[java] Guard against NPE in Platform.extractFromSysProperty - #17151

Merged
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean
Mar 1, 2026
Merged

[java] Guard against NPE in Platform.extractFromSysProperty#17151
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean

Conversation

@seethinajayadileep

@seethinajayadileepseethinajayadileep commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

💥 What does this PR do?

Prevents a possible NullPointerException in
Platform.extractFromSysProperty(String osName, String osVersion).

Previously:

  • osName and osVersion were assumed to be non-null
  • Calls such as osVersion.equals("6.2") could throw NullPointerException
  • The public 2-argument method could receive null directly from callers

This PR makes the method defensive against null inputs.


🔧 Implementation Notes

The following changes were made:

  1. Normalize osName and osVersion using Objects.requireNonNullElse:

    osName = requireNonNullElse(osName, "");
    osVersion = requireNonNullElse(osVersion, "");
    osName = osName.toLowerCase(Locale.ENGLISH);
  2. Provide a safe default when reading the system property:

    System.getProperty("os.version", "")

These changes ensure:

  • No NPE when null is passed to the public 2-argument method
  • No NPE during version comparisons
  • Existing platform detection logic remains unchanged

💡 Additional Considerations

  • Backwards compatible change
  • No modification to detection heuristics
  • Default behavior continues to fall back to UNIX when no match is found
  • Improves defensive robustness for external callers

🔄 Types of changes

  • Bug fix (backwards compatible)

@qodo-code-review

Copy link
Copy Markdown
Contributor

PR Type

Bug fix


Description

  • Guard against NullPointerException in Platform.extractFromSysProperty

  • Normalize null osName and osVersion parameters to empty strings

  • Provide safe default for System.getProperty("os.version") call

  • Maintain backwards compatibility and existing platform detection behavior


File Walkthrough

Relevant files
Bug fix
Platform.java
Add null-safety guards to Platform.extractFromSysProperty

java/src/org/openqa/selenium/Platform.java

  • Added null-safety checks for osName and osVersion parameters by
    normalizing them to empty strings
  • Modified single-argument extractFromSysProperty to provide empty
    string default for System.getProperty("os.version")
  • Prevents NullPointerException when system properties are restricted or
    null values are passed
  • Maintains existing platform detection logic and backwards
    compatibility
+3/-1

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Compliance Guide 🔍

Below is a summary of compliance checks for this PR:

Security Compliance
🟢
No security concerns identified No security vulnerabilities detected by AI analysis. Human verification advised for critical code.
Ticket Compliance
🎫 No ticket provided
  • Create ticket/issue
Codebase Duplication Compliance
Codebase context is not defined

Follow the guide to enable codebase context checks.

Custom Compliance
🟢
Generic: Comprehensive Audit Trails

Objective: To create a detailed and reliable record of critical system actions for security analysis
and compliance.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Meaningful Naming and Self-Documenting Code

Objective: Ensure all identifiers clearly express their purpose and intent, making code
self-documenting

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Robust Error Handling and Edge Case Management

Objective: Ensure comprehensive error handling that provides meaningful context and graceful
degradation

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Error Handling

Objective: To prevent the leakage of sensitive system information through error messages while
providing sufficient detail for internal debugging.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Logging Practices

Objective: To ensure logs are useful for debugging and auditing without exposing sensitive
information like PII, PHI, or cardholder data.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Security-First Input Validation and Data Handling

Objective: Ensure all data inputs are validated, sanitized, and handled securely to prevent
vulnerabilities

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

  • Update
Compliance status legend 🟢 - Fully Compliant
🟡 - Partial Compliant
🔴 - Not Compliant
⚪ - Requires Further Human Verification
🏷️ - Compliance label

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Code Suggestions ✨

Explore these optional code suggestions:

CategorySuggestion Impact
General
Combine null-check and method call
Suggestion Impact:The commit refactored the null-handling for osName (and osVersion) by replacing the ternary null-check with requireNonNullOrElse before the toLowerCase call, addressing the same null-check cleanup area but not combining the null-check and toLowerCase into one expression.

code diff:

- osName = osName == null ? "" : osName;+ osName = requireNonNullOrElse(osName, "");+ osVersion = requireNonNullOrElse(osVersion, "");
osName = osName.toLowerCase(Locale.ENGLISH);
- osVersion = osVersion == null ? "" : osVersion;

Combine the null-check and toLowerCase() method call for the osName variable
into a single, more concise line.

java/src/org/openqa/selenium/Platform.java [431-433]

-osName = osName == null ? "" : osName;-osName = osName.toLowerCase(Locale.ENGLISH);+osName = (osName == null ? "" : osName).toLowerCase(Locale.ENGLISH);
osVersion = osVersion == null ? "" : osVersion;

[Suggestion processed]

Suggestion importance[1-10]: 3

__

Why: The suggestion offers a valid stylistic refactoring to make the code more concise. However, the impact on readability is subjective and the performance gain is negligible, making it a low-priority improvement.

Low
  • Update

@VietND96
VietND96 requested a review from asolntsevMarch 1, 2026 08:22

@asolntsevasolntsev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • few minor optional suggestions

Comment threadjava/src/org/openqa/selenium/Platform.java
Comment threadjava/src/org/openqa/selenium/Platform.java Outdated
@asolntsevasolntsev added this to the 4.42.0 milestone Mar 1, 2026
@asolntsevasolntsev self-assigned this Mar 1, 2026
@asolntsev
asolntsev merged commit 99a2547 into SeleniumHQ:trunkMar 1, 2026
43 of 44 checks passed
AutomatedTester pushed a commit that referenced this pull request Mar 11, 2026
* [java] Guard against NPE in Platform.extractFromSysProperty
* [java] Improve null-safety and formatting in Platform.extractFromSysProperty
* [java] Harden Platform.extractFromSysProperty against null inputs
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@seethinajayadileep@asolntsev@selenium-ci
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

[java] Guard against NPE in Platform.extractFromSysProperty - #17151

Merged
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean
Mar 1, 2026
Merged

[java] Guard against NPE in Platform.extractFromSysProperty#17151
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean

Conversation

@seethinajayadileep

@seethinajayadileepseethinajayadileep commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

💥 What does this PR do?

Prevents a possible NullPointerException in
Platform.extractFromSysProperty(String osName, String osVersion).

Previously:

  • osName and osVersion were assumed to be non-null
  • Calls such as osVersion.equals("6.2") could throw NullPointerException
  • The public 2-argument method could receive null directly from callers

This PR makes the method defensive against null inputs.


🔧 Implementation Notes

The following changes were made:

  1. Normalize osName and osVersion using Objects.requireNonNullElse:

    osName = requireNonNullElse(osName, "");
    osVersion = requireNonNullElse(osVersion, "");
    osName = osName.toLowerCase(Locale.ENGLISH);
  2. Provide a safe default when reading the system property:

    System.getProperty("os.version", "")

These changes ensure:

  • No NPE when null is passed to the public 2-argument method
  • No NPE during version comparisons
  • Existing platform detection logic remains unchanged

💡 Additional Considerations

  • Backwards compatible change
  • No modification to detection heuristics
  • Default behavior continues to fall back to UNIX when no match is found
  • Improves defensive robustness for external callers

🔄 Types of changes

  • Bug fix (backwards compatible)

@qodo-code-review

Copy link
Copy Markdown
Contributor

PR Type

Bug fix


Description

  • Guard against NullPointerException in Platform.extractFromSysProperty

  • Normalize null osName and osVersion parameters to empty strings

  • Provide safe default for System.getProperty("os.version") call

  • Maintain backwards compatibility and existing platform detection behavior


File Walkthrough

Relevant files
Bug fix
Platform.java
Add null-safety guards to Platform.extractFromSysProperty

java/src/org/openqa/selenium/Platform.java

  • Added null-safety checks for osName and osVersion parameters by
    normalizing them to empty strings
  • Modified single-argument extractFromSysProperty to provide empty
    string default for System.getProperty("os.version")
  • Prevents NullPointerException when system properties are restricted or
    null values are passed
  • Maintains existing platform detection logic and backwards
    compatibility
+3/-1

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Compliance Guide 🔍

Below is a summary of compliance checks for this PR:

Security Compliance
🟢
No security concerns identified No security vulnerabilities detected by AI analysis. Human verification advised for critical code.
Ticket Compliance
🎫 No ticket provided
  • Create ticket/issue
Codebase Duplication Compliance
Codebase context is not defined

Follow the guide to enable codebase context checks.

Custom Compliance
🟢
Generic: Comprehensive Audit Trails

Objective: To create a detailed and reliable record of critical system actions for security analysis
and compliance.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Meaningful Naming and Self-Documenting Code

Objective: Ensure all identifiers clearly express their purpose and intent, making code
self-documenting

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Robust Error Handling and Edge Case Management

Objective: Ensure comprehensive error handling that provides meaningful context and graceful
degradation

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Error Handling

Objective: To prevent the leakage of sensitive system information through error messages while
providing sufficient detail for internal debugging.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Logging Practices

Objective: To ensure logs are useful for debugging and auditing without exposing sensitive
information like PII, PHI, or cardholder data.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Security-First Input Validation and Data Handling

Objective: Ensure all data inputs are validated, sanitized, and handled securely to prevent
vulnerabilities

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

  • Update
Compliance status legend 🟢 - Fully Compliant
🟡 - Partial Compliant
🔴 - Not Compliant
⚪ - Requires Further Human Verification
🏷️ - Compliance label

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Code Suggestions ✨

Explore these optional code suggestions:

CategorySuggestion Impact
General
Combine null-check and method call
Suggestion Impact:The commit refactored the null-handling for osName (and osVersion) by replacing the ternary null-check with requireNonNullOrElse before the toLowerCase call, addressing the same null-check cleanup area but not combining the null-check and toLowerCase into one expression.

code diff:

- osName = osName == null ? "" : osName;+ osName = requireNonNullOrElse(osName, "");+ osVersion = requireNonNullOrElse(osVersion, "");
osName = osName.toLowerCase(Locale.ENGLISH);
- osVersion = osVersion == null ? "" : osVersion;

Combine the null-check and toLowerCase() method call for the osName variable
into a single, more concise line.

java/src/org/openqa/selenium/Platform.java [431-433]

-osName = osName == null ? "" : osName;-osName = osName.toLowerCase(Locale.ENGLISH);+osName = (osName == null ? "" : osName).toLowerCase(Locale.ENGLISH);
osVersion = osVersion == null ? "" : osVersion;

[Suggestion processed]

Suggestion importance[1-10]: 3

__

Why: The suggestion offers a valid stylistic refactoring to make the code more concise. However, the impact on readability is subjective and the performance gain is negligible, making it a low-priority improvement.

Low
  • Update

@VietND96
VietND96 requested a review from asolntsevMarch 1, 2026 08:22

@asolntsevasolntsev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • few minor optional suggestions

Comment threadjava/src/org/openqa/selenium/Platform.java
Comment threadjava/src/org/openqa/selenium/Platform.java Outdated
@asolntsevasolntsev added this to the 4.42.0 milestone Mar 1, 2026
@asolntsevasolntsev self-assigned this Mar 1, 2026
@asolntsev
asolntsev merged commit 99a2547 into SeleniumHQ:trunkMar 1, 2026
43 of 44 checks passed
AutomatedTester pushed a commit that referenced this pull request Mar 11, 2026
* [java] Guard against NPE in Platform.extractFromSysProperty
* [java] Improve null-safety and formatting in Platform.extractFromSysProperty
* [java] Harden Platform.extractFromSysProperty against null inputs
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@seethinajayadileep@asolntsev@selenium-ci
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[java] Guard against NPE in Platform.extractFromSysProperty - #17151

Merged
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean
Mar 1, 2026
Merged

[java] Guard against NPE in Platform.extractFromSysProperty#17151
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean

Conversation

@seethinajayadileep

@seethinajayadileepseethinajayadileep commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

💥 What does this PR do?

Prevents a possible NullPointerException in
Platform.extractFromSysProperty(String osName, String osVersion).

Previously:

  • osName and osVersion were assumed to be non-null
  • Calls such as osVersion.equals("6.2") could throw NullPointerException
  • The public 2-argument method could receive null directly from callers

This PR makes the method defensive against null inputs.


🔧 Implementation Notes

The following changes were made:

  1. Normalize osName and osVersion using Objects.requireNonNullElse:

    osName = requireNonNullElse(osName, "");
    osVersion = requireNonNullElse(osVersion, "");
    osName = osName.toLowerCase(Locale.ENGLISH);
  2. Provide a safe default when reading the system property:

    System.getProperty("os.version", "")

These changes ensure:

  • No NPE when null is passed to the public 2-argument method
  • No NPE during version comparisons
  • Existing platform detection logic remains unchanged

💡 Additional Considerations

  • Backwards compatible change
  • No modification to detection heuristics
  • Default behavior continues to fall back to UNIX when no match is found
  • Improves defensive robustness for external callers

🔄 Types of changes

  • Bug fix (backwards compatible)

@qodo-code-review

Copy link
Copy Markdown
Contributor

PR Type

Bug fix


Description

  • Guard against NullPointerException in Platform.extractFromSysProperty

  • Normalize null osName and osVersion parameters to empty strings

  • Provide safe default for System.getProperty("os.version") call

  • Maintain backwards compatibility and existing platform detection behavior


File Walkthrough

Relevant files
Bug fix
Platform.java
Add null-safety guards to Platform.extractFromSysProperty

java/src/org/openqa/selenium/Platform.java

  • Added null-safety checks for osName and osVersion parameters by
    normalizing them to empty strings
  • Modified single-argument extractFromSysProperty to provide empty
    string default for System.getProperty("os.version")
  • Prevents NullPointerException when system properties are restricted or
    null values are passed
  • Maintains existing platform detection logic and backwards
    compatibility
+3/-1

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Compliance Guide 🔍

Below is a summary of compliance checks for this PR:

Security Compliance
🟢
No security concerns identified No security vulnerabilities detected by AI analysis. Human verification advised for critical code.
Ticket Compliance
🎫 No ticket provided
  • Create ticket/issue
Codebase Duplication Compliance
Codebase context is not defined

Follow the guide to enable codebase context checks.

Custom Compliance
🟢
Generic: Comprehensive Audit Trails

Objective: To create a detailed and reliable record of critical system actions for security analysis
and compliance.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Meaningful Naming and Self-Documenting Code

Objective: Ensure all identifiers clearly express their purpose and intent, making code
self-documenting

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Robust Error Handling and Edge Case Management

Objective: Ensure comprehensive error handling that provides meaningful context and graceful
degradation

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Error Handling

Objective: To prevent the leakage of sensitive system information through error messages while
providing sufficient detail for internal debugging.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Logging Practices

Objective: To ensure logs are useful for debugging and auditing without exposing sensitive
information like PII, PHI, or cardholder data.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Security-First Input Validation and Data Handling

Objective: Ensure all data inputs are validated, sanitized, and handled securely to prevent
vulnerabilities

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

  • Update
Compliance status legend 🟢 - Fully Compliant
🟡 - Partial Compliant
🔴 - Not Compliant
⚪ - Requires Further Human Verification
🏷️ - Compliance label

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Code Suggestions ✨

Explore these optional code suggestions:

CategorySuggestion Impact
General
Combine null-check and method call
Suggestion Impact:The commit refactored the null-handling for osName (and osVersion) by replacing the ternary null-check with requireNonNullOrElse before the toLowerCase call, addressing the same null-check cleanup area but not combining the null-check and toLowerCase into one expression.

code diff:

- osName = osName == null ? "" : osName;+ osName = requireNonNullOrElse(osName, "");+ osVersion = requireNonNullOrElse(osVersion, "");
osName = osName.toLowerCase(Locale.ENGLISH);
- osVersion = osVersion == null ? "" : osVersion;

Combine the null-check and toLowerCase() method call for the osName variable
into a single, more concise line.

java/src/org/openqa/selenium/Platform.java [431-433]

-osName = osName == null ? "" : osName;-osName = osName.toLowerCase(Locale.ENGLISH);+osName = (osName == null ? "" : osName).toLowerCase(Locale.ENGLISH);
osVersion = osVersion == null ? "" : osVersion;

[Suggestion processed]

Suggestion importance[1-10]: 3

__

Why: The suggestion offers a valid stylistic refactoring to make the code more concise. However, the impact on readability is subjective and the performance gain is negligible, making it a low-priority improvement.

Low
  • Update

@VietND96
VietND96 requested a review from asolntsevMarch 1, 2026 08:22

@asolntsevasolntsev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • few minor optional suggestions

Comment threadjava/src/org/openqa/selenium/Platform.java
Comment threadjava/src/org/openqa/selenium/Platform.java Outdated
@asolntsevasolntsev added this to the 4.42.0 milestone Mar 1, 2026
@asolntsevasolntsev self-assigned this Mar 1, 2026
@asolntsev
asolntsev merged commit 99a2547 into SeleniumHQ:trunkMar 1, 2026
43 of 44 checks passed
AutomatedTester pushed a commit that referenced this pull request Mar 11, 2026
* [java] Guard against NPE in Platform.extractFromSysProperty
* [java] Improve null-safety and formatting in Platform.extractFromSysProperty
* [java] Harden Platform.extractFromSysProperty against null inputs
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@seethinajayadileep@asolntsev@selenium-ci
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[java] Guard against NPE in Platform.extractFromSysProperty - #17151

Merged
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean
Mar 1, 2026
Merged

[java] Guard against NPE in Platform.extractFromSysProperty#17151
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean

Conversation

@seethinajayadileep

@seethinajayadileepseethinajayadileep commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

💥 What does this PR do?

Prevents a possible NullPointerException in
Platform.extractFromSysProperty(String osName, String osVersion).

Previously:

  • osName and osVersion were assumed to be non-null
  • Calls such as osVersion.equals("6.2") could throw NullPointerException
  • The public 2-argument method could receive null directly from callers

This PR makes the method defensive against null inputs.


🔧 Implementation Notes

The following changes were made:

  1. Normalize osName and osVersion using Objects.requireNonNullElse:

    osName = requireNonNullElse(osName, "");
    osVersion = requireNonNullElse(osVersion, "");
    osName = osName.toLowerCase(Locale.ENGLISH);
  2. Provide a safe default when reading the system property:

    System.getProperty("os.version", "")

These changes ensure:

  • No NPE when null is passed to the public 2-argument method
  • No NPE during version comparisons
  • Existing platform detection logic remains unchanged

💡 Additional Considerations

  • Backwards compatible change
  • No modification to detection heuristics
  • Default behavior continues to fall back to UNIX when no match is found
  • Improves defensive robustness for external callers

🔄 Types of changes

  • Bug fix (backwards compatible)

@qodo-code-review

Copy link
Copy Markdown
Contributor

PR Type

Bug fix


Description

  • Guard against NullPointerException in Platform.extractFromSysProperty

  • Normalize null osName and osVersion parameters to empty strings

  • Provide safe default for System.getProperty("os.version") call

  • Maintain backwards compatibility and existing platform detection behavior


File Walkthrough

Relevant files
Bug fix
Platform.java
Add null-safety guards to Platform.extractFromSysProperty

java/src/org/openqa/selenium/Platform.java

  • Added null-safety checks for osName and osVersion parameters by
    normalizing them to empty strings
  • Modified single-argument extractFromSysProperty to provide empty
    string default for System.getProperty("os.version")
  • Prevents NullPointerException when system properties are restricted or
    null values are passed
  • Maintains existing platform detection logic and backwards
    compatibility
+3/-1

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Compliance Guide 🔍

Below is a summary of compliance checks for this PR:

Security Compliance
🟢
No security concerns identified No security vulnerabilities detected by AI analysis. Human verification advised for critical code.
Ticket Compliance
🎫 No ticket provided
  • Create ticket/issue
Codebase Duplication Compliance
Codebase context is not defined

Follow the guide to enable codebase context checks.

Custom Compliance
🟢
Generic: Comprehensive Audit Trails

Objective: To create a detailed and reliable record of critical system actions for security analysis
and compliance.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Meaningful Naming and Self-Documenting Code

Objective: Ensure all identifiers clearly express their purpose and intent, making code
self-documenting

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Robust Error Handling and Edge Case Management

Objective: Ensure comprehensive error handling that provides meaningful context and graceful
degradation

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Error Handling

Objective: To prevent the leakage of sensitive system information through error messages while
providing sufficient detail for internal debugging.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Logging Practices

Objective: To ensure logs are useful for debugging and auditing without exposing sensitive
information like PII, PHI, or cardholder data.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Security-First Input Validation and Data Handling

Objective: Ensure all data inputs are validated, sanitized, and handled securely to prevent
vulnerabilities

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

  • Update
Compliance status legend 🟢 - Fully Compliant
🟡 - Partial Compliant
🔴 - Not Compliant
⚪ - Requires Further Human Verification
🏷️ - Compliance label

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Code Suggestions ✨

Explore these optional code suggestions:

CategorySuggestion Impact
General
Combine null-check and method call
Suggestion Impact:The commit refactored the null-handling for osName (and osVersion) by replacing the ternary null-check with requireNonNullOrElse before the toLowerCase call, addressing the same null-check cleanup area but not combining the null-check and toLowerCase into one expression.

code diff:

- osName = osName == null ? "" : osName;+ osName = requireNonNullOrElse(osName, "");+ osVersion = requireNonNullOrElse(osVersion, "");
osName = osName.toLowerCase(Locale.ENGLISH);
- osVersion = osVersion == null ? "" : osVersion;

Combine the null-check and toLowerCase() method call for the osName variable
into a single, more concise line.

java/src/org/openqa/selenium/Platform.java [431-433]

-osName = osName == null ? "" : osName;-osName = osName.toLowerCase(Locale.ENGLISH);+osName = (osName == null ? "" : osName).toLowerCase(Locale.ENGLISH);
osVersion = osVersion == null ? "" : osVersion;

[Suggestion processed]

Suggestion importance[1-10]: 3

__

Why: The suggestion offers a valid stylistic refactoring to make the code more concise. However, the impact on readability is subjective and the performance gain is negligible, making it a low-priority improvement.

Low
  • Update

@VietND96
VietND96 requested a review from asolntsevMarch 1, 2026 08:22

@asolntsevasolntsev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • few minor optional suggestions

Comment threadjava/src/org/openqa/selenium/Platform.java
Comment threadjava/src/org/openqa/selenium/Platform.java Outdated
@asolntsevasolntsev added this to the 4.42.0 milestone Mar 1, 2026
@asolntsevasolntsev self-assigned this Mar 1, 2026
@asolntsev
asolntsev merged commit 99a2547 into SeleniumHQ:trunkMar 1, 2026
43 of 44 checks passed
AutomatedTester pushed a commit that referenced this pull request Mar 11, 2026
* [java] Guard against NPE in Platform.extractFromSysProperty
* [java] Improve null-safety and formatting in Platform.extractFromSysProperty
* [java] Harden Platform.extractFromSysProperty against null inputs
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@seethinajayadileep@asolntsev@selenium-ci
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

[java] Guard against NPE in Platform.extractFromSysProperty - #17151

Merged
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean
Mar 1, 2026
Merged

[java] Guard against NPE in Platform.extractFromSysProperty#17151
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean

Conversation

@seethinajayadileep

@seethinajayadileepseethinajayadileep commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

💥 What does this PR do?

Prevents a possible NullPointerException in
Platform.extractFromSysProperty(String osName, String osVersion).

Previously:

  • osName and osVersion were assumed to be non-null
  • Calls such as osVersion.equals("6.2") could throw NullPointerException
  • The public 2-argument method could receive null directly from callers

This PR makes the method defensive against null inputs.


🔧 Implementation Notes

The following changes were made:

  1. Normalize osName and osVersion using Objects.requireNonNullElse:

    osName = requireNonNullElse(osName, "");
    osVersion = requireNonNullElse(osVersion, "");
    osName = osName.toLowerCase(Locale.ENGLISH);
  2. Provide a safe default when reading the system property:

    System.getProperty("os.version", "")

These changes ensure:

  • No NPE when null is passed to the public 2-argument method
  • No NPE during version comparisons
  • Existing platform detection logic remains unchanged

💡 Additional Considerations

  • Backwards compatible change
  • No modification to detection heuristics
  • Default behavior continues to fall back to UNIX when no match is found
  • Improves defensive robustness for external callers

🔄 Types of changes

  • Bug fix (backwards compatible)

@qodo-code-review

Copy link
Copy Markdown
Contributor

PR Type

Bug fix


Description

  • Guard against NullPointerException in Platform.extractFromSysProperty

  • Normalize null osName and osVersion parameters to empty strings

  • Provide safe default for System.getProperty("os.version") call

  • Maintain backwards compatibility and existing platform detection behavior


File Walkthrough

Relevant files
Bug fix
Platform.java
Add null-safety guards to Platform.extractFromSysProperty

java/src/org/openqa/selenium/Platform.java

  • Added null-safety checks for osName and osVersion parameters by
    normalizing them to empty strings
  • Modified single-argument extractFromSysProperty to provide empty
    string default for System.getProperty("os.version")
  • Prevents NullPointerException when system properties are restricted or
    null values are passed
  • Maintains existing platform detection logic and backwards
    compatibility
+3/-1

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Compliance Guide 🔍

Below is a summary of compliance checks for this PR:

Security Compliance
🟢
No security concerns identified No security vulnerabilities detected by AI analysis. Human verification advised for critical code.
Ticket Compliance
🎫 No ticket provided
  • Create ticket/issue
Codebase Duplication Compliance
Codebase context is not defined

Follow the guide to enable codebase context checks.

Custom Compliance
🟢
Generic: Comprehensive Audit Trails

Objective: To create a detailed and reliable record of critical system actions for security analysis
and compliance.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Meaningful Naming and Self-Documenting Code

Objective: Ensure all identifiers clearly express their purpose and intent, making code
self-documenting

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Robust Error Handling and Edge Case Management

Objective: Ensure comprehensive error handling that provides meaningful context and graceful
degradation

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Error Handling

Objective: To prevent the leakage of sensitive system information through error messages while
providing sufficient detail for internal debugging.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Logging Practices

Objective: To ensure logs are useful for debugging and auditing without exposing sensitive
information like PII, PHI, or cardholder data.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Security-First Input Validation and Data Handling

Objective: Ensure all data inputs are validated, sanitized, and handled securely to prevent
vulnerabilities

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

  • Update
Compliance status legend 🟢 - Fully Compliant
🟡 - Partial Compliant
🔴 - Not Compliant
⚪ - Requires Further Human Verification
🏷️ - Compliance label

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Code Suggestions ✨

Explore these optional code suggestions:

CategorySuggestion Impact
General
Combine null-check and method call
Suggestion Impact:The commit refactored the null-handling for osName (and osVersion) by replacing the ternary null-check with requireNonNullOrElse before the toLowerCase call, addressing the same null-check cleanup area but not combining the null-check and toLowerCase into one expression.

code diff:

- osName = osName == null ? "" : osName;+ osName = requireNonNullOrElse(osName, "");+ osVersion = requireNonNullOrElse(osVersion, "");
osName = osName.toLowerCase(Locale.ENGLISH);
- osVersion = osVersion == null ? "" : osVersion;

Combine the null-check and toLowerCase() method call for the osName variable
into a single, more concise line.

java/src/org/openqa/selenium/Platform.java [431-433]

-osName = osName == null ? "" : osName;-osName = osName.toLowerCase(Locale.ENGLISH);+osName = (osName == null ? "" : osName).toLowerCase(Locale.ENGLISH);
osVersion = osVersion == null ? "" : osVersion;

[Suggestion processed]

Suggestion importance[1-10]: 3

__

Why: The suggestion offers a valid stylistic refactoring to make the code more concise. However, the impact on readability is subjective and the performance gain is negligible, making it a low-priority improvement.

Low
  • Update

@VietND96
VietND96 requested a review from asolntsevMarch 1, 2026 08:22

@asolntsevasolntsev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • few minor optional suggestions

Comment threadjava/src/org/openqa/selenium/Platform.java
Comment threadjava/src/org/openqa/selenium/Platform.java Outdated
@asolntsevasolntsev added this to the 4.42.0 milestone Mar 1, 2026
@asolntsevasolntsev self-assigned this Mar 1, 2026
@asolntsev
asolntsev merged commit 99a2547 into SeleniumHQ:trunkMar 1, 2026
43 of 44 checks passed
AutomatedTester pushed a commit that referenced this pull request Mar 11, 2026
* [java] Guard against NPE in Platform.extractFromSysProperty
* [java] Improve null-safety and formatting in Platform.extractFromSysProperty
* [java] Harden Platform.extractFromSysProperty against null inputs
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@seethinajayadileep@asolntsev@selenium-ci
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[java] Guard against NPE in Platform.extractFromSysProperty - #17151

Merged
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean
Mar 1, 2026
Merged

[java] Guard against NPE in Platform.extractFromSysProperty#17151
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean

Conversation

@seethinajayadileep

@seethinajayadileepseethinajayadileep commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

💥 What does this PR do?

Prevents a possible NullPointerException in
Platform.extractFromSysProperty(String osName, String osVersion).

Previously:

  • osName and osVersion were assumed to be non-null
  • Calls such as osVersion.equals("6.2") could throw NullPointerException
  • The public 2-argument method could receive null directly from callers

This PR makes the method defensive against null inputs.


🔧 Implementation Notes

The following changes were made:

  1. Normalize osName and osVersion using Objects.requireNonNullElse:

    osName = requireNonNullElse(osName, "");
    osVersion = requireNonNullElse(osVersion, "");
    osName = osName.toLowerCase(Locale.ENGLISH);
  2. Provide a safe default when reading the system property:

    System.getProperty("os.version", "")

These changes ensure:

  • No NPE when null is passed to the public 2-argument method
  • No NPE during version comparisons
  • Existing platform detection logic remains unchanged

💡 Additional Considerations

  • Backwards compatible change
  • No modification to detection heuristics
  • Default behavior continues to fall back to UNIX when no match is found
  • Improves defensive robustness for external callers

🔄 Types of changes

  • Bug fix (backwards compatible)

@qodo-code-review

Copy link
Copy Markdown
Contributor

PR Type

Bug fix


Description

  • Guard against NullPointerException in Platform.extractFromSysProperty

  • Normalize null osName and osVersion parameters to empty strings

  • Provide safe default for System.getProperty("os.version") call

  • Maintain backwards compatibility and existing platform detection behavior


File Walkthrough

Relevant files
Bug fix
Platform.java
Add null-safety guards to Platform.extractFromSysProperty

java/src/org/openqa/selenium/Platform.java

  • Added null-safety checks for osName and osVersion parameters by
    normalizing them to empty strings
  • Modified single-argument extractFromSysProperty to provide empty
    string default for System.getProperty("os.version")
  • Prevents NullPointerException when system properties are restricted or
    null values are passed
  • Maintains existing platform detection logic and backwards
    compatibility
+3/-1

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Compliance Guide 🔍

Below is a summary of compliance checks for this PR:

Security Compliance
🟢
No security concerns identified No security vulnerabilities detected by AI analysis. Human verification advised for critical code.
Ticket Compliance
🎫 No ticket provided
  • Create ticket/issue
Codebase Duplication Compliance
Codebase context is not defined

Follow the guide to enable codebase context checks.

Custom Compliance
🟢
Generic: Comprehensive Audit Trails

Objective: To create a detailed and reliable record of critical system actions for security analysis
and compliance.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Meaningful Naming and Self-Documenting Code

Objective: Ensure all identifiers clearly express their purpose and intent, making code
self-documenting

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Robust Error Handling and Edge Case Management

Objective: Ensure comprehensive error handling that provides meaningful context and graceful
degradation

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Error Handling

Objective: To prevent the leakage of sensitive system information through error messages while
providing sufficient detail for internal debugging.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Logging Practices

Objective: To ensure logs are useful for debugging and auditing without exposing sensitive
information like PII, PHI, or cardholder data.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Security-First Input Validation and Data Handling

Objective: Ensure all data inputs are validated, sanitized, and handled securely to prevent
vulnerabilities

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

  • Update
Compliance status legend 🟢 - Fully Compliant
🟡 - Partial Compliant
🔴 - Not Compliant
⚪ - Requires Further Human Verification
🏷️ - Compliance label

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Code Suggestions ✨

Explore these optional code suggestions:

CategorySuggestion Impact
General
Combine null-check and method call
Suggestion Impact:The commit refactored the null-handling for osName (and osVersion) by replacing the ternary null-check with requireNonNullOrElse before the toLowerCase call, addressing the same null-check cleanup area but not combining the null-check and toLowerCase into one expression.

code diff:

- osName = osName == null ? "" : osName;+ osName = requireNonNullOrElse(osName, "");+ osVersion = requireNonNullOrElse(osVersion, "");
osName = osName.toLowerCase(Locale.ENGLISH);
- osVersion = osVersion == null ? "" : osVersion;

Combine the null-check and toLowerCase() method call for the osName variable
into a single, more concise line.

java/src/org/openqa/selenium/Platform.java [431-433]

-osName = osName == null ? "" : osName;-osName = osName.toLowerCase(Locale.ENGLISH);+osName = (osName == null ? "" : osName).toLowerCase(Locale.ENGLISH);
osVersion = osVersion == null ? "" : osVersion;

[Suggestion processed]

Suggestion importance[1-10]: 3

__

Why: The suggestion offers a valid stylistic refactoring to make the code more concise. However, the impact on readability is subjective and the performance gain is negligible, making it a low-priority improvement.

Low
  • Update

@VietND96
VietND96 requested a review from asolntsevMarch 1, 2026 08:22

@asolntsevasolntsev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • few minor optional suggestions

Comment threadjava/src/org/openqa/selenium/Platform.java
Comment threadjava/src/org/openqa/selenium/Platform.java Outdated
@asolntsevasolntsev added this to the 4.42.0 milestone Mar 1, 2026
@asolntsevasolntsev self-assigned this Mar 1, 2026
@asolntsev
asolntsev merged commit 99a2547 into SeleniumHQ:trunkMar 1, 2026
43 of 44 checks passed
AutomatedTester pushed a commit that referenced this pull request Mar 11, 2026
* [java] Guard against NPE in Platform.extractFromSysProperty
* [java] Improve null-safety and formatting in Platform.extractFromSysProperty
* [java] Harden Platform.extractFromSysProperty against null inputs
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@seethinajayadileep@asolntsev@selenium-ci
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

[java] Guard against NPE in Platform.extractFromSysProperty - #17151

Merged
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean
Mar 1, 2026
Merged

[java] Guard against NPE in Platform.extractFromSysProperty#17151
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean

Conversation

@seethinajayadileep

@seethinajayadileepseethinajayadileep commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

💥 What does this PR do?

Prevents a possible NullPointerException in
Platform.extractFromSysProperty(String osName, String osVersion).

Previously:

  • osName and osVersion were assumed to be non-null
  • Calls such as osVersion.equals("6.2") could throw NullPointerException
  • The public 2-argument method could receive null directly from callers

This PR makes the method defensive against null inputs.


🔧 Implementation Notes

The following changes were made:

  1. Normalize osName and osVersion using Objects.requireNonNullElse:

    osName = requireNonNullElse(osName, "");
    osVersion = requireNonNullElse(osVersion, "");
    osName = osName.toLowerCase(Locale.ENGLISH);
  2. Provide a safe default when reading the system property:

    System.getProperty("os.version", "")

These changes ensure:

  • No NPE when null is passed to the public 2-argument method
  • No NPE during version comparisons
  • Existing platform detection logic remains unchanged

💡 Additional Considerations

  • Backwards compatible change
  • No modification to detection heuristics
  • Default behavior continues to fall back to UNIX when no match is found
  • Improves defensive robustness for external callers

🔄 Types of changes

  • Bug fix (backwards compatible)

@qodo-code-review

Copy link
Copy Markdown
Contributor

PR Type

Bug fix


Description

  • Guard against NullPointerException in Platform.extractFromSysProperty

  • Normalize null osName and osVersion parameters to empty strings

  • Provide safe default for System.getProperty("os.version") call

  • Maintain backwards compatibility and existing platform detection behavior


File Walkthrough

Relevant files
Bug fix
Platform.java
Add null-safety guards to Platform.extractFromSysProperty

java/src/org/openqa/selenium/Platform.java

  • Added null-safety checks for osName and osVersion parameters by
    normalizing them to empty strings
  • Modified single-argument extractFromSysProperty to provide empty
    string default for System.getProperty("os.version")
  • Prevents NullPointerException when system properties are restricted or
    null values are passed
  • Maintains existing platform detection logic and backwards
    compatibility
+3/-1

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Compliance Guide 🔍

Below is a summary of compliance checks for this PR:

Security Compliance
🟢
No security concerns identified No security vulnerabilities detected by AI analysis. Human verification advised for critical code.
Ticket Compliance
🎫 No ticket provided
  • Create ticket/issue
Codebase Duplication Compliance
Codebase context is not defined

Follow the guide to enable codebase context checks.

Custom Compliance
🟢
Generic: Comprehensive Audit Trails

Objective: To create a detailed and reliable record of critical system actions for security analysis
and compliance.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Meaningful Naming and Self-Documenting Code

Objective: Ensure all identifiers clearly express their purpose and intent, making code
self-documenting

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Robust Error Handling and Edge Case Management

Objective: Ensure comprehensive error handling that provides meaningful context and graceful
degradation

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Error Handling

Objective: To prevent the leakage of sensitive system information through error messages while
providing sufficient detail for internal debugging.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Logging Practices

Objective: To ensure logs are useful for debugging and auditing without exposing sensitive
information like PII, PHI, or cardholder data.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Security-First Input Validation and Data Handling

Objective: Ensure all data inputs are validated, sanitized, and handled securely to prevent
vulnerabilities

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

  • Update
Compliance status legend 🟢 - Fully Compliant
🟡 - Partial Compliant
🔴 - Not Compliant
⚪ - Requires Further Human Verification
🏷️ - Compliance label

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Code Suggestions ✨

Explore these optional code suggestions:

CategorySuggestion Impact
General
Combine null-check and method call
Suggestion Impact:The commit refactored the null-handling for osName (and osVersion) by replacing the ternary null-check with requireNonNullOrElse before the toLowerCase call, addressing the same null-check cleanup area but not combining the null-check and toLowerCase into one expression.

code diff:

- osName = osName == null ? "" : osName;+ osName = requireNonNullOrElse(osName, "");+ osVersion = requireNonNullOrElse(osVersion, "");
osName = osName.toLowerCase(Locale.ENGLISH);
- osVersion = osVersion == null ? "" : osVersion;

Combine the null-check and toLowerCase() method call for the osName variable
into a single, more concise line.

java/src/org/openqa/selenium/Platform.java [431-433]

-osName = osName == null ? "" : osName;-osName = osName.toLowerCase(Locale.ENGLISH);+osName = (osName == null ? "" : osName).toLowerCase(Locale.ENGLISH);
osVersion = osVersion == null ? "" : osVersion;

[Suggestion processed]

Suggestion importance[1-10]: 3

__

Why: The suggestion offers a valid stylistic refactoring to make the code more concise. However, the impact on readability is subjective and the performance gain is negligible, making it a low-priority improvement.

Low
  • Update

@VietND96
VietND96 requested a review from asolntsevMarch 1, 2026 08:22

@asolntsevasolntsev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • few minor optional suggestions

Comment threadjava/src/org/openqa/selenium/Platform.java
Comment threadjava/src/org/openqa/selenium/Platform.java Outdated
@asolntsevasolntsev added this to the 4.42.0 milestone Mar 1, 2026
@asolntsevasolntsev self-assigned this Mar 1, 2026
@asolntsev
asolntsev merged commit 99a2547 into SeleniumHQ:trunkMar 1, 2026
43 of 44 checks passed
AutomatedTester pushed a commit that referenced this pull request Mar 11, 2026
* [java] Guard against NPE in Platform.extractFromSysProperty
* [java] Improve null-safety and formatting in Platform.extractFromSysProperty
* [java] Harden Platform.extractFromSysProperty against null inputs
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@seethinajayadileep@asolntsev@selenium-ci
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

[java] Guard against NPE in Platform.extractFromSysProperty - #17151

Merged
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean
Mar 1, 2026
Merged

[java] Guard against NPE in Platform.extractFromSysProperty#17151
asolntsev merged 3 commits into
SeleniumHQ:trunkfrom
seethinajayadileep:fix-platform-extractFromSysProperty-npe-clean

Conversation

@seethinajayadileep

@seethinajayadileepseethinajayadileep commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

💥 What does this PR do?

Prevents a possible NullPointerException in
Platform.extractFromSysProperty(String osName, String osVersion).

Previously:

  • osName and osVersion were assumed to be non-null
  • Calls such as osVersion.equals("6.2") could throw NullPointerException
  • The public 2-argument method could receive null directly from callers

This PR makes the method defensive against null inputs.


🔧 Implementation Notes

The following changes were made:

  1. Normalize osName and osVersion using Objects.requireNonNullElse:

    osName = requireNonNullElse(osName, "");
    osVersion = requireNonNullElse(osVersion, "");
    osName = osName.toLowerCase(Locale.ENGLISH);
  2. Provide a safe default when reading the system property:

    System.getProperty("os.version", "")

These changes ensure:

  • No NPE when null is passed to the public 2-argument method
  • No NPE during version comparisons
  • Existing platform detection logic remains unchanged

💡 Additional Considerations

  • Backwards compatible change
  • No modification to detection heuristics
  • Default behavior continues to fall back to UNIX when no match is found
  • Improves defensive robustness for external callers

🔄 Types of changes

  • Bug fix (backwards compatible)

@qodo-code-review

Copy link
Copy Markdown
Contributor

PR Type

Bug fix


Description

  • Guard against NullPointerException in Platform.extractFromSysProperty

  • Normalize null osName and osVersion parameters to empty strings

  • Provide safe default for System.getProperty("os.version") call

  • Maintain backwards compatibility and existing platform detection behavior


File Walkthrough

Relevant files
Bug fix
Platform.java
Add null-safety guards to Platform.extractFromSysProperty

java/src/org/openqa/selenium/Platform.java

  • Added null-safety checks for osName and osVersion parameters by
    normalizing them to empty strings
  • Modified single-argument extractFromSysProperty to provide empty
    string default for System.getProperty("os.version")
  • Prevents NullPointerException when system properties are restricted or
    null values are passed
  • Maintains existing platform detection logic and backwards
    compatibility
+3/-1

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Compliance Guide 🔍

Below is a summary of compliance checks for this PR:

Security Compliance
🟢
No security concerns identified No security vulnerabilities detected by AI analysis. Human verification advised for critical code.
Ticket Compliance
🎫 No ticket provided
  • Create ticket/issue
Codebase Duplication Compliance
Codebase context is not defined

Follow the guide to enable codebase context checks.

Custom Compliance
🟢
Generic: Comprehensive Audit Trails

Objective: To create a detailed and reliable record of critical system actions for security analysis
and compliance.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Meaningful Naming and Self-Documenting Code

Objective: Ensure all identifiers clearly express their purpose and intent, making code
self-documenting

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Robust Error Handling and Edge Case Management

Objective: Ensure comprehensive error handling that provides meaningful context and graceful
degradation

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Error Handling

Objective: To prevent the leakage of sensitive system information through error messages while
providing sufficient detail for internal debugging.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Secure Logging Practices

Objective: To ensure logs are useful for debugging and auditing without exposing sensitive
information like PII, PHI, or cardholder data.

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

Generic: Security-First Input Validation and Data Handling

Objective: Ensure all data inputs are validated, sanitized, and handled securely to prevent
vulnerabilities

Status: Passed

Learn more about managing compliance generic rules or creating your own custom rules

  • Update
Compliance status legend 🟢 - Fully Compliant
🟡 - Partial Compliant
🔴 - Not Compliant
⚪ - Requires Further Human Verification
🏷️ - Compliance label

@qodo-code-review

qodo-code-reviewBot commented Mar 1, 2026

Copy link
Copy Markdown
Contributor

PR Code Suggestions ✨

Explore these optional code suggestions:

CategorySuggestion Impact
General
Combine null-check and method call
Suggestion Impact:The commit refactored the null-handling for osName (and osVersion) by replacing the ternary null-check with requireNonNullOrElse before the toLowerCase call, addressing the same null-check cleanup area but not combining the null-check and toLowerCase into one expression.

code diff:

- osName = osName == null ? "" : osName;+ osName = requireNonNullOrElse(osName, "");+ osVersion = requireNonNullOrElse(osVersion, "");
osName = osName.toLowerCase(Locale.ENGLISH);
- osVersion = osVersion == null ? "" : osVersion;

Combine the null-check and toLowerCase() method call for the osName variable
into a single, more concise line.

java/src/org/openqa/selenium/Platform.java [431-433]

-osName = osName == null ? "" : osName;-osName = osName.toLowerCase(Locale.ENGLISH);+osName = (osName == null ? "" : osName).toLowerCase(Locale.ENGLISH);
osVersion = osVersion == null ? "" : osVersion;

[Suggestion processed]

Suggestion importance[1-10]: 3

__

Why: The suggestion offers a valid stylistic refactoring to make the code more concise. However, the impact on readability is subjective and the performance gain is negligible, making it a low-priority improvement.

Low
  • Update

@VietND96
VietND96 requested a review from asolntsevMarch 1, 2026 08:22

@asolntsevasolntsev left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • few minor optional suggestions

Comment threadjava/src/org/openqa/selenium/Platform.java
Comment threadjava/src/org/openqa/selenium/Platform.java Outdated
@asolntsevasolntsev added this to the 4.42.0 milestone Mar 1, 2026
@asolntsevasolntsev self-assigned this Mar 1, 2026
@asolntsev
asolntsev merged commit 99a2547 into SeleniumHQ:trunkMar 1, 2026
43 of 44 checks passed
AutomatedTester pushed a commit that referenced this pull request Mar 11, 2026
* [java] Guard against NPE in Platform.extractFromSysProperty
* [java] Improve null-safety and formatting in Platform.extractFromSysProperty
* [java] Harden Platform.extractFromSysProperty against null inputs
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@seethinajayadileep@asolntsev@selenium-ci