feat(v5): implement vendored Maven reactors and Gradle builds - #287
Conversation
Vendored Maven today works for a single pom.xml only. It refuses multi-module reactors and Gradle builds, which covers most enterprise Java. This design says how vendored mode should handle both without dropping any Maven or Gradle version that works today. - Maven uses the server's suffixed version (<v>-socket.<hex8>), found through a committed maven2 tree. Maven 3.9.2+ reads it through maven.repo.local.tail; every version also gets a file:// fallback repository and dependencyManagement pins in each local root pom. - Gradle keeps the same coordinates. One owned settings script, applied by one line, adds an exclusiveContent file repository and checks the vendored files' sha256 on every configuration. Lockfiles, catalogs and build.gradle files are never edited. - Build-time Maven pins (trusted checksums, deny lines) are opt-in for later. The adversarial review found crashes and silent no-ops in them on common Maven versions. The doc includes the supported-shapes matrix, the failure modes, the refusal-code mapping, the migration plan, the server/CLI split, the test plan, the panel scores and the adversarial review findings. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_019ZLLAZfofQZ2ywkgrHkdEZ
|
CI note: This isn't caused by this PR. The head commit only adds Generated by Claude Code |
Workspace clippy with -D warnings failed on two fields of the covgap_commands_rollback fixture that nothing reads. The hashes are still computed and used to stage the manifest and blobs. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_019ZLLAZfofQZ2ywkgrHkdEZ
Vendored Maven refuses multi-module reactors and Gradle builds today. With SOCKET_PATCH_EXPERIMENTAL_JVM_VENDOR=1 set, those two shapes now go to a new backend (vendor/jvm) that implements the v5.0 cut of docs/design/maven-vendoring.md. With the variable unset, nothing that vendors today behaves differently. - Maven reactor: pins the server's suffixed version in every local root pom and rewrites literal and property declarations (including in profiles and middle parents). Adds one shared file:// fallback repository, two .mvn/maven.config lines (offline file protocol and maven.repo.local.tail) and a committed maven2 tree. - Gradle: keeps the same coordinates. One apply line per settings file (root, buildSrc, literal includeBuild) loads an owned script. It adds an exclusiveContent file repository and fails configuration if a vendored file's sha256 no longer matches the index. Lockfiles, catalogs and build scripts are never edited; an existing verification-metadata.xml gets the patched hash. - Revert is per fragment and byte-exact in any order. Shared pieces stay until no other patch uses them. Re-runs, patch updates, --preserve-state, the cold-cache fast path, VEX liveness and repair all handle the new trees. The real-tool capstones (e2e_vendor_jvm_build, ignored by default) build a reactor and a locked Kotlin DSL Gradle build offline from a fresh checkout. They pass on Maven 3.8.8 to 4.0.0-rc-7 and Gradle 6.9.4 to 9.8.0. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_019ZLLAZfofQZ2ywkgrHkdEZ
|
CI note for head 251b7a3: the Generated by Claude Code |
The previous commit dropped two fixture fields to quiet clippy on Linux. A macOS-only test reads them, so the macOS test build broke. Restore the fields and allow dead code on other platforms instead. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_019ZLLAZfofQZ2ywkgrHkdEZ
The owned Gradle script is embedded with include_str! and written into user repos as is. A Windows checkout with autocrlf turned it into CRLF, so Windows builds would write different script bytes (and the script sanity test failed there). Mark it -text like the other byte-exact files. Co-Authored-By: Claude Opus 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_019ZLLAZfofQZ2ywkgrHkdEZ
|
#283 landed on release/v5-prerelease as 06437d2; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
|
[agent] Not ready yet. The agent session's permission check is blocking the steps needed to land this.
Needed from a human or another session with push rights:
The only CI failures still expected are the base-branch ones already noted above. Generated by Claude Code |
|
#281 landed on release/v5-prerelease as 73c0c4f; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
|
#279 landed on release/v5-prerelease as f6bdad5; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
|
#282 landed on release/v5-prerelease as 14a9cb0; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
|
Coordinator: #287 is next in the landing order but is blocked: it is still a draft, has no Generated by Claude Code |
|
[agent] Replying to the coordinator: the blocker from my earlier comment (5870683708) still applies.
Until that happens, please skip #287 in the landing order. Generated by Claude Code |
|
#294 landed on release/v5-prerelease as 180f10f; please merge origin/release/v5-prerelease again, resolve conflicts, get green, and keep it ready. Generated by Claude Code |
|
Claude (@claude) review |
|
BugBot review |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 6 potential issues.
Bugbot Autofix prepared fixes for both issues found in the latest run.
- ✅ Fixed: Corrupt ledger routes off JVM backend
- Changed jvm_shape to fail-closed on load_state error and vendor_maven_jvm to propagate vendor_ledger_corrupt error instead of silently skipping peer records inheritance.
- ✅ Fixed: VEX misses live JVM wiring
- Changed maven_reactor::wired to return true on discovery errors and entry_wired to check escaped paths first, both implementing fail-closed semantics.
Or push these changes by commenting:
@cursor push 79ee1f8a1a
Preview (79ee1f8a1a)
diff --git a/crates/socket-patch-core/src/vendor/jvm/apply.rs b/crates/socket-patch-core/src/vendor/jvm/apply.rs
--- a/crates/socket-patch-core/src/vendor/jvm/apply.rs
+++ b/crates/socket-patch-core/src/vendor/jvm/apply.rs
@@ -619,13 +619,17 @@
uuid: &entry.uuid,
};
let reader = ProjectReader::new(root);
+ // Fail-closed: a path escaping the checkout is not proof the entry is
+ // unwired; treat it as still live (same as revert's refusal).
+ if reader.escaped().is_some() {
+ return true;
+ }
let read = |rel: &str| reader.read(rel);
- let wired = if is_gradle(&entry.wiring) {
+ if is_gradle(&entry.wiring) {
gradle::wired(&read, &c)
} else {
maven_reactor::wired(&read, &c)
- };
- wired && reader.escaped().is_none()
+ }
}
/// The vendored jar of the JVM `entry` for `uuid`, project-relative: the
diff --git a/crates/socket-patch-core/src/vendor/jvm/maven_reactor.rs b/crates/socket-patch-core/src/vendor/jvm/maven_reactor.rs
--- a/crates/socket-patch-core/src/vendor/jvm/maven_reactor.rs
+++ b/crates/socket-patch-core/src/vendor/jvm/maven_reactor.rs
@@ -352,12 +352,17 @@
/// (outside comments): the liveness proof `vex` needs for this layout.
pub fn wired(read: ReadFn<'_>, c: &Coords<'_>) -> bool {
let sv = c.suffixed_version();
- Reactor::discover(read).is_ok_and(|reactor| {
- reactor
+ match Reactor::discover(read) {
+ Ok(reactor) => reactor
.scope
.iter()
- .any(|rel| reactor.poms[rel].doc.masked.contains(&sv))
- })
+ .any(|rel| reactor.poms[rel].doc.masked.contains(&sv)),
+ Err(_) => {
+ // Fail-closed: discovery failure (broken pom, nested .mvn, etc.)
+ // is not proof the entry is unwired; treat it as still live.
+ true
+ }
+ }
}
/// `<!-- socket-patch <uuid>:` — the start of `c`'s pin comment.
diff --git a/crates/socket-patch-core/src/vendor/maven_repo.rs b/crates/socket-patch-core/src/vendor/maven_repo.rs
--- a/crates/socket-patch-core/src/vendor/maven_repo.rs
+++ b/crates/socket-patch-core/src/vendor/maven_repo.rs
@@ -716,9 +716,17 @@
/// flag), and only for a reactor or a Gradle build.
async fn jvm_shape(project_root: &Path) -> Option<super::jvm::Shape> {
if !super::jvm::experimental_enabled() {
- let state = super::state::load_state(project_root).await.ok()?;
- if !state.entries.values().any(super::jvm::apply::is_jvm_entry) {
- return None;
+ match super::state::load_state(project_root).await {
+ Ok(state) => {
+ if !state.entries.values().any(super::jvm::apply::is_jvm_entry) {
+ return None;
+ }
+ }
+ Err(_) => {
+ // Fail-closed: unreadable or corrupt ledger is never empty.
+ // Continue to detect shape so a corrupt ledger with JVM entries
+ // still routes to the JVM backend.
+ }
}
}
let reader = super::jvm::apply::ProjectReader::new(project_root);
@@ -914,8 +922,19 @@
};
// Shared fragments another JVM entry wrote, and the pristine originals
// of a patch update, come from the ledger (§7.3).
- if let Ok(state) = super::state::load_state(project_root).await {
- super::jvm::apply::inherit_peer_records(&mut wiring, state.entries.values());
+ match super::state::load_state(project_root).await {
+ Ok(state) => {
+ super::jvm::apply::inherit_peer_records(&mut wiring, state.entries.values());
+ }
+ Err(e) => {
+ // Fail-closed: unreadable or corrupt ledger is never empty. Without
+ // peer records, a later revert cannot restore shared fragments.
+ return done(
+ failed_result(purl, &jar_path, format!("vendor_ledger_corrupt: {e}")),
+ None,
+ warnings,
+ );
+ }
}
let entry = maven_entry(
build_maven_purl(&group_id, &artifact_id, &version),You can send follow-ups to the cloud agent here.
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit e3695a2. Configure here.
ae775fb
into
release/v5-prerelease


Enable committable vendoring for Maven reactors and Gradle builds in v5. A fresh checkout resolves patched dependencies from the committed repository without socket-patch or Socket API access.
--maven-config=nonesupports the fallback repository path.vendor --checkand optional local Maven cache conflict checks. Authenticate upstream bytes against registry checksums online and track offline provenance.Single-POM vendoring retains its existing backend. The implementation and supported limits are documented in
docs/design/maven-vendoring.md; The usage guide, README, CLI contract, and changelog follow the current v5 documentation structure.Validation:
The v5 refresh also corrects stale warning/help expectations and records canonical Composer restore fixtures where hosted mode cannot retain local mirror settings or the original source-block position.