Repository navigation
Explain Windows pnpm failures, refuse unreadable package manager scripts, and polish the CLI - #189
Merged
Merged
Conversation
Nothing undid `nvx allow-host` except editing the policy file by hand. `--remove` takes the host out of `allow_hosts` in the file the command adds to. A project file that was trusted stays trusted, since removing a host only narrows it. A file nobody had trusted is not trusted by it. `nvx --strict tsc` answered "Unknown command: tsc", and the form that works is `nvx --strict shim tsc`. When the name is a program in the project's node_modules/.bin, nvx now says so and prints that form with the flags that were typed. It still exits 2 and does not run the program.
nvx added --disable-warning=UNDICI-EHPA to NODE_OPTIONS only for a command inside a Node it installed. bunx and a program in node_modules/.bin run on the Node that a `node` they start finds first on the contained PATH, which is nvx's own, and each ended with "[UNDICI-EHPA] Warning". The flag now goes in whenever that Node is one nvx installed and reads NODE_USE_ENV_PROXY. The version comes from the folder name, and a Node that refuses the flag still does not get it.
…lved When a host was refused, the step that asks npm what an install brings in failed, nvx had already explained, and it then asked "Proceed?" with a refusal that told the reader to set NVX_YES=true. Approving cannot help, since the install goes through the same host. The run now ends with one line saying it was stopped for that reason, and -y and NVX_YES do not approve it. A failure nvx has not explained is still asked about. The line printed when a command fails after a host was refused no longer says the host is why: nvx cannot read the command's output. It says what happened and that allowing the host helps only if the command's own error is about that connection.
…a script it cannot read doctor no longer fails yarn or pnpm for being corepack's launcher. A launcher downloads the package manager the first time it runs, and doctor starts it with no network. A contained pnpm run that fails on Windows ends with a note naming the two failures that mention no sandbox. pnpm 12 stops with "Access is denied. (os error 5)" as it reads its --dir argument. pnpm 9, 10 and 11 panic with "Failed to get source volume info" when an install includes a package that has install scripts, because they copy it with a native call that asks Windows about the drive's root folder. No pnpm option avoids that call, and the limitations page now says so, with the ways round, and why curl.exe fails TLS in the sandbox. A package manager's script that node is asked to run, from a folder the sandbox cannot read, is refused with the way to run it. It stopped with "Cannot find module" and exit 1.
`nvx grants reset --all` exited 1 for a granted folder that was deleted. The record held only the path, so for a path with nothing at it the reset could not tell a deleted folder, whose permission went with it, from a renamed one, whose permission is still in force, and treated both as a failure. A record now keeps the folder's file ID beside its path. The reset finds a renamed or moved folder by that ID and withdraws the permission where it is now, and finds a deleted one gone, with nothing to withdraw. A record written before IDs were kept gets one the next time a contained run starts with the folder still in allow_read_exec, and until then behaves as it did.
… wording The cases that pin what must not change now sit in the tests that cover the change, so each test fails on the old code. The pnpm note, the project program hint and the limitations page say what was measured and no more.
… its two exit codes `nvx allow-host --remove` on a project with no policy file says there is no file, instead of naming a file that does not exist as one that lacks the host. The pnpm note follows the two failures it describes, which end with exit 1 and 127, so an interrupted install does not get it.
…ath is spelled The path found from a folder's ID is the final path Windows gives back. A folder reached through a junction, a short name or a substituted drive is spelled differently there though it has not moved, so a reset reported it as renamed. The CI runner's temp folder is a short name, and its test failed on that. A folder whose ID is the one at the recorded path is where it was.
corepack picks pnpm 12 unless the project pins another version, and npm install -g pnpm installs pnpm 12 today. The limitations page now says to install an earlier one with npm install -g pnpm@11.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes for someone using nvx
nvx allow-host --remove <host[:port]>takes a host back out ofallow_hosts, in the file the command adds to. A trusted project file stays trusted, because taking a host out only narrows it. A file nobody had trusted is not trusted by it.nvx --strict tscsays thattscis a program in the project'snode_modules/.binand prints the working form,nvx --strict shim tsc. It still exits 2 and does not run the program, because running whatevernode_modules/.binholds for a mistyped nvx command would let a cloned project answer it with its own code.bunxand a project's own programs no longer end with[UNDICI-EHPA] Warning. They run on the Node.js that nvx put first on the containedPATH. nvx reads its version from the folder name, so a Node.js that refuses the flag still does not get it.NVX_YES. The run ends with one line saying it was stopped because nvx refused a connection. The sandbox-did-not-start half of that second refusal was already fixed in Fix Windows stdin-only pipe hang, launch attribute lifetime, and lost scaffolds #188.nvx doctorno longer fails yarn or pnpm for being corepack's launcher. A launcher downloads the package manager the first time it runs, and doctor starts it with no network.node. It stopped withCannot find module, exit 1. It is now refused with exit 77, naming the folder to put inallow_read_exec. That folder inallow_read_execruns it contained.Failed to get source volume info) is not a workspace problem. It comes from any install that includes a package with install scripts, with pnpm 9.15.9, 10.34.6 and 11.28.5. No pnpm option avoids it, so it is documented with the ways round.nvx grants reset --allexits 0 when a granted folder was deleted, and withdraws the permission where a renamed folder went. A record now keeps the folder's file ID beside its path. The old exit 1 existed because a path with nothing at it cannot say whether the folder was deleted or renamed. A record from before this change gets an ID on the next contained run, and behaves as it did until then.curl.exefails TLS withCRYPT_E_REVOCATION_OFFLINEand names--ssl-no-revoke. Allowing the certificate authority's host cannot help, because Windows makes that request itself and it never reaches nvx's proxy.How it was checked
gofmt -l internal cmdprints nothing, andgo vet ./...passes for windows, linux and darwin.go test ./internal/nvx -count=1passes on Windows, and so does the same run withNVX_PROBE=1, which launches real AppContainers.TestContainedProcessCannotTypeIntoTheTerminalfails, and it fails the same way on main, because the image has noip.NVX_HOMEare the measurements in the changelog entries.site:npm run buildends with pagefind's known localAccess is deniedpanic,npm run check:contentand the changelog date check pass.