fix(pm): refresh dependencies with the installed project tools

The uv step used a nonexistent command. Both dependency steps used the
caller directory instead of the PM repository. Run uv lock --upgrade
and the installed npm executable in the correct project. Require the
installed tool closure without installing a fallback.

Reuse npm environment sanitization for unpack and update. The separately
pinned npm keeps its Node dependency on PATH without changing the parent.
Missing tools and failed commands return failure before venv sync.

Real uv and npm commands ran in guarded temporary projects. The test
removes Node's bundled npm before update and preserves unrelated files.
The missing-Python test checks the actual refusal and unchanged facts.
All 87 focused tests pass. Lint passes. No project pins or locks changed.
This commit is contained in:
ethernet
2026-09-10 03:50:40 -04:00
parent 11c65c4f33
commit b2be572937
4 changed files with 210 additions and 13 deletions

View File

@@ -556,6 +556,18 @@ class TermuxDocker(Package):
return ""
def npm_env(cache_dir: Path, base_env: Optional[dict] = None) -> dict[str, str]:
"""Keep ambient Node and npm options out of PM's child process."""
env = {
key: value
for key, value in (os.environ if base_env is None else base_env).items()
if not key.lower().startswith("npm_config_")
and key.upper() not in ("NODE_OPTIONS", "NODE_PATH", "NODE_ENV")
}
env["npm_config_cache"] = str(cache_dir)
return env
@register
class Npm(BinaryPackage):
name = "npm"
@@ -616,13 +628,7 @@ class Npm(BinaryPackage):
if not bundled_cli.is_file():
raise InstallError(self.name, "node's entry is missing its bundled npm-cli.js")
env = {
key: value
for key, value in os.environ.items()
if not key.lower().startswith("npm_config_")
and key not in ("NODE_OPTIONS", "NODE_PATH", "NODE_ENV")
}
env["npm_config_cache"] = str(archive.parent / ".npm-cache")
env = npm_env(archive.parent / ".npm-cache")
staged.mkdir(parents=True, exist_ok=True)
proc = subprocess.run(