[security-dev 01146]: Re: TimeZone.setDefaultZone() permission check change between 6 and 7

Andrew John Hughes gnu_andrew at member.fsf.org
Sun Aug 30 00:16:57 UTC 2009


2009/8/28 Mark Wielaard <mjw at redhat.com>:
> Hi,
>
> While investigating a bug report reported by one of the JBoss hackers:
> http://icedtea.classpath.org/bugzilla/show_bug.cgi?id=381
> "Stackoverflow error with security manager, signed jars and
> -Djava.security.debug set", I noticed there is a change in permission
> check between openjdk6 and openjdk7 with respect to the
> TimeZone.setDefaultZone() method.
>
> Attached is the diff. The first change is similar to what I would have
> suggested. But I am not sure about the second change.
>
> I couldn't find a commit or bug report for this issue. Does someone
> remember why the changes were made? I would like to backport them to 6.
>
> Thanks,
>
> Mark
>

There is nothing in hg log to suggest that file has changed since the
initial Mercurial import.  Thus the change occurred in the period
between the version of OpenJDK7 used as the base for OpenJDK6 (b20?)
and the first Mercurial revision (b24).
-- 
Andrew :-)

Free Java Software Engineer
Red Hat, Inc. (http://www.redhat.com)

Support Free Java!
Contribute to GNU Classpath and the OpenJDK
http://www.gnu.org/software/classpath
http://openjdk.java.net

PGP Key: 94EFD9D8 (http://subkeys.pgp.net)
Fingerprint: F8EF F1EA 401E 2E60 15FA  7927 142C 2591 94EF D9D8



More information about the security-dev mailing list