4 ms·
JEP 539: Strict Field Initialization in the JVM moved to preview
- cogman10 3mo agoThis is a great change that will undoubtedly cause a lot of headaches. There's a number of libraries (particularly around serialization/marshaling) which will end up mutating `final` fields. In fact, this is a trick I've pulled once or twice in my own code for "reasons" (generally needing to modify behavior of a library because it was deficient). I suspect this will be one of those things that ends up requiring java devs everywhere to bump up the versions of the libraries they use.
- kasperni 3mo agoStrict Field Initialization is opt-in. A flag needs to be set in the classfile in order to enable it. So should not effect any existing code.
- cogman10 3mo agoIt won't bite initially, it will bite when you go to update your version of javac in the future and this becomes the default. Or when you update a library that just so happened to be compiled with a newer version of javac. This particularly matters when you have something likes this class Local { private final ThirdPartyObject tpo; } or even something like this class Local { private final LocalDate ld; }
- vips7L 3mo agoExtremely easy to fix. Turn it into a record. I’m also pretty sure that cracking final fields is already disabled by default.
- cogman10 3mo ago> Extremely easy to fix. Nope, if the deserializer is initializing that field by directly setting values both by the field and by the internals of the field, it'll be a problem. The fix is to update the deserializer to a newer version. Apache Fury recently fixed this very issue, but it still relies on internal JDK APIs in order to do it's work. > I’m also pretty sure that cracking final fields is already disabled by default. Nope. There's sun.misc.Unsafe apis that allow for cracking and modifying those final fields. There are new jdk.internal APIs for doing the same that you'd have to move over to in order to accomplish the same. This JEP is about making final (mostly) meaning final. At very least, it will enforce that final once observed is final with the internal APIs allowing a final field to be set once, just outside the constructor.
- vips7L 3mo ago> sun.misc.Unsafe Yeah idk man sounds like it sucks to suck in this case. Don’t use unsafe. From your example: record Local(LocalDate ld) {} Will work perfectly fine with every deserializer I’ve ever seen.
- pjmlp 3mo agosun.misc.Unsafe will eventually be no longer, plenty of methods have already been removed since safer alternatives were introduced. Java isn't alone in this, as usual due to their relationship, .NET is also clamping down some of this stuff, including changing the memory model around unsafe code blocks. There are other ecosystems for monkey patching.
- debugnik 3mo agoThat's a separate series of JEPs known as "final means final", also starting to land nowadays. https://openjdk.org/jeps/500 https://openjdk.org/jeps/500
- cogman10 3mo agoI believe these 2 are effectively linked. There's a jdk.internal API which will work as an escape hatch, but that does come with the need for non-compliant libraries to switch over to it. That safety hatch also only allows the setting of final fields once before observation (which is generally fine). So if your code is doing something more esoteric that sets a final field multiple times you will be SOL. In any case, if you are using the sun.misc.Unsafe methods for setting final and private fields you'll need to update.
- well_ackshually 3mo ago>particularly around serialization/marshaling The solution being to drop those dogshit reflection based libraries as everyone should have done 10 years ago when codegen became more common. Looking at you, Gson.
- vips7L 3mo agoI swapped to Avaje Jsonb a while ago. Can’t recommend it and the rest of the Avaje libraries enough, especially Ebean instead of Hibernate.
- rvcdbn 3mo agooracle planning a new jvm language? have we ever seen a feature like this that is explicitly not usable from Java?
- Skinney 3mo agoThis is required in order to implement value classes in Java (project valhala).
- hueho 3mo agoIt's a VM feature - value classes will use it when they land eventually. https://openjdk.org/projects/valhalla/ https://openjdk.org/projects/valhalla/
- cogman10 3mo ago> have we ever seen a feature like this that is explicitly not usable from Java? Loads. Invoke dynamic and Nest-Based Access Control come to mind. This sort of thing is also about tightening the VM specification so things like Valhala are possible. Value classes really can't function reasonably without strict field initialization. That's because these value classes can have multiple copies while an application is running. If there's a way to go in and tinker with the fields before, after, or during initialization it could lead to very hard to fix and debug issues. 1 object in 2 parts of the code with different field values. And the reason for this tightening is because, from java, there are routes to violate this strict field initialization.
- vips7L 3mo agoAll the time. Oracle and the OpenJdk team do VM changes way more than language changes.
- someonebaggy 3mo agoinvokedynamic comes to mind. It was later used to implement lambda expressions but originally had no use in the Java language and isn't tailored to lambda expressions.
- deleted 3mo ago[deleted]
- joe_mwangi 3mo agoAlso, this will be used for future null-restricted types.
- exabrial 3mo agoThis a much needed change. Glad to see it! Might be some headaches in the short term, but thats ok.