jmx-dev RFR: 8283093: JMX connections should default to using an ObjectInputFilter [v4]

Serguei Spitsyn sspitsyn at openjdk.org
Wed Oct 26 11:35:23 UTC 2022


On Wed, 26 Oct 2022 10:18:28 GMT, Kevin Walls <kevinw at openjdk.org> wrote:

>> Set the management.properties  "com.sun.management.jmxremote.serial.filter.pattern" value by default, to restrict types that can be deserialized.
>> 
>> Use the example value from the Core Libraries guide (see section 2. Serialization Filtering / Built-in Filters / Filters for JMX), plus Subject which is needed when using authentication.
>> 
>> The sun/management tests run OK with this change.  The existing test sun/management/jmxremote/startstop/JMXStartStopTest.java will fail if the filter specified is made too restrictive.
>
> Kevin Walls has updated the pull request incrementally with one additional commit since the last revision:
> 
>   Split long line

Thank you for the update and creating a RN sub-task.
Looks good.
Thanks,
Serguei

-------------

Marked as reviewed by sspitsyn (Reviewer).

PR: https://git.openjdk.org/jdk/pull/10507


More information about the jmx-dev mailing list