=== LeakyOrder: a record field that LOOKS immutable but isn't === leaky.items() right after construction = [widget, gadget] caller mutates their OWN list reference afterwards: callerList.add(...) leaky.items() now = [widget, gadget, SNEAKY EXTRA ITEM] <- the record's field changed too, because it's the SAME list object === LeakyOrder.items() also returns the live mutable reference - callers can mutate it directly === leaky.items() after leaky.items().add(...) = [widget, gadget, SNEAKY EXTRA ITEM, MUTATED THROUGH THE ACCESSOR] === SafeOrder: List.copyOf(...) in a compact constructor closes both holes === safe.items() right after construction = [widget, gadget] caller mutates their OWN list reference afterwards: callerList2.add(...) safe.items() now = [widget, gadget] <- unchanged, it's an independent copy === And the accessor's result rejects mutation too, since List.copyOf returns an immutable list === safe.items().add(...) threw UnsupportedOperationException === The constructor itself still rejects null elements, same as List.of === new SafeOrder(..., listContainingNull) threw NullPointerException from inside List.copyOf(...)