On Mon, 28 Sep 2026 13:51:27 GMT, Kieran Farrell <[email protected]> wrote:

>> This patch adds a new jcmd diagnostic command, `VM.show_settings`, to make 
>> the existing -`XshowSettings` output available from a running VM. The 
>> command accepts the same sections as`XshowSettings` (all, vm, properties, 
>> locale, security, system, security:all, security:properties, 
>> security:providers, security:tls). 
>> 
>> HotSpot registers the new diagnostic command, validates the requested 
>> section, then calls into `sun.launcher.LauncherHelper` to reuse the existing 
>> show settings formatting and return the result as bytes for the jcmd stream. 
>> The VM settings path also passes hotspots `InitialHeapSize`, `MaxHeapSize`, 
>> and Java thread stack size into the Java helper. A new jcmd test covers VM, 
>> properties, security TLS, and invalid-input output.
>> 
>> ---------
>> - [x] I confirm that I make this contribution in accordance with the 
>> [OpenJDK Interim AI Policy](https://openjdk.org/legal/ai).
>
> Kieran Farrell has updated the pull request incrementally with one additional 
> commit since the last revision:
> 
>   remove code

The default action here is to print "all" settings. This differs from the 
launch argument where a compact summary of JDK settings is printed. Could we 
consider defaulting to this compact (no arg) format ?

I had assumed that the argument format would be similar to that used for 
launcher.  Have you considered letting the following scenario work ?


jcmd 8867  VM.show_settings:vm
8867:
java.lang.IllegalArgumentException: Unknown diagnostic command


Regarding the help output:


8867:
VM.show_settings
Print effective VM configuration and settings queried at command execution, 
e.g. 'VM.show_settings all'. See 'java -X' for supported -XshowSettings 
sections.

Impact: Low

Syntax : VM.show_settings  [<section>]

Arguments:
        section : [optional] Optional -XshowSettings section. Settings are 
queried when the command runs; see 'java -X' for supported -XshowSettings 
sections. (STRING, all)

Would "current VM configuration" be better than "effective VM configuration" ? 
likewise, maybe "Current settings are printed when the command runs" in place 
of "Settings are queried.."

In the Arguments section, there are only 3-4 options, maybe we should print 
them ?

***

For the security info, I see "Security provider static configuration: (in order 
of preference)" printed. I don't think this is accurate. You're printing 
current provider configuration which could also contain providers registered 
dynamically.

A nice feature but maybe one for a follow on (?)  would be to highlight 
properties that have changed since launch time. You have access to both sets. 
This would be especially useful for audits where modifying important security 
properties could be detected.

-------------

PR Comment: https://git.openjdk.org/jdk/pull/31742#issuecomment-5926605463

Reply via email to