Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-49054

Lack of finally block in TreeUnmarshaller can cause DescribableList to throw ClassCastException or NoSuchMethodException


      TreeUnmarshaller in XStream has a bug that it pushes a class onto a types stack but fails to pop it in a finally block. Then if there is an error, the context's requiredType will be bogus, which can confuse DescribableList.ConverterImpl.unmarshal as it tries to pick the right kind of list to create—it will find the type of one of the list's elements. You will end up with a ClassCastException if that type has a public no-arg constructor, or a NoSuchMethodException if it does not. The XStream bug is aggravated by the order in which the Jenkins code calls things.

      Not to be confused with JENKINS-27736, which is quite different.

            jglick Jesse Glick
            jglick Jesse Glick
            0 Vote for this issue
            3 Start watching this issue