java-topology/test/langtools/tools/javac/warnings/Serial/ImproperSerialPF.java
russell@unturf.com 0a580b313d undefect. CWE-407 — 63 sites patched across 27 ecosystems
Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
2026-03-26 17:11:57 -04:00

37 lines
1.2 KiB
Java

/*
* @test /nodynamiccopyright/
* @bug 8202056
* @compile/ref=ImproperSerialPF.out -XDrawDiagnostics -Xlint:serial ImproperSerialPF.java
*/
import java.io.*;
class ImproperSerialPF implements Serializable {
// Proper declaration of serialPersistentFields is:
// private static final ObjectStreamField[] serialPersistentFields = ...
public /*instance*/ Object serialPersistentFields = Boolean.TRUE;
private static final long serialVersionUID = 42;
static class LiteralNullSPF implements Serializable {
private static final ObjectStreamField[] serialPersistentFields = null;
private static final long serialVersionUID = 42;
}
// Casting obscures the simple syntactic null-check
static class CastedNullSPF implements Serializable {
private static final ObjectStreamField[] serialPersistentFields =
(ObjectStreamField[])null;
private static final long serialVersionUID = 42;
}
// Conditional obscures the simple syntactic null-check too
static class ConditionalNullSPF implements Serializable {
private static final ObjectStreamField[] serialPersistentFields =
(true ? null : null);
private static final long serialVersionUID = 42;
}
}