Files
codegraph/scripts/npm-shim.js
T
c41559a9d0 fix(installer): Windows npm launcher EINVAL on modern Node (#289) (#292)
The npm thin-installer shim spawned the per-platform bundle's `.cmd`
launcher directly. Modern Node on Windows refuses to spawn `.cmd`/`.bat`
without `shell: true` (the CVE-2024-27980 hardening), so every `codegraph`
command failed with `spawnSync …\codegraph.cmd EINVAL` (seen on Node 24).

On Windows the shim now invokes the bundled `node.exe` against the app
entry point directly, bypassing the `.cmd` (and avoiding the arg-quoting
pitfalls of `shell: true`). Unix is unchanged.

Validated end-to-end against a real win32-x64 bundle: `npm install` of the
packed tarballs + `codegraph init -i`/`status` run on the bundled Node 24.

Also cuts release 0.9.2, rolling up the pending Drupal, zero-config,
config-removal, Hermes-installer, and symlink-security changes.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-21 21:22:50 -05:00

56 lines
2.3 KiB
JavaScript
Executable File

#!/usr/bin/env node
'use strict';
//
// npm thin-installer launcher for CodeGraph.
//
// The heavy artifact (a vendored Node runtime + the app) ships as a per-platform
// optionalDependency: @colbymchenry/codegraph-<platform>-<arch>. npm installs
// only the one matching the host, via each package's `os`/`cpu` fields (the
// esbuild pattern). This shim — run by the user's OWN Node — locates that bundle
// and execs its launcher, so the real work always runs on the bundled Node 24
// (with node:sqlite), regardless of the user's Node version. The user's Node is
// only ever a launcher; even an ancient version can run this file.
//
// Wired up at release time as the main package's `bin`:
// "bin": { "codegraph": "scripts/npm-shim.js" }
// with the platform packages listed in `optionalDependencies`.
var childProcess = require('child_process');
var target = process.platform + '-' + process.arch; // e.g. darwin-arm64, linux-x64
var pkg = '@colbymchenry/codegraph-' + target;
var isWindows = process.platform === 'win32';
// On Windows the bundle's launcher is a .cmd batch file. Modern Node refuses to
// spawn .cmd/.bat directly — spawnSync throws EINVAL (the CVE-2024-27980
// hardening, observed on Node 24). So on Windows we skip the .cmd and invoke the
// bundled node.exe against the app entry point directly. On unix the bin launcher
// is a shell script that spawns cleanly.
var command, args;
try {
if (isWindows) {
command = require.resolve(pkg + '/node.exe');
var entry = require.resolve(pkg + '/lib/dist/bin/codegraph.js');
args = [entry].concat(process.argv.slice(2));
} else {
command = require.resolve(pkg + '/bin/codegraph');
args = process.argv.slice(2);
}
} catch (e) {
process.stderr.write(
'codegraph: no prebuilt bundle for ' + target + '.\n' +
'Expected the optional package ' + pkg + ' to be installed.\n' +
'Try reinstalling: npm i -g @colbymchenry/codegraph\n' +
'Or use the standalone installer (no Node required):\n' +
' curl -fsSL https://raw.githubusercontent.com/colbymchenry/codegraph/main/install.sh | sh\n'
);
process.exit(1);
}
var res = childProcess.spawnSync(command, args, { stdio: 'inherit' });
if (res.error) {
process.stderr.write('codegraph: ' + res.error.message + '\n');
process.exit(1);
}
process.exit(res.status === null ? 1 : res.status);