RFR: 8294696 - BufferedInputStream.transferTo should drain buffer when mark set [v2]

Alan Bateman alanb at openjdk.org
Tue Oct 18 17:06:00 UTC 2022


On Tue, 18 Oct 2022 08:19:41 GMT, Markus KARG <duke at openjdk.org> wrote:

> Does "security review" mean, that I shall proof the absence of the problem, or does that term mean a formal process in the OpenJDK organization (and how do I trigger it)?

I sent a link to this PR to one of the security engineers and they share the concern. Have you done any performance testing with an implementation that makes a defensive copy?

-------------

PR: https://git.openjdk.org/jdk/pull/10525


More information about the core-libs-dev mailing list