Skip to content

Hosted Maven redirects cannot be reverted, and remove recommends an unscoped rollback that also fails #271

Description

[agent] Filed by Claude Code on behalf of Mikola Lysenko (@mikolalysenko) while adding Maven patch SBOM annotations to depscan. Reproduced with a release build of socket-patch 3efdc31d (sha256 dc5fb57f…), a stub patch API, and real Apache Maven 2.2.1 through 4.0.0-rc-7 (13 lines) on macOS arm64 / JDK 26.

Severity: medium (no data loss; the CLI refuses without touching files, but there is no supported undo).

Cells: every hosted cell with changed files, all 13 Maven lines (562 cells). The harness accepts this as
"refused fail-closed"; it is still a CLI gap.

Repro (after scan --mode hosted on the direct shape, commons-text 1.9 → 1.9-socket.c0de7e19):

socket-patch rollback --offline --json --yes --cwd <project>

Output: status: "partial_failure", hosted.failed: [{"purl": "group:maven", "error": "no hosted-redirect revert implementation for redirect_maven_trusted_checksums — re-run scan --mode hosted to normalize, or restore the file from version control (.mvn/checksums/checksums.sha256, .mvn/maven.config, pom.xml)"}]. pom.xml, .mvn/ and
.socket/vendor/redirect-state.json are unchanged. Legacy same-GAV mode fails the same way on
redirect_maven_repository.

  • remove <uuid> with one record: error.code: hosted_revert_failed, same message.
  • remove <uuid> with two records (two-patched): error.code: hosted_revert_unsupported, "no per-purl
    hosted-redirect revert exists for: pkg:maven/org.apache.commons/commons-text@1.9?ext=jar. Run an unscoped
    socket-patch rollback to unwind ALL hosted redirects". The unscoped rollback then fails as above.
  • Cause: crates/socket-patch-core/src/patch/redirect/replay.rs:174 maps every redirect_maven_* kind to
    Inverse::Unsupported (pinned by the test maven_structured_edits_refuse_and_keep_the_record).
  • The purl: "group:maven" label is also not a purl.
  • Expected: either implement the inverse (every maven edit records original/new, like the vendored wiring's
    whole-file snapshot), or make remove stop recommending the unscoped rollback for maven.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions