nic-6443 opened a new pull request, #13921:
URL: https://github.com/apache/apisix/pull/13921

   CI on master is currently red across `CI`, `CI Kubernetes`, `CI Tars` and 
`CLI Test`, and it is not a test failure — every failing job dies during 
environment setup, before APISIX is built or a single `.t` runs:
   
   ```
   Downloading the pnpm 12.3.4 binary for linux-x64...
   Error: ERR_PNPM_SUDO_NOT_SUPPORTED
     × Running "pnpm setup" with sudo is not supported
   ```
   
   pnpm 12.3.4 (published 2026-09-04) started refusing `pnpm setup` when 
`SUDO_USER` is set, which is exactly how `ci/common.sh` runs it.
   
   The fix is to delete the call, because it is redundant. `pnpm setup` exists 
to write `PNPM_HOME` and the matching `PATH` entry into a shell profile, and 
`install_nodejs()` already exports both itself, in the same shell that later 
runs `pnpm install`. The `pnpm` binary comes from the corepack shim on `PATH`, 
not from `setup`.
   
   It is also the only unpinned pnpm invocation in CI. It runs from the 
repository root, which has no `package.json`, so corepack resolves it to 
whatever is latest — that is why a pnpm release broke us. Every pnpm command 
that does real work runs under `t/`, whose `package.json` pins `packageManager` 
to `[email protected]`.
   
   I checked the one global install, `pnpm install -g tsx` in 
`t/plugin/grpc-web/setup.sh`, since that is the case `pnpm setup` would 
plausibly be there for. With the line removed it still resolves to 10.14.0 
(inherited from `t/package.json`), succeeds with `SUDO_USER` set, and puts 
`tsx` in `PNPM_HOME`, which is on `PATH`. Verified in a clean `ubuntu:24.04` 
container reproducing the CI setup: `pnpm setup` fails as above, while `pnpm 
install`, `pnpm exec jest` and the global `tsx` install all succeed without it.
   
   Two workflows here already run `corepack enable pnpm` followed by `pnpm 
install` with no `pnpm setup`, so this brings `ci/common.sh` in line with them.
   
   Pinning instead would also work, but it would leave the sudo interaction in 
place to break again later; removing the call drops it entirely and leaves 
every pnpm version in CI pinned.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to