Skip to content

fix(deno): recognize Deno's npm-referrer missing-package error - #3560

Merged
kojiwakayama merged 1 commit into
mainfrom
fix/dx-20260811-0742-4
Aug 11, 2026
Merged

kojiwakayama merged 1 commit into
mainfrom
fix/dx-20260811-0742-4

Conversation

@kojiwakayama

@kojiwakayama kojiwakayama commented Aug 11, 2026 •

Copy link
Copy Markdown
Contributor

Found by a DX dogfood walk of https://veryfront.com/docs/code/getting-started/create-project against published CLI 0.1.1228.

Symptom

The documented Deno path is dead on arrival. Scaffold succeeds and prints cd test-app / deno task dev, but the very next documented command never binds a port:

$ veryfront init test-app --template ai-agent --runtime deno
  ✓ test-app ready
  cd test-app
  deno task dev

$ deno task dev
Task dev deno run -A npm:veryfront@0.1.1228 dev
Veryfront (v0.1.1228)

✗ [unknown-error] Unknown/unclassified error

  Detail: Could not find package '@veryfront/ext-auth-jwt' from referrer
  'file:///.../test-app/node_modules/.deno/veryfront@0.1.1228/node_modules/veryfront/esm/src/extensions/first-party-import.js'.
  Suggestion: Check logs for more details

curl → 000, the server never starts. Reproduced twice. The equivalent --runtime bun scaffold works, so this is Deno-specific.

Root cause

@veryfront/ext-auth-jwt is builtin-deferred with rootNpm: false (src/extensions/first-party-defaults.ts) — it is deliberately not a dependency of the root npm package. Failing to import it is the expected path, and createOptionalBuiltinExtension is supposed to swallow that failure via isMissingFirstPartyExtensionModule.

The classifier never got the chance. A --runtime deno scaffold runs its tasks as deno run -A npm:veryfront@<version>, so the extension probe is issued from a referrer inside the npm cache. In that configuration Deno words the resolution failure as:

Could not find package 'X' from referrer 'file:///...'.

reportedMissingSpecifier recognized Cannot find package …, Cannot find module … from …, Import "…" not a dependency, and Unable to resolve …, but not Could not find package … from referrer …. error.code is ERR_MODULE_NOT_FOUND, so isMissingModuleError said yes, but the anchored specifier could not be extracted — and the function fails closed, returning false. The optional-builtin handler then rethrew, and boot died.

Fix: add the referrer shape to the recognized resolver messages. One anchored pattern, no behaviour change anywhere else.

Regression test

src/extensions/first-party-import.test.ts — Deno BDD, alongside the existing per-runtime message-shape cases (parses exact Deno and Node package-subpath error shapes, parses Bun relative, package, and object-shaped missing-module errors). It lives there rather than in veryfront-e2e because the defect is a pure string-classification bug: it needs no browser, no deployment, and no credentials, and it runs in the pre-push gate.

The new case asserts both directions, which is the point of this classifier:

  • Could not find package '@veryfront/ext-auth-jwt' from referrer '…/node_modules/.deno/veryfront@…/…/first-party-import.js'. anchored on @veryfront/ext-auth-jwt → true (tolerate: extension genuinely not installed).
  • Could not find package 'jose' from referrer '…/node_modules/@veryfront/ext-auth-jwt/esm/src/index.js'. anchored on @veryfront/ext-auth-jwt → false (surface: a broken transitive dependency of an installed extension must not be misread as "not installed").

The test was written first and confirmed failing on the first assertion (Values are not equal: false / true) before the one-line fix landed.

Verification of the original symptom

Reproduced end to end in a sandbox outside the repo with the published CLI pinned at 0.1.1228, then re-ran the exact documented command with the same pattern applied to the scaffold's resolved copy of first-party-import.js:

$ deno task dev
Veryfront (v0.1.1228)
  ✓ Ready in 509ms
  http://veryfront.me:3000

$ curl -o /dev/null -w '%{http_code}' http://veryfront.me:3000/
200

Before: no bind, 000. After: 200.

Full pre-push suite passes.

Summary by CodeRabbit

  • Bug Fixes

    • Improved detection of missing first-party extensions in Deno npm cache error messages.
    • Prevented missing transitive dependencies from being incorrectly classified as absent extensions.
  • Tests

    • Added coverage for Deno npm-referrer missing-package error scenarios.

A scaffolded `--runtime deno` project runs its tasks as
`deno run -A npm:veryfront@<version>`, so optional first-party
extensions are probed from inside the npm cache. Deno reports an
unresolvable package from such a referrer as

  Could not find package 'X' from referrer 'file:///...'.

`reportedMissingSpecifier` did not know that shape, so
`isMissingFirstPartyExtensionModule` returned false and the probe for
the not-installed-by-default `@veryfront/ext-auth-jwt` was rethrown
instead of being tolerated, killing boot before the server ever bound.

Add the referrer shape to the recognized resolver messages. The
transitive-dependency guard is unchanged: a missing `jose` reported from
an installed extension still fails the anchor check and surfaces.
@coderabbitai

coderabbitai Bot commented Aug 11, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 3f1cf130-a2a2-4042-9f27-1f1209b9da04

📥 Commits

Reviewing files that changed from the base of the PR and between fe5d5b8 and a6fdb0a.

📒 Files selected for processing (2)
  • src/extensions/first-party-import.test.ts
  • src/extensions/first-party-import.ts

📝 Walkthrough

Walkthrough

The extension resolver now parses Deno npm-referrer missing-package errors. Tests cover classification of missing first-party packages and exclusion of missing transitive dependencies.

Changes

Deno package resolution

Layer / File(s) Summary
Package error classification
src/extensions/first-party-import.ts, src/extensions/first-party-import.test.ts
The resolver extracts missing package specifiers from Deno package-resolution errors. Tests distinguish missing first-party packages from missing transitive dependencies.

Estimated code review effort: 2 (Simple) | ~10 minutes

Possibly related PRs

Suggested reviewers: kwakayama

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the Deno npm-referrer missing-package error fix, which is the main change.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/dx-20260811-0742-4

Comment @coderabbitai help to get the list of available commands.

@kojiwakayama
kojiwakayama added this pull request to the merge queue Aug 11, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Aug 11, 2026
@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 11, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@kojiwakayama

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 11, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@kojiwakayama
kojiwakayama added this pull request to the merge queue Aug 11, 2026
Merged via the queue into main with commit 65a85ea Aug 11, 2026
33 checks passed
@kojiwakayama
kojiwakayama deleted the fix/dx-20260811-0742-4 branch August 11, 2026 08:22
kojiwakayama added a commit that referenced this pull request Aug 11, 2026
`deno add npm:veryfront` and `deno install -g npm:veryfront` resolve the
CLI out of the global Deno npm cache. From that referrer Deno appends the
owning package identifier to its resolution failure:

  Could not find package 'X' from referrer 'Y' (veryfront@0.1.1228).

#3560 taught `reportedMissingSpecifier` the bare referrer shape, but the
trailing parenthetical left the message unparsed, so every optional
first-party extension the root npm package deliberately does not depend on
still threw a fatal unclassified error on the documented `deno add` install
path and the published CLI could not start a project.

Extend that one pattern with the optional ` (pkg@version)` suffix. The
transitive-dependency guard is unchanged: a missing `jose` reported from an
installed extension still fails the anchor check and surfaces.

Found during a DX dogfood walk of the published installation docs, which
advertise Deno as a first-class runtime.

Confidence: high

Scope-risk: narrow

Reversibility: clean
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant