voidzero-dev / voidzero-dev/vite-task

Package.json script tasks don't expose npm lifecycle env; cache-enabled tasks strip host-stamped values

Open
#692 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
466
Forks
42
Avg merge
1d 15h
Merged PRs (30d)
19

Description

Summary

When vite-task spawns a package.json script, the child gets none of the npm lifecycle environment variables (npm_execpath, npm_config_user_agent, npm_lifecycle_event, npm_node_execpath, …) that npm, pnpm, and Yarn all set when they run scripts. Tools that detect their invoking package manager from that env — npm-run-all2/run-p being the common one — silently fall back to npm, which then fails devEngines.packageManager enforcement in pnpm projects.

Downstream report: voidzero-dev/vite-plus#2317 (vpr checkrun-p → npm → EBADDEVENGINES). Reproduced there with a minimal project: pnpm run check sets npm_execpath=<pnpm>/bin/pnpm.mjs, npm_config_user_agent=pnpm/11.20.0 …, npm_lifecycle_event=probe for the child; the same script through the task runner gets none of them.

Why a vite-plus-side fix can't fully cover it

voidzero-dev/vite-plus#2385 stamps npm_execpath / npm_config_user_agent / npm_node_execpath / INIT_CWD into the process env before Session::init snapshots it. That works for plain scripts (which default to cache: scripts: false), but two pieces need the planner:

  1. Cache-enabled tasks strip the stamped vars again. plan_spawn_execution runs EnvFingerprints::resolve(&mut spawn_envs, &cache_config.env_config) before spawning, and DEFAULT_UNTRACKED_ENV contains no lowercase npm_* name (matching is case-sensitive on Unix). So for cache: { scripts: true } or config-defined tasks (cached by default), the session-level stamp is filtered out and the npm fallback returns — only in the cached case, which no fixture currently exercises. The VP_RUN marker had this exact problem and is re-inserted after the filter, with a comment explaining why.
  2. npm_lifecycle_event / npm_lifecycle_script are per-task values (script name / script body). Only the planner knows them; a session-level stamp can't provide them. pnpm sets both for every script it runs.

Suggested direction

  • Re-insert the lifecycle names post-filter next to the existing MARKER_ENV_NAME insert in vt_plan (or add them to DEFAULT_UNTRACKED_ENV), so host-provided lifecycle env survives cache-enabled tasks.
  • Optionally set npm_lifecycle_event (and npm_lifecycle_script) from the task itself when spawning package.json scripts, which vite-plus cannot do from outside.

Happy to send a PR for either or both if the direction sounds right — the vp_run_env e2e fixture looks like the natural place for coverage (its cached case already demonstrates the marker surviving the env filter).

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in vt_plan at plan_spawn_execution and inspect EnvFingerprints::resolve, DEFAULT_UNTRACKED_ENV, and the existing MARKER_ENV_NAME insertion. Then read the vp_run_env end-to-end fixture, including its cached case. Done means package.json tasks retain the relevant npm lifecycle environment, including cache-enabled tasks, with coverage for the reported behavior.

Written by the indexing model from the issue text.

Assessment

Tech stack
nodejs, rust
Domain
build-system, tooling
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
65/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.