AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Turbopack External Module Hash Mismatch With Pnpm In Cross-Environment Deployment

Next.js 16 with Turbopack generates external module references with content-based hashes that depend on the node_modules directory structure at build time. When deploying to a different environment and reinstalling dependencies (especially with pnpm symlinks), the hashes no longer match the installed packages, causing the production server to fail to start with 'Cannot find module' errors.

criticalConfidence 85%Next.jsAffected V16.0.0Affected V16.1.1

Origin Analysis

Turbopack computes a hash for external modules based on the node_modules layout (including pnpm's symlink paths) during the build and embeds this hash in the runtime require statements. After reinstallation in a different environment, the node_modules structure changes, making the embedded hash point to a non-existent module name.
1. Create a Next.js 16.1.1+ project with OpenTelemetry instrumentation. 2. Add instrumentation.ts that imports @opentelemetry/auto-instrumentations-node. 3. Build the project in CI/CD using pnpm install --frozen-lockfile followed by next build. 4. Archive the build output excluding node_modules. 5. Extract the archive in a different environment. 6. Run pnpm install to reinstall dependencies. 7. Run next start and observe the 'Cannot find module require-in-the-middle-a99415fa67232f7f' error.

Fixing Code Block

Edge Case Audit

Switching to Webpack may significantly increase build time and could introduce Webpack-specific behavior differences. Rollback: change the build script back to 'next build' once the official fix is available. For teams that require minimal build time, monitor CI performance and consider using output: 'standalone' as an alternative mitigation, though it may have its own deployment implications.

Ecosystem Topology