Skip to content

fix: Make npm prune rehoisting deterministic and complete - #13323

Merged
anthonyshew merged 1 commit into
mainfrom
shew/fix-npm-prune-rehoist-determinism
Jul 9, 2026
Merged

anthonyshew merged 1 commit into
mainfrom
shew/fix-npm-prune-rehoist-determinism

Conversation

@anthonyshew

Copy link
Copy Markdown
Contributor

Why

Fixes #13321. turbo prune on npm lockfiles could nondeterministically drop packages from the pruned lockfile, producing Docker images that fail at runtime with errors like Cannot find module 'http-errors'.

What

In rehoist_packages, promotion candidates come from HashMap iteration and were processed in random order, with relocate_stranded_closure running interleaved after each promotion. A relocation could copy a sibling package to the root slot and remove its nested source; if that sibling was itself a still-queued promotion candidate, its turn would then remove the root entry and find nothing left to promote — silently dropping the package.

How

  • Split rehoist_packages into two phases: perform all promotions first, then run stranded-closure relocation for each promoted package. A relocation can no longer consume the nested source of a pending promotion.
  • Sort the candidate list so relocation placement decisions don't depend on hash ordering — pruned output is now byte-identical across runs.

Testing

  • Unit test test_subgraph_rehoist_is_deterministic_and_complete replicates the issue's lockfile shape, runs the prune 32 times, and asserts the promoted package's deps survive and output is byte-stable. It fails reliably on the pre-fix code.
  • New lockfile-tests/fixtures/issue-13321 fixture (real npm@11.7.0 lockfile): app-1 depends on send@0.19.0 (tree hoisted at root), app-2 on send@1.2.1 (six conflicting deps nested under the workspace). Pruning to app-2 makes all six nested entries rehoist candidates. Verified the harness fails on a pre-fix binary (npm ls reports unresolvable deps) and passes post-fix; the full --pm npm suite (35 cases) passes.

Note: root-workspace devDependencies can't reproduce this — they're part of the prune closure, so their hoisted entries are protected from rehoisting. The stale hoisted copies must belong to a pruned-away workspace, hence the two-app fixture layout.

@anthonyshew
anthonyshew requested a review from a team as a code owner July 9, 2026 14:37
@anthonyshew
anthonyshew requested review from tknickman and removed request for a team July 9, 2026 14:37
@vercel

vercel Bot commented Jul 9, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
examples-basic-web Ready Ready Preview, Comment, Open in v0 Jul 9, 2026 2:38pm
examples-designsystem-docs Ready Ready Preview, Comment, Open in v0 Jul 9, 2026 2:38pm
examples-gatsby-web Ready Ready Preview, Comment, Open in v0 Jul 9, 2026 2:38pm
examples-kitchensink-blog Ready Ready Preview, Comment, Open in v0 Jul 9, 2026 2:38pm
examples-nonmonorepo Ready Ready Preview, Comment, Open in v0 Jul 9, 2026 2:38pm
examples-svelte-web Ready Ready Preview, Comment, Open in v0 Jul 9, 2026 2:38pm
examples-tailwind-web Ready Ready Preview, Comment, Open in v0 Jul 9, 2026 2:38pm
examples-vite-web Ready Ready Preview, Comment, Open in v0 Jul 9, 2026 2:38pm
turbo-site Ready Ready Preview, Comment, Open in v0 Jul 9, 2026 2:38pm
turborepo-eve-agent Ready Ready Preview, Comment, Open in v0 Jul 9, 2026 2:38pm

@anthonyshew
anthonyshew merged commit 2dac737 into main Jul 9, 2026
42 checks passed
@anthonyshew
anthonyshew deleted the shew/fix-npm-prune-rehoist-determinism branch July 9, 2026 23:29
anthonyshew pushed a commit that referenced this pull request Jul 10, 2026
## Release v2.10.5-canary.5

> [!CAUTION]
> Versioned docs aliasing FAILED. [View
logs](https://github.com/vercel/turborepo/actions/runs/29092745941)

### Changes

- release(turborepo): 2.10.5-canary.4 (#13325) (`6626261`)
- feat: Run the Rust workspace tests through nextest via command
override (#13316) (`6711bbc`)
- feat: Engage the Remote Cache and sccache compile cache for Rust CI
(#13292) (`1ae2065`)
- ci: Pin GitHub Actions to full commit SHAs (#13143) (`ad614d6`)
- fix: Make npm prune rehoisting deterministic and complete (#13323)
(`2dac737`)
- feat: Report incremental cache reuse in the run summary (#13327)
(`9f3d24a`)
- chore: Remove planning docs (#13329) (`5cd1d02`)
- docs: Migrate docs site to @vercel/geistdocs package (#13320)
(`5517bb2`)
- ci: Update Remote Cache action (#13330) (`4a39887`)

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
anthonyshew pushed a commit that referenced this pull request Jul 13, 2026
## Release v2.10.5

> [!CAUTION]
> Versioned docs aliasing FAILED. [View
logs](https://github.com/vercel/turborepo/actions/runs/29267191097)

### Changes

- perf: Evaluate simple include globs without wax compilation (#13285)
(`189897a`)
- chore: Dogfood native Cargo support in this repository (#13283)
(`42f067b`)
- release(turborepo): 2.10.4 (#13286) (`f2fce38`)
- ci: Remove dead sccache configuration (#13289) (`558df3f`)
- feat: Serve the Remote Cache as an sccache backend for Cargo tasks
(#13288) (`0d9803f`)
- fix: Reject output path traversal (#13290) (`733ccca`)
- fix: Disable the sccache proxy when remote cache use is off (#13291)
(`3249e22`)
- feat: Embed sccache so the Cargo compile cache needs no installation
(#13293) (`b6d0035`)
- release(turborepo): 2.10.5-canary.1 (#13294) (`e6cd498`)
- fix: Pin a flag-aware turbo canary for the eve-agent deployment
(#13295) (`e60a4bd`)
- fix: Make the sccache compile cache actually cache (#13296)
(`2ac099c`)
- release(turborepo): 2.10.5-canary.2 (#13297) (`e6e6fb6`)
- fix: Stop ambient CARGO_INCREMENTAL from suppressing compile cache
injection (#13298) (`784af75`)
- fix: Never let compile cache storage failures fail the build (#13299)
(`a6fc6c5`)
- test: Add outputs path-traversal negative-case regression tests
(#13300) (`2ff6df9`)
- release(turborepo): 2.10.5-canary.3 (#13302) (`7e44a29`)
- ci: Authenticate to Remote Cache via OIDC token exchange (#13303)
(`a86839c`)
- fix: Keep pnpm patches with version range keys during prune (#13307)
(`3c27a89`)
- test: Scrub ambient turbo configuration from integration test children
(#13306) (`b03d0d6`)
- fix: Show toolchain tasks in the TUI and never run in silence (#13308)
(`d7622b6`)
- ci: Fix change detection on push events (#13304) (`eec3d61`)
- refactor: Rename the Cargo toolchain id to rust (#13311) (`a548b02`)
- fix: Remove extraneous bun.lock entries during prune (#13317)
(`382e9f5`)
- feat: Require a user-declared name for the Cargo workspace package
(#13312) (`5f01746`)
- feat: Parse and validate the task command field (#13313) (`389ea49`)
- chore: Harden turbo-vsc to invoke turbo without a shell (#13319)
(`4a19b6e`)
- feat: Resolve and execute task command overrides (#13315) (`a549baa`)
- release(turborepo): 2.10.5-canary.4 (#13325) (`6626261`)
- feat: Run the Rust workspace tests through nextest via command
override (#13316) (`6711bbc`)
- feat: Engage the Remote Cache and sccache compile cache for Rust CI
(#13292) (`1ae2065`)
- ci: Pin GitHub Actions to full commit SHAs (#13143) (`ad614d6`)
- fix: Make npm prune rehoisting deterministic and complete (#13323)
(`2dac737`)
- feat: Report incremental cache reuse in the run summary (#13327)
(`9f3d24a`)
- chore: Remove planning docs (#13329) (`5cd1d02`)
- docs: Migrate docs site to @vercel/geistdocs package (#13320)
(`5517bb2`)
- ci: Update Remote Cache action (#13330) (`4a39887`)
- release(turborepo): 2.10.5-canary.5 (#13331) (`f699719`)
- ci: Remove path-based workflow scheduling (#13332) (`84f2b2c`)
- fix: Resolve EADDRINUSE in kitchen-sink api dev script (#13328)
(`5886c71`)
- ci: Disable telemetry messages in workflows (#13334) (`2218dea`)
- fix: Prevent Cargo run tasks from being cached (#13335) (`68f449b`)
- fix: Isolate Cargo cache by host platform (#13337) (`c71f5cd`)
- fix: Continue TUI text selection beyond viewport (#13338) (`9cbfd90`)
- ci: Dogfood Cargo target restoration (#13336) (`8ad90a7`)
- fix: Require current Cargo lockfiles for caching (#13339) (`3a3d381`)
- fix: Reject unsupported Cargo local packages (#13340) (`708d656`)
- fix: Allow outputs outside package roots (#13342) (`de6a0d3`)
- fix: Resolve Cargo lock dependencies by source (#13343) (`2223a33`)
- docs: Update Cargo workspace support (#13349) (`241ada8`)
- fix: Build Ghostty for baseline CPUs (#13352) (`a2a04cc`)
- fix: Preserve watch rerun semantics for task inputs (#13351)
(`6ed5eab`)
- fix: Isolate Command Overrides From Toolchain Cache I/O (#13354)
(`e76f0b4`)
- release(turborepo): 2.10.5-canary.6 (#13355) (`f82e2c7`)
- fix: Include patched Ghostty crate in Cargo workspace (#13357)
(`b3cd7a1`)
- ci: Shard Rust tests across runners (#13356) (`ef122d9`)
- fix: Hash Cargo build environment inputs (#13348) (`d533266`)
- fix: Synchronize Cargo prune Docker lockfile (#13350) (`ed17249`)
- chore: Update agents app Eve dependency (#13364) (`38aa7d2`)
- fix: Preserve Yarn package extension ranges when pruning (#13363)
(`6ed2fb4`)
- refactor: Add `Toolchain` output availability (#13360) (`82bcfb6`)

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>

This branch was successfully deployed

1 active deployment
Preview – turborepo-eve-agent 2339dce7 Deployed Jul 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

turbo prune nondeterministic npm rehoist

2 participants