Skip to content

Commit 8ca01c3

Browse files
authored
fix(npmRegistryUtils): env vars names in integrity check fail error message (#854)
When signature verification fails in fetchLatestStableVersion, the error tells users they can disable the check by setting COREPACK_INTEGRITY_CHECK=0 or fall back to the bundled latest release by setting COREPACK_USE_LATEST=0. Neither of those variables exists anywhere else in the codebase. The runtime actually reads COREPACK_INTEGRITY_KEYS (in shouldSkipIntegrityCheck) and COREPACK_DEFAULT_TO_LATEST (in corepackUtils.ts and Engine.ts), and both are the names documented in the README. So a user who hits the error and follows the suggestion sets two variables that have no effect, then keeps hitting the same wall. This patch rewords the error to name the variables the runtime actually checks. Behaviour of fetchLatestStableVersion is otherwise unchanged. Tests cover both axes: the failing path now mentions the real names and no longer mentions the phantom ones; and the happy path that sets COREPACK_INTEGRITY_KEYS=0 still skips verification and returns the resolved version (regression guard for the env-var name we now advertise). Fixes: #849 Signed-off-by: Yarchik <spoko.dev@gmail.com>
1 parent b81e92c commit 8ca01c3

2 files changed

Lines changed: 57 additions & 6 deletions

File tree

‎sources/npmRegistryUtils.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -83,7 +83,7 @@ export async function fetchLatestStableVersion(packageName: string) {
8383
});
8484
} catch (cause) {
8585
// TODO: consider switching to `UsageError` when https://github.com/arcanis/clipanion/issues/157 is fixed
86-
throw new Error(`Corepack cannot download the latest stable version of ${packageName}; you can disable signature verification by setting COREPACK_INTEGRITY_CHECK to 0 in your env, or instruct Corepack to use the latest stable release known by this version of Corepack by setting COREPACK_USE_LATEST to 0`, {cause});
86+
throw new Error(`Corepack cannot download the latest stable version of ${packageName}; you can disable signature verification by setting COREPACK_INTEGRITY_KEYS to 0 in your env, or instruct Corepack to use the latest stable release known by this version of Corepack by setting COREPACK_DEFAULT_TO_LATEST to 0`, {cause});
8787
}
8888
}
8989

‎tests/npmRegistryUtils.test.ts‎

Lines changed: 56 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
1-
import {Buffer} from 'node:buffer';
2-
import process from 'node:process';
3-
import {describe, beforeEach, it, expect, vi} from 'vitest';
1+
import {Buffer} from 'node:buffer';
2+
import process from 'node:process';
3+
import {describe, beforeEach, it, expect, vi} from 'vitest';
44

5-
import {fetchAsJson as httpFetchAsJson} from '../sources/httpUtils.ts';
6-
import {DEFAULT_HEADERS, DEFAULT_NPM_REGISTRY_URL, fetchAsJson} from '../sources/npmRegistryUtils.ts';
5+
import {fetchAsJson as httpFetchAsJson} from '../sources/httpUtils.ts';
6+
import {DEFAULT_HEADERS, DEFAULT_NPM_REGISTRY_URL, fetchAsJson, fetchLatestStableVersion} from '../sources/npmRegistryUtils.ts';
77

88
vi.mock(`../sources/httpUtils.ts`);
99

@@ -99,3 +99,54 @@ describe(`npm registry utils fetchAsJson`, () => {
9999
expect(httpFetchAsJson).lastCalledWith(`${DEFAULT_NPM_REGISTRY_URL}/package-name`, {headers: DEFAULT_HEADERS});
100100
});
101101
});
102+
103+
// https://github.com/nodejs/corepack/issues/849
104+
describe(`fetchLatestStableVersion`, () => {
105+
beforeEach(() => {
106+
vi.resetAllMocks();
107+
});
108+
109+
it(`raises an error pointing at the real env vars when integrity verification fails`, async () => {
110+
vi.mocked(httpFetchAsJson).mockResolvedValueOnce({
111+
version: `1.0.0`,
112+
dist: {
113+
integrity: `sha512-AAAA`,
114+
signatures: [],
115+
shasum: `abc`,
116+
},
117+
});
118+
119+
let caught: Error | undefined;
120+
try {
121+
await fetchLatestStableVersion(`some-package`);
122+
} catch (e) {
123+
caught = e as Error;
124+
}
125+
expect(caught).toBeInstanceOf(Error);
126+
// The error must steer users at the real env vars used by the runtime
127+
// - COREPACK_INTEGRITY_KEYS is read by shouldSkipIntegrityCheck()
128+
// - COREPACK_DEFAULT_TO_LATEST is read by the version-resolution path
129+
expect(caught!.message).toContain(`COREPACK_INTEGRITY_KEYS to 0`);
130+
expect(caught!.message).toContain(`COREPACK_DEFAULT_TO_LATEST to 0`);
131+
// Neither of these names exist anywhere else in the codebase, so the
132+
// error must not point users at them.
133+
expect(caught!.message).not.toContain(`COREPACK_INTEGRITY_CHECK`);
134+
expect(caught!.message).not.toContain(`COREPACK_USE_LATEST`);
135+
expect(caught!.message).toContain(`some-package`);
136+
});
137+
138+
it(`skips signature verification and returns when COREPACK_INTEGRITY_KEYS=0`, async () => {
139+
process.env.COREPACK_INTEGRITY_KEYS = `0`;
140+
vi.mocked(httpFetchAsJson).mockResolvedValueOnce({
141+
version: `2.3.4`,
142+
dist: {
143+
integrity: `sha512-BBBB`,
144+
signatures: [],
145+
shasum: `def`,
146+
},
147+
});
148+
149+
const out = await fetchLatestStableVersion(`some-package`);
150+
expect(out).toBe(`2.3.4+sha512.${Buffer.from(`BBBB`, `base64`).toString(`hex`)}`);
151+
});
152+
});

0 commit comments

Comments
 (0)