voidzero-dev / voidzero-dev/vite-plus

Vite Plus PATH shim can shadow external CLI upgrades (OpenCode example)

未关闭
#2,181 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Rust
星标
5.8k
派生
262
平均合并
23 小时 41 分钟
30 天内合并 PR
138

描述

## Summary

On Windows, a Vite Plus-owned executable in `~\.vite-plus\bin` can remain ahead of a newer version installed by that CLI's own updater. The shell command then continues to run the stale Vite Plus executable.

OpenCode is the confirmed example below. This may affect any externally updatable CLI for which Vite Plus installs an executable with the same command name, but this report does **not** claim other packages are currently affected.

## Environment

- Windows
- Vite Plus: `0.2.4`
- OpenCode before upgrade: `1.17.18`

## Reproduction

```powershell
opencode --version
# 1.17.18

opencode upgrade --print-logs
```

The updater reported:

```text
Using method: npm
From 1.17.18 → 1.18.1
Upgrade complete
```

But immediately afterwards:

```powershell
opencode --version
# 1.17.18
```

## Investigation

The command resolved to the Vite Plus-owned path:

```text
C:\Users\\.vite-plus\bin\opencode.exe
```

The updater had installed OpenCode `1.18.1` at:

```text
C:\Users\\.vite-plus\js_runtime\node\22.19.0\node_modules\opencode-ai\bin\opencode.exe
```

Running that executable directly returned `1.18.1`; the PATH executable remained at `1.17.18`.

## Scope checked

- **Confirmed:** `opencode` was shadowed by the stale Vite Plus executable.
- **Not implicated in this installation:** `npm`, `npx`, and `corepack` resolve to NVM rather than `~\.vite-plus\bin`.
- **Potentially affected pattern:** any CLI that manages its own upgrades while Vite Plus also places a same-named executable earlier on PATH.

## Expected behavior

After a CLI reports a successful self-upgrade, its normal shell command should run the upgraded version.

## Workaround

Replacing the stale Vite Plus executable with the newly installed OpenCode executable made `opencode --version` report `1.18.1`.

## Suggested direction

Vite Plus could avoid installing static, same-named binaries for externally self-updating CLIs, make them forwarding shims, or provide a way to refresh the Vite Plus bin entry after an external upgrade.

贡献指南

打开贡献指南

调研方向

首先使用 `opencode --version` 和 `opencode upgrade --print-logs` 复现 Windows PowerShell 案例,然后检查 Vite Plus 如何将可执行文件放置在 `~/.vite-plus/bin` 中,以及 PATH 如何解析它们。完成的标准是:外部升级成功后,普通的 `opencode` 命令能够运行新安装的版本,而无需手动替换;除非确认了其他案例,否则保持围绕 OpenCode 所声明的范围。

由索引模型根据 Issue 内容生成。

评估

技术栈
node.js, rust
领域
cli, operating-systems, tooling
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
冷清
描述清晰度
基本清楚
新手友好度
50/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。