|
| 1 | +name: bughunt gradle probe |
| 2 | +on: |
| 3 | + push: |
| 4 | + branches: ['bughunt/gradle/**'] |
| 5 | +permissions: |
| 6 | + contents: read |
| 7 | +jobs: |
| 8 | + probe: |
| 9 | + strategy: |
| 10 | + fail-fast: false |
| 11 | + matrix: |
| 12 | + os: [ubuntu-latest, macos-latest, windows-latest] |
| 13 | + gradle: ['6.9.4', '7.6.6', '8.14.3', '9.8.0'] |
| 14 | + include: |
| 15 | + - gradle: '6.9.4' |
| 16 | + jdk: '11' |
| 17 | + - gradle: '7.6.6' |
| 18 | + jdk: '17' |
| 19 | + - gradle: '8.14.3' |
| 20 | + jdk: '21' |
| 21 | + - gradle: '9.8.0' |
| 22 | + jdk: '21' |
| 23 | + runs-on: ${{ matrix.os }} |
| 24 | + timeout-minutes: 30 |
| 25 | + defaults: |
| 26 | + run: |
| 27 | + shell: bash |
| 28 | + steps: |
| 29 | + - name: Probe hosted exclusiveContent snippet under dependency locking |
| 30 | + env: |
| 31 | + GV: ${{ matrix.gradle }} |
| 32 | + JDK: ${{ matrix.jdk }} |
| 33 | + run: | |
| 34 | + set -u |
| 35 | + for v in JAVA_HOME_${JDK}_X64 JAVA_HOME_${JDK}_arm64 JAVA_HOME_${JDK}_ARM64; do |
| 36 | + if [ -n "${!v:-}" ]; then export JAVA_HOME="${!v}"; break; fi |
| 37 | + done |
| 38 | + echo "JAVA_HOME=$JAVA_HOME" |
| 39 | + W="$RUNNER_TEMP/w"; mkdir -p "$W"; cd "$W" |
| 40 | + [ -f g.zip ] || curl -sSfL --retry 6 --retry-all-errors --retry-delay 15 -o g.zip "https://services.gradle.org/distributions/gradle-$GV-bin.zip" |
| 41 | + python3 -c "import zipfile;zipfile.ZipFile('g.zip').extractall('.')" || python -c "import zipfile;zipfile.ZipFile('g.zip').extractall('.')" |
| 42 | + PY=$(command -v python3 || command -v python) |
| 43 | + G="$W/gradle-$GV/bin/gradle"; if [ "$RUNNER_OS" = Windows ]; then G="$G.bat"; else chmod +x "$G"; fi |
| 44 | + export GRADLE_USER_HOME="$W/gh" |
| 45 | + SFX=1.10.0-socket.4d5e6f70 |
| 46 | + C=https://repo.maven.apache.org/maven2/org/apache/commons/commons-text/1.10.0 |
| 47 | + for e in jar pom; do [ -f orig.$e ] || curl -sSfL --retry 6 --retry-all-errors --retry-delay 15 -o orig.$e "$C/commons-text-1.10.0.$e"; done |
| 48 | + # Socket-shaped maven2 repo: patched jar + upstream pom re-versioned to the suffix. |
| 49 | + REPO=$("$PY" - "$SFX" <<'PYEOF' |
| 50 | + import zipfile,hashlib,os,sys,pathlib |
| 51 | + SFX=sys.argv[1] |
| 52 | + zi=zipfile.ZipFile("orig.jar"); zo=zipfile.ZipFile("patched.jar","w",zipfile.ZIP_DEFLATED) |
| 53 | + for i in zi.infolist(): |
| 54 | + d=zi.read(i.filename) |
| 55 | + if i.filename=="META-INF/NOTICE.txt": d+=b"\nSOCKET-PATCH-GRADLE-MARKER\n" |
| 56 | + zo.writestr(i,d) |
| 57 | + zo.close() |
| 58 | + pom=open("orig.pom").read(); a=pom.index("</parent>"); n="<version>1.10.0</version>"; b=pom.index(n,a) |
| 59 | + pom=pom[:b]+"<version>%s</version>"%SFX+pom[b+len(n):] |
| 60 | + d=f"repo/org/apache/commons/commons-text/{SFX}"; os.makedirs(d,exist_ok=True) |
| 61 | + for ext,data in (("jar",open("patched.jar","rb").read()),("pom",pom.encode())): |
| 62 | + p=f"{d}/commons-text-{SFX}.{ext}"; open(p,"wb").write(data); open(p+".sha1","w").write(hashlib.sha1(data).hexdigest()) |
| 63 | + print(pathlib.Path("repo").resolve().as_uri()) |
| 64 | + PYEOF |
| 65 | + ) |
| 66 | + echo "REPO=$REPO" |
| 67 | + probe() { # $1 = case name, $2 = dependencyLocking block (or empty) |
| 68 | + D="$W/$1"; rm -rf "$D"; mkdir -p "$D"; cd "$D" |
| 69 | + echo "rootProject.name='app'" > settings.gradle |
| 70 | + printf '%s\n' "plugins { id 'java' }" "repositories { mavenCentral() }" "$2" \ |
| 71 | + "dependencies { implementation 'org.apache.commons:commons-text:1.10.0' }" \ |
| 72 | + "tasks.register('cp', Copy) { from configurations.runtimeClasspath; into 'build/cp' }" > build.gradle |
| 73 | + if [ -n "$2" ]; then "$G" -q --no-daemon dependencies --write-locks > wl.log 2>&1 || { echo "write-locks failed"; cat wl.log; }; fi |
| 74 | + # The snippet exactly as `scan --mode hosted` prints it (redirect_gradle_manual_snippet), url swapped to the local repo. |
| 75 | + cat >> build.gradle <<SNIP |
| 76 | + repositories { |
| 77 | + exclusiveContent { |
| 78 | + forRepository { |
| 79 | + maven { url "$REPO" } |
| 80 | + } |
| 81 | + filter { |
| 82 | + includeVersion("org.apache.commons", "commons-text", "$SFX") |
| 83 | + } |
| 84 | + } |
| 85 | + } |
| 86 | + SNIP |
| 87 | + "$PY" -c "import sys;p='build.gradle';t=open(p).read().replace(\"commons-text:1.10.0'\",\"commons-text:$SFX'\");open(p,'w').write(t)" |
| 88 | + rc=0; ok=0 |
| 89 | + for try in 1 2 3; do "$G" -q --no-daemon cp > g.log 2>&1 && { rc=0; ok=1; break; }; rc=$?; grep -q "429" g.log || break; sleep 30; done |
| 90 | + jar=$(ls build/cp 2>/dev/null | grep commons-text || true) |
| 91 | + m=$("$PY" -c "import zipfile,glob;fs=glob.glob('build/cp/commons-text-*.jar');print(zipfile.ZipFile(fs[0]).read('META-INF/NOTICE.txt').count(b'SOCKET-PATCH') if fs else 'none')") |
| 92 | + echo "RESULT os=$RUNNER_OS gradle=$GV case=$1 exit=$rc jar=$jar patched=$m" |
| 93 | + [ "$rc" != 0 ] && grep -v JAVA_TOOL g.log | head -20 |
| 94 | + cd "$W" |
| 95 | + } |
| 96 | + probe nolock "" |
| 97 | + probe lock-default "dependencyLocking { lockAllConfigurations() }" |
| 98 | + probe lock-strict "dependencyLocking { lockAllConfigurations(); lockMode = LockMode.STRICT }" |
| 99 | + probe lock-lenient "dependencyLocking { lockAllConfigurations(); lockMode = LockMode.LENIENT }" |
0 commit comments