SIGN IN SIGN UP

fix(cmd-shim): try system cygpath and wslpath before caller path (#14963)

Generated POSIX bin shims resolve cygpath and wslpath through the caller's PATH,
which allows a dependency with a bin named cygpath or wslpath to override path
conversion on Cygwin, MSYS2, and WSL2.

The POSIX bin shim header now tries each helper via command -p first. If
execution succeeds with non-empty output, the system helper's result is used.
If command -p fails or returns empty output, it falls back to searching the
caller's PATH as before, so a host without the helper on the system default
path keeps working.

Both warm-install staleness checks -- is_sh_shim_hardened in pacquet and
isShimHardened in @pnpm/bins.linker -- now require the two conversion lines as
well. Without that, a shim written after the readlink hardening but before this
one still points at the right target, so nothing else about it looks stale and
an upgrade would never replace it.

Fixes pnpm/pnpm#14866.

---------

Co-authored-by: Zoltan Kochan <z@kochan.io>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
A
Ayush Singh committed
b5e863229df941d6806a0ddddbd434b88fd6940f
Parent: 9936922
Committed by GitHub <noreply@github.com> on 9/19/2026, 12:03:25 AM