Menu ▾ ▴

#665 Proguard should not introspect class files contained in META-INF

v5.3.3
closed-fixed
None
High
2019-12-05
2017-09-12
William
No

Proguard attempts to introspect and process classes from the META-INF folder which is an invalid location for class files. It should not attempt to process as classes any files found in META-INF.

While clients could configure Proguard to ignore the META-INF folder, this would mean that the contents of the META-INF folder would be omitted from the obfuscated jar. Contents should be included in the output (unless specifically excluded), but any class files should be exlucded from Proguard obfuscation etc.

Note that even if this didn't fail becayuse of the class file version, you wouldn't want Proguard to process META-INF/versions/9/org/apache/logging/log4j/util/ProcessIdUtil.class, but you would want that entry to appear in the obfuscated output jar.

[INFO] Proguarding output
[INFO] java.io.IOException: Can't read [E:\maven-local-repository\org\apache\logging\log4j\log4j-api\2.9.0\log4j-api-2.9.0.jar(;;;;;;!META-INF/maven/**,!META-INF/MANIFEST.MF)] (Can't process class [META-INF/versions/9/org/apache/logging/log4j/util/ProcessIdUtil.class] (Unsupported class version number [53.0] (maximum 52.0, Java 1.8)))
[INFO]  at proguard.InputReader.readInput(InputReader.java:188)
[INFO]  at proguard.InputReader.readInput(InputReader.java:158)
[INFO]  at proguard.InputReader.readInput(InputReader.java:136)
[INFO]  at proguard.InputReader.execute(InputReader.java:66)
[INFO]  at proguard.ProGuard.readInput(ProGuard.java:218)
[INFO]  at proguard.ProGuard.execute(ProGuard.java:82)
[INFO]  at proguard.ProGuard.main(ProGuard.java:538)
[INFO] Caused by: java.io.IOException: Can't process class [META-INF/versions/9/org/apache/logging/log4j/util/ProcessIdUtil.class] (Unsupported class version number [53.0] (maximum 52.0, Java 1.8))
[INFO]  at proguard.io.ClassReader.read(ClassReader.java:112)
[INFO]  at proguard.io.FilteredDataEntryReader.read(FilteredDataEntryReader.java:87)
[INFO]  at proguard.io.FilteredDataEntryReader.read(FilteredDataEntryReader.java:87)
[INFO]  at proguard.io.FilteredDataEntryReader.read(FilteredDataEntryReader.java:87)
[INFO]  at proguard.io.JarReader.read(JarReader.java:65)
[INFO]  at proguard.io.DirectoryPump.readFiles(DirectoryPump.java:65)
[INFO]  at proguard.io.DirectoryPump.pumpDataEntries(DirectoryPump.java:53)
[INFO]  at proguard.InputReader.readInput(InputReader.java:184)
[INFO]  ... 6 more
[INFO] Caused by: java.lang.UnsupportedOperationException: Unsupported class version number [53.0] (maximum 52.0, Java 1.8)
[INFO]  at proguard.classfile.util.ClassUtil.checkVersionNumbers(ClassUtil.java:145)
[INFO]  at proguard.classfile.io.ProgramClassReader.visitProgramClass(ProgramClassReader.java:95)
[INFO]  at proguard.classfile.ProgramClass.accept(ProgramClass.java:358)
[INFO]  at proguard.io.ClassReader.read(ClassReader.java:91)
[INFO]  ... 13 more

Discussion

  • William

    William - 2017-09-12

    This was raised out of this ticket https://issues.apache.org/jira/browse/LOG4J2-2041

     
  • Eric Lafortune

    Eric Lafortune - 2017-09-12

    Thanks for the report. ProGuard 6.0 will support Java 9 class files, although the current implementation doesn't support multiple class file versions (the prefix META-INF/versions). ProGuard currently reads class files in such unexpected locations, but doesn't write them to the output.

    As a workaround, you can filter out these class files:

    -injars log4j-api-2.9.0.jar(!META-INF/versions/**.class)
    

    This is assuming that you specify the -injars explicitly in your configuration file, not through some automatic build process.

    Alternatively, if the classes don't use any of the new Java 9 features, you could update the accepted class version in src/proguard/classfile/ClassConstants.java and recompile ProGuard. It doesn't change the issue with META-INF/versions though.

     
    • Narendran Jothiram

      Thanks Eric. Filter workaround did work! In our case apache log4j2 libs are used as libraryjars.

      -libraryjars "log4j-api-2.9.0.jar"(!META-INF/versions/9/**.class)

      As per the release page of apache log4j2 2.9.0, to build and run Java 7 is minimum required. Also, since it is multi release jar file it will ignore jdk 9 classes in META-INF when jdk 8 or 7 is used.

       
      • Boris Petrov

        Boris Petrov - 2017-09-14

        Yes, the workaround worked for me also. We are using it via some build system but with some Gradle magic and hacks, I managed to make it work. :)

        Waiting for ProGuard 6 for the "real" fix as this problem will become ubiquitous in the next few weeks after Java 9 comes out!

         
  • Eric Lafortune

    Eric Lafortune - 2017-09-12
    • status: open --> open-accepted
    • assigned_to: Eric Lafortune
     
  • William

    William - 2017-09-13

    Thanks Eric. Is the plan for Proguard 6.0 to support multiple class file versions?

     

    Last edit: William 2017-09-13
  • Eric Lafortune

    Eric Lafortune - 2017-09-13

    ProGuard 6.0 probably won't support multiple class versions (yet). ProGuard's internal data structures represent a single consistent application on which the algorithms operate. This mechanism allows to input interweaved but potentially completely different versions of the code. I'll think about workarounds.

     
  • T. Neidhart

    T. Neidhart - 2019-12-05
    • status: open-accepted --> closed-fixed
    • Priority: 5 --> High
     
  • T. Neidhart

    T. Neidhart - 2019-12-05

    With the next relese 6.2.1 a default filter for versioned class files located in META-INF/versions is added to prevent such cases.

     

Log in to post a comment.