SocketDev / SocketDev/socket-cli

socket npm run build crashes with ERR_MISSING_OPTION: --permission on Node v24 + Next.js

Open Beginner friendly
#1,160 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
TypeScript
Stars
317
Forks
65
Avg merge
1h 26m
Merged PRs (30d)
30

Description

Description

socket npm run build crashes during Next.js's TypeScript checking phase on Node v24. Running npm run build directly works fine.

Root cause

In shadow-npm-bin2.js:67, the --node-options value is wrapped in literal single quotes:

`--node-options='${...}${utils.cmdFlagsToString(permArgs)}'`

Since this argument is passed via child_process.spawn() (no shell), the quotes are not interpreted — npm receives them as part of the value and sets:

NODE_OPTIONS='--permission --allow-child-process --allow-fs-read=* --allow-fs-write=...'

Node.js silently ignores the garbled tokens. However, Next.js re-parses NODE_OPTIONS for its build workers using a tokenizer that splits on whitespace and only handles " as string delimiters, not '. This causes:

  • '--permission (leading ') → unrecognized, dropped
  • --allow-child-process, --allow-fs-read=*, --allow-fs-write=... → valid, kept

The TypeScript worker then receives --allow-* flags without --permission, and Node v24 throws ERR_MISSING_OPTION.

Suggested fix

Remove the single quotes — they are unnecessary and harmful when arguments are passed via spawn():

- `--node-options='${nodeOptionsArg ? nodeOptionsArg.slice(15) : ''}${utils.cmdFlagsToString(permArgs)}'`
+ `--node-options=${nodeOptionsArg ? nodeOptionsArg.slice(15) : ''}${utils.cmdFlagsToString(permArgs)}`
Repro
  • Node v24.11.1, Next.js 16.2.1, Socket CLI 1.1.78 (also 1.1.76)
  • npm run build → succeeds
  • socket npm run build → crashes at "Running TypeScript ..."
TypeError [ERR_MISSING_OPTION]: --permission is required
    at node:internal/process/pre_execution:656:15
    at Array.forEach (<anonymous>)
    at initializePermission (node:internal/process/pre_execution:653:5)
Related
  • #1036 — a separate bug on the same line where user-set NODE_OPTIONS are replaced rather than merged

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Inspect shadow-npm-bin2.js around line 67 and reproduce the failure with Node v24 using socket npm run build versus npm run build. Remove the literal single quotes from the spawned --node-options value, then verify that the Next.js TypeScript checking phase completes without ERR_MISSING_OPTION.

Written by the indexing model from the issue text.

Assessment

Tech stack
next.js, node.js, typescript
Domain
build-system, cli
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
78/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.