Skip to content

macOS: spawn-helper shipped without execute bit in npm tarball causes posix_spawnp failures (pnpm) #850

Description

Description

The spawn-helper binary in the darwin prebuilds is published to npm without the execute permission bit (644 instead of 755), causing posix_spawnp failed errors when using package managers that preserve file permissions during extraction.

This primarily affects pnpm users, as pnpm's content-addressable store preserves the original tarball permissions, whereas npm/yarn may not exhibit the issue due to different extraction behavior.

Steps to Reproduce

mkdir test-pty && cd test-pty
npm init -y
pnpm add node-pty

# Check permissions - shows 644 instead of 755
ls -la node_modules/.pnpm/node-pty@1.1.0/node_modules/node-pty/prebuilds/darwin-arm64/spawn-helper

# Try to use node-pty
node -e "require('node-pty').spawn('/bin/echo', ['test'])"

Expected Behavior

spawn-helper should have execute permission (755) and the spawn should succeed.

Actual Behavior

Error: posix_spawnp failed.
    at new UnixTerminal (node_modules/node-pty/lib/unixTerminal.js:92:24)

The tarball contains spawn-helper with 644 permissions:

$ npm pack node-pty@1.1.0 && tar -tvf node-pty-1.1.0.tgz | grep spawn-helper
-rw-r--r--  0 0      0       50480 Oct 26  1985 package/prebuilds/darwin-arm64/spawn-helper
-rw-r--r--  0 0      0        9248 Oct 26  1985 package/prebuilds/darwin-x64/spawn-helper

Workaround

chmod +x node_modules/.pnpm/node-pty@*/node_modules/node-pty/prebuilds/darwin-*/spawn-helper

Environment

  • node-pty: 1.1.0
  • Node.js: v25.2.1 (also reproduced on v22.x)
  • OS: macOS (darwin-arm64)
  • Package manager: pnpm 10.11.0

Related Issues

Suggested Fix

Ensure spawn-helper has execute permission when creating prebuilds. This might be addressed in the prebuild pipeline or by setting file modes before npm pack.

Activity

  1. Tyriar commented on Jan 3, 2026

    @Tyriar
    Contributor

    Spawn helper added in #589

  2. Tyriar commented on Jan 3, 2026

    @Tyriar
    Contributor

    Fresh local build shows it's got executable bit Image

  3. Tyriar commented on Jan 3, 2026

    @Tyriar
    Contributor

    Missing on prebuilds only:

    Image
  4. added a commit that references this issue on Jan 3, 2026
    d08cd36
  5. added this to the milestone on Jan 3, 2026
  6. Tyriar commented on Jan 4, 2026

    @Tyriar
    Contributor

    Verified it fixes it, but only for the active arch prebuild binary.

  7. lydell commented on Jan 4, 2026

    @lydell
    Contributor

    Unfortunately, chmod +x-ing the file as a (post)install script means that node-pty does not work out of the box in pnpm, since by default it does not run (post)install scripts for security reasons. On macOS, node-pty’s (post)install scripts aren’t really needed – except for the chmod +x. So you have to approve the (post)install scripts for node-pty. Which is easy, but one unnecessary step.

    Couldn’t you make sure that the tarball contains an already chmod +x-ed spawn-helper instead? I did that in the just-released @lydell/node-pty@1.2.0-beta.2. It then works out of the box with pnpm.

    It looks like the prebuilds are downloaded here:

    node-pty/publish.yml

    Lines 63 to 78 in 732ebf7

    - task: DownloadPipelineArtifact@2
    displayName: 'Download prebuilds'
    inputs:
    buildType: 'specific'
    project: 'Monaco'
    definition: '647'
    buildVersionToDownload: 'latestFromBranch'
    branchName: 'refs/heads/main'
    artifactName: 'prebuilds'
    targetPath: 'prebuilds'
    - script: npm ci
    displayName: 'Install dependencies and build'
    - script: npm test
    displayName: 'Test'
    - script: npm run lint
    displayName: 'Lint'

    Then it sounds like it would be possible to add a chmod +x step for spawn-helper there.

  8. Tyriar commented on Jan 4, 2026

    @Tyriar
    Contributor

    Simon Lydell (@lydell) thanks for the extra nudge, sounds like a good plan

  9. 20 remaining items

  10. BENZOOgataga commented on Aug 8, 2026

    @BENZOOgataga

    Reproduced on npm rather than pnpm. macOS 26.5.2, arm64, node-pty 1.1.0, from a clean npm ci. The published tarball itself carries mode 0644:

    tar -tvf node-pty-1.1.0.tgz
    -rw-r--r--  package/prebuilds/darwin-arm64/spawn-helper
    -rw-r--r--  package/prebuilds/darwin-x64/spawn-helper
    

    A plain tar -xzf outside any package manager gives the same, so the extractor is not the variable. 1.2.0-beta.15 ships both as 0755, so the fix exists but not on the stable line.

    Source builds are unaffected because loadNativeModule checks build/Release before prebuilds, and darwin prebuilds are new in 1.1.0, which is likely why this is not reported more widely.

    Worth adding for anyone packaging: asar preserves the mode through pack and unpack, so a 0644 helper in the tree at package time becomes a 0644 helper in the shipped .app, where posix_spawnp fails for every user and reproduces on no development machine that ran a fix locally.

  11. lydell commented on Aug 8, 2026

    @lydell
    Contributor

    BENZOOgataga (@BENZOOgataga) v1.1.0 is broken, this PR was shipped in v1.2.0-beta.2. There is unfortunately no release marked as “stable” with a fix in it. (But the beta isn't really a beta, it's stable, IMO.)

  12. BENZOOgataga commented on Aug 8, 2026

    @BENZOOgataga

    BENZOOgataga (@BENZOOgataga) v1.1.0 is broken, this PR was shipped in v1.2.0-beta.2. There is unfortunately no release marked as “stable” with a fix in it. (But the beta isn't really a beta, it's stable, IMO.)

    Oh alright thank you for your answer!

  13. added a commit that references this issue on Aug 31, 2026
    888f391
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

bugIssue identified by VS Code Team member as probable bugmacos

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions