Skip to content

[maven-4.0.x] DefaultMaven: LegacySupport.setSession() thread safety in @Singleton #12594

Description

@elharo

DefaultMaven: LegacySupport.setSession() thread safety in @singleton

Found in: maven-4.0.x branch
File: impl/maven-core/src/main/java/org/apache/maven/DefaultMaven.java (lines 225, 161)
Severity: High

Description

DefaultMaven is annotated @Singleton, meaning a single instance is shared across the application. LegacySupport is a thread-local-like holder for the current MavenSession. The setSession() calls at lines 225 and 161 are not synchronized:

// line 225:
legacySupport.setSession(session);

// line 161 (in finally):
legacySupport.setSession(null);

If execute() were called concurrently from multiple threads, calls to setSession() and setSession(null) from different threads would race, causing sessions to leak or be corrupted. While Maven is traditionally single-threaded per JVM, the @Singleton annotation combined with mutable instance state is a latent concurrency bug.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingmvn4

    Type

    No type

    Projects

    No projects

      Milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions