[agent] Filed by Claude Code on behalf of Mikola Lysenko (@mikolalysenko) while adding Maven patch SBOM annotations to depscan. Reproduced with a release build of socket-patch 3efdc31d (sha256 dc5fb57f…), a stub patch API, and real Apache Maven 2.2.1 through 4.0.0-rc-7 (13 lines) on macOS arm64 / JDK 26.
Severity: medium (no data loss; the CLI refuses without touching files, but there is no supported undo).
Cells: every hosted cell with changed files, all 13 Maven lines (562 cells). The harness accepts this as
"refused fail-closed"; it is still a CLI gap.
Repro (after scan --mode hosted on the direct shape, commons-text 1.9 → 1.9-socket.c0de7e19):
socket-patch rollback --offline --json --yes --cwd <project>
Output: status: "partial_failure", hosted.failed: [{"purl": "group:maven", "error": "no hosted-redirect revert implementation for redirect_maven_trusted_checksums — re-run scan --mode hosted to normalize, or restore the file from version control (.mvn/checksums/checksums.sha256, .mvn/maven.config, pom.xml)"}]. pom.xml, .mvn/ and
.socket/vendor/redirect-state.json are unchanged. Legacy same-GAV mode fails the same way on
redirect_maven_repository.
remove <uuid> with one record: error.code: hosted_revert_failed, same message.
remove <uuid> with two records (two-patched): error.code: hosted_revert_unsupported, "no per-purl
hosted-redirect revert exists for: pkg:maven/org.apache.commons/commons-text@1.9?ext=jar. Run an unscoped
socket-patch rollback to unwind ALL hosted redirects". The unscoped rollback then fails as above.
- Cause:
crates/socket-patch-core/src/patch/redirect/replay.rs:174 maps every redirect_maven_* kind to
Inverse::Unsupported (pinned by the test maven_structured_edits_refuse_and_keep_the_record).
- The
purl: "group:maven" label is also not a purl.
- Expected: either implement the inverse (every maven edit records
original/new, like the vendored wiring's
whole-file snapshot), or make remove stop recommending the unscoped rollback for maven.
[agent] Filed by Claude Code on behalf of Mikola Lysenko (@mikolalysenko) while adding Maven patch SBOM annotations to depscan. Reproduced with a release build of socket-patch
3efdc31d(sha256dc5fb57f…), a stub patch API, and real Apache Maven 2.2.1 through 4.0.0-rc-7 (13 lines) on macOS arm64 / JDK 26.Severity: medium (no data loss; the CLI refuses without touching files, but there is no supported undo).
Cells: every hosted cell with changed files, all 13 Maven lines (562 cells). The harness accepts this as
"refused fail-closed"; it is still a CLI gap.
Repro (after
scan --mode hostedon thedirectshape, commons-text 1.9 →1.9-socket.c0de7e19):Output:
status: "partial_failure",hosted.failed: [{"purl": "group:maven", "error": "no hosted-redirect revert implementation for redirect_maven_trusted_checksums — re-runscan --mode hostedto normalize, or restore the file from version control (.mvn/checksums/checksums.sha256, .mvn/maven.config, pom.xml)"}].pom.xml,.mvn/and.socket/vendor/redirect-state.jsonare unchanged. Legacy same-GAV mode fails the same way onredirect_maven_repository.remove <uuid>with one record:error.code: hosted_revert_failed, same message.remove <uuid>with two records (two-patched):error.code: hosted_revert_unsupported, "no per-purlhosted-redirect revert exists for: pkg:maven/org.apache.commons/commons-text@1.9?ext=jar. Run an unscoped
socket-patch rollbackto unwind ALL hosted redirects". The unscoped rollback then fails as above.crates/socket-patch-core/src/patch/redirect/replay.rs:174maps everyredirect_maven_*kind toInverse::Unsupported(pinned by the testmaven_structured_edits_refuse_and_keep_the_record).purl: "group:maven"label is also not a purl.original/new, like the vendored wiring'swhole-file snapshot), or make
removestop recommending the unscoped rollback for maven.