nodejs / nodejs/node

Package map entry whose url resolves to a directory-form URL never matches its files

Đang mở
#66,043 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Ngôn ngữ chính
JavaScript
Star
122k
Fork
37.3k
Merge trung bình
4 ngày 2 giờ
Pull request đã merge (30 ngày)
283

Mô tả

Version

v26.8.1

Platform

Windows 11 x64 (the mechanism is platform independent; see analysis)

Subsystem

module, package maps

What steps will reproduce the bug?

A package entry whose url resolves to a directory-form URL (one ending in /) never matches any file inside it. The natural relative spellings for "the directory above the map file" — "..", "../", ".", "./" — all produce such a URL.

project/
  package.json          {"private":true}
  index.cjs             console.log(require("dep"));
  node_modules/
    .package-map.json
    dep/package.json    {"name":"dep","main":"index.cjs"}
    dep/index.cjs       module.exports="ok";

node_modules/.package-map.json:

{
  "packages": {
    "root": { "url": "..", "dependencies": { "dep": "dep" } },
    "dep": { "url": "./dep", "dependencies": {} }
  }
}
$ node --experimental-package-map=node_modules/.package-map.json index.cjs
How often does it reproduce? Is there a required condition?

Always. The condition is that the entry's url resolves to a URL ending in /.

Results for the same map with only the root url changed:

root url result
".." ERR_PACKAGE_MAP_EXTERNAL_FILE
"../" ERR_PACKAGE_MAP_EXTERNAL_FILE
"." ERR_PACKAGE_MAP_EXTERNAL_FILE
"./" ERR_PACKAGE_MAP_EXTERNAL_FILE
absolute file: URL without a trailing slash ok
What is the expected behavior? Why is that the expected behavior?

require("dep") from index.cjs should print ok. The documentation says url is "An absolute or relative URL ... parsed using the WHATWG URL API, using the configuration file URL as base", and puts no restriction on directory-form URLs. "." and ".." are ordinary relative URLs that denote directories, which is what a package entry points at.

What do you see instead?
Error [ERR_PACKAGE_MAP_EXTERNAL_FILE]: Cannot resolve "dep" from ".../nodemap/index.cjs": file is not within any package defined in .../nodemap/node_modules/.package-map.json
    at PackageMap.resolve (node:internal/modules/package_map:179:13)
    at packageMapResolve (node:internal/modules/package_map:305:14)
    at tryPackageMapResolveCJS (node:internal/modules/cjs/loader:697:18)
  code: 'ERR_PACKAGE_MAP_EXTERNAL_FILE'
Additional information

Cause, in lib/internal/modules/package_map.js (v26.8.1):

  • #parse stores the package path unnormalized: absolutePath = fileURLToPath(packageURL) followed by this.#pathToKey.set(absolutePath, key). For a directory-form URL this keeps the trailing separator, for example /home/u/proj/.
  • #getKeyForPath does filePath = pathResolve(filePath) and then walks up with dirname, comparing by exact string. pathResolve and dirname never yield a trailing separator except at a filesystem root, so the stored key is unreachable and resolve() throws ERR_PACKAGE_MAP_EXTERNAL_FILE.

The same reasoning applies on POSIX: fileURLToPath keeps the trailing /, and path.posix.dirname("/home/u/proj/index.cjs") is /home/u/proj.

Suggested fix: normalize when storing, that is absolutePath = pathResolve(fileURLToPath(packageURL)) in #parse, so stored paths, duplicate detection and lookup all use the same spelling. Normalizing only in #getKeyForPath would leave the stored identity inconsistent.

Test coverage: the fixtures in test/fixtures/package-map/ use only "./name" style URLs, so no test exercises a directory-form URL. A regression test could add an entry with url: ".." and require a dependency from a file in that directory.

This is not the same as #65501 / #65502, which concern subpaths escaping the target package directory.

Found via pnpm, which writes "url": ".." for the workspace root importer in node_modules/.package-map.json, so no file at a project root can resolve a bare specifier.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

Đọc lib/internal/modules/package_map.js, đặc biệt là #parse và #getKeyForPath, sau đó kiểm tra các fixture trong test/fixtures/package-map/. Thêm một trường hợp hồi quy sử dụng URL dạng thư mục như ".." và xác minh rằng việc require dependency được resolve thành công thay vì phát sinh ERR_PACKAGE_MAP_EXTERNAL_FILE.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
javascript
Lĩnh vực
backend
Loại issue
Lỗi
Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức độ hoạt động
Sôi nổi
Độ rõ ràng
Đặc tả rõ ràng
Mức phù hợp với người mới
78/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.