Skip to content

Setup inherits npm --prefix and adds dependencies to the plugin source #44

Description

@ajhcs

The documented npm --prefix plugins/codex-co-engineer run setup command can pass its local npm_config_prefix into setup's child npm install --global. On the 3.4.3 release installation, this created dependencies under the plugin's lib/node_modules and three generated executable links in its bin directory. Registering that local marketplace then copied the unintended dependencies into the plugin cache. The 476 released plugin files were unchanged, but the installation no longer had the exact release inventory.

bin/setup.mjs already removes npm_config_prefix and npm_config_local_prefix when inspecting the global npm root. Its installation subprocess should consistently use the intended global prefix. Preserve intentionally configured global-prefix behavior; do not clear unrelated user environment or modify existing credentials/configuration.

The current workaround is to invoke the released script directly from the release checkout, outside an npm --prefix invocation:

node plugins/codex-co-engineer/bin/setup.mjs
node plugins/codex-co-engineer/bin/setup.mjs --check

The source-archive integrity check passed; this is an installation-path defect, not a changed published artifact. The first failed inventory and local recovery evidence are retained privately. The release notes disclose the workaround. Clean-environment onboarding remains unqualified.

Acceptance for a follow-up patch:

  • The documented setup command installs its pinned dependencies into the intended global prefix without adding lib/node_modules or generated bin links to the plugin source.
  • Exercise prefix inheritance with a fake npm process in an isolated fixture; do not install real global packages in the regression test.
  • Existing explicit global-root/prefix configuration and the check path agree.
  • The shipped plugin file inventory remains unchanged by setup and normal plugin registration.
  • Update source and packaged setup guidance together; independently review the fix and qualify the changed release candidate.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions