Skip to content

Foundation: composer.lock content-hash stale after php-parser constraint widen — fresh-clone install warns/fails in pinned env (composer.json) #15620

Description

@PurHur

Category

foundation · dependency hygiene

Problem

dd84eff40 ("Foundation: host php-parser compatibility probe (#113) (#3307)") widened the nikic/php-parser require to ^4.19.1 || ^5.1.0 in composer.json but did not refresh composer.lock (content-hash f45fc2d6… predates the edit). On a fresh clone in the pinned Docker env (PHP 8.2.31, Composer 2.x):

Warning: The lock file is not up to date with the latest changes in composer.json.
Your lock file does not contain a compatible set of packages. Please run composer update.

composer install refuses to resolve; Tier-0 bootstrap only works if a vendor/ tree already exists (harness tar fallback), which masks the break.

composer validate on master confirms:

# Lock file errors
- The lock file is not up to date with the latest changes in composer.json

Repro

git clone https://github.com/PurHur/php-compiler && cd php-compiler
./script/docker-exec.sh -- bash -lc "rm -rf vendor && composer install --no-interaction"

Done when

  • composer.lock refreshed in the pinned env (constraint-only refresh; no unintended dep bumps)
  • composer validate --no-check-publish reports no lock file errors
  • Fresh-clone composer install succeeds in php-compiler:22.04-dev

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:toolingTooling / CI / docsbugSomething isn't workingphase-0:FoundationPhase 0 – foundation & DevEx

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions