Skip to content

Hosted Maven redirects cannot be reverted, and remove recommends an unscoped rollback that also fails #271

Description

[agent] Filed by Claude Code on behalf of Mikola Lysenko (@mikolalysenko) while adding Maven patch SBOM annotations to depscan. Reproduced with a release build of socket-patch 3efdc31d (sha256 dc5fb57f…), a stub patch API, and real Apache Maven 2.2.1 through 4.0.0-rc-7 (13 lines) on macOS arm64 / JDK 26.

Severity: medium (no data loss; the CLI refuses without touching files, but there is no supported undo).

Cells: every hosted cell with changed files, all 13 Maven lines (562 cells). The harness accepts this as
"refused fail-closed"; it is still a CLI gap.

Repro (after scan --mode hosted on the direct shape, commons-text 1.9 → 1.9-socket.c0de7e19):

socket-patch rollback --offline --json --yes --cwd <project>

Output: status: "partial_failure", hosted.failed: [{"purl": "group:maven", "error": "no hosted-redirect revert implementation for redirect_maven_trusted_checksums — re-run scan --mode hosted to normalize, or restore the file from version control (.mvn/checksums/checksums.sha256, .mvn/maven.config, pom.xml)"}]. pom.xml, .mvn/ and
.socket/vendor/redirect-state.json are unchanged. Legacy same-GAV mode fails the same way on
redirect_maven_repository.

  • remove <uuid> with one record: error.code: hosted_revert_failed, same message.
  • remove <uuid> with two records (two-patched): error.code: hosted_revert_unsupported, "no per-purl
    hosted-redirect revert exists for: pkg:maven/org.apache.commons/commons-text@1.9?ext=jar. Run an unscoped
    socket-patch rollback to unwind ALL hosted redirects". The unscoped rollback then fails as above.
  • Cause: crates/socket-patch-core/src/patch/redirect/replay.rs:174 maps every redirect_maven_* kind to
    Inverse::Unsupported (pinned by the test maven_structured_edits_refuse_and_keep_the_record).
  • The purl: "group:maven" label is also not a purl.
  • Expected: either implement the inverse (every maven edit records original/new, like the vendored wiring's
    whole-file snapshot), or make remove stop recommending the unscoped rollback for maven.

Activity

  1. mikolalysenko commented on Sep 30, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] Scheduled Maven bug-hunt routine (ledger #318): one more consequence of this issue, on main f6b7fb9.

    Hosted → vendored takeover doesn't revert anything, and says nothing about it. After scan --mode hosted pinned commons-text to 1.10.0-socket.4d5e6f70, running vendor --json --offline over the same purl (with a hand-staged manifest + blob):

    • exits 0, applied: 1, and emits only the usual vendor_maven_local_cache_shadow advisory;
    • emits no vendor_takeover_reverted_redirect / vendor_would_revert_redirect, and no warning that the hosted wiring stays;
    • leaves the pom with the suffixed <version>, the socket-patch-<uuid> repository and .mvn/ untouched, and adds socket-patch-vendor-<uuid> for the base GAV, which no dependency now requests.

    The build still resolves the hosted jar, so nothing goes unpatched. But the user asked to switch modes and got dead vendored wiring, while the project stays dependent on patch.socket.dev. For cargo and the npm family, CLI_CONTRACT.md's "Takeover reconciliation" reverts the hosted edits first. For Maven, vendor could at least warn that the hosted pin remains until this revert exists.


    Generated by Claude Code

  2. mikolalysenko commented on Oct 1, 2026

    @mikolalysenko
    CollaboratorAuthor

    [agent] Janitor: fixed on main by #277 (squash-merged as 2463257).

    • Maven now has an offline hosted restore: crates/socket-patch-core/src/patch/redirect/upstream/maven.rs:235. It is dispatched for Format::Maven in upstream/mod.rs:690, and v4's replay.rs Inverse::Unsupported mapping is gone.
    • rollback --offline restores pom.xml byte-for-byte and removes the .mvn/ files hosted mode wrote. The test is crates/socket-patch-cli/tests/e2e_redirect_maven_build.rs:575-603.
    • remove no longer emits hosted_revert_unsupported (CLI_CONTRACT.md:1146: "every ecosystem has a restore").
    • Hosted → vendored takeover (from the follow-up comment) now runs the same restore_upstream first for every hosted ecosystem, Maven included. It emits vendor_takeover_reverted_redirect (CLI_CONTRACT.md:123).

    Reopen if this still reproduces on v5.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions