FrankChen021 commented on PR #20373:
URL: https://github.com/apache/druid/pull/20373#issuecomment-5724785584

   This is an automated review by Codex GPT-5.6 Luna(Max).
   
   ## ROUND_1 closure decision
   
   Close this PR without approval. The requested 
`org.apache.maven.resolver:maven-resolver-api` upgrade from `1.3.1` to `2.0.23` 
is INCOMPATIBLE as submitted: it changes only the API module while Druid 
packages and runs the rest of the Maven Resolver stack at `1.3.1`. Apache Maven 
Resolver's published compatibility guidance requires non-Maven consumers to use 
the same version for the API, SPI, implementation, utilities, connectors, and 
transports. Aligning that stack, the Maven resolver provider, the session 
lifecycle, and Druid's license registry is a separate coordinated change and is 
too broad/risky for this one-line Dependabot PR.
   
   ## Release inventory and cumulative effect
   
   The complete Maven Central metadata for 
`org.apache.maven.resolver:maven-resolver-api` was read from the official 
artifact repository. Inclusive of the source and target, it contains 73 
published artifact versions and 72 transitions:
   
   - `1.3.1` -> `1.3.2`, `1.3.3`, `1.4.0`, `1.4.1`, `1.4.2`, `1.6.1`, `1.6.2`, 
`1.6.3`, `1.7.0`, `1.7.1`, `1.7.2`, `1.7.3`, `1.8.0`, `1.8.1`, `1.8.2`.
   - `1.9.0`, `1.9.1`, `1.9.2`, `1.9.4`, `1.9.5`, `1.9.6`, `1.9.7`, `1.9.8`, 
`1.9.10`, `1.9.11`, `1.9.12`, `1.9.13`, `1.9.14`, `1.9.15`, `1.9.16`, `1.9.17`, 
`1.9.18`, `1.9.19`, `1.9.20`, `1.9.21`, `1.9.22`, `1.9.23`, `1.9.24`, `1.9.25`, 
`1.9.26`, `1.9.27`.
   - `2.0.0-alpha-1`, `2.0.0-alpha-2`, `2.0.0-alpha-3`, `2.0.0-alpha-5`, 
`2.0.0-alpha-6`, `2.0.0-alpha-7`, `2.0.0-alpha-8`, `2.0.0-alpha-10`, 
`2.0.0-alpha-11`.
   - `2.0.0`, `2.0.1`, `2.0.2`, `2.0.3`, `2.0.4`, `2.0.5`, `2.0.6`, `2.0.7`, 
`2.0.8`, `2.0.9`, `2.0.10`, `2.0.11`, `2.0.13`, `2.0.14`, `2.0.15`, `2.0.16`, 
`2.0.17`, `2.0.18`, `2.0.20`, `2.0.21`, `2.0.22`, `2.0.23`.
   
   Source tags that do not appear in the artifact metadata (`1.6.0`, `1.9.3`, 
`1.9.9`, `2.0.0-alpha-4`, `2.0.0-alpha-9`, `2.0.12`, and `2.0.19`) were not 
counted as published `maven-resolver-api` artifacts. The cumulative target 
effect includes the 2.0 major contract: `RepositorySystem` now extends 
`Closeable` and adds lifecycle/session methods; `RepositorySystemSession` adds 
closeable-session and lifecycle contracts; and the legacy 
`DefaultRepositorySystemSession()` path used by Druid is deprecated because it 
can leak resources. The 2.0.23 release also contains later resolver security 
and repository-integrity fixes, but this PR does not update the matching 
implementation, SPI, connector, or transport modules that would consume them.
   
   ## Compatibility categories
   
   | Category | Decision | Evidence |
   | --- | --- | --- |
   | API/ABI | INCOMPATIBLE | Target `RepositorySystem` adds abstract 
`flattenDependencyNodes`, `createSessionBuilder`, `addOnSystemEndedHandler`, 
and `shutdown` methods and extends `Closeable`; target 
`RepositorySystemSession` adds lifecycle methods. Resolver's own 
API-compatibility contract says major versions do not provide backward 
compatibility. |
   | Runtime | INCOMPATIBLE | 
`services/src/main/java/org/apache/druid/cli/PullDependencies.java` creates the 
service locator at lines 202-207, creates the legacy session at lines 210-214, 
and resolves dependencies at lines 364-373 without closing the system/session. 
The target's 2.x lifecycle contract is not adopted, while the implementation 
remains 1.3.1. |
   | Configuration | SAFE | The PR changes no Druid configuration, CLI option, 
or default; only one Maven version is changed. |
   | Serialization/wire | SAFE | No Druid wire format, serialized class, query 
protocol, or schema is changed by this metadata-only diff. |
   | Persistence | SAFE | No Druid persistence format is changed; the existing 
extension/local-repository paths remain in source. Resolver local-repository 
behavior is not safely upgradeable independently of the rest of the stack. |
   | Clients | CONCERN | `PullDependencies` is Druid's Maven Resolver network 
client and explicitly wires the 1.3.1 HTTP transport/connector into the target 
API path. |
   | Transitive dependencies | INCOMPATIBLE | The current reactor dependency 
tree resolves `maven-resolver-api:2.0.23` but `maven-resolver-connector-basic`, 
`maven-resolver-transport-http`, `maven-resolver-util`, `maven-resolver-impl`, 
and `maven-resolver-spi` at `1.3.1`; `maven-resolver-provider:3.6.0` also 
brings the 1.3.1 stack. |
   | Licenses | CONCERN | Both endpoint JARs are Apache-2.0, but target 
`META-INF/NOTICE` says `Copyright 2010-2026` while `licenses.yaml` lines 2109 
and 2122-2124 register the grouped Resolver artifacts only at `1.3.1` with the 
2001-2018 API notice. The target version/notice is not registered. |
   | Extension/plugin SPI | INCOMPATIBLE | Druid's dependency graph exposes 
Resolver SPI and connector implementations at `1.3.1` beside API `2.0.23`; 
Apache's compatibility guide explicitly requires the API, SPI, impl, util, 
connector, and transport versions to match for applications outside Maven. |
   
   ## Druid impact and validation
   
   The complete PR diff is one tracked line in `services/pom.xml`; no Druid 
production source or test file changed. The affected call sites are 
`PullDependencies.java` lines 35-59, 182-214, 327-372 and 
`PullDependenciesTest.java` lines 26-50, 96-156, 296-357. The source/test path 
still compiles and its existing behavior is covered, but that does not make the 
unsupported mixed Resolver module set safe.
   
   Validation performed:
   
   - `git diff --check`: passed.
   - `mvn -ntp -pl services -DskipTests dependency:tree -Dverbose 
'-Dincludes=org.apache.maven.resolver:*'`: passed and showed the mixed versions 
above.
   - `mvn -ntp -pl distribution -am -DskipTests dependency:tree -Dverbose 
'-Dincludes=org.apache.maven.resolver:*'`: passed and showed the same mixed 
versions in the packaged reactor.
   - Focused reactor test `mvn -ntp test -pl services -am 
-Dtest="org.apache.druid.cli.PullDependenciesTest" 
-Dsurefire.failIfNoSpecifiedTests=false -Pskip-static-checks 
-Dweb.console.skip=true -T1C`: passed, 12 tests, 0 failures/errors/skips.
   - Current generated `services/target/reports/dependencies.html` and 
`distribution/target/reports/dependencies.html`: confirmed 
`maven-resolver-api:2.0.23` and the other Resolver modules at `1.3.1`; target 
artifact inspection confirmed Apache-2.0 LICENSE/NOTICE.
   - The standalone `check-licenses.py` invocation could not run locally 
because the environment lacks PyYAML (`ModuleNotFoundError: No module named 
'yaml'`); the registry/report mismatch above was verified directly.
   
   ## CI and automation actions
   
   Exact reserved/current head: `ae32b418bdb1a48177e50ea08263549073eba0f8`. The 
live PR was OPEN, non-draft, MERGEABLE/CLEAN with no prior reviews. The 
complete current rollup was 27 CheckRuns, all `COMPLETED/SUCCESS`, and 0 
StatusContexts; there were no failed, pending, cancelled, skipped, neutral, or 
unknown items, so no failed-job diagnosis or rerun was needed. No worktree 
repair, commit, or push was made. No approval was submitted because 
compatibility was not SAFE. This closure is not a merge; no merge was performed.
   
   Official evidence: [Maven Central 
metadata](https://repo1.maven.org/maven2/org/apache/maven/resolver/maven-resolver-api/maven-metadata.xml),
 [Resolver API compatibility 
guidance](https://github.com/apache/maven-resolver/blob/maven-resolver-2.0.23/src/site/markdown/api-compatibility.md),
 and [Resolver 1.x to 2.x upgrade 
guide](https://github.com/apache/maven-resolver/blob/maven-resolver-2.0.23/src/site/markdown/upgrading-resolver.md).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to