fix(deploy): export HOME before writing the registry .npmrc #503

Merged
gmackie merged 1 commit from fix/registry-npmrc-home into main 2026-08-27 21:29:44 +00:00
Owner

Main is red and it is my fault. #499's registry-auth block does not work:

ERR_PNPM_FETCH_401  GET https://npm.forgegraf.com/@preflight/runreport/-/runreport-0.1.0.tgz: Unauthorized - 401

(Deploy ForgeGraf / test, tasks 24652 / 24665 / 24667)

The token is not missing — FG_REGISTRY_TOKEN exists as a repo Actions secret and the step declares it. The block writes to "$HOME/.npmrc" in steps that never export HOME. This same workflow's other steps already carry the fix and even explain it: # unset in runner host jobs. With HOME empty the token lands in /.npmrc while pnpm resolves config against the passwd home, so the write succeeds and the auth never applies.

Worse, it fails silently: the [ -n "${FG_REGISTRY_TOKEN:-}" ] guard passes, so the ::warning::FG_REGISTRY_TOKEN unset branch never fires. Nothing in the log says the token was dropped — only the 401 downstream.

Adds the same export HOME="${HOME:-$(getent passwd "$(id -u)" | cut -d: -f6)}" line the sibling steps use, before all three auth blocks (both installs in deploy.yml, one in deploy-staging.yml). Verified HOME precedes the .npmrc write at every site and both files still parse.

Why the deploy job passed while test failed

Deploy ForgeGraf / deploy succeeded on the same commit. Its runner's pnpm store was warm, so the tarball fetch never happened. That masks the bug rather than avoiding it — the next cold deploy hits the same 401, and deploy.yml's own rm -rf node_modules guarantees a cold install eventually.

Unrelated, worth knowing

@preflight/runreport@0.1.1 is now published (preflight-app #22), fixing the ESM defect where the published dist used extensionless specifiers Node cannot resolve. Main's lockfile still pins 0.1.0; the ^0.1.0 range permits 0.1.1, so a relock picks it up. Not urgent — the OpenNext build tolerated 0.1.0 — but it removes a latent failure that only bites where the real ESM resolver is used.

**Main is red and it is my fault.** #499's registry-auth block does not work: ``` ERR_PNPM_FETCH_401 GET https://npm.forgegraf.com/@preflight/runreport/-/runreport-0.1.0.tgz: Unauthorized - 401 ``` (`Deploy ForgeGraf / test`, tasks 24652 / 24665 / 24667) The token is not missing — `FG_REGISTRY_TOKEN` exists as a repo Actions secret and the step declares it. The block writes to `"$HOME/.npmrc"` in steps that **never export HOME**. This same workflow's other steps already carry the fix and even explain it: `# unset in runner host jobs`. With HOME empty the token lands in `/.npmrc` while pnpm resolves config against the passwd home, so the write succeeds and the auth never applies. Worse, it fails *silently*: the `[ -n "${FG_REGISTRY_TOKEN:-}" ]` guard passes, so the `::warning::FG_REGISTRY_TOKEN unset` branch never fires. Nothing in the log says the token was dropped — only the 401 downstream. Adds the same `export HOME="${HOME:-$(getent passwd "$(id -u)" | cut -d: -f6)}"` line the sibling steps use, before all three auth blocks (both installs in `deploy.yml`, one in `deploy-staging.yml`). Verified HOME precedes the `.npmrc` write at every site and both files still parse. ### Why the deploy job passed while test failed `Deploy ForgeGraf / deploy` succeeded on the same commit. Its runner's pnpm store was warm, so the tarball fetch never happened. That masks the bug rather than avoiding it — the next cold deploy hits the same 401, and `deploy.yml`'s own `rm -rf node_modules` guarantees a cold install eventually. ### Unrelated, worth knowing `@preflight/runreport@0.1.1` is now published (preflight-app #22), fixing the ESM defect where the published `dist` used extensionless specifiers Node cannot resolve. Main's lockfile still pins `0.1.0`; the `^0.1.0` range permits 0.1.1, so a relock picks it up. Not urgent — the OpenNext build tolerated 0.1.0 — but it removes a latent failure that only bites where the real ESM resolver is used.
fix(deploy): export HOME before writing the registry .npmrc
All checks were successful
CI / gitleaks (pull_request) Successful in 6s
CI / storybook (pull_request) Successful in 2m13s
forgegraph/ci CI passed
CI / ci (pull_request) Successful in 9m44s
80ad8a39b2
My registry-auth fix (#499) does not work, and main is red because of it:

    ERR_PNPM_FETCH_401  GET https://npm.forgegraf.com/@preflight/runreport/
    -/runreport-0.1.0.tgz: Unauthorized - 401

The token is present — FG_REGISTRY_TOKEN exists as a repo Actions secret and
the step declares it — but the block writes to "$HOME/.npmrc" in steps that
never export HOME. This workflow's other steps already carry the fix and say
why: "unset in runner host jobs". With HOME empty the token lands in /.npmrc
while pnpm resolves its config against the passwd home, so the write succeeds
and the auth still never applies. The `-n "${FG_REGISTRY_TOKEN:-}"` guard
passes, so nothing warns either — it fails silently and then 401s.

Adds the same `export HOME="${HOME:-$(getent passwd "$(id -u)" | cut -d: -f6)}"`
line the sibling steps use, before all three auth blocks: both installs in
deploy.yml and the one in deploy-staging.yml.

Verified HOME is exported before the .npmrc write at every site, and both
files still parse as YAML.

Note the deploy job itself passed while `test` failed — the deploy runner's
pnpm store was warm, so the tarball fetch never happened there. That masks the
bug rather than avoiding it: the next cold deploy would hit the same 401.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
gmackie/ForgeGraph!503
No description provided.