The npm thin-installer shim spawned the per-platform bundle's `.cmd` launcher directly. Modern Node on Windows refuses to spawn `.cmd`/`.bat` without `shell: true` (the CVE-2024-27980 hardening), so every `codegraph` command failed with `spawnSync …\codegraph.cmd EINVAL` (seen on Node 24). On Windows the shim now invokes the bundled `node.exe` against the app entry point directly, bypassing the `.cmd` (and avoiding the arg-quoting pitfalls of `shell: true`). Unix is unchanged. Validated end-to-end against a real win32-x64 bundle: `npm install` of the packed tarballs + `codegraph init -i`/`status` run on the bundled Node 24. Also cuts release 0.9.2, rolling up the pending Drupal, zero-config, config-removal, Hermes-installer, and symlink-security changes. Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.7
parent
f6772dac7c
commit
c41559a9d0
+3
-1
@@ -50,7 +50,9 @@ linux/amd64`).
|
||||
bundles ship as per-platform `optionalDependencies`
|
||||
(`@colbymchenry/codegraph-<target>` with `os`/`cpu`), so npm installs only the
|
||||
matching one. The shim — run by the user's Node — execs the bundle, so the
|
||||
real work runs on the bundled Node 24. Works even on old Node.
|
||||
real work runs on the bundled Node 24. Works even on old Node. On Windows it
|
||||
invokes the bundled `node.exe` against the app entry directly (not the `.cmd`
|
||||
launcher) — modern Node throws `EINVAL` when asked to spawn a `.cmd`/`.bat`.
|
||||
3. **Windows** ([`install.ps1`](install.ps1)) — `irm … | iex`; same flow as
|
||||
install.sh (detect arch, pull the `.zip` from Releases, add to PATH).
|
||||
4. **Homebrew / Scoop** — TODO (tap + cask pointing at the Release archives).
|
||||
|
||||
Reference in New Issue
Block a user