<Beans Dev> beans Statement package accessibility checks
Mark Wielaard
mjw at redhat.com
Wed Aug 29 17:57:24 UTC 2012
Hi Omair,
On Wed, 2012-08-29 at 13:32 -0400, Omair Majid wrote:
> On 08/29/2012 06:24 AM, Mark Wielaard wrote:
> > I have only very lightly tested it but this code is somewhat hairy, so
> > some extra pair of eyes and some more testing would not be a bad thing.
> > I do think it makes sense to try to do an icedtea/openjdk release with
> > this (or some other/better) fix ASAP because it seems to be actively
> > exploited in the wild.
>
> The patch looks sensible to me. It adds back the checks that existed in
> older versions of the code so it seems safe too.
>
> I ran all the java.beans jtreg tests and they pass with this change too.
Thanks for the review and thanks for running those tests.
Andrew Hughes was so nice to integrate the patch into the icedtea7
forest so various autobuilders are chewing on it now.
Cheers,
Mark
More information about the beans-dev
mailing list