AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Standalone File Tracing Misses Dlopen'D Native Libraries (E.G., Sharp Libvips)

Next.js output: 'standalone' file tracing fails to include shared libraries loaded at runtime via dlopen by native addons, causing production crashes (e.g., sharp's libvips). Build succeeds silently; failure occurs only at runtime.

highConfidence 95%Next.jsAffected V16.2.11

Origin Analysis

Next.js standalone file tracing (based on @vercel/nft) performs static analysis of JavaScript module graphs (require/import) but does not inspect native .node binaries for dynamically linked shared libraries. Packages like sharp 0.35+ restructured to load libvips via dlopen rather than statically linking, so the tracer misses the ~18MB libvips-cpp.8.18.3.dylib/.so file. This is a general limitation for any native addon using runtime dynamic loading.
1. git clone https://github.com/clintongreen/nextjs-sharp-standalone-repro 2. cd nextjs-sharp-standalone-repro 3. pnpm install 4. pnpm exec next build 5. node .next/standalone/server.js & 6. curl http://localhost:3000/api/sharp-test Expected: 'sharp resize OK, 214 bytes'. Actual: HTTP 500 with error: 'Could not load the "sharp" module ... ERR_DLOPEN_FAILED ... Library not loaded: @rpath/libvips-cpp.8.18.3.dylib'. Confirm missing file: find .next/standalone/node_modules/.pnpm -path '*sharp-libvips-*/lib' -exec ls -la {} \; (shared library absent). Note: must use pnpm; npm masks the bug via @img/sharp-wasm32 fallback.

Fixing Code Block

Edge Case Audit

This workaround is fragile: (1) Glob patterns may match unintended files, increasing build size; (2) If sharp changes its library naming or directory structure, the globs break silently; (3) Cross-platform builds: if building on macOS and deploying to Linux (or vice versa), the included binary may be wrong architecture—ensure builds happen on target platform or use multi-arch docker; (4) Does not solve the general problem for other native addons; each package would need its own globs. Rollback: remove the outputFileTracingIncludes entry from next.config.js; monitor build output size and runtime behavior. Strongly recommend adding a post-build smoke test that exercises sharp against the traced standalone output to catch regressions early.

Ecosystem Topology