]> &project; Craig R. McClanahan Yoav Shapira Class Loader How-To

Like many server applications, Tomcat installs a variety of class loaders (that is, classes that implement java.lang.ClassLoader) to allow different portions of the container, and the web applications running on the container, to have access to different repositories of available classes and resources. This mechanism is used to provide the functionality defined in the Servlet Specification, version 2.4 — in particular, Sections 9.4 and 9.6.

In a Java environment, class loaders are arranged in a parent-child tree. Normally, when a class loader is asked to load a particular class or resource, it delegates the request to a parent class loader first, and then looks in its own repositories only if the parent class loader(s) cannot find the requested class or resource. Note, that the model for web application class loaders differs slightly from this, as discussed below, but the main principles are the same.

When Tomcat is started, it creates a set of class loaders that are organized into the following parent-child relationships, where the parent class loader is above the child class loader:

Bootstrap | System | Common / \ Webapp1 Webapp2 ...

The characteristics of each of these class loaders, including the source of classes and resources that they make visible, are discussed in detail in the following section.

As indicated in the diagram above, Tomcat creates the following class loaders as it is initialized:

As mentioned above, the web application class loader diverges from the default Java delegation model (in accordance with the recommendations in the Servlet Specification, version 2.4, section 9.7.2 Web Application Classloader). When a request to load a class from the web application's WebappX class loader is processed, this class loader will look in the local repositories first, instead of delegating before looking. There are exceptions. Classes which are part of the JRE base classes cannot be overridden. There are some exceptions such as the XML parser components which can be overridden using the appropriate JVM feature which is the endorsed standards override feature for Java <= 8 and the upgradeable modules feature for Java 9+. Lastly, the web application class loader will always delegate first for JavaEE API classes for the specifications implemented by Tomcat (Servlet, JSP, EL, WebSocket). All other class loaders in Tomcat follow the usual delegation pattern.

Therefore, from the perspective of a web application, class or resource loading looks in the following repositories, in this order:

If the web application class loader is configured with <Loader delegate="true"/> then the order becomes:

Starting with Java 1.4 a copy of JAXP APIs and an XML parser are packed inside the JRE. This has impacts on applications that wish to use their own XML parser.

In old versions of Tomcat, you could simply replace the XML parser in the Tomcat libraries directory to change the parser used by all web applications. However, this technique will not be effective when you are running modern versions of Java, because the usual class loader delegation process will always choose the implementation inside the JDK in preference to this one.

Java <= 8 supports a mechanism called the "Endorsed Standards Override Mechanism" to allow replacement of APIs created outside of the JCP (i.e. DOM and SAX from W3C). It can also be used to update the XML parser implementation. For more information, see: http://docs.oracle.com/javase/1.5.0/docs/guide/standards/index.html. For Java 9+, use the upgradeable modules feature.

Tomcat utilizes the endorsed mechanism by including the system property setting -Djava.endorsed.dirs=$JAVA_ENDORSED_DIRS in the command line that starts the container. The default value of this option is $CATALINA_HOME/endorsed. This endorsed directory is not created by default. Note that the endorsed feature is no longer supported with Java 9 and the above system property will only be set if either the directory $CATALINA_HOME/endorsed exists, or the variable JAVA_ENDORSED_DIRS has been set.

Note that overriding any JRE component carries risk. If the overriding component does not provide a 100% compatible API (e.g. the API provided by Xerces is not 100% compatible with the XML API provided by the JRE) then there is a risk that Tomcat and/or the deployed application will experience errors.

When running under a security manager the locations from which classes are permitted to be loaded will also depend on the contents of your policy file. See Security Manager How-To for further information.

A more complex class loader hierarchy may also be configured. See the diagram below. By default, the Server and Shared class loaders are not defined and the simplifed hierarchy shown above is used. This more complex hierarchy may be use by defining values for the server.loader and/or shared.loader properties in conf/catalina.properties.

Bootstrap | System | Common / \ Server Shared / \ Webapp1 Webapp2 ...

The Server class loader is only visible to Tomcat internals and is completely invisible to web applications.

The Shared class loader is visible to all web applications and may be used to shared code across all web applications. However, any updates to this shared code will require a Tomcat restart.