Skip to content

acp: Allow resolving older npm package versions - #55770

Merged
benbrandt merged 2 commits into
mainfrom
npm-fallback
May 5, 2026
Merged

acp: Allow resolving older npm package versions#55770
benbrandt merged 2 commits into
mainfrom
npm-fallback

Conversation

@benbrandt

@benbrandt benbrandt commented May 5, 2026

Copy link
Copy Markdown
Member

Lots of people are using min-release-age in their .npmrc files these days.

I saw two options:

  1. Force min-release-age=0 so we can always install the latest
  2. Be more lenient in what we allow

I opted for 2, which means we convert package@0.1.2 to package@<=0.1.2. This means npm can find the latest version we can that meets the user's requirements.

The downside is, the registry args/env may or may not work with the resolved version, but that should at least surface better thanks to #55757

There is also the issue that npm will cache package metadata and an older version it has cached would still resolve. However, once the metadata is updated, npm does use the newer tarball at least, so it will update eventually.

It's a tradeoff, but I'd rather start with this until we have a better solution on the ACP registry, rather than have users be upset becaue we installed packages in a way they didn't want.

Self-Review Checklist:

  • I've reviewed my own diff for quality, security, and reliability
  • Unsafe blocks (if any) have justifying comments
  • The content is consistent with the UI/UX checklist
  • Tests cover the new/changed behavior
  • Performance impact has been considered and is acceptable

Closes agentclientprotocol/claude-agent-acp#516

Release Notes:

  • acp: Better support min-release-age settings for npx-based agents from the registry

benbrandt added 2 commits May 5, 2026 15:21
Replace fallback command retries with bounded npm package specs when
building local registry agent commands, and remove the unused fallback
command path from ACP and proto APIs.
@cla-bot cla-bot Bot added the cla-signed The user has signed the Contributor License Agreement label May 5, 2026
@zed-community-bot zed-community-bot Bot added the staff Pull requests authored by a current member of Zed staff label May 5, 2026
@benbrandt
benbrandt requested a review from bennetbo May 5, 2026 13:50
@benbrandt
benbrandt enabled auto-merge May 5, 2026 13:58
@benbrandt

Copy link
Copy Markdown
Member Author

/cherry-pick preview

@benbrandt
benbrandt added this pull request to the merge queue May 5, 2026
Merged via the queue into main with commit cdbab19 May 5, 2026
42 checks passed
@benbrandt
benbrandt deleted the npm-fallback branch May 5, 2026 14:17
@zed-zippy

zed-zippy Bot commented May 5, 2026

Copy link
Copy Markdown
Contributor

github-actions Bot pushed a commit that referenced this pull request May 5, 2026
Lots of people are using `min-release-age` in their .npmrc files these
days.

I saw two options:

1. Force min-release-age=0 so we can always install the latest
2. Be more lenient in what we allow

I opted for 2, which means we convert `package@0.1.2` to
`package@<=0.1.2`. This means npm can find the latest version we can
that meets the user's requirements.

The downside is, the registry args/env may or may not work with the
resolved version, but that should at least surface better thanks to
#55757

There is also the issue that npm will cache package metadata and an
older version it has cached would still resolve. However, once the
metadata is updated, npm does use the newer tarball at least, so it will
update eventually.

It's a tradeoff, but I'd rather start with this until we have a better
solution on the ACP registry, rather than have users be upset becaue we
installed packages in a way they didn't want.

Self-Review Checklist:

- [x] I've reviewed my own diff for quality, security, and reliability
- [x] Unsafe blocks (if any) have justifying comments
- [x] The content is consistent with the [UI/UX
checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist)
- [x] Tests cover the new/changed behavior
- [x] Performance impact has been considered and is acceptable

Closes
agentclientprotocol/claude-agent-acp#516

Release Notes:

- acp: Better support min-release-age settings for npx-based agents from
the registry
zed-zippy Bot added a commit that referenced this pull request May 5, 2026
… to preview) (#55775)

Cherry-pick of #55770 to preview

----
Lots of people are using `min-release-age` in their .npmrc files these
days.

I saw two options:

1. Force min-release-age=0 so we can always install the latest
2. Be more lenient in what we allow

I opted for 2, which means we convert `package@0.1.2` to
`package@<=0.1.2`. This means npm can find the latest version we can
that meets the user's requirements.

The downside is, the registry args/env may or may not work with the
resolved version, but that should at least surface better thanks to
#55757

There is also the issue that npm will cache package metadata and an
older version it has cached would still resolve. However, once the
metadata is updated, npm does use the newer tarball at least, so it will
update eventually.

It's a tradeoff, but I'd rather start with this until we have a better
solution on the ACP registry, rather than have users be upset becaue we
installed packages in a way they didn't want.

Self-Review Checklist:

- [x] I've reviewed my own diff for quality, security, and reliability
- [x] Unsafe blocks (if any) have justifying comments
- [x] The content is consistent with the [UI/UX

checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist)
- [x] Tests cover the new/changed behavior
- [x] Performance impact has been considered and is acceptable

Closes
agentclientprotocol/claude-agent-acp#516

Release Notes:

- acp: Better support min-release-age settings for npx-based agents from
the registry

Co-authored-by: Ben Brandt <benjamin.j.brandt@gmail.com>
ebaah46 pushed a commit to ebaah46/zed that referenced this pull request May 6, 2026
Lots of people are using `min-release-age` in their .npmrc files these
days.

I saw two options:

1. Force min-release-age=0 so we can always install the latest
2. Be more lenient in what we allow

I opted for 2, which means we convert `package@0.1.2` to
`package@<=0.1.2`. This means npm can find the latest version we can
that meets the user's requirements.

The downside is, the registry args/env may or may not work with the
resolved version, but that should at least surface better thanks to
zed-industries#55757

There is also the issue that npm will cache package metadata and an
older version it has cached would still resolve. However, once the
metadata is updated, npm does use the newer tarball at least, so it will
update eventually.

It's a tradeoff, but I'd rather start with this until we have a better
solution on the ACP registry, rather than have users be upset becaue we
installed packages in a way they didn't want.

Self-Review Checklist:

- [x] I've reviewed my own diff for quality, security, and reliability
- [x] Unsafe blocks (if any) have justifying comments
- [x] The content is consistent with the [UI/UX
checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist)
- [x] Tests cover the new/changed behavior
- [x] Performance impact has been considered and is acceptable

Closes
agentclientprotocol/claude-agent-acp#516

Release Notes:

- acp: Better support min-release-age settings for npx-based agents from
the registry
@Qard

Qard commented May 6, 2026

Copy link
Copy Markdown
Contributor

@benbrandt I noticed the github copilot plugin also has the same issue. Perhaps the solution could be made more generic to fix that too?

github-merge-queue Bot pushed a commit that referenced this pull request May 6, 2026
Self-Review Checklist:

- [x] I've reviewed my own diff for quality, security, and reliability
- [x] Unsafe blocks (if any) have justifying comments
- [x] The content is consistent with the [UI/UX
checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist)
- [x] Tests cover the new/changed behavior
- [x] Performance impact has been considered and is acceptable

#55770 changed the npm package version spec to `package@<=1.2.3`. On
Windows this fails with `The system cannot find the file specified.`
because:

- `npm` resolves to `npm.cmd`, a batch file. Windows runs `.cmd` files
via cmd.exe, which parses the invocation and treats unquoted `<` as
input redirection.
- The single quotes our shell builder emits around args are PowerShell
string-literal syntax that PS strips during parsing. PS only re-adds
CRT-style transport quotes around native command args containing
whitespace, so `package@<=0.25.3` reaches `npm.cmd` bare and cmd.exe
fails before the batch body even runs.

Switch to npm's hyphen-range syntax (`0.0.0 - <version>`, equivalent to
`<=<version>`), which has no `<`.

Closes #55921

Release Notes:

- Fixed ACP agents failing to launch on Windows with "The system cannot
find the file specified"
zed-zippy Bot added a commit that referenced this pull request May 6, 2026
…o stable) (#55947)

Cherry-pick of #55938 to stable

----
Self-Review Checklist:

- [x] I've reviewed my own diff for quality, security, and reliability
- [x] Unsafe blocks (if any) have justifying comments
- [x] The content is consistent with the [UI/UX

checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist)
- [x] Tests cover the new/changed behavior
- [x] Performance impact has been considered and is acceptable

#55770 changed the npm package version spec to `package@<=1.2.3`. On
Windows this fails with `The system cannot find the file specified.`
because:

- `npm` resolves to `npm.cmd`, a batch file. Windows runs `.cmd` files
via cmd.exe, which parses the invocation and treats unquoted `<` as
input redirection.
- The single quotes our shell builder emits around args are PowerShell
string-literal syntax that PS strips during parsing. PS only re-adds
CRT-style transport quotes around native command args containing
whitespace, so `package@<=0.25.3` reaches `npm.cmd` bare and cmd.exe
fails before the batch body even runs.

Switch to npm's hyphen-range syntax (`0.0.0 - <version>`, equivalent to
`<=<version>`), which has no `<`.

Closes #55921

Release Notes:

- Fixed ACP agents failing to launch on Windows with "The system cannot
find the file specified"

Co-authored-by: Agus Zubiaga <agus@zed.dev>
zed-zippy Bot added a commit that referenced this pull request May 6, 2026
…o preview) (#55946)

Cherry-pick of #55938 to preview

----
Self-Review Checklist:

- [x] I've reviewed my own diff for quality, security, and reliability
- [x] Unsafe blocks (if any) have justifying comments
- [x] The content is consistent with the [UI/UX

checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist)
- [x] Tests cover the new/changed behavior
- [x] Performance impact has been considered and is acceptable

#55770 changed the npm package version spec to `package@<=1.2.3`. On
Windows this fails with `The system cannot find the file specified.`
because:

- `npm` resolves to `npm.cmd`, a batch file. Windows runs `.cmd` files
via cmd.exe, which parses the invocation and treats unquoted `<` as
input redirection.
- The single quotes our shell builder emits around args are PowerShell
string-literal syntax that PS strips during parsing. PS only re-adds
CRT-style transport quotes around native command args containing
whitespace, so `package@<=0.25.3` reaches `npm.cmd` bare and cmd.exe
fails before the batch body even runs.

Switch to npm's hyphen-range syntax (`0.0.0 - <version>`, equivalent to
`<=<version>`), which has no `<`.

Closes #55921

Release Notes:

- Fixed ACP agents failing to launch on Windows with "The system cannot
find the file specified"

Co-authored-by: Agus Zubiaga <agus@zed.dev>
ubunatic pushed a commit to ubunatic/zed that referenced this pull request May 16, 2026
Self-Review Checklist:

- [x] I've reviewed my own diff for quality, security, and reliability
- [x] Unsafe blocks (if any) have justifying comments
- [x] The content is consistent with the [UI/UX
checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist)
- [x] Tests cover the new/changed behavior
- [x] Performance impact has been considered and is acceptable

zed-industries#55770 changed the npm package version spec to `package@<=1.2.3`. On
Windows this fails with `The system cannot find the file specified.`
because:

- `npm` resolves to `npm.cmd`, a batch file. Windows runs `.cmd` files
via cmd.exe, which parses the invocation and treats unquoted `<` as
input redirection.
- The single quotes our shell builder emits around args are PowerShell
string-literal syntax that PS strips during parsing. PS only re-adds
CRT-style transport quotes around native command args containing
whitespace, so `package@<=0.25.3` reaches `npm.cmd` bare and cmd.exe
fails before the batch body even runs.

Switch to npm's hyphen-range syntax (`0.0.0 - <version>`, equivalent to
`<=<version>`), which has no `<`.

Closes zed-industries#55921

Release Notes:

- Fixed ACP agents failing to launch on Windows with "The system cannot
find the file specified"
jonx pushed a commit to jonx/zed-aros that referenced this pull request Jul 17, 2026
Lots of people are using `min-release-age` in their .npmrc files these
days.

I saw two options:

1. Force min-release-age=0 so we can always install the latest
2. Be more lenient in what we allow

I opted for 2, which means we convert `package@0.1.2` to
`package@<=0.1.2`. This means npm can find the latest version we can
that meets the user's requirements.

The downside is, the registry args/env may or may not work with the
resolved version, but that should at least surface better thanks to
zed-industries#55757

There is also the issue that npm will cache package metadata and an
older version it has cached would still resolve. However, once the
metadata is updated, npm does use the newer tarball at least, so it will
update eventually.

It's a tradeoff, but I'd rather start with this until we have a better
solution on the ACP registry, rather than have users be upset becaue we
installed packages in a way they didn't want.

Self-Review Checklist:

- [x] I've reviewed my own diff for quality, security, and reliability
- [x] Unsafe blocks (if any) have justifying comments
- [x] The content is consistent with the [UI/UX
checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist)
- [x] Tests cover the new/changed behavior
- [x] Performance impact has been considered and is acceptable

Closes
agentclientprotocol/claude-agent-acp#516

Release Notes:

- acp: Better support min-release-age settings for npx-based agents from
the registry
jonx pushed a commit to jonx/zed-aros that referenced this pull request Jul 17, 2026
Self-Review Checklist:

- [x] I've reviewed my own diff for quality, security, and reliability
- [x] Unsafe blocks (if any) have justifying comments
- [x] The content is consistent with the [UI/UX
checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist)
- [x] Tests cover the new/changed behavior
- [x] Performance impact has been considered and is acceptable

zed-industries#55770 changed the npm package version spec to `package@<=1.2.3`. On
Windows this fails with `The system cannot find the file specified.`
because:

- `npm` resolves to `npm.cmd`, a batch file. Windows runs `.cmd` files
via cmd.exe, which parses the invocation and treats unquoted `<` as
input redirection.
- The single quotes our shell builder emits around args are PowerShell
string-literal syntax that PS strips during parsing. PS only re-adds
CRT-style transport quotes around native command args containing
whitespace, so `package@<=0.25.3` reaches `npm.cmd` bare and cmd.exe
fails before the batch body even runs.

Switch to npm's hyphen-range syntax (`0.0.0 - <version>`, equivalent to
`<=<version>`), which has no `<`.

Closes zed-industries#55921

Release Notes:

- Fixed ACP agents failing to launch on Windows with "The system cannot
find the file specified"
jolutz pushed a commit to jolutz/zed that referenced this pull request Aug 8, 2026
Lots of people are using `min-release-age` in their .npmrc files these
days.

I saw two options:

1. Force min-release-age=0 so we can always install the latest
2. Be more lenient in what we allow

I opted for 2, which means we convert `package@0.1.2` to
`package@<=0.1.2`. This means npm can find the latest version we can
that meets the user's requirements.

The downside is, the registry args/env may or may not work with the
resolved version, but that should at least surface better thanks to
zed-industries#55757

There is also the issue that npm will cache package metadata and an
older version it has cached would still resolve. However, once the
metadata is updated, npm does use the newer tarball at least, so it will
update eventually.

It's a tradeoff, but I'd rather start with this until we have a better
solution on the ACP registry, rather than have users be upset becaue we
installed packages in a way they didn't want.

Self-Review Checklist:

- [x] I've reviewed my own diff for quality, security, and reliability
- [x] Unsafe blocks (if any) have justifying comments
- [x] The content is consistent with the [UI/UX
checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist)
- [x] Tests cover the new/changed behavior
- [x] Performance impact has been considered and is acceptable

Closes
agentclientprotocol/claude-agent-acp#516

Release Notes:

- acp: Better support min-release-age settings for npx-based agents from
the registry
jolutz pushed a commit to jolutz/zed that referenced this pull request Aug 8, 2026
Self-Review Checklist:

- [x] I've reviewed my own diff for quality, security, and reliability
- [x] Unsafe blocks (if any) have justifying comments
- [x] The content is consistent with the [UI/UX
checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist)
- [x] Tests cover the new/changed behavior
- [x] Performance impact has been considered and is acceptable

zed-industries#55770 changed the npm package version spec to `package@<=1.2.3`. On
Windows this fails with `The system cannot find the file specified.`
because:

- `npm` resolves to `npm.cmd`, a batch file. Windows runs `.cmd` files
via cmd.exe, which parses the invocation and treats unquoted `<` as
input redirection.
- The single quotes our shell builder emits around args are PowerShell
string-literal syntax that PS strips during parsing. PS only re-adds
CRT-style transport quotes around native command args containing
whitespace, so `package@<=0.25.3` reaches `npm.cmd` bare and cmd.exe
fails before the batch body even runs.

Switch to npm's hyphen-range syntax (`0.0.0 - <version>`, equivalent to
`<=<version>`), which has no `<`.

Closes zed-industries#55921

Release Notes:

- Fixed ACP agents failing to launch on Windows with "The system cannot
find the file specified"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cla-signed The user has signed the Contributor License Agreement staff Pull requests authored by a current member of Zed staff

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Failed to Launch - Internal error: "server shut down unexpectedly"

3 participants