Frun1na opened a new issue, #5085:
URL: https://github.com/apache/rocketmq-dashboard/issues/5085

   ### Before creating
   
   - [x] I have searched the existing issues and found no duplicate.
   - [x] I have checked the latest `rocketmq-studio` branch where this problem 
still exists.
   
   ### Bug report
   
   **Which page or component**
   
   Server build: `mvn package` → `binary-license-gate` (maven-antrun, 
`server/scripts/legal.py jar ...`), bound to the default `package` phase in 
`server/pom.xml`.
   
   **What happened**
   
   `mvn -DskipTests package` fails on every run at tip `a562601d`:
   
   ```
   [ERROR] Failed to execute goal 
org.apache.maven.plugins:maven-antrun-plugin:3.2.0:run (binary-license-gate)
       on project rocketmq-studio: ... exec returned: 1
   ```
   
   Reproducing the gate command directly shows why — the gate requires 
**every** dependency JAR inside `BOOT-INF/lib/` to carry its complete license 
text, but the vast majority of Maven-published JARs do not embed one:
   
   ```
   $ python3 scripts/legal.py jar target/rocketmq-studio-3.0.0.jar --output 
target/legal
   license gate: release license gate failed:
   HikariCP-7.0.2.jar: missing complete upstream LICENSE/COPYING; ...
   ST4-4.3.4.jar: missing complete upstream LICENSE/COPYING; ...
   ... (164 jars in total)
   Spring Boot loader: missing the original META-INF/LICENSE.txt or NOTICE.txt
   ```
   
   I verified one representative: `HikariCP-7.0.2.jar` (extracted from the fat 
JAR) contains 98 entries and none named LICENSE/NOTICE/COPYING. The gate's own 
synthetic tests only ever exercise a one-component fixture (`legal_test.py` 
reports "1 actual components"), so this was never run against the real 
dependency set. Consequences:
   
   - `mvn package` fails for every developer;
   - the CI / docker compose default image build (server/Dockerfile stage 
`build`) fails at the same step;
   - the same batch also introduced the web license gate failure tracked in 
#5084 (fixed by #5083).
   
   **Expected behaviour**
   
   `mvn -DskipTests package` should complete. The gate's contract needs a 
decision before it can pass, e.g.:
   
   - vendor the complete license texts for the dependencies that omit them, 
with pinned checksums like the web side does 
(`web/licenses/toggle-selection-1.0.6/LICENSE` pattern) — but that is ~164 
texts to source and verify; or
   - require license materials only for a defined release profile / 
redistribute the license obligations differently; or
   - relax the per-jar requirement to a curated allowlist of components that 
actually ship license files.
   
   I can help implement whichever direction is chosen, but sourcing and 
verifying 164 license texts is not something I can do unilaterally, hence 
issue-first.
   
   **Environment**
   
   - RocketMQ Studio: upstream `rocketmq-studio` tip `a562601d`
   - `mvn -B -ntp package -DskipTests`, OpenJDK 21, Maven 3.9.9
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to