Sitelet https://github.com/apache/maven/pull/13149
Skip to content

Normalize lazy StAX parse failures in MavenXpp3Reader (backport of #13117 to maven-4.0.x) - #13149

Merged
gnodet merged 1 commit into
apache:maven-4.0.xfrom
gnodet:backport/13117-to-4.0.x
Sep 15, 2026
Merged

gnodet merged 1 commit into
apache:maven-4.0.xfrom
gnodet:backport/13117-to-4.0.x

Conversation

@gnodet

@gnodet gnodet commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Backport of #13117 to the maven-4.0.x branch.

Cherry-pick of 030cb93, applied cleanly with no conflicts.

* Normalize lazy StAX parse failures in MavenXpp3Reader

Woodstox can defer malformed character-reference errors until text access and wrap the XMLStreamException in a runtime exception. MavenXpp3Reader currently translates only directly thrown XMLStreamException values, allowing the lazy wrapper to escape the declared XmlPullParserException contract.

Translate runtime exceptions whose cause is an XMLStreamException while preserving unrelated runtime failures. Add regression coverage for both Reader and InputStream paths.

Signed-off-by: Robert McConnell <robert@mcc0nnell.org>

* Extend lazy StAX exception fix to SettingsXpp3Reader, MetadataXpp3Reader, MavenToolchainsXpp3Reader

Same WstxLazyException escape path exists in all four compat readers.
Also strengthen the test to assert the cause is an XMLStreamException.

* Extend RuntimeException guard to XMLStreamReader overloads in Settings/MetadataXpp3Reader

---------

Signed-off-by: Robert McConnell <robert@mcc0nnell.org>
Co-authored-by: Guillaume Nodet <gnodet@gmail.com>
@gnodet gnodet added the bug Something isn't working label Sep 15, 2026
@gnodet gnodet added this to the 4.0.0-rc-7 milestone Sep 15, 2026

@gnodet-bot gnodet-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clean backport of #13117 to maven-4.0.x (cherry-pick of 030cb93, applied without conflicts).

The fix is structurally identical to the approved original:

  • MavenXpp3Reader: both Reader and InputStream read() overloads patched
  • MetadataXpp3Reader / SettingsXpp3Reader: Reader, InputStream, and XMLStreamReader overloads all covered (5 overloads each)
  • MavenToolchainsXpp3Reader: one patch on read(Reader, boolean, strict) is sufficient — the InputStream overloads chain through it (read(InputStream, boolean) → read(XmlStreamReader, boolean) → read(Reader, boolean)), so coverage is complete
  • MavenXpp3ReaderTest carries over and exercises both Reader and InputStream paths

All findings from the original multi-round review of #13117 were addressed before merge; this backport inherits that clean state.

This review was generated by an AI agent, Hermès on behalf of @gnodet.

@gnodet
gnodet merged commit 42dc31c into apache:maven-4.0.x Sep 15, 2026
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants