Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

ManifestVersionReader leaks a ZipFile Inflater per JAR (openStream never closed)

已关闭
#6,120 2 条评论 0 个 reaction 已指派 1 人 在 GitHub 查看

@0xadam-brown 已经在做这个了。

开始于 2026年9月16日。

评估

这个 Issue 还没有评估数据。

描述

Platform: Java Type: Bug

Description

ManifestVersionReader.readManifestFiles() enumerates every META-INF/MANIFEST.MF on the classpath and passes URL.openStream() into new Manifest(InputStream) without closing the stream.

java.util.jar.Manifest(InputStream) reads the stream and does not close it. For jar: URLs that stream is a ZipFileInflaterInputStream. Closing it is what calls ZipFile$CleanableResource.releaseInflater(). If it is never closed, each JAR leaves a live java.util.zip.Inflater (~64 KiB zlib window).

This still matches main and 8.41.0 / 8.52.0.

Call site

final Enumeration<URL> resources =
    ClassLoader.getSystemClassLoader().getResources("META-INF/MANIFEST.MF");
while (resources.hasMoreElements()) {
  try {
    final Manifest manifest = new Manifest(resources.nextElement().openStream());
    // ...
  } catch (Exception e) {
    // ignore
  }
}

Triggered from ManifestVersionDetector.checkForMixedVersions()InitUtil.shouldInit()Sentry.init().

Observed

Compose Desktop / packaged JVM app with ~80 JARs on the classpath (sentry-java 8.41.0):

  • GC.class_histogram: 168 live java.util.zip.Inflater
  • async-profiler event=java.util.zip.Inflater.<init> from process start: 79 / 174 constructors (45%) are
java.util.zip.Inflater.<init>
java.util.zip.ZipFile$CleanableResource.getInflater
java.util.zip.ZipFile$ZipFileInflaterInputStream.<init>
java.util.zip.ZipFile.getInputStream
java.util.jar.JarFile.getBytes
java.util.jar.JarFile.checkForSpecialAttributes
java.util.jar.JarFile.isMultiRelease
java.util.jar.JarFile.getEntry
sun.net.www.protocol.jar.URLJarFile.getEntry
sun.net.www.protocol.jar.JarURLConnection.connect
sun.net.www.protocol.jar.JarURLConnection.getInputStream
java.net.URL.openStream
io.sentry.internal.ManifestVersionReader.readManifestFiles
io.sentry.ManifestVersionDetector.checkForMixedVersions
io.sentry.util.InitUtil.shouldInit
io.sentry.Sentry.init

Suggested fix

try (InputStream is = resources.nextElement().openStream()) {
  final Manifest manifest = new Manifest(is);
  // existing attribute handling
} catch (Exception e) {
  // ignore
}

Manifest does not take ownership of the stream, so try-with-resources is required even on the success path.

主要语言
Kotlin
星标
1.4k
派生
478
平均合并
2 天 20 小时
30 天内合并 PR
71

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

getsentry/sentry-java 的其他 Issue

查看 getsentry/sentry-java 的全部 Issue

相似的 Issue

更多 Kotlin Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。