pavelhoral opened a new issue, #13390:
URL: https://github.com/apache/maven/issues/13390

   ### Affected version
   
   3.10.0
   
   ### Bug description
   
   Disclamer: I got help from ChatGPT with generating the issue description 
bellow. Our builds started failing on 
https://repo1.maven.org/maven2/org/jruby/jruby-base/9.4.2.0/jruby-base-9.4.2.0.pom
 dependency that uses `tzdata.version` property profile activation and it is 
getting activated by its own property with Maven 3.10.0.
   
   ---
   
   Maven 3.10.0 activates property-based profiles in dependency POMs when the 
activation property is declared in that POM’s own `<properties>` section.
   
   According to the [profile activation 
documentation](https://maven.apache.org/guides/introduction/introduction-to-profiles.html#properties),
 property activation uses system or CLI user properties. The documentation 
additionally mentions properties from active settings.xml profiles and the 
special packaging property. POM-defined properties should not themselves 
activate profiles.
   
   ## Reproduction
   
   Publish or install an artifact with this POM:
   
   ```xml
   <project xmlns="http://maven.apache.org/POM/4.0.0";>
     <modelVersion>4.0.0</modelVersion>
     <groupId>example</groupId>
     <artifactId>profiled-dependency</artifactId>
     <version>1.0</version>
     <packaging>pom</packaging>
   
     <properties>
       <example.enable.extra>true</example.enable.extra>
     </properties>
   
     <profiles>
       <profile>
         <id>extra-dependency</id>
         <activation>
           <property>
             <name>example.enable.extra</name>
           </property>
         </activation>
         <dependencies>
           <dependency>
             <groupId>org.apache.commons</groupId>
             <artifactId>commons-lang3</artifactId>
             <version>3.12.0</version>
           </dependency>
         </dependencies>
       </profile>
     </profiles>
   </project>
   ```
   
   Reference it from a separate consumer project:
   
   ```xml
   <project xmlns="http://maven.apache.org/POM/4.0.0";>
     <modelVersion>4.0.0</modelVersion>
     <groupId>example</groupId>
     <artifactId>consumer</artifactId>
     <version>1.0</version>
   
     <dependencies>
       <dependency>
         <groupId>example</groupId>
         <artifactId>profiled-dependency</artifactId>
         <version>1.0</version>
         <type>pom</type>
       </dependency>
     </dependencies>
   </project>
   ```
   
   Run `mvn dependency:tree` with Maven 3.9.16 and 3.10.0.
   
   
   ## Expected behavior
   
   The extra-dependency profile remains inactive. Declaring 
`example.enable.extra` inside the dependency POM should not activate it.
   
   ### Actual behavior
   
   Maven 3.10.0 makes POM-local properties available to the profile activator, 
causing the profile to activate and contribute dependencies.
   
   ### Potential cause
   
   The change appears related to the fix for 
[#13084](https://github.com/apache/maven/issues/13084), backported through 
[#13114](https://github.com/apache/maven/pull/13114).
   In 
[DefaultModelBuilder.externalActivationContext()](https://github.com/apache/maven/blob/maven-3.10.0/maven-model-builder/src/main/java/org/apache/maven/model/building/DefaultModelBuilder.java#L539-L551),
 the POM’s project properties are merged into the system properties exposed to 
the profile activator.
   This appears to introduce an additional activation source that conflicts 
with the documented semantics. The behavior is still present in maven-3.10.x.
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to