Skip to content

Mvn4: Remove extracted Mac OS JLine binaries from Maven distro#11997

Merged
kwin merged 1 commit into
maven-4.0.xfrom
bugfix/remove-extracted-macos-jline-binaries-mvn4
Apr 28, 2026
Merged

Mvn4: Remove extracted Mac OS JLine binaries from Maven distro#11997
kwin merged 1 commit into
maven-4.0.xfrom
bugfix/remove-extracted-macos-jline-binaries-mvn4

Conversation

@kwin
Copy link
Copy Markdown
Member

@kwin kwin commented Apr 28, 2026

This prevents issues with the quarantine flag otherwise preventing binaries with that flag from being executed
(https://www.cisa.gov/eviction-strategies-tool/info-attack/T1144). The fallback automatically kicks in which loads the binary from the JAR (https://github.com/jline/jline3/blob/master/native/src/main/java/org/jline/nativ/JLineNativeLoader.java) which doesn't have the quarantine flag.

This closes #10747

Following this checklist to help us incorporate your
contribution quickly and easily:

  • Your pull request should address just one issue, without pulling in other changes.
  • Write a pull request description that is detailed enough to understand what the pull request does, how, and why.
  • Each commit in the pull request should have a meaningful subject line and body.
    Note that commits might be squashed by a maintainer on merge.
  • Write unit tests that match behavioral changes, where the tests fail if the changes to the runtime are not applied.
    This may not always be possible but is a best-practice.
  • Run mvn verify to make sure basic checks pass.
    A more thorough check will be performed on your pull request automatically.
  • You have run the Core IT successfully.

If your pull request is about ~20 lines of code you don't need to sign an
Individual Contributor License Agreement if you are unsure
please ask on the developers list.

To make clear that you license your contribution under
the Apache License Version 2.0, January 2004
you have to acknowledge this by using the following check-box.

This prevents issues with the quarantine flag otherwise preventing
binaries with that flag from being executed
(https://www.cisa.gov/eviction-strategies-tool/info-attack/T1144).
The fallback automatically kicks in which loads the binary from the JAR
(https://github.com/jline/jline3/blob/master/native/src/main/java/org/jline/nativ/JLineNativeLoader.java)
which doesn't have the quarantine flag.

This closes #10747
@kwin kwin requested a review from gnodet April 28, 2026 16:01
@kwin kwin added bug Something isn't working backport-to-4.0.x labels Apr 28, 2026
@kwin kwin changed the title Remove extracted Mac OS JLine binaries from Maven distro Mvn4: Remove extracted Mac OS JLine binaries from Maven distro Apr 28, 2026
@kwin kwin requested a review from slawekjaranowski April 28, 2026 16:01
@kwin kwin modified the milestones: 4.0.0, 4.0.0-rc-6 Apr 28, 2026
@kwin kwin added the mvn40 label Apr 28, 2026
@kwin kwin modified the milestones: 4.0.0-rc-6, 4.0.0 Apr 28, 2026
@slawekjaranowski slawekjaranowski linked an issue Apr 28, 2026 that may be closed by this pull request
@kwin kwin modified the milestones: 4.0.0-rc-6, 4.0.0 Apr 28, 2026
@kwin kwin merged commit f81a828 into maven-4.0.x Apr 28, 2026
24 checks passed
@kwin kwin deleted the bugfix/remove-extracted-macos-jline-binaries-mvn4 branch April 28, 2026 17:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-to-4.0.x bug Something isn't working mvn40

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[MNG-8471] library load disallowed by system policy on Mac

2 participants