Records re-run their validation when read
Java serialization turns an object graph into bytes (ObjectOutputStream) and rebuilds it later (ObjectInputStream). It's built in and easy, but it's fragile across versions and reading untrusted bytes is a classic security hole, so modern code prefers explicit formats like JSON and uses filters when it must deserialize.
Change the code and press Run (Ctrl+Enter). Try to predict the output first, then break it on purpose and read the error. Your edits are saved and match the lesson page.
Practice questions
Write the code in the editor, run it, then open the model answer to compare.
Serialize a list of two records to a byte array and read it back, printing the list.
Show that a static field is not serialized: change it after writing, then read the object back.
Explain it without notes
What happens, step by step, when you call writeObject and readObject?
Why is deserializing untrusted data dangerous, and how do you defend against it?
What do transient and serialVersionUID do?
Expected output
read back: Range[lo=1, hi=5]
a record is rebuilt through its constructor, so the check runs on every read