Tue, 06 Oct 2009 21:40:55 -0700 Merge
asaha [Tue, 06 Oct 2009 21:40:55 -0700] rev 4209
Merge
Thu, 24 Sep 2009 22:50:41 +0100 6863503: SECURITY: MessageDigest.isEqual introduces timing attack vulnerabilities
vinnie [Thu, 24 Sep 2009 22:50:41 +0100] rev 4208
6863503: SECURITY: MessageDigest.isEqual introduces timing attack vulnerabilities Reviewed-by: mullan, wetmore
Mon, 14 Sep 2009 11:46:16 +0400 6872358: JRE AWT setBytePixels vulnerable to Heap Overflow
bae [Mon, 14 Sep 2009 11:46:16 +0400] rev 4207
6872358: JRE AWT setBytePixels vulnerable to Heap Overflow Reviewed-by: prr, hawtin
Thu, 10 Sep 2009 14:15:47 +0400 6631533: ICC_Profile allows detecting if some files exist
bae [Thu, 10 Sep 2009 14:15:47 +0400] rev 4206
6631533: ICC_Profile allows detecting if some files exist Reviewed-by: prr, hawtin
Thu, 10 Sep 2009 14:04:38 +0400 6632445: DoS from parsing BMPs with UNC ICC links
bae [Thu, 10 Sep 2009 14:04:38 +0400] rev 4205
6632445: DoS from parsing BMPs with UNC ICC links Reviewed-by: prr, hawtin
Thu, 10 Sep 2009 13:52:27 +0400 6822057: X11 and Win32GraphicsDevice don't clone arrays returned from getConfigurations()
bae [Thu, 10 Sep 2009 13:52:27 +0400] rev 4204
6822057: X11 and Win32GraphicsDevice don't clone arrays returned from getConfigurations() Reviewed-by: prr, hawtin
Thu, 10 Sep 2009 13:35:28 +0400 6862968: JPEG Image Writer quantization problem
bae [Thu, 10 Sep 2009 13:35:28 +0400] rev 4203
6862968: JPEG Image Writer quantization problem Reviewed-by: prr, hawtin
Thu, 10 Sep 2009 12:50:09 +0400 6872357: JRE AWT setDifflCM vulnerable to Stack Overflow
bae [Thu, 10 Sep 2009 12:50:09 +0400] rev 4202
6872357: JRE AWT setDifflCM vulnerable to Stack Overflow Reviewed-by: prr, hawtin
Thu, 10 Sep 2009 12:26:34 +0400 6874643: ImageI/O JPEG is vulnerable to Heap Overflow
bae [Thu, 10 Sep 2009 12:26:34 +0400] rev 4201
6874643: ImageI/O JPEG is vulnerable to Heap Overflow Reviewed-by: prr, hawtin
Sat, 05 Sep 2009 07:55:05 -0700 Merge
asaha [Sat, 05 Sep 2009 07:55:05 -0700] rev 4200
Merge
Thu, 03 Sep 2009 19:42:27 +0400 6657026: Numerous static security flaws in Swing (findbugs)
malenkov [Thu, 03 Sep 2009 19:42:27 +0400] rev 4199
6657026: Numerous static security flaws in Swing (findbugs) Reviewed-by: hawtin, peterz
Tue, 01 Sep 2009 08:15:00 -0700 Merge
asaha [Tue, 01 Sep 2009 08:15:00 -0700] rev 4198
Merge
Mon, 31 Aug 2009 08:54:39 -0700 Merge
asaha [Mon, 31 Aug 2009 08:54:39 -0700] rev 4197
Merge
Thu, 27 Aug 2009 15:08:10 -0700 Merge
asaha [Thu, 27 Aug 2009 15:08:10 -0700] rev 4196
Merge
Wed, 26 Aug 2009 08:38:57 -0700 Merge
asaha [Wed, 26 Aug 2009 08:38:57 -0700] rev 4195
Merge
Wed, 26 Aug 2009 17:05:15 +0900 6824265: (tz) TimeZone.getTimeZone allows probing local filesystem
okutsu [Wed, 26 Aug 2009 17:05:15 +0900] rev 4194
6824265: (tz) TimeZone.getTimeZone allows probing local filesystem Reviewed-by: peytoia
Thu, 20 Aug 2009 17:16:13 -0700 6874407: Missing regression test for 6636650
valeriep [Thu, 20 Aug 2009 17:16:13 -0700] rev 4193
6874407: Missing regression test for 6636650 Summary: Prevent classloader from resurrection Reviewed-by: hawtin
Thu, 20 Aug 2009 14:49:31 -0700 6636650: (cl) Resurrected ClassLoaders can still have children
valeriep [Thu, 20 Aug 2009 14:49:31 -0700] rev 4192
6636650: (cl) Resurrected ClassLoaders can still have children Summary: Prevent classloader from resurrection Reviewed-by: hawtin
Thu, 20 Aug 2009 12:46:43 +0400 6664512: Component and [Default]KeyboardFocusManager pass security sensitive objects to loggers
dcherepanov [Thu, 20 Aug 2009 12:46:43 +0400] rev 4191
6664512: Component and [Default]KeyboardFocusManager pass security sensitive objects to loggers Summary: toString is called on security sensitive objects Reviewed-by: art, hawtin
Tue, 18 Aug 2009 20:47:13 -0700 6861062: Disable MD2 support
xuelei [Tue, 18 Aug 2009 20:47:13 -0700] rev 4190
6861062: Disable MD2 support Reviewed-by: mullan, weijun
Tue, 18 Aug 2009 16:53:23 -0700 Merge
asaha [Tue, 18 Aug 2009 16:53:23 -0700] rev 4189
Merge
Tue, 18 Aug 2009 12:10:12 +0800 6864911: ASN.1/DER input stream parser needs more work
weijun [Tue, 18 Aug 2009 12:10:12 +0800] rev 4188
6864911: ASN.1/DER input stream parser needs more work Reviewed-by: mullan, xuelei
Sun, 08 Nov 2009 15:11:10 -0800 6888927: Fix jdk jtreg tests to indicate which ones need othervm, allow for use of samevm option
ohair [Sun, 08 Nov 2009 15:11:10 -0800] rev 4187
6888927: Fix jdk jtreg tests to indicate which ones need othervm, allow for use of samevm option Reviewed-by: tbell, jjg, alanb
Fri, 06 Nov 2009 17:27:41 -0800 Merge
tbell [Fri, 06 Nov 2009 17:27:41 -0800] rev 4186
Merge
Thu, 05 Nov 2009 16:12:45 -0800 6898220: Optimize Formatter.parse (including String.printf)
martin [Thu, 05 Nov 2009 16:12:45 -0800] rev 4185
6898220: Optimize Formatter.parse (including String.printf) Summary: Create fewer objects when parsing Reviewed-by: sherman Contributed-by: Daniel Martin <dtm@google.com>
Thu, 05 Nov 2009 16:12:45 -0800 6897553: LinkedList performance improvements
martin [Thu, 05 Nov 2009 16:12:45 -0800] rev 4184
6897553: LinkedList performance improvements Summary: LinkedList of size N creates N+1 instead of N+2 objects. Comparing against null is faster than comparing against sentinel node Reviewed-by: dl, jjb, forax
Wed, 04 Nov 2009 15:22:30 -0800 6897993: (se) Close or cancel performance issue when number of pending updates is high (lnx)
martin [Wed, 04 Nov 2009 15:22:30 -0800] rev 4183
6897993: (se) Close or cancel performance issue when number of pending updates is high (lnx) Summary: Use O(1) Iterator instead of O(N) operations on LinkedList updateList Reviewed-by: alanb Contributed-by: Igor Chernyshev <igorc@google.com>
Tue, 03 Nov 2009 15:01:50 -0800 6897550: BigInteger constructor should use local cached String length
darcy [Tue, 03 Nov 2009 15:01:50 -0800] rev 4182
6897550: BigInteger constructor should use local cached String length Reviewed-by: andrew, chegar
Fri, 30 Oct 2009 21:31:02 +0000 6896829: test/sun/util/logging/PlatformLoggerTest.java needs @compile tag to be compiled by jtreg
alanb [Fri, 30 Oct 2009 21:31:02 +0000] rev 4181
6896829: test/sun/util/logging/PlatformLoggerTest.java needs @compile tag to be compiled by jtreg Reviewed-by: mchung, tbell
Fri, 30 Oct 2009 13:12:24 -0700 Merge
tbell [Fri, 30 Oct 2009 13:12:24 -0700] rev 4180
Merge
Fri, 30 Oct 2009 09:06:38 -0700 Merge
tbell [Fri, 30 Oct 2009 09:06:38 -0700] rev 4179
Merge
Fri, 30 Oct 2009 13:01:16 -0700 6894950: test/java/util/zip/Bounds.java fails with OoutOfMemoryError
sherman [Fri, 30 Oct 2009 13:01:16 -0700] rev 4178
6894950: test/java/util/zip/Bounds.java fails with OoutOfMemoryError Summary: Fixed the boundary check in Deflater.java Reviewed-by: alanb
Fri, 30 Oct 2009 15:06:24 +0000 6896573: Arrays.sort(long[]) fails with StackOverflowError
alanb [Fri, 30 Oct 2009 15:06:24 +0000] rev 4177
6896573: Arrays.sort(long[]) fails with StackOverflowError Reviewed-by: jjb Contributed-by: vladimir.yaroslavskiy@sun.com
Fri, 30 Oct 2009 11:28:42 +0800 6894534: SeedGenerator shouldn't require java.nio.file to be present
weijun [Fri, 30 Oct 2009 11:28:42 +0800] rev 4176
6894534: SeedGenerator shouldn't require java.nio.file to be present Reviewed-by: alanb
Thu, 29 Oct 2009 19:55:52 -0700 Merge
mchung [Thu, 29 Oct 2009 19:55:52 -0700] rev 4175
Merge
Thu, 29 Oct 2009 09:22:00 -0700 6896422: Add @ignore to test/java/util/zip/Bounds.java
mchung [Thu, 29 Oct 2009 09:22:00 -0700] rev 4174
6896422: Add @ignore to test/java/util/zip/Bounds.java Summary: ignore test/java/util/zip/Bounds.java until 6896424 is resolved Reviewed-by: sherman
Wed, 28 Oct 2009 11:18:01 -0700 6895875: Missing serialVersionUID in sun.management classes
mchung [Wed, 28 Oct 2009 11:18:01 -0700] rev 4173
6895875: Missing serialVersionUID in sun.management classes Summary: Added serialVersionUID to fix warning errors Reviewed-by: alanb
Tue, 27 Oct 2009 16:32:23 -0700 6876135: Add PlatformLoggingMXBean to eliminate the dependency on JMX from logging
mchung [Tue, 27 Oct 2009 16:32:23 -0700] rev 4172
6876135: Add PlatformLoggingMXBean to eliminate the dependency on JMX from logging Summary: Added a new PlatformLoggingMXBean interface to extend PlatformManagedObject instead of LoggingMXBean Reviewed-by: alanb
Tue, 27 Oct 2009 16:31:01 -0700 6895456: Eliminate dependency on java.io.ObjectStreamClass during boot
mchung [Tue, 27 Oct 2009 16:31:01 -0700] rev 4171
6895456: Eliminate dependency on java.io.ObjectStreamClass during boot Summary: Duplicate ObjectStreamClass.getClassSignature method in ObjectStreamField class Reviewed-by: alanb
Thu, 29 Oct 2009 11:18:37 +0000 6880672: Replace quicksort in java.util.Arrays with dual-pivot implementation
alanb [Thu, 29 Oct 2009 11:18:37 +0000] rev 4170
6880672: Replace quicksort in java.util.Arrays with dual-pivot implementation Reviewed-by: jjb Contributed-by: vladimir.yaroslavskiy@sun.com, joshua.bloch@google.com, jbentley@avaya.com
Wed, 28 Oct 2009 15:32:49 +0800 6890872: keytool -printcert to recognize signed jar files
weijun [Wed, 28 Oct 2009 15:32:49 +0800] rev 4169
6890872: keytool -printcert to recognize signed jar files Reviewed-by: mullan
Wed, 28 Oct 2009 15:32:30 +0800 6893158: AP_REQ check should use key version number
weijun [Wed, 28 Oct 2009 15:32:30 +0800] rev 4168
6893158: AP_REQ check should use key version number Reviewed-by: valeriep, xuelei
Tue, 27 Oct 2009 08:55:35 +0000 6888179: Separate out dependency on CORBA
alanb [Tue, 27 Oct 2009 08:55:35 +0000] rev 4167
6888179: Separate out dependency on CORBA Reviewed-by: dfuchs
Sat, 24 Oct 2009 20:36:01 +0100 6894633: NetHooks should not require provider to be present (sol)
alanb [Sat, 24 Oct 2009 20:36:01 +0100] rev 4166
6894633: NetHooks should not require provider to be present (sol) Reviewed-by: chegar, jccollet
Fri, 23 Oct 2009 11:18:17 -0700 6891113: More methods for java.util.Objects: deepEquals, hash, toString with default
darcy [Fri, 23 Oct 2009 11:18:17 -0700] rev 4165
6891113: More methods for java.util.Objects: deepEquals, hash, toString with default Reviewed-by: alanb, gafter
Thu, 22 Oct 2009 15:44:42 +0100 6894169: Move HttpLogFormatter into a separate package
chegar [Thu, 22 Oct 2009 15:44:42 +0100] rev 4164
6894169: Move HttpLogFormatter into a separate package Reviewed-by: alanb
Wed, 21 Oct 2009 11:52:04 -0700 Merge
sherman [Wed, 21 Oct 2009 11:52:04 -0700] rev 4163
Merge
Wed, 21 Oct 2009 11:50:25 -0700 4206909: want java.util.zip to work for interactive use (Z_SYNC_FLUSH)
sherman [Wed, 21 Oct 2009 11:50:25 -0700] rev 4162
4206909: want java.util.zip to work for interactive use (Z_SYNC_FLUSH) Summary: Add sync_flush option into Deflater/DefalterOutputStream Reviewed-by: martin, alanb
Wed, 21 Oct 2009 11:40:40 -0700 6878475: Better syntax for the named capture group in regex
sherman [Wed, 21 Oct 2009 11:40:40 -0700] rev 4161
6878475: Better syntax for the named capture group in regex Summary: Updated the syntax of the newly added named capture group Reviewed-by: martin, alanb
Wed, 21 Oct 2009 09:53:23 -0700 6560935: BigInteger.modPow() throws ArithmeticException for negative exponent
darcy [Wed, 21 Oct 2009 09:53:23 -0700] rev 4160
6560935: BigInteger.modPow() throws ArithmeticException for negative exponent Reviewed-by: alanb
Wed, 21 Oct 2009 16:50:44 +0100 Merge
chegar [Wed, 21 Oct 2009 16:50:44 +0100] rev 4159
Merge
Wed, 21 Oct 2009 15:47:09 +0100 Merge
chegar [Wed, 21 Oct 2009 15:47:09 +0100] rev 4158
Merge
Wed, 21 Oct 2009 15:41:42 +0100 6893238: Move NTLM and SPNEGO implementations into separate packages
chegar [Wed, 21 Oct 2009 15:41:42 +0100] rev 4157
6893238: Move NTLM and SPNEGO implementations into separate packages Reviewed-by: michaelm, alanb
Wed, 21 Oct 2009 17:33:18 +0200 6851617: Remove JSR 255 (JMX API 2.0) from JDK 7
emcmanus [Wed, 21 Oct 2009 17:33:18 +0200] rev 4156
6851617: Remove JSR 255 (JMX API 2.0) from JDK 7 Summary: See http://weblogs.java.net/blog/2009/06/16/jsr-255-jmx-api-20-postponed Reviewed-by: dfuchs
Wed, 21 Oct 2009 16:28:57 +0200 6893702: Overhaul of Ftp Client internal code
jccollet [Wed, 21 Oct 2009 16:28:57 +0200] rev 4155
6893702: Overhaul of Ftp Client internal code Summary: Major reorg of internal FTP client code Reviewed-by: chegar
Wed, 21 Oct 2009 13:42:39 +0200 6873543: CookieManager doesn't enforce httpOnly
jccollet [Wed, 21 Oct 2009 13:42:39 +0200] rev 4154
6873543: CookieManager doesn't enforce httpOnly Summary: Adds check for httpOnly tag and clarifies javadoc Reviewed-by: chegar
(0) -3000 -1000 -300 -100 -56 +56 +100 +300 +1000 +3000 +10000 +30000 tip