slachiewicz opened a new issue, #2156: URL: https://github.com/apache/maven-resolver/issues/2156
### Affected version 2.0.23 (also master at a90b7f7f) ### Bug description `DefaultArtifactResolver` evaluates the remote repository filter for every repository in the request, before the policy check and the local availability check ([DefaultArtifactResolver.java#L274-L287](https://github.com/apache/maven-resolver/blob/master/maven-resolver-impl/src/main/java/org/eclipse/aether/internal/impl/DefaultArtifactResolver.java#L274-L287)). The prefixes filter is on by default, so its first evaluation per repository downloads `.meta/prefixes.txt`. As a result, every repository in the list is contacted once per session, including repositories that would never be asked for the artifact. This shows up in two common cases: - **Snapshot-only repositories for release artifacts.** `sonatype-nexus-snapshots` and `plexus.snapshots` are probed, although the policy check a few lines later skips them. - **Repositories declared in dependency POMs.** The collector merges these into the children's requests (`BfDependencyCollector` → `aggregateRepositories(…, true, true)`). A dead one is contacted on every build. Transfer errors are not cached, so this happens even when every artifact is already local. Reproducer: a minimal jar project, running `mvn org.apache.maven.plugins:maven-checkstyle-plugin:3.6.0:check` on Maven 4.0.0-rc-7 (resolver 2.0.23) against an empty local repository. The plugin's graph pulls in `javax.xml.bind:jaxb-api:2.3.1`, whose parent `net.java:jvnet-parent` declares `jvnet-nexus-releases` (`https://maven.java.net/content/repositories/releases/`, expired certificate). Both a cold and a warm run log the following, and the warm run downloads nothing: ``` [WARNING] Could not transfer metadata /.meta/prefixes.txt from/to jvnet-nexus-releases (https://maven.java.net/content/repositories/releases/): (certificate_expired) PKIX path validation failed ``` Maven 3.9.16 (resolver 1.9, filter off by default) never contacts that host, because central answers first. On resolver 2, any hostname named in any POM in the graph is contacted on every build, including a repository domain that has since lapsed. A host that accepts connections and never answers costs up to the connect or request timeout. User-facing report: apache/maven#13050. Proposed: 1. Skip filter evaluation for repositories whose policy is disabled for the request's nature, in `DefaultArtifactResolver` and `DefaultMetadataResolver`. They are skipped a few lines later anyway; same principle as MNG-4771/MNG-4772. 2. Skip prefixes auto-discovery for repositories that `aggregateRepositories` received with `recessiveIsFromDescriptor=true`, behind `aether.remoteRepositoryFilter.prefixes.useDescriptorRepositories` (default `false`), the same shape as `useMirroredRepositories`. This needs the provenance from #2090 to be visible to the filter, for example through session data. User-provided prefix files keep applying to both. Neither change alters which repositories serve artifacts; both only remove probes. Workaround: `-Daether.remoteRepositoryFilter.prefixes.<repoId>=false`. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
