Bug hunt ledger: Gradle #319
Replies: 5 comments
|
[agent] 2026-09-30: Gradle bug-hunt run This is the first run. The ledger was empty and there were no Tested: main Setup: the sandbox can't reach the Socket API. A small Python mock of Cells
Issues
False positives ruled out
Next
|
|
[agent] 2026-09-30: Gradle bug-hunt run This is run 2. Tested: main Re-triage: #347, #348 and #349 are still open. Main hasn't moved since they were filed, so there was nothing new to verify and I left no comment. Mock setup (reusable): the Python mock of Cells
Issues
False positives ruled out
Blocked
Next
|
|
[agent] 2026-10-01: maintainer note: test global ( This is a maintainer request, not a run report. Add it to the top of the backlog and keep it there until the cells below are covered. Ask: make sure we correctly scan global installs when Where Gradle puts global installs: The Gradle cache ( What to check (prove each with a real global install, not by reading source):
Add OS × Gradle version cells for |
|
[agent] 2026-10-01: Gradle bug-hunt run This is run 3. Tested: main
Harness (reusable): a scratch Re-triage
Cells (vendored Gradle, new on main)
Issues
False positives ruled out
Blocked
Next
|
|
[agent] 2026-10-01: Gradle bug-hunt run This is run 4. Tested: main Harness: a scratch Re-triageMain hasn't moved since run 3, which re-checked #349 and #395 on this SHA and filed #428 and #429 against it. I re-ran nothing and changed no issues. Cells
Issues
False positives ruled out
Next
|
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
[agent] Progress ledger for the scheduled Gradle bug-hunt routine (label pm:gradle).
Last updated: 2026-10-01 (run 4), main
2463257(#277, v5: Gradle 6.8+ vendoring backend), latest release v4.0.0.Coverage matrix
Hosted (manual snippet). The real CLI prints the snippet against a mock API, and it's pasted into a real build. These cells are from runs 1–2.
gradle_snippetis unchanged on2463257.Vendored (v5 Gradle backend, new in
2463257). "Shapes" means: Groovy project repos, no settings file, Kotlin DSL, CRLF settings, allprojects, buildSrc, transitive-only. Probes: runs 36821273765 and 36821988108. Run 4 used Linux only.vendor --checkon a git checkoutGlobal (
-g), Linux, 8.14.3 cache.scan -greport: fail. No Gradle-cached purls (scan reports success with 0 packages on a resolved Gradle project because the Gradle cache (~/.gradle/caches/modules-2) is never crawled #349 comment).scan -g --mode hosted/--global-prefix --mode hostedrefusal: pass (exit 2, no writes).-gapply / rollback / vex: blocked (nothing discovered).Backlog
-gmode. Linux report and refusal are covered. Still to do: macOS / Windows, and apply / rollback / vex through--global-prefix …/modules-2/files-2.1if that's meant to be supported (see the 20261001T040000Z entry).settings.gradle.kts+pluginManagement { includeBuild("build-logic") }convention plugins: isbuild-logicwired, and are its repositories checked (Vendored Gradle: gradle_exclusive_content_conflict refusal doesn't fire for a subproject build script or a buildSrc convention plugin, so vendor exits 0, the build then fails with "Could not find", and VEX attests not_affected #461)?vendor. Check the result and VEX.apply from: 'gradle/repos.gradle'script plugins declaring repositories (a likely Vendored Gradle: gradle_exclusive_content_conflict refusal doesn't fire for a subproject build script or a buildSrc convention plugin, so vendor exits 0, the build then fails with "Could not find", and VEX attests not_affected #461 sibling).dependencyResolutionManagementFAIL_ON_PROJECT_REPOS with the hosted snippet; multi-project hosted snippet placement.cd <subproject> && gradlebreaks #428, Vendored Gradle: on a Windows (core.autocrlf=true) checkout,vendor --checkfails andvendor --revert/remove/rollbackleave the settings script behind, because the index and script aren't covered by the -text .gitattributes #429 and Vendored Gradle: gradle_exclusive_content_conflict refusal doesn't fire for a subproject build script or a buildSrc convention plugin, so vendor exits 0, the build then fails with "Could not find", and VEX attests not_affected #461 when main moves.Known non-bugs
prebuilt_common::prepare_command+ a staged manifest/blob (see the run 3 entry). For hosted, use the wiremock shaped likee2e_redirect_maven_build.repo.maven.apache.org429s in the sandbox. Use an init script that rewrites it torepo1.maven.org. JDK 11/17 cells must run on GitHub runners.vendor_jvm_upstream_unavailable/verification_metadata_unavailable404 from the fixture means the m2 seed is missing (junit-bom:5.9.0/5.9.1:module). It's a mock artifact.settings.gradlewhen none exists. All documented.gradle_below_6_8), as documented.6.8-rc-*parses as 6.8 and is caught by the script's runtime check.scan/get --mode hostedkeeps its vendored patch (already); there's no takeover. That's safe.scan --vexending inmanifest_not_foundis correct.vexhas no Gradle product auto-detection (pass--product, or use the git remote), as documented.verification-metadata.xmlfails loudly, which is fail-closed.repo.maven.apache.organdrepo1.maven.org) can 429 Gradle in the sandbox. Point mavenCentral atfile://<seeded m2>with an init script.remove <purl>, or a manifest edit + re-vendor) keeps the other wired correctly. Verified in run 4.All reactions