From cf08e9985c23ef56a122c0389ccdd9fdb316a37f Mon Sep 17 00:00:00 2001 From: Weijun Wang Date: Thu, 19 Sep 2013 10:41:29 +0800 Subject: [PATCH] 8024659: Clarify JarFile API Reviewed-by: mullan, ahgross --- jdk/src/share/classes/java/util/jar/JarFile.java | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/jdk/src/share/classes/java/util/jar/JarFile.java b/jdk/src/share/classes/java/util/jar/JarFile.java index 2d5d5861dd4..9aac6a10ca3 100644 --- a/jdk/src/share/classes/java/util/jar/JarFile.java +++ b/jdk/src/share/classes/java/util/jar/JarFile.java @@ -53,6 +53,13 @@ import sun.misc.SharedSecrets; * or method in this class will cause a {@link NullPointerException} to be * thrown. * + * If the verify flag is on when opening a signed jar file, the content of the + * file is verified against its signature embedded inside the file. Please note + * that the verification process does not include validating the signer's + * certificate. A caller should inspect the return value of + * {@link JarEntry#getCodeSigners()} to further determine if the signature + * can be trusted. + * * @author David Connelly * @see Manifest * @see java.util.zip.ZipFile