Skip to content

fix: peer edge crash due to no parent or detached node - #8448

Merged
wraithgar merged 2 commits into
npm:latestfrom
milaninfy:mm/fix-peer-load
Aug 28, 2025
Merged

wraithgar merged 2 commits into
npm:latestfrom
milaninfy:mm/fix-peer-load

Conversation

@milaninfy

@milaninfy milaninfy commented Jul 21, 2025 •

Copy link
Copy Markdown
Contributor

node.parent is resulting in null value somewhere in recursive/looped calls to #loadPeerSet method in building ideal tree.

When circular peer ref of a top level dependency replaced/resolved with different compatible version, it makes top level dependency to be removed from it's parent ( node.parent = null ) since it's been replaced, so no longer need to proceed with further peer set exploration.

fixes: #8261

@milaninfy
milaninfy marked this pull request as ready for review July 31, 2025 17:40
@milaninfy
milaninfy requested a review from a team as a code owner July 31, 2025 17:40
Comment thread workspaces/arborist/lib/arborist/build-ideal-tree.js
@wraithgar
wraithgar merged commit 208c06e into npm:latest Aug 28, 2025
@github-actions github-actions Bot mentioned this pull request Aug 28, 2025
carlajarchuleta1-a11y

This comment was marked as spam.

ymichael added a commit to get-bb/bb that referenced this pull request Sep 11, 2026
…esolver fix (#3529)

## Human comments

## What was wrong

BB delegated plugin installation to whichever npm was on the server's
PATH. npm 10.9.8 reproducibly crashes installing the original BB Office
1.0.0 with `Cannot read properties of null (reading 'edgesOut')`.

The crash reproduces outside BB with just
`{"name":"repro","version":"1.0.0","devDependencies":{"vitest":"4.1.11"}}`
and `npm install --ignore-scripts --omit=dev --omit=optional --no-audit
--no-fund`. It also reproduces without `--omit=dev`; having development
dependencies is not itself an error.

Tracing Arborist shows Vitest 4.1.11 → Vite 8.3.0 → optional
@vitejs/devtools 0.7.3 → optional @vitejs/devtools-vitest 0.7.3 → Vitest
5.0.0. Resolving the circular peer set replaces the Vitest 5 node with
Vitest 4, but npm 10.9.8 continues traversing the detached node and
dereferences its null parent. This is fixed upstream by
npm/cli#8448. Adding only that upstream parent
guard in a process-local diagnostic hook makes the minimal reproduction
pass; npm 11.16.0 also passes unchanged.

Separately, an intentionally restricted-PATH experiment confirmed that
no npm executable means every Git install reaching the npm step fails.
Ayu succeeded normally and failed only in that artificial environment.
This is not an Ayu bug, and neither result has been attributed to the
original reporting user's incident without their full error and
environment.

## What changed

Ship pinned npm 11.16.0, containing the upstream resolver fix, and
invoke its CLI through BB's running Node executable for plugin
dependency installation and build-tool downloads. This makes the npm
version deterministic and removes the external-npm prerequisite. Keep
normal npm `--omit=dev --omit=optional --ignore-scripts` behavior.
Plugin manifests and development dependency declarations are not
rewritten.

Show installation errors persistently in the dialog, and update
CLI/skill/configuration guidance. UI, SDK, and CLI installs and updates
share these server paths. No server/daemon wire contract changed.
Office's independent unused-dependency cleanup is
ymichael/bb-plugins#2 and is not required for
this fix.

## How you verified

- Minimal standalone Vitest 4.1.11 reproduction: npm 10.9.8 fails; the
same npm with only the upstream parent guard succeeds; npm 11.16.0
succeeds. TypeScript-only devDependencies and Vitest 5.0.0 succeed on
npm 10.9.8 as controls.
- Original Office 1.0.0 (b2a8da0c497b9d63d525b061e2d22829686a9c57), with
its complete original devDependencies: exact BB npm command succeeds
with npm 11.16.0, installing one runtime package. Removing Office's
unused dependencies alone still crashes on npm 10.9.8.
- Built and packed the revised BB app into a fresh prefix and launched
with a fresh store. Clicked Install BB Office in the actual catalog UI:
original Office 1.0.0 reached `running`, remained enabled after reload,
and its installed manifest matched the original Git bytes with all 25
devDependencies intact. First-use toolchain download and frontend/server
builds succeeded using shipped npm 11.16.0.
- Turbo build/typecheck passed for server, plugin-build, and bb-app with
their dependencies.
- Server installer tests: 60 passed, including real shipped-npm
invocation, intact development dependency declarations, disabled
lifecycle scripts, and empty PATH. Build-toolchain tests: 5 passed, one
opt-in network test skipped.

> AGENT GENERATED
armando-navarro added a commit to armando-navarro/angularfire that referenced this pull request Oct 5, 2026
Every Node.js 20 and 22 release bundles npm 10, so the recovery note
under step 1 reached those readers only after the command had failed
once. Asking for npm 11.6 up front avoids the failure. The fix is
npm/cli#8448, shipped in arborist 9.1.4 with npm 11.6.0, and npm 10
stays on arborist 8.
armando-navarro added a commit to angular/angularfire that referenced this pull request Oct 5, 2026
…3787)

* docs: tell quickstart readers how to get past the npm edgesOut crash

`npm create @angular@21` fails with "Cannot read properties of null
(reading 'edgesOut')" on npm older than 11.6, which is what the
newest Node.js 20 and 22 releases come with. It is an npm bug
(npm/cli#9787), but a reader hits it at step 1.

The line says to delete the project folder because the failed run
leaves one behind, and running the command again into it fails with
a merge conflict on package.json.

Fixes #3785

* docs: require npm 11.6 or later before the quickstart's first step

Every Node.js 20 and 22 release bundles npm 10, so the recovery note
under step 1 reached those readers only after the command had failed
once. Asking for npm 11.6 up front avoids the failure. The fix is
npm/cli#8448, shipped in arborist 9.1.4 with npm 11.6.0, and npm 10
stays on arborist 8.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] Cannot read properties of null (reading 'edgesOut') - on npm i

3 participants