| Contents |Prev |Next |Index | The Java Virtual Machine Specification |
CHAPTER 4
File FormatThis chapter describes the Java virtual machineclass file format. Eachclass file contains the definition of a single class or interface. Although a class or interface need not have an external representation literally contained in a file (for instance, because the class is generated by a class loader), we will colloquially refer to any valid representation of a class or interface as being in theclass file format.
Aclass file consists of a stream of 8-bit bytes. All 16-bit, 32-bit, and 64-bit quantities are constructed by reading in two, four, and eight consecutive 8-bit bytes, respectively. Multibyte data items are always stored in big-endian order, where the high bytes come first. In the Java and Java 2 platforms, this format is supported by interfacesjava.io.DataInput andjava.io.DataOutput and classes such asjava.io.DataInputStream andjava.io.DataOutputStream.
This chapter defines its own set of data types representingclass file data: The typesu1,u2, andu4 represent an unsigned one-, two-, or four-byte quantity, respectively. In the Java and Java 2 platforms, these types may be read by methods such asreadUnsignedByte,readUnsignedShort, andreadInt of the interfacejava.io.DataInput.
This chapter presents theclass file format using pseudostructures written in a C-like structure notation. To avoid confusion with the fields of classes and class instances, etc., the contents of the structures describing theclass file format are referred to asitems. Successive items are stored in theclass file sequentially, without padding or alignment.
Tables, consisting of zero or more variable-sized items, are used in severalclass file structures. Although we use C-like array syntax to refer to table items, the fact that tables are streams of varying-sized structures means that it is not possible to translate a table index directly to a byte offset into the table.
Where we refer to a data structure as an array, it consists of zero or more contiguous fixed-sized items and can be indexed like an array.
ClassFile Structureclass file consists of a singleClassFile structure:The items in the
ClassFile {u4 magic;u2 minor_version;u2 major_version;u2 constant_pool_count;cp_info constant_pool[constant_pool_count-1];u2 access_flags;u2 this_class;u2 super_class;u2 interfaces_count;u2 interfaces[interfaces_count];u2 fields_count;field_info fields[fields_count];u2 methods_count;method_info methods[methods_count];u2 attributes_count;attribute_info attributes[attributes_count];}
ClassFile structure are as follows:magicmagic item supplies the magic number identifying theclass file format; it has the value0xCAFEBABE.minor_version,major_versionminor_version andmajor_version items are the minor and major version numbers of thisclass file.Together, a major and a minor version number determine the version of theclass file format. If aclass file has major version number M and minor version number m, we denote the version of itsclass file format as M.m. Thus,class file format versions may be ordered lexicographically, for example, 1.5< 2.0< 2.1.A Java virtual machine implementation can support aclass file format of version v if and only if v lies in some contiguous range Mi.0
v
Mj.m. Only Sun can specify what range of versions a Java virtual machine implementation conforming to a certain release level of the Java platform may support.1
constant_pool_countconstant_pool_count item is equal to the number of entries in theconstant_pool table plus one. Aconstant_pool index is considered valid if it is greater than zero and less thanconstant_pool_count, with the exception for constants of typelong anddouble noted in§4.4.5.constant_pool[]constant_pool is a table of structures(§4.4) representing various string constants, class and interface names, field names, and other constants that are referred to within theClassFile structure and its substructures. The format of eachconstant_pool table entry is indicated by its first "tag" byte.Theconstant_pool table is indexed from1 toconstant_pool_count-1.
access_flagsaccess_flags item is a mask of flags used to denote access permissions to and properties of this class or interface. The interpretation of each flag, when set, is as shown inTable 4.1.An interface is distinguished by itsACC_INTERFACE flag being set. If itsACC_INTERFACE flag is not set, thisclass file defines a class, not an interface.
If theACC_INTERFACE flag of thisclass file is set, itsACC_ABSTRACT flag must also be set(§2.13.1) and itsACC_PUBLIC flag may be set. Such aclass file may not have any of the other flags inTable 4.1 set.
If theACC_INTERFACE flag of thisclass file is not set, it may have any of the other flags inTable 4.1 set. However, such aclass file cannot have both itsACC_FINAL andACC_ABSTRACT flags set(§2.8.2).
The setting of theACC_SUPER flag indicates which of two alternative semantics for itsinvokespecial instruction the Java virtual machine is to express; theACC_SUPER flag exists for backward compatibility for code compiled by Sun's older compilers for the Java programming language. All new implementations of the Java virtual machine should implement the semantics forinvokespecial documented in this specification. All new compilers to the instruction set of the Java virtual machine should set theACC_SUPER flag. Sun's older compilers generatedClassFile flags withACC_SUPER unset. Sun's older Java virtual machine implementations ignore the flag if it is set.
All bits of theaccess_flags item not assigned inTable 4.1 are reserved for future use. They should be set to zero in generatedclass files and should be ignored by Java virtual machine implementations.
this_classthis_class item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Class_info(§4.4.1) structure representing the class or interface defined by thisclass file.super_classsuper_class item either must be zero or must be a valid index into theconstant_pool table. If the value of thesuper_class item is nonzero, theconstant_pool entry at that index must be aCONSTANT_Class_info(§4.4.1) structure representing the direct superclass of the class defined by thisclass file. Neither the direct superclass nor any of its superclasses may be afinal class.If the value of thesuper_class item is zero, then thisclass file must represent the classObject, the only class or interface without a direct superclass.
For an interface, the value of thesuper_class item must always be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Class_info structure representing the classObject.
interfaces_countinterfaces_count item gives the number of direct superinterfaces of this class or interface type.interfaces[]interfaces array must be a valid index into theconstant_pool table. Theconstant_pool entry at each value ofinterfaces[i], where0
i<interfaces_count, must be aCONSTANT_Class_info(§4.4.1) structure representing an interface that is a direct superinterface of this class or interface type, in the left-to-right order given in the source for the type.fields_count item gives the number offield_info structures in thefields table. Thefield_info(§4.5) structures represent all fields, both class variables and instance variables, declared by this class or interface type.fields[]fields table must be afield_info(§4.5) structure giving a complete description of a field in this class or interface. Thefields table includes only those fields that are declared by this class or interface. It does not include items representing fields that are inherited from superclasses or superinterfaces.methods_countmethods_count item gives the number ofmethod_info structures in themethods table.methods[]methods table must be amethod_info(§4.6) structure giving a complete description of a method in this class or interface. If the method is notnative orabstract, the Java virtual machine instructions implementing the method are also supplied.Themethod_info structures represent all methods declared by this class or interface type, including instance methods, class (static) methods, instance initialization methods(§3.9), and any class or interface initialization method(§3.9). Themethods table does not include items representing methods that are inherited from superclasses or superinterfaces.
attributes_countattributes_count item gives the number of attributes(§4.7) in theattributes table of this class.attributes[]attributes table must be an attribute structure(§4.7).The only attributes defined by this specification as appearing in theattributes table of aClassFile structure are theSourceFile attribute(§4.7.7) and theDeprecated(§4.7.10) attribute.
A Java virtual machine implementation is required to silently ignore any or all attributes in theattributes table of aClassFile structure that it does not recognize. Attributes not defined in this specification are not allowed to affect the semantics of theclass file, but only to provide additional descriptive information(§4.7.1).
class file structures are always representedin a fully qualified form(§2.7.5). Such names are always represented asCONSTANT_Utf8_info(§4.4.7) structures and thus may be drawn, where not furtherconstrained, from the entire Unicode character set. Class names and interfacesare referenced both from thoseCONSTANT_NameAndType_info(§4.4.6) structures that have such names as part of their descriptor(§4.3) and from allCONSTANT_Class_info(§4.4.1) structures.For historical reasons the syntax of fully qualified class and interface names that appear inclass file structures differs from the familiar syntax of fully qualified names documented in§2.7.5. In this internal form, the ASCII periods ('.') that normally separate the identifiers that make up the fully qualified name are replaced by ASCII forward slashes ('/'). For example, the normal fully qualified name of classThread isjava.lang.Thread. In the form used in descriptors in theclass file format, a reference to the name of classThread is implemented using aCONSTANT_Utf8_info structure representing the string"java/lang/Thread".
class file format using UTF-8 strings(§4.4.7) and thus may be drawn, where not further constrained, from the entire Unicode character set.FieldType:
BaseType
ObjectType
ArrayType
states that aFieldType may represent either aBaseType, anObjectType, or anArrayType.
A nonterminal symbol on the right-hand side of a production that is followed by an asterisk (*) represents zero or more possibly different values produced from that nonterminal, appended without any intervening space. The production:
MethodDescriptor:
(ParameterDescriptor* )ReturnDescriptor
states that aMethodDescriptor represents a left parenthesis, followed by zero or moreParameterDescriptor values, followed by a right parenthesis, followed by aReturnDescriptor.
FieldType
FieldType
BaseType
BObjectType:
L <classname> ;ArrayType:
[ComponentTypeThe characters ofBaseType, the L and ; ofObjectType, and the [ ofArrayType are all ASCII characters. The <classname> represents a fully qualified class or interface name. For historical reasons it is encoded in internal form (§4.2).
The interpretation of the field types is as shown inTable 4.2.
For example, the descriptor of an instance variable of typeint is simply I. The descriptor of an instance variable of typeObject is Ljava/lang/Object;. Note that the internal form of the fully qualified name for classObject is used. The descriptor of an instance variable that is a multidimensionaldouble array,
double d[][][];is[[[D
MethodDescriptor:Aparameter descriptorrepresents a parameter passed to a method:
(ParameterDescriptor* )ReturnDescriptor
ParameterDescriptor:Areturn descriptorrepresents the type of the value returned from a method. It is a series of characters generated by the grammar:
FieldType
ReturnDescriptor:The character V indicates that the method returns no value (its return type is
FieldType
V
void).A method descriptor is valid only if it represents method parameters with a total length of 255 or less, where that length includes the contribution forthis in the case of instance or interface method invocations. The total length is calculated by summing the contributions of the individual parameters, where a parameter of typelong ordouble contributes two units to the length and a parameter of any other type contributes one unit.
For example, the method descriptor for the method
Object mymethod(int i, double d, Thread t)is(IDLjava/lang/Thread;)Ljava/lang/Object;Note that internal forms of the fully qualified names of
Thread andObject are used in the method descriptor.The method descriptor formymethod is the same whethermymethod is a class or an instance method. Although an instance method is passedthis, a reference to the current class instance, in addition to its intended parameters, that fact is not reflected in the method descriptor. (A reference tothis is not passed to a class method.) The reference tothis is passed implicitly by the method invocation instructions of the Java virtual machine used to invoke instance methods.
constant_pool table.Allconstant_pool table entries have the following general format:
Each item in the
cp_info {u1 tag;u1 info[];}
constant_pool table must begin with a 1-byte tag indicating the kind ofcp_info entry. The contents of theinfo array vary with the value oftag. The valid tags and their values are listed inTable 4.3. Each tag byte must be followed by two or more bytes giving information about the specific constant. The formatof the additional information varies with the tag value.CONSTANT_Class_info StructureCONSTANT_Class_info structure is used to represent a class or an interface:The items of the
CONSTANT_Class_info {u1 tag;u2 name_index;}
CONSTANT_Class_info structure are the following:tagtag item has the valueCONSTANT_Class (7).name_indexname_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing a valid fully qualified class or interface name(§2.8.1) encoded in internal form (§4.2).Because arrays are objects, the opcodesanewarray andmultianewarray can reference array "classes" viaCONSTANT_Class_info(§4.4.1) structures in theconstant_pool table. For such array classes, the name of the class is the descriptor of the array type. For example, the class name representing a two-dimensionalint array type
int[][]is [[IThe class name representing the type array of classThread Thread[]is [Ljava/lang/Thread;An array type descriptor is valid only if it represents 255 or fewer dimensions.CONSTANT_Fieldref_info,CONSTANT_Methodref_info, andCONSTANT_InterfaceMethodref_info StructuresThe items of these structures are as follows:
CONSTANT_Fieldref_info {u1 tag;u2 class_index;u2 name_and_type_index;}
CONSTANT_Methodref_info {u1 tag;u2 class_index;u2 name_and_type_index;}
CONSTANT_InterfaceMethodref_info {u1 tag;u2 class_index;u2 name_and_type_index;}
tagtag item of aCONSTANT_Fieldref_info structure has the valueCONSTANT_Fieldref (9).Thetag item of aCONSTANT_Methodref_info structure has the valueCONSTANT_Methodref (10).
Thetag item of aCONSTANT_InterfaceMethodref_info structure has the valueCONSTANT_InterfaceMethodref (11).
class_indexclass_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Class_info(§4.4.1) structure representing the class or interface type that contains the declaration of the field or method.Theclass_index item of aCONSTANT_Methodref_info structure must be a class type, not an interface type. Theclass_index item of aCONSTANT_InterfaceMethodref_info structure must be an interface type. Theclass_index item of aCONSTANT_Fieldref_info structure may be either a class type or an interface type.
name_and_type_indexname_and_type_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_NameAndType_info(§4.4.6) structure. Thisconstant_pool entry indicates the name and descriptor of the field or method. In aCONSTANT_Fieldref_info the indicated descriptor must be a field descriptor(§4.3.2). Otherwise, the indicated descriptor must be a method descriptor(§4.3.3).If the name of the method of aCONSTANT_Methodref_info structure begins with a' <' ('\u003c'), then the name must be the special name<init>, representing an instance initialization method(§3.9). Such a method must return no value.
CONSTANT_String_info StructureCONSTANT_String_info structure is used to represent constant objects of the typeString:The items of the
CONSTANT_String_info {u1 tag;u2 string_index;}
CONSTANT_String_info structure are as follows:tagtag item of theCONSTANT_String_info structure has the valueCONSTANT_String (8).string_indexstring_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing the sequence of characters to which theString object is to be initialized.CONSTANT_Integer_info andCONSTANT_Float_info StructuresCONSTANT_Integer_info andCONSTANT_Float_info structures represent 4-byte numeric (int andfloat) constants:The items of these structures are as follows:
CONSTANT_Integer_info {u1 tag;u4 bytes;}
CONSTANT_Float_info {u1 tag;u4 bytes;}
tagtag item of theCONSTANT_Integer_info structure has the valueCONSTANT_Integer (3).Thetag item of theCONSTANT_Float_info structure has the valueCONSTANT_Float (4).
bytesbytes item of theCONSTANT_Integer_info structure represents the value of theint constant. The bytes of the value are stored in big-endian (high byte first) order.Thebytes item of theCONSTANT_Float_info structure represents the value of thefloat constant in IEEE 754 floating-point single format(§3.3.2). The bytes of the single format representation are stored in big-endian (high byte first) order.
The value represented by theCONSTANT_Float_info structure is determined as follows. The bytes of the value are first converted into anint constant bits. Then:
0x7f800000, thefloat value will be positive infinity.0xff800000, thefloat value will be negative infinity.0x7f800001 through0x7fffffff or in the range0xff800001 through0xffffffff, thefloat value will be NaN.s,e, andm be three values that might be computed frombits:int s = ((bits>> 31) == 0) ? 1 : -1;int e = ((bits>> 23) & 0xff);int m = (e == 0) ?(bits& 0x7fffff) << 1 :(bits& 0x7fffff) | 0x800000;Then thefloatvalue equals the result of the mathematical expressions·m·2e-150.
CONSTANT_Long_info andCONSTANT_Double_info StructuresCONSTANT_Long_info andCONSTANT_Double_info represent 8-byte numeric (long anddouble) constants:All 8-byte constants take up two entries in the
CONSTANT_Long_info {u1 tag;u4 high_bytes;u4 low_bytes;}
CONSTANT_Double_info {u1 tag;u4 high_bytes;u4 low_bytes;}
constant_pool table of theclass file. If aCONSTANT_Long_info orCONSTANT_Double_info structure is the item in theconstant_pool table at indexn, then the next usable item in the pool is located at indexn+2. Theconstant_pool indexn+1 must be valid but is considered unusable.2The items of these structures are as follows:
tagtag item of theCONSTANT_Long_info structure has the valueCONSTANT_Long (5).Thetag item of theCONSTANT_Double_info structure has the valueCONSTANT_Double (6).
high_bytes,low_byteshigh_bytes andlow_bytes items of theCONSTANT_Long_info structure together represent the value of thelong constant ((long)high_bytes<< 32) +low_bytes, where the bytes of each ofhigh_bytes andlow_bytes are stored in big-endian (high byte first) order.Thehigh_bytes andlow_bytes items of theCONSTANT_Double_info structure together represent thedouble value in IEEE 754 floating-point double format(§3.3.2). The bytes of each item are stored in big-endian (high byte first) order.
The value represented by theCONSTANT_Double_info structure is determined as follows. Thehigh_bytes andlow_bytes items are first converted into thelong constant bits, which is equal to ((long)high_bytes<< 32) +low_bytes. Then:
0x7ff0000000000000L, thedouble value will be positive infinity.0xfff0000000000000L, thedouble value will be negative infinity.0x7ff0000000000001L through0x7fffffffffffffffL or in the range0xfff0000000000001L through0xffffffffffffffffL, thedouble value will be NaN.s,e, andm be three values that might be computed from bits:int s = ((bits>> 63) == 0) ? 1 : -1;int e = (int)((bits>> 52) & 0x7ffL);long m = (e == 0) ?(bits& 0xfffffffffffffL) << 1 :(bits& 0xfffffffffffffL) | 0x10000000000000L;
double value of the mathematical expressions·m·2e-1075.CONSTANT_NameAndType_info StructureCONSTANT_NameAndType_info structure is used to represent a field or method, without indicating which class or interface type it belongs to:The items of the
CONSTANT_NameAndType_info {u1 tag;u2 name_index;u2 descriptor_index;}
CONSTANT_NameAndType_info structure are as follows:tagtag item of theCONSTANT_NameAndType_info structure has the valueCONSTANT_NameAndType (12).name_indexname_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing either a valid field or method name(§2.7) stored as a simple name(§2.7.1), that is, as a Java programming language identifier(§2.2) or as the special method name<init>(§3.9).descriptor_indexdescriptor_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing a valid field descriptor(§4.3.2) or method descriptor(§4.3.3).CONSTANT_Utf8_info StructureCONSTANT_Utf8_info structure is used to represent constant string values.UTF-8 strings are encoded so that character sequences that contain only non-null ASCII characters can be represented using only 1 byte per character, but characters of up to 16 bits can be represented. All characters in the range'\u0001' to'\u007F' are represented by a single byte:
| 0 | bits 6-0 |
The 7 bits of data in the byte give the value of the character represented. The null character ('\u0000') and characters in the range'\u0080' to'\u07FF' are representedby a pair of bytes x and y:
| 1 | 1 | 0 | bits 10-6 |
| 1 | 0 | bits 5-0 |
The bytes represent the character with the value ((x &0x1f)<<6) + (y &0x3f).
Characters in the range'\u0800' to'\uFFFF' are represented by 3 bytes x, y, and z:
| 1 | 1 | 1 | 0 | bits 15-12 |
| 1 | 0 | bits 11-6 |
| 1 | 0 | bits 5-0 |
The character with the value ((x &0xf)<<12) + ((y &0x3f)<<6) + (z &0x3f) is represented by the bytes.
The bytes of multibyte characters are stored in theclass file in big-endian (high byte first) order.
There are two differences between this format and the "standard" UTF-8 format. First, the null byte(byte)0 is encoded using the 2-byte format rather than the 1-byte format, so that Java virtual machine UTF-8 strings never have embedded nulls. Second, only the 1-byte, 2-byte, and 3-byte formats are used. The Java virtual machine does not recognize the longer UTF-8 formats.
For more information regarding the UTF-8 format, seeFile System Safe UCS Transformation Format (FSS_UTF), X/Open Preliminary Specification (X/Open Company Ltd., Document Number: P316). This information also appears in ISO/IEC 10646, Annex P.
TheCONSTANT_Utf8_info structure is
The items of the
CONSTANT_Utf8_info {u1 tag;u2 length;u1 bytes[length];}
CONSTANT_Utf8_info structure are the following:tagtag item of theCONSTANT_Utf8_info structure has the valueCONSTANT_Utf8 (1).lengthlength item gives the number of bytes in thebytes array (not the length of the resulting string). The strings in theCONSTANT_Utf8_info structure are not null-terminated.bytes[]bytes array contains the bytes of the string. No byte may have the value(byte)0 or lie in the range(byte)0xf0-(byte)0xff.field_info structure. No two fields in oneclass file may have the same name and descriptor(§4.3.2). The format of this structure isThe items of the
field_info {u2 access_flags;u2 name_index;u2 descriptor_index;u2 attributes_count;attribute_info attributes[attributes_count];}
field_info structure are as follows:access_flags access_flags item is a mask of flags used to denote access permission to and properties of this field. The interpretation of each flag, when set, is as shown inTable 4.4.Fields of classes may set any of the flags inTable 4.4. However, a specific field of a class may have at most one of itsACC_PRIVATE,ACC_PROTECTED, andACC_PUBLIC flags set(§2.7.4) and may not have both itsACC_FINAL andACC_VOLATILE flags set(§2.9.1).
Fields of classes may set any of the flags inTable 4.4. However, a specific field of a class may have at most one of itsACC_PRIVATE,ACC_PROTECTED, andACC_PUBLIC flags set(§2.7.4) and may not have both itsACC_FINAL andACC_VOLATILE flags set(§2.9.1).
All fields of interfaces must have theirACC_PUBLIC,ACC_STATIC, andACC_FINAL flags set and may not have any of the other flags inTable 4.4 set(§2.13.3.1).
All bits of theaccess_flags item not assigned inTable 4.4 are reserved for future use. They should be set to zero in generatedclass files and should be ignored by Java virtual machine implementations.
name_indexname_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure which must represent a valid field name(§2.7) stored as a simple name(§2.7.1), that is, as a Java programming language identifier(§2.2).descriptor_indexdescriptor_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure that must represent a valid field descriptor(§4.3.2).attributes_countattributes_count item indicates the number of additional attributes(§4.7) of this field.attributes[]attributes table must be an attribute structure(§4.7). A field can have any number of attributes associated with it.The attributes defined by this specification as appearing in theattributes table of afield_info structure are theConstantValue(§4.7.2),Synthetic(§4.7.6), andDeprecated(§4.7.10) attributes.
A Java virtual machine implementation must recognize and correctly readConstantValue(§4.7.2) attributes found in theattributes table of afield_info structure. A Java virtual machine implementation is required to silently ignore any or all other attributes in theattributes table that it does not recognize. Attributes not defined in this specification are not allowed to affect the semantics of theclass file, but only to provide additional descriptive information(§4.7.1).
method_info structure. No two methods in oneclass file may have the same name and descriptor(§4.3.3).The structure has the following format:
The items of the
method_info {u2 access_flags;u2 name_index;u2 descriptor_index;u2 attributes_count;attribute_info attributes[attributes_count];}
method_info structure are as follows:access_flags access_flags item is a mask of flags used to denote access permission to and properties of this method. The interpretation of each flag, when set, is as shown inTable 4.5.Methods of classes may set any of the flags inTable 4.5. However, a specific method of a class may have at most one of itsACC_PRIVATE,ACC_PROTECTED, andACC_PUBLICflags set(§2.7.4). If such a method has itsACC_ABSTRACT flag set it may not have any of itsACC_FINAL,ACC_NATIVE,ACC_PRIVATE,ACC_STATIC,ACC_STRICT, orACC_SYNCHRONIZED flags set(§2.13.3.2).
All interface methods must have theirACC_ABSTRACT andACC_PUBLIC flags set and may not have any of the other flags inTable 4.5 set(§2.13.3.2).
A specific instance initialization method(§3.9) may have at most one of itsACC_PRIVATE,ACC_PROTECTED, andACC_PUBLIC flags set and may also have itsACC_STRICT flag set, but may not have any of the other flags inTable 4.5 set.
Class and interface initialization methods(§3.9) are called implicitly by the Java virtual machine; the value of theiraccess_flags item is ignored except for the settings of theACC_STRICTflag.
All bits of theaccess_flags item not assigned inTable 4.5 are reserved for future use. They should be set to zero in generatedclass files and should be ignored by Java virtual machine implementations.
name_indexname_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing either one of the special method names(§3.9),<init> or<clinit>, or a valid method name in the Java programming language(§2.7), stored as a simple name(§2.7.1).descriptor_indexdescriptor_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing a valid method descriptor(§4.3.3).attributes_countattributes_count item indicates the number of additional attributes(§4.7) of this method.attributes[]attributes table must be an attribute structure(§4.7). A method can have any number of optional attributes associated with it.The only attributes defined by this specification as appearing in theattributes table of amethod_info structure are theCode(§4.7.3),Exceptions(§4.7.4),Synthetic(§4.7.6), andDeprecated(§4.7.10) attributes.
A Java virtual machine implementation must recognize and correctly readCode(§4.7.3) andExceptions(§4.7.4) attributes found in theattributes table of amethod_info structure. A Java virtual machine implementation is required to silently ignore any or all other attributes in theattributes table of amethod_info structure that it does not recognize. Attributes not defined in this specification are not allowed to affect the semantics of theclass file, but only to provide additional descriptive information(§4.7.1).
ClassFile(§4.1),field_info(§4.5),method_info(§4.6), andCode_attribute(§4.7.3) structures of theclass file format. All attributes have the following general format:For all attributes, the
attribute_info {u2 attribute_name_index;u4 attribute_length;u1 info[attribute_length];}
attribute_name_index must be a valid unsigned 16-bit index into the constant pool of the class. Theconstant_pool entry atattribute_name_index must be aCONSTANT_Utf8_info(§4.4.7) structure representing the name of the attribute. The value of theattribute_length item indicates the length of the subsequent information in bytes. The length does not include the initial six bytes that contain theattribute_name_index andattribute_length items.Certain attributes are predefined as part of theclass file specification. The predefined attributes are theSourceFile(§4.7.7),ConstantValue(§4.7.2),Code(§4.7.3),Exceptions(§4.7.4),InnerClasses(§4.7.5),Synthetic(§4.7.6),LineNumberTable(§4.7.8),LocalVariableTable(§4.7.9), andDeprecated(§4.7.10) attributes. Within the context of their use in this specification, that is, in theattributes tables of theclass file structures in which they appear, the names of these predefined attributes are reserved.
Of the predefined attributes, theCode,ConstantValue, andExceptions attributes must be recognized and correctly read by aclass file reader for correct interpretation of theclass file by a Java virtual machine implementation. TheInnerClasses andSynthetic attributes must be recognized and correctly read by aclass file reader in order to properly implement the Java and Java 2 platform class libraries(§3.12). Use of the remaining predefined attributes is optional; aclass file reader may use the information they contain, or otherwise must silently ignore those attributes.
class files containing new attributes in theattributes tables ofclass file structures. Java virtual machine implementationsare permitted to recognize and use new attributes found in theattributes tables ofclass file structures. However, any attribute not defined as part of this Java virtual machine specification must not affect the semantics of class or interface types. Java virtual machine implementations are required to silently ignore attributes they do not recognize.For instance, defining a new attribute to support vendor-specific debugging is permitted. Because Java virtual machine implementations are required to ignore attributes they do not recognize,class files intended for that particular Java virtual machine implementation will be usable by other implementations even if those implementations cannot make use of the additional debugging information that theclass files contain.
Java virtual machine implementations are specifically prohibited from throwing an exception or otherwise refusing to useclass files simply because of the presence of some new attribute. Of course, tools operating onclass files may not run correctly if givenclass files that do not contain all the attributes they require.
Two attributes that are intended to be distinct, but that happen to use the same attribute name and are of the same length, will conflict on implementations that recognize either attribute. Attributes defined other than by Sun must have names chosen according to the package naming convention defined byThe Java Language Specification. For instance, a new attribute defined by Netscape might have the name"com.Netscape.new-attribute".3
Sun may define additional attributes in future versions of thisclass file specification.
ConstantValue AttributeConstantValue attribute is a fixed-length attribute used in theattributes table of thefield_info(§4.5) structures. AConstantValue attribute represents the value of a constant field that must be (explicitly or implicitly)static; that is, theACC_STATIC bit (Table 4.4) in theflags item of thefield_info structure must be set. There can be no more than oneConstantValue attribute in theattributes table of a givenfield_info structure. The constant field represented by thefield_info structure is assigned the value referenced by itsConstantValue attribute as part of the initialization of the class or interface declaring the constant field(§2.17.4). This occurs immediately prior to the invocation of the class or interfaceinitialization method(§3.9) of that class or interface.If afield_info structure representing a non-static field has aConstantValue attribute, then that attribute must silently be ignored. Every Java virtual machine implementation must recognizeConstantValue attributes.
TheConstantValue attribute has the following format:
The items of the
ConstantValue_attribute {u2 attribute_name_index;u4 attribute_length;u2 constantvalue_index;}
ConstantValue_attribute structure are as follows:attribute_name_indexattribute_name_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing the string"ConstantValue".attribute_lengthattribute_length item of aConstantValue_attribute structure must be2.constantvalue_indexconstantvalue_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index gives the constant value represented by this attribute. Theconstant_pool entry must be of a type appropriate to the field, as shown byTable 4.6.| Field Type | Entry Type |
long | CONSTANT_Long |
float | CONSTANT_Float |
double | CONSTANT_Double |
int,short,char,byte,boolean | CONSTANT_Integer |
String | CONSTANT_String |
Code AttributeCode attribute is a variable-length attribute used in theattributes table ofmethod_info structures. ACode attribute contains the Java virtual machine instructions and auxiliary information for a single method, instance initialization method(§3.9), or class or interface initialization method(§3.9). Every Java virtual machine implementation must recognizeCode attributes. If the method is eithernative orabstract, itsmethod_info structure must not have aCode attribute. Otherwise, itsmethod_info structure must have exactly oneCode attribute.TheCode attribute has the following format:
The items of the
Code_attribute {u2 attribute_name_index;u4 attribute_length;u2 max_stack;u2 max_locals;u4 code_length;u1 code[code_length];u2 exception_table_length;{ u2 start_pc;u2 end_pc;u2 handler_pc;u2 catch_type;}exception_table[exception_table_length];u2 attributes_count;attribute_info attributes[attributes_count];}
Code_attribute structure are as follows:attribute_name_indexattribute_name_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing the string"Code".attribute_lengthattribute_length item indicates the length of the attribute, excluding the initial six bytes.max_stackmax_stack item gives the maximum depth(§3.6.2) of the operand stack of this method at any point during execution of the method.max_localsmax_locals item gives the number of local variables in the local variable array allocated upon invocation of this method, including the local variables used to pass parameters to the method on its invocation.The greatest local variable index for a value of typelong ordouble ismax_locals-2. The greatest local variable index for a value of any other type ismax_locals-1.
code_lengthcode_length item gives the number of bytes in thecode array for this method. The value ofcode_length must be greater than zero; thecode array must not be empty.code[]code array gives the actual bytes of Java virtual machine code that implement the method.When thecode array is read into memory on a byte-addressable machine, if the first byte of the array is aligned on a 4-byte boundary, thetableswitch andlookupswitch 32-bit offsets will be 4-byte aligned. (Refer to the descriptions of those instructions for more information on the consequences ofcode array alignment.)
The detailed constraints on the contents of thecode array are extensive and are given in a separate section(§4.8).
exception_table_lengthexception_table_length item gives the number of entries in theexception_table table.exception_table[]exception_table array describes one exception handler in thecode array. The order of the handlers in theexception_table array is significant. SeeSection 3.10 for more details.Eachexception_table entry contains the following four items:
start_pc,end_pcstart_pc andend_pc indicate the ranges in thecode array at which the exception handler is active. The value ofstart_pc must be a valid index into thecode array of the opcode of an instruction. The value ofend_pc either must be a valid index into thecode array of the opcode of an instruction or must be equal tocode_length, the length of thecode array. The value ofstart_pc must be less than the value ofend_pc.Thestart_pc is inclusive andend_pc is exclusive; that is, the exception handler must be active while the program counter is within the interval [start_pc,end_pc).4
handler_pchandler_pc item indicates the start of the exception handler. The value of the item must be a valid index into thecode array and must be the index of the opcode of an instruction.catch_typecatch_type item is nonzero, it must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Class_info(§4.4.1) structure representing a class of exceptions that this exception handler is designated to catch. This class must be the classThrowable or one of its subclasses. The exception handler will be called only if the thrown exception is an instance of the given class or one of its subclasses.If the value of thecatch_type item is zero, this exception handler is called for all exceptions. This is used to implementfinally (seeSection 7.13, "Compilingfinally").
attributes_countattributes_count item indicates the number of attributes of theCode attribute.attributes[]attributes table must be an attribute structure(§4.7). ACode attribute can have any number of optional attributes associated with it.Currently, theLineNumberTable(§4.7.8) andLocalVariableTable(§4.7.9) attributes, both of which contain debugging information, are defined and used with theCode attribute.
A Java virtual machine implementation is permitted to silently ignore any or all attributes in theattributes table of aCode attribute. Attributes not defined in this specification are not allowed to affect the semantics of theclass file, but only to provide additional descriptive information(§4.7.1).
Exceptions AttributeExceptions attribute is a variable-length attribute used in theattributes table of amethod_info(§4.6) structure. TheExceptions attribute indicates which checked exceptions a method may throw. There may be at most oneExceptions attribute in eachmethod_info structure.TheExceptions attribute has the following format:
The items of the
Exceptions_attribute {u2 attribute_name_index;u4 attribute_length;u2 number_of_exceptions;u2 exception_index_table[number_of_exceptions];}
Exceptions_attribute structure are as follows:attribute_name_indexattribute_name_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must betheCONSTANT_Utf8_info(§4.4.7) structure representing the string"Exceptions".attribute_lengthattribute_length item indicates the attribute length, excluding the initial six bytes.number_of_exceptionsnumber_of_exceptions item indicates the number of entries in theexception_index_table.exception_index_table[]exception_index_table array must be a valid index into theconstant_pool table. Theconstant_pool entry referenced by each table item must be aCONSTANT_Class_info(§4.4.1) structure representing a class type that this method is declared to throw.RuntimeException or one of its subclasses.Error or one of its subclasses.exception_index_table just described, or one of their subclasses.InnerClasses AttributeInnerClasses attribute5 is a variable-length attribute in theattributes table of theClassFile(§4.1) structure. If the constant pool of a class or interface refers to any class or interface that is not a member of a package, itsClassFile structure must have exactly oneInnerClasses attribute in itsattributes table.TheInnerClasses attribute has the following format:
The items of the
InnerClasses_attribute {u2 attribute_name_index;u4 attribute_length;u2 number_of_classes;{ u2 inner_class_info_index;u2 outer_class_info_index;u2 inner_name_index;u2 inner_class_access_flags;} classes[number_of_classes];}
InnerClasses_attribute structure are as follows:attribute_name_indexattribute_name_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing the string"InnerClasses".attribute_lengthattribute_length item indicates the length of the attribute, excluding the initial six bytes.number_of_classesnumber_of_classes item indicates the number of entries in theclasses array.classes[]CONSTANT_Class_info entry in theconstant_pool table which represents a class or interface C that is not a package member must have exactly one corresponding entry in theclasses array.If a class has members that are classes or interfaces, itsconstant_pool table (and hence itsInnerClasses attribute) must refer to each such member, even if that member is not otherwise mentioned by the class. These rules imply that a nested class or interface member will haveInnerClasses information for each enclosing class and for each immediate member.
Eachclasses array entry contains the following four items:
inner_class_info_indexinner_class_info_index item must be zero or a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Class_info(§4.4.1) structure representing C. The remaining items in theclasses array entry give information about C.outer_class_info_indexouter_class_info_index item must be zero. Otherwise, the value of theouter_class_info_index item must be a valid index into theconstant_pool table, and the entry at that index must be aCONSTANT_Class_info(§4.4.1) structure representing the class or interface of which C is a member.inner_name_indexinner_name_index item must be zero. Otherwise, the value of theinner_name_index item must be a valid index into theconstant_pool table, and the entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure that represents the original simple name of C, as given in the source code from which thisclass file was compiled.inner_class_access_flagsinner_class_access_flags item is a mask of flags used to denote access permissions to and properties of class or interface C as declared in the source code from which thisclass file was compiled. It is used by compilers to recover the original information when source code is not available. The flags are shown inTable 4.7.All bits of theinner_class_access_flags item not assigned inTable 4.7 are reserved for future use. They should be set to zero in generatedclass files and should be ignored by Java virtual machine implementations.
InnerClasses attribute with anyclass file actually representing a class or interface referenced by the attribute.Synthetic AttributeSynthetic attribute6 is a fixed-length attribute in theattributes table ofClassFile(§4.1),field_info(§4.5), andmethod_info(§4.6) structures. A class member that does not appear in the source code must be marked using aSynthetic attribute.TheSynthetic attribute has the following format:
The items of the
Synthetic_attribute {u2 attribute_name_index;u4 attribute_length;}
Synthetic_attribute structure are as follows:attribute_name_indexattribute_name_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing the string"Synthetic".attribute_lengthattribute_length item is zero.SourceFile AttributeSourceFile attribute is an optional fixed-length attribute in theattributes table of theClassFile(§4.1) structure. There can be no more than oneSourceFile attribute in theattributes table of a givenClassFile structure.TheSourceFile attribute has the following format:
The items of the
SourceFile_attribute {u2 attribute_name_index;u4 attribute_length;u2 sourcefile_index;}
SourceFile_attribute structure are as follows:attribute_name_indexattribute_name_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing the string"SourceFile".attribute_lengthattribute_length item of aSourceFile_attribute structure must be2.sourcefile_indexsourcefile_index item must be a valid index into theconstant_pool table. The constant pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing a string.The string referenced by thesourcefile_index item will be interpreted as indicating the name of the source file from which thisclass file was compiled. It will not be interpreted as indicating the name of a directory containing the file or an absolute path name for the file; such platform-specific additional information must be supplied by the runtime interpreter or development tool at the time the file name is actually used.
LineNumberTable AttributeLineNumberTable attribute is an optional variable-length attribute in theattributes table of aCode(§4.7.3) attribute. It may be used by debuggers to determine which part of the Java virtual machinecode array corresponds to a given line number in the original source file. IfLineNumberTable attributes are present in theattributes table of a givenCode attribute, then they may appear in any order. Furthermore, multipleLineNumberTable attributes may together represent a given line of a source file; that is,LineNumberTable attributes need not be one-to-one with source lines.TheLineNumberTable attribute has the following format:
The items of the
LineNumberTable_attribute {u2 attribute_name_index;u4 attribute_length;u2 line_number_table_length;{ u2 start_pc;u2 line_number;} line_number_table[line_number_table_length];}
LineNumberTable_attribute structure are as follows:attribute_name_indexattribute_name_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing the string"LineNumberTable".attribute_lengthattribute_length item indicates the length of the attribute, excluding the initial six bytes.line_number_table_lengthline_number_table_length item indicates the number of entries in theline_number_table array.line_number_table[]line_number_table array indicates that the line number in the original source file changes at a given point in thecode array. Eachline_number_table entry must contain the following two items:start_pcstart_pc item must indicate the index into thecode array at which the code for a new line in the original source file begins. The value ofstart_pc must be less than the value of thecode_length item of theCode attribute of which thisLineNumberTable is an attribute.line_numberline_number item must give the corresponding line number in the original source file.LocalVariableTable AttributeLocalVariableTable attribute is an optional variable-length attribute of aCode(§4.7.3) attribute. It may be used by debuggers to determine the value of a given local variable during the execution of a method. IfLocalVariableTable attributes are present in theattributes table of a givenCode attribute, then they may appear in any order. There may be no more than oneLocalVariableTable attribute per local variable in theCode attribute.TheLocalVariableTable attribute has the following format:
The items of the
LocalVariableTable_attribute {u2 attribute_name_index;u4 attribute_length;u2 local_variable_table_length;{ u2 start_pc;u2 length;u2 name_index;u2 descriptor_index;u2 index;} local_variable_table[local_variable_table_length];}
LocalVariableTable_attribute structure are as follows:attribute_name_indexattribute_name_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing the string"LocalVariableTable".attribute_lengthattribute_length item indicates the length of the attribute, excluding the initial six bytes.local_variable_table_lengthlocal_variable_table_length item indicates the number of entries in thelocal_variable_table array.local_variable_table[]local_variable_table array indicates a range ofcode array offsets within which a local variable has a value. It also indicates the index into the local variable array of the current frame at which that local variable can be found. Each entry must contain the following five items:start_pc,lengthcode array in the interval [start_pc,start_pc+length], that is, betweenstart_pc andstart_pc+length inclusive. The value ofstart_pc must be a valid index into thecode array of thisCode attribute and must be the index of the opcode of an instruction. Either the value ofstart_pc+length must be a valid index into thecode array of thisCode attribute and be the index of the opcode of an instruction, or it must be the first index beyond the end of thatcode array.name_index,descriptor_indexname_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must contain aCONSTANT_Utf8_info(§4.4.7)structure representing a valid local variable name stored as a simple name(§2.7.1).The value of thedescriptor_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must contain aCONSTANT_Utf8_info(§4.4.7) structure representing a field descriptor(§4.3.2) encoding the type of a local variable in the source program.
indexindex in the local variable array of the current frame. If the local variable atindex is of typedouble orlong, it occupies bothindex andindex+1.Deprecated AttributeDeprecated attribute7 is an optional fixed-length attribute in theattributes table ofClassFile(§4.1),field_info(§4.5), andmethod_info(§4.6) structures.A class, interface, method, or field may be marked using aDeprecated attribute to indicate that the class, interface, method, or field has been superseded. A runtime interpreter or tool that reads theclass file format, such as a compiler, can use this marking to advise the user that a superseded class, interface, method, or field is being referred to. The presence of aDeprecated attribute does not alter the semantics of a class or interface.TheDeprecated attribute has the following format:
The items of the
Deprecated_attribute {u2 attribute_name_index;u4 attribute_length;}
Deprecated_attribute structure are as follows:attribute_name_indexattribute_name_index item must be a valid index into theconstant_pool table. Theconstant_pool entry at that index must be aCONSTANT_Utf8_info(§4.4.7) structure representing the string"Deprecated".attribute_lengthattribute_length item is zero.code array of theCode attribute of amethod_info structure of aclass file. This section describes the constraints associated with the contents of theCode_attribute structure.class file are those defining the well-formedness of the file. With the exception of the static constraints on the Java virtual machine code of theclass file, these constraints have been given in the previous section. The static constraints on the Java virtual machine code in aclass file specify how Java virtual machine instructions must be laid out in thecode array and what the operands of individual instructions must be.The static constraints on the instructions in thecode array are as follows:
code array must not be empty, so thecode_length item cannot have the value0.code_length item must be less than65536.code array begins at index0.code array. Instances of instructions using the reserved opcodes(§6.2) or any opcodes not documented in this specification may not appear in thecode array.code array except the last, the index of the opcode of the next instruction equals the index of the opcode of the current instruction plus the length of that instruction, including all its operands. Thewide instruction is treated like any other instruction for these purposes; the opcode specifying the operation that awide instruction is to modify is treated as one of the operands of thatwide instruction. That opcode must never be directly reachable by the computation.code array must be the byte at indexcode_length-1.code array are as follows:constant_pool table. The operands of eachldc_w instruction must represent a valid index into theconstant_pool table. In both cases the constant pool entry referenced by that index must be of typeCONSTANT_Integer,CONSTANT_Float, orCONSTANT_String.constant_pool table. The constant pool entry referenced by that index must be of typeCONSTANT_Long orCONSTANT_Double. In addition, the subsequent constant pool index must also be a valid index into the constant pool, and the constant pool entry at that index must not be used.constant_pool table. The constant pool entry referenced by that index must be of typeCONSTANT_Fieldref.constant_pool table. The constant pool entry referenced by that index must be of typeCONSTANT_Methodref.'<' ('\u003c') may be called by the method invocation instructions. In particular, the class or interface initialization method specially named<clinit> is never called explicitly from Java virtual machine instructions, but only implicitly by the Java virtual machine itself.constant_pool table. The constant pool entry referenced by that index must be of typeCONSTANT_InterfaceMethodref. The value of thecount operand of eachinvokeinterface instruction must reflect the number of local variables necessary to store the arguments to be passed to the interface method, as implied by the descriptor of theCONSTANT_NameAndType_info structure referenced by theCONSTANT_InterfaceMethodref constant pool entry. The fourth operand byte of eachinvokeinterface instruction must have the value zero.constant_pool table. The constant pool entry referenced by that index must be of typeCONSTANT_Class.CONSTANT_Classconstant_pool table entry representing an array class. Thenew instruction cannot be used to create an array. Thenew instruction also cannot be used to create an instance of an interface or an instance of anabstract class.T_BOOLEAN (4),T_CHAR (5),T_FLOAT (6),T_DOUBLE (7),T_BYTE (8),T_SHORT (9),T_INT (10), orT_LONG (11).max_locals-1.max_locals-1.max_locals-2.max_locals-2.max_locals-1. The indexbyte operands of eachwide instruction modifying anlload,dload,lstore, ordstore instruction must represent a nonnegative integer no greater thanmax_locals-2.code array specify constraints on relationships between Java virtual machine instructions. The structural constraints are as follows:int is also permitted to operate on values of typeboolean,byte,char, andshort. (As noted in§3.3.4 and§3.11.1, the Java virtual machine internally converts values of typesboolean,byte,char, andshort to typeint.)long ordouble be reversed or the pair split up. At no point can the local variables of such a pair be operated on individually.long ordouble) can be accessed before it is assigned a value.max_stack item.Object, must call either another instance initialization method ofthis or an instance initialization method of its direct superclasssuper before its instance members are accessed. However, instance fields ofthis that are declared in the current class may be assigned before calling any instance initialization method.boolean,byte,char,short, orint, only theireturn instruction may be used. If the method returns afloat,long, ordouble, only anfreturn,lreturn, or dreturninstruction, respectively, may be used. If the method returns areference type, it must do so using anareturn instruction, and the type of the returned value must be assignment compatible(§2.6.7) with the return descriptor(§4.3.3) of the method. All instance initialization methods, class or interface initialization methods, and methods declared to returnvoid must use only thereturn instruction.protected field of a superclass, then the type of the class instance being accessed must be the same as or a subclass of the current class. Ifinvokevirtual orinvokespecialis used to access aprotected method of a superclass, then the type of the class instance being accessed must be the same as or a subclass of the current class.boolean,byte,char,short, orint, then the value must be anint. If the descriptor type isfloat,long, ordouble, then the value must be afloat,long, ordouble, respectively. If the descriptor type is areference type, then the value must be of a type that is assignment compatible(§2.6.7) with the descriptor type.reference by anaastore instruction must be assignment compatible(§2.6.7) with the component type of the array.Throwable or of subclasses ofThrowable.code array.returnAddress) may be loaded from a local variable.try-finally constructs from within afinally clause. For more information on Java virtual machine subroutines, see§4.9.6.)returnAddress can be returned to at most once. If aret instruction returns to a point in the subroutine call chain above theret instruction corresponding to a given instance of typereturnAddress, then that instance can never be used as a return address. Filesclass files. The HotJava browser needs to determine whether theclass file was produced by a trustworthy compiler or by an adversary attempting to exploit the virtual machine.An additional problem with compile-time checking is version skew. A user may have successfully compiled a class, sayPurchaseStockOptions, to be a subclass ofTradingClass. But the definition ofTradingClass might have changed since the time the class was compiled in a way that is not compatible with preexisting binaries. Methods might have been deleted or had their return types or modifiers changed. Fields might have changed types or changed from instance variables to class variables. The access modifiers of a method or variable may have changed frompublic toprivate. For a discussion of these issues, see Chapter 13, "Binary Compatibility," in the first edition ofTheJava Language Specification or the equivalent chapter in the second edition.
Because of these potential problems, the Java virtual machine needs to verify for itself that the desired constraints are satisfied by theclass files it attempts to incorporate. A Java virtual machine implementation verifies that eachclass file satisfies the necessary constraints at linking time(§2.17.3). Structural constraints on the Java virtual machine code may be checked using a simple theorem prover.
Linking-time verification enhances the performance of the interpreter. Expensive checks that would otherwise have to be performed to verify constraints at run time for each interpreted instruction can be eliminated. The Java virtual machine can assume that these checks have already been performed. For example, the Java virtual machine will already know the following:
class file verifier is independent of any compiler. It should certify all code generated by Sun's compiler for the Java programming language; it should also certify code that other compilers can generate, as well as code that the current compiler could not possibly generate. Anyclass file that satisfies the structural criteria and static constraints will be certified by the verifier.Theclass file verifier is also independent of the Java programming language. Programs written in other languages can be compiled into theclass file format, but will pass verification only if all the same constraints are satisfied.
class file verifier operates in four passes: Pass 1:
When a prospectiveclass file is loaded(§2.17.2) by the Java virtual machine, the Java virtual machine first ensures that the file has the basic format of aclass file. The first four bytes must contain the right magic number. All recognized attributes must be of the proper length. Theclass file must not be truncated or have extra bytes at the end. The constant pool must not contain any superficially unrecognizable information.
Whileclass file verification properly occurs during class linking(§2.17.3), this check for basicclass file integrity is necessary for any interpretation of theclass file contents and can be considered to be logically part of the verification process.
Pass 2:
When theclass file is linked, the verifier performs all additional verification that can be done without looking at thecode array of theCode attribute (§4.7.3). The checks performed by this pass include the following:
final classes are not subclassed and thatfinal methods are not overridden.Object) has a direct superclass.CONSTANT_Class_info structure in the constant pool contains in itsname_index item a valid constant pool index for aCONSTANT_Utf8_info structure. Pass 3:
During linking, the verifier checks thecode array of theCode attribute for each method of theclass file by performing data-flow analysis on each method. The verifier ensures that at any given point in the program, no matter what code path is taken to reach that point, the following is true:
Pass 4:
For efficiency reasons, certain tests that could in principle be performed in Pass 3 are delayed until the first time the code for the method is actually invoked. In so doing, Pass 3 of the verifier avoids loadingclass files unless it has to.
For example, if a method invokes another method that returns an instance of classA, and that instance is assigned only to a field of the same type, the verifier does not bother to check if the classA actually exists. However, if it is assigned to a field of the typeB, the definitions of bothA andB must be loaded in to ensure thatA is a subclass ofB.
Pass 4 is a virtual pass whose checking is done by the appropriate Java virtual machine instructions. The first time an instruction that references a type is executed, the executing instruction does the following:
LinkageError to be thrown.A Java virtual machine implementation is allowed to perform any or all of the Pass 4 steps as part of Pass 3; see2.17.1, "Virtual Machine Start-up" for an example and more discussion.
In one of Sun's Java virtual machine implementations, after the verification has been performed, the instruction in the Java virtual machine code is replaced with an alternative form of the instruction. This alternative instruction indicates that the verification needed by this instruction has taken place and does not need to be performed again. Subsequent invocations of the method will thus be faster. It is illegal for these alternative instruction forms to appear inclass files, and they should never be encountered by the verifier.
class file verification. This section looks at the verification of Java virtual machine code in Pass 3 in more detail.The code for each method is verified independently. First, the bytes that make up the code are broken up into a sequence of instructions, and the index into thecode array of the start of each instruction is placed in an array. The verifier then goes through the code a second time and parses the instructions. During this pass a data structure is built to hold information about each Java virtual machine instruction in the method. The operands, if any, of each instruction are checked to make sure they are valid. For instance:
code array for the method.int or float or for instances of classString; the instructiongetfield must reference a field.byte,short,char) when determining the value types on the operand stack.Next, a data-flow analyzer is initialized. For the first instruction of the method, the local variables that represent parameters initially contain values of the types indicated by the method's type descriptor; the operand stack is empty. All other local variables contain an illegal value. For the other instructions, which have not been examined yet, no information is available regarding the operand stack or local variables.
Finally, the data-flow analyzer is run. For each instruction, a "changed" bit indicates whether this instruction needs to be looked at. Initially, the "changed" bit is set only for the first instruction. The data-flow analyzer executes the following loop:
reference values may appear at corresponding places on the two stacks. In this case, the merged operand stack contains areference to an instance of the first common superclass of the two types. Such a reference type always exists because the typeObject is a superclass of all class and interface types. If the operand stacks cannot be merged, verification of the method fails.To merge two local variable array states, corresponding pairs of local variables are compared. If the two types are not identical, then unless both containreference values, the verifier records that the local variable contains an unusable value. If both of the pair of local variables containreference values, the merged state contains areference to an instance of the first common superclass of the two types.
If the data-flow analyzer runs on a method without reporting a verification failure, then the method has been successfully verified by Pass 3 of theclass file verifier.
Certain instructions and data types complicate the data-flow analyzer. We now examine each of these in more detail.
long anddoublelong anddouble types are treated specially by the verification process.Whenever a value of typelong ordouble is moved into a local variable at indexn, indexn + 1 is specially marked to indicate that it has been reserved by the value at indexn and may not be used as a local variable index. Any value previously at indexn + 1 becomes unusable.
Whenever a value is moved to a local variable at indexn, the indexn - 1 is examined to see if it is the index of a value of typelong ordouble. If so, the local variable at indexn - 1 is changed to indicate that it now contains an unusable value. Since the local variable at indexn has been overwritten, the local variable at indexn - 1 cannot represent a value of typelong ordouble.
Dealing with values of typeslong ordouble on the operand stack is simpler; the verifier treats them as single values on the stack. For example, the verification code for thedadd opcode (add twodouble values) checks that the top two items on the stack are both of typedouble. When calculating operand stack length, values of typelong anddouble have length two.
Untyped instructions that manipulate the operand stack must treat values of typedouble andlong as atomic (indivisible). For example, the verifier reports a failure if the top value on the stack is adouble and it encounters an instruction such aspop ordup. The instructionspop2 ordup2 must be used instead.
can be implemented by the following:
...new myClass(i, j, k);...
This instruction sequence leaves the newly created and initialized object on top of the operand stack. (Additional examples of compilation to the instruction set of the Java virtual machine are given inChapter 7,"Compiling for the Java Virtual Machine.")
... new#1// Allocate uninitialized space formyClassdup// Duplicate object on the operand stack iload_1// Push i iload_2// Push j iload_3// Push k invokespecial #5 // InvokemyClass.<init>...
The instance initialization method(§3.9) for classmyClass sees the new uninitialized object as itsthis argument in local variable0. Before that method invokes another instance initialization method ofmyClass or its direct superclass onthis, the only operation the method can perform onthis is assigning fields declared withinmyClass.
When doing dataflow analysis on instance methods, the verifier initializes local variable0 to contain an object of the current class, or, for instance initialization methods, local variable0 contains a special type indicating an uninitialized object. After an appropriate instance initialization method is invoked (from the current class or the current superclass) on this object, all occurrences of this special type on the verifier's model of the operand stack and in the local variable array are replaced by the current class type. The verifier rejects code that uses the new object before it has been initialized or that initializes the object more than once. In addition, it ensures that every normal return of the method has invoked an instance initialization method either in the class of this method or in the direct superclass.
Similarly, a special type is created and pushed on the verifier's model of the operand stack as the result of the Java virtual machine instructionnew. The special type indicates the instruction by which the class instance was created and the type of the uninitialized class instance created. When an instance initialization method is invoked on that class instance, all occurrences of the special type are replaced by the intended type of the class instance. This change in type may propagate to subsequent instructions as the dataflow analysis proceeds.
The instruction number needs to be stored as part of the special type, as there may be multiple not-yet-initialized instances of a class in existence on the operand stack at one time. For example, the Java virtual machine instruction sequence that implements
new InputStream(new Foo(), new InputStream("foo"))may have two uninitialized instances ofInputStream on the operand stack at once. When an instance initialization method is invoked on a class instance, only those occurrences of the special type on the operand stack or in the local variable array that are thesame object as the class instance are replaced.
A valid instruction sequence must not have an uninitialized object on the operand stack or in a local variable during a backwards branch, or in a local variable in code protected by an exception handler or afinally clause. Otherwise, a devious piece of code might fool the verifier into thinking it had initialized a class instance when it had, in fact, initialized a class instance created in a previous pass through a loop.
class file verifier since they do not pose a threat to the integrity of the Java virtual machine. As long as every nonexceptional path to the exception handler causes there to be a single object on the operand stack, and as long as all other criteria of the verifier are met, the verifier will pass the code.finallythe Java programming language guarantees that
...try {startFaucet();waterLawn();} finally {stopFaucet();}...
stopFaucet is invoked (the faucetis turned off) whether we finish watering the lawn or whether an exception occurs while starting the faucet or watering the lawn. That is, thefinally clause is guaranteed to be executed whether itstry clause completes normally or completesabruptly by throwing an exception.To implement thetry-finally construct, Sun's compiler for the Java programming language uses the exception-handling facilities together with two special instructions:jsr ("jump to subroutine") andret ("return from subroutine"). Thefinally clause is compiled as a subroutine within the Java virtual machine code for its method, much like the code for an exception handler. When ajsr instruction that invokes the subroutine is executed, it pushes its return address, the address of the instruction after thejsr that is being executed, onto the operand stack as a value of typereturnAddress. The code for the subroutine stores the return address in a local variable. At the end of the subroutine, aret instruction fetches the return address from the local variable and transfers control to the instruction at the return address.
Control can be transferred to thefinally clause (thefinally subroutine can be invoked) in several different ways. If thetry clause completes normally, thefinally subroutine is invoked via ajsr instruction before evaluating the next expression. Abreak orcontinue inside thetry clause that transfers control outside thetry clause executes ajsr to the code for thefinally clause first. If thetry clause executes areturn, the compiled code does the following:
finally clause.finally clause, returns the value saved in the local variable.try clause. If an exception is thrown in thetry clause, this exception handler does the following:finally clause.finally clause, rethrows the exception.try-finally construct, seeSection 7.13, "Compilingfinally."The code for thefinally clause presents a special problem to the verifier. Usually, if a particular instruction can be reached via multiple paths and a particular local variable contains incompatible values through those multiple paths, then the local variable becomes unusable. However, afinally clause might be called from several different places, yielding several different circumstances:
return may have some local variable that contains the return value.try clause may have an indeterminate value in that same local variable.finally clause itself might pass verification, but after completing the updating all the successors of theret instruction, the verifier would note that the local variable that the exception handler expects to hold an exception, or that the return code expects to hold a return value, now contains an indeterminate value.Verifying code that contains afinally clause is complicated. The basic idea is the following:
finally clause, it is of length one. For multiply nestedfinally code (extremely rare!), it may be longer than one.class file format:constant_pool_count field of theClassFile structure(§4.1). This acts as an internal limit on the total complexity of a single class or interface.native, non-abstract method is limited to 65536 bytes by the sizes of the indices in theexception_table of theCode attribute (§4.7.3), in theLineNumberTable attribute(§4.7.8), and in theLocalVariableTable attribute(§4.7.9).max_locals item of theCode attribute(§4.7.3) giving the code of the method. Note that values of typelong anddouble are each considered to reserve two local variables and contribute two units toward themax_locals value, so use of local variables of those types further reduces this limit.fields_count item of theClassFile structure(§4.1). Note that the value of thefields_count item of theClassFile structure does not include fields that are inherited from superclasses or superinterfaces.methods_count item of theClassFile structure(§4.1). Note that the value of themethods_count item of theClassFile structure does not include methods that are inherited from superclasses or superinterfaces.interfaces_count item of theClassFile structure(§4.1).max_stack field of theCode_attribute structure(§4.7.3). Note that values of typelong anddouble are each considered to contribute two units toward themax_stack value, so use of values of these types on the operand stack further reduces this limit.max_locals field of theCode_attribute structure(§4.7.3) and the 16-bit local variable indexing of the Java virtual machine instruction set.this in the case of instance or interface method invocations. Note that a method descriptor is defined in terms of a notion of method parameter length in which a parameter of typelong ordouble contributes two units to the length, so parameters of these types further reduce the limit.length item of theCONSTANT_Utf8_info structure(§4.4.7). Note that the limit is on the number of bytes in the encoding and not on the number of encoded characters. UTF-8 encodes some characters using two or three bytes. Thus, strings incorporating multibyte characters are further constrained.class file format versions 45.0 through 45.3 inclusive. Sun's JDK releases 1.1.X can supportclass file formats of versions in the range 45.0 through 45.65535 inclusive. Implementations of version 1.2 of the Java 2 platform can supportclass file formats of versions in the range 45.0 through 46.0 inclusive.2 In retrospect, making 8-byte constants take two constant pool entries was a poor choice.
3 The first edition ofThe Java Language Specification required that "com" be in uppercase in this example. The second edition will reverse that convention and use lowercase.
4 The fact thatend_pc is exclusive is a historical mistake in the design of the Java virtual machine: if the Java virtual machine code for a method is exactly 65535 bytes long and ends with an instruction that is 1 byte long, then that instruction cannot be protected by an exception handler. A compiler writer can work around this bug by limiting the maximum size of the generated Java virtual machine code for any method, instance initialization method, or static initializer (the size of anycode array) to 65534 bytes.
5 TheInnerClasses attribute was introduced in JDK release 1.1 to support nested classes and interfaces.
6 TheSynthetic attribute was introduced in JDK release 1.1 to support nested classes and interfaces.
7 TheDeprecated attribute was introduced in JDK release 1.1 to support the@deprecated tag in documentation comments.