← Back to Core Java Course | Chapter 12: File I/O | Lesson 8 of 9

Java में Serialization

Serialization एक object को एक ऐसे form में बदलता है जिसे save या send किया जा सके, इसे ship करने के लिए एक toy को एक box में flatten करने जैसा। आप इसे बाद में rebuild कर सकते हैं।
Syntax
java
class ClassName implements Serializable {
    // fields
}

ObjectOutputStream out = new ObjectOutputStream(new FileOutputStream("file"));
out.writeObject(object);

What is Serialization?

Serialization एक live Java object को एक byte stream में convert करता है जिसे एक file में save या network पर send किया जा सकता है, और बाद में वापस एक equivalent object में reconstruct किया जा सकता है — class को marker interface Serializable implement करना चाहिए।

उदाहरण: What is Serialization?

java
// Import java.io.Serializable so it can be used by its short name
import java.io.Serializable;
// Define the class Person
class Person implements Serializable {
	// Declare name and set it to "Alice"
	String name = "Alice";
}
// Define the class Main
public class Main {
	// Program entry point: the JVM starts running here
	public static void main(String[] args) {
		// Create a new Person object and store it in p
		Person p = new Person();
		// Print a line to the console
		System.out.println(p instanceof Serializable);
	}
}

Writing Objects with ObjectOutputStream

ObjectOutputStream एक serializable object की पूरी state को writeObject() के ज़रिए एक underlying stream में लिखता है, हर non-transient field की current value capture करते हुए।

उदाहरण: Writing Objects with ObjectOutputStream

java
// Import java.io.* so it can be used by its short name
import java.io.*;
// Define the class Person
class Person implements Serializable {
	// Declare name and set it to "Alice"
	String name = "Alice";
}
// Define the class Main
public class Main {
	// Program entry point: the JVM starts running here
	public static void main(String[] args) throws IOException {
		// Create a new ObjectOutputStream object and store it in out
		ObjectOutputStream out = new ObjectOutputStream(new FileOutputStream("person.ser"));
		out.writeObject(new Person());
		out.close();
		// Print a line to the console
		System.out.println("Written");
	}
}

Reading Objects with ObjectInputStream

ObjectInputStream वह byte stream वापस पढ़ता है और readObject() के ज़रिए object reconstruct करता है, इसकी fields को serialization time पर उनकी values में restore करते हुए।

उदाहरण: Reading Objects with ObjectInputStream

java
// Import java.io.* so it can be used by its short name
import java.io.*;
// Define the class Person
class Person implements Serializable {
	// Declare name and set it to "Alice"
	String name = "Alice";
}
// Define the class Main
public class Main {
	// Program entry point: the JVM starts running here
	public static void main(String[] args) throws IOException, ClassNotFoundException {
		// Create a new ObjectOutputStream object and store it in out
		ObjectOutputStream out = new ObjectOutputStream(new FileOutputStream("person.ser"));
		out.writeObject(new Person());
		out.close();
		// Create a new ObjectInputStream object and store it in in
		ObjectInputStream in = new ObjectInputStream(new FileInputStream("person.ser"));
		Person p = (Person) in.readObject();
		in.close();
		// Print a line to the console
		System.out.println(p.name);
	}
}

Transient Fields

एक field को transient मार्क करना इसे serialization से पूरी तरह exclude करता है — आमतौर पर passwords जैसे sensitive data के लिए, या उन fields के लिए (जैसे एक open file handle) जिन्हें बस meaningfully save और restore नहीं किया जा सकता।

उदाहरण: Transient Fields

java
import java.io.Serializable;
class Person implements Serializable {
	String name = "Alice";
	transient String password = "secret"; // excluded from serialization
}
public class Main {
	public static void main(String[] args) {
		Person p = new Person();
		System.out.println(p.password);
	}
}

Safe Serialization Practices

अगर आप untrusted data deserialize करें तो Serialization में असली security risks हैं, क्योंकि एक malicious byte stream unexpected code execution trigger कर सकता है — सिर्फ उन sources से data deserialize करें जिन पर आप पूरी तरह भरोसा करते हैं।

उदाहरण: Safe Serialization Practices

java
// Import java.io.Serializable so it can be used by its short name
import java.io.Serializable;
// Define the class Main
public class Main {
	// Define the class Data
	static class Data implements Serializable {
		// Declare value and set it to 5
		int value = 5;
	}
	// Program entry point: the JVM starts running here
	public static void main(String[] args) {
		// Print a line to the console
		System.out.println("Only deserialize data from trusted sources");
	}
}
Related Topics
{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. Serializable implement करना भूल जाना, जो NotSerializableException throw करता है।
  2. यह उम्मीद करना कि transient fields save होंगी, जब वे skip होती हैं और वापस default values के रूप में पढ़ी जाती हैं।
  3. पढ़े object को गलत class में cast करना, जो ClassCastException throw करता है।

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.