[14] RFR 8229775: Incorrect warning when jar was signed with -sectionsonly
Sean Mullan
sean.mullan at oracle.com
Thu Aug 15 17:10:57 UTC 2019
Looks fine to me.
--Sean
On 8/15/19 9:34 AM, Weijun Wang wrote:
> Please take a review at
>
> http://cr.openjdk.java.net/~weijun/8229775/webrev.00/
>
> The updated code checks both SHA-256-Digest-Manifest and SHA-256-Digest-Manifest-Main-Attributes. The latter should always appear in a SF file generated by our own jarsigner but theoretically it could be missing if MANIFEST.MF has no header. Anyway, checking both is more reliable.
>
> Thanks,
> Max
>
More information about the security-dev
mailing list