socket npm run build crashes with ERR_MISSING_OPTION: --permission on Node v24 + Next.js
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 78/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Quiet
- Tech stack
- next.js, node.js, typescript
- Domain
- build-system, cli
Research direction
Inspect shadow-npm-bin2.js around line 67 and reproduce the failure with Node v24 using socket npm run build versus npm run build. Remove the literal single quotes from the spawned --node-options value, then verify that the Next.js TypeScript checking phase completes without ERR_MISSING_OPTION.
Written by the indexing model from the issue text.
Description
Description
socket npm run build crashes during Next.js's TypeScript checking phase on Node v24. Running npm run build directly works fine.
Root cause
In shadow-npm-bin2.js:67, the --node-options value is wrapped in literal single quotes:
`--node-options='${...}${utils.cmdFlagsToString(permArgs)}'`
Since this argument is passed via child_process.spawn() (no shell), the quotes are not interpreted — npm receives them as part of the value and sets:
NODE_OPTIONS='--permission --allow-child-process --allow-fs-read=* --allow-fs-write=...'
Node.js silently ignores the garbled tokens. However, Next.js re-parses NODE_OPTIONS for its build workers using a tokenizer that splits on whitespace and only handles " as string delimiters, not '. This causes:
'--permission(leading') → unrecognized, dropped--allow-child-process,--allow-fs-read=*,--allow-fs-write=...→ valid, kept
The TypeScript worker then receives --allow-* flags without --permission, and Node v24 throws ERR_MISSING_OPTION.
Suggested fix
Remove the single quotes — they are unnecessary and harmful when arguments are passed via spawn():
- `--node-options='${nodeOptionsArg ? nodeOptionsArg.slice(15) : ''}${utils.cmdFlagsToString(permArgs)}'`
+ `--node-options=${nodeOptionsArg ? nodeOptionsArg.slice(15) : ''}${utils.cmdFlagsToString(permArgs)}`
Repro
- Node v24.11.1, Next.js 16.2.1, Socket CLI 1.1.78 (also 1.1.76)
npm run build→ succeedssocket npm run build→ crashes at "Running TypeScript ..."
TypeError [ERR_MISSING_OPTION]: --permission is required
at node:internal/process/pre_execution:656:15
at Array.forEach (<anonymous>)
at initializePermission (node:internal/process/pre_execution:653:5)
Related
- #1036 — a separate bug on the same line where user-set
NODE_OPTIONSare replaced rather than merged
- Dominant language
- TypeScript
- Stars
- 317
- Forks
- 65
- Avg merge
- 1h 26m
- Merged PRs (30d)
- 30
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from SocketDev/socket-cli
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
SocketDev/socket-cli#1547 ·
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
SocketDev/socket-cli#1525 ·
-
Difficulty 3/5 1-2 days Newbie friendliness 45/100
SocketDev/socket-cli#1517 ·
-
Difficulty 3/5 1-2 days Newbie friendliness 68/100
SocketDev/socket-cli#1498 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 48/100
SocketDev/socket-cli#1497 · 1 reaction ·
All issues in SocketDev/socket-cli
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Eynzof/Hermes-CN-Desktop#610 ·
-
bug clawsweeper:linked-pr-open clawsweeper:needs-live-repro clawsweeper:no-new-fix-pr impact:message-loss issue-rating: 🐚 platinum hermit P2 regression
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
calcite-components needs triage refactor
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Esri/calcite-design-system#15203 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 78/100
fullcalendar/fullcalendar#8106 ·