feat(install): support pnpm v12 native binary distribution - #2289
Conversation
pnpm >= 12 is a native binary: the npm package only ships placeholder
bins that a preinstall script replaces from the platform-specific
@pnpm/exe.* packages. Lifecycle scripts never run for managed package
manager installs, so no bin/pnpm.cjs exists and exec of bin/pnpm failed
with ENOENT (and the completeness check re-downloaded on every run).
Download the @pnpm/exe.{os}-{arch} package directly for pnpm >= 12,
place the binary at bin/pnpm.native, and create native shims, mirroring
the bun flow. The pnpx shim injects dlx explicitly because shims do not
preserve the launch name the binary self-detects for alias behavior.
Fixes voidzero-dev#2276
✅ Deploy Preview for viteplus-preview ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 891f54bd39
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
The hash names the main pnpm tarball, not the platform package: verify it against the artifact it describes before the native download, so a bad pin fails the same way it does for pnpm <= 11.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c8e25e0645
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
The hash path reuses the same download_and_extract_tgz_with_hash / verify_file_hash mechanism the pnpm <= 11 flow uses, which is already covered by the mock-server tests in request.rs; neither flow needs a registry-hitting integration test for it.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 98062166c4
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
The @pnpm/exe.* platform tarball was downloaded without any hash check because the declared packageManager hash only names the main pnpm package. Fetch the platform package's registry version metadata and verify the tarball against its dist.integrity (SRI), converted to the algo.hex format verify_file_hash already understands. Registries that omit the field keep the previous unverified behavior.
|
@codex review |
|
Codex Review: Didn't find any major issues. Keep them coming! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
…trip Teach verify_file_hash the registry dist.integrity SRI format (algorithm-base64) alongside the declared algorithm.hex format, comparing the digest in the encoding the expected hash uses. The pnpm 12 flow now passes dist.integrity straight through instead of converting it to hex first, dropping sri_to_expected_hash.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4b3913c3a8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 11715354e8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
This fixes running pnpm 12 (currently
12.0.0-beta.0) through Vite+. Executing any pnpm command failed with:error: Failed to exec .../.vite-plus/package_manager/pnpm/12.0.0-beta.0/pnpm/bin/pnpm: No such file or directory (os error 2)Root cause
pnpm 12 is a native binary (Rust rewrite). The
pnpmnpm package no longer shipsbin/pnpm.cjs— it only contains shebang-less placeholder bins that apreinstallscript replaces with the platform binary from the@pnpm/exe.*optional dependencies (install.js).Vite+ extracts the tarball without running lifecycle scripts, so
create_shim_filesfound no JS entrypoint, silently created no shims, and the exec ofbin/pnpmfailed. The completeness check also never passed, so every invocation re-downloaded the tarball.Fix
For pnpm >= 12, download the platform-specific
@pnpm/exe.{os}-{arch}package directly and place the binary atbin/pnpm.nativewith native shims, mirroring the existing bun flow. pnpm <= 11 keeps the JS flow unchanged.The
pnpxshim injectsdlxexplicitly: upstream's binary self-detects its launch name viacurrent_exeto aliaspnpx(argv_with_alias_subcommand), which a wrapper script cannot trigger. This matches upstream's own Unixpnpxscript (exec pnpm dlx "$@"). Shimsgenerated with no injected args are byte-identical to before, so bun is unaffected.
Resolves #2276