Bug hunt ledger: Gradle #319
Replies: 13 comments
|
[agent] 2026-09-30: Gradle bug-hunt run This is the first run. The ledger was empty and there were no Tested: main Setup: the sandbox can't reach the Socket API. A small Python mock of Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-09-30: Gradle bug-hunt run This is run 2. Tested: main Re-triage: #347, #348 and #349 are still open. Main hasn't moved since they were filed, so there was nothing new to verify and I left no comment. Mock setup (reusable): the Python mock of Cells
Issues
False positives ruled out
Blocked
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Gradle puts global installs: The Gradle cache ( What to check (prove each with a real global install, not by reading source):
Add OS × Gradle version cells for |
|
[agent] 2026-10-01: Gradle bug-hunt run This is run 3. Tested: main
Harness (reusable): a scratch Re-triage
Cells (vendored Gradle, new on main)
Issues
False positives ruled out
Blocked
Next
|
|
[agent] 2026-10-01: Gradle bug-hunt run This is run 4. Tested: main Harness: a scratch Re-triageMain hasn't moved since run 3, which re-checked #349 and #395 on this SHA and filed #428 and #429 against it. I re-ran nothing and changed no issues. Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-10-01: Gradle bug-hunt run This is run 5. Tested: main Harness: a scratch
Re-triage
Cells (Linux)
Issues
False positives ruled out
Not run
Next
|
|
[agent] 2026-10-01: Gradle bug-hunt run This is run 6. Tested: main Harness: a scratch Re-triage
Cells (Linux)
Issues
False positives ruled out
Not run
Next
|
|
[agent] 2026-10-02: Gradle bug-hunt run This is run 8. Tested: main Re-triageMain hasn't moved since run 7 re-confirmed #461 and #511 on this SHA (and #487 on run 6). I re-ran nothing and changed no issues. Cells (Linux, 8.14.3)
Issues
False positives ruled out
Not run
Next
|
|
[agent] 2026-10-02: Gradle bug-hunt run This is run 9. Tested: main Harness: a scratch Re-triage
Cells (Linux, 8.14.3, vendored, fresh clone)
Issues
False positives ruled out
Not run
Next
|
|
[agent] 2026-10-02: Gradle bug-hunt run This is run 10. Tested: main Harness: a scratch Re-triage
Cells
Issues
False positives ruled out
Not run
Next
|
|
[agent] 2026-10-03: Gradle bug-hunt run This is run 11. Tested: main Harness: a scratch Re-triage
Cells
Issues
False positives ruled out
Not run
Next
|
|
[agent] 2026-10-03: Gradle bug-hunt run This is run 12. Tested: main Harness: the same scratch Re-triage
Cells
Issues
False positives ruled out
Not run
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Gradle bug-hunt routine (label pm:gradle).
Last updated: 2026-10-03 (run 12), main
045d7ec(no Gradle/JVM code changes since2463257/ #277), latest release v4.0.0. #551 and #349 were re-confirmed on045d7ecin run 10. Run 8 filed #551, run 9 filed nothing, run 10 filed #620, run 11 filed #656 and commented on #511, and run 12 commented on #620.Coverage matrix
Hosted (manual snippet). The real CLI prints the snippet against a mock API, and it's pasted into a real build. These cells are from runs 1–2.
gradle_snippetis unchanged on2463257.Vendored (v5 Gradle backend, new in
2463257). "Shapes" means: Groovy project repos, no settings file, Kotlin DSL, CRLF settings, allprojects, buildSrc, transitive-only. Probes: runs 36821273765 and 36821988108. Run 4 used Linux only.vendor --checkon a git checkoutVendored, run 5 cells (Linux).
.moduleartifact (jackson-core)includeBuild("build-logic")apply from:script with exclusiveContentVendored, run 6 cells (Linux).
[1.9,1.10.0]strictlyrange +prefer1.10.0!!1.+/latest.releasevendor --checkon pgp verification-metadatavendor --reverton pgp verification-metadataHosted snippet vs settings
dependencyResolutionManagement(run 6, Linux, 8.14.3 / 9.8.0). Pasted inbuild.gradleunder FAIL_ON_PROJECT_REPOS / PREFER_SETTINGS / PREFER_PROJECT: loud failure in each mode (fail-closed). Wrapped inside settings DRMrepositories: pass.Vendored, run 7 cells (Linux).
:testsclassifier depclassifier =requirerangeVendored vs corporate init scripts, run 9 (Linux, 8.14.3, fresh clone).
afterEvaluate { repositories.clear() }: pass (fail-closed).repositories.clear()before the build script: pass (patched).allprojects,settingsEvaluated/beforeSettings→ settings DRM): pass (patched).Vendored, run 10 cells (Linux).
.gitignorewith*.jar(github Java template), then vendor, commit, fresh clone: fail Vendored Gradle exits 0 when the project's .gitignore excludes *.jar, so the commit silently drops the patched jar and every fresh checkout fails to build #620 on 8.14.3 (Groovy) and 9.8.0 (Kotlin). vendor and--checkexit 0, the jar is never committed, and the fresh build fails loudly. In the fresh clone,--checkandvexcorrectly refuse.repositories.clear()before /afterEvaluate, enterprise plugin) on 9.8.0: pass, the same as 8.14.3.%41and#, on 8.14.3 and 9.8.0: pass.Vendored, run 11 cells (Linux).
.DS_Storein the vendored version directory: fail Vendored Gradle build fails on a stray file such as .DS_Store in the vendored tree, and the fix the error prescribes ("re-run socket-patch vendor") does nothing: vendor says already_vendored and repair is a no-op #656 on 8.14.3 (Groovy) and 9.8.0 (Kotlin). The build fails, andvendor/repairreport success without removing the file.vendorre-run: pass (rebuilt).Vendored, run 12 cells (Linux).
.gitignorewithvendor/: fail Vendored Gradle exits 0 when the project's .gitignore excludes *.jar, so the commit silently drops the patched jar and every fresh checkout fails to build #620 on 8.14.3. The whole.socket/vendor/tree, including the index, is never committed, and vendor and--checkexit 0.alias(...)plugin ids: theandroid_or_kmprefusal doesn't fire (vendor exits 0). The build is untested because dl.google.com is blocked. KMP wizard-style (jvm()) with catalog aliases: vendor exits 0, and the fresh build is patched (pass).pluginManagement { includeBuild("build-logic") }+ subproject buildscript classpath, fresh clone: pass (all three classpaths patched).vendor --revert: byte-exact (pass).Agent mode, run 8 (Linux, 8.14.3).
mavenCentral()) with the same GAV in~/.m2:applypatches m2,vexsaysnot_affected, and the build uses the unpatched cache jar. fail Agent-mode apply in a Gradle-only project patches the ~/.m2 copy Gradle never reads, reports success, and VEX attests not_affected while the build uses the unpatched ~/.gradle jar #551.mavenLocal()first (+-Dmaven.repo.local): pass (control).bf0e0d1(run 9), after Fix agent apply writing into shared package stores (#332, #361) #486's shared-store refusal: still fail Agent-mode apply in a Gradle-only project patches the ~/.m2 copy Gradle never reads, reports success, and VEX attests not_affected while the build uses the unpatched ~/.gradle jar #551.apply --global-prefix …/modules-2/files-2.1: loudpackage_not_installed, exit 1 (pass, fail-loud; scan reports success with 0 packages on a resolved Gradle project because the Gradle cache (~/.gradle/caches/modules-2) is never crawled #349 layout gap).Global (
-g), Linux, 8.14.3 cache.scan -greport: fail. No Gradle-cached purls (scan reports success with 0 packages on a resolved Gradle project because the Gradle cache (~/.gradle/caches/modules-2) is never crawled #349 comment).scan -g --mode hosted/--global-prefix --mode hostedrefusal: pass (exit 2, no writes).-gapply / rollback / vex: blocked (nothing discovered).-gcommands run inside a vendored Gradle project leave the project byte-unchanged (pass, run 5, after Fix -g touching the cwd project's state (#436, #445) #446).Backlog
android_or_kmpthere (run 12). Build it and file only if AGP fails or resolves the unpatched jar.-gmode. Linux is covered (the report, the refusal, no project leakage, and--global-prefixapply failing loudly). Still to do: macOS / Windows, andapply -g/rollback -g/vex -gwith the GAV in~/.m2(see the 20261001T040000Z entry).verify-signatureswith.moduleartifacts and imported BOMs..moduleartifact (jackson-core) cell on 9.8.0. It needs a second patch fixture.strictly/prefer.vendor. Check the result and VEX. Also the hosted snippet plus a classifier dependency (the hosted analogue of Vendored Gradle exits 0 with no warning on a classifier dependency of the patched module, then the build fails with "Could not find …-tests.jar" and IDE sources silently disappear #533).apply+vexwhenGRADLE_USER_HOMEand~/.m2hold different versions (a Agent-mode apply in a Gradle-only project patches the ~/.m2 copy Gradle never reads, reports success, and VEX attests not_affected while the build uses the unpatched ~/.gradle jar #551 variant).cd <subproject> && gradlebreaks #428, Vendored Gradle: on a Windows (core.autocrlf=true) checkout,vendor --checkfails andvendor --revert/remove/rollbackleave the settings script behind, because the index and script aren't covered by the -text .gitattributes #429, Vendored Gradle: gradle_exclusive_content_conflict refusal doesn't fire for a subproject build script or a buildSrc convention plugin, so vendor exits 0, the build then fails with "Could not find", and VEX attests not_affected #461, Vendored Gradle with PGP signature verification exits 0 but breaks the build, because pgp-only verification-metadata entries for the vendored pom and its parent chain are kept without a checksum #487, Vendored Gradle silently downgrades a version-range dependency to an older unpatched release (1.10.0 → 1.9), because the vendored repository has no maven-metadata.xml; vendor --check and VEX still report it patched #511, Vendored Gradle exits 0 with no warning on a classifier dependency of the patched module, then the build fails with "Could not find …-tests.jar" and IDE sources silently disappear #533, Agent-mode apply in a Gradle-only project patches the ~/.m2 copy Gradle never reads, reports success, and VEX attests not_affected while the build uses the unpatched ~/.gradle jar #551, Vendored Gradle exits 0 when the project's .gitignore excludes *.jar, so the commit silently drops the patched jar and every fresh checkout fails to build #620 and Vendored Gradle build fails on a stray file such as .DS_Store in the vendored tree, and the fix the error prescribes ("re-run socket-patch vendor") does nothing: vendor says already_vendored and repair is a no-op #656 whenvendor/jvm/,maven_crawler.rsorgradle_snippetchange.Known non-bugs
prebuilt_common::prepare_command+ a staged manifest/blob (see the run 3 entry). For hosted, use the wiremock shaped likee2e_redirect_maven_build.repo.maven.apache.org429s in the sandbox. Use an init script that rewrites it torepo1.maven.org. JDK 11/17 cells must run on GitHub runners.vendor_jvm_upstream_unavailable/verification_metadata_unavailable404 from the fixture means the m2 seed is missing (junit-bom:5.9.0/5.9.1:module). It's a mock artifact.settings.gradlewhen none exists. All documented.gradle_below_6_8), as documented.6.8-rc-*parses as 6.8 and is caught by the script's runtime check.scan/get --mode hostedkeeps its vendored patch (already); there's no takeover. That's safe.scan --vexending inmanifest_not_foundis correct.vexhas no Gradle product auto-detection (pass--product, or use the git remote), as documented.verification-metadata.xmlfails loudly, which is fail-closed.repo.maven.apache.organdrepo1.maven.org) can 429 Gradle in the sandbox. Point mavenCentral atfile://<seeded m2>with an init script.remove <purl>, or a manifest edit + re-vendor) keeps the other wired correctly. Verified in run 4.settings.gradleis rejected by Gradle itself; it isn't a valid fixture.vex -gattests the cwd project's vendored or hosted state by design (vex.rs:1013).applywith "File not found", which is a fixture error.allprojects; the vendored script itself is IP-compatible on 9.8.0.build.gradleof a settings-DRM build fails loudly in everyrepositoriesMode. It works when wrapped insidedependencyResolutionManagement { repositories { … } }. That's placement, not a silent bypass.1.+/latest.releasedeclarations resolve the newest release before and after vendoring, so a base-version patch correctly doesn't apply. That isn't Vendored Gradle silently downgrades a version-range dependency to an older unpatched release (1.10.0 → 1.9), because the vendored repository has no maven-metadata.xml; vendor --check and VEX still report it patched #511.vendor --revertis byte-exact on a verification-metadata file with pgp entries (run 6).mvn-seededfile://m2 has nomaven-metadata.xml, so range or dynamic-version cells fail before vendoring too. Use real Central for those.gradle.lockfilewritten before vendoring masks Vendored Gradle silently downgrades a version-range dependency to an older unpatched release (1.10.0 → 1.9), because the vendored repository has no maven-metadata.xml; vendor --check and VEX still report it patched #511: the range resolves to the locked, vendored version (run 7).mavenLocal()ignores theMAVEN_REPO_LOCALenv var. It uses-Dmaven.repo.localor settings.xml, so a harness must pass the system property (run 8).repositories.clear()) doesn't make vendored Gradle fail open. Gradle keeps the exclusiveContent exclusivity after the vendored repository is removed, so the build fails loudly (run 9).File.toURI(), notfile://strings: Gradle normalizesfile:///xtofile:/x/(run 9 harness note).InvalidPathExceptionon non-ASCII project paths in the sandbox because there's no UTF-8 locale. ExportLC_ALL=C.UTF-8(run 10).gradle::wired()accepts the apply line in eithersettings.gradleorsettings.gradle.kts. Gradle reads the Groovy file when both exist, and the planner targets it too, so a mismatch only happens if someone hand-moves the line. That's contrived, so it hasn't been filed (run 10).build.gradle.ktswith thejavaplugin applied,java.util.…resolvesjavato the extension. Use a top-levelimport(run 11).vendor(rebuilt). Only extra files hit Vendored Gradle build fails on a stray file such as .DS_Store in the vendored tree, and the fix the error prescribes ("re-run socket-patch vendor") does nothing: vendor says already_vendored and repair is a no-op #656 (run 11).android_or_kmponly matches literal plugin ids (gradle.rs:1043), so catalogalias(...)builds aren't refused. On a KMPjvm()build the vendored jar is correctly on the classpath, so that's not filed unless an Android build shows harm (run 12).build-logic*.gradle.ktsscripts hit the samejava.extension shadowing as build scripts. Use top-level imports (run 12).All reactions