Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Vendored Maven reactor with --maven-config=none can't build offline (mvn -o) on any Maven line, or from a module directory on Maven 3, because the fallback repo loses the offline-protocol line and the .mvn root marker

オープン
#430 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
68/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
活発
技術スタック
java, rust
領域
build-system

調査の方向性

Start in crates/socket-patch-core/src/vendor/jvm/maven_reactor.rs, especially the config_enabled branch at line 229, OFFLINE_LINE at line 27, and REPO_URL at line 32. Run the e2e_vendor_jvm_build::maven_reactor capstone with --maven-config=none on Maven 3.9.11 and 4.0.0-rc-7. Done means the documented none mode either preserves offline and module builds or clearly warns and documents those limitations.

索引モデルが issue の本文から書いたものです。

説明

agent:triaged bug bughunt pm:maven priority:p3

[agent] Found by the scheduled Maven bug-hunt routine (ledger #318).

Summary

v5 reactor vendoring has two wiring choices. --maven-config=auto (the default) writes .mvn/maven.config with -Daether.offline.protocols=file plus -Dmaven.repo.local.tail=…. --maven-config=none "uses only the fallback file repository": <url>file://${maven.multiModuleProjectDirectory}/.socket/vendor/maven2</url> in the local root pom. The docs recommend none as the workaround for the Maven 3.9.2–3.9.8 -f limitation.

With none, nothing is written under .mvn/, and the fallback repository relies on two things that .mvn/ provided:

  1. Offline builds break on every tested Maven line. Without aether.offline.protocols=file, mvn -o refuses the file:// repository: Cannot access socket-patch-vendor (file:///…/.socket/vendor/maven2) in offline mode and the artifact org.apache.commons:commons-text:jar:1.10.0-socket.1d3c1fd2 has not been downloaded from it before. Same checkout, same Maven, auto mode: mvn -o passes (the e2e_vendor_jvm_build capstone).
  2. Module invocations break on Maven 3.9. Without a .mvn/ directory, Maven 3 sets maven.multiModuleProjectDirectory to the directory it was started from. cd a && mvn … and mvn -f a/pom.xml from the root then look for the repository under a/.socket/vendor/maven2, which doesn't exist: Could not find artifact org.apache.commons:commons-text:jar:1.10.0-socket.1d3c1fd2. Maven 4.0.0-rc-7 detects the root here and passes.

Both fail loudly, because the suffixed coordinate exists nowhere else, so nothing silently goes unpatched. But a fresh checkout of a none-vendored reactor can't build in the two shapes that auto supports and that the capstone tests: offline, and cd <module>.

Impact

none is the documented escape hatch for Maven 3.9.2–3.9.8 users, and it persists in the ledger ("remains in effect on later runs and repair"). Projects that pick it lose offline / air-gapped builds (vendored mode's selling point: "hermetic, offline-safe installs") and, on Maven 3, per-module builds. Nothing warns about either, and the docs don't mention them.

Repro (Linux, JDK 21)

I used a local copy of the e2e_vendor_jvm_build::maven_reactor capstone, changed only to add --maven-config=none to the vendor call and to skip the .mvn/maven.config assertions:

# reactor: aggregator + corp-parent + a (commons-text 1.10.0 literal) + b; staged agent patch; then
socket-patch vendor --json --offline --maven-config=none      # exit 0, applied 1, no .mvn/ written
# fresh checkout (no manifest/blobs), commons-text purged from the local repository:
mvn -o package dependency:build-classpath                     # FAIL: Cannot access socket-patch-vendor (...) in offline mode
mvn package dependency:build-classpath                        # ok: module a resolves 1.10.0-socket.1d3c1fd2 (patched)
mvn -f /abs/root/pom.xml ... (from outside the root)          # ok
cd a && mvn package dependency:build-classpath                # FAIL (3.9.11): Could not find artifact ...:1.10.0-socket.1d3c1fd2
mvn -f a/pom.xml package ...  (from the root)                 # FAIL (3.9.11): same

The unmodified capstone (auto) passes on 3.9.11 and 4.0.0-rc-7, including the offline root build and the offline cd a build.

Expected vs actual

  • Expected: per docs/design/maven-vendoring.md, a vendored reactor commits "a local repository so another checkout can build without socket-patch or the Socket service", and none "uses the fallback file repository only". It is offered as the safe choice for awkward invocation shapes. The scan help describes vendored mode as "hermetic, offline-safe installs". So either the none wiring keeps offline and module builds working (for example by still writing .mvn/maven.config with only -Daether.offline.protocols=file, which also gives Maven 3 its root marker), or vendor warns that none gives up offline and module invocations, and the docs say so.
  • Actual: no warning, nothing in the docs, and mvn -o / module builds fail on a fresh checkout.

Matrix (Linux, JDK 21)

Maven auto capstone (root, -o, cd a -o) none: root online none: root -o none: cd a / -f a/pom.xml none: -f root from outside
3.6.3 blocked (Central 429 during fixture warm-up) blocked blocked blocked blocked
3.8.8 blocked (429) blocked blocked blocked pass
3.9.11 pass pass fail (2/2) fail (offline in the harness, online by hand, 2/2) pass
4.0.0-rc-7 pass pass fail (2/2) pass pass

macOS and Windows are untested. The cause is in the generated wiring, not the OS.

Tested on: main 2463257 (#277, the new reactor backend). There is no earlier release to bisect: the backend is new in this commit.

Suspect code

  • crates/socket-patch-core/src/vendor/jvm/maven_reactor.rs:229: if config_enabled { … } is the only place OFFLINE_LINE (maven_reactor.rs:27) is written, so none drops it along with the tail.
  • maven_reactor.rs:32: REPO_URL = "file://${maven.multiModuleProjectDirectory}/.socket/vendor/maven2". On Maven 3 this depends on a .mvn/ directory existing at the root, which only auto creates.
主要言語
Rust
スター
8
フォーク
0
平均マージ
18時間 4分
マージ済み PR(30日)
70

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

SocketDev/socket-patch のほかの issue

SocketDev/socket-patch の issue をすべて見る

似ている issue

Rust の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。