Skip to content

8361635: Missing List length validation in the Class-File API #26252

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 8 commits into
base: pr/26201
Choose a base branch
from

Conversation

liach
Copy link
Member

@liach liach commented Jul 10, 2025

The class file format often only stores lists up to 65535 in size because size is encoded as a u2. Currently, we truncate the list size and write all contents, creating malformed class files. Almost all scenarios where such oversized lists are created can be considered an error; we should eagerly reject lists that would never be encodable in the class file format when users construct model objects.


Progress

  • Change must be properly reviewed (1 review required, with at least 1 Reviewer)
  • Change must not contain extraneous whitespace
  • Commit message must refer to an issue
  • Change requires CSR request JDK-8361906 to be approved

Integration blocker

 ⚠️ Dependency #26201 must be integrated first

Issues

  • JDK-8361635: Missing List length validation in the Class-File API (Bug - P4)
  • JDK-8361906: Missing List length validation in the Class-File API (CSR)

Reviewers

Reviewing

Using git

Checkout this PR locally:
$ git fetch https://git.openjdk.org/jdk.git pull/26252/head:pull/26252
$ git checkout pull/26252

Update a local copy of the PR:
$ git checkout pull/26252
$ git pull https://git.openjdk.org/jdk.git pull/26252/head

Using Skara CLI tools

Checkout this PR locally:
$ git pr checkout 26252

View PR using the GUI difftool:
$ git pr show -t 26252

Using diff file

Download this PR as a diff file:
https://git.openjdk.org/jdk/pull/26252.diff

Using Webrev

Link to Webrev Comment

@bridgekeeper
Copy link

bridgekeeper bot commented Jul 10, 2025

👋 Welcome back liach! A progress list of the required criteria for merging this PR into pr/26201 will be added to the body of your pull request. There are additional pull request commands available for use with this pull request.

@openjdk
Copy link

openjdk bot commented Jul 10, 2025

❗ This change is not yet ready to be integrated.
See the Progress checklist in the description for automated requirements.

@openjdk
Copy link

openjdk bot commented Jul 10, 2025

@liach The following label will be automatically applied to this pull request:

  • core-libs

When this pull request is ready to be reviewed, an "RFR" email will be sent to the corresponding mailing list. If you would like to change these labels, use the /label pull request command.

@openjdk openjdk bot added core-libs core-libs-dev@openjdk.org csr Pull request needs approved CSR before integration labels Jul 10, 2025
@liach liach marked this pull request as ready for review July 10, 2025 21:26
@openjdk openjdk bot added the rfr Pull request is ready for review label Jul 10, 2025
@mlbridge
Copy link

mlbridge bot commented Jul 10, 2025

Webrevs

@@ -171,7 +171,8 @@ default boolean has(AccessFlag flag) {
* @param uses the consumed services
* @param provides the provided services
* @throws IllegalArgumentException if {@code moduleFlags} is not in the
* range {@code [0, 65535]}
* range {@code [0, 65535]}, or any of the collections have more than
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm sorry, I take it back. It is OK.

Copy link
Member

@asotona asotona left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Great job for mitigating accidental building of invalid class files!

@openjdk
Copy link

openjdk bot commented Jul 13, 2025

⚠️ @liach This pull request contains merges that bring in commits not present in the target repository. Since this is not a "merge style" pull request, these changes will be squashed when this pull request in integrated. If this is your intention, then please ignore this message. If you want to preserve the commit structure, you must change the title of this pull request to Merge <project>:<branch> where <project> is the name of another project in the OpenJDK organization (for example Merge jdk:master).

@bridgekeeper
Copy link

bridgekeeper bot commented Aug 11, 2025

@liach This pull request has been inactive for more than 4 weeks and will be automatically closed if another 4 weeks passes without any activity. To avoid this, simply issue a /touch or /keepalive command to the pull request. Feel free to ask for assistance if you need help with progressing this pull request towards integration!

@liach
Copy link
Member Author

liach commented Aug 11, 2025

/touch

@openjdk
Copy link

openjdk bot commented Aug 11, 2025

@liach The pull request is being re-evaluated and the inactivity timeout has been reset.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
core-libs core-libs-dev@openjdk.org csr Pull request needs approved CSR before integration rfr Pull request is ready for review
Development

Successfully merging this pull request may close these issues.

2 participants