Bug hunt ledger: Maven #318
Replies: 2 comments
|
[agent] 2026-09-30: Maven bug-hunt run Tested: main Filed
Commented
Cells covered
False positives ruled out
Held (not filed yet)
Probe:
Next
|
|
[agent] 2026-09-30: Maven bug-hunt run Tested: main Re-triage: #342 and #350 are still open. main hasn't moved since they were filed, so there's nothing to re-check. Filed
Cells covered (Linux, 3.9.11 unless noted)
False positives ruled out
Probe: none this run. The stale branch Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Maven bug-hunt routine (label pm:maven).
Last updated: 2026-09-30 (run 2), main
f6b7fb9(CLI 4.0.0), latest release 4.0.0.Coverage matrix
Cells are "pass", "fail #N" or "untested". Every cell uses a real Maven resolve (
maven-dependency-plugin:3.1.2:copy-dependencies, fresh local repository) plus a jar oracle: the patch appends a marker toMETA-INF/NOTICE.txtoforg.apache.commons:commons-text:1.10.0. Vendored mode uses a hand-staged.socket/manifest.json+ blob, thenvendor --offline, then deletes the manifest and blobs (a fresh checkout). Hosted mode uses a local Python stub of the patch API + Socket maven2 repository. It serves the same grant astests/e2e_redirect_maven_build.rs(suffix1.10.0-socket.4d5e6f70), with asettings.xmlmirror ofsocket-patch-<uuid>onto the stub. Use plugin 3.1.2, not 3.6.1: 3.6.1 itself depends on commons-text 1.10.0 and pollutes the local repo (#274). Linux runs use JDK 21. The macOS / Windows probes use the runner's default JDK (17).%XXin path<repositories/><repositories/>,<dependencyManagement/>, comment in depMgmtfile://D:\...resolves)Backlog
bughunt/maven/20260930-vendored-paths: the git proxy refusedgit push --deletein runs 1 and 2. A maintainer needs to delete it.e2e_redirect_maven_build(SOCKET_PATCH_MAVEN_E2E_MVN=<mvn>) on 3.6.3 / 3.8.8 with a warm cache. In run 2, 3.8.8 failed once ate2e_redirect_maven_build.rs:437(the re-signed-jar resolve that should pass on <3.9). That's probably a Central 429, but it's unconfirmed..socket/vendor/maven/<uuid>/<group path>/…, and a CRLF checkout (core.autocrlf=true) of the committed.pom/.sha1sidecars. The probe script is in the run 1 entry.<dependency>blocks inside<exclusions>-heavy poms with unusual child order, BOMimportscope for the patched GA, and-ooffline on a fresh checkout (should fail loudly).<subprojects>aggregators (model 4.1.0): re-check on Maven 4.0.0 GA and with-pl childon a cold cache.Known non-bugs
patches-api.socket.dev/patch.socket.devaren't used. Stage manifests locally, or use the Python / wiremock stubs.maven-dependency-plugin:3.6.1depends on commons-text 1.10.0, so fixtures that patch commons-text 1.10.0 get the plugin realm's Central copy in the local repository (the same effect as Same-GAV Maven patches are shadowed when a build plugin depends on the same GAV in a reactor build #274). Use plugin 3.1.2 for the resolve oracle.InvalidPathException … unmappable characterson a unicode project path unlessLC_ALL=C.UTF-8. That's a sandbox artifact, not a socket-patch bug.<version>[1.10.0]</version>→redirect_maven_dep_version_mismatch,redirected: 0, nothing written: documented behaviour..pomfiles ("Non-parseable POM … Your…") are rate-limit artifacts. Delete poms under 200 bytes from the seed repo and retry.<subprojects>aggregator not refused by vendored mode: harmless on 4.0.0-rc-7 (see backlog 6).<classifier>and suffixes sources/tests/native classifier dependencies, which breaks the build #262, repository order / mirrors Vendored Maven silently resolves the unpatched jar when an earlier<repository>or amirrorOf *mirror serves the same GAV, and VEX still attests #263, crawler lists all of ~/.m2 Maven hosted scan pins, and VEX attests, artifacts the project doesn't depend on (the crawler lists all of~/.m2) #265, no re-pin Hosted Maven never re-pins: a superseding patch uuid or a rotated grant token leaves the old wiring in place #266, CI matrix Maven CI matrix has no Windows leg, a stale 4.0 RC, and no legs at the resolver boundaries #267, no hosted revert Hosted Maven redirects cannot be reverted, andremoverecommends an unscoped rollback that also fails #271, lowercased GAV Vendored Maven payload is written under the lowercased GAV, so mixed-case artifacts silently fall through to Central on case-sensitive file systems #272, CRLF Maven pom edits insert LF lines into CRLF pom.xml files (hosted and vendored) #273, plugin shadow Same-GAV Maven patches are shadowed when a build plugin depends on the same GAV in a reactor build #274).All reactions