paulrutter commented on PR #564:
URL: https://github.com/apache/felix-dev/pull/564#issuecomment-6016527461

   Agreed, and thanks for checking the osgi.core 8.0.0 sources. The contract is 
broken in `ResourceImpl.getCapabilities(String)` and `getRequirements(String)`. 
With a `null` namespace they return the live internal `caps` / `reqs` list, 
while `Resource` documents the result as "an unmodifiable list". With a 
non-null namespace they return a fresh copy, so only the `null` case is 
affected. That behaviour predates this PR; it comes from the original 
"optimized resource" implementation (5a07d17328).
   
   This PR doesn't introduce the violation, but it makes it matter: the cached 
hash is only invalidated by the `add*` methods, so a caller that mutates the 
list returned for `null` bypasses the invalidation. I'm fine with leaving it as 
is, since returning the live list avoids an allocation per call. It may be 
worth a short comment on those two methods saying the `null`-namespace result 
is the live list and must not be modified.
   
   Bumping this in Karaf sounds right, since it's the downstream consumer and 
the place a subclass using the formerly protected fields would break.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to