`AddJaxbAPIDependencies` silently no-ops when `javax.xml.bind` is only JDK-provided
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 68/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- java
- Área
- build-system, devtools
Línea de trabajo
Start with jaxb-apis.yml at the AddJaxbAPIDependencies recipe and trace its onlyIfUsing condition when parsing the supplied Java example on JDK 11 or later. Compare the related recipes named in the issue and add a regression test for a module using javax.xml.bind with no JAXB dependency. Done means the migration adds the required JAXB dependencies and the project no longer has the reported compile break.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
What version of OpenRewrite are you using?
- Moderne CLI v4.8.8
org.openrewrite.recipe:rewrite-migrate-java:3.44.0-20260829.193944-5
Recipe YAML is unchanged on main as of b6526609.
How are you running OpenRewrite?
Moderne CLI against a single-module Maven project:
mod run . --recipe org.openrewrite.java.migrate.UpgradeToJava25
Reached via UpgradeToJava25 -> 21 -> 17 -> Java8toJava11 -> AddJaxbDependenciesWithRuntime -> AddJaxbAPIDependencies. Should also affect the Maven/Gradle plugin whenever the JDK parsing the project is 11+.
Public reproducer: https://github.com/CSPF-Founder/JavaVulnerableLab
What is the smallest, simplest way to reproduce the problem?
A Maven project using JAXB with no JAXB dependency declared — i.e. relying on the JDK to provide it:
<maven.compiler.source>1.7</maven.compiler.source>
<maven.compiler.target>1.7</maven.compiler.target>
<!-- no javax.xml.bind:jaxb-api / jakarta.xml.bind dependency -->
import javax.xml.bind.DatatypeConverter;
class JwtUtil {
static String base64Url(byte[] data) {
return DatatypeConverter.printBase64Binary(data);
}
}
Run UpgradeToJava25 (or Java8toJava11) parsing with a JDK >= 11.
What did you expect to see?
AddJaxbAPIDependencies adds jakarta.xml.bind:jakarta.xml.bind-api (plus the glassfish runtime), so the project still compiles once source/target are raised.
What did you see instead?
source/target raised to 25, but no JAXB dependency added — leaving the exact compile break the recipe exists to prevent:
[ERROR] .../JwtUtil.java:[6,22] package javax.xml.bind does not exist
[ERROR] .../JwtUtil.java:[59,16] cannot find symbol
[ERROR] symbol: variable DatatypeConverter
Root cause: type-attribution bootstrap problem
# jaxb-apis.yml:117-123
- org.openrewrite.java.dependencies.AddDependency:
groupId: jakarta.xml.bind
artifactId: jakarta.xml.bind-api
version: 2.3.x
onlyIfUsing: javax.xml.bind..* # never matches
acceptTransitive: true
onlyIfUsing needs the type attributed in the LST. But javax.xml.bind is JDK-provided only through Java 8 and was removed in 11 — so when parsed by a JDK >= 11 with no JAXB dependency declared, it never resolves.
The recipe that adds the missing JAXB dependency only fires if the JAXB dependency is already there.
This is attribution, not a broken classpath — FindTypes on the same LST, types from the same file:
| Type | Provided by | Found |
|---|---|---|
javax.crypto.Mac |
JDK (still present) | 1 |
org.json.JSONObject |
declared dep | 2 |
javax.servlet.http.HttpServletRequest |
declared dep | 10 |
javax.xml.bind.DatatypeConverter |
JDK-only, removed in 11 | 0 |
Note the preconditions are not at fault — both recipes use preconditions: [org.openrewrite.Singleton] (jaxb-apis.yml:32, :93) and do run. The inner onlyIfUsing silently no-ops.
Likely affects sibling recipes
Same flaw for any onlyIfUsing on a JDK-11-removed package:
javax.annotation..*—add-common-annotations-dependencies.yml:50javax.activation..*—jakarta-ee-9.yml:106javax.xml.bind..*—jakarta-ee-9.yml:997javax.xml.soap..*—jakarta-ee-9.yml:1092AddJaxwsDependencies
Suggested fix
onlyIfUsing can't be the sole trigger for JDK-removed modules. Either fall back to matching unresolved imports when the type is unattributed, or add an onlyIfUsingImport-style option to AddDependency.
Worth a regression test on a module that uses javax.xml.bind with no JAXB dependency, parsed on a modern JDK — existing tests likely declare it, which is how this slipped through.
Impact
Upgrading any Java <= 8 project relying on JDK-provided JAXB to 11+ produces a silent compile break, with no warning in the recipe output.
- Lenguaje dominante
- Java
- Estrellas
- 156
- Forks
- 129
- Merge medio
- 3 d 8 h
- PR fusionados (30 d)
- 14
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Sin plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de openrewrite/rewrite-migrate-java
-
Dificultad 3/5 1-2 días Aptitud para principiantes 70/100
openrewrite/rewrite-migrate-java#1228 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 32/100
openrewrite/rewrite-migrate-java#1227 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 3/5 1-2 días Aptitud para principiantes 70/100
openrewrite/rewrite-migrate-java#1146 · 3 comentarios ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 4/5 3-5 días Aptitud para principiantes 50/100
openrewrite/rewrite-migrate-java#1119 · 5 comentarios ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 4/5 3-5 días Aptitud para principiantes 45/100
openrewrite/rewrite-migrate-java#1069 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
Todos los issues de openrewrite/rewrite-migrate-java
Issues similares
-
type/bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
objectionary/lints#1520 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
SchweizerischeBundesbahnen/ch.sbb.polarion.extension.pdf-exporter#1109 ·
Los mantenedores suelen responder en 1 día