Tarun4201 commented on code in PR #13277: URL: https://github.com/apache/maven/pull/13277#discussion_r4123602154
########## impl/maven-cli/src/main/java/org/apache/maven/cling/MavenClappCling.java: ########## @@ -0,0 +1,302 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ +package org.apache.maven.cling; + +import java.io.IOException; +import java.io.InputStream; +import java.io.OutputStream; +import java.lang.reflect.InvocationTargetException; +import java.lang.reflect.Method; +import java.net.MalformedURLException; +import java.net.URL; +import java.net.URLClassLoader; +import java.nio.file.DirectoryStream; +import java.nio.file.Files; +import java.nio.file.Path; +import java.nio.file.Paths; +import java.util.ArrayList; +import java.util.List; + +import org.apache.maven.api.annotations.Nullable; +import org.apache.maven.api.cli.Invoker; +import org.apache.maven.api.cli.Parser; +import org.apache.maven.api.cli.ParserRequest; +import org.apache.maven.cling.invoker.ProtoLookup; +import org.apache.maven.cling.invoker.mvn.MavenInvoker; +import org.apache.maven.cling.invoker.mvn.MavenParser; +import org.apache.maven.api.services.MavenException; +import org.codehaus.plexus.classworlds.ClassWorld; + +/** + * Maven CLAPP (Command Line App) entry point. + * <p> + * This class acts as the launcher for external Maven CLI tools ("CLAPPs") that ship their + * own dependencies in {@code ${maven.home}/lib/clapp/<toolName>/} instead of requiring + * those jars to be in the shared {@code ${maven.home}/lib/} directory. + * <p> + * The {@code maven.clapp.name} system property identifies which CLAPP to launch. + * The CLAPP's jar directory is {@code ${maven.home}/lib/clapp/<toolName>/}. + * That directory is scanned for {@code *.jar} files which are added to a child + * {@link URLClassLoader} that delegates to the core Maven class-loader. + * The CLAPP's main entry point class is then looked up via the + * {@code maven.clapp.mainClass} system property and invoked. + * <p> + * This mechanism allows future {@code mvnXxx} tools to package tool-specific + * dependencies in isolation without bloating the core Maven classpath. + * + * @since 4.1.0 + */ +public class MavenClappCling extends ClingSupport { + + /** + * System property that specifies the CLAPP tool name (e.g., {@code "mvnenc"}). + * Used to locate {@code ${maven.home}/lib/clapp/<toolName>/}. + */ + public static final String MAVEN_CLAPP_NAME_PROPERTY = "maven.clapp.name"; + + /** + * System property that specifies the fully-qualified main class name of the CLAPP tool. + * That class must expose a {@code public static int main(String[], ClassWorld)} method. + */ + public static final String MAVEN_CLAPP_MAIN_CLASS_PROPERTY = "maven.clapp.mainClass"; + + /** + * Exception thrown when a CLAPP tool cannot be loaded, configured, or launched. + * + * @since 4.1.0 + */ + public static class ClappException extends MavenException { + public ClappException(String message) { + super(message); + } + + public ClappException(String message, Throwable cause) { + super(message, cause); + } + } + + /** + * Relative path under {@code ${maven.home}} where per-CLAPP jar directories live. + */ + static final String CLAPP_LIB_RELATIVE_PATH = "lib/clapp"; + + /** + * "Normal" Java entry point. Note: Maven uses ClassWorld Launcher and this entry point is NOT + * used under normal circumstances. + */ + public static void main(String[] args) throws IOException { + int exitCode = new MavenClappCling().run(args, null, null, null, false); + System.exit(exitCode); + } + + /** + * ClassWorld Launcher "enhanced" entry point: returning exitCode and accepts ClassWorld. + * <p> + * When {@code maven.clapp.name} and {@code maven.clapp.mainClass} system properties are set, + * this method builds a per-CLAPP child classloader and delegates to the CLAPP's main class. + * Otherwise, it falls back to the standard {@link MavenCling} behaviour. + */ + public static int main(String[] args, ClassWorld world) throws IOException { + String clappName = System.getProperty(MAVEN_CLAPP_NAME_PROPERTY); + String clappMainClass = System.getProperty(MAVEN_CLAPP_MAIN_CLASS_PROPERTY); + + if (clappName != null && !clappName.isBlank() && clappMainClass != null && !clappMainClass.isBlank()) { + return launchClapp(clappName.trim(), clappMainClass.trim(), args, world); + } + + // Fallback: behave as MavenCling when no CLAPP is configured + return MavenCling.main(args, world); + } + + /** + * ClassWorld Launcher "embedded" entry point: returning exitCode and accepts ClassWorld and streams. + */ + public static int main( + String[] args, + ClassWorld world, + @Nullable InputStream stdIn, + @Nullable OutputStream stdOut, + @Nullable OutputStream stdErr) + throws IOException { + return new MavenClappCling(world).run(args, stdIn, stdOut, stdErr, true); + } + + public MavenClappCling() { + super(); + } + + public MavenClappCling(ClassWorld classWorld) { + super(classWorld); + } + + // ------------------------------------------------------------------------- + // ClingSupport contract – used when invoked as a fallback Maven build + // ------------------------------------------------------------------------- + + @Override + protected Invoker createInvoker() { + return new MavenInvoker( + ProtoLookup.builder().addMapping(ClassWorld.class, classWorld).build(), null); + } + + @Override + protected Parser createParser() { + return new MavenParser(); + } + + @Override + protected ParserRequest.Builder createParserRequestBuilder(String[] args) { + return ParserRequest.mvn(args, createMessageBuilderFactory()); + } + + // ------------------------------------------------------------------------- + // CLAPP launch logic + // ------------------------------------------------------------------------- + + /** + * Constructs a per-CLAPP child class-loader, loads the CLAPP main class from it, + * and invokes its {@code main(String[], ClassWorld)} method. + * + * @param clappName the CLAPP tool name (e.g., {@code "mvnenc"}) + * @param clappMainClass fully-qualified name of the CLAPP entry-point class + * @param args command-line arguments + * @param world the ClassWorld shared with the Maven core + * @return the exit code returned by the CLAPP + * @throws IOException if the CLAPP lib directory exists but cannot be read + * @throws ClappException if the CLAPP cannot be loaded or invocation fails + * @throws IllegalArgumentException if the CLAPP tool name is invalid or attempts path traversal + */ + static int launchClapp(String clappName, String clappMainClass, String[] args, ClassWorld world) + throws IOException, ClappException { + String mavenHome = System.getProperty("maven.home"); + if (mavenHome == null || mavenHome.isBlank()) { + throw new ClappException( + "System property 'maven.home' is not set; cannot locate CLAPP lib directory for: " + clappName); + } + + // Validate tool name to prevent path traversal + if (!clappName.matches("^[a-zA-Z0-9_-]+$")) { + throw new IllegalArgumentException("Invalid CLAPP tool name: '" + clappName + "'"); + } + + Path baseDir = Paths.get(mavenHome).resolve(CLAPP_LIB_RELATIVE_PATH).normalize(); + Path clappLibDir = baseDir.resolve(clappName).normalize(); + if (!clappLibDir.startsWith(baseDir)) { + throw new IllegalArgumentException("Invalid CLAPP lib directory path traversal attempt for: " + clappName); + } + + // Build the list of jar URLs from the CLAPP-specific lib directory + List<URL> jarUrls = collectJarUrls(clappLibDir, clappName); + + // Create a child class-loader that sees the core classes + the CLAPP's own jars + ClassLoader parentLoader = Thread.currentThread().getContextClassLoader(); + try (URLClassLoader clappLoader = new URLClassLoader(jarUrls.toArray(new URL[0]), parentLoader)) { + Class<?> clazz = clappLoader.loadClass(clappMainClass); Review Comment: Fixed in commit ca84dc3d: Replaced URLClassLoader with child-first ClappClassLoader that loads classes from the tool private jars first, while delegating core Java (java.*, javax.*, etc.) and Maven API (org.apache.maven.api.*, org.codehaus.plexus.classworlds.*) parent-first to preserve type compatibility with the runtime. ########## impl/maven-cli/src/test/java/org/apache/maven/cling/MavenClappClingTest.java: ########## @@ -0,0 +1,200 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ +package org.apache.maven.cling; + +import java.io.IOException; +import java.net.URL; +import java.nio.file.Files; +import java.nio.file.Path; +import java.util.List; + +import org.junit.jupiter.api.Test; +import org.junit.jupiter.api.io.TempDir; + +import static org.junit.jupiter.api.Assertions.assertEquals; +import static org.junit.jupiter.api.Assertions.assertThrows; +import static org.junit.jupiter.api.Assertions.assertTrue; + +/** + * Unit tests for {@link MavenClappCling}. + */ +class MavenClappClingTest { + + @TempDir + Path tempDir; + + // ------------------------------------------------------------------------- + // collectJarUrls + // ------------------------------------------------------------------------- + + @Test + void collectJarUrlsReturnsEmptyListWhenDirectoryDoesNotExist() throws IOException { + Path nonExistent = tempDir.resolve("does-not-exist"); + List<URL> urls = MavenClappCling.collectJarUrls(nonExistent, "mytool"); + assertTrue(urls.isEmpty(), "Expected empty list for non-existent CLAPP lib directory"); + } + + @Test + void collectJarUrlsReturnsJarsWhenDirectoryContainsJars() throws IOException { + Path clappDir = Files.createDirectory(tempDir.resolve("mytool")); + Files.createFile(clappDir.resolve("a.jar")); + Files.createFile(clappDir.resolve("b.jar")); + // non-jar file – must be ignored + Files.createFile(clappDir.resolve("readme.txt")); + + List<URL> urls = MavenClappCling.collectJarUrls(clappDir, "mytool"); + assertEquals(2, urls.size(), "Expected exactly 2 jar URLs"); + assertTrue(urls.stream().allMatch(u -> u.toString().endsWith(".jar")), "All URLs should end with .jar"); + } + + @Test + void collectJarUrlsReturnsEmptyListWhenDirectoryIsEmpty() throws IOException { + Path clappDir = Files.createDirectory(tempDir.resolve("empty-tool")); + List<URL> urls = MavenClappCling.collectJarUrls(clappDir, "empty-tool"); + assertTrue(urls.isEmpty(), "Expected empty list for empty CLAPP lib directory"); + } + + @Test + void collectJarUrlsThrowsIOExceptionWhenPathIsNotDirectory() throws IOException { + Path file = Files.createFile(tempDir.resolve("not-a-dir")); + assertThrows( + IOException.class, + () -> MavenClappCling.collectJarUrls(file, "badtool"), + "Expected IOException when clapp lib path is a file, not a directory"); + } + + // ------------------------------------------------------------------------- + // launchClapp – error paths (without actually launching a JVM/ClassWorld) + // ------------------------------------------------------------------------- + + @Test + void launchClappThrowsClappExceptionWhenMavenHomeNotSet() { + String saved = System.getProperty("maven.home"); + try { + System.clearProperty("maven.home"); + assertThrows( + MavenClappCling.ClappException.class, + () -> MavenClappCling.launchClapp("mytool", "com.example.Main", new String[0], null), + "Expected ClappException when maven.home is not set"); + } finally { + if (saved != null) { + System.setProperty("maven.home", saved); + } + } + } + + @Test + void launchClappThrowsClappExceptionWhenMainClassNotFound() { + System.setProperty("maven.home", tempDir.toString()); + try { + // No jars in lib/clapp/mytool/, main class definitely not on classpath + assertThrows( + MavenClappCling.ClappException.class, + () -> MavenClappCling.launchClapp( + "mytool", "com.example.NonExistentMain", new String[0], null), + "Expected ClappException when CLAPP main class cannot be found"); + } finally { + System.clearProperty("maven.home"); + } + } + + @Test + void launchClappThrowsIllegalArgumentExceptionWhenToolNameInvalid() { + System.setProperty("maven.home", tempDir.toString()); + try { + assertThrows( + IllegalArgumentException.class, + () -> MavenClappCling.launchClapp( + "../badtool", "com.example.Main", new String[0], null), + "Expected IllegalArgumentException when CLAPP tool name contains invalid path characters"); + } finally { + System.clearProperty("maven.home"); + } + } + + @Test + void launchClappInvokesRunMethodSuccessfully() throws Exception { + System.setProperty("maven.home", tempDir.toString()); + try { + int exitCode = MavenClappCling.launchClapp( + "mytool", SampleRunTool.class.getName(), new String[] {"test"}, null); Review Comment: Fixed in commit ca84dc3d: Added `launchClappLoadsFromJarInClappDirectory()` which dynamically compiles a standalone tool class at test time, packages it into a fixture JAR placed in `lib/clapp/standalone/`, and verifies execution through `MavenClappCling.launchClapp()`. This ensures entry points and classes are loaded from child-loader jars. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
