RFR 9: 8155760 Implement Serialization Filtering - revised for extensibility

Roger Riggs Roger.Riggs at Oracle.com
Fri Sep 30 19:00:52 UTC 2016


Converging on a final version.

The ObjectInputFilter.FilterInfo.getClazz method was renamed to 
serialClass to improve readability
and reduce ambiguity with getClass. A few other editorial improvements 
have been made in the docs
of the FilterInfo interface for arrays, depth(), references(), and 
streamBytes() with respect to the initial values.

Any additional review comments?


Complete webrev supporting Serialization Filtering:
http://cr.openjdk.java.net/~rriggs/webrev-serial-filter-jdk9-8155760/

The specdiff of changes supporting evolving the API more easily:
http://cr.openjdk.java.net/~rriggs/filter-diffs-8166739/overview-summary.html

Javadoc (subset)
http://cr.openjdk.java.net/~rriggs/filter-javadoc/java/io/ObjectInputStream.html 

http://cr.openjdk.java.net/~rriggs/filter-javadoc/java/io/ObjectInputFilter.html 

http://cr.openjdk.java.net/~rriggs/filter-javadoc/java/io/SerializablePermission.html 


Thanks, Roger




More information about the core-libs-dev mailing list