Skip to content

Fix hosted Maven reactor silently unpatched (#261) - #1349

Merged
Mikola Lysenko (mikolalysenko) merged 6 commits into
mainfrom
agent/v5-maven-hosted-reactor
Oct 9, 2026
Merged

Mikola Lysenko (mikolalysenko) merged 6 commits into
mainfrom
agent/v5-maven-hosted-reactor

Conversation

@mikolalysenko

@mikolalysenko Mikola Lysenko (mikolalysenko) commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

LLM Description written by Claude Code:claude-opus-5-5

Fixes #261

Summary

Hosted Maven no longer reports a multi-module build as patched when only
the root pom was changed, and vex no longer attests such a pin.

Root cause

Hosted Maven (rewrite_maven_pom) reads only the root pom.xml. In a
reactor (<modules> / Maven 4 <subprojects>), a module that declares the
patched GA with its own literal <version> is invisible to it. The GA then
falls into the "transitive" branch and gets a root <dependencyManagement>
pin. A module literal always beats an inherited managed version, so that
module keeps resolving the unpatched upstream jar, while scan reports
redirected: 1 and vex attests not_affected from the root pin.

Change

  • Hosted rewriter (patch/redirect/mod.rs): a root that declares
    <modules> / <subprojects> (a profile's included; commented-out or
    plugin-config markup excluded, via the existing
    maven_reactor::declares_modules) is refused whole with
    redirect_maven_multimodule_unsupported. Nothing is written to the pom or
    .mvn/, so the dep is not counted as redirected. The warning names the GA
    and points at --mode vendored, whose reactor planner rewrites each
    module's declaration. This is option (a) in the issue: narrowing the
    advertised support, which the release triage allows.
  • VEX discovery (vex/discover/maven.rs): a hosted pin found in a
    reactor root (written by an older release) stays a ref, so list,
    rollback and remove still find and unwind it. It is marked with the new
    UnattestedKind::MavenReactorRoot, so vex omits it with
    vex_maven_reactor_root (run warning + failed[].reason), like the
    existing Gradle / pnpm / deno unattested cases.
  • Docs: CLI_CONTRACT.md (hosted Maven refusal, unattested-references
    section, note-code table) and docs/ecosystems.md (Maven caveats).

No npm/pypi/gem wrapper change needed (no flag or envelope change).

Per-issue checklist

Red before the fix (on origin/main + tests only):

---- patch::redirect::tests::maven_pom_reactor_root_is_refused stdout ----
modules: a reactor root must not be edited: files=[".mvn/checksums/checksums.sha256", ".mvn/maven.config", "pom.xml"] edits=[FileEdit { path: "pom.xml", kind: "redirect_maven_dep_management", ... }]
failures:
    patch::redirect::tests::maven_pom_reactor_root_is_refused
    vex::discover::maven::tests::hosted_pin_in_a_reactor_root_is_not_attested
test result: FAILED. 0 passed; 2 failed

Green after: cargo test -p socket-patch-core --lib -- maven unattest →
261 passed, 0 failed.

Out of scope

#265 (Maven crawler walks the whole ~/.m2, so unrelated cached artifacts
get transitive pins) shares the depMgmt branch but its root cause is the
crawler's project scoping (#595); it is not addressed here.

Commands run

  • cargo fmt --all -- --check
  • cargo clippy --workspace --all-features -- -D warnings
  • cargo test -p socket-patch-core --lib -- maven unattest
  • cargo test -p socket-patch-cli --bins --lib -- vex contract unattest note
  • cargo test -p socket-patch-core --lib (full): 6093 passed, 4 failed. The 4 (copy_tree::relax_loop_must_not_traverse_symlinked_root, vlt_heal::an_unremovable_hidden_lock_keeps_every_store_entry, pypi_poetry::wire_write_failure_maps_error_and_leaves_lock_untouched, pypi_requirements::wire_failure_rolls_back_already_written_files) depend on unwritable files and fail only because the sandbox runs as root; none touch Maven or VEX code.

🤖 Generated with Claude Code


Generated by Claude Code

Assisted-by: Claude Code:claude-opus-5-5
Hosted Maven reads only the root pom.xml. In a multi-module build a
module that declares the patched artifact with its own literal
<version> kept resolving the unpatched upstream jar, because that
literal beats the root <dependencyManagement> pin the rewriter added.
Scan still reported the package as redirected and `vex` attested
not_affected for it.

A root that declares <modules> or <subprojects> (a profile's
included) is now refused with redirect_maven_multimodule_unsupported
and left untouched, pointing at --mode vendored, whose reactor
planner rewrites each module. VEX discovery no longer attests a hosted
pin it finds in a reactor root, so pins written by older releases stop
producing false not_affected statements.

Assisted-by: Claude Code:claude-opus-5-5
Dropping a hosted pin found in a reactor root from discovery would
have left rollback, remove and list unable to find a pin an older
release wrote. Keep it a ref and mark it unattested instead
(vex_maven_reactor_root), so only `vex` omits it, with a note saying
to re-patch the reactor in vendored mode.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko
Mikola Lysenko (mikolalysenko) marked this pull request as ready for review October 9, 2026 17:39
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

Comment thread crates/socket-patch-core/src/patch/redirect/mod.rs
In a root with both pom.xml and a Gradle build, the Gradle planner
still runs, so "Nothing was written" was not true for that run. Say
what the refusal actually guarantees: pom.xml and .mvn/ are left as
they are and the dep is not counted as redirected.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

The production patch server withdrew the minimist@1.2.2 patch these
suites pinned (#1293), so hosted-e2e, e2e_safety_pnpm and the Bun and
vlt backtests are red on main and on every PR. This carries #1301's
repin to the republished patch 642d7f02 unchanged; it becomes a no-op
once #1301 lands on main.

Assisted-by: Claude Code:claude-opus-5-5
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[agent] hosted-e2e failed on 3a7ff71, and it isn't caused by this PR. It is red on main too (a8e9397, this PR's base). The cause is #1293: the production patch server withdrew the minimist@1.2.2 patch that hosted-e2e, e2e_safety_pnpm and the Bun/vlt backtests pin. This PR's diff only touches the Maven rewriter, Maven VEX discovery and docs.

#1301 repins those suites to the republished patch 642d7f02, and its hosted-e2e is green. I ported its diff unchanged in f3d0e58: 8 files, the backtest harness unittests pass (85 OK), and fmt is clean. That commit becomes a no-op once #1301 merges.


Generated by Claude Code

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale Bugbot comment from a previous run.

@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

BugBot review


Generated by Claude Code

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Bugbot reviewed your changes and found no new issues!

Comment @cursor review or bugbot run to trigger another review on this PR

Reviewed by Cursor Bugbot for commit f3d0e58. Configure here.

@mikolalysenko Mikola Lysenko (mikolalysenko) added the Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review label Oct 9, 2026
@mikolalysenko

Copy link
Copy Markdown
Collaborator Author

[burn-down agent] Labeled Ready for review at f3d0e585.

  • CI: all 311 check runs on this head are success/skipped/neutral; mergeable (clean). No CHANGELOG.md change.
  • Bugbot: reviewed f3d0e585, no new issues; no unresolved review threads.
  • Reviewer: nothing specific to flag beyond the PR description.

Generated by Claude Code

@mikolalysenko
Mikola Lysenko (mikolalysenko) added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit 2b0aa3c Oct 9, 2026
25 of 37 checks passed
@mikolalysenko
Mikola Lysenko (mikolalysenko) deleted the agent/v5-maven-hosted-reactor branch October 9, 2026 22:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Ready for review Agent-verified: mergeable, CI green, Bugbot clean — awaiting human review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Hosted Maven mode edits only the root pom of a multi-module build, leaves child literals unpatched, and still attests VEX

3 participants