8296343: CPVE thrown on missing content-length in OCSP response #332
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Hi!
Here is backport of JDK-8296343: CPVE thrown on missing content-length in OCSP response. The patch from
11uapplied with the following changes (except the path shuflling):jdk/src/java.base/share/classes/sun/security/provider/certpath/OCSP.javaInputStream.readAllBytes()andIOUtils.readExactlyNBytes()are not available in8jdk/test/sun/security/provider/certpath/OCSP/OCSPNoContentLength.javaList.of()andSet.of()replaced with equivalent codeVerification (amd64/20.04): newly added
test/jdk/sun/security/provider/certpath/OCSP/OCSPNoContentLength.javaFAILS, will be fixed by backporting of JDK-8300939Regression (amd64/20.04):
jdk_securityProgress
Integration blocker
Issue
Reviewing
Using
gitCheckout this PR locally:
$ git fetch https://git.openjdk.org/jdk8u-dev.git pull/332/head:pull/332$ git checkout pull/332Update a local copy of the PR:
$ git checkout pull/332$ git pull https://git.openjdk.org/jdk8u-dev.git pull/332/headUsing Skara CLI tools
Checkout this PR locally:
$ git pr checkout 332View PR using the GUI difftool:
$ git pr show -t 332Using diff file
Download this PR as a diff file:
https://git.openjdk.org/jdk8u-dev/pull/332.diff
Webrev
Link to Webrev Comment