# HG changeset patch # User weijun # Date 1379558489 -28800 # Node ID 5668a8abf2121e2072eb2b325f28fa893daf3e8c # Parent 529f1cc322fc51aaa8fbff0cf971b582803f5a6c 8024659: Clarify JarFile API Reviewed-by: mullan, ahgross diff -r 529f1cc322fc -r 5668a8abf212 jdk/src/share/classes/java/util/jar/JarFile.java --- a/jdk/src/share/classes/java/util/jar/JarFile.java Thu Sep 19 10:40:16 2013 +0800 +++ b/jdk/src/share/classes/java/util/jar/JarFile.java Thu Sep 19 10:41:29 2013 +0800 @@ -53,6 +53,13 @@ * or method in this class will cause a {@link NullPointerException} to be * thrown. * + * If the verify flag is on when opening a signed jar file, the content of the + * file is verified against its signature embedded inside the file. Please note + * that the verification process does not include validating the signer's + * certificate. A caller should inspect the return value of + * {@link JarEntry#getCodeSigners()} to further determine if the signature + * can be trusted. + * * @author David Connelly * @see Manifest * @see java.util.zip.ZipFile