Mmc秒杀圈百科 

klassptr:查看版本 v2

由 mcst12345 于 2026-10-03 23:59 保存 · 1267 字节
{{#679BD1|class}} {{#72C7B1|oopDesc}} {{#F9D949|"{"}} {{#679BD1|volatile}} {{#72C7B1|markWord}} {{#AADAFB|_mark}}; {{#679BD1|union}} {{#72C7B1|_metadata}} {{#F9D949|"{"}} {{#72C7B1|Klass}}{{#679BD1|*}} {{#AADAFB|_klass}}; {{#74985D|// 正常指针}} {{#72C7B1|narrowKlass}} {{#AADAFB|_compressed_klass}}; {{#74985D|// 压缩指针}} {{#F9D949|"}"}} {{#AADAFB|_metadata}}; {{#F9D949|"}"}}; oopDesc是每一个java对象头部都有的结构,_metadata这个联合体保存的就是java对象的类型,所以通过更改_metadata可以控制java对象的行为。 oopDesc is part of the metadata of a Java object. Field _klass (or _compressed_klass depending on the environment) stores the type of the object. Change it can spoof the JVM of the object's type. For example <code>Unsafe unsafe = getUnsafe(); Object o = new Object(); unsafe.putInt(o,8L,unsafe.getInt(new ArrayList<>(),8L)); System.out.println(o.getClass());</code> should print "class java.util.ArrayList". **Sorry but I can't figure out how to nextline inside <code> block in this wiki Unfortunately, changing an object's klass metadata is an undefined behaviour which will corrupt the gc state that it can easily crash JVM. I personally don't recommend anyone to use it.

其他版本