[RFR] 8205525 : Improve exception messages during manifest parsing of jar archives

Baesken, Matthias matthias.baesken at sap.com
Mon Jun 25 14:29:49 UTC 2018


Hi, do you consider  both  the file name and  line number as sensitive ?

>
> There was a similar discussion on net-dev recently related to
> leaking host names in exceptions. Something similar may be needed here
>

Do you know the outcome of this discussion ?

Best regards, Matthias



> -----Original Message-----
> From: Alan Bateman [mailto:Alan.Bateman at oracle.com]
> Sent: Montag, 25. Juni 2018 16:17
> To: Baesken, Matthias <matthias.baesken at sap.com>; core-libs-
> dev at openjdk.java.net
> Subject: Re: [RFR] 8205525 : Improve exception messages during manifest
> parsing of jar archives
> 
> On 25/06/2018 14:55, Baesken, Matthias wrote:
> > Hello, please review this small change  that  improve exception messages
> during manifest parsing of jar archives .
> >
> > Thanks, Matthias
> >
> >    Bug :
> >
> > https://bugs.openjdk.java.net/browse/JDK-8205525
> >
> >    Webrev :
> >
> > http://cr.openjdk.java.net/~mbaesken/webrevs/8205525/
> This potentially leaks sensitive information and will require a security
> review. There was a similar discussion on net-dev recently related to
> leaking host names in exceptions. Something similar may be needed here.
> 
> -Alan.



More information about the core-libs-dev mailing list