Expand description
vivacity-resolver: port of Composer 2.10.3’s dependency resolution: versions and constraints (composer/semver), Packagist v2 metadata, pool construction, then the solver. Each module is a port of the source vendored under docs/reference/resolver/, checked by an oracle against the phar.
Modules§
- config_
source - Port of
Composer\Config\JsonConfigSourcefor composer.json (not auth.json): every edit goes throughJsonManipulatoron the file text; if the manipulator gives up (false), Composer re-reads the file, applies the same modification to the decoded array and rewrites everything withJsonFile::write(detected indentation, empty arrays rendered as{}for keys that are objects in the schema). - constraint
- Port of
Composer\Semver\Constraint\*andVersionParser::parseConstraints(docs/reference/resolver/semver-Constraint.php, semver-MultiConstraint.php, semver-Bound.php, semver-VersionParser.php). A constraint is a tree: leaf (operator, normalized version), conjunction/disjunction, match-all, match-none.matchesreproducesConstraint::matchSpecific(and thusCompilingMatcher::match, which is merely a compiled form of it). - decisions
- Port of
Composer\DependencyResolver\Decisions: the decision map (package -> +/-level) and the decision queue with its rules. - flex_
filter - Port of
Symfony\Flex\PackageFilter(symfony/flex 2.11): Flex’sPRE_POOL_CREATElistener (Flex::truncatePackages) that removes from the pool, before it is created, the versions of the packages listed insymfony/symfonythat do not matchextra.symfony.require(SYMFONY_REQUIREwins; a trailing.xbecomes.x-dev). The data comes from the Flex endpoints’index.json, keyversions(splits: package → versions it ships in;next: the branch.xresolves to), merged first endpoint wins. Fetching and caching are the command layer’s business (vivacity::flex); this module is pure. - intervals
- Port of
Composer\Semver\Intervals(docs/reference/resolver/ semver-Intervals.php): a constraint becomes a list of numeric intervals[bound, bound]plus a set of branches (dev-*) that are either included or excluded;isSubsetOf,haveIntersectionsandcompactConstraintderive from it. PoolBuilder uses it to know whether an already loaded package covers a new constraint, and to merge constraints. - json_
manipulator - Port of
Composer\Json\JsonManipulator(docs/reference/JsonManipulator.php) for the scope reached byrequireandremove: textual editing of composer.json through regular expressions, so as to touch only the modified part and preserve the file’s formatting. - loader
- Port of
Composer\Package\Loader\ArrayLoader(docs/reference/resolver/ ArrayLoader.php) restricted to the model’s fields, and ofMetadataMinifier::expand. A JSON entry (p2 version or lock entry) becomes aPackage, plus its branch alias if any. - lockfile
- Lock writing: port of
ArrayDumper::dump(from the raw metadata and the model, withArrayLoader’s normalizations), ofLocker::lockPackagesand ofLocker::setLockData; JsonFile encoding. - merge_
plugin - Emulation of
wikimedia/composer-merge-pluginv2.1.0 (v2.0.1 alike; docs/reference/plugins/composer-merge-plugin/, MIT) for aninstalland an autoload dump: thecomposer.jsonfiles named byextra.merge-plugin.include/require(PHPglob()patterns, no flags) are merged into the root package —require/require-dev,autoload/autoload-dev(paths re-based on each file’s directory),conflict/replace/provide,extrawithmerge-extra— in the order and with the duplicate rules ofExtraPackage::mergeInto/mergeDevInto, recursively (recurse). - metacache
- Metadata cache of a
composerrepository, in Composer’s format and location (Cacheoncache-repo-dir/<sanitized url>/): same file names (packages.json,provider-<vendor>~<name>[~dev].json), same content (the JSON re-encoded withlast-modifiedinjected when the server sent the header, the raw body otherwise). A cache written by one is read by the other, and vice versa. - optimizer
- Port of
Composer\DependencyResolver\PoolOptimizer: removes from the pool the versions whose dependencies are identical to a preferred version, and those a locked package makes impossible. - package
- Package model of the resolver: port of
Composer\Package\{BasePackage, Package, CompletePackage, AliasPackage, Link}reduced to what the pool and the solver read, plus the raw JSON of the version (to write the lock identically). Packages live in an arena (Vec<Package>) and refer to each other by index, as Composer does by object identity. - path_
repo Composer\Repository\PathRepository(docs/reference/PathRepository.php): every directory matched by theurlglob that holds acomposer.jsonbecomes a package with apathdist. The dist reference issha1(json . serialize(options))(the raw file bytes and the repository options withrelativeauto-appended), replaced by the HEAD commit when the directory has a.gitof its own andreferenceisauto, null withreference: none. The version comes, in this order, fromoptions.versions[name], the package’sversion,COMPOSER_ROOT_VERSION(when the directory and the project share the same HEAD), the git guess (a feature branch adds the branch AND its parent as two packages), elsedev-main.- phpver
- Exact port of PHP’s
version_compare()(ext/standard/versioning.c): canonicalization (-,_,+->., a.inserted at every digit/non-digit transition), then component-by-component comparison; the special forms are ordereddev < alpha = a < beta = b < RC = rc < # < pl = p, a number counting as#. This is the ordering thatConstraint::versionCompare, the bounds and version sorting rely on. - platform
- Port of
Composer\Repository\PlatformRepository: the platform packages (composer*, php*, ext-, lib-, hhvm) in Composer’s exact order, with theconfig.platformoverrides. Probing the current PHP is done by assets/platform-probe.php (a transcription ofinitialize(), raw versions); normalization and its fallbacks are replayed here with the exact port of VersionParser. - platform_
filter - Port of
Composer\Filter\PlatformRequirementFilter\*: what--ignore-platform-reqs/--ignore-platform-reqremove from the rules. - policy
- Port of
Composer\DependencyResolver\DefaultPolicy: the choice of preferred versions (stability, highest/lowest, root alias, replacement, same vendor, pool id). - policy_
config - Port of
Composer\Policy\PolicyConfigand the policy classes (docs/reference/policy/*.php): whatconfig.policyand the legacyconfig.auditsay about the three pool filters (security advisories, filter lists (malware), abandoned packages) after the global/project merge ofConfig::merge, the environment variables (COMPOSER_POLICY,COMPOSER_POLICY_*_BLOCK,COMPOSER_NO_BLOCKING…) and--no-blocking. - pool
- Port of
Composer\DependencyResolver\{Request, PoolBuilder, Pool}andComposer\Repository\RepositorySet(docs/reference/resolver/). The pool is the ordered list of packages the solver will see: the order is Composer’s, index by index, because the literal ids depend on it. - pool_
filters - The filters
PoolBuilder::buildPoolapplies to the pool before the optimizer:SecurityAdvisoryPoolFilter(security advisories and abandoned packages) thenFilterListPoolFilter(filter lists, with Packagist’s malware list first), driven bycrate::policy_config::PolicyConfig. - problem
- Composer’s explanations of an unsolvable set: port of
SolverProblemsException::getPrettyString,Problem::getPrettyString(withgetMissingPackageReason,getPackageList,formatDeduplicatedRules…) andRule::getPrettyString(docs/reference/resolver/). The text is Composer’s--no-ansirendering: the output styles (<error>,<warning>,<info>,<comment>,<href=…>) are stripped, any other angle-bracket text is kept verbatim. - repository
- Repositories as seen by the pool:
ComposerRepositoryv2 (metadata-url, minified p2 files,~dev), the lock repository (LockArrayRepository), the root and the platform (lists of already loaded packages). Port of docs/reference/resolver/ComposerRepository.php (v2 path only: v1providers-url/provider-includes-> rejected). - root
- The root package as
RootPackageLoader::loadbuilds it (docs/reference/RootPackageLoader.php): version (composer.json, COMPOSER_ROOT_VERSION, git, otherwise1.0.0+no-version-set), links,minimum-stability,prefer-stable, and the three extractions from the require constraints: aliases (X as Y), stability flags (@dev, branches), references (#sha). - rule
- Port of
Rule,GenericRule,Rule2Literals,MultiConflictRuleandRuleSet(docs/reference/resolver/). Rules live in theRuleSetand are referred to by theirruleById; literals are signed pool ids. - rules_
gen - Port of
Composer\DependencyResolver\RuleSetGenerator. - session
- Setup of an
update: whatFactory::createComposerthenInstaller::doUpdatedo beforecreatePool: root, platform, repositories (global config + composer.json, same merge rules asConfig::merge), lock repository,Request. Rust-side replica of tools/oracle-pool.php. - solver
- Port of
Composer\DependencyResolver\Solver(CDCL) and of the skeleton ofProblem(the offending rules; messages come with R5). - transaction
- Port of
TransactionandLockTransaction: the packages kept by the decisions, the operations relative to the present lock, the packages to write into the lock. - version
- Port of
Composer\Semver\VersionParser(docs/reference/resolver/ semver-VersionParser.php):normalize,normalizeBranch,parseStability,parseNumericAliasPrefix, with the same PCRE expressions (pcre2), so that every string is accepted or rejected exactly as Composer does. - version_
selector - Port of
Composer\Package\Version\VersionSelector(docs/reference/VersionSelector.php): the best candidate for a name (preferred stability, then descending version, filtered by platform requirements) and the recommended constraint forrequire(^x.y,@stability, branch alias). - watch
- Port of
RuleWatchGraph,RuleWatchNode,RuleWatchChain: two watched literals per rule (all of them for a MultiConflictRule), one chain per literal, inserted at the head of the list (unshift).