Skip to content

Commit 7ac89be

Browse files
committed
gradle: run 2 ledger (#395, #396)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JTf6M8pLMnXg9DDFoc7oh5
1 parent 6b9aa43 commit 7ac89be

2 files changed

Lines changed: 54 additions & 19 deletions

File tree

‎entries/gradle/20260930T233200Z.md‎

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,33 @@
1+
[agent] 2026-09-30: Gradle bug-hunt run
2+
3+
This is run 2. **Tested:** main `f6b7fb9` (CLI 4.0.0, unchanged since run 1), latest release v4.0.0. Linux sandbox with Gradle 8.14.3 and 9.8.0 (JDK 21). Probe run https://github.com/SocketDev/socket-patch/actions/runs/36791121715 covered ubuntu, macos and windows × Gradle 6.9.4 (JDK 11), 7.6.6 (JDK 17), 8.14.3 and 9.8.0 (JDK 21).
4+
5+
**Re-triage:** #347, #348 and #349 are still open. Main hasn't moved since they were filed, so there was nothing new to verify and I left no comment.
6+
7+
**Mock setup (reusable):** the Python mock of `/v0/orgs/<org>/patches/{batch,by-package,package,view}` from run 1 again. Vendored mode needs the view keyed by the **jar member** (`META-INF/NOTICE.txt`) with `blobContent`, like `e2e_vendor_maven_build.rs`. With a jar-name key, or without `blobContent`, the run stops at `no_local_source` / `apply_failed`, which are mock artifacts. Discovery still needs a seeded `MAVEN_REPO_LOCAL` (#349).
8+
9+
## Cells
10+
- **Vendored, gradle-only:** pass. `vendor_gradle_unsupported` fires and nothing is written.
11+
- **Vendored, mixed pom.xml + build.gradle:** **fail → #395**. Success, no Gradle warning, the Gradle build uses the unpatched jar, and `vex` attests `not_affected (vendored)`. Maven on the same tree is patched. Reproduced 3×. `release/v5-prerelease` `jvm::detect` has the same gap.
12+
- **Hosted snippet + dependency locking (default / STRICT / LENIENT):** **fail → #396** in all 12 OS × Gradle cells. Exit 0 with the upstream jar, because the lock's `{strictly 1.10.0}` wins. The no-lock control passes in all 12.
13+
- **Hosted snippet + verification-metadata.xml (sha256):** Gradle 8.14.3 fails loudly ("Dependency verification failed"), so it's fail-closed. Not filed. The snippet could carry the `<sha256>` entry, but that's UX.
14+
- **Hosted snippet + version catalog (bump in libs.versions.toml):** pass on 8.14.3 and 9.8.0.
15+
- **Hosted gradle-only `scan --vex`:** VEX correctly refuses (`manifest_not_found`, nothing attested). That VEX never attributes a pasted Gradle snippet is documented (README VEX table: maven "no Gradle").
16+
17+
## Issues
18+
- Filed #395: https://github.com/SocketDev/socket-patch/issues/395
19+
- Filed #396: https://github.com/SocketDev/socket-patch/issues/396
20+
21+
## False positives ruled out
22+
- Gradle "BUILD FAILED" during the mixed repro was a Maven Central HTTP 429. It passed on rerun.
23+
- Sandbox curl to Maven Central and Adoptium gets 403/429 from the egress proxy, so JDK 11/17 cells ran on GitHub runners.
24+
25+
## Blocked
26+
- The probe branch `bughunt/gradle/20260930-lockfile-snippet` could **not be deleted**: git push of the delete got HTTP 403 from the session's git proxy. It only adds `.github/workflows/bughunt-gradle.yml`. A maintainer should delete it.
27+
28+
## Next
29+
1. `FAIL_ON_PROJECT_REPOS` / `PREFER_SETTINGS` in settings.gradle `dependencyResolutionManagement`: where does the pasted snippet go, and is the result loud or silent?
30+
2. Multi-project builds: snippet pasted in a subproject vs root, and `allprojects {}`.
31+
3. Kotlin DSL + locking and Kotlin DSL + catalogs, once #348's Kotlin snippet exists.
32+
4. Agent mode on the `~/.gradle/caches/modules-2/files-2.1/<g>/<a>/<v>/<sha1>/` layout via `--global-prefix` (still blocked by #349).
33+
5. Re-test #347, #348, #349, #395 and #396 when main moves, and check `release/v5-prerelease` Gradle vendoring.

‎state/gradle.md‎

Lines changed: 21 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -1,30 +1,32 @@
11
[agent] Progress ledger for the scheduled Gradle bug-hunt routine (label pm:gradle).
22

3-
Last updated: 2026-09-30 (run 1), main `f6b7fb9`, latest release v4.0.0 (the Gradle snippet first shipped in v4.0.0).
3+
Last updated: 2026-09-30 (run 2), main `f6b7fb9`, latest release v4.0.0 (the Gradle snippet first shipped in v4.0.0).
44

55
## Coverage matrix
66

7-
Hosted cells: the real CLI prints the snippet against a local mock API, it's pasted verbatim into a real Gradle build, and a `file://` repo stands in for patch.socket.dev.
7+
Hosted cells: the real CLI prints the snippet against a local mock API, it's pasted verbatim into a real Gradle build, and a `file://` repo stands in for patch.socket.dev. Probe run: https://github.com/SocketDev/socket-patch/actions/runs/36791121715
88

9-
| OS | Gradle (JDK) | Discovery (scan, gradle-only) | Agent apply | Hosted Groovy, direct | Hosted Groovy, + transitive base | Hosted Kotlin DSL | Vendored refusal | Locking / verification-metadata | Version catalog |
10-
|---|---|---|---|---|---|---|---|---|---|
11-
| Linux | 6.9.4 (11) | fail #349 | fail #349 | pass | fail #347 | fail #348 | untested | untested | untested |
12-
| Linux | 7.6.6 (17) | fail #349 | fail #349 | pass | fail #347 | fail #348 | untested | untested | untested |
13-
| Linux | 8.14.3 (21) | fail #349 | fail #349 | pass | fail #347 | fail #348 | blocked (#349 / mock) | untested | untested |
14-
| Linux | 9.8.0 (21) | fail #349 | fail #349 | pass | fail #347 | fail #348 | untested | untested | untested |
15-
| macOS | any | untested (OS-independent) | untested | untested | untested (OS-independent) | untested (OS-independent) | untested | untested | untested |
16-
| Windows | any | untested (OS-independent) | untested | untested | untested (OS-independent) | untested (OS-independent) | untested | untested | untested |
9+
| OS | Gradle (JDK) | Discovery (scan) | Agent apply | Hosted Groovy direct | Hosted + transitive base | Hosted Kotlin DSL | Hosted + gradle.lockfile | Hosted + verification-metadata | Hosted + version catalog | Vendored gradle-only refusal | Vendored mixed pom+gradle |
10+
|---|---|---|---|---|---|---|---|---|---|---|---|
11+
| Linux | 6.9.4 (11) | fail #349 | fail #349 | pass | fail #347 | fail #348 | fail #396 | untested | untested | pass (OS/version-independent) | fail #395 (version-independent) |
12+
| Linux | 7.6.6 (17) | fail #349 | fail #349 | pass | fail #347 | fail #348 | fail #396 | untested | untested | pass | fail #395 |
13+
| Linux | 8.14.3 (21) | fail #349 | fail #349 | pass | fail #347 | fail #348 | fail #396 | pass (loud failure) | pass | pass | fail #395 |
14+
| Linux | 9.8.0 (21) | fail #349 | fail #349 | pass | fail #347 | fail #348 | fail #396 | untested | pass | pass | fail #395 |
15+
| macOS | 6.9.4 / 7.6.6 / 8.14.3 / 9.8.0 | untested (OS-independent) | untested | pass (probe) | untested (OS-independent) | untested (OS-independent) | fail #396 | untested | untested | untested | untested |
16+
| Windows | 6.9.4 / 7.6.6 / 8.14.3 / 9.8.0 | untested (OS-independent) | untested | pass (probe) | untested (OS-independent) | untested (OS-independent) | fail #396 | untested | untested | untested | untested |
1717

1818
## Backlog
19-
1. `vendor_gradle_unsupported`: fires on gradle-only and not on mixed pom + Gradle (mock with `--vendor-source build` + `blobContent`).
20-
2. Snippet with `verification-metadata.xml` and `gradle.lockfile` (strict / lenient). Loud vs silent.
21-
3. Version catalogs, `settings.gradle` `dependencyResolutionManagement` + `FAIL_ON_PROJECT_REPOS`, and multi-project builds.
22-
4. Mixed pom.xml + build.gradle: pom edit + snippet together, VEX attestation.
23-
5. Agent `--global-prefix` on the Gradle cache (the `<sha1>` directory layout), and Windows `GRADLE_USER_HOME` with spaces (probe branch).
19+
1. `dependencyResolutionManagement` with `FAIL_ON_PROJECT_REPOS` / `PREFER_SETTINGS`: snippet placement, loud vs silent.
20+
2. Multi-project builds (snippet in a subproject vs root, `allprojects {}`).
21+
3. Kotlin DSL combined with locking and catalogs.
22+
4. Agent mode on the Gradle cache `<sha1>` layout via `--global-prefix` (blocked by #349), and Windows `GRADLE_USER_HOME` with spaces.
23+
5. `release/v5-prerelease` Gradle vendoring (#287) once it lands on main.
2424

2525
## Known non-bugs
26-
- The sandbox can't reach `patches-api.socket.dev` / `api.socket.dev`. Use a local mock API (`--api-url … --org test-org --api-token fake`).
26+
- The sandbox can't reach `patches-api.socket.dev` / `api.socket.dev`. Use a local mock API (`--api-url … --org test-org --api-token fake`). For vendored, key the view by jar member (`META-INF/NOTICE.txt`) with `blobContent`, otherwise the run ends in `no_local_source` / `apply_failed`, which are mock artifacts.
2727
- Gradle build scripts are never edited in hosted mode; the snippet is the documented path.
28-
- Vendoring a gradle-only project is refused (`vendor_gradle_unsupported`). Documented.
29-
- Maven Central HTTP 429 during rapid Gradle matrix runs is rate limiting. Rerun slowly.
30-
- A mock vendored run ending in `no_local_source` is a mock artifact.
28+
- Vendoring a gradle-only project is refused (`vendor_gradle_unsupported`). Documented, and verified correct.
29+
- VEX never attributes Gradle-pasted snippets (README VEX table: maven "no Gradle"). A hosted gradle-only `scan --vex` ends in `manifest_not_found`, which is correct: nothing is attested.
30+
- Snippet + `verification-metadata.xml` fails loudly (missing checksum for the suffixed artifact). That's fail-closed, not a silent bypass.
31+
- Maven Central HTTP 429 during rapid Gradle runs is rate limiting. Sandbox curl to Central and Adoptium is blocked (403/429), so use GitHub runners for JDK 11/17.
32+
- The session's git proxy refuses branch deletes (HTTP 403), so probe branches may need maintainer cleanup.

0 commit comments

Comments
 (0)