[
https://issues.apache.org/jira/browse/FELIX-6857?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Paul Rütter closed FELIX-6857.
------------------------------
> maven-bundle-plugin: do not embed type=pom dependencies (bnd 7.3.0 fails
> opening the .pom as a JAR)
> ---------------------------------------------------------------------------------------------------
>
> Key: FELIX-6857
> URL: https://issues.apache.org/jira/browse/FELIX-6857
> Project: Felix
> Issue Type: Bug
> Components: Maven Bundle Plugin
> Affects Versions: maven-bundle-plugin-6.1.0
> Reporter: Paul Rütter
> Assignee: Paul Rütter
> Priority: Major
> Fix For: maven-bundle-plugin-6.1.2
>
>
> h3. Summary
> When a bundle uses {{Embed-Dependency}} and one of the selected dependencies
> is a
> {{type=pom}} artifact (a BOM/aggregator declared as a compile dependency), the
> maven-bundle-plugin adds that artifact's {{.pom}} file to the bundle classpath
> ({{{}Bundle-ClassPath{}}} / {{{}-includeresource{}}}). bnd's CDI-annotations
> analyzer then
> tries to open the {{.pom}} as a JAR/ZIP and fails.
> * maven-bundle-plugin *6.0.2* (embeds bnd 7.0.0): emits {{[WARNING] Invalid
> bundle
> classpath entry}} and {*}builds successfully{*}.
> * maven-bundle-plugin *6.1.0* (embeds bnd 7.3.0): the same condition is now
> a fatal
> {{[ERROR] Error(s) found in bundle configuration}} and {*}fails the build{*}.
> Upgrading the plugin therefore breaks any bundle that embeds a pom-type
> dependency.
> h3. Root cause
> {{DependencyEmbedder}} embeds any selected artifact whose file exists, without
> checking its type. A {{type=pom}} dependency resolves to a {{.pom}} file,
> which is
> then placed on the bundle classpath. A pom contains no classes and must never
> be on
> the classpath. (The non-embed classpath path in
> {{BundlePlugin.getClasspath()}}
> already excludes poms via {{{}ArtifactHandler.isAddedToClasspath(){}}}, so
> only the embed
> path is affected.)
> The hard-fail itself is a bnd 7.0.0 -> 7.3.0 behaviour change in
> {{aQute.bnd.cdi.CDIAnnotations#analyzeJar}} (warning promoted to fatal
> error), but the
> plugin should never have put the {{.pom}} on the classpath in the first place.
> h3. Reproducer
> {code:xml}
> <packaging>bundle</packaging>
> <dependencies>
> <dependency>
> <groupId>software.amazon.awssdk</groupId>
> <artifactId>core</artifactId>
> <version>2.54.3</version>
> <type>pom</type>
> </dependency>
> </dependencies>
> ...
> <Embed-Dependency>*;scope=compile</Embed-Dependency>
> <Embed-Transitive>true</Embed-Transitive>
> {code}
> {{mvn clean package}} fails on 6.1.0, succeeds on 6.0.2.
> h3. Failure output (6.1.0)
> {noformat}
> [ERROR] Bundle ... : Analyzer Plugin CDIAnnotations failed The JAR/ZIP file
> (.../software/amazon/awssdk/core/2.54.3/core-2.54.3.pom) seems corrupted,
> error: zip END header not found -> zip END header not found for AnalyzerPlugin
> [ERROR] Error(s) found in bundle configuration
> {noformat}
> The {{.pom}} is valid XML, not corrupt — bnd is opening a pom as an archive.
> h3. Fix
> Exclude {{type=pom}} artifacts from embedding in {{DependencyEmbedder}}
> (covering both
> the embed and inline paths), logging a warning so it is not silent.
> h3. Notes
> A companion change in bnd to skip non-zip classpath entries would also be
> reasonable,
> but the plugin-side guard prevents the invalid entry regardless.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)