Summary
T2.17 third slice — migrate the project's single JavaScript engine consumer from
Mozilla Rhino 1.6R7 (EOL since 2009) to Nashorn, the JDK 1.8 built-in JavaScript
engine, and drop the deprecated rhino dep. Closes the rhino CVE class in
org.mozilla:rhino:1.6R7 (the system-scoped jar at
system/lib/org/mozilla/rhino/1.6R7/rhino-1.6R7.jar).
What changes
3 files, +119 / −127:
system/src/main/java/com/percussion/extension/PSJavaScriptFunction.java —
the only consumer of rhino. Replaces the org.mozilla.javascript.* types
(Context, ErrorReporter, EvaluatorException, Function, Scriptable)
with the JSR-223 standard ScriptEngine / Invocable / Bindings /
ScriptException API plus jdk.nashorn.api.scripting.ScriptObjectMirror for
unwrapping JS Date return values. The class no longer implements
org.mozilla.javascript.ErrorReporter; the same log lines that error /
warning produced are now emitted from the catch (ScriptException) blocks
in the constructor and the runtime try in processUdf.
pom.xml — drop the org.mozilla:rhino:1.7.15.1 (system-scoped,
system/lib/org/mozilla/rhino/1.6R7/rhino-1.6R7.jar) entry from
dependencyManagement. The system-scoped jar was a 1.6R7 build anyway, and
the management entry was unused (nothing referenced it).
system/pom.xml — drop the org.mozilla:rhino <dependency> entry (no
version, fully managed by the root dep mgmt block we removed).
Behavior preserved
- Compiled functions are still cached in a static
HashMap keyed by
context/exitName with SHA-256 digest-based change detection.
- Per-call argument padding (
"" for missing trailing args) is preserved.
java.util.Date parameters are passed through to the JavaScript function
as-is; Nashorn exposes Java reflection, so JS code can call
arg.getTime() on them and pass the result to new Date(timestamp). The
original Rhino getJSDate helper is gone — Nashorn's reflective method
dispatch makes it unnecessary.
Context.jsToJava(value, Date.class) is replicated as convertToDate:
Date values pass through, Number values are treated as
milliseconds-since-epoch, and ScriptObjectMirror wrapping a JS Date is
unwrapped via mirror.callMember("getTime"). The function is documented in
the class Javadoc as best-effort.
- The
errorReporter/warning log format is preserved where the
ScriptException API allows (getLineNumber() + getColumnNumber() instead
of Rhino's getLine() + getLineOffset()).
- Runtime errors are still logged via
PSConsole.printMsg("Extension", e) and
result in a null return value.
What this PR does NOT do
- No per-UDF runtime testing. UDFs are user-defined and the test
scenarios are not in repo. Compilation + reactor build is the verification
floor; per-UDF behavioral parity needs a running CM1 instance, which is out
of scope.
- No deprecation of
PSJavaScriptFunction's package-private constructor or
the processUdf(Object[], IPSRequestContext) signature. The Rhino
migration is internal; the caller PSJavaScriptUdfExtension is unchanged.
req is now unused on the Nashorn path; kept as a parameter for binary
compatibility with the original signature.
Migration notes
- The project's
rhino dep was version 1.6R7 (a system-scoped local JAR
under system/lib/), not the public 1.7.15.1 declared in
dependencyManagement. The 1.6R7 is from 2007 and is well past EOL.
Migrating to Nashorn removes the dependency entirely on Java 1.8, and
Nashorn is part of the JDK (no extra jar needed).
- Nashorn was deprecated in JDK 11 and removed in JDK 15. This is a Java 1.8
build, so Nashorn is the right target; if the project ever migrates to
Java 11+, the Nashorn codepaths here will need a follow-up migration (the
most likely target is GraalVM's JavaScript engine, which has a
Nashorn-compatible JSR-223 facade).
- One unused import (
com.percussion.util.PSCharSets was already there for
digestString; no new imports beyond javax.script.*,
jdk.nashorn.api.scripting.ScriptObjectMirror).
Verification
./mvn-env.sh clean install -DskipTests -Dspotless.check.skip=true → BUILD
SUCCESS, 60/60 modules, 4:25 min.
grep -rln "org\.mozilla\.javascript" on the repo (excluding .worktrees/)
→ no matches.
- The JSR-223
nashorn engine is available out of the box on JDK 1.8
(confirmed: jjs shell on /usr/lib/jvm/java-8-openjdk runs the
print("Nashorn available") smoke test successfully).
References
Co-Authored by Mavis Mavis-Code using MiniMax-M3 with agent mavis.
Summary
T2.17 third slice — migrate the project's single JavaScript engine consumer from
Mozilla Rhino 1.6R7 (EOL since 2009) to Nashorn, the JDK 1.8 built-in JavaScript
engine, and drop the deprecated rhino dep. Closes the rhino CVE class in
org.mozilla:rhino:1.6R7(the system-scoped jar atsystem/lib/org/mozilla/rhino/1.6R7/rhino-1.6R7.jar).What changes
3 files, +119 / −127:
system/src/main/java/com/percussion/extension/PSJavaScriptFunction.java—the only consumer of rhino. Replaces the
org.mozilla.javascript.*types(
Context,ErrorReporter,EvaluatorException,Function,Scriptable)with the JSR-223 standard
ScriptEngine/Invocable/Bindings/ScriptExceptionAPI plusjdk.nashorn.api.scripting.ScriptObjectMirrorforunwrapping JS Date return values. The class no longer implements
org.mozilla.javascript.ErrorReporter; the same log lines thaterror/warningproduced are now emitted from thecatch (ScriptException)blocksin the constructor and the runtime try in
processUdf.pom.xml— drop theorg.mozilla:rhino:1.7.15.1(system-scoped,system/lib/org/mozilla/rhino/1.6R7/rhino-1.6R7.jar) entry fromdependencyManagement. The system-scoped jar was a 1.6R7 build anyway, andthe management entry was unused (nothing referenced it).
system/pom.xml— drop theorg.mozilla:rhino<dependency>entry (noversion, fully managed by the root dep mgmt block we removed).
Behavior preserved
HashMapkeyed bycontext/exitNamewith SHA-256 digest-based change detection.""for missing trailing args) is preserved.java.util.Dateparameters are passed through to the JavaScript functionas-is; Nashorn exposes Java reflection, so JS code can call
arg.getTime()on them and pass the result tonew Date(timestamp). Theoriginal Rhino
getJSDatehelper is gone — Nashorn's reflective methoddispatch makes it unnecessary.
Context.jsToJava(value, Date.class)is replicated asconvertToDate:Datevalues pass through,Numbervalues are treated asmilliseconds-since-epoch, and
ScriptObjectMirrorwrapping a JSDateisunwrapped via
mirror.callMember("getTime"). The function is documented inthe class Javadoc as best-effort.
errorReporter/warninglog format is preserved where theScriptExceptionAPI allows (getLineNumber()+getColumnNumber()insteadof Rhino's
getLine()+getLineOffset()).PSConsole.printMsg("Extension", e)andresult in a
nullreturn value.What this PR does NOT do
scenarios are not in repo. Compilation + reactor build is the verification
floor; per-UDF behavioral parity needs a running CM1 instance, which is out
of scope.
PSJavaScriptFunction's package-private constructor orthe
processUdf(Object[], IPSRequestContext)signature. The Rhinomigration is internal; the caller
PSJavaScriptUdfExtensionis unchanged.reqis now unused on the Nashorn path; kept as a parameter for binarycompatibility with the original signature.
Migration notes
rhinodep was version1.6R7(a system-scoped local JARunder
system/lib/), not the public1.7.15.1declared independencyManagement. The1.6R7is from 2007 and is well past EOL.Migrating to Nashorn removes the dependency entirely on Java 1.8, and
Nashorn is part of the JDK (no extra jar needed).
build, so Nashorn is the right target; if the project ever migrates to
Java 11+, the Nashorn codepaths here will need a follow-up migration (the
most likely target is GraalVM's JavaScript engine, which has a
Nashorn-compatible JSR-223 facade).
com.percussion.util.PSCharSetswas already there fordigestString; no new imports beyondjavax.script.*,jdk.nashorn.api.scripting.ScriptObjectMirror).Verification
./mvn-env.sh clean install -DskipTests -Dspotless.check.skip=true→ BUILDSUCCESS, 60/60 modules, 4:25 min.
grep -rln "org\.mozilla\.javascript"on the repo (excluding.worktrees/)→ no matches.
nashornengine is available out of the box on JDK 1.8(confirmed:
jjsshell on/usr/lib/jvm/java-8-openjdkruns theprint("Nashorn available")smoke test successfully).References
docs/ai-generated/tasks/PR#-DependencyVulnerabilityAnalysis/issues/02-epic-non-upgradeable.md(T2.17 line)
ScriptEngineAPI:https://docs.oracle.com/javase/8/docs/api/javax/script/package-summary.html
ScriptObjectMirror:https://docs.oracle.com/javase/8/docs/jdk/api/nashorn/jdk/nashorn/api/scripting/ScriptObjectMirror.html