-
-
Notifications
You must be signed in to change notification settings - Fork 33
Expand file tree
/
Copy pathspotbugs-exclude.xml
More file actions
109 lines (103 loc) · 5.4 KB
/
Copy pathspotbugs-exclude.xml
File metadata and controls
109 lines (103 loc) · 5.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
<!--
~ Copyright 2020-2020 Equinix, Inc
~ Copyright 2014-2020 The Billing Project, LLC
~
~ The Billing Project licenses this file to you under the Apache License, version 2.0
~ (the "License"); you may not use this file except in compliance with the
~ License. You may obtain a copy of the License at:
~
~ http://www.apache.org/licenses/LICENSE-2.0
~
~ Unless required by applicable law or agreed to in writing, software
~ distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
~ WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
~ License for the specific language governing permissions and limitations
~ under the License.
-->
<FindBugsFilter>
<Match>
<Or>
<Class name="org.killbill.billing.plugin.analytics.reports.KillBillBooleanExprLexer"/>
<Class name="org.killbill.billing.plugin.analytics.reports.KillBillBooleanExprParser"/>
<Class name="org.killbill.billing.plugin.analytics.reports.KillBillArithmeticExprLexer"/>
<Class name="org.killbill.billing.plugin.analytics.reports.KillBillArithmeticExprLexer$DFA6"/>
<Class name="org.killbill.billing.plugin.analytics.reports.KillBillArithmeticExprParser"/>
</Or>
</Match>
<!-- justification: this whole plugin's DTOs/DAOs (BusinessXXX, XXXModelDao, json.*) are plain data holders whose
getters/setters/constructors intentionally return or store their Collection/Map/DateTime fields directly
(no defensive copies), matching the same convention already excluded repo-wide in killbill/spotbugs-exclude.xml. -->
<Match>
<Class name="~org\.killbill\.billing\.plugin\.analytics\..*"/>
<Bug pattern="EI_EXPOSE_REP,EI_EXPOSE_REP2"/>
</Match>
<!-- justification: ObjectMapperProvider is a static utility exposing shared, intentionally mutable
Jackson ObjectMapper/ObjectWriter singletons; this is the same accessor-exposure pattern as
EI_EXPOSE_REP above, just flagged under the static-field variant of the bug. -->
<Match>
<Class name="org.killbill.billing.plugin.analytics.http.ObjectMapperProvider"/>
<Bug pattern="MS_EXPOSE_REP"/>
</Match>
<!-- justification: constructors below eagerly wire notification queues / JDBI-jOOQ metadata / parse
configuration and should fail fast during plugin startup if that eager initialization fails,
rather than defer the error. Same accepted pattern as killbill/spotbugs-exclude.xml. -->
<Match>
<Class name="org.killbill.billing.plugin.analytics.AnalyticsListener"/>
<Method name="<init>"/>
<Bug pattern="CT_CONSTRUCTOR_THROW"/>
</Match>
<Match>
<Class name="org.killbill.billing.plugin.analytics.api.core.AnalyticsConfiguration"/>
<Method name="<init>"/>
<Bug pattern="CT_CONSTRUCTOR_THROW"/>
</Match>
<Match>
<Class name="org.killbill.billing.plugin.analytics.dao.factory.BusinessContextFactory"/>
<Method name="<init>"/>
<Bug pattern="CT_CONSTRUCTOR_THROW"/>
</Match>
<Match>
<Class name="org.killbill.billing.plugin.analytics.reports.ReportsUserApi"/>
<Method name="<init>"/>
<Bug pattern="CT_CONSTRUCTOR_THROW"/>
</Match>
<Match>
<Class name="org.killbill.billing.plugin.analytics.reports.SqlReportDataExtractor"/>
<Method name="<init>"/>
<Bug pattern="CT_CONSTRUCTOR_THROW"/>
</Match>
<Match>
<Class name="org.killbill.billing.plugin.analytics.reports.scheduler.JobsScheduler"/>
<Method name="<init>"/>
<Bug pattern="CT_CONSTRUCTOR_THROW"/>
</Match>
<Match>
<Class name="org.killbill.billing.plugin.analytics.reports.sql.Metadata"/>
<Method name="<init>"/>
<Bug pattern="CT_CONSTRUCTOR_THROW"/>
</Match>
<!-- justification: org.jooq.Parser#parseQuery(String) never returns null (it throws ParserException on
failure); SpotBugs' interface-dispatch nullness inference cannot see that contract and flags a false
positive null dereference on the returned Query in these two call sites. -->
<Match>
<Class name="org.killbill.billing.plugin.analytics.reports.SqlReportDataExtractor"/>
<Method name="<init>"/>
<Bug pattern="NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE"/>
</Match>
<Match>
<Class name="org.killbill.billing.plugin.analytics.reports.sql.Metadata"/>
<Method name="getTemplateVariables"/>
<Bug pattern="NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE"/>
</Match>
<!-- justification: org.jooq.SelectConditionStep#and(Condition) is annotated @CheckReturnValue, but its
concrete implementation (org.jooq.impl.SelectImpl#and, jooq-3.14.16 sources) mutates the shared
underlying SelectQueryImpl in place and returns "this" rather than a new step. "statement" here is
that same mutable instance, so the call at SqlReportDataExtractor.java:149 already applies the
tenant_record_id condition to it even though the (identical) return value is not reassigned.
SpotBugs cannot see this same-instance mutation semantics from the annotation alone. -->
<Match>
<Class name="org.killbill.billing.plugin.analytics.reports.SqlReportDataExtractor"/>
<Method name="toString"/>
<Bug pattern="RV_RETURN_VALUE_IGNORED"/>
</Match>
</FindBugsFilter>