Repository navigation
v2.5.2
Fixed
-
Six npm flag spellings read a literal
nullas the package name. 2.5.1
added a table of the boolean flags that take a literalnullas their value
rather than as the package name —nullis a real published npm package, so
the distinction decides a server's identity, andrefresher.py's freshness
gate treats a matching identity as positive confirmation that a cached
tool description still describes the configured package. That table was
written by hand with 12 entries. npm has five nullable boolean definitions
(yes,optional,production,workspaces,expect-results) but
eighteen spellings for them, becausey,ws,nandnoare
shorthands —nandnoboth expand to--no-yes— and each is legal in
both its-xand--xform. The six that were missing are--y,-ws,
-n,--n,-no,--no: under 2.5.1 each of these read the following
nullas the package name, sonpm exec -n null server-aand
npm exec -n null server-bboth resolved to the packagenulland could be
served each other's cached tool descriptions.Not a regression between releases — 2.4.1, 2.5.0 and 2.5.1 all resolve
these six tonull; verified by running each released version's
detect_package_typedirectly. The blanket rule that briefly handled them
correctly existed only onmainbetween two unreleased commits, so no shipped
version was ever right about them. 2.5.2 is the first. -
The set is now generated, not hand-listed.
.consiliency/notes/derive_npm_flags.pyderives it from npm's own
@npmcli/configdefinitions: a spelling is nullable iff its resolution
target, after shorthand expansion and after stripping a leadingno-, is a
definition whose declared type includesnull. It was the fourth defect in
this parser traceable to hand-transcribing npm's behaviour. -
--verifynow covers this table, which previously had no drift
protection at all. Each definition is probed with a literalnull, and every
one of npm's 442 enumerable flag spellings is run through npm's own parser as
npm exec <flag> null zz— a definition-level check alone would not have
caught a spelling omission. The new check rejects the shipped 2.5.1 table
with exactly six mismatches.This does not close the broader gap tracked in
#195: attached values (--global=pkg), npx's own-p=
rewriting, and npx's-nremoval are still unhandled.