gnodet-bot commented on code in PR #13197:
URL: https://github.com/apache/maven/pull/13197#discussion_r4052316056


##########
impl/maven-impl/src/main/java/org/apache/maven/impl/model/DefaultModelBuilder.java:
##########
@@ -1204,11 +1204,21 @@ void buildEffectiveModel(Collection<String> importIds) 
throws ModelBuilderExcept
             }
 
             // effective model validation
-            modelValidator.validateEffectiveModel(
-                    session,
-                    resultModel,
-                    isBuildRequest() ? ModelValidator.VALIDATION_LEVEL_STRICT 
: ModelValidator.VALIDATION_LEVEL_MINIMAL,
-                    this);
+            // BUILD_EFFECTIVE is a tooling-only mode (mvnup, IDEs) that runs 
without a reactor
+            // scan, so BOM imports from reactor siblings cannot be resolved. 
When such a BOM is
+            // unresolvable the managed versions are absent, and strict 
validation would fire a
+            // cascade of misleading "version is missing" errors for every 
dependency that relied
+            // on that BOM. Using MAVEN_2_0 level for BUILD_EFFECTIVE still 
catches real structural
+            // errors while keeping version-managed-by-BOM from becoming a 
fatal cascade.
+            // The root cause (Non-resolvable import POM) is already reported 
by importDependencyManagement.
+            // TODO 4.1.0: refactor BUILD_EFFECTIVE out of isBuildRequest() so 
the distinction is
+            //             architectural rather than a special-case here.
+            int effectiveValidationLevel = isBuildRequest()
+                    ? (request.getRequestType() == 
ModelBuilderRequest.RequestType.BUILD_EFFECTIVE
+                            ? ModelValidator.VALIDATION_LEVEL_MAVEN_2_0
+                            : ModelValidator.VALIDATION_LEVEL_STRICT)
+                    : ModelValidator.VALIDATION_LEVEL_MINIMAL;
+            modelValidator.validateEffectiveModel(session, resultModel, 
effectiveValidationLevel, this);

Review Comment:
   ⚠️ **Mechanism broken**: `VALIDATION_LEVEL_MAVEN_2_0` does not suppress 
`validateDependencyVersion`'s ERROR for a null version — that check uses 
`Severity.ERROR, Version.BASE` with no level gate. Switching from `STRICT` to 
`MAVEN_2_0` leaves the cascade intact while silently adding scope, optional, 
and format checks that were absent under `MINIMAL`.
   
   If the goal is to avoid cascading "version is missing" errors when a 
reactor-sibling BOM is unresolvable, the level selector needs to either lower 
the severity inside `validateDependencyVersion`, or the entire validation 
should be skipped for `BUILD_EFFECTIVE` (it has no reactor context, so 
effective-model invariants cannot be satisfied anyway).



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to