Soundness: a field of another class or object is read as this class's field with the same name
維護者通常 2 天內回覆
還沒有人認領這個 Issue。
評估
研究方向
Start at OperationsChecker.getOperationRefinements and RefinementTypeChecker.visitCtFieldRead, using the supplied Limits/Repro example as the first reproducer. Trace how CtFieldRead targets are resolved for class fields, object fields, and enum constants, then verify that the reproducer reports a refinement error and that the name-clash cases no longer use the current class's field refinement.
由索引模型根據 Issue 內容生成。
描述
Description
Reading a field of another class or object (Limits.max, other.val) resolves to the current class's own field with the same name (this.max) when the current class has one. The wrong refinement is used, so real violations are accepted.
Minimal reproducer
import liquidjava.specification.Refinement;
class Limits {
static final int max = 10;
}
public class Repro {
int max = 5; // this class also has a field named max
void check() {
@Refinement("_ == 5") int k = Limits.max; // expected error: Limits.max is 10
}
}
Expected
A refinement error: Limits.max is 10, not 5.
Actual
Correct! Passed Verification.
Removing the field int max = 5; from Repro gives the expected error (k == 10 is not a subtype of k == 5), so the name clash is what hides it.
Reproduced on main at fbfb4e23.
Where
OperationsChecker.getOperationRefinements / RefinementTypeChecker.visitCtFieldRead: a CtFieldRead is named with Formats.THIS (this#<name>) regardless of its target, so any field read whose simple name matches a field of the current class picks up that field's refinement. The same shape affects enum constants (Format.JPG read as this.JPG when the class has a field JPG) and fields of other objects (other.val read as this.val).
Context
Found by the adversarial review of #319 (fix for #302). Pre-existing on main, independent of #319.
- 主要語言
- Java
- 星號
- 67
- 分支
- 36
- 平均合併
- 3 天 16 小時
- 30 天內合併 PR
- 9
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
liquid-java/liquidjava 的其他 Issue
-
bug
難度 2/5 1-3 小時 新手友好度 78/100
liquid-java/liquidjava#321 ·
維護者通常 2 天內回覆
-
Soundness: short-circuit RHS assignments are treated as executed可能已有人在做 關聯的 PR 仍在進行中或已合併。 未關閉
難度 4/5 3-5 天 新手友好度 68/100
liquid-java/liquidjava#323 ·
維護者通常 2 天內回覆
-
Fields with the same name in different classes collide可能已有人在做 關聯的 PR 仍在進行中或已合併。 未關閉bug
難度 4/5 3-5 天 新手友好度 52/100
liquid-java/liquidjava#318 ·
維護者通常 2 天內回覆
-
Nested classes wipe the outer class's field refinements可能已有人在做 關聯的 PR 仍在進行中或已合併。 未關閉bug
難度 4/5 3-5 天 新手友好度 55/100
liquid-java/liquidjava#317 ·
維護者通常 2 天內回覆
-
Reading a field of a class declared later in the file loses its refinement可能已有人在做 關聯的 PR 仍在進行中或已合併。 未關閉bug
難度 4/5 3-5 天 新手友好度 62/100
liquid-java/liquidjava#316 ·
維護者通常 2 天內回覆
查看 liquid-java/liquidjava 的全部 Issue
相似的 Issue
-
Clarify Javadoc for Logger methods taking Object... arguments with regards to Throwable detection未關閉
難度 2/5 1-3 小時 新手友好度 68/100
-
難度 1/5 1-3 小時 新手友好度 88/100
-
[Bug] The shared instance selector's placeholder and no-match text ignore the display language可能已有人在做 關聯的 PR 仍在進行中或已合併。 未關閉
難度 2/5 1-3 小時 新手友好度 90/100
apache/rocketmq-dashboard#5561 ·
維護者通常 3 天內回覆
-
enhancement
難度 2/5 1-3 小時 新手友好度 68/100
維護者通常 1 天內回覆
-
test(setup): GitHub configuration tests fail when the temp path is long enough for YAML folding可能已有人在做 關聯的 PR 仍在進行中或已合併。 未關閉bug good first issue help wanted priority medium size S
難度 2/5 1-3 小時 新手友好度 84/100
martin-francois/symphony-trello#776 · 1 則留言 ·
維護者通常 1 天內回覆