Skip to content

ci: CITGM relies on native-build option forwarding rejected by npm 12 #10023

Description

@reggi

Summary

CITGM supplies --build-from-source to npm install for thread-sleep. npm 12 rejects that option with EUNKNOWNCONFIG before installation or testing. Both Node 22 and Node 23 failures share this cause.

This is a compatibility break in historical native-tool option forwarding, not evidence that source builds were removed from Node.js or that --build-from-source never worked.

Affected run

Branch: latest, commit c039090578a5b21a1aa3aba9c96e199feaf1823a, npm 12.1.0.

Workflow: https://github.com/npm/cli/actions/runs/35779328486

These are the workflow's displayed package versions; the downloaded source is selected separately from package metadata. The corresponding v11 integration jobs passed.

Failure

npm install --no-audit --no-fund --build-from-source
npm error code EUNKNOWNCONFIG
npm error Unknown cli flag:
npm error   - --build-from-source
npm error Run `npm help config` for supported options.

The CITGM lookup contains:

"install": ["install", "--build-from-source"]

npm/cli's matrix generator appends those arguments to npm install. The (flaky) label does not explain or excuse this deterministic configuration rejection.

Historical context: how this worked

--build-from-source is a documented node-pre-gyp option, not a Node.js runtime flag and not a source-build operation implemented by npm itself.

In mapbox/node-pre-gyp#58, the maintainer recommended npm install --build-from-source in 2014. That invocation worked through npm's permissive configuration forwarding:

  1. npm accepted the otherwise unknown CLI configuration key.
  2. npm exported npm_config_build_from_source=true to lifecycle scripts.
  3. A package's installer using node-pre-gyp read that environment variable.
  4. node-pre-gyp selected compilation instead of a prebuilt binary download.

npm 11 still accepts the CLI option with an unknown-config warning. npm 12 changed unknown CLI flags from warnings to errors in #9276, as documented in the npm 12.0.0 breaking changes.

The node-pre-gyp README still documents the option and the old npm invocation. Its option parser still reads npm_config_ environment variables, and its installer still honors build-from-source or build_from_source. The tool capability remains; the npm CLI transport is what now rejects this invocation.

Proposed resolution

Inspect the exact thread-sleep source and installer selected by CITGM before choosing a replacement. Do not assume that its current source still needs this legacy flag merely because other native packages use it.

If forcing compilation is still required, use the actual installer's supported configuration mechanism rather than passing an unknown flag to npm. For node-pre-gyp, the existing environment-variable mechanism avoids this particular npm CLI rejection, but support must be verified for the tool and version used by the fixture. node-gyp and node-pre-gyp are different tools and must not be treated as having interchangeable configuration.

If the selected source no longer has a native build path, retire the stale metadata instead. Preserve genuine source-build coverage where applicable. npm 12's separate lifecycle-script approval policy must also be handled; successful argument parsing alone does not prove a native build happened.

Acceptance criteria

  • The CITGM invocation no longer supplies an unknown npm CLI flag.
  • The selected fixture's actual installer and source-build requirement are documented.
  • Where a native build is required, the job demonstrates that it ran rather than silently skipping scripts or using a prebuilt binary.
  • The relevant jobs pass on supported npm 12 runtimes and remain compatible with v11.
  • The fix reaches the CITGM metadata consumed by npm/cli, or the npm/cli workflow and its source template as appropriate.

Scope boundary

This also fails on supported Node 22, so it is independent of the Node 23 engine mismatch. It is separate from Git-dependency policy failures, #10016, and #10020.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions