ramanathan1504 commented on PR #4270: URL: https://github.com/apache/logging-log4j2/pull/4270#issuecomment-5573947393
I checked the Java 9+ branch with a packaged `log4j-api` jar. `Config.createFilter` returns UNDECIDED for names it does not list, so the default allowlist still runs after it. `java.io.File` is rejected with no extras and allowed when passed as one. Arrays of it too. Nothing tests it though. On `2.x` today `SerialUtil.getObjectInputStream` returns a plain `ObjectInputStream` on JDK 17 and reads a `java.io.File` back fine. One `assertThrows(IOException.class, ...)` in `log4j-api-test` fails before this change and passes after, on Java 8 and Java 9+ both. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
