Skip to content

feat(install): support pnpm v12 native binary distribution - #2289

Merged
fengmk2 merged 12 commits into
voidzero-dev:mainfrom
jong-kyung:fix/pnpm-v12-native-binary
Aug 3, 2026
Merged

feat(install): support pnpm v12 native binary distribution#2289
fengmk2 merged 12 commits into
voidzero-dev:mainfrom
jong-kyung:fix/pnpm-v12-native-binary

Conversation

@jong-kyung

@jong-kyung jong-kyung commented Aug 1, 2026

Copy link
Copy Markdown
Collaborator

This fixes running pnpm 12 (currently 12.0.0-beta.0) through Vite+. Executing any pnpm command failed with:

error: Failed to exec .../.vite-plus/package_manager/pnpm/12.0.0-beta.0/pnpm/bin/pnpm: No such file or directory
(os error 2)

Root cause

pnpm 12 is a native binary (Rust rewrite). The pnpm npm package no longer ships bin/pnpm.cjs — it only contains shebang-less placeholder bins that a preinstall script replaces with the platform binary from the @pnpm/exe.* optional dependencies (install.js).
Vite+ extracts the tarball without running lifecycle scripts, so create_shim_files found no JS entrypoint, silently created no shims, and the exec of bin/pnpm failed. The completeness check also never passed, so every invocation re-downloaded the tarball.

Fix

For pnpm >= 12, download the platform-specific @pnpm/exe.{os}-{arch} package directly and place the binary at bin/pnpm.native with native shims, mirroring the existing bun flow. pnpm <= 11 keeps the JS flow unchanged.

The pnpx shim injects dlx explicitly: upstream's binary self-detects its launch name via current_exe to alias pnpx (argv_with_alias_subcommand), which a wrapper script cannot trigger. This matches upstream's own Unix pnpxscript (exec pnpm dlx "$@"). Shims
generated with no injected args are byte-identical to before, so bun is unaffected.

Resolves #2276

pnpm >= 12 is a native binary: the npm package only ships placeholder
bins that a preinstall script replaces from the platform-specific
@pnpm/exe.* packages. Lifecycle scripts never run for managed package
manager installs, so no bin/pnpm.cjs exists and exec of bin/pnpm failed
with ENOENT (and the completeness check re-downloaded on every run).

Download the @pnpm/exe.{os}-{arch} package directly for pnpm >= 12,
place the binary at bin/pnpm.native, and create native shims, mirroring
the bun flow. The pnpx shim injects dlx explicitly because shims do not
preserve the launch name the binary self-detects for alias behavior.

Fixes voidzero-dev#2276
@netlify

netlify Bot commented Aug 1, 2026

Copy link
Copy Markdown

Deploy Preview for viteplus-preview ready!

Name Link
🔨 Latest commit 5a5ecb9
🔍 Latest deploy log https://app.netlify.com/projects/viteplus-preview/deploys/6a700ae3841ae8000894e9b2
😎 Deploy Preview https://deploy-preview-2289--viteplus-preview.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@jong-kyung

Copy link
Copy Markdown
Collaborator Author

@codex review

@jong-kyung jong-kyung changed the title fix(install): support pnpm v12 native binary distribution feat(install): support pnpm v12 native binary distribution Aug 1, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 891f54bd39

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/vite_install/src/package_manager.rs Outdated
The hash names the main pnpm tarball, not the platform package: verify
it against the artifact it describes before the native download, so a
bad pin fails the same way it does for pnpm <= 11.
@jong-kyung

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c8e25e0645

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/vite_install/src/package_manager.rs Outdated
The hash path reuses the same download_and_extract_tgz_with_hash /
verify_file_hash mechanism the pnpm <= 11 flow uses, which is already
covered by the mock-server tests in request.rs; neither flow needs a
registry-hitting integration test for it.
@jong-kyung

Copy link
Copy Markdown
Collaborator Author

@codex review

@jong-kyung jong-kyung self-assigned this Aug 1, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 98062166c4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/vite_install/src/package_manager.rs
@jong-kyung
jong-kyung marked this pull request as ready for review August 1, 2026 10:51
@jong-kyung
jong-kyung requested a review from fengmk2 August 1, 2026 10:51
Comment thread crates/vite_install/src/package_manager.rs Outdated
The @pnpm/exe.* platform tarball was downloaded without any hash check
because the declared packageManager hash only names the main pnpm
package. Fetch the platform package's registry version metadata and
verify the tarball against its dist.integrity (SRI), converted to the
algo.hex format verify_file_hash already understands. Registries that
omit the field keep the previous unverified behavior.
@jong-kyung

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Keep them coming!

Reviewed commit: 76664d98b9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/vite_install/src/package_manager.rs Outdated
…trip

Teach verify_file_hash the registry dist.integrity SRI format
(algorithm-base64) alongside the declared algorithm.hex format, comparing
the digest in the encoding the expected hash uses. The pnpm 12 flow now
passes dist.integrity straight through instead of converting it to hex
first, dropping sri_to_expected_hash.
@jong-kyung

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4b3913c3a8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/vite_install/src/request.rs
@jong-kyung
jong-kyung requested a review from fengmk2 August 2, 2026 15:51
@jong-kyung

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 11715354e8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread crates/vite_install/src/package_manager.rs
Comment thread crates/vite_install/src/package_manager.rs
Comment thread crates/vite_install/src/request.rs Outdated
@fengmk2
fengmk2 merged commit cc455a3 into voidzero-dev:main Aug 3, 2026
44 checks passed
@jong-kyung
jong-kyung deleted the fix/pnpm-v12-native-binary branch August 3, 2026 03:49
fengmk2 added a commit that referenced this pull request Aug 5, 2026
…t variable renames, and install fixes (#2325)

Release vite-plus v0.2.8: monorepo target resolution, breaking `VP_*`
environment variable renames, and install fixes.

Bare `vp dev`/`build`/`preview`/`pack` at a monorepo root now resolve a
target package instead of silently running against the root, and three
Vite+-specific environment variables move to the `VP_*` prefix without
compatibility aliases. Two failures that broke Vite+ before it could run
are also fixed: the crash on container images that ship no CA
certificates, and the missing Rolldown binding under pnpm's global
virtual store.

### Breaking Changes

- Rename three Vite+-specific environment variables to the `VP_*`
prefix, with no compatibility aliases, so the old names stop working
([#2312](#2312)), by
@jong-kyung:

  | Old | New |
  | --- | --- |
  | `VITE_LOG` | `VP_LOG` |
  | `VITE_GLOBAL_CLI_JS_SCRIPTS_DIR` | `VP_GLOBAL_CLI_JS_SCRIPTS_DIR` |
  | `VITE_UPDATE_TASK_TYPES` | `VP_UPDATE_TASK_TYPES` |

Update any shell profile, CI job, or Dockerfile that sets the old names.

### Highlights

- Resolve a target package for `vp dev`, `build`, `preview`, and `pack`
at a monorepo root: interactive shells get a fuzzy package picker,
non-interactive runs list the candidates and exit 1 instead of building
the root, and a new global `-C <dir>` flag or a `defaultPackage` setting
(a single directory, or an object mapping each of the four commands to
its own directory) skips the prompt
([#2031](#2031),
[#2305](#2305)), by
@fengmk2
- Stop aborting with exit 134 on container images that ship no CA
certificates (Debian slim, distroless): the shared HTTP client now
retries once with the bundled Mozilla root list, like Node's own bundled
roots, and reports a real error instead of panicking when it still
cannot be built
([#2273](#2273),
[#2295](#2295)), by
@jbmusso and @fengmk2
- Resolve the bundled Rolldown binding through platform packages instead
of an undeclared require back into `vite-plus`, fixing `Cannot find
module 'vite-plus/binding'` under pnpm `enable-global-virtual-store` and
in standalone `@voidzero-dev/vite-plus-core` installs
([#2313](#2313)), by
@fengmk2
- Add `vp pm ci` for reproducible frozen-lockfile installs, and `vp pm
patch` / `vp pm patch-commit` for editing dependencies in place on pnpm,
bun, and Yarn Berry (npm and Yarn Classic warn and exit successfully)
([#2082](#2082),
[#2308](#2308)), by
@forehalo and @jong-kyung

### Features

- Upgrade the bundled toolchain: vite `8.1.5` -> `8.2.0`, rolldown
`1.2.0` -> `1.2.2`, oxlint `1.75.0` -> `1.76.0`, oxfmt `0.60.0` ->
`0.61.0`, and Vite DevTools `0.4.5` -> `0.4.10`
([#2302](#2302),
[#2311](#2311)), by
@voidzero-guard[bot]. The new oxfmt and oxlint can flag code that passed
before, so run `vp fmt` after upgrading if your CI runs `vp check`.
- Read the Node.js version from `.nvmrc` when no other version source is
present ([#2244](#2244)),
by @BlankParticle
- Support pnpm v12, which ships as a native binary: Vite+ now downloads
the platform-specific `@pnpm/exe.*` package and generates native shims,
so `pnpm` and `pnpx` work instead of failing to exec
([#2289](#2289)), by
@jong-kyung
- Verify the downloaded bun platform tarball against the registry
`dist.integrity` hash
([#2310](#2310)), by
@jong-kyung

### Fixes & Enhancements

- Let `vp config` install the Git hook dispatcher without creating or
modifying project hook scripts or staged-file configuration, so a custom
`.vite-hooks/pre-commit` survives
([#2280](#2280)), by
@TheAlexLichter
- Nest immutable global package installs under
`packages/<package>/<uuid>` instead of using `#` in the path, which Node
treated as a URL fragment and which broke dynamic imports inside
installed packages
([#2222](#2222)), by
@liangmiQwQ
- Keep the recorded version spec on global installs, so `vp update -g`
follows a dist tag or range instead of silently resolving back to
`latest`, `vp outdated -g` reports Wanted versus Latest, and `vp update
-g --latest` explicitly moves packages back to `latest`
([#2249](#2249)), by
@TheAlexLichter
- Stop deleting a managed Node.js runtime that another process is
concurrently installing
([#2248](#2248)), by
@shulaoda
- Preserve the real exit code when a spawned process is terminated by a
signal on Unix
([#2154](#2154)), by
@liangmiQwQ
- Honor an explicit `vp create --package-manager` outside monorepos
instead of inheriting the manager from a non-monorepo ancestor directory
([#2226](#2226)), by
@jong-kyung
- Scaffold the `vite:library` template into a directory that contains
only `.git`, while still refusing to overwrite existing user files
([#2287](#2287)), by
@RSS1102
- Render help for delegated commands from the local CLI, so `vp
<command> --help` matches the installed toolchain instead of drifting
([#2184](#2184)), by
@liangmiQwQ
- Resolve `typeAware` and `typeCheck` options inherited through Oxlint
`extends`, so `vp check --no-lint` runs and classifies type checking
correctly
([#2228](#2228)), by
@jong-kyung
- Report `(no version)` instead of `unknown` when globally installing a
local package that has no `version` field
([#2232](#2232)), by
@liangmiQwQ

### Refactor

- Rename the Git hooks environment variable to `VP_GIT_HOOKS`, keeping
`VITE_GIT_HOOKS` working as a deprecated alias
([#2195](#2195)), by
@dennybiasiolli
- Consolidate the package manager infrastructure so typed command
arguments are the source of truth for per-manager compatibility
([#2140](#2140)), by
@forehalo
- Generate the Zed language settings from a language list instead of 17
near-identical blocks
([#2294](#2294)), by
@jong-kyung
- Share the agent-file detect and write traversal helpers so both passes
apply identical rules
([#2296](#2296)), by
@jong-kyung
- Drop redundant clippy allow attributes in the global CLI
([#2235](#2235)), by
@shulaoda

### Docs

- Avoid a duplicate `vp` installation step in the onboarding prompt
([#2291](#2291)), by
@Arcadi4
- Recommend stacked pull requests for submitting changes
([#2281](#2281)), by
@fengmk2
- Correct stale delegation comments in the global CLI
([#2236](#2236)), by
@shulaoda
- Improve the release draft review guidance in the release-manager skill
([#2285](#2285)), by
@wan9chi

### Chore

- Stop emitting unmet peer warnings for the `vite-plus` peer of oxfmt
and oxlint on every install
([#2321](#2321)), by
@fengmk2
- Remove duplicate direct dependency declarations so each build
dependency is owned by one workspace
([#2318](#2318)), by
@jong-kyung
- Declare `@emnapi` peers where `@napi-rs/cli` is used
([#2319](#2319)), by
@jong-kyung
- Exclude `rollup-tests` from the workspace and update `basic-ftp`
([#2322](#2322)), by
@fengmk2
- Remove unused `EnvConfig` fields
([#2320](#2320)), by
@jong-kyung
- Remove the obsolete peer dependency merger tool
([#2303](#2303)), by
@jong-kyung
- Stop the staging deploy from triggering on external pull requests
([#2293](#2293)), by
@BlankParticle
- Kill the real `vp` process, and kill it before its children, in the
`env_install_interrupt` snapshot test
([#2299](#2299),
[#2316](#2316)), by
@fengmk2
- Suppress racy optimizer logs in the `vitest_browser_mode` snapshot
test ([#2297](#2297)), by
@fengmk2
- Remove the obsolete auto-install environment from the snapshot tests
([#2163](#2163)), by
@liangmiQwQ

### Bundled Versions

| Tool | Version | Source |
| --------------- | ---------- |
-------------------------------------------------------------------------------------------------
|
| vite | `8.2.0` |
[`fa79f9a`](vitejs/vite@fa79f9a)
|
| rolldown | `1.2.2` |
[`872b98a`](rolldown/rolldown@872b98a)
|
| tsdown | `0.22.14` | [npm](https://npmx.dev/package/tsdown/v/0.22.14)
|
| vitest | `4.1.10` | [npm](https://npmx.dev/package/vitest/v/4.1.10) |
| oxlint | `1.76.0` | [npm](https://npmx.dev/package/oxlint/v/1.76.0) |
| oxlint-tsgolint | `7.0.2001` |
[npm](https://npmx.dev/package/oxlint-tsgolint/v/7.0.2001) |
| oxfmt | `0.61.0` | [npm](https://npmx.dev/package/oxfmt/v/0.61.0) |

### Upgrade

```bash
vp upgrade
```

### New Contributors

@jbmusso, @Arcadi4, @dennybiasiolli, @RSS1102

**Full Changelog**:
v0.2.7...v0.2.8

---

Merging this PR will trigger the release workflow.

---------

Co-authored-by: voidzero-guard[bot] <278573678+voidzero-guard[bot]@users.noreply.github.com>
Co-authored-by: MK <fengmk2@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Support for pnpm v12

2 participants