[agent] Filed by the October 7 architecture audit campaign (ecosystems). Register: arch-audit register.
Kind: bug. Source: audit B63 (new finding), register E86.
Problem: maven_registry_base() returns SOCKET_MAVEN_REGISTRY or Maven Central, and it is the only remote base for acquire_classifier, verify_jvm_upstream, acquire_jvm_artifact, acquire_upstream_pom and agent-mode jvm_jar.rs. settings.xml <mirrors>, pom <repositories>, Gradle repositories {} and sbt resolvers are never read. An online vendor always fetches .sha512/.sha1 from that base, even when the bytes came from a local cache, and refuses with vendor_jvm_upstream_unavailable on any fetch error.
Impact: on a network that reaches Central only through a corporate mirror, every online JVM vendor fails closed; the process-global env var is the only workaround. No silent unpatched build. Low priority per the maintainer's ecosystem triage.
Proposed change: resolve the upstream base per build (the effective settings.xml mirror for central, the Gradle repositories, or the sbt/Coursier resolution URL already in the gate evidence) and fall back to Central with a named warning. Land it in vendor::jvm::layout::registry_base (#1032).
Acceptance criteria:
Dependencies: after #1032. Related: E43, #263.
Generated by Claude Code
[agent] Filed by the October 7 architecture audit campaign (ecosystems). Register: arch-audit register.
Kind: bug. Source: audit B63 (new finding), register E86.
Problem:
maven_registry_base()returnsSOCKET_MAVEN_REGISTRYor Maven Central, and it is the only remote base foracquire_classifier,verify_jvm_upstream,acquire_jvm_artifact,acquire_upstream_pomand agent-modejvm_jar.rs. settings.xml<mirrors>, pom<repositories>, Gradlerepositories {}and sbtresolversare never read. An online vendor always fetches.sha512/.sha1from that base, even when the bytes came from a local cache, and refuses withvendor_jvm_upstream_unavailableon any fetch error.Impact: on a network that reaches Central only through a corporate mirror, every online JVM vendor fails closed; the process-global env var is the only workaround. No silent unpatched build. Low priority per the maintainer's ecosystem triage.
Proposed change: resolve the upstream base per build (the effective settings.xml mirror for
central, the Gradle repositories, or the sbt/Coursier resolution URL already in the gate evidence) and fall back to Central with a named warning. Land it invendor::jvm::layout::registry_base(#1032).Acceptance criteria:
mirrorOf centralmirror vendors online against the mirror.Dependencies: after #1032. Related: E43, #263.
Generated by Claude Code