Repository navigation
Fix vendored JVM/NuGet artifacts dropped by .gitignore (#1061) - #1330
Merged
Mikola Lysenko (mikolalysenko) merged 7 commits intoOct 10, 2026
Merged
Conversation
Draft placeholder for #1061. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Vendoring a Maven, Gradle or NuGet package exited 0 even when the project's .gitignore dropped the payload from the commit: GitHub's stock Java.gitignore ignores *.jar and VisualStudio.gitignore ignores *.nupkg, so every fresh clone lost the patched artifact while `vendor --check` and VEX later failed. Only the npm family checked. - The Maven reactor (.socket/vendor/maven2) and Gradle (.socket/vendor/gradle) tree roots now own a `!*` .gitignore, the way sbt and Coursier already did: created when absent, adopted when present, removed with the last entry, restored by repair. - Every JVM shape refuses vendor_artifact_gitignored before writing when git ignores the tree root itself (a .socket/ rule). - NuGet refuses an ignored <uuid>/ before writing, writes <uuid>/.gitignore next to the nupkg, and probes the written nupkg again like npm does. Fixes #1061 (and its Gradle twin #620). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Mikola Lysenko (mikolalysenko)
marked this pull request as ready for review
October 9, 2026 17:15
Collaborator
Author
|
BugBot review |
Mikola Lysenko (mikolalysenko)
enabled auto-merge
October 9, 2026 17:15
Review follow-ups for #1061: - jvm_gate_preflight now also refuses vendor_artifact_gitignored when git ignores a JVM tree root. It runs before a hosted->vendored takeover restores upstream, so a Gradle pin (whose hosted index the group commit can't roll back) stays hosted instead of ending neither hosted nor vendored. - NuGet checks the ignored uuid dir before the empty-patch success return, so an empty patch can't report success under a .socket/ rule. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Collaborator
Author
|
BugBot review |
Tanmay Singla (Tanmay182003)
approved these changes
Oct 9, 2026
Collaborator
Author
|
bugbot run Generated by Claude Code |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.
Bugbot Autofix is ON. A cloud agent has been kicked off to fix the reported issue.
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit 129f1c3. Configure here.
Mikola Lysenko (mikolalysenko)
disabled auto-merge
October 9, 2026 19:55
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
write_uuid_gitignore only accepted an exact `!*\n`, so a Windows core.autocrlf checkout (`!*\r\n`) was rewritten to LF on every wet re-vendor, dirtying the tree. Compare eol-blind. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
# Conflicts: # crates/socket-patch-cli/CLI_CONTRACT.md
Mikola Lysenko (mikolalysenko)
enabled auto-merge
October 10, 2026 15:48
Mikola Lysenko (mikolalysenko)
deleted the
agent/v5-vendored-gitignore-all
branch
October 10, 2026 16:07
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

LLM Description written by Claude Code:claude-opus-5-5
Fixes #1061 (and its Gradle twin #620, closed as a duplicate).
Summary
vendorof a Maven, Gradle or NuGet package exited 0 even when the project's.gitignoredropped the payload from the commit. GitHub's stock Java.gitignore ignores*.jarand VisualStudio.gitignore ignores*.nupkg, so every fresh clone lost the patched artifact (vendor --checkexits 1, VEX omits the purl). Vendored JVM and NuGet artifacts now get the same handling npm already had: a!*re-include, plus a refusal when git would still drop the artifact.Root cause
Only the npm-family sink checked whether git would commit the vendored artifact.
npm_common::stage_patch_packrefuses an ignored<uuid>/and writes a<uuid>/.gitignorere-include. sbt and Coursier own a!*.gitignoreat their tree roots. The Maven reactor (.socket/vendor/maven2, which every pom root uses), Gradle (.socket/vendor/gradle) and NuGet (.socket/vendor/nuget/<uuid>) had neither the re-include nor the probe.Change
!*.gitignoreat their tree roots, following the sbt / Coursier pattern:record_allowed, line-ending-blind compare, group-commit capture);repair(restore_jvm_owned_files).The reactor shares sbt's
.socket/vendor/maven2/.gitignore.vendor_artifact_gitignoredinjvm_preludewhen git ignores the tree root itself, for example with a.socket/rule. No nested.gitignorecan override such a rule. This runs before any write, dry run included, and also in the service download plan, so no grant is wasted.nuget_preluderefuses an ignored<uuid>/before anything is written.write_nupkgwrites<uuid>/.gitignore(!*) next to the nupkg, and the in-sync hot path backfills it for directories vendored before this change.vendor_artifact_gitignore_unchecked.jvm_gate_preflight(run before a hosted->vendored takeover restores upstream) also refuses an ignored tree root, so a Gradle pin stays hosted instead of ending neither; NuGet checks the ignored uuid dir before the empty-patch success return.CLI_CONTRACT.md(nuget/maven artifact rows and thevendor_artifact_gitignored/_uncheckedcode rows) anddocs/ecosystems.md.The diff stays small around #1279 (crate-bloat cleanup) and #1288 (nuget.config): it adds no parameters to any backend signature.
Per-issue checklist
maven_repo::tests::a_jar_ignore_rule_is_overridden_by_the_tree_gitignore. Every written.socket/file is committable, and revert leaves no.gitignorebehind..socket//.socket/vendor/rules refuse with nothing written (wet and dry):maven_repo::tests::a_jvm_tree_directory_ignore_rule_refuses_before_any_write.nuget_feed::tests::a_nupkg_ignore_rule_is_overridden_by_the_uuid_gitignore.nuget_feed::tests::a_directory_ignore_rule_refuses_before_any_write.groovy_settings_gets_the_apply_line_and_the_tree), CRLF owned-file test (vendor_jvm_cli) and the real-toolchain capstones' expected file sets (e2e_vendor_jvm_build) are updated for the new owned file.Red → green
Before the fix,
a_jar_ignore_rule_is_overridden_by_the_tree_gitignorefailed withleft: Some(".gitignore:14:*.jar\t.socket/vendor/maven2/…/commons-text-1.10.0-socket.9f6b2c4e.jar"), anda_nupkg_ignore_rule_is_overridden_by_the_uuid_gitignorefailed because no<uuid>/.gitignoreexisted. Both pass after the fix.Commands run
cargo test -p socket-patch-core --lib: 6113 passed.cargo test -p socket-patch-cli --all-featureswith--testset to vendor_jvm_cli, in_process_vendor, e2e_nuget, e2e_sbt_vendor, e2e_scala_cli_vendor, maven_sidecar_cli, vendor_eject, vendor_eject_fresh_checkout, vendor_group_commit_e2e, covgap_commands_vendor, e2e_maven, e2e_vex_vendor and vendor_crash_safety_e2e: all green.cargo clippy --workspace --all-features -- -D warnings: clean.🤖 Generated with Claude Code
Note
Medium Risk
Touches vendoring write paths and preflight gates for Maven, Gradle, and NuGet; behavior change is additive (new files + fail-closed on uncommittable trees) with broad test coverage.
Overview
Fixes vendored JVM and NuGet payloads being dropped from git when projects use stock ignore rules (
*.jar,*.nupkg), aligning them with npm-family behavior.JVM: Maven reactor (
.socket/vendor/maven2) and Gradle (.socket/vendor/gradle) now write a tree-root.gitignorewith!*(same content as sbt/Coursier). It is an owned file (plan, revert, repair, group commit). Vendoring refusesvendor_artifact_gitignoredwhen git ignores the tree root itself (e.g..socket/), including dry runs and hosted→vendored preflight.NuGet: Each uuid feed dir gets
<uuid>/.gitignore(!*); preflight refuses an ignored uuid dir; after writing the nupkg, git is probed again with unwind on failure. In-sync re-runs backfill.gitignoreon older vendored dirs.Shared helper
npm_dir::ignored_root_refusaldrives the directory-level checks. Docs (CLI_CONTRACT.md,docs/ecosystems.md) and e2e expectations are updated; new git-worktree tests cover Java/Visual Studio ignore templates.Reviewed by Cursor Bugbot for commit 129f1c3. Configure here.
Generated by Claude Code