Skip to content

Preload the FEP-7aa9 JSON-LD context (https://w3id.org/fep/7aa9) #1078

Description

@dahlia

Problem

Looking up a Hackers' Pub post from Hollo fails when the remote FEP-7aa9 JSON-LD context returns HTTP 502.

The affected post is:

https://hackers.pub/@botkit/2026/CVE-2026-96625

Both the post's ActivityPub document and its author's actor document return HTTP 200. However, the actor document includes https://w3id.org/fep/7aa9 in its @context. When requested as application/ld+json, that URL redirects to:

https://raw.codeberg.page/fediverse/fep/fep/7aa9/fep-7aa9.jsonld

During the incident, this endpoint repeatedly returned HTTP 502 with an empty body. Fedify consequently failed to deserialize the actor, causing Hollo's /api/v2/search request with resolve=true to fail.

The same 502 response was reproduced by fetching the context directly from inside the Hollo container.

Error

Shortened logs from September 27, 2026, at 10:46:25 UTC:

ERR fedify·runtime·docloader: Failed to fetch document: 502 'https://raw.codeberg.page/fediverse/fep/fep/7aa9/fep-7aa9.jsonld'

ERR fedify·federation·http: An error occurred while serving request 'GET'
'https://hollo.social/api/v2/search?q=https%3A%2F%2Fhackers.pub%2F%40botkit%2F2026%2FCVE-2026-96625&resolve=true&limit=5':
jsonld.InvalidUrl: Dereferencing a URL did not result in a valid JSON-LD object.
URL: "https://w3id.org/fep/7aa9".

details: {
  code: 'loading remote context failed',
  url: 'https://w3id.org/fep/7aa9',
  cause: FetchError: https://raw.codeberg.page/fediverse/fep/fep/7aa9/fep-7aa9.jsonld: HTTP 502
}

Expected behavior

Fedify should resolve the FEP-7aa9 context locally, so parsing documents that reference it does not depend on the availability of the remote context server.

Suggested solution

Bundle the FEP-7aa9 JSON-LD context as a static asset under packages/vocab-runtime/src/contexts/ and register https://w3id.org/fep/7aa9 in preloadedContexts in packages/vocab-runtime/src/contexts.ts.

Add a regression test confirming that the default document loader resolves this context without a network request, and a changelog entry for @fedify/vocab-runtime.

This addresses the same availability failure as the FEP-ef61 context issue in #982. The context-preloading change could be handled independently of the broader FEP-7aa9 vocabulary work in #810.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Fields

Priority

None yet

Effort

None yet

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions