Harper auto-resolution silently tests the published npm package when the consumer doesn't declare harper
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 52/100
- issue の種類
- バグ
- 明瞭さ
- おおむね明確
- 活発さ
- 静か
- 技術スタック
- node.js, typescript
- 領域
- testing-qa, tooling
調査の方向性
まず getHarperScript とパッケージマニフェストを見つけ、HARPER_INTEGRATION_TEST_INSTALL_SCRIPT なしで、ドキュメントに記載された統合テストコマンドを再現します。インストール済みの harper パッケージを選択する解決分岐を追跡し、ローカルの dist フォールバックと比較します。未宣言の harper 依存関係によって公開済みパッケージが暗黙的に選択されなくなり、関連する統合動作がカバーされるか、明確に報告されれば完了です。
索引モデルが issue の本文から書いたものです。
説明
What happened
Running npm run test:integration -- integrationTests/server/v1-gateway.test.ts locally in the harper core repo (without HARPER_INTEGRATION_TEST_INSTALL_SCRIPT, which only CI sets) silently ran the suite against [email protected] from the npm registry instead of the repo's freshly built dist/. Every test failed with 404s/401s because the published binary predates the feature under test — nothing indicated the wrong binary was in play, and the misdiagnosis cost hours.
Why
The README documents resolution step 3 as:
Auto-resolved from a
harperpackage installed as a project dependency
and harper is correctly declared as a peerDependency (^5.0.0) — but npm ≥7 auto-installs peerDependencies. A consumer that never declares harper (the core repo itself, or any component repo that forgot) still ends up with [email protected] hoisted into its node_modules, and getHarperScript step 3 resolves it:
$ npm ls harper # in HarperFast/harper — which declares no harper dep
[email protected]
└─┬ @harperfast/[email protected]
└── [email protected] # npm auto-installed to satisfy the peer range
The auto-install defeats the documented "project dependency" intent, and step 4 (cwd/ancestor dist/bin/harper.js — the fallback that would find the local build) is never reached.
Candidate fixes
peerDependenciesMeta: { harper: { optional: true } }(preferred): npm stops auto-installing the peer. Consumers that declare harper resolve exactly as documented; consumers that don't fall through to the cwd/ancestordistfallback or get the existing clear "Harper CLI script not found" error telling them their options. Behavior change only for repos that were (likely unknowingly) leaning on the auto-installed registry copy.- Prefer cwd/ancestor
dist/bin/harper.jsovernode_moduleswhen both exist (swap steps 3↔4 precedence): fixes the harper source tree, and is a no-op for component repos (whose owndist/is not a harper build). Slightly riskier for unusual directory layouts.
Note that resolving step 3 "from the project instead of the harness module" does not fix this — npm hoists the auto-installed peer into the consumer's root node_modules, so a cwd-based resolve finds the same wrong copy.
Regardless of direction, observability for the resolution decision is being proposed separately (log the resolved path + warn when node_modules/harper wins while a cwd dist/bin/harper.js exists).
🤖 Filed with Claude Code on behalf of @heskew
- 主要言語
- TypeScript
- スター
- 1
- フォーク
- 0
- 平均マージ
- 8日 9分
- マージ済み PR(30日)
- 1
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
HarperFast/integration-testing のほかの issue
-
setupHarperWithFixture overwrites ctx.harper, dropping pre-set hostname (breaks multi-node add_node)オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
-
enhancement good first issue
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
-
難易度 3/5 1〜2日 初心者へのやさしさ 74/100
-
難易度 4/5 3〜5日 初心者へのやさしさ 58/100
-
Detached Harper children are orphaned permanently when the runner dies by SIGKILL/SIGHUP — reap guard only covers exit/SIGINT/SIGTERM再び着手できるかも @kriszyp が 48 日前に担当しましたが、オープン中のプルリクエストはありません。 オープン
HarperFast/integration-testing#29 · コメント 1 件 · 担当者 1 名 ·
HarperFast/integration-testing の issue をすべて見る
似ている issue
-
area: backend bug priority: low
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
snapotter-hq/SnapOtter#2254 ·
メンテナーはふだん 1 日以内に返信
-
bug ticket
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
cratestack/cratestack#1154 ·
メンテナーはふだん 1 日以内に返信
-
server 消息处理器 cmd 分支补显式错误回报——竞态非法命令现走未处理拒绝対応中かも @openaddr が今日担当しました。 オープンready-for-agent refactor wayfinder:task
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
openaddr/dafung-web#428 ·
メンテナーはふだん 1 日以内に返信
-
Flaky: mongodb-memory-server 'Port already in use' when another process starts a mongod concurrentlyオープンarea:testing bug effort:S priority:P2
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
メンテナーはふだん 1 日以内に返信
-
lens:agent lens:process process
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
thebristolsound/birdbrain#1772 ·
メンテナーはふだん 1 日以内に返信