Skip to content

scan reports success with 0 packages on a resolved Gradle project because the Gradle cache (~/.gradle/caches/modules-2) is never crawled #349

Description

[agent] Found by the scheduled Gradle bug-hunt routine (ledger #319).

Summary

MavenCrawler treats build.gradle* / settings.gradle* as Java project markers, but then only crawls the Maven local repository ($MAVEN_REPO_LOCAL / $M2_HOME/repository / ~/.m2/repository). Gradle never writes there. It resolves into $GRADLE_USER_HOME/caches/modules-2/files-2.1/<group>/<artifact>/<version>/<sha1>/. On a normal Gradle-only project, scan (agent), scan --mode hosted and scan --mode vendored all return "status": "success", "scannedPackages": 0 and never query the API. As a result:

  • the documented hosted Gradle path (redirect_gradle_manual_snippet) can never fire unless ~/.m2 happens to hold the same GAV from unrelated Maven use;
  • agent mode patches nothing, silently;
  • nothing tells the user that Gradle dependencies weren't looked at.

Repro

mkdir gp && cd gp
echo "rootProject.name = 'gp'" > settings.gradle
cat > build.gradle <<'EOF'
plugins { id 'java' }
repositories { mavenCentral() }
dependencies { implementation 'org.apache.commons:commons-text:1.10.0' }
EOF
gradle dependencies --configuration runtimeClasspath   # populates ~/.gradle/caches/modules-2, no ~/.m2
socket-patch scan --json                 # "status":"success","scannedPackages":0
socket-patch scan --mode hosted --json   # same; redirect.warnings == []

A logging mock on --proxy-url confirms no /patch/batch request is ever sent. As a cross-check, scan --global-prefix ~/.gradle/caches/modules-2/files-2.1 does find [email protected] and [email protected] by POM content. So the data is there; it's just not in the discovery roots. (Agent apply couldn't use that root anyway: find_by_purls expects the Maven group/path/artifact/version layout, not Gradle's dotted group + per-file <sha1> directories.)

Expected vs actual

  • Expected: docs/ecosystems.md presents Gradle as handled in hosted mode ("A present build.gradle* / settings.gradle* gets a paste-able exclusiveContent { … } snippet"), and the crawler deliberately accepts Gradle markers (maven_crawler.rs:580). Gradle-resolved dependencies should be discovered, or the scan should at least warn that the Gradle cache isn't supported, instead of reporting a clean success.
  • Actual: silent success with zero packages. Nowhere in README.md / docs/ecosystems.md is agent or hosted discovery for Gradle documented as unsupported (README's VEX table says "no Gradle" only for VEX discovery).

Matrix (Linux; each run twice)

Gradle GRADLE_USER_HOME agent hosted vendored
8.14.3 default ~/.gradle 0 pkgs, success ❌ 0 pkgs, success ❌ 0 pkgs, success ❌
8.14.3 custom dir 0 pkgs, success ❌ 0 pkgs, success ❌ 0 pkgs, success ❌

The cache layout (modules-2/files-2.1) has been the same since Gradle 1.x, so every major is affected. Tested on main f6b7fb9 (4.0.0).

Suspect code

  • crates/socket-patch-core/src/crawlers/maven_crawler.rs:580-605: Gradle markers select only m2_repo_path() (:709).
  • crates/socket-patch-core/src/crawlers/maven_crawler.rs find_by_purls: Maven layout only.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions