module: add a read-only mode to the compile cache - #65302

Merged
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only
Aug 23, 2026
Merged

module: add a read-only mode to the compile cache#65302
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only

Conversation

@codebytere

Copy link
Copy Markdown
Member

A compile cache generated ahead of time and shipped inside an application package should only ever be read: the package may be immutable (an Electron app.asar, a read-only image) or covered by an integrity check, and a cache directory that appears at run time next to shipped code is a surprise either way. Today enabling the cache always implies writing: the tag directory is created on enable, and every module without an accepted entry is serialized and persisted at exit or on flushCompileCache().

This adds readOnly to module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1. With it, existing entries are looked up and loaded exactly as before; nothing is serialized into the in-memory store or written to disk, flushCompileCache() is a no-op, the write-permission check is skipped, and the cache directory is used as found rather than created, so enabling against a directory that does not exist fails (FAILED, with a message) instead of making one.

EnableOption becomes a small flag set (PORTABLE, READ_ONLY) since the two combine. Docs cover the option, the environment variable (cli.md, node.1) and a short section in module.md; test-compile-cache-api-readonly covers the missing-directory case, reading a previously generated cache without writing new entries, and the environment variable.

Context: same application as #65293 (an Electron app shipping its main-process cache in the package); review there asked that production launches never attempt writes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/loaders

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 15, 2026
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from 447fb62 to 133e37bCompareAugust 15, 2026 09:09
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from d57ec48 to dc597d8CompareAugust 16, 2026 18:31
@codebyterecodebytere added request-ci Add this label to start a Jenkins CI on a PR. and removed needs-ci PRs that need a full CI run. labels Aug 16, 2026
@codecov

codecovBot commented Aug 16, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.10448% with 14 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.13%. Comparing base (bc813a7) to head (f201d83).
⚠️ Report is 142 commits behind head on main.

Files with missing linesPatch %Lines
src/compile_cache.cc75.60%5 Missing and 5 partials ⚠️
src/env.cc50.00%1 Missing and 3 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65302 +/- ##
==========================================
- Coverage 90.32% 90.13% -0.19% 
==========================================
Files 751 751 Lines 249960 252344 +2384 Branches 47204 47452 +248 ==========================================
+ Hits 225774 227448 +1674 - Misses 15564 16193 +629 - Partials 8622 8703 +81 
Files with missing linesCoverage Δ
lib/internal/modules/helpers.js98.94% <100.00%> (+<0.01%)⬆️
src/compile_cache.h100.00% <100.00%> (ø)
src/node_modules.cc80.22% <100.00%> (-0.01%)⬇️
src/env.cc85.24% <50.00%> (-0.18%)⬇️
src/compile_cache.cc79.94% <75.60%> (+0.85%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 18, 2026
@nodejs-github-botnodejs-github-bot added commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. and removed commit-queue PRs queued for automated landing through the Commit Queue. labels Aug 18, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator
Commit Queue failed
- Loading data for nodejs/node/pull/65302
✔ Done loading data for nodejs/node/pull/65302
----------------------------------- PR info ------------------------------------
Title module: add a read-only mode to the compile cache (#65302)
Author Shelley Vohr <shelley.vohr@gmail.com> (@codebytere)
Branch codebytere:compile-cache-read-only -> nodejs:main
Labels c++, lib / src, commit-queue
Commits 1
- module: add a read-only mode to the compile cache
Committers 1
- Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
------------------------------ Generated metadata ------------------------------
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
--------------------------------------------------------------------------------
ℹ This PR was created on Sat, 15 Aug 2026 08:56:32 GMT
✔ Approvals: 1
✔ - James M Snell (@jasnell) (TSC): https://github.com/nodejs/node/pull/65302#pullrequestreview-4948260342
✘ This PR needs to wait 91 more hours to land (or 0 minutes if there is one more approval)
✔ Last GitHub CI successful
ℹ Last Full PR CI on 2026-08-17T03:52:44Z: https://ci.nodejs.org/job/node-test-pull-request/75904/
- Querying data for job/node-test-pull-request/75904/
✔ Build data downloaded
- Querying failures of job/node-test-commit/90633/
✔ Data downloaded
✘ 1 failure(s) on the last Jenkins CI run
--------------------------------------------------------------------------------
✔ Aborted `git node land` session in /home/runner/work/node/node/.ncu
https://github.com/nodejs/node/actions/runs/32149688331

@codebyterecodebytere removed the commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. label Aug 20, 2026
@codebytere

Copy link
Copy Markdown
MemberAuthor

@aduh95 PTAL when you have a moment!

Comment threaddoc/api/module.md Outdated
Comment threadsrc/compile_cache.cc
Comment on lines +594 to +599
if (!is_dir) {
result.message =
"Cache directory does not exist (read-only): " + cache_dir_with_tag;
result.status = CompileCacheEnableStatus::FAILED;
return result;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should this emit a warning?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i don't think so, for consistency: none of the other FAILED paths here (can't create the directory, not writable) warn either. through module.enableCompileCache() the caller gets { status, message } back and can decide what to do with it, and for NODE_COMPILE_CACHE the existing behavior is an inherited env var never adds output to a program that didn't ask for the cache; NODE_DEBUG_NATIVE=COMPILE_CACHE prints it. happy to add one if you feel strongly, but i'd rather do it for all the FAILED cases at once in a follow-up than special-case read-only.

A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
@codebytere
codebytereforce-pushed the compile-cache-read-only branch from dc597d8 to f201d83CompareAugust 21, 2026 18:17
@codebyterecodebytere added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 21, 2026
@Renegade334Renegade334 added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 21, 2026
@codebyterecodebytere removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 22, 2026
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
@nodejs-github-bot
nodejs-github-bot merged commit 65f518c into nodejs:mainAug 23, 2026
76 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in 65f518c

@nodejs-github-botnodejs-github-bot removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@codebytere@nodejs-github-bot@jasnell@Renegade334
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

module: add a read-only mode to the compile cache - #65302

Merged
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only
Aug 23, 2026
Merged

module: add a read-only mode to the compile cache#65302
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only

Conversation

@codebytere

Copy link
Copy Markdown
Member

A compile cache generated ahead of time and shipped inside an application package should only ever be read: the package may be immutable (an Electron app.asar, a read-only image) or covered by an integrity check, and a cache directory that appears at run time next to shipped code is a surprise either way. Today enabling the cache always implies writing: the tag directory is created on enable, and every module without an accepted entry is serialized and persisted at exit or on flushCompileCache().

This adds readOnly to module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1. With it, existing entries are looked up and loaded exactly as before; nothing is serialized into the in-memory store or written to disk, flushCompileCache() is a no-op, the write-permission check is skipped, and the cache directory is used as found rather than created, so enabling against a directory that does not exist fails (FAILED, with a message) instead of making one.

EnableOption becomes a small flag set (PORTABLE, READ_ONLY) since the two combine. Docs cover the option, the environment variable (cli.md, node.1) and a short section in module.md; test-compile-cache-api-readonly covers the missing-directory case, reading a previously generated cache without writing new entries, and the environment variable.

Context: same application as #65293 (an Electron app shipping its main-process cache in the package); review there asked that production launches never attempt writes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/loaders

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 15, 2026
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from 447fb62 to 133e37bCompareAugust 15, 2026 09:09
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from d57ec48 to dc597d8CompareAugust 16, 2026 18:31
@codebyterecodebytere added request-ci Add this label to start a Jenkins CI on a PR. and removed needs-ci PRs that need a full CI run. labels Aug 16, 2026
@codecov

codecovBot commented Aug 16, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.10448% with 14 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.13%. Comparing base (bc813a7) to head (f201d83).
⚠️ Report is 142 commits behind head on main.

Files with missing linesPatch %Lines
src/compile_cache.cc75.60%5 Missing and 5 partials ⚠️
src/env.cc50.00%1 Missing and 3 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65302 +/- ##
==========================================
- Coverage 90.32% 90.13% -0.19% 
==========================================
Files 751 751 Lines 249960 252344 +2384 Branches 47204 47452 +248 ==========================================
+ Hits 225774 227448 +1674 - Misses 15564 16193 +629 - Partials 8622 8703 +81 
Files with missing linesCoverage Δ
lib/internal/modules/helpers.js98.94% <100.00%> (+<0.01%)⬆️
src/compile_cache.h100.00% <100.00%> (ø)
src/node_modules.cc80.22% <100.00%> (-0.01%)⬇️
src/env.cc85.24% <50.00%> (-0.18%)⬇️
src/compile_cache.cc79.94% <75.60%> (+0.85%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 18, 2026
@nodejs-github-botnodejs-github-bot added commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. and removed commit-queue PRs queued for automated landing through the Commit Queue. labels Aug 18, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator
Commit Queue failed
- Loading data for nodejs/node/pull/65302
✔ Done loading data for nodejs/node/pull/65302
----------------------------------- PR info ------------------------------------
Title module: add a read-only mode to the compile cache (#65302)
Author Shelley Vohr <shelley.vohr@gmail.com> (@codebytere)
Branch codebytere:compile-cache-read-only -> nodejs:main
Labels c++, lib / src, commit-queue
Commits 1
- module: add a read-only mode to the compile cache
Committers 1
- Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
------------------------------ Generated metadata ------------------------------
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
--------------------------------------------------------------------------------
ℹ This PR was created on Sat, 15 Aug 2026 08:56:32 GMT
✔ Approvals: 1
✔ - James M Snell (@jasnell) (TSC): https://github.com/nodejs/node/pull/65302#pullrequestreview-4948260342
✘ This PR needs to wait 91 more hours to land (or 0 minutes if there is one more approval)
✔ Last GitHub CI successful
ℹ Last Full PR CI on 2026-08-17T03:52:44Z: https://ci.nodejs.org/job/node-test-pull-request/75904/
- Querying data for job/node-test-pull-request/75904/
✔ Build data downloaded
- Querying failures of job/node-test-commit/90633/
✔ Data downloaded
✘ 1 failure(s) on the last Jenkins CI run
--------------------------------------------------------------------------------
✔ Aborted `git node land` session in /home/runner/work/node/node/.ncu
https://github.com/nodejs/node/actions/runs/32149688331

@codebyterecodebytere removed the commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. label Aug 20, 2026
@codebytere

Copy link
Copy Markdown
MemberAuthor

@aduh95 PTAL when you have a moment!

Comment threaddoc/api/module.md Outdated
Comment threadsrc/compile_cache.cc
Comment on lines +594 to +599
if (!is_dir) {
result.message =
"Cache directory does not exist (read-only): " + cache_dir_with_tag;
result.status = CompileCacheEnableStatus::FAILED;
return result;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should this emit a warning?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i don't think so, for consistency: none of the other FAILED paths here (can't create the directory, not writable) warn either. through module.enableCompileCache() the caller gets { status, message } back and can decide what to do with it, and for NODE_COMPILE_CACHE the existing behavior is an inherited env var never adds output to a program that didn't ask for the cache; NODE_DEBUG_NATIVE=COMPILE_CACHE prints it. happy to add one if you feel strongly, but i'd rather do it for all the FAILED cases at once in a follow-up than special-case read-only.

A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
@codebytere
codebytereforce-pushed the compile-cache-read-only branch from dc597d8 to f201d83CompareAugust 21, 2026 18:17
@codebyterecodebytere added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 21, 2026
@Renegade334Renegade334 added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 21, 2026
@codebyterecodebytere removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 22, 2026
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
@nodejs-github-bot
nodejs-github-bot merged commit 65f518c into nodejs:mainAug 23, 2026
76 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in 65f518c

@nodejs-github-botnodejs-github-bot removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@codebytere@nodejs-github-bot@jasnell@Renegade334
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

module: add a read-only mode to the compile cache - #65302

Merged
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only
Aug 23, 2026
Merged

module: add a read-only mode to the compile cache#65302
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only

Conversation

@codebytere

Copy link
Copy Markdown
Member

A compile cache generated ahead of time and shipped inside an application package should only ever be read: the package may be immutable (an Electron app.asar, a read-only image) or covered by an integrity check, and a cache directory that appears at run time next to shipped code is a surprise either way. Today enabling the cache always implies writing: the tag directory is created on enable, and every module without an accepted entry is serialized and persisted at exit or on flushCompileCache().

This adds readOnly to module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1. With it, existing entries are looked up and loaded exactly as before; nothing is serialized into the in-memory store or written to disk, flushCompileCache() is a no-op, the write-permission check is skipped, and the cache directory is used as found rather than created, so enabling against a directory that does not exist fails (FAILED, with a message) instead of making one.

EnableOption becomes a small flag set (PORTABLE, READ_ONLY) since the two combine. Docs cover the option, the environment variable (cli.md, node.1) and a short section in module.md; test-compile-cache-api-readonly covers the missing-directory case, reading a previously generated cache without writing new entries, and the environment variable.

Context: same application as #65293 (an Electron app shipping its main-process cache in the package); review there asked that production launches never attempt writes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/loaders

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 15, 2026
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from 447fb62 to 133e37bCompareAugust 15, 2026 09:09
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from d57ec48 to dc597d8CompareAugust 16, 2026 18:31
@codebyterecodebytere added request-ci Add this label to start a Jenkins CI on a PR. and removed needs-ci PRs that need a full CI run. labels Aug 16, 2026
@codecov

codecovBot commented Aug 16, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.10448% with 14 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.13%. Comparing base (bc813a7) to head (f201d83).
⚠️ Report is 142 commits behind head on main.

Files with missing linesPatch %Lines
src/compile_cache.cc75.60%5 Missing and 5 partials ⚠️
src/env.cc50.00%1 Missing and 3 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65302 +/- ##
==========================================
- Coverage 90.32% 90.13% -0.19% 
==========================================
Files 751 751 Lines 249960 252344 +2384 Branches 47204 47452 +248 ==========================================
+ Hits 225774 227448 +1674 - Misses 15564 16193 +629 - Partials 8622 8703 +81 
Files with missing linesCoverage Δ
lib/internal/modules/helpers.js98.94% <100.00%> (+<0.01%)⬆️
src/compile_cache.h100.00% <100.00%> (ø)
src/node_modules.cc80.22% <100.00%> (-0.01%)⬇️
src/env.cc85.24% <50.00%> (-0.18%)⬇️
src/compile_cache.cc79.94% <75.60%> (+0.85%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 18, 2026
@nodejs-github-botnodejs-github-bot added commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. and removed commit-queue PRs queued for automated landing through the Commit Queue. labels Aug 18, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator
Commit Queue failed
- Loading data for nodejs/node/pull/65302
✔ Done loading data for nodejs/node/pull/65302
----------------------------------- PR info ------------------------------------
Title module: add a read-only mode to the compile cache (#65302)
Author Shelley Vohr <shelley.vohr@gmail.com> (@codebytere)
Branch codebytere:compile-cache-read-only -> nodejs:main
Labels c++, lib / src, commit-queue
Commits 1
- module: add a read-only mode to the compile cache
Committers 1
- Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
------------------------------ Generated metadata ------------------------------
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
--------------------------------------------------------------------------------
ℹ This PR was created on Sat, 15 Aug 2026 08:56:32 GMT
✔ Approvals: 1
✔ - James M Snell (@jasnell) (TSC): https://github.com/nodejs/node/pull/65302#pullrequestreview-4948260342
✘ This PR needs to wait 91 more hours to land (or 0 minutes if there is one more approval)
✔ Last GitHub CI successful
ℹ Last Full PR CI on 2026-08-17T03:52:44Z: https://ci.nodejs.org/job/node-test-pull-request/75904/
- Querying data for job/node-test-pull-request/75904/
✔ Build data downloaded
- Querying failures of job/node-test-commit/90633/
✔ Data downloaded
✘ 1 failure(s) on the last Jenkins CI run
--------------------------------------------------------------------------------
✔ Aborted `git node land` session in /home/runner/work/node/node/.ncu
https://github.com/nodejs/node/actions/runs/32149688331

@codebyterecodebytere removed the commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. label Aug 20, 2026
@codebytere

Copy link
Copy Markdown
MemberAuthor

@aduh95 PTAL when you have a moment!

Comment threaddoc/api/module.md Outdated
Comment threadsrc/compile_cache.cc
Comment on lines +594 to +599
if (!is_dir) {
result.message =
"Cache directory does not exist (read-only): " + cache_dir_with_tag;
result.status = CompileCacheEnableStatus::FAILED;
return result;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should this emit a warning?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i don't think so, for consistency: none of the other FAILED paths here (can't create the directory, not writable) warn either. through module.enableCompileCache() the caller gets { status, message } back and can decide what to do with it, and for NODE_COMPILE_CACHE the existing behavior is an inherited env var never adds output to a program that didn't ask for the cache; NODE_DEBUG_NATIVE=COMPILE_CACHE prints it. happy to add one if you feel strongly, but i'd rather do it for all the FAILED cases at once in a follow-up than special-case read-only.

A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
@codebytere
codebytereforce-pushed the compile-cache-read-only branch from dc597d8 to f201d83CompareAugust 21, 2026 18:17
@codebyterecodebytere added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 21, 2026
@Renegade334Renegade334 added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 21, 2026
@codebyterecodebytere removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 22, 2026
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
@nodejs-github-bot
nodejs-github-bot merged commit 65f518c into nodejs:mainAug 23, 2026
76 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in 65f518c

@nodejs-github-botnodejs-github-bot removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@codebytere@nodejs-github-bot@jasnell@Renegade334
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

module: add a read-only mode to the compile cache - #65302

Merged
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only
Aug 23, 2026
Merged

module: add a read-only mode to the compile cache#65302
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only

Conversation

@codebytere

Copy link
Copy Markdown
Member

A compile cache generated ahead of time and shipped inside an application package should only ever be read: the package may be immutable (an Electron app.asar, a read-only image) or covered by an integrity check, and a cache directory that appears at run time next to shipped code is a surprise either way. Today enabling the cache always implies writing: the tag directory is created on enable, and every module without an accepted entry is serialized and persisted at exit or on flushCompileCache().

This adds readOnly to module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1. With it, existing entries are looked up and loaded exactly as before; nothing is serialized into the in-memory store or written to disk, flushCompileCache() is a no-op, the write-permission check is skipped, and the cache directory is used as found rather than created, so enabling against a directory that does not exist fails (FAILED, with a message) instead of making one.

EnableOption becomes a small flag set (PORTABLE, READ_ONLY) since the two combine. Docs cover the option, the environment variable (cli.md, node.1) and a short section in module.md; test-compile-cache-api-readonly covers the missing-directory case, reading a previously generated cache without writing new entries, and the environment variable.

Context: same application as #65293 (an Electron app shipping its main-process cache in the package); review there asked that production launches never attempt writes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/loaders

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 15, 2026
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from 447fb62 to 133e37bCompareAugust 15, 2026 09:09
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from d57ec48 to dc597d8CompareAugust 16, 2026 18:31
@codebyterecodebytere added request-ci Add this label to start a Jenkins CI on a PR. and removed needs-ci PRs that need a full CI run. labels Aug 16, 2026
@codecov

codecovBot commented Aug 16, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.10448% with 14 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.13%. Comparing base (bc813a7) to head (f201d83).
⚠️ Report is 142 commits behind head on main.

Files with missing linesPatch %Lines
src/compile_cache.cc75.60%5 Missing and 5 partials ⚠️
src/env.cc50.00%1 Missing and 3 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65302 +/- ##
==========================================
- Coverage 90.32% 90.13% -0.19% 
==========================================
Files 751 751 Lines 249960 252344 +2384 Branches 47204 47452 +248 ==========================================
+ Hits 225774 227448 +1674 - Misses 15564 16193 +629 - Partials 8622 8703 +81 
Files with missing linesCoverage Δ
lib/internal/modules/helpers.js98.94% <100.00%> (+<0.01%)⬆️
src/compile_cache.h100.00% <100.00%> (ø)
src/node_modules.cc80.22% <100.00%> (-0.01%)⬇️
src/env.cc85.24% <50.00%> (-0.18%)⬇️
src/compile_cache.cc79.94% <75.60%> (+0.85%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 18, 2026
@nodejs-github-botnodejs-github-bot added commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. and removed commit-queue PRs queued for automated landing through the Commit Queue. labels Aug 18, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator
Commit Queue failed
- Loading data for nodejs/node/pull/65302
✔ Done loading data for nodejs/node/pull/65302
----------------------------------- PR info ------------------------------------
Title module: add a read-only mode to the compile cache (#65302)
Author Shelley Vohr <shelley.vohr@gmail.com> (@codebytere)
Branch codebytere:compile-cache-read-only -> nodejs:main
Labels c++, lib / src, commit-queue
Commits 1
- module: add a read-only mode to the compile cache
Committers 1
- Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
------------------------------ Generated metadata ------------------------------
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
--------------------------------------------------------------------------------
ℹ This PR was created on Sat, 15 Aug 2026 08:56:32 GMT
✔ Approvals: 1
✔ - James M Snell (@jasnell) (TSC): https://github.com/nodejs/node/pull/65302#pullrequestreview-4948260342
✘ This PR needs to wait 91 more hours to land (or 0 minutes if there is one more approval)
✔ Last GitHub CI successful
ℹ Last Full PR CI on 2026-08-17T03:52:44Z: https://ci.nodejs.org/job/node-test-pull-request/75904/
- Querying data for job/node-test-pull-request/75904/
✔ Build data downloaded
- Querying failures of job/node-test-commit/90633/
✔ Data downloaded
✘ 1 failure(s) on the last Jenkins CI run
--------------------------------------------------------------------------------
✔ Aborted `git node land` session in /home/runner/work/node/node/.ncu
https://github.com/nodejs/node/actions/runs/32149688331

@codebyterecodebytere removed the commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. label Aug 20, 2026
@codebytere

Copy link
Copy Markdown
MemberAuthor

@aduh95 PTAL when you have a moment!

Comment threaddoc/api/module.md Outdated
Comment threadsrc/compile_cache.cc
Comment on lines +594 to +599
if (!is_dir) {
result.message =
"Cache directory does not exist (read-only): " + cache_dir_with_tag;
result.status = CompileCacheEnableStatus::FAILED;
return result;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should this emit a warning?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i don't think so, for consistency: none of the other FAILED paths here (can't create the directory, not writable) warn either. through module.enableCompileCache() the caller gets { status, message } back and can decide what to do with it, and for NODE_COMPILE_CACHE the existing behavior is an inherited env var never adds output to a program that didn't ask for the cache; NODE_DEBUG_NATIVE=COMPILE_CACHE prints it. happy to add one if you feel strongly, but i'd rather do it for all the FAILED cases at once in a follow-up than special-case read-only.

A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
@codebytere
codebytereforce-pushed the compile-cache-read-only branch from dc597d8 to f201d83CompareAugust 21, 2026 18:17
@codebyterecodebytere added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 21, 2026
@Renegade334Renegade334 added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 21, 2026
@codebyterecodebytere removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 22, 2026
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
@nodejs-github-bot
nodejs-github-bot merged commit 65f518c into nodejs:mainAug 23, 2026
76 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in 65f518c

@nodejs-github-botnodejs-github-bot removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@codebytere@nodejs-github-bot@jasnell@Renegade334
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

module: add a read-only mode to the compile cache - #65302

Merged
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only
Aug 23, 2026
Merged

module: add a read-only mode to the compile cache#65302
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only

Conversation

@codebytere

Copy link
Copy Markdown
Member

A compile cache generated ahead of time and shipped inside an application package should only ever be read: the package may be immutable (an Electron app.asar, a read-only image) or covered by an integrity check, and a cache directory that appears at run time next to shipped code is a surprise either way. Today enabling the cache always implies writing: the tag directory is created on enable, and every module without an accepted entry is serialized and persisted at exit or on flushCompileCache().

This adds readOnly to module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1. With it, existing entries are looked up and loaded exactly as before; nothing is serialized into the in-memory store or written to disk, flushCompileCache() is a no-op, the write-permission check is skipped, and the cache directory is used as found rather than created, so enabling against a directory that does not exist fails (FAILED, with a message) instead of making one.

EnableOption becomes a small flag set (PORTABLE, READ_ONLY) since the two combine. Docs cover the option, the environment variable (cli.md, node.1) and a short section in module.md; test-compile-cache-api-readonly covers the missing-directory case, reading a previously generated cache without writing new entries, and the environment variable.

Context: same application as #65293 (an Electron app shipping its main-process cache in the package); review there asked that production launches never attempt writes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/loaders

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 15, 2026
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from 447fb62 to 133e37bCompareAugust 15, 2026 09:09
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from d57ec48 to dc597d8CompareAugust 16, 2026 18:31
@codebyterecodebytere added request-ci Add this label to start a Jenkins CI on a PR. and removed needs-ci PRs that need a full CI run. labels Aug 16, 2026
@codecov

codecovBot commented Aug 16, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.10448% with 14 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.13%. Comparing base (bc813a7) to head (f201d83).
⚠️ Report is 142 commits behind head on main.

Files with missing linesPatch %Lines
src/compile_cache.cc75.60%5 Missing and 5 partials ⚠️
src/env.cc50.00%1 Missing and 3 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65302 +/- ##
==========================================
- Coverage 90.32% 90.13% -0.19% 
==========================================
Files 751 751 Lines 249960 252344 +2384 Branches 47204 47452 +248 ==========================================
+ Hits 225774 227448 +1674 - Misses 15564 16193 +629 - Partials 8622 8703 +81 
Files with missing linesCoverage Δ
lib/internal/modules/helpers.js98.94% <100.00%> (+<0.01%)⬆️
src/compile_cache.h100.00% <100.00%> (ø)
src/node_modules.cc80.22% <100.00%> (-0.01%)⬇️
src/env.cc85.24% <50.00%> (-0.18%)⬇️
src/compile_cache.cc79.94% <75.60%> (+0.85%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 18, 2026
@nodejs-github-botnodejs-github-bot added commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. and removed commit-queue PRs queued for automated landing through the Commit Queue. labels Aug 18, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator
Commit Queue failed
- Loading data for nodejs/node/pull/65302
✔ Done loading data for nodejs/node/pull/65302
----------------------------------- PR info ------------------------------------
Title module: add a read-only mode to the compile cache (#65302)
Author Shelley Vohr <shelley.vohr@gmail.com> (@codebytere)
Branch codebytere:compile-cache-read-only -> nodejs:main
Labels c++, lib / src, commit-queue
Commits 1
- module: add a read-only mode to the compile cache
Committers 1
- Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
------------------------------ Generated metadata ------------------------------
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
--------------------------------------------------------------------------------
ℹ This PR was created on Sat, 15 Aug 2026 08:56:32 GMT
✔ Approvals: 1
✔ - James M Snell (@jasnell) (TSC): https://github.com/nodejs/node/pull/65302#pullrequestreview-4948260342
✘ This PR needs to wait 91 more hours to land (or 0 minutes if there is one more approval)
✔ Last GitHub CI successful
ℹ Last Full PR CI on 2026-08-17T03:52:44Z: https://ci.nodejs.org/job/node-test-pull-request/75904/
- Querying data for job/node-test-pull-request/75904/
✔ Build data downloaded
- Querying failures of job/node-test-commit/90633/
✔ Data downloaded
✘ 1 failure(s) on the last Jenkins CI run
--------------------------------------------------------------------------------
✔ Aborted `git node land` session in /home/runner/work/node/node/.ncu
https://github.com/nodejs/node/actions/runs/32149688331

@codebyterecodebytere removed the commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. label Aug 20, 2026
@codebytere

Copy link
Copy Markdown
MemberAuthor

@aduh95 PTAL when you have a moment!

Comment threaddoc/api/module.md Outdated
Comment threadsrc/compile_cache.cc
Comment on lines +594 to +599
if (!is_dir) {
result.message =
"Cache directory does not exist (read-only): " + cache_dir_with_tag;
result.status = CompileCacheEnableStatus::FAILED;
return result;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should this emit a warning?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i don't think so, for consistency: none of the other FAILED paths here (can't create the directory, not writable) warn either. through module.enableCompileCache() the caller gets { status, message } back and can decide what to do with it, and for NODE_COMPILE_CACHE the existing behavior is an inherited env var never adds output to a program that didn't ask for the cache; NODE_DEBUG_NATIVE=COMPILE_CACHE prints it. happy to add one if you feel strongly, but i'd rather do it for all the FAILED cases at once in a follow-up than special-case read-only.

A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
@codebytere
codebytereforce-pushed the compile-cache-read-only branch from dc597d8 to f201d83CompareAugust 21, 2026 18:17
@codebyterecodebytere added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 21, 2026
@Renegade334Renegade334 added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 21, 2026
@codebyterecodebytere removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 22, 2026
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
@nodejs-github-bot
nodejs-github-bot merged commit 65f518c into nodejs:mainAug 23, 2026
76 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in 65f518c

@nodejs-github-botnodejs-github-bot removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@codebytere@nodejs-github-bot@jasnell@Renegade334
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

module: add a read-only mode to the compile cache - #65302

Merged
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only
Aug 23, 2026
Merged

module: add a read-only mode to the compile cache#65302
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only

Conversation

@codebytere

Copy link
Copy Markdown
Member

A compile cache generated ahead of time and shipped inside an application package should only ever be read: the package may be immutable (an Electron app.asar, a read-only image) or covered by an integrity check, and a cache directory that appears at run time next to shipped code is a surprise either way. Today enabling the cache always implies writing: the tag directory is created on enable, and every module without an accepted entry is serialized and persisted at exit or on flushCompileCache().

This adds readOnly to module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1. With it, existing entries are looked up and loaded exactly as before; nothing is serialized into the in-memory store or written to disk, flushCompileCache() is a no-op, the write-permission check is skipped, and the cache directory is used as found rather than created, so enabling against a directory that does not exist fails (FAILED, with a message) instead of making one.

EnableOption becomes a small flag set (PORTABLE, READ_ONLY) since the two combine. Docs cover the option, the environment variable (cli.md, node.1) and a short section in module.md; test-compile-cache-api-readonly covers the missing-directory case, reading a previously generated cache without writing new entries, and the environment variable.

Context: same application as #65293 (an Electron app shipping its main-process cache in the package); review there asked that production launches never attempt writes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/loaders

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 15, 2026
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from 447fb62 to 133e37bCompareAugust 15, 2026 09:09
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from d57ec48 to dc597d8CompareAugust 16, 2026 18:31
@codebyterecodebytere added request-ci Add this label to start a Jenkins CI on a PR. and removed needs-ci PRs that need a full CI run. labels Aug 16, 2026
@codecov

codecovBot commented Aug 16, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.10448% with 14 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.13%. Comparing base (bc813a7) to head (f201d83).
⚠️ Report is 142 commits behind head on main.

Files with missing linesPatch %Lines
src/compile_cache.cc75.60%5 Missing and 5 partials ⚠️
src/env.cc50.00%1 Missing and 3 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65302 +/- ##
==========================================
- Coverage 90.32% 90.13% -0.19% 
==========================================
Files 751 751 Lines 249960 252344 +2384 Branches 47204 47452 +248 ==========================================
+ Hits 225774 227448 +1674 - Misses 15564 16193 +629 - Partials 8622 8703 +81 
Files with missing linesCoverage Δ
lib/internal/modules/helpers.js98.94% <100.00%> (+<0.01%)⬆️
src/compile_cache.h100.00% <100.00%> (ø)
src/node_modules.cc80.22% <100.00%> (-0.01%)⬇️
src/env.cc85.24% <50.00%> (-0.18%)⬇️
src/compile_cache.cc79.94% <75.60%> (+0.85%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 18, 2026
@nodejs-github-botnodejs-github-bot added commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. and removed commit-queue PRs queued for automated landing through the Commit Queue. labels Aug 18, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator
Commit Queue failed
- Loading data for nodejs/node/pull/65302
✔ Done loading data for nodejs/node/pull/65302
----------------------------------- PR info ------------------------------------
Title module: add a read-only mode to the compile cache (#65302)
Author Shelley Vohr <shelley.vohr@gmail.com> (@codebytere)
Branch codebytere:compile-cache-read-only -> nodejs:main
Labels c++, lib / src, commit-queue
Commits 1
- module: add a read-only mode to the compile cache
Committers 1
- Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
------------------------------ Generated metadata ------------------------------
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
--------------------------------------------------------------------------------
ℹ This PR was created on Sat, 15 Aug 2026 08:56:32 GMT
✔ Approvals: 1
✔ - James M Snell (@jasnell) (TSC): https://github.com/nodejs/node/pull/65302#pullrequestreview-4948260342
✘ This PR needs to wait 91 more hours to land (or 0 minutes if there is one more approval)
✔ Last GitHub CI successful
ℹ Last Full PR CI on 2026-08-17T03:52:44Z: https://ci.nodejs.org/job/node-test-pull-request/75904/
- Querying data for job/node-test-pull-request/75904/
✔ Build data downloaded
- Querying failures of job/node-test-commit/90633/
✔ Data downloaded
✘ 1 failure(s) on the last Jenkins CI run
--------------------------------------------------------------------------------
✔ Aborted `git node land` session in /home/runner/work/node/node/.ncu
https://github.com/nodejs/node/actions/runs/32149688331

@codebyterecodebytere removed the commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. label Aug 20, 2026
@codebytere

Copy link
Copy Markdown
MemberAuthor

@aduh95 PTAL when you have a moment!

Comment threaddoc/api/module.md Outdated
Comment threadsrc/compile_cache.cc
Comment on lines +594 to +599
if (!is_dir) {
result.message =
"Cache directory does not exist (read-only): " + cache_dir_with_tag;
result.status = CompileCacheEnableStatus::FAILED;
return result;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should this emit a warning?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i don't think so, for consistency: none of the other FAILED paths here (can't create the directory, not writable) warn either. through module.enableCompileCache() the caller gets { status, message } back and can decide what to do with it, and for NODE_COMPILE_CACHE the existing behavior is an inherited env var never adds output to a program that didn't ask for the cache; NODE_DEBUG_NATIVE=COMPILE_CACHE prints it. happy to add one if you feel strongly, but i'd rather do it for all the FAILED cases at once in a follow-up than special-case read-only.

A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
@codebytere
codebytereforce-pushed the compile-cache-read-only branch from dc597d8 to f201d83CompareAugust 21, 2026 18:17
@codebyterecodebytere added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 21, 2026
@Renegade334Renegade334 added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 21, 2026
@codebyterecodebytere removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 22, 2026
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
@nodejs-github-bot
nodejs-github-bot merged commit 65f518c into nodejs:mainAug 23, 2026
76 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in 65f518c

@nodejs-github-botnodejs-github-bot removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@codebytere@nodejs-github-bot@jasnell@Renegade334
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

module: add a read-only mode to the compile cache - #65302

Merged
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only
Aug 23, 2026
Merged

module: add a read-only mode to the compile cache#65302
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only

Conversation

@codebytere

Copy link
Copy Markdown
Member

A compile cache generated ahead of time and shipped inside an application package should only ever be read: the package may be immutable (an Electron app.asar, a read-only image) or covered by an integrity check, and a cache directory that appears at run time next to shipped code is a surprise either way. Today enabling the cache always implies writing: the tag directory is created on enable, and every module without an accepted entry is serialized and persisted at exit or on flushCompileCache().

This adds readOnly to module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1. With it, existing entries are looked up and loaded exactly as before; nothing is serialized into the in-memory store or written to disk, flushCompileCache() is a no-op, the write-permission check is skipped, and the cache directory is used as found rather than created, so enabling against a directory that does not exist fails (FAILED, with a message) instead of making one.

EnableOption becomes a small flag set (PORTABLE, READ_ONLY) since the two combine. Docs cover the option, the environment variable (cli.md, node.1) and a short section in module.md; test-compile-cache-api-readonly covers the missing-directory case, reading a previously generated cache without writing new entries, and the environment variable.

Context: same application as #65293 (an Electron app shipping its main-process cache in the package); review there asked that production launches never attempt writes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/loaders

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 15, 2026
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from 447fb62 to 133e37bCompareAugust 15, 2026 09:09
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from d57ec48 to dc597d8CompareAugust 16, 2026 18:31
@codebyterecodebytere added request-ci Add this label to start a Jenkins CI on a PR. and removed needs-ci PRs that need a full CI run. labels Aug 16, 2026
@codecov

codecovBot commented Aug 16, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.10448% with 14 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.13%. Comparing base (bc813a7) to head (f201d83).
⚠️ Report is 142 commits behind head on main.

Files with missing linesPatch %Lines
src/compile_cache.cc75.60%5 Missing and 5 partials ⚠️
src/env.cc50.00%1 Missing and 3 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65302 +/- ##
==========================================
- Coverage 90.32% 90.13% -0.19% 
==========================================
Files 751 751 Lines 249960 252344 +2384 Branches 47204 47452 +248 ==========================================
+ Hits 225774 227448 +1674 - Misses 15564 16193 +629 - Partials 8622 8703 +81 
Files with missing linesCoverage Δ
lib/internal/modules/helpers.js98.94% <100.00%> (+<0.01%)⬆️
src/compile_cache.h100.00% <100.00%> (ø)
src/node_modules.cc80.22% <100.00%> (-0.01%)⬇️
src/env.cc85.24% <50.00%> (-0.18%)⬇️
src/compile_cache.cc79.94% <75.60%> (+0.85%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 18, 2026
@nodejs-github-botnodejs-github-bot added commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. and removed commit-queue PRs queued for automated landing through the Commit Queue. labels Aug 18, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator
Commit Queue failed
- Loading data for nodejs/node/pull/65302
✔ Done loading data for nodejs/node/pull/65302
----------------------------------- PR info ------------------------------------
Title module: add a read-only mode to the compile cache (#65302)
Author Shelley Vohr <shelley.vohr@gmail.com> (@codebytere)
Branch codebytere:compile-cache-read-only -> nodejs:main
Labels c++, lib / src, commit-queue
Commits 1
- module: add a read-only mode to the compile cache
Committers 1
- Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
------------------------------ Generated metadata ------------------------------
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
--------------------------------------------------------------------------------
ℹ This PR was created on Sat, 15 Aug 2026 08:56:32 GMT
✔ Approvals: 1
✔ - James M Snell (@jasnell) (TSC): https://github.com/nodejs/node/pull/65302#pullrequestreview-4948260342
✘ This PR needs to wait 91 more hours to land (or 0 minutes if there is one more approval)
✔ Last GitHub CI successful
ℹ Last Full PR CI on 2026-08-17T03:52:44Z: https://ci.nodejs.org/job/node-test-pull-request/75904/
- Querying data for job/node-test-pull-request/75904/
✔ Build data downloaded
- Querying failures of job/node-test-commit/90633/
✔ Data downloaded
✘ 1 failure(s) on the last Jenkins CI run
--------------------------------------------------------------------------------
✔ Aborted `git node land` session in /home/runner/work/node/node/.ncu
https://github.com/nodejs/node/actions/runs/32149688331

@codebyterecodebytere removed the commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. label Aug 20, 2026
@codebytere

Copy link
Copy Markdown
MemberAuthor

@aduh95 PTAL when you have a moment!

Comment threaddoc/api/module.md Outdated
Comment threadsrc/compile_cache.cc
Comment on lines +594 to +599
if (!is_dir) {
result.message =
"Cache directory does not exist (read-only): " + cache_dir_with_tag;
result.status = CompileCacheEnableStatus::FAILED;
return result;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should this emit a warning?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i don't think so, for consistency: none of the other FAILED paths here (can't create the directory, not writable) warn either. through module.enableCompileCache() the caller gets { status, message } back and can decide what to do with it, and for NODE_COMPILE_CACHE the existing behavior is an inherited env var never adds output to a program that didn't ask for the cache; NODE_DEBUG_NATIVE=COMPILE_CACHE prints it. happy to add one if you feel strongly, but i'd rather do it for all the FAILED cases at once in a follow-up than special-case read-only.

A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
@codebytere
codebytereforce-pushed the compile-cache-read-only branch from dc597d8 to f201d83CompareAugust 21, 2026 18:17
@codebyterecodebytere added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 21, 2026
@Renegade334Renegade334 added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 21, 2026
@codebyterecodebytere removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 22, 2026
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
@nodejs-github-bot
nodejs-github-bot merged commit 65f518c into nodejs:mainAug 23, 2026
76 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in 65f518c

@nodejs-github-botnodejs-github-bot removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@codebytere@nodejs-github-bot@jasnell@Renegade334
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

module: add a read-only mode to the compile cache - #65302

Merged
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only
Aug 23, 2026
Merged

module: add a read-only mode to the compile cache#65302
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
codebytere:compile-cache-read-only

Conversation

@codebytere

Copy link
Copy Markdown
Member

A compile cache generated ahead of time and shipped inside an application package should only ever be read: the package may be immutable (an Electron app.asar, a read-only image) or covered by an integrity check, and a cache directory that appears at run time next to shipped code is a surprise either way. Today enabling the cache always implies writing: the tag directory is created on enable, and every module without an accepted entry is serialized and persisted at exit or on flushCompileCache().

This adds readOnly to module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1. With it, existing entries are looked up and loaded exactly as before; nothing is serialized into the in-memory store or written to disk, flushCompileCache() is a no-op, the write-permission check is skipped, and the cache directory is used as found rather than created, so enabling against a directory that does not exist fails (FAILED, with a message) instead of making one.

EnableOption becomes a small flag set (PORTABLE, READ_ONLY) since the two combine. Docs cover the option, the environment variable (cli.md, node.1) and a short section in module.md; test-compile-cache-api-readonly covers the missing-directory case, reading a previously generated cache without writing new entries, and the environment variable.

Context: same application as #65293 (an Electron app shipping its main-process cache in the package); review there asked that production launches never attempt writes.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/loaders

@nodejs-github-botnodejs-github-bot added c++ Issues and PRs that require attention from people who are familiar with C++. lib / src Issues and PRs involving general changes in the lib/ or src/ directories. needs-ci PRs that need a full CI run. labels Aug 15, 2026
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from 447fb62 to 133e37bCompareAugust 15, 2026 09:09
@codebytere
codebytereforce-pushed the compile-cache-read-only branch 2 times, most recently from d57ec48 to dc597d8CompareAugust 16, 2026 18:31
@codebyterecodebytere added request-ci Add this label to start a Jenkins CI on a PR. and removed needs-ci PRs that need a full CI run. labels Aug 16, 2026
@codecov

codecovBot commented Aug 16, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 79.10448% with 14 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.13%. Comparing base (bc813a7) to head (f201d83).
⚠️ Report is 142 commits behind head on main.

Files with missing linesPatch %Lines
src/compile_cache.cc75.60%5 Missing and 5 partials ⚠️
src/env.cc50.00%1 Missing and 3 partials ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #65302 +/- ##
==========================================
- Coverage 90.32% 90.13% -0.19% 
==========================================
Files 751 751 Lines 249960 252344 +2384 Branches 47204 47452 +248 ==========================================
+ Hits 225774 227448 +1674 - Misses 15564 16193 +629 - Partials 8622 8703 +81 
Files with missing linesCoverage Δ
lib/internal/modules/helpers.js98.94% <100.00%> (+<0.01%)⬆️
src/compile_cache.h100.00% <100.00%> (ø)
src/node_modules.cc80.22% <100.00%> (-0.01%)⬇️
src/env.cc85.24% <50.00%> (-0.18%)⬇️
src/compile_cache.cc79.94% <75.60%> (+0.85%)⬆️

... and 119 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 17, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 18, 2026
@nodejs-github-botnodejs-github-bot added commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. and removed commit-queue PRs queued for automated landing through the Commit Queue. labels Aug 18, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator
Commit Queue failed
- Loading data for nodejs/node/pull/65302
✔ Done loading data for nodejs/node/pull/65302
----------------------------------- PR info ------------------------------------
Title module: add a read-only mode to the compile cache (#65302)
Author Shelley Vohr <shelley.vohr@gmail.com> (@codebytere)
Branch codebytere:compile-cache-read-only -> nodejs:main
Labels c++, lib / src, commit-queue
Commits 1
- module: add a read-only mode to the compile cache
Committers 1
- Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
------------------------------ Generated metadata ------------------------------
PR-URL: https://github.com/nodejs/node/pull/65302
Reviewed-By: James M Snell <jasnell@gmail.com>
--------------------------------------------------------------------------------
ℹ This PR was created on Sat, 15 Aug 2026 08:56:32 GMT
✔ Approvals: 1
✔ - James M Snell (@jasnell) (TSC): https://github.com/nodejs/node/pull/65302#pullrequestreview-4948260342
✘ This PR needs to wait 91 more hours to land (or 0 minutes if there is one more approval)
✔ Last GitHub CI successful
ℹ Last Full PR CI on 2026-08-17T03:52:44Z: https://ci.nodejs.org/job/node-test-pull-request/75904/
- Querying data for job/node-test-pull-request/75904/
✔ Build data downloaded
- Querying failures of job/node-test-commit/90633/
✔ Data downloaded
✘ 1 failure(s) on the last Jenkins CI run
--------------------------------------------------------------------------------
✔ Aborted `git node land` session in /home/runner/work/node/node/.ncu
https://github.com/nodejs/node/actions/runs/32149688331

@codebyterecodebytere removed the commit-queue-failed PRs whose Commit Queue landing failed and need manual intervention before retrying. label Aug 20, 2026
@codebytere

Copy link
Copy Markdown
MemberAuthor

@aduh95 PTAL when you have a moment!

Comment threaddoc/api/module.md Outdated
Comment threadsrc/compile_cache.cc
Comment on lines +594 to +599
if (!is_dir) {
result.message =
"Cache directory does not exist (read-only): " + cache_dir_with_tag;
result.status = CompileCacheEnableStatus::FAILED;
return result;
}

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should this emit a warning?

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

i don't think so, for consistency: none of the other FAILED paths here (can't create the directory, not writable) warn either. through module.enableCompileCache() the caller gets { status, message } back and can decide what to do with it, and for NODE_COMPILE_CACHE the existing behavior is an inherited env var never adds output to a program that didn't ask for the cache; NODE_DEBUG_NATIVE=COMPILE_CACHE prints it. happy to add one if you feel strongly, but i'd rather do it for all the FAILED cases at once in a follow-up than special-case read-only.

A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
@codebytere
codebytereforce-pushed the compile-cache-read-only branch from dc597d8 to f201d83CompareAugust 21, 2026 18:17
@codebyterecodebytere added the request-ci Add this label to start a Jenkins CI on a PR. label Aug 21, 2026
@Renegade334Renegade334 added the author ready PRs with CI started, the required approvals, and no outstanding review comments. label Aug 21, 2026
@codebyterecodebytere removed the request-ci Add this label to start a Jenkins CI on a PR. label Aug 22, 2026
@nodejs-github-bot

This comment was marked as outdated.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@codebyterecodebytere added the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
@nodejs-github-bot
nodejs-github-bot merged commit 65f518c into nodejs:mainAug 23, 2026
76 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in 65f518c

@nodejs-github-botnodejs-github-bot removed the commit-queue PRs queued for automated landing through the Commit Queue. label Aug 23, 2026
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
aduh95 pushed a commit that referenced this pull request Aug 25, 2026
A compile cache generated ahead of time and shipped inside an
application package should only ever be read: the package may be
immutable or covered by an integrity check, and a cache directory that
appears at run time would be a surprise. Add readOnly to
module.enableCompileCache() and NODE_COMPILE_CACHE_READONLY=1: existing
entries are loaded as before, nothing is serialized or persisted,
flushCompileCache() is a no-op, and the cache directory is used as found
rather than created, so enabling against a missing directory fails
instead of making one.
Signed-off-by: Shelley Vohr <shelley.vohr@gmail.com>
PR-URL: #65302
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: René <contact.9a5d6388@renegade334.me.uk>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

author readyPRs with CI started, the required approvals, and no outstanding review comments.c++Issues and PRs that require attention from people who are familiar with C++.lib / srcIssues and PRs involving general changes in the lib/ or src/ directories.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@codebytere@nodejs-github-bot@jasnell@Renegade334