Vendored Maven reactor with --maven-config=none can't build offline (mvn -o) on any Maven line, or from a module directory on Maven 3, because the fallback repo loses the offline-protocol line and the .mvn root marker
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 68/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Lĩnh vực
- build-system
Hướng nghiên cứu
Start in crates/socket-patch-core/src/vendor/jvm/maven_reactor.rs, especially the config_enabled branch at line 229, OFFLINE_LINE at line 27, and REPO_URL at line 32. Run the e2e_vendor_jvm_build::maven_reactor capstone with --maven-config=none on Maven 3.9.11 and 4.0.0-rc-7. Done means the documented none mode either preserves offline and module builds or clearly warns and documents those limitations.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
[agent] Found by the scheduled Maven bug-hunt routine (ledger #318).
Summary
v5 reactor vendoring has two wiring choices. --maven-config=auto (the default) writes .mvn/maven.config with -Daether.offline.protocols=file plus -Dmaven.repo.local.tail=…. --maven-config=none "uses only the fallback file repository": <url>file://${maven.multiModuleProjectDirectory}/.socket/vendor/maven2</url> in the local root pom. The docs recommend none as the workaround for the Maven 3.9.2–3.9.8 -f limitation.
With none, nothing is written under .mvn/, and the fallback repository relies on two things that .mvn/ provided:
- Offline builds break on every tested Maven line. Without
aether.offline.protocols=file,mvn -orefuses thefile://repository:Cannot access socket-patch-vendor (file:///…/.socket/vendor/maven2) in offline mode and the artifact org.apache.commons:commons-text:jar:1.10.0-socket.1d3c1fd2 has not been downloaded from it before.Same checkout, same Maven,automode:mvn -opasses (thee2e_vendor_jvm_buildcapstone). - Module invocations break on Maven 3.9. Without a
.mvn/directory, Maven 3 setsmaven.multiModuleProjectDirectoryto the directory it was started from.cd a && mvn …andmvn -f a/pom.xmlfrom the root then look for the repository undera/.socket/vendor/maven2, which doesn't exist:Could not find artifact org.apache.commons:commons-text:jar:1.10.0-socket.1d3c1fd2. Maven 4.0.0-rc-7 detects the root here and passes.
Both fail loudly, because the suffixed coordinate exists nowhere else, so nothing silently goes unpatched. But a fresh checkout of a none-vendored reactor can't build in the two shapes that auto supports and that the capstone tests: offline, and cd <module>.
Impact
none is the documented escape hatch for Maven 3.9.2–3.9.8 users, and it persists in the ledger ("remains in effect on later runs and repair"). Projects that pick it lose offline / air-gapped builds (vendored mode's selling point: "hermetic, offline-safe installs") and, on Maven 3, per-module builds. Nothing warns about either, and the docs don't mention them.
Repro (Linux, JDK 21)
I used a local copy of the e2e_vendor_jvm_build::maven_reactor capstone, changed only to add --maven-config=none to the vendor call and to skip the .mvn/maven.config assertions:
# reactor: aggregator + corp-parent + a (commons-text 1.10.0 literal) + b; staged agent patch; then
socket-patch vendor --json --offline --maven-config=none # exit 0, applied 1, no .mvn/ written
# fresh checkout (no manifest/blobs), commons-text purged from the local repository:
mvn -o package dependency:build-classpath # FAIL: Cannot access socket-patch-vendor (...) in offline mode
mvn package dependency:build-classpath # ok: module a resolves 1.10.0-socket.1d3c1fd2 (patched)
mvn -f /abs/root/pom.xml ... (from outside the root) # ok
cd a && mvn package dependency:build-classpath # FAIL (3.9.11): Could not find artifact ...:1.10.0-socket.1d3c1fd2
mvn -f a/pom.xml package ... (from the root) # FAIL (3.9.11): same
The unmodified capstone (auto) passes on 3.9.11 and 4.0.0-rc-7, including the offline root build and the offline cd a build.
Expected vs actual
- Expected: per docs/design/maven-vendoring.md, a vendored reactor commits "a local repository so another checkout can build without socket-patch or the Socket service", and
none"uses the fallback file repository only". It is offered as the safe choice for awkward invocation shapes. The scan help describes vendored mode as "hermetic, offline-safe installs". So either thenonewiring keeps offline and module builds working (for example by still writing.mvn/maven.configwith only-Daether.offline.protocols=file, which also gives Maven 3 its root marker), orvendorwarns thatnonegives up offline and module invocations, and the docs say so. - Actual: no warning, nothing in the docs, and
mvn -o/ module builds fail on a fresh checkout.
Matrix (Linux, JDK 21)
| Maven | auto capstone (root, -o, cd a -o) |
none: root online |
none: root -o |
none: cd a / -f a/pom.xml |
none: -f root from outside |
|---|---|---|---|---|---|
| 3.6.3 | blocked (Central 429 during fixture warm-up) | blocked | blocked | blocked | blocked |
| 3.8.8 | blocked (429) | blocked | blocked | blocked | pass |
| 3.9.11 | pass | pass | fail (2/2) | fail (offline in the harness, online by hand, 2/2) | pass |
| 4.0.0-rc-7 | pass | pass | fail (2/2) | pass | pass |
macOS and Windows are untested. The cause is in the generated wiring, not the OS.
Tested on: main 2463257 (#277, the new reactor backend). There is no earlier release to bisect: the backend is new in this commit.
Suspect code
crates/socket-patch-core/src/vendor/jvm/maven_reactor.rs:229:if config_enabled { … }is the only placeOFFLINE_LINE(maven_reactor.rs:27) is written, sononedrops it along with the tail.maven_reactor.rs:32:REPO_URL = "file://${maven.multiModuleProjectDirectory}/.socket/vendor/maven2". On Maven 3 this depends on a.mvn/directory existing at the root, which onlyautocreates.
- Ngôn ngữ chính
- Rust
- Star
- 8
- Fork
- 0
- Merge trung bình
- 19 giờ 21 phút
- Pull request đã merge (30 ngày)
- 421
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của SocketDev/socket-patch
-
agent:triaged bug bughunt pm:npm priority:p3
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
SocketDev/socket-patch#1072 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Hosted gem `rollback` / `remove` strips the `DEPENDENCIES` `!` of a gem the user declared inside a `source "https://rubygems.org" do` block, so every frozen install fails after the unwindCó thể đã có người làm @mikolalysenko đã nhận 1 ngày trước. Đang mởagent:triaged bug bughunt pm:bundler priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 80/100
SocketDev/socket-patch#1056 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:bundler priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
SocketDev/socket-patch#896 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:yarn-berry priority:p1
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 73/100
SocketDev/socket-patch#783 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
agent:triaged bug bughunt pm:cargo priority:p2
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
SocketDev/socket-patch#651 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của SocketDev/socket-patch
Issue tương tự
-
C-bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
rust-lang/rust-analyzer#23501 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
Maintainer thường phản hồi trong vòng 1 ngày
-
[Bug]: Web chat input doesn't regain focus after a reply finishesCó thể đã có người làm @GaijinSystems đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
zeroclaw-labs/zeroclaw#11658 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
good first issue help wanted
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
bytecodealliance/wasm-tools#2768 ·
Maintainer thường phản hồi trong vòng 1 ngày