Repository navigation
macOS: spawn-helper shipped without execute bit in npm tarball causes posix_spawnp failures (pnpm) #850
Description
Activity
Spawn helper added in #589
- added a commit that references this issue
on Jan 3, 2026 - addedbugIssue identified by VS Code Team member as probable bugIssue identified by VS Code Team member as probable bug
on Jan 3, 2026 Verified it fixes it, but only for the active arch prebuild binary.
Unfortunately,
chmod +x-ing the file as a (post)install script means that node-pty does not work out of the box in pnpm, since by default it does not run (post)install scripts for security reasons. On macOS, node-pty’s (post)install scripts aren’t really needed – except for thechmod +x. So you have to approve the (post)install scripts for node-pty. Which is easy, but one unnecessary step.Couldn’t you make sure that the tarball contains an already
chmod +x-edspawn-helperinstead? I did that in the just-released@lydell/node-pty@1.2.0-beta.2. It then works out of the box with pnpm.It looks like the prebuilds are downloaded here:
Lines 63 to 78 in 732ebf7
- task: DownloadPipelineArtifact@2 displayName: 'Download prebuilds' inputs: buildType: 'specific' project: 'Monaco' definition: '647' buildVersionToDownload: 'latestFromBranch' branchName: 'refs/heads/main' artifactName: 'prebuilds' targetPath: 'prebuilds' - script: npm ci displayName: 'Install dependencies and build' - script: npm test displayName: 'Test' - script: npm run lint displayName: 'Lint' Then it sounds like it would be possible to add a
chmod +xstep forspawn-helperthere.Reacted by Daniel ImmsSimon Lydell (@lydell) thanks for the extra nudge, sounds like a good plan
20 remaining items
- added a commit that references this issue
on Jul 26, 2026 - added a commit that references this issue
on Jul 29, 2026 - added a commit that references this issue
on Jul 29, 2026 Reproduced on npm rather than pnpm. macOS 26.5.2, arm64, node-pty 1.1.0, from a clean npm ci. The published tarball itself carries mode 0644:
tar -tvf node-pty-1.1.0.tgz -rw-r--r-- package/prebuilds/darwin-arm64/spawn-helper -rw-r--r-- package/prebuilds/darwin-x64/spawn-helperA plain
tar -xzfoutside any package manager gives the same, so the extractor is not the variable. 1.2.0-beta.15 ships both as 0755, so the fix exists but not on the stable line.Source builds are unaffected because
loadNativeModulechecksbuild/Releasebeforeprebuilds, and darwin prebuilds are new in 1.1.0, which is likely why this is not reported more widely.Worth adding for anyone packaging: asar preserves the mode through pack and unpack, so a 0644 helper in the tree at package time becomes a 0644 helper in the shipped
.app, whereposix_spawnpfails for every user and reproduces on no development machine that ran a fix locally.BENZOOgataga (@BENZOOgataga) v1.1.0 is broken, this PR was shipped in v1.2.0-beta.2. There is unfortunately no release marked as “stable” with a fix in it. (But the beta isn't really a beta, it's stable, IMO.)
BENZOOgataga (@BENZOOgataga) v1.1.0 is broken, this PR was shipped in v1.2.0-beta.2. There is unfortunately no release marked as “stable” with a fix in it. (But the beta isn't really a beta, it's stable, IMO.)
Oh alright thank you for your answer!
- added a commit that references this issue
on Aug 10, 2026 - added a commit that references this issue
on Aug 13, 2026 - added a commit that references this issue
on Aug 15, 2026 - added a commit that references this issue
on Aug 31, 2026 - added a commit that references this issue
on Sep 1, 2026 - added a commit that references this issue
on Sep 18, 2026 - added a commit that references this issue
on Sep 21, 2026 - added a commit that references this issue
on Sep 24, 2026 - added a commit that references this issue
on Sep 29, 2026


Description
The
spawn-helperbinary in the darwin prebuilds is published to npm without the execute permission bit (644 instead of 755), causingposix_spawnp failederrors when using package managers that preserve file permissions during extraction.This primarily affects pnpm users, as pnpm's content-addressable store preserves the original tarball permissions, whereas npm/yarn may not exhibit the issue due to different extraction behavior.
Steps to Reproduce
Expected Behavior
spawn-helper should have execute permission (755) and the spawn should succeed.
Actual Behavior
The tarball contains spawn-helper with 644 permissions:
Workaround
Environment
Related Issues
Suggested Fix
Ensure spawn-helper has execute permission when creating prebuilds. This might be addressed in the prebuild pipeline or by setting file modes before
npm pack.