commons-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Pascal Schumacher (JIRA)" <>
Subject [jira] [Commented] (LANG-1296) ArrayUtils.addAll() has unsafe use of varargs
Date Mon, 12 Dec 2016 22:48:58 GMT


Pascal Schumacher commented on LANG-1296:

A version of commons-lang containing this method with the @SafeVarargs annotation has not
been release yet, so it can just be removed.

> ArrayUtils.addAll() has unsafe use of varargs
> ---------------------------------------------
>                 Key: LANG-1296
>                 URL:
>             Project: Commons Lang
>          Issue Type: Bug
>          Components: lang.*
>    Affects Versions: 3.5
>            Reporter: Duncan Jones
>            Priority: Critical
> {{ArrayUtils.addAll()}} is marked as {{@SafeVarargs}}, but I suspect the use of the varargs
is unsafe.
> An example, drawn heavily from [this StackOverflow answer|],
demonstrates this:
> {code:java}
> static <T> T[] arrayOfTwo(T a, T b) {
>    return ArrayUtils.addAll(null, a, b);
> }
> @Test
> public void testBadVarArgs() throws Exception {
>    @SuppressWarnings("unused") // Need to assign to trigger exception
>    String[] result = arrayOfTwo("foo", "bar");
> }
> {code}
> the above code throws an exception: {{java.lang.ClassCastException: [Ljava.lang.Object;
cannot be cast to [Ljava.lang.String;}}.
> Here, the {{null}} input array causes the method to return a clone of the vararg array.
This is what triggers the problem.
> I faced a similar issue when adding the {{ArrayUtils.insert(...)}} methods and I solved
it by returning {{null}} if the input array is {{null}}. We can't do this here without breaking

This message was sent by Atlassian JIRA

View raw message