Summary
oss-licenses-plugin 0.11.0 and later (0.11.0 / 0.12.0 / 0.13.0 all affected; 0.10.10 is fine) breaks every configureCMake* task in projects that use externalNativeBuild, when the Gradle daemon runs on JDK 17+ (mandatory with current AGP):
Execution failed for task ':app:configureCMakeDebug[arm64-v8a]'.
> Failed making field 'java.lang.ref.Reference#referent' accessible; either increase
its visibility or write a custom TypeAdapter for its declaring type.
See https://github.com/google/gson/blob/main/Troubleshooting.md#reflection-inaccessible
...
Caused by: java.lang.reflect.InaccessibleObjectException: Unable to make field private
java.lang.Object java.lang.ref.Reference.referent accessible: module java.base does
not "opens java.lang.ref" to unnamed module
at com.google.gson.internal.reflect.ReflectionHelper.makeAccessible(ReflectionHelper.java:68)
...
at com.android.build.gradle.internal.cxx.logging.PassThroughRecordingLoggingEnvironmentKt.toJsonString(PassThroughRecordingLoggingEnvironment.kt:107)
at com.android.build.gradle.tasks.ExternalNativeJsonGenerator.configureOneAbi(ExternalNativeJsonGenerator.kt:341)
Root cause
The plugin (since 0.11.0) depends on com.google.protobuf:protobuf-java:4.x (4.35.1 via 0.13.0). Gradle's highest-version conflict resolution upgrades the whole build classpath away from the 3.25.5 that AGP is built against:
# buildEnvironment, AGP 8.13.2 alone: protobuf-java:3.25.5
# with oss-licenses-plugin 0.13.0 applied: protobuf-java:4.35.1 (3.19.3/3.22.3/3.24.4/3.25.5 -> 4.35.1)
AGP's native-configure structured logging Gson-serializes a protobuf message reflectively; under the protobuf-4 runtime that object graph reaches a java.lang.ref.Reference, which JDK 17 module encapsulation forbids reflecting into.
Verified in both directions with a minimal project (AGP 8.13.2 + one dummy CMake library + this plugin, nothing else):
| configuration |
result |
| plugin 0.10.10 |
OK |
| plugin 0.11.0 / 0.12.0 / 0.13.0 |
FAILED as above |
plugin 0.13.0 + strictly("com.google.protobuf:protobuf-java:3.25.5") buildscript constraint |
OK |
| no plugin |
OK |
Gson (2.11.0) and all com.android.tools artifact versions are identical with and without the plugin — protobuf-java is the only relevant classpath change.
Environment
- oss-licenses-plugin 0.13.0 (also 0.12.0, 0.11.0) — 0.10.10 OK
- AGP 8.13.2, Gradle 9.0.0, daemon JDK 17 (temurin/openjdk), launcher JDK 21
- Any
externalNativeBuild { cmake { ... } } module; Linux x86_64
Steps to reproduce
- New single-module app project, AGP 8.13.2, add a minimal
externalNativeBuild CMake library (one dummy .cpp).
- Apply
com.google.android.gms.oss-licenses-plugin version 0.13.0.
./gradlew :app:configureCMakeDebug
Suggested fix
Don't force a protobuf-java major-version upgrade onto the shared buildscript classpath that AGP runs on — depend on protobuf-java 3.25.x, shade it, or mark the 4.x need as a compileOnly/isolated detail. (Note: the testapp verification suite has no externalNativeBuild module, which is likely why CI doesn't catch this.)
Workarounds for affected users
- Pin the plugin to
0.10.10, or
- keep the latest plugin and add a buildscript dependency constraint:
com.google.protobuf:protobuf-java strictly("3.25.5").
A secondary hardening opportunity exists on the AGP side (reflective Gson over protobuf runtime internals in PassThroughRecordingLoggingEnvironment rather than protobuf's own serializer); happy to cross-file there if useful.
Summary
oss-licenses-plugin0.11.0 and later (0.11.0 / 0.12.0 / 0.13.0 all affected; 0.10.10 is fine) breaks everyconfigureCMake*task in projects that useexternalNativeBuild, when the Gradle daemon runs on JDK 17+ (mandatory with current AGP):Root cause
The plugin (since 0.11.0) depends on
com.google.protobuf:protobuf-java:4.x(4.35.1 via 0.13.0). Gradle's highest-version conflict resolution upgrades the whole build classpath away from the 3.25.5 that AGP is built against:AGP's native-configure structured logging Gson-serializes a protobuf message reflectively; under the protobuf-4 runtime that object graph reaches a
java.lang.ref.Reference, which JDK 17 module encapsulation forbids reflecting into.Verified in both directions with a minimal project (AGP 8.13.2 + one dummy CMake library + this plugin, nothing else):
strictly("com.google.protobuf:protobuf-java:3.25.5")buildscript constraintGson (2.11.0) and all
com.android.toolsartifact versions are identical with and without the plugin — protobuf-java is the only relevant classpath change.Environment
externalNativeBuild { cmake { ... } }module; Linux x86_64Steps to reproduce
externalNativeBuildCMake library (one dummy.cpp).com.google.android.gms.oss-licenses-pluginversion 0.13.0../gradlew :app:configureCMakeDebugSuggested fix
Don't force a protobuf-java major-version upgrade onto the shared buildscript classpath that AGP runs on — depend on protobuf-java 3.25.x, shade it, or mark the 4.x need as a
compileOnly/isolated detail. (Note: thetestappverification suite has noexternalNativeBuildmodule, which is likely why CI doesn't catch this.)Workarounds for affected users
0.10.10, orcom.google.protobuf:protobuf-javastrictly("3.25.5").A secondary hardening opportunity exists on the AGP side (reflective Gson over protobuf runtime internals in
PassThroughRecordingLoggingEnvironmentrather than protobuf's own serializer); happy to cross-file there if useful.