From 9ddddd86e18a0047d131d896ed1b1acf9cb582a4 Mon Sep 17 00:00:00 2001 From: Rahul Krishna Date: Tue, 29 Sep 2026 14:27:22 -0400 Subject: [PATCH] fix(artifacts): a non-identifier view-dispatch target is not a dataflow variable, not a NullPointerException ViewDispatches.resolve() ran the intra-procedural dataflow tier on s.varName() unguarded, but Site.varName() returns null for any dispatch target that is not a bare identifier -- a call expression like `return String.valueOf(count);` inside a @RestController, as seen in Robot Shop's shipping service (Controller.count()). Spring entrypoint detection does not yet distinguish @RestController from @Controller (SpringEntrypointFinder.isEntrypointClass matches on annotation.getNameAsString().contains("Controller")), so a REST endpoint's String return is still gated into the view-name tier. That null then reached DataflowTiers.intra and crashed in IntraTier.reachingLiteral's `var.equals(edge.getVar())` at analysis level >= 3. The very next tier down (interprocAll, L4) already guards the identical null with `s.varName() == null ? null : ...` -- the L3 call was just missing the equivalent check. Guarded `var == null` at the shared DataflowTiers.intra choke point rather than only at the call site, so any future caller is protected too. Added ViewNameDispatchTest.aNonIdentifierReturnExpressionStaysNonLiteralInsteadOfCrashing, reproducing the exact Robot Shop shape, and ViewDispatchDataflowTierTest.aCallExpressionTargetStaysNonLiteralInsteadOfCrashing for the analogous dispatcher-call-site shape; both reproduce the NPE on the old code and pass with the guard. Full suite: 606 tests, only the Docker-only integration test unrun (no local Docker daemon). Separately, @RestController return values are HTTP response bodies, not Spring view names -- conflating them with @Controller in SpringEntrypointFinder is a real semantic gap, left untouched here since it changes detection scope rather than just fixing the crash. --- .../com/ibm/cldk/artifacts/DataflowTiers.java | 3 ++- .../ViewDispatchDataflowTierTest.java | 15 +++++++++++ .../cldk/artifacts/ViewNameDispatchTest.java | 26 +++++++++++++++++++ 3 files changed, 43 insertions(+), 1 deletion(-) diff --git a/src/main/java/com/ibm/cldk/artifacts/DataflowTiers.java b/src/main/java/com/ibm/cldk/artifacts/DataflowTiers.java index 1e823745..d6fa8758 100644 --- a/src/main/java/com/ibm/cldk/artifacts/DataflowTiers.java +++ b/src/main/java/com/ibm/cldk/artifacts/DataflowTiers.java @@ -65,7 +65,8 @@ private static void collect(Map types, String source, Map