Hi all, Hi Guix Java-team, Recently, while rewriting and cleaning up my Gradle build recipe I've got bit by Guix Groovy package not shading dependencies where the upstream does it. For Gradle being able to compile Groovy is quite fundamental, and thus Gradle has dependency on various Groovy JARs. Gradle also uses separate classloaders to avoid polluting classpaths of its workers and compiling routines. That means Gradle needs to know upfront which JARs are needed to invoke Groovy compiler, so the list is hardcoded and some routines working with Groovy even make assumptions on what this list consist of. This is where patching Gradle to build for Guix gets complicated. Upstream Groovy shades ASM, Antlr and Picoli. In turn, Groovy support routines in Gradle depend on that. However Guix build of Groovy doesn't shade any libraries. While I managed to patch to make Gradle support Guix build of Groovy before[0], I changed something when rewriting the build recipe and got bit by this again. Overall this patching look quite hackish to me making me feel I'm on very shaky ground - I'm sure I've broken some edge cases (or even not really edge ones).
So, what do you think about changing the Groovy build recipe to shade in those libraries and thus match what upstream build process does? And if you approve the shading, do I need to make Groovy package output still reference store paths of the libraries that are shaded? As otherwise, the only way to find out about the dependencies (for example, to check for usages of vulnerable packages) is to inspect the package recipe or Groovy build derivation. [0]: https://github.com/TarCV/gradle-guix/blob/develop/patches/gradle-4.5.1-unshaded-groovy.patch Small vocabulary for those not working with Java ecosystem: Classpath - list of locations where Java looks for symbol implementations. In this message I mean runtime classpath - a list that is used during application exectution. Shading - it's a process somewhat similar to compiling libraries statically into an application or another library. During shading bytecode from a dependency is copied to an application (or library) with patched symbol names, i.e. org.ow2.asm.Opcodes becomes something like my.app.asm.Opcodes). Regards, Constantin
