Go to file
Jeremiah Jordan 26d7b166ba
Verify extension type before initializing reflectively-loaded classes
Cassandra resolves pluggable extensions by class name from configuration, schema, and tooling
inputs. These names were loaded with an initializing Class.forName(name) and type-checked only
afterward, so the named class ran its static initializer before its type was confirmed. After this
change such classes will be loaded without initialization, verified against the expected interface or
base class, and initialized only through normal use after validation.

A shared FBUtilities.classForNameWithoutInitialization helper and typed
instanceOrConstruct/construct overloads apply this to the configurable extension points loaded by
class name: the authentication, authorization, role-management, network and
internode-authenticator backends, the partitioner, audit logger, configuration loader, seed provider,
snitch, abstract types, secondary and custom indexes, compaction strategy, compressor, replication
strategy, SASI analyzers, key and cache providers, query handler, storage and stream hooks, tracing,
the JMX authorization proxy, MBeans, the monotonic clock, nodetool Sjk, triggers, the
sstableloader and stress class options, and diagnostic event classes (loaded without initialization
and checked against DiagnosticEvent, preserving the InvalidClassException contract and the existing
package restriction).

Regression tests confirm that an invalid-type load is rejected without initializing the target
class, and that valid implementations still resolve.

Hadoop client integration and hard-coded JDK and internal class probes are left unchanged.

patch by Jeremiah Jordan; reviewed by Stefan Miklosovic for CASSANDRA-21525
2026-07-20 20:03:45 +02:00
.build Update OWASP dependency-check to 12.1.6, suppress unrelevant CVEs 2025-09-26 16:02:06 +02:00
.circleci Bug in generate.sh removal of jobs 2024-02-26 07:43:40 +01:00
.jenkins Merge branch 'cassandra-3.11' into cassandra-4.0 2023-08-31 22:39:56 +02:00
bin Add option to disable cqlsh history 2026-03-17 23:01:57 +01:00
conf Add option to disable cqlsh history 2026-03-17 23:01:57 +01:00
debian Prepare debian changelog for 4.0.21 2026-07-13 13:12:00 +02:00
doc CASSANDRA-21342: Long-tail xref follow-up (cassandra-4.0 subset) 2026-06-10 10:59:01 -07:00
examples/triggers Fix trigger example on 4.0 2017-08-24 08:34:34 -07:00
ide CASSANDRA-20884 - Move JMX classes to the in-jvm-dtest API project 2025-10-24 13:37:08 -04:00
lib Migrate dependency handling from maven-ant-tasks to resolver-ant-tasks 2021-07-25 11:37:32 -05:00
pylib Add option to disable cqlsh history 2026-03-17 23:01:57 +01:00
redhat Autogenerate toplevel .snyk file from owasp suppressions 2025-03-30 09:27:39 +02:00
src Verify extension type before initializing reflectively-loaded classes 2026-07-20 20:03:45 +02:00
test Verify extension type before initializing reflectively-loaded classes 2026-07-20 20:03:45 +02:00
tools Verify extension type before initializing reflectively-loaded classes 2026-07-20 20:03:45 +02:00
.gitignore Add VS code local folder to gitignore 2025-09-08 00:36:11 +01:00
.snyk Update OWASP dependency-check to 12.1.6, suppress unrelevant CVEs 2025-09-26 16:02:06 +02:00
CASSANDRA-14092.txt Merge branch 'cassandra-2.2' into cassandra-3.0 2018-02-10 14:57:53 -02:00
CHANGES.txt Verify extension type before initializing reflectively-loaded classes 2026-07-20 20:03:45 +02:00
CONTRIBUTING.md Merge branch 'cassandra-3.11' into trunk 2021-04-22 08:32:58 -05:00
LICENSE.txt Merge branch 'cassandra-3.11' into cassandra-4.0 2023-08-31 22:39:56 +02:00
NEWS.txt Switch lz4-java to at.yawk.lz4 version due to CVE 2025-12-18 10:51:26 -08:00
NOTICE.txt Merge branch 'cassandra-3.11' into cassandra-4.0 2023-02-22 10:25:08 -06:00
README.asc Fix links in README 2026-01-20 15:14:12 +01:00
TESTING.md Merge branch 'cassandra-3.11' into trunk 2021-04-19 17:39:10 +02:00
build-shaded-dtest-jar.sh Merge branch 'cassandra-3.11' into trunk 2021-04-19 17:39:10 +02:00
build.properties.default Add snapshot remote repo to build resolution and build.properties.default 2024-09-16 15:49:14 -04:00
build.xml generate-eclipse-files missing simulator/harry and missing src class path 2026-04-17 04:51:54 -07:00
eclipse_compiler.properties Merge branch 'cassandra-3.11' into cassandra-4.0 2023-08-31 22:39:56 +02:00
relocate-dependencies.pom Update maven-shade-plugin to version 3.6.1 2026-02-25 09:13:04 +01:00

README.asc

Apache Cassandra
-----------------

Apache Cassandra is a highly-scalable partitioned row store. Rows are organized into tables with a required primary key.

https://cwiki.apache.org/confluence/display/CASSANDRA2/Partitioners[Partitioning] means that Cassandra can distribute your data across multiple machines in an application-transparent matter. Cassandra will automatically repartition as machines are added and removed from the cluster.

https://cwiki.apache.org/confluence/display/CASSANDRA2/DataModel[Row store] means that like relational databases, Cassandra organizes data by rows and columns. The Cassandra Query Language (CQL) is a close relative of SQL.

For more information, see https://cassandra.apache.org/[the Apache Cassandra web site].

Requirements
------------
. Java >= 1.8 (OpenJDK and Oracle JVMS have been tested)
. Python 3.6+ (for cqlsh; 2.7 works but is deprecated)

Getting started
---------------

This short guide will walk you through getting a basic one node cluster up
and running, and demonstrate some simple reads and writes. For a more-complete guide, please see the Apache Cassandra website's https://cassandra.apache.org/doc/4.0/cassandra/getting_started/index.html[Getting Started Guide].

First, we'll unpack our archive:

  $ tar -zxvf apache-cassandra-$VERSION.tar.gz
  $ cd apache-cassandra-$VERSION

After that we start the server. Running the startup script with the -f argument will cause
Cassandra to remain in the foreground and log to standard out; it can be stopped with ctrl-C.

  $ bin/cassandra -f

Now let's try to read and write some data using the Cassandra Query Language:

  $ bin/cqlsh

The command line client is interactive so if everything worked you should
be sitting in front of a prompt:

----
Connected to Test Cluster at localhost:9160.
[cqlsh 2.2.0 | Cassandra 1.2.0 | CQL spec 3.0.0 | Thrift protocol 19.35.0]
Use HELP for help.
cqlsh>
----

As the banner says, you can use 'help;' or '?' to see what CQL has to
offer, and 'quit;' or 'exit;' when you've had enough fun. But lets try
something slightly more interesting:

----
cqlsh> CREATE KEYSPACE schema1
       WITH replication = { 'class' : 'SimpleStrategy', 'replication_factor' : 1 };
cqlsh> USE schema1;
cqlsh:Schema1> CREATE TABLE users (
                 user_id varchar PRIMARY KEY,
                 first varchar,
                 last varchar,
                 age int
               );
cqlsh:Schema1> INSERT INTO users (user_id, first, last, age)
               VALUES ('jsmith', 'John', 'Smith', 42);
cqlsh:Schema1> SELECT * FROM users;
 user_id | age | first | last
---------+-----+-------+-------
  jsmith |  42 |  john | smith
cqlsh:Schema1>
----

If your session looks similar to what's above, congrats, your single node
cluster is operational!

For more on what commands are supported by CQL, see
https://cassandra.apache.org/doc/4.0/cassandra/cql/[the CQL reference]. A
reasonable way to think of it is as, "SQL minus joins and subqueries, plus collections."

Wondering where to go from here?

  * Join us in #cassandra on the https://s.apache.org/slack-invite[ASF Slack] and ask questions
  * Subscribe to the Users mailing list by sending a mail to
    user-subscribe@cassandra.apache.org
  * Visit the https://cassandra.apache.org/community/[community section] of the Cassandra website for more information on getting involved.
  * Visit the https://cassandra.apache.org/doc/latest/development/index.html[development section] of the Cassandra website for more information on how to contribute.