[14] RFR 8229775: Incorrect warning when jar was signed with -sectionsonly

Sean Mullan sean.mullan at oracle.com
Thu Aug 15 17:10:57 UTC 2019


Looks fine to me.

--Sean

On 8/15/19 9:34 AM, Weijun Wang wrote:
> Please take a review at
> 
>     http://cr.openjdk.java.net/~weijun/8229775/webrev.00/
> 
> The updated code checks both SHA-256-Digest-Manifest and SHA-256-Digest-Manifest-Main-Attributes. The latter should always appear in a SF file generated by our own jarsigner but theoretically it could be missing if MANIFEST.MF has no header. Anyway, checking both is more reliable.
> 
> Thanks,
> Max
> 



More information about the security-dev mailing list