slachiewicz opened a new issue, #13200:
URL: https://github.com/apache/maven/issues/13200
### Affected version
3.9.x and master (same code on both).
### Bug description
`MavenProject.getArtifacts()` initialises its set lazily and assigns the
field before filling it:
```java
artifacts = new LinkedHashSet<>(resolvedArtifacts.size() * 2);
for (Artifact artifact : resolvedArtifacts) {
if (artifactFilter.include(artifact)) {
artifacts.add(artifact);
}
}
```
([maven-3.9.x
MavenProject.java:675](https://github.com/apache/maven/blob/maven-3.9.x/maven-core/src/main/java/org/apache/maven/project/MavenProject.java#L675),
[master
MavenProject.java:897](https://github.com/apache/maven/blob/master/impl/maven-core/src/main/java/org/apache/maven/project/MavenProject.java#L897))
A second thread calling `getArtifacts()` during the loop receives the
half-built set and any iteration over it throws
`ConcurrentModificationException` while the first thread keeps adding. The
`MojoExecutor` project and aggregator locks keep mojo executions apart, so in a
plain build the two callers should not overlap; the trace in
apache/maven-plugin-tools#852 (`maven-plugin-plugin:descriptor` on a parallel
build, `LinkedHashMap$LinkedHashIterator.nextNode` under
`JavaAnnotationsMojoDescriptorExtractor.extendJavaProjectBuilder`) shows that
something does overlap. The trigger there is not identified; the publication
itself is unsafe regardless.
Fill a local set and assign it once, so a concurrent reader sees either
`null` handling or a complete set:
```java
Set<Artifact> result = new LinkedHashSet<>(...);
for (...) { ... result.add(artifact); }
artifacts = result;
```
The same pattern exists in `getArtifactMap()` / `getDependencyArtifacts()`
and is worth the same treatment.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]