如何修改JDK 10仅保留java.lang包,限制编译与运行时的包访问
java.lang Package Alright, let's tackle this problem step by step. You want to modify your extracted JDK 10 installation so that both compilation and runtime restrict access to only the java.lang package—any reference to other core packages like java.io or java.util should throw a ClassNotFoundException. Here's how to make that happen:
Step 1: Extract and Filter Core Classes from java.base
JDK 9+ uses modules, and all core packages (including java.lang, java.io, java.util) live in the java.base module. We need to extract this module and keep only the java.lang classes (plus critical internal dependencies that java.lang relies on, like sun.misc).
Navigate to your extracted JDK's
jmodsdirectory, then extract thejava.base.jmodfile:jmod extract java.base.jmodThis creates a
java.basedirectory with aclassessubfolder containing all core class files.Clean up the
classesdirectory to retain only necessary content:# Enter the classes folder cd java.base/classes # Delete all Java subdirectories except java/lang find java -type d ! -name "lang" ! -path "java" | xargs rm -rf # Keep critical internal directories (like sun/misc) that java.lang depends on # Adjust this list if you run into runtime errors find . -type d \( ! -name "lang" ! -name "misc" ! -path "./java" ! -path "./sun" \) | xargs rm -rf
Step 2: Package the Filtered Classes into a Custom JAR
Create a custom JAR that contains only our filtered core classes:
jar cf custom-java-base.jar -C ../java.base/classes .
This JAR will act as our restricted core class library.
Step 3: Compile Code with Restricted Classpath
When compiling your Java code, use the -Xbootclasspath/p flag to force javac to prioritize our custom JAR over the default JDK core classes. This ensures any reference to non-java.lang packages will trigger a ClassNotFoundException:
javac -Xbootclasspath/p:./custom-java-base.jar YourJavaFile.java
For example, if your code includes import java.util.ArrayList;, the compiler will fail with an error stating the class cannot be found.
Step 4: Run Code with Restricted Class Loading
To enforce the same restriction at runtime, use the same -Xbootclasspath/p flag when launching your application:
java -Xbootclasspath/p:./custom-java-base.jar YourJavaFile
Even if code tries to access non-java.lang classes via reflection, the class loader will fail to locate them and throw a ClassNotFoundException.
Key Notes
- Dependency Checks:
java.langrelies on some internal classes (e.g.,sun.misc.Unsafe), so we can't delete all non-java.langdirectories. Test your setup with simple code (like a basicHelloWorldusing onlyjava.langfeatures) to adjust which internal directories to keep. - Modular Compatibility: JDK 10 marks
-Xbootclasspath/pas deprecated, but it still works reliably for this use case. If you want a more modular approach, you could create a custom module with onlyjava.langexported, but this requires resolving complex module dependencies. - Strict Enforcement: This setup blocks both explicit imports and reflective access to non-
java.langpackages, fully meeting your requirement.
内容的提问来源于stack exchange,提问作者Vijay

