slachiewicz opened a new issue, #2156:
URL: https://github.com/apache/maven-resolver/issues/2156

   ### Affected version
   
   2.0.23 (also master at a90b7f7f)
   
   ### Bug description
   
   `DefaultArtifactResolver` evaluates the remote repository filter for every 
repository in the request, before the policy check and the local availability 
check 
([DefaultArtifactResolver.java#L274-L287](https://github.com/apache/maven-resolver/blob/master/maven-resolver-impl/src/main/java/org/eclipse/aether/internal/impl/DefaultArtifactResolver.java#L274-L287)).
 The prefixes filter is on by default, so its first evaluation per repository 
downloads `.meta/prefixes.txt`. As a result, every repository in the list is 
contacted once per session, including repositories that would never be asked 
for the artifact.
   
   This shows up in two common cases:
   
   - **Snapshot-only repositories for release artifacts.** 
`sonatype-nexus-snapshots` and `plexus.snapshots` are probed, although the 
policy check a few lines later skips them.
   - **Repositories declared in dependency POMs.** The collector merges these 
into the children's requests (`BfDependencyCollector` → 
`aggregateRepositories(…, true, true)`). A dead one is contacted on every 
build. Transfer errors are not cached, so this happens even when every artifact 
is already local.
   
   Reproducer: a minimal jar project, running `mvn 
org.apache.maven.plugins:maven-checkstyle-plugin:3.6.0:check` on Maven 
4.0.0-rc-7 (resolver 2.0.23) against an empty local repository. The plugin's 
graph pulls in `javax.xml.bind:jaxb-api:2.3.1`, whose parent 
`net.java:jvnet-parent` declares `jvnet-nexus-releases` 
(`https://maven.java.net/content/repositories/releases/`, expired certificate). 
Both a cold and a warm run log the following, and the warm run downloads 
nothing:
   
   ```
   [WARNING] Could not transfer metadata /.meta/prefixes.txt from/to 
jvnet-nexus-releases (https://maven.java.net/content/repositories/releases/): 
(certificate_expired) PKIX path validation failed
   ```
   
   Maven 3.9.16 (resolver 1.9, filter off by default) never contacts that host, 
because central answers first. On resolver 2, any hostname named in any POM in 
the graph is contacted on every build, including a repository domain that has 
since lapsed. A host that accepts connections and never answers costs up to the 
connect or request timeout.
   
   User-facing report: apache/maven#13050.
   
   Proposed:
   
   1. Skip filter evaluation for repositories whose policy is disabled for the 
request's nature, in `DefaultArtifactResolver` and `DefaultMetadataResolver`. 
They are skipped a few lines later anyway; same principle as MNG-4771/MNG-4772.
   2. Skip prefixes auto-discovery for repositories that 
`aggregateRepositories` received with `recessiveIsFromDescriptor=true`, behind 
`aether.remoteRepositoryFilter.prefixes.useDescriptorRepositories` (default 
`false`), the same shape as `useMirroredRepositories`. This needs the 
provenance from #2090 to be visible to the filter, for example through session 
data.
   
   User-provided prefix files keep applying to both. Neither change alters 
which repositories serve artifacts; both only remove probes.
   
   Workaround: `-Daether.remoteRepositoryFilter.prefixes.<repoId>=false`.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to