cassandra/tools
Jeremiah Jordan a94e4c5192 Verify extension type before initializing reflectively-loaded classes
Cassandra resolves pluggable extensions by class name from configuration, schema, and tooling
inputs. These names were loaded with an initializing Class.forName(name) and type-checked only
afterward, so the named class ran its static initializer before its type was confirmed. After this
change such classes will be loaded without initialization, verified against the expected interface or
base class, and initialized only through normal use after validation.

A shared FBUtilities.classForNameWithoutInitialization helper and typed
instanceOrConstruct/construct overloads apply this to the configurable extension points loaded by
class name: the guardrail value generator and validator, disk-error handler,
Accord agent, TCM extension values, the authentication backends and mutual-TLS validators, seed
provider, snitch and its location providers, abstract types, secondary and custom indexes, compaction
strategy, compressor, replication strategy (including its metadata serializers), SASI analyzers, key
and cache providers, query handler, storage and stream hooks, tracing, the JMX authorization proxy,
MBeans, clocks, nodetool Sjk, triggers, the memtable factory contract, the guardrails config provider,
the auto-repair token-range splitter, crypto provider, SSL context factory, the sstableloader and
stress class options, and diagnostic event classes. ParameterizedClass.newInstance also takes an expected type and loads without initialization.

Regression tests confirm that an invalid-type load is rejected without initializing the target
class, and that valid implementations still resolve.

Hard-coded JDK and internal class probes are left unchanged.

patch by Jeremiah Jordan; reviewed by <reviewer> for CASSANDRA-21525
2026-07-15 19:48:59 -05:00
..
bin Offline tool for working with cluster metadata dump files 2026-05-15 14:41:06 +01:00
fqltool Add JDK21 support 2026-02-02 12:39:05 -05:00
sstableloader Verify extension type before initializing reflectively-loaded classes 2026-07-15 19:48:59 -05:00
stress Verify extension type before initializing reflectively-loaded classes 2026-07-15 19:48:59 -05:00
cqlstress-counter-example.yaml Add sequence distribution type to cassandra stress: fix problem with setSeed() 2016-10-24 11:09:04 +08:00
cqlstress-example.yaml Remove deprecated properties in CompressionParams 2023-09-29 15:19:12 +02:00
cqlstress-insanity-example.yaml Add sequence distribution type to cassandra stress: fix problem with setSeed() 2016-10-24 11:09:04 +08:00
cqlstress-lwt-example.yaml Add stress profile yaml with LWT 2017-08-31 06:42:41 -07:00