serialization: Java serialization companion code (UID drift, JEP 290/415 filters, records, JSON/Protobuf comparison)
Co-Authored-By: Claude Sonnet 5.5 <[email protected]> Claude-Session: https://claude.ai/code/session_01KqJyCidz3ZgRyHABv2GVJh
This commit is contained in:
@@ -0,0 +1,16 @@
|
||||
max heap = 256 MiB
|
||||
forged stream is 37 bytes long but claims a byte[1000000000]
|
||||
no filter -> OutOfMemoryError: Java heap space
|
||||
maxarray=100000 -> InvalidClassException: filter status: REJECTED
|
||||
filter saw: class=class [B arrayLength=-1 depth=1 streamBytes=21 -> UNDECIDED
|
||||
filter saw: class=class [B arrayLength=1000000000 depth=1 streamBytes=27 -> REJECTED
|
||||
maxarray, logged -> InvalidClassException: filter status: REJECTED
|
||||
|
||||
a legitimate-looking chain of 200 nodes is 1324 bytes
|
||||
no filter -> accepted: Node
|
||||
maxdepth=50 -> InvalidClassException: filter status: REJECTED
|
||||
|
||||
maxbytes=10000, one 50 KB array -> accepted: byte[]
|
||||
an ArrayList of 5000 integers is 50125 bytes
|
||||
maxbytes=10000, 5000 integers -> InvalidClassException: filter status: REJECTED
|
||||
maxbytes=1000000, 5000 integers -> accepted: ArrayList
|
||||
Reference in New Issue
Block a user