Files
orca/config/scripts
Neil b0caa00bed fix(windows): stop shipping an unpatched conpty prebuild a cross-arch package can load
Two halves of one hole. node-pty's loader falls through
build/Release -> build/Debug -> prebuilds/<platform>-<arch>, and the published
prebuild has never carried the MSYS breakaway denial.

The prune only removed that prebuild when `electronArch === process.arch`. That
proxy stood in for "build/Release holds an addon the target can actually load",
but it is false for an arm64 slice cross-built on an x64 Windows host -- a
rebuild that DOES produce a correct arm64 addon. That slice shipped the
unpatched prebuild as a live fallback. Read the PE `Machine` field instead of
guessing (`conptyTargetsArch`, shaped after readElfMachine() in
verify-linux-glibc-floor.cjs).

Deleting it unconditionally was the other option and is wrong: in the true
cross-host case (packaging Windows from macOS) build/Release is not a Windows
binary at all, and removing the prebuild would leave the package with no
loadable ConPTY.

So the verifier closes the remainder. It treated "no build output" as "no addon
at all" and warned -- which is exactly the package whose sole loadable addon is
the unpatched prebuild. It now checks the prebuild the loader would fall
through to, and a present-but-unmarked binary there is fatal. Absence still
warns only when nothing else would load.

Together there is no hole: either the prebuild is pruned, or it is the sole
loadable addon and the verifier fails the release.

Latent today -- the patched build output wins the load order. The trigger is
someone packaging cross-arch.

Verified by mutation, not assumed: restoring the old `electronArch ===
process.arch` prune fails 2 rows in packaged-node-pty-prebuild-prune, and
disabling the verifier's prebuild fallback fails 2 rows in
verify-packaged-node-pty-job-ownership.
2026-09-11 01:26:14 -07:00
..
2026-05-15 05:44:25 -04:00