ikxeno commented on PR #13276:
URL: https://github.com/apache/maven/pull/13276#issuecomment-5869748746

   @gnodet 
   
   Two things I'd like you to decide.
   
   Should `validate()` read `RequestType`? `BUILD_PROJECT` raw as now,
   `BUILD_EFFECTIVE` running `validateEffectiveModel` and collecting the 
problems
   rather than throwing. Then `--depth` is just the request, and there is never 
a
   second method. I didn't do it on my own because nothing in the enum means 
"stop at
   the raw model" today, and both branches of `build()` run to the end.
   
   And can `--depth` default to `raw`? With `effective` as the default the 
offline
   cases die: no repository, and no `settings.xml` either, so no mirrors or 
proxies.
   There is also this. Once anything resolves, the `<repositories>` of the POM 
being
   validated are part of where it resolves from, `DefaultModelBuilder` near 699 
and
   731. A gate in front of Central would be letting untrusted input pick the 
URLs it
   fetches. As an opt-in flag I'll add it today.
   
   The rest is in, adf8539 and 6f09770. Renamed, cache clear gone, one session 
for
   the run.
   
   Two things I got wrong. Sharing a session doesn't trip `No unique Source` 
when two
   roots share coordinates; I claimed it did in the description, and there is a 
test
   now. And the parent still isn't read once:
   
   ```
   $ mvnval -X a/pom.xml b/pom.xml c/pom.xml | grep 'Reading file model' | sort 
| uniq -c
      3 a/pom.xml   3 b/pom.xml   3 c/pom.xml   3 pom.xml
   ```
   
   Same numbers with a session per POM, because every `validate()` walks the 
reactor
   from the root again. If you want the batch case cheaper, that's the walk, 
not the
   session.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to