fix(arborist): invalid filterNode crash under the linked strategy - #9637

Merged
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters
Jun 24, 2026
Merged

fix(arborist): invalid filterNode crash under the linked strategy#9637
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters

Conversation

@manzoorwanijk

@manzoorwanijkmanzoorwanijk commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

In continuation of our exploration of using install-strategy=linked in the Gutenberg monorepo, which powers the WordPress Block Editor.

Under install-strategy=linked, several common installs failed with npm error invalid filterNode: outside idealTree/actualTree, with no workaround besides dropping the linked strategy. Hoisted handled all of them. This fixes two distinct paths that both produced that error.

Why

A linked reify diffs the ideal tree against a synthesized actual wrapper (#linkedActualForDiff) rather than this.actualTree. Diff.calculate rejects any filter node whose root is neither the ideal nor the actual it was given, so a filter node taken from the real this.actualTree is "outside" the diff and throws.

Two places fed it such nodes:

  • --workspaces=false and -w <ws> --include-workspace-root go through the includeRootDeps branch of _diffTrees(), which collected root-dep edge targets from both this.idealTree and this.actualTree. The actual-side targets are rooted at the real actual tree, not the wrapper, so they tripped the guard. The sibling includeWorkspaces branch already accounted for this; the root-dep branch did not.

  • A global install with a per-call installStrategy: 'linked' re-engaged the linked path even though the constructor normalizes global installs to shallow (the linked layout is unsupported for globals). Re-installing an already-present global package then hit the global explicit-request branch, which pushes actual-side nodes, and tripped the same guard. Suppressing the crash there was worse: the isolated reifier does not materialize the global layout and removed the package instead.

How

_diffTrees() now iterates only the ideal tree for root-dep filter nodes when the linked wrapper is in use, matching the existing workspace-node handling. The ideal-side nodes are sufficient to scope the diff, and the post-reify orphan sweep continues to prune deps removed from the manifest.

reify() now honors the constructor's global-to-shallow normalization when deriving the linked flag, so a global install never engages the linked path regardless of a per-call installStrategy. Global installs fall back to shallow, which materializes and upgrades packages correctly. No change to the global explicit-request branch is needed once global is never linked.

References

Fixes#9614
Part of #9608

Under the linked strategy the diff's actual side is a synthesized wrapper tree. When includeRootDeps was active (--workspaces=false or -w <ws> --include-workspace-root), the root-dep filter nodes were pulled from this.actualTree, whose root is the real actual tree rather than the wrapper, tripping Diff.calculate's invalid filterNode guard. Use only the ideal-side root-dep targets when the linked wrapper is in use, matching the existing workspace-node handling.
Global installs are normalized to the shallow strategy in the Arborist constructor, but reify() re-derived the linked flag from the raw per-call installStrategy option, bypassing that normalization. A global install passed installStrategy:'linked' would engage the unsupported linked path: re-installing an already-present global package tripped Diff.calculate's invalid filterNode guard, and once the guard was bypassed the isolated reifier deleted the global package instead of materializing it. Honor the global-to-shallow normalization in reify() so global installs never use the linked strategy.
@manzoorwanijk
manzoorwanijk marked this pull request as ready for review June 24, 2026 16:59
@manzoorwanijk
manzoorwanijk requested review from a team as code ownersJune 24, 2026 16:59
@owlstronaut
owlstronaut merged commit 2b976b5 into npm:latestJun 24, 2026
25 checks passed
@manzoorwanijk
manzoorwanijk deleted the fix/linked-filternode-workspace-filters branch June 24, 2026 18:40
@github-actions

Copy link
Copy Markdown
Contributor

🎉 Backport to release/v11 created: #9645

@github-actionsgithub-actionsBot mentioned this pull request Jun 24, 2026
owlstronaut pushed a commit that referenced this pull request Jun 24, 2026
)
Backport of #9637 to `release/v11`.
Co-authored-by: Manzoor Wani <manzoorwani.jk@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] install-strategy=linked: --workspaces=false and --include-workspace-root fail with invalid filterNode

2 participants

@manzoorwanijk@owlstronaut
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(arborist): invalid filterNode crash under the linked strategy - #9637

Merged
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters
Jun 24, 2026
Merged

fix(arborist): invalid filterNode crash under the linked strategy#9637
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters

Conversation

@manzoorwanijk

@manzoorwanijkmanzoorwanijk commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

In continuation of our exploration of using install-strategy=linked in the Gutenberg monorepo, which powers the WordPress Block Editor.

Under install-strategy=linked, several common installs failed with npm error invalid filterNode: outside idealTree/actualTree, with no workaround besides dropping the linked strategy. Hoisted handled all of them. This fixes two distinct paths that both produced that error.

Why

A linked reify diffs the ideal tree against a synthesized actual wrapper (#linkedActualForDiff) rather than this.actualTree. Diff.calculate rejects any filter node whose root is neither the ideal nor the actual it was given, so a filter node taken from the real this.actualTree is "outside" the diff and throws.

Two places fed it such nodes:

  • --workspaces=false and -w <ws> --include-workspace-root go through the includeRootDeps branch of _diffTrees(), which collected root-dep edge targets from both this.idealTree and this.actualTree. The actual-side targets are rooted at the real actual tree, not the wrapper, so they tripped the guard. The sibling includeWorkspaces branch already accounted for this; the root-dep branch did not.

  • A global install with a per-call installStrategy: 'linked' re-engaged the linked path even though the constructor normalizes global installs to shallow (the linked layout is unsupported for globals). Re-installing an already-present global package then hit the global explicit-request branch, which pushes actual-side nodes, and tripped the same guard. Suppressing the crash there was worse: the isolated reifier does not materialize the global layout and removed the package instead.

How

_diffTrees() now iterates only the ideal tree for root-dep filter nodes when the linked wrapper is in use, matching the existing workspace-node handling. The ideal-side nodes are sufficient to scope the diff, and the post-reify orphan sweep continues to prune deps removed from the manifest.

reify() now honors the constructor's global-to-shallow normalization when deriving the linked flag, so a global install never engages the linked path regardless of a per-call installStrategy. Global installs fall back to shallow, which materializes and upgrades packages correctly. No change to the global explicit-request branch is needed once global is never linked.

References

Fixes#9614
Part of #9608

Under the linked strategy the diff's actual side is a synthesized wrapper tree. When includeRootDeps was active (--workspaces=false or -w <ws> --include-workspace-root), the root-dep filter nodes were pulled from this.actualTree, whose root is the real actual tree rather than the wrapper, tripping Diff.calculate's invalid filterNode guard. Use only the ideal-side root-dep targets when the linked wrapper is in use, matching the existing workspace-node handling.
Global installs are normalized to the shallow strategy in the Arborist constructor, but reify() re-derived the linked flag from the raw per-call installStrategy option, bypassing that normalization. A global install passed installStrategy:'linked' would engage the unsupported linked path: re-installing an already-present global package tripped Diff.calculate's invalid filterNode guard, and once the guard was bypassed the isolated reifier deleted the global package instead of materializing it. Honor the global-to-shallow normalization in reify() so global installs never use the linked strategy.
@manzoorwanijk
manzoorwanijk marked this pull request as ready for review June 24, 2026 16:59
@manzoorwanijk
manzoorwanijk requested review from a team as code ownersJune 24, 2026 16:59
@owlstronaut
owlstronaut merged commit 2b976b5 into npm:latestJun 24, 2026
25 checks passed
@manzoorwanijk
manzoorwanijk deleted the fix/linked-filternode-workspace-filters branch June 24, 2026 18:40
@github-actions

Copy link
Copy Markdown
Contributor

🎉 Backport to release/v11 created: #9645

@github-actionsgithub-actionsBot mentioned this pull request Jun 24, 2026
owlstronaut pushed a commit that referenced this pull request Jun 24, 2026
)
Backport of #9637 to `release/v11`.
Co-authored-by: Manzoor Wani <manzoorwani.jk@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] install-strategy=linked: --workspaces=false and --include-workspace-root fail with invalid filterNode

2 participants

@manzoorwanijk@owlstronaut
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(arborist): invalid filterNode crash under the linked strategy - #9637

Merged
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters
Jun 24, 2026
Merged

fix(arborist): invalid filterNode crash under the linked strategy#9637
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters

Conversation

@manzoorwanijk

@manzoorwanijkmanzoorwanijk commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

In continuation of our exploration of using install-strategy=linked in the Gutenberg monorepo, which powers the WordPress Block Editor.

Under install-strategy=linked, several common installs failed with npm error invalid filterNode: outside idealTree/actualTree, with no workaround besides dropping the linked strategy. Hoisted handled all of them. This fixes two distinct paths that both produced that error.

Why

A linked reify diffs the ideal tree against a synthesized actual wrapper (#linkedActualForDiff) rather than this.actualTree. Diff.calculate rejects any filter node whose root is neither the ideal nor the actual it was given, so a filter node taken from the real this.actualTree is "outside" the diff and throws.

Two places fed it such nodes:

  • --workspaces=false and -w <ws> --include-workspace-root go through the includeRootDeps branch of _diffTrees(), which collected root-dep edge targets from both this.idealTree and this.actualTree. The actual-side targets are rooted at the real actual tree, not the wrapper, so they tripped the guard. The sibling includeWorkspaces branch already accounted for this; the root-dep branch did not.

  • A global install with a per-call installStrategy: 'linked' re-engaged the linked path even though the constructor normalizes global installs to shallow (the linked layout is unsupported for globals). Re-installing an already-present global package then hit the global explicit-request branch, which pushes actual-side nodes, and tripped the same guard. Suppressing the crash there was worse: the isolated reifier does not materialize the global layout and removed the package instead.

How

_diffTrees() now iterates only the ideal tree for root-dep filter nodes when the linked wrapper is in use, matching the existing workspace-node handling. The ideal-side nodes are sufficient to scope the diff, and the post-reify orphan sweep continues to prune deps removed from the manifest.

reify() now honors the constructor's global-to-shallow normalization when deriving the linked flag, so a global install never engages the linked path regardless of a per-call installStrategy. Global installs fall back to shallow, which materializes and upgrades packages correctly. No change to the global explicit-request branch is needed once global is never linked.

References

Fixes#9614
Part of #9608

Under the linked strategy the diff's actual side is a synthesized wrapper tree. When includeRootDeps was active (--workspaces=false or -w <ws> --include-workspace-root), the root-dep filter nodes were pulled from this.actualTree, whose root is the real actual tree rather than the wrapper, tripping Diff.calculate's invalid filterNode guard. Use only the ideal-side root-dep targets when the linked wrapper is in use, matching the existing workspace-node handling.
Global installs are normalized to the shallow strategy in the Arborist constructor, but reify() re-derived the linked flag from the raw per-call installStrategy option, bypassing that normalization. A global install passed installStrategy:'linked' would engage the unsupported linked path: re-installing an already-present global package tripped Diff.calculate's invalid filterNode guard, and once the guard was bypassed the isolated reifier deleted the global package instead of materializing it. Honor the global-to-shallow normalization in reify() so global installs never use the linked strategy.
@manzoorwanijk
manzoorwanijk marked this pull request as ready for review June 24, 2026 16:59
@manzoorwanijk
manzoorwanijk requested review from a team as code ownersJune 24, 2026 16:59
@owlstronaut
owlstronaut merged commit 2b976b5 into npm:latestJun 24, 2026
25 checks passed
@manzoorwanijk
manzoorwanijk deleted the fix/linked-filternode-workspace-filters branch June 24, 2026 18:40
@github-actions

Copy link
Copy Markdown
Contributor

🎉 Backport to release/v11 created: #9645

@github-actionsgithub-actionsBot mentioned this pull request Jun 24, 2026
owlstronaut pushed a commit that referenced this pull request Jun 24, 2026
)
Backport of #9637 to `release/v11`.
Co-authored-by: Manzoor Wani <manzoorwani.jk@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] install-strategy=linked: --workspaces=false and --include-workspace-root fail with invalid filterNode

2 participants

@manzoorwanijk@owlstronaut
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(arborist): invalid filterNode crash under the linked strategy - #9637

Merged
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters
Jun 24, 2026
Merged

fix(arborist): invalid filterNode crash under the linked strategy#9637
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters

Conversation

@manzoorwanijk

@manzoorwanijkmanzoorwanijk commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

In continuation of our exploration of using install-strategy=linked in the Gutenberg monorepo, which powers the WordPress Block Editor.

Under install-strategy=linked, several common installs failed with npm error invalid filterNode: outside idealTree/actualTree, with no workaround besides dropping the linked strategy. Hoisted handled all of them. This fixes two distinct paths that both produced that error.

Why

A linked reify diffs the ideal tree against a synthesized actual wrapper (#linkedActualForDiff) rather than this.actualTree. Diff.calculate rejects any filter node whose root is neither the ideal nor the actual it was given, so a filter node taken from the real this.actualTree is "outside" the diff and throws.

Two places fed it such nodes:

  • --workspaces=false and -w <ws> --include-workspace-root go through the includeRootDeps branch of _diffTrees(), which collected root-dep edge targets from both this.idealTree and this.actualTree. The actual-side targets are rooted at the real actual tree, not the wrapper, so they tripped the guard. The sibling includeWorkspaces branch already accounted for this; the root-dep branch did not.

  • A global install with a per-call installStrategy: 'linked' re-engaged the linked path even though the constructor normalizes global installs to shallow (the linked layout is unsupported for globals). Re-installing an already-present global package then hit the global explicit-request branch, which pushes actual-side nodes, and tripped the same guard. Suppressing the crash there was worse: the isolated reifier does not materialize the global layout and removed the package instead.

How

_diffTrees() now iterates only the ideal tree for root-dep filter nodes when the linked wrapper is in use, matching the existing workspace-node handling. The ideal-side nodes are sufficient to scope the diff, and the post-reify orphan sweep continues to prune deps removed from the manifest.

reify() now honors the constructor's global-to-shallow normalization when deriving the linked flag, so a global install never engages the linked path regardless of a per-call installStrategy. Global installs fall back to shallow, which materializes and upgrades packages correctly. No change to the global explicit-request branch is needed once global is never linked.

References

Fixes#9614
Part of #9608

Under the linked strategy the diff's actual side is a synthesized wrapper tree. When includeRootDeps was active (--workspaces=false or -w <ws> --include-workspace-root), the root-dep filter nodes were pulled from this.actualTree, whose root is the real actual tree rather than the wrapper, tripping Diff.calculate's invalid filterNode guard. Use only the ideal-side root-dep targets when the linked wrapper is in use, matching the existing workspace-node handling.
Global installs are normalized to the shallow strategy in the Arborist constructor, but reify() re-derived the linked flag from the raw per-call installStrategy option, bypassing that normalization. A global install passed installStrategy:'linked' would engage the unsupported linked path: re-installing an already-present global package tripped Diff.calculate's invalid filterNode guard, and once the guard was bypassed the isolated reifier deleted the global package instead of materializing it. Honor the global-to-shallow normalization in reify() so global installs never use the linked strategy.
@manzoorwanijk
manzoorwanijk marked this pull request as ready for review June 24, 2026 16:59
@manzoorwanijk
manzoorwanijk requested review from a team as code ownersJune 24, 2026 16:59
@owlstronaut
owlstronaut merged commit 2b976b5 into npm:latestJun 24, 2026
25 checks passed
@manzoorwanijk
manzoorwanijk deleted the fix/linked-filternode-workspace-filters branch June 24, 2026 18:40
@github-actions

Copy link
Copy Markdown
Contributor

🎉 Backport to release/v11 created: #9645

@github-actionsgithub-actionsBot mentioned this pull request Jun 24, 2026
owlstronaut pushed a commit that referenced this pull request Jun 24, 2026
)
Backport of #9637 to `release/v11`.
Co-authored-by: Manzoor Wani <manzoorwani.jk@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] install-strategy=linked: --workspaces=false and --include-workspace-root fail with invalid filterNode

2 participants

@manzoorwanijk@owlstronaut
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(arborist): invalid filterNode crash under the linked strategy - #9637

Merged
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters
Jun 24, 2026
Merged

fix(arborist): invalid filterNode crash under the linked strategy#9637
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters

Conversation

@manzoorwanijk

@manzoorwanijkmanzoorwanijk commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

In continuation of our exploration of using install-strategy=linked in the Gutenberg monorepo, which powers the WordPress Block Editor.

Under install-strategy=linked, several common installs failed with npm error invalid filterNode: outside idealTree/actualTree, with no workaround besides dropping the linked strategy. Hoisted handled all of them. This fixes two distinct paths that both produced that error.

Why

A linked reify diffs the ideal tree against a synthesized actual wrapper (#linkedActualForDiff) rather than this.actualTree. Diff.calculate rejects any filter node whose root is neither the ideal nor the actual it was given, so a filter node taken from the real this.actualTree is "outside" the diff and throws.

Two places fed it such nodes:

  • --workspaces=false and -w <ws> --include-workspace-root go through the includeRootDeps branch of _diffTrees(), which collected root-dep edge targets from both this.idealTree and this.actualTree. The actual-side targets are rooted at the real actual tree, not the wrapper, so they tripped the guard. The sibling includeWorkspaces branch already accounted for this; the root-dep branch did not.

  • A global install with a per-call installStrategy: 'linked' re-engaged the linked path even though the constructor normalizes global installs to shallow (the linked layout is unsupported for globals). Re-installing an already-present global package then hit the global explicit-request branch, which pushes actual-side nodes, and tripped the same guard. Suppressing the crash there was worse: the isolated reifier does not materialize the global layout and removed the package instead.

How

_diffTrees() now iterates only the ideal tree for root-dep filter nodes when the linked wrapper is in use, matching the existing workspace-node handling. The ideal-side nodes are sufficient to scope the diff, and the post-reify orphan sweep continues to prune deps removed from the manifest.

reify() now honors the constructor's global-to-shallow normalization when deriving the linked flag, so a global install never engages the linked path regardless of a per-call installStrategy. Global installs fall back to shallow, which materializes and upgrades packages correctly. No change to the global explicit-request branch is needed once global is never linked.

References

Fixes#9614
Part of #9608

Under the linked strategy the diff's actual side is a synthesized wrapper tree. When includeRootDeps was active (--workspaces=false or -w <ws> --include-workspace-root), the root-dep filter nodes were pulled from this.actualTree, whose root is the real actual tree rather than the wrapper, tripping Diff.calculate's invalid filterNode guard. Use only the ideal-side root-dep targets when the linked wrapper is in use, matching the existing workspace-node handling.
Global installs are normalized to the shallow strategy in the Arborist constructor, but reify() re-derived the linked flag from the raw per-call installStrategy option, bypassing that normalization. A global install passed installStrategy:'linked' would engage the unsupported linked path: re-installing an already-present global package tripped Diff.calculate's invalid filterNode guard, and once the guard was bypassed the isolated reifier deleted the global package instead of materializing it. Honor the global-to-shallow normalization in reify() so global installs never use the linked strategy.
@manzoorwanijk
manzoorwanijk marked this pull request as ready for review June 24, 2026 16:59
@manzoorwanijk
manzoorwanijk requested review from a team as code ownersJune 24, 2026 16:59
@owlstronaut
owlstronaut merged commit 2b976b5 into npm:latestJun 24, 2026
25 checks passed
@manzoorwanijk
manzoorwanijk deleted the fix/linked-filternode-workspace-filters branch June 24, 2026 18:40
@github-actions

Copy link
Copy Markdown
Contributor

🎉 Backport to release/v11 created: #9645

@github-actionsgithub-actionsBot mentioned this pull request Jun 24, 2026
owlstronaut pushed a commit that referenced this pull request Jun 24, 2026
)
Backport of #9637 to `release/v11`.
Co-authored-by: Manzoor Wani <manzoorwani.jk@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] install-strategy=linked: --workspaces=false and --include-workspace-root fail with invalid filterNode

2 participants

@manzoorwanijk@owlstronaut
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(arborist): invalid filterNode crash under the linked strategy - #9637

Merged
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters
Jun 24, 2026
Merged

fix(arborist): invalid filterNode crash under the linked strategy#9637
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters

Conversation

@manzoorwanijk

@manzoorwanijkmanzoorwanijk commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

In continuation of our exploration of using install-strategy=linked in the Gutenberg monorepo, which powers the WordPress Block Editor.

Under install-strategy=linked, several common installs failed with npm error invalid filterNode: outside idealTree/actualTree, with no workaround besides dropping the linked strategy. Hoisted handled all of them. This fixes two distinct paths that both produced that error.

Why

A linked reify diffs the ideal tree against a synthesized actual wrapper (#linkedActualForDiff) rather than this.actualTree. Diff.calculate rejects any filter node whose root is neither the ideal nor the actual it was given, so a filter node taken from the real this.actualTree is "outside" the diff and throws.

Two places fed it such nodes:

  • --workspaces=false and -w <ws> --include-workspace-root go through the includeRootDeps branch of _diffTrees(), which collected root-dep edge targets from both this.idealTree and this.actualTree. The actual-side targets are rooted at the real actual tree, not the wrapper, so they tripped the guard. The sibling includeWorkspaces branch already accounted for this; the root-dep branch did not.

  • A global install with a per-call installStrategy: 'linked' re-engaged the linked path even though the constructor normalizes global installs to shallow (the linked layout is unsupported for globals). Re-installing an already-present global package then hit the global explicit-request branch, which pushes actual-side nodes, and tripped the same guard. Suppressing the crash there was worse: the isolated reifier does not materialize the global layout and removed the package instead.

How

_diffTrees() now iterates only the ideal tree for root-dep filter nodes when the linked wrapper is in use, matching the existing workspace-node handling. The ideal-side nodes are sufficient to scope the diff, and the post-reify orphan sweep continues to prune deps removed from the manifest.

reify() now honors the constructor's global-to-shallow normalization when deriving the linked flag, so a global install never engages the linked path regardless of a per-call installStrategy. Global installs fall back to shallow, which materializes and upgrades packages correctly. No change to the global explicit-request branch is needed once global is never linked.

References

Fixes#9614
Part of #9608

Under the linked strategy the diff's actual side is a synthesized wrapper tree. When includeRootDeps was active (--workspaces=false or -w <ws> --include-workspace-root), the root-dep filter nodes were pulled from this.actualTree, whose root is the real actual tree rather than the wrapper, tripping Diff.calculate's invalid filterNode guard. Use only the ideal-side root-dep targets when the linked wrapper is in use, matching the existing workspace-node handling.
Global installs are normalized to the shallow strategy in the Arborist constructor, but reify() re-derived the linked flag from the raw per-call installStrategy option, bypassing that normalization. A global install passed installStrategy:'linked' would engage the unsupported linked path: re-installing an already-present global package tripped Diff.calculate's invalid filterNode guard, and once the guard was bypassed the isolated reifier deleted the global package instead of materializing it. Honor the global-to-shallow normalization in reify() so global installs never use the linked strategy.
@manzoorwanijk
manzoorwanijk marked this pull request as ready for review June 24, 2026 16:59
@manzoorwanijk
manzoorwanijk requested review from a team as code ownersJune 24, 2026 16:59
@owlstronaut
owlstronaut merged commit 2b976b5 into npm:latestJun 24, 2026
25 checks passed
@manzoorwanijk
manzoorwanijk deleted the fix/linked-filternode-workspace-filters branch June 24, 2026 18:40
@github-actions

Copy link
Copy Markdown
Contributor

🎉 Backport to release/v11 created: #9645

@github-actionsgithub-actionsBot mentioned this pull request Jun 24, 2026
owlstronaut pushed a commit that referenced this pull request Jun 24, 2026
)
Backport of #9637 to `release/v11`.
Co-authored-by: Manzoor Wani <manzoorwani.jk@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] install-strategy=linked: --workspaces=false and --include-workspace-root fail with invalid filterNode

2 participants

@manzoorwanijk@owlstronaut
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(arborist): invalid filterNode crash under the linked strategy - #9637

Merged
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters
Jun 24, 2026
Merged

fix(arborist): invalid filterNode crash under the linked strategy#9637
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters

Conversation

@manzoorwanijk

@manzoorwanijkmanzoorwanijk commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

In continuation of our exploration of using install-strategy=linked in the Gutenberg monorepo, which powers the WordPress Block Editor.

Under install-strategy=linked, several common installs failed with npm error invalid filterNode: outside idealTree/actualTree, with no workaround besides dropping the linked strategy. Hoisted handled all of them. This fixes two distinct paths that both produced that error.

Why

A linked reify diffs the ideal tree against a synthesized actual wrapper (#linkedActualForDiff) rather than this.actualTree. Diff.calculate rejects any filter node whose root is neither the ideal nor the actual it was given, so a filter node taken from the real this.actualTree is "outside" the diff and throws.

Two places fed it such nodes:

  • --workspaces=false and -w <ws> --include-workspace-root go through the includeRootDeps branch of _diffTrees(), which collected root-dep edge targets from both this.idealTree and this.actualTree. The actual-side targets are rooted at the real actual tree, not the wrapper, so they tripped the guard. The sibling includeWorkspaces branch already accounted for this; the root-dep branch did not.

  • A global install with a per-call installStrategy: 'linked' re-engaged the linked path even though the constructor normalizes global installs to shallow (the linked layout is unsupported for globals). Re-installing an already-present global package then hit the global explicit-request branch, which pushes actual-side nodes, and tripped the same guard. Suppressing the crash there was worse: the isolated reifier does not materialize the global layout and removed the package instead.

How

_diffTrees() now iterates only the ideal tree for root-dep filter nodes when the linked wrapper is in use, matching the existing workspace-node handling. The ideal-side nodes are sufficient to scope the diff, and the post-reify orphan sweep continues to prune deps removed from the manifest.

reify() now honors the constructor's global-to-shallow normalization when deriving the linked flag, so a global install never engages the linked path regardless of a per-call installStrategy. Global installs fall back to shallow, which materializes and upgrades packages correctly. No change to the global explicit-request branch is needed once global is never linked.

References

Fixes#9614
Part of #9608

Under the linked strategy the diff's actual side is a synthesized wrapper tree. When includeRootDeps was active (--workspaces=false or -w <ws> --include-workspace-root), the root-dep filter nodes were pulled from this.actualTree, whose root is the real actual tree rather than the wrapper, tripping Diff.calculate's invalid filterNode guard. Use only the ideal-side root-dep targets when the linked wrapper is in use, matching the existing workspace-node handling.
Global installs are normalized to the shallow strategy in the Arborist constructor, but reify() re-derived the linked flag from the raw per-call installStrategy option, bypassing that normalization. A global install passed installStrategy:'linked' would engage the unsupported linked path: re-installing an already-present global package tripped Diff.calculate's invalid filterNode guard, and once the guard was bypassed the isolated reifier deleted the global package instead of materializing it. Honor the global-to-shallow normalization in reify() so global installs never use the linked strategy.
@manzoorwanijk
manzoorwanijk marked this pull request as ready for review June 24, 2026 16:59
@manzoorwanijk
manzoorwanijk requested review from a team as code ownersJune 24, 2026 16:59
@owlstronaut
owlstronaut merged commit 2b976b5 into npm:latestJun 24, 2026
25 checks passed
@manzoorwanijk
manzoorwanijk deleted the fix/linked-filternode-workspace-filters branch June 24, 2026 18:40
@github-actions

Copy link
Copy Markdown
Contributor

🎉 Backport to release/v11 created: #9645

@github-actionsgithub-actionsBot mentioned this pull request Jun 24, 2026
owlstronaut pushed a commit that referenced this pull request Jun 24, 2026
)
Backport of #9637 to `release/v11`.
Co-authored-by: Manzoor Wani <manzoorwani.jk@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] install-strategy=linked: --workspaces=false and --include-workspace-root fail with invalid filterNode

2 participants

@manzoorwanijk@owlstronaut
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(arborist): invalid filterNode crash under the linked strategy - #9637

Merged
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters
Jun 24, 2026
Merged

fix(arborist): invalid filterNode crash under the linked strategy#9637
owlstronaut merged 2 commits into
npm:latestfrom
manzoorwanijk:fix/linked-filternode-workspace-filters

Conversation

@manzoorwanijk

@manzoorwanijkmanzoorwanijk commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

In continuation of our exploration of using install-strategy=linked in the Gutenberg monorepo, which powers the WordPress Block Editor.

Under install-strategy=linked, several common installs failed with npm error invalid filterNode: outside idealTree/actualTree, with no workaround besides dropping the linked strategy. Hoisted handled all of them. This fixes two distinct paths that both produced that error.

Why

A linked reify diffs the ideal tree against a synthesized actual wrapper (#linkedActualForDiff) rather than this.actualTree. Diff.calculate rejects any filter node whose root is neither the ideal nor the actual it was given, so a filter node taken from the real this.actualTree is "outside" the diff and throws.

Two places fed it such nodes:

  • --workspaces=false and -w <ws> --include-workspace-root go through the includeRootDeps branch of _diffTrees(), which collected root-dep edge targets from both this.idealTree and this.actualTree. The actual-side targets are rooted at the real actual tree, not the wrapper, so they tripped the guard. The sibling includeWorkspaces branch already accounted for this; the root-dep branch did not.

  • A global install with a per-call installStrategy: 'linked' re-engaged the linked path even though the constructor normalizes global installs to shallow (the linked layout is unsupported for globals). Re-installing an already-present global package then hit the global explicit-request branch, which pushes actual-side nodes, and tripped the same guard. Suppressing the crash there was worse: the isolated reifier does not materialize the global layout and removed the package instead.

How

_diffTrees() now iterates only the ideal tree for root-dep filter nodes when the linked wrapper is in use, matching the existing workspace-node handling. The ideal-side nodes are sufficient to scope the diff, and the post-reify orphan sweep continues to prune deps removed from the manifest.

reify() now honors the constructor's global-to-shallow normalization when deriving the linked flag, so a global install never engages the linked path regardless of a per-call installStrategy. Global installs fall back to shallow, which materializes and upgrades packages correctly. No change to the global explicit-request branch is needed once global is never linked.

References

Fixes#9614
Part of #9608

Under the linked strategy the diff's actual side is a synthesized wrapper tree. When includeRootDeps was active (--workspaces=false or -w <ws> --include-workspace-root), the root-dep filter nodes were pulled from this.actualTree, whose root is the real actual tree rather than the wrapper, tripping Diff.calculate's invalid filterNode guard. Use only the ideal-side root-dep targets when the linked wrapper is in use, matching the existing workspace-node handling.
Global installs are normalized to the shallow strategy in the Arborist constructor, but reify() re-derived the linked flag from the raw per-call installStrategy option, bypassing that normalization. A global install passed installStrategy:'linked' would engage the unsupported linked path: re-installing an already-present global package tripped Diff.calculate's invalid filterNode guard, and once the guard was bypassed the isolated reifier deleted the global package instead of materializing it. Honor the global-to-shallow normalization in reify() so global installs never use the linked strategy.
@manzoorwanijk
manzoorwanijk marked this pull request as ready for review June 24, 2026 16:59
@manzoorwanijk
manzoorwanijk requested review from a team as code ownersJune 24, 2026 16:59
@owlstronaut
owlstronaut merged commit 2b976b5 into npm:latestJun 24, 2026
25 checks passed
@manzoorwanijk
manzoorwanijk deleted the fix/linked-filternode-workspace-filters branch June 24, 2026 18:40
@github-actions

Copy link
Copy Markdown
Contributor

🎉 Backport to release/v11 created: #9645

@github-actionsgithub-actionsBot mentioned this pull request Jun 24, 2026
owlstronaut pushed a commit that referenced this pull request Jun 24, 2026
)
Backport of #9637 to `release/v11`.
Co-authored-by: Manzoor Wani <manzoorwani.jk@gmail.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] install-strategy=linked: --workspaces=false and --include-workspace-root fail with invalid filterNode

2 participants

@manzoorwanijk@owlstronaut