undefect. CWE-407 — 63 sites patched across 27 ecosystems

Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
This commit is contained in:
russell@unturf.com 2026-03-26 17:11:57 -04:00
commit 0a580b313d
70422 changed files with 17213626 additions and 0 deletions

View file

@ -0,0 +1,37 @@
/*
* @test /nodynamiccopyright/
* @bug 8202056
* @compile/ref=ImproperSerialPF.out -XDrawDiagnostics -Xlint:serial ImproperSerialPF.java
*/
import java.io.*;
class ImproperSerialPF implements Serializable {
// Proper declaration of serialPersistentFields is:
// private static final ObjectStreamField[] serialPersistentFields = ...
public /*instance*/ Object serialPersistentFields = Boolean.TRUE;
private static final long serialVersionUID = 42;
static class LiteralNullSPF implements Serializable {
private static final ObjectStreamField[] serialPersistentFields = null;
private static final long serialVersionUID = 42;
}
// Casting obscures the simple syntactic null-check
static class CastedNullSPF implements Serializable {
private static final ObjectStreamField[] serialPersistentFields =
(ObjectStreamField[])null;
private static final long serialVersionUID = 42;
}
// Conditional obscures the simple syntactic null-check too
static class ConditionalNullSPF implements Serializable {
private static final ObjectStreamField[] serialPersistentFields =
(true ? null : null);
private static final long serialVersionUID = 42;
}
}