Copilot commented on code in PR #13276: URL: https://github.com/apache/maven/pull/13276#discussion_r4115200364
########## impl/maven-cli/src/main/java/org/apache/maven/cling/MavenValCling.java: ########## @@ -0,0 +1,90 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ +package org.apache.maven.cling; + +import java.io.IOException; +import java.io.InputStream; +import java.io.OutputStream; + +import org.apache.maven.api.annotations.Nullable; +import org.apache.maven.api.cli.Invoker; +import org.apache.maven.api.cli.Parser; +import org.apache.maven.api.cli.ParserRequest; +import org.apache.maven.cling.invoker.ProtoLookup; +import org.apache.maven.cling.invoker.mvnval.ValidateInvoker; +import org.apache.maven.cling.invoker.mvnval.ValidateParser; +import org.codehaus.plexus.classworlds.ClassWorld; + +/** + * Maven POM validation CLI "new-gen". + */ +public class MavenValCling extends ClingSupport { + /** + * "Normal" Java entry point. Note: Maven uses ClassWorld Launcher and this entry point is NOT used under normal + * circumstances. + */ + public static void main(String[] args) throws IOException { + int exitCode = new MavenValCling().run(args, null, null, null, false); + System.exit(exitCode); + } + + /** + * ClassWorld Launcher "enhanced" entry point: returning exitCode and accepts Class World. + */ + public static int main(String[] args, ClassWorld world) throws IOException { + return new MavenValCling(world).run(args, null, null, null, false); + } + + /** + * ClassWorld Launcher "embedded" entry point: returning exitCode and accepts Class World and streams. + */ + public static int main( + String[] args, + ClassWorld world, + @Nullable InputStream stdIn, + @Nullable OutputStream stdOut, + @Nullable OutputStream stdErr) + throws IOException { + return new MavenValCling(world).run(args, stdIn, stdOut, stdErr, true); + } + + public MavenValCling() { + super(); + } + + public MavenValCling(ClassWorld classWorld) { + super(classWorld); + } + + @Override + protected Invoker createInvoker() { + return new ValidateInvoker( + ProtoLookup.builder().addMapping(ClassWorld.class, classWorld).build(), null); Review Comment: This tool still inherits the normal `LookupInvoker` bootstrap, so `createContainerCapsule()` selects project core extensions and `BootstrapCoreExtensionManager.loadCoreExtensions()` resolves and loads them before `execute()` reaches `buildRaw`. A POM under `.mvn/extensions.xml` can therefore trigger repository access and arbitrary extension code, contradicting the documented file-only/no-network behavior and making validation of an untrusted POM unsafe. Use a no-extension bootstrap for `mvnval` (and cover this with a fixture), or explicitly document and accept this behavior. ########## impl/maven-cli/src/main/java/org/apache/maven/cling/invoker/mvnval/CommonsCliValidateOptions.java: ########## @@ -0,0 +1,111 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ +package org.apache.maven.cling.invoker.mvnval; + +import java.util.List; +import java.util.Optional; +import java.util.function.Consumer; + +import org.apache.commons.cli.CommandLine; +import org.apache.commons.cli.Option; +import org.apache.commons.cli.ParseException; +import org.apache.maven.api.annotations.Nonnull; +import org.apache.maven.api.cli.Options; +import org.apache.maven.api.cli.ParserRequest; +import org.apache.maven.api.cli.mvnval.ValidateOptions; +import org.apache.maven.cling.invoker.CommonsCliOptions; + +/** + * Implementation of {@link ValidateOptions} (base + mvnval). + */ +public class CommonsCliValidateOptions extends CommonsCliOptions implements ValidateOptions { + + public static CommonsCliValidateOptions parse(String[] args) throws ParseException { + CLIManager cliManager = new CLIManager(); + CommonsCliValidateOptions options = + new CommonsCliValidateOptions(Options.SOURCE_CLI, cliManager, cliManager.parse(args)); + // Reject a bad --format here, so the user gets a usage error rather than a failure + // after the container has been built. + try { + options.format().ifPresent(OutputFormat::parse); + } catch (IllegalArgumentException e) { + throw new ParseException(e.getMessage()); + } + return options; + } Review Comment: Because `ValidateParser` throws here, `BaseParser.parseInvocation` marks the request as `parsingFailed`; `LookupInvoker.validate` then exits with code 1 before `ValidateInvoker.execute` can return `BAD_OPERATION` (2). Consequently an actual `mvnval --format xml` is reported with the parser-failure exit code, contrary to the documented “2 on bad usage” contract. Defer format validation to the invoker (which already maps `OutputFormat.parse` failures to 2), or otherwise give this parser a tool-specific bad-usage path. ########## impl/maven-cli/src/main/java/org/apache/maven/cling/invoker/mvnval/ValidateParser.java: ########## @@ -0,0 +1,35 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY + * KIND, either express or implied. See the License for the + * specific language governing permissions and limitations + * under the License. + */ +package org.apache.maven.cling.invoker.mvnval; + +import org.apache.commons.cli.ParseException; +import org.apache.maven.api.cli.Options; +import org.apache.maven.cling.invoker.BaseParser; + +public class ValidateParser extends BaseParser { + + @Override + protected Options parseCliOptions(LocalContext context) { + try { + return CommonsCliValidateOptions.parse(context.parserRequest.args().toArray(new String[0])); + } catch (ParseException e) { + throw new IllegalArgumentException("Failed to parse command line options: " + e.getMessage(), e); Review Comment: An invalid `--format` is rejected here during parsing, which makes `BaseParser` set `parsingFailed` and `LookupInvoker.validate()` return exit code 1 before `ValidateInvoker.BAD_OPERATION` can run. That violates this tool's documented contract of exit code 2 for bad usage; add a tool-specific parser-error exit path or defer this validation to execution, and test the actual CLI exit code. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
