Back to home page

OSCL-LXR

 
 

    


0001 /*
0002  * Licensed to the Apache Software Foundation (ASF) under one or more
0003  * contributor license agreements.  See the NOTICE file distributed with
0004  * this work for additional information regarding copyright ownership.
0005  * The ASF licenses this file to You under the Apache License, Version 2.0
0006  * (the "License"); you may not use this file except in compliance with
0007  * the License.  You may obtain a copy of the License at
0008  *
0009  *    http://www.apache.org/licenses/LICENSE-2.0
0010  *
0011  * Unless required by applicable law or agreed to in writing, software
0012  * distributed under the License is distributed on an "AS IS" BASIS,
0013  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
0014  * See the License for the specific language governing permissions and
0015  * limitations under the License.
0016  */
0017 
0018 package org.apache.spark.launcher;
0019 
0020 import java.io.InputStream;
0021 import java.io.IOException;
0022 import java.io.ObjectInputStream;
0023 import java.io.ObjectStreamClass;
0024 import java.util.Arrays;
0025 import java.util.List;
0026 
0027 /**
0028  * An object input stream that only allows classes used by the launcher protocol to be in the
0029  * serialized stream. See SPARK-20922.
0030  */
0031 class FilteredObjectInputStream extends ObjectInputStream {
0032 
0033   private static final List<String> ALLOWED_PACKAGES = Arrays.asList(
0034     "org.apache.spark.launcher.",
0035     "java.lang.");
0036 
0037   FilteredObjectInputStream(InputStream is) throws IOException {
0038     super(is);
0039   }
0040 
0041   @Override
0042   protected Class<?> resolveClass(ObjectStreamClass desc)
0043       throws IOException, ClassNotFoundException {
0044 
0045     boolean isValid = ALLOWED_PACKAGES.stream().anyMatch(p -> desc.getName().startsWith(p));
0046     if (!isValid) {
0047       throw new IllegalArgumentException(
0048         String.format("Unexpected class in stream: %s", desc.getName()));
0049     }
0050     return super.resolveClass(desc);
0051   }
0052 
0053 }