1a451bfaeb
Review follow-up, and a real platform bug. On Windows npm's `.bin` holds three siblings per binary — the extensionless sh script, `<name>.cmd` and `<name>.ps1`. Spawning the sh one from a Windows process fails, and `os.access(X_OK)` there is effectively an existence check, so the previous candidate test could not tell them apart: it would have picked a file that cannot run and broken server startup that works today via npx. Select by extension instead (`.cmd`, then `.exe`), the same precedence hermes_constants._candidate_node_command_names already uses for npm/npx/node, and fall back to npx when no launcher is present. The platform branch moved into `_npx_bin_candidates(..., windows=...)` so it is testable by injection. Patching `os.name` instead took pytest's own traceback formatting down with an INTERNALERROR — a test that cannot report its own failure is worse than no test. Also from review: an `npx pkg -y` shape (flag AFTER the spec) now falls back to npx, since those args are forwarded verbatim and would hand the server a flag npx would have consumed. And the structural OSV-ordering guard reports a rename explicitly instead of raising a bare ValueError that reads like a broken test.