Debian Patches

Status for gradle/4.6-3

Patch Description Author Forwarded Bugs Origin Last update
java11-compatibility.patch Fixes the compatibility with Java 11. The patch can be removed after upgrading to the version 4.8 https://github.com/gradle/gradle/commit/028548460bd929fd034a552704798ad7f689493a
https://github.com/gradle/gradle/commit/3db6e256987053171178aa96a0ef46caedc8d1a4
https://github.com/gradle/gradle/commit/b645d9b576d0ecfa116a213f6df299fd2b1a9b7e
no backport, https://github.com/gradle/gradle/commit/ac15612d41b43c39c8e39d12fdd6621589b0f782
asm7.patch no
ivy-artifact-backport.patch Backports the refactored IvyArtifact classes from Gradle 4.8 to help building Kotlin no backport, https://github.com/gradle/gradle/commit/e076a783
fix-CVE-2019-11065.patch not-needed backport, https://github.com/gradle/gradle/pull/8927
guava-compatibility.patch Fixes the compatibility with the recent versions of Guava. Source level must be 1.8 or higher to use the updated predicates in Guava. Emmanuel Bourg <ebourg@apache.org> not-needed
backport-ComponentWithCoordinates.patch Backporting ComponentWithCoordinates (needed to package kotlin) Samyak Jain <samyak.jn11@gmail.com> no
backport-CommandLineArgumentProvider.patch Backport CommandLineArgumentProvider (Needed to package kotlin) Samyak Jain <samyak.jn11@gmail.com> no
backport-FeaturePreviews.patch Backport the newer feature previews (needed to package kotlin) Gradle 4.6 ships its own FeaturePreviews, so the later feature names are added
to it rather than to a second class in core-api: core-api comes first on the
classpath, and its copy would hide the one Gradle itself uses, dropping
IMPROVED_POM_SUPPORT.
Samyak Jain <samyak.jn11@gmail.com> no https://github.com/gradle/gradle/subprojects/core-api/src/main/java/org/gradle/api/internal/FeaturePreviews.java
backport-TaskProvider.patch Backport TaskProvider (Needed to package kotlin) Samyak Jain <samyak.jn11@gmail.com> no
backport-NamedDomainObjectProvider.patch Backport NamedDomainObjectProvider (Needed to package kotlin) Samyak Jain <samyak.jn11@gmail.com> no
backport-capabilities.patch Backport capabilities (Needed to package kotlin) Samyak Jain <samyak.jn11@gmail.com> no
source-level.patch Set the language level to 1.8 to fix the build failure with Ant 1.10 and OpenJDK 17 Emmanuel Bourg <ebourg@apache.org> not-needed
permit-illegal-access.patch Adds the --add-opens option to run Gradle on Java 17 Emmanuel Bourg <ebourg@apache.org> not-needed
java17-compatibility.patch Fix SourcepathIgnoringInvocationHandler on Java 9 Use the method provided by the proxy API instead of
trying to look up the same method on the delegate's
class. It is unclear why this was done in the first place.
Trying to access the method from the delegate lead to
illegal access exceptions on certain JDKs.
.
This patch can be removed after upgrading to Gradle 4.8
Stefan Oehme <stefan@gradle.com> no upstream, https://github.com/gradle/gradle/commit/f6fd43e1
auto-adjust-language-level.patch Adjust the source/target level automatically for building with recent JDKs Emmanuel Bourg <ebourg@apache.org> not-needed
docs.patch Builds Javadoc only Use a simplified `docs.gradle` which builds only the Javadoc. Kai-Chung Yan not-needed
drop-http-builder.patch drop http builder
http-builder is not in Debian yet
Markus Koschany <apo@debian.org> no 2017-11-18
drop-jmh-gradle-plugin.patch drop jmh gradle plugin
jmh-gradle-plugin is not in Debian yet
Markus Koschany <apo@debian.org> no 2017-11-18
drop-dependency-check-plugin.patch Drop the OWASP dependency check plugin The plugin is not packaged in Debian, and it downloads the National
Vulnerability Database at build time, which a Debian build cannot do.
Emmanuel Bourg <ebourg@apache.org> not-needed
eclipse-aether.patch eclipse aether
Maven module originally uses aether which is deprecated. This patch changes it
to use eclipse-aether/maven-resolver.
Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> no 2017-11-29
restore-groovy-build-scripts.patch Restore the Groovy build scripts converted to the Kotlin DSL upstream Gradle 4.5 began converting its own build to the Kotlin DSL and 4.6 went
further: the settings files, some of the subproject scripts and part of the
buildSrc plugins now exist only as Kotlin sources. The Debian package ships
no Kotlin DSL, and Gradle silently ignores a settings file it cannot
evaluate: the build is then seen as a single project with no subproject at
all, and still reports success.
.
This patch restores Groovy equivalents of the converted build scripts, and
reimplements in Groovy the buildSrc plugins rewritten in Kotlin, so that
building Gradle needs no Kotlin compiler. The upstream Kotlin files are left
in place and simply ignored: Gradle reads settings.gradle in preference to
settings.gradle.kts, and the subproject build files are named by
settings.gradle itself. build.gradle is the only upstream file modified, to
apply the Groovy groovyProject.gradle.
.
The scripts follow their .kts counterparts, minus what Debian does not build:
the subprojects disabled by the packaging are left out of settings.gradle,
and the checkSameDaemonArgs task is dropped, a CI-only consistency check
reading the gradle.properties that debian/rules removes before the build. The
classycle and strict-compile plugins only register their extension, since
neither check runs here, and the improved POM support feature preview is left
disabled, it ignores the relocations the Debian repository relies on.
.
The patch must stay first in the series, since the patches that follow modify
the files it creates. At each new upstream release the .kts scripts are to be
checked for changes and mirrored into the Groovy equivalents.
Emmanuel Bourg <ebourg@apache.org> not-needed
gradle-debian-helper-hook.patch Adds a hook in MavenResolver to resolve the artifacts from the system repository Emmanuel Bourg <ebourg@apache.org> not-needed
33_scala_zinc.diff _scala_zinc
No Zinc Compiler (https://github.com/typesafehub/zinc) in Debian. Zinc depends
on SBT compiler and SBT is not yet in Debian See SBT ITP :
https://bugs.debian.org/639910
Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> not-needed 2017-11-12
search_system_jar.diff search_system_jar
Gradle searches its own directory for Java libraries ignoring /usr/share/java/.
Somehow Gradle even fails to locate its home directory which is
/usr/share/gradle/. This patch fixes these issues, and the large amount of
symlinks in the binary packages may be possible to remove. Maintaining so many
symlinks is too error prone.
Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> no 2017-11-12
generate-pom.patch generate_pom
By default Gradle won't generate POMs for itself. generate_pom.gradle makes
Gradle auto generate POMs for all of the JARs so that we can install the POMs
to /usr/share/maven-repo
Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> not-needed 2017-11-12
ivy-2.4.0.patch ivy 2.4.0
Rml4IEZUQkZTIHdpdGggaXZ5IDIuNC4wLiBQYXRjaCB0YWtlbiBmcm9tCmh0dHBzOi8vZ2l0aHVi
LmNvbS9taXpkZWJzay9ncmFkbGUvY29tbWl0L2UwMTM4YjEKVGhhbmtzIHRvIE1pa2/FgmFqIEl6
ZGVic2tpCgpGb3J3YXJkZWQ6IG5vCg==
Markus Koschany <apo@debian.org> no 2015-11-11
34-disable-code-quality.patch 34 disable code quality
Disable checkstyle and codenarc tasks during build Gradle failed to build on
amd64 due to an apparent upstream bug. As extra comment, the issue is not
present when gradle is built with Oracle JDK.
Markus Koschany <apo@debian.org> not-needed debian 2017-11-12
disable-Kotlin.patch Disable Kotlin support. Kotlin is not in Debian yet. Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> no 2017-11-29
disable-aws.patch disable aws
AWS SDK for Java is not in Debian yet.
Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> no 2017-11-29
disable_buildSrc_tests.patch disable_buildSrc_tests Markus Koschany <apo@debian.org> no 2017-11-12
normalize-classpath.patch Normalize the generated classpath in every JAR Gradle uses its own class loading mechanism which uses a dedicated classpath file stored in
every JAR. The JAR names are really names, not paths,
so they need to be normalized so that Gradle can search `/usr/share/java`
for them. . This patch also sorts the generated classpath to improve
reproducibility. . One bug of this patch is that the Groovy version is
hard-coded,
but it seems not to affect the actual result of running `gradle --version`.
Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org> no 2022-09-29
jcommander.patch jcommander
Various modules use jcommander but do not declare.
Markus Koschany <apo@debian.org> not-needed 2017-11-18
maven-3.3-compatibility.patch maven 3.3 compatibility
Fix the compatibility with Maven 3.3
Emmanuel Bourg <ebourg@apache.org> no 2017-11-18
remove-timestamps.patch remove timestamps
This patch manually sets the timestamps and other dynamic strings that break
the reproducibility.
Markus Koschany <apo@debian.org> no 2017-11-18
use-local-artifacts.patch use local artifacts Use local jar files to build Gradle. The core point is using a local Maven
repository pointing to `/usr/share/maven-repo`. Due to some invisible bug,
`resolutionStrategy` is able to override artifact versions only, so we have
to patch some artifact names here.
Markus Koschany <apo@debian.org> not-needed 2017-11-18
cast-estimated-runtime-to-long.patch gradle 3.4.1 FTBFS with a missing cast to long estimatedRuntime must be cast to long otherwise gradle 3.4.1 FTBFS with
buildSrc/src/main/groovy/org/gradle/testing/DistributedPerformanceTest.groovy:
134: [Static type checking] - Cannot assign value of type java.math.BigDecimal
to variable of type long.
Tiago Stürmer Daitx <tiago.daitx@ubuntu.com> no debian 2018-03-19
java8-compatibility.patch Makes Gradle usable with Java 8 even if compiled with Java 9 Emmanuel Bourg <ebourg@apache.org> not-needed
disable-binary-compatibility.patch Disable binary-compatibility plugin The plugin requires `javaparser` and `japicmp` which are not in Debian yet Kai-Chung Yan not-needed
gradle-4-compatibility.patch Gradle 4 compatibility Some APIs buildSrc uses are from Gradle 4 and but we have Gradle 3.4.1 only. Kai-Chung Yan not-needed
disable-google-apis.patch Disable Google APIs Google Apis are not in Debian yet. Kai-Chung Yan not-needed
disable-internal-android-performance-testing.patch Disable internalAndroidPerformanceTesting No idea why this project keeps being run while being excluded, have to
disable it by force.
Kai-Chung Yan not-needed
CVE-2019-16370.patch signing plugin: use SHA512 instead of SHA1 when signing artifacts

PGP signs a digest, so MITM is still possible provided an attacker can update
the artifact in such a way that its SHA1 is intact.

Relevant article is https://medium.com/@jonathan.leitschuh/many-of-these-gpg-signatures-are-signed-with-sha-1-which-is-vulnerable-to-a-second-preimage-attack-67104d827930
Vladimir Sitnikov <sitnikov.vladimir@gmail.com> no 2019-09-10
type-inference-fix.patch Fixes the type inference errors when building with the source/target level set to Java 8 Emmanuel Bourg <ebourg@apache.org> not-needed
java25-compat.patch Catch exception when clearing Security Manager Java 25 disables setting Security Manager. The class may be removed in
the future releases.
The patch is not needed upstream, as Gradle 9.x is compatible
with Java 25.
Vladimir Petko <vladimir.petko@canonical.com> not-needed debian 2025-02-11
snakeyaml-2-compatibility.patch Compatibility with SnakeYAML 2 JavaBeanDumper and Loader were removed in SnakeYAML 2, which is the version
packaged in Debian. The bean is now dumped with a Representer mapping the
class to a plain map, which is what JavaBeanDumper(false) used to produce.
Emmanuel Bourg <ebourg@apache.org> not-needed
java9-modules-compatibility.patch Implement CompilationTask.addModules() JavaCompiler.CompilationTask gained addModules() in Java 9, after this class
was written, and the decorator no longer compiles without it. The call is
simply forwarded to the wrapped task.
Emmanuel Bourg <ebourg@apache.org> not-needed
serializer-equality.patch Make the annotation processor serializer comparable DefaultCacheAccess compares the serializers of a cache with equals() before
reusing it. This one holds no state but inherits the identity equals(), so two
equivalent instances never match and the annotation processor cache is refused
with a mismatch naming the very same type on both sides.
Emmanuel Bourg <ebourg@apache.org> not-needed
gradle-debian-helper-plugin-filter.patch Ignore the plugins and projects listed in debian/gradle.ignoreRules With this patch Gradle ignores the plugins, projects and blocks declared in
debian/gradle.ignoreRules. The rules are parsed by gradle-debian-helper, called
by reflection because Gradle does not depend on it. Nothing is ignored when the
file is absent or the helper isn't installed.
Emmanuel Bourg <ebourg@apache.org> not-needed

All known versions for source package 'gradle'

Links