Class: Bundler::Definition

Inherits:
Object
  • Object
show all
Defined in:
lib/bundler/definition.rb

Class Attribute Summary collapse

Instance Attribute Summary collapse

Class Method Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(lockfile, dependencies, sources, unlock, ruby_version = nil, optional_groups = [], gemfiles = []) ⇒ Definition

How does the new system work?

  • Load information from Gemfile and Lockfile

  • Invalidate stale locked specs

  • All specs from stale source are stale

  • All specs that are reachable only through a stale dependency are stale.

  • If all fresh dependencies are satisfied by the locked

specs, then we can try to resolve locally.

Parameters:

  • lockfile (Pathname)

    Path to Gemfile.lock

  • dependencies (Array(Bundler::Dependency))

    array of dependencies from Gemfile

  • sources (Bundler::SourceList)
  • unlock (Hash, Boolean, nil)

    Gems that have been requested to be updated or true if all gems should be updated

  • ruby_version (Bundler::RubyVersion, nil) (defaults to: nil)

    Requested Ruby Version

  • optional_groups (Array(String)) (defaults to: [])

    A list of optional groups



61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
# File 'lib/bundler/definition.rb', line 61

def initialize(lockfile, dependencies, sources, unlock, ruby_version = nil, optional_groups = [], gemfiles = [])
  unlock ||= {}

  if unlock == true
    @unlocking_all = true
    strict = false
    @unlocking_bundler = false
    @unlocking = unlock
    @sources_to_unlock = []
    @unlocking_ruby = false
    @explicit_unlocks = []
    conservative = false
  else
    @unlocking_all = false
    strict = unlock.delete(:strict)
    @unlocking_bundler = unlock.delete(:bundler)
    @unlocking = unlock.any? {|_k, v| !Array(v).empty? }
    @sources_to_unlock = unlock.delete(:sources) || []
    @unlocking_ruby = unlock.delete(:ruby)
    @explicit_unlocks = unlock.delete(:gems) || []
    conservative = unlock.delete(:conservative)
  end

  @dependencies    = dependencies
  @sources         = sources
  @optional_groups = optional_groups
  @prefer_local    = false
  @specs           = nil
  @ruby_version    = ruby_version
  @gemfiles        = gemfiles

  @lockfile               = lockfile
  @lockfile_contents      = String.new

  @locked_bundler_version = nil
  @resolved_bundler_version = nil

  @locked_ruby_version = nil
  @new_platforms = []
  @removed_platforms = []
  @originally_invalid_platforms = []

  if lockfile_exists?
    @lockfile_contents = Bundler.read_file(lockfile)
    @locked_gems = LockfileParser.new(@lockfile_contents, strict: strict)
    @locked_platforms = @locked_gems.platforms
    @most_specific_locked_platform = @locked_gems.most_specific_locked_platform
    @platforms = @locked_platforms.dup
    @locked_bundler_version = @locked_gems.bundler_version
    @locked_ruby_version = @locked_gems.ruby_version
    @locked_deps = @locked_gems.dependencies
    @originally_locked_specs = SpecSet.new(@locked_gems.specs)
    @originally_locked_sources = @locked_gems.sources
    @locked_checksums = @locked_gems.checksums

    if @unlocking_all
      @locked_specs   = SpecSet.new([])
      @locked_sources = []
    else
      @locked_specs   = @originally_locked_specs
      @locked_sources = @originally_locked_sources
    end

    locked_gem_sources = @originally_locked_sources.select {|s| s.is_a?(Source::Rubygems) }
    multisource_lockfile = locked_gem_sources.size == 1 && locked_gem_sources.first.multiple_remotes?

    if multisource_lockfile
      msg = "Your lockfile contains a single rubygems source section with multiple remotes, which is insecure. Make sure you run `bundle install` in non frozen mode and commit the result to make your lockfile secure."

      Bundler::SharedHelpers.feature_removed! msg
    end
  else
    @locked_gems = nil
    @locked_platforms = []
    @most_specific_locked_platform = nil
    @platforms      = []
    @locked_deps    = {}
    @locked_specs   = SpecSet.new([])
    @locked_sources = []
    @originally_locked_specs = @locked_specs
    @originally_locked_sources = @locked_sources
    @locked_checksums = Bundler.settings[:lockfile_checksums]
  end

  @unlocking_ruby ||= if @ruby_version && locked_ruby_version_object
    @ruby_version.diff(locked_ruby_version_object)
  end
  @unlocking ||= @unlocking_ruby ||= (!@locked_ruby_version ^ !@ruby_version)

  @current_platform_missing = add_current_platform unless Bundler.frozen_bundle?

  @source_changes = converge_sources
  @path_changes = converge_paths

  if conservative
    @gems_to_unlock = @explicit_unlocks.any? ? @explicit_unlocks : @dependencies.map(&:name)
  else
    eager_unlock = @explicit_unlocks.map {|name| Dependency.new(name, ">= 0") }
    @gems_to_unlock = @locked_specs.for(eager_unlock, platforms).map(&:name).uniq
  end

  @dependency_changes = converge_dependencies
  @local_changes = converge_locals

  check_lockfile
end

Class Attribute Details

.no_lockObject

Do not create or modify a lockfile (Makes #lock a noop)



10
11
12
# File 'lib/bundler/definition.rb', line 10

def no_lock
  @no_lock
end

Instance Attribute Details

#dependenciesObject (readonly)

Returns the value of attribute dependencies.



15
16
17
# File 'lib/bundler/definition.rb', line 15

def dependencies
  @dependencies
end

#gemfilesObject (readonly)

Returns the value of attribute gemfiles.



15
16
17
# File 'lib/bundler/definition.rb', line 15

def gemfiles
  @gemfiles
end

#locked_checksumsObject (readonly)

Returns the value of attribute locked_checksums.



15
16
17
# File 'lib/bundler/definition.rb', line 15

def locked_checksums
  @locked_checksums
end

#locked_depsObject (readonly)

Returns the value of attribute locked_deps.



15
16
17
# File 'lib/bundler/definition.rb', line 15

def locked_deps
  @locked_deps
end

#locked_gemsObject (readonly)

Returns the value of attribute locked_gems.



15
16
17
# File 'lib/bundler/definition.rb', line 15

def locked_gems
  @locked_gems
end

#lockfileObject

Returns the value of attribute lockfile.



15
16
17
# File 'lib/bundler/definition.rb', line 15

def lockfile
  @lockfile
end

#platformsObject (readonly)

Returns the value of attribute platforms.



15
16
17
# File 'lib/bundler/definition.rb', line 15

def platforms
  @platforms
end

#ruby_versionObject (readonly)

Returns the value of attribute ruby_version.



15
16
17
# File 'lib/bundler/definition.rb', line 15

def ruby_version
  @ruby_version
end

#sourcesObject (readonly)

Returns the value of attribute sources.



15
16
17
# File 'lib/bundler/definition.rb', line 15

def sources
  @sources
end

Class Method Details

.build(gemfile, lockfile, unlock) ⇒ Bundler::Definition

Given a gemfile and lockfile creates a Bundler definition

Parameters:

  • gemfile (Pathname)

    Path to Gemfile

  • lockfile (Pathname, nil)

    Path to Gemfile.lock

  • unlock (Hash, Boolean, nil)

    Gems that have been requested to be updated or true if all gems should be updated

Returns:

Raises:



34
35
36
37
38
39
40
41
# File 'lib/bundler/definition.rb', line 34

def self.build(gemfile, lockfile, unlock)
  unlock ||= {}
  gemfile = Pathname.new(gemfile).expand_path

  raise GemfileNotFound, "#{gemfile} not found" unless gemfile.file?

  Dsl.evaluate(gemfile, lockfile, unlock)
end

Instance Method Details

#add_checksumsObject



552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
# File 'lib/bundler/definition.rb', line 552

def add_checksums
  require "rubygems/package"

  @locked_checksums = true

  setup_domain!(add_checksums: true)

  # force materialization to real specifications, so that checksums are fetched
  specs.each do |spec|
    next unless spec.source.is_a?(Bundler::Source::Rubygems)
    # Checksum was fetched from the compact index API.
    next if !spec.source.checksum_store.missing?(spec) && !spec.source.checksum_store.empty?(spec)
    # The gem isn't installed, can't compute the checksum.
    next unless spec.loaded_from

    package = Gem::Package.new(spec.source.cached_built_in_gem(spec))
    checksum = Checksum.from_gem_package(package)
    spec.source.checksum_store.register(spec, checksum)
  end
end

#add_platform(platform) ⇒ Object



526
527
528
529
530
531
# File 'lib/bundler/definition.rb', line 526

def add_platform(platform)
  return if @platforms.include?(platform)

  @new_platforms << platform
  @platforms << platform
end

#bundler_version_to_lockObject



454
455
456
# File 'lib/bundler/definition.rb', line 454

def bundler_version_to_lock
  @resolved_bundler_version || Bundler.gem_version
end

#check!Object



172
173
174
175
176
177
178
179
180
181
182
# File 'lib/bundler/definition.rb', line 172

def check!
  # If dependencies have changed, we need to resolve remotely. Otherwise,
  # since we'll be resolving with a single local source, we may end up
  # locking gems under the wrong source in the lockfile, and missing lockfile
  # checksums
  resolve_remotely! if @dependency_changes

  # Now do a local only resolve, to verify if any gems are missing locally
  sources.local_only!
  resolve
end

#current_dependenciesObject



290
291
292
# File 'lib/bundler/definition.rb', line 290

def current_dependencies
  filter_relevant(dependencies)
end

#current_locked_dependenciesObject



294
295
296
# File 'lib/bundler/definition.rb', line 294

def current_locked_dependencies
  filter_relevant(locked_dependencies)
end

#deleted_depsObject



318
319
320
# File 'lib/bundler/definition.rb', line 318

def deleted_deps
  @deleted_deps ||= locked_dependencies - @dependencies
end

#dependencies_for(groups) ⇒ Object



328
329
330
331
332
333
334
335
# File 'lib/bundler/definition.rb', line 328

def dependencies_for(groups)
  groups.map!(&:to_sym)
  deps = current_dependencies # always returns a new array
  deps.select! do |d|
    d.groups.intersect?(groups)
  end
  deps
end

#ensure_equivalent_gemfile_and_lockfile(explicit_flag = false) ⇒ Object

Raises:



463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
# File 'lib/bundler/definition.rb', line 463

def ensure_equivalent_gemfile_and_lockfile(explicit_flag = false)
  return unless Bundler.frozen_bundle?

  raise ProductionError, "Frozen mode is set, but there's no lockfile" unless lockfile_exists?

  msg = lockfile_changes_summary("frozen mode is set")
  return unless msg

  unless explicit_flag
    suggested_command = unless Bundler.settings.locations("frozen").keys.include?(:env)
      "bundle config set frozen false"
    end
    msg << "\n\nIf this is a development machine, remove the #{SharedHelpers.relative_lockfile_path} " \
           "freeze by running `#{suggested_command}`." if suggested_command
  end

  raise ProductionError, msg
end

#filter_relevant(dependencies) ⇒ Object



298
299
300
301
302
# File 'lib/bundler/definition.rb', line 298

def filter_relevant(dependencies)
  dependencies.select do |d|
    relevant_deps?(d)
  end
end

#gem_version_promoterObject



168
169
170
# File 'lib/bundler/definition.rb', line 168

def gem_version_promoter
  @gem_version_promoter ||= GemVersionPromoter.new
end

#groupsObject



369
370
371
# File 'lib/bundler/definition.rb', line 369

def groups
  dependencies.flat_map(&:groups).uniq
end

#lock(file_or_preserve_unknown_sections = false, preserve_unknown_sections_or_unused = false) ⇒ Object



373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
# File 'lib/bundler/definition.rb', line 373

def lock(file_or_preserve_unknown_sections = false, preserve_unknown_sections_or_unused = false)
  if [true, false, nil].include?(file_or_preserve_unknown_sections)
    target_lockfile = lockfile
    preserve_unknown_sections = file_or_preserve_unknown_sections
  else
    target_lockfile = file_or_preserve_unknown_sections
    preserve_unknown_sections = preserve_unknown_sections_or_unused

    suggestion = if target_lockfile == lockfile
      "To fix this warning, remove it from the `Definition#lock` call."
    else
      "Instead, instantiate a new definition passing `#{target_lockfile}`, and call `lock` without a file argument on that definition"
    end

    msg = "`Definition#lock` was passed a target file argument. #{suggestion}"

    Bundler::SharedHelpers.feature_removed! msg
  end

  write_lock(target_lockfile, preserve_unknown_sections)
end

#locked_dependenciesObject



310
311
312
# File 'lib/bundler/definition.rb', line 310

def locked_dependencies
  @locked_deps.values
end

#locked_ruby_versionObject



433
434
435
436
437
438
439
440
# File 'lib/bundler/definition.rb', line 433

def locked_ruby_version
  return unless ruby_version
  if @unlocking_ruby || !@locked_ruby_version
    Bundler::RubyVersion.system
  else
    @locked_ruby_version
  end
end

#locked_ruby_version_objectObject



442
443
444
445
446
447
448
449
450
451
452
# File 'lib/bundler/definition.rb', line 442

def locked_ruby_version_object
  return unless @locked_ruby_version
  @locked_ruby_version_object ||= begin
    unless version = RubyVersion.from_string(@locked_ruby_version)
      raise LockfileError, "The Ruby version #{@locked_ruby_version} from " \
        "#{@lockfile} could not be parsed. " \
        "Try running bundle update --ruby to resolve this."
    end
    version
  end
end

#missing_specsObject



261
262
263
264
# File 'lib/bundler/definition.rb', line 261

def missing_specs
  preload_git_sources
  resolve.missing_specs_for(requested_dependencies)
end

#missing_specs?Boolean

Returns:

  • (Boolean)


266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
# File 'lib/bundler/definition.rb', line 266

def missing_specs?
  missing = missing_specs
  return false if missing.empty?
  Bundler.ui.debug "The definition is missing #{missing.map(&:full_name)}"
  true
rescue BundlerError => e
  @resolve = nil
  @resolver = nil
  @resolution_base = nil
  @source_requirements = nil
  @specs = nil

  Bundler.ui.debug "The definition is missing dependencies, failed to resolve & materialize locally (#{e})"
  true
end

#new_depsObject



314
315
316
# File 'lib/bundler/definition.rb', line 314

def new_deps
  @new_deps ||= @dependencies - locked_dependencies
end

#new_specsObject



253
254
255
# File 'lib/bundler/definition.rb', line 253

def new_specs
  specs - @locked_specs
end

#no_resolve_needed?Boolean

Returns:

  • (Boolean)


544
545
546
# File 'lib/bundler/definition.rb', line 544

def no_resolve_needed?
  !resolve_needed?
end

#normalize_platformsObject



520
521
522
523
524
# File 'lib/bundler/definition.rb', line 520

def normalize_platforms
  resolve.normalize_platforms!(current_dependencies, platforms)

  @resolve = SpecSet.new(resolve.for(current_dependencies, @platforms))
end

#nothing_changed?Boolean

Returns:

  • (Boolean)


540
541
542
# File 'lib/bundler/definition.rb', line 540

def nothing_changed?
  !something_changed?
end

#prefer_local!Object



227
228
229
230
231
# File 'lib/bundler/definition.rb', line 227

def prefer_local!
  @prefer_local = true

  sources.prefer_local!
end

#release_resolution_memory!Object

Releases memory only needed during resolution, such as remote spec indexes and resolver state. Only safe to call once resolution is complete and the result has been materialized, since any further resolution will need to refetch remote specs.



237
238
239
240
241
# File 'lib/bundler/definition.rb', line 237

def release_resolution_memory!
  @resolver = nil
  @resolution_base = nil
  sources.release_resolution_memory!
end

#relevant_deps?(dep) ⇒ Boolean

Returns:

  • (Boolean)


304
305
306
307
308
# File 'lib/bundler/definition.rb', line 304

def relevant_deps?(dep)
  platforms_array = [Bundler.generic_local_platform].freeze

  dep.should_include? && !dep.gem_platforms(platforms_array).empty?
end

#remotely!Object



222
223
224
225
# File 'lib/bundler/definition.rb', line 222

def remotely!
  sources.cached!
  sources.remote!
end

#remove_platform(platform) ⇒ Object

Raises:



533
534
535
536
537
538
# File 'lib/bundler/definition.rb', line 533

def remove_platform(platform)
  raise InvalidOption, "Unable to remove the platform `#{platform}` since the only platforms are #{@platforms.join ", "}" unless @platforms.include?(platform)

  @removed_platforms << platform
  @platforms.delete(platform)
end

#removed_specsObject



257
258
259
# File 'lib/bundler/definition.rb', line 257

def removed_specs
  @locked_specs - specs
end

#requested_dependenciesObject



286
287
288
# File 'lib/bundler/definition.rb', line 286

def requested_dependencies
  dependencies_for(requested_groups)
end

#requested_specsObject



282
283
284
# File 'lib/bundler/definition.rb', line 282

def requested_specs
  specs_for(requested_groups)
end

#resolveSpecSet

Resolve all the dependencies specified in Gemfile. It ensures that dependencies that have been already resolved via locked file and are fresh are reused when resolving dependencies

Returns:

  • (SpecSet)

    resolved dependencies



342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
# File 'lib/bundler/definition.rb', line 342

def resolve
  @resolve ||= if Bundler.frozen_bundle?
    Bundler.ui.debug "Frozen, using resolution from the lockfile"
    @locked_specs
  elsif no_resolve_needed?
    if deleted_deps.any?
      Bundler.ui.debug "Some dependencies were deleted, using a subset of the resolution from the lockfile"
      SpecSet.new(filter_specs(@locked_specs, @dependencies - deleted_deps))
    else
      Bundler.ui.debug "Found no changes, using resolution from the lockfile"
      if @removed_platforms.any? || @locked_gems.may_include_redundant_platform_specific_gems?
        SpecSet.new(filter_specs(@locked_specs, @dependencies))
      else
        @locked_specs
      end
    end
  else
    Bundler.ui.debug resolve_needed_reason

    start_resolution
  end
end

#resolve_remotely!Object



216
217
218
219
220
# File 'lib/bundler/definition.rb', line 216

def resolve_remotely!
  remotely!

  resolve
end

#resolve_with_cache!Object



205
206
207
208
209
# File 'lib/bundler/definition.rb', line 205

def resolve_with_cache!
  with_cache!

  resolve
end

#setup_domain!(options = {}) ⇒ Boolean

Setup sources according to the given options and the state of the definition.

Returns:

  • (Boolean)

    Whether fetching remote information will be necessary or not



190
191
192
193
194
195
196
197
198
199
200
201
202
203
# File 'lib/bundler/definition.rb', line 190

def setup_domain!(options = {})
  prefer_local! if options[:"prefer-local"]

  sources.cached!

  if options[:add_checksums] || (!options[:local] && install_needed?)
    sources.remote!
    true
  else
    Bundler.settings.set_command_option(:jobs, 1) unless install_needed? # to avoid the overhead of Bundler::Worker
    sources.local!
    false
  end
end

#spec_git_pathsObject



365
366
367
# File 'lib/bundler/definition.rb', line 365

def spec_git_paths
  sources.git_sources.filter_map {|s| File.realpath(s.path) if File.exist?(s.path) }
end

#specsBundler::SpecSet

For given dependency list returns a SpecSet with Gemspec of all the required dependencies.

1. The method first resolves the dependencies specified in Gemfile
2. After that it tries and fetches gemspec of resolved dependencies

Returns:



249
250
251
# File 'lib/bundler/definition.rb', line 249

def specs
  @specs ||= materialize(requested_dependencies)
end

#specs_for(groups) ⇒ Object



322
323
324
325
326
# File 'lib/bundler/definition.rb', line 322

def specs_for(groups)
  return specs if groups.empty?
  deps = dependencies_for(groups)
  materialize(deps)
end

#to_lockObject



458
459
460
461
# File 'lib/bundler/definition.rb', line 458

def to_lock
  require_relative "lockfile_generator"
  LockfileGenerator.generate(self)
end

#unlocking?Boolean

Returns:

  • (Boolean)


548
549
550
# File 'lib/bundler/definition.rb', line 548

def unlocking?
  @unlocking
end

#validate_platforms!Object

Raises:



512
513
514
515
516
517
518
# File 'lib/bundler/definition.rb', line 512

def validate_platforms!
  return if current_platform_locked? || @platforms.include?(Gem::Platform::RUBY)

  raise ProductionError, "Your bundle only supports platforms #{@platforms.map(&:to_s)} " \
    "but your local platform is #{Bundler.local_platform}. " \
    "Add the current platform to the lockfile with\n`bundle lock --add-platform #{Bundler.local_platform}` and try again."
end

#validate_ruby!Object



487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
# File 'lib/bundler/definition.rb', line 487

def validate_ruby!
  return unless ruby_version

  if diff = ruby_version.diff(Bundler::RubyVersion.system)
    problem, expected, actual = diff

    msg = case problem
          when :engine
            "Your Ruby engine is #{actual}, but your Gemfile specified #{expected}"
          when :version
            "Your Ruby version is #{actual}, but your Gemfile specified #{expected}"
          when :engine_version
            "Your #{Bundler::RubyVersion.system.engine} version is #{actual}, but your Gemfile specified #{ruby_version.engine} #{expected}"
          when :patchlevel
            if !expected.is_a?(String)
              "The Ruby patchlevel in your Gemfile must be a string"
            else
              "Your Ruby patchlevel is #{actual}, but your Gemfile specified #{expected}"
            end
    end

    raise RubyVersionMismatch, msg
  end
end

#validate_runtime!Object



482
483
484
485
# File 'lib/bundler/definition.rb', line 482

def validate_runtime!
  validate_ruby!
  validate_platforms!
end

#with_cache!Object



211
212
213
214
# File 'lib/bundler/definition.rb', line 211

def with_cache!
  sources.local!
  sources.cached!
end

#write_lock(file, preserve_unknown_sections) ⇒ Object



395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
# File 'lib/bundler/definition.rb', line 395

def write_lock(file, preserve_unknown_sections)
  return if Definition.no_lock || !lockfile || file.nil?

  contents = to_lock

  # Convert to \r\n if the existing lock has them
  # i.e., Windows with `git config core.autocrlf=true`
  contents.gsub!(/\n/, "\r\n") if @lockfile_contents.match?("\r\n")

  if @locked_bundler_version
    locked_major = @locked_bundler_version.segments.first
    current_major = bundler_version_to_lock.segments.first

    updating_major = locked_major < current_major
  end

  preserve_unknown_sections ||= !updating_major && (Bundler.frozen_bundle? || !(unlocking? || @unlocking_bundler))

  if File.exist?(file) && lockfiles_equal?(@lockfile_contents, contents, preserve_unknown_sections)
    return if Bundler.frozen_bundle?
    SharedHelpers.filesystem_access(file) { FileUtils.touch(file) }
    return
  end

  if Bundler.frozen_bundle?
    Bundler.ui.error "Cannot write a changed lockfile while frozen."
    return
  end

  begin
    SharedHelpers.filesystem_access(file) do |p|
      File.open(p, "wb") {|f| f.puts(contents) }
    end
  rescue ReadOnlyFileSystemError
    raise ProductionError, lockfile_changes_summary("file system is read-only")
  end
end