Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Parasoft Jtest 2022.2

Because an exception is caught by its type, it is better to define exceptions for specific purposes rather than to use the general exception types for a variety of different multiple purposes. Throwing the general exception types makes code hard to understand and maintain , and defeats much of the advantage of the Java exception-handling mechanism.

...

Noncompliant Code Example

This noncompliant code example attempts to distinguish between different exceptional behavior behaviors by looking at the exception's message.:

Code Block
bgColor#FFcccc

try {
    doSomething();
} catch (ExceptionThrowable e) {
  String msg = e.getMessage();
  switch (msg) {
    case "stackfile not underflowfound":
      // ...Handle error
      break;
    case "connection timeout":
      // ...Handle error
      break;
    case "security violation":
      // ...Handle error
      break;
    default: throw e;
  }
}

If doSomething() throws an exception , or error whose type is a subclass of Exception, with message "stack underflow" then the appropriate action will be of Throwable, the switch statement allows selection of a specific case to execute. For example, if the exception message is "file not found," the appropriate action is taken in the exception handler-handling code.

However, any change to the exception message literals involved will break the code. For example, if a maintainer should edit the throw expression to read throw Exception("Stack Underflow"); the exception will be rethrown by the code of the noncompliant code example rather than handled. Also, an exception may be thrown with no message.

Compliant Solution

suppose this code is executed:

Code Block
throw new Exception("cannot find file");

This exception should be handled by the first case clause, but it will be rethrown because the string does not match any case clause.

Furthermore, exceptions may be thrown without a message.

This noncompliant code example falls under ERR08-J-EX0 of ERR08-J. Do not catch NullPointerException or any of its ancestors because it catches general exceptions but rethrows them.

Compliant Solution

This compliant solution uses specific exception types and defines new special-purpose exception types where requiredIt is better to user specific existing exception types, or define new, special purpose exception types.

Code Block
bgColor#ccccff

public class StackUnderflowExceptionTimeoutException extends Exception {
  StackUnderflowExceptionTimeoutException () {
    super();
  }
  StackUnderflowExceptionTimeoutException (String msg) {
    super(msg);
  }
}

// ...

try {
    doSomething();
} catch (StackUnderflowExceptionFileNotFoundException suee) {
  // ...Handle error
} catch (TimeoutException te) {
  // ...Handle error
} catch (SecurityException se) {
  // ...
} catch(Exception e) {
  // ...
  throw e;Handle error
}

...

Applicability

Exceptions are used to handle exceptional conditions. If an exception is not caught, the program thread will be terminated, which may cause the program to exit. An exception that is incorrectly caught , or is caught at the wrong level of recovery will likely often cause incorrect behavior.

...

Automated Detection

Severity
Tool
Likelihood
Version
Remediation Cost
Checker
Priority
Description

Level

ERR54-J

low

probable

medium

P4

L3

Automated Detection

Automated detection is not feasible.

Related Vulnerabilities

Search for vulnerabilities resulting from the violation of this guideline on the CERT website.

Other Languages

This guideline appears in the C++ Secure Coding Standard as ERR08-CPP. Prefer special-purpose types for exceptions.

Bibliography

Parasoft Jtest
Include Page
Parasoft_V
Parasoft_V
CERT.ERR51.NCEDo not catch exception types which are too general or are unchecked exceptions
SonarQube
Include Page
SonarQube_V
SonarQube_V
S1193


Bibliography


...

Image Added Image Added Image Added Wiki Markup\[[JLS 2011|AA. References#JLS 11]\] Chapter 11. Exceptions