United StatesChange Country, Oracle Worldwide Web Sites Communities I am a... I want to...
Bug ID: JDK-6589656 Bundle security improvements for JKernel
JDK-6589656 : Bundle security improvements for JKernel

Details
Type:
Bug
Submit Date:
2007-08-06
Status:
Closed
Updated Date:
2012-10-18
Project Name:
JDK
Resolved Date:
2008-06-13
Component:
deploy
OS:
generic
Sub-Component:
deployment_toolkit
CPU:
generic
Priority:
P3
Resolution:
Fixed
Affected Versions:
6u4
Fixed Versions:
6u10 (b02)

Related Reports
Relates:

Sub Tasks

Description
Incorporate review feedback into security pieces of JKernel:

   1) Avoid unnecessary code:
       a) Optimization in StandaloneByteArrayAccess (stripped out)
       b) Usage of custom digest stream classes (omitted)
   2) sun.jkernel.StandaloneSHA class should be package private
   3) StandaloneMessageDigest should guard itself against bypassing its factory method.
   4) DownloadManager and SplitJRE should use StandaloneMessageDigest directly.
   5) Unit tests accidently left out of the external code review and integration
      putback are included, with a few small improvements. (See the CR 6572493 j2se
      webrev URL for the originals)
        test/sun/jkernel/DownloadManager/ParallelClassloading.java
        test/sun/jkernel/StandaloneMessageDigest/ByteArrayToFromHexDigits.java
        test/sun/jkernel/StandaloneMessageDigest/MeasureStandaloneMessageDigest.java
        test/sun/jkernel/StandaloneMessageDigest/StandaloneMessageDigest.java

                                    

Comments
EVALUATION

Need to get this in final state ASAP.
                                     
2007-08-07



Hardware and Software, Engineered to Work Together