fix(plugins): drain subprocess pipes concurrently with proc.exited

PluginManager.install (bun install + bun update), PluginManager.uninstall,
PluginManager.#fixMissingPlugin, the legacy installer.ts install/uninstall
helpers, and generate-legacy-pi-bundled-registry.ts's formatInPlace all
called Bun.spawn with stdout/stderr piped and awaited proc.exited before
touching either stream. Once a child's output exceeded the ~64 KiB OS
pipe buffer, the child would block on write(2) while the parent blocked
on exit — a classic pipe-buffer deadlock. Even where Bun's current runtime
happens to buffer eagerly, the pattern silently leaked unbounded bytes.

Each site now starts new Response(proc.stdout).text() and stderr readers
immediately after Bun.spawn and awaits them alongside proc.exited via
Promise.all. Existing error semantics are preserved: install throws with
stderr, uninstall keeps its generic error, and formatInPlace still includes
Biome's stderr in the failure message.

Adds a regression test (plugin-install-git.test.ts) that models the
OS-pipe deadlock by holding proc.exited until both mock streams are
drained — install must read them before awaiting exit, else the test hits
its 2s Promise.race timeout.

Fixes #4230
This commit is contained in:
roboomp
2026-07-02 08:33:32 +00:00
parent 0ea6ea630b
commit d2be57a8f7
5 changed files with 114 additions and 13 deletions
@@ -332,9 +332,15 @@ async function formatInPlace(targets: readonly string[]): Promise<void> {
stdout: "pipe",
stderr: "pipe",
});
const exit = await proc.exited;
// Drain both pipes concurrently with proc.exited to avoid a pipe-buffer
// deadlock — biome check can emit thousands of lines when it rewrites the
// generated registry, easily exceeding the ~64 KiB OS pipe buffer.
const [exit, , stderr] = await Promise.all([
proc.exited,
new Response(proc.stdout).text(),
new Response(proc.stderr).text(),
]);
if (exit !== 0) {
const stderr = await new Response(proc.stderr).text();
throw new Error(`biome check --write failed (exit ${exit}): ${stderr}`);
}
}