NassimBtk opened a new issue, #13388:
URL: https://github.com/apache/maven/issues/13388

   ### Affected version
   
   3.10.0
   
   ### Bug description
   
   Since Maven 3.10.0, 
`LegacyLocalRepositoryManager.overlay(ArtifactRepository, 
RepositorySystemSession, RepositorySystem)` changed:
   - **3.10.0:** for a repository that uses `DefaultRepositoryLayout`, it 
returns a session whose local repository manager is a regular Resolver 2 
manager, set up by 
`DefaultRepositorySystemSessionFactory.setUpLocalRepositoryManager`. This came 
with #11778.
   - **3.9.x:** it always wrapped the repository in a 
`LegacyLocalRepositoryManager`.
   
   As a result, a plugin that calls the maven-compat 
`ArtifactInstaller.install(file, artifact, repository)` to install into a 
directory that is **not** the local repository now gets local-repository 
bookkeeping files in that directory:
   
   | File | 3.9.x | 3.10.0 |
   | --- | --- | --- |
   | Group/artifact-level metadata | `maven-metadata-<repositoryId>.xml` | 
`maven-metadata-local.xml` |
   | Origin tracking | none | `<version>/_remote.repositories` |
   | Locks | none | `.locks/*.lock` (file-lock named locks, the Resolver 2 
default) |
   
   **Impact.** `org.sonatype.central:central-publishing-maven-plugin` 0.11.0, 
the current release used to publish to Maven Central, stages release artifacts 
this way into `target/central-staging` (repository id `central-staging`). It 
then:
   1. deletes only `maven-metadata-central-staging.xml`;
   2. zips the staging directory;
   3. uploads the bundle.
   
   Maven Central then rejects the deployment:
   
   ```
   Deployment ... failed
   common:
    - Bundle has content that does NOT have a .pom file: org/metricshub/jflat
   ```
   
   This is also reported at 
https://github.com/mavenplugins/central-publishing-maven-plugin/issues/78, 
where a multi-module project hits the same error. The plugin sources are not 
public, so I am reporting the Maven side here, and I am reporting the plugin 
side to Sonatype support.
   
   **Reproduction**
   1. Use Maven 3.10.0 with any jar project that has a release version and 
`central-publishing-maven-plugin` 0.11.0 as an extension 
(`<extensions>true</extensions>`).
   2. Run `mvn deploy -DcentralBaseUrl=http://127.0.0.1:9`. The bundle is 
built, and the upload then fails locally.
   3. List `target/central-publishing/central-bundle.zip`. It contains:
      - `.locks/artifact~<g>~<a>~...lock`
      - `<g>/<a>/<v>/_remote.repositories`
      - `<g>/<a>/maven-metadata-local.xml`
   
   With Maven 3.9.12, the same bundle contains only the artifacts and their 
checksums.
   
   **Workaround (release build only)**
   
   ```
   -Daether.priority.VersionsMetadataGeneratorFactory=NaN
   -Daether.priority.EnhancedLocalRepositoryManagerFactory=NaN
   -Daether.syncContext.named.factory=rwlock-local
   ```
   
   **Expected.** Either:
   - keep the 3.9 behaviour of `overlay()` for a repository that is not the 
session's local repository: metadata named after the repository id, and no 
tracking or lock files written into the target directory; or
   - list this as a breaking change for maven-compat callers in the 3.10.0 
release notes, so that plugin authors can adapt.
   
   I can test a fix or a snapshot.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to