Skip to content

postdeploy hook fails on Windows with modern Node (spawnSync az.cmd EINVAL) — needs shell: true #35

Description

@vladpm

Summary

On Windows with modern Node.js (18.20.2+/20.12.2+/22/24), the postdeploy azd hook fails immediately with spawnSync az.cmd EINVAL. The run() helper in scripts/azd/postdeploy.mjs calls spawnSync("az.cmd", …) without shell: true, which Node now refuses for .cmd/.bat files as part of the CVE-2024-27980 fix. The web deploy succeeds; only the post-deploy migration/seed step fails.

Error

ERROR: failed running post hooks: 'postdeploy' hook failed with exit code: '1',
Path: '...\scripts\azd\postdeploy.mjs'.
stdout: Starting migrations job dpp-<env>-migrations; synthetic demo seeding is true.
stderr:
  Error: Unable to run az.cmd: spawnSync az.cmd EINVAL
    at run (.../scripts/azd/postdeploy.mjs:17:11)
Node.js v24.13.0

Root cause

scripts/azd/postdeploy.mjs run():

const result = spawnSync(executable, args, {
  cwd: projectRoot,
  encoding: "utf8",
  stdio: ["ignore", "pipe", "pipe"],
});

azExecutable is az.cmd on Windows. Since Node's security fix (CVE-2024-27980), spawning a .cmd requires shell: true, otherwise it throws EINVAL. azd.exe is unaffected because it's a real .exe.

Proposed fix

Enable a shell when spawning on Windows:

const result = spawnSync(executable, args, {
  cwd: projectRoot,
  encoding: "utf8",
  stdio: ["ignore", "pipe", "pipe"],
  shell: process.platform === "win32",
});

The same guard should be applied to any other hook that shells out to az.cmd (e.g. preprovision.mjs).

Workaround

Run the migration/seed job manually after the failed hook (deploy itself succeeded):

az containerapp job start --name dpp-<env>-migrations --resource-group rg-dpp-<env>

Or use a Node LTS < 18.20.2 / 20.12.2.

Steps to reproduce

  1. On Windows with Node ≥ v22/v24, run azd deploy web (or azd up).
  2. Web deploys successfully; the postdeploy hook throws spawnSync az.cmd EINVAL.

Environment

  • Windows, Node.js v24.13.0, azd, Azure CLI (az.cmd on PATH)

Impact

azd up / azd deploy cannot complete cleanly on Windows with current Node LTS — the migration/seed step always fails, blocking a one-shot deployment for most Windows users.

Related

Same governed/Windows deployment path as #33 (unquoted buildArgs) and #34 (ACR network default-action).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions