`AddJaxbAPIDependencies` silently no-ops when `javax.xml.bind` is only JDK-provided
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 68/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- java
- Lĩnh vực
- build-system, devtools
Hướng nghiên cứu
Start with jaxb-apis.yml at the AddJaxbAPIDependencies recipe and trace its onlyIfUsing condition when parsing the supplied Java example on JDK 11 or later. Compare the related recipes named in the issue and add a regression test for a module using javax.xml.bind with no JAXB dependency. Done means the migration adds the required JAXB dependencies and the project no longer has the reported compile break.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
What version of OpenRewrite are you using?
- Moderne CLI v4.8.8
org.openrewrite.recipe:rewrite-migrate-java:3.44.0-20260829.193944-5
Recipe YAML is unchanged on main as of b6526609.
How are you running OpenRewrite?
Moderne CLI against a single-module Maven project:
mod run . --recipe org.openrewrite.java.migrate.UpgradeToJava25
Reached via UpgradeToJava25 -> 21 -> 17 -> Java8toJava11 -> AddJaxbDependenciesWithRuntime -> AddJaxbAPIDependencies. Should also affect the Maven/Gradle plugin whenever the JDK parsing the project is 11+.
Public reproducer: https://github.com/CSPF-Founder/JavaVulnerableLab
What is the smallest, simplest way to reproduce the problem?
A Maven project using JAXB with no JAXB dependency declared — i.e. relying on the JDK to provide it:
<maven.compiler.source>1.7</maven.compiler.source>
<maven.compiler.target>1.7</maven.compiler.target>
<!-- no javax.xml.bind:jaxb-api / jakarta.xml.bind dependency -->
import javax.xml.bind.DatatypeConverter;
class JwtUtil {
static String base64Url(byte[] data) {
return DatatypeConverter.printBase64Binary(data);
}
}
Run UpgradeToJava25 (or Java8toJava11) parsing with a JDK >= 11.
What did you expect to see?
AddJaxbAPIDependencies adds jakarta.xml.bind:jakarta.xml.bind-api (plus the glassfish runtime), so the project still compiles once source/target are raised.
What did you see instead?
source/target raised to 25, but no JAXB dependency added — leaving the exact compile break the recipe exists to prevent:
[ERROR] .../JwtUtil.java:[6,22] package javax.xml.bind does not exist
[ERROR] .../JwtUtil.java:[59,16] cannot find symbol
[ERROR] symbol: variable DatatypeConverter
Root cause: type-attribution bootstrap problem
# jaxb-apis.yml:117-123
- org.openrewrite.java.dependencies.AddDependency:
groupId: jakarta.xml.bind
artifactId: jakarta.xml.bind-api
version: 2.3.x
onlyIfUsing: javax.xml.bind..* # never matches
acceptTransitive: true
onlyIfUsing needs the type attributed in the LST. But javax.xml.bind is JDK-provided only through Java 8 and was removed in 11 — so when parsed by a JDK >= 11 with no JAXB dependency declared, it never resolves.
The recipe that adds the missing JAXB dependency only fires if the JAXB dependency is already there.
This is attribution, not a broken classpath — FindTypes on the same LST, types from the same file:
| Type | Provided by | Found |
|---|---|---|
javax.crypto.Mac |
JDK (still present) | 1 |
org.json.JSONObject |
declared dep | 2 |
javax.servlet.http.HttpServletRequest |
declared dep | 10 |
javax.xml.bind.DatatypeConverter |
JDK-only, removed in 11 | 0 |
Note the preconditions are not at fault — both recipes use preconditions: [org.openrewrite.Singleton] (jaxb-apis.yml:32, :93) and do run. The inner onlyIfUsing silently no-ops.
Likely affects sibling recipes
Same flaw for any onlyIfUsing on a JDK-11-removed package:
javax.annotation..*—add-common-annotations-dependencies.yml:50javax.activation..*—jakarta-ee-9.yml:106javax.xml.bind..*—jakarta-ee-9.yml:997javax.xml.soap..*—jakarta-ee-9.yml:1092AddJaxwsDependencies
Suggested fix
onlyIfUsing can't be the sole trigger for JDK-removed modules. Either fall back to matching unresolved imports when the type is unattributed, or add an onlyIfUsingImport-style option to AddDependency.
Worth a regression test on a module that uses javax.xml.bind with no JAXB dependency, parsed on a modern JDK — existing tests likely declare it, which is how this slipped through.
Impact
Upgrading any Java <= 8 project relying on JDK-provided JAXB to 11+ produces a silent compile break, with no warning in the recipe output.
- Ngôn ngữ chính
- Java
- Star
- 156
- Fork
- 129
- Merge trung bình
- 3 ngày 8 giờ
- Pull request đã merge (30 ngày)
- 14
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của openrewrite/rewrite-migrate-java
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 70/100
openrewrite/rewrite-migrate-java#1228 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 32/100
openrewrite/rewrite-migrate-java#1227 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 70/100
openrewrite/rewrite-migrate-java#1146 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 50/100
openrewrite/rewrite-migrate-java#1119 · 5 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 45/100
openrewrite/rewrite-migrate-java#1069 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của openrewrite/rewrite-migrate-java
Issue tương tự
-
type/bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
objectionary/lints#1520 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
SchweizerischeBundesbahnen/ch.sbb.polarion.extension.pdf-exporter#1109 ·
Maintainer thường phản hồi trong vòng 1 ngày