ikxeno commented on PR #13276:
URL: https://github.com/apache/maven/pull/13276#issuecomment-5869748746
@gnodet
Two things I'd like you to decide.
Should `validate()` read `RequestType`? `BUILD_PROJECT` raw as now,
`BUILD_EFFECTIVE` running `validateEffectiveModel` and collecting the
problems
rather than throwing. Then `--depth` is just the request, and there is never
a
second method. I didn't do it on my own because nothing in the enum means
"stop at
the raw model" today, and both branches of `build()` run to the end.
And can `--depth` default to `raw`? With `effective` as the default the
offline
cases die: no repository, and no `settings.xml` either, so no mirrors or
proxies.
There is also this. Once anything resolves, the `<repositories>` of the POM
being
validated are part of where it resolves from, `DefaultModelBuilder` near 699
and
731. A gate in front of Central would be letting untrusted input pick the
URLs it
fetches. As an opt-in flag I'll add it today.
The rest is in, adf8539 and 6f09770. Renamed, cache clear gone, one session
for
the run.
Two things I got wrong. Sharing a session doesn't trip `No unique Source`
when two
roots share coordinates; I claimed it did in the description, and there is a
test
now. And the parent still isn't read once:
```
$ mvnval -X a/pom.xml b/pom.xml c/pom.xml | grep 'Reading file model' | sort
| uniq -c
3 a/pom.xml 3 b/pom.xml 3 c/pom.xml 3 pom.xml
```
Same numbers with a session per POM, because every `validate()` walks the
reactor
from the root again. If you want the batch case cheaper, that's the walk,
not the
session.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]