Skip to content

Tracking: read and edit pom.xml through one element scanner in formats::maven #715

Description

[agent] Filed by the scheduled architecture audit routine (ecosystems and formats). Register: discussion #560 register.

Kind: tracking. Source: review Part 5.4 ("XML: eight hand-rolled scanners"), Maven/Gradle half; register E10. The NuGet half is #594.

Problem

On main @ 045d7ec, pom.xml is read or edited by seven independent scanners. Each has its own rules for comments, CDATA, profiles, plugin <dependencies>, <exclusions> and tag boundaries:

# Where Used by Comments / CDATA Scoping
1 formats/maven/mod.rs#L55-L104 parse_pom (+ blank_non_markup, open_tags, elements L212-L304) VEX discovery, restore gate both blanked, offsets kept skips build/reporting/pluginRepositories/distributionManagement, profiles and <exclusions>
2 patch/redirect/mod.rs#L6052-L6099 MAVEN_DEPENDENCY_BLOCK_RE + maven_tag_inner_range; insert_maven_repository / insert_maven_dependency_management L6510-L6545 hosted rewrite none none; first <groupId> in the block wins (an exclusion's, if it comes first)
3 patch/redirect/upstream/maven.rs#L59-L111 `dep_matches`, `dm_sections`; [`modules` L221-L233](https://github.com/SocketDev/socket-patch/blob/045d7ec783d788bf3c5a1310724b51e09fb6505d/crates/socket-patch-core/src/patch/redirect/upstream/maven.rs#L221-L233)`` upstream restore none none (reuses #2's regex)
4 vendor/maven_repo.rs#L1519-L1625 find_wireable_anchor, comment_spans, profiles_spans; declares_modules / strip_xml_comments / real_open_tag L1660-L1706 vendored single-pom comments only profiles only
5 vendor/jvm/maven_reactor.rs#L1638-L1712 mask + Doc::parse (a nested tree with parent links) vendored reactor comments, CDATA, PIs full tree
6 vendor/jvm/maven_reactor.rs#L2189-L2330 scan_pom_project (a port of depscan's maven-pom-scan.ts), in the same file as #5 suffixed upstream pom comments, CDATA, PIs project children
7 crawlers/maven_crawler.rs#L80-L240 line scanner parse_pom_group_artifact_version; vex/product.rs#L218-L300 parse_pom_xml / xml_element_texts crawler, VEX product per-line / own own

The writers (#2, #3, #4) never use the readers (#1, #5), so a writer can edit an element the reader says does not exist, and the reverse.

Symptoms

#259 (hosted edits commented-out, plugin and profile markup), #342 (a second <repositories> / <dependencyManagement> when the existing one is self-closed or commented), #683 (<exclusions> first: the direct literal isn't matched), #260 (confirmation by substring, so the scan and VEX disagree), and #716 (two declares_modules disagree, so a single-module EAR pom is refused).

Impact: the symptoms above are open bugs, and each comes from a scanner that the other modes don't share. Each fix today has to be made two or three times.

Target design

One masked element scanner in formats::maven. Comments, CDATA and PIs are blanked with offsets kept, the result is a tree with parent links (the shape of maven_reactor::Doc), and scope queries are built on it (project-level vs profile vs build/plugin, <exclusions> excluded). Readers (VEX, crawler, product) and splicing writers (hosted, restore, vendored, reactor) locate elements through it. Writers keep their own byte-splices; only the locating is shared.

Checklist (one PR each)

Out of scope: line-ending policy for inserted blocks (#273; E16), Maven model semantics (parents, BOM imports, profile activation).

Acceptance criteria

  • All children closed, and each deletes the scanner it replaces
  • grep -rn '"<!--"' crates/socket-patch-core/src finds no pom-specific comment handling outside formats/
  • The Maven redirect goldens, maven_reactor tests, vex::discover::maven tests and e2e_vendor_jvm_build stay green

Dependencies

Not blocked. Overlaps E26 (two Maven backends) and E38 (product probes). #690 (sbt/Mill) touches maven_reactor.rs and maven_crawler.rs, so land the move child after it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:triagedarch-auditFiled by a scheduled architecture audit routine (see the architecture review discussion)pm:mavenMavenpriority:p3refactorStructural change: duplicated code or logic, missing abstraction, layering, dead code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions