gnodet opened a new issue, #861:
URL: https://github.com/apache/maven-shade-plugin/issues/861

   ## Description
   
   When running a multi-module build with `-T` (parallel builds), the `shade` 
goal intermittently produces a shaded JAR that contains **only the project's 
own classes** (typically a few KB), with no dependency JARs included, even 
though the project has runtime dependencies declared.
   
   ## Reproduction
   
   Observed with:
   - `maven-shade-plugin:3.6.0` (likely affects all versions)
   - `mvn -T 3 package` (or any `-T N` > 1)
   - Multi-module project where multiple modules use the `shade` goal
   
   ## Symptom
   
   In the failing build, the shade mojo runs but produces no `"Including X in 
the shaded jar."` log lines for any dependency — meaning it resolved zero 
artifacts to include. The resulting JAR is only the size of the project's own 
class files.
   
   Example log from a successful build:
   ```
   [INFO] --- maven-shade-plugin:3.6.0:shade (default) @ module-A ---
   [INFO] Including com.example:dep:jar:1.0 in the shaded jar.
   ...
   ```
   
   Example log from a failing (parallel) build, where `module-B` is packaging 
simultaneously:
   ```
   [INFO] --- maven-shade-plugin:3.6.0:shade (default) @ module-A ---
   [INFO] No artifact matching filter com.example:some-exclude   <- 
exclude-filter noise (normal)
   [INFO] Replacing original artifact with shaded artifact.
   [INFO] Replacing .../module-A.jar with .../module-A-shaded.jar
   ```
   No `"Including..."` lines — shade included zero dependencies.
   
   ## Root Cause Hypothesis
   
   The shade mojo is declared `@threadSafe = true`, but there are known 
concurrency issues (MSHADE-329, MSHADE-384, MSHADE-467). The specific symptom 
here — zero artifacts resolved — suggests that either:
   
   1. `project.getArtifacts()` returns an empty set due to a race in Maven's 
`MavenProject` (see MNG-6843, fixed in Maven 3.8+), **or**
   2. Some internal state in `ShadeMojo` or its `DefaultShader` is 
reset/corrupted when two executions overlap in the same JVM.
   
   ## Related Issues
   
   - MSHADE-329: Concurrent writes of dependency-reduced-pom.xml (infinite 
loop) — still open
   - MSHADE-384: Build hang with `-T` on JDK 11 — still open
   - MSHADE-467: Concurrency problem with dependency-reduced POM — fixed in 2024
   - MNG-6843: Thread-safe artifacts in MavenProject (Maven core fix)
   
   ## Workaround
   
   Run without `-T` (single-threaded). Alternatively, add 
`<forceCreation>true</forceCreation>` to maven-jar-plugin config to ensure a 
fresh unshaded JAR is always produced before shade runs — this eliminates 
incremental-build confusion though it does not fix the shade 
artifact-resolution race itself.
   
   ## Notes
   
   Originally reported as a maven-jar-plugin issue 
(apache/maven-jar-plugin#144), but the jar plugin is not at fault — it 
correctly packages the project classes. The race is in how the shade mojo 
resolves/uses project artifacts during parallel execution.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to