FrankChen021 commented on PR #20374:
URL: https://github.com/apache/druid/pull/20374#issuecomment-5724834033

   This is an automated dependency triage by Codex GPT-5.6 Luna(Max).
   
   Decision: close this PR as INCOMPATIBLE in isolation. The reserved head was 
revalidated immediately before this comment as 
`9eb7ff61fde2588c0aa5bc8a074dfa8ace2fcd74`; the PR was OPEN, non-draft, 
MERGEABLE/UNSTABLE, with no reviews or prior comments.
   
   ## Change and published-release inventory
   
   The only PR diff is `services/pom.xml`, changing 
`org.apache.maven.resolver:maven-resolver-spi` from `1.3.1` to `2.0.23` 
(`+1/-1`; no Druid source or test file is changed). The complete Maven Central 
artifact history reviewed, inclusive of the source and target and excluding 
project tags that did not publish this GAV, is:
   
   `1.3.1`, `1.3.2`, `1.3.3`, `1.4.0`, `1.4.1`, `1.4.2`, `1.6.1`, `1.6.2`, 
`1.6.3`, `1.7.0`, `1.7.1`, `1.7.2`, `1.7.3`, `1.8.0`, `1.8.1`, `1.8.2`, 
`1.9.0`, `1.9.1`, `1.9.2`, `1.9.4`, `1.9.5`, `1.9.6`, `1.9.7`, `1.9.8`, 
`1.9.10`, `1.9.11`, `1.9.12`, `1.9.13`, `1.9.14`, `1.9.15`, `1.9.16`, `1.9.17`, 
`1.9.18`, `1.9.19`, `1.9.20`, `1.9.21`, `1.9.22`, `1.9.23`, `1.9.24`, `1.9.25`, 
`1.9.26`, `1.9.27`, `2.0.0-alpha-1`, `2.0.0-alpha-2`, `2.0.0-alpha-3`, 
`2.0.0-alpha-5`, `2.0.0-alpha-6`, `2.0.0-alpha-7`, `2.0.0-alpha-8`, 
`2.0.0-alpha-10`, `2.0.0-alpha-11`, `2.0.0`, `2.0.1`, `2.0.2`, `2.0.3`, 
`2.0.4`, `2.0.5`, `2.0.6`, `2.0.7`, `2.0.8`, `2.0.9`, `2.0.10`, `2.0.11`, 
`2.0.13`, `2.0.14`, `2.0.15`, `2.0.16`, `2.0.17`, `2.0.18`, `2.0.20`, `2.0.21`, 
`2.0.22`, `2.0.23`.
   
   The target is the cumulative 72-artifact-version transition from the 1.3.1 
line through the 2.0.x line. The Resolver 2.0.0 release notes document the 
major removal of `ServiceLocator`, transport cleanup/renames, resolver API 
changes, and Maven 4/module alignment: 
https://github.com/apache/maven-resolver/releases/tag/maven-resolver-2.0.0. The 
target 2.0.23 release adds later repository-key, integrity, path-validation, 
and coordinate-validation changes: 
https://github.com/apache/maven-resolver/releases/tag/maven-resolver-2.0.23. 
The artifact metadata used for the complete inventory is 
https://repo.maven.apache.org/maven2/org/apache/maven/resolver/maven-resolver-spi/maven-metadata.xml.
   
   ## Compatibility analysis
   
   - API/ABI: INCOMPATIBLE. `maven-resolver-spi:1.3.1` contains 
`org.eclipse.aether.spi.locator.ServiceLocator` and `Service.class`; `2.0.23` 
removes `org/eclipse/aether/spi/locator` entirely. `maven-resolver-api:2.0.23` 
also changes `RepositorySystem` (including `Closeable` and new 
lifecycle/session APIs), while this PR leaves Druid's resolver 
API/impl/util/connector modules at 1.3.1.
   - Runtime: INCOMPATIBLE. The existing Maven 3.6 provider bootstrap calls 
`MavenRepositorySystemUtils.newServiceLocator()` and Druid then calls 
`locator.getService(RepositorySystem.class)`. The target 2.0.23 implementation 
no longer provides the old `DefaultServiceLocator` bootstrap, and the current 
build fails before runtime.
   - Configuration: SAFE in isolation; no Druid configuration keys or defaults 
change.
   - Serialization/wire: SAFE in isolation; no Druid serialized format, 
protocol, or wire contract changes.
   - Persistence: SAFE in isolation; no segment, metadata-store, or persistence 
format changes.
   - Clients: SAFE for Druid public client contracts; no client-facing source 
changes are present. The dependency resolver runtime is covered by the 
extension/plugin SPI decision below.
   - Transitive dependencies: INCOMPATIBLE. The target SPI POM brings 
`maven-resolver-api:2.0.23`, while Druid still directly selects resolver 
API/impl/util/connector/transport 1.3.1 and `maven-resolver-provider:3.6.0`; 
RequireUpperBoundDeps fails on this mixed graph.
   - Licenses: UNRESOLVED/CONCERN. The published target resolver POM is 
Apache-2.0, but Druid's exact-version license registry still records the 
resolver entries at 1.3.1 and has no matching java-core Gson entry for the 
target graph. The license check therefore needs a coordinated registry update; 
it was not safe to claim completion from this one-line bump.
   - Extension/plugin SPI behavior: INCOMPATIBLE. 
`services/src/main/java/org/apache/druid/cli/PullDependencies.java` imports 
`DefaultServiceLocator`, `RepositoryConnectorFactory`, `TransporterFactory`, 
and `HttpTransporterFactory`, and constructs the old locator at lines 204-207. 
The 2.0.23 stack requires coordinated bootstrap and transport changes; the old 
HTTP transport artifact has no 2.0.23 release, while Resolver 2.0.23 publishes 
the renamed `maven-resolver-transport-apache`/`ApacheTransporterFactory` 
surface.
   
   ## Druid impact
   
   Affected call sites are 
`services/src/main/java/org/apache/druid/cli/PullDependencies.java:35-59,204-207`
 and the equivalent service bootstrap in 
`services/src/test/java/org/apache/druid/cli/PullDependenciesTest.java:341-346`.
 The tracked source/test code is unchanged by the PR, but both call sites are 
affected by the changed resolver SPI. A safe implementation requires 
coordinated changes to the resolver API/SPI/util/impl/connector stack, the 
Maven provider/bootstrap, the HTTP transport artifact and factory, and the 
exact license registry.
   
   ## Validation and CI gate
   
   Local validation confirmed the supplied diff is one version-line change and 
the worktree has no repair edits. The published 1.3.1/2.0.23 POMs and JAR class 
lists were compared, including `javap` checks for `ServiceLocator`, 
`RepositorySystem`, `DefaultServiceLocator`, and the transport factories. All 
20 failed job logs and the available static/unit artifacts were inspected: no 
test-specific failure was found; unit reports contained no additional 
`<failure>` or `<error>` beyond the compile abort.
   
   At the exact current head `9eb7ff61fde2588c0aa5bc8a074dfa8ace2fcd74`, the 
complete rollup was 27 completed CheckRuns and 0 StatusContexts: 5 SUCCESS, 20 
FAILURE, 1 SKIPPED (`coverage-jacoco`), and 1 NEUTRAL (aggregate `CodeQL`). The 
20 failures were deterministic and PR-caused:
   
   - Missing `org.eclipse.aether.spi.locator.ServiceLocator` at 
`PullDependencies.java:205`: `Analyze (java)` job `105428435862`; `web-checks` 
`105428437368`; `docker-tests` `105428437447`; all 13 unit jobs `105428437938`, 
`105428438018`, `105428437878`, `105428437829`, `105428437742`, `105428437801`, 
`105428437881`, `105428437686`, `105428437808`, `105428437771`, `105428437689`, 
`105428437744`, `105428437786`.
   - RequireUpperBoundDeps conflicts between resolver 1.3.1 and target-induced 
API 2.0.23: `packaging-check-jdk25` `105428437356`; `static-checks-maven` 
`105428437307`; `strict-compilation` `105428437186`; `openrewrite` 
`105428437382`.
   
   Because these failures are deterministic consequences of the incompatible 
mixed dependency graph, no CI rerun was eligible or useful, and no rerun was 
attempted. No repair commit or push was made. Approval was not submitted 
because the compatibility gates are not all SAFE and the exact-head rollup is 
not green.
   
   ## Automation actions
   
   This is a non-duplicate, evidence-backed closure recommendation for the 
assigned ROUND_1 PR. The bounded action is to close the PR. A future safe 
change must be a coordinated Maven Resolver 2.x migration with focused 
source/test/bootstrap/transport/license updates followed by a fresh full CI 
run. No merge was performed.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to