Skip to content

fix(arborist): derive linked bin cleanup paths through bin-links - #10057

Draft
martinrrm wants to merge 1 commit into
latestfrom
fix/arborist-bin-paths
Draft

martinrrm wants to merge 1 commit into
latestfrom
fix/arborist-bin-paths

Conversation

@martinrrm

Copy link
Copy Markdown
Contributor

Summary

Route linked-install bin cleanup paths through bin-links#getPaths() instead of manually joining lockfile-provided bin keys. Regular Node.binPaths already uses this API, so both strategies can share the defensive bin normalization introduced by npm/bin-links#187.

This is the Arborist integration for CLI-CROW-GEN-002. It does not introduce an Arborist-owned normalizer or modify the bundled dependency.

Changes

  • Replace linked-mode manual bin path derivation with bin-links#getPaths() using the dependency's consumer-facing installation path, not its store path.
  • Add Node.binPaths regression coverage for traversal-bearing, absolute, Windows-style and invalid bin metadata, including preservation of the caller's metadata.
  • Add hoisted and linked optional-extraction-failure regressions that verify an external sentinel survives cleanup with scripts disabled.

Dependency and draft status

This change depends on npm CLI bundling a released bin-links artifact containing npm/bin-links#187. The currently bundled bin-links@7.0.0 lacks that normalization, so this patch alone is not a complete fix and the new regressions are not expected to pass against the old dependency.

Keep this PR in draft until the patched dependency is integrated and the targeted tests and lint are run. A corresponding release/v11 backport is also needed.

Validation

  • JavaScript syntax checks and git diff --check passed.
  • Earlier bounded runtime checks, applying the bin-links normalization in memory without modifying the bundled dependency, preserved the external sentinel for hoisted and linked install/CI-like flows. These are not substitutes for the repository tests.
  • Repository TAP tests and Arborist lint remain blocked locally: tap, eslint and @npmcli/mock-registry are missing. No dependencies were installed and no snapshots were refreshed.

Use the same bin path derivation for regular and linked installs so both consume the defensive normalization from npm/bin-links#187. Add traversal and optional-cleanup regression coverage.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant