Package map entry whose url resolves to a directory-form URL never matches its files
まだ誰も着手していません。
- 主要言語
- JavaScript
- スター
- 122k
- フォーク
- 37.3k
- 平均マージ
- 4日 2時間
- マージ済み PR(30日)
- 283
説明
Version
v26.8.1
Platform
Windows 11 x64 (the mechanism is platform independent; see analysis)
Subsystem
module, package maps
What steps will reproduce the bug?
A package entry whose url resolves to a directory-form URL (one ending in /) never matches any file inside it. The natural relative spellings for "the directory above the map file" — "..", "../", ".", "./" — all produce such a URL.
project/
package.json {"private":true}
index.cjs console.log(require("dep"));
node_modules/
.package-map.json
dep/package.json {"name":"dep","main":"index.cjs"}
dep/index.cjs module.exports="ok";
node_modules/.package-map.json:
{
"packages": {
"root": { "url": "..", "dependencies": { "dep": "dep" } },
"dep": { "url": "./dep", "dependencies": {} }
}
}
$ node --experimental-package-map=node_modules/.package-map.json index.cjs
How often does it reproduce? Is there a required condition?
Always. The condition is that the entry's url resolves to a URL ending in /.
Results for the same map with only the root url changed:
root url |
result |
|---|---|
".." |
ERR_PACKAGE_MAP_EXTERNAL_FILE |
"../" |
ERR_PACKAGE_MAP_EXTERNAL_FILE |
"." |
ERR_PACKAGE_MAP_EXTERNAL_FILE |
"./" |
ERR_PACKAGE_MAP_EXTERNAL_FILE |
absolute file: URL without a trailing slash |
ok |
What is the expected behavior? Why is that the expected behavior?
require("dep") from index.cjs should print ok. The documentation says url is "An absolute or relative URL ... parsed using the WHATWG URL API, using the configuration file URL as base", and puts no restriction on directory-form URLs. "." and ".." are ordinary relative URLs that denote directories, which is what a package entry points at.
What do you see instead?
Error [ERR_PACKAGE_MAP_EXTERNAL_FILE]: Cannot resolve "dep" from ".../nodemap/index.cjs": file is not within any package defined in .../nodemap/node_modules/.package-map.json
at PackageMap.resolve (node:internal/modules/package_map:179:13)
at packageMapResolve (node:internal/modules/package_map:305:14)
at tryPackageMapResolveCJS (node:internal/modules/cjs/loader:697:18)
code: 'ERR_PACKAGE_MAP_EXTERNAL_FILE'
Additional information
Cause, in lib/internal/modules/package_map.js (v26.8.1):
#parsestores the package path unnormalized:absolutePath = fileURLToPath(packageURL)followed bythis.#pathToKey.set(absolutePath, key). For a directory-form URL this keeps the trailing separator, for example/home/u/proj/.#getKeyForPathdoesfilePath = pathResolve(filePath)and then walks up withdirname, comparing by exact string.pathResolveanddirnamenever yield a trailing separator except at a filesystem root, so the stored key is unreachable andresolve()throwsERR_PACKAGE_MAP_EXTERNAL_FILE.
The same reasoning applies on POSIX: fileURLToPath keeps the trailing /, and path.posix.dirname("/home/u/proj/index.cjs") is /home/u/proj.
Suggested fix: normalize when storing, that is absolutePath = pathResolve(fileURLToPath(packageURL)) in #parse, so stored paths, duplicate detection and lookup all use the same spelling. Normalizing only in #getKeyForPath would leave the stored identity inconsistent.
Test coverage: the fixtures in test/fixtures/package-map/ use only "./name" style URLs, so no test exercises a directory-form URL. A regression test could add an entry with url: ".." and require a dependency from a file in that directory.
This is not the same as #65501 / #65502, which concern subpaths escaping the target package directory.
Found via pnpm, which writes "url": ".." for the workspace root importer in node_modules/.package-map.json, so no file at a project root can resolve a bare specifier.
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
調査の方向性
lib/internal/modules/package_map.js、特に #parse と #getKeyForPath を読み、その後 test/fixtures/package-map/ 配下の fixture を調べます。".." のようなディレクトリ形式の URL を使用する回帰テストケースを追加し、ERR_PACKAGE_MAP_EXTERNAL_FILE を発生させるのではなく、依存関係の require が正常に解決されることを確認します。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- javascript
- 領域
- backend
- issue の種類
- バグ
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 活発さ
- 活発
- 明瞭さ
- 明確に書かれている
- 初心者へのやさしさ
- 78/100