Bug hunt ledger: Gradle #319
Replies: 10 comments
|
[agent] 2026-09-30: Gradle bug-hunt run This is the first run. The ledger was empty and there were no Tested: main Setup: the sandbox can't reach the Socket API. A small Python mock of Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-09-30: Gradle bug-hunt run This is run 2. Tested: main Re-triage: #347, #348 and #349 are still open. Main hasn't moved since they were filed, so there was nothing new to verify and I left no comment. Mock setup (reusable): the Python mock of Cells
Issues
False positives ruled out
Blocked
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Gradle puts global installs: The Gradle cache ( What to check (prove each with a real global install, not by reading source):
Add OS × Gradle version cells for |
|
[agent] 2026-10-01: Gradle bug-hunt run This is run 3. Tested: main
Harness (reusable): a scratch Re-triage
Cells (vendored Gradle, new on main)
Issues
False positives ruled out
Blocked
Next
|
|
[agent] 2026-10-01: Gradle bug-hunt run This is run 4. Tested: main Harness: a scratch Re-triageMain hasn't moved since run 3, which re-checked #349 and #395 on this SHA and filed #428 and #429 against it. I re-ran nothing and changed no issues. Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: Gradle bug-hunt run This is run 5. Tested: main Harness: a scratch
Re-triage
Cells (Linux)
Issues
False positives ruled out
Not run
Next
|
|
[agent] 2026-10-01: Gradle bug-hunt run This is run 6. Tested: main Harness: a scratch Re-triage
Cells (Linux)
Issues
False positives ruled out
Not run
Next
|
|
[agent] 2026-10-02: Gradle bug-hunt run This is run 8. Tested: main Re-triageMain hasn't moved since run 7 re-confirmed #461 and #511 on this SHA (and #487 on run 6). I re-ran nothing and changed no issues. Cells (Linux, 8.14.3)
Issues
False positives ruled out
Not run
Next
|
|
[agent] 2026-10-02: Gradle bug-hunt run This is run 9. Tested: main Harness: a scratch Re-triage
Cells (Linux, 8.14.3, vendored, fresh clone)
Issues
False positives ruled out
Not run
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Gradle bug-hunt routine (label pm:gradle).
Last updated: 2026-10-02 (run 9), main
bf0e0d1(no Gradle/JVM code changes since2463257/ #277), latest release v4.0.0. #551 was re-confirmed onbf0e0d1, #461 and #487 on61cfb9b, and #428 on9d718cf. Run 8 filed #551; run 9 filed nothing.Coverage matrix
Hosted (manual snippet). The real CLI prints the snippet against a mock API, and it's pasted into a real build. These cells are from runs 1–2.
gradle_snippetis unchanged on2463257.Vendored (v5 Gradle backend, new in
2463257). "Shapes" means: Groovy project repos, no settings file, Kotlin DSL, CRLF settings, allprojects, buildSrc, transitive-only. Probes: runs 36821273765 and 36821988108. Run 4 used Linux only.vendor --checkon a git checkoutVendored, run 5 cells (Linux).
.moduleartifact (jackson-core)includeBuild("build-logic")apply from:script with exclusiveContentVendored, run 6 cells (Linux).
[1.9,1.10.0]strictlyrange +prefer1.10.0!!1.+/latest.releasevendor --checkon pgp verification-metadatavendor --reverton pgp verification-metadataHosted snippet vs settings
dependencyResolutionManagement(run 6, Linux, 8.14.3 / 9.8.0). Pasted inbuild.gradleunder FAIL_ON_PROJECT_REPOS / PREFER_SETTINGS / PREFER_PROJECT: loud failure in each mode (fail-closed). Wrapped inside settings DRMrepositories: pass.Vendored, run 7 cells (Linux).
:testsclassifier depclassifier =requirerangeVendored vs corporate init scripts, run 9 (Linux, 8.14.3, fresh clone).
afterEvaluate { repositories.clear() }: pass (fail-closed).repositories.clear()before the build script: pass (patched).allprojects,settingsEvaluated/beforeSettings→ settings DRM): pass (patched).Agent mode, run 8 (Linux, 8.14.3).
mavenCentral()) with the same GAV in~/.m2:applypatches m2,vexsaysnot_affected, and the build uses the unpatched cache jar. fail Agent-mode apply in a Gradle-only project patches the ~/.m2 copy Gradle never reads, reports success, and VEX attests not_affected while the build uses the unpatched ~/.gradle jar #551.mavenLocal()first (+-Dmaven.repo.local): pass (control).bf0e0d1(run 9), after Fix agent apply writing into shared package stores (#332, #361) #486's shared-store refusal: still fail Agent-mode apply in a Gradle-only project patches the ~/.m2 copy Gradle never reads, reports success, and VEX attests not_affected while the build uses the unpatched ~/.gradle jar #551.apply --global-prefix …/modules-2/files-2.1: loudpackage_not_installed, exit 1 (pass, fail-loud; scan reports success with 0 packages on a resolved Gradle project because the Gradle cache (~/.gradle/caches/modules-2) is never crawled #349 layout gap).Global (
-g), Linux, 8.14.3 cache.scan -greport: fail. No Gradle-cached purls (scan reports success with 0 packages on a resolved Gradle project because the Gradle cache (~/.gradle/caches/modules-2) is never crawled #349 comment).scan -g --mode hosted/--global-prefix --mode hostedrefusal: pass (exit 2, no writes).-gapply / rollback / vex: blocked (nothing discovered).-gcommands run inside a vendored Gradle project leave the project byte-unchanged (pass, run 5, after Fix -g touching the cwd project's state (#436, #445) #446).Backlog
-gmode. Linux is covered (the report, the refusal, no project leakage, and--global-prefixapply failing loudly). Still to do: macOS / Windows, andapply -g/rollback -g/vex -gwith the GAV in~/.m2(see the 20261001T040000Z entry).verify-signatureswith.moduleartifacts and imported BOMs.strictly/prefer.vendor. Check the result and VEX. Also the hosted snippet plus a classifier dependency (the hosted analogue of Vendored Gradle exits 0 with no warning on a classifier dependency of the patched module, then the build fails with "Could not find …-tests.jar" and IDE sources silently disappear #533).apply+vexwhenGRADLE_USER_HOMEand~/.m2hold different versions (a Agent-mode apply in a Gradle-only project patches the ~/.m2 copy Gradle never reads, reports success, and VEX attests not_affected while the build uses the unpatched ~/.gradle jar #551 variant).cd <subproject> && gradlebreaks #428, Vendored Gradle: on a Windows (core.autocrlf=true) checkout,vendor --checkfails andvendor --revert/remove/rollbackleave the settings script behind, because the index and script aren't covered by the -text .gitattributes #429, Vendored Gradle: gradle_exclusive_content_conflict refusal doesn't fire for a subproject build script or a buildSrc convention plugin, so vendor exits 0, the build then fails with "Could not find", and VEX attests not_affected #461, Vendored Gradle with PGP signature verification exits 0 but breaks the build, because pgp-only verification-metadata entries for the vendored pom and its parent chain are kept without a checksum #487, Vendored Gradle silently downgrades a version-range dependency to an older unpatched release (1.10.0 → 1.9), because the vendored repository has no maven-metadata.xml; vendor --check and VEX still report it patched #511, Vendored Gradle exits 0 with no warning on a classifier dependency of the patched module, then the build fails with "Could not find …-tests.jar" and IDE sources silently disappear #533 and Agent-mode apply in a Gradle-only project patches the ~/.m2 copy Gradle never reads, reports success, and VEX attests not_affected while the build uses the unpatched ~/.gradle jar #551 whenvendor/jvm/,maven_crawler.rsorgradle_snippetchange.Known non-bugs
prebuilt_common::prepare_command+ a staged manifest/blob (see the run 3 entry). For hosted, use the wiremock shaped likee2e_redirect_maven_build.repo.maven.apache.org429s in the sandbox. Use an init script that rewrites it torepo1.maven.org. JDK 11/17 cells must run on GitHub runners.vendor_jvm_upstream_unavailable/verification_metadata_unavailable404 from the fixture means the m2 seed is missing (junit-bom:5.9.0/5.9.1:module). It's a mock artifact.settings.gradlewhen none exists. All documented.gradle_below_6_8), as documented.6.8-rc-*parses as 6.8 and is caught by the script's runtime check.scan/get --mode hostedkeeps its vendored patch (already); there's no takeover. That's safe.scan --vexending inmanifest_not_foundis correct.vexhas no Gradle product auto-detection (pass--product, or use the git remote), as documented.verification-metadata.xmlfails loudly, which is fail-closed.repo.maven.apache.organdrepo1.maven.org) can 429 Gradle in the sandbox. Point mavenCentral atfile://<seeded m2>with an init script.remove <purl>, or a manifest edit + re-vendor) keeps the other wired correctly. Verified in run 4.settings.gradleis rejected by Gradle itself; it isn't a valid fixture.vex -gattests the cwd project's vendored or hosted state by design (vex.rs:1013).applywith "File not found", which is a fixture error.allprojects; the vendored script itself is IP-compatible on 9.8.0.build.gradleof a settings-DRM build fails loudly in everyrepositoriesMode. It works when wrapped insidedependencyResolutionManagement { repositories { … } }. That's placement, not a silent bypass.1.+/latest.releasedeclarations resolve the newest release before and after vendoring, so a base-version patch correctly doesn't apply. That isn't Vendored Gradle silently downgrades a version-range dependency to an older unpatched release (1.10.0 → 1.9), because the vendored repository has no maven-metadata.xml; vendor --check and VEX still report it patched #511.vendor --revertis byte-exact on a verification-metadata file with pgp entries (run 6).mvn-seededfile://m2 has nomaven-metadata.xml, so range or dynamic-version cells fail before vendoring too. Use real Central for those.gradle.lockfilewritten before vendoring masks Vendored Gradle silently downgrades a version-range dependency to an older unpatched release (1.10.0 → 1.9), because the vendored repository has no maven-metadata.xml; vendor --check and VEX still report it patched #511: the range resolves to the locked, vendored version (run 7).mavenLocal()ignores theMAVEN_REPO_LOCALenv var. It uses-Dmaven.repo.localor settings.xml, so a harness must pass the system property (run 8).repositories.clear()) doesn't make vendored Gradle fail open. Gradle keeps the exclusiveContent exclusivity after the vendored repository is removed, so the build fails loudly (run 9).File.toURI(), notfile://strings: Gradle normalizesfile:///xtofile:/x/(run 9 harness note).All reactions