Inspired by ZK-3006 , I develop a simple static analysis tool to find other Potential NPE like ZK-3006. This bug is found by this tool ,and I have carefully studied it. But i am a newbie at here so i may be wrong, hope someone could confirm it and help me improve this tool.
callee BinaryInputArchive#startVector will return null:
and caller ReferenceCountedACLCache#deserialize call it without null check
but all the other 14 caller of BinaryInputArchive#startVector performs null checker like:
so i think we also need add null check in caller ReferenceCountedACLCache#deserialize just like other 14 caller