gnodet commented on issue #144:
URL: 
https://github.com/apache/maven-jar-plugin/issues/144#issuecomment-5837727540

   Thanks for the detailed report. After investigating the code paths in both 
`maven-jar-plugin` and `maven-shade-plugin`, I'm confident this is not a bug in 
the jar plugin itself.
   
   ## Why maven-jar-plugin is not at fault
   
   In `3.4.2` (which uses Plexus `JarArchiver`), the mojo is declared 
`@threadSafe = true` and each module execution gets its own `JarArchiver` 
instance with completely isolated state. The two "Building jar:" lines you see 
at the same timestamp are **two different modules** writing to their own 
`target/` directories — that's normal and correct `-T` behaviour, with no 
shared files or state between them.
   
   The jar plugin correctly produced the ~10 KB JAR containing your project's 
own classes. That part worked fine.
   
   ## The actual bug: shade plugin resolves zero dependencies
   
   Looking at your failing log closely, the shade plugin ran but produced no 
`"Including X in the shaded jar."` lines for any dependency — meaning it saw 
**zero resolved artifacts** to include, despite your project having runtime 
dependencies. The `"No artifact matching filter..."` lines are from your 
`<filters>/<excludes>` configuration and are just informational noise.
   
   This is a known class of concurrency bugs in `maven-shade-plugin`:
   - **MSHADE-329** (still open): concurrent writes of 
`dependency-reduced-pom.xml` produce an infinite loop
   - **MSHADE-384** (still open): build hangs with `-T` on JDK 11
   - **MSHADE-467** (fixed 2024): concurrency problem with dependency-reduced 
POM
   
   The empty-dependencies symptom you're seeing is a distinct variant — likely 
`project.getArtifacts()` returning an empty/incomplete set when two module 
builds overlap (see also Maven core issue **MNG-6843**). I've filed 
https://github.com/apache/maven-shade-plugin/issues/861 to track this 
specifically.
   
   ## Workaround
   
   Until the shade plugin issue is fixed:
   - Run without `-T` (single-threaded), **or**
   - Add `<forceCreation>true</forceCreation>` to your jar plugin config:
   
   ```xml
   <plugin>
     <groupId>org.apache.maven.plugins</groupId>
     <artifactId>maven-jar-plugin</artifactId>
     <configuration>
       <forceCreation>true</forceCreation>
     </configuration>
   </plugin>
   ```
   
   This ensures the jar plugin always rebuilds the unshaded JAR even if it 
considers it up-to-date, eliminating any incremental-build confusion — though 
it doesn't fix the underlying shade artifact-resolution race.
   
   Closing this issue as "not a jar plugin bug". Please follow 
https://github.com/apache/maven-shade-plugin/issues/861 for the actual fix.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to