Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

Vendored Gradle exits 0 with no warning on a classifier dependency of the patched module, then the build fails with "Could not find …-tests.jar" and IDE sources silently disappear

已關閉
#533 2 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

維護者通常 1 天內回覆

@mikolalysenko 已經在處理了。

開始於 2026年10月3日。

  • #646 來自 @mikolalysenko —— 未關閉

評估

難度
4/5
預估耗時
3-5 天
新手友好度
52/100
Issue 類型
缺陷
描述清晰度
基本清楚
活躍度
活躍
技術堆疊
java, kotlin, rust
領域
build-system, cli

研究方向

Start with crates/socket-patch-core/src/vendor/jvm/gradle.rs around lines 119-120 and 157-158, then compare the classifier handling in maven_reactor.rs:983-988 and the generated filter in socket-patch.settings.gradle:49-52. Run the supplied Gradle classifier and sources reproductions to observe the silent success. Done means unsupported classifier declarations no longer pass as successful without the documented warning or refusal, with the relevant checks covered.

由索引模型根據 Issue 內容生成。

描述

agent:claimed agent:triaged bug bughunt pm:gradle priority:p3

[agent] Found by the scheduled Gradle bug-hunt routine (ledger #319).

Summary

The generated Gradle script claims the patched coordinates with exclusiveContent { … includeVersion(g, a, v) } (crates/socket-patch-core/src/vendor/jvm/socket-patch.settings.gradle:51). That claim covers every artifact of g:a:v, including classifier variants (tests, sources, javadoc, …), but the vendored repo only holds the main jar and pom. So once a project is vendored:

  • A declared classifier dependency (testImplementation 'org.apache.commons:commons-text:1.10.0:tests', or Kotlin classifier = "tests") can't be resolved, and the build fails with Could not find commons-text-1.10.0-tests.jar … Searched in .socket/vendor/gradle/….
  • IDE-style sources resolution (ArtifactResolutionQuery … SourcesArtifact, which is what IntelliJ / Eclipse sync use) silently returns no sources for the patched module. Before vendoring it returned commons-text-1.10.0-sources.jar.

vendor still exits 0 with status: success and no warning. vendor --check returns vendor_check_ok, and vex attests not_affected / inline_mitigations_already_exist.

The Maven backend already handles this: maven_reactor.rs:983 warns classifier_declared ("a classifier variant of … bypasses the pin"), and docs/design/maven-vendoring.md lists classifier artifacts as unsupported scope. The Gradle planner has no equivalent check. gradle.rs only runs check_android and check_exclusive_content on build files (gradle.rs:119-120, 157-158), so the unsupported declaration goes through without a warning or a refusal.

Impact

A repo that uses a tests-classifier artifact of a patched library stops building once the vendored commit lands, even though vendor, check and VEX all report success. Every IDE user also silently loses source attachment for the patched module.

Repro (Linux, Gradle 8.14.3 and 9.8.0, main 61cfb9b)

mkdir c1 && cd c1 && git init -q
echo "rootProject.name = 'c1'" > settings.gradle
cat > build.gradle <<'EOF'
plugins { id 'java' }
repositories { mavenCentral() }
dependencies {
  implementation 'org.apache.commons:commons-text:1.10.0'
  testImplementation 'org.apache.commons:commons-text:1.10.0:tests'
}
tasks.register('cp') { doLast { configurations.testRuntimeClasspath.files.each { println "CP " + it } } }
EOF
gradle -q cp            # OK: commons-text-1.10.0.jar, commons-text-1.10.0-tests.jar, commons-lang3
git add -A && git commit -qm init
# stage .socket/manifest.json + blob for a pkg:maven/org.apache.commons/[email protected] patch
socket-patch vendor --json   # exit 0, status success, no warnings
git add -A && git commit -qm vendored && git clone -q . ../fresh
gradle -q -p ../fresh cp
# > Could not find commons-text-1.10.0-tests.jar (org.apache.commons:commons-text:1.10.0).
#   Searched in the following locations:
#     file:/…/.socket/vendor/gradle/org/apache/commons/commons-text/1.10.0/commons-text-1.10.0-tests.jar
socket-patch vendor --check --json   # vendor_check_ok, exit 0

Sources check (add to build.gradle, then run gradle -q src):

tasks.register('src') { doLast {
  def ids = configurations.runtimeClasspath.incoming.resolutionResult.allComponents.collect { it.id }.findAll { it instanceof ModuleComponentIdentifier }
  def r = dependencies.createArtifactResolutionQuery().forComponents(ids).withArtifacts(JvmLibrary, SourcesArtifact).execute()
  r.resolvedComponents.each { c -> c.getArtifacts(SourcesArtifact).each { a -> println "SRC ${c.id} -> ${a instanceof ResolvedArtifactResult ? a.file.name : a.failure}" } }
} }

Before vendoring it prints SRC org.apache.commons:commons-text:1.10.0 -> commons-text-1.10.0-sources.jar. After vendoring it prints nothing.

The patch data came from the repo's own fixture path (prebuilt_common::prepare_command plus a staged manifest and blob for a META-INF/NOTICE.txt marker patch, the same as e2e_vendor_jvm_build.rs).

Expected vs actual

  • Expected: docs/design/maven-vendoring.md says classifier artifacts are not enabled in this release, and that for unsupported declarations "the backend does not silently claim those unsupported declarations are patched." So vendor should warn or refuse (like Maven's classifier_declared) when a build file declares a classifier of the patched GAV. Alternatively, the exclusive filter or the vendored repo should still let classifier artifacts resolve upstream.
  • Actual: exit 0, no warning, a broken build, lost IDE sources, vendor_check_ok, and VEX not_affected.

Matrix

OS Gradle DSL Result
Linux 8.14.3 (JDK 21) Groovy :tests fail (×2: original tree and fresh clone)
Linux 9.8.0 (JDK 21) Groovy :tests fail (fresh clone)
Linux 9.8.0 (JDK 21) Kotlin classifier = "tests" fail, VEX not_affected
Linux 8.14.3 sources via ArtifactResolutionQuery fail (silently empty)
macOS / Windows — — untested. The behaviour comes from the OS-independent script and Gradle resolution

The Gradle backend is new in v5 (2463257), so there's no earlier good release.

Suspect code

  • crates/socket-patch-core/src/vendor/jvm/socket-patch.settings.gradle:49-52: exclusiveContent with includeVersion claims every classifier of the GAV.
  • crates/socket-patch-core/src/vendor/jvm/gradle.rs:119-120 / 157-158: no classifier-declaration warning to match maven_reactor.rs:983-988.
主要語言
Rust
星號
8
分支
0
平均合併
1 天 1 小時
30 天內合併 PR
257

環境準備

  • 沒有 Dockerfile 或 Docker Compose 檔案
  • 沒有 Pull Request 範本
  • 閱讀貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

SocketDev/socket-patch 的其他 Issue

查看 SocketDev/socket-patch 的全部 Issue

相似的 Issue

更多 Rust Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。