You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
- rollback/remove restore a ~/.m2 copy a Gradle-only build no longer reads
(patched by an earlier apply); skipping it reported success while the
shared jar stayed patched and remove dropped the record.
- A Gradle version dir holding only some of a leaf record's files is an
install: apply patches the held files and fails the missing ones as not
found (as on ~/.m2), and vex keeps the copy so it withholds.
- mismatch_blob_gaps expands Gradle version dirs into their hash dirs, so a
drifted Gradle copy queues the afterHash blob the Warn policy needs.
- New gradle_m2_may_be_unconsumed warning when a Gradle-only build reading
mavenLocal() has only the ~/.m2 copy patched.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copy file name to clipboardExpand all lines: crates/socket-patch-cli/CLI_CONTRACT.md
+12-5Lines changed: 12 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1690,13 +1690,18 @@ never filters.
1690
1690
`apply` writes every copy a build consumes: each `~/.m2` version directory the build
1691
1691
reads and each Gradle hash directory that holds the record's files. A Gradle version
1692
1692
directory holding none of the record's files is not an install of it
1693
-
(`package_not_installed`). A record keyed by jar members (`<a>-<v>.jar/<member>`,
1693
+
(`package_not_installed`). One holding only some of them is: the held files are
1694
+
patched and the missing ones fail that copy as not found, as on `~/.m2` (the build
1695
+
still loads the held jar). A record keyed by jar members (`<a>-<v>.jar/<member>`,
1694
1696
#264) swaps the whole jar for the patch service's build of it, in one transaction
1695
1697
across every consumed copy: one download, one backup per distinct original under
1696
1698
`.socket/jvm-originals/`, and a failed write puts every copy already swapped back.
1697
-
`rollback` restores only copies `apply` writes (never the read-only cache, never a
1698
-
`~/.m2` copy a Gradle-only build does not read), from the backup, else, online and
1699
-
for a Gradle copy only, from an upstream download that hashes to the copy's hash
1699
+
`rollback` (and `remove`) restores every writable copy that still holds the record's
1700
+
patched bytes: never the read-only cache, but also a `~/.m2` copy a Gradle-only build
1701
+
no longer reads (an earlier apply wrote it while the build declared `mavenLocal()`,
1702
+
or before v5.0 gated `~/.m2`; leaving it would strand the shared jar patched once
1703
+
`remove` drops the record). It restores from the backup, else, online and for a
1704
+
Gradle copy only, from an upstream download that hashes to the copy's hash
1700
1705
directory.
1701
1706
1702
1707
Run-level `warnings[]` codes (a refusal is also a `failed` event whose `error`
@@ -1706,6 +1711,7 @@ starts with the code):
1706
1711
|---|---|---|
1707
1712
|`gradle_verification_metadata_present`| refused, exit 1 |`gradle/verification-metadata.xml` exists; rewritten cache bytes would fail (or, with key-only trust, slip past) Gradle's dependency verification. Nothing is written; use `--mode vendored` or `--mode hosted`. |
1708
1713
|`gradle_build_ignores_m2`| refused, exit 1 | The only installed copy is in `~/.m2`, which this Gradle-only build never reads. Nothing is patched; build once so Gradle caches it, then apply again. |
1714
+
|`gradle_m2_may_be_unconsumed`| warning | A Gradle-only build that declares `mavenLocal()` (or may) has no Gradle cache copy, so only the `~/.m2` copy was patched. Gradle takes a module from the first declared repository that has it: with another repository before `mavenLocal()`, the next build downloads the unpatched jar. Run the build once and apply again. |
1709
1715
|`gradle_ro_cache_shadows`| exit 1 | The read-only cache holds a copy that is never written and that Gradle may read first. Writable copies are still patched. |
1710
1716
|`gradle_copy_unexpected_bytes`| refused, exit 1 | A hash directory's file is the pristine download (its sha1 names the directory) but neither side of the record, or a hash directory holds a variant's files whose bytes no variant was made for. That copy is left unpatched and the run fails (changed in v5.0: it used to only warn), since the build still loads it. |
1711
1717
|`gradle_transform_copy_stale`| that copy fails | After the write, Gradle still holds a copy derived from the pristine jar (`caches/transforms-*`, `caches/jars-*`, instrumented jars). Run `gradle --stop`, delete those directories, apply again. |
@@ -1844,7 +1850,8 @@ CLI.
1844
1850
`vex` re-hashes every copy a build consumes (`~/.m2` copies the build reads, every
1845
1851
Gradle hash directory holding the record's files, and the suffixed copies of a
1846
1852
hosted pin) and attests only when all of them carry the patch. A Gradle version
1847
-
directory that holds none of the record's files is ignored. A derived copy
1853
+
directory that holds none of the record's files is ignored; one that holds only some
1854
+
of them is judged, and its missing files withhold the statement. A derived copy
1848
1855
(`caches/transforms-*`, `caches/jars-*`, instrumented jars) proven to come from the
1849
1856
pristine jar, or a same-named one that is older than the patched jar and does not
"{}: the only patched copy is in the Maven local repository ({}). This Gradle build reads it only when no repository declared before mavenLocal() has the module; otherwise its next build downloads the unpatched jar. Run the build once and apply again so the Gradle cache copy is patched too.",
2570
+
normalize_purl(m.base_purl),
2571
+
copies
2572
+
.consumed
2573
+
.iter()
2574
+
.map(|p| p.display().to_string())
2575
+
.collect::<Vec<_>>()
2576
+
.join(", ")
2577
+
),
2578
+
);
2579
+
}
2580
+
2530
2581
let multi = variants.len() > 1 || variants.first().is_some_and(|v| **v != m.base_purl);
0 commit comments