From unknown Sat Sep 13 00:38:27 2025 X-Loop: help-debbugs@gnu.org Subject: bug#55776: maven-core fails to build Resent-From: "Dr. Arne Babenhauserheide" Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Fri, 03 Jun 2022 06:07:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 55776 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: 55776@debbugs.gnu.org X-Debbugs-Original-To: bug-guix@gnu.org Received: via spool by submit@debbugs.gnu.org id=B.16542364207517 (code B ref -1); Fri, 03 Jun 2022 06:07:01 +0000 Received: (at submit) by debbugs.gnu.org; 3 Jun 2022 06:07:00 +0000 Received: from localhost ([127.0.0.1]:55012 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nx0SZ-0001xA-Mu for submit@debbugs.gnu.org; Fri, 03 Jun 2022 02:07:00 -0400 Received: from lists.gnu.org ([209.51.188.17]:43990) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nx0SV-0001wp-JR for submit@debbugs.gnu.org; Fri, 03 Jun 2022 02:06:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:51646) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nx0SV-0003Iu-AX for bug-guix@gnu.org; Fri, 03 Jun 2022 02:06:55 -0400 Received: from mout.web.de ([212.227.17.11]:45479) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nx0SO-0007n3-Fl for bug-guix@gnu.org; Fri, 03 Jun 2022 02:06:54 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=web.de; s=dbaedf251592; t=1654236405; bh=jZVpj40CdwRUwzRy5Pl8mehQqPZoPgMEMwZ2WuZm+Uc=; h=X-UI-Sender-Class:From:To:Subject:Date; b=MlOiFIDHFeJp/X5Wg3Hn9M61irVHJHESl9gdvLlgy7WipeFjCAoQSdMgpA8aBPE/j iBdVw981Np9KZk3wbAvLOsyZk3tcPyPORiauQ1i20+VUT+YJNrSJZF38mJlT92Z/Ea ZqHJ3zgyfOw1+ZkwmX19sPi1qzfeA9g9REmRl7uk= X-UI-Sender-Class: c548c8c5-30a9-4db5-a2e7-cb6cb037b8f9 Received: from fluss ([84.165.24.191]) by smtp.web.de (mrweb106 [213.165.67.124]) with ESMTPSA (Nemesis) id 1MGQC7-1o01FZ3tpV-00GpHd; Fri, 03 Jun 2022 08:06:44 +0200 User-agent: mu4e 1.6.10; emacs 28.1 From: "Dr. Arne Babenhauserheide" Date: Fri, 03 Jun 2022 08:05:02 +0200 Message-ID: <87sfomwaa6.fsf@web.de> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" X-Provags-ID: V03:K1:AKPaV2jlQQLo2rtnGxX7RLOvEjnRBiAo8U7PHEwXu7adyokWHE3 wn7XKnvn1zS1D7CMF0+1K+vDAnoJN4wyteWDcSYPvmL+g+LxZ7c6S1u5xB9c3LXFXwUuq6i LI1geBC3lbtXDcd0mCZxd+XM3w7J8G/C3bkEz3xUwTQ1lsNE+v4S8JsZyTGbWYVeU2qKLuO k6RxhNewx2UDAPZBe5DEQ== X-Spam-Flag: NO X-UI-Out-Filterresults: notjunk:1;V03:K0:KEcNjmsGctY=:68bulGeI4VhfXpRfllFX7Z /A0MEoh59XuBYDKdc/R05houi3ycVFMCKK9+QUDJJDI1i91P4QsD1kd9yZ0KZgqipEPAPDpE7 XKj8NbUaxFEnSu/aU5EIYE2PTr3OoUHQpu7igZh/wLP1sFI+hO0ZjmPsIR0Xhjfx84rWt4pEA KDrBzn/ZVWjTnQRduSMwcg81MT7QPQ5gJbE/2N5xx/BNanHupIDH/RXjsFXhByBqH78BxaHfY 2RQiDHnVn+ddSanqDCOZhqo/AaxnrsoMh9945X9g1dGzxw2y8IBtgGpJ5CxkTVMfJxuV9V0wW 2f12irmAjnftIrIsb83bzyoguViptjezuCcEwxh19PMKw0Be5vq5F4IBaUV59oear1jcER9ky i2ZrY6Ur1gsR8g8nbU+rCB33JhvM5eZAfnYNsQeMsnkfcGMS1qmUiDHCM1ZsMpBeTs1588GJ/ PQYSXmiOnxNBtklePooUgxPRK9lKZd/lzoKyZi2jGG1ttUyl+daDKHxbcO8DU58UkLku3fpcf wlA0cWwpsaRWSxfBJddFMmDNV+R5TqbNSMC6v2W+9mXbZI9oFyWPv3MIqVPSrNIpps8qxiPFk RRcHDwR/AuNdltjtSoQfZBZcakrEF9+YOuo1qLAhbJA516KtfE7Wl4X9t6GZmJBuZeffsrp5l 3zsFUEHTT8+UISdqbUQptxmOlh/oSBqrSuI86LcA/DuKq9eBsz5ol2HboK70z1lDNvu+RZMYw y19zVV0b2bNp7cobRoPRiK0S7W9n35B7vUJPBvQsvZDDWMezEBhLmFbCHbe03DN7do94ig6vC FA6M9VDSGF/9RiDjFr5Ee1Os1nqJZR/z4dRLMXZrUhAvIcb0C1N4PtO+8UOgnIUulHPgWinOS BsCYTOuHdQ7F8RaTNI2ySTI4ZnVwjcvFwbJZxwpabyltZJH+4To/PV/tHkPvl3WLJN5RSbHYA V08UxYMT9ZsuGBRcMh+C6ROBBEdK4osoiVXYhdxlrWEakcwNP+A3Hcc7thvvl/CtlVIgB5tEp vqWZNzahyq6XjrWiCsge3DzMMBO6O6TW/3u9UM5ZkMbIAk73o4/hX6oyN2nfaFSUC2G17KCn5 ymTyEuQ7vG7BpGEj0/b+qWAZS6G8D+yoF7ApvBxG6mJjqALLuPCJftvig== Received-SPF: pass client-ip=212.227.17.11; envelope-from=arne_bab@web.de; helo=mout.web.de X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, T_SPF_HELO_TEMPERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: 0.2 (/) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -2.4 (--) --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Hi, I currently cannot get maven, because maven-core fails to build. To reprodu= ce: guix shell maven Log: [mkdir] Created dir: /tmp/guix-build-maven-core-3.8.5.drv-0/apache-mave= n-3.8.5/maven-core/build/jar [jar] Building jar: /tmp/guix-build-maven-core-3.8.5.drv-0/apache-mav= en-3.8.5/maven-core/build/jar/maven-core.jar BUILD SUCCESSFUL Total time: 1 second phase `build' succeeded after 2.3 seconds starting phase `generate-metadata' SLF4J: Failed to load class "org.slf4j.impl.StaticLoggerBinder". SLF4J: Defaulting to no-operation (NOP) logger implementation SLF4J: See http://www.slf4j.org/codes.html#StaticLoggerBinder for further d= etails. [INFO] Discovered 58 component descriptors(s) Problem executing command line. Error stacktrace: java.io.IOException: Invalid input descriptor for merge: /tmp/plexus-metada= ta3957336728290309540xml --> http://xml.org/sax/features/external-general-e= ntities feature http://xml.org/sax/features/external-general-entities not s= upported for SAX driver org.codehaus.plexus.metadata.merge.Driver at org.codehaus.plexus.metadata.merge.AbstractMerger.mergeDescriptors(Unkn= own Source) at org.codehaus.plexus.metadata.DefaultMetadataGenerator.generateDescripto= r(Unknown Source) at org.codehaus.plexus.metadata.PlexusMetadataGeneratorCli.invokePlexusCom= ponent(Unknown Source) at org.codehaus.plexus.tools.cli.AbstractCli.execute(Unknown Source) at org.codehaus.plexus.tools.cli.AbstractCli.execute(Unknown Source) at org.codehaus.plexus.metadata.PlexusMetadataGeneratorCli.main(Unknown So= urce) error: in phase 'generate-metadata': uncaught exception: system-error "open-file" "~A: ~S" ("No such file or directory" "build/class= es/META-INF/plexus/components.t.xml") (2)=20 phase `generate-metadata' failed after 0.8 seconds Backtrace: 12 (primitive-load "/gnu/store/ndhm39px4lh3jrcqpkaa3ykwgji=E2=80= =A6") In guix/build/gnu-build-system.scm: 906:2 11 (gnu-build #:source _ #:outputs _ #:inputs _ #:phases . #) In ice-9/boot-9.scm: 1752:10 10 (with-exception-handler _ _ #:unwind? _ # _) In srfi/srfi-1.scm: 634:9 9 (for-each # =E2=80=A6) In ice-9/boot-9.scm: 1752:10 8 (with-exception-handler _ _ #:unwind? _ # _) In guix/build/gnu-build-system.scm: 927:23 7 (_) In ice-9/eval.scm: 619:8 6 (_ #(#(#(#) (=E2=80=A6)) = #)) 311:34 5 (_ #(#(#(#) (=E2=80=A6)) = #)) 293:34 4 (_ #(#(#) "build=E2=80=A6= ")) In ice-9/ports.scm: 450:11 3 (call-with-input-file "build/classes/META-INF/plexus/c=E2=80= =A6" =E2=80=A6) In unknown file: 2 (open-file "build/classes/META-INF/plexus/components.t=E2=80= =A6" =E2=80=A6) In ice-9/boot-9.scm: 1685:16 1 (raise-exception _ #:continuable? _) 1685:16 0 (raise-exception _ #:continuable? _) ice-9/boot-9.scm:1685:16: In procedure raise-exception: In procedure open-file: No such file or directory: "build/classes/META-INF/= plexus/components.t.xml" Best wishes, Arne =2D-=20 Unpolitisch sein hei=C3=9Ft politisch sein, ohne es zu merken. draketo.de --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQJEBAEBCAAuFiEE801qEjXQSQPNItXAE++NRSQDw+sFAmKZpPIQHGFybmVfYmFi QHdlYi5kZQAKCRAT741FJAPD60XTD/9+fOj0hcNBXk2DXHIyqQ32Qz5iB+i6mfyT WiFgUXSgEwORjucnW8boGqcm1PhQRv2VsrM4ydulVyUH/jtGvHI89GQwI8S0qslC sEHMtBs5Yx1PXQyhE5qf8YeVnbpQem+Bj6S5uWIxKCVwd38kg/VHmGVUId76wFbz sE5qfchIhfVmL8Lhp0SMCK8VCSk6mVut4ZPxBQA/FRQWBrRqjem3q2a6LdX0hWKb CC1eWEJZhMajuc4qjc3rNNmo7DlSRAk0OPZKMr/9f1bq8RZ3JxdTa+XwipKRVbvC 3ZLz+IPbB8A9mmmX2KYyxev7H2O0Hch5NezR1nxT3ZWYGaY+GqTyMvEhT0xMnIp6 Clruq9QyyMFpYnpE1aZ4jWXrXrrlDxP/o3CdHQAbsupCv2R0HDLm8nqaDsws7Buy LLwtV3Wn/wKh15l006FqN/Y+r4GqdAeiGJwMostjl13oaYwFCvX9fMdfYaR3gPF7 1Hd/ViQ5+IcI3RZSUECzwmn1FOkkxgUS449Drlh6u1+GBXP3ZcpNpICq7cJGa/oT JvTYje5PIzPxkhFU+nqDFw6C/QEskM/PNg1+9D/JXgIY5i8d3AQ3rypCrAcqF+aA 7BB9uUrJM9foKVlqry/x8USsBbaq633F9BzU+yTV2UpQXyVh18K2iap/6tf6FEmP wf+oes2fCIjEBAEBCAAuFiEE3Si95tmHXKvOSosd3M8NswvBBUgFAmKZpPQQHGFy bmVfYmFiQHdlYi5kZQAKCRDczw2zC8EFSCTIA/9MQs+4rKdD9H7NRSZWqAnLUqVw JeYsdcg9cgVg76BfhiibFnBpQAQIU2Eiiy6xIFl8wC3kkLQurmJDFIMH+4/49gK+ RT+enninAFLLcnPx+mQf2wqmnYjkqvGxlP+USc9GAIoIV3kFlAk2PEO0DLq3uDxb 3YDR+tU319j0q0TELQ== =MLHT -----END PGP SIGNATURE----- --=-=-=-- From unknown Sat Sep 13 00:38:27 2025 X-Loop: help-debbugs@gnu.org Subject: bug#55776: maven-core fails to build Resent-From: Remco van 't Veer Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Sat, 04 Jun 2022 10:26:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 55776 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: 55776@debbugs.gnu.org Cc: "Dr. Arne Babenhauserheide" Received: via spool by 55776-submit@debbugs.gnu.org id=B55776.16543383378708 (code B ref 55776); Sat, 04 Jun 2022 10:26:01 +0000 Received: (at 55776) by debbugs.gnu.org; 4 Jun 2022 10:25:37 +0000 Received: from localhost ([127.0.0.1]:57706 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nxQyO-0002GO-KE for submit@debbugs.gnu.org; Sat, 04 Jun 2022 06:25:36 -0400 Received: from out2-smtp.messagingengine.com ([66.111.4.26]:55389) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nxQyL-0002G1-Ew for 55776@debbugs.gnu.org; Sat, 04 Jun 2022 06:25:34 -0400 Received: from compute5.internal (compute5.nyi.internal [10.202.2.45]) by mailout.nyi.internal (Postfix) with ESMTP id 58DD75C00FF; Sat, 4 Jun 2022 06:25:26 -0400 (EDT) Received: from mailfrontend1 ([10.202.2.162]) by compute5.internal (MEProxy); Sat, 04 Jun 2022 06:25:26 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=remworks.net; h= cc:cc:content-type:date:date:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:sender:subject :subject:to:to; s=fm3; t=1654338326; x=1654424726; bh=teJzfJ0NsK QPdNaBRQMfJC5G44UxJFHerZTSpuK5KZ0=; b=vtlbX30a/nWfEEKhBM3g+GHABA jOYVlmfPFzjQmm3qHjQQK9D7cfUzSxOFozo4+fAbHdw1FPN+l2SRwmi7Ri4kpfiP +KLEM2ipAFrdAJ3Mi9HSwiRiwC2L8ZgRQ3Aj3N4bDaL4h3aLDZbBtnRBx1u0E9iE krNY5YOr79fAxqUyDBNMQNez/KUAvkRDW7ha+VOwiuUwM40DnC4/GXkxN/muuOj9 QDmEU6uMA0UijgncfyaE0IhRVpiNvSK44Rrchd766tTs7SHDmmxKA98vrOXbgFDC 6kLf0sswVVbKQy2rSf6buy6mynFButGe7htK0E+YH+rSxXbMTy58kBnUTRMw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:date:date:feedback-id :feedback-id:from:from:in-reply-to:in-reply-to:message-id :mime-version:references:reply-to:sender:subject:subject:to:to :x-me-proxy:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s= fm1; t=1654338326; x=1654424726; bh=teJzfJ0NsKQPdNaBRQMfJC5G44Ux JFHerZTSpuK5KZ0=; b=q5Q2f+v18Xb2fZQ2pYljMjTE/ZpKr4cokMNYRIpA3y9A RBV6ybETZI80x7GAvYICSSXDExFfPLFpgc90ocgp/7xqOltfitGtWcjvKH8/Yeie jVb7eky7GUf8hibPHn/Kev/ra+1BUZffDe7L3tCHalB+V62qTTPvnJCzNTOJwQeM 3MvH5RyMMWiRYh0/0rgGNZDL/YDZ/CEi98uyZpnAl2sm6BRv61jISqZiwXRZlRCj jPuwUgcbGu0JRIXMBLew7C3YrlYJgUYfwTcUlL5PayPTcyQTXFLO9BuW9Aa4C4lv iohuxlQoWDGs7/In9+5aA0WOgalXFd7935kqDhRDyQ== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvfedrleekgddvjecutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfghnecu uegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmdenuc fjughrpefhvfevufhfffgjkfgfgggtsehttdertddtredtnecuhfhrohhmpeftvghmtgho uchvrghnucdkthcugggvvghruceorhgvmhgtohesrhgvmhifohhrkhhsrdhnvghtqeenuc ggtffrrghtthgvrhhnpeeuheegvdeujeffjefhvefgudekvdeifeduledtgfejfeehjeff fefhheefffegieenucffohhmrghinhepgihmlhdrohhrghdpghhithhhuhgsrdgtohhmpd hhthhtphhrvghquhgvshhtrdgrthenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgr mhepmhgrihhlfhhrohhmpehrvghmtghosehrvghmfihorhhkshdrnhgvth X-ME-Proxy: Feedback-ID: i568842cc:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Sat, 4 Jun 2022 06:25:25 -0400 (EDT) From: Remco van 't Veer References: <87sfomwaa6.fsf@web.de> Date: Sat, 04 Jun 2022 12:25:21 +0200 In-Reply-To: <87sfomwaa6.fsf@web.de> (Arne Babenhauserheide's message of "Fri, 03 Jun 2022 08:05:02 +0200") Message-ID: <87wndwn2su.fsf@remworks.net> User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/28.1 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain X-Spam-Score: -0.7 (/) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.7 (-) I did some digging and found this regression is caused by commit: 6068b83b82475566acd4162467bcf54270f338f9 "gnu: java-jdom: Update to 2.0.6.1 [fixes CVE-2021-33813]." Apparently the fix for this issue causes jdom to be very strict; > java.io.IOException: Invalid input descriptor for merge: > /tmp/plexus-metadata3957336728290309540xml --> > http://xml.org/sax/features/external-general-entities feature > http://xml.org/sax/features/external-general-entities not supported > for SAX driver org.codehaus.plexus.metadata.merge.Driver Which sound familiar when looking at that CVE (https://github.com/advisories/GHSA-2363-cqg2-863c): > An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to > cause a denial of service via a crafted HTTP request. At this time > there is not released fixed version of JDOM. As a workaround, to avoid > external entities being expanded, one can call > builder.setExpandEntities(false) and they won't be expanded. I dunno how to fix this though, I'm just a curious guixer. Easiest path seems to be to make a new java-jdom-2.0.6 var and use that as a native-input for maven. Would that be an acceptable solution? Cheers, Remco From unknown Sat Sep 13 00:38:27 2025 X-Loop: help-debbugs@gnu.org Subject: bug#55776: maven-core fails to build Resent-From: Julien Lepiller Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Sat, 04 Jun 2022 13:48:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 55776 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: Remco van 't Veer Cc: "Dr. Arne Babenhauserheide" , 55776@debbugs.gnu.org Received: via spool by 55776-submit@debbugs.gnu.org id=B55776.165435043630391 (code B ref 55776); Sat, 04 Jun 2022 13:48:02 +0000 Received: (at 55776) by debbugs.gnu.org; 4 Jun 2022 13:47:16 +0000 Received: from localhost ([127.0.0.1]:57923 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nxU7Y-0007u7-6w for submit@debbugs.gnu.org; Sat, 04 Jun 2022 09:47:16 -0400 Received: from lepiller.eu ([89.234.186.109]:39120) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nxU7W-0007tw-0v for 55776@debbugs.gnu.org; Sat, 04 Jun 2022 09:47:15 -0400 Received: from lepiller.eu (localhost [127.0.0.1]) by lepiller.eu (OpenSMTPD) with ESMTP id 2dc41ba0; Sat, 4 Jun 2022 13:47:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=lepiller.eu; h=date:from :to:cc:subject:message-id:in-reply-to:references:mime-version :content-type; s=dkim; bh=4pAS9u9JREczWvjtj2QjeR4bSNF035QyBuMH/l hxIJ8=; b=Xt+yxq6/LBT5rqozSPvkzROsB0DfO0/DJ3ENusTvY4044WzV/IWJ27 Wuy9/CGpCoO4uQBm8pGaMtbTmcj61e6udvHYeyFlxy602wRgnW9c0Q+z8gM5r9fM zPzZQdV1K0BN5XGc0hxTqK0A5q98mfyDOQ4ki/K4xBsqGIehdlUN+pc+7sE3hDyX 8zDQRpnr6O5pLP/fQiMTGokyEnPwl3DTEkFKAGiZFMdSJRUX9t2N9/K+npILdHMC dXcKQBTMiGgCjK+IoLEI+qDlzsldCkg5uV/yyCeBE4YfsNnQifuJGl20ZFjFaHDX WxgOQL9ij2aYS19wxaXMv+ZA/A0GQlJQ== Received: by lepiller.eu (OpenSMTPD) with ESMTPSA id 2b5fea9e (TLSv1.3:AEAD-AES256-GCM-SHA384:256:NO); Sat, 4 Jun 2022 13:47:10 +0000 (UTC) Date: Sat, 4 Jun 2022 15:47:07 +0200 From: Julien Lepiller Message-ID: <20220604154707.099a3679@sybil.lepiller.eu> In-Reply-To: <87wndwn2su.fsf@remworks.net> References: <87sfomwaa6.fsf@web.de> <87wndwn2su.fsf@remworks.net> X-Mailer: Claws Mail 4.0.0 (GTK+ 3.24.30; x86_64-pc-linux-gnu) MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="MP_/lx+e1Iwlc1.N82XsMZ/k4VF" X-Spam-Score: -0.0 (/) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) --MP_/lx+e1Iwlc1.N82XsMZ/k4VF Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline Le Sat, 04 Jun 2022 12:25:21 +0200, Remco van 't Veer a =C3=A9crit : > I did some digging and found this regression is caused by commit: >=20 > 6068b83b82475566acd4162467bcf54270f338f9 > "gnu: java-jdom: Update to 2.0.6.1 [fixes CVE-2021-33813]." >=20 > Apparently the fix for this issue causes jdom to be very strict; >=20 > > java.io.IOException: Invalid input descriptor for merge: > > /tmp/plexus-metadata3957336728290309540xml --> > > http://xml.org/sax/features/external-general-entities feature > > http://xml.org/sax/features/external-general-entities not supported > > for SAX driver org.codehaus.plexus.metadata.merge.Driver =20 >=20 > Which sound familiar when looking at that CVE > (https://github.com/advisories/GHSA-2363-cqg2-863c): >=20 > > An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to > > cause a denial of service via a crafted HTTP request. At this time > > there is not released fixed version of JDOM. As a workaround, to > > avoid external entities being expanded, one can call > > builder.setExpandEntities(false) and they won't be expanded. =20 >=20 > I dunno how to fix this though, I'm just a curious guixer. Easiest > path seems to be to make a new java-jdom-2.0.6 var and use that as a > native-input for maven. Would that be an acceptable solution? >=20 > Cheers, > Remco >=20 Like you say, the issue is with the new jdom. Believe it or not, but between 2.0.6 and 2.0.6.1 there's some breakage (and > 1 year of changes, too)! So I figured I could fix java-plexus-component-metadata that we use to generate some xml files during the build of maven. jdom is one of its inputs. Adding another jdom to the native inputs would probably not fix the issue. What I did instead is, since jdom wants to set more features than supported in the driver, to add dummy support for all these additional features by just not throwing the exception. It's not very satisfying, but it works and we don't keep a vulnerable jdom around. With the attached patch, I built up to maven. --MP_/lx+e1Iwlc1.N82XsMZ/k4VF Content-Type: text/x-patch Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=0001-gnu-java-plexus-component-metadata-Fix-package.patch >From 2523b6c6b3f81f8a86b7c768dfed9dae97978e93 Mon Sep 17 00:00:00 2001 From: Julien Lepiller Date: Sat, 4 Jun 2022 15:41:41 +0200 Subject: [PATCH] gnu: java-plexus-component-metadata: Fix package. * gnu/packages/java.scm (java-plexus-component-metadat): Apply fix for newer jdom. --- gnu/packages/java.scm | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/gnu/packages/java.scm b/gnu/packages/java.scm index 336e84e3e5..f475f7c270 100644 --- a/gnu/packages/java.scm +++ b/gnu/packages/java.scm @@ -4537,6 +4537,14 @@ (define-public java-plexus-component-metadata-1.7 (copy-recursively "src/main/resources" "build/classes/") #t)) + (add-before 'build 'fix-jdom + (lambda _ + ;; The newer version of jdom now sets multiple features by default + ;; that are not supported. + ;; Skip these features + (substitute* "src/main/java/org/codehaus/plexus/metadata/merge/MXParser.java" + (("throw new XmlPullParserException\\(\"unsupporte feature \"\\+name\\);") + "// skip")))) (add-before 'check 'fix-test-location (lambda _ (substitute* '("src/test/java/org/codehaus/plexus/metadata/DefaultComponentDescriptorWriterTest.java" -- 2.35.1 --MP_/lx+e1Iwlc1.N82XsMZ/k4VF-- From unknown Sat Sep 13 00:38:27 2025 X-Loop: help-debbugs@gnu.org Subject: bug#55776: maven-core fails to build Resent-From: Remco van 't Veer Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Sat, 04 Jun 2022 14:26:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 55776 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: Julien Lepiller Cc: "Dr. Arne Babenhauserheide" , 55776@debbugs.gnu.org Received: via spool by 55776-submit@debbugs.gnu.org id=B55776.16543527333144 (code B ref 55776); Sat, 04 Jun 2022 14:26:02 +0000 Received: (at 55776) by debbugs.gnu.org; 4 Jun 2022 14:25:33 +0000 Received: from localhost ([127.0.0.1]:59462 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nxUib-0000oe-3T for submit@debbugs.gnu.org; Sat, 04 Jun 2022 10:25:33 -0400 Received: from wout4-smtp.messagingengine.com ([64.147.123.20]:56297) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nxUiZ-0000oO-F7 for 55776@debbugs.gnu.org; Sat, 04 Jun 2022 10:25:32 -0400 Received: from compute5.internal (compute5.nyi.internal [10.202.2.45]) by mailout.west.internal (Postfix) with ESMTP id 50AB13200413; Sat, 4 Jun 2022 10:25:25 -0400 (EDT) Received: from mailfrontend2 ([10.202.2.163]) by compute5.internal (MEProxy); Sat, 04 Jun 2022 10:25:25 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=remworks.net; h= cc:cc:content-type:date:date:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:sender:subject :subject:to:to; s=fm3; t=1654352724; x=1654439124; bh=nfcihOirUh 2QARLvYRpATgX5dQ+1/NP3gFRbSvDzx5U=; b=jXJsrjwtQa4KMUc9IQd+IuqwEq ZLPgHED1OYoFJ67YDrLbdnmJOX3A9UaC8m49lz7AYvwAz71lQ0vlfKPC2JLyGRbb RiubLXXsSBxO6aCy4E+KT8G60S+zFbmkQXjVEWuZA3qbrXiGW+/8PX8mBtiyJkky SzOeWA9zRp2MSy3NGgX4DbFWNF70OQAQDjf1rRh4DnmTAjUeomYJEaAra+DiqeXF 8M1w1l25Mni3bQzVJJmnrarXPupanxmmXaN1iOlYkqMPHSd6DW1PVNOErj0vRDFg wPzHKIRVejwQ0X6xkPPswpI2+EUFaOSF5CNKbs8vZ0UzxUBo1iQY/goXJ2gg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-type:date:date:feedback-id :feedback-id:from:from:in-reply-to:in-reply-to:message-id :mime-version:references:reply-to:sender:subject:subject:to:to :x-me-proxy:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s= fm1; t=1654352724; x=1654439124; bh=nfcihOirUh2QARLvYRpATgX5dQ+1 /NP3gFRbSvDzx5U=; b=NAyBoYlEPWrPUv1sEFQhJmnp8qcWiK/cqriXnozVoxM4 1L8Et2pR6JqlqsGskdTu32ev+tR5c3hLSr3p0EGR6vPBkyS3YSS4IIMGxgkliJCc yDtRRp1W2Z0HgvWD67trurHT98V+iH3MklbD54opVTi1t7ldiI6Y8OSL+d3HXvC2 VudhoWKDm4Pr22A4MVtJL5H/3Yo+Oz+O2ji+rMNFFZ3xpeVq56y/YpDSy/zPCWJl DiI7Oz8Y9vu4rSVdda5I5cRzMCfGpdrHaJEeDU4oJ2X7I2XqqGRDx/dJmwq2wJcK dRZjiZSIEPUhrD7I4u1vnN/fegHE1K4YNoHZclto+Q== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvfedrleekgdejiecutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfghnecu uegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmdenuc fjughrpehffgfhvfevufgjfffkgggtsehttdertddtredtnecuhfhrohhmpeftvghmtgho uchvrghnucdkthcugggvvghruceorhgvmhgtohesrhgvmhifohhrkhhsrdhnvghtqeenuc ggtffrrghtthgvrhhnpeekudevgeefudefleehvdeuvdfhueeftdetveekhefhiefgveel hfegueektdefveenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfh hrohhmpehrvghmtghosehrvghmfihorhhkshdrnhgvth X-ME-Proxy: Feedback-ID: i568842cc:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Sat, 4 Jun 2022 10:25:24 -0400 (EDT) References: <87sfomwaa6.fsf@web.de> <87wndwn2su.fsf@remworks.net> <20220604154707.099a3679@sybil.lepiller.eu> User-agent: mu4e 1.6.10; emacs 28.1 From: Remco van 't Veer In-reply-to: <20220604154707.099a3679@sybil.lepiller.eu> Date: Sat, 04 Jun 2022 16:25:23 +0200 Message-ID: <87ilpgmros.fsf@remworks.net> MIME-Version: 1.0 Content-Type: text/plain X-Spam-Score: -0.7 (/) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.7 (-) 2022/06/04 15:47, Julien Lepiller: > So I figured I could fix java-plexus-component-metadata that we use to > generate some xml files during the build of maven. jdom is one of its > inputs. Adding another jdom to the native inputs would probably not fix > the issue. Reverting the jdom upgrade patch, I did get mave-core to build. I admit I did not try running it. My interest in maven is as a dependency to clojure-tools, I don't really know how to test maven is actually working by itself. > What I did instead is, since jdom wants to set more features than > supported in the driver, to add dummy support for all these additional > features by just not throwing the exception. It's not very satisfying, > but it works and we don't keep a vulnerable jdom around. With the > attached patch, I built up to maven. Smart! I look forward to seeing your patch land in the main branch. Cheers, Remco From unknown Sat Sep 13 00:38:27 2025 X-Loop: help-debbugs@gnu.org Subject: bug#55776: maven-core fails to build Resent-From: "Dr. Arne Babenhauserheide" Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Sat, 04 Jun 2022 15:02:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 55776 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: Julien Lepiller Cc: Remco van 't Veer , 55776@debbugs.gnu.org Received: via spool by 55776-submit@debbugs.gnu.org id=B55776.16543549126689 (code B ref 55776); Sat, 04 Jun 2022 15:02:02 +0000 Received: (at 55776) by debbugs.gnu.org; 4 Jun 2022 15:01:52 +0000 Received: from localhost ([127.0.0.1]:59485 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nxVHk-0001jp-5F for submit@debbugs.gnu.org; Sat, 04 Jun 2022 11:01:52 -0400 Received: from mout.web.de ([212.227.15.3]:60503) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nxVHh-0001jb-Hy for 55776@debbugs.gnu.org; Sat, 04 Jun 2022 11:01:50 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=web.de; s=dbaedf251592; t=1654354897; bh=JqFMGRoyoZukwQpUHfcYJ2jZ77S5YyVYUKcni4OE9bA=; h=X-UI-Sender-Class:References:From:To:Cc:Subject:Date:In-reply-to; b=IQCCXuCy152s4JiLbzLoTDK7YX8va5Wwqs6APgIEEn/m0bDjGkzfMVaS9A4YFMSWO ymG5NbNbJYgtyhKYVeZCZDLcGGkrzlZUDP8Oa10s4iHKcoP81WtTHThL60Qx/NPGjw WS8KyW/ui0jAnRFcoFIUQ2wWJpT4VeH2mIWBJbug= X-UI-Sender-Class: c548c8c5-30a9-4db5-a2e7-cb6cb037b8f9 Received: from fluss ([84.165.24.191]) by smtp.web.de (mrweb005 [213.165.67.108]) with ESMTPSA (Nemesis) id 1N1Lwd-1nlibS0ofr-012dkH; Sat, 04 Jun 2022 17:01:37 +0200 References: <87sfomwaa6.fsf@web.de> <87wndwn2su.fsf@remworks.net> <20220604154707.099a3679@sybil.lepiller.eu> User-agent: mu4e 1.6.10; emacs 28.1 From: "Dr. Arne Babenhauserheide" Date: Sat, 04 Jun 2022 17:00:15 +0200 In-reply-to: <20220604154707.099a3679@sybil.lepiller.eu> Message-ID: <874k10wjzo.fsf@web.de> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" X-Provags-ID: V03:K1:msnwfUGHTY4rXCrEFsFV4Hlfo7xqMgcriWJJwNTKGAO4YpFKs+e ectCnPCWTkq8acGDaFT4t0aZb34cK1wgtN+eDkbZaaoADrcztwojQ12Ec6nwfTfTrWx3SzI TCUdZRltGUpuoVqWC++eeSuRzbIAhY9M8QZKbF2CFzLR4MXNXI2DCxp232NPPCR5yz1ibyU m4ikil6RWNVE32mmoTmbw== X-Spam-Flag: NO X-UI-Out-Filterresults: notjunk:1;V03:K0:FllMIYTgs5Q=:bacDn/lOwPN8qROgaOWP2n O3vs2jc8UtBQ0uaxpo5cLNWP9Iys/A9nkvEBgKhPJRllmHBzpA1m7FQUELUky+cgTzaYsYOsL eb/z7LfhhWuncbUOan4Mi6kc3fAtK9q2lAZTksT5i3ir5m/CxKrvoZUgPZFR9eDq4uVnDEP3e XW/8An84YMKTS3HDMdEskK/6m4eAU7tsqdOn46f0quY3E3QyesZzo4736V7pXFS5TjxnYnamX 78Vx9Qy4c96uKhQRMPvr4/BCFmKKxQ2omszCv9TY9xVSBuGaB+vfrq8DDVKouJKMlW+gqyy7o b1dBNMjmuRJ9o9HkTGa+Szgu1mb/N//gGh23u4I5zDy4zQdem4hNfTeT8M++/1i8HEu8sWkzJ Bgp/Esea1IMBYlgUzSnhtXBXbP/9VmYEZ5juCJWb/8Yke1Lq8INrNC215AkzBwlMTRkWc2DVf hO2HBypvgMjS0WmMyfEqP7GUdv+ovr5RQ1JI2p0b0/108SyyaXiR4/9Rd1KD2Kc9w+0U77tap EDtRR80XcRaHv8pJAmnVGFnAV9rKG8xPIP2z9UA+XHxUwxB09OXcUw4sukNqtaEd216KUR8+B Ea5xvFzamas15NqfHJOTTkn9OHu1GMs9qi2klcH3vKPAnb/s2/XdRFpE5UHfir07CPN19oCpm IfCTiVj6cez6idopJi+H+wguGjP6GgJALpWHvWYl/LHneE7qpDZ3e1zA009ADiLcMUt4QK48A G0A3ZkYhYtp7q8SFIudWnOdWajZjpHFphnOkJvijBxx9XGF4w5DCHgIOmLaYlkIEqk1txzH4o L7yWE4OVqiuRXu9QVdejJbx+EkZIhpvJzh7Ot1oO6vci4n6LTjXqwuqc1ETxo/QFx5FJGLYVP 6uyjOcQKjWh4i5I0rpg4ywAJOI1T+mB6PyKEM4dLu4D6RuLc+HwoCU/W8BA2DQJqx94zea3Re YjUIICKe2GLMZisL+TkYDwTc1rius5rG4BQf57HW1Y104CZtojm3IQ2srvDct/kGhYzTIq0V6 px7cmswXyskIqWrbi+T7slMuImnB3osVCNopVHm7e5FRh2iQpcKWI9iuN+LBpVxu+BY0Bic7k DCI/iYbuKskXRi8aULg9mO5PtYFEYKMXzsLmOGLVSE4NvGdpiBMrh/hpw== X-Spam-Score: -0.7 (/) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.7 (-) --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Julien Lepiller writes: > What I did instead is, since jdom wants to set more features than > supported in the driver, to add dummy support for all these additional > features by just not throwing the exception. It's not very satisfying, > but it works and we don't keep a vulnerable jdom around. With the > attached patch, I built up to maven. Thank you! The patch looks clear enough =E2=80=94 will you push it? Best wishes, Arne =2D-=20 Unpolitisch sein hei=C3=9Ft politisch sein, ohne es zu merken. draketo.de --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQJEBAEBCAAuFiEE801qEjXQSQPNItXAE++NRSQDw+sFAmKbc84QHGFybmVfYmFi QHdlYi5kZQAKCRAT741FJAPD66+aD/9SDSDPtF7IUW0YkR61OPe2YhD6Igjr6xP9 tsepi77lvFvg0o8yrJZ9Q0J8dr3Tyx6Qeal5FqvLjl9QsoazxRTHVmrxbtoTBCxH 3XXrJvWuCG1EwQvIqtoYcC7ZuXP5dJl5tDzF/eL7BELFePsGdfxSfZFhdWl+QJSr Wsj+xnyMtgbLVWj38mhZ6AKCu/7afoQLYmw11UyI6AdkeqRYqxyAUh0EeO34y3oT glE/ycpgV9bfRPiEEwR0yWgec9WVkRK34tuDq4PsRcELv+q6OIp0qdb8cKNXtdkq 1DBJWa6t0ChJP6olblyTLg3Gd+qwDz+z/5spzklnRmId0gvTA1KFuIHiPZ6y4qWX koZOTnxkofGITvJJ+LjoLlNbHm3p27MZ22jdi20HqURFqORQ7VVkh1+YQv6/w0Ro pnX1otsHFx0dOlfa0nkmSKw4S+hSeXckdmn3aeS0M2b0e7iktvnrMNRxRUDFeNut g27tK9/s7OkD0mHv78mEZXFkKCpdT+GDPp4oL76YN4otFCi/XL0tOKuIKrevKeKn Fc7IjFX1UXeHDN09h50AO5xkZOqSEdFHH2UKPixoTAv0Kk8ihIDsxdYcJKdx30at TWlHhJGPJA6dSFlZGeRYDuk2DJkYP0BJrYgVUKTqQ0BM7QQr1GcHvmjV9dEcDXJX +zF+yswPrYjEBAEBCAAuFiEE3Si95tmHXKvOSosd3M8NswvBBUgFAmKbc84QHGFy bmVfYmFiQHdlYi5kZQAKCRDczw2zC8EFSKWQA/4wNLk21LzFn33OAMa0zl5KTWC3 bAtS5eX8DRcDYz9+nvJNCG4Fmi2xu5Pi3lDC5lZGC2Pq5M2j6rG19AamIEBP4Sv1 gZdJwdphR/sjSvwyV6hi74eX6UkXc3Wk3Ls8aEjCybO45zReDRFvNOuvgCjS6fur XkSEgJewhy7hqPf1/w== =3IXP -----END PGP SIGNATURE----- --=-=-=-- From unknown Sat Sep 13 00:38:27 2025 X-Loop: help-debbugs@gnu.org Subject: bug#55776: maven-core fails to build References: <87sfomwaa6.fsf@web.de> In-Reply-To: <87sfomwaa6.fsf@web.de> Resent-From: Steve George Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Tue, 07 Jun 2022 14:33:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 55776 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: 55776@debbugs.gnu.org Received: via spool by 55776-submit@debbugs.gnu.org id=B55776.165461233428983 (code B ref 55776); Tue, 07 Jun 2022 14:33:01 +0000 Received: (at 55776) by debbugs.gnu.org; 7 Jun 2022 14:32:14 +0000 Received: from localhost ([127.0.0.1]:41090 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nyaFh-0007Wn-Hs for submit@debbugs.gnu.org; Tue, 07 Jun 2022 10:32:14 -0400 Received: from mailtransmit05.runbox.com ([185.226.149.38]:38406) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nyWW5-0006LG-VV for 55776@debbugs.gnu.org; Tue, 07 Jun 2022 06:32:54 -0400 Received: from mailtransmit03.runbox ([10.9.9.163] helo=aibo.runbox.com) by mailtransmit05.runbox.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.93) (envelope-from ) id 1nyWVz-00D7OF-E4 for 55776@debbugs.gnu.org; Tue, 07 Jun 2022 12:32:47 +0200 Received: from [10.9.9.72] (helo=submission01.runbox) by mailtransmit03.runbox with esmtp (Exim 4.86_2) (envelope-from ) id 1nyWVy-0005i1-T2 for 55776@debbugs.gnu.org; Tue, 07 Jun 2022 12:32:47 +0200 Received: by submission01.runbox with esmtpsa [Authenticated ID (641962)] (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) id 1nyWVf-0006ez-1n for 55776@debbugs.gnu.org; Tue, 07 Jun 2022 12:32:27 +0200 Message-ID: <22246d27-ce50-4361-4bb9-cd5065c76269@futurile.net> Date: Tue, 7 Jun 2022 10:32:26 +0000 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Thunderbird/91.9.1 Content-Language: en-US From: Steve George Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Spam-Score: -0.0 (/) X-Mailman-Approved-At: Tue, 07 Jun 2022 10:32:13 -0400 X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) Hi, I was able to build java-plexus-component-metadata using this patch, and from there maven to clojure-tools. Cheers, Futurile From unknown Sat Sep 13 00:38:27 2025 X-Loop: help-debbugs@gnu.org Subject: bug#55776: maven-core fails to build Resent-From: Andrew Tropin Original-Sender: "Debbugs-submit" Resent-CC: bug-guix@gnu.org Resent-Date: Wed, 08 Jun 2022 15:37:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 55776 X-GNU-PR-Package: guix X-GNU-PR-Keywords: To: Julien Lepiller , Remco van 't Veer Cc: "Dr. Arne Babenhauserheide" , 55776@debbugs.gnu.org Received: via spool by 55776-submit@debbugs.gnu.org id=B55776.165470257227106 (code B ref 55776); Wed, 08 Jun 2022 15:37:02 +0000 Received: (at 55776) by debbugs.gnu.org; 8 Jun 2022 15:36:12 +0000 Received: from localhost ([127.0.0.1]:44015 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nyxj9-000737-K0 for submit@debbugs.gnu.org; Wed, 08 Jun 2022 11:36:11 -0400 Received: from relay12.mail.gandi.net ([217.70.178.232]:48247) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nyxj5-00072a-CF for 55776@debbugs.gnu.org; Wed, 08 Jun 2022 11:36:10 -0400 Received: (Authenticated sender: andrew@trop.in) by mail.gandi.net (Postfix) with ESMTPSA id 3FAC220000C; Wed, 8 Jun 2022 15:35:58 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trop.in; s=gm1; t=1654702561; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=2+Ae+iXlv21+7Z4EYIJ6RgWNOJGQMe+c6TU3yb9h8yc=; b=bWW0zEkhw3U1jS87IGmE9yBAwa1dh8tkDDIgQP+7wlXE3y7d6bZ/ShAbOOQs6wcdetjmKp pGaBWReYziALnwaZ+Q4Fl9cL67XfsF8XWMEgyzcFWPhYqaTtHzQqhr1+x4k048uPQhgU7c q3LGLQUSWpwAAKLaWugtD5/OkPfPDOZhPqUPWMK1OCJ9nwYDLoGnFkPK2gzgRE2P5aJgz0 50h8S1aSpq5NzZ8fbGGbw6rfSgo3AhaKe/aViplrcg16xCvt8PraWKgmbMXcP4J50VhuN6 4Qnb/xrMxisVqMV/Bp2cTgP+FpiFyx6yCtw7wH0b9j43jRwv1QIqc82nnci+dw== From: Andrew Tropin In-Reply-To: <20220604154707.099a3679@sybil.lepiller.eu> References: <87sfomwaa6.fsf@web.de> <87wndwn2su.fsf@remworks.net> <20220604154707.099a3679@sybil.lepiller.eu> Date: Wed, 08 Jun 2022 18:35:54 +0300 Message-ID: <87k09r9nhh.fsf@trop.in> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" X-Spam-Score: -0.7 (/) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.7 (-) --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable On 2022-06-04 15:47, Julien Lepiller wrote: > Le Sat, 04 Jun 2022 12:25:21 +0200, > Remco van 't Veer a =C3=A9crit : > >> I did some digging and found this regression is caused by commit: >>=20 >> 6068b83b82475566acd4162467bcf54270f338f9 >> "gnu: java-jdom: Update to 2.0.6.1 [fixes CVE-2021-33813]." >>=20 >> Apparently the fix for this issue causes jdom to be very strict; >>=20 >> > java.io.IOException: Invalid input descriptor for merge: >> > /tmp/plexus-metadata3957336728290309540xml --> >> > http://xml.org/sax/features/external-general-entities feature >> > http://xml.org/sax/features/external-general-entities not supported >> > for SAX driver org.codehaus.plexus.metadata.merge.Driver=20=20 >>=20 >> Which sound familiar when looking at that CVE >> (https://github.com/advisories/GHSA-2363-cqg2-863c): >>=20 >> > An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to >> > cause a denial of service via a crafted HTTP request. At this time >> > there is not released fixed version of JDOM. As a workaround, to >> > avoid external entities being expanded, one can call >> > builder.setExpandEntities(false) and they won't be expanded.=20=20 >>=20 >> I dunno how to fix this though, I'm just a curious guixer. Easiest >> path seems to be to make a new java-jdom-2.0.6 var and use that as a >> native-input for maven. Would that be an acceptable solution? >>=20 >> Cheers, >> Remco >>=20 > > Like you say, the issue is with the new jdom. Believe it or not, but > between 2.0.6 and 2.0.6.1 there's some breakage (and > 1 year of > changes, too)! > > So I figured I could fix java-plexus-component-metadata that we use to > generate some xml files during the build of maven. jdom is one of its > inputs. Adding another jdom to the native inputs would probably not fix > the issue. > > What I did instead is, since jdom wants to set more features than > supported in the driver, to add dummy support for all these additional > features by just not throwing the exception. It's not very satisfying, > but it works and we don't keep a vulnerable jdom around. With the > attached patch, I built up to maven. > From 2523b6c6b3f81f8a86b7c768dfed9dae97978e93 Mon Sep 17 00:00:00 2001 > From: Julien Lepiller > Date: Sat, 4 Jun 2022 15:41:41 +0200 > Subject: [PATCH] gnu: java-plexus-component-metadata: Fix package. > > * gnu/packages/java.scm (java-plexus-component-metadat): Apply fix for > newer jdom. > --- > gnu/packages/java.scm | 8 ++++++++ > 1 file changed, 8 insertions(+) > > diff --git a/gnu/packages/java.scm b/gnu/packages/java.scm > index 336e84e3e5..f475f7c270 100644 > --- a/gnu/packages/java.scm > +++ b/gnu/packages/java.scm > @@ -4537,6 +4537,14 @@ (define-public java-plexus-component-metadata-1.7 > (copy-recursively "src/main/resources" > "build/classes/") > #t)) > + (add-before 'build 'fix-jdom > + (lambda _ > + ;; The newer version of jdom now sets multiple features by = default > + ;; that are not supported. > + ;; Skip these features > + (substitute* "src/main/java/org/codehaus/plexus/metadata/me= rge/MXParser.java" > + (("throw new XmlPullParserException\\(\"unsupporte featur= e \"\\+name\\);") > + "// skip")))) > (add-before 'check 'fix-test-location > (lambda _ > (substitute* '("src/test/java/org/codehaus/plexus/metadata/= DefaultComponentDescriptorWriterTest.java" Work for me as well. Probably can be merged to master? =2D-=20 Best regards, Andrew Tropin --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKEGaxlA4dEDH6S/6IgjSCVjB3rAFAmKgwdoACgkQIgjSCVjB 3rDO6BAAgMtp7Te99O5ICVD+/T9IhnRlc26T4TfBPgzTyzeS1Lgl7rFsFMNJsaUa MiOyA1Dg3xoi6XD/CTtoYmTNfrn/J//sspwbZGlt5vyhZOU65OKeuNltPe2RtNzX KNmgVMN9HUwK7srXVSQmcmsU9MX5Vpdtt8QRg8P3hCI9pdH5o4DUUByLhyR4lITF 3/v2jdHVeKHe1cJy7s+imSFw/A9xJeyFDqhUx8r+AQwHHFby6RLhEYTDgrSQluE9 B7C/jpBs62uFQ2YPyTit2oZ2G9nTKUivs6CLDkOdi/dgNKkqI0LY1R6IraTdK7+H ArSwxJhf+1EiR7JLqHbWJc0+z567+1VayHZrQiF2UGgTOQ4psPwIgDl9AxJyRQfn qQ5lzDyJx+q0FgvTbLuhK3QwbY72Agq5vGYQBuofBSiekvl5FiM8wg5n154hjvCh fm1pW9RZPoTj5d0cI8Hg0UT61lIEM9JWCMnqIuFE6/WHgPJUFVIdi2UofiPmlir0 CtOOKdrPikI1V3pX98VubWcJsOyotw4YcfSaOna6SEpIHNf17yGc6K5B9Fd2ulVo 2kNTMImi2eUHsvj/VssFXs2oc6Bkd16aCI4CcZC/ptX7ulIiPP6WdEE/rORrJnRQ Va2RxCMSr8+vRkA0IaUPLzCGEb5faa1XSU8DSc9E4tZ0ljPt4KQ= =I+wN -----END PGP SIGNATURE----- --=-=-=-- From unknown Sat Sep 13 00:38:27 2025 MIME-Version: 1.0 X-Mailer: MIME-tools 5.505 (Entity 5.505) X-Loop: help-debbugs@gnu.org From: help-debbugs@gnu.org (GNU bug Tracking System) To: "Dr. Arne Babenhauserheide" Subject: bug#55776: closed (Re: bug#55776: maven-core fails to build) Message-ID: References: <20220608203627.724d3682@sybil.lepiller.eu> <87sfomwaa6.fsf@web.de> X-Gnu-PR-Message: they-closed 55776 X-Gnu-PR-Package: guix Reply-To: 55776@debbugs.gnu.org Date: Wed, 08 Jun 2022 18:37:01 +0000 Content-Type: multipart/mixed; boundary="----------=_1654713421-6004-1" This is a multi-part message in MIME format... ------------=_1654713421-6004-1 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Your bug report #55776: maven-core fails to build which was filed against the guix package, has been closed. The explanation is attached below, along with your original report. If you require more details, please reply to 55776@debbugs.gnu.org. --=20 55776: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=3D55776 GNU Bug Tracking System Contact help-debbugs@gnu.org with problems ------------=_1654713421-6004-1 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at 55776-done) by debbugs.gnu.org; 8 Jun 2022 18:36:37 +0000 Received: from localhost ([127.0.0.1]:44283 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nz0Xk-0001YD-RO for submit@debbugs.gnu.org; Wed, 08 Jun 2022 14:36:37 -0400 Received: from lepiller.eu ([89.234.186.109]:39656) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nz0Xf-0001Xx-Fy for 55776-done@debbugs.gnu.org; Wed, 08 Jun 2022 14:36:35 -0400 Received: from lepiller.eu (localhost [127.0.0.1]) by lepiller.eu (OpenSMTPD) with ESMTP id 722b2389; Wed, 8 Jun 2022 18:36:29 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=lepiller.eu; h=date:from :to:cc:subject:message-id:in-reply-to:references:mime-version :content-type:content-transfer-encoding; s=dkim; bh=PquS2RHBHD8I eEjRvl57UWc7foEfTI5BmLzmpvYDns4=; b=MlGmKKQonnx4bo4Ysq6QRsg0cO3E JQ0UrMqe9bhqX6kL8/HRZ74d92a5ZJonpO+Ze5mwJK4mCyPvaF74sLsT0tVejSGG jkBBqL+4eONLfM1dssgR4u4U0xHT0QjrGZZKFEeAB9lsBKmpS9TFyZf0jCI9KhgS ZH2GPyflZo9A5gfKOJzLjwBvKvbvdr5gr2XARrMBSDooWStAxuXCicz7+U7/hbU6 Ng1LylnzckRwAWO7EvXKfrTY9mtOZ4dzMRWxlfp1a/N487FDjgKAjkxR6umaECeI PQZU30mtAdXwChxj122Dzm6b5+wGMUq4TFQ+bAinMdskg/nyC3Xz39Mjew== Received: by lepiller.eu (OpenSMTPD) with ESMTPSA id 8941b145 (TLSv1.3:AEAD-AES256-GCM-SHA384:256:NO); Wed, 8 Jun 2022 18:36:29 +0000 (UTC) Date: Wed, 8 Jun 2022 20:36:27 +0200 From: Julien Lepiller To: "Dr. Arne Babenhauserheide" Subject: Re: bug#55776: maven-core fails to build Message-ID: <20220608203627.724d3682@sybil.lepiller.eu> In-Reply-To: <874k10wjzo.fsf@web.de> References: <87sfomwaa6.fsf@web.de> <87wndwn2su.fsf@remworks.net> <20220604154707.099a3679@sybil.lepiller.eu> <874k10wjzo.fsf@web.de> X-Mailer: Claws Mail 4.0.0 (GTK+ 3.24.30; x86_64-pc-linux-gnu) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-Spam-Score: -0.0 (/) X-Debbugs-Envelope-To: 55776-done Cc: Remco van 't Veer , 55776-done@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) Le Sat, 04 Jun 2022 17:00:15 +0200, "Dr. Arne Babenhauserheide" a =C3=A9crit : > Julien Lepiller writes: > > What I did instead is, since jdom wants to set more features than > > supported in the driver, to add dummy support for all these > > additional features by just not throwing the exception. It's not > > very satisfying, but it works and we don't keep a vulnerable jdom > > around. With the attached patch, I built up to maven. =20 >=20 > Thank you! >=20 > The patch looks clear enough =E2=80=94 will you push it? >=20 > Best wishes, > Arne Pushed to master as f0d9248267dabd2feb5c004d6e4610cbdf3e5b87, thanks for testing it :) ------------=_1654713421-6004-1 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by debbugs.gnu.org; 3 Jun 2022 06:07:00 +0000 Received: from localhost ([127.0.0.1]:55012 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nx0SZ-0001xA-Mu for submit@debbugs.gnu.org; Fri, 03 Jun 2022 02:07:00 -0400 Received: from lists.gnu.org ([209.51.188.17]:43990) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1nx0SV-0001wp-JR for submit@debbugs.gnu.org; Fri, 03 Jun 2022 02:06:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:51646) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nx0SV-0003Iu-AX for bug-guix@gnu.org; Fri, 03 Jun 2022 02:06:55 -0400 Received: from mout.web.de ([212.227.17.11]:45479) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nx0SO-0007n3-Fl for bug-guix@gnu.org; Fri, 03 Jun 2022 02:06:54 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=web.de; s=dbaedf251592; t=1654236405; bh=jZVpj40CdwRUwzRy5Pl8mehQqPZoPgMEMwZ2WuZm+Uc=; h=X-UI-Sender-Class:From:To:Subject:Date; b=MlOiFIDHFeJp/X5Wg3Hn9M61irVHJHESl9gdvLlgy7WipeFjCAoQSdMgpA8aBPE/j iBdVw981Np9KZk3wbAvLOsyZk3tcPyPORiauQ1i20+VUT+YJNrSJZF38mJlT92Z/Ea ZqHJ3zgyfOw1+ZkwmX19sPi1qzfeA9g9REmRl7uk= X-UI-Sender-Class: c548c8c5-30a9-4db5-a2e7-cb6cb037b8f9 Received: from fluss ([84.165.24.191]) by smtp.web.de (mrweb106 [213.165.67.124]) with ESMTPSA (Nemesis) id 1MGQC7-1o01FZ3tpV-00GpHd; Fri, 03 Jun 2022 08:06:44 +0200 User-agent: mu4e 1.6.10; emacs 28.1 From: "Dr. Arne Babenhauserheide" To: bug-guix@gnu.org Subject: maven-core fails to build Date: Fri, 03 Jun 2022 08:05:02 +0200 Message-ID: <87sfomwaa6.fsf@web.de> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha256; protocol="application/pgp-signature" X-Provags-ID: V03:K1:AKPaV2jlQQLo2rtnGxX7RLOvEjnRBiAo8U7PHEwXu7adyokWHE3 wn7XKnvn1zS1D7CMF0+1K+vDAnoJN4wyteWDcSYPvmL+g+LxZ7c6S1u5xB9c3LXFXwUuq6i LI1geBC3lbtXDcd0mCZxd+XM3w7J8G/C3bkEz3xUwTQ1lsNE+v4S8JsZyTGbWYVeU2qKLuO k6RxhNewx2UDAPZBe5DEQ== X-Spam-Flag: NO X-UI-Out-Filterresults: notjunk:1;V03:K0:KEcNjmsGctY=:68bulGeI4VhfXpRfllFX7Z /A0MEoh59XuBYDKdc/R05houi3ycVFMCKK9+QUDJJDI1i91P4QsD1kd9yZ0KZgqipEPAPDpE7 XKj8NbUaxFEnSu/aU5EIYE2PTr3OoUHQpu7igZh/wLP1sFI+hO0ZjmPsIR0Xhjfx84rWt4pEA KDrBzn/ZVWjTnQRduSMwcg81MT7QPQ5gJbE/2N5xx/BNanHupIDH/RXjsFXhByBqH78BxaHfY 2RQiDHnVn+ddSanqDCOZhqo/AaxnrsoMh9945X9g1dGzxw2y8IBtgGpJ5CxkTVMfJxuV9V0wW 2f12irmAjnftIrIsb83bzyoguViptjezuCcEwxh19PMKw0Be5vq5F4IBaUV59oear1jcER9ky i2ZrY6Ur1gsR8g8nbU+rCB33JhvM5eZAfnYNsQeMsnkfcGMS1qmUiDHCM1ZsMpBeTs1588GJ/ PQYSXmiOnxNBtklePooUgxPRK9lKZd/lzoKyZi2jGG1ttUyl+daDKHxbcO8DU58UkLku3fpcf wlA0cWwpsaRWSxfBJddFMmDNV+R5TqbNSMC6v2W+9mXbZI9oFyWPv3MIqVPSrNIpps8qxiPFk RRcHDwR/AuNdltjtSoQfZBZcakrEF9+YOuo1qLAhbJA516KtfE7Wl4X9t6GZmJBuZeffsrp5l 3zsFUEHTT8+UISdqbUQptxmOlh/oSBqrSuI86LcA/DuKq9eBsz5ol2HboK70z1lDNvu+RZMYw y19zVV0b2bNp7cobRoPRiK0S7W9n35B7vUJPBvQsvZDDWMezEBhLmFbCHbe03DN7do94ig6vC FA6M9VDSGF/9RiDjFr5Ee1Os1nqJZR/z4dRLMXZrUhAvIcb0C1N4PtO+8UOgnIUulHPgWinOS BsCYTOuHdQ7F8RaTNI2ySTI4ZnVwjcvFwbJZxwpabyltZJH+4To/PV/tHkPvl3WLJN5RSbHYA V08UxYMT9ZsuGBRcMh+C6ROBBEdK4osoiVXYhdxlrWEakcwNP+A3Hcc7thvvl/CtlVIgB5tEp vqWZNzahyq6XjrWiCsge3DzMMBO6O6TW/3u9UM5ZkMbIAk73o4/hX6oyN2nfaFSUC2G17KCn5 ymTyEuQ7vG7BpGEj0/b+qWAZS6G8D+yoF7ApvBxG6mJjqALLuPCJftvig== Received-SPF: pass client-ip=212.227.17.11; envelope-from=arne_bab@web.de; helo=mout.web.de X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, T_SPF_HELO_TEMPERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: 0.2 (/) X-Debbugs-Envelope-To: submit X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -2.4 (--) --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Hi, I currently cannot get maven, because maven-core fails to build. To reprodu= ce: guix shell maven Log: [mkdir] Created dir: /tmp/guix-build-maven-core-3.8.5.drv-0/apache-mave= n-3.8.5/maven-core/build/jar [jar] Building jar: /tmp/guix-build-maven-core-3.8.5.drv-0/apache-mav= en-3.8.5/maven-core/build/jar/maven-core.jar BUILD SUCCESSFUL Total time: 1 second phase `build' succeeded after 2.3 seconds starting phase `generate-metadata' SLF4J: Failed to load class "org.slf4j.impl.StaticLoggerBinder". SLF4J: Defaulting to no-operation (NOP) logger implementation SLF4J: See http://www.slf4j.org/codes.html#StaticLoggerBinder for further d= etails. [INFO] Discovered 58 component descriptors(s) Problem executing command line. Error stacktrace: java.io.IOException: Invalid input descriptor for merge: /tmp/plexus-metada= ta3957336728290309540xml --> http://xml.org/sax/features/external-general-e= ntities feature http://xml.org/sax/features/external-general-entities not s= upported for SAX driver org.codehaus.plexus.metadata.merge.Driver at org.codehaus.plexus.metadata.merge.AbstractMerger.mergeDescriptors(Unkn= own Source) at org.codehaus.plexus.metadata.DefaultMetadataGenerator.generateDescripto= r(Unknown Source) at org.codehaus.plexus.metadata.PlexusMetadataGeneratorCli.invokePlexusCom= ponent(Unknown Source) at org.codehaus.plexus.tools.cli.AbstractCli.execute(Unknown Source) at org.codehaus.plexus.tools.cli.AbstractCli.execute(Unknown Source) at org.codehaus.plexus.metadata.PlexusMetadataGeneratorCli.main(Unknown So= urce) error: in phase 'generate-metadata': uncaught exception: system-error "open-file" "~A: ~S" ("No such file or directory" "build/class= es/META-INF/plexus/components.t.xml") (2)=20 phase `generate-metadata' failed after 0.8 seconds Backtrace: 12 (primitive-load "/gnu/store/ndhm39px4lh3jrcqpkaa3ykwgji=E2=80= =A6") In guix/build/gnu-build-system.scm: 906:2 11 (gnu-build #:source _ #:outputs _ #:inputs _ #:phases . #) In ice-9/boot-9.scm: 1752:10 10 (with-exception-handler _ _ #:unwind? _ # _) In srfi/srfi-1.scm: 634:9 9 (for-each # =E2=80=A6) In ice-9/boot-9.scm: 1752:10 8 (with-exception-handler _ _ #:unwind? _ # _) In guix/build/gnu-build-system.scm: 927:23 7 (_) In ice-9/eval.scm: 619:8 6 (_ #(#(#(#) (=E2=80=A6)) = #)) 311:34 5 (_ #(#(#(#) (=E2=80=A6)) = #)) 293:34 4 (_ #(#(#) "build=E2=80=A6= ")) In ice-9/ports.scm: 450:11 3 (call-with-input-file "build/classes/META-INF/plexus/c=E2=80= =A6" =E2=80=A6) In unknown file: 2 (open-file "build/classes/META-INF/plexus/components.t=E2=80= =A6" =E2=80=A6) In ice-9/boot-9.scm: 1685:16 1 (raise-exception _ #:continuable? _) 1685:16 0 (raise-exception _ #:continuable? _) ice-9/boot-9.scm:1685:16: In procedure raise-exception: In procedure open-file: No such file or directory: "build/classes/META-INF/= plexus/components.t.xml" Best wishes, Arne =2D-=20 Unpolitisch sein hei=C3=9Ft politisch sein, ohne es zu merken. draketo.de --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQJEBAEBCAAuFiEE801qEjXQSQPNItXAE++NRSQDw+sFAmKZpPIQHGFybmVfYmFi QHdlYi5kZQAKCRAT741FJAPD60XTD/9+fOj0hcNBXk2DXHIyqQ32Qz5iB+i6mfyT WiFgUXSgEwORjucnW8boGqcm1PhQRv2VsrM4ydulVyUH/jtGvHI89GQwI8S0qslC sEHMtBs5Yx1PXQyhE5qf8YeVnbpQem+Bj6S5uWIxKCVwd38kg/VHmGVUId76wFbz sE5qfchIhfVmL8Lhp0SMCK8VCSk6mVut4ZPxBQA/FRQWBrRqjem3q2a6LdX0hWKb CC1eWEJZhMajuc4qjc3rNNmo7DlSRAk0OPZKMr/9f1bq8RZ3JxdTa+XwipKRVbvC 3ZLz+IPbB8A9mmmX2KYyxev7H2O0Hch5NezR1nxT3ZWYGaY+GqTyMvEhT0xMnIp6 Clruq9QyyMFpYnpE1aZ4jWXrXrrlDxP/o3CdHQAbsupCv2R0HDLm8nqaDsws7Buy LLwtV3Wn/wKh15l006FqN/Y+r4GqdAeiGJwMostjl13oaYwFCvX9fMdfYaR3gPF7 1Hd/ViQ5+IcI3RZSUECzwmn1FOkkxgUS449Drlh6u1+GBXP3ZcpNpICq7cJGa/oT JvTYje5PIzPxkhFU+nqDFw6C/QEskM/PNg1+9D/JXgIY5i8d3AQ3rypCrAcqF+aA 7BB9uUrJM9foKVlqry/x8USsBbaq633F9BzU+yTV2UpQXyVh18K2iap/6tf6FEmP wf+oes2fCIjEBAEBCAAuFiEE3Si95tmHXKvOSosd3M8NswvBBUgFAmKZpPQQHGFy bmVfYmFiQHdlYi5kZQAKCRDczw2zC8EFSCTIA/9MQs+4rKdD9H7NRSZWqAnLUqVw JeYsdcg9cgVg76BfhiibFnBpQAQIU2Eiiy6xIFl8wC3kkLQurmJDFIMH+4/49gK+ RT+enninAFLLcnPx+mQf2wqmnYjkqvGxlP+USc9GAIoIV3kFlAk2PEO0DLq3uDxb 3YDR+tU319j0q0TELQ== =MLHT -----END PGP SIGNATURE----- --=-=-=-- ------------=_1654713421-6004-1--