FrankChen021 commented on PR #20373: URL: https://github.com/apache/druid/pull/20373#issuecomment-5724785584
This is an automated review by Codex GPT-5.6 Luna(Max). ## ROUND_1 closure decision Close this PR without approval. The requested `org.apache.maven.resolver:maven-resolver-api` upgrade from `1.3.1` to `2.0.23` is INCOMPATIBLE as submitted: it changes only the API module while Druid packages and runs the rest of the Maven Resolver stack at `1.3.1`. Apache Maven Resolver's published compatibility guidance requires non-Maven consumers to use the same version for the API, SPI, implementation, utilities, connectors, and transports. Aligning that stack, the Maven resolver provider, the session lifecycle, and Druid's license registry is a separate coordinated change and is too broad/risky for this one-line Dependabot PR. ## Release inventory and cumulative effect The complete Maven Central metadata for `org.apache.maven.resolver:maven-resolver-api` was read from the official artifact repository. Inclusive of the source and target, it contains 73 published artifact versions and 72 transitions: - `1.3.1` -> `1.3.2`, `1.3.3`, `1.4.0`, `1.4.1`, `1.4.2`, `1.6.1`, `1.6.2`, `1.6.3`, `1.7.0`, `1.7.1`, `1.7.2`, `1.7.3`, `1.8.0`, `1.8.1`, `1.8.2`. - `1.9.0`, `1.9.1`, `1.9.2`, `1.9.4`, `1.9.5`, `1.9.6`, `1.9.7`, `1.9.8`, `1.9.10`, `1.9.11`, `1.9.12`, `1.9.13`, `1.9.14`, `1.9.15`, `1.9.16`, `1.9.17`, `1.9.18`, `1.9.19`, `1.9.20`, `1.9.21`, `1.9.22`, `1.9.23`, `1.9.24`, `1.9.25`, `1.9.26`, `1.9.27`. - `2.0.0-alpha-1`, `2.0.0-alpha-2`, `2.0.0-alpha-3`, `2.0.0-alpha-5`, `2.0.0-alpha-6`, `2.0.0-alpha-7`, `2.0.0-alpha-8`, `2.0.0-alpha-10`, `2.0.0-alpha-11`. - `2.0.0`, `2.0.1`, `2.0.2`, `2.0.3`, `2.0.4`, `2.0.5`, `2.0.6`, `2.0.7`, `2.0.8`, `2.0.9`, `2.0.10`, `2.0.11`, `2.0.13`, `2.0.14`, `2.0.15`, `2.0.16`, `2.0.17`, `2.0.18`, `2.0.20`, `2.0.21`, `2.0.22`, `2.0.23`. Source tags that do not appear in the artifact metadata (`1.6.0`, `1.9.3`, `1.9.9`, `2.0.0-alpha-4`, `2.0.0-alpha-9`, `2.0.12`, and `2.0.19`) were not counted as published `maven-resolver-api` artifacts. The cumulative target effect includes the 2.0 major contract: `RepositorySystem` now extends `Closeable` and adds lifecycle/session methods; `RepositorySystemSession` adds closeable-session and lifecycle contracts; and the legacy `DefaultRepositorySystemSession()` path used by Druid is deprecated because it can leak resources. The 2.0.23 release also contains later resolver security and repository-integrity fixes, but this PR does not update the matching implementation, SPI, connector, or transport modules that would consume them. ## Compatibility categories | Category | Decision | Evidence | | --- | --- | --- | | API/ABI | INCOMPATIBLE | Target `RepositorySystem` adds abstract `flattenDependencyNodes`, `createSessionBuilder`, `addOnSystemEndedHandler`, and `shutdown` methods and extends `Closeable`; target `RepositorySystemSession` adds lifecycle methods. Resolver's own API-compatibility contract says major versions do not provide backward compatibility. | | Runtime | INCOMPATIBLE | `services/src/main/java/org/apache/druid/cli/PullDependencies.java` creates the service locator at lines 202-207, creates the legacy session at lines 210-214, and resolves dependencies at lines 364-373 without closing the system/session. The target's 2.x lifecycle contract is not adopted, while the implementation remains 1.3.1. | | Configuration | SAFE | The PR changes no Druid configuration, CLI option, or default; only one Maven version is changed. | | Serialization/wire | SAFE | No Druid wire format, serialized class, query protocol, or schema is changed by this metadata-only diff. | | Persistence | SAFE | No Druid persistence format is changed; the existing extension/local-repository paths remain in source. Resolver local-repository behavior is not safely upgradeable independently of the rest of the stack. | | Clients | CONCERN | `PullDependencies` is Druid's Maven Resolver network client and explicitly wires the 1.3.1 HTTP transport/connector into the target API path. | | Transitive dependencies | INCOMPATIBLE | The current reactor dependency tree resolves `maven-resolver-api:2.0.23` but `maven-resolver-connector-basic`, `maven-resolver-transport-http`, `maven-resolver-util`, `maven-resolver-impl`, and `maven-resolver-spi` at `1.3.1`; `maven-resolver-provider:3.6.0` also brings the 1.3.1 stack. | | Licenses | CONCERN | Both endpoint JARs are Apache-2.0, but target `META-INF/NOTICE` says `Copyright 2010-2026` while `licenses.yaml` lines 2109 and 2122-2124 register the grouped Resolver artifacts only at `1.3.1` with the 2001-2018 API notice. The target version/notice is not registered. | | Extension/plugin SPI | INCOMPATIBLE | Druid's dependency graph exposes Resolver SPI and connector implementations at `1.3.1` beside API `2.0.23`; Apache's compatibility guide explicitly requires the API, SPI, impl, util, connector, and transport versions to match for applications outside Maven. | ## Druid impact and validation The complete PR diff is one tracked line in `services/pom.xml`; no Druid production source or test file changed. The affected call sites are `PullDependencies.java` lines 35-59, 182-214, 327-372 and `PullDependenciesTest.java` lines 26-50, 96-156, 296-357. The source/test path still compiles and its existing behavior is covered, but that does not make the unsupported mixed Resolver module set safe. Validation performed: - `git diff --check`: passed. - `mvn -ntp -pl services -DskipTests dependency:tree -Dverbose '-Dincludes=org.apache.maven.resolver:*'`: passed and showed the mixed versions above. - `mvn -ntp -pl distribution -am -DskipTests dependency:tree -Dverbose '-Dincludes=org.apache.maven.resolver:*'`: passed and showed the same mixed versions in the packaged reactor. - Focused reactor test `mvn -ntp test -pl services -am -Dtest="org.apache.druid.cli.PullDependenciesTest" -Dsurefire.failIfNoSpecifiedTests=false -Pskip-static-checks -Dweb.console.skip=true -T1C`: passed, 12 tests, 0 failures/errors/skips. - Current generated `services/target/reports/dependencies.html` and `distribution/target/reports/dependencies.html`: confirmed `maven-resolver-api:2.0.23` and the other Resolver modules at `1.3.1`; target artifact inspection confirmed Apache-2.0 LICENSE/NOTICE. - The standalone `check-licenses.py` invocation could not run locally because the environment lacks PyYAML (`ModuleNotFoundError: No module named 'yaml'`); the registry/report mismatch above was verified directly. ## CI and automation actions Exact reserved/current head: `ae32b418bdb1a48177e50ea08263549073eba0f8`. The live PR was OPEN, non-draft, MERGEABLE/CLEAN with no prior reviews. The complete current rollup was 27 CheckRuns, all `COMPLETED/SUCCESS`, and 0 StatusContexts; there were no failed, pending, cancelled, skipped, neutral, or unknown items, so no failed-job diagnosis or rerun was needed. No worktree repair, commit, or push was made. No approval was submitted because compatibility was not SAFE. This closure is not a merge; no merge was performed. Official evidence: [Maven Central metadata](https://repo1.maven.org/maven2/org/apache/maven/resolver/maven-resolver-api/maven-metadata.xml), [Resolver API compatibility guidance](https://github.com/apache/maven-resolver/blob/maven-resolver-2.0.23/src/site/markdown/api-compatibility.md), and [Resolver 1.x to 2.x upgrade guide](https://github.com/apache/maven-resolver/blob/maven-resolver-2.0.23/src/site/markdown/upgrading-resolver.md). -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
