Go to file
Norman Maurer c735357bf2 Use Files.createTempFile(...) to ensure the file is created with proper permissions
Motivation:

File.createTempFile(String, String)` will create a temporary file in the system temporary directory if the 'java.io.tmpdir'. The permissions on that file utilize the umask. In a majority of cases, this means that the file that java creates has the permissions: `-rw-r--r--`, thus, any other local user on that system can read the contents of that file.
This can be a security concern if any sensitive data is stored in this file.

This was reported by Jonathan Leitschuh <jonathan.leitschuh@gmail.com> as a security problem.

Modifications:

Use Files.createTempFile(...) which will use safe-defaults when running on java 7 and later. If running on java 6 there isnt much we can do, which is fair enough as java 6 shouldnt be considered "safe" anyway.

Result:

Create temporary files with sane permissions by default.
2021-02-08 11:44:05 +01:00
.github Fix test reports name 2021-02-07 19:25:38 +01:00
.mvn Use latest maven release (#9820) 2019-11-27 14:45:28 +01:00
all Update dependency declaration in all pom.xml (#10967) 2021-01-27 10:25:08 +01:00
bom [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
buffer Use Files.createTempFile(...) to ensure the file is created with proper permissions 2021-02-08 11:44:05 +01:00
codec Correctly handle fragmentation in JdkZlibDecoder (#10948) 2021-01-18 14:02:37 +01:00
codec-dns [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
codec-haproxy [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
codec-http Use Files.createTempFile(...) to ensure the file is created with proper permissions 2021-02-08 11:44:05 +01:00
codec-http2 Ignore priority frames for non existing streams and so prevent a NPE (#10943) 2021-01-18 14:11:07 +01:00
codec-memcache [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
codec-mqtt Allow to use int while build MqttMessageIdVariableHeader (#10930) 2021-01-21 14:40:45 +01:00
codec-redis [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
codec-smtp [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
codec-socks [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
codec-stomp [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
codec-xml [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
common Use Files.createTempFile(...) to ensure the file is created with proper permissions 2021-02-08 11:44:05 +01:00
dev-tools [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
docker Ensure we also build dependent modules for deployments (#10936) 2021-01-14 18:08:44 +01:00
example [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
handler Use Files.createTempFile(...) to ensure the file is created with proper permissions 2021-02-08 11:44:05 +01:00
handler-proxy [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
license Enable nohttp check during the build (#10708) 2020-10-23 14:44:18 +02:00
microbench DecodeHexBenchmark is too branch-predictor friendly (#9942) 2021-02-05 15:27:35 +01:00
resolver [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
resolver-dns [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
resolver-dns-native-macos Fix possible SEGV when using native dns resolver on macos (#10971) 2021-01-28 15:15:21 +01:00
tarball [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
testsuite Use Files.createTempFile(...) to ensure the file is created with proper permissions 2021-02-08 11:44:05 +01:00
testsuite-autobahn [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
testsuite-http2 [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
testsuite-native Verify we can load native modules and add job that verifies on aarch64 as well (#10933) 2021-01-14 17:11:19 +01:00
testsuite-native-image [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
testsuite-native-image-client [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
testsuite-native-image-client-runtime-init [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
testsuite-osgi [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
testsuite-shading [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
transport Use Files.createTempFile(...) to ensure the file is created with proper permissions 2021-02-08 11:44:05 +01:00
transport-blockhound-tests Allow blocking calls in UnixResolverDnsServerAddressStreamProvider#parse (#10935) 2021-01-14 18:27:12 +01:00
transport-native-epoll Use Files.createTempFile(...) to ensure the file is created with proper permissions 2021-02-08 11:44:05 +01:00
transport-native-kqueue Ensure native methods for unix-native-common are only registered once. (#10932) 2021-01-14 17:52:04 +01:00
transport-native-unix-common Ensure native methods for unix-native-common are only registered once. (#10932) 2021-01-14 17:52:04 +01:00
transport-native-unix-common-tests Use Files.createTempFile(...) to ensure the file is created with proper permissions 2021-02-08 11:44:05 +01:00
transport-rxtx [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
transport-sctp [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
transport-udt [maven-release-plugin] prepare for next development iteration 2021-01-13 10:28:54 +00:00
.fbprefs Updated Find Bugs configuration 2009-03-04 10:33:09 +00:00
.gitattributes Include mvn wrapper to make setup of development env easier 2018-01-26 08:13:17 +01:00
.gitignore Ignore .shelf/ folder generated by IntelliJ IDEA (#10445) 2020-08-03 07:51:53 +02:00
.lgtm.yml Enables lgtm.com to process this project and create a CodeQL database 2020-01-17 11:05:53 +01:00
CONTRIBUTING.md Change the netty.io homepage scheme(http -> https) (#9344) 2019-07-09 21:09:42 +02:00
LICENSE.txt Enable nohttp check during the build (#10708) 2020-10-23 14:44:18 +02:00
mvnw Enable nohttp check during the build (#10708) 2020-10-23 14:44:18 +02:00
mvnw.cmd Enable nohttp check during the build (#10708) 2020-10-23 14:44:18 +02:00
nohttp-checkstyle-suppressions.xml Ensure Checkstyle suppression for dependency-reduced-pom.xml on Windows (#10899) 2021-01-01 19:30:13 +01:00
nohttp-checkstyle.xml Enable nohttp check during the build (#10708) 2020-10-23 14:44:18 +02:00
NOTICE.txt Fix License type of dnsinfo (#10773) 2020-11-04 10:40:43 +01:00
pom.xml Update to latest os-maven-plugin (#11003) 2021-02-08 08:35:41 +01:00
README.md Fix url in README.md (#10915) 2021-01-11 07:48:58 +01:00
run-example.sh Add DNS client examples for run-example.sh (#10283) 2020-05-14 12:10:32 +02:00
SECURITY.md Added a security policy (#10692) 2020-10-15 20:39:37 +02:00

Build project

Netty Project

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients.

How to build

For the detailed information about building and developing Netty, please visit the developer guide. This page only gives very basic information.

You require the following to build Netty:

Note that this is build-time requirement. JDK 5 (for 3.x) or 6 (for 4.0+ / 4.1+) is enough to run your Netty-based application.

Branches to look

Development of all versions takes place in each branch whose name is identical to <majorVersion>.<minorVersion>. For example, the development of 3.9 and 4.1 resides in the branch '3.9' and the branch '4.1' respectively.

Usage with JDK 9+

Netty can be used in modular JDK9+ applications as a collection of automatic modules. The module names follow the reverse-DNS style, and are derived from subproject names rather than root packages due to historical reasons. They are listed below:

  • io.netty.all
  • io.netty.buffer
  • io.netty.codec
  • io.netty.codec.dns
  • io.netty.codec.haproxy
  • io.netty.codec.http
  • io.netty.codec.http2
  • io.netty.codec.memcache
  • io.netty.codec.mqtt
  • io.netty.codec.redis
  • io.netty.codec.smtp
  • io.netty.codec.socks
  • io.netty.codec.stomp
  • io.netty.codec.xml
  • io.netty.common
  • io.netty.handler
  • io.netty.handler.proxy
  • io.netty.resolver
  • io.netty.resolver.dns
  • io.netty.transport
  • io.netty.transport.epoll (native omitted - reserved keyword in Java)
  • io.netty.transport.kqueue (native omitted - reserved keyword in Java)
  • io.netty.transport.unix.common (native omitted - reserved keyword in Java)
  • io.netty.transport.rxtx
  • io.netty.transport.sctp
  • io.netty.transport.udt

Automatic modules do not provide any means to declare dependencies, so you need to list each used module separately in your module-info file.