Tarun4201 commented on code in PR #13277:
URL: https://github.com/apache/maven/pull/13277#discussion_r4123602154


##########
impl/maven-cli/src/main/java/org/apache/maven/cling/MavenClappCling.java:
##########
@@ -0,0 +1,302 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements.  See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership.  The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License.  You may obtain a copy of the License at
+ *
+ *   http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing,
+ * software distributed under the License is distributed on an
+ * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ * KIND, either express or implied.  See the License for the
+ * specific language governing permissions and limitations
+ * under the License.
+ */
+package org.apache.maven.cling;
+
+import java.io.IOException;
+import java.io.InputStream;
+import java.io.OutputStream;
+import java.lang.reflect.InvocationTargetException;
+import java.lang.reflect.Method;
+import java.net.MalformedURLException;
+import java.net.URL;
+import java.net.URLClassLoader;
+import java.nio.file.DirectoryStream;
+import java.nio.file.Files;
+import java.nio.file.Path;
+import java.nio.file.Paths;
+import java.util.ArrayList;
+import java.util.List;
+
+import org.apache.maven.api.annotations.Nullable;
+import org.apache.maven.api.cli.Invoker;
+import org.apache.maven.api.cli.Parser;
+import org.apache.maven.api.cli.ParserRequest;
+import org.apache.maven.cling.invoker.ProtoLookup;
+import org.apache.maven.cling.invoker.mvn.MavenInvoker;
+import org.apache.maven.cling.invoker.mvn.MavenParser;
+import org.apache.maven.api.services.MavenException;
+import org.codehaus.plexus.classworlds.ClassWorld;
+
+/**
+ * Maven CLAPP (Command Line App) entry point.
+ * <p>
+ * This class acts as the launcher for external Maven CLI tools ("CLAPPs") 
that ship their
+ * own dependencies in {@code ${maven.home}/lib/clapp/<toolName>/} instead of 
requiring
+ * those jars to be in the shared {@code ${maven.home}/lib/} directory.
+ * <p>
+ * The {@code maven.clapp.name} system property identifies which CLAPP to 
launch.
+ * The CLAPP's jar directory is {@code ${maven.home}/lib/clapp/<toolName>/}.
+ * That directory is scanned for {@code *.jar} files which are added to a child
+ * {@link URLClassLoader} that delegates to the core Maven class-loader.
+ * The CLAPP's main entry point class is then looked up via the
+ * {@code maven.clapp.mainClass} system property and invoked.
+ * <p>
+ * This mechanism allows future {@code mvnXxx} tools to package tool-specific
+ * dependencies in isolation without bloating the core Maven classpath.
+ *
+ * @since 4.1.0
+ */
+public class MavenClappCling extends ClingSupport {
+
+    /**
+     * System property that specifies the CLAPP tool name (e.g., {@code 
"mvnenc"}).
+     * Used to locate {@code ${maven.home}/lib/clapp/<toolName>/}.
+     */
+    public static final String MAVEN_CLAPP_NAME_PROPERTY = "maven.clapp.name";
+
+    /**
+     * System property that specifies the fully-qualified main class name of 
the CLAPP tool.
+     * That class must expose a {@code public static int main(String[], 
ClassWorld)} method.
+     */
+    public static final String MAVEN_CLAPP_MAIN_CLASS_PROPERTY = 
"maven.clapp.mainClass";
+
+    /**
+     * Exception thrown when a CLAPP tool cannot be loaded, configured, or 
launched.
+     *
+     * @since 4.1.0
+     */
+    public static class ClappException extends MavenException {
+        public ClappException(String message) {
+            super(message);
+        }
+
+        public ClappException(String message, Throwable cause) {
+            super(message, cause);
+        }
+    }
+
+    /**
+     * Relative path under {@code ${maven.home}} where per-CLAPP jar 
directories live.
+     */
+    static final String CLAPP_LIB_RELATIVE_PATH = "lib/clapp";
+
+    /**
+     * "Normal" Java entry point. Note: Maven uses ClassWorld Launcher and 
this entry point is NOT
+     * used under normal circumstances.
+     */
+    public static void main(String[] args) throws IOException {
+        int exitCode = new MavenClappCling().run(args, null, null, null, 
false);
+        System.exit(exitCode);
+    }
+
+    /**
+     * ClassWorld Launcher "enhanced" entry point: returning exitCode and 
accepts ClassWorld.
+     * <p>
+     * When {@code maven.clapp.name} and {@code maven.clapp.mainClass} system 
properties are set,
+     * this method builds a per-CLAPP child classloader and delegates to the 
CLAPP's main class.
+     * Otherwise, it falls back to the standard {@link MavenCling} behaviour.
+     */
+    public static int main(String[] args, ClassWorld world) throws IOException 
{
+        String clappName = System.getProperty(MAVEN_CLAPP_NAME_PROPERTY);
+        String clappMainClass = 
System.getProperty(MAVEN_CLAPP_MAIN_CLASS_PROPERTY);
+
+        if (clappName != null && !clappName.isBlank() && clappMainClass != 
null && !clappMainClass.isBlank()) {
+            return launchClapp(clappName.trim(), clappMainClass.trim(), args, 
world);
+        }
+
+        // Fallback: behave as MavenCling when no CLAPP is configured
+        return MavenCling.main(args, world);
+    }
+
+    /**
+     * ClassWorld Launcher "embedded" entry point: returning exitCode and 
accepts ClassWorld and streams.
+     */
+    public static int main(
+            String[] args,
+            ClassWorld world,
+            @Nullable InputStream stdIn,
+            @Nullable OutputStream stdOut,
+            @Nullable OutputStream stdErr)
+            throws IOException {
+        return new MavenClappCling(world).run(args, stdIn, stdOut, stdErr, 
true);
+    }
+
+    public MavenClappCling() {
+        super();
+    }
+
+    public MavenClappCling(ClassWorld classWorld) {
+        super(classWorld);
+    }
+
+    // 
-------------------------------------------------------------------------
+    // ClingSupport contract – used when invoked as a fallback Maven build
+    // 
-------------------------------------------------------------------------
+
+    @Override
+    protected Invoker createInvoker() {
+        return new MavenInvoker(
+                ProtoLookup.builder().addMapping(ClassWorld.class, 
classWorld).build(), null);
+    }
+
+    @Override
+    protected Parser createParser() {
+        return new MavenParser();
+    }
+
+    @Override
+    protected ParserRequest.Builder createParserRequestBuilder(String[] args) {
+        return ParserRequest.mvn(args, createMessageBuilderFactory());
+    }
+
+    // 
-------------------------------------------------------------------------
+    // CLAPP launch logic
+    // 
-------------------------------------------------------------------------
+
+    /**
+     * Constructs a per-CLAPP child class-loader, loads the CLAPP main class 
from it,
+     * and invokes its {@code main(String[], ClassWorld)} method.
+     *
+     * @param clappName      the CLAPP tool name (e.g., {@code "mvnenc"})
+     * @param clappMainClass fully-qualified name of the CLAPP entry-point 
class
+     * @param args           command-line arguments
+     * @param world          the ClassWorld shared with the Maven core
+     * @return the exit code returned by the CLAPP
+     * @throws IOException              if the CLAPP lib directory exists but 
cannot be read
+     * @throws ClappException          if the CLAPP cannot be loaded or 
invocation fails
+     * @throws IllegalArgumentException if the CLAPP tool name is invalid or 
attempts path traversal
+     */
+    static int launchClapp(String clappName, String clappMainClass, String[] 
args, ClassWorld world)
+            throws IOException, ClappException {
+        String mavenHome = System.getProperty("maven.home");
+        if (mavenHome == null || mavenHome.isBlank()) {
+            throw new ClappException(
+                    "System property 'maven.home' is not set; cannot locate 
CLAPP lib directory for: " + clappName);
+        }
+
+        // Validate tool name to prevent path traversal
+        if (!clappName.matches("^[a-zA-Z0-9_-]+$")) {
+            throw new IllegalArgumentException("Invalid CLAPP tool name: '" + 
clappName + "'");
+        }
+
+        Path baseDir = 
Paths.get(mavenHome).resolve(CLAPP_LIB_RELATIVE_PATH).normalize();
+        Path clappLibDir = baseDir.resolve(clappName).normalize();
+        if (!clappLibDir.startsWith(baseDir)) {
+            throw new IllegalArgumentException("Invalid CLAPP lib directory 
path traversal attempt for: " + clappName);
+        }
+
+        // Build the list of jar URLs from the CLAPP-specific lib directory
+        List<URL> jarUrls = collectJarUrls(clappLibDir, clappName);
+
+        // Create a child class-loader that sees the core classes + the 
CLAPP's own jars
+        ClassLoader parentLoader = 
Thread.currentThread().getContextClassLoader();
+        try (URLClassLoader clappLoader = new 
URLClassLoader(jarUrls.toArray(new URL[0]), parentLoader)) {
+            Class<?> clazz = clappLoader.loadClass(clappMainClass);

Review Comment:
   Fixed in commit ca84dc3d: Replaced URLClassLoader with child-first 
ClappClassLoader that loads classes from the tool private jars first, while 
delegating core Java (java.*, javax.*, etc.) and Maven API 
(org.apache.maven.api.*, org.codehaus.plexus.classworlds.*) parent-first to 
preserve type compatibility with the runtime.



##########
impl/maven-cli/src/test/java/org/apache/maven/cling/MavenClappClingTest.java:
##########
@@ -0,0 +1,200 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one
+ * or more contributor license agreements.  See the NOTICE file
+ * distributed with this work for additional information
+ * regarding copyright ownership.  The ASF licenses this file
+ * to you under the Apache License, Version 2.0 (the
+ * "License"); you may not use this file except in compliance
+ * with the License.  You may obtain a copy of the License at
+ *
+ *   http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing,
+ * software distributed under the License is distributed on an
+ * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+ * KIND, either express or implied.  See the License for the
+ * specific language governing permissions and limitations
+ * under the License.
+ */
+package org.apache.maven.cling;
+
+import java.io.IOException;
+import java.net.URL;
+import java.nio.file.Files;
+import java.nio.file.Path;
+import java.util.List;
+
+import org.junit.jupiter.api.Test;
+import org.junit.jupiter.api.io.TempDir;
+
+import static org.junit.jupiter.api.Assertions.assertEquals;
+import static org.junit.jupiter.api.Assertions.assertThrows;
+import static org.junit.jupiter.api.Assertions.assertTrue;
+
+/**
+ * Unit tests for {@link MavenClappCling}.
+ */
+class MavenClappClingTest {
+
+    @TempDir
+    Path tempDir;
+
+    // 
-------------------------------------------------------------------------
+    // collectJarUrls
+    // 
-------------------------------------------------------------------------
+
+    @Test
+    void collectJarUrlsReturnsEmptyListWhenDirectoryDoesNotExist() throws 
IOException {
+        Path nonExistent = tempDir.resolve("does-not-exist");
+        List<URL> urls = MavenClappCling.collectJarUrls(nonExistent, "mytool");
+        assertTrue(urls.isEmpty(), "Expected empty list for non-existent CLAPP 
lib directory");
+    }
+
+    @Test
+    void collectJarUrlsReturnsJarsWhenDirectoryContainsJars() throws 
IOException {
+        Path clappDir = Files.createDirectory(tempDir.resolve("mytool"));
+        Files.createFile(clappDir.resolve("a.jar"));
+        Files.createFile(clappDir.resolve("b.jar"));
+        // non-jar file – must be ignored
+        Files.createFile(clappDir.resolve("readme.txt"));
+
+        List<URL> urls = MavenClappCling.collectJarUrls(clappDir, "mytool");
+        assertEquals(2, urls.size(), "Expected exactly 2 jar URLs");
+        assertTrue(urls.stream().allMatch(u -> u.toString().endsWith(".jar")), 
"All URLs should end with .jar");
+    }
+
+    @Test
+    void collectJarUrlsReturnsEmptyListWhenDirectoryIsEmpty() throws 
IOException {
+        Path clappDir = Files.createDirectory(tempDir.resolve("empty-tool"));
+        List<URL> urls = MavenClappCling.collectJarUrls(clappDir, 
"empty-tool");
+        assertTrue(urls.isEmpty(), "Expected empty list for empty CLAPP lib 
directory");
+    }
+
+    @Test
+    void collectJarUrlsThrowsIOExceptionWhenPathIsNotDirectory() throws 
IOException {
+        Path file = Files.createFile(tempDir.resolve("not-a-dir"));
+        assertThrows(
+                IOException.class,
+                () -> MavenClappCling.collectJarUrls(file, "badtool"),
+                "Expected IOException when clapp lib path is a file, not a 
directory");
+    }
+
+    // 
-------------------------------------------------------------------------
+    // launchClapp – error paths (without actually launching a JVM/ClassWorld)
+    // 
-------------------------------------------------------------------------
+
+    @Test
+    void launchClappThrowsClappExceptionWhenMavenHomeNotSet() {
+        String saved = System.getProperty("maven.home");
+        try {
+            System.clearProperty("maven.home");
+            assertThrows(
+                    MavenClappCling.ClappException.class,
+                    () -> MavenClappCling.launchClapp("mytool", 
"com.example.Main", new String[0], null),
+                    "Expected ClappException when maven.home is not set");
+        } finally {
+            if (saved != null) {
+                System.setProperty("maven.home", saved);
+            }
+        }
+    }
+
+    @Test
+    void launchClappThrowsClappExceptionWhenMainClassNotFound() {
+        System.setProperty("maven.home", tempDir.toString());
+        try {
+            // No jars in lib/clapp/mytool/, main class definitely not on 
classpath
+            assertThrows(
+                    MavenClappCling.ClappException.class,
+                    () -> MavenClappCling.launchClapp(
+                            "mytool", "com.example.NonExistentMain", new 
String[0], null),
+                    "Expected ClappException when CLAPP main class cannot be 
found");
+        } finally {
+            System.clearProperty("maven.home");
+        }
+    }
+
+    @Test
+    void launchClappThrowsIllegalArgumentExceptionWhenToolNameInvalid() {
+        System.setProperty("maven.home", tempDir.toString());
+        try {
+            assertThrows(
+                    IllegalArgumentException.class,
+                    () -> MavenClappCling.launchClapp(
+                            "../badtool", "com.example.Main", new String[0], 
null),
+                    "Expected IllegalArgumentException when CLAPP tool name 
contains invalid path characters");
+        } finally {
+            System.clearProperty("maven.home");
+        }
+    }
+
+    @Test
+    void launchClappInvokesRunMethodSuccessfully() throws Exception {
+        System.setProperty("maven.home", tempDir.toString());
+        try {
+            int exitCode = MavenClappCling.launchClapp(
+                    "mytool", SampleRunTool.class.getName(), new String[] 
{"test"}, null);

Review Comment:
   Fixed in commit ca84dc3d: Added `launchClappLoadsFromJarInClappDirectory()` 
which dynamically compiles a standalone tool class at test time, packages it 
into a fixture JAR placed in `lib/clapp/standalone/`, and verifies execution 
through `MavenClappCling.launchClapp()`. This ensures entry points and classes 
are loaded from child-loader jars.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to