slachiewicz opened a new issue, #13200:
URL: https://github.com/apache/maven/issues/13200

   ### Affected version
   
   3.9.x and master (same code on both).
   
   ### Bug description
   
   `MavenProject.getArtifacts()` initialises its set lazily and assigns the 
field before filling it:
   
   ```java
   artifacts = new LinkedHashSet<>(resolvedArtifacts.size() * 2);
   for (Artifact artifact : resolvedArtifacts) {
       if (artifactFilter.include(artifact)) {
           artifacts.add(artifact);
       }
   }
   ```
   
   ([maven-3.9.x 
MavenProject.java:675](https://github.com/apache/maven/blob/maven-3.9.x/maven-core/src/main/java/org/apache/maven/project/MavenProject.java#L675),
 [master 
MavenProject.java:897](https://github.com/apache/maven/blob/master/impl/maven-core/src/main/java/org/apache/maven/project/MavenProject.java#L897))
   
   A second thread calling `getArtifacts()` during the loop receives the 
half-built set and any iteration over it throws 
`ConcurrentModificationException` while the first thread keeps adding. The 
`MojoExecutor` project and aggregator locks keep mojo executions apart, so in a 
plain build the two callers should not overlap; the trace in 
apache/maven-plugin-tools#852 (`maven-plugin-plugin:descriptor` on a parallel 
build, `LinkedHashMap$LinkedHashIterator.nextNode` under 
`JavaAnnotationsMojoDescriptorExtractor.extendJavaProjectBuilder`) shows that 
something does overlap. The trigger there is not identified; the publication 
itself is unsafe regardless.
   
   Fill a local set and assign it once, so a concurrent reader sees either 
`null` handling or a complete set:
   
   ```java
   Set<Artifact> result = new LinkedHashSet<>(...);
   for (...) { ... result.add(artifact); }
   artifacts = result;
   ```
   
   The same pattern exists in `getArtifactMap()` / `getDependencyArtifacts()` 
and is worth the same treatment.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to