fix(nix): build bcrypt's native binding again under pnpm 10 — unbreaks nsecbunkerd on aio-demo #54
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/pnpm10-bcrypt-native-build"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
What broke
nsecbunkerdhas been crashlooping on aio-demo (restart counter climbing past 21). Every restart dies with:aio-demo'sflake.lockpinsnsecbunkerd-devat exactly0d8c436f— thenodejs_20/pnpm_9→nodejs_24/pnpm_10bump. Its store path contains onlybinding.gypand the C++ sources underbcrypt@5.1.1; there is nolib/binding/and no.nodefile anywhere. The daemon requiresbcryptat load, so it dies in about a second, every time.Why
buildPhasere-runspnpm install --force --offlinespecifically to fire bcrypt's node-gyp postinstall, becauseconfigHookinstalls with--ignore-scripts.pnpm 10 changed that contract. Unlike pnpm 9, it refuses to run any dependency lifecycle script unless the package is allow-listed (
onlyBuiltDependencies/pnpm approve-builds) — and it skips them silently, with the install still reporting success. So the bump turned that line into a no-op, the build kept passing, and the breakage only surfaced at boot on the deployed host.Fix
d2ec84a— restore the native build, and make the failure loud--config.dangerouslyAllowAllBuilds=trueon the offline reinstall, restoring the pnpm 9 semantics this build has always relied on. We run inside the nix sandbox against a store-seeded offline cache, so "all builds" is the same closed set of scripts pnpm 9 already ran.doInstallCheckthatrequire()s bcrypt from the installed$outtree, the same waydist/daemon/index.jsdoes. This failure mode is invisible at build time and fatal at boot, so it has to break the build rather than the host.e05e184— stop the launcher erroring on every bootscripts/start.jsshells out tonpm run prisma:migrate, but the wrapper only putnodejsandopensslon PATH, so npm could not spawn a shell at all:Never fatal —
ExecStartPrealready applies migrations ("No pending migrations to apply") — but it's journal noise that made the real bcrypt crash harder to spot. A shell alone isn't enough either: pnpm's generatednode_modules/.bin/prismais itself a/bin/shscript resolving its basedir withdirname+sed. Shipsbash+coreutils+gnusedso the launcher stands on its own under any caller's environment.Verification
Built against the same nixpkgs the deploy uses (
da5ad661), both commits independently:lib/binding/napi-v3/bcrypt_lib.nodeis producedinstallCheckPhaseprintsbcrypt native binding loads OKPATH=/nonexistent, the wrapper applies all 25 migrations and the daemon reaches✅ nsecBunker ready to serve requests.— zeroMODULE_NOT_FOUNDpnpmDepshash unchangedAfter merge
The daemon cannot recover without a new build, so this needs a
flake.lockbump ofnsecbunkerd-devindeploy/server-deployand a redeploy toaio-demo.🤖 Generated with Claude Code
https://claude.ai/code/session_01QBjd9Rw4ct134JH3CnLVaw