Skip to content
体验新版
项目
组织
正在加载...
登录
切换导航
打开侧边栏
openanolis
dragonwell8_jdk
提交
60b36253
D
dragonwell8_jdk
项目概览
openanolis
/
dragonwell8_jdk
通知
4
Star
2
Fork
0
代码
文件
提交
分支
Tags
贡献者
分支图
Diff
Issue
0
列表
看板
标记
里程碑
合并请求
0
Wiki
0
Wiki
分析
仓库
DevOps
项目成员
Pages
D
dragonwell8_jdk
项目概览
项目概览
详情
发布
仓库
仓库
文件
提交
分支
标签
贡献者
分支图
比较
Issue
0
Issue
0
列表
看板
标记
里程碑
合并请求
0
合并请求
0
Pages
分析
分析
仓库分析
DevOps
Wiki
0
Wiki
成员
成员
收起侧边栏
关闭侧边栏
动态
分支图
创建新Issue
提交
Issue看板
提交
60b36253
编写于
3月 28, 2013
作者:
L
lancea
浏览文件
操作
浏览文件
下载
电子邮件补丁
差异文件
8009554: Improve SerialJavaObject.getFields
Reviewed-by: alanb, skoivu, mchung
上级
6f725660
变更
1
隐藏空白更改
内联
并排
Showing
1 changed file
with
45 addition
and
1 deletion
+45
-1
src/share/classes/javax/sql/rowset/serial/SerialJavaObject.java
...are/classes/javax/sql/rowset/serial/SerialJavaObject.java
+45
-1
未找到文件。
src/share/classes/javax/sql/rowset/serial/SerialJavaObject.java
浏览文件 @
60b36253
/*
* Copyright (c) 2003, 201
2
, Oracle and/or its affiliates. All rights reserved.
* Copyright (c) 2003, 201
3
, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
...
...
@@ -30,6 +30,7 @@ import java.lang.reflect.*;
import
java.util.Arrays
;
import
java.util.Vector
;
import
javax.sql.rowset.RowSetWarning
;
import
sun.reflect.Reflection
;
/**
* A serializable mapping in the Java programming language of an SQL
...
...
@@ -119,10 +120,19 @@ public class SerialJavaObject implements Serializable, Cloneable {
* @return an array of <code>Field</code> objects
* @throws SerialException if an error is encountered accessing
* the serialized object
* @throws SecurityException If a security manager, <i>s</i>, is present
* and the caller's class loader is not the same as or an
* ancestor of the class loader for the class of the
* {@linkplain #getObject object} being serialized
* and invocation of {@link SecurityManager#checkPackageAccess
* s.checkPackageAccess()} denies access to the package
* of that class.
* @see Class#getFields
*/
public
Field
[]
getFields
()
throws
SerialException
{
if
(
fields
!=
null
)
{
Class
<?>
c
=
this
.
obj
.
getClass
();
checkPackageAccess
(
c
);
return
c
.
getFields
();
}
else
{
throw
new
SerialException
(
"SerialJavaObject does not contain"
+
...
...
@@ -254,4 +264,38 @@ public class SerialJavaObject implements Serializable, Cloneable {
}
return
false
;
}
/*
* Check if the caller is allowed to access the specified class's package. If access is denied,
* throw a SecurityException.
*
*/
private
void
checkPackageAccess
(
Class
<?>
clz
)
{
SecurityManager
s
=
System
.
getSecurityManager
();
if
(
s
!=
null
)
{
if
(
sun
.
reflect
.
misc
.
ReflectUtil
.
needsPackageAccessCheck
(
getCallerClassLoader
(),
clz
.
getClassLoader
()))
{
String
name
=
clz
.
getName
();
int
i
=
name
.
lastIndexOf
(
'.'
);
if
(
i
!=
-
1
)
{
s
.
checkPackageAccess
(
name
.
substring
(
0
,
i
));
}
}
}
}
/* Internal method used to get the caller's caller class loader.
* Caution is required if you attempt to make changes as this method assumes
* the following stack frame count:
* 0: Reflection
* 1: getCallerClassLoader
* 2: checkPackageAccess
* 3: getFields
* 4: caller of getFields
*/
private
static
ClassLoader
getCallerClassLoader
()
{
Class
<?>
cc
=
Reflection
.
getCallerClass
(
4
);
ClassLoader
cl
=
(
cc
!=
null
)
?
cc
.
getClassLoader
()
:
null
;
return
cl
;
}
}
编辑
预览
Markdown
is supported
0%
请重试
或
添加新附件
.
添加附件
取消
You are about to add
0
people
to the discussion. Proceed with caution.
先完成此消息的编辑!
取消
想要评论请
注册
或
登录