduction tests. Add the implementation fix to this same branch; CI is expected to fail until that fix is included.

uniqueItems false enables uniqueness

Module: SchemaRepresentation
Audit ID: core-s-z-testing-schema-representation-unique-items-false
Severity / confidence: medium / high

What happens

Importing a JSON Schema array with uniqueItems set to false rejects duplicate elements.

Why it happens

collectArrayChecks adds the effect/schema/isUnique filter for either boolean value, so the importer strengthens a valid external schema and rejects values it must accept.

Expected behavior

JSON Schema Draft 2020-12 uniqueItems: false imposes no uniqueness constraint.

Relevant implementation

These links and excerpts are pinned to audit base c9b56ab507f224426ee8388dc450da447ec4715f.

View problematic code at packages/effect/src/internal/schema/fromJsonSchemaDocument.ts:811-820
  function collectArrayChecks(schema: JsonSchema.JsonSchema): Array<Check> {
    const checks: Array<Check> = []
    if (schema.prefixItems === undefined) {
      addNumberCheck(checks, schema.minItems, "effect/schema/isMinLength", "minLength")
      addNumberCheck(checks, schema.maxItems, "effect/schema/isMaxLength", "maxLength")
    }
    if (typeof schema.uniqueItems === "boolean") {
      checks.push(jsonSchemaFilter("effect/schema/isUnique", null))
    }
    return checks

View exact lines on GitHub

Reproduction

pnpm test --run packages/effect/test/schema/representation/fromJsonSchemaDocument.test.ts -t "does not require uniqueness when uniqueItems is false"

Observed failure: validity false instead of true

Implementation handoff

The initial reproduction tests on this branch are the regression specification for the implementation fix that should follow in this PR.

  1. Start with the pinned implementation excerpts and the Why it happens analysis above.
  2. Change the implementation so it satisfies the stated Expected behavior; do not weaken or remove the reproduction assertions.
  3. Run the focused reproduction command(s) and confirm the observed failures become passing tests:
pnpm test --run packages/effect/test/schema/representation/fromJsonSchemaDocument.test.ts -t "does not require uniqueness when uniqueItems is false"
  1. Run the affected package's existing tests, then the repository lint and type checks before requesting review.

Audit provenance

  • Audit base: c9b56ab507f224426ee8388dc450da447ec4715f
  • Reproduction base: c9b56ab507f224426ee8388dc450da447ec4715f
  • Findings: core-s-z-testing-schema-representation-unique-items-false
  • Initial patch: focused reproduction tests; implementation fix pending

@fubhy fubhy added the audit Findings originating from the Effect runtime correctness audit label Aug 3, 2026
@github-project-automation github-project-automation Bot moved this to Discussion Ongoing in PR Backlog Aug 3, 2026
@changeset-bot

changeset-bot Bot commented Aug 3, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: c83020b

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 30 packages
Name Type
effect Patch
@effect/opentelemetry Patch
@effect/platform-browser Patch
@effect/platform-bun Patch
@effect/platform-deno Patch
@effect/platform-node-shared Patch
@effect/platform-node Patch
@effect/vitest Patch
@effect/ai-anthropic Patch
@effect/ai-openai-compat Patch
@effect/ai-openai Patch
@effect/ai-openrouter Patch
@effect/atom-react Patch
@effect/atom-solid Patch
@effect/atom-vue Patch
@effect/sql-clickhouse Patch
@effect/sql-d1 Patch
@effect/sql-libsql Patch
@effect/sql-mssql Patch
@effect/sql-mysql2 Patch
@effect/sql-pg Patch
@effect/sql-pglite Patch
@effect/sql-sqlite-bun Patch
@effect/sql-sqlite-do Patch
@effect/sql-sqlite-node Patch
@effect/sql-sqlite-react-native Patch
@effect/sql-sqlite-wasm Patch
@effect/docgen Patch
@effect/doctest Patch
@effect/openapi-generator Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@fubhy
fubhy requested a review from gcanti August 3, 2026 19:30

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

The reproduction test is correct and verifies the expected behavior, but the implementation fix at fromJsonSchemaDocument.ts:817 still needs to be applied.

Reviewed changes

  • Reproduction test for uniqueItems: false: Adds a test confirming that uniqueItems: false does not impose a uniqueness constraint — ["a", "a"] should validate as true. Confirmed the test correctly fails against the current code.

⚠️ Implementation fix still needed

The test is a faithful reproduction, but collectArrayChecks still adds isUnique for any boolean uniqueItems value.

Technical details
# Tighten `uniqueItems` guard to `true` only

## Affected sites
- `packages/effect/src/internal/schema/fromJsonSchemaDocument.ts:817``typeof schema.uniqueItems === "boolean"` pushes `isUnique` for both `true` and `false`, adding a uniqueness constraint even when it is explicitly disclaimed.

## Required outcome
- Change the guard so `uniqueItems: false` yields no `isUnique` check.

## Suggested approach
- Replace `typeof schema.uniqueItems === "boolean"` with `schema.uniqueItems === true` on line 817.
- No callers or tests should regress — the existing `uniqueItems: true` test at `fromJsonSchemaDocument.test.ts:1696` will continue to pass, and the new test will go green.

Pullfrog  | Fix it ➔View workflow run | Using DeepSeek Pro (free via Pullfrog for OSS) (Kimi K2 not used — the program covers this model; add its provider key to run your pick) | 𝕏

@gcanti gcanti changed the title Ignore uniqueItems when false in SchemaRepresentation imports Ignore uniqueItems when set to false while importing JSON Schema documents Aug 3, 2026
@gcanti
gcanti force-pushed the audit/repro-core-schemarepresentation-uniqueitems-false branch from c0a7b6d to c83020b Compare August 3, 2026 20:22

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

  • Applied the uniqueItems === true guard: Changed collectArrayChecks from typeof schema.uniqueItems === "boolean" to schema.uniqueItems === true so that uniqueItems: false no longer pushes an isUnique filter.
  • Added patch changeset: effect patch-level changeset describing the fix.

The implementation matches the suggested fix from the prior review exactly. The new reproduction test passes, and the existing uniqueItems: true test is unaffected.

Pullfrog  | View workflow run | Using DeepSeek Pro (free via Pullfrog for OSS) (Kimi K2 not used — the program covers this model; add its provider key to run your pick) | 𝕏

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bundle Size Analysis

Generated from PR build output; treat the content below as untrusted.

File Name Current Size Previous Size Difference
basic.ts 7.06 KB 7.06 KB 0.00 KB (0.00%)
batching.ts 9.86 KB 9.86 KB 0.00 KB (0.00%)
brand.ts 6.34 KB 6.34 KB 0.00 KB (0.00%)
cache.ts 10.62 KB 10.62 KB 0.00 KB (0.00%)
config.ts 20.60 KB 20.60 KB 0.00 KB (0.00%)
differ.ts 20.20 KB 20.20 KB 0.00 KB (0.00%)
http-client.ts 21.49 KB 21.49 KB 0.00 KB (0.00%)
logger.ts 10.76 KB 10.76 KB 0.00 KB (0.00%)
metric.ts 8.99 KB 8.99 KB 0.00 KB (0.00%)
optic.ts 7.18 KB 7.18 KB 0.00 KB (0.00%)
pubsub.ts 14.90 KB 14.90 KB 0.00 KB (0.00%)
queue.ts 11.58 KB 11.58 KB 0.00 KB (0.00%)
schedule.ts 10.74 KB 10.74 KB 0.00 KB (0.00%)
schema-class.ts 19.14 KB 19.14 KB 0.00 KB (0.00%)
schema-fromJsonSchemaDocument.ts 28.96 KB 28.96 KB +0.00 KB (+0.00%)
schema-representation-roundtrip.ts 25.29 KB 25.29 KB 0.00 KB (0.00%)
schema-string-transformation.ts 13.30 KB 13.30 KB 0.00 KB (0.00%)
schema-string.ts 10.94 KB 10.94 KB 0.00 KB (0.00%)
schema-template-literal.ts 15.17 KB 15.17 KB 0.00 KB (0.00%)
schema-toArbitraryLazy.ts 21.94 KB 21.94 KB 0.00 KB (0.00%)
schema-toCodeDocument.ts 24.34 KB 24.34 KB 0.00 KB (0.00%)
schema-toCodecJson.ts 19.18 KB 19.18 KB 0.00 KB (0.00%)
schema-toEquivalence.ts 19.01 KB 19.01 KB 0.00 KB (0.00%)
schema-toFormatter.ts 18.87 KB 18.87 KB 0.00 KB (0.00%)
schema-toJsonSchemaDocument.ts 22.60 KB 22.60 KB 0.00 KB (0.00%)
schema-toRepresentation.ts 19.52 KB 19.52 KB 0.00 KB (0.00%)
schema.ts 18.41 KB 18.41 KB 0.00 KB (0.00%)
stm.ts 12.54 KB 12.54 KB 0.00 KB (0.00%)
stream.ts 9.79 KB 9.79 KB 0.00 KB (0.00%)

@gcanti
gcanti merged commit a94cbed into main Aug 3, 2026
17 checks passed
@gcanti
gcanti deleted the audit/repro-core-schemarepresentation-uniqueitems-false branch August 3, 2026 20:28
@github-project-automation github-project-automation Bot moved this from Discussion Ongoing to Done in PR Backlog Aug 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

audit Findings originating from the Effect runtime correctness audit

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants