Skip to content

Upgrade to Java 27 & small improvements - #570

Merged
rob93c merged 10 commits into
mainfrom
java-27-improvements
Oct 4, 2026
Merged

rob93c merged 10 commits into
mainfrom
java-27-improvements

Conversation

@MartelliEnrico

@MartelliEnrico MartelliEnrico commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary by CodeRabbit

  • Compatibility

    • The application, build environment and setup instructions now require JDK 27 or later.
    • Windows startup diagnostics are directed to error output; the Java launch command is unchanged.
  • Media

    • Video conversion now uses a single FFmpeg filter thread for each conversion pass.
  • Bug Fixes

    • Improved startup handling when operating system information is unavailable, avoiding an error if that information is missing.

- Compact Object Headers are on by default, so the jre creation was simplified
- C1 is the new GC, and for the bot usage should be better than Generational Shenandoah
These checks enable the new jdk nullability data, so nullable lib methods are properly annotated now
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 44 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 8e754f4b-b61f-4d51-82e9-3c22b38f2d26
📥 Commits

Reviewing files that changed from the base of the PR and between 45e671f and d7cf7c1.

⛔ Files ignored due to path filters (1)
  • qodana.yaml is excluded by !**/*.yaml
📒 Files selected for processing (4)
  • .dockerignore
  • .github/workflows/unit-test.yml
  • .gitignore
  • Bumpfile

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 1a9dfdd9-1a25-4146-8380-3825baee899c
📥 Commits

Reviewing files that changed from the base of the PR and between 5c9eba0 and 45e671f.

📒 Files selected for processing (2)
  • build.gradle.kts
  • buildSrc/src/main/java/com/github/stickerifier/stickerify/DownloadOpenTelemetryAgentTask.java

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The project now uses Java 27 in its build, CI, Docker builder, and setup instructions. The Gradle build updates jlink and nullability settings and packages an OpenTelemetry agent. Application code, the Windows launcher, and test helpers also change.

Changes

Project updates

Layer / File(s) Summary
Java 27 toolchain
.github/workflows/unit-test.yml, Dockerfile, README.md, buildSrc/build.gradle.kts, gradle/gradle-daemon-jvm.properties
CI, the Docker builder, setup instructions, and Gradle toolchain configuration now select Java 27.
Gradle build and OpenTelemetry packaging
build.gradle.kts, buildSrc/src/main/java/com/github/stickerifier/stickerify/JlinkTask.java, buildSrc/src/main/java/com/github/stickerifier/stickerify/DownloadOpenTelemetryAgentTask.java, gradle/libs.versions.toml, Dockerfile
The build updates jlink options and nullability settings. It downloads and packages the OpenTelemetry agent and uses it in application JVM arguments. The Docker runtime no longer downloads or configures the agent.
Application runtime settings
src/main/java/com/github/stickerifier/stickerify/bot/Stickerify.java, src/main/java/com/github/stickerifier/stickerify/media/MediaHelper.java, src/main/java/com/github/stickerifier/stickerify/process/OsConstants.java
The bot token is declared nullable, the bot.answer span is marked as a consumer span, a missing OS name is handled, and FFmpeg filter processing is limited to one thread.
Windows launcher error paths
src/main/resources/customWindowsStartScript.txt
Java lookup error messages are redirected to standard error, and both error paths jump to :exitWithErrorLevel. The source reference and compatibility comment also change.
Test helper null handling
src/test/java/com/github/stickerifier/stickerify/ResourceHelper.java, src/test/java/com/github/stickerifier/stickerify/junit/TempFilesCleanupExtension.java, src/test/java/com/github/stickerifier/stickerify/media/MediaHelperTest.java
Test helpers handle absent class loaders, temporary-directory properties, path file names, and exception messages.

Priority: ⬇️ Low

Merge Risk: 🟡 Moderate · up to 45e67

Installed launchers can fail to start when invoked outside the installation directory. Resolve the agent path before merging.

Security Architecture Review

Security architecture risk: 🟡 Moderate · up to 45e67

The packaged launchers select the monitoring agent relative to the caller's working directory. A local attacker able to place a same-named JAR there could have it loaded with the bot process's authority. The standard Docker command resolves the intended packaged agent, limiting exposure for that invocation.

Retained concerns

  • Medium · security · inferred: The generated launchers identify executable agent code by a bare relative filename rather than by the installation-owned path. If a victim launches from an attacker-writable directory containing opentelemetry-javaagent.jar, the JVM can load that JAR before application startup with the victim process's permissions and credentials. Otherwise, launching outside the distribution root can fail because the intended agent is not found. The base Docker configuration used an absolute agent path; standard head Docker startup avoids substitution through its root-directory layout, but does not protect other working-directory invocations.
Security review details

Security Blast Radius

  • inferred — Agent substitution affects individual application JVMs launched from a directory containing attacker-supplied agent bytes. Execution inherits that process's permissions and environment, potentially including the documented STICKERIFY_TOKEN. The source does not establish remote exploitability, cross-tenant access, or production-wide exposure.

Security Findings and Attack Paths

  • inferred — A local attacker places a loadable opentelemetry-javaagent.jar in a directory from which the victim invokes an installed launcher. The bare -javaagent filename selects that file rather than the installation's agent, permitting execution before the bot entry point. This requires attacker-controlled file placement and victim invocation from that directory; standard Docker startup does not meet this path-substitution scenario.

Trust Boundaries and Controls

  • inferred — Build configuration controls the requested version and destination, and HTTPS protects acquisition transport. Runtime selection nevertheless crosses from the caller's working directory into executable JVM authority without binding the selected file to APP_HOME. Telemetry-disable settings control intended telemetry behavior, not the identity or authority of substituted agent code.

Resilience and Maintainability Implications

  • inferred — Declared version and timeout inputs, a declared output file, propagated failures, and producer-before-distribution ordering provide failure containment. They do not demonstrate protection against concurrent external replacement or an interrupted direct write. Those limitations alone do not prove that a failed artifact is subsequently packaged successfully.

Hardening Proposals

  • proposed — Resolve the agent beneath the installation's APP_HOME in both launchers, with platform-appropriate quoting, rather than selecting it from the caller's working directory.
  • proposed — Strengthen the pre-existing upstream artifact trust model with a pinned expected digest, and stage downloads before verified publication to the final output. This would improve content identity and interruption recovery without treating current partial-write behavior as proven fail-open packaging.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 7.69% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 13 functions across 10 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the Java 27 upgrade and describes the additional changes as small improvements, which fits the pull request’s broad scope.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread src/main/java/com/github/stickerifier/stickerify/process/OsConstants.java Outdated
Comment thread build.gradle.kts Outdated
Comment thread qodana.yaml Outdated
@rob93c rob93c added the enhancement New feature or request label Oct 3, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2


ℹ️ Review info
⚙️ Run configuration
  • Configuration used: Repository UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 0fd6f75e-b040-44b5-b29f-76dd03185ee2
📥 Commits

Reviewing files that changed from the base of the PR and between dab606c and 5c9eba0.

📒 Files selected for processing (6)
  • Dockerfile
  • build.gradle.kts
  • buildSrc/src/main/java/com/github/stickerifier/stickerify/DownloadOpenTelemetryAgentTask.java
  • gradle/libs.versions.toml
  • src/main/java/com/github/stickerifier/stickerify/bot/Stickerify.java
  • src/main/java/com/github/stickerifier/stickerify/process/OsConstants.java
💤 Files with no reviewable changes (1)
  • Dockerfile

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

Comment thread build.gradle.kts Outdated
Comment thread build.gradle.kts
@rob93c
rob93c merged commit 5366b0b into main Oct 4, 2026
3 checks passed
@rob93c
rob93c deleted the java-27-improvements branch October 4, 2026 19:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants