Hi all, Hi Guix Java-team,

Recently, while rewriting and cleaning up my Gradle build recipe I've got bit 
by Guix Groovy package not shading dependencies where the upstream does it.
For Gradle being able to compile Groovy is quite fundamental, and thus Gradle 
has dependency on various Groovy JARs. Gradle also uses separate classloaders 
to avoid polluting classpaths of its workers and compiling routines. That means 
Gradle needs to know upfront which JARs are needed to invoke Groovy compiler, 
so the list is hardcoded and some routines working with Groovy even make 
assumptions on what this list consist of.
This is where patching Gradle to build for Guix gets complicated. Upstream 
Groovy shades ASM, Antlr and Picoli. In turn, Groovy support routines in Gradle 
depend on that. However Guix build of Groovy doesn't shade any libraries. While 
I managed to patch to make Gradle support Guix build of Groovy before[0], I 
changed something when rewriting the build recipe and got bit by this again. 
Overall this patching look quite hackish to me making me feel I'm on very shaky 
ground - I'm sure I've broken some edge cases (or even not really edge ones).

So, what do you think about changing the Groovy build recipe to shade in those 
libraries and thus match what upstream build process does? And if you approve 
the shading, do I need to make Groovy package output still reference store 
paths of the libraries that are shaded? As otherwise, the only way to find out 
about the dependencies (for example, to check for usages of vulnerable 
packages) is to inspect the package recipe or Groovy build derivation.

[0]: 
https://github.com/TarCV/gradle-guix/blob/develop/patches/gradle-4.5.1-unshaded-groovy.patch
Small vocabulary for those not working with Java ecosystem:
Classpath - list of locations where Java looks for symbol implementations. In 
this message I mean runtime classpath - a list that is used during application 
exectution.
Shading - it's a process somewhat similar to compiling libraries statically 
into an application or another library. During shading bytecode from a 
dependency is copied to an application (or library) with patched symbol names, 
i.e. org.ow2.asm.Opcodes becomes something like my.app.asm.Opcodes).
Regards,
Constantin

Reply via email to