Commit Graph
35145 Commits
Author SHA1 Message Date
Juergen Hoeller b2181e7da4 Remove DOCTYPE declaration (stricter enforcement by XMLUnit) 2026-10-06 20:25:57 +02:00
Juergen Hoeller 0f573d314e Upgrade to SnakeYAML 2.7, Protobuf 4.36.2, Eclipse Yasson 3.0.5, FreeMarker 2.3.35, WebJars Locator Lite 1.1.5, JRuby 10.1.2, XMLUnit 2.14 2026-10-06 19:57:44 +02:00
Juergen Hoeller f660a68319 Reliably unpause execution thread in case of late shutdown
Closes gh-37406
2026-10-06 19:14:07 +02:00
Brian Clozel f0f71009b2 Fix lost completion in PartGenerator CreateFileState
Prior to this commit, `CreateFileState.onComplete()` would only set
its own `completed` flag. If `fileCreated()` had already switched to
`WritingFileState`, the flag was written to a superseded state and the
completion signal was lost, so the part was never emitted.

This commit re-reads the current state after setting the flag and
delegates to it when it has changed, as `WritingFileState` does.

Fixes gh-37409
2026-10-06 17:11:20 +02:00
Sam Brannen 1ef3d070c9 Revise contribution
- Add tests for @⁠CachePut, @⁠Cacheable, and
  @⁠CacheEvict with Flux resubscription in
  ReactiveCachingTests, using plain Reactor retry() instead of
  @⁠Retryable.
- Reduce the block() timeouts in ReactiveRetryInterceptorTests from 5
  seconds to 1 second so that regressions fail faster.

See gh-37403
2026-10-06 16:09:00 +02:00
Hyunwoo Jung 440139fec1 Fix Flux resubscription in reactive caching
Fix an existing bug in processPutRequest() affecting `@Cacheable`
and `@CachePut` since 6.1: resubscription after an error hangs while
publish().refCount(2) waits for a second subscriber.

Also fix an unreleased regression introduced by 26de340 (gh-37309) for
`@CacheEvict`, which copied the same pattern into processCacheEvicts().

Create the shared Flux and cache subscriber for each subscription
via Flux.defer(). Add regression tests combining reactive caching
with `@Retryable`.

See gh-37309
Closes gh-37403

Signed-off-by: Hyunwoo Jung <hyunwoojung@kakao.com>
2026-10-06 16:02:00 +02:00
Tran Ngoc Nhan 3709672494 Fix Kotlin examples in the reference manual
This commit fixes the following issues in the reference manual.

- Remove the dangling opening brace from the Kotlin `PlaceOfBirth`
  example in example-classes.adoc.
- Use `JsonView::class.java.name` instead of
  `JsonView::class.qualifiedName` in the Kotlin examples in
  jackson.adoc, since `qualifiedName` is nullable whereas
  `Model#set()` does not accept a null key.
- Remove unnecessary semicolons after the empty interface bodies in the
  Java examples in jackson.adoc.

Closes gh-37101

Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com>
2026-10-06 15:48:32 +02:00
Brian Clozel 2e478e52d8 Document the XXE threat model of SourceHttpMessageConverter
This commit adds Javadoc content to the `SourceHttpMessageConverter` to
better explain the threat model around XMLserialization/deserialization.

Closes gh-37407
2026-10-06 14:51:27 +02:00
Sam Brannen 4a75bbb3a1 Ignore unused lambda parameters in Eclipse
Since commit bda69f0ce2, Eclipse projects use a Java 24 baseline in
spring-core, so Eclipse flags unused lambda parameters (Java 22+) as
warnings. This commit configures the setting to be ignored, as is
already done for unused method parameters.

See gh-37397
2026-10-06 11:43:07 +02:00
Sam Brannen 4aba35b268 Remove unused nested class 2026-10-06 11:31:15 +02:00
Juergen Hoeller 2abe09ea1c Upgrade to JSpecify 1.0.1, Tomcat 11.0.26, Jetty 12.1.14, EclipseLink 5.0.2, Hibernate ORM 7.2.25, Hibernate Validator 9.1.4, Caffeine 3.3, Mockito 5.24, Checkstyle 14.3 2026-10-05 17:21:03 +02:00
Juergen Hoeller 0a84a41b3a Polishing 2026-10-05 17:20:54 +02:00
Juergen Hoeller 08e8408b45 Align fallback implementation with AbstractMessageSource
Closes gh-37383
2026-10-05 17:20:45 +02:00
Juergen Hoeller ee1aac605b Add runtime compatibility with JPA 4.0 M7 and Hibernate ORM 8.0
Closes gh-37315
2026-10-05 17:20:28 +02:00
Sam Brannen bda69f0ce2 Support multi-release sources in Eclipse
Prior to this commit, the Java 21 and Java 24 multi-release sources in
spring-core could not be developed or tested within Eclipse, since an
Eclipse project supports only a single Java compliance level.

This commit configures Eclipse projects that use the multiReleaseJar
plugin with the highest multi-release version as their Java baseline
(Java 24 for spring-core) and includes the corresponding multi-release
source folders. Types which are overridden by a multi-release source
folder are excluded from lower source folders, and higher source
folders are placed first so that the debugger's source lookup resolves
overriding types.

A lower baseline can be configured via the "eclipseJavaBaseline"
project property: for example, -PeclipseJavaBaseline=17.

See gh-37397
2026-10-05 17:06:51 +02:00
Sam Brannen 46d7ffde9c Exclude multi-release outputs from Eclipse classpath
Although the multi-release source sets in spring-core were already
excluded from the Eclipse classpath, their Gradle output directories
(such as build/classes/java/java21) were still added as libraries
once they existed, resulting in duplicate types on the classpath.

This commit removes those entries as well, generalizes the exclusion
to any Java release version, revises the outdated comment in
ide.gradle, and documents the limitation in the Eclipse import
instructions.

See gh-37397
2026-10-05 15:56:42 +02:00
Sam Brannen 328def4b23 Update Eclipse IDE import instructions
This commit updates the Eclipse import instructions for modern versions
of Eclipse IDE and Spring Tools for Eclipse (STS no longer exists as a
product), and notes that the Eclipse IDE for Java Developers package
works as well.

- All references to Buildship have been removed, since we don't use it.
  Projects are now imported via "Existing Projects into Workspace"
  after running `./gradlew testClasses` and
  `./gradlew cleanEclipse eclipse`.
- Obsolete advice has been removed: Kotlin/AJDT compatibility notes,
  the manual JAXB source folder step, and the JDK 8 and `MaxPermSize`
  hints.
- The `--add-opens` and `-Xshare:off` VM options that the Gradle build
  applies to tests are now documented.
- The broken TestNG link has been replaced with the Eclipse Marketplace
  one.

Closes gh-37397
2026-10-05 15:11:10 +02:00
Sébastien Deleuze 90400757e8 Avoid Kotlin reflection for non-suspending return types
Previously, KotlinDelegate.getReturnType() and getGenericReturnType()
resolved the KFunction of every Kotlin method, which materializes the
members of the declaring KClass and is costly at startup. Kotlin
reflection is only needed to resolve the return type of suspending
functions, so both methods now only use it when
KotlinDetector.isSuspendingFunction() returns true.

Closes gh-37300

Signed-off-by: Sébastien Deleuze <sdeleuze@users.noreply.github.com>
2026-10-05 10:53:14 +02:00
Sam Brannen 14dc767dd6 Fix syntax errors in code examples in reference manual
This commit fixes syntax errors in Java, Kotlin, and XML examples in
the reference manual, such as Java syntax in Kotlin examples,
unbalanced braces and parentheses, and unclosed XML elements.

Closes gh-37392
2026-10-04 15:27:56 +02:00
머랭 f96403da2a Fix cached ID reuse after commit failure in MySQLMaxValueIncrementer
Invalidate the cached ID range when commit or auto-commit restoration
fails so subsequent calls obtain a new range from the database.

Closes gh-37322

Signed-off-by: cookie-meringue <daehyeon3351@gmail.com>
2026-10-04 13:09:52 +02:00
Tran Ngoc Nhan eb9928f993 Fix Kotlin example in Spring MVC test docs
This commit updates spring-mvc-test-client.adoc to use valid Kotlin
syntax for a constructor.

Closes gh-37388

Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com>
2026-10-04 12:48:25 +02:00
머랭 5e45b9be1b Fix connection leak in MySQLMaxValueIncrementer
Move connection cleanup into a finally block so the connection
is closed even if commit or auto-commit restoration fails.

Closes gh-37321

Signed-off-by: cookie-meringue <daehyeon3351@gmail.com>
2026-10-03 18:36:50 +02:00
Hyunwoo Jung f03b76a53d Copy cookies in RenderingResponse.from()
Prior to this commit, RenderingResponse.from() did not copy the
cookies of the given response, unlike ServerResponse.from().

See gh-22481
Closes gh-37378

Signed-off-by: Hyunwoo Jung <hyunwoojung@kakao.com>
2026-10-03 14:14:09 +02:00
Sam Brannen d5a7fc9a9c Update exception message in HttpMessageNotReadableException
See gh-33809
2026-10-03 13:59:21 +02:00
Sébastien Deleuze c377da58d9 Make CONTRIBUTING.md self-contained and add AGENTS.md
Prior to this commit, CONTRIBUTING.md delegated build instructions
and code style to wiki pages, which are planned for removal.

This commit inlines the build, code style and testing guidelines
into CONTRIBUTING.md, aligns them with the current build and
Checkstyle rules, and documents the commit message conventions, the
security policy and the policy on AI-assisted contributions. It also
adds a concise AGENTS.md extract for coding agents, and updates the
README to link to the Build from Source section.

Closes gh-37372

Signed-off-by: Sébastien Deleuze <sdeleuze@users.noreply.github.com>
2026-10-02 16:48:13 +02:00
Rene Schakmann 23cdf8465c Clarify ConcurrentReferenceHashMap reference semantics
Prior to this commit, the Javadoc for ConcurrentReferenceHashMap
stated that soft or weak references are used for both keys and values.

However, the references are applied to the internal map entries, each
of which holds strong references to its key and value. Consequently,
an entry may be discarded even if its key and value are still strongly
reachable from elsewhere, which differs from the semantics of
WeakHashMap.

This commit revises the class-level Javadoc as well as the Javadoc for
the ReferenceType constants to document this behavior.

See gh-24253
Closes gh-37357

Signed-off-by: rene.schakmann <rene.schakmann@reetgroup.com>
2026-10-02 15:13:24 +02:00
Sam Brannen 105c39bab7 Document type support in JSP <form:input> and point to <form:password>
Prior to this commit, the reference manual mentioned that the JSP
<form:input> tag supports HTML5-specific types, but the Javadoc and
spring-form.tld did not document the `type` attribute at all, and none
of the documentation explained which types are supported or that
<form:password> must be used for password fields.

This commit updates the documentation as follows.

- Document in InputTag, spring-form.tld, and the reference manual that
  a `type` can be supplied as a dynamic attribute, that `checkbox` and
  `radio` are not supported, and that the bound value is rendered as-is.
- Add notes to InputTag, the reference manual, and spring-form.tld
  stating that <form:input type="password"> must not be used and that
  <form:password> should be used instead.
- Document in PasswordInputTag, spring-form.tld, and the reference
  manual that <form:password> does not render the bound value by default.

Closes gh-37376
2026-10-02 13:41:27 +02:00
Sam Brannen 846521d8c5 Work around Eclipse compiler type inference errors
Eclipse fails to infer the generic types in XmlEventDecoder and
DefaultWebClient, even though javac and IntelliJ IDEA compile the code
without issues.

This commit introduces explicit type arguments for the calls to
flatMapIterable() and exceptionWrappingFunction() to work around those
bugs.
2026-10-01 12:09:57 +02:00
Sam Brannen 3a600481d2 Polish code base
- Remove redundant super() calls from constructors
- Add missing @⁠Override annotations
- Use switch rules in JdkClientHttpRequest and RfcUriParser
- Use instanceof pattern matching
- Use method references instead of trivial lambda expressions
- Use lambda expressions instead of anonymous inner classes
- Remove unused code and redundant semicolons
- Use braces with if-blocks
2026-09-30 17:08:47 +02:00
Sam Brannen 043442a2a1 Test single-value to primitive array adaptation via @⁠AliasFor
This commit adds a test to MergedAnnotationsTests that verifies a
single primitive attribute in a composed annotation can be aliased via
@⁠AliasFor to a primitive array attribute in a meta-annotation.

See gh-37349
2026-09-30 13:42:35 +02:00
Chengang Guan 6afb65b225 Fix single-value adaptation for primitive array types in TypeMappedAnnotation
Prior to this commit, `adaptForAttribute(Method, Object)` created
the wrapping array from `value.getClass()` when a single non-array
value was provided for an array attribute. This worked for object
array types but failed for primitive array types: wrapping a boxed
value produced a boxed array, which then failed the compatibility
check and threw an `IllegalStateException`.

This commit derives the component type from the declared attribute
type when it is assignable from the value type, falling back to
`value.getClass()` otherwise. The existing adaptation path for
object array types is therefore preserved, and all primitive array
types now accept a single value.

The accompanying test covers single-value wrapping for every array
type declared by ArrayTypes.

Closes gh-37349

Signed-off-by: Chengang Guan <guanchengang@qq.com>
2026-09-30 13:37:25 +02:00
Sam Brannen 4d3beb5c3b Stop using Tomcat's deprecated addServletMappingDecoded() method
(cherry picked from commit 4f51801320)
2026-09-30 12:50:37 +02:00
김준형 1b4955e49f Avoid phantom keys in LinkedCaseInsensitiveMap.computeIfAbsent
computeIfAbsent registered the case-insensitive key before invoking the
mapping function. If the function returned null or threw an exception,
no mapping was recorded in the target map, but the key registration was
left behind. The map then reported containsKey(key) as true while size()
was 0, keySet() was empty, and get(key) returned null. A later insertion
with a different casing also reused the stale casing of the failed call,
since the existing-key branch resolved to the registered key.

The case-insensitive key is now only looked up up front. For a new key,
it is registered from within the mapping function once a non-null value
has been computed, which is still before the entry is inserted. A null
result or an exception therefore leaves both maps untouched, while a
removeEldestEntry override that evicts the new entry right away still
removes the registration, as it does for put. The existing-key path
keeps computing under the stored casing.

Closes gh-37351

Signed-off-by: junhyeong9812 <pickjog@gmail.com>
2026-09-30 12:47:30 +02:00
Sébastien Deleuze 06c597ed6f Use equality check for value class KClass comparison
KClass instances representing the same class are not guaranteed to be
identical, so the overridden function return type check introduced in
c39edeff15 could wrongly skip unboxing, for example when a class
implements an interface declaring the same suspending function.

See gh-37191
2026-09-30 10:23:53 +02:00
Sébastien Deleuze c39edeff15 Refine Kotlin value class contribution
Only unbox value class results when the caller expects their unboxed
representation (non-primitive underlying type, non-nullable underlying
type for nullable return types, and no overridden function with a
different return type), and add related tests.

Cache the unbox method resolution per method and make it accessible
to support non-public value classes.

Closes gh-37191
2026-09-29 16:49:17 +02:00
Dmitry Sulman c08fd24de3 Fix value class return handling for suspending AOP methods
Unbox Kotlin value class results returned from proxied suspending
methods before returning them to the caller.

Spring AOP interceptor chains expose return values as Object, which
causes Kotlin value class results to be boxed. For suspending functions,
the direct return path expects the unboxed value class representation.

Update both CglibAopProxy and JdkDynamicAopProxy to detect value class
return types and unbox boxed results after coroutine adaptation.

Add tests for suspending methods returning value classes.

See gh-37191
See gh-37155

Signed-off-by: Dmitry Sulman <dmitry.sulman@gmail.com>
2026-09-29 15:01:39 +02:00
Sam Brannen c70c434486 Recognize relocated Mockito MockAccess interface
Since Mockito 5.16.1, MockAccess moved from
org.mockito.internal.creation.bytebuddy.MockAccess to
org.mockito.internal.creation.bytebuddy.access.MockAccess.

Consequently, ProxyProcessorSupport.isInternalLanguageInterface() no
longer recognized it, causing an auto-proxied mock created with the
subclass mock maker and proxyTargetClass=false to receive a JDK proxy
that only implements MockAccess instead of a CGLIB proxy of its own
class.

This commit adds a check for the new package name alongside the
existing one, since older Mockito versions may still be on the
classpath.

Closes gh-37342
2026-09-28 18:38:07 +02:00
Tran Ngoc Nhan e19e17eca5 Add missing enclosing single quotes in Javadoc
Closes gh-37338

Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com>
2026-09-28 10:43:38 +02:00
Hyunwoo Jung fd23ae2393 Fix MockMvc async requests example in documentation
See gh-24103
Closes gh-37318

Signed-off-by: Hyunwoo Jung <hyunwoojung@kakao.com>
2026-09-25 17:39:02 +02:00
Brian Clozel a2e3c0d81d Skip invalid links in CssLinkResourceTransformer
Prior to this commit, both `CssLinkResourceTransformer` implementations
could fail at runtime in case of invalid CSS links (for example, with
out of bounds exceptions).

This commit skips invalid links and writes them out to the resulting CSS
without any transformation.

Fixes gh-37336
2026-09-25 17:06:28 +02:00
Sam Brannen 24645069f9 Upgrade to Gradle 9.8
Closes gh-37160
2026-09-25 16:14:12 +02:00
Brian Clozel 1cfc7f8ebc Do not perform expansion on license file 2026-09-22 22:17:57 +02:00
Brian Clozel 7be3a61a14 ResponseStatusException should not override custom reason
Prior to this commit, `ResponseStatusException` would resolve the
"detail" part of a problem detail response from message codes only
(default or custom ones). If the `reason` given as an argument to the
exception was a custom message, it would be overwritten in the process.

This commit ensures that we use custom reason messages when they don't
resolve as message codes.

Fixes gh-36984
2026-09-22 16:56:40 +02:00
Sam Brannen edd497c20f Polish Javadoc and reference documentation for caching annotations
This commit documents the semantics for the `#result` SpEL expression
variable for a method that returns a Flux for @⁠Cacheable and
@⁠CachePut, both of which have always collected such a Flux's values
into a List. For such a method, `#result` refers to that List rather
than the Flux itself.

This commit addresses a number of unrelated inconsistencies in the
documentation as well.

See gh-37309
2026-09-21 17:16:43 +02:00
Sam Brannen 26de340102 Stop truncating Flux results to first element with @⁠CacheEvict
Prior to this commit, ReactiveCachingHandler.processCacheEvicts()
adapted every reactive return value via Mono.from(), which subscribes
for only the first element and cancels the upstream Publisher. For a
@⁠CacheEvict method that returns a Flux, this silently truncated the
returned sequence to its first element. In addition, the `#result`
variable in `condition` SpEL expressions was bound to only that first
emitted element.

To address that, this commit mirrors the existing multi-value handling
in processPutRequest(). When the adapter reports isMultiValue(), a side
Subscriber is subscribed via publish().refCount(2) that exhausts the
Flux and collects its values into a List for eviction, while the
original, unmodified Flux is returned to the caller. Consequently, the
`#result` variable in `condition` SpEL expressions for a Flux-returning
@⁠CacheEvict method is now the full List of emitted elements rather
than just the first element, making it consistent with @⁠Cacheable and
@⁠CachePut.

This commit also improves spr14235AdaptsToReactorFlux() in
CacheReproTests. Previously it exercised @⁠CacheEvict only with a
single-element Flux and never asserted on the returned sequence. Now it
uses a multi-element Flux and verifies that all elements are both
returned to the caller and visible to the `condition` expression.

Last but not least, this commit documents the aforementioned
`#result`/Flux semantics in @⁠CacheEvict's Javadoc and in the reference
manual, since both were previously invalid or incomplete for this
scenario.

Closes gh-37309
2026-09-21 17:16:34 +02:00
이태경 9637d12785 Fix target-class counter assertions in AOP tests
Both target-class tests asserted the target-interface counter,
leaving the intended pointcut unchecked. Assert the target-class
counter in both the XML and @⁠AspectJ variants.

Closes gh-37310

Signed-off-by: itaekyung <taeyun1411@gmail.com>
2026-09-20 16:34:09 +02:00
Tran Ngoc Nhan a8608e681b Remove redundant whitespace in exception messages
Closes gh-37277

Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com>
2026-09-20 14:58:09 +02:00
Sam Brannen 48b59dfaec Polish contribution
See gh-37305
2026-09-19 19:39:48 +02:00
Tran Ngoc Nhan b5454b1a69 Add closing braces to examples
Closes gh-37305

Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com>
2026-09-19 19:36:24 +02:00
Juergen Hoeller 83ecf67455 Match manifest-specified jar names with pre-encoded escape sequence
Closes gh-37280
2026-09-18 20:58:46 +02:00