解决Jackson Afterburner模块非法反射访问警告的疑问
Jackson非法反射访问警告的解决方案与疑问解答
触发的警告信息:
WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.fasterxml.jackson.module.afterburner.util.MyClassLoader (file:/Users/pedro.maria/.m2/repository/com/fasterxml/jackson/module/jackson-module-afterburner/2.13.4/jackson-module-afterburner-2.13.4.jar) to method java.lang.ClassLoader.findLoadedClass(java.lang.String) WARNING: Please consider reporting this to the maintainers of com.fasterxml.jackson.module.afterburner.util.MyClassLoader WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release
1. --add-opens标记的传递位置
根据不同运行场景,传递方式如下:
- Maven运行/测试:
- 临时执行:通过
-DargLine参数传递,示例命令:mvn exec:java -DargLine="--add-opens java.base/java.lang.ClassLoader=ALL-UNNAMED" - 持久化配置:在pom.xml的
maven-surefire-plugin(测试场景)或maven-exec-plugin中配置argLine,示例:<plugin> <groupId>org.apache.maven.plugins</groupId> <artifactId>maven-surefire-plugin</artifactId> <configuration> <argLine>--add-opens java.base/java.lang.ClassLoader=ALL-UNNAMED</argLine> </configuration> </plugin> - 全局生效:设置
MAVEN_OPTS环境变量,例如:export MAVEN_OPTS="--add-opens java.base/java.lang.ClassLoader=ALL-UNNAMED"
- 临时执行:通过
- Docker环境:在
CMD或ENTRYPOINT中直接添加JVM参数,示例:CMD ["java", "--add-opens", "java.base/java.lang.ClassLoader=ALL-UNNAMED", "-jar", "your-application.jar"] - IDE本地运行:在Run/Debug配置的「VM options」栏中添加
--add-opens java.base/java.lang.ClassLoader=ALL-UNNAMED
2. --add-opens标记的正确写法及制定依据
正确写法
精准的标记应为:
--add-opens java.base/java.lang.ClassLoader=ALL-UNNAMED
你之前尝试的--add-opens java.base/java.lang=ALL-UNNAMED范围过宽,会开放整个java.lang包的反射权限,存在安全隐患,建议使用类级别的精准开放。
制定依据
Java 9引入的模块系统(JPMS)默认限制跨模块反射访问:
java.base是JDK核心模块,包含java.lang.ClassLoader等基础类- 被访问的
findLoadedClass是ClassLoader的protected方法,默认不允许未授权的外部模块反射调用 ALL-UNNAMED表示将权限开放给所有未命名模块——Jackson的afterburner模块是传统jar包,不属于任何JPMS命名模块,因此需要用该值指定目标范围。
额外建议
优先升级Jackson afterburner模块到2.14.0及以上版本,官方在该版本中修复了此非法反射问题,无需手动添加JVM参数。
内容的提问来源于stack exchange,提问作者Pmsmm
相关产品推荐
相关产品推荐

