|
1 | 1 | [agent] Progress ledger for the scheduled Gradle bug-hunt routine (label pm:gradle). |
2 | 2 |
|
3 | | -Last updated: 2026-09-30 (run 1), main `f6b7fb9`, latest release v4.0.0 (the Gradle snippet first shipped in v4.0.0). |
| 3 | +Last updated: 2026-09-30 (run 2), main `f6b7fb9`, latest release v4.0.0 (the Gradle snippet first shipped in v4.0.0). |
4 | 4 |
|
5 | 5 | ## Coverage matrix |
6 | 6 |
|
7 | | -Hosted cells: the real CLI prints the snippet against a local mock API, it's pasted verbatim into a real Gradle build, and a `file://` repo stands in for patch.socket.dev. |
| 7 | +Hosted cells: the real CLI prints the snippet against a local mock API, it's pasted verbatim into a real Gradle build, and a `file://` repo stands in for patch.socket.dev. Probe run: https://github.com/SocketDev/socket-patch/actions/runs/36791121715 |
8 | 8 |
|
9 | | -| OS | Gradle (JDK) | Discovery (scan, gradle-only) | Agent apply | Hosted Groovy, direct | Hosted Groovy, + transitive base | Hosted Kotlin DSL | Vendored refusal | Locking / verification-metadata | Version catalog | |
10 | | -|---|---|---|---|---|---|---|---|---|---| |
11 | | -| Linux | 6.9.4 (11) | fail #349 | fail #349 | pass | fail #347 | fail #348 | untested | untested | untested | |
12 | | -| Linux | 7.6.6 (17) | fail #349 | fail #349 | pass | fail #347 | fail #348 | untested | untested | untested | |
13 | | -| Linux | 8.14.3 (21) | fail #349 | fail #349 | pass | fail #347 | fail #348 | blocked (#349 / mock) | untested | untested | |
14 | | -| Linux | 9.8.0 (21) | fail #349 | fail #349 | pass | fail #347 | fail #348 | untested | untested | untested | |
15 | | -| macOS | any | untested (OS-independent) | untested | untested | untested (OS-independent) | untested (OS-independent) | untested | untested | untested | |
16 | | -| Windows | any | untested (OS-independent) | untested | untested | untested (OS-independent) | untested (OS-independent) | untested | untested | untested | |
| 9 | +| OS | Gradle (JDK) | Discovery (scan) | Agent apply | Hosted Groovy direct | Hosted + transitive base | Hosted Kotlin DSL | Hosted + gradle.lockfile | Hosted + verification-metadata | Hosted + version catalog | Vendored gradle-only refusal | Vendored mixed pom+gradle | |
| 10 | +|---|---|---|---|---|---|---|---|---|---|---|---| |
| 11 | +| Linux | 6.9.4 (11) | fail #349 | fail #349 | pass | fail #347 | fail #348 | fail #396 | untested | untested | pass (OS/version-independent) | fail #395 (version-independent) | |
| 12 | +| Linux | 7.6.6 (17) | fail #349 | fail #349 | pass | fail #347 | fail #348 | fail #396 | untested | untested | pass | fail #395 | |
| 13 | +| Linux | 8.14.3 (21) | fail #349 | fail #349 | pass | fail #347 | fail #348 | fail #396 | pass (loud failure) | pass | pass | fail #395 | |
| 14 | +| Linux | 9.8.0 (21) | fail #349 | fail #349 | pass | fail #347 | fail #348 | fail #396 | untested | pass | pass | fail #395 | |
| 15 | +| macOS | 6.9.4 / 7.6.6 / 8.14.3 / 9.8.0 | untested (OS-independent) | untested | pass (probe) | untested (OS-independent) | untested (OS-independent) | fail #396 | untested | untested | untested | untested | |
| 16 | +| Windows | 6.9.4 / 7.6.6 / 8.14.3 / 9.8.0 | untested (OS-independent) | untested | pass (probe) | untested (OS-independent) | untested (OS-independent) | fail #396 | untested | untested | untested | untested | |
17 | 17 |
|
18 | 18 | ## Backlog |
19 | | -1. `vendor_gradle_unsupported`: fires on gradle-only and not on mixed pom + Gradle (mock with `--vendor-source build` + `blobContent`). |
20 | | -2. Snippet with `verification-metadata.xml` and `gradle.lockfile` (strict / lenient). Loud vs silent. |
21 | | -3. Version catalogs, `settings.gradle` `dependencyResolutionManagement` + `FAIL_ON_PROJECT_REPOS`, and multi-project builds. |
22 | | -4. Mixed pom.xml + build.gradle: pom edit + snippet together, VEX attestation. |
23 | | -5. Agent `--global-prefix` on the Gradle cache (the `<sha1>` directory layout), and Windows `GRADLE_USER_HOME` with spaces (probe branch). |
| 19 | +1. `dependencyResolutionManagement` with `FAIL_ON_PROJECT_REPOS` / `PREFER_SETTINGS`: snippet placement, loud vs silent. |
| 20 | +2. Multi-project builds (snippet in a subproject vs root, `allprojects {}`). |
| 21 | +3. Kotlin DSL combined with locking and catalogs. |
| 22 | +4. Agent mode on the Gradle cache `<sha1>` layout via `--global-prefix` (blocked by #349), and Windows `GRADLE_USER_HOME` with spaces. |
| 23 | +5. `release/v5-prerelease` Gradle vendoring (#287) once it lands on main. |
24 | 24 |
|
25 | 25 | ## Known non-bugs |
26 | | -- The sandbox can't reach `patches-api.socket.dev` / `api.socket.dev`. Use a local mock API (`--api-url … --org test-org --api-token fake`). |
| 26 | +- The sandbox can't reach `patches-api.socket.dev` / `api.socket.dev`. Use a local mock API (`--api-url … --org test-org --api-token fake`). For vendored, key the view by jar member (`META-INF/NOTICE.txt`) with `blobContent`, otherwise the run ends in `no_local_source` / `apply_failed`, which are mock artifacts. |
27 | 27 | - Gradle build scripts are never edited in hosted mode; the snippet is the documented path. |
28 | | -- Vendoring a gradle-only project is refused (`vendor_gradle_unsupported`). Documented. |
29 | | -- Maven Central HTTP 429 during rapid Gradle matrix runs is rate limiting. Rerun slowly. |
30 | | -- A mock vendored run ending in `no_local_source` is a mock artifact. |
| 28 | +- Vendoring a gradle-only project is refused (`vendor_gradle_unsupported`). Documented, and verified correct. |
| 29 | +- VEX never attributes Gradle-pasted snippets (README VEX table: maven "no Gradle"). A hosted gradle-only `scan --vex` ends in `manifest_not_found`, which is correct: nothing is attested. |
| 30 | +- Snippet + `verification-metadata.xml` fails loudly (missing checksum for the suffixed artifact). That's fail-closed, not a silent bypass. |
| 31 | +- Maven Central HTTP 429 during rapid Gradle runs is rate limiting. Sandbox curl to Central and Adoptium is blocked (403/429), so use GitHub runners for JDK 11/17. |
| 32 | +- The session's git proxy refuses branch deletes (HTTP 403), so probe branches may need maintainer cleanup. |
0 commit comments