Go to file
Jeremiah Jordan a94e4c5192 Verify extension type before initializing reflectively-loaded classes
Cassandra resolves pluggable extensions by class name from configuration, schema, and tooling
inputs. These names were loaded with an initializing Class.forName(name) and type-checked only
afterward, so the named class ran its static initializer before its type was confirmed. After this
change such classes will be loaded without initialization, verified against the expected interface or
base class, and initialized only through normal use after validation.

A shared FBUtilities.classForNameWithoutInitialization helper and typed
instanceOrConstruct/construct overloads apply this to the configurable extension points loaded by
class name: the guardrail value generator and validator, disk-error handler,
Accord agent, TCM extension values, the authentication backends and mutual-TLS validators, seed
provider, snitch and its location providers, abstract types, secondary and custom indexes, compaction
strategy, compressor, replication strategy (including its metadata serializers), SASI analyzers, key
and cache providers, query handler, storage and stream hooks, tracing, the JMX authorization proxy,
MBeans, clocks, nodetool Sjk, triggers, the memtable factory contract, the guardrails config provider,
the auto-repair token-range splitter, crypto provider, SSL context factory, the sstableloader and
stress class options, and diagnostic event classes. ParameterizedClass.newInstance also takes an expected type and loads without initialization.

Regression tests confirm that an invalid-type load is rejected without initializing the target
class, and that valid implementations still resolve.

Hard-coded JDK and internal class probes are left unchanged.

patch by Jeremiah Jordan; reviewed by <reviewer> for CASSANDRA-21525
2026-07-15 19:48:59 -05:00
.build Merge branch 'cassandra-6.0' into trunk 2026-07-10 11:16:49 +02:00
.circleci Remove 4.0 upgrade paths and related 4.0 tests 2026-06-02 23:54:38 +02:00
.claude/skills Add suite of skills for AI 2026-06-09 17:31:47 +02:00
.github Add a github action that runs .build/docker/check-code.sh 2025-10-13 12:34:51 +02:00
.idea/codeStyles Add configuration for sorted imports in source files 2025-12-30 22:34:12 +01:00
.jenkins Merge branch 'cassandra-5.0' into cassandra-6.0 2026-07-03 11:08:42 +02:00
bin Merge branch 'cassandra-5.0' into cassandra-6.0 2026-07-03 11:08:42 +02:00
ci Implementation of Transactional Cluster Metadata as described in CEP-21 2023-11-24 10:26:08 +00:00
conf Merge branch 'cassandra-6.0' into trunk 2026-06-24 15:08:41 +01:00
debian Prepare debian changelog for 6.0-alpha2 2026-07-10 16:53:07 +02:00
doc Implementation of CEP-49: Hardware-accelerated compression 2026-06-23 11:37:53 +02:00
examples Support custom StartupCheck implementations via SPI 2026-02-02 10:12:37 +11:00
ide Depend only on platform-specific Zstd JNI native libraries 2026-07-10 11:15:25 +02:00
lib Accord: PreLoadContext must properly and consistently support ranges 2025-04-17 11:59:50 -07:00
modules Fix publishing to ASF Nexus of Accord artefacts when release staging 2026-07-01 19:25:15 +02:00
pylib Merge branch 'cassandra-5.0' into cassandra-6.0 2026-07-03 11:08:42 +02:00
redhat ninja: replace addtocmstool with cmsofflinetool in rpm/deb packages 2026-05-18 14:04:33 +01:00
src Verify extension type before initializing reflectively-loaded classes 2026-07-15 19:48:59 -05:00
test Verify extension type before initializing reflectively-loaded classes 2026-07-15 19:48:59 -05:00
tools Verify extension type before initializing reflectively-loaded classes 2026-07-15 19:48:59 -05:00
.asf.yaml Set up default protection ruleset for default and release branches 2026-05-25 11:11:43 +02:00
.git-blame-ignore-revs ninja: add a commit with the import order to ignore revs 2025-12-30 22:39:50 +01:00
.gitignore Merge branch 'cassandra-5.0' into trunk 2026-04-16 10:53:26 -05:00
.gitmodules Split AsyncChain and AsyncResult; normalise AsyncResult with C* Future 2025-09-18 12:31:13 +01:00
.snyk Merge branch 'cassandra-5.0' into trunk 2026-02-17 11:46:44 +11:00
AGENTS.md Add security-model discoverability (AGENTS.md -> SECURITY.md -> security model) 2026-06-16 10:21:37 +02:00
CASSANDRA-14092.txt Correct typo in CASSANDRA-14092.txt 2026-04-10 15:05:47 -07:00
CHANGES.txt Merge branch 'cassandra-6.0' into trunk 2026-07-10 11:16:49 +02:00
CLAUDE.md Add AGENTS.md and CLAUDE.md 2026-05-14 12:49:47 +02:00
CONTRIBUTING.md Improving CONTRIBUTING.md for new contributors 2025-09-01 23:54:00 +08:00
LICENSE.txt Merge branch 'cassandra-3.11' into cassandra-4.0 2023-08-31 22:39:56 +02:00
NEWS.txt Implementation of CEP-49: Hardware-accelerated compression 2026-06-23 11:37:53 +02:00
NOTICE.txt Merge branch 'cassandra-3.11' into cassandra-4.0 2023-02-22 10:25:08 -06:00
README.asc Merge branch 'cassandra-6.0' into trunk 2026-04-21 12:51:13 +02:00
SECURITY.md Add security-model discoverability (AGENTS.md -> SECURITY.md -> security model) 2026-06-16 10:21:37 +02:00
TESTING.md Improve and clean up documentation and fix typos 2023-01-26 14:42:47 +01:00
build-shaded-dtest-jar.sh Merge branch 'cassandra-3.11' into trunk 2021-04-19 17:39:10 +02:00
build.properties.default Merge branch 'cassandra-5.0' into trunk 2024-09-16 15:53:25 -04:00
build.xml Merge branch 'cassandra-6.0' into trunk 2026-07-01 19:29:25 +02:00
relocate-dependencies.pom Update maven-shade-plugin to version 3.6.1 2026-02-25 09:13:04 +01:00

README.asc

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

image:https://img.shields.io/badge/License-Apache%202.0-blue.svg[License, link=https://github.com/apache/cassandra/blob/trunk/LICENSE.txt]
image:https://ci-cassandra.apache.org/job/Cassandra-trunk/badge/icon[Build Status, link=https://ci-cassandra.apache.org/job/Cassandra-trunk/]      
image:https://img.shields.io/badge/Official-Downloads-brightgreen[Official Downloads, link=https://cassandra.apache.org/$$_$$/download.html]
image:https://img.shields.io/docker/pulls/$$_$$/cassandra[Docker Pulls, link=https://hub.docker.com/r/$$_$$/cassandra]      
image:https://img.shields.io/badge/Slack-4A154B?style=flat&logo=slack&logoColor=white[Slack, link=https://infra.apache.org/slack.html]
image:https://img.shields.io/badge/Bluesky-0285FF?logo=bluesky&logoColor=fff&color=0285FF[Bluesky, link=https://bsky.app/profile/cassandra.apache.org]
image:https://img.shields.io/badge/-LinkedIn-blue?style=flat-square&logo=Linkedin&logoColor=white&link=https://www.linkedin.com/company/apache-cassandra/[LinkedIn, link=https://www.linkedin.com/company/apache-cassandra/]
image:https://img.shields.io/badge/YouTube-FF0000?style=flat&logo=youtube&logoColor=white[Youtube, link=https://www.youtube.com/c/PlanetCassandra]


Apache Cassandra
-----------------

Apache Cassandra is a highly-scalable partitioned row store. Rows are organized into tables with a required primary key.

https://cwiki.apache.org/confluence/display/CASSANDRA2/Partitioners[Partitioning] means that Cassandra can distribute your data across multiple machines in an application-transparent matter. Cassandra will automatically repartition as machines are added and removed from the cluster.

https://cwiki.apache.org/confluence/display/CASSANDRA2/DataModel[Row store] means that like relational databases, Cassandra organizes data by rows and columns. The Cassandra Query Language (CQL) is a close relative of SQL.

For more information, see https://cassandra.apache.org/[the Apache Cassandra web site].

Issues should be reported on https://issues.apache.org/jira/projects/CASSANDRA/issues/[The Cassandra Jira].

Requirements
------------
- Java: see supported versions in build.xml (search for property "java.supported").
- Python: for `cqlsh`, see `bin/cqlsh` (search for function "is_supported_version").


Getting started
---------------

This short guide will walk you through getting a basic one node cluster up
and running, and demonstrate some simple reads and writes. For a more-complete guide, please see the Apache Cassandra website's https://cassandra.apache.org/doc/trunk/cassandra/getting-started/index.html[Getting Started Guide].

First, we'll unpack our archive:

  $ tar -zxvf apache-cassandra-$VERSION.tar.gz
  $ cd apache-cassandra-$VERSION

After that we start the server. Running the startup script with the -f argument will cause
Cassandra to remain in the foreground and log to standard out; it can be stopped with ctrl-C.

  $ bin/cassandra -f

Now let's try to read and write some data using the Cassandra Query Language:

  $ bin/cqlsh

The command line client is interactive so if everything worked you should
be sitting in front of a prompt:

----
Connected to Test Cluster at localhost:9160.
[cqlsh 6.3.0 | Cassandra 7.0-SNAPSHOT | CQL spec 3.4.8 | Native protocol v5]
Use HELP for help.
cqlsh>
----

As the banner says, you can use 'help;' or '?' to see what CQL has to
offer, and 'quit;' or 'exit;' when you've had enough fun. But lets try
something slightly more interesting:

----
cqlsh> CREATE KEYSPACE schema1
       WITH replication = { 'class' : 'SimpleStrategy', 'replication_factor' : 1 };
cqlsh> USE schema1;
cqlsh:Schema1> CREATE TABLE users (
                 user_id varchar PRIMARY KEY,
                 first varchar,
                 last varchar,
                 age int
               );
cqlsh:Schema1> INSERT INTO users (user_id, first, last, age)
               VALUES ('jsmith', 'John', 'Smith', 42);
cqlsh:Schema1> SELECT * FROM users;
 user_id | age | first | last
---------+-----+-------+-------
  jsmith |  42 |  john | smith
cqlsh:Schema1>
----

If your session looks similar to what's above, congrats, your single node
cluster is operational!

For more on what commands are supported by CQL, see
https://cassandra.apache.org/doc/trunk/cassandra/developing/cql/index.html[the CQL reference]. A
reasonable way to think of it is as, "SQL minus joins and subqueries, plus collections."

Wondering where to go from here?

  * Join us in #cassandra on the https://s.apache.org/slack-invite[ASF Slack] and ask questions.
  * Subscribe to the Users mailing list by sending a mail to
    user-subscribe@cassandra.apache.org.
  * Subscribe to the Developer mailing list by sending a mail to
    dev-subscribe@cassandra.apache.org.
  * Visit the https://cassandra.apache.org/community/[community section] of the Cassandra website for more information on getting involved.
  * Visit the https://cassandra.apache.org/doc/latest/development/index.html[development section] of the Cassandra website for more information on how to contribute.