Skip to content

Soundness: a field of another class or object is read as this class's field with the same name #322

Description

@CatarinaGamboa

Description

Reading a field of another class or object (Limits.max, other.val) resolves to the current class's own field with the same name (this.max) when the current class has one. The wrong refinement is used, so real violations are accepted.

Minimal reproducer

import liquidjava.specification.Refinement;

class Limits {
    static final int max = 10;
}

public class Repro {
    int max = 5;                       // this class also has a field named max

    void check() {
        @Refinement("_ == 5") int k = Limits.max;   // expected error: Limits.max is 10
    }
}

Expected

A refinement error: Limits.max is 10, not 5.

Actual

Correct! Passed Verification.

Removing the field int max = 5; from Repro gives the expected error (k == 10 is not a subtype of k == 5), so the name clash is what hides it.

Reproduced on main at fbfb4e2.

Where

OperationsChecker.getOperationRefinements / RefinementTypeChecker.visitCtFieldRead: a CtFieldRead is named with Formats.THIS (this#<name>) regardless of its target, so any field read whose simple name matches a field of the current class picks up that field's refinement. The same shape affects enum constants (Format.JPG read as this.JPG when the class has a field JPG) and fields of other objects (other.val read as this.val).

Context

Found by the adversarial review of #319 (fix for #302). Pre-existing on main, independent of #319.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions