• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1'use strict'
2
3const BB = require('bluebird')
4
5var fs = require('fs')
6var assert = require('assert')
7var path = require('path')
8var semver = require('semver')
9var asyncMap = require('slide').asyncMap
10var chain = require('slide').chain
11var iferr = require('iferr')
12var npa = require('npm-package-arg')
13var validate = require('aproba')
14var dezalgo = require('dezalgo')
15var fetchPackageMetadata = require('../fetch-package-metadata.js')
16var andAddParentToErrors = require('./and-add-parent-to-errors.js')
17var addBundled = require('../fetch-package-metadata.js').addBundled
18var readShrinkwrap = require('./read-shrinkwrap.js')
19var inflateShrinkwrap = require('./inflate-shrinkwrap.js')
20var inflateBundled = require('./inflate-bundled.js')
21var andFinishTracker = require('./and-finish-tracker.js')
22var npm = require('../npm.js')
23var flatNameFromTree = require('./flatten-tree.js').flatNameFromTree
24var createChild = require('./node.js').create
25var resetMetadata = require('./node.js').reset
26var isInstallable = require('./validate-args.js').isInstallable
27var packageId = require('../utils/package-id.js')
28var moduleName = require('../utils/module-name.js')
29var isDevDep = require('./is-dev-dep.js')
30var isProdDep = require('./is-prod-dep.js')
31var reportOptionalFailure = require('./report-optional-failure.js')
32var getSaveType = require('./save.js').getSaveType
33var unixFormatPath = require('../utils/unix-format-path.js')
34var isExtraneous = require('./is-extraneous.js')
35var isRegistry = require('../utils/is-registry.js')
36var hasModernMeta = require('./has-modern-meta.js')
37
38// The export functions in this module mutate a dependency tree, adding
39// items to them.
40
41var registryTypes = { range: true, version: true }
42
43function doesChildVersionMatch (child, requested, requestor) {
44  if (child.fromShrinkwrap && !child.hasRequiresFromLock) return true
45  // ranges of * ALWAYS count as a match, because when downloading we allow
46  // prereleases to match * if there are ONLY prereleases
47  if (requested.type === 'range' && requested.fetchSpec === '*') return true
48
49  if (requested.type === 'directory') {
50    if (!child.isLink) return false
51    return path.relative(child.realpath, requested.fetchSpec) === ''
52  }
53
54  if (requested.type === 'git' && child.fromShrinkwrap) {
55    const fromSw = child.package._from ? npa(child.package._from) : child.fromShrinkwrap
56    fromSw.name = requested.name // we're only checking specifiers here
57    if (fromSw.toString() === requested.toString()) return true
58  }
59
60  if (requested.type === 'git' && requested.gitRange) {
61    const sameRepo = npa(child.package._from).fetchSpec === requested.fetchSpec
62    try {
63      return sameRepo && semver.satisfies(child.package.version, requested.gitRange, true)
64    } catch (e) {
65      return false
66    }
67  }
68
69  if (requested.type === 'alias') {
70    return doesChildVersionMatch(child, requested.subSpec, requestor)
71  }
72
73  if (!registryTypes[requested.type]) {
74    var childReq = child.package._requested
75    if (childReq) {
76      if (childReq.rawSpec === requested.rawSpec) return true
77      if (childReq.type === requested.type) {
78        if (childReq.saveSpec === requested.saveSpec) return true
79        if ((childReq.fetchSpec === requested.fetchSpec) && requested.type !== 'git') return true
80      }
81    }
82    // If _requested didn't exist OR if it didn't match then we'll try using
83    // _from. We pass it through npa to normalize the specifier.
84    // This can happen when installing from an `npm-shrinkwrap.json` where `_requested` will
85    // be the tarball URL from `resolved` and thus can't match what's in the `package.json`.
86    // In those cases _from, will be preserved and we can compare that to ensure that they
87    // really came from the same sources.
88    // You'll see this scenario happen with at least tags and git dependencies.
89    // Some buggy clients will write spaces into the module name part of a _from.
90    if (child.package._from) {
91      var fromReq = npa(child.package._from)
92      if (fromReq.rawSpec === requested.rawSpec) return true
93      if (fromReq.type === requested.type && fromReq.saveSpec && fromReq.saveSpec === requested.saveSpec) return true
94    }
95    return false
96  }
97  try {
98    return semver.satisfies(child.package.version, requested.fetchSpec, true)
99  } catch (e) {
100    return false
101  }
102}
103
104function childDependencySpecifier (tree, name, spec, where) {
105  return npa.resolve(name, spec, where || packageRelativePath(tree))
106}
107
108exports.computeMetadata = computeMetadata
109function computeMetadata (tree, seen) {
110  if (!seen) seen = new Set()
111  if (!tree || seen.has(tree)) return
112  seen.add(tree)
113  if (tree.parent == null) {
114    resetMetadata(tree)
115    tree.isTop = true
116  }
117  tree.location = flatNameFromTree(tree)
118
119  function findChild (name, spec, kind) {
120    try {
121      var req = childDependencySpecifier(tree, name, spec)
122    } catch (err) {
123      return
124    }
125    var child = findRequirement(tree, req.name, req)
126    if (child) {
127      resolveWithExistingModule(child, tree)
128      return true
129    }
130  }
131
132  const deps = tree.package.dependencies || {}
133  const reqs = tree.swRequires || {}
134  for (let name of Object.keys(deps)) {
135    if (findChild(name, deps[name])) continue
136    if (name in reqs && findChild(name, reqs[name])) continue
137    tree.missingDeps[name] = deps[name]
138  }
139  if (tree.isTop) {
140    const devDeps = tree.package.devDependencies || {}
141    for (let name of Object.keys(devDeps)) {
142      if (findChild(name, devDeps[name])) continue
143      tree.missingDevDeps[name] = devDeps[name]
144    }
145  }
146
147  tree.children.filter((child) => !child.removed).forEach((child) => computeMetadata(child, seen))
148
149  return tree
150}
151
152function isDep (tree, child) {
153  var name = moduleName(child)
154  var prodVer = isProdDep(tree, name)
155  var devVer = isDevDep(tree, name)
156
157  try {
158    var prodSpec = childDependencySpecifier(tree, name, prodVer)
159  } catch (err) {
160    return {isDep: true, isProdDep: false, isDevDep: false}
161  }
162  var matches
163  if (prodSpec) matches = doesChildVersionMatch(child, prodSpec, tree)
164  if (matches) return {isDep: true, isProdDep: prodSpec, isDevDep: false}
165  if (devVer === prodVer) return {isDep: child.fromShrinkwrap, isProdDep: false, isDevDep: false}
166  try {
167    var devSpec = childDependencySpecifier(tree, name, devVer)
168    return {isDep: doesChildVersionMatch(child, devSpec, tree) || child.fromShrinkwrap, isProdDep: false, isDevDep: devSpec}
169  } catch (err) {
170    return {isDep: child.fromShrinkwrap, isProdDep: false, isDevDep: false}
171  }
172}
173
174function addRequiredDep (tree, child) {
175  var dep = isDep(tree, child)
176  if (!dep.isDep) return false
177  replaceModuleByPath(child, 'requiredBy', tree)
178  replaceModuleByName(tree, 'requires', child)
179  if (dep.isProdDep && tree.missingDeps) delete tree.missingDeps[moduleName(child)]
180  if (dep.isDevDep && tree.missingDevDeps) delete tree.missingDevDeps[moduleName(child)]
181  return true
182}
183
184exports.removeObsoleteDep = removeObsoleteDep
185function removeObsoleteDep (child, log) {
186  if (child.removed) return
187  child.removed = true
188  if (log) {
189    log.silly('removeObsoleteDep', 'removing ' + packageId(child) +
190      ' from the tree as its been replaced by a newer version or is no longer required')
191  }
192  // remove from physical tree
193  if (child.parent) {
194    child.parent.children = child.parent.children.filter(function (pchild) { return pchild !== child })
195  }
196  // remove from logical tree
197  var requires = child.requires || []
198  requires.forEach(function (requirement) {
199    requirement.requiredBy = requirement.requiredBy.filter(function (reqBy) { return reqBy !== child })
200    // we don't just check requirement.requires because that doesn't account
201    // for circular deps.  isExtraneous does.
202    if (isExtraneous(requirement)) removeObsoleteDep(requirement, log)
203  })
204}
205
206exports.packageRelativePath = packageRelativePath
207function packageRelativePath (tree) {
208  if (!tree) return ''
209  var requested = tree.package._requested || {}
210  if (requested.type === 'directory') {
211    return requested.fetchSpec
212  } else if (requested.type === 'file') {
213    return path.dirname(requested.fetchSpec)
214  } else if ((tree.isLink || tree.isInLink) && !preserveSymlinks()) {
215    return tree.realpath
216  } else {
217    return tree.path
218  }
219}
220
221function matchingDep (tree, name) {
222  if (!tree || !tree.package) return
223  if (tree.package.dependencies && tree.package.dependencies[name]) return tree.package.dependencies[name]
224  if (tree.package.devDependencies && tree.package.devDependencies[name]) return tree.package.devDependencies[name]
225}
226
227exports.getAllMetadata = function (args, tree, where, next) {
228  asyncMap(args, function (arg, done) {
229    let spec
230    try {
231      spec = npa(arg)
232    } catch (e) {
233      return done(e)
234    }
235    if (spec.type !== 'file' && spec.type !== 'directory' && (spec.name == null || spec.rawSpec === '')) {
236      return fs.stat(path.join(arg, 'package.json'), (err) => {
237        if (err) {
238          var version = matchingDep(tree, spec.name)
239          if (version) {
240            try {
241              return fetchPackageMetadata(npa.resolve(spec.name, version), where, done)
242            } catch (e) {
243              return done(e)
244            }
245          } else {
246            return fetchPackageMetadata(spec, where, done)
247          }
248        } else {
249          try {
250            return fetchPackageMetadata(npa('file:' + arg), where, done)
251          } catch (e) {
252            return done(e)
253          }
254        }
255      })
256    } else {
257      return fetchPackageMetadata(spec, where, done)
258    }
259  }, next)
260}
261
262// Add a list of args to tree's top level dependencies
263exports.loadRequestedDeps = function (args, tree, saveToDependencies, log, next) {
264  validate('AOOF', [args, tree, log, next])
265  asyncMap(args, function (pkg, done) {
266    var depLoaded = andAddParentToErrors(tree, done)
267    resolveWithNewModule(pkg, tree, log.newGroup('loadRequestedDeps'), iferr(depLoaded, function (child, tracker) {
268      validate('OO', arguments)
269      if (npm.config.get('global')) {
270        child.isGlobal = true
271      }
272      var childName = moduleName(child)
273      child.saveSpec = computeVersionSpec(tree, child)
274      child.userRequired = true
275      child.save = getSaveType(tree, child)
276      const types = ['dependencies', 'devDependencies', 'optionalDependencies']
277      if (child.save) {
278        tree.package[child.save][childName] = child.saveSpec
279        // Astute readers might notice that this exact same code exists in
280        // save.js under a different guise. That code is responsible for deps
281        // being removed from the final written `package.json`. The removal in
282        // this function is specifically to prevent "installed as both X and Y"
283        // warnings when moving an existing dep between different dep fields.
284        //
285        // Or, try it by removing this loop, and do `npm i -P x && npm i -D x`
286        for (let saveType of types) {
287          if (child.save !== saveType) {
288            delete tree.package[saveType][childName]
289          }
290        }
291        if (child.save === 'optionalDependencies') tree.package.dependencies[childName] = child.saveSpec
292      }
293
294      // For things the user asked to install, that aren't a dependency (or
295      // won't be when we're done), flag it as "depending" on the user
296      // themselves, so we don't remove it as a dep that no longer exists
297      var childIsDep = addRequiredDep(tree, child)
298      if (!childIsDep) child.userRequired = true
299      depLoaded(null, child, tracker)
300    }))
301  }, andForEachChild(loadDeps, andFinishTracker(log, next)))
302}
303
304function isNotEmpty (value) {
305  return value != null && value !== ''
306}
307
308exports.computeVersionSpec = computeVersionSpec
309function computeVersionSpec (tree, child) {
310  validate('OO', arguments)
311  var requested
312  var childReq = child.package._requested
313  if (child.isLink) {
314    requested = npa.resolve(moduleName(child), 'file:' + child.realpath, getTop(tree).path)
315  } else if (childReq && (isNotEmpty(childReq.saveSpec) || (isNotEmpty(childReq.rawSpec) && isNotEmpty(childReq.fetchSpec)))) {
316    requested = child.package._requested
317  } else if (child.package._from) {
318    requested = npa(child.package._from, tree.path)
319  } else if (child.name && child.name !== child.package.name) {
320    requested = npa.resolve(child.name, `npm:${child.package.name}@${child.package.version})`)
321  } else {
322    requested = npa.resolve(child.package.name, child.package.version)
323  }
324  if (isRegistry(requested)) {
325    var version = child.package.version
326    var rangeDescriptor = ''
327    if (semver.valid(version, true) &&
328        semver.gte(version, '0.1.0', true) &&
329        !npm.config.get('save-exact')) {
330      rangeDescriptor = npm.config.get('save-prefix')
331    }
332    if (requested.type === 'alias') {
333      rangeDescriptor = `npm:${requested.subSpec.name}@${rangeDescriptor}`
334    }
335    return rangeDescriptor + version
336  } else if (requested.type === 'directory' || requested.type === 'file') {
337    return 'file:' + unixFormatPath(path.relative(getTop(tree).path, requested.fetchSpec))
338  } else {
339    return requested.saveSpec || requested.rawSpec
340  }
341}
342
343function moduleNameMatches (name) {
344  return function (child) { return moduleName(child) === name }
345}
346
347// while this implementation does not require async calling, doing so
348// gives this a consistent interface with loadDeps et al
349exports.removeDeps = function (args, tree, saveToDependencies, next) {
350  validate('AOSF|AOZF', [args, tree, saveToDependencies, next])
351  for (let pkg of args) {
352    var pkgName = moduleName(pkg)
353    var toRemove = tree.children.filter(moduleNameMatches(pkgName))
354    var pkgToRemove = toRemove[0] || createChild({name: pkgName})
355    var saveType = getSaveType(tree, pkg) || 'dependencies'
356    if (tree.isTop && saveToDependencies) {
357      pkgToRemove.save = saveType
358    }
359    if (tree.package[saveType][pkgName]) {
360      delete tree.package[saveType][pkgName]
361      if (saveType === 'optionalDependencies' && tree.package.dependencies[pkgName]) {
362        delete tree.package.dependencies[pkgName]
363      }
364    }
365    replaceModuleByPath(tree, 'removedChildren', pkgToRemove)
366    for (let parent of pkgToRemove.requiredBy) {
367      parent.requires = parent.requires.filter((child) => child !== pkgToRemove)
368    }
369    pkgToRemove.requiredBy = pkgToRemove.requiredBy.filter((parent) => parent !== tree)
370    flagAsRemoving(pkgToRemove)
371  }
372  next()
373}
374
375function flagAsRemoving (toRemove, seen) {
376  if (!seen) seen = new Set()
377  if (seen.has(toRemove)) return
378  seen.add(toRemove)
379  toRemove.removing = true
380  toRemove.requires.forEach((required) => {
381    flagAsRemoving(required, seen)
382  })
383}
384
385exports.removeExtraneous = function (args, tree, next) {
386  for (let pkg of args) {
387    var pkgName = moduleName(pkg)
388    var toRemove = tree.children.filter(moduleNameMatches(pkgName))
389    if (toRemove.length) {
390      removeObsoleteDep(toRemove[0])
391    }
392  }
393  next()
394}
395
396function andForEachChild (load, next) {
397  validate('F', [next])
398  next = dezalgo(next)
399  return function (er, children, logs) {
400    // when children is empty, logs won't be passed in at all (asyncMap is weird)
401    // so shortcircuit before arg validation
402    if (!er && (!children || children.length === 0)) return next()
403    validate('EAA', arguments)
404    if (er) return next(er)
405    assert(children.length === logs.length)
406    var cmds = []
407    for (var ii = 0; ii < children.length; ++ii) {
408      cmds.push([load, children[ii], logs[ii]])
409    }
410    var sortedCmds = cmds.sort(function installOrder (aa, bb) {
411      return moduleName(aa[1]).localeCompare(moduleName(bb[1]))
412    })
413    chain(sortedCmds, next)
414  }
415}
416
417function isDepOptional (tree, name, pkg) {
418  if (pkg.package && pkg.package._optional) return true
419  const optDeps = tree.package.optionalDependencies
420  if (optDeps && optDeps[name] != null) return true
421
422  const devDeps = tree.package.devDependencies
423  if (devDeps && devDeps[name] != null) {
424    const includeDev = npm.config.get('dev') ||
425      (!/^prod(uction)?$/.test(npm.config.get('only')) && !npm.config.get('production')) ||
426      /^dev(elopment)?$/.test(npm.config.get('only')) ||
427      /^dev(elopment)?$/.test(npm.config.get('also'))
428    return !includeDev
429  }
430  const prodDeps = tree.package.dependencies
431  if (prodDeps && prodDeps[name] != null) {
432    const includeProd = !/^dev(elopment)?$/.test(npm.config.get('only'))
433    return !includeProd
434  }
435  return false
436}
437
438exports.failedDependency = failedDependency
439function failedDependency (tree, name, pkg) {
440  if (name) {
441    if (isDepOptional(tree, name, pkg || {})) {
442      return false
443    }
444  }
445
446  tree.failed = true
447
448  if (tree.isTop) return true
449
450  if (tree.userRequired) return true
451
452  if (!tree.requiredBy) return false
453
454  let anyFailed = false
455  for (var ii = 0; ii < tree.requiredBy.length; ++ii) {
456    var requireParent = tree.requiredBy[ii]
457    if (failedDependency(requireParent, moduleName(tree), tree)) {
458      anyFailed = true
459    }
460  }
461  return anyFailed
462}
463
464function andHandleOptionalErrors (log, tree, name, done) {
465  validate('OOSF', arguments)
466  return function (er, child, childLog) {
467    if (!er) validate('OO', [child, childLog])
468    if (!er) return done(er, child, childLog)
469    var isFatal = failedDependency(tree, name)
470    if (er && !isFatal) {
471      reportOptionalFailure(tree, name, er)
472      return done()
473    } else {
474      return done(er, child, childLog)
475    }
476  }
477}
478
479exports.prefetchDeps = prefetchDeps
480function prefetchDeps (tree, deps, log, next) {
481  validate('OOOF', arguments)
482  var skipOptional = !npm.config.get('optional')
483  var seen = new Set()
484  const finished = andFinishTracker(log, next)
485  const fpm = BB.promisify(fetchPackageMetadata)
486  resolveBranchDeps(tree.package, deps).then(
487    () => finished(), finished
488  )
489
490  function resolveBranchDeps (pkg, deps) {
491    return BB.resolve(null).then(() => {
492      var allDependencies = Object.keys(deps).map((dep) => {
493        return npa.resolve(dep, deps[dep])
494      }).filter((dep) => {
495        return isRegistry(dep) &&
496               !seen.has(dep.toString()) &&
497               !findRequirement(tree, dep.name, dep)
498      })
499      if (skipOptional) {
500        var optDeps = pkg.optionalDependencies || {}
501        allDependencies = allDependencies.filter((dep) => !optDeps[dep.name])
502      }
503      return BB.map(allDependencies, (dep) => {
504        seen.add(dep.toString())
505        return fpm(dep, '', {tracker: log.newItem('fetchMetadata')}).then(
506          (pkg) => {
507            return pkg && pkg.dependencies && resolveBranchDeps(pkg, pkg.dependencies)
508          },
509          () => null
510        )
511      })
512    })
513  }
514}
515
516// Load any missing dependencies in the given tree
517exports.loadDeps = loadDeps
518function loadDeps (tree, log, next) {
519  validate('OOF', arguments)
520  if (tree.loaded || (tree.parent && tree.parent.failed) || tree.removed) return andFinishTracker.now(log, next)
521  if (tree.parent) tree.loaded = true
522  if (!tree.package.dependencies) tree.package.dependencies = {}
523  asyncMap(Object.keys(tree.package.dependencies), function (dep, done) {
524    var version = tree.package.dependencies[dep]
525    addDependency(dep, version, tree, log.newGroup('loadDep:' + dep), andHandleOptionalErrors(log, tree, dep, done))
526  }, andForEachChild(loadDeps, andFinishTracker(log, next)))
527}
528
529// Load development dependencies into the given tree
530exports.loadDevDeps = function (tree, log, next) {
531  validate('OOF', arguments)
532  if (!tree.package.devDependencies) return andFinishTracker.now(log, next)
533  asyncMap(Object.keys(tree.package.devDependencies), function (dep, done) {
534    // things defined as both dev dependencies and regular dependencies are treated
535    // as the former
536    if (tree.package.dependencies[dep]) return done()
537
538    var logGroup = log.newGroup('loadDevDep:' + dep)
539    addDependency(dep, tree.package.devDependencies[dep], tree, logGroup, andHandleOptionalErrors(log, tree, dep, done))
540  }, andForEachChild(loadDeps, andFinishTracker(log, next)))
541}
542
543var loadExtraneous = exports.loadExtraneous = function (tree, log, next) {
544  var seen = new Set()
545
546  function loadExtraneous (tree) {
547    if (seen.has(tree)) return
548    seen.add(tree)
549    for (var child of tree.children) {
550      if (child.loaded) continue
551      resolveWithExistingModule(child, tree)
552      loadExtraneous(child)
553    }
554  }
555  loadExtraneous(tree)
556  log.finish()
557  next()
558}
559
560exports.loadExtraneous.andResolveDeps = function (tree, log, next) {
561  validate('OOF', arguments)
562  // For canonicalized trees (eg from shrinkwrap) we don't want to bother
563  // resolving the dependencies of extraneous deps.
564  if (tree.loaded) return loadExtraneous(tree, log, next)
565  asyncMap(tree.children.filter(function (child) { return !child.loaded }), function (child, done) {
566    resolveWithExistingModule(child, tree)
567    done(null, child, log)
568  }, andForEachChild(loadDeps, andFinishTracker(log, next)))
569}
570
571function addDependency (name, versionSpec, tree, log, done) {
572  validate('SSOOF', arguments)
573  var next = andAddParentToErrors(tree, done)
574  try {
575    var req = childDependencySpecifier(tree, name, versionSpec)
576    if (tree.swRequires && tree.swRequires[name]) {
577      var swReq = childDependencySpecifier(tree, name, tree.swRequires[name])
578    }
579  } catch (err) {
580    return done(err)
581  }
582  var child = findRequirement(tree, name, req)
583  if (!child && swReq) child = findRequirement(tree, name, swReq)
584  if (hasModernMeta(child)) {
585    resolveWithExistingModule(child, tree)
586    if (child.package._shrinkwrap === undefined) {
587      readShrinkwrap.andInflate(child, function (er) { next(er, child, log) })
588    } else {
589      next(null, child, log)
590    }
591  } else {
592    if (child) {
593      if (req.registry) {
594        req = childDependencySpecifier(tree, name, child.package.version)
595      }
596      if (child.fromBundle) reportBundleOverride(child, log)
597      removeObsoleteDep(child, log)
598    }
599    fetchPackageMetadata(req, packageRelativePath(tree), {tracker: log.newItem('fetchMetadata')}, iferr(next, function (pkg) {
600      resolveWithNewModule(pkg, tree, log, next)
601    }))
602  }
603}
604
605function getTop (pkg) {
606  const seen = new Set()
607  while (pkg.parent && !seen.has(pkg.parent)) {
608    pkg = pkg.parent
609    seen.add(pkg)
610  }
611  return pkg
612}
613
614function reportBundleOverride (child, log) {
615  const code = 'EBUNDLEOVERRIDE'
616  const top = getTop(child.fromBundle)
617  const bundlerId = packageId(child.fromBundle)
618  if (!top.warnings.some((w) => {
619    return w.code === code
620  })) {
621    const err = new Error(`${bundlerId} had bundled packages that do not match the required version(s). They have been replaced with non-bundled versions.`)
622    err.code = code
623    top.warnings.push(err)
624  }
625  if (log) log.verbose('bundle', `${code}: Replacing ${bundlerId}'s bundled version of ${moduleName(child)} with ${packageId(child)}.`)
626}
627
628function resolveWithExistingModule (child, tree) {
629  validate('OO', arguments)
630  addRequiredDep(tree, child)
631  if (tree.parent && child.parent !== tree) updatePhantomChildren(tree.parent, child)
632}
633
634var updatePhantomChildren = exports.updatePhantomChildren = function (current, child) {
635  validate('OO', arguments)
636  while (current && current !== child.parent) {
637    if (!current.phantomChildren) current.phantomChildren = {}
638    current.phantomChildren[moduleName(child)] = child
639    current = current.parent
640  }
641}
642
643exports._replaceModuleByPath = replaceModuleByPath
644function replaceModuleByPath (obj, key, child) {
645  return replaceModule(obj, key, child, function (replacing, child) {
646    return replacing.path === child.path
647  })
648}
649
650exports._replaceModuleByName = replaceModuleByName
651function replaceModuleByName (obj, key, child) {
652  var childName = moduleName(child)
653  return replaceModule(obj, key, child, function (replacing, child) {
654    return moduleName(replacing) === childName
655  })
656}
657
658function replaceModule (obj, key, child, matchBy) {
659  validate('OSOF', arguments)
660  if (!obj[key]) obj[key] = []
661  // we replace children with a new array object instead of mutating it
662  // because mutating it results in weird failure states.
663  // I would very much like to know _why_ this is. =/
664  var children = [].concat(obj[key])
665  for (var replaceAt = 0; replaceAt < children.length; ++replaceAt) {
666    if (matchBy(children[replaceAt], child)) break
667  }
668  var replacing = children.splice(replaceAt, 1, child)
669  obj[key] = children
670  return replacing[0]
671}
672
673function resolveWithNewModule (pkg, tree, log, next) {
674  validate('OOOF', arguments)
675
676  log.silly('resolveWithNewModule', packageId(pkg), 'checking installable status')
677  return isInstallable(tree, pkg, (err) => {
678    let installable = !err
679    addBundled(pkg, (bundleErr) => {
680      var parent = earliestInstallable(tree, tree, pkg, log) || tree
681      var isLink = pkg._requested.type === 'directory'
682      var name = pkg._requested.name || pkg.name
683      var child = createChild({
684        name,
685        package: pkg,
686        parent: parent,
687        path: path.join(parent.isLink ? parent.realpath : parent.path, 'node_modules', name),
688        realpath: isLink ? pkg._requested.fetchSpec : path.join(parent.realpath, 'node_modules', name),
689        children: pkg._bundled || [],
690        isLink: isLink,
691        isInLink: parent.isLink,
692        knownInstallable: installable
693      })
694      if (!installable || bundleErr) child.failed = true
695      delete pkg._bundled
696      var hasBundled = child.children.length
697
698      var replaced = replaceModuleByName(parent, 'children', child)
699      if (replaced) {
700        if (replaced.fromBundle) reportBundleOverride(replaced, log)
701        removeObsoleteDep(replaced)
702      }
703      addRequiredDep(tree, child)
704      child.location = flatNameFromTree(child)
705
706      if (tree.parent && parent !== tree) updatePhantomChildren(tree.parent, child)
707
708      if (hasBundled) {
709        inflateBundled(child, child, child.children)
710      }
711
712      if (pkg._shrinkwrap && pkg._shrinkwrap.dependencies) {
713        return inflateShrinkwrap(child, pkg._shrinkwrap, (swErr) => {
714          if (swErr) child.failed = true
715          next(err || bundleErr || swErr, child, log)
716        })
717      }
718      next(err || bundleErr, child, log)
719    })
720  })
721}
722
723var isOptionalPeerDep = exports.isOptionalPeerDep = function (tree, pkgname) {
724  if (!tree.package.peerDependenciesMeta) return
725  if (!tree.package.peerDependenciesMeta[pkgname]) return
726  return !!tree.package.peerDependenciesMeta[pkgname].optional
727}
728
729var validatePeerDeps = exports.validatePeerDeps = function (tree, onInvalid) {
730  if (!tree.package.peerDependencies) return
731  Object.keys(tree.package.peerDependencies).forEach(function (pkgname) {
732    var version = tree.package.peerDependencies[pkgname]
733    try {
734      var spec = npa.resolve(pkgname, version)
735    } catch (e) {}
736    var match = spec && findRequirement(tree.parent || tree, pkgname, spec)
737    if (!match && !isOptionalPeerDep(tree, pkgname)) onInvalid(tree, pkgname, version)
738  })
739}
740
741exports.validateAllPeerDeps = function (tree, onInvalid) {
742  validateAllPeerDeps(tree, onInvalid, new Set())
743}
744
745function validateAllPeerDeps (tree, onInvalid, seen) {
746  validate('OFO', arguments)
747  if (seen.has(tree)) return
748  seen.add(tree)
749  validatePeerDeps(tree, onInvalid)
750  tree.children.forEach(function (child) { validateAllPeerDeps(child, onInvalid, seen) })
751}
752
753// Determine if a module requirement is already met by the tree at or above
754// our current location in the tree.
755var findRequirement = exports.findRequirement = function (tree, name, requested, requestor) {
756  validate('OSO', [tree, name, requested])
757  if (!requestor) requestor = tree
758  var nameMatch = function (child) {
759    return moduleName(child) === name && child.parent && !child.removed
760  }
761  var versionMatch = function (child) {
762    return doesChildVersionMatch(child, requested, requestor)
763  }
764  if (nameMatch(tree)) {
765    // this *is* the module, but it doesn't match the version, so a
766    // new copy will have to be installed
767    return versionMatch(tree) ? tree : null
768  }
769
770  var matches = tree.children.filter(nameMatch)
771  if (matches.length) {
772    matches = matches.filter(versionMatch)
773    // the module exists as a dependent, but the version doesn't match, so
774    // a new copy will have to be installed above here
775    if (matches.length) return matches[0]
776    return null
777  }
778  if (tree.isTop) return null
779  if (!preserveSymlinks() && /^[.][.][\\/]/.test(path.relative(tree.parent.realpath, tree.realpath))) return null
780  return findRequirement(tree.parent, name, requested, requestor)
781}
782
783function preserveSymlinks () {
784  if (!('NODE_PRESERVE_SYMLINKS' in process.env)) return false
785  const value = process.env.NODE_PRESERVE_SYMLINKS
786  if (value == null || value === '' || value === 'false' || value === 'no' || value === '0') return false
787  return true
788}
789
790// Find the highest level in the tree that we can install this module in.
791// If the module isn't installed above us yet, that'd be the very top.
792// If it is, then it's the level below where its installed.
793var earliestInstallable = exports.earliestInstallable = function (requiredBy, tree, pkg, log) {
794  validate('OOOO', arguments)
795
796  function undeletedModuleMatches (child) {
797    return !child.removed && moduleName(child) === ((pkg._requested && pkg._requested.name) || pkg.name)
798  }
799  const undeletedMatches = tree.children.filter(undeletedModuleMatches)
800  if (undeletedMatches.length) {
801    // if there's a conflict with another child AT THE SAME level then we're replacing it, so
802    // mark it as removed and continue with resolution normally.
803    if (tree === requiredBy) {
804      undeletedMatches.forEach((pkg) => {
805        if (pkg.fromBundle) reportBundleOverride(pkg, log)
806        removeObsoleteDep(pkg, log)
807      })
808    } else {
809      return null
810    }
811  }
812
813  // If any of the children of this tree have conflicting
814  // binaries then we need to decline to install this package here.
815  var binaryMatches = pkg.bin && tree.children.some(function (child) {
816    if (child.removed || !child.package.bin) return false
817    return Object.keys(child.package.bin).some(function (bin) {
818      return pkg.bin[bin]
819    })
820  })
821
822  if (binaryMatches) return null
823
824  // if this tree location requested the same module then we KNOW it
825  // isn't compatible because if it were findRequirement would have
826  // found that version.
827  var deps = tree.package.dependencies || {}
828  if (!tree.removed && requiredBy !== tree && deps[pkg.name]) {
829    return null
830  }
831
832  var devDeps = tree.package.devDependencies || {}
833  if (tree.isTop && devDeps[pkg.name]) {
834    var requested = childDependencySpecifier(tree, pkg.name, devDeps[pkg.name])
835    if (!doesChildVersionMatch({package: pkg}, requested, tree)) {
836      return null
837    }
838  }
839
840  if (tree.phantomChildren && tree.phantomChildren[pkg.name]) return null
841
842  if (tree.isTop) return tree
843  if (tree.isGlobal) return tree
844
845  if (npm.config.get('global-style') && tree.parent.isTop) return tree
846  if (npm.config.get('legacy-bundling')) return tree
847
848  if (!preserveSymlinks() && /^[.][.][\\/]/.test(path.relative(tree.parent.realpath, tree.realpath))) return tree
849
850  return (earliestInstallable(requiredBy, tree.parent, pkg, log) || tree)
851}
852