Skip to content

npx-migration: link the staged bundle's bin so npx resolves the local override - #26

Merged
GraemeF merged 1 commit into
mainfrom
comms-hl7y
Jun 14, 2026
Merged

GraemeF merged 1 commit into
mainfrom
comms-hl7y

Conversation

@GraemeF

@GraemeF GraemeF commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

Problem

The frozen marketplace's .mcp.json launches npx -y @codeforbreakfast/commy-mcp with cwd = ${CLAUDE_PLUGIN_ROOT}, designed to resolve the bundle from a local node_modules override with zero registry hops. But npx resolves a package's bin, and stageMarketplace only copied the assembled package into node_modules/@codeforbreakfast/commy-mcp/ — it never created the node_modules/.bin/commy-mcp symlink that npm install makes, and left server.js non-executable.

Result: npx @codeforbreakfast/commy-mcp from the plugin dir falls through to a PATH lookup and dies with sh: commy-mcp: command not found, so a plugin installed from the local-override marketplace never boots its server. The published-package path was unaffected — a registry install links the bin itself; only the local-override path broke.

The boot smoke test missed it because verifyBoots launched node .../server.js directly, bypassing the bin resolution entirely.

Fix

  • stageMarketplace now recreates the .bin link (relative, so it survives atomicSwap renaming the staging dir into the fixed path) and marks the entry executable, mirroring what npm install does. Bin names follow npm's normalisation (string bin → unscoped package name).
  • verifyBoots now launches the staged bundle through its bin entry (node_modules/.bin/<name>, the exact file npx resolves and execs via its shebang), so the smoke test covers a missing/broken bin link or a non-executable entry as well as a bundle that fails to load.

Verification

Confirmed end-to-end through the real npx launcher against a freshly staged tree: npx resolves the local override (node .../node_modules/.bin/commy-mcp, no registry hop), boots under node, answers the MCP initialize handshake, and exits cleanly on stdin EOF (no orphaned process). The published registry path was independently confirmed working too.

… npx resolves the local override (comms-hl7y)

The frozen marketplace launches `npx -y @codeforbreakfast/commy-mcp` with
cwd=${CLAUDE_PLUGIN_ROOT}, and resolves the bundle from the local
node_modules override (zero registry hops). But npx resolves a package's
*bin*, and stageMarketplace only copied the assembled package — it never
created the node_modules/.bin/commy-mcp link an `npm install` makes, and
left server.js non-executable. So npx fell through to a PATH lookup and
died `commy-mcp: command not found`; a seat installed from the local
override never booted the server.

stageMarketplace now recreates that link (relative, so it survives the
atomic rename into the fixed path) and marks the entry executable,
mirroring an install. The published-package path was unaffected — a
registry install links the bin itself — only the local-override path
broke.

verifyBoots was blind to this: it launched `node .../server.js` directly,
bypassing the bin resolution. It now launches through the bin entry
(node_modules/.bin/<name>, the exact file npx execs via its shebang), so
the boot smoke test covers a missing/broken bin link or a non-executable
entry as well as a bundle that fails to load.
@GraemeF
GraemeF merged commit fa26618 into main Jun 14, 2026
2 checks passed
@GraemeF
GraemeF deleted the comms-hl7y branch June 14, 2026 16:45
GraemeF added a commit that referenced this pull request Jun 14, 2026
First release carrying the npx delivery migration (#21–#26): the MCP
server and PreToolUse hook now run on node, the plugin launches via `npx
@codeforbreakfast/commy-mcp`, and the publishable
`@codeforbreakfast/commy-mcp` npm package is assembled by `bun run
pack:npm`. This is the tag the github-source marketplace cutover
(comms-taa3) pins to.

**Patch bump** — npx is infrastructure; no new tool, userConfig key, or
env var.

Bumps the six version sites + `clients/hermes/uv.lock` in lockstep
(0.11.2 → 0.11.3):
- `clients/claude-code/.claude-plugin/plugin.json`
- `clients/claude-code/package.json`
- `packages/mcp/package.json`
- `packages/mcp/mcp-server.ts` (`PLUGIN_VERSION`)
- `clients/hermes/pyproject.toml`
- `clients/hermes/commy/plugin.yaml`
- `clients/hermes/uv.lock`
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant