Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

`AddJaxbAPIDependencies` silently no-ops when `javax.xml.bind` is only JDK-provided

Đang mở
#1,246 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
68/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
java
Lĩnh vực
build-system, devtools

Hướng nghiên cứu

Start with jaxb-apis.yml at the AddJaxbAPIDependencies recipe and trace its onlyIfUsing condition when parsing the supplied Java example on JDK 11 or later. Compare the related recipes named in the issue and add a regression test for a module using javax.xml.bind with no JAXB dependency. Done means the migration adds the required JAXB dependencies and the project no longer has the reported compile break.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

bug

What version of OpenRewrite are you using?

  • Moderne CLI v4.8.8
  • org.openrewrite.recipe:rewrite-migrate-java:3.44.0-20260829.193944-5

Recipe YAML is unchanged on main as of b6526609.

How are you running OpenRewrite?

Moderne CLI against a single-module Maven project:

mod run . --recipe org.openrewrite.java.migrate.UpgradeToJava25

Reached via UpgradeToJava25 -> 21 -> 17 -> Java8toJava11 -> AddJaxbDependenciesWithRuntime -> AddJaxbAPIDependencies. Should also affect the Maven/Gradle plugin whenever the JDK parsing the project is 11+.

Public reproducer: https://github.com/CSPF-Founder/JavaVulnerableLab

What is the smallest, simplest way to reproduce the problem?

A Maven project using JAXB with no JAXB dependency declared — i.e. relying on the JDK to provide it:

<maven.compiler.source>1.7</maven.compiler.source>
<maven.compiler.target>1.7</maven.compiler.target>
<!-- no javax.xml.bind:jaxb-api / jakarta.xml.bind dependency -->
import javax.xml.bind.DatatypeConverter;

class JwtUtil {
    static String base64Url(byte[] data) {
        return DatatypeConverter.printBase64Binary(data);
    }
}

Run UpgradeToJava25 (or Java8toJava11) parsing with a JDK >= 11.

What did you expect to see?

AddJaxbAPIDependencies adds jakarta.xml.bind:jakarta.xml.bind-api (plus the glassfish runtime), so the project still compiles once source/target are raised.

What did you see instead?

source/target raised to 25, but no JAXB dependency added — leaving the exact compile break the recipe exists to prevent:

[ERROR] .../JwtUtil.java:[6,22] package javax.xml.bind does not exist
[ERROR] .../JwtUtil.java:[59,16] cannot find symbol
[ERROR]   symbol: variable DatatypeConverter
Root cause: type-attribution bootstrap problem
# jaxb-apis.yml:117-123
- org.openrewrite.java.dependencies.AddDependency:
    groupId: jakarta.xml.bind
    artifactId: jakarta.xml.bind-api
    version: 2.3.x
    onlyIfUsing: javax.xml.bind..*   # never matches
    acceptTransitive: true

onlyIfUsing needs the type attributed in the LST. But javax.xml.bind is JDK-provided only through Java 8 and was removed in 11 — so when parsed by a JDK >= 11 with no JAXB dependency declared, it never resolves.

The recipe that adds the missing JAXB dependency only fires if the JAXB dependency is already there.

This is attribution, not a broken classpath — FindTypes on the same LST, types from the same file:

Type Provided by Found
javax.crypto.Mac JDK (still present) 1
org.json.JSONObject declared dep 2
javax.servlet.http.HttpServletRequest declared dep 10
javax.xml.bind.DatatypeConverter JDK-only, removed in 11 0

Note the preconditions are not at fault — both recipes use preconditions: [org.openrewrite.Singleton] (jaxb-apis.yml:32, :93) and do run. The inner onlyIfUsing silently no-ops.

Likely affects sibling recipes

Same flaw for any onlyIfUsing on a JDK-11-removed package:

  • javax.annotation..* — add-common-annotations-dependencies.yml:50
  • javax.activation..* — jakarta-ee-9.yml:106
  • javax.xml.bind..* — jakarta-ee-9.yml:997
  • javax.xml.soap..* — jakarta-ee-9.yml:1092
  • AddJaxwsDependencies
Suggested fix

onlyIfUsing can't be the sole trigger for JDK-removed modules. Either fall back to matching unresolved imports when the type is unattributed, or add an onlyIfUsingImport-style option to AddDependency.

Worth a regression test on a module that uses javax.xml.bind with no JAXB dependency, parsed on a modern JDK — existing tests likely declare it, which is how this slipped through.

Impact

Upgrading any Java <= 8 project relying on JDK-provided JAXB to 11+ produces a silent compile break, with no warning in the recipe output.

Ngôn ngữ chính
Java
Star
156
Fork
129
Merge trung bình
3 ngày 8 giờ
Pull request đã merge (30 ngày)
14

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của openrewrite/rewrite-migrate-java

Tất cả issue của openrewrite/rewrite-migrate-java

Issue tương tự

Thêm issue về Java

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.