Skip to content

fix(installer): accept well-formed Windows PATHEXT entries such as Python .PY and .PYW - #1983

Merged
Alan-TheGentleman merged 2 commits into
mainfrom
fix/1978-pathext-any-extension
Oct 9, 2026
Merged

Alan-TheGentleman merged 2 commits into
mainfrom
fix/1978-pathext-any-extension

Conversation

@Alan-TheGentleman

@Alan-TheGentleman Alan-TheGentleman commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Closes #1978

Summary

  • The Windows browser-installer bootstrap stopped with pathext (pnpm-discovery) whenever PATHEXT contained an extension outside a fixed list, for example Python's .PY and .PYW, even though cmd.exe resolves the existing pnpm fine.
  • The same failure class was already patched once for PowerShell's .CPL (5ed499ade). Extending the list again would only wait for the next runtime (.RB, .PL, …), so this fixes the class instead.
  • findWindowsCommand now accepts any well-formed extension (^\.[a-z0-9]+$) and still resolves in the inherited PATH-then-PATHEXT order. It still rejects duplicate, empty and malformed entries.

Why this keeps the guard safe

The list never decided what runs; it only decided which PATHEXT values we model. What runs is still gated after resolution:

  • the first match must be a .cmd npm shim whose exact content is proven, or the bootstrap fails closed with Unknown pnpm wrapper; refusing replacement;
  • the wrapper-selected Node must be an .exe;
  • the storage, ACL and CLI-proof checks are unchanged.

So a pnpm.py found before the genuine pnpm.cmd is resolved first and refused; it is never executed. This is the same rule the code comment already stated for .cpl.

Changes

File Change
scripts/installer-windows.mjs PATHEXT extensions validated by shape instead of a fixed allowlist; comment updated
tests/installer-windows-bootstrap.test.ts Python PATHEXT resolves pnpm (with and without .CPL); an earlier pnpm.py fails closed and is never run; duplicates/empty/malformed still rejected; the step-name test uses a still-invalid PATHEXT

Test plan

  • RED on main: the two new tests fail with Unknown Windows PATHEXT semantics, the exact error from the issue.
  • GREEN: node --experimental-strip-types --test tests/installer-windows-bootstrap.test.ts → 36 pass, 0 fail, 15 skipped (native-Windows lanes). tests/installer-probes.test.ts and tests/installer-runner.test.ts → 89/89.
  • Full tests/*.test.ts locally: the same 92 failures with and without this change, all from a worktree without node_modules; CI runs the complete suite.
  • Not run: a native Windows double-click reproduction. The fix is covered through the helper's public ensureWindowsPnpm interface.

Summary by CodeRabbit

  • Bug Fixes
    • Windows command discovery now recognizes unique PATHEXT extensions matching the supported format, including Python extensions, while rejecting empty, malformed, or duplicate entries.
    • Search order remains unchanged. If an earlier matching command uses an extension other than .cmd or .exe, discovery continues to fail closed without downloading or executing it.

…thon .PY and .PYW

Any well-formed extension resolves in its PATHEXT place; only a verified .cmd npm shim with an .exe Node is ever accepted, so an unlisted extension found first still fails closed. Closes #1978.
@Alan-TheGentleman Alan-TheGentleman added the type:bug Bug fix label Oct 9, 2026
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 93a45b0d-8486-4cd5-8a13-c5d481cb6cc7

📥 Commits

Reviewing files that changed from the base of the PR and between d3cf716 and 5e57a95.


📒 Files selected for processing (2)
  • scripts/installer-windows.mjs
  • tests/installer-windows-bootstrap.test.ts

Included review availability: This review used your included allowance. Your plan provides up to 4 included reviews per hour; 0 remain after this review.



📝 Walkthrough

Walkthrough

The Windows command resolver now accepts any unique PATHEXT extension matching .[a-z0-9]+. Tests cover Python extensions, duplicate and malformed entries, and rejection of an earlier Python wrapper.

Changes

Windows PATHEXT Resolution

Layer / File(s) Summary
PATHEXT validation and command discovery
scripts/installer-windows.mjs, tests/installer-windows-bootstrap.test.ts
findWindowsCommand accepts unique extensions matching .[a-z0-9]+ while retaining checks for empty, duplicate, or malformed entries. Tests cover .PY and .PYW, reject an earlier pnpm.py wrapper, and check duplicate extensions and invalid entries.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix · Severity of issue fixed: Medium

Suggested reviewers: dnlrsls


Merge Risk: ⚪ Minimal · up to 5e57a

The change broadens support for well-formed PATHEXT entries. No actionable merge risk is established here; proceed with normal checks.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check Passed The title clearly and concisely describes the main change: accepting well-formed Windows PATHEXT entries such as .PY and .PYW in the installer.
Linked Issues check Passed Issue #1978 requires the Windows bootstrap to accept Python .PY and .PYW entries in PATHEXT without changing the user environment. The implementation validates well-formed unique extensions and …
Out of Scope Changes check Passed The implementation changes only PATHEXT validation in scripts/installer-windows.mjs. The test changes directly cover the issue behavior and preserved safety checks. No unrelated changes are identifi…


  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR

🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Alan-TheGentleman
Alan-TheGentleman merged commit bac4890 into main Oct 9, 2026
14 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type:bug Bug fix

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug(installer): Windows bootstrap rejects Python PATHEXT entries before pnpm discovery

1 participant