[
https://issues.apache.org/jira/browse/WW-5724?focusedWorklogId=1040939&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1040939
]
ASF GitHub Bot logged work on WW-5724:
--------------------------------------
Author: ASF GitHub Bot
Created on: 11/Sep/26 13:28
Start Date: 11/Sep/26 13:28
Worklog Time Spent: 10m
Work Description: sonarqubecloud[bot] commented on PR #1914:
URL: https://github.com/apache/struts/pull/1914#issuecomment-5635139330
## [](https://sonarcloud.io/dashboard?id=apache_struts&pullRequest=1914)
**Quality Gate passed**
Issues
 [0 New
issues](https://sonarcloud.io/project/issues?id=apache_struts&pullRequest=1914&issueStatuses=OPEN,CONFIRMED&sinceLeakPeriod=true)
 [0 Accepted
issues](https://sonarcloud.io/project/issues?id=apache_struts&pullRequest=1914&issueStatuses=ACCEPTED)
Measures
 [0 Security
Hotspots](https://sonarcloud.io/project/security_hotspots?id=apache_struts&pullRequest=1914&issueStatuses=OPEN,CONFIRMED&sinceLeakPeriod=true)
 [100.0% Coverage on New
Code](https://sonarcloud.io/component_measures?id=apache_struts&pullRequest=1914&metric=new_coverage&view=list)
 [0.0% Duplication on New
Code](https://sonarcloud.io/component_measures?id=apache_struts&pullRequest=1914&metric=new_duplicated_lines_density&view=list)
<!
Issue Time Tracking
-------------------
Worklog Id: (was: 1040939)
Time Spent: 20m (was: 10m)
> Cached MessageFormat instances in AbstractLocalizedTextProvider are shared
> between concurrent callers
> -----------------------------------------------------------------------------------------------------
>
> Key: WW-5724
> URL: https://issues.apache.org/jira/browse/WW-5724
> Project: Struts 2
> Issue Type: Bug
> Reporter: Lukasz Lenart
> Priority: Major
> Fix For: 6.12.0, 7.4.0
>
> Time Spent: 20m
> Remaining Estimate: 0h
>
> h2. Summary
> {{AbstractLocalizedTextProvider}} caches {{java.text.MessageFormat}}
> instances keyed by pattern and locale and returns the cached instance from
> {{buildMessageFormat}}, while {{DefaultTextProvider}} builds a fresh instance
> per call. {{MessageFormat}} is not thread-safe, so callers rendering the same
> message concurrently format through one shared instance.
> h2. Current behaviour
> {{buildMessageFormat}} returns the cached instance on a hit and
> {{formatWithNullDetection}} calls {{format()}} on it directly. The provider
> is a singleton bean, so the cache and every instance in it are shared
> application-wide. The sibling {{DefaultTextProvider.getText}} constructs a
> new {{MessageFormat}} on each call.
> A pattern carrying a date or time sub-format delegates to a
> {{SimpleDateFormat}} held by the {{MessageFormat}}, which keeps per-call
> state in its {{Calendar}}; concurrent {{format()}} calls on the shared
> instance can render the wrong argument or throw. Number and choice
> sub-formats and plain placeholders are not affected on current JDKs.
> h2. Proposed change
> Keep the cache, but have {{buildMessageFormat}} return a clone of the cached
> instance, so the cached entry is only ever a template and is never formatted
> directly. {{MessageFormat.clone()}} deep-copies its sub-formats. This
> preserves the pattern-parsing cache the WW-5540 work relies on; measured
> against a fresh instance per call and against synchronizing on the shared
> instance, cloning is the cheapest of the three.
> h2. Compatibility notes
> No configuration or API change. Descendant classes that override
> {{buildMessageFormat}} keep their current behaviour; only the base
> implementation changes.
> Applies to both maintenance lines.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)