gnodet commented on code in PR #599:
URL: https://github.com/apache/maven-jar-plugin/pull/599#discussion_r4089174683
##########
src/main/java/org/apache/maven/plugins/jar/AbstractJarMojo.java:
##########
@@ -50,6 +50,20 @@
* @author Martin Desruisseaux
*/
public abstract class AbstractJarMojo implements
org.apache.maven.api.plugin.Mojo {
+ /**
+ * Minimum Unix time (seconds since epoch) accepted by the {@code jar}
tool.
+ * The {@code jar} tool enforces that all ZIP entry timestamps fall within
the range
+ * {@code 1980-01-01T00:00:02Z} to {@code 2099-12-31T23:59:59Z}.
+ * The lower bound is {@code T00:00:02Z} rather than {@code T00:00:00Z}
because
+ * {@code 1980-01-01T00:00:00Z} is a sentinel value ({@code
DOSTIME_BEFORE_1980}) in the
+ * JDK ZIP implementation that causes extra timezone metadata to be
written, breaking
+ * reproducibility (see JDK-8246129). The next instant after that sentinel
representable
+ * in MS-DOS time (which has 2-second granularity) is {@code T00:00:02Z}.
Review Comment:
Fixed in 020f347: changed 'causes' → 'caused (fixed in JDK 15, see
JDK-8246129)' and replaced 'The next instant after that sentinel representable
in MS-DOS time (which has 2-second granularity) is T00:00:02Z' with the
accurate explanation: 'The value T00:00:01Z is not representable in MS-DOS time
(2-second granularity), so T00:00:02Z is the lowest safe value.'
##########
src/main/java/org/apache/maven/plugins/jar/AbstractJarMojo.java:
##########
@@ -270,13 +292,31 @@ protected String getOutputTimestamp() {
for (int i = time.length(); --i >= 0; ) {
char c = time.charAt(i);
if ((c < '0' || c > '9') && (i != 0 || c != '-')) {
+ // Not a plain integer — treat as ISO 8601 and pass through
as-is.
return time;
}
}
+ // Plain integer: convert from seconds to ISO 8601, clamping to
EPOCH_MIN if needed.
try {
- return Instant.ofEpochSecond(Long.parseLong(time)).toString();
+ long seconds = Long.parseLong(time);
+ if (seconds < EPOCH_MIN) {
+ String instant = Instant.ofEpochSecond(seconds).toString();
+ String minValid = Instant.ofEpochSecond(EPOCH_MIN).toString();
+ log.warn("Output timestamp \""
+ + time
+ + "\" (resolved to "
+ + instant
+ + ") is before the minimum value accepted by the jar
tool ("
+ + minValid
+ + "). Clamping to minimum. "
+ + "If you use SOURCE_DATE_EPOCH=0, set it to at least "
+ + EPOCH_MIN
Review Comment:
Fixed in 020f347: replaced `+ EPOCH_MIN` with `+ minValid` — the warning
message now reads 'set it to at least 1980-01-01T00:00:02Z' instead of the
opaque epoch-seconds value.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]