-
Notifications
You must be signed in to change notification settings - Fork 231
8278851: Correct signer logic for jars signed with multiple digestalgs #262
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
👋 Welcome back goetz! A progress list of the required criteria for merging this PR into |
|
This backport pull request has now been updated with issue from the original commit. |
MBaesken
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
|
@GoeLin This change now passes all automated pre-integration checks. ℹ️ This project also has non-automated pre-integration requirements. Please see the file CONTRIBUTING.md for details. After integration, the commit message for the final commit will be: You can use pull request commands such as /summary, /contributor and /issue to adjust it as needed. At the time when this comment was updated there had been 2 new commits pushed to the
Please see this link for an up-to-date comparison between the source branch of this pull request and the ➡️ To integrate this PR with the above commit message to the |
|
/integrate |
|
Going to push as commit cbe4973.
Your commit was automatically rebased without conflicts. |
I backport this for parity with 17.0.4-oracle.
JarVerifier: resolve due to context.
ManifestEntryVerifier.java: I had to remove an argument 'false' because "JDK-8275887: jarsigner prints invalid digest/signature algorithm warnings if keysize is weak/disabled" is not in 17.
I had to add a hunk from "JDK-8269039: Disable SHA-1 Signed JARs" to
SecurityUtils.java to make a method public that is called in a test.
Progress
Issue
Reviewers
Reviewing
Using
gitCheckout this PR locally:
$ git fetch https://git.openjdk.java.net/jdk17u-dev pull/262/head:pull/262$ git checkout pull/262Update a local copy of the PR:
$ git checkout pull/262$ git pull https://git.openjdk.java.net/jdk17u-dev pull/262/headUsing Skara CLI tools
Checkout this PR locally:
$ git pr checkout 262View PR using the GUI difftool:
$ git pr show -t 262Using diff file
Download this PR as a diff file:
https://git.openjdk.java.net/jdk17u-dev/pull/262.diff