Cloning Java objects using serialization
Sometimes you need to clone objects, and sometimes you can't
use their clone method, and sometimes serialization provides an
alternative. Here's an explanation of when you might need this
exotic and expensive technique, and how you can use it.
When do you need to clone?
The commonest time that you need to clone an object is when it
is a parameter or return value of one of your public methods.
If it is a parameter that you save somewhere, then you don't
want the caller to be able to modify it later. So you save a
copy of the object. Likewise, if you are returning an object
that is part of your class's internal state, you need to return
a copy instead so that callers can't accidentally or
deliberately change that internal state.
A second case when you might want to clone is when you need to
modify an object, but you don't know who else might have a
reference to it. So you make a copy and modify that.
[In both cases, if the object in question is of one of your
classes, you should ask yourself if it couldn't be
instead. Immutability has many advantages regarding
performance, security, and thread-safety.]
Can't I just use Object.clone()?
Happily, java.lang.Object defines a
method whose intent is exactly to produce a copy of the object
on which it is called. Unhappily, this method, which dates from
the very earliest days of the Java platform, has some design
The first problem is that the method is protected. The idea,
presumably, is that subclasses have to explicitly agree to be
cloneable by overriding this protected method with a public
method. The various Collections classes all do this, for
example. (
etc.) The subclass also has to implement
for the default cloning mechanism in Object.clone() to work.
If you have an object that you know has a public clone()
method, but you don't know the type of the object at compile-time,
you are stuck. Say x is declared as an Object. You can't just
call x.clone(), because Object.clone() is protected. If Cloneable
defined a public clone() method, then you could use ((Cloneable)
x).clone(). But it doesn't. So you either have to enumerate all the classes that you think x could be...
Object copy;
if(x instanceofArrayList)
copy =((ArrayList<?>) x).clone();
elseif(x instanceofIdentityHashMap)
copy =((IdentityHashMap<?,?>) x).clone();
...or you have to resort to reflection...
Object copy;
Method clone = x.getClass().getMethod("clone");
copy = clone.invoke(x);
}catch(Exception e){
Both solutions are pretty nasty.
A second potential problem is that the default behaviour of
Object.clone() is to make a shallow copy of the object.
Most system classes that provide a clone() method do this too.
A shallow copy means that the copy object itself is different,
but if the original object referenced other objects, the copy
will reference those same objects, and not a copy of them. For
example, what does the following code print?
HashMap<String,List<String>>citiesClone=(HashMap) cities.clone();
Of course, it prints "[Dublin, Grenoble]". The original
object has been modified through its clone,
because the clone operation does not clone the list in each
Cloning through serialization
One solution to these problems is to clone using serialization.
Usually, serialization is used to send objects off somewhere (into
a file or over the network) so that somebody else can reconstruct
them later. But you can abuse it to reconstruct the object
yourself immediately. If the object is serializable at all, then
the reconstruction should be a faithful copy. In normal uses of
serialization, the original object is nowhere near; it could be on
the other side of the world at the far end of a network
connection. So you can be sure that changing the copy will have
no effect on the original.
Before going any further, I should caution that this technique
is not to be used lightly. First of all, serialization is
hugely expensive. It could easily be a hundred times more
expensive than the clone() method. Secondly, not all objects
are serializable. Thirdly, making a class serializable is
tricky and not all classes can be relied on to get it right.
(You can assume that system classes are correct, though.)
Class-loading subtleties
When an object is being deserialized, the platform has to be
able to find its class in order to construct an instance of that
class. Imagine that you're deserializing an object you received
over the network. If it's a com.example.Foo
, the
serialization framework is going to have to find that class
somehow. How does it do it?
The answer is that it uses the ClassLoader of the code that is
doing the deserialization. So if I define a class
that serializes and deserializes an
object, then by default the class of that object, and the
classes of other objects it references, need to be known to the
ClassLoader of SerialClone
In simple cases, this will always be true. Every class of
interest is on the classpath, including SerialClone
and the class of any object it might be asked to copy.
In more complicated environments, with several ClassLoaders,
this default behaviour is not necessarily what you want. In a
web server, for example, typically every web app has its own
ClassLoader. If the web server wanted to serial-clone an object
it got from a web app, it would need to reconstruct the object
using the web app's ClassLoader. How could it do that?
The answer is that it can use class annotations. RMI
uses these to write information into the serial stream that
tells the remote partner where it can find the classes of
objects that are being sent. The information is the appropriate
URL to download the class from.
We don't need anything nearly as complicated as that. We
already have the class locally. We know the class when we're
serializing. We just need to figure out how to recover it when
The first time any class is referenced from an object being serialized, ObjectOutputStream calls its annotateClass method. Correspondingly, the first time a
class is referenced from an object being deserialized,
ObjectInputStream calls its
resolveClass method.
So we can create subclasses of ObjectOutputStream and
ObjectInputStream that override these methods. Our
annotateClass method will simply record the class in a list; it
won't actually write anything into the stream. The resolveClass
is called at the same point in deserialization as annotateClass
is called in serialization. So resolveClass can simply consume
the classes one by one from the list where annotateClass
recorded them.
Deep modifications in the cloned object
Another method that you can override in ObjectOutputStream is
This allows you to replace one object with another. For
example, suppose you wanted to change the string "foo" into the
string "bar" everywhere it occurs within an object. Your
ObjectOutputStream subclass might look like this:
protectedObject replaceObject(Object obj)throwsIOException{
This will change "foo" into "bar" even if it occurs deep inside
the object being serialized, for example in any of the Strings in
a Map>. Don't forget
to call enableReplaceObject(true) or nothing will
Of course the ability to make arbitrary changes to object
contents is potentially very dangerous. Proceed with caution.
For this reason, unprivileged code cannot override replaceObject
in this way; if there is a SecurityManager then you must have
The code
Here's a basic class that clones using serialization. Once
again, only use this as a last resort, for all the reasons
mentioned above.
Usage is copy =SerialClone.clone(object)
package serialclone;
import java.util.LinkedList;
import java.util.Queue;
publicstatic<T> T clone(T x){
return cloneX(x);
}catch(IOException e){
}catch(ClassNotFoundException e){
privatestatic<T> T cloneX(T x)throwsIOException,ClassNotFoundException{
ByteArrayOutputStream bout =newByteArrayOutputStream();
CloneOutput cout =newCloneOutput(bout);
byte[] bytes = bout.toByteArray();
ByteArrayInputStream bin =newByteArrayInputStream(bytes);
CloneInput cin =newCloneInput(bin, cout);
@SuppressWarnings("unchecked") // thanks to Bas de Bakker for the tip!
T clone =(T) cin.readObject();
return clone;
Queue<Class<?>> classQueue =newLinkedList<Class<?>>();
protectedvoid annotateClass(Class<?> c){
protectedvoid annotateProxyClass(Class<?> c){
privatefinalCloneOutput output;
CloneInput(InputStreamin,CloneOutput output)throwsIOException{
this.output = output;
protectedClass<?> resolveClass(ObjectStreamClass osc)
Class<?> c = output.classQueue.poll();
String expected = osc.getName();
String found =(c ==null)?null: c.getName();
thrownewInvalidClassException("Classes desynchronized: "+
"found "+ found +" when expecting "+ expected);
return c;
protectedClass<?> resolveProxyClass(String[] interfaceNames)
return output.classQueue.poll();
Cloning Java objects using serialization的更多相关文章
- Java序列化(Serialization)
关于Java的序列化的文章在网上已经够多了,在这里写关于Java序列化的文章是对自己关于这方面的的一种总结,结合以前的开发经验与网上的资料,写了这篇文章,对自己是有着巩固记忆的作用,也希望能够对大家有 ...
- Effective Java 78 Consider serialization proxies instead of serialized instances
Serialization proxy pattern private static nested class (has a single constructor whose parameter ty ...
- Unity学习笔记 - Assets, Objects and Serialization
Assets和Objects Asset是存储在硬盘上的文件,保存在Unity项目的Assets文件夹内.比如:纹理贴图.材质和FBX都是Assets.一些Assets以Unity原生格式保存数据,例 ...
- learning java Objects.requireNonNull 当传入参数为null时,该方法返回参数本身
System.out.println(Objects.hashCode(obj)); System.out.println(Objects.toString(obj)); System.out.pri ...
- java的Serialization 机制
基本使用方法 Serialization是指把类或者基本的数据类型持久化(persistence)到数据流(Stream)中,包括文件.字节流.网络数据流. ...
- Objects First with Java 读书笔记 (1)
umm...这学期被发了助教Java的任务,为了避免误人子弟从零开始现学.课是英语教学,就不逐字翻译了,方便记. 参考书目:Objects First with Java - A Practical ...
- Java性能提示(全) the performance of LinkedLi ...
- 115 Java Interview Questions and Answers – The ULTIMATE List--reference
In this tutorial we will discuss about different types of questions that can be used in a Java inter ...
- Java资源大全中文版(Awesome最新版)
Awesome系列的Java资源整理.awesome-java 就是akullpp发起维护的Java资源列表,内容包括:构建工具.数据库.框架.模板.安全.代码分析.日志.第三方库.书籍.Java 站 ...
- JSP(二)
JSTL JSTL不仅可以实现EL所不能实现的逻辑循环或者条件判断,还有强大的定制标记. 使用JSTL 需要将两个文件("jstl.jar"和"standard.jar& ...
- VB2012读取xml
上回谢了生成写xml的,现在把读取的补上 文件如下 <?xml version="1.0" encoding="UTF-8" standalone=&qu ...
- ERS卫星 ERS-2 ROLE Earth observation (EO) LAUNCH DATE 21 ...
- 在ubuntu10.0.4下更新git
今天想到要在ubuntu10.0.4下下载android的源码学习一下.源码下载用到了git.以前安装过git以为应该没什么问题的,没想到报了 “fatal: git 1.7.2 or later r ...
- Unicode其实是Latin1的扩展。只有一个低字节的Uncode字符其实就是Latin1字符——附各种字符编码表及转换表
一.概念 1,ASCII ASCII(American Standard Code for Information Interchange),中文名称为美国信息交换标准代码.是 ...
- 如何同时激活两个不同版本的MyEclipse 【MyEclipse2013和MyEclipse2014同时激活】
激活一个MyEclipse的步骤,大家都会,在这里就不多说了,不会的可以看: ...
- Spring、Bean 的作用域
Singleton作用域(默认) 当一个bean的作用域为singleton,那么Spring Ioc容器中只会存在一个共享的bean实例,并且所有对bean的请求,只要id与该bean定义相匹配,则 ...
- JAVA装饰器模式
Java程序员们应该对java.io对不会陌生,因为java.io包采用了装饰器模式. 一.定义: Decorator装饰器,顾名思义,就是动态地给一个对象添加一些额外的职责,就好比为房子进行装修一样 ...
- html教程系列--form frameset
<font> 标签: 规定文本的字体.字体尺寸.字体颜色.不建议直接使用,可以使用样式表替代. <footer> 标签:定义公用的底部信息.通常包含文档的作者.版权信息.使用条 ...
- javascript 全选与反选
<html xmlns=""><head runat="server"> ...