diff options
| author | nsfisis <nsfisis@gmail.com> | 2026-07-24 20:23:01 +0900 |
|---|---|---|
| committer | nsfisis <nsfisis@gmail.com> | 2026-07-24 20:23:01 +0900 |
| commit | 93733a249437e63774ac1989e0544b2d422e13b3 (patch) | |
| tree | c89f1121d291f5e60727c9bf0bee195933e0bc88 /crates/shirabe/src/package/loader | |
| parent | 8c316f2c5e93888f4b3a5b8c18df3373b54fa816 (diff) | |
| download | php-shirabe-93733a249437e63774ac1989e0544b2d422e13b3.tar.gz php-shirabe-93733a249437e63774ac1989e0544b2d422e13b3.tar.zst php-shirabe-93733a249437e63774ac1989e0544b2d422e13b3.zip | |
fix(pool-builder): use plain getPackages() on locked repository
PoolBuilder::build_pool() and warn_about_non_matching_update_allow_list()
called get_canonical_packages() on the locked repository during a
partial update, but PHP's PoolBuilder uses the plain getPackages().
get_canonical_packages() unwraps AliasPackage down to its base package,
discarding the alias's own version identity.
Locker::get_locked_repository() wraps a lock entry with
extra.branch-alias in a single CompleteAliasPackage rather than adding
a separate base object, so canonicalizing it silently dropped the
locked branch-alias version (e.g. 2.2.x-dev), leaving only the raw
dev-master version behind. For a package excluded from the partial
update's allow-list, that meant its locked branch-alias version could
no longer satisfy the root's constraint, producing a spurious solver
conflict instead of keeping the package pinned exactly as locked.
Fixed the same bug in AuditCommand's --locked package listing, which
had the identical get_canonical_packages()/getPackages() mismatch
against AuditCommand.php.
Diffstat (limited to 'crates/shirabe/src/package/loader')
0 files changed, 0 insertions, 0 deletions
