acp: Allow resolving older npm package versions - #55770
Merged
Merged
Conversation
Replace fallback command retries with bounded npm package specs when building local registry agent commands, and remove the unused fallback command path from ACP and proto APIs.
bennetbo
approved these changes
May 5, 2026
benbrandt
enabled auto-merge
May 5, 2026 13:58
Member
Author
|
/cherry-pick preview |
Contributor
|
🍒💥 Cherry-pick did not succeed |
github-actions Bot
pushed a commit
that referenced
this pull request
May 5, 2026
Lots of people are using `min-release-age` in their .npmrc files these days. I saw two options: 1. Force min-release-age=0 so we can always install the latest 2. Be more lenient in what we allow I opted for 2, which means we convert `package@0.1.2` to `package@<=0.1.2`. This means npm can find the latest version we can that meets the user's requirements. The downside is, the registry args/env may or may not work with the resolved version, but that should at least surface better thanks to #55757 There is also the issue that npm will cache package metadata and an older version it has cached would still resolve. However, once the metadata is updated, npm does use the newer tarball at least, so it will update eventually. It's a tradeoff, but I'd rather start with this until we have a better solution on the ACP registry, rather than have users be upset becaue we installed packages in a way they didn't want. Self-Review Checklist: - [x] I've reviewed my own diff for quality, security, and reliability - [x] Unsafe blocks (if any) have justifying comments - [x] The content is consistent with the [UI/UX checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist) - [x] Tests cover the new/changed behavior - [x] Performance impact has been considered and is acceptable Closes agentclientprotocol/claude-agent-acp#516 Release Notes: - acp: Better support min-release-age settings for npx-based agents from the registry
5 tasks
zed-zippy Bot
added a commit
that referenced
this pull request
May 5, 2026
… to preview) (#55775) Cherry-pick of #55770 to preview ---- Lots of people are using `min-release-age` in their .npmrc files these days. I saw two options: 1. Force min-release-age=0 so we can always install the latest 2. Be more lenient in what we allow I opted for 2, which means we convert `package@0.1.2` to `package@<=0.1.2`. This means npm can find the latest version we can that meets the user's requirements. The downside is, the registry args/env may or may not work with the resolved version, but that should at least surface better thanks to #55757 There is also the issue that npm will cache package metadata and an older version it has cached would still resolve. However, once the metadata is updated, npm does use the newer tarball at least, so it will update eventually. It's a tradeoff, but I'd rather start with this until we have a better solution on the ACP registry, rather than have users be upset becaue we installed packages in a way they didn't want. Self-Review Checklist: - [x] I've reviewed my own diff for quality, security, and reliability - [x] Unsafe blocks (if any) have justifying comments - [x] The content is consistent with the [UI/UX checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist) - [x] Tests cover the new/changed behavior - [x] Performance impact has been considered and is acceptable Closes agentclientprotocol/claude-agent-acp#516 Release Notes: - acp: Better support min-release-age settings for npx-based agents from the registry Co-authored-by: Ben Brandt <benjamin.j.brandt@gmail.com>
ebaah46
pushed a commit
to ebaah46/zed
that referenced
this pull request
May 6, 2026
Lots of people are using `min-release-age` in their .npmrc files these days. I saw two options: 1. Force min-release-age=0 so we can always install the latest 2. Be more lenient in what we allow I opted for 2, which means we convert `package@0.1.2` to `package@<=0.1.2`. This means npm can find the latest version we can that meets the user's requirements. The downside is, the registry args/env may or may not work with the resolved version, but that should at least surface better thanks to zed-industries#55757 There is also the issue that npm will cache package metadata and an older version it has cached would still resolve. However, once the metadata is updated, npm does use the newer tarball at least, so it will update eventually. It's a tradeoff, but I'd rather start with this until we have a better solution on the ACP registry, rather than have users be upset becaue we installed packages in a way they didn't want. Self-Review Checklist: - [x] I've reviewed my own diff for quality, security, and reliability - [x] Unsafe blocks (if any) have justifying comments - [x] The content is consistent with the [UI/UX checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist) - [x] Tests cover the new/changed behavior - [x] Performance impact has been considered and is acceptable Closes agentclientprotocol/claude-agent-acp#516 Release Notes: - acp: Better support min-release-age settings for npx-based agents from the registry
Contributor
|
@benbrandt I noticed the github copilot plugin also has the same issue. Perhaps the solution could be made more generic to fix that too? |
This was referenced May 6, 2026
github-merge-queue Bot
pushed a commit
that referenced
this pull request
May 6, 2026
Self-Review Checklist: - [x] I've reviewed my own diff for quality, security, and reliability - [x] Unsafe blocks (if any) have justifying comments - [x] The content is consistent with the [UI/UX checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist) - [x] Tests cover the new/changed behavior - [x] Performance impact has been considered and is acceptable #55770 changed the npm package version spec to `package@<=1.2.3`. On Windows this fails with `The system cannot find the file specified.` because: - `npm` resolves to `npm.cmd`, a batch file. Windows runs `.cmd` files via cmd.exe, which parses the invocation and treats unquoted `<` as input redirection. - The single quotes our shell builder emits around args are PowerShell string-literal syntax that PS strips during parsing. PS only re-adds CRT-style transport quotes around native command args containing whitespace, so `package@<=0.25.3` reaches `npm.cmd` bare and cmd.exe fails before the batch body even runs. Switch to npm's hyphen-range syntax (`0.0.0 - <version>`, equivalent to `<=<version>`), which has no `<`. Closes #55921 Release Notes: - Fixed ACP agents failing to launch on Windows with "The system cannot find the file specified"
This was referenced May 6, 2026
zed-zippy Bot
added a commit
that referenced
this pull request
May 6, 2026
…o stable) (#55947) Cherry-pick of #55938 to stable ---- Self-Review Checklist: - [x] I've reviewed my own diff for quality, security, and reliability - [x] Unsafe blocks (if any) have justifying comments - [x] The content is consistent with the [UI/UX checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist) - [x] Tests cover the new/changed behavior - [x] Performance impact has been considered and is acceptable #55770 changed the npm package version spec to `package@<=1.2.3`. On Windows this fails with `The system cannot find the file specified.` because: - `npm` resolves to `npm.cmd`, a batch file. Windows runs `.cmd` files via cmd.exe, which parses the invocation and treats unquoted `<` as input redirection. - The single quotes our shell builder emits around args are PowerShell string-literal syntax that PS strips during parsing. PS only re-adds CRT-style transport quotes around native command args containing whitespace, so `package@<=0.25.3` reaches `npm.cmd` bare and cmd.exe fails before the batch body even runs. Switch to npm's hyphen-range syntax (`0.0.0 - <version>`, equivalent to `<=<version>`), which has no `<`. Closes #55921 Release Notes: - Fixed ACP agents failing to launch on Windows with "The system cannot find the file specified" Co-authored-by: Agus Zubiaga <agus@zed.dev>
zed-zippy Bot
added a commit
that referenced
this pull request
May 6, 2026
…o preview) (#55946) Cherry-pick of #55938 to preview ---- Self-Review Checklist: - [x] I've reviewed my own diff for quality, security, and reliability - [x] Unsafe blocks (if any) have justifying comments - [x] The content is consistent with the [UI/UX checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist) - [x] Tests cover the new/changed behavior - [x] Performance impact has been considered and is acceptable #55770 changed the npm package version spec to `package@<=1.2.3`. On Windows this fails with `The system cannot find the file specified.` because: - `npm` resolves to `npm.cmd`, a batch file. Windows runs `.cmd` files via cmd.exe, which parses the invocation and treats unquoted `<` as input redirection. - The single quotes our shell builder emits around args are PowerShell string-literal syntax that PS strips during parsing. PS only re-adds CRT-style transport quotes around native command args containing whitespace, so `package@<=0.25.3` reaches `npm.cmd` bare and cmd.exe fails before the batch body even runs. Switch to npm's hyphen-range syntax (`0.0.0 - <version>`, equivalent to `<=<version>`), which has no `<`. Closes #55921 Release Notes: - Fixed ACP agents failing to launch on Windows with "The system cannot find the file specified" Co-authored-by: Agus Zubiaga <agus@zed.dev>
This was referenced May 8, 2026
ubunatic
pushed a commit
to ubunatic/zed
that referenced
this pull request
May 16, 2026
Self-Review Checklist: - [x] I've reviewed my own diff for quality, security, and reliability - [x] Unsafe blocks (if any) have justifying comments - [x] The content is consistent with the [UI/UX checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist) - [x] Tests cover the new/changed behavior - [x] Performance impact has been considered and is acceptable zed-industries#55770 changed the npm package version spec to `package@<=1.2.3`. On Windows this fails with `The system cannot find the file specified.` because: - `npm` resolves to `npm.cmd`, a batch file. Windows runs `.cmd` files via cmd.exe, which parses the invocation and treats unquoted `<` as input redirection. - The single quotes our shell builder emits around args are PowerShell string-literal syntax that PS strips during parsing. PS only re-adds CRT-style transport quotes around native command args containing whitespace, so `package@<=0.25.3` reaches `npm.cmd` bare and cmd.exe fails before the batch body even runs. Switch to npm's hyphen-range syntax (`0.0.0 - <version>`, equivalent to `<=<version>`), which has no `<`. Closes zed-industries#55921 Release Notes: - Fixed ACP agents failing to launch on Windows with "The system cannot find the file specified"
jonx
pushed a commit
to jonx/zed-aros
that referenced
this pull request
Jul 17, 2026
Lots of people are using `min-release-age` in their .npmrc files these days. I saw two options: 1. Force min-release-age=0 so we can always install the latest 2. Be more lenient in what we allow I opted for 2, which means we convert `package@0.1.2` to `package@<=0.1.2`. This means npm can find the latest version we can that meets the user's requirements. The downside is, the registry args/env may or may not work with the resolved version, but that should at least surface better thanks to zed-industries#55757 There is also the issue that npm will cache package metadata and an older version it has cached would still resolve. However, once the metadata is updated, npm does use the newer tarball at least, so it will update eventually. It's a tradeoff, but I'd rather start with this until we have a better solution on the ACP registry, rather than have users be upset becaue we installed packages in a way they didn't want. Self-Review Checklist: - [x] I've reviewed my own diff for quality, security, and reliability - [x] Unsafe blocks (if any) have justifying comments - [x] The content is consistent with the [UI/UX checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist) - [x] Tests cover the new/changed behavior - [x] Performance impact has been considered and is acceptable Closes agentclientprotocol/claude-agent-acp#516 Release Notes: - acp: Better support min-release-age settings for npx-based agents from the registry
jonx
pushed a commit
to jonx/zed-aros
that referenced
this pull request
Jul 17, 2026
Self-Review Checklist: - [x] I've reviewed my own diff for quality, security, and reliability - [x] Unsafe blocks (if any) have justifying comments - [x] The content is consistent with the [UI/UX checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist) - [x] Tests cover the new/changed behavior - [x] Performance impact has been considered and is acceptable zed-industries#55770 changed the npm package version spec to `package@<=1.2.3`. On Windows this fails with `The system cannot find the file specified.` because: - `npm` resolves to `npm.cmd`, a batch file. Windows runs `.cmd` files via cmd.exe, which parses the invocation and treats unquoted `<` as input redirection. - The single quotes our shell builder emits around args are PowerShell string-literal syntax that PS strips during parsing. PS only re-adds CRT-style transport quotes around native command args containing whitespace, so `package@<=0.25.3` reaches `npm.cmd` bare and cmd.exe fails before the batch body even runs. Switch to npm's hyphen-range syntax (`0.0.0 - <version>`, equivalent to `<=<version>`), which has no `<`. Closes zed-industries#55921 Release Notes: - Fixed ACP agents failing to launch on Windows with "The system cannot find the file specified"
jolutz
pushed a commit
to jolutz/zed
that referenced
this pull request
Aug 8, 2026
Lots of people are using `min-release-age` in their .npmrc files these days. I saw two options: 1. Force min-release-age=0 so we can always install the latest 2. Be more lenient in what we allow I opted for 2, which means we convert `package@0.1.2` to `package@<=0.1.2`. This means npm can find the latest version we can that meets the user's requirements. The downside is, the registry args/env may or may not work with the resolved version, but that should at least surface better thanks to zed-industries#55757 There is also the issue that npm will cache package metadata and an older version it has cached would still resolve. However, once the metadata is updated, npm does use the newer tarball at least, so it will update eventually. It's a tradeoff, but I'd rather start with this until we have a better solution on the ACP registry, rather than have users be upset becaue we installed packages in a way they didn't want. Self-Review Checklist: - [x] I've reviewed my own diff for quality, security, and reliability - [x] Unsafe blocks (if any) have justifying comments - [x] The content is consistent with the [UI/UX checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist) - [x] Tests cover the new/changed behavior - [x] Performance impact has been considered and is acceptable Closes agentclientprotocol/claude-agent-acp#516 Release Notes: - acp: Better support min-release-age settings for npx-based agents from the registry
jolutz
pushed a commit
to jolutz/zed
that referenced
this pull request
Aug 8, 2026
Self-Review Checklist: - [x] I've reviewed my own diff for quality, security, and reliability - [x] Unsafe blocks (if any) have justifying comments - [x] The content is consistent with the [UI/UX checklist](https://github.com/zed-industries/zed/blob/main/CONTRIBUTING.md#uiux-checklist) - [x] Tests cover the new/changed behavior - [x] Performance impact has been considered and is acceptable zed-industries#55770 changed the npm package version spec to `package@<=1.2.3`. On Windows this fails with `The system cannot find the file specified.` because: - `npm` resolves to `npm.cmd`, a batch file. Windows runs `.cmd` files via cmd.exe, which parses the invocation and treats unquoted `<` as input redirection. - The single quotes our shell builder emits around args are PowerShell string-literal syntax that PS strips during parsing. PS only re-adds CRT-style transport quotes around native command args containing whitespace, so `package@<=0.25.3` reaches `npm.cmd` bare and cmd.exe fails before the batch body even runs. Switch to npm's hyphen-range syntax (`0.0.0 - <version>`, equivalent to `<=<version>`), which has no `<`. Closes zed-industries#55921 Release Notes: - Fixed ACP agents failing to launch on Windows with "The system cannot find the file specified"
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Lots of people are using
min-release-agein their .npmrc files these days.I saw two options:
I opted for 2, which means we convert
package@0.1.2topackage@<=0.1.2. This means npm can find the latest version we can that meets the user's requirements.The downside is, the registry args/env may or may not work with the resolved version, but that should at least surface better thanks to #55757
There is also the issue that npm will cache package metadata and an older version it has cached would still resolve. However, once the metadata is updated, npm does use the newer tarball at least, so it will update eventually.
It's a tradeoff, but I'd rather start with this until we have a better solution on the ACP registry, rather than have users be upset becaue we installed packages in a way they didn't want.
Self-Review Checklist:
Closes agentclientprotocol/claude-agent-acp#516
Release Notes: