Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

ManifestVersionReader leaks a ZipFile Inflater per JAR (openStream never closed)

Đã đóng
#6,120 2 bình luận 0 reaction 1 người được giao Xem trên GitHub

@0xadam-brown đang làm issue này rồi.

Từ ngày 16/9/2026.

Đánh giá

Issue này chưa được đánh giá.

Mô tả

Platform: Java Type: Bug

Description

ManifestVersionReader.readManifestFiles() enumerates every META-INF/MANIFEST.MF on the classpath and passes URL.openStream() into new Manifest(InputStream) without closing the stream.

java.util.jar.Manifest(InputStream) reads the stream and does not close it. For jar: URLs that stream is a ZipFileInflaterInputStream. Closing it is what calls ZipFile$CleanableResource.releaseInflater(). If it is never closed, each JAR leaves a live java.util.zip.Inflater (~64 KiB zlib window).

This still matches main and 8.41.0 / 8.52.0.

Call site

final Enumeration<URL> resources =
    ClassLoader.getSystemClassLoader().getResources("META-INF/MANIFEST.MF");
while (resources.hasMoreElements()) {
  try {
    final Manifest manifest = new Manifest(resources.nextElement().openStream());
    // ...
  } catch (Exception e) {
    // ignore
  }
}

Triggered from ManifestVersionDetector.checkForMixedVersions()InitUtil.shouldInit()Sentry.init().

Observed

Compose Desktop / packaged JVM app with ~80 JARs on the classpath (sentry-java 8.41.0):

  • GC.class_histogram: 168 live java.util.zip.Inflater
  • async-profiler event=java.util.zip.Inflater.<init> from process start: 79 / 174 constructors (45%) are
java.util.zip.Inflater.<init>
java.util.zip.ZipFile$CleanableResource.getInflater
java.util.zip.ZipFile$ZipFileInflaterInputStream.<init>
java.util.zip.ZipFile.getInputStream
java.util.jar.JarFile.getBytes
java.util.jar.JarFile.checkForSpecialAttributes
java.util.jar.JarFile.isMultiRelease
java.util.jar.JarFile.getEntry
sun.net.www.protocol.jar.URLJarFile.getEntry
sun.net.www.protocol.jar.JarURLConnection.connect
sun.net.www.protocol.jar.JarURLConnection.getInputStream
java.net.URL.openStream
io.sentry.internal.ManifestVersionReader.readManifestFiles
io.sentry.ManifestVersionDetector.checkForMixedVersions
io.sentry.util.InitUtil.shouldInit
io.sentry.Sentry.init

Suggested fix

try (InputStream is = resources.nextElement().openStream()) {
  final Manifest manifest = new Manifest(is);
  // existing attribute handling
} catch (Exception e) {
  // ignore
}

Manifest does not take ownership of the stream, so try-with-resources is required even on the success path.

Ngôn ngữ chính
Kotlin
Star
1.4k
Fork
478
Merge trung bình
2 ngày 20 giờ
Pull request đã merge (30 ngày)
71

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của getsentry/sentry-java

Tất cả issue của getsentry/sentry-java

Issue tương tự

Thêm issue về Kotlin

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.