-
Notifications
You must be signed in to change notification settings - Fork 6.2k
8367049: URLPermission.<init> throws StringIndexOutOfBoundsException in avm mode #27896
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
Hi @OumaIntissar, welcome to this OpenJDK project and thanks for contributing! We do not recognize you as Contributor and need to ensure you have signed the Oracle Contributor Agreement (OCA). If you have not signed the OCA, please follow the instructions. Please fill in your GitHub username in the "Username" field of the application. Once you have signed the OCA, please let us know by writing If you already are an OpenJDK Author, Committer or Reviewer, please click here to open a new issue so that we can record that fact. Please use "Add GitHub user OumaIntissar" as summary for the issue. If you are contributing this work on behalf of your employer and your employer has signed the OCA, please let us know by writing |
|
@OumaIntissar This change now passes all automated pre-integration checks. ℹ️ This project also has non-automated pre-integration requirements. Please see the file CONTRIBUTING.md for details. After integration, the commit message for the final commit will be: You can use pull request commands such as /summary, /contributor and /issue to adjust it as needed. At the time when this comment was updated there had been 5 new commits pushed to the
As there are no conflicts, your changes will automatically be rebased on top of these commits when integrating. If you prefer to avoid this automatic rebasing, please check the documentation for the /integrate command for further details. As you do not have Committer status in this project an existing Committer must agree to sponsor your change. Possible candidates are the reviewers of this PR (@coffeys, @Michael-Mc-Mahon, @dfuch) but any other Committer may sponsor as well. ➡️ To flag this PR as ready for integration with the above commit message, type |
|
@OumaIntissar The following label will be automatically applied to this pull request:
When this pull request is ready to be reviewed, an "RFR" email will be sent to the corresponding mailing list. If you would like to change these labels, use the /label pull request command. |
|
/covered |
|
Thank you! Please allow for a few business days to verify that your employer has signed the OCA. Also, please note that pull requests that are pending an OCA check will not usually be evaluated, so your patience is appreciated! |
|
@OumaIntissar Please do not rebase or force-push to an active PR as it invalidates existing review comments. Note for future reference, the bots always squash all changes into a single commit automatically as part of the integration. See OpenJDK Developers’ Guide for more information. |
Webrevs
|
|
The title on the JBS issue and PR is a bit confusing. Opening a URL connection shouldn't use URLPermission anymore so I think the issue (in main line) is really with code that uses the deprecated URLPermission class directly. Would it be possible to confirm this, and if confirmed, can the JBS issue be renamed? |
coffeys
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks fine to me
|
|
I agree with Alan that we should update the JBS issue title to match what is being fixed. |
Thank you for your feedback. The issue was reported specifically for JDK 17, so the current JBS issue title accurately reflects the context and version concerned. While the root cause is with The planned approach is to address and fix the issue in the main line first. Once resolved, the fix will then be backported to JDK 17 and other affected releases. |
|
I've renamed the JBS issue as it is too confusing to target main line with commit suggestion URLConnection then it's an issue with the deprecated URLPermission. |
|
/integrate |
|
@OumaIntissar This pull request has not yet been marked as ready for integration. |
17d1c7a to
409b886
Compare
|
@OumaIntissar Please do not rebase or force-push to an active PR as it invalidates existing review comments. Note for future reference, the bots always squash all changes into a single commit automatically as part of the integration. See OpenJDK Developers’ Guide for more information. |
dfuch
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM - please run tier2 before integrating.
Michael-Mc-Mahon
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks fine.
thanks! tier1, tier2 and tier3 are tested and passing well. |
a62187b to
d154b1d
Compare
|
@OumaIntissar Please do not rebase or force-push to an active PR as it invalidates existing review comments. Note for future reference, the bots always squash all changes into a single commit automatically as part of the integration. See OpenJDK Developers’ Guide for more information. |
Michael-Mc-Mahon
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
|
/integrate |
|
@OumaIntissar |
|
/sponsor |
|
Going to push as commit 5f806e7.
Your commit was automatically rebased without conflicts. |
|
@coffeys @OumaIntissar Pushed as commit 5f806e7. 💡 You may see a message that your pull request was closed with unmerged commits. This can be safely ignored. |
Constructing URLPermission with an empty/missing host in the authority (e.g.,
"http:///path") could throwStringIndexOutOfBoundsException.Problem
Empty or malformed authorities reach HostPortrange, which does
charAt(0)without checking, causingStringIndexOutOfBoundsException.Fix
URLPermission.Authority: after stripping userinfo, fail fast if host part is empty.HostPortrange: add guards for null/empty input and leading ':' (port without host).HttpURLConnectionchanges needed in JDK 26 (theSecurityManagerpermission path is gone).Compatibility
Only affects malformed inputs: previously
StringIndexOutOfBoundsException, nowIllegalArgumentException. Valid inputs unaffected.Testing
New jtreg test:
test/jdk/java/net/URLPermission/EmptyAuthorityTest.javaverifiesIllegalArgumentExceptionfor malformed authorities and success for valid ones.Progress
Issue
Reviewers
Reviewing
Using
gitCheckout this PR locally:
$ git fetch https://git.openjdk.org/jdk.git pull/27896/head:pull/27896$ git checkout pull/27896Update a local copy of the PR:
$ git checkout pull/27896$ git pull https://git.openjdk.org/jdk.git pull/27896/headUsing Skara CLI tools
Checkout this PR locally:
$ git pr checkout 27896View PR using the GUI difftool:
$ git pr show -t 27896Using diff file
Download this PR as a diff file:
https://git.openjdk.org/jdk/pull/27896.diff
Using Webrev
Link to Webrev Comment