You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何修改JDK 10仅保留java.lang包,限制编译与运行时的包访问

Restricting JDK 10 to Only Allow java.lang Package

Alright, let's tackle this problem step by step. You want to modify your extracted JDK 10 installation so that both compilation and runtime restrict access to only the java.lang package—any reference to other core packages like java.io or java.util should throw a ClassNotFoundException. Here's how to make that happen:

Step 1: Extract and Filter Core Classes from java.base

JDK 9+ uses modules, and all core packages (including java.lang, java.io, java.util) live in the java.base module. We need to extract this module and keep only the java.lang classes (plus critical internal dependencies that java.lang relies on, like sun.misc).

  1. Navigate to your extracted JDK's jmods directory, then extract the java.base.jmod file:

    jmod extract java.base.jmod
    

    This creates a java.base directory with a classes subfolder containing all core class files.

  2. Clean up the classes directory to retain only necessary content:

    # Enter the classes folder
    cd java.base/classes
    
    # Delete all Java subdirectories except java/lang
    find java -type d ! -name "lang" ! -path "java" | xargs rm -rf
    
    # Keep critical internal directories (like sun/misc) that java.lang depends on
    # Adjust this list if you run into runtime errors
    find . -type d \( ! -name "lang" ! -name "misc" ! -path "./java" ! -path "./sun" \) | xargs rm -rf
    

Step 2: Package the Filtered Classes into a Custom JAR

Create a custom JAR that contains only our filtered core classes:

jar cf custom-java-base.jar -C ../java.base/classes .

This JAR will act as our restricted core class library.

Step 3: Compile Code with Restricted Classpath

When compiling your Java code, use the -Xbootclasspath/p flag to force javac to prioritize our custom JAR over the default JDK core classes. This ensures any reference to non-java.lang packages will trigger a ClassNotFoundException:

javac -Xbootclasspath/p:./custom-java-base.jar YourJavaFile.java

For example, if your code includes import java.util.ArrayList;, the compiler will fail with an error stating the class cannot be found.

Step 4: Run Code with Restricted Class Loading

To enforce the same restriction at runtime, use the same -Xbootclasspath/p flag when launching your application:

java -Xbootclasspath/p:./custom-java-base.jar YourJavaFile

Even if code tries to access non-java.lang classes via reflection, the class loader will fail to locate them and throw a ClassNotFoundException.

Key Notes

  • Dependency Checks: java.lang relies on some internal classes (e.g., sun.misc.Unsafe), so we can't delete all non-java.lang directories. Test your setup with simple code (like a basic HelloWorld using only java.lang features) to adjust which internal directories to keep.
  • Modular Compatibility: JDK 10 marks -Xbootclasspath/p as deprecated, but it still works reliably for this use case. If you want a more modular approach, you could create a custom module with only java.lang exported, but this requires resolving complex module dependencies.
  • Strict Enforcement: This setup blocks both explicit imports and reflective access to non-java.lang packages, fully meeting your requirement.

内容的提问来源于stack exchange,提问作者Vijay

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 06:33:10