This is the mail archive of the java@gcc.gnu.org mailing list for the Java project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

Re: JSP Servlet container / WEB server


Hi Andrew,

> > I know you said to continue the discussion elsewhere, but I've got one
> > gcj-related question which may or may not be sacrilegious for this list.
> > Doesn't running the webserver and compiled JSPs as native code
> > potentially bypass all of Java's purportedly wonderful security features?
> > I don't recall if I'm remembering this correctly, but isn't gcj somewhat
> > lacking in things like class verification and maybe even security checks?
>
>This is true.  The gcj libraries don't implement the Java security
>sandbox.

Do they not implement this at all? Maybe not a true applet sandbox, but I
see lots of SecurityManager calls in the net code for example. I haven't
followed these to see if they lead anywhere, though.

> > I know there are a million ways to secure a webserver, but I kind of
> > like the idea of a real JVM being sort of a safety net.
>
>It's not the jvm that provides this, but the libraries -- there's no
>reason fully compiled Java can't be just as secure as a conventional
>VM.

You're right. Java code is JITed a lot anyway. I guess I have prejudices that
I have to discard even though I work with gcj myself!

-- Mohan
http://www.thisiscool.com/
http://www.animalsong.org/





Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]