Is there an existing issue for this?
This issue exists in the latest npm version
This is not just a request to bump a dependency for a CVE
Current Behavior
Using Guix to to build taler-util, npm install crashes like the following:
[...]
npm verbose cli /gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/bin/node /gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/lib/node_modules/npm/bin/npm-cli.js
npm info using npm@11.19.1
npm info using node@v26.10.0
npm verbose title npm install
npm verbose argv "--loglevel" "verbose" "--offline" "--fetch-retries" "0" "--ignore-scripts" "--install-links" "--no-audit" "--prefix" "/tmp/guix-build-taler-util-1.6.5.drv-0/source/packages/taler-util" "install"
npm verbose logfile logs-max:10 dir:/tmp/guix-build-taler-util-1.6.5.drv-0/source/packages/npm-home-0/.npm/_logs/2026-09-24T05_24_04_331Z-
npm verbose logfile /tmp/guix-build-taler-util-1.6.5.drv-0/source/packages/npm-home-0/.npm/_logs/2026-09-24T05_24_04_331Z-debug-0.log
npm http fetch GET https://registry.npmjs.org/npm attempt 1 failed with EAI_AGAIN
npm verbose cwd /tmp/guix-build-taler-util-1.6.5.drv-0/source/packages/taler-util
npm verbose os Linux 7.1.8
npm verbose node v26.10.0
npm verbose npm v11.19.1
npm error Exit handler never called!
npm error This is an error with npm itself. Please report this error at:
npm error <https://github.com/npm/cli/issues>
npm verbose exit 1
npm verbose code 1
npm error A complete log of this run can be found in: /tmp/guix-build-taler-util-1.6.5.drv-0/source/packages/npm-home-0/.npm/_logs/2026-09-24T05_24_04_331Z-debug-0.log
error: in phase 'configure': uncaught exception:
%exception #<&invoke-error program: "/gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/bin/npm" arguments: ("--verbose" "--offline" "--fetch-retries=0" "--ignore-scripts" "--install-links" "--no-audit" "--prefix=/tmp/guix-build-taler-util-1.6.5.drv-0/source/packages/taler-util" "install") exit-status: 1 term-signal: #f stop-signal: #f>
phase `configure' failed after 2.5 seconds
command "/gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/bin/npm" "--verbose" "--offline" "--fetch-retries=0" "--ignore-scripts" "--install-links" "--no-audit" "--prefix=/tmp/guix-build-taler-util-1.6.5.drv-0/source/packages/taler-util" "install" failed with status 1
Despite the package.json dependencies being patched to be absolute file names, which npm appears to be satisfied with, npm tries to reach to the network, fails (this happens in a containerized, isolated environment) and crashes without a useful error.
Expected Behavior
A useful error should be produced instead of a crash asking me to file a bug.
Steps To Reproduce
I'm using these components:
node@26.10.0 node-big-integer@1.6.52 node-esbuild@0.28.2 node-fflate@0.8.3 node-follow-redirects@1.16.0 node-hash-wasm@4.12.0 node-jed@1.1.1 node-tslib@2.8.1 node-types-follow-redirects@22.14.0
+ node-types-node@22.14.0 node-typescript@6.0.3
I was not able to reproduce outside of the minimal Guix build container; at least it should be easy to reproduce with GNU Guix, which can run on top of any GNU/Linux distribution (to install, see: https://guix.gnu.org/manual/devel/en/guix.html#Binary-Installation-1, and use the guix-install.sh script).
guix time-machine -q --url=https://codeberg.org/guixotic/guix -commit=npm-crash-issue-10030-repro -- build -K taler-util
It should leave the failed build directory under /tmp/guix-build-taler-util-1.6.5.drv-0, which you can enter and try the same thing, this time outside the container.
cd /tmp/guix-build-taler-util-1.6.5.drv-0
. environment-variables
cd source/packages/taler-util
npm "--verbose" "--offline" "--fetch-retries=0" "--ignore-scripts" "--install-links" "--no-audit" "--prefix=/tmp/guix-build-taler-util-1.6.5.drv-0/source/packages/taler-util" "install"
npm verbose cli /gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/bin/node /gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/lib/node_modules/npm/bin/npm-cli.js
npm info using npm@11.19.1
npm info using node@v26.10.0
npm verbose title npm install
npm verbose argv "--loglevel" "verbose" "--offline" "--fetch-retries" "0" "--ignore-scripts" "--install-links" "--no-audit" "--prefix" "/tmp/guix-build-taler-util-1.6.5.drv-0/source/packages/taler-util" "install"
npm verbose logfile logs-max:10 dir:/tmp/guix-build-taler-util-1.6.5.drv-0/source/packages/npm-home-0/.npm/_logs/2026-09-24T08_47_32_149Z-
npm verbose logfile /tmp/guix-build-taler-util-1.6.5.drv-0/source/packages/npm-home-0/.npm/_logs/2026-09-24T08_47_32_149Z-debug-0.log
npm verbose stack Error: request to https://registry.npmjs.org/typescript failed: cache mode is 'only-if-cached' but no cached response is available.
npm verbose stack at cacheFetch (/gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/lib/node_modules/npm/node_modules/make-fetch-happen/lib/cache/index.js:12:13)
npm verbose stack at async fetch (/gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/lib/node_modules/npm/node_modules/make-fetch-happen/lib/fetch.js:98:7)
npm verbose stack at async RegistryFetcher.packument (/gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/lib/node_modules/npm/node_modules/pacote/lib/registry.js:90:19)
npm verbose stack at async RegistryFetcher.manifest (/gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/lib/node_modules/npm/node_modules/pacote/lib/registry.js:128:23)
npm verbose stack at async RegistryFetcher.resolve (/gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/lib/node_modules/npm/node_modules/pacote/lib/registry.js:55:5)
npm verbose stack at async #extractOrLink (/gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/lib/node_modules/npm/node_modules/@npmcli/arborist/lib/arborist/reify.js:775:7)
npm verbose stack at async /gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/lib/node_modules/npm/node_modules/@npmcli/arborist/lib/arborist/reify.js:699:7
npm verbose stack at async Promise.allSettled (index 0)
npm verbose stack at async #reifyPackages (/gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/lib/node_modules/npm/node_modules/@npmcli/arborist/lib/arborist/reify.js:353:11)
npm verbose stack at async Arborist.reify (/gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/lib/node_modules/npm/node_modules/@npmcli/arborist/lib/arborist/reify.js:139:7)
npm error code ENOTCACHED
npm error request to https://registry.npmjs.org/typescript failed: cache mode is 'only-if-cached' but no cached response is available.
npm verbose cwd /tmp/guix-build-taler-util-1.6.5.drv-0/source/packages/taler-util
npm verbose os Linux 7.1.8
npm verbose node v26.10.0
npm verbose npm v11.19.1
npm verbose exit 1
npm verbose code 1
npm error A complete log of this run can be found in: /tmp/guix-build-taler-util-1.6.5.drv-0/source/packages/npm-home-0/.npm/_logs/2026-09-24T08_47_32_149Z-debug-0.log
As you can see, it doesn't crash in this environment, so it looks like the minimal Guix build environment is key to trigger the crash.
I tried reproducing in a similar container via:
$ guix time-machine -q --url=https://codeberg.org/guixotic/guix -commit=npm-crash-issue-10030-repro -- shell --writable-root -CD taler-util
Which will leave you in a container, but it also won't reproduce.
Attached is the Guix build log;
node-26.10.0-crash-building-taler-util.log.txt
The npm log:
2026-09-24T06_00_55_521Z-debug-0.log
A strace of npm execution, strace -s800 -f [...]:
taler-util.strace.txt
Environment
- npm: 11.19.1
- Node.js: 26.10.0
- OS Name: Guix System
- System Model Name: x86_64
- npm config:
$ npm config ls
; node bin location = /gnu/store/m8k90i2k51xbmbprf3s9vga0g1p39rwq-node-26.10.0/bin/node
; node version = v26.10.0
; npm local prefix = /tmp/guix-build-taler-util-1.6.5.drv-0/source
; npm version = 11.19.1
; cwd = /tmp/guix-build-taler-util-1.6.5.drv-0/source
; HOME = /tmp/guix-build-taler-util-1.6.5.drv-0/source/packages/npm-home-0
; Run `npm config ls -l` to show all defaults.
Is there an existing issue for this?
This issue exists in the latest npm version
This is not just a request to bump a dependency for a CVE
Current Behavior
Using Guix to to build
taler-util,npm installcrashes like the following:Despite the
package.jsondependencies being patched to be absolute file names, which npm appears to be satisfied with, npm tries to reach to the network, fails (this happens in a containerized, isolated environment) and crashes without a useful error.Expected Behavior
A useful error should be produced instead of a crash asking me to file a bug.
Steps To Reproduce
I'm using these components:
I was not able to reproduce outside of the minimal Guix build container; at least it should be easy to reproduce with GNU Guix, which can run on top of any GNU/Linux distribution (to install, see: https://guix.gnu.org/manual/devel/en/guix.html#Binary-Installation-1, and use the
guix-install.shscript).It should leave the failed build directory under
/tmp/guix-build-taler-util-1.6.5.drv-0, which you can enter and try the same thing, this time outside the container.As you can see, it doesn't crash in this environment, so it looks like the minimal Guix build environment is key to trigger the crash.
I tried reproducing in a similar container via:
Which will leave you in a container, but it also won't reproduce.
Attached is the Guix build log;
node-26.10.0-crash-building-taler-util.log.txt
The npm log:
2026-09-24T06_00_55_521Z-debug-0.log
A strace of npm execution,
strace -s800 -f [...]:taler-util.strace.txt
Environment