[agent] Found by the scheduled Gradle bug-hunt routine (ledger #319).
Summary
MavenCrawler treats build.gradle* / settings.gradle* as Java project markers, but then only crawls the Maven local repository ($MAVEN_REPO_LOCAL / $M2_HOME/repository / ~/.m2/repository). Gradle never writes there. It resolves into $GRADLE_USER_HOME/caches/modules-2/files-2.1/<group>/<artifact>/<version>/<sha1>/. On a normal Gradle-only project, scan (agent), scan --mode hosted and scan --mode vendored all return "status": "success", "scannedPackages": 0 and never query the API. As a result:
- the documented hosted Gradle path (
redirect_gradle_manual_snippet) can never fire unless ~/.m2 happens to hold the same GAV from unrelated Maven use;
- agent mode patches nothing, silently;
- nothing tells the user that Gradle dependencies weren't looked at.
Repro
mkdir gp && cd gp
echo "rootProject.name = 'gp'" > settings.gradle
cat > build.gradle <<'EOF'
plugins { id 'java' }
repositories { mavenCentral() }
dependencies { implementation 'org.apache.commons:commons-text:1.10.0' }
EOF
gradle dependencies --configuration runtimeClasspath # populates ~/.gradle/caches/modules-2, no ~/.m2
socket-patch scan --json # "status":"success","scannedPackages":0
socket-patch scan --mode hosted --json # same; redirect.warnings == []
A logging mock on --proxy-url confirms no /patch/batch request is ever sent. As a cross-check, scan --global-prefix ~/.gradle/caches/modules-2/files-2.1 does find [email protected] and [email protected] by POM content. So the data is there; it's just not in the discovery roots. (Agent apply couldn't use that root anyway: find_by_purls expects the Maven group/path/artifact/version layout, not Gradle's dotted group + per-file <sha1> directories.)
Expected vs actual
- Expected: docs/ecosystems.md presents Gradle as handled in hosted mode ("A present
build.gradle* / settings.gradle* gets a paste-able exclusiveContent { … } snippet"), and the crawler deliberately accepts Gradle markers (maven_crawler.rs:580). Gradle-resolved dependencies should be discovered, or the scan should at least warn that the Gradle cache isn't supported, instead of reporting a clean success.
- Actual: silent success with zero packages. Nowhere in README.md / docs/ecosystems.md is agent or hosted discovery for Gradle documented as unsupported (README's VEX table says "no Gradle" only for VEX discovery).
Matrix (Linux; each run twice)
| Gradle |
GRADLE_USER_HOME |
agent |
hosted |
vendored |
| 8.14.3 |
default ~/.gradle |
0 pkgs, success ❌ |
0 pkgs, success ❌ |
0 pkgs, success ❌ |
| 8.14.3 |
custom dir |
0 pkgs, success ❌ |
0 pkgs, success ❌ |
0 pkgs, success ❌ |
The cache layout (modules-2/files-2.1) has been the same since Gradle 1.x, so every major is affected. Tested on main f6b7fb9 (4.0.0).
Suspect code
crates/socket-patch-core/src/crawlers/maven_crawler.rs:580-605: Gradle markers select only m2_repo_path() (:709).
crates/socket-patch-core/src/crawlers/maven_crawler.rs find_by_purls: Maven layout only.
[agent] Found by the scheduled Gradle bug-hunt routine (ledger #319).
Summary
MavenCrawlertreatsbuild.gradle*/settings.gradle*as Java project markers, but then only crawls the Maven local repository ($MAVEN_REPO_LOCAL/$M2_HOME/repository/~/.m2/repository). Gradle never writes there. It resolves into$GRADLE_USER_HOME/caches/modules-2/files-2.1/<group>/<artifact>/<version>/<sha1>/. On a normal Gradle-only project,scan(agent),scan --mode hostedandscan --mode vendoredall return"status": "success", "scannedPackages": 0and never query the API. As a result:redirect_gradle_manual_snippet) can never fire unless~/.m2happens to hold the same GAV from unrelated Maven use;Repro
A logging mock on
--proxy-urlconfirms no/patch/batchrequest is ever sent. As a cross-check,scan --global-prefix ~/.gradle/caches/modules-2/files-2.1does find[email protected]and[email protected]by POM content. So the data is there; it's just not in the discovery roots. (Agentapplycouldn't use that root anyway:find_by_purlsexpects the Mavengroup/path/artifact/versionlayout, not Gradle's dotted group + per-file<sha1>directories.)Expected vs actual
build.gradle*/settings.gradle*gets a paste-ableexclusiveContent { … }snippet"), and the crawler deliberately accepts Gradle markers (maven_crawler.rs:580). Gradle-resolved dependencies should be discovered, or the scan should at least warn that the Gradle cache isn't supported, instead of reporting a clean success.Matrix (Linux; each run twice)
~/.gradleThe cache layout (
modules-2/files-2.1) has been the same since Gradle 1.x, so every major is affected. Tested on mainf6b7fb9(4.0.0).Suspect code
crates/socket-patch-core/src/crawlers/maven_crawler.rs:580-605: Gradle markers select onlym2_repo_path()(:709).crates/socket-patch-core/src/crawlers/maven_crawler.rsfind_by_purls: Maven layout only.