deps.js 30 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851
  1. 'use strict'
  2. const BB = require('bluebird')
  3. var fs = require('fs')
  4. var assert = require('assert')
  5. var path = require('path')
  6. var semver = require('semver')
  7. var asyncMap = require('slide').asyncMap
  8. var chain = require('slide').chain
  9. var iferr = require('iferr')
  10. var npa = require('npm-package-arg')
  11. var validate = require('aproba')
  12. var dezalgo = require('dezalgo')
  13. var fetchPackageMetadata = require('../fetch-package-metadata.js')
  14. var andAddParentToErrors = require('./and-add-parent-to-errors.js')
  15. var addBundled = require('../fetch-package-metadata.js').addBundled
  16. var readShrinkwrap = require('./read-shrinkwrap.js')
  17. var inflateShrinkwrap = require('./inflate-shrinkwrap.js')
  18. var inflateBundled = require('./inflate-bundled.js')
  19. var andFinishTracker = require('./and-finish-tracker.js')
  20. var npm = require('../npm.js')
  21. var flatNameFromTree = require('./flatten-tree.js').flatNameFromTree
  22. var createChild = require('./node.js').create
  23. var resetMetadata = require('./node.js').reset
  24. var isInstallable = require('./validate-args.js').isInstallable
  25. var packageId = require('../utils/package-id.js')
  26. var moduleName = require('../utils/module-name.js')
  27. var isDevDep = require('./is-dev-dep.js')
  28. var isProdDep = require('./is-prod-dep.js')
  29. var reportOptionalFailure = require('./report-optional-failure.js')
  30. var getSaveType = require('./save.js').getSaveType
  31. var unixFormatPath = require('../utils/unix-format-path.js')
  32. var isExtraneous = require('./is-extraneous.js')
  33. var isRegistry = require('../utils/is-registry.js')
  34. var hasModernMeta = require('./has-modern-meta.js')
  35. // The export functions in this module mutate a dependency tree, adding
  36. // items to them.
  37. var registryTypes = { range: true, version: true }
  38. function doesChildVersionMatch (child, requested, requestor) {
  39. if (child.fromShrinkwrap && !child.hasRequiresFromLock) return true
  40. // ranges of * ALWAYS count as a match, because when downloading we allow
  41. // prereleases to match * if there are ONLY prereleases
  42. if (requested.type === 'range' && requested.fetchSpec === '*') return true
  43. if (requested.type === 'directory') {
  44. if (!child.isLink) return false
  45. return path.relative(child.realpath, requested.fetchSpec) === ''
  46. }
  47. if (requested.type === 'git' && child.fromShrinkwrap) {
  48. const fromSw = child.package._from ? npa(child.package._from) : child.fromShrinkwrap
  49. fromSw.name = requested.name // we're only checking specifiers here
  50. if (fromSw.toString() === requested.toString()) return true
  51. }
  52. if (requested.type === 'git' && requested.gitRange) {
  53. const sameRepo = npa(child.package._from).fetchSpec === requested.fetchSpec
  54. try {
  55. return sameRepo && semver.satisfies(child.package.version, requested.gitRange, true)
  56. } catch (e) {
  57. return false
  58. }
  59. }
  60. if (requested.type === 'alias') {
  61. return doesChildVersionMatch(child, requested.subSpec, requestor)
  62. }
  63. if (!registryTypes[requested.type]) {
  64. var childReq = child.package._requested
  65. if (childReq) {
  66. if (childReq.rawSpec === requested.rawSpec) return true
  67. if (childReq.type === requested.type) {
  68. if (childReq.saveSpec === requested.saveSpec) return true
  69. if ((childReq.fetchSpec === requested.fetchSpec) && requested.type !== 'git') return true
  70. }
  71. }
  72. // If _requested didn't exist OR if it didn't match then we'll try using
  73. // _from. We pass it through npa to normalize the specifier.
  74. // This can happen when installing from an `npm-shrinkwrap.json` where `_requested` will
  75. // be the tarball URL from `resolved` and thus can't match what's in the `package.json`.
  76. // In those cases _from, will be preserved and we can compare that to ensure that they
  77. // really came from the same sources.
  78. // You'll see this scenario happen with at least tags and git dependencies.
  79. // Some buggy clients will write spaces into the module name part of a _from.
  80. if (child.package._from) {
  81. var fromReq = npa(child.package._from)
  82. if (fromReq.rawSpec === requested.rawSpec) return true
  83. if (fromReq.type === requested.type && fromReq.saveSpec && fromReq.saveSpec === requested.saveSpec) return true
  84. }
  85. return false
  86. }
  87. try {
  88. return semver.satisfies(child.package.version, requested.fetchSpec, true)
  89. } catch (e) {
  90. return false
  91. }
  92. }
  93. function childDependencySpecifier (tree, name, spec, where) {
  94. return npa.resolve(name, spec, where || packageRelativePath(tree))
  95. }
  96. exports.computeMetadata = computeMetadata
  97. function computeMetadata (tree, seen) {
  98. if (!seen) seen = new Set()
  99. if (!tree || seen.has(tree)) return
  100. seen.add(tree)
  101. if (tree.parent == null) {
  102. resetMetadata(tree)
  103. tree.isTop = true
  104. }
  105. tree.location = flatNameFromTree(tree)
  106. function findChild (name, spec, kind) {
  107. try {
  108. var req = childDependencySpecifier(tree, name, spec)
  109. } catch (err) {
  110. return
  111. }
  112. var child = findRequirement(tree, req.name, req)
  113. if (child) {
  114. resolveWithExistingModule(child, tree)
  115. return true
  116. }
  117. }
  118. const deps = tree.package.dependencies || {}
  119. const reqs = tree.swRequires || {}
  120. for (let name of Object.keys(deps)) {
  121. if (findChild(name, deps[name])) continue
  122. if (name in reqs && findChild(name, reqs[name])) continue
  123. tree.missingDeps[name] = deps[name]
  124. }
  125. if (tree.isTop) {
  126. const devDeps = tree.package.devDependencies || {}
  127. for (let name of Object.keys(devDeps)) {
  128. if (findChild(name, devDeps[name])) continue
  129. tree.missingDevDeps[name] = devDeps[name]
  130. }
  131. }
  132. tree.children.filter((child) => !child.removed).forEach((child) => computeMetadata(child, seen))
  133. return tree
  134. }
  135. function isDep (tree, child) {
  136. var name = moduleName(child)
  137. var prodVer = isProdDep(tree, name)
  138. var devVer = isDevDep(tree, name)
  139. try {
  140. var prodSpec = childDependencySpecifier(tree, name, prodVer)
  141. } catch (err) {
  142. return {isDep: true, isProdDep: false, isDevDep: false}
  143. }
  144. var matches
  145. if (prodSpec) matches = doesChildVersionMatch(child, prodSpec, tree)
  146. if (matches) return {isDep: true, isProdDep: prodSpec, isDevDep: false}
  147. if (devVer === prodVer) return {isDep: child.fromShrinkwrap, isProdDep: false, isDevDep: false}
  148. try {
  149. var devSpec = childDependencySpecifier(tree, name, devVer)
  150. return {isDep: doesChildVersionMatch(child, devSpec, tree) || child.fromShrinkwrap, isProdDep: false, isDevDep: devSpec}
  151. } catch (err) {
  152. return {isDep: child.fromShrinkwrap, isProdDep: false, isDevDep: false}
  153. }
  154. }
  155. function addRequiredDep (tree, child) {
  156. var dep = isDep(tree, child)
  157. if (!dep.isDep) return false
  158. replaceModuleByPath(child, 'requiredBy', tree)
  159. replaceModuleByName(tree, 'requires', child)
  160. if (dep.isProdDep && tree.missingDeps) delete tree.missingDeps[moduleName(child)]
  161. if (dep.isDevDep && tree.missingDevDeps) delete tree.missingDevDeps[moduleName(child)]
  162. return true
  163. }
  164. exports.removeObsoleteDep = removeObsoleteDep
  165. function removeObsoleteDep (child, log) {
  166. if (child.removed) return
  167. child.removed = true
  168. if (log) {
  169. log.silly('removeObsoleteDep', 'removing ' + packageId(child) +
  170. ' from the tree as its been replaced by a newer version or is no longer required')
  171. }
  172. // remove from physical tree
  173. if (child.parent) {
  174. child.parent.children = child.parent.children.filter(function (pchild) { return pchild !== child })
  175. }
  176. // remove from logical tree
  177. var requires = child.requires || []
  178. requires.forEach(function (requirement) {
  179. requirement.requiredBy = requirement.requiredBy.filter(function (reqBy) { return reqBy !== child })
  180. // we don't just check requirement.requires because that doesn't account
  181. // for circular deps. isExtraneous does.
  182. if (isExtraneous(requirement)) removeObsoleteDep(requirement, log)
  183. })
  184. }
  185. exports.packageRelativePath = packageRelativePath
  186. function packageRelativePath (tree) {
  187. if (!tree) return ''
  188. var requested = tree.package._requested || {}
  189. if (requested.type === 'directory') {
  190. return requested.fetchSpec
  191. } else if (requested.type === 'file') {
  192. return path.dirname(requested.fetchSpec)
  193. } else if ((tree.isLink || tree.isInLink) && !preserveSymlinks()) {
  194. return tree.realpath
  195. } else {
  196. return tree.path
  197. }
  198. }
  199. function matchingDep (tree, name) {
  200. if (!tree || !tree.package) return
  201. if (tree.package.dependencies && tree.package.dependencies[name]) return tree.package.dependencies[name]
  202. if (tree.package.devDependencies && tree.package.devDependencies[name]) return tree.package.devDependencies[name]
  203. }
  204. exports.getAllMetadata = function (args, tree, where, next) {
  205. asyncMap(args, function (arg, done) {
  206. let spec
  207. try {
  208. spec = npa(arg)
  209. } catch (e) {
  210. return done(e)
  211. }
  212. if (spec.type !== 'file' && spec.type !== 'directory' && (spec.name == null || spec.rawSpec === '')) {
  213. return fs.stat(path.join(arg, 'package.json'), (err) => {
  214. if (err) {
  215. var version = matchingDep(tree, spec.name)
  216. if (version) {
  217. try {
  218. return fetchPackageMetadata(npa.resolve(spec.name, version), where, done)
  219. } catch (e) {
  220. return done(e)
  221. }
  222. } else {
  223. return fetchPackageMetadata(spec, where, done)
  224. }
  225. } else {
  226. try {
  227. return fetchPackageMetadata(npa('file:' + arg), where, done)
  228. } catch (e) {
  229. return done(e)
  230. }
  231. }
  232. })
  233. } else {
  234. return fetchPackageMetadata(spec, where, done)
  235. }
  236. }, next)
  237. }
  238. // Add a list of args to tree's top level dependencies
  239. exports.loadRequestedDeps = function (args, tree, saveToDependencies, log, next) {
  240. validate('AOOF', [args, tree, log, next])
  241. asyncMap(args, function (pkg, done) {
  242. var depLoaded = andAddParentToErrors(tree, done)
  243. resolveWithNewModule(pkg, tree, log.newGroup('loadRequestedDeps'), iferr(depLoaded, function (child, tracker) {
  244. validate('OO', arguments)
  245. if (npm.config.get('global')) {
  246. child.isGlobal = true
  247. }
  248. var childName = moduleName(child)
  249. child.saveSpec = computeVersionSpec(tree, child)
  250. child.userRequired = true
  251. child.save = getSaveType(tree, child)
  252. const types = ['dependencies', 'devDependencies', 'optionalDependencies']
  253. if (child.save) {
  254. tree.package[child.save][childName] = child.saveSpec
  255. // Astute readers might notice that this exact same code exists in
  256. // save.js under a different guise. That code is responsible for deps
  257. // being removed from the final written `package.json`. The removal in
  258. // this function is specifically to prevent "installed as both X and Y"
  259. // warnings when moving an existing dep between different dep fields.
  260. //
  261. // Or, try it by removing this loop, and do `npm i -P x && npm i -D x`
  262. for (let saveType of types) {
  263. if (child.save !== saveType) {
  264. delete tree.package[saveType][childName]
  265. }
  266. }
  267. if (child.save === 'optionalDependencies') tree.package.dependencies[childName] = child.saveSpec
  268. }
  269. // For things the user asked to install, that aren't a dependency (or
  270. // won't be when we're done), flag it as "depending" on the user
  271. // themselves, so we don't remove it as a dep that no longer exists
  272. var childIsDep = addRequiredDep(tree, child)
  273. if (!childIsDep) child.userRequired = true
  274. depLoaded(null, child, tracker)
  275. }))
  276. }, andForEachChild(loadDeps, andFinishTracker(log, next)))
  277. }
  278. function isNotEmpty (value) {
  279. return value != null && value !== ''
  280. }
  281. exports.computeVersionSpec = computeVersionSpec
  282. function computeVersionSpec (tree, child) {
  283. validate('OO', arguments)
  284. var requested
  285. var childReq = child.package._requested
  286. if (child.isLink) {
  287. requested = npa.resolve(moduleName(child), 'file:' + child.realpath, getTop(tree).path)
  288. } else if (childReq && (isNotEmpty(childReq.saveSpec) || (isNotEmpty(childReq.rawSpec) && isNotEmpty(childReq.fetchSpec)))) {
  289. requested = child.package._requested
  290. } else if (child.package._from) {
  291. requested = npa(child.package._from, tree.path)
  292. } else if (child.name && child.name !== child.package.name) {
  293. requested = npa.resolve(child.name, `npm:${child.package.name}@${child.package.version})`)
  294. } else {
  295. requested = npa.resolve(child.package.name, child.package.version)
  296. }
  297. if (isRegistry(requested)) {
  298. var version = child.package.version
  299. var rangeDescriptor = ''
  300. if (semver.valid(version, true) &&
  301. semver.gte(version, '0.1.0', true) &&
  302. !npm.config.get('save-exact')) {
  303. rangeDescriptor = npm.config.get('save-prefix')
  304. }
  305. if (requested.type === 'alias') {
  306. rangeDescriptor = `npm:${requested.subSpec.name}@${rangeDescriptor}`
  307. }
  308. return rangeDescriptor + version
  309. } else if (requested.type === 'directory' || requested.type === 'file') {
  310. return 'file:' + unixFormatPath(path.relative(getTop(tree).path, requested.fetchSpec))
  311. } else {
  312. return requested.saveSpec || requested.rawSpec
  313. }
  314. }
  315. function moduleNameMatches (name) {
  316. return function (child) { return moduleName(child) === name }
  317. }
  318. // while this implementation does not require async calling, doing so
  319. // gives this a consistent interface with loadDeps et al
  320. exports.removeDeps = function (args, tree, saveToDependencies, next) {
  321. validate('AOSF|AOZF', [args, tree, saveToDependencies, next])
  322. for (let pkg of args) {
  323. var pkgName = moduleName(pkg)
  324. var toRemove = tree.children.filter(moduleNameMatches(pkgName))
  325. var pkgToRemove = toRemove[0] || createChild({name: pkgName})
  326. var saveType = getSaveType(tree, pkg) || 'dependencies'
  327. if (tree.isTop && saveToDependencies) {
  328. pkgToRemove.save = saveType
  329. }
  330. if (tree.package[saveType][pkgName]) {
  331. delete tree.package[saveType][pkgName]
  332. if (saveType === 'optionalDependencies' && tree.package.dependencies[pkgName]) {
  333. delete tree.package.dependencies[pkgName]
  334. }
  335. }
  336. replaceModuleByPath(tree, 'removedChildren', pkgToRemove)
  337. for (let parent of pkgToRemove.requiredBy) {
  338. parent.requires = parent.requires.filter((child) => child !== pkgToRemove)
  339. }
  340. pkgToRemove.requiredBy = pkgToRemove.requiredBy.filter((parent) => parent !== tree)
  341. flagAsRemoving(pkgToRemove)
  342. }
  343. next()
  344. }
  345. function flagAsRemoving (toRemove, seen) {
  346. if (!seen) seen = new Set()
  347. if (seen.has(toRemove)) return
  348. seen.add(toRemove)
  349. toRemove.removing = true
  350. toRemove.requires.forEach((required) => {
  351. flagAsRemoving(required, seen)
  352. })
  353. }
  354. exports.removeExtraneous = function (args, tree, next) {
  355. for (let pkg of args) {
  356. var pkgName = moduleName(pkg)
  357. var toRemove = tree.children.filter(moduleNameMatches(pkgName))
  358. if (toRemove.length) {
  359. removeObsoleteDep(toRemove[0])
  360. }
  361. }
  362. next()
  363. }
  364. function andForEachChild (load, next) {
  365. validate('F', [next])
  366. next = dezalgo(next)
  367. return function (er, children, logs) {
  368. // when children is empty, logs won't be passed in at all (asyncMap is weird)
  369. // so shortcircuit before arg validation
  370. if (!er && (!children || children.length === 0)) return next()
  371. validate('EAA', arguments)
  372. if (er) return next(er)
  373. assert(children.length === logs.length)
  374. var cmds = []
  375. for (var ii = 0; ii < children.length; ++ii) {
  376. cmds.push([load, children[ii], logs[ii]])
  377. }
  378. var sortedCmds = cmds.sort(function installOrder (aa, bb) {
  379. return moduleName(aa[1]).localeCompare(moduleName(bb[1]))
  380. })
  381. chain(sortedCmds, next)
  382. }
  383. }
  384. function isDepOptional (tree, name, pkg) {
  385. if (pkg.package && pkg.package._optional) return true
  386. const optDeps = tree.package.optionalDependencies
  387. if (optDeps && optDeps[name] != null) return true
  388. const devDeps = tree.package.devDependencies
  389. if (devDeps && devDeps[name] != null) {
  390. const includeDev = npm.config.get('dev') ||
  391. (!/^prod(uction)?$/.test(npm.config.get('only')) && !npm.config.get('production')) ||
  392. /^dev(elopment)?$/.test(npm.config.get('only')) ||
  393. /^dev(elopment)?$/.test(npm.config.get('also'))
  394. return !includeDev
  395. }
  396. const prodDeps = tree.package.dependencies
  397. if (prodDeps && prodDeps[name] != null) {
  398. const includeProd = !/^dev(elopment)?$/.test(npm.config.get('only'))
  399. return !includeProd
  400. }
  401. return false
  402. }
  403. exports.failedDependency = failedDependency
  404. function failedDependency (tree, name, pkg) {
  405. if (name) {
  406. if (isDepOptional(tree, name, pkg || {})) {
  407. return false
  408. }
  409. }
  410. tree.failed = true
  411. if (tree.isTop) return true
  412. if (tree.userRequired) return true
  413. if (!tree.requiredBy) return false
  414. let anyFailed = false
  415. for (var ii = 0; ii < tree.requiredBy.length; ++ii) {
  416. var requireParent = tree.requiredBy[ii]
  417. if (failedDependency(requireParent, moduleName(tree), tree)) {
  418. anyFailed = true
  419. }
  420. }
  421. return anyFailed
  422. }
  423. function andHandleOptionalErrors (log, tree, name, done) {
  424. validate('OOSF', arguments)
  425. return function (er, child, childLog) {
  426. if (!er) validate('OO', [child, childLog])
  427. if (!er) return done(er, child, childLog)
  428. var isFatal = failedDependency(tree, name)
  429. if (er && !isFatal) {
  430. reportOptionalFailure(tree, name, er)
  431. return done()
  432. } else {
  433. return done(er, child, childLog)
  434. }
  435. }
  436. }
  437. exports.prefetchDeps = prefetchDeps
  438. function prefetchDeps (tree, deps, log, next) {
  439. validate('OOOF', arguments)
  440. var skipOptional = !npm.config.get('optional')
  441. var seen = new Set()
  442. const finished = andFinishTracker(log, next)
  443. const fpm = BB.promisify(fetchPackageMetadata)
  444. resolveBranchDeps(tree.package, deps).then(
  445. () => finished(), finished
  446. )
  447. function resolveBranchDeps (pkg, deps) {
  448. return BB.resolve(null).then(() => {
  449. var allDependencies = Object.keys(deps).map((dep) => {
  450. return npa.resolve(dep, deps[dep])
  451. }).filter((dep) => {
  452. return isRegistry(dep) &&
  453. !seen.has(dep.toString()) &&
  454. !findRequirement(tree, dep.name, dep)
  455. })
  456. if (skipOptional) {
  457. var optDeps = pkg.optionalDependencies || {}
  458. allDependencies = allDependencies.filter((dep) => !optDeps[dep.name])
  459. }
  460. return BB.map(allDependencies, (dep) => {
  461. seen.add(dep.toString())
  462. return fpm(dep, '', {tracker: log.newItem('fetchMetadata')}).then(
  463. (pkg) => {
  464. return pkg && pkg.dependencies && resolveBranchDeps(pkg, pkg.dependencies)
  465. },
  466. () => null
  467. )
  468. })
  469. })
  470. }
  471. }
  472. // Load any missing dependencies in the given tree
  473. exports.loadDeps = loadDeps
  474. function loadDeps (tree, log, next) {
  475. validate('OOF', arguments)
  476. if (tree.loaded || (tree.parent && tree.parent.failed) || tree.removed) return andFinishTracker.now(log, next)
  477. if (tree.parent) tree.loaded = true
  478. if (!tree.package.dependencies) tree.package.dependencies = {}
  479. asyncMap(Object.keys(tree.package.dependencies), function (dep, done) {
  480. var version = tree.package.dependencies[dep]
  481. addDependency(dep, version, tree, log.newGroup('loadDep:' + dep), andHandleOptionalErrors(log, tree, dep, done))
  482. }, andForEachChild(loadDeps, andFinishTracker(log, next)))
  483. }
  484. // Load development dependencies into the given tree
  485. exports.loadDevDeps = function (tree, log, next) {
  486. validate('OOF', arguments)
  487. if (!tree.package.devDependencies) return andFinishTracker.now(log, next)
  488. asyncMap(Object.keys(tree.package.devDependencies), function (dep, done) {
  489. // things defined as both dev dependencies and regular dependencies are treated
  490. // as the former
  491. if (tree.package.dependencies[dep]) return done()
  492. var logGroup = log.newGroup('loadDevDep:' + dep)
  493. addDependency(dep, tree.package.devDependencies[dep], tree, logGroup, andHandleOptionalErrors(log, tree, dep, done))
  494. }, andForEachChild(loadDeps, andFinishTracker(log, next)))
  495. }
  496. var loadExtraneous = exports.loadExtraneous = function (tree, log, next) {
  497. var seen = new Set()
  498. function loadExtraneous (tree) {
  499. if (seen.has(tree)) return
  500. seen.add(tree)
  501. for (var child of tree.children) {
  502. if (child.loaded) continue
  503. resolveWithExistingModule(child, tree)
  504. loadExtraneous(child)
  505. }
  506. }
  507. loadExtraneous(tree)
  508. log.finish()
  509. next()
  510. }
  511. exports.loadExtraneous.andResolveDeps = function (tree, log, next) {
  512. validate('OOF', arguments)
  513. // For canonicalized trees (eg from shrinkwrap) we don't want to bother
  514. // resolving the dependencies of extraneous deps.
  515. if (tree.loaded) return loadExtraneous(tree, log, next)
  516. asyncMap(tree.children.filter(function (child) { return !child.loaded }), function (child, done) {
  517. resolveWithExistingModule(child, tree)
  518. done(null, child, log)
  519. }, andForEachChild(loadDeps, andFinishTracker(log, next)))
  520. }
  521. function addDependency (name, versionSpec, tree, log, done) {
  522. validate('SSOOF', arguments)
  523. var next = andAddParentToErrors(tree, done)
  524. try {
  525. var req = childDependencySpecifier(tree, name, versionSpec)
  526. if (tree.swRequires && tree.swRequires[name]) {
  527. var swReq = childDependencySpecifier(tree, name, tree.swRequires[name])
  528. }
  529. } catch (err) {
  530. return done(err)
  531. }
  532. var child = findRequirement(tree, name, req)
  533. if (!child && swReq) child = findRequirement(tree, name, swReq)
  534. if (hasModernMeta(child)) {
  535. resolveWithExistingModule(child, tree)
  536. if (child.package._shrinkwrap === undefined) {
  537. readShrinkwrap.andInflate(child, function (er) { next(er, child, log) })
  538. } else {
  539. next(null, child, log)
  540. }
  541. } else {
  542. if (child) {
  543. if (req.registry) {
  544. req = childDependencySpecifier(tree, name, child.package.version)
  545. }
  546. if (child.fromBundle) reportBundleOverride(child, log)
  547. removeObsoleteDep(child, log)
  548. }
  549. fetchPackageMetadata(req, packageRelativePath(tree), {tracker: log.newItem('fetchMetadata')}, iferr(next, function (pkg) {
  550. resolveWithNewModule(pkg, tree, log, next)
  551. }))
  552. }
  553. }
  554. function getTop (pkg) {
  555. const seen = new Set()
  556. while (pkg.parent && !seen.has(pkg.parent)) {
  557. pkg = pkg.parent
  558. seen.add(pkg)
  559. }
  560. return pkg
  561. }
  562. function reportBundleOverride (child, log) {
  563. const code = 'EBUNDLEOVERRIDE'
  564. const top = getTop(child.fromBundle)
  565. const bundlerId = packageId(child.fromBundle)
  566. if (!top.warnings.some((w) => {
  567. return w.code === code
  568. })) {
  569. const err = new Error(`${bundlerId} had bundled packages that do not match the required version(s). They have been replaced with non-bundled versions.`)
  570. err.code = code
  571. top.warnings.push(err)
  572. }
  573. if (log) log.verbose('bundle', `${code}: Replacing ${bundlerId}'s bundled version of ${moduleName(child)} with ${packageId(child)}.`)
  574. }
  575. function resolveWithExistingModule (child, tree) {
  576. validate('OO', arguments)
  577. addRequiredDep(tree, child)
  578. if (tree.parent && child.parent !== tree) updatePhantomChildren(tree.parent, child)
  579. }
  580. var updatePhantomChildren = exports.updatePhantomChildren = function (current, child) {
  581. validate('OO', arguments)
  582. while (current && current !== child.parent) {
  583. if (!current.phantomChildren) current.phantomChildren = {}
  584. current.phantomChildren[moduleName(child)] = child
  585. current = current.parent
  586. }
  587. }
  588. exports._replaceModuleByPath = replaceModuleByPath
  589. function replaceModuleByPath (obj, key, child) {
  590. return replaceModule(obj, key, child, function (replacing, child) {
  591. return replacing.path === child.path
  592. })
  593. }
  594. exports._replaceModuleByName = replaceModuleByName
  595. function replaceModuleByName (obj, key, child) {
  596. var childName = moduleName(child)
  597. return replaceModule(obj, key, child, function (replacing, child) {
  598. return moduleName(replacing) === childName
  599. })
  600. }
  601. function replaceModule (obj, key, child, matchBy) {
  602. validate('OSOF', arguments)
  603. if (!obj[key]) obj[key] = []
  604. // we replace children with a new array object instead of mutating it
  605. // because mutating it results in weird failure states.
  606. // I would very much like to know _why_ this is. =/
  607. var children = [].concat(obj[key])
  608. for (var replaceAt = 0; replaceAt < children.length; ++replaceAt) {
  609. if (matchBy(children[replaceAt], child)) break
  610. }
  611. var replacing = children.splice(replaceAt, 1, child)
  612. obj[key] = children
  613. return replacing[0]
  614. }
  615. function resolveWithNewModule (pkg, tree, log, next) {
  616. validate('OOOF', arguments)
  617. log.silly('resolveWithNewModule', packageId(pkg), 'checking installable status')
  618. return isInstallable(tree, pkg, (err) => {
  619. let installable = !err
  620. addBundled(pkg, (bundleErr) => {
  621. var parent = earliestInstallable(tree, tree, pkg, log) || tree
  622. var isLink = pkg._requested.type === 'directory'
  623. var name = pkg._requested.name || pkg.name
  624. var child = createChild({
  625. name,
  626. package: pkg,
  627. parent: parent,
  628. path: path.join(parent.isLink ? parent.realpath : parent.path, 'node_modules', name),
  629. realpath: isLink ? pkg._requested.fetchSpec : path.join(parent.realpath, 'node_modules', name),
  630. children: pkg._bundled || [],
  631. isLink: isLink,
  632. isInLink: parent.isLink,
  633. knownInstallable: installable
  634. })
  635. if (!installable || bundleErr) child.failed = true
  636. delete pkg._bundled
  637. var hasBundled = child.children.length
  638. var replaced = replaceModuleByName(parent, 'children', child)
  639. if (replaced) {
  640. if (replaced.fromBundle) reportBundleOverride(replaced, log)
  641. removeObsoleteDep(replaced)
  642. }
  643. addRequiredDep(tree, child)
  644. child.location = flatNameFromTree(child)
  645. if (tree.parent && parent !== tree) updatePhantomChildren(tree.parent, child)
  646. if (hasBundled) {
  647. inflateBundled(child, child, child.children)
  648. }
  649. if (pkg._shrinkwrap && pkg._shrinkwrap.dependencies) {
  650. return inflateShrinkwrap(child, pkg._shrinkwrap, (swErr) => {
  651. if (swErr) child.failed = true
  652. next(err || bundleErr || swErr, child, log)
  653. })
  654. }
  655. next(err || bundleErr, child, log)
  656. })
  657. })
  658. }
  659. var isOptionalPeerDep = exports.isOptionalPeerDep = function (tree, pkgname) {
  660. if (!tree.package.peerDependenciesMeta) return
  661. if (!tree.package.peerDependenciesMeta[pkgname]) return
  662. return !!tree.package.peerDependenciesMeta[pkgname].optional
  663. }
  664. var validatePeerDeps = exports.validatePeerDeps = function (tree, onInvalid) {
  665. if (!tree.package.peerDependencies) return
  666. Object.keys(tree.package.peerDependencies).forEach(function (pkgname) {
  667. var version = tree.package.peerDependencies[pkgname]
  668. try {
  669. var spec = npa.resolve(pkgname, version)
  670. } catch (e) {}
  671. var match = spec && findRequirement(tree.parent || tree, pkgname, spec)
  672. if (!match && !isOptionalPeerDep(tree, pkgname)) onInvalid(tree, pkgname, version)
  673. })
  674. }
  675. exports.validateAllPeerDeps = function (tree, onInvalid) {
  676. validateAllPeerDeps(tree, onInvalid, new Set())
  677. }
  678. function validateAllPeerDeps (tree, onInvalid, seen) {
  679. validate('OFO', arguments)
  680. if (seen.has(tree)) return
  681. seen.add(tree)
  682. validatePeerDeps(tree, onInvalid)
  683. tree.children.forEach(function (child) { validateAllPeerDeps(child, onInvalid, seen) })
  684. }
  685. // Determine if a module requirement is already met by the tree at or above
  686. // our current location in the tree.
  687. var findRequirement = exports.findRequirement = function (tree, name, requested, requestor) {
  688. validate('OSO', [tree, name, requested])
  689. if (!requestor) requestor = tree
  690. var nameMatch = function (child) {
  691. return moduleName(child) === name && child.parent && !child.removed
  692. }
  693. var versionMatch = function (child) {
  694. return doesChildVersionMatch(child, requested, requestor)
  695. }
  696. if (nameMatch(tree)) {
  697. // this *is* the module, but it doesn't match the version, so a
  698. // new copy will have to be installed
  699. return versionMatch(tree) ? tree : null
  700. }
  701. var matches = tree.children.filter(nameMatch)
  702. if (matches.length) {
  703. matches = matches.filter(versionMatch)
  704. // the module exists as a dependent, but the version doesn't match, so
  705. // a new copy will have to be installed above here
  706. if (matches.length) return matches[0]
  707. return null
  708. }
  709. if (tree.isTop) return null
  710. if (!preserveSymlinks() && /^[.][.][\\/]/.test(path.relative(tree.parent.realpath, tree.realpath))) return null
  711. return findRequirement(tree.parent, name, requested, requestor)
  712. }
  713. function preserveSymlinks () {
  714. if (!('NODE_PRESERVE_SYMLINKS' in process.env)) return false
  715. const value = process.env.NODE_PRESERVE_SYMLINKS
  716. if (value == null || value === '' || value === 'false' || value === 'no' || value === '0') return false
  717. return true
  718. }
  719. // Find the highest level in the tree that we can install this module in.
  720. // If the module isn't installed above us yet, that'd be the very top.
  721. // If it is, then it's the level below where its installed.
  722. var earliestInstallable = exports.earliestInstallable = function (requiredBy, tree, pkg, log) {
  723. validate('OOOO', arguments)
  724. function undeletedModuleMatches (child) {
  725. return !child.removed && moduleName(child) === ((pkg._requested && pkg._requested.name) || pkg.name)
  726. }
  727. const undeletedMatches = tree.children.filter(undeletedModuleMatches)
  728. if (undeletedMatches.length) {
  729. // if there's a conflict with another child AT THE SAME level then we're replacing it, so
  730. // mark it as removed and continue with resolution normally.
  731. if (tree === requiredBy) {
  732. undeletedMatches.forEach((pkg) => {
  733. if (pkg.fromBundle) reportBundleOverride(pkg, log)
  734. removeObsoleteDep(pkg, log)
  735. })
  736. } else {
  737. return null
  738. }
  739. }
  740. // If any of the children of this tree have conflicting
  741. // binaries then we need to decline to install this package here.
  742. var binaryMatches = pkg.bin && tree.children.some(function (child) {
  743. if (child.removed || !child.package.bin) return false
  744. return Object.keys(child.package.bin).some(function (bin) {
  745. return pkg.bin[bin]
  746. })
  747. })
  748. if (binaryMatches) return null
  749. // if this tree location requested the same module then we KNOW it
  750. // isn't compatible because if it were findRequirement would have
  751. // found that version.
  752. var deps = tree.package.dependencies || {}
  753. if (!tree.removed && requiredBy !== tree && deps[pkg.name]) {
  754. return null
  755. }
  756. var devDeps = tree.package.devDependencies || {}
  757. if (tree.isTop && devDeps[pkg.name]) {
  758. var requested = childDependencySpecifier(tree, pkg.name, devDeps[pkg.name])
  759. if (!doesChildVersionMatch({package: pkg}, requested, tree)) {
  760. return null
  761. }
  762. }
  763. if (tree.phantomChildren && tree.phantomChildren[pkg.name]) return null
  764. if (tree.isTop) return tree
  765. if (tree.isGlobal) return tree
  766. if (npm.config.get('global-style') && tree.parent.isTop) return tree
  767. if (npm.config.get('legacy-bundling')) return tree
  768. if (!preserveSymlinks() && /^[.][.][\\/]/.test(path.relative(tree.parent.realpath, tree.realpath))) return tree
  769. return (earliestInstallable(requiredBy, tree.parent, pkg, log) || tree)
  770. }