Thursday, September 3, 2026

AI Series - Learn How to Build Java Agentic Apps with LangGraph4j and Jupyter Notebooks

A Java Multi-Turn, Multi-Agent Conversational System 

Welcome to the tutorial for building java agentic apps powered by LangChain4j and LangGraph4j. 

We will build a conversational application with two specialized agents: a career advisor and an education advisor. The graph keeps the conversation history in an in-memory checkpoint and hands the conversation between advisors when the user's intent changes.

You will learn how to:

  • Define LangChain4j tools in Java
  • Wrap specialized agents in LangGraph4j nodes
  • Pause between turns while retaining conversation state
  • Route a follow-up turn to another agent using the same thread ID

Prerequisites

Install the following before running the notebook:

  • Java 11 or newer. Check with java -version.
  • Python and JupyterLab or Jupyter Notebook. On macOS, the Jupyter documentation's Homebrew recipe is brew install jupyter. On Windows, install Python from python.org and then run pip install jupyterlab (or pip install notebook).
  • The JJava kernel. Download jjava-${version}-kernelspec.zip from the JJava GitHub releases, unzip it, and install the kernel from the directory containing the unzipped folder:
jupyter kernelspec install jjava-${version}-kernelspec --user --name=java
  • Maven 3.9 or newer, available as mvn on PATH. The dependency cell uses it to download LangGraph4j, LangChain4j, and their transitive dependencies.
  • Network access to Maven Central for the first dependency download.
  • An OPENAI_API_KEY environment variable. The key is read by Java and is never stored in this notebook.

Verify the installation with jupyter kernelspec list, then start Jupyter with jupyter lab or jupyter notebook and select the Java (jjava) kernel. If another Java kernel is already installed under the same name, remove it first with jupyter kernelspec remove java.

These requirements follow the JJava prerequisites.

Step 1: Prepare the Java dependencies

This notebook uses the Java (jjava) kernel and the LangGraph4j/LangChain4j libraries. The tutorial implementation itself is embedded below; only the third-party JARs need to be placed on the kernel classpath. Run the next Java cell once from this notebook. It writes a standalone Maven POM and downloads the dependencies without relying on the repository's Java source tree.

mkdir -p java-notebook-dependencies
cat > java-notebook-dependencies/pom.xml <<'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0">
  <modelVersion>4.0.0</modelVersion>
  <groupId>local.notebook</groupId>
  <artifactId>langgraph4j-notebook-dependencies</artifactId>
  <version>1.0.0</version>
  <dependencyManagement>
    <dependencies>
      <dependency>
        <groupId>dev.langchain4j</groupId>
        <artifactId>langchain4j-bom</artifactId>
        <version>1.19.0</version>
        <type>pom</type>
        <scope>import</scope>
      </dependency>
    </dependencies>
  </dependencyManagement>
  <dependencies>
    <dependency>
      <groupId>org.bsc.langgraph4j</groupId>
      <artifactId>langgraph4j-agent-executor</artifactId>
      <version>1.8.26</version>
    </dependency>
    <dependency>
      <groupId>org.bsc.langgraph4j</groupId>
      <artifactId>langgraph4j-langchain4j</artifactId>
      <version>1.8.26</version>
    </dependency>
    <dependency>
      <groupId>dev.langchain4j</groupId>
      <artifactId>langchain4j-open-ai</artifactId>
    </dependency>
  </dependencies>
</project>
EOF
mvn -f java-notebook-dependencies/pom.xml dependency:copy-dependencies -DincludeScope=runtime -DoutputDirectory=lib

The standalone POM downloads the direct and transitive dependencies from Maven Central into java-notebook-dependencies/lib. The optional shell commands above are equivalent to the runnable Java cell. The following classpath cell adds those JARs to jjava. No application source files are imported by this notebook.

import java.io.IOException;
import java.nio.file.Files;
import java.nio.file.Path;

Path dependencyDirectory = Path.of("java-notebook-dependencies");
Path pomFile = dependencyDirectory.resolve("pom.xml");
try {
    Files.createDirectories(dependencyDirectory);

String pom = """
        <?xml version="1.0" encoding="UTF-8"?>
        <project xmlns="http://maven.apache.org/POM/4.0.0">
          <modelVersion>4.0.0</modelVersion>
          <groupId>local.notebook</groupId>
          <artifactId>langgraph4j-notebook-dependencies</artifactId>
          <version>1.0.0</version>
          <dependencyManagement>
            <dependencies>
              <dependency>
                <groupId>dev.langchain4j</groupId>
                <artifactId>langchain4j-bom</artifactId>
                <version>1.19.0</version>
                <type>pom</type>
                <scope>import</scope>
              </dependency>
            </dependencies>
          </dependencyManagement>
          <dependencies>
            <dependency>
              <groupId>org.bsc.langgraph4j</groupId>
              <artifactId>langgraph4j-agent-executor</artifactId>
              <version>1.8.26</version>
            </dependency>
            <dependency>
              <groupId>org.bsc.langgraph4j</groupId>
              <artifactId>langgraph4j-langchain4j</artifactId>
              <version>1.8.26</version>
            </dependency>
            <dependency>
              <groupId>dev.langchain4j</groupId>
              <artifactId>langchain4j-open-ai</artifactId>
            </dependency>
          </dependencies>
        </project>
        """;
    Files.writeString(pomFile, pom);

    Process maven = new ProcessBuilder(
            "mvn", "-f", pomFile.toString(), "dependency:copy-dependencies",
            "-DincludeScope=runtime", "-DoutputDirectory=lib")
            .inheritIO()
            .start();
    int exitCode = maven.waitFor();
    if (exitCode != 0) {
        throw new IllegalStateException("Maven dependency download failed with exit code " + exitCode);
    }
    System.out.println("Dependencies are ready in " + dependencyDirectory.resolve("lib").toAbsolutePath());
} catch (IOException | InterruptedException exception) {
    if (exception instanceof InterruptedException) {
        Thread.currentThread().interrupt();
    }
    throw new IllegalStateException("Could not download Maven dependencies", exception);
}
Dependencies are ready in java-notebook-dependencies/lib
%classpath java-notebook-dependencies/lib/*

Step 2: Configure the model

Set OPENAI_API_KEY in the environment before starting Jupyter. Do not paste an API key into a notebook cell. The model and endpoint can also be overridden for an OpenAI-compatible provider such as DeepInfra.

import dev.langchain4j.agent.tool.P;
import dev.langchain4j.agent.tool.ReturnBehavior;
import dev.langchain4j.agent.tool.Tool;
import dev.langchain4j.data.message.AiMessage;
import dev.langchain4j.data.message.ChatMessage;
import dev.langchain4j.data.message.SystemMessage;
import dev.langchain4j.data.message.ToolExecutionResultMessage;
import dev.langchain4j.data.message.UserMessage;
import dev.langchain4j.model.chat.ChatModel;
import dev.langchain4j.model.openai.OpenAiChatModel;
import org.bsc.langgraph4j.CompiledGraph;
import org.bsc.langgraph4j.GraphDefinition;
import org.bsc.langgraph4j.GraphInput;
import org.bsc.langgraph4j.GraphStateException;
import org.bsc.langgraph4j.RunnableConfig;
import org.bsc.langgraph4j.StateGraph;
import org.bsc.langgraph4j.agentexecutor.AgentExecutor;
import org.bsc.langgraph4j.action.AsyncNodeAction;
import org.bsc.langgraph4j.checkpoint.MemorySaver;
import org.bsc.langgraph4j.langchain4j.serializer.std.LC4jStateSerializer;
import org.bsc.langgraph4j.prebuilt.MessagesState;
import org.bsc.langgraph4j.prebuilt.MessagesStateGraph;
import java.util.Objects;
import java.util.concurrent.CompletableFuture;
import java.util.List;
import java.util.Map;

String apiKey = System.getenv("OPENAI_API_KEY");
if (apiKey == null || apiKey.isBlank()) {
    throw new IllegalStateException("Set OPENAI_API_KEY before running the model cells.");
}

String modelName = System.getenv().getOrDefault("OPENAI_MODEL", "gpt-4o-mini");
String baseUrl = System.getenv().getOrDefault("OPENAI_BASE_URL", "https://api.openai.com/v1"); System.out.println("Using model: " + modelName); System.out.println("Using endpoint: " + baseUrl);
Using model: gpt-4o-mini
Using endpoint: https://api.openai.com/v1

Step 3: Define the agent tools

The Java implementation expresses tools with LangChain4j's @Tool and @P annotations. All tool classes are defined in the next cell, so the notebook does not depend on application source files. The advisor-specific wrappers expose only the tools that belong to each agent: getCareerPaths, getLearningResources, transfer_to_education_advisor, and transfer_to_career_advisor.

interface Advisor {
    List<ChatMessage> respond(List<ChatMessage> messages);
}

class CareerEducationTools {
    private static final List<String> CAREER_PATHS =
            List.of("data science", "product management", "cybersecurity");
    private static final Map<String, List<String>> LEARNING_RESOURCES = Map.of(
            "data science", List.of("Coursera: IBM Data Science", "edX: Harvard's Data Science Series"),
            "product management", List.of("Udemy: Become a Product Manager", "Reforge Programs"),
            "cybersecurity", List.of("Cybrary", "CompTIA Security+ Certification"));

    @Tool("Suggest career options based on general user interest.")
    public String getCareerPaths() {
        return CAREER_PATHS.get(java.util.concurrent.ThreadLocalRandom.current()
                .nextInt(CAREER_PATHS.size()));
    }

    @Tool("Provide online resources or certifications for a given career path.")
    public List<String> getLearningResources(
            @P("One of: data science, product management, cybersecurity") String career) {
        List<String> resources = LEARNING_RESOURCES.get(career.toLowerCase());
        if (resources == null) {
            throw new IllegalArgumentException("Unsupported career path: " + career);
        }
        return resources;
    }

    @Tool(value = "Ask the education advisor agent for help.",
            returnBehavior = ReturnBehavior.IMMEDIATE)
    public String transferToEducationAdvisor() {
        return "Successfully transferred to education advisor.";
    }

    @Tool(value = "Ask the career advisor agent for help.",
            returnBehavior = ReturnBehavior.IMMEDIATE)
    public String transferToCareerAdvisor() {
        return "Successfully transferred to career advisor.";
    }
}

class CareerAdvisorTools {
    private final CareerEducationTools tools;

    CareerAdvisorTools(CareerEducationTools tools) {
        this.tools = tools;
    }

    @Tool("Suggest career options based on general user interest.")
    public String getCareerPaths() {
        return tools.getCareerPaths();
    }

    @Tool(name = "transfer_to_education_advisor",
            value = "Ask the education advisor agent for help.",
            returnBehavior = ReturnBehavior.IMMEDIATE)
    public String transferToEducationAdvisor() {
        return tools.transferToEducationAdvisor();
    }
}

class EducationAdvisorTools {
    private final CareerEducationTools tools;

    EducationAdvisorTools(CareerEducationTools tools) {
        this.tools = tools;
    }

    @Tool("Provide online resources or certifications for a given career path.")
    public List<String> getLearningResources(
            @P("One of: data science, product management, cybersecurity") String career) {
        return tools.getLearningResources(career);
    }

    @Tool(name = "transfer_to_career_advisor",
            value = "Ask the career advisor agent for help.",
            returnBehavior = ReturnBehavior.IMMEDIATE)
    public String transferToCareerAdvisor() {
        return tools.transferToCareerAdvisor();
    }
}

CareerEducationTools toolSet = new CareerEducationTools();
CareerAdvisorTools careerTools = new CareerAdvisorTools(toolSet);
EducationAdvisorTools educationTools = new EducationAdvisorTools(toolSet);

System.out.println("Example career: " + toolSet.getCareerPaths());
System.out.println("Data science resources: " + toolSet.getLearningResources("data science"));
Example career: data science
Data science resources: [Coursera: IBM Data Science, edX: Harvard's Data Science Series]

Step 4: Create the specialized agents

Each agent uses the same chat model but has a different system prompt and tool set. AgentExecutor provides the ReAct-style tool-calling loop, while the embedded graph controller will decide which advisor receives the next turn.

ChatModel model = OpenAiChatModel.builder()
        .apiKey(apiKey)
        .modelName(modelName)
        .baseUrl(baseUrl)
        .temperature(0.0)
        .maxRetries(2)
        .build();

final CompiledGraph<AgentExecutor.State> careerAgent;
final CompiledGraph<AgentExecutor.State> educationAgent;
try {
    careerAgent = AgentExecutor.builder()
            .chatModel(model)
            .systemMessage(SystemMessage.from(
                    "You are a career expert. Help users explore career options. "
                            + "If they ask about courses or education, transfer to the education advisor. "
                            + "Always explain your reasoning before transferring."))
            .toolsFromObject(careerTools)
            .build()
            .compile();

    educationAgent = AgentExecutor.builder()
            .chatModel(model)
            .systemMessage(SystemMessage.from(
                    "You are an education expert. Recommend learning paths for specific careers. "
                            + "If the user changes their career preference, transfer back to the career advisor. "
                            + "Always explain your reasoning before transferring."))
            .toolsFromObject(educationTools)
            .build()
            .compile();
} catch (GraphStateException exception) {
    throw new IllegalStateException("Could not compile the advisor agents", exception);
}

Step 5: Wrap the agents in LangGraph4j advisors

The embedded Advisor functional interface accepts the complete ChatMessage history and returns the messages generated by an agent. This is the Java equivalent of the Python @task functions.

Advisor careerAdvisor = messages -> careerAgent.invoke(Map.of("messages", messages))
        .orElseThrow(() -> new IllegalStateException("Career advisor produced no state"))
        .messages();

Advisor educationAdvisor = messages -> educationAgent.invoke(Map.of("messages", messages))
        .orElseThrow(() -> new IllegalStateException("Education advisor produced no state"))
        .messages();

Step 6: Create the multi-turn controller

The embedded CareerEducationGraph is the LangGraph4j controller. It starts at the career advisor, stores messages in a MemorySaver, interrupts after each answer, and routes the next turn to the education advisor when the user asks about courses, learning, or resources. A request using the same thread ID resumes the checkpointed conversation.

class CareerEducationGraph {
    static final String CAREER_ADVISOR = "career_advisor";
    static final String EDUCATION_ADVISOR = "education_advisor";
    private static final String CAREER_WAIT = "career_wait";
    private static final String EDUCATION_WAIT = "education_wait";

    private final CompiledGraph<MessagesState<ChatMessage>> graph;

    CareerEducationGraph(Advisor careerAdvisor, Advisor educationAdvisor) {
        Objects.requireNonNull(careerAdvisor, "careerAdvisor");
        Objects.requireNonNull(educationAdvisor, "educationAdvisor");
        try {
            var serializer = new LC4jStateSerializer<MessagesState<ChatMessage>>(MessagesState::new);
            StateGraph<MessagesState<ChatMessage>> workflow = new MessagesStateGraph<>(serializer);
            workflow.addNode(CAREER_ADVISOR,
                    AsyncNodeAction.node_async(state -> invoke(careerAdvisor, state)));
            workflow.addNode(EDUCATION_ADVISOR,
                    AsyncNodeAction.node_async(state -> invoke(educationAdvisor, state)));
            workflow.addNode(CAREER_WAIT, AsyncNodeAction.node_async(state -> Map.of()));
            workflow.addNode(EDUCATION_WAIT, AsyncNodeAction.node_async(state -> Map.of()));
            workflow.addEdge(GraphDefinition.START, CAREER_ADVISOR);
            workflow.addEdge(CAREER_ADVISOR, CAREER_WAIT);
            workflow.addEdge(EDUCATION_ADVISOR, EDUCATION_WAIT);
            workflow.addConditionalEdges(CAREER_WAIT,
                    state -> CompletableFuture.completedFuture(nextAdvisor(state, CAREER_ADVISOR)),
                    Map.of(CAREER_ADVISOR, CAREER_ADVISOR, EDUCATION_ADVISOR, EDUCATION_ADVISOR));
            workflow.addConditionalEdges(EDUCATION_WAIT,
                    state -> CompletableFuture.completedFuture(nextAdvisor(state, EDUCATION_ADVISOR)),
                    Map.of(CAREER_ADVISOR, CAREER_ADVISOR, EDUCATION_ADVISOR, EDUCATION_ADVISOR));
            graph = workflow.compile(org.bsc.langgraph4j.CompileConfig.builder()
                    .checkpointSaver(new MemorySaver())
                    .interruptAfter(CAREER_WAIT, EDUCATION_WAIT)
                    .interruptBeforeEdge(true)
                    .releaseThread(false)
                    .build());
        } catch (GraphStateException exception) {
            throw new IllegalStateException("Could not compile the career conversation graph", exception);
        }
    }

    ConversationTurn turn(String threadId, String userInput) {
        if (threadId == null || threadId.isBlank()) {
            throw new IllegalArgumentException("threadId must not be blank");
        }
        if (userInput == null || userInput.isBlank()) {
            throw new IllegalArgumentException("userInput must not be blank");
        }
        var config = RunnableConfig.builder().threadId(threadId).build();
        Map<String, Object> input = Map.of(MessagesState.MESSAGES_STATE,
                List.of(UserMessage.from(userInput)));
        GraphInput graphInput = graph.stateOf(config).isPresent()
                ? GraphInput.resume(input) : GraphInput.args(input);
        var outputs = graph.stream(graphInput, config).stream().toList();
        if (outputs.isEmpty()) {
            throw new IllegalStateException("The conversation graph produced no output");
        }
        var output = outputs.get(outputs.size() - 1);
        String response = output.state().messages().stream()
                .filter(AiMessage.class::isInstance).map(AiMessage.class::cast)
                .reduce((first, second) -> second).map(AiMessage::text).orElse("");
        String advisor = CAREER_WAIT.equals(output.node()) ? CAREER_ADVISOR
                : EDUCATION_WAIT.equals(output.node()) ? EDUCATION_ADVISOR : output.node();
        return new ConversationTurn(threadId, advisor, response, true);
    }

    private static Map<String, Object> invoke(Advisor advisor, MessagesState<ChatMessage> state) {
        int previousSize = state.messages().size();
        List<ChatMessage> generated = advisor.respond(List.copyOf(state.messages()));
        if (generated == null || generated.isEmpty()) {
            throw new IllegalStateException("Advisor produced no messages");
        }
        List<ChatMessage> newMessages = generated.size() >= previousSize
                && generated.subList(0, previousSize).equals(state.messages())
                ? generated.subList(previousSize, generated.size()) : generated;
        return Map.of(MessagesState.MESSAGES_STATE, List.copyOf(newMessages));
    }

    private static String nextAdvisor(MessagesState<ChatMessage> state, String currentAdvisor) {
        for (int index = state.messages().size() - 1; index >= 0; index--) {
            var message = state.messages().get(index);
            if (message instanceof ToolExecutionResultMessage toolResult) {
                if ("transfer_to_education_advisor".equals(toolResult.toolName())) {
                    return EDUCATION_ADVISOR;
                }
                if ("transfer_to_career_advisor".equals(toolResult.toolName())) {
                    return CAREER_ADVISOR;
                }
            }
        }
        String latestUserText = state.messages().stream()
                .filter(UserMessage.class::isInstance).map(UserMessage.class::cast)
                .reduce((first, second) -> second).map(UserMessage::singleText)
                .orElse("").toLowerCase();
        if (CAREER_ADVISOR.equals(currentAdvisor)
                && containsAny(latestUserText, "course", "education", "learn", "resource")) {
            return EDUCATION_ADVISOR;
        }
        if (EDUCATION_ADVISOR.equals(currentAdvisor)
                && containsAny(latestUserText, "career", "change", "different path")) {
            return CAREER_ADVISOR;
        }
        return currentAdvisor;
    }

    private static boolean containsAny(String text, String... terms) {
        for (String term : terms) {
            if (text.contains(term)) return true;
        }
        return false;
    }

    record ConversationTurn(String threadId, String advisor, String response,
                           boolean waitingForUser) {}
}

CareerEducationGraph conversation = new CareerEducationGraph(careerAdvisor, educationAdvisor);
String threadId = java.util.UUID.randomUUID().toString();
System.out.println("Conversation thread: " + threadId);
Conversation thread: c67b69e6-2788-48ec-897d-70ae2398ae46

Step 7: Test the multi-turn conversation

The three prompts below use one stable thread ID. The first turn starts with the career advisor; the second asks about courses and is routed to the education advisor; the third remains in the education conversation. This is the Java equivalent of resuming the Python graph with Command(resume=...).

List<String> prompts = List.of(
        "I'm interested in technology but not sure what career fits me.",
        "That sounds good. What courses should I take to get started?",
        "Awesome! Are these resources beginner friendly?");

for (int index = 0; index < prompts.size(); index++) {
    String prompt = prompts.get(index);
    var turn = conversation.turn(threadId, prompt);
    System.out.println("\n--- Conversation Turn " + (index + 1) + " ---");
    System.out.println("User: " + prompt);
    System.out.println("Advisor: " + turn.advisor());
    System.out.println("Assistant: " + turn.response());
}
--- Conversation Turn 1 ---
User: I'm interested in technology but not sure what career fits me.
Advisor: career_advisor
Assistant: Based on your interest in technology, one potential career path to consider is **Data Science**.

Data Science involves using statistical and computational methods to extract insights from structured and unstructured data. It's a broad field that can lead to roles like Data Analyst, Data Scientist, or Machine Learning Engineer. It often appeals to people who enjoy problem-solving, working with numbers, and finding patterns.

Would you like to explore other tech careers, or do you have questions about the education or courses needed to become a Data Scientist? If you're interested in the educational path, I can transfer you to an education advisor.

--- Conversation Turn 2 ---
User: That sounds good. What courses should I take to get started?
Advisor: education_advisor
Assistant: To get started in Data Science, here are two highly recommended courses:

1.  **Coursera: IBM Data Science** - This course provides a comprehensive introduction to data science, covering Python, SQL, and data visualization. It's a great starting point for beginners.
2.  **edX: Harvard's Data Science Series** - This series offers a more academic approach, starting with foundational statistics and programming in R, which is excellent for building a strong theoretical background.

Would you like more details on either of these courses, or are you interested in exploring a different career path?

--- Conversation Turn 3 ---
User: Awesome! Are these resources beginner friendly?
Advisor: education_advisor
Assistant: Yes, both resources are designed to be beginner-friendly.

*   **Coursera: IBM Data Science** is structured to take you from the basics to more advanced topics, making it accessible for those new to the field.
*   **edX: Harvard's Data Science Series** also starts with foundational concepts, ensuring that even if you have no prior experience, you can build up your skills step-by-step.

Would you like to dive deeper into either of these courses, or is there anything else I can help you with?

Notes

MemorySaver is process-local and is intended for this tutorial. For a deployed application, replace it with a persistent checkpoint saver and keep the thread ID stable across requests.


You can find the downloadable jupyter notebook here. It should be fully executable provided you have fulfilled the prequisites.


Enjoy!

Dikran

Thursday, August 13, 2026

How to Get an Extra Hour of Battery Life When a Long-Running, Can’t-Stop Workload Eats It in Minutes

The situation

  • You are working on your laptop.

  • Your long-running (8-hour), terminal-launched, compute-intensive, iterative task, which produces data for the next iteration, is halfway through its work.

  • You need to take your laptop to a place where you will have no power source for a couple of hours.

  • At some point, your battery gets low and you receive a warning that the computer will soon go into sleep mode.

  • You should not put your computer to sleep because, apart from needing the computer for the activity you have there, sleep mode may interrupt connections and cause other undesired side effects that would disrupt the running task.

The solution?

1. Freeze the task/process

Get the process ID and run:

kill -STOP <your process id>

The task freezes, CPU usage drops, and your battery lasts much longer.


You can now keep working on other things, while your battery lasts much longer. I my case I it took more than an hour before getting back to my power adapter.

Once you return to a power source, plug in your laptop.

2. Unfreeze the process

Run:

kill -CONT <your process id>

Your task resumes unaffected. Your work is safe.


Note: If your task was running in a terminal, you likely won't be able to run the unfreeze command from that terminal, because the terminal process itself is already frozen.

You will need to find an alternative way to run the command. For instance:

On Mac: use the Shortcuts app → New Shortcut → Shortcut type "Run shell" → set the unfreeze command → Run.

On Linux: there are also various methods, such as the "Run Command" or "Quick Run" prompt (Alt+F2), available in most Linux GUI variants.


Disclaimer: This is based on my personal experience. I have not tested multiple cases, such as having multiple parent-child processes used by or connected to the frozen task. Test it with your particular case and use with caution.

Good luck!

Dikran

Monday, February 8, 2021

SLF4j Logging performance: lazy argument evaluation

Sometimes we need to log a dynamically generated expressions that are very expensive to compute. For instance I had to log an object to yaml format only when debug was enabled. Serializing an object to yaml is an expensive operation especially when you need to scale up to thousands of calls per second.

(As reference, I am using java 8 with slf4j-1.7.25)

If I had directly used

 log.debug("The message is:{}", toYamlString(myObject));

then the message generating method would be called every time even if debug as disabled on the logger. This is because of the java argument evaluation mechanism.

The obvious choice here is:

if(log.isDebugEnabled()){
  log.debug("The message is:{}", toYamlString(myObject));
} 

but, apart of adding unpleasing code on top of your method, this is also doubling the call on if(log.isDebugEnabled()) that is also performed in the logging framework itself.So I took some time to see if it could be done in a better way.

At some point I found this post that was nicely solving this. I liked it and wrote my code accordingly. Then I realised it could be even simpler!

So I simplified it to only this:

  private static Object lazyString(final Supplier<?> stringSupplier) {
    return new Object() {
      @Override
      public String toString() {
        return String.valueOf(stringSupplier.get());
    }
  }

Then in my logging call:

  log.debug("The message is:{}",lazyString(() -> toYamlString(myObject)));

or, if your method take no arguments, you can use method reference:

  log.debug("The message is:{}",lazyString(this::toYamlString));

That's it! Simple and elegant.

The good news is that more and more logging frameworks added or are adding native support for deferred evaluation of arguments.

Until then we can use simple nice workarounds like this.

Have a nice day,

Dikran.

Tuesday, April 3, 2018

Compile Maven project and tests with different compilers and with different unit and integration test directories

My project is java, and I wanted to give my team the possibility to use java/junit and groovy/spock for our tests.

Moreover I wanted to keep unit tests separated from integration tests and if possible with different compilation life cycles so that the flow is:

1. compile the project code from src/main/java using the default compiler
2. compile and run the unit tests using the mixed java-groovy eclipse compiler
3. compile and run the integration tests using the mixed java-groovy eclipse compiler

This way the production code is compiled natively while we can play with java-groovy mixed classes in unit and integration tests.

After digging a lot and trying many unsuccessful approaches I got it working exactly as I wished.
Here is the pom:

As you may notice, I have left the unit tests in the standard maven path ie. src/test/java, but, if I want to further move them to src/test/unit/java then I need to configure both the compiler section and the surefire-plugin section in the same way I did for the integration tests.

Basically the secret in in instructing the compiler on:
- when to run (we configure this aspect within an execution section)
- where to compile sources from - within the element compilesourceroots
- where to output classes
- what classes (by name or pattern) to include - in the element outputDirectory
and at the same time to instruct the test runner (surefire or failsafe) on:
- where the test sources are located - within testSourceDirectory
- when the test classes are located - within testClassesDirectory

One essential thing to notice is the id of each execution element (in our case default-testCompile and integration-testCompile, because maven identifies each instance by it's id s it must be uniquely named.

Another thing that many don't know is that the ids can be overridden and indeed I have used the default maven compiler id for the unit test compilation so that only the eclipse compiler shall be run instead of runing also the default compiler. you can change the id and test yourself.

 Hope that shall help you too!

Cheers, Dikran

Friday, October 14, 2016

How to install docker on centos 6 - quick and dirty

Installing docker 1.12 on centos 6.8

While doing consultancy work at one big telecom company, I proposed introducing Docker in the process of automating and autoscaling parts of the software infrastructure, especially on the the java development chain and runtime deployment sides. They were enthusiastic about this so I got the task of making it happen. Just that at the time I did not know their infrastructure (all Centos 6.8) did not support docker...

Who got here must be quite desperate, as I got for a while after taking this task.
Lots of research and trial got me to put together the following instructions that made it work.

This is an unpolished, quick hand log of what I had to do in order to make docker successfully run on this OS version.

WARNING: Be sure of your deep linux understanding and knowledge before trying this into production systems!

Hopefully it shall help. I'll come back to this post time allowing, to better arrange, document and cleanup.

Cheers,
Dikran

Wednesday, March 30, 2016

Updating all branches from all local git projects in one shot


There are many times when I need to update at once more than just one git project.
I usually structure my projects under a common directory like /Users/Dikran/workspace/projects.
When I update I cd to the respective project and git pull.

I justs happens that recently I needed two things:
1) check updated code of more than one project.
2) check changes made on other branches than the current one.

As you know, git pull is updating only the current branch in a project. Moreover it has the following limitations (quoting from git-up project):

"It merges upstream changes by default, when it's really more polite to rebase over them, unless your collaborators enjoy a commit graph that looks like bedhead.
It only updates the branch you're currently on, which means git push will shout at you for being behind on branches you don't particularly care about right now."


So in order to solve those needs at once, there is a simple solution enabled by a simple script and a great git extension called git-up. This is a very convenient tool that does many nice things in completion to what git already offers. Check the site for docs and info.

The steps:

1. Install git-up extension
For Ruby (the original):
gem install git-up
Or for the Python port:
pip install git-up

2. Create a script (i.e. updateAll.sh) in the root directory of your git subprojects, containing the following:
#!/bin/bash

set -x

for project in */
  do git -C $project up &
done

wait
The script cycles through all subdirectories in the current directory, and issues background calls to git-up on every discovered directory.

The wait is added at the end so that the script shall exit only after all directory updating commands finished.

For a variation you can filter directory names if for instance you want updated only specific directories within a certain project. So for instance if you have your main project called myshop and the composing modules are myshop-frontend/ myshop-backend/ myshop-tests/ then just change the
for project in */
with
for project in myshop*/
Thats't all. Simple, isn't it?

A warning note though. Although git-up suits most cases, please check the documentation first, to be sure it won't mess things in your specific project's commit conventions.

Have a nice day,
Dikran

Tuesday, December 1, 2015

Automated Testing Aid: Manually Running a Quartz Job

I work in a project where testing is a first class citizen. We do unit tests, security tests, integration tests, end-to-ends api tests (SBE), and end-to-end functional (interface based) tests also by using SBE.
All right, everything's fine, until I need to throw in some asserts at the end of my integration/sbe test where I should check if the whole process performed well. Ok, only that this part of the process is accomplished by quartz jobs that run asynchronously in their specific setup, beyond our control.

Note: The assumption for this post is that your Quartz scheduler can be run within the same application with your tested classes. For distributed quartz jobs there is another story.

Some could say, ok, by you have the possibility to get a job by it's name and call triggerJob(JobKey) on a quartz scheduler instance, that should trigger the job immediately. But, be careful is about triggering a job, and not running the job. That means that:

  • the command is asynchronous and return immediately;
  • the job could actually start later, depending on the schedule's config and
  • you don't actually know when the job shall finish so that you can test your assumptions about the outcome of it.

Two quick solutions:
  1. after test's execution finished, before asserting on data, sleep the test thread for a while to give quartz time to do it's work. But sleep for how long? Some manual tries could give us some empirical idea of how long should we wait before the jos is usually executed, but we are never going to be 100% sure it actually was. And then, this approach could bring the execution of our test suite to last forever, imagine running hundreds of tests of this type that each are sleeping for few seconds... It doesn't sound very appealing.
  2. add a JobListener listener to the scheduler, then trigger the job and then put your main thread in wait until the listener is triggered on execution finished, and notifies your main thread so it can resume it's testing task. But, again, there might be many jobs already triggered and running until ours get's it's change to run. And after all, would you really want to get into unexpected threading issues? I think not.

So, after trying the aforementioned approaches and not really being happy with them I thought, why not directly run the jobs I am directly interested in?
Well this is not that trivial, because I'd like to run the jobs as they are, without having to know what other stuff is injected in each of my classes extending QuartzJob in order to make it work. So, after some research and study of how quartz works in collaboration with spring, that is what came out:


import org.quartz.Job;
import org.quartz.JobExecutionContext;
import org.quartz.Scheduler;
import org.springframework.beans.BeanWrapper;
import org.springframework.beans.BeansException;
import org.springframework.beans.MutablePropertyValues;
import org.springframework.beans.PropertyAccessorFactory;
import org.springframework.context.ApplicationContext;
import org.springframework.context.ApplicationContextAware;

import java.lang.reflect.Method;
import java.util.Map;

public class ManualJobExecutor implements ApplicationContextAware {

    private ApplicationContext applicationContext;

    public void executeJob(final Class<Job> jobClass) {

        try {
            //create job instance
            final Job quartzJob = jobClass.newInstance();
            // For the created job instance, search all services that are injected by quartz.
            // Those service instances are kept inside each scheduler context as a map
            final BeanWrapper beanWrapper = PropertyAccessorFactory.forBeanPropertyAccess(quartzJob);
            final MutablePropertyValues propertyValues = new MutablePropertyValues();
            //get all schedulers defined across all spring configurations for this application
            final Map<String, Scheduler> schedulers = applicationContext.getBeansOfType(Scheduler.class);
            for (final Scheduler scheduler : schedulers.values()) {
                // Populate the possible properties with service instances found
                propertyValues.addPropertyValues(scheduler.getContext());
            }
            //set the properties of the job (injected dependencies) with the matching services
            //the other services in the list that have no matching properties shall be ignored 
            beanWrapper.setPropertyValues(propertyValues, true);

            //get method executeInternal(JobExecutionContext) from job class extending QuartzJobBean 
            final Method executeJobMethod = quartzJob.getClass().getDeclaredMethod("executeInternal", (JobExecutionContext.class));
            executeJobMethod.setAccessible(true);
            //call the processItems method on the Job class instance
            executeJobMethod.invoke(quartzJob);
        } catch (final Exception e) {
            throw new RuntimeException(String.format("Exception while retrieving and executing job for name=%s", jobClass.getName()), e);
        }
    }

    @Override
    public void setApplicationContext(final ApplicationContext applicationContext) throws BeansException {
        this.applicationContext = applicationContext;
    }
}

That's it!
Of course there are also other aspects, i.e checking if other job of the same class is already executing so that it won't overlap with your execution. Usually in Quarz, @DisableConcurrentExecution takes care of this but here you need to check it yourself.
You could also make your method accept a job by its name instead of class so you can get the names from your database instead of looking into project classes.

I hope this is going to ease your testing.
Please share your thoughts.


Have a nice day,
Dikran

Wednesday, May 27, 2015

Spring Boot & Jasypt easy: Keep your sensitive properties encrypted


Goal


I want to store my database password encrypted in the application properties file and provide the property encryption password at runtime as java system property or environment variable.

Context:


Java 7, Spring Boot 1.2.3.RELEASE
Currently Spring Boot does not offer native property encryption support.

Solution


Use jasypt encryption library and integrate it into Spring Boot's configuration flow.

How?
Here is a quick and dirty example:

1. Download jasypt and unzip the contents in a folder;
2. Choose a password for encrypting your sensitive properties; for the purpose of this example we choose "my-encryption-password";
3. Choose the property you want encrypted; here we choose to encrypt the database password "my-database-password";
4. Encrypt the database password ("my-database-password") using jasypt and the encryption password ("my-encryption-password"); go into the jasypt bin folder and run:

$ encrypt.sh  input=my-database-password password=my-encryption-password

----ENVIRONMENT-----------------

Runtime: Oracle Corporation Java HotSpot(TM) 64-Bit Server VM 24.60-b09

----ARGUMENTS-------------------

input: my-database-password

password: my-encryption-password

----OUTPUT----------------------

TJ1vA+DLWFrwEmbZKmGmawEonbJw4DxhkFf53JzKfvY=

The output is the encrypted password.
To configure the database in the SpringBoot's application.properties we add:

#for this example we use H2 database
spring.datasource.driver-class-name=org.h2.Driver
spring.datasource.url=jdbc:h2:mem:my-schema
spring.datasource.username=test-user

#here we provide the database encrypted password by enclosing in ENC()
#so that jasypt can detect and decrypt it
spring.datasource.password=ENC(TJ1vA+DLWFrwEmbZKmGmawEonbJw4DxhkFf53JzKfvY=)


Integrating Spring Boot and Jasypt


In order to instruct Spring Boot to transparently interpret our property file and extract and decrypt the encrypted properties we need to:

1. Create a PropertySourceLoader implementation that knows how to parse property files, identify encrypted properties and decrypt them before making them available to other components. Also the class knows to get the encryption password from system properties (provided at command line by -Dproperty.encryption.password=my-encryption-password) or as an environment variable in the operating system (export PROPERTY_ENCRYPTION_PASSWORD="my-encryption-password"). Listing follows:
package com.myexample;

import org.jasypt.encryption.pbe.StandardPBEStringEncryptor;
import org.jasypt.spring31.properties.EncryptablePropertiesPropertySource;
import org.springframework.boot.env.PropertySourceLoader;
import org.springframework.core.PriorityOrdered;
import org.springframework.core.env.PropertySource;
import org.springframework.core.io.Resource;
import org.springframework.core.io.support.PropertiesLoaderUtils;

import java.io.IOException;
import java.util.Properties;


/**
 * This class is a replacement for the default Spring PropertySourceLoader. It has the capability of detecting
 * and decrypting encrypted properties via Jasypt Encryption Library.
 * The decryption password must be provided via an environment variable or via a System property. The name of the property can be {@code PROPERTY_ENCRYPTION_PASSWORD} or {@code property.encryption.password}.
 * For more information see http://www.jasypt.org/ and http://www.jasypt.org/spring31.html
 * For Spring Boot integration the default {@link PropertySourceLoader} configuration was overriden by
 * META-INF/spring.factories file.
 *
 * @see org.springframework.boot.env.PropertySourceLoader
 */

public class EncryptedPropertySourceLoader implements PropertySourceLoader, PriorityOrdered {

    private static final String ENCRYPTION_PASSWORD_ENVIRONMENT_VAR_NAME_UNDERSCORE = "PROPERTY_ENCRYPTION_PASSWORD";
    private static final String ENCRYPTION_PASSWORD_ENVIRONMENT_VAR_NAME_DOT = "property.encryption.password";
    private static final String ENCRYPTION_PASSWORD_NOT_SET = "ENCRYPTION_PASSWORD_NOT_SET";

    private final StandardPBEStringEncryptor encryptor = new StandardPBEStringEncryptor();

    public EncryptedPropertySourceLoader() {
        this.encryptor.setPassword(getPasswordFromEnvAndSystemProperties());
    }

    private String getPasswordFromEnvAndSystemProperties() {
        String password = System.getenv(ENCRYPTION_PASSWORD_ENVIRONMENT_VAR_NAME_UNDERSCORE);
        if (password == null) {
            password = System.getenv(ENCRYPTION_PASSWORD_ENVIRONMENT_VAR_NAME_DOT);
            if (password == null) {
                password = System.getProperty(ENCRYPTION_PASSWORD_ENVIRONMENT_VAR_NAME_UNDERSCORE);
                if (password == null) {
                    password = System.getProperty(ENCRYPTION_PASSWORD_ENVIRONMENT_VAR_NAME_DOT);
                    if (password == null) {
                        password = ENCRYPTION_PASSWORD_NOT_SET;
                    }
                }
            }
        }
        return password;
    }

    @Override
    public String[] getFileExtensions() {
        return new String[]{"properties"};
    }

    @Override
    public PropertySource load(final String name, final Resource resource, final String profile) throws
            IOException {
        if (profile == null) {
            //load the properties
            final Properties props = PropertiesLoaderUtils.loadProperties(resource);

            if (!props.isEmpty()) {
                //create the encryptable properties property source
                return new EncryptablePropertiesPropertySource(name, props, this.encryptor);
            }
        }

        return null;
    }

    @Override
    public int getOrder() {
        return HIGHEST_PRECEDENCE;
    }
}

2. Create a com/myexample/META_INF/spring.factories file to override the default PropertyResurceLoader (org.springframework.boot.env.PropertiesPropertySourceLoader) which is provided with the Spring Boot distribution in META-INF/spring.factories. Our file should contain one line as follows:
org.springframework.boot.env.PropertySourceLoader=com.myexample.EncryptedPropertySourceLoader

That's it! Now your application should be able to use encrypted properties.

Thanks for reading!
Dikran

To give the right credits, info that helped me solving the problem and writing this post were gathered from this Stackoverflow post.


Friday, October 5, 2012

Scrum and Story Points, what's the story?

After working with scrum for a while and watching this debate of time vs story points I came to a personal conclusion that helped me to make better estimations and use the story points at their best value.

  In my opinion story points best measure risk. You estimate this risk taking into account your proficiency, overall experience and the expertise in the technology, the project and it's business, the dependencies involved that you need to rely on to move forward (could be external systems/teams, business analysts, other people availability) and your average capacity of solving problems in a given time.

  So when it comes to estimating a user story you should ask yourself: “what is the risk of this story?” I would categorize the risk vs story points as follows:

1 point - Virtually no risk, insignificant work doable in a very short time

3 points - Extremely low risk, know all about it can do it quickly, probably a matter of 1-2 hours

5 points - Low risk, know most about what I need to do, probably can fit in few hours to one working day

8 points - Medium risk, know quite well about what I need to do, I might have some unexpected obstacles and maybe some dependencies on other (external) resources, but I am confident I can do it in 1-3 days.

13 points - High risk, there are aspects about I have no idea on how to tackle, have external dependencies about that I am worried, it might take half of a sprint to get it done.

21 points - Highest risk, I have right now no knowledge about the subject and no idea of how to do it, there are lots of dependencies on other (external) resources that I cannot manage, I am not sure I can solve it in a sprint so that story becomes demoable. Then you should ask yourself: is this really a good story or rather an epic? Shouldn't  it better go into a research spike first so that we gather more knowledge about how to do it?

However, when you estimate always take into consideration collateral aspects such as unit/functional/integration test writing (that can take as much or more than time need to code functionality), team communication, code reviews and other things that should be part of your development process.

What do you think?

Cheers,
Dikran.

Tuesday, September 25, 2012

Always Elevated Privileges in Windows 7

As a developer I usually need to execute lots of commands and programs that require administrative privileges. Although my Windows user is in the Administrators group I always needed to do "Run as administrator" on command prompt, text editors and other applications that required privilege elevation, even if they were created by me or by programs that I launched!
After digging a little through Windows permissions system system I found out that in order to improve security and minimize virus propagation risks, the windows team has decided that even if you are in the administrator group, and even if you are the Administrator, there is better to explicitly grant yourself the rights to do elevated privileges in an interactive way, so that underground malicious programs would not be able to go through without you knowing this.
That said, I am quite sure that an experienced user can do fine even without this kind of assistance, especially in corporate environments where almost everything is filtered and secured.

So, to grant yourself elevated privileges without prompt you need to:
1. open security policy configuration, by typing in the command prompt:

%windir%\system32\secpol.msc /s

A window titled "Local Security Policy" should open as below:


2. Navigate to the Security Options node:


3. On the right side click on the "Policy" table header at the top to order alphabetically the entries so that you shall have all entries starting with "User Account Control" easy to spot.

4. Select the entry called "User Account Control: Run all administrators in Admin Approval Mode":


5. Here it is all. When activated, this option instructs Windows to ask for your permission every time when elevated privileges are required, even if you already own them. Double click on the entry and set this option to Disabled. It will require you to  restart Windows in order to get effective:


As a bottom line, be sure that you know what you are doing, as this will downgrade your system's overall security.

Good luck!

Wednesday, May 4, 2011

Tailing log files over SSH in Windows

My problem: I wanted to be able to track logs on Unix machines using BareTail or something similar.
Until now the only solution was to use putty and log console output into a local file, then open it with BareTail.
Disadvantages: for each log file had to open another putty.

Solution:
Dokan SSHFS (SSH File System)
It's a file system mapping application that allows a remote file system map to a Windows local drive.
After I installed the one I could open all 6 log files with baretail as if it was on a
local drive (N).

Installation Steps:
1. Install the NET 2.0 Runtime;
2. Install the Visual C++ 2005 Runtime;
3. Install the Dokan library 0.6
4. Install the Dokan sshfs 0.2;
5. Download the Dohan sshfs 0.6;
6. From 0.6 zip copy DokanSSHFS.exe and DokanNet.dll over the files installed by the 0.2 installer. This is because there is no yet an installer for the 0.6 version;
7. Run DokanSSHFS.exe then choose the remote path, username and password, and choose the letter for windows drive to be assigned;
8. In the options tab to check the cache disable;
9. Click on CONNECT

From this moment you have a new drive in Windows where you can work normally with explorer, BareTail, etc. plus an icon in the Windows taskbar that allows mount/unmount on-the-fly
I hope you will find this useful.

Update:
There is an excellent log viewer called LogExpert that can directly use tailing over sftp on *nix servers. In my opinion this is the most complete log viewer at least for Windows: highliting, regular expression filtering in a separate panel, columnizers and a lot of other useful stuff. Try it with confidence.

Good luck!

Dikran

Saturday, October 10, 2009

How to know when Java Virtual Machine is shutting down

The question is: why would someone need to know such thing?

You already have the jdk's Runtime.getRuntime().addShutdownHook() method that adds your thread to be called when the jvm is shutting down. So why another way?

Well, I would have asked the same thing if I didn't experience an unusual situation.
(For the inpatient reader that wants to skip the story, you can jump directly to the answer)

I was working on a complex web aplication that was running in a jBoss/Tomcat container. We needed a clean server shutdown in order to release  the resources (connection pools, sockets, temporary files, etc). At a certain moment the team members noticed that the undeploy operation worked well while the majority of the shutdowns (but not all) were hanging at a certain point. The displayed reason was a strange exception raised from the AWT thread:

Exception in thread "AWT-Windows" java.lang.IllegalStateException: Shutdown in progress
at java.lang.Shutdown.add(Shutdown.java:81)
at java.lang.Runtime.addShutdownHook(Runtime.java:190)

We could not understand why the exception would come from the AWT as we were not using at all the AWT in our application... Or at least we didn't know it... However, who was calling the Runtime.addShutdownHook() and why was it driving to a jvm crash?

After digging around the problem I discovered that, indeed, we were using AWT, although indirectly, by using a reporting engine. And that reporting engine was using classes of AWT to do it's job. The reporting library that we were using was packaged as a Struts plugin. The plugin's contract is simple: Struts calls the  init() method at startup and the destroy()method at shutdown, on all the registered plugins. The plugin's control class was a singleton that was simply redirecting the destroy() calls to it's internal methods. Of course, after creating an instance of itself.
So what? you may say. This is the normal way to do such things.
Yes, only that, in this particular case, unless you used the reporting feature while working with the application, the reporting engine was not initialized until shutdown. So, at server's shutdown, Struts was calling destroy on all it's plugins and at his turn the reporting plugin, inside it's destroy() method, was calling ReportsInitializer.getInstance().shutdown(). And... Boom! JVM freeze.

Ok, but why? It's just a class instance that does something within itself! What might drive it to crash all the system?
Well, the nice part is just coming. So, we have a system shutdown and a Struts plugin called that is instantiating some class that uses some AWT elements inside. It does not look like something to be scared of... Only that there is a catch: when a class AWT is instantiated, the AWT Toolkit itself adds a ShutDownHook  to the  Runtime. I haven't yet dug inside to understand why. But, as java specs state, it is illegal to add a  ShutdownHook  if the JVM shutdown sequence has already started.
Some people consider that this behavior inside AWT is a bug, because AWT should check itself if the JVM is shutting down before attempting to add its own ShutdownHook.
Ok. now, we found the reason why all happened. What next? I evaluated three possible solutions:
- to add a generic thread exception handler and simply "swallow" this exception.
- to add a myself a ShutdownHook and set some flag on the reporting reporting plugin not to instantiate anymore the reporting initializer.
- to detect (inside the destroy method in the plugin) if the virtual machine is shutting down and skip calling the reporting initializer.

The solution I chose was the last, because the generic thread exception handler couldn't prevent the exception to happen, and for the second option, the order in which JVM calls the ShutdownHooks  is not guaranteed, so you'll never know if it will be called before or after the Struts's own ShutdownHook, making of the solution a non deterministic one.

So I made some research to see if I may possibly know at any time if the Java Virtual Machine is shutting down. I discovered that when java.lang.Runtime.exit(int status) is called, it forwards the call to a class named java.lang.Shutdown.exit(int status), that calls all the ShutdownHooks before calling the native halt() method. Inside this class there are fields describing the state of the system. Unfortunately the class is private package and there is no public method that returns the System's state. But luckily, in Java we have the blessed reflection. So, here comes the answer:


private boolean isSystemShuttingDown() {
  try {
    Field running = Class.forName("java.lang.Shutdown").getDeclaredField("RUNNING");
    Field state = Class.forName("java.lang.Shutdown").getDeclaredField("state");
    running.setAccessible(true);
    state.setAccessible(true);
    return state.getInt(null) > running.getInt(null);
  }
  catch (Exception ex) {
    ex.printStackTrace();
    return false;
  }
}

I would not advise anyone to use this on a daily basis unless he is exceptionally needing such a solution, primarily because:
- the java.lang.Shutdown class is a package private class in the JDK and it may be changed or removed in any upcoming release. Of course, for custom built projects, that usually run for a long time on a single jdk version this is not such a big issue.
- In public distributions there is a chance that the SecurityManager is set to forbid the access to jdk internals. But again, inside custom projects you can configure your own SecurityManager.

I hope that you enjoyed reading this post and I am waiting for your comments.

Greetings,
Dikran

P.S. Thanks to Alex Gorbatchev for his excellent SyntaxHighlighter.