1.66.2 replaced the #732 duplicate merge with a rewrite of `name@a || b` into
a BARE package name. That was wrong, and the review on #733 had already said
so before it shipped:
- `name@a || b` is a documented pnpm spelling (the validator's "Use exact
versions only" is about ranges and name patterns, not exact-version unions);
- a bare name exempts EVERY version of that package from the release-age
cooldown, which is wider than what the file declares. The market pins exact
versions precisely so a fresh install cannot silently land on an older
release (#594), so widening the exclusion list works against that;
- the 80 GiB abort it was meant to avoid could not be reproduced by review or
by the reporter's own follow-up, and pnpm's maintainers took it upstream
(pnpm/pnpm#15867).
Back to merging: several rules for one name become one union of the versions
the file already lists, a union that is already the only rule for its name is
left exactly as written, and a bare name stays bare. Nothing is widened, and
nothing pnpm wrote is rewritten into a form it did not ask for.
Kept from 1.66.2: the merge runs BEFORE the command instead of after a
failure, and covers every verb that reads the key (add, remove, install,
update). That ordering is what keeps the #732 failure from happening at all,
and it costs one small file read.