Bug hunt ledger: Maven #318
Replies: 6 comments
|
[agent] 2026-09-30: Maven bug-hunt run Tested: main Filed
Commented
Cells covered
False positives ruled out
Held (not filed yet)
Probe:
Next
|
|
[agent] 2026-09-30: Maven bug-hunt run Tested: main Re-triage: #342 and #350 are still open. main hasn't moved since they were filed, so there's nothing to re-check. Filed
Cells covered (Linux, 3.9.11 unless noted)
False positives ruled out
Probe: none this run. The stale branch Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Maven puts global installs: The local repository ( What to check (prove each with a real global install, not by reading source):
Add OS × Maven version cells for |
|
[agent] 2026-10-01: Maven bug-hunt run Tested: main Maintainer backlog item 0 (global Filed
Re-triage
Cells covered
False positives ruled out
Probe branches: Next
|
|
[agent] 2026-10-01: Maven bug-hunt run Tested: main Filed
Commented
Re-triage: main is unchanged since run 3, so #430 / #423 / #424 / #350 / #342 still hold. No re-runs beyond #394. Cells covered (reactor capstone variant
False positives ruled out
Probe branches: Next
|
|
[agent] 2026-10-01: Maven bug-hunt run Tested: main Filed
Commented
Re-triage: the vendor/jvm and agent/global code is unchanged since run 4, so #459 / #430 / #423 / #424 / #394 / #350 / #342 still stand (not re-run). Cells covered (local uncommitted variant of
False positives ruled out
Probe branches: Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Maven bug-hunt routine (label pm:maven).
Last updated: 2026-10-01 (run 5), main
c7af4df, latest release 4.0.0.Coverage matrix
Oracles: a real Maven resolve, plus a marker in the patched member (jar or pom). Global
-gcells use real Maven installs into the local repository and a stub patch API (/tmp-local Python stub serving batch / by-package / view / blob). v5 vendored cells use the repo capstones (e2e_vendor_jvm_build,e2e_vendor_maven_build,e2e_redirect_maven_build) and local, uncommitted variants of them. Linux runs use JDK 21; the macOS / Windows probes use the runner's default JDK.v5 global mode (
-g)<localRepository>-g --mode hostedrefusalv5 vendored / hosted (Linux unless noted)
--maven-config=none:-onone:cd modulenone:-f rootfrom outside,/ space /%2Fmaven.config(CRLF / no EOL / user tail)aether.checksums.algorithms=SHA-256${prop}%XXpath<repositories/>v5 vendored reactor: external version management (run 5, Linux)
v5 hosted Trusted Checksums boundary (#258, run 5, Linux)
e2e_redirect_maven_build(unenforced warning ⇔ tamper enforcement)v4.0.0 results (runs 1–2, main
f6b7fb9; not re-run on v5 unless shown above)%XXin path<repositories/><repositories/>,<dependencyManagement/>, comment in depMgmtBacklog
-g): mostly covered in run 3 (see the matrix and the 20261001T061707Z entry). Still open:-gagent apply / rollback / vex and the read-only global dir on macOS / Windows (probe). Keep this item until those cells pass or fail.bughunt/maven/20260930-vendored-pathsandbughunt/maven/20261001-global-repo.git push --deletehung up from the sandbox in run 4 and was denied by the session permission policy in run 5. Probe commits must use the default (signed) git identity. Don't overrideuser.email.none), the hosted capstone and the Vendored Maven reactor ignores profile <properties>, so a version an active profile raises is silently downgraded to the patched base (1.11.0 → 1.10.0-socket.*) with exit 0 and no warning #459 / Vendored Maven reactor pins over an imported BOM or external parent, so a build that uses 1.11.0 is silently downgraded to 1.10.0-socket.* and a later BOM bump never takes effect #488 fixtures on 3.6.3 / 3.8.8 when Central isn't throttling (the fallback-repo-only path). Warm the m2 in an early, separate step.~/.m2) #265?), and hosted-oon a fresh checkout.<properties>overridden in the reactor root, andspring-boot-starter-parent-style property-driven management..mvn/maven.configpluschecksums.sha256round trip through rollback (maven_trusted_checksums_left)..socket/vendor/maven2(the* -text.gitattributes).%2Fpaths, existing CRLFmaven.config).Known non-bugs
patches-api.socket.dev/patch.socket.devaren't used. Stage manifests locally, or use the Python / wiremock stubs.maven-dependency-plugin:3.6.1depends on commons-text 1.10.0, so fixtures that patch commons-text 1.10.0 get the plugin realm's Central copy in the local repository (the same effect as Same-GAV Maven patches are shadowed when a build plugin depends on the same GAV in a reactor build #274). Use plugin 3.1.2 for the resolve oracle.InvalidPathException … unmappable characterson a unicode project path unlessLC_ALL=C.UTF-8. That's a sandbox artifact, not a socket-patch bug.<version>[1.10.0]</version>→redirect_maven_dep_version_mismatch,redirected: 0, nothing written: documented behaviour..pomfiles ("Non-parseable POM … Your…") are rate-limit artifacts. Delete poms under 200 bytes from the seed repo and retry.<subprojects>aggregator not refused by vendored mode: harmless on 4.0.0-rc-7 (see backlog 6).user.homecomes from passwd, not$HOME. Pass-Duser.home=$HOMEto Maven when faking a home directory.--maven-config=nonecells need a local repo warmed per Maven version: a repo warmed for one version misses the other versions' default lifecycle plugins.rollback -gwithout the before-blob → loud exit 1 "--offline prevents fetching": documented.<classifier>and suffixes sources/tests/native classifier dependencies, which breaks the build #262, repository order / mirrors Vendored Maven silently resolves the unpatched jar when an earlier<repository>or amirrorOf *mirror serves the same GAV, and VEX still attests #263, crawler lists all of ~/.m2 Maven hosted scan pins, and VEX attests, artifacts the project doesn't depend on (the crawler lists all of~/.m2) #265, no re-pin Hosted Maven never re-pins: a superseding patch uuid or a rotated grant token leaves the old wiring in place #266, CI matrix Maven CI matrix has no Windows leg, a stale 4.0 RC, and no legs at the resolver boundaries #267, no hosted revert Hosted Maven redirects cannot be reverted, andremoverecommends an unscoped rollback that also fails #271, lowercased GAV Vendored Maven payload is written under the lowercased GAV, so mixed-case artifacts silently fall through to Central on case-sensitive file systems #272, CRLF Maven pom edits insert LF lines into CRLF pom.xml files (hosted and vendored) #273, plugin shadow Same-GAV Maven patches are shadowed when a build plugin depends on the same GAV in a reactor build #274)..mvn/maven.config: Maven 3.9.11 and 4.0.0-rc-7 refuse the file themselves ("Unrecognized maven.config file entries"). Not caused by socket-patch.maven.repo.local.tailsplits, and Maven falls back to thesocket-patch-vendorfile repository (the jar is copied into m2, still the patched suffixed version). Degraded but fail-closed, not filed.merge_checksumsdrops non-<sha> <path>lines (#comments) and re-sorts a user'schecksums.sha256. Maven ignores those lines, so this is cosmetic and not filed.vendorhas no local artifact building: without a patch service it failsvendor_service_offline_conflict. Drive it through the harness fixture server (prebuilt_common::prepare_command), not a bare manifest +--offline.vendor_unwired). Recorded on Vendored Maven reactor ignores profile <properties>, so a version an active profile raises is silently downgraded to the patched base (1.11.0 → 1.10.0-socket.*) with exit 0 and no warning #459, not re-filed.not_affected, which is the Maven hosted scan pins, and VEX attests, artifacts the project doesn't depend on (the crawler lists all of~/.m2) #265 family. Not filed.All reactions