Getting started with
Java 9 modules
pom.xml pom.xml
module {} module {
module {
exports api;
Task module descriptor
module descriptor
deployment descriptor
build execution descriptor
API for custom tasks
Type declarative declarative/programmatic
Unit Java package (sub-)project
api/Foo.class internal/Qux.class api/Bar.class internal/Baz.class
api/Foo.class internal/Qux.class api/Bar.class internal/Baz.class
(system) class path
Modularity prior to Java 9 is emulated by class loader hierarchies. By tweaking class
loaders to define multiple parents, it is also possible to run several versions of the
same module (e.g. OSGi).
api/Foo.class internal/Qux.class api/Bar.class internal/Baz.class
api/Foo.class internal/Qux.class api/Bar.class internal/Baz.class
module loader
“ reads”
The integrity of the module graph is verified by the Java 9 runtime. Jars without a
module-info.class are typically contained by the unnamed module that reads all modules.
module example.qux {
module {
exports api;
module {
module {
requires transitive;
Imports are non-transitive by default (what is a good default for a runtime module system).
module {
requires java.xml;
module java.base {
exports java.lang;
exports java.util;
// ...
module java.xml {
exports org.xml.sax;
// ...
module {
exports api;
// ...
module {
requires java.xml;
module java.base {
exports java.lang;
exports java.util;
// ...
module java.xml {
exports org.xml.sax;
// ...
Modules can use non-modularized code as automatic modules (referenced by jar name).
Automatic modules export every package and import any module.
Automatic modules should only be used locally to avoid depending on a name.
module java.base {
exports java.lang;
exports java.util;
// ...
module java.xml {
exports org.xml.sax;
// ...
module {
exports api;
// ...
Non-modularized code can still run on the class path within the unnamed module.
The unnamed module imports any module but does not export any packages.
module java.base {
exports java.lang;
exports java.util;
// ...
import sun.misc.BASE64Encoder
module java.base {
exports java.lang;
exports java.util;
// ...
import sun.misc.Unsafe
module jdk.unsupported {
exports sun.misc;
// ...
module java.base {
exports java.lang;
exports java.util;
// ...
import sun.misc.Unsafe
module jdk.unsupported {
exports sun.misc;
// ...
module {
requires jdk.unsupported;
Despite its name, the jdk.unsupported module is also contained in regular JVMs.
module {
requires some.lib;
java -p foo-bar-1.0.jar Main
java -p foo-bar-qux.jar Main
name version
module {
module some.lib {
Automatic module names are instable because of:
1. The inpredictability of a jar's file name
2. The inpredictability of a dependencys future module name
Module names should follow the reverse DNS convention known from package names.
Ideally, a module name should be equal to the module's root package.
Avoid an impedance mismatch between module names and (Maven) artifact ids.
Automatic module names and module naming convention.
throws ResolutionException
class foo.Bar class pkg.Main
Loading a class from the class path.
–cp first.jar:second.jar:third.jar 
Class<?> load(String className) {
for (JarFile jarFile : getClassPath()) {
if (jarFile.contains(className)) {
return jarFile.load(className);
throw new ClassNotFoundException(className);
class foo.Bar
Packages can be split among jars unless they are sealed. Yet, sealing is vulnerable.
Loading a class from the module path.
Map<String, Module> packageToModule;
Class<?> load(String className) {
Module module = packageToModule.get(pkgName(className));
if (module != null && module.contains(className)) {
return module.load(className);
throw new ClassNotFoundException(className);
Module-Package-ownership: split packages or concealed packages are no longer permitted.
–p first.jar:second.jar:third.jar 
module java.base
module java.scripting
module java.logging module java.instrument
module java.xml
module java.sql
module java.compiler
module java.datatransfer
module java.sql.rowset
module java.naming
module java.rmi
module java.prefs
module java.activation
module java.desktop
module java.corba
module java.transaction
module java.xml.crypto
module java.xml.bindmodule
package library;
class Api {
String foo() {
return "foo";
String bar() {
return "bar";
package library;
class Api {
String foo() {
return "foo";
Dealing with "jar hell"
package library;
class Api {
String bar() {
return "bar";
library-1.0.jar library-2.0.jar
Api api = new Api();;
Api api = new Api();;
throws NoSuchMethodError
package library;
class Api {
String foo() {
return "foo";
package library;
class Api2 {
String bar() {
return "bar";
library-1.0.jar library-2.0.jar
Class<?> entryPoint = ModuleLayer.empty()
ModuleFinder.of(), // no late resolved modules
name -> makeClassLoader(name)
With little tweaking, the JPMS is however already capable of isolating packages:
Jars, modular jars and jmods.
-d target 
src/ src/pkg/
--file lib/
-C target
--class-path target
A jar file containing a module-info.class is considered a modular jar.
Both the jar and the jmod tool support a --module-version parameter.
Versions are however not currently a part of JPMS, “jar hell” is therefore not averted.
Linking modules prior to execution.
–-module-path ${JAVA_HOME}/jmods:mods 
--output myapp
Hello world!
du –hs myapp
44M myapp
./myapp/bin/java --list-modules
Jlink (as of today) can only process jmods and modular jars.
package api;
public class SomeClass {
public void foo() {
/* do something */
private void bar() {
/* do something */
Method foo = SomeClass.class.getMethod("foo");
foo.invoke(new SomeClass());
Method bar = SomeClass.class.getDeclaredMethod("bar");
bar.setAccessible(true); // check against security manager
bar.invoke(new SomeClass());
Reflection and breaking encapsulation
module {
opens api;
open module { }
JVM modules do not open any of their packages (unless specified on the command line)!
java --add-opens
java --illegal-access=<permit,deny>
module {
requires spring;
requires hibernate;
module spring {
// ...
module hibernate {
// ...
open module {
requires spring;
requires hibernate;
module {
requires spring;
requires hibernate;
opens beans;
opens dtos;
} package beans;
interface MyBean {
void foo();
package internal;
class MyBeanImpl
implements MyBean {
public void foo() {
/* ... */
Object foo = ...
module java.base {
exports java.lang;
// ...
module my.library { }
Field value = String.class.getDeclaredField("value");
value.setAccessible(true); // java.lang is not 'open'
Reflection against closed APIs is not discovered by the jdeps tool.
An existing class-path application that compiles and
runs on Java SE 8 will, thus, compile and run in
exactly the same way on Java SE 9, so long as it only
uses standard, non-deprecated Java SE APIs.
An existing class-path application that compiles and
runs on Java SE 8 will, thus, compile and run in
exactly the same way on Java SE 9, so long as it only
uses standard, non-deprecated Java SE APIs,
excluding the use of reflection on non-public members.
package java.lang;
public class ClassLoader {
protected Class<?> defineClass(String name, byte[] b,
int off, int len) {
/* define class and return */
public class MyBean
public void foo() { }
void bar() { }
public class ProxyBean extends MyBean
@Override public void foo() { }
@Override void bar() { }
MyBean mock = Mockito.mock(MyBean.class);
MyBean persisted = entityManager.merge(myBean);
MyBean bean = applicationContext.getBean(MyBean.class);
ClassLoader proxyLoader = new ProxyClassLoader(parent);
Class<?> proxy = proxyLoader.loadClass("ProxyBean");
MethodHandles.Lookup lookup = MethodHandles.lookup();
MethodHandle bar = lookup.findVirtual(MyBean.class,
bar.invoke(new MyBean());
MyBean mock = Mockito.mock(
MyBean.class, MethodHandles.lookup());
module my.library {
requires jdk.unsupported;
module jdk.unsupported {
exports sun.misc;
opens sun.misc;
// ...
module java.base {
exports java.lang;
// ...
Field theUnsafe = Unsafe.class.getDeclaredField("theUnsafe");
Unsafe unsafe = (Unsafe) theUnsafe.get(null);
unsafe.defineClass( ... );
package java.lang;
public class Accessor {
public void access() {
// within module
module my.library { }
Field value = String.class.getDeclaredField("value");
value.setAccessible(true); // java.lang is not 'open'
module example.service {
requires example.spi;
provides pkg.MyService
with impl.MyServiceImpl;
module example.spi {
exports pkg.MyService;
module {
requires example.spi;
uses pkg.MyService;
interface MyService {
String hello();
class MyServiceImpl
implements MyService {
String hello() {
return "foo";
MyService service =
Compatible with non-modularized META-INF/services entries.
public class SomeHttpClient {
void call(String url) {
try {
} catch (ClassNotFoundException ignored) {
JVMDispatcher.doCall(new URL(url).openConnection());
module library.http {
requires static
Could be substituted by using a service loader and modules that implement the binding.
module {
requires spring;
opens beans;
module {
requires spring;
requires careless.lib;
opens beans to spring;
module {
requires spring;
requires careless.lib;
opens beans;
module spring {
// ...
module careless.lib {
// has vulnerability
class Util {
void doCall(String httpVal)
throws Exception {
It is also possible to qualify exports statements for the creation of friend modules.
This can be useful for priviledged modules within the same module family.
module {
requires web.framework;
opens app;
URL ressource = getClass().getResource("/foo/bar.txt");
Resources are only visible to other modules if:
1. They reside in an exported package
2. Belong to the module conducting the lookup
3. Reside in a folder that is not a legal package-name (e.g. META-INF)
4. End with .class
abstract class BaseWebPage {
URL findTemplate() {
String name = getClass()
.getSimpleName() + ".html";
return getClass()
module web.framework {
// ...
module {
requires web.framework;
class MyWebPage
extends BaseWebPage {
/* ... */
Alternative Java module systems: OSGi and JBoss modules
abstract class ClassLoader {
final ClassLoader parent;
Class<?> findClass(String name) {
/* 1. Call parent.findClass
2. Call this.loadClass */
Class<?> loadClass(String name) { /* ... */ }
class MyModuleClassLoader extends ClassLoader {
final Set<String> selfOwned;
final Map<String, ClassLoader> visible;
@Override Class<?> findClass(String name) {
String pkg = packageOf(name);
if (selfOwned.contains(pkg)) {
return loadClass(name);
ClassLoader delegate = visible.get(pkg);
if (delegate != null) {
return delegate.findClass(name);
} else {
throw new ClassNotFoundException();
@Override Class<?> loadClass(String name) { /* ... */ }
Bundle-Name: sampleapp
Bundle-Version: 1.0
Bundle-Activator: my.Main
Import-Package: some.lib;version="1.0"
Export-Package: my.pkg;version="1.0"
module {
requires osgi.api;
requires some.lib;
exports my.pkg;
class Foo {
String bar() { return "bar"; }
assertThat(new Foo().bar(), is("Hello World!"));
public static void premain(String arguments,
Instrumentation instrumentation) {
new AgentBuilder.Default()
.transform((builder, type, loader, module) ->
.intercept(value("Hello World!"));
Java agents with Byte Buddy
class Foo {
String bar() {
long start = System.currentTimeMillis();
try {
return somethingComplex();
} finally {"Foo", "bar",
System.currentTimeMillis() - start);
class Foo {
String bar(InternalState state) {
long start = System.currentTimeMillis();
try {
return somethingComplex();
} finally {"Foo", "bar", state,
System.currentTimeMillis() - start);
class Foo {
String bar() {
return somethingComplex();
module { }
Java agents are capable of breaking module boundaries:
interface Instrumentation {
void redefineModule(Module module,
Set<Module> extraReads,
Map<String, Set<Module>> extraExports,
Map<String, Set<Module>> extraOpens,
Set<Class<?>> extraUses,
Map<Class<?>, List<Class<?>>> extraProvides);
module { exports internal.state; }
static void agentmain(String arg,
Instrumentation inst) {
/* ... */
static void agentmain(String arg,
Instrumentation inst) {
/* ... */
String processId = ...
.loadAgent(jarFile, argument);
class Foo {
void bar() {
/* ... */
class Foo$Mock extends Foo {
@Override void bar() {
class Foo {
void bar() {
if (Mockito.isMock(this)) {
/* ... */
String processId = ...
.loadAgent(jarFile, argument);
new ProcessBuilder(
"java attach.Helper <processId>"
Java platform module system: the controversy
Are modules even (still/even) useful?
Considering microservices, modules are often the better option, both considering
maintainability and performance. We have always used modules with Maven; adding
first-level support offers a chance to better interact with them at runtime.
Think of what we could have instead of Jigsaw in the time it took!
Remember the last time you had to defend a refactoring/maintenance release?
You should always clean up before you expand your feature set.
Java modules breaks all the things!
The "growth only" model is not sustainable if Java should have a future. The JVM
must at some point apply breaking changes to survive/strive.
To make full use of Java, some code needs to cross module boundaries!
Nobody relies on internal APIs for laziness but because it is necessary. Without the
openness of sun.misc.Unsafe in the past, a lot of libraries that make the JVM such
an attractive choice would not exist today. The standard library only offers basic
functionality by design. Especially test libraries and tooling have a legitimate wish
to "cross the line". As of today, any code can however still use Unsafe to leverage
low-level functionality. The standard library still relies heavily on qualified exports!

