Skip to content

Avoid implicit narrowing compound assignments in SchemaTypeSystemImpl.nextBytes - #129

Merged
pjfanning merged 1 commit into
apache:trunkfrom
pjfanning:fix-implicit-narrowing-casts
Oct 4, 2026
Merged

pjfanning merged 1 commit into
apache:trunkfrom
pjfanning:fix-implicit-narrowing-casts

Conversation

@pjfanning

Copy link
Copy Markdown
Member

Fixes code-scanning alerts #6 and #7 (java/implicit-cast-in-compound-assignment) in SchemaTypeSystemImpl.nextBytes. The byte wraparound is intended, so the two byte compound assignments are now one assignment with an explicit (byte) cast.

While there, two fixes in the same method. Both affect only how random the generated type-system names are:

  • The mixing loop added the index i and never read bytes[i], so the mask depended only on how many bytes of system info there were, not on their content.
  • The mask was indexed with i & _mask.length (i & 16), which is always 0 for i in 0..15, so only _mask[0] was ever applied. It is now i % _mask.length, like the earlier loop.

Alerts #1–#5 (GDurationBuilder, GDateBuilder, PushedInputStream) were raised against an older commit and are already fixed on trunk, so they should close on the next scan.

🤖 Generated with Claude Code

….nextBytes

Fixes code-scanning alerts for java/implicit-cast-in-compound-assignment.
Also mix the system-info bytes (not just their index) into the mask, and
index the mask with % rather than & so all mask bytes are used.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@pjfanning
pjfanning merged commit 7d4d483 into apache:trunk Oct 4, 2026
3 checks passed
@pjfanning
pjfanning deleted the fix-implicit-narrowing-casts branch October 4, 2026 15:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant